release-notes-4.0.26.rst 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263
  1. Release notes for Yocto-4.0.26 (Kirkstone)
  2. ------------------------------------------
  3. Security Fixes in Yocto-4.0.26
  4. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  5. - bind: Fix :cve_nist:`2024-11187` and :cve_nist:`2024-12705`
  6. - binutils: Fix :cve_nist:`2025-0840`
  7. - elfutils: Fix :cve_nist:`2025-1352` and :cve_nist:`2025-1372`
  8. - ffmpeg: Fix CVE-2024-28661, :cve_nist:`2024-35369`, :cve_nist:`2024-36613`, :cve_nist:`2024-36616`,
  9. :cve_nist:`2024-36617`, :cve_nist:`2024-36618`, :cve_nist:`2025-0518` and :cve_nist:`2025-25473`
  10. - ffmpeg: Ignore :cve_nist:`2023-46407`, :cve_nist:`2023-47470`, :cve_nist:`2024-7272`,
  11. :cve_nist:`2024-22860`, :cve_nist:`2024-22861` and :cve_nist:`2024-22862`
  12. - freetype: Fix :cve_nist:`2025-27363`
  13. - gnutls: Fix :cve_nist:`2024-12243`
  14. - grub: Fix :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2024-45776`,
  15. :cve_nist:`2024-45777`, :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2024-45780`,
  16. :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-45783`, :cve_nist:`2024-56737`,
  17. :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`,
  18. :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`, :cve_nist:`2025-0678`,
  19. :cve_nist:`2025-0690`, :cve_nist:`2025-1118` and :cve_nist:`2025-1125`
  20. - gstreamer1.0-rtsp-server: fix :cve_nist:`2024-44331`
  21. - libarchive: Fix :cve_nist:`2025-25724`
  22. - libarchive: Ignore :cve_nist:`2025-1632`
  23. - libcap: Fix :cve_nist:`2025-1390`
  24. - linux-yocto/5.10: Fix :cve_nist:`2024-36476`, :cve_nist:`2024-43098`, :cve_nist:`2024-47143`,
  25. :cve_nist:`2024-48881`, :cve_nist:`2024-50051`, :cve_nist:`2024-50074`, :cve_nist:`2024-50082`,
  26. :cve_nist:`2024-50083`, :cve_nist:`2024-50099`, :cve_nist:`2024-50115`, :cve_nist:`2024-50116`,
  27. :cve_nist:`2024-50117`, :cve_nist:`2024-50142`, :cve_nist:`2024-50148`, :cve_nist:`2024-50150`,
  28. :cve_nist:`2024-50151`, :cve_nist:`2024-50167`, :cve_nist:`2024-50168`, :cve_nist:`2024-50171`,
  29. :cve_nist:`2024-50185`, :cve_nist:`2024-50192`, :cve_nist:`2024-50193`, :cve_nist:`2024-50194`,
  30. :cve_nist:`2024-50195`, :cve_nist:`2024-50198`, :cve_nist:`2024-50201`, :cve_nist:`2024-50202`,
  31. :cve_nist:`2024-50205`, :cve_nist:`2024-50208`, :cve_nist:`2024-50209`, :cve_nist:`2024-50229`,
  32. :cve_nist:`2024-50230`, :cve_nist:`2024-50233`, :cve_nist:`2024-50234`, :cve_nist:`2024-50236`,
  33. :cve_nist:`2024-50237`, :cve_nist:`2024-50251`, :cve_nist:`2024-50262`, :cve_nist:`2024-50264`,
  34. :cve_nist:`2024-50265`, :cve_nist:`2024-50267`, :cve_nist:`2024-50268`, :cve_nist:`2024-50269`,
  35. :cve_nist:`2024-50273`, :cve_nist:`2024-50278`, :cve_nist:`2024-50279`, :cve_nist:`2024-50282`,
  36. :cve_nist:`2024-50287`, :cve_nist:`2024-50292`, :cve_nist:`2024-50296`, :cve_nist:`2024-50299`,
  37. :cve_nist:`2024-50301`, :cve_nist:`2024-50302`, :cve_nist:`2024-53042`, :cve_nist:`2024-53052`,
  38. :cve_nist:`2024-53057`, :cve_nist:`2024-53059`, :cve_nist:`2024-53060`, :cve_nist:`2024-53061`,
  39. :cve_nist:`2024-53063`, :cve_nist:`2024-53066`, :cve_nist:`2024-53096`, :cve_nist:`2024-53097`,
