summaryrefslogtreecommitdiffstats
path: root/meta-oe
Commit message (Collapse)AuthorAgeFilesLines
* openct: Fix typo in SUMMARY variableJulian Haller2025-10-011-1/+1
| | | | | | | Signed-off-by: Julian Haller <julian.haller@philips.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 38f62a5fb36ea55205598830bb683ab7447e7fe2) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* ne10: append +git instead of gitr+Martin Jansa2025-10-011-1/+1
| | | | | | | | | | * looks like a typo introduced in: https://git.openembedded.org/meta-openembedded/commit/?id=6e431331d18ded23a78e238ed40d03434e7719d9 * use +git as most other recipes are using Signed-off-by: Martin Jansa <martin.jansa@gmail.com> (cherry picked from commit 10703e5c6a51ef14b357c5c2021979ecedcaeb13) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* multipath-tools: Use https for githubFabio Estevam2025-10-011-1/+1
| | | | | | | | | | | | Per convert-srcuri.py script, github repos should be accessed via https. Change it accordingly. Signed-off-by: Fabio Estevam <festevam@denx.de> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 4cef1e68ea59510d85b778e11179a2dac47c658b) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libtinyxml: patch CVE-2023-34194Peter Marko2025-10-012-0/+32
| | | | | | | | | | Take patch from Debian: https://salsa.debian.org/debian/tinyxml/-/commit/2366e1f23d059d4c20c43c54176b6bd78d6a83fc Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f4a6966bf0cc48ee7fa83c64c2eec2c4fbf91eb4) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libtinyxml: patch CVE-2021-42260Peter Marko2025-10-012-1/+30
| | | | | | | | | | Take patch from Debian: https://salsa.debian.org/debian/tinyxml/-/commit/38db99c12e43d7d6e349403ce4d39a706708603d Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 066cf35ae588ef5f81266b216624b95d37777661) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libtar: patch CVEsKatariina Lounento2025-10-0113-0/+854
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | cve-check.bbclass reported unpatched vulnerabilities in libtar [1,2,3,4,5]. The NIST assigned base score for the worst vulnerability is 9.1 / critical. The patches were taken from the libtar [6] master branch after the latest tag v1.2.20 (the changes in libtar master mostly originate from Fedora and their patches), and from the Fedora 41 libtar source package [7] and the Debian libtar package 1.2.20-8 [8] where the patches were not available in the libtar repository itself. The Fedora patch series was taken in its entirety in order to minimize differences to Fedora's source tree instead of cherry-picking only CVE fixes. Minimizing the differences should avoid issues with potential inter-dependencies between the patches, and hopefully provide better confidence as even the newest patches have been in use in Fedora for nearly 2 years (since December 2022; Fedora rpms/libtar.git commit e25b692fc7ceaa387dafb865b472510754f51bd2). The series includes even the Fedora patch libtar-1.2.20-no-static-buffer.patch, which contains changes *) that match the libtar commit ec613af2e9371d7a3e1f7c7a6822164a4255b4d1 ("decode: avoid using a static buffer in th_get_pathname()") whose commit message says Note this can break programs that expect sizeof(TAR) to be fixed. The patches applied cleanly except for the Fedora srpm patch libtar-1.2.11-bz729009.patch, which is identical with the pre-existing meta-oe patch 0002-Do-not-strip-libtar.patch and is thus omitted. The meta-openembedded recipe does not include any of the patches in Kirkstone [9] nor the current master [10]. libtar does not have newer releases, and the libtar master doesn't contain all of the changes included in the patches. Fedora's libtar.1.2.11-*.patch are not included in the libtar v1.2.20 release either but only in the master branch after the tag v1.2.20. The version number in the filename is supposedly due to the patches being created originally against v1.2.11 but have been upstreamed or at least committed to the master only after v1.2.20. The commit metadata could not be practically completed in most of the cases due to missing commit messages in the original commits