<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git, branch walnascar</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=walnascar</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=walnascar'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2025-09-25T19:29:56+00:00</updated>
<entry>
<title>build-appliance-image: Update to walnascar head revision</title>
<updated>2025-09-25T19:29:56+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2025-09-25T19:27:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d0b46a6624ec9c61c47270745dd0b2d5abbe6ac1'/>
<id>urn:sha1:d0b46a6624ec9c61c47270745dd0b2d5abbe6ac1</id>
<content type='text'>
(From OE-Core rev: ff1c54df4e7b15df2e2c9fced59d9ad3e92ed565)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>poky.conf: bump version for 5.2.4</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2025-09-23T15:46:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=316baad50b45319057753fa698cd74aeb49a0a9f'/>
<id>urn:sha1:316baad50b45319057753fa698cd74aeb49a0a9f</id>
<content type='text'>
(From meta-yocto rev: 0993c45a1f78f302fd40c78a2a1f709daa7a0ae0)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>tiff: patch CVE-2025-8961</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=639a818fd0681225e935722b500bd078ed4a816f'/>
<id>urn:sha1:639a818fd0681225e935722b500bd078ed4a816f</id>
<content type='text'>
Pick commit mentioned in [1].

[1] https://security-tracker.debian.org/tracker/CVE-2025-8961

(From OE-Core rev: c171a41e58e2f151dada61ee2a53c15ceaaa85c0)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>tiff: patch CVE-2025-9165</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ac184e133bbb0e88d6aaf0584cff0304a036c562'/>
<id>urn:sha1:ac184e133bbb0e88d6aaf0584cff0304a036c562</id>
<content type='text'>
Pick commit mentioned in NVD report.

(From OE-Core rev: af4a1f0140fc7739b1bd6e39be1df28681628312)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>tiff: ignore CVE-2025-8851</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=73a25f197b117a5c8118d28043c350be930b5399'/>
<id>urn:sha1:73a25f197b117a5c8118d28043c350be930b5399</id>
<content type='text'>
This is fixed in v4.7.0, however cve_check cannot match it as NVD says
"Up to (excluding) 2024-08-11".

(From OE-Core rev: 17a71c67a8a9242e5ae8985a9ebcc51bfa112c3d)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>cups: patch CVE-2025-58364</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=91844fbbf23e4edde8cef24edc54353b7322d5a2'/>
<id>urn:sha1:91844fbbf23e4edde8cef24edc54353b7322d5a2</id>
<content type='text'>
Pick commit mentioned in NVD report

(From OE-Core rev: 09a9653c51ac3eae545deeaa004fbbff8c00c827)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>cups: patch CVE-2025-58060</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=a443a81cf82ccdc99a562e199d876dface5e0403'/>
<id>urn:sha1:a443a81cf82ccdc99a562e199d876dface5e0403</id>
<content type='text'>
Pick commit mentioned in NVD report.

(From OE-Core rev: cd732eb0cf1f4dc4fbfd64c7cc67125736480b37)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>grub2: mark CVE-2024-2312 as not applicable</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2025-09-25T14:05:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=77fb27f68027d23667316f0bcd09a2452082854c'/>
<id>urn:sha1:77fb27f68027d23667316f0bcd09a2452082854c</id>
<content type='text'>
This issue is specific to the peimage module that Ubuntu add, and is not
an upstream issue.

(From OE-Core rev: 8d2fe3f403e6435e1ffe122a6776381090752d8a)

(From OE-Core rev: 37c224f51817a948f2558f78eec23a3b1df1cb24)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>pulseaudio: ignore CVE-2024-11586</title>
<updated>2025-09-25T19:25:52+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2025-09-25T14:05:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=f15ade2e8a3dc0c4552b1e712d6d08a9bcb6c01a'/>
<id>urn:sha1:f15ade2e8a3dc0c4552b1e712d6d08a9bcb6c01a</id>
<content type='text'>
As per the linked ticket, this issue is related to an Ubuntu-specific
patch that we don't have.

(From OE-Core rev: dc81fdc6bdf8ab39b7f2fd994d50256430c36558)

(From OE-Core rev: 72e63e44a0c6ad5a408c4dc59a24288c36463439)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>gstreamer1.0: set status of CVE-2025-3887 to patched</title>
<updated>2025-09-25T19:25:51+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-09-25T14:05:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b066c3a8cc312c2922d181890e6c5add96d8b5a9'/>
<id>urn:sha1:b066c3a8cc312c2922d181890e6c5add96d8b5a9</id>
<content type='text'>
This CVE was fixed in plugins-bad.
See [1] and [2] which is included in 1.24.13.
These commits are backport of [3] to 1.24.
Commits fixing this CVE were copied from [4].

[1] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/e4351ef03f1331410b0c1216a6178d885f37e495
[2] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/ed4c2ce380f7168bd4a3423f4398eb341cb931c7
[3] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8884
[4] https://security-tracker.debian.org/tracker/CVE-2025-3887

(From OE-Core rev: 13d7e30b45e90187800ba5a383c9579ba2fa0344)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
</feed>
