release-notes-5.0.9.rst 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Release notes for Yocto-5.0.9 (Scarthgap)
  3. -----------------------------------------
  4. Security Fixes in Yocto-5.0.9
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. - binutils: Fix :cve_nist:`2024-57360`, :cve_nist:`2025-1176`, :cve_nist:`2025-1178` and
  7. :cve_nist:`2025-1181`
  8. - expat: Fix :cve_nist:`2024-8176`
  9. - freetype: Fix :cve_nist:`2025-27363`
  10. - ghostscript: Fix :cve_nist:`2025-27830`, :cve_nist:`2025-27831`, :cve_nist:`2025-27832`,
  11. :cve_nist:`2025-27833`, :cve_nist:`2025-27833`, :cve_nist:`2025-27834`, :cve_nist:`2025-27835`
  12. and :cve_nist:`2025-27836`
  13. - go: fix :cve_nist:`2025-22870` and :cve_nist:`2025-22871`
  14. - grub: Fix :cve_nist:`2024-45781`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`,
  15. :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2024-45778`, :cve_nist:`2024-45779`,
  16. :cve_nist:`2024-45780`, :cve_nist:`2024-45782`, :cve_nist:`2024-45783`, :cve_nist:`2024-56737`,
  17. :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`, :cve_nist:`2025-0678`,
  18. :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`,
  19. :cve_nist:`2025-0690`, :cve_nist:`2025-1118` and :cve_nist:`2025-1125`
  20. - libarchive: Fix :cve_nist:`2024-20696`, :cve_nist:`2024-48957`, :cve_nist:`2024-48958`,
  21. :cve_nist:`2025-1632` and :cve_nist:`2025-25724`
  22. - libxslt: Fix :cve_nist:`2024-24855` and :cve_nist:`2024-55549`
  23. - linux-yocto/6.6: Fix :cve_nist:`2024-54458`, :cve_nist:`2024-57834`, :cve_nist:`2024-57973`,
  24. :cve_nist:`2024-57978`, :cve_nist:`2024-57979`, :cve_nist:`2024-57980`, :cve_nist:`2024-57981`,
  25. :cve_nist:`2024-57984`, :cve_nist:`2024-57996`, :cve_nist:`2024-57997`, :cve_nist:`2024-58002`,
  26. :cve_nist:`2024-58005`, :cve_nist:`2024-58007`, :cve_nist:`2024-58010`, :cve_nist:`2024-58011`,
  27. :cve_nist:`2024-58013`, :cve_nist:`2024-58017`, :cve_nist:`2024-58020`, :cve_nist:`2024-58034`,
  28. :cve_nist:`2024-58052`, :cve_nist:`2024-58055`, :cve_nist:`2024-58058`, :cve_nist:`2024-58063`,
  29. :cve_nist:`2024-58068`, :cve_nist:`2024-58069`, :cve_nist:`2024-58070`, :cve_nist:`2024-58071`,
  30. :cve_nist:`2024-58076`, :cve_nist:`2024-58080`, :cve_nist:`2024-58083`, :cve_nist:`2024-58088`,
  31. :cve_nist:`2025-21700`, :cve_nist:`2025-21703`, :cve_nist:`2025-21707`, :cve_nist:`2025-21711`,
  32. :cve_nist:`2025-21715`, :cve_nist:`2025-21716`, :cve_nist:`2025-21718`, :cve_nist:`2025-21726`,
  33. :cve_nist:`2025-21727`, :cve_nist:`2025-21731`, :cve_nist:`2025-21735`, :cve_nist:`2025-21736`,
  34. :cve_nist:`2025-21741`, :cve_nist:`2025-21742`, :cve_nist:`2025-21743`, :cve_nist:`2025-21744`,
  35. :cve_nist:`2025-21745`, :cve_nist:`2025-21748`, :cve_nist:`2025-21749`, :cve_nist:`2025-21753`,
  36. :cve_nist:`2025-21756`, :cve_nist:`2025-21759`, :cve_nist:`2025-21760`, :cve_nist:`2025-21761`,
  37. :cve_nist:`2025-21762`, :cve_nist:`2025-21763`, :cve_nist:`2025-21764`, :cve_nist:`2025-21773`,
