<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git, branch mickledore-next</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2024-01-07T18:15:11+00:00</updated>
<entry>
<title>nginx: fix CVE-2023-44487</title>
<updated>2024-01-07T18:15:11+00:00</updated>
<author>
<name>Meenali Gupta</name>
<email>meenali.gupta@windriver.com</email>
</author>
<published>2023-12-21T03:45:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=8e1f0fa6bfac0e96fedc666fe9066f92c85afb27'/>
<id>urn:sha1:8e1f0fa6bfac0e96fedc666fe9066f92c85afb27</id>
<content type='text'>
The HTTP/2 protocol allows a denial of service (server resource consumption)
because request cancellation can reset many streams quickly,
as exploited in the wild in August through October 2023.

Signed-off-by: Meenali Gupta &lt;meenali.gupta@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>poco: fix branch</title>
<updated>2024-01-07T18:15:11+00:00</updated>
<author>
<name>Alexandre Belloni</name>
<email>alexandre.belloni@bootlin.com</email>
</author>
<published>2023-12-20T14:47:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=b0d67900ae9e8911f734c25c0674fe55df8cd188'/>
<id>urn:sha1:b0d67900ae9e8911f734c25c0674fe55df8cd188</id>
<content type='text'>
The current SRCREV is not on any branch anymore, switch to the 1.12.4
branch HEAD which is similar and the only change is irrelevant.

Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Martin Jansa &lt;martin.jansa@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-django: move to version 4.2.7</title>
<updated>2023-12-04T14:47:03+00:00</updated>
<author>
<name>Joe Slater</name>
<email>joe.slater@windriver.com</email>
</author>
<published>2023-11-27T20:24:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=f29290563cb821fae95340ba959749641c69ed7f'/>
<id>urn:sha1:f29290563cb821fae95340ba959749641c69ed7f</id>
<content type='text'>
Version 4.2.5 fixes CVE-2023-36053 and CVE-2023-41164.
Version 4.2.7 fixes CVE-2023-46695 and CVE-2023-43665.

Signed-off-by: Joe Slater &lt;joe.slater@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-gcovr: switch to main branch</title>
<updated>2023-12-04T14:47:03+00:00</updated>
<author>
<name>Christian Eggers</name>
<email>ceggers@arri.de</email>
</author>
<published>2023-11-24T07:40:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=ad7da539788b28436dfecaaf88768a0ca2c013e5'/>
<id>urn:sha1:ad7da539788b28436dfecaaf88768a0ca2c013e5</id>
<content type='text'>
Branch "master" has been renamed to "main".

Signed-off-by: Christian Eggers &lt;ceggers@arri.de&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>gattlib: Upgrade to latest tip of trunk</title>
<updated>2023-12-04T14:47:03+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2023-11-22T09:40:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=c6eb66377af7f06105a938b8a947f3a17660c672'/>
<id>urn:sha1:c6eb66377af7f06105a938b8a947f3a17660c672</id>
<content type='text'>
License-Update: Year changed [1]

Remove build directory from include directives in generated sourcecode
via gdbus-codegen

Upgrade includes fix for CVE-2019-6498

[1] https://github.com/labapart/gattlib/commit/5c87eda925c597e72107b5026c6b8d490ce76d62

Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Tan Wen Yan &lt;wen.yan.tan@intel.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>libvpx: upgrade 1.13.0 -&gt; 1.13.1</title>
<updated>2023-12-04T14:47:03+00:00</updated>
<author>
<name>Benjamin Bara</name>
<email>benjamin.bara@skidata.com</email>
</author>
<published>2023-11-22T03:14:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=d1cb0ddb0142d43e4258818b0bf302ff3706ddb6'/>
<id>urn:sha1:d1cb0ddb0142d43e4258818b0bf302ff3706ddb6</id>
<content type='text'>
Changelog:
=========
This release contains two security related fixes. One each for VP8 and
VP9.

- Upgrading:
  This release is ABI compatible with the previous release.

