release-notes-5.0.8.rst 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Release notes for Yocto-5.0.8 (Scarthgap)
  3. -----------------------------------------
  4. Security Fixes in Yocto-5.0.8
  5. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  6. - binutils: Fix :cve_nist:`2025-0840`
  7. - curl: Ignore :cve_nist:`2025-0725`
  8. - elfutils: Fix :cve_nist:`2025-1352`, :cve_nist:`2025-1365` and :cve_nist:`2025-1372`
  9. - ffmpeg: Fix :cve_nist:`2024-35365`, :cve_nist:`2024-35369`, :cve_nist:`2024-36613`,
  10. :cve_nist:`2024-36616`, :cve_nist:`2024-36617`, :cve_nist:`2024-36618`, :cve_nist:`2024-36619`,
  11. :cve_nist:`2025-0518`, :cve_nist:`2025-22919`, :cve_nist:`2025-22921` and :cve_nist:`2025-25473`
  12. - glibc: Fix :cve_nist:`2025-0395`
  13. - gnutls: Fix :cve_nist:`2024-12243`
  14. - go: Fix :cve_nist:`2024-45336`, :cve_nist:`2024-45341` and :cve_nist:`2025-22866`
  15. - gstreamer1.0-rtsp-server: Fix :cve_nist:`2024-44331`
  16. - libcap: Fix :cve_nist:`2025-1390`
  17. - libtasn1: Fix :cve_nist:`2024-12133`
  18. - libxml2: Fix :cve_nist:`2024-56171` and :cve_nist:`2025-24928`
  19. - linux-yocto/6.6: Fix :cve_nist:`2024-36476`, :cve_nist:`2024-53179`, :cve_nist:`2024-56582`,
  20. :cve_nist:`2024-56703`, :cve_nist:`2024-57801`, :cve_nist:`2024-57802`, :cve_nist:`2024-57841`,
  21. :cve_nist:`2024-57882`, :cve_nist:`2024-57887`, :cve_nist:`2024-57890`, :cve_nist:`2024-57892`,
  22. :cve_nist:`2024-57895`, :cve_nist:`2024-57896`, :cve_nist:`2024-57900`, :cve_nist:`2024-57901`,
  23. :cve_nist:`2024-57902`, :cve_nist:`2024-57906`, :cve_nist:`2024-57907`, :cve_nist:`2024-57908`,
  24. :cve_nist:`2024-57910`, :cve_nist:`2024-57911`, :cve_nist:`2024-57912`, :cve_nist:`2024-57913`,
  25. :cve_nist:`2024-57916`, :cve_nist:`2024-57922`, :cve_nist:`2024-57925`, :cve_nist:`2024-57926`,
  26. :cve_nist:`2024-57933`, :cve_nist:`2024-57938`, :cve_nist:`2024-57939`, :cve_nist:`2024-57940`,
  27. :cve_nist:`2024-57949`, :cve_nist:`2024-57951`, :cve_nist:`2025-21631`, :cve_nist:`2025-21636`,
  28. :cve_nist:`2025-21637`, :cve_nist:`2025-21638`, :cve_nist:`2025-21639`, :cve_nist:`2025-21640`,
  29. :cve_nist:`2025-21642`, :cve_nist:`2025-21652`, :cve_nist:`2025-21658`, :cve_nist:`2025-21665`,
  30. :cve_nist:`2025-21666`, :cve_nist:`2025-21667`, :cve_nist:`2025-21669`, :cve_nist:`2025-21670`,
  31. :cve_nist:`2025-21671`, :cve_nist:`2025-21673`, :cve_nist:`2025-21674`, :cve_nist:`2025-21675`,
  32. :cve_nist:`2025-21676`, :cve_nist:`2025-21680`, :cve_nist:`2025-21681`, :cve_nist:`2025-21683`,
  33. :cve_nist:`2025-21684`, :cve_nist:`2025-21687`, :cve_nist:`2025-21689`, :cve_nist:`2025-21690`,
  34. :cve_nist:`2025-21692`, :cve_nist:`2025-21694`, :cve_nist:`2025-21697` and :cve_nist:`2025-21699`
  35. - openssh: Fix :cve_nist:`2025-26466`
  36. - openssl: Fix :cve_nist:`2024-9143`, :cve_nist:`2024-12797` and :cve_nist:`2024-13176`
  37. - pyhton3: Fix :cve_nist:`2024-12254` and :cve_nist:`2025-0938`
  38. - subversion: Ignore :cve_nist:`2024-45720`
