<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git/meta-networking/recipes-protocols, branch mickledore-next</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2023-10-15T23:09:42+00:00</updated>
<entry>
<title>frr: Security fix CVE-2023-38802</title>
<updated>2023-10-15T23:09:42+00:00</updated>
<author>
<name>Yi Zhao</name>
<email>yi.zhao@eng.windriver.com</email>
</author>
<published>2023-10-10T08:09:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=513d4afd251eed5504a417c5ac37a8703a67b32b'/>
<id>urn:sha1:513d4afd251eed5504a417c5ac37a8703a67b32b</id>
<content type='text'>
CVE-2023-38802:
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote
attacker to cause a denial of service via a crafted BGP update with a
corrupted attribute 23 (Tunnel Encapsulation).

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-38802

Patch from:
https://github.com/FRRouting/frr/commit/46817adab03802355c3cce7b753c7a735bdcc5ae

Signed-off-by: Yi Zhao &lt;yi.zhao@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>frr: Fix CVE-2023-41358 and CVE-2023-41360</title>
<updated>2023-10-15T23:09:42+00:00</updated>
<author>
<name>Robert Yang</name>
<email>liezhi.yang@windriver.com</email>
</author>
<published>2023-10-10T08:09:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=332fce9304d841574e29684e399c9c1e111e0545'/>
<id>urn:sha1:332fce9304d841574e29684e399c9c1e111e0545</id>
<content type='text'>
Backport patches to fix CVE-2023-41358 and CVE-2023-41360.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-41358
https://nvd.nist.gov/vuln/detail/CVE-2023-41360

Signed-off-by: Robert Yang &lt;liezhi.yang@windriver.com&gt;
Signed-off-by: Yi Zhao &lt;yi.zhao@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>frr: Security fix CVE-2023-3748</title>
<updated>2023-08-31T12:49:13+00:00</updated>
<author>
<name>Yi Zhao</name>
<email>yi.zhao@windriver.com</email>
</author>
<published>2023-08-28T10:49:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=32e47b26e93a9e17e53e928ca6df073c453b1bc3'/>
<id>urn:sha1:32e47b26e93a9e17e53e928ca6df073c453b1bc3</id>
<content type='text'>
CVE-2023-3748:
A flaw was found in FRRouting when parsing certain babeld unicast hello
messages that are intended to be ignored. This issue may allow an
attacker to send specially crafted hello messages with the unicast flag
set, the interval field set to 0, or any TLV that contains a sub-TLV
with the Mandatory flag set to enter an infinite loop and cause a denial
of service.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-3748

Patch from:
https://github.com/FRRouting/frr/commit/ae1e0e1fed77716bc06f181ad68c4433fb5523d0

Signed-off-by: Yi Zhao &lt;yi.zhao@windriver.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit ee1026ab77dcb31b0f5cb723b4d998aab4c00382)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>frr: upgrade 8.4.2 -&gt; 8.4.4</title>
<updated>2023-06-28T20:28:27+00:00</updated>
<author>
<name>Yi Zhao</name>
<email>yi.zhao@eng.windriver.com</email>
</author>
<published>2023-06-28T12:58:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=c403568572bc40d7c7f2a2fe1c021485623dc985'/>
<id>urn:sha1:c403568572bc40d7c7f2a2fe1c021485623dc985</id>
<content type='text'>
ChangeLog:
https://github.com/FRRouting/frr/releases/tag/frr-8.4.4
https://github.com/FRRouting/frr/commit/45e36c0c00a517ad1606135b18c5753e210cfc0d

Signed-off-by: Yi Zhao &lt;yi.zhao@windriver.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>frr: add CVE_PRODUCT</title>
<updated>2023-05-28T19:57:29+00:00</updated>
<author>
<name>Chen Qi</name>
<email>Qi.Chen@windriver.com</email>
</author>
<published>2023-05-08T10:09:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=6208630ac5f3372ee852724705ee49f072fcbcee'/>
<id>urn:sha1:6208630ac5f3372ee852724705ee49f072fcbcee</id>
<content type='text'>
The CVE_PRODUCT is frrouting in NVD database.

Signed-off-by: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit 10c7793832ec492da50c89889c5cdd114962b7a5)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>freediameter: fix typo and old overide syntax</title>
<updated>2023-05-07T16:31:52+00:00</updated>
<author>
<name>Bergin, Peter</name>
<email>peter.bergin@windriver.com</email>
</author>
<published>2023-05-02T08:13:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=d6d62cced2bc7d6bf89582497692d1c245048350'/>
<id>urn:sha1:d6d62cced2bc7d6bf89582497692d1c245048350</id>
<content type='text'>
A typo that probably caused a left over from override syntax conversion.

    INITSCRIPT_PARAMS$_${PN} --&gt; INITSCRIPT_PARAMS:${PN}

Signed-off-by: Peter Bergin &lt;peter.bergin@windriver.com&gt;
Signed-off-by: Peter Bergin &lt;peter@berginkonsult.se&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit 77f031776ec9c9edb18e7323b17b697f5c52d5f5)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>radiusclient-ng: Point SRC_URI to archive.ubuntu.com</title>
<updated>2023-05-07T16:31:13+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2023-05-02T04:52:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=a1de54c73439a4fb2ff8e63456cb52ec2242b377'/>
<id>urn:sha1:a1de54c73439a4fb2ff8e63456cb52ec2242b377</id>
<content type='text'>
This tarball is not available on debian ftp archive anymore

Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit fe62e64c973730da0e385ddbbab8cdc3217e0e69)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>rp-pppoe: Point SRC_URI to valid location</title>
<updated>2023-05-07T16:30:14+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2023-04-30T22:34:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=55b3b2be4d7145675fbc2d1e79943aa1eff7c3df'/>
<id>urn:sha1:55b3b2be4d7145675fbc2d1e79943aa1eff7c3df</id>
<content type='text'>
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
(cherry picked from commit 2b2cc606ecc795e65d5b551ae30c8e0cef429bf9)
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>rp-pppoe: Define _GNU_SOURCE</title>
<updated>2023-03-22T16:10:39+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2023-03-21T04:50:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=864cea3d642757206fc2f1e07021d881e79b2021'/>
<id>urn:sha1:864cea3d642757206fc2f1e07021d881e79b2021</id>
<content type='text'>
Ensures that it picks up definitions of strlcpy() from string.h

Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
<entry>
<title>rp-pppoe: upgrade 3.14 -&gt; 3.15</title>
<updated>2023-03-10T07:45:17+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2023-03-10T06:13:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=d72b4945ed290589cfcbb0e0e9a19ddb56230658'/>
<id>urn:sha1:d72b4945ed290589cfcbb0e0e9a19ddb56230658</id>
<content type='text'>
dont-swallow-errors.patch
configure.in-Error-fix.patch
removed since they're not available in 3.14.

configure_in_cross.patch
refreshed for 3.14.

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
</feed>
