<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-support, branch mickledore</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=mickledore'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2023-11-11T18:23:01+00:00</updated>
<entry>
<title>curl: Fix CVE-2023-38039</title>
<updated>2023-11-11T18:23:01+00:00</updated>
<author>
<name>Mingli Yu</name>
<email>mingli.yu@windriver.com</email>
</author>
<published>2023-11-02T08:46:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=eefb8f69cebc052f2fe4f081ce6f74413df099f7'/>
<id>urn:sha1:eefb8f69cebc052f2fe4f081ce6f74413df099f7</id>
<content type='text'>
Backport patch [1] to fix CVE-2023-38039 and reference [2] and [3] to fix
the build error.

[1] https://github.com/curl/curl/commit/3ee79c1674fd6f9
[2] https://github.com/curl/curl/commit/2cb0d346aaa
[3] https://github.com/curl/curl/commit/83319e027179

(From OE-Core rev: 77a7921660e8da1cb618ba3634835790ae8adfdd)

Signed-off-by: Mingli Yu &lt;mingli.yu@windriver.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libevent: fix patch Upstream-Status</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Michael Opdenacker</name>
<email>michael.opdenacker@bootlin.com</email>
</author>
<published>2023-09-20T09:33:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=29bcbba9d9c5f9ed9c24c910e8c84e69bfa971d8'/>
<id>urn:sha1:29bcbba9d9c5f9ed9c24c910e8c84e69bfa971d8</id>
<content type='text'>
(From OE-Core rev: 6afee5ac3b419532d290d8a0c533e5d144913e92)

Signed-off-by: Michael Opdenacker &lt;michael.opdenacker@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 8c987afb2054f24d9bf86305774c186a6e015a8f)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>vim: Upgrade 9.0.2009 -&gt; 9.0.2048</title>
<updated>2023-10-25T14:51:01+00:00</updated>
<author>
<name>Siddharth Doshi</name>
<email>sdoshi@mvista.com</email>
</author>
<published>2023-10-19T04:12:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3f2a31ddc64e86f708b866f3c96fb0b7dbad8f12'/>
<id>urn:sha1:3f2a31ddc64e86f708b866f3c96fb0b7dbad8f12</id>
<content type='text'>
This includes CVE fix for CVE-2023-5535.

(From OE-Core rev: b385544941a4d974ab95b0a886031d5c9f3971ba)

Signed-off-by: Siddharth Doshi &lt;sdoshi@mvista.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libsoup-2.4: Only specify --cross-file when building for target</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Peter Kjellerstedt</name>
<email>peter.kjellerstedt@axis.com</email>
</author>
<published>2023-09-14T23:41:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=629f043c8f1e066bf0e2c0548a0882b301a9a636'/>
<id>urn:sha1:629f043c8f1e066bf0e2c0548a0882b301a9a636</id>
<content type='text'>
The soup.cross file is only created when building for target so only
tell meson to read it when it exists. This allows libsoup-2.4-native to
be built again.

(From OE-Core rev: d52003dd13cb17e32ccfa717f8462c8301334dd1)

Signed-off-by: Peter Kjellerstedt &lt;peter.kjellerstedt@axis.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 4acbd2269931b500846d56885c3304d244e514f8)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>vim: Upgrade 9.0.1894 -&gt; 9.0.2009</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Siddharth Doshi</name>
<email>sdoshi@mvista.com</email>
</author>
<published>2023-10-12T06:05:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=6f40a967bde1508e1e6c8574f95145e2175513b0'/>
<id>urn:sha1:6f40a967bde1508e1e6c8574f95145e2175513b0</id>
<content type='text'>
This includes CVE fix for CVE-2023-5441.

(From OE-Core rev: 7166f503211c39542d828aa3fef5006dccf2c07a)

Signed-off-by: Siddharth Doshi &lt;sdoshi@mvista.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>curl: fix CVE-2023-38546</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Archana Polampalli</name>
<email>archana.polampalli@windriver.com</email>
</author>
<published>2023-10-13T01:49:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=af8586bde2b8910ab7d0712aaf553720683cbd8e'/>
<id>urn:sha1:af8586bde2b8910ab7d0712aaf553720683cbd8e</id>
<content type='text'>
A flaw was found in the Curl package. This flaw allows an attacker to insert
cookies into a running program using libcurl if the specific series of conditions are met.

(From OE-Core rev: a6c5931192a1315cfc5f708585d22bc7bed9f7fd)

Signed-off-by: Archana Polampalli &lt;archana.polampalli@windriver.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>curl: fix CVE-2023-38545</title>
<updated>2023-10-18T15:25:19+00:00</updated>
<author>
<name>Archana Polampalli</name>
<email>archana.polampalli@windriver.com</email>
</author>
<published>2023-10-12T13:33:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=d1c80c5f4abbc064f23e01d8ce950b09f6a3c161'/>
<id>urn:sha1:d1c80c5f4abbc064f23e01d8ce950b09f6a3c161</id>
<content type='text'>
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.

(From OE-Core rev: 9b0867861a9c053f19bdb99bd6cba44ee5cb64e1)

Signed-off-by: Archana Polampalli &lt;archana.polampalli@windriver.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>libsoup-2.4: update PACKAGECONFIG</title>
<updated>2023-10-13T14:31:05+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2023-09-06T18:14:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=efdb7d00b8e80fb90090a8ee692625bfee04362e'/>
<id>urn:sha1:efdb7d00b8e80fb90090a8ee692625bfee04362e</id>
<content type='text'>
Add explicit PACKAGECONFIGs for brotli,ntlm, and sysprof.

libsoup needs to be told where ntlm_auth will be on the target, so write
a cross file to do so.

(From OE-Core rev: c78a34caf466524356572b8cdd2ada615081bfc2)

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 54b6ea078daeb58a3bb20bb4275d1140640a77d2)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>gnupg: upgrade 2.4.2 -&gt; 2.4.3</title>
<updated>2023-10-13T14:31:04+00:00</updated>
<author>
<name>Alexander Kanavin</name>
<email>alex.kanavin@gmail.com</email>
</author>
<published>2023-09-06T16:56:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=5fa9c019e357804f5701ee86511112c706998ee7'/>
<id>urn:sha1:5fa9c019e357804f5701ee86511112c706998ee7</id>
<content type='text'>
New stable GnuPG release: version 2.4.3.  This version fixes some minor bugs and
improves the performance on Windows.

(From OE-Core rev: e0641f1ff96e7f3835bde0196ea8d4d3a734f0f2)

Signed-off-by: Alexander Kanavin &lt;alex@linutronix.de&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 0c2365540ae61fe6fab61fb076ddb976ca26ce47)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
<entry>
<title>nettle: avoid neon on unsupported machines</title>
<updated>2023-10-11T13:54:46+00:00</updated>
<author>
<name>Benjamin Bara</name>
<email>benjamin.bara@skidata.com</email>
</author>
<published>2023-09-04T08:48:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=62630557f62d61bbae9975c9f8059e218581feb7'/>
<id>urn:sha1:62630557f62d61bbae9975c9f8059e218581feb7</id>
<content type='text'>
Disable neon if the machine does not support it. --enable-fat also
includes the neon assembler code, therefore also disable it.

(From OE-Core rev: 9a0c8796cc5788a88b3e4fea50de130185b11a18)

Signed-off-by: Benjamin Bara &lt;benjamin.bara@skidata.com&gt;
Signed-off-by: Alexandre Belloni &lt;alexandre.belloni@bootlin.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit 768c6bb46e1cc4a1d8c12c6f30408bb821ec4534)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
</content>
</entry>
</feed>