  39. - u-boot: Fix :cve_nist:`2024-57254`, :cve_nist:`2024-57255`, :cve_nist:`2024-57256`,
  40. :cve_nist:`2024-57257`, :cve_nist:`2024-57258` and :cve_nist:`2024-57259`
  41. - vim: Fix :cve_nist:`2025-22134` and :cve_nist:`2025-24014`
  42. - xwayland: Fix :cve_nist:`2024-9632`, :cve_nist:`2025-26594`, :cve_nist:`2025-26595`,
  43. :cve_nist:`2025-26596`, :cve_nist:`2025-26597`, :cve_nist:`2025-26598`, :cve_nist:`2025-26599`,
  44. :cve_nist:`2025-26600` and :cve_nist:`2025-26601`
  45. Fixes in Yocto-5.0.8
  46. ~~~~~~~~~~~~~~~~~~~~
  47. - base-files: Drop /bin/sh dependency
  48. - bind: upgrade to 9.18.33
  49. - binutils: File name too long causing failure to open temporary head file in dlltool
  50. - binutils: stable 2.42 branch update
  51. - bitbake: bblayers/query: Fix using "removeprefix" string method
  52. - bitbake: bitbake-diffsigs: fix handling when finding only a single sigfile
  53. - bitbake: data_smart.py: clear expand_cache in _setvar_update_overridevars
  54. - bitbake: data_smart.py: remove unnecessary ? from __expand_var_regexp__
  55. - bitbake: data_smart.py: simple clean up
  56. - build-appliance-image: Update to scarthgap head revision
  57. - ccache.conf: Add include_file_ctime to sloppiness
  58. - cmake: apply parallel build settings to ptest tasks
  59. - contributor-guide/submit-changes: add policy on AI generated code
  60. - dev-manual/building: document the initramfs-framework recipe
  61. - devtool: ide-sdk recommend :term:`DEBUG_BUILD`
  62. - devtool: ide-sdk remove the plugin from eSDK installer
  63. - devtool: ide-sdk sort cmake preset
  64. - devtool: modify support debug-builds
  65. - docs: Add favicon for the documentation html
  66. - docs: Fix typo in standards.md
  67. - docs: Remove all mention of core-image-lsb
  68. - docs: vulnerabilities/classes: remove references to cve-check text format
  69. - files: Amend overlayfs unit descriptions with path information
  70. - files: overlayfs-create-dirs: Improve mount unit dependency
  71. - glibc: stable 2.39 branch updates
  72. - gnupg: upgrade to 2.4.5
  73. - go: upgrade 1.22.12
  74. - icu: remove host references in nativesdk to fix reproducibility
  75. - libtasn1: upgrade to 4.20.0
  76. - libxml2: upgrade to 2.12.10
  77. - linux-yocto/6.6: upgrade to v6.6.75
  78. - meta: Enable '-o pipefail' for the SDK installer
  79. - migration-guides: add release notes for 4.0.24, 4.0.25 and 5.0.7
  80. - oe-selftest: devtool ide-sdk use modify debug-build
  81. - oeqa/sdk/context: fix for gtk3 test failure during do_testsdk
  82. - oeqa/selftest/rust: skip on all MIPS platforms
  83. - openssl: upgrade to 3.2.4
  84. - pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH
  85. - poky.conf: add ubuntu2404 to :term:`SANITY_TESTED_DISTROS`
  86. - poky.conf: bump version for 5.0.8
  87. - ppp: Revert lock path to /var/lock
  88. - python3-setuptools-scm: respect GIT_CEILING_DIRECTORIES
  89. - python3: upgrade to 3.12.9