- Bug fixes:
  https://crbug.com/1486441 (CVE-2023-5217)
  Fix to a crash related to VP9 encoding (#1642)

Signed-off-by: Benjamin Bara &lt;benjamin.bara@skidata.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Tan Wen Yan &lt;wen.yan.tan@intel.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>wireshark: Fix CVE-2023-2906</title>
<updated>2023-12-04T14:47:03+00:00</updated>
<author>
<name>Hitendra Prajapati</name>
<email>hprajapati@mvista.com</email>
</author>
<published>2023-11-15T18:34:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=8d511904a5850439d44253af15a21cb3c0b2f6fa'/>
<id>urn:sha1:8d511904a5850439d44253af15a21cb3c0b2f6fa</id>
<content type='text'>
Upstream-Status: Backport from https://gitlab.com/wireshark/wireshark/-/commit/44dc70cc5aadca91cb8ba3710c59c3651b7b0d4d

Signed-off-by: Hitendra Prajapati &lt;hprajapati@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
(cherry picked from commit 919a2074586ff957362ae2dbd3438fa648bb9bee)
Signed-off-by: Deepak Rathore &lt;deeratho@cisco.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>nlohmann-json: Add ptest support</title>
<updated>2023-11-17T02:49:15+00:00</updated>
<author>
<name>Mingli Yu</name>
<email>mingli.yu@windriver.com</email>
</author>
<published>2023-11-10T11:52:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=aa5e8edabbc414d8ec1b2ad63c8743c7baf99626'/>
<id>urn:sha1:aa5e8edabbc414d8ec1b2ad63c8743c7baf99626</id>
<content type='text'>
* Backport 2 patches [1] [2] to fix the build failure under tests dir.

* Fetch the test data during do_fetch phase to avoid internet access
during test as some tests need test data.
 # ./run-ptest
PASS: test-algorithms_cpp11
PASS: test-allocator_cpp11
PASS: test-alt-string_cpp11
PASS: test-assert_macro_cpp11
PASS: test-binary_formats_cpp11
[snip]
PASS: test-unicode5_cpp11
PASS: test-user_defined_input_cpp11
PASS: test-windows_h_cpp11
PASS: test-wstring_cpp11

[1] https://github.com/nlohmann/json/commit/6cec5aefc97ad219b6fd5a4132f88f7c8f6800ee
[2] https://github.com/nlohmann/json/commit/660d0b58565073975d6f5d94365d6cbf150a4cf8

Signed-off-by: Mingli Yu &lt;mingli.yu@windriver.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit 013b4d50432a3eba08a9cb54b9edf6b25a6378a8)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>traceroute: upgrade 2.1.2 -&gt; 2.1.3</title>
<updated>2023-11-17T02:49:15+00:00</updated>
<author>
<name>Narpat Mali</name>
<email>narpat.mali@windriver.com</email>
</author>
<published>2023-11-15T11:56:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=3265d38e8344081d9780a43d27bc26f748b4187c'/>
<id>urn:sha1:3265d38e8344081d9780a43d27bc26f748b4187c</id>
<content type='text'>
This upgrade incorporates the CVE-2023-46316 fix.

Changelog:
----------
- Fix command line parsing in wrappers.

References:
https://security-tracker.debian.org/tracker/CVE-2023-46316
https://sourceforge.net/projects/traceroute/files/traceroute/traceroute-2.1.3/

Signed-off-by: Narpat Mali &lt;narpat.mali@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>open-vm-tools: fix CVE-2023-34058</title>
<updated>2023-11-17T02:49:15+00:00</updated>
<author>
<name>Archana Polampalli</name>
<email>archana.polampalli@windriver.com</email>
</author>
<published>2023-11-14T05:49:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=76ed1e8bc43bf26c9b33d96696d5acb46743c001'/>
<id>urn:sha1:76ed1e8bc43bf26c9b33d96696d5acb46743c001</id>
<content type='text'>
A flaw was found in open-vm-tools. This flaw allows a malicious actor that
has been granted Guest Operation Privileges in a target virtual machine to
elevate their privileges if that target virtual machine has been assigned
a more privileged Guest Alias.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-34058

Signed-off-by: Archana Polampalli &lt;archana.polampalli@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
</feed>
