release-notes-4.0.10.rst 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Release notes for Yocto-4.0.10 (Kirkstone)
  3. ------------------------------------------
  4. Security Fixes in Yocto-4.0.10
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. - binutils: Fix :cve_nist:`2023-1579`, :cve_nist:`2023-1972`, :cve_mitre:`2023-25584`, :cve_mitre:`2023-25585` and :cve_mitre:`2023-25588`
  7. - cargo : Ignore :cve_nist:`2022-46176`
  8. - connman: Fix :cve_nist:`2023-28488`
  9. - curl: Fix :cve_nist:`2023-27533`, :cve_nist:`2023-27534`, :cve_nist:`2023-27535`, :cve_nist:`2023-27536` and :cve_nist:`2023-27538`
  10. - ffmpeg: Fix :cve_nist:`2022-48434`
  11. - freetype: Fix :cve_nist:`2023-2004`
  12. - ghostscript: Fix :cve_mitre:`2023-29979`
  13. - git: Fix :cve_nist:`2023-25652` and :cve_nist:`2023-29007`
  14. - go: Fix :cve_nist:`2022-41722`, :cve_nist:`2022-41724`, :cve_nist:`2022-41725`, :cve_nist:`2023-24534`, :cve_nist:`2023-24537` and :cve_nist:`2023-24538`
  15. - go: Ignore :cve_nist:`2022-41716`
  16. - libxml2: Fix :cve_nist:`2023-28484` and :cve_nist:`2023-29469`
  17. - libxpm: Fix :cve_nist:`2022-44617`, :cve_nist:`2022-46285` and :cve_nist:`2022-4883`
  18. - linux-yocto: Ignore :cve_nist:`2021-3759`, :cve_nist:`2021-4135`, :cve_nist:`2021-4155`, :cve_nist:`2022-0168`, :cve_nist:`2022-0171`, :cve_nist:`2022-1016`, :cve_nist:`2022-1184`, :cve_nist:`2022-1198`, :cve_nist:`2022-1199`, :cve_nist:`2022-1462`, :cve_nist:`2022-1734`, :cve_nist:`2022-1852`, :cve_nist:`2022-1882`, :cve_nist:`2022-1998`, :cve_nist:`2022-2078`, :cve_nist:`2022-2196`, :cve_nist:`2022-2318`, :cve_nist:`2022-2380`, :cve_nist:`2022-2503`, :cve_nist:`2022-26365`, :cve_nist:`2022-2663`, :cve_nist:`2022-2873`, :cve_nist:`2022-2905`, :cve_nist:`2022-2959`, :cve_nist:`2022-3028`, :cve_nist:`2022-3078`, :cve_nist:`2022-3104`, :cve_nist:`2022-3105`, :cve_nist:`2022-3106`, :cve_nist:`2022-3107`, :cve_nist:`2022-3111`, :cve_nist:`2022-3112`, :cve_nist:`2022-3113`, :cve_nist:`2022-3115`, :cve_nist:`2022-3202`, :cve_nist:`2022-32250`, :cve_nist:`2022-32296`, :cve_nist:`2022-32981`, :cve_nist:`2022-3303`, :cve_nist:`2022-33740`, :cve_nist:`2022-33741`, :cve_nist:`2022-33742`, :cve_nist:`2022-33743`, :cve_nist:`2022-33744`, :cve_nist:`2022-33981`, :cve_nist:`2022-3424`, :cve_nist:`2022-3435`, :cve_nist:`2022-34918`, :cve_nist:`2022-3521`, :cve_nist:`2022-3545`, :cve_nist:`2022-3564`, :cve_nist:`2022-3586`, :cve_nist:`2022-3594`, :cve_nist:`2022-36123`, :cve_nist:`2022-3621`, :cve_nist:`2022-3623`, :cve_nist:`2022-3629`, :cve_nist:`2022-3633`, :cve_nist:`2022-3635`, :cve_nist:`2022-3646`, :cve_nist:`2022-3649`, :cve_nist:`2022-36879`, :cve_nist:`2022-36946`, :cve_nist:`2022-3707`, :cve_nist:`2022-39188`, :cve_nist:`2022-39190`, :cve_nist:`2022-39842`, :cve_nist:`2022-40307`, :cve_nist:`2022-40768`, :cve_nist:`2022-4095`, :cve_nist:`2022-41218`, :cve_nist:`2022-4139`, :cve_nist:`2022-41849`, :cve_nist:`2022-41850`, :cve_nist:`2022-41858`, :cve_nist:`2022-42328`, :cve_nist:`2022-42329`, :cve_nist:`2022-42703`, :cve_nist:`2022-42721`, :cve_nist:`2022-42722`, :cve_nist:`2022-42895`, :cve_nist:`2022-4382`, :cve_nist:`2022-4662`, :cve_nist:`2022-47518`, :cve_nist:`2022-47519`, :cve_nist:`2022-47520`, :cve_nist:`2022-47929`, :cve_nist:`2023-0179`, :cve_nist:`2023-0394`, :cve_nist:`2023-0461`, :cve_nist:`2023-0590`, :cve_nist:`2023-1073`, :cve_nist:`2023-1074`, :cve_nist:`2023-1077`, :cve_nist:`2023-1078`, :cve_nist:`2023-1079`, :cve_nist:`2023-1095`, :cve_nist:`2023-1118`, :cve_nist:`2023-1249`, :cve_nist:`2023-1252`, :cve_nist:`2023-1281`, :cve_nist:`2023-1382`, :cve_nist:`2023-1513`, :cve_nist:`2023-1829`, :cve_nist:`2023-1838`, :cve_nist:`2023-1998`, :cve_nist:`2023-2006`, :cve_nist:`2023-2008`, :cve_nist:`2023-2162`, :cve_nist:`2023-2166`, :cve_nist:`2023-2177`, :cve_nist:`2023-22999`, :cve_nist:`2023-23002`, :cve_nist:`2023-23004`, :cve_nist:`2023-23454`, :cve_nist:`2023-23455`, :cve_nist:`2023-23559`, :cve_nist:`2023-25012`, :cve_nist:`2023-26545`, :cve_nist:`2023-28327` and :cve_nist:`2023-28328`
  19. - nasm: Fix :cve_nist:`2022-44370`
  20. - python3-cryptography: Fix :cve_nist:`2023-23931`
  21. - qemu: Ignore :cve_nist:`2023-0664`
  22. - ruby: Fix :cve_nist:`2023-28755` and :cve_nist:`2023-28756`
  23. - screen: Fix :cve_nist:`2023-24626`
  24. - shadow: Fix :cve_nist:`2023-29383`
  25. - tiff: Fix :cve_nist:`2022-4645`
  26. - webkitgtk: Fix :cve_nist:`2022-32888` and :cve_nist:`2022-32923`
  27. - xserver-xorg: Fix :cve_nist:`2023-1393`
  28. Fixes in Yocto-4.0.10
  29. ~~~~~~~~~~~~~~~~~~~~~
  30. - bitbake: bin/utils: Ensure locale en_US.UTF-8 is available on the system
  31. - build-appliance-image: Update to kirkstone head revision
  32. - cmake: add CMAKE_SYSROOT to generated toolchain file
  33. - glibc: stable 2.35 branch updates.
