<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git, branch stable/dufell-nut</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=stable%2Fdufell-nut</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=stable%2Fdufell-nut'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2021-12-27T21:23:37+00:00</updated>
<entry>
<title>dovecot: refresh patches</title>
<updated>2021-12-27T21:23:37+00:00</updated>
<author>
<name>Armin kuster</name>
<email>akuster808@gamil.com</email>
</author>
<published>2021-12-27T21:22:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=95969f0f5f4264644a5dbfb6d4fb66e2ac3a2cde'/>
<id>urn:sha1:95969f0f5f4264644a5dbfb6d4fb66e2ac3a2cde</id>
<content type='text'>
Signed-off-by: Armin kuster &lt;akuster808@gamil.com&gt;
</content>
</entry>
<entry>
<title>postgresql: Update to 12.9</title>
<updated>2021-12-27T19:50:07+00:00</updated>
<author>
<name>Robert Joslyn</name>
<email>robert.joslyn@redrectangle.org</email>
</author>
<published>2021-12-27T18:40:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=197453e127c7a30b2b3ef0c24180e2d31c2fb572'/>
<id>urn:sha1:197453e127c7a30b2b3ef0c24180e2d31c2fb572</id>
<content type='text'>
Bug and security fixes. Fix patch fuzz as well to remove bitbake
warning. Release notes available at:

https://www.postgresql.org/docs/release/12.8/
https://www.postgresql.org/docs/release/12.9/

12.8 fixes:
CVE-2021-3677

12.9 fixes:
CVE-2021-23214
CVE-2021-23222

Signed-off-by: Robert Joslyn &lt;robert.joslyn@redrectangle.org&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>libmicrohttpd: Add patch to fix CVE-2021-3466</title>
<updated>2021-12-27T19:50:03+00:00</updated>
<author>
<name>Ernst Sjöstrand</name>
<email>ernst.sjostrand@verisure.com</email>
</author>
<published>2021-12-22T09:56:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=ddaf5f92cc553ce7deb43a39de7a731a2f081d2d'/>
<id>urn:sha1:ddaf5f92cc553ce7deb43a39de7a731a2f081d2d</id>
<content type='text'>
Extract patch from the 0.9.71 release commit.

Upstream-Status: Backport
CVE: CVE-2021-3466

Signed-off-by: Ernst Sjöstrand &lt;ernst.sjostrand@verisure.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>nss: Fix CVE-2021-43527</title>
<updated>2021-12-18T19:08:54+00:00</updated>
<author>
<name>sana kazi</name>
<email>sanakazisk19@gmail.com</email>
</author>
<published>2021-12-16T10:53:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=82264cbf0b69e9f0f07428a48f26f0261aa9a0d8'/>
<id>urn:sha1:82264cbf0b69e9f0f07428a48f26f0261aa9a0d8</id>
<content type='text'>
Add patch to fix CVE-2021-43527 which causes heap overflow in nss.

Signed-off-by: Sana Kazi &lt;Sana.Kazi@kpit.com&gt;
Signed-off-by: Sana Kazi &lt;sanakazisk19@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>c-ares: switch from master to main</title>
<updated>2021-12-18T19:08:51+00:00</updated>
<author>
<name>Jeremy Puhlman</name>
<email>jpuhlman@mvista.com</email>
</author>
<published>2021-12-13T23:34:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=6025097d083a36d9af3d53d2dd95631a2de87a8d'/>
<id>urn:sha1:6025097d083a36d9af3d53d2dd95631a2de87a8d</id>
<content type='text'>
Signed-off-by: Jeremy A. Puhlman &lt;jpuhlman@mvista.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>brotli: add patch to fix CVE-2020-8927</title>
<updated>2021-12-03T20:28:09+00:00</updated>
<author>
<name>Spectrejan</name>
<email>jan@spectrejan.de</email>
</author>
<published>2021-12-03T09:12:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=69f94af4d91215e7d4e225bab54bf3bcfee42f1c'/>
<id>urn:sha1:69f94af4d91215e7d4e225bab54bf3bcfee42f1c</id>
<content type='text'>
Port patch to fix CVE-2020-8927 for brotli from Debian Buster

CVE: CVE-2020-8927

Signed-off-by: Jan Kraemer &lt;jan@spectrejan.de&gt;
[Fixup to apply with URL changes]
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>dovecot: Fix CVE-2020-12674</title>
<updated>2021-12-03T20:23:42+00:00</updated>
<author>
<name>sana kazi</name>
<email>sanakazisk19@gmail.com</email>
</author>
<published>2021-12-03T12:29:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=fba8ff0d916383ce65045c36ba4c805b5a2dfcc0'/>
<id>urn:sha1:fba8ff0d916383ce65045c36ba4c805b5a2dfcc0</id>
<content type='text'>
Added patch for CVE-2020-12674

Link: http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz

Signed-off-by: Sana Kazi &lt;Sana.Kazi@kpit.com&gt;
Signed-off-by: Sana Kazi &lt;sanakazisk19@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>dovecot: Fix CVE-2020-12673</title>
<updated>2021-12-03T20:23:38+00:00</updated>
<author>
<name>sana kazi</name>
<email>sanakazisk19@gmail.com</email>
</author>
<published>2021-12-03T12:29:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=7804c8e5bd2975c9829e1667ab1954373a3ede48'/>
<id>urn:sha1:7804c8e5bd2975c9829e1667ab1954373a3ede48</id>
<content type='text'>
Added patch for CVE-2020-12673

Link: http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz

Signed-off-by: Sana Kazi &lt;Sana.Kazi@kpit.com&gt;
Signed-off-by: Sana Kazi &lt;sanakazisk19@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>dovecot: Fix CVE-2020-12100</title>
<updated>2021-12-03T20:23:33+00:00</updated>
<author>
<name>sana kazi</name>
<email>sanakazisk19@gmail.com</email>
</author>
<published>2021-12-03T12:27:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=00ad99f4f9a06d66bd5686d2b1dd07c578c8dc2a'/>
<id>urn:sha1:00ad99f4f9a06d66bd5686d2b1dd07c578c8dc2a</id>
<content type='text'>
Added patches to fix CVE-2020-12100

Link: http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz

Signed-off-by: Sana Kazi &lt;Sana.Kazi@kpit.com&gt;
Signed-off-by: Sana Kazi &lt;sanakazisk19@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>jansson: whitelist CVE-2020-36325</title>
<updated>2021-11-30T22:40:43+00:00</updated>
<author>
<name>Marta Rybczynska</name>
<email>marta.rybczynska@huawei.com</email>
</author>
<published>2021-11-29T18:54:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=e0e79bbde23f17185cc59908fee97c0cea098428'/>
<id>urn:sha1:e0e79bbde23f17185cc59908fee97c0cea098428</id>
<content type='text'>
According to the upstream [1], the bug happens only if the programmer
does not follow the API definition.

[1] https://github.com/akheron/jansson/issues/548

Signed-off-by: Marta Rybczynska &lt;marta.rybczynska@huawei.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
</feed>
