From 09fcc28cd0e7671ee92241d40a0a77f586c9fd82 Mon Sep 17 00:00:00 2001 From: Saravanan Date: Tue, 30 Sep 2025 14:51:41 +0530 Subject: udisks2: upgrade 2.10.1 -> 2.10.2 This patch addresses below CVE's: CVE-2025-6019 CVE-2025-8067 Changelog: https://github.com/storaged-project/udisks/releases Signed-off-by: Saravanan Signed-off-by: Khem Raj --- .../udisks/udisks2/CVE-2025-6019.patch | 51 ------------------ meta-oe/recipes-support/udisks/udisks2_2.10.1.bb | 63 ---------------------- meta-oe/recipes-support/udisks/udisks2_2.10.2.bb | 62 +++++++++++++++++++++ 3 files changed, 62 insertions(+), 114 deletions(-) delete mode 100644 meta-oe/recipes-support/udisks/udisks2/CVE-2025-6019.patch delete mode 100644 meta-oe/recipes-support/udisks/udisks2_2.10.1.bb create mode 100644 meta-oe/recipes-support/udisks/udisks2_2.10.2.bb (limited to 'meta-oe') diff --git a/meta-oe/recipes-support/udisks/udisks2/CVE-2025-6019.patch b/meta-oe/recipes-support/udisks/udisks2/CVE-2025-6019.patch deleted file mode 100644 index 2e94c8497f..0000000000 --- a/meta-oe/recipes-support/udisks/udisks2/CVE-2025-6019.patch +++ /dev/null @@ -1,51 +0,0 @@ -From d0d04a381036b79df91616552706d515639bb762 Mon Sep 17 00:00:00 2001 -From: Tomas Bzatek -Date: Wed, 4 Jun 2025 15:26:46 +0200 -Subject: [PATCH] udiskslinuxfilesystemhelpers: Mount private mounts with - 'nodev,nosuid' - -The private mount done in take_filesystem_ownership() should always -default to 'nodev,nosuid' for security and 'errors=remount-ro' for -selected filesystem types to handle an corrupted filesystem. This is -consistent with mount options calculation for regular mounts. - -CVE: CVE-2025-6019 -Upstream-Status: Backport [ https://github.com/storaged-project/udisks/commit/5e7277debea926370e587408517560afe87d28c9 ] - -Signed-off-by: Changqing Li ---- - src/udiskslinuxfilesystemhelpers.c | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/src/udiskslinuxfilesystemhelpers.c b/src/udiskslinuxfilesystemhelpers.c -index 7c5fc037..9eb7742c 100644 ---- a/src/udiskslinuxfilesystemhelpers.c -+++ b/src/udiskslinuxfilesystemhelpers.c -@@ -123,6 +123,7 @@ take_filesystem_ownership (const gchar *device, - - { - gchar *mountpoint = NULL; -+ const gchar *mount_opts; - GError *local_error = NULL; - gboolean unmount = FALSE; - gboolean success = TRUE; -@@ -151,8 +152,15 @@ take_filesystem_ownership (const gchar *device, - goto out; - } - -+ mount_opts = "nodev,nosuid"; -+ if (g_strcmp0 (fstype, "ext2") == 0 || -+ g_strcmp0 (fstype, "ext3") == 0 || -+ g_strcmp0 (fstype, "ext4") == 0 || -+ g_strcmp0 (fstype, "jfs") == 0) -+ mount_opts = "nodev,nosuid,errors=remount-ro"; -+ - /* TODO: mount to a private mount namespace */ -- if (!bd_fs_mount (device, mountpoint, fstype, NULL, NULL, &local_error)) -+ if (!bd_fs_mount (device, mountpoint, fstype, mount_opts, NULL, &local_error)) - { - g_set_error (error, UDISKS_ERROR, UDISKS_ERROR_FAILED, - "Cannot mount %s at %s: %s", --- -2.34.1 - diff --git a/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb b/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb deleted file mode 100644 index cc0c19ec8e..0000000000 --- a/meta-oe/recipes-support/udisks/udisks2_2.10.1.bb +++ /dev/null @@ -1,63 +0,0 @@ -SUMMARY = "udisks provides dbus interfaces for disks and storage devices" -LICENSE = "GPL-2.0-or-later & LGPL-2.0-or-later" -LIC_FILES_CHKSUM = "file://COPYING;md5=dd79f6dbbffdbc8e86b086a8f0c0ef43" - -DEPENDS = " \ - glib-2.0-native \ - libxslt-native \ - acl \ - libatasmart \ - polkit \ - libgudev \ - glib-2.0 \ - dbus-glib \ - libblockdev \ -" -DEPENDS += "${@bb.utils.filter('DISTRO_FEATURES', 'systemd', d)}" - -RDEPENDS:${PN} = "acl" - -SRC_URI = " \ - git://github.com/storaged-project/udisks.git;branch=2.10.x-branch;protocol=https \ - file://0001-Makefile.am-Dont-include-buildpath.patch \ - file://CVE-2025-6019.patch \ -" -SRCREV = "18c9faf089e306ad6f3f51f5cb887a6b9aa08350" - -CVE_PRODUCT = "udisks" - -inherit autotools-brokensep systemd gtk-doc gobject-introspection gettext features_check - -REQUIRED_DISTRO_FEATURES = "polkit" - -EXTRA_OECONF = "--disable-man --disable-gtk-doc" - -do_configure:prepend() { - # | configure.ac:656: error: required file 'build-aux/config.rpath' not found - mkdir -p ${S}/build-aux - touch ${S}/build-aux/config.rpath -} - -PACKAGECONFIG ?= "" - -PACKAGECONFIG[lvm2] = "--enable-lvm2,--disable-lvm2,lvm2" -PACKAGECONFIG[btrfs] = "--enable-btrfs,--disable-btrfs,,btrfs-tools" -PACKAGECONFIG[lsm] = "--enable-lsm,--disable-lsm,libstoragemgmt" - -FILES:${PN} += " \ - ${datadir}/dbus-1/ \ - ${datadir}/polkit-1 \ - ${datadir}/bash-completion \ - ${datadir}/zsh \ - ${libdir}/polkit-1/extensions/*.so \ - ${nonarch_base_libdir}/udev/* \ - ${exec_prefix}${nonarch_base_libdir}/udisks2/* \ - ${systemd_system_unitdir} \ -" - -PACKAGES =+ "${PN}-libs" -FILES:${PN}-libs = "${libdir}/lib*${SOLIBS}" -FILES:${PN} += "${nonarch_libdir}/tmpfiles.d" - -SYSTEMD_SERVICE:${PN} = "${BPN}.service" -SYSTEMD_AUTO_ENABLE = "disable" diff --git a/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb b/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb new file mode 100644 index 0000000000..081b315b9b --- /dev/null +++ b/meta-oe/recipes-support/udisks/udisks2_2.10.2.bb @@ -0,0 +1,62 @@ +SUMMARY = "udisks provides dbus interfaces for disks and storage devices" +LICENSE = "GPL-2.0-or-later & LGPL-2.0-or-later" +LIC_FILES_CHKSUM = "file://COPYING;md5=dd79f6dbbffdbc8e86b086a8f0c0ef43" + +DEPENDS = " \ + glib-2.0-native \ + libxslt-native \ + acl \ + libatasmart \ + polkit \ + libgudev \ + glib-2.0 \ + dbus-glib \ + libblockdev \ +" +DEPENDS += "${@bb.utils.filter('DISTRO_FEATURES', 'systemd', d)}" + +RDEPENDS:${PN} = "acl" + +SRC_URI = " \ + git://github.com/storaged-project/udisks.git;branch=2.10.x-branch;protocol=https \ + file://0001-Makefile.am-Dont-include-buildpath.patch \ +" +SRCREV = "bc623acf9e7488dc105e4b00069d57e303e2616b" + +CVE_PRODUCT = "udisks" + +inherit autotools-brokensep systemd gtk-doc gobject-introspection gettext features_check + +REQUIRED_DISTRO_FEATURES = "polkit" + +EXTRA_OECONF = "--disable-man --disable-gtk-doc" + +do_configure:prepend() { + # | configure.ac:656: error: required file 'build-aux/config.rpath' not found + mkdir -p ${S}/build-aux + touch ${S}/build-aux/config.rpath +} + +PACKAGECONFIG ?= "" + +PACKAGECONFIG[lvm2] = "--enable-lvm2,--disable-lvm2,lvm2" +PACKAGECONFIG[btrfs] = "--enable-btrfs,--disable-btrfs,,btrfs-tools" +PACKAGECONFIG[lsm] = "--enable-lsm,--disable-lsm,libstoragemgmt" + +FILES:${PN} += " \ + ${datadir}/dbus-1/ \ + ${datadir}/polkit-1 \ + ${datadir}/bash-completion \ + ${datadir}/zsh \ + ${libdir}/polkit-1/extensions/*.so \ + ${nonarch_base_libdir}/udev/* \ + ${exec_prefix}${nonarch_base_libdir}/udisks2/* \ + ${systemd_system_unitdir} \ +" + +PACKAGES =+ "${PN}-libs" +FILES:${PN}-libs = "${libdir}/lib*${SOLIBS}" +FILES:${PN} += "${nonarch_libdir}/tmpfiles.d" + +SYSTEMD_SERVICE:${PN} = "${BPN}.service" +SYSTEMD_AUTO_ENABLE = "disable" -- cgit v1.2.3-54-g00ecf