  34. - kernel-devsrc: depend on python3-core instead of python3
  35. - kernel: improve initramfs bundle processing time
  36. - libarchive: Enable acls, xattr for native as well as target
  37. - libbsd: Add correct license for all packages
  38. - libpam: Fix the xtests/tst-pam_motd[1|3] failures
  39. - libxpm: upgrade to 3.5.15
  40. - linux-firmware: upgrade to 20230404
  41. - linux-yocto/5.15: upgrade to v5.15.108
  42. - migration-guides: add release-notes for 4.0.9
  43. - oeqa/utils/metadata.py: Fix running oe-selftest running with no distro set
  44. - openssl: Move microblaze to linux-latomic config
  45. - package.bbclass: correct check for /build in copydebugsources()
  46. - poky.conf: bump version for 4.0.10
  47. - populate_sdk_base: add zip options
  48. - populate_sdk_ext.bbclass: set :term:`METADATA_REVISION` with an :term:`DISTRO` override
  49. - run-postinsts: Set dependency for ldconfig to avoid boot issues
  50. - update-alternatives.bbclass: fix old override syntax
  51. - wic/bootimg-efi: if fixed-size is set then use that for mkdosfs
  52. - wpebackend-fdo: upgrade to 1.14.2
  53. - xorg-lib-common: Add variable to set tarball type
  54. - xserver-xorg: upgrade to 21.1.8
  55. Known Issues in Yocto-4.0.10
  56. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  57. - N/A
  58. Contributors to Yocto-4.0.10
  59. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  60. - Archana Polampalli
  61. - Arturo Buzarra
  62. - Bruce Ashfield
  63. - Christoph Lauer
  64. - Deepthi Hemraj
  65. - Dmitry Baryshkov
  66. - Frank de Brabander
  67. - Hitendra Prajapati
  68. - Joe Slater
  69. - Kai Kang
  70. - Kyle Russell
  71. - Lee Chee Yang
  72. - Mark Hatle
  73. - Martin Jansa
  74. - Mingli Yu
  75. - Narpat Mali
  76. - Pascal Bach
  77. - Pawan Badganchi
  78. - Peter Bergin
  79. - Peter Marko
  80. - Piotr Łobacz
  81. - Randolph Sapp
  82. - Ranjitsinh Rathod
  83. - Ross Burton
  84. - Shubham Kulkarni
  85. - Siddharth Doshi
  86. - Steve Sakoman
  87. - Sundeep KOKKONDA
  88. - Thomas Roos
  89. - Virendra Thakur
  90. - Vivek Kumbhar
  91. - Wang Mingyu
  92. - Xiangyu Chen
  93. - Yash Shinde
  94. - Yoann Congal
  95. - Yogita Urade
  96. - Zhixiong Chi
  97. Repositories / Downloads for Yocto-4.0.10
  98. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  99. poky
  100. - Repository Location: :yocto_git:`/poky`
  101. - Branch: :yocto_git:`kirkstone </poky/log/?h=kirkstone>`
  102. - Tag: :yocto_git:`yocto-4.0.10 </poky/log/?h=yocto-4.0.10>`
  103. - Git Revision: :yocto_git:`f53ab3a2ff206a130cdc843839dd0ea5ec4ad02f </poky/commit/?id=f53ab3a2ff206a130cdc843839dd0ea5ec4ad02f>`
  104. - Release Artefact: poky-f53ab3a2ff206a130cdc843839dd0ea5ec4ad02f
  105. - sha: 8820aeac857ce6bbd1c7ef26cadbb86eca02be93deded253b4a5f07ddd69255d
  106. - Download Locations:
  107. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.10/poky-f53ab3a2ff206a130cdc843839dd0ea5ec4ad02f.tar.bz2
  108. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.10/poky-f53ab3a2ff206a130cdc843839dd0ea5ec4ad02f.tar.bz2
  109. openembedded-core
  110. - Repository Location: :oe_git:`/openembedded-core`
  111. - Branch: :oe_git:`kirkstone </openembedded-core/log/?h=kirkstone>`
  112. - Tag: :oe_git:`yocto-4.0.10 </openembedded-core/log/?h=yocto-4.0.10>`
