[yocto-security] [OE-core CVE] branch master-next updated. 2582668a348b6fcd1377b762ca26a05fb6d14b9d

cve-notice at lists.openembedded.org cve-notice at lists.openembedded.org
Sat Oct 5 09:57:30 PDT 2019


This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "".

The branch, master-next has been updated
  discards  88db2f65e0166ded39cdda46925488c66c750881 (commit)
       via  2582668a348b6fcd1377b762ca26a05fb6d14b9d (commit)
       via  a82f449dab48f014ba935ee842ad420fdfef004c (commit)
       via  35a85e1f7898d5703cb598d996b76b081034e950 (commit)
       via  e0f10bd78d03edd1846243d1115ba11b87cd69b0 (commit)
       via  c95c94d689f3b4972db72f511a60bcef52b8080d (commit)

This update added new revisions after undoing existing revisions.  That is
to say, the old revision is not a strict subset of the new revision.  This
situation occurs when you --force push a change and generate a repository
containing something like this:

 * -- * -- B -- O -- O -- O (88db2f65e0166ded39cdda46925488c66c750881)
            \
             N -- N -- N (2582668a348b6fcd1377b762ca26a05fb6d14b9d)

When this happens we assume that you've already had alert emails for all
of the O revisions, and so we here report only the revisions in the N
branch from the common base, B.

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
commit 2582668a348b6fcd1377b762ca26a05fb6d14b9d
Author: Khem Raj <raj.khem at gmail.com>
Date:   Sat Oct 5 09:50:52 2019 -0700

    fio: Fix build when march is armv7ve
    
    Signed-off-by: Khem Raj <raj.khem at gmail.com>

commit a82f449dab48f014ba935ee842ad420fdfef004c
Author: Khem Raj <raj.khem at gmail.com>
Date:   Sat Oct 5 08:51:05 2019 -0700

    fio: Depend on coreutils-native for fmt utility
    
    It needs fmt during build, fixes
    /bin/sh: fmt: command not found
    
    Signed-off-by: Khem Raj <raj.khem at gmail.com>

commit 35a85e1f7898d5703cb598d996b76b081034e950
Author: Denys Dmytriyenko <denys at ti.com>
Date:   Fri Sep 27 20:56:39 2019 -0400

    mariadb: update SRC_URI to use archive.mariadb.org
    
    archive.mariadb.org does not go 404 on releases over time
    
    Signed-off-by: Denys Dmytriyenko <denys at ti.com>
    Signed-off-by: Khem Raj <raj.khem at gmail.com>

commit e0f10bd78d03edd1846243d1115ba11b87cd69b0
Author: Trevor Gamblin <trevor.gamblin at windriver.com>
Date:   Fri Oct 4 22:53:53 2019 -0400

    gnome-desktop3: upgrade from 3.32.0 to 3.34.0
    
    Update to fix CVE-2019-11460 as well as add various bugfixes
    from upstream.
    
    CVE: CVE-2019-11460
    
    Signed-off-by: Trevor Gamblin <trevor.gamblin at windriver.com>
    Acked-by: Andreas Müller <schnitzeltony at gmail.com>
    Signed-off-by: Khem Raj <raj.khem at gmail.com>

commit c95c94d689f3b4972db72f511a60bcef52b8080d
Author: Khem Raj <raj.khem at gmail.com>
Date:   Sat Oct 5 08:33:45 2019 -0700

    xorg-fonts-100dpi: Change License Custom -> MIT
    
    This is a meta package which collects a bunch of 100dpi font packages
    together which all are also under MIT license, Custom is not a known
    type moreover MIT is well suited for this recipe for compatibility
    
    Signed-off-by: Khem Raj <raj.khem at gmail.com>

-----------------------------------------------------------------------

Summary of changes:
 ...01-arch-arm-Consider-armv7ve-arch-as-well.patch | 28 ++++++++++++++++++++++
 meta-oe/recipes-benchmark/fio/fio_3.16.bb          |  3 ++-
 meta-oe/recipes-dbs/mysql/mariadb.inc              |  2 +-
 .../xorg-font/xorg-fonts-100dpi.bb                 |  2 +-
 4 files changed, 32 insertions(+), 3 deletions(-)
 create mode 100644 meta-oe/recipes-benchmark/fio/files/0001-arch-arm-Consider-armv7ve-arch-as-well.patch


hooks/post-receive
-- 



More information about the yocto-security mailing list