and patches. The informal note about the author ("Authored by") was added to the patch commit messages where the commit message was missing the original author(s)' Signed-off-by. *) The patch also contains the changes split to the libtar commits 495d0c0eabc5648186e7d58ad54b508d14af38f4 ("Check for NULL before freeing th_pathname") and 20aa09bd7775094a2beb0f136c2c7d9e9fd6c7e6 ("Added stdlib.h for malloc() in lib/decode.c")) [1] https://nvd.nist.gov/vuln/detail/CVE-2021-33643 [2] https://nvd.nist.gov/vuln/detail/CVE-2021-33644 [3] https://nvd.nist.gov/vuln/detail/CVE-2021-33645 [4] https://nvd.nist.gov/vuln/detail/CVE-2021-33646 [5] https://nvd.nist.gov/vuln/detail/CVE-2013-4420 [6] https://repo.or.cz/libtar.git [7] https://src.fedoraproject.org/rpms/libtar/tree/f41 [8] https://sources.debian.org/patches/libtar/1.2.20-8/CVE-2013-4420.patch/ [9] https://git.openembedded.org/meta-openembedded/tree/meta-oe/recipes-support/libtar/libtar_1.2.20.bb?h=kirkstone&id=9a24b7679810628b594cc5a9b52f77f53d37004f [10] https://git.openembedded.org/meta-openembedded/tree/meta-oe/recipes-support/libtar/libtar_1.2.20.bb?h=master&id=9356340655b3a4f87f98be88f2d167bb2514a54c Signed-off-by: Katariina Lounento <katariina.lounento@vaisala.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 3c9b5b36c8dc619240ac422de2a0aaed0949de08) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* liboop: set correct LICENSEGyorgy Sarvari2025-10-011-1/+1
| | | | | | | Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 0ea9584b84b5e23af9cc7285757d9032f31a968f) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libjs-jquery-icheck: Correct LIC_FILES_CHKSUMPeter Kjellerstedt2025-10-011-1/+1
| | | | | | | | | | | Only include the lines from icheck.js that cover the copyright and the license text. License-Update: Only include the relevant parts of icheck.js Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit e1bced739968a68ed2743d011cd82791d380678b) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* dash: correct licenceDan McGregor2025-10-011-1/+1
| | | | | | | | | | | | According to its copyright file, dash is only BSD-3-Clause. It has a build time tool from bash that's under the GPL, but only the tool's output is used, not the tool itself. So all compiled artefacts in dash appear to share the same licence. Signed-off-by: Dan McGregor <dan.mcgregor@usask.ca> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 8eba35f8b03659ffd73aceb52b6e78da8661a6dd) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* softhsm: switch source to GitHub repositoryJiaying Song2025-10-011-2/+3
| | | | | | | | | | The original source URL is unavailable, so it has been replaced with the official GitHub repository. Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f88db75ffa29e0d654f73cc174e01d9edaec6df2) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* nmap: add missing dependencyGyorgy Sarvari2025-10-011-1/+1
| | | | | | | | | | | | | | | Building with ndiff PACKAGECONFIG failed with the following error: | File "/yocto/sandbox/build/tmp/work/cortexa53-poky-linux/nmap/7.95/nmap-7.95/ndiff/setup.py", line 11, in <module> | import setuptools.command.install | ModuleNotFoundError: No module named 'setuptools' Fix it by adding the missing dependency. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 3564ec12de4b5ed470e75a9e045adc6bec83c74d) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* python3-nmap: add missing run-time dependenciesBartosz Golaszewski2025-10-011-1/+5
| | | | | | | | | Add missing RDEPENDS for this package. Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@linaro.org> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit e20ebe6ce4f8b991cd4f153352274850d416f090) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libmad: patch CVE-2017-8372 and CVE-2017-8373Peter Marko2025-10-012-0/+831
| | | | | | | | | | | | Pick patch [1] from Debian based on [2]. [1] https://salsa.debian.org/multimedia-team/libmad/-/raw/debian/0.15.1b-11/debian/patches/length-check.patch?ref_type=tags [2] https://security-tracker.debian.org/tracker/CVE-2017-8374 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 60eb0214e71c5f761d450bcc484b57df6955bd09) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libmad: patch CVE-2017-8372 and CVE-2017-8373Peter Marko2025-10-012-0/+70
| | | | | | | | | | | | | Pick patch [1] from Debian based on [2] and [3]. [1] https://salsa.debian.org/multimedia-team/libmad/-/blob/debian/0.15.1b-11/debian/patches/md_size.diff?ref_type=tags [2] https://security-tracker.debian.org/tracker/CVE-2017-8372 [3] https://security-tracker.debian.org/tracker/CVE-2017-8373 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 437635f608f2d9b69fefcde9ebfcff2bab64d35e) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libmad: ignore CVE-2017-11552 and CVE-2018-7263Peter Marko2025-10-011-0/+3
| | | | | | | | | | | | | | | These CVEs are for mpg321, not libmad. See Debian assessment: * https://security-tracker.debian.org/tracker/CVE-2017-11552 * https://security-tracker.debian.org/tracker/CVE-2018-7263 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit fee86a312fbcaef7aaad66fe2f6756bd7e57d585) Adapted to Kirkstone. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libmad: switch links/SRC_URI to https sitesRandy MacLeod2025-10-011-4/+3
| | | | | | | | | | | Switch to the sourceforge SRC_URI since the mars.org site only supports ftp. Also switch the HOMEPAGE and BUGTRACKER links over to https. and drop the obsolete SRC_URI[md5sum]. Signed-off-by: Randy MacLeod <Randy.MacLeod@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f61cc5260954e840494194805f6f957f60cd4833) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* audiofile: patch CVE-2017-6839Peter Marko2025-10-012-0/+127
| | | | | | | | | | Use patch from buildroot: https://github.com/buildroot/buildroot/commit/844a7c6281eb442881330a5d36d5a0719f2870bf Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 88faae83b2b0e68827c457f4f348f7d7868f5258) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* audiofile: patch CVE-2017-6831Peter Marko2025-10-012-0/+47
| | | | | | | | | | Use patch from buildroot: https://github.com/buildroot/buildroot/commit/bd5f84d301c4e74ca200a9336eca88468ec0e1f3 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 9d668989b1447fb19aff55c1a47acdf8d4e8c5e2) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* audiofile: fix multiple CVEsPeter Marko2025-10-012-0/+80
| | | | | | | | | | | | CVE-2017-6830 / CVE-2017-6834 / CVE-2017-6836 / CVE-2017-6838 Use patch from buildroot: https://github.com/buildroot/buildroot/commit/4a1a8277bba490d227f413e218138e39f1fe1203 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 75f2bd2b3b145d8282db9926d8212c6d81bde99e) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* audiofile: patch CVE-2017-6829Peter Marko2025-10-012-0/+44
| | | | | | | | | | Use patch from buildroot: https://github.com/buildroot/buildroot/commit/434890df2a7c131b40fec1c49e6239972ab299d2 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit f29fbaa4650201a059c65572947ed8faa991fcd8) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* audiofile: fix multiple CVEsPeter Marko2025-10-012-0/+46
| | | | | | | | | | | | CVE-2017-6827 / CVE-2017-6828 / CVE-2017-6832 / CVE-2017-6833 / CVE-2017-6835 / CVE-2017-6837 Use patch from buildroot: https://github.com/buildroot/buildroot/commit/cc00bde57fc20d11f8fa4e8ec5f193c091714c55 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 634cbcb91c3ab7154e0cda707663a1e4aa500f4a) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* minicoredumper: correct the sysvinit service file attributeMingli Yu2025-10-011-1/+1
| | | | | | | | | | | | Add the execute attribute for sysvinit service file to fix the below error: $ service minicoredumper status minicoredumper: unrecognized service Signed-off-by: Mingli Yu <mingli.yu@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit d477cbb5267f39846d129f27d0f6a7f2b001db7b) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* x11vnc: Fix CVE-2020-29074Lee Chee Yang2025-10-012-0/+28
| | | | | | | Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit dbdea59838054f9c908533d486cf3c0c2897c791) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* openbox: fix crash on alt+tab with fullscreen appAlexandre Videgrain2025-10-012-0/+57
