summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* editorconfig-core-c: patch CVE-2024-53849Ankur Tyagi2025-12-173-1/+106
| | | | | | | Details https://nvd.nist.gov/vuln/detail/CVE-2024-53849 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* flatpak: patch CVE-2024-42472Ankur Tyagi2025-12-173-0/+215
| | | | | | | Details https://nvd.nist.gov/vuln/detail/CVE-2024-42472 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* libcupsfilters: patch CVE-2025-57812Ankur Tyagi2025-12-172-0/+130
| | | | | | | Details https://nvd.nist.gov/vuln/detail/CVE-2025-57812 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* jasper: patch CVE-2024-31744Ankur Tyagi2025-12-172-0/+31
| | | | | | | Details https://nvd.nist.gov/vuln/detail/CVE-2024-31744 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* mbedtls: fix CVE-2025-47917Kai Kang2025-12-172-0/+53
| | | | | | | | | | | CVE-2025-47917 is that the function mbedtls_x509_string_to_names() takes a head argument and performs a deep free() on it. Backport patch to fix CVE-2025-47917 and drop the modification in doc file and comment in header file which lack of context. Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* proftpd: Fix CVE-2023-48795Vijay Anusuri2025-12-112-0/+786
| | | | | | | | | | Upstream-Status: Backport from https://github.com/proftpd/proftpd/commit/bcec15efe6c53dac40420731013f1cd2fd54123b Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> (cherry picked from commit 6c8ae54fc345fb6249f1cc92ed769d451ddc12b5) Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* wireshark: fix CVE-2025-13499Hitendra Prajapati2025-12-112-0/+46
| | | | | | | Upstream-Status: Backport from https://gitlab.com/wireshark/wireshark/-/commit/e180152d3dae668249f78c72a55a4ba436b57af7 Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* gflags: switch Git branch from master to mainViswanath Kraleti2025-12-111-1/+1
| | | | | | | | Update SRC_URI to use the 'main' branch instead of 'master' since the upstream GitHub repository has renamed its default branch. Signed-off-by: Viswanath Kraleti <viswanath.kraleti@oss.qualcomm.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* hdf5 1.14.4-3: fix CVE-2025-2912Sudhir Dumbhare2025-12-112-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Upstream Repository: https://github.com/HDFGroup/hdf5.git Bug Details: https://nvd.nist.gov/vuln/detail/CVE-2025-2912 Type: Security Fix CVE: CVE-2025-2912 Score: 4.8 Patch: https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a Analysis: - CVE-2025-2913 was previously fixed by [1], which is also addresses CVE-2025-2912 as noted in [4]. - NVD [2] references the GitHub discussion [3] for CVE-2025-2912, and we successfully reproduced the issue following the steps outlined there. - Applied the fix from [4] and verified resolution using the reproduction steps. - The same patch [4] is already included in OE-scarthgap [5] for CVE-2025-2913. - Therefore, reused the patch from [5] to resolve CVE-2025-2912. References: [1] https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a [2] https://nvd.nist.gov/vuln/detail/CVE-2025-2912 [3] https://github.com/HDFGroup/hdf5/issues/5370#issue-2917388806 [4] https://github.com/HDFGroup/hdf5/issues/5370#issuecomment-3542881855 [5] https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-support/hdf5?h=scarthgap&id=b42e6eb3e51a Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* apache2: upgrade 2.4.65 -> 2.4.66Valeria Petrov2025-12-111-1/+1
| | | | | | | | | | | | | | | Security fixes: - CVE-2025-66200 - CVE-2025-65082 - CVE-2025-59775 - CVE-2025-58098 - CVE-2025-55753 See: http://www.apache.org/dist/httpd/CHANGES_2.4.66 Signed-off-by: Valeria Petrov <valeria.petrov@spinetix.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* libavif: patch CVE-2025-48174Ankur Tyagi2025-12-115-1/+163
| | | | | | | Details https://nvd.nist.gov/vuln/detail/CVE-2025-48174 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* smarty: update CVE_PRODUCTAnkur Tyagi2025-12-111-0/+2
| | | | | Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* corosync: upgrade 3.1.9 -> 3.1.10Wang Mingyu2025-12-092-72/+2
| | | | | | | | | | | CVE-2025-30472.patch removed since it's included in 3.1.10 Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 7915bcecf5b25eb525c5700fc4196422596b5a38) Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* python3-django: upgrade 5.0.11 -> 5.0.14Ankur Tyagi2025-12-092-103/+1
| | | | | | | | | | | | Drop patch merged in the upstream. Release notes: https://docs.djangoproject.com/en/dev/releases/5.0.12/ https://docs.djangoproject.com/en/dev/releases/5.0.13/ https://docs.djangoproject.com/en/dev/releases/5.0.14/ Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* nftables: remove python dependency from main packagePeter Marko2025-12-091-0/+2
| | | | | | | | | | | | | The recipe splits python code to nftables-python package, however setuptools classes add the dependency to main package. Since nftables-python package already has python3-core explicit dependency, remove it from the main package. (From meta-openembedded rev: 331126a6d0a48ebcf12069df554b3abacaeb512a) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* net-snmp: Update Upstream-status in the net-snmp-5.9.4-kernel-6.7.patchVijay Anusuri2025-12-051-1/+1
| | | | | Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* net-snmp: Fix a crash and support for 6.7+ kernelKhem Raj2025-12-053-0/+142
| | | | | | | Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from 8147a884c68d8fdd89939a8443a902b65297520c) Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* hdf5 1.14.4-3: Fix CVE tag format in patchesDeepak Rathore2025-12-053-3/+6
| | | | | | | | | | | | | | | | | | | - The CVE tags in multiple hdf5 patches were using comma-separated format which caused false positives in CVE reports. - Multiple CVEs should be separated by space in CVE-ID.patch file as per recipe style guide in Yocto documentation so CVE report tool can scan those CVEs and mark it as patched. Fixed the following patches: - CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_01.patch - CVE-2025-6269-CVE-2025-6270-CVE-2025-6516_02.patch - CVE-2025-2923-CVE-2025-6816-CVE-2025-6856.patch Reference: - https://docs.yoctoproject.org/contributor-guide/recipe-style-guide.html#cve-patches Signed-off-by: Deepak Rathore <deeratho@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2023-42822Gyorgy Sarvari2025-12-042-0/+305
| | | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2023-42822 Pick the patch the references the github advisory[1] and the cve ID also from the nvd report. The patch is a backported version of the patch referenced by the nvd report. [1]: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-2hjx-rm4f-r9hw Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2023-40184Gyorgy Sarvari2025-12-042-0/+74
| | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2023-40184 Pick the patch that is associated with the github advisory[1], which is a backported version of the patch that is referenced by the nvd report. [1]: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-f489-557v-47jq Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23493Gyorgy Sarvari2025-12-042-0/+34
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23493 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23484Gyorgy Sarvari2025-12-042-0/+32
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23484 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23483Gyorgy Sarvari2025-12-042-0/+66
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23483 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23482Gyorgy Sarvari2025-12-042-0/+70
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23482 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23481Gyorgy Sarvari2025-12-042-0/+47
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23481 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23480Gyorgy Sarvari2025-12-043-0/+412
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23480 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23479Gyorgy Sarvari2025-12-042-0/+84
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23479 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23478Gyorgy Sarvari2025-12-042-0/+86
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23478 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23477Gyorgy Sarvari2025-12-042-0/+39
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23477 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* xrdp: patch CVE-2022-23468Gyorgy Sarvari2025-12-042-0/+35
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-23468 Pick the patch that mentions this vulnerability explicitly. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* pidgin: fix reproducibility issuesAnuj Mittal2025-12-031-0/+7
| | | | | | | | Backport changes fixing reproducibility issues from master: 9697fd958e Yoann Congal pidgin: Upgrade to 2.14.13 Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* trace-cmd: Update SRC_URI to use HTTPS protocolyuyu2025-12-031-1/+1
| | | | | | Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f00b6ad12f2fead06487711c48544b3dd62bb987) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* crash: add zlib-native to depends for crash-crossYi Zhao2025-12-031-0/+2
| | | | | | | | | | | | | Fix the following error when using buildtools-extended: va_server.c:20:10: fatal error: zlib.h: No such file or directory 20 | #include <zlib.h> | ^~~~~~~~ Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit bd745115de76de7242e3e7e69b29f1ae507fea13) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* nbdkit: patch CVE-2025-47712Gyorgy Sarvari2025-12-032-1/+168
| | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2025-47712 Pick the patch from the project's repository which explicitly mentions this vulnerability ID. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* nbdkit: patch CVE-2025-47711Gyorgy Sarvari2025-12-032-1/+174
| | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2025-47711 Pick the patch from the repository which explicitly mentions this CVE ID. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* redis: handle CVE-2025-27151Gyorgy Sarvari2025-12-033-1/+35
| | | | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2025-27151 In redis 7 this is already patched[1], and the recipe contains the fix. For redis 6 backport the relevant patch (which is referenced in the nvd report) [1]: https://github.com/redis/redis/commit/d0eeee6e31f0fefb510007a8cfdf5dce729a8be9 Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* redis: ignore CVE-2022-0543Gyorgy Sarvari2025-12-032-0/+3
| | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2022-0543 The issue is specific to the version packaged by Debian, it can be ignored. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* yasm: patch CVE-2021-33456Gyorgy Sarvari2025-12-032-0/+36
| | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2021-33465 The patch was taken from Debian: https://sources.debian.org/patches/yasm/1.3.0-8/1020-hash-null-CVE-2021-33456.patch/ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 1e2731fce05d15020fddf3dca5d8ee42ec3c04e1) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* yasm: patch CVE-2021-33464Gyorgy Sarvari2025-12-032-0/+35
| | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2021-33464 The patch was taken from Debian: https://sources.debian.org/patches/yasm/1.3.0-8/1010-nasm-pp-no-env-CVE-2021-33464.patch/ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 66a0b01b52e5d1cd2af4c41ae0b67541464874e6) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* yasm: patch CVE-2023-29579Gyorgy Sarvari2025-12-032-1/+41
| | | | | | | | | | | | Details: https://nvd.nist.gov/vuln/detail/CVE-2023-29579 The patch was taken from Debian: https://sources.debian.org/patches/yasm/1.3.0-8/1000-x86-dir-cpu-CVE-2023-29579.patch/ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit cc30757a7fd0af5f60b9a6408b3eb94c0810acda) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* yasm: add alternative CVE_PRODUCTGyorgy Sarvari2025-12-031-0/+1
| | | | | | | | | | | | | | | There are multiple vendors for yasm: $ sqlite3 ./nvdcve_2-2.db "select distinct vendor, product from products where product = 'yasm';" tortall|yasm yasm_project|yasm Both products refer to the same application Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 93f85e4fd2fb124cb047f6b378cf0052a1f102aa) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* libtracefs: avoid run bisonKai Kang2025-12-032-0/+109
| | | | | | | | | | | | | | | There is a rare compile failure | In file included from sqlhist-parse.h:25, | from tracefs-sqlhist.c:17: | sqlhist.tab.h:120:8: error: unterminated comment | 120 | #endif /* !YY_TRACEFS_SQLHIST_TAB_H_INCLUDED */ | | ^ Backport patch to avoid run bison that not re-gerate sqlhist.tab.h. Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* cockpit: set correct CVE_PRODUCTGyorgy Sarvari2025-11-281-0/+2
| | | | | | | Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit af4df551eec582844a8b56154117915ace1596cd) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* fbida: Require opengl feature for pdf onlyPavel Zhukov2025-11-281-1/+1
| | | | | | | | | | Don't require it for entire distro if pdf package config disabled. Signed-off-by: Pavel Zhukov <pavel@zhukoff.net> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f22451b51bf668fbbf27b50744786c64316ef700) Signed-off-by: Chris Laplante <chris.laplante@agilent.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* links: set CVE_PRODUCTGyorgy Sarvari2025-11-281-0/+2
| | | | | | | | | | | | | There are some unrelated software called "links", which cases false-positive CVEs to be reported by the CVE checker. Set the vendor/product pairs that were historically used with CVEs for this software. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 62a53097324ace9161d8fdcfbc533baac9ee6309) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* uw-imap: patch CVE-2018-19518Peter Marko2025-11-252-0/+25
| | | | | | | | | | | Take patch from Debian from https://salsa.debian.org/lts-team/packages/uw-imap/-/commit/873b07f46ce40f43bca10ec85fe63a7a0b934294 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 9f7c1e6bd101494c6cc5dad16a7fa65a13cbac70) Signed-off-by: Anil Dongare <adongare@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* zfs: fix host-related reproducibilityYoann Congal2025-11-251-0/+6
| | | | | | | | | | | | | The zfs package content varies depending the host distro. To fix this, force target distribution ("vendor") to Debian to match default values for things like: NFS server service name, bash completion path, configuration files, ... The Debian values do match the OpenEmbedded ones. Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 4990a36eb404d5ae603acd6f777c38d62b7973a3) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* ot-br-posix: Define config files explicitlyKhem Raj2025-11-251-0/+2
| | | | | | | | Otherwise it picks up from build area with absolute paths into builddir Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 0439d42c556d97405b13deecc412605ca8fc202f) Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* libwebsockets: fix CVE-2025-11678Hugo SIMELIERE2025-11-212-0/+129
| | | | | | | | | | | Backport a fix from Debian: https://sources.debian.org/patches/libwebsockets/4.3.5-1+deb13u1/CVE-2025-11678.patch Upstream commit: https://github.com/warmcat/libwebsockets/commit/2bb9598562b37c942ba5b04bcde3f7fdf66a9d3a Signed-off-by: Bruno VERNAY <bruno.vernay@se.com> Signed-off-by: Hugo SIMELIERE <hsimeliere.opensource@witekio.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
* libwebsockets: fix CVE-2025-11677Hugo SIMELIERE2025-11-212-1/+164
| | | | | | | | | | | Backport a fix from Debian: https://sources.debian.org/patches/libwebsockets/4.3.5-1+deb13u1/CVE-2025-11677.patch Upstream commit: https://github.com/warmcat/libwebsockets/commit/2f082ec31261f556969160143ba94875d783971a Signed-off-by: Bruno VERNAY <bruno.vernay@se.com> Signed-off-by: Hugo SIMELIERE <hsimeliere.opensource@witekio.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>