  38. :cve_nist:`2025-21775`, :cve_nist:`2025-21776`, :cve_nist:`2025-21779`, :cve_nist:`2025-21780`,
  39. :cve_nist:`2025-21782`, :cve_nist:`2025-21783`, :cve_nist:`2025-21785`, :cve_nist:`2025-21787`,
  40. :cve_nist:`2025-21789`, :cve_nist:`2025-21790`, :cve_nist:`2025-21791`, :cve_nist:`2025-21792`,
  41. :cve_nist:`2025-21793`, :cve_nist:`2025-21796`, :cve_nist:`2025-21811`, :cve_nist:`2025-21812`,
  42. :cve_nist:`2025-21814`, :cve_nist:`2025-21820`, :cve_nist:`2025-21844`, :cve_nist:`2025-21846`,
  43. :cve_nist:`2025-21847`, :cve_nist:`2025-21848`, :cve_nist:`2025-21853`, :cve_nist:`2025-21854`,
  44. :cve_nist:`2025-21855`, :cve_nist:`2025-21856`, :cve_nist:`2025-21857`, :cve_nist:`2025-21858`,
  45. :cve_nist:`2025-21859`, :cve_nist:`2025-21862`, :cve_nist:`2025-21863`, :cve_nist:`2025-21864`,
  46. :cve_nist:`2025-21865`, :cve_nist:`2025-21866`, :cve_nist:`2025-21867`, :cve_nist:`2025-21887`,
  47. :cve_nist:`2025-21891`, :cve_nist:`2025-21898`, :cve_nist:`2025-21904`, :cve_nist:`2025-21905`,
  48. :cve_nist:`2025-21908`, :cve_nist:`2025-21912`, :cve_nist:`2025-21915`, :cve_nist:`2025-21917`,
  49. :cve_nist:`2025-21918`, :cve_nist:`2025-21919`, :cve_nist:`2025-21920`, :cve_nist:`2025-21922`,
  50. :cve_nist:`2025-21928`, :cve_nist:`2025-21934`, :cve_nist:`2025-21936`, :cve_nist:`2025-21937`,
  51. :cve_nist:`2025-21941`, :cve_nist:`2025-21943`, :cve_nist:`2025-21945`, :cve_nist:`2025-21947`,
  52. :cve_nist:`2025-21948`, :cve_nist:`2025-21951`, :cve_nist:`2025-21957`, :cve_nist:`2025-21959`,
  53. :cve_nist:`2025-21962`, :cve_nist:`2025-21963`, :cve_nist:`2025-21964`, :cve_nist:`2025-21966`,
  54. :cve_nist:`2025-21967`, :cve_nist:`2025-21968`, :cve_nist:`2025-21969`, :cve_nist:`2025-21979`,
  55. :cve_nist:`2025-21980`, :cve_nist:`2025-21981`, :cve_nist:`2025-21991` and :cve_nist:`2025-21993`
  56. - mpg123: Fix :cve_nist:`2024-10573`
  57. - ofono: Fix :cve_nist:`2024-7537`
  58. - openssh: Fix :cve_nist:`2025-26465`
  59. - puzzles: Ignore :cve_nist:`2024-13769`, :cve_nist:`2024-13770` and :cve_nist:`2025-0837`
  60. - qemu: Ignore :cve_nist:`2023-1386`
  61. - ruby: Fix :cve_nist:`2025-27219` and :cve_nist:`2025-27220`
  62. - rust-cross-canadian: Ignore :cve_nist:`2024-43402`
  63. - vim: Fix :cve_nist:`2025-1215`, :cve_nist:`2025-26603`, :cve_nist:`2025-27423` and
  64. :cve_nist:`2025-29768`
  65. - xserver-xorg: Fix :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`,
  66. :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600`
  67. and :cve_nist:`2025-26601`
  68. - xz: Fix :cve_nist:`2025-31115`
  69. Fixes in Yocto-5.0.9
  70. ~~~~~~~~~~~~~~~~~~~~
  71. - babeltrace2: extend to nativesdk
  72. - babeltrace: extend to nativesdk
  73. - bitbake: event/utils: Avoid deadlock from lock_timeout() and recursive events
  74. - bitbake: utils: Add signal blocking for lock_timeout
  75. - bitbake: utils: Print information about lock issue before exiting