  40. :cve_nist:`2024-53101`, :cve_nist:`2024-53103`, :cve_nist:`2024-53104`, :cve_nist:`2024-53145`,
  41. :cve_nist:`2024-53146`, :cve_nist:`2024-53150`, :cve_nist:`2024-53155`, :cve_nist:`2024-53156`,
  42. :cve_nist:`2024-53157`, :cve_nist:`2024-53161`, :cve_nist:`2024-53165`, :cve_nist:`2024-53171`,
  43. :cve_nist:`2024-53173`, :cve_nist:`2024-53174`, :cve_nist:`2024-53194`, :cve_nist:`2024-53197`,
  44. :cve_nist:`2024-53217`, :cve_nist:`2024-53226`, :cve_nist:`2024-53227`, :cve_nist:`2024-53237`,
  45. :cve_nist:`2024-53239`, :cve_nist:`2024-55916`, :cve_nist:`2024-56548`, :cve_nist:`2024-56558`,
  46. :cve_nist:`2024-56567`, :cve_nist:`2024-56568`, :cve_nist:`2024-56569`, :cve_nist:`2024-56572`,
  47. :cve_nist:`2024-56574`, :cve_nist:`2024-56581`, :cve_nist:`2024-56587`, :cve_nist:`2024-56593`,
  48. :cve_nist:`2024-56595`, :cve_nist:`2024-56596`, :cve_nist:`2024-56598`, :cve_nist:`2024-56600`,
  49. :cve_nist:`2024-56601`, :cve_nist:`2024-56602`, :cve_nist:`2024-56603`, :cve_nist:`2024-56605`,
  50. :cve_nist:`2024-56606`, :cve_nist:`2024-56615`, :cve_nist:`2024-56619`, :cve_nist:`2024-56623`,
  51. :cve_nist:`2024-56629`, :cve_nist:`2024-56634`, :cve_nist:`2024-56642`, :cve_nist:`2024-56643`,
  52. :cve_nist:`2024-56648`, :cve_nist:`2024-56650`, :cve_nist:`2024-56659`, :cve_nist:`2024-56662`,
  53. :cve_nist:`2024-56670`, :cve_nist:`2024-56688`, :cve_nist:`2024-56698`, :cve_nist:`2024-56704`,
  54. :cve_nist:`2024-56716`, :cve_nist:`2024-56720`, :cve_nist:`2024-56723`, :cve_nist:`2024-56724`,
  55. :cve_nist:`2024-56728`, :cve_nist:`2024-56739`, :cve_nist:`2024-56746`, :cve_nist:`2024-56747`,
  56. :cve_nist:`2024-56748`, :cve_nist:`2024-56754`, :cve_nist:`2024-56756`, :cve_nist:`2024-56770`,
  57. :cve_nist:`2024-56779`, :cve_nist:`2024-56780`, :cve_nist:`2024-56781`, :cve_nist:`2024-56785`,
  58. :cve_nist:`2024-57802`, :cve_nist:`2024-57807`, :cve_nist:`2024-57850`, :cve_nist:`2024-57874`,
  59. :cve_nist:`2024-57890`, :cve_nist:`2024-57896`, :cve_nist:`2024-57900`, :cve_nist:`2024-57901`,
  60. :cve_nist:`2024-57902`, :cve_nist:`2024-57910`, :cve_nist:`2024-57911`, :cve_nist:`2024-57913`,
  61. :cve_nist:`2024-57922`, :cve_nist:`2024-57938`, :cve_nist:`2024-57939`, :cve_nist:`2024-57946`,
  62. :cve_nist:`2024-57951`, :cve_nist:`2025-21638`, :cve_nist:`2025-21687`, :cve_nist:`2025-21689`,
  63. :cve_nist:`2025-21692`, :cve_nist:`2025-21694`, :cve_nist:`2025-21697` and :cve_nist:`2025-21699`
  64. - linux-yocto/5.15: Fix :cve_nist:`2024-57979`, :cve_nist:`2024-58034`, :cve_nist:`2024-58052`,
  65. :cve_nist:`2024-58055`, :cve_nist:`2024-58058`, :cve_nist:`2024-58063`, :cve_nist:`2024-58069`,
  66. :cve_nist:`2024-58071`, :cve_nist:`2024-58076`, :cve_nist:`2024-58083`, :cve_nist:`2025-21700`,
  67. :cve_nist:`2025-21703`, :cve_nist:`2025-21715`, :cve_nist:`2025-21722`, :cve_nist:`2025-21727`,
  68. :cve_nist:`2025-21731`, :cve_nist:`2025-21753`, :cve_nist:`2025-21756`, :cve_nist:`2025-21760`,
  69. :cve_nist:`2025-21761`, :cve_nist:`2025-21762`, :cve_nist:`2025-21763`, :cve_nist:`2025-21764`,
  70. :cve_nist:`2025-21796`, :cve_nist:`2025-21811`, :cve_nist:`2025-21887`, :cve_nist:`2025-21898`,
