<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-graphics, branch mickledore</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2023-11-11T18:23:01+00:00</updated>
<entry>
<title>xserver-xorg: Fix for CVE-2023-5367 and CVE-2023-5380</title>
<updated>2023-11-11T18:23:01+00:00</updated>
<author>
<name>Vijay Anusuri</name>
<email>vanusuri@mvista.com</email>
</author>
<published>2023-11-08T03:35:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=b5686f826dc3cfa60dff4703e641f3ec177c3418'/>
<id>urn:sha1:b5686f826dc3cfa60dff4703e641f3ec177c3418</id>
<content type='text'>
Upstream-Status: Backport
[https://gitlab.freedesktop.org/xorg/xserver/-/commit/541ab2ecd41d4d8689e71855d93e492bc554719a
&amp;
https://gitlab.freedesktop.org/xorg/xserver/-/commit/564ccf2ce9616620456102727acb8b0256b7bbd7]

(From OE-Core rev: d7ecf2b605cef1ec5b3a9d253d4b46590a7c6891)

Signed-off-by: Vijay Anusuri &lt;vanusuri@mvista.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>pixman: ignore CVE-2023-37769</title>
<updated>2023-11-11T18:23:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-11-03T13:28:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=c97d2f0f0961a7d524beb7716d24aa249980e604'/>
<id>urn:sha1:c97d2f0f0961a7d524beb7716d24aa249980e604</id>
<content type='text'>
This issue relates to a floating point exception in stress-test, which
is an unlikely security exploit at the best of times, but the test is
not installed so isn't relevant.

(From OE-Core rev: 3625bed6d7432091bfb144314b8ef979b5246e4c)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit a36d62a06be6cce1a438f8f2178eb60aad6b7267)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxpm: upgrade to 3.5.17</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-10-04T21:43:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=57fb41f5c6ef03a6df4a4a3f848b6ed66eebdc2b'/>
<id>urn:sha1:57fb41f5c6ef03a6df4a4a3f848b6ed66eebdc2b</id>
<content type='text'>
This release fixes the following CVEs:

- CVE-2023-43788
- CVE-2023-43789

(From OE-Core rev: b4596281de1f96fdf6533ab4caa957f1eaeff756)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 46dd8ce41756dbc2aa0f9001416f208cced1c8d5)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libx11: upgrade to 1.8.7</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-10-04T21:43:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d441582b0673f69f2cf56081e6b5d7992a78fe4c'/>
<id>urn:sha1:d441582b0673f69f2cf56081e6b5d7992a78fe4c</id>
<content type='text'>
This incorporates fixes for the following CVEs:

- CVE-2023-43785
- CVE-2023-43786
- CVE-2023-43787

(From OE-Core rev: 79f9c062df37ca15649d41bb6501e6fab2d73114)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit a1534bb34b680bfc5cb2f35b5fd5a0c2afed6368)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>igt-gpu-tools: do not write shortened git commit hash into binaries</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex.kanavin@gmail.com</email>
</author>
<published>2023-09-17T19:30:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=ec061cddc719ee0ab6ea3415332f591f3efd676d'/>
<id>urn:sha1:ec061cddc719ee0ab6ea3415332f591f3efd676d</id>
<content type='text'>
Shortened hashes are prone to collisions, and in this case git
lengthens the hash to resolve the collision. This in turn breaks
reproducibility, depending on whether the colliding hash is present
in the history or not. This has been observed here:
http://autobuilder.yocto.io/pub/repro-fail/oe-reproducible-20230917-br60if6q/packages/diff-html/

(From OE-Core rev: e0cdfefe3054a2278f7db5d382045304b710118b)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit a74e1eff93d4de5724481e3298308a6d925a4512)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>weston-init: fix init code indentation</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Otavio Salvador</name>
<email>otavio@ossystems.com.br</email>
</author>
<published>2023-09-09T12:54:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=04296bff893dd92aaa8918cf9c36feb31485a0bd'/>
<id>urn:sha1:04296bff893dd92aaa8918cf9c36feb31485a0bd</id>
<content type='text'>
Tested-by: Tom Hochstein &lt;tom.hochstein@nxp.com&gt;
(From OE-Core rev: feb3af7fe3f1a062946de71a76c11388f9e50c90)

Signed-off-by: Otavio Salvador &lt;otavio@ossystems.com.br&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit c08d474c97ce071ba376b66f30d6ee0a6159d596)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>weston-init: remove misleading comment about udev rule</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Otavio Salvador</name>
<email>otavio@ossystems.com.br</email>
</author>
<published>2023-09-09T12:54:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d6b645127c40fe5731ac5bacdaf09b6895503133'/>
<id>urn:sha1:d6b645127c40fe5731ac5bacdaf09b6895503133</id>
<content type='text'>
The udev rule has been removed but the comment has kept, by
mistake. Remove it.

Fixes: dd83fb40f7 ("weston-init: Stop running weston as root")
Tested-by: Tom Hochstein &lt;tom.hochstein@nxp.com&gt;
(From OE-Core rev: 35367d029fedc78724396d94abd899e4bd8bef0c)

Signed-off-by: Otavio Salvador &lt;otavio@ossystems.com.br&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 8aa3d43fa1c53cdce45ec88a49f27b076d3812ac)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libxkbcommon: add CVE_PRODUCT</title>
<updated>2023-10-13T14:31:05+00:00</updated>
<author>
<name>Emil Kronborg Andersen</name>
<email>emkan@prevas.dk</email>
</author>
<published>2023-08-24T13:41:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d61e137c1a7ff48c57cd4506411bdce940309abb'/>
<id>urn:sha1:d61e137c1a7ff48c57cd4506411bdce940309abb</id>
<content type='text'>
(From OE-Core rev: 7d395b97e864bb081866eb029168aee7335ed98e)

Signed-off-by: Emil Kronborg Andersen &lt;emkan@prevas.dk&gt;
(cherry picked from commit a23a4a3f156f5758dc4d9dcf1ab27c74302eb2a8)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>wayland-utils: add libdrm PACKAGECONFIG</title>
<updated>2023-10-13T14:31:05+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-09-06T18:14:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=88216a956584637456eccb0050a58e20c65f6e47'/>
<id>urn:sha1:88216a956584637456eccb0050a58e20c65f6e47</id>
<content type='text'>
wayland-utils has optional libdrm support, so add a PACKAGECONFIG and
enable it.

(From OE-Core rev: 0ba10930f73e4b0c2896afd326229fc6ae460f51)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit c6c488c259d1f38a05a71e576ca2f32d412413f1)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>pango: explictly enable/disable libthai</title>
<updated>2023-10-13T14:31:05+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-09-06T18:14:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=9103dc5b8959ac965388159178b905cf8430df54'/>
<id>urn:sha1:9103dc5b8959ac965388159178b905cf8430df54</id>
<content type='text'>
Pango has had an explicit option since 1.46.2

(From OE-Core rev: dc939fbc70c124a515b882b3425d7810be0c6748)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 42755f135d2d015e564d783996fbb3ef860f2bf7)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
</feed>
