poky/meta
Soumya Sambu 12f14af0bb elfutils: Fix CVE-2025-1376
A vulnerability classified as problematic was found in GNU elfutils 0.192. This
vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c
of the component eu-strip. The manipulation leads to denial of service. It is
possible to launch the attack on the local host. The complexity of an attack is
rather high. The exploitation appears to be difficult. The exploit has been
disclosed to the public and may be used. The name of the patch is
b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to
fix this issue.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-1376

Upstream patch:
https://sourceware.org/git/?p=elfutils.git;a=commit;h=b16f441cca0a4841050e3215a9f120a6d8aea918

(From OE-Core rev: 06e3cd0891f553b0ed036d9247dfa7c5ed814d78)

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-11-03 07:17:01 -08:00
..
classes cve-check: Add missing call to exit_if_errors 2025-08-22 05:59:54 -07:00
classes-global sanity.bbclass: skip check_userns for non-local uid 2025-01-09 06:25:36 -08:00
classes-recipe uboot: Allow for customizing installed/deployed file names 2025-07-07 07:42:58 -07:00
conf conf/bitbake.conf: use gnu mirror instead of main server 2025-10-13 12:42:58 -07:00
files meta: Enable '-o pipefail' for the SDK installer 2025-03-05 06:03:47 -08:00
lib oeqa/runtime/ping: don't bother trying to ping localhost 2025-10-24 06:23:40 -07:00
recipes-bsp grub2: mark CVE-2024-2312 as not applicable 2025-10-13 12:42:57 -07:00
recipes-connectivity openssh: fix CVE-2025-61984 2025-10-24 06:23:40 -07:00
recipes-core expat: patch CVE-2025-59375 2025-11-03 07:17:01 -08:00
recipes-devtools elfutils: Fix CVE-2025-1376 2025-11-03 07:17:01 -08:00
recipes-extended libpam: mark CVE-2025-6018 as not applicable 2025-11-03 07:17:01 -08:00
recipes-gnome gdk-pixbuf: fix CVE-2025-7345 2025-07-21 09:07:21 -07:00
recipes-graphics cairo: fix build with gcc-15 on host 2025-08-22 05:59:55 -07:00
recipes-kernel linux-yocto/6.6: update to v6.6.111 2025-10-24 06:23:40 -07:00
recipes-multimedia ffmpeg: ignore 8 CVEs fixed in 6.1.1 and 6.1.3 releases 2025-10-13 12:42:58 -07:00
recipes-rt rt-tests: rt_bmark.py: fix TypeError 2024-08-06 19:11:18 -07:00
recipes-sato puzzles: ignore three new CVEs for a different puzzles 2025-03-15 06:40:07 -07:00
recipes-support icu: Backport patch to fix build issues with long paths (>512 chars) 2025-10-24 06:23:40 -07:00
site
COPYING.MIT
recipes.txt