  71. :cve_nist:`2025-21904`, :cve_nist:`2025-21905`, :cve_nist:`2025-21912`, :cve_nist:`2025-21917`,
  72. :cve_nist:`2025-21919`, :cve_nist:`2025-21920`, :cve_nist:`2025-21922`, :cve_nist:`2025-21934`,
  73. :cve_nist:`2025-21943`, :cve_nist:`2025-21948` and :cve_nist:`2025-21951`
  74. - libpcre2: Ignore :cve_nist:`2022-1586`
  75. - libtasn1: Fix :cve_nist:`2024-12133`
  76. - libxml2: Fix :cve_nist:`2022-49043`, :cve_nist:`2024-56171`, :cve_nist:`2025-24928` and
  77. :cve_nist:`2025-27113`
  78. - libxslt: Fix :cve_nist:`2024-55549` and :cve_nist:`2025-24855`
  79. - llvm: Fix :cve_nist:`2024-0151`
  80. - mpg123: Fix :cve_nist:`2024-10573`
  81. - openssh: Fix :cve_nist:`2025-26465`
  82. - ovmf: Revert Fix for CVE-2023-45236 :cve_nist:`2023-45237`
  83. - perl: Ignore :cve_nist:`2023-47038`
  84. - puzzles: Ignore :cve_nist:`2024-13769`, :cve_nist:`2024-13770` and :cve_nist:`2025-0837`
  85. - python3: Fix :cve_nist:`2025-0938`
  86. - ruby: Fix :cve_nist:`2024-41946`, :cve_nist:`2025-27219` and :cve_nist:`2025-27220`
  87. - subversion: Ignore :cve_nist:`2024-45720`
  88. - systemd: Fix :cve_nist:`2022-3821`, :cve_nist:`2022-4415`, :cve_nist:`2022-45873` and
  89. :cve_nist:`2023-7008`
  90. - tiff: mark :cve_nist:`2023-30774` as patched with existing patch
  91. - u-boot: Fix :cve_nist:`2022-2347`, :cve_nist:`2022-30767`, :cve_nist:`2022-30790`,
  92. :cve_nist:`2024-57254`, :cve_nist:`2024-57255`, :cve_nist:`2024-57256`, :cve_nist:`2024-57257`,
  93. :cve_nist:`2024-57258` and :cve_nist:`2024-57259`
  94. - vim: Fix :cve_nist:`2025-1215`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`,
  95. :cve_nist:`2025-26603`, :cve_nist:`2025-27423` and :cve_nist:`2025-29768`
  96. - xserver-xorg: Fix :cve_nist:`2022-49737`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`,
  97. :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`,
  98. :cve_nist:`2025-26600` and :cve_nist:`2025-26601`
  99. - xwayland: Fix :cve_nist:`2022-49737`, :cve_nist:`2024-9632`, :cve_nist:`2024-21885`,
  100. :cve_nist:`2024-21886`, :cve_nist:`2024-31080`, :cve_nist:`2024-31081`, :cve_nist:`2024-31083`,
  101. :cve_nist:`2025-26594`, :cve_nist:`2025-26595`, :cve_nist:`2025-26596`, :cve_nist:`2025-26597`,
  102. :cve_nist:`2025-26598`, :cve_nist:`2025-26599`, :cve_nist:`2025-26600` and :cve_nist:`2025-26601`
  103. - zlib: Fix :cve_nist:`2014-9485`
  104. Fixes in Yocto-4.0.26
  105. ~~~~~~~~~~~~~~~~~~~~~
  106. - bind: Upgrade to 9.18.33
  107. - bitbake: cache: bump cache version
  108. - bitbake: siggen.py: Improve taskhash reproducibility
  109. - boost: fix do_fetch error
  110. - build-appliance-image: Update to kirkstone head revision
  111. - contributor-guide/submit-changes: add policy on AI generated code
  112. - cve-update-nvd2-native: handle missing vulnStatus
  113. - docs: Add favicon for the documentation html
  114. - docs: Remove all mention of core-image-lsb
  115. - libtasn1: upgrade to 4.20.0
  116. - libxcrypt-compat: Remove libcrypt.so to fix conflict with libcrypt
  117. - libxml2: fix compilation of explicit child axis in pattern
  118. - linux-yocto/5.10: update to v5.10.234
  119. - linux-yocto/5.15: update to v5.15.179
  120. - mesa: Fix missing GLES3 headers in SDK sysroot
  121. - mesa: Update :term:`SRC_URI`
  122. - meta: Enable '-o pipefail' for the SDK installer
  123. - migration-guides: add release notes for 4.0.25
  124. - poky.conf: add ubuntu2404 to :term:`SANITY_TESTED_DISTROS`
  125. - poky.conf: bump version for 4.0.26
  126. - procps: replaced one use of fputs(3) with a write(2) call
  127. - ref-manual: don't refer to poky-lsb
  128. - scripts/install-buildtools: Update to 4.0.24
  129. - scritps/runqemu: Ensure we only have two serial ports
  130. - systemd: upgrade to 250.14
  131. - tzcode-native: Fix compiler setting from 2023d version
  132. - tzcode: Update :term:`SRC_URI`
  133. - tzdata/tzcode-native: upgrade 2025a
  134. - vim: Upgrade to 9.1.1198
  135. - virglrenderer: fix do_fetch error
  136. - vulnerabilities/classes: remove references to cve-check text format
  137. - xz: Update :term:`SRC_URI`
  138. - yocto-uninative: Update to 4.7 for glibc 2.41
  139. Known Issues in Yocto-4.0.26
  140. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  141. - N/A
  142. Contributors to Yocto-4.0.26
  143. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  144. Thanks to the following people who contributed to this release:
  145. - Aleksandar Nikolic
  146. - Alessio Cascone
  147. - Antonin Godard
  148. - Archana Polampalli
  149. - Ashish Sharma
  150. - Bruce Ashfield
  151. - Carlos Dominguez
  152. - Deepesh Varatharajan
  153. - Divya Chellam
  154. - Guocai He
  155. - Hitendra Prajapati
  156. - Hongxu Jia
  157. - Jiaying Song
  158. - Johannes Kauffmann
  159. - Kai Kang
  160. - Lee Chee Yang
  161. - Libo Chen
  162. - Marta Rybczynska
  163. - Michael Halstead
  164. - Mingli Yu
  165. - Moritz Haase
  166. - Narpat Mali
  167. - Paulo Neves
  168. - Peter Marko
  169. - Priyal Doshi
  170. - Richard Purdie
  171. - Robert Yang
  172. - Ross Burton
  173. - Sakib Sajal
  174. - Steve Sakoman
  175. - Vijay Anusuri
  176. - Yogita Urade
  177. - Zhang Peng
  178. Repositories / Downloads for Yocto-4.0.26
  179. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  180. poky
  181. - Repository Location: :yocto_git:`/poky`
  182. - Branch: :yocto_git:`kirkstone </poky/log/?h=kirkstone>`
  183. - Tag: :yocto_git:`yocto-4.0.26 </poky/log/?h=yocto-4.0.26>`
  184. - Git Revision: :yocto_git:`d70d287a77d5026b698ac237ab865b2dafd36bb8 </poky/commit/?id=d70d287a77d5026b698ac237ab865b2dafd36bb8>`
  185. - Release Artefact: poky-d70d287a77d5026b698ac237ab865b2dafd36bb8
  186. - sha: 3ebfadb8bff4c1ca12b3cf3e4ef6e3ac2ce52b73570266daa98436c9959249f2
  187. - Download Locations:
  188. https://downloads.yoctoproject.org/releases/yocto/yocto-4.0.26/poky-d70d287a77d5026b698ac237ab865b2dafd36bb8.tar.bz2
  189. https://mirrors.kernel.org/yocto/yocto/yocto-4.0.26/poky-d70d287a77d5026b698ac237ab865b2dafd36bb8.tar.bz2
  190. openembedded-core
  191. - Repository Location: :oe_git:`/openembedded-core`
  192. - Branch: :oe_git:`kirkstone </openembedded-core/log/?h=kirkstone>`
  193. - Tag: :oe_git:`yocto-4.0.26 </openembedded-core/log/?h=yocto-4.0.26>`
  194. - Git Revision: :oe_git:`1efbe1004bc82e7c14c1e8bd4ce644f5015c3346 </openembedded-core/commit/?id=1efbe1004bc82e7c14c1e8bd4ce644f5015c3346>`
  195. - Release Artefact: oecore-1efbe1004bc82e7c14c1e8bd4ce644f5015c3346
  196. - sha: d3805e034dabd0865dbf55488b2c16d4ea0351d37aa826f0054a6bfdde5a8be9
  197. - Download Locations:
  198. https://downloads.yoctoproject.org/releases/yocto/yocto-4.0.26/oecore-1efbe1004bc82e7c14c1e8bd4ce644f5015c3346.tar.bz2
  199. https://mirrors.kernel.org/yocto/yocto/yocto-4.0.26/oecore-1efbe1004bc82e7c14c1e8bd4ce644f5015c3346.tar.bz2
  200. meta-mingw
  201. - Repository Location: :yocto_git:`/meta-mingw`
  202. - Branch: :yocto_git:`kirkstone </meta-mingw/log/?h=kirkstone>`
  203. - Tag: :yocto_git:`yocto-4.0.26 </meta-mingw/log/?h=yocto-4.0.26>`
  204. - Git Revision: :yocto_git:`87c22abb1f11be430caf4372e6b833dc7d77564e </meta-mingw/commit/?id=87c22abb1f11be430caf4372e6b833dc7d77564e>`
  205. - Release Artefact: meta-mingw-87c22abb1f11be430caf4372e6b833dc7d77564e
  206. - sha: f0bc4873e2e0319fb9d6d6ab9b98eb3f89664d4339a167d2db6a787dd12bc1a8
  207. - Download Locations:
  208. https://downloads.yoctoproject.org/releases/yocto/yocto-4.0.26/meta-mingw-87c22abb1f11be430caf4372e6b833dc7d77564e.tar.bz2
  209. https://mirrors.kernel.org/yocto/yocto/yocto-4.0.26/meta-mingw-87c22abb1f11be430caf4372e6b833dc7d77564e.tar.bz2
  210. meta-gplv2
  211. - Repository Location: :yocto_git:`/meta-gplv2`
  212. - Branch: :yocto_git:`kirkstone </meta-gplv2/log/?h=kirkstone>`
  213. - Tag: :yocto_git:`yocto-4.0.26 </meta-gplv2/log/?h=yocto-4.0.26>`
  214. - Git Revision: :yocto_git:`d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a </meta-gplv2/commit/?id=d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a>`
  215. - Release Artefact: meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a
  216. - sha: c386f59f8a672747dc3d0be1d4234b6039273d0e57933eb87caa20f56b9cca6d
  217. - Download Locations:
  218. https://downloads.yoctoproject.org/releases/yocto/yocto-4.0.26/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  219. https://mirrors.kernel.org/yocto/yocto/yocto-4.0.26/meta-gplv2-d2f8b5cdb285b72a4ed93450f6703ca27aa42e8a.tar.bz2
  220. bitbake
  221. - Repository Location: :oe_git:`/bitbake`
  222. - Branch: :oe_git:`2.0 </bitbake/log/?h=2.0>`
  223. - Tag: :oe_git:`yocto-4.0.26 </bitbake/log/?h=yocto-4.0.26>`
  224. - Git Revision: :oe_git:`046871d9fd76efdca7b72718b328d8f545523f7e </bitbake/commit/?id=046871d9fd76efdca7b72718b328d8f545523f7e>`
  225. - Release Artefact: bitbake-046871d9fd76efdca7b72718b328d8f545523f7e
  226. - sha: e9df0a9f5921b583b539188d66b23f120e1751000e7822e76c3391d5c76ee21a
  227. - Download Locations:
  228. https://downloads.yoctoproject.org/releases/yocto/yocto-4.0.26/bitbake-046871d9fd76efdca7b72718b328d8f545523f7e.tar.bz2
  229. https://mirrors.kernel.org/yocto/yocto/yocto-4.0.26/bitbake-046871d9fd76efdca7b72718b328d8f545523f7e.tar.bz2
  230. yocto-docs
  231. - Repository Location: :yocto_git:`/yocto-docs`
  232. - Branch: :yocto_git:`kirkstone </yocto-docs/log/?h=kirkstone>`
  233. - Tag: :yocto_git:`yocto-4.0.26 </yocto-docs/log/?h=yocto-4.0.26>`
  234. - Git Revision: :yocto_git:`9b4c36f7b02dd4bedfec90206744a1e90e37733c </yocto-docs/commit/?id=9b4c36f7b02dd4bedfec90206744a1e90e37733c>`