  76. - bitbake: utils: Tweak lock_timeout logic
  77. - build-appliance-image: Update to scarthgap head revision
  78. - cve-check.bbclass: Mitigate symlink related error
  79. - cve-update-nvd2-native: add workaround for json5 style list
  80. - cve-update-nvd2-native: handle missing vulnStatus
  81. - gcc: remove paths to sysroot from configargs.h and checksum-options for gcc-cross-canadian
  82. - gcc: unify cleanup of include-fixed, apply to cross-canadian
  83. - ghostscript: upgrade to 10.05.0
  84. - grub: backport strlcpy function
  85. - grub: drop obsolete CVE statuses
  86. - icu: Adjust ICU_DATA_DIR path on big endian targets
  87. - kernel-arch: add macro-prefix-map in KERNEL_CC
  88. - libarchive: upgrade to 3.7.9
  89. - libxslt: upgrade to 1.1.43
  90. - linux-yocto/6.6: update to v6.6.84
  91. - mc: set ac_cv_path_ZIP to avoid buildpaths QA issues
  92. - mpg123: upgrade to 1.32.10
  93. - nativesdk-libtool: sanitize the script, remove buildpaths
  94. - openssl: rewrite ptest installation
  95. - overview-manual/concepts: remove :term:`PR` from the build dir list
  96. - patch.py: set commituser and commitemail for addNote
  97. - poky.conf: bump version for 5.0.9
  98. - vim: Upgrade to 9.1.1198
  99. - xserver-xf86-config: add a configuration fragment to disable screen blanking
  100. - xserver-xf86-config: remove obsolete configuration files
  101. - xserver-xorg: upgrade to 21.1.16
  102. - xz: upgrade to 5.4.7
  103. - yocto-uninative: Update to 4.7 for glibc 2.41
  104. Known Issues in Yocto-5.0.9
  105. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  106. - N/A
  107. Contributors to Yocto-5.0.9
  108. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  109. Thanks to the following people who contributed to this release:
  110. - Antonin Godard
  111. - Archana Polampalli
  112. - Ashish Sharma
  113. - Bruce Ashfield
  114. - Changqing Li
  115. - Denys Dmytriyenko
  116. - Divya Chellam
  117. - Hitendra Prajapati
  118. - Madhu Marri
  119. - Makarios Christakis
  120. - Martin Jansa
  121. - Michael Halstead
  122. - Niko Mauno
  123. - Oleksandr Hnatiuk
  124. - Peter Marko
  125. - Richard Purdie
  126. - Ross Burton
  127. - Sana Kazi
  128. - Stefan Mueller-Klieser
  129. - Steve Sakoman
  130. - Vijay Anusuri
  131. - Virendra Thakur
  132. - Vishwas Udupa
  133. - Wang Mingyu
  134. - Zhang Peng
  135. Repositories / Downloads for Yocto-5.0.9
  136. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  137. poky
  138. - Repository Location: :yocto_git:`/poky`
  139. - Branch: :yocto_git:`scarthgap </poky/log/?h=scarthgap>`
  140. - Tag: :yocto_git:`yocto-5.0.9 </poky/log/?h=yocto-5.0.9>`
  141. - Git Revision: :yocto_git:`bab0f9f62af9af580744948dd3240f648a99879a </poky/commit/?id=bab0f9f62af9af580744948dd3240f648a99879a>`
  142. - Release Artefact: poky-bab0f9f62af9af580744948dd3240f648a99879a
  143. - sha: ee6811d9fb6c4913e19d6e3569f1edc8ccd793779b237520596506446a6b4531
