Release notes for Yocto-4.0.33 (Kirkstone)
Security Fixes in Yocto-4.0.33
binutils: Fix CVE-2025-1181, CVE-2025-11494, CVE-2025-11839 and CVE-2025-11840
cups: Fix CVE-2025-58436 and CVE-2025-61915
curl: Fix CVE-2025-14017, CVE-2025-15079 and CVE-2025-15224
dropbear: Fix CVE-2019-6111
glib-2.0: Fix CVE-2025-13601, CVE-2025-14087 and CVE-2025-14512
gnupg: Fix CVE-2025-68973
go: Fix CVE-2023-39323, CVE-2025-61727 and CVE-2025-61729
go: Fix CVE-2025-58187 (update patch)
grub: Fix CVE-2025-61661, CVE-2025-61662, CVE-2025-61663 and CVE-2025-61664
libarchive: Fix CVE-2025-60753 (update patch)
libpcap: Fix CVE-2025-11961 and CVE-2025-11964
libsoup: fix CVE-2025-12105
libxslt: Fix CVE-2025-11731
python3: Fix CVE-2025-13836
python3-urllib3: Fix CVE-2025-66418
qemu: Fix CVE-2025-12464
qemu: Ignore CVE-2025-54566 and CVE-2025-54567
rsync: Fix CVE-2025-10158
util-linux: Fix CVE-2025-14104
Fixes in Yocto-4.0.33
build-appliance-image: Update to kirkstone head revision
contributor-guide/recipe-style-guide.rst: explain difference between layer and recipe license(s)
cross.bbclass: Propagate dependencies to outhash
cups: allow unknown directives in conf files
docs: Add a new “Security” section
oeqa: Use 2.14 release of cpio instead of 2.13
overview-manual/yp-intro.rst: change removed ECOSYSTEM to ABOUT
overview-manual/yp-intro.rst: fix SDK type in bullet list
overview-manual/yp-intro.rst: link to YP members and participants
overview-manual: convert YP-flow-diagram.png to SVG
poky.conf: Bump version for 4.0.33 release
pseudo: Upgrade to 1.9.2+git125b020dd2
ref-manual/classes.rst: document the image-container class
ref-manual/release-process.rst: add a “Development Cycle” section
ref-manual/svg/releases.svg: mark styhead and walnascar EOL
ref-manual/svg/releases.svg: mark whinlatter as current release
ref-manual/variables.rst: document the CCACHE_TOP_DIR variable
scripts/install-buildtools: Update to 4.0.31
test-manual/ptest.rst: detail the exit code and output requirements
Known Issues in Yocto-4.0.33
N/A
Contributors to Yocto-4.0.33
Aleksandar Nikolic
Antonin Godard
Changqing Li
Deepesh Varatharajan
Hitendra Prajapati
Jiaying Song
Kai Kang
Khem Raj
Libo Chen
Liyin Zhang
Martin Jansa
Mingli Yu
Paul Barker
Peter Marko
Richard Purdie
Robert Yang
Vijay Anusuri
Yash Shinde
Repositories / Downloads for Yocto-4.0.33
yocto-docs
Repository Location: https://git.yoctoproject.org/yocto-docs
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: 6799b1be5d48f4bf5dcd0b16c2dbc2e297d4ecd9
Release Artefact: yocto-docs-6799b1be5d48f4bf5dcd0b16c2dbc2e297d4ecd9
sha: 42a0eb89c8f87a9a966aecb8265f463486d4383cb67d1e67382ddf9d4d7f88b5
Download Locations:
poky
Repository Location: https://git.yoctoproject.org/poky
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: ff118ede826a9ae45eb35025a5f7f612880fba01
Release Artefact: poky-ff118ede826a9ae45eb35025a5f7f612880fba01
sha: 2a8c24406fa96fc52728a96f25136a3fd7ee652eea6e12319a6b7c0457ccfdfd
Download Locations:
openembedded-core
Repository Location: https://git.openembedded.org/openembedded-core
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: 036f76ea35c49a78d612093dcd8eb1fac7ded8d7
Release Artefact: oecore-036f76ea35c49a78d612093dcd8eb1fac7ded8d7
sha: fc180ff224529fd73a7aec4a4cf5beb40fba17646ee694715cf603baba26610c
Download Locations:
meta-yocto
Repository Location: https://git.yoctoproject.org/meta-yocto
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: 677379f21941363d50f9d946963542b4ccb7e27c
Release Artefact: meta-yocto-677379f21941363d50f9d946963542b4ccb7e27c
sha: 90f52c406f4e69748b8d73eee07b8a1247d19cc29f4893174f110a034b10415f
Download Locations:
meta-mingw
Repository Location: https://git.yoctoproject.org/meta-mingw
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: 87c22abb1f11be430caf4372e6b833dc7d77564e
Release Artefact: meta-mingw-87c22abb1f11be430caf4372e6b833dc7d77564e
sha: f0bc4873e2e0319fb9d6d6ab9b98eb3f89664d4339a167d2db6a787dd12bc1a8
Download Locations:
meta-gplv2
Repository Location: https://git.yoctoproject.org/meta-gplv2
Branch: kirkstone
Tag: yocto-4.0.33
Git Revision: d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a
Release Artefact: meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a
sha: c386f59f8a672747dc3d0be1d4234b6039273d0e57933eb87caa20f56b9cca6d
Download Locations:
bitbake
Repository Location: https://git.openembedded.org/bitbake
Branch: 2.0
Tag: yocto-4.0.33
Git Revision: 8e2d1f8de055549b2101614d85454fcd1d0f94b2
Release Artefact: bitbake-8e2d1f8de055549b2101614d85454fcd1d0f94b2
sha: fad4e7699bae62082118e89785324b031b0af0743064caee87c91ba28549afb0
Download Locations: