<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-connectivity, branch 5.2_M2</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=5.2_M2</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=5.2_M2'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2025-01-23T12:14:29+00:00</updated>
<entry>
<title>ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542</title>
<updated>2025-01-23T12:14:29+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-01-19T16:34:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=9e54ce7eac6886a037a6dc791abca2b918d96137'/>
<id>urn:sha1:9e54ce7eac6886a037a6dc791abca2b918d96137</id>
<content type='text'>
Cherry-pick commit
https://git.kernel.org/pub/scm/network/ofono/ofono.git/commit/?id=29ff6334b492504ace101be748b256e6953d2c2f

(From OE-Core rev: 2513c7504a270c7a079f4e942252f92d0e48bd32)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
</content>
</entry>
<entry>
<title>ofono: fix CVE-2024-7539</title>
<updated>2025-01-20T13:38:59+00:00</updated>
<author>
<name>Yogita Urade</name>
<email>yogita.urade@windriver.com</email>
</author>
<published>2025-01-14T12:51:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=49863645a07ae6e3970cf72ee856627706abdcb1'/>
<id>urn:sha1:49863645a07ae6e3970cf72ee856627706abdcb1</id>
<content type='text'>
oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability.
This vulnerability allows local attackers to execute arbitrary code
on affected installations of oFono. An attacker must first obtain
the ability to execute code on the target modem in order to exploit
this vulnerability.

The specific flaw exists within the parsing of responses from AT+CUSD
commands. The issue results from the lack of proper validation of the
length of user-supplied data prior to copying it to a stack-based buffer.
An attacker can leverage this vulnerability to execute code in the
context of root. Was ZDI-CAN-23195.

Reference:
https://security-tracker.debian.org/tracker/CVE-2024-7539

Upstream patch:
https://git.kernel.org/pub/scm/network/ofono/ofono.git/commit/?id=389e2344f86319265fb72ae590b470716e038fdc

(From OE-Core rev: 55aea716ca4665cf45579247dd5feec5668dd94f)

Signed-off-by: Yogita Urade &lt;yogita.urade@windriver.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>openssl: remove obsolete CVE version suffix</title>
<updated>2025-01-20T13:38:59+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2025-01-15T18:49:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=23e695407ec0c663de3106863a46f597e2c31f2e'/>
<id>urn:sha1:23e695407ec0c663de3106863a46f597e2c31f2e</id>
<content type='text'>
Since 3.0.0 openssl no longer uses characters in version suffix.

(From OE-Core rev: 80151340b0b20610030f3026e9fc71ef5970c2c5)

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>boost: update 1.86.0 -&gt; 1.87.0</title>
<updated>2025-01-10T11:10:00+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex@linutronix.de</email>
</author>
<published>2025-01-08T08:42:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c65340f13eebf8a42782b3443f0c79cc96552e9e'/>
<id>urn:sha1:c65340f13eebf8a42782b3443f0c79cc96552e9e</id>
<content type='text'>
Backport a kea patch to address 1.87.0 compatibility.

(From OE-Core rev: ac328183d4592ad146c41e48c2c92d1dbb53a894)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>ppp: update 2.5.1 -&gt; 2.5.2</title>
<updated>2025-01-10T11:10:00+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex@linutronix.de</email>
</author>
<published>2025-01-08T08:42:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=9c80c18f829b35497f6cdd3871af66a2621d5478'/>
<id>urn:sha1:9c80c18f829b35497f6cdd3871af66a2621d5478</id>
<content type='text'>
License-Update: BSD items clarified to be 2-clause:
https://github.com/ppp-project/ppp/commit/d4ec06ec5839350bd728da0e92a8cb2e1c37d880
passprompt plugin removed upstream.

Add an enable a multilink option, as the build breaks without it at the linking
step (upstream presumably didn't test that it works): https://github.com/ppp-project/ppp/issues/541

(From OE-Core rev: e6ea3ade8f3977ec93c68229d2660bbc335a80a6)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>iproute2: update 6.11.0 -&gt; 6.12.0</title>
<updated>2025-01-04T12:34:03+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex@linutronix.de</email>
</author>
<published>2025-01-03T10:45:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=84287daee01e5f8661dbf5098f4eb2f4d0b1b959'/>
<id>urn:sha1:84287daee01e5f8661dbf5098f4eb2f4d0b1b959</id>
<content type='text'>
(From OE-Core rev: f8c665ca16bf643039bd3f0a918ea9cf9d1a3726)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>nfs-utils: Use v2 of upstream patch for tpyecast fix</title>
<updated>2024-12-20T18:00:26+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2024-12-20T17:14:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=9dbeec7fa712ec6149b955721343bf2651fd72de'/>
<id>urn:sha1:9dbeec7fa712ec6149b955721343bf2651fd72de</id>
<content type='text'>
(From OE-Core rev: a2c5b2cad7857250b4a1b36ba792a8110989733a)

Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>ofono: fix the build when toolchain has old linux headers</title>
<updated>2024-12-20T15:47:14+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2024-12-19T13:54:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=e52d5e692f20eb820924a409289bd5603f176485'/>
<id>urn:sha1:e52d5e692f20eb820924a409289bd5603f176485</id>
<content type='text'>
Whilst our default toolchain has modern kernel headers (6.12, at time of
writing), some external toolchains may use old kernel headers.

As ofono's rmnet module uses kernel defines which were added in 5.14,
add some compatibility defines in case they are not set.

(From OE-Core rev: 0313ea48a75480c2bcc6d35035f74a4dcf22f263)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>bind: upgrade 9.20.3 -&gt; 9.20.4</title>
<updated>2024-12-20T15:47:14+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2024-12-19T09:13:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=26fe17e505ac334c93cceba5e8ac21a63632216c'/>
<id>urn:sha1:26fe17e505ac334c93cceba5e8ac21a63632216c</id>
<content type='text'>
bind-ensure-searching-for-json-headers-searches-sysr.patch
refreshed for 9.20.4

(From OE-Core rev: 5da817ca4d58eb70ad42fc1fa0f7f4edf696585d)

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>nfs-utils: Fix warnings found with clang</title>
<updated>2024-12-20T15:47:14+00:00</updated>
<author>
<name>Khem Raj</name>
<email>raj.khem@gmail.com</email>
</author>
<published>2024-12-19T03:35:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=8a051bd0ea67e16c6eaac82036c62bfc933f6978'/>
<id>urn:sha1:8a051bd0ea67e16c6eaac82036c62bfc933f6978</id>
<content type='text'>
(From OE-Core rev: 5a6232b730e8d791cd270267cb32bbe15cc1ce14)

Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Mathieu Dubois-Briand &lt;mathieu.dubois-briand@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