  90. - qemu: Do not define sched_attr with glibc >= 2.41
  91. - ref-manual/faq: add q&a on systemd as default
  92. - ref-manual: Add missing variable :term:`IMAGE_ROOTFS_MAXSIZE`
  93. - ref-manual: don't refer to poky-lsb
  94. - ref-manual: remove OE_IMPORTS
  95. - rust-common.bbclass: soft assignment for RUSTLIB path
  96. - rust: fix for rust multilib sdk configuration
  97. - rust: remove redundant cargo config file
  98. - scripts/install-buildtools: Update to 5.0.7
  99. - sdk-manual: extensible.rst: devtool ide-sdk improve
  100. - sdk-manual: extensible.rst: update devtool ide-sdk
  101. - selftest/rust: correctly form the PATH environment variable
  102. - systemd: add libpcre2 as :term:`RRECOMMENDS` if pcre2 is enabled
  103. - systemd: upgrade to 255.17
  104. - test-manual/ptest: link to common framework ptest classes
  105. - tzcode-native: Fix compiler setting from 2023d version
  106. - tzdata/tzcode-native: upgrade to 2025a
  107. - u-boot: kernel-fitimage: Fix dependency loop if :term:`UBOOT_SIGN_ENABLE` and UBOOT_ENV enabled
  108. - u-boot: kernel-fitimage: Restore FIT_SIGN_INDIVIDUAL="1" behavior
  109. - uboot-config: fix devtool modify with kernel-fitimage
  110. - vim: upgrade to 9.1.1043
  111. Known Issues in Yocto-5.0.8
  112. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  113. - N/A
  114. Contributors to Yocto-5.0.8
  115. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  116. Thanks to the following people who contributed to this release:
  117. - Adrian Freihofer
  118. - Aleksandar Nikolic
  119. - Alessio Cascone
  120. - Alexander Kanavin
  121. - Alexis Cellier
  122. - Antonin Godard
  123. - Archana Polampalli
  124. - Bruce Ashfield
  125. - Chen Qi
  126. - Deepesh Varatharajan
  127. - Divya Chellam
  128. - Enrico Jörns
  129. - Esben Haabendal
  130. - Etienne Cordonnier
  131. - Fabio Berton
  132. - Guðni Már Gilbert
  133. - Harish Sadineni
  134. - Hitendra Prajapati
  135. - Hongxu Jia
  136. - Jiaying Song
  137. - Joerg Schmidt
  138. - Johannes Schneider
  139. - Khem Raj
  140. - Lee Chee Yang
  141. - Marek Vasut
  142. - Marta Rybczynska
  143. - Moritz Haase
  144. - Oleksandr Hnatiuk
  145. - Pedro Ferreira
  146. - Peter Marko
  147. - Poonam Jadhav
  148. - Priyal Doshi
  149. - Ross Burton
  150. - Simon A. Eugster
  151. - Steve Sakoman
  152. - Vijay Anusuri
  153. - Wang Mingyu
  154. - Weisser, Pascal
  155. Repositories / Downloads for Yocto-5.0.8
  156. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  157. poky
  158. - Repository Location: :yocto_git:`/poky`
  159. - Branch: :yocto_git:`scarthgap </poky/log/?h=scarthgap>`
  160. - Tag: :yocto_git:`yocto-5.0.8 </poky/log/?h=yocto-5.0.8>`
  161. - Git Revision: :yocto_git:`dc4827b3660bc1a03a2bc3b0672615b50e9137ff </poky/commit/?id=dc4827b3660bc1a03a2bc3b0672615b50e9137ff>`
  162. - Release Artefact: poky-dc4827b3660bc1a03a2bc3b0672615b50e9137ff
  163. - sha: ace7264e16e18ed02ef0ad2935fa10b5fad2c4de38b2356f4192b38ef2184504