| | | | | | | | | | | | | | Apply an openbox patch to openbox recipe to fix crashes on alt+tab with fullscreen app. Github issue: https://github.com/openembedded/meta-openembedded/issues/837 Signed-off-by: Alexandre Videgrain <alexandre.videgrain@smile.fr> Suggested-by: Ludovic Jozeau <ludovic.jozeau@smile.fr> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 85132c16210d1bdf83e8be5b3da4f430ce7b4b91) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libsdl: fix CVE-2022-34568Lee Chee Yang2025-10-012-0/+29
| | | | | | | | | | | CVE-2022-34568 affected From (including) 1.2.1 Up to (including) 1.2.15 Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 49c97b4eefa6efc87f023c07ce6fbb7a93c79a0f) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* gtk+: Fix CVE-2024-6655Soumya Sambu2025-10-012-0/+41
| | | | | | | | | | | | | | | | A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory. References: https://nvd.nist.gov/vuln/detail/CVE-2024-6655 Upstream-patch: https://gitlab.gnome.org/GNOME/gtk/-/commit/3bbf0b6176d42836d23c36a6ac410e807ec0a7a7 Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 4bd9d757c10265dbf75034b50504ad7340ae3012) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* dialog: Update the SRC_URIMingli Yu2025-10-011-1/+1
| | | | | | | | | Update the SRC_URI to fix the do_fetch error. Signed-off-by: Mingli Yu <mingli.yu@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 6d1b7df8c0f751777625ecbae3a5505087788b81) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* vlock: fix do_fetch errorJiaying Song2025-10-011-1/+1
| | | | | | | | | | | Change the SRC_URI to the correct value due to the following error: WARNING: vlock-2.2.3-r0.vr2401 do_fetch: Failed to fetch URL http://distfiles.gentoo.org/distfiles/vlock-2.2.3.tar.gz, attempting MIRRORS if available Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 784942b68ef0a9533defee6c6f3d695e1c02cd3f) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* p8platform: unbreak do_populate_sdkMarkus Volk2025-10-011-0/+2
| | | | | | | | | | | | | Error: Problem: package libcec-dev-6.0.2-r0.corei7_64 requires p8platform-dev, but none of the providers can be installed - conflicting requests - nothing provides p8platform = 2.1.0.1-r0 needed by p8platform-dev-2.1.0.1-r0.corei7_64 (try to add '--skip-broken' to skip uninstallable packages) Signed-off-by: Markus Volk <f_l_k@t-online.de> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 03a1a24618e7366235af76ea58514442669f0a76) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* nicstat: Use SOURCEFORGE_MIRROR in SRC_URIKhem Raj2025-10-011-1/+1
| | | | | | Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 256ea730b030ec18871dada8953cf5f40e6fc4e3) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* libconfig: switch source to GitHub repositoryJiaying Song2025-10-011-4/+6
| | | | | | | | | | | The original tarball URL no longer provides version 1.7.3 or any other historical releases.To ensure reproducible builds, the source has been switched to the official GitHub repository. Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit c5de36f5882f0dbaa63f88bb8f9010910cdbb9cf) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* tk: inherit pkgconfigJustin Bronder2025-10-011-1/+1
| | | | | | | | | | I noticed that xft was not getting enabled as expected because the recipe was using pkg-config from the host. Signed-off-by: Justin Bronder <jsbronder@cold-front.org> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 95c14a92544e4f0e2dc94ef6a1f26d35beb82d7e) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* fsverity-utils: fix SRC_URIEtienne Cordonnier2025-10-011-1/+1
| | | | | | | | | | | This URL does not exist any more, and do_fetch works only because a mirrored file is available at http://downloads.yoctoproject.org/mirror/sources/git2_git.kernel.org.pub.scm.linux.kernel.git.ebiggers.fsverity-utils.git.tar.gz Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit d54e2671e62b87532e2dd8f80b73d545fc54aeb4) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* paho-mqtt-cpp: Improve the license informationPeter Kjellerstedt2025-10-011-2/+1