  144. - Download Locations:
  145. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.9/poky-bab0f9f62af9af580744948dd3240f648a99879a.tar.bz2
  146. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.9/poky-bab0f9f62af9af580744948dd3240f648a99879a.tar.bz2
  147. openembedded-core
  148. - Repository Location: :oe_git:`/openembedded-core`
  149. - Branch: :oe_git:`scarthgap </openembedded-core/log/?h=scarthgap>`
  150. - Tag: :oe_git:`yocto-5.0.9 </openembedded-core/log/?h=yocto-5.0.9>`
  151. - Git Revision: :oe_git:`04038ecd1edd6592b826665a2b787387bb7074fa </openembedded-core/commit/?id=04038ecd1edd6592b826665a2b787387bb7074fa>`
  152. - Release Artefact: oecore-04038ecd1edd6592b826665a2b787387bb7074fa
  153. - sha: 6e201a4b486dfbdfcb7e96d83b962a205ec4764db6ad0e34bd623db18910eddb
  154. - Download Locations:
  155. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.9/oecore-04038ecd1edd6592b826665a2b787387bb7074fa.tar.bz2
  156. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.9/oecore-04038ecd1edd6592b826665a2b787387bb7074fa.tar.bz2
  157. meta-mingw
  158. - Repository Location: :yocto_git:`/meta-mingw`
  159. - Branch: :yocto_git:`scarthgap </meta-mingw/log/?h=scarthgap>`
  160. - Tag: :yocto_git:`yocto-5.0.9 </meta-mingw/log/?h=yocto-5.0.9>`
  161. - Git Revision: :yocto_git:`bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f </meta-mingw/commit/?id=bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f>`
  162. - Release Artefact: meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f
  163. - sha: ab073def6487f237ac125d239b3739bf02415270959546b6b287778664f0ae65
  164. - Download Locations:
  165. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.9/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
  166. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.9/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
  167. bitbake
  168. - Repository Location: :oe_git:`/bitbake`
  169. - Branch: :oe_git:`2.8 </bitbake/log/?h=2.8>`
  170. - Tag: :oe_git:`yocto-5.0.9 </bitbake/log/?h=yocto-5.0.9>`
  171. - Git Revision: :oe_git:`696c2c1ef095f8b11c7d2eff36fae50f58c62e5e </bitbake/commit/?id=696c2c1ef095f8b11c7d2eff36fae50f58c62e5e>`
  172. - Release Artefact: bitbake-696c2c1ef095f8b11c7d2eff36fae50f58c62e5e
  173. - sha: fc83f879cd6dd14b9b7eba0161fec23ecc191fed0fb00556ba729dceef6c145f
  174. - Download Locations:
  175. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.9/bitbake-696c2c1ef095f8b11c7d2eff36fae50f58c62e5e.tar.bz2
  176. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.9/bitbake-696c2c1ef095f8b11c7d2eff36fae50f58c62e5e.tar.bz2
  177. yocto-docs
  178. - Repository Location: :yocto_git:`/yocto-docs`
  179. - Branch: :yocto_git:`scarthgap </yocto-docs/log/?h=scarthgap>`
  180. - Tag: :yocto_git:`yocto-5.0.9 </yocto-docs/log/?h=yocto-5.0.9>`
  181. - Git Revision: :yocto_git:`56db4fd81f6235428bef9e46a61c11ca0ba89733 </yocto-docs/commit/?id=56db4fd81f6235428bef9e46a61c11ca0ba89733>`