  164. - Download Locations:
  165. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.8/poky-dc4827b3660bc1a03a2bc3b0672615b50e9137ff.tar.bz2
  166. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.8/poky-dc4827b3660bc1a03a2bc3b0672615b50e9137ff.tar.bz2
  167. openembedded-core
  168. - Repository Location: :oe_git:`/openembedded-core`
  169. - Branch: :oe_git:`scarthgap </openembedded-core/log/?h=scarthgap>`
  170. - Tag: :oe_git:`yocto-5.0.8 </openembedded-core/log/?h=yocto-5.0.8>`
  171. - Git Revision: :oe_git:`cd2b6080a4c0f2ed2c9939ec0b87763aef595048 </openembedded-core/commit/?id=cd2b6080a4c0f2ed2c9939ec0b87763aef595048>`
  172. - Release Artefact: oecore-cd2b6080a4c0f2ed2c9939ec0b87763aef595048
  173. - sha: 14c7cd5c62a96ceb9c2141164ea0f087fdbaed99ca3e9a722977a3f12d6381f6
  174. - Download Locations:
  175. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.8/oecore-cd2b6080a4c0f2ed2c9939ec0b87763aef595048.tar.bz2
  176. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.8/oecore-cd2b6080a4c0f2ed2c9939ec0b87763aef595048.tar.bz2
  177. meta-mingw
  178. - Repository Location: :yocto_git:`/meta-mingw`
  179. - Branch: :yocto_git:`scarthgap </meta-mingw/log/?h=scarthgap>`
  180. - Tag: :yocto_git:`yocto-5.0.8 </meta-mingw/log/?h=yocto-5.0.8>`
  181. - Git Revision: :yocto_git:`bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f </meta-mingw/commit/?id=bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f>`
  182. - Release Artefact: meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f
  183. - sha: ab073def6487f237ac125d239b3739bf02415270959546b6b287778664f0ae65
  184. - Download Locations:
  185. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.8/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
  186. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.8/meta-mingw-bd9fef71ec005be3c3a6d7f8b99d8116daf70c4f.tar.bz2
  187. bitbake
  188. - Repository Location: :oe_git:`/bitbake`
  189. - Branch: :oe_git:`2.8 </bitbake/log/?h=2.8>`
  190. - Tag: :oe_git:`yocto-5.0.8 </bitbake/log/?h=yocto-5.0.8>`
  191. - Git Revision: :oe_git:`7375d32e8c1af20c51abec4eb3b072b4ca58b239 </bitbake/commit/?id=7375d32e8c1af20c51abec4eb3b072b4ca58b239>`
  192. - Release Artefact: bitbake-7375d32e8c1af20c51abec4eb3b072b4ca58b239
  193. - sha: 13dffbc162c5b6e2c95fa72936a430b9a542d52d81d502a5d0afc592fbf4a16b
  194. - Download Locations:
  195. https://downloads.yoctoproject.org/releases/yocto/yocto-5.0.8/bitbake-7375d32e8c1af20c51abec4eb3b072b4ca58b239.tar.bz2
  196. https://mirrors.kernel.org/yocto/yocto/yocto-5.0.8/bitbake-7375d32e8c1af20c51abec4eb3b072b4ca58b239.tar.bz2
  197. yocto-docs
  198. - Repository Location: :yocto_git:`/yocto-docs`
  199. - Branch: :yocto_git:`scarthgap </yocto-docs/log/?h=scarthgap>`
  200. - Tag: :yocto_git:`yocto-5.0.8 </yocto-docs/log/?h=yocto-5.0.8>`
  201. - Git Revision: :yocto_git:`7d3cce5b962ca9f73b29affceb7ebc6710627739 </yocto-docs/commit/?id=7d3cce5b962ca9f73b29affceb7ebc6710627739>`