| | | | | | | | | | | | | Replace the about.html and notice.html files in LIC_FILES_CHKSUM with the license information from one of the source files. Including HTML files in LIC_FILES_CHKSUM complicates things when the license files that OE collects are, e.g., later processed and presented to a user where the expectation is that they are plain text files. Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 71e75357af45b3c45e09bf8f5ead3c47c0d2d0ff) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* paho-mqtt-c: upgrade 1.3.12 -> 1.3.13Matthias Klein2025-09-291-1/+1
| | | | | | | | | | | Service release. Issues resolved: https://github.com/eclipse/paho.mqtt.c/milestone/20?closed=1 Signed-off-by: Matthias Klein <matthias@extraklein.de> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 9f70554e435b31490cbec4c660363a3dea72db92) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* recipes: Remove double protocol= from SRC_URIsPeter Kjellerstedt2025-09-2911-11/+11
| | | | | | | | | | | | With the exception of paho-mqtt-cpp, the double protocol= attributes were added to the SRC_URIs when protocol=https was added to all SRC_URIs fetching from github.com in commit b402a3076f (recipes: Update SRC_URI branch and protocols). Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 2e0a581bee7fc15a78f6e19ba1e596930edee414) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* paho-mqtt-c: Improve the license informationPeter Kjellerstedt2025-09-291-2/+1
| | | | | | | | | | | | | Replace the about.html and notice.html files in LIC_FILES_CHKSUM with the LICENSE file. Including HTML files in LIC_FILES_CHKSUM complicates things when the license files that OE collects are, e.g., later processed and presented to a user where the expectation is that they are plain text files. Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 4decf7d0a71c4bc3056349d0c5f5a097d17b1cc0) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* paho-mqtt-c: upgrade 1.3.11 -> 1.3.12Matthias Klein2025-09-291-1/+1
| | | | | | | | | | Service release. Issues resolved: https://github.com/eclipse/paho.mqtt.c/milestone/19?closed=1 Signed-off-by: Matthias Klein <matthias@extraklein.de> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 29c4df0cbea8e84dc27a2d651360fd8e516d51be) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* paho-mqtt-c: upgrade 1.3.10 -> 1.3.11Matthias Klein2025-09-291-1/+1
| | | | | | | | | | Service release. Issues resolved: https://github.com/eclipse/paho.mqtt.c/milestone/18?closed=1 Signed-off-by: Matthias Klein <matthias@extraklein.de> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit ef4fb2211e3488bb0412557e1f933e4e201fe9b9) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* debootstrap: Update SRC_URI to point to valid URLKhem Raj2025-09-291-2/+1
| | | | | | Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 2db438f241b966ed8a0d26f52c2fc2fe395cdcc7) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* flashrom: upgrade 1.2 -> 1.2.1Wang Mingyu2025-09-292-48/+1
| | | | | | | | | | 0001-typecast-enum-conversions-explicitly.patc removed since it's included in 1.2.1 Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit d8e50a9507da7441b1694b025df17b0c8484d44d) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: upgrade 3.14 -> 3.15Wang Mingyu2025-09-292-135/+1
| | | | | | | | | | | | | | | | | | | Changelog: =========== Several bugs that could allow the iperf3 server to hang waiting for input on the control connection has been fixed. A bug that caused garbled output with UDP tests on 32-bit hosts has been fixed (PR #1554, PR #1556). This bug was introduced in iperf-3.14. A bug in counting UDP messages has been fixed (PR #1367, PR #1380). Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 8765f02ffb85ddff21e461b716ef3f86d368cb4e) Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: Fix CVE-2024-53580Soumya Sambu2025-09-262-0/+277
| | | | | | | | | | | | | | | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. References: https://nvd.nist.gov/vuln/detail/CVE-2024-53580 https://security-tracker.debian.org/tracker/CVE-2024-53580 Upstream patch: https://github.com/esnet/iperf/commit/3f66f604df7f1038a49108c48612c2f4fe71331f Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: Fix CVE-2024-26306Soumya Sambu2025-09-262-0/+219
| | | | | | | | | | | | | | | | | | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. References: https://nvd.nist.gov/vuln/detail/CVE-2024-26306 https://security-tracker.debian.org/tracker/CVE-2024-26306 Upstream patch: https://github.com/esnet/iperf/commit/299b356df6939f71619bf45bf7a7d2222e17d840 Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: Fix CVE-2023-7250Soumya Sambu2025-09-262-0/+134
| | | | | | | | | | | | | | | | | | A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service. References: https://nvd.nist.gov/vuln/detail/CVE-2023-7250 https://security-tracker.debian.org/tracker/CVE-2023-7250 Upstream patch: https://github.com/esnet/iperf/commit/5e3704dd850a5df2fb2b3eafd117963d017d07b4 Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: Fix CVE-2025-54349Nitin Wankhade2025-09-262-0/+57
| | | | | | | | | This commit fix heap overflow for iperf3 package Reference: https://github.com/esnet/iperf/commit/4e5313bab0b9b3fe03513ab54f722c8a3e4b7bdf Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* iperf3: Fix CVE-2025-54350Nitin Wankhade2025-09-262-0/+26
| | | | | | | | | | remove assert to prevent crash due to assertion failure on malformed authentication attempt Reference: https://github.com/esnet/iperf/commit/4eab661da0bbaac04493fa40164e928c6df7934a Signed-off-by: Nitin Wankhade <nitin.wankhade333@gmail.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* image_types_sparse: backport optionally remove RAW imageAshishKumar Mishra2025-09-261-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | When creating sparse images, the RAW image is no longer needed in some workflows such as Android and CI pipelines. These RAW images can be multi-GB artifacts and consume significant disk space. This change introduces a configuration option `DELETE_RAWIMAGE_AFTER_SPARSE_CMD` which, when set to "1", removes the RAW image after sparse image generation. This reduces disk usage in builds where sparse images are the final deliverables and RAW images are not required. Default behavior is unchanged: RAW images are kept unless the variable is explicitly enabled: This change corresponds to upstream f5246b7df447ac76ec04c6e5add398862d1c9ccd DELETE_RAWIMAGE_AFTER_SPARSE_CMD = "1" # Delete RAW image DELETE_RAWIMAGE_AFTER_SPARSE_CMD = "0" # Default behavior Signed-off-by: AshishKumar Mishra <emailaddress.ashish@gmail.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> Signed-off-by: AshishKumar Mishra <emailaddress.ashish@gmail.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* image_types_sparse: backport generate "don't care" chunksSean Anderson2025-09-265-1/+366
| | | | | | | | | | | | | By default, img2simg will only generate raw and fill chunks. This adds support for "don't care" chunks, based on file holes. This is similar to how bmaptool works. "don't care" chunks do not need to be written, speeding up flashing time. This change corresponds to upstream 9862a017fa7f88424f0670ba89af58e5051550b0 Signed-off-by: Sean Anderson <sean.anderson@seco.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> Signed-off-by: AshishKumar Mishra <emailaddress.ashish@gmail.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
* image_types_sparse: backport fix pad source image to block sizeSean Anderson2025-09-261-2/+10
| | | | | | | | | | | | | | | | | | If the source image's size is not aligned to the sparse image's block size, then conversion will fail with img2simg: libsparse/sparse.cpp:133: int write_all_blocks(sparse_file*, output_file*): Assertion `pad >= 0' failed. This is a bug in img2simg, but an easy way to work around it is to pad the source image ourselves. The default block size of 4096 matches img2simg's default block size. This change corresponds to upstream fb331cb62eafd1e534dee292525084ccee0ef3e1 Signed-off-by: Sean Anderson <sean.anderson@seco.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> Signed-off-by: AshishKumar Mishra <emailaddress.ashish@gmail.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>