  113. - Git Revision: :oe_git:`d2713785f9cd2d58731df877bc8b7bcc71b6c8e6 </openembedded-core/commit/?id=d2713785f9cd2d58731df877bc8b7bcc71b6c8e6>`
  114. - Release Artefact: oecore-d2713785f9cd2d58731df877bc8b7bcc71b6c8e6
  115. - sha: 78e084a1aceaaa6ec022702f29f80eaffade3159e9c42b6b8985c1b7ddd2fbab
  116. - Download Locations:
  117. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.10/oecore-d2713785f9cd2d58731df877bc8b7bcc71b6c8e6.tar.bz2
  118. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.10/oecore-d2713785f9cd2d58731df877bc8b7bcc71b6c8e6.tar.bz2
  119. meta-mingw
  120. - Repository Location: :yocto_git:`/meta-mingw`
  121. - Branch: :yocto_git:`kirkstone </meta-mingw/log/?h=kirkstone>`
  122. - Tag: :yocto_git:`yocto-4.0.10 </meta-mingw/log/?h=yocto-4.0.10>`
  123. - Git Revision: :yocto_git:`a90614a6498c3345704e9611f2842eb933dc51c1 </meta-mingw/commit/?id=a90614a6498c3345704e9611f2842eb933dc51c1>`
  124. - Release Artefact: meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1
  125. - sha: 49f9900bfbbc1c68136f8115b314e95d0b7f6be75edf36a75d9bcd1cca7c6302
  126. - Download Locations:
  127. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.10/meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1.tar.bz2
  128. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.10/meta-mingw-a90614a6498c3345704e9611f2842eb933dc51c1.tar.bz2
  129. meta-gplv2
  130. - Repository Location: :yocto_git:`/meta-gplv2`
  131. - Branch: :yocto_git:`kirkstone </meta-gplv2/log/?h=kirkstone>`
  132. - Tag: :yocto_git:`yocto-4.0.10 </meta-gplv2/log/?h=yocto-4.0.10>`
  133. - Git Revision: :yocto_git:`d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a </meta-gplv2/commit/?id=d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a>`
  134. - Release Artefact: meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a
  135. - sha: c386f59f8a672747dc3d0be1d4234b6039273d0e57933eb87caa20f56b9cca6d
  136. - Download Locations:
  137. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.10/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  138. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.10/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  139. bitbake
  140. - Repository Location: :oe_git:`/bitbake`
  141. - Branch: :oe_git:`2.0 </bitbake/log/?h=2.0>`
  142. - Tag: :oe_git:`yocto-4.0.10 </bitbake/log/?h=yocto-4.0.10>`
  143. - Git Revision: :oe_git:`0c6f86b60cfba67c20733516957c0a654eb2b44c </bitbake/commit/?id=0c6f86b60cfba67c20733516957c0a654eb2b44c>`
  144. - Release Artefact: bitbake-0c6f86b60cfba67c20733516957c0a654eb2b44c
  145. - sha: 4caa94ee4d644017b0cc51b702e330191677f7d179018cbcec8b1793949ebc74
  146. - Download Locations:
  147. http://downloads.yoctoproject.org/releases/yocto/yocto-4.0.10/bitbake-0c6f86b60cfba67c20733516957c0a654eb2b44c.tar.bz2
  148. http://mirrors.kernel.org/yocto/yocto/yocto-4.0.10/bitbake-0c6f86b60cfba67c20733516957c0a654eb2b44c.tar.bz2
  149. yocto-docs
  150. - Repository Location: :yocto_git:`/yocto-docs`
  151. - Branch: :yocto_git:`kirkstone </yocto-docs/log/?h=kirkstone>`
  152. - Tag: :yocto_git:`yocto-4.0.10 </yocto-docs/log/?h=yocto-4.0.10>`
  153. - Git Revision: :yocto_git:`8388be749806bd0bf4fccf1005dae8f643aa4ef4 </yocto-docs/commit/?id=8388be749806bd0bf4fccf1005dae8f643aa4ef4>`