poky/meta/recipes-devtools
Praveen Kumar 792947d444 python3: fix CVE-2025-6075
If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment variables.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-6075

Upstream-patch:
9ab89c026a

(From OE-Core rev: 5313fa5236cd3943f90804de2af81358971894bc)

Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-12-05 07:13:42 -08:00
..
apt Revert "apt: runtime error: filename too long (tmpdir length)" 2024-07-23 06:05:47 -07:00
autoconf autoconf: 2.72d -> 2.72e 2024-01-21 12:27:12 +00:00
autoconf-archive
automake automake: mark new_rt_path_for_test-driver.patch as Inappropriate 2024-08-01 06:08:09 -07:00
binutils binutils: patch CVE-2025-11413 2025-11-07 06:54:41 -08:00
bison autoconf: Upgrade to 2.72c 2023-07-30 07:54:44 +01:00
bootchart2 recipes: Drop remaining PR values from recipes 2023-09-22 07:45:17 +01:00
btrfs-tools btrfs-tools: upgrade 6.5.3 -> 6.7.1 2024-03-07 17:25:02 +00:00
ccache ccache: upgrade 4.9 -> 4.9.1 2024-03-01 09:28:51 +00:00
cdrtools cdrtools-native: fix build with gcc-14 2024-06-20 06:29:44 -07:00
chrpath
cmake cmake: fix CVE-2025-9301 2025-10-24 06:23:40 -07:00
createrepo-c createrepo-c: upgrade 1.0.3 -> 1.0.4 2024-03-01 09:28:51 +00:00
debugedit debugedit: Use musl-legacy-error 2023-09-26 10:35:28 +01:00
dejagnu dejagnu: Fix LICENSE 2024-09-19 05:11:35 -07:00
desktop-file-utils pulseaudio, desktop-file-utils: correct freedesktop.org -> www.freedesktop.org SRC_URI 2024-10-02 06:15:15 -07:00
devel-config recipes: Drop remaining PR values from recipes 2023-09-22 07:45:17 +01:00
diffstat diffstat: upgrade 1.65 -> 1.66 2024-02-03 22:08:26 +00:00
distcc
dmidecode
dnf dnf: drop python3-iniparse from DEPENDS and RDEPENDS 2024-12-13 05:21:54 -08:00
docbook-xml
dosfstools
dpkg dpkg: patch CVE-2025-6297 2025-09-01 08:30:56 -07:00
dwarfsrcfiles
e2fsprogs e2fsprogs: Fix build failure with gcc 15 2025-08-22 05:59:55 -07:00
elfutils elfutils: Fix CVE-2025-1377 2025-11-03 07:17:01 -08:00
erofs-utils erofs-utils: upgrade 1.6 -> 1.7.1 2023-11-30 08:43:04 +00:00
expect expect: fix native build with GCC 15 2025-10-09 12:16:46 -07:00
fdisk gptfdisk: Make the version consistent 2024-01-10 17:01:28 +00:00
file file: enable additional internal compressor support 2024-02-08 10:59:06 +00:00
flex flex: fix build with gcc-15 on host 2025-11-03 07:17:01 -08:00
gcc gcc: Upgrade to GCC 13.4 2025-06-20 08:38:12 -07:00
gdb gdb: Upgrade 14.1 -> 14.2 2024-03-05 12:24:49 +00:00
git buildtools-tarball: fix unbound variable issues under 'set -u' 2025-09-22 13:17:52 -07:00
gnu-config gnu-config: Update to latest version 2024-02-06 10:32:19 +00:00
go go: fix CVE-2025-61724 2025-11-14 06:45:29 -08:00
help2man
i2c-tools
icecc-create-env recipes: Drop remaining PR values from recipes 2023-09-22 07:45:17 +01:00
icecc-toolchain
intltool
jquery jquery: upgrade 3.7.0 -> 3.7.1 2023-09-26 10:35:27 +01:00
json-c json-c: fix icecc compilation 2023-12-02 17:18:57 +00:00
libcomps libcomps: upgrade 0.1.19 -> 0.1.20 2023-10-19 13:38:57 +01:00
libdnf libdnf: upgrade 0.73.1 -> 0.73.2 2024-09-09 06:08:10 -07:00
libedit libedit: Make docs generation deterministic 2024-09-19 05:11:35 -07:00
libmodulemd
librepo librepo: update 1.16.0 -> 1.17.0 2024-03-07 17:25:02 +00:00
libtool nativesdk-libtool: sanitize the script, remove buildpaths 2025-03-26 08:48:51 -07:00
llvm llvm: fix build with gcc-15 2025-09-30 08:01:59 -07:00
log4cplus log4cplus: upgrade 2.1.0 -> 2.1.1 2023-11-30 08:43:03 +00:00
lua lua: update 5.4.4 -> 5.4.6 2023-06-27 16:23:40 +01:00
m4 m4: Stick to C17 standard 2025-09-01 08:30:56 -07:00
make
makedevs makedevs: Fix matching uid/gid 2024-10-18 06:04:41 -07:00
meson meson: don't use deprecated pkgconfig variable 2024-07-17 05:36:14 -07:00
mmc mmc-utils: fix URL 2024-07-26 07:43:46 -07:00
mtd mtd-utils: upgrade 2.1.5 -> 2.1.6 2023-09-26 10:35:27 +01:00
mtools mtools: upgrade 4.0.48 -> 4.0.49 2025-07-29 07:59:53 -07:00
nasm nasm: Upgrade 2.16.01 -> 2.16.03 2024-08-10 06:34:25 -07:00
ninja ninja: fix build with python 3.13 2024-12-06 05:50:25 -08:00
opkg opkg-arch-config: update recipe HOMEPAGE 2024-02-09 13:55:06 +00:00
opkg-utils opkg-utils: Backport fix to drop --numeric-owner parameter 2024-01-12 11:54:05 +00:00
orc orc: set CVE_PRODUCT 2025-07-29 07:59:52 -07:00
patch
patchelf patchelf: add 3 fixes to optimize and fix uninative 2023-08-01 09:51:20 +01:00
perl perl: upgrade 5.38.2 -> 5.38.4 2025-05-02 08:20:12 -07:00
perl-cross perlcross: 1.6 -> 1.6.2 2025-05-02 08:20:11 -07:00
pkgconf pkg-config-native: pick additional search paths from $EXTRA_NATIVE_PKGCONFIG_PATH 2025-02-12 06:25:37 -08:00
pkgconfig pkgconfig: fix build with gcc-15 2025-09-01 08:30:56 -07:00
pseudo pseudo: Fix envp bug and add posix_spawn wrapper 2024-11-18 06:59:35 -08:00
python python3: fix CVE-2025-6075 2025-12-05 07:13:42 -08:00
qemu qemu: patch CVE-2024-8354 2025-10-24 06:23:39 -07:00
quilt
repo repo: upgrade 2.41 -> 2.42 2024-03-07 17:25:03 +00:00
rpm rpm: keep leading `/' from sed operation 2025-09-09 09:08:09 -07:00
rsync rsync: fix CVE-2024-12747 2025-01-25 06:20:37 -08:00
ruby ruby-ptest : some ptest fixes 2025-09-01 08:30:57 -07:00
run-postinsts run-postinsts.service: Removed --no-reload to fix reload warning when users execute systemctl in the first boot. 2024-06-14 05:19:22 -07:00
rust rust-llvm: fix build with gcc-15 2025-09-01 08:30:56 -07:00
squashfs-tools
strace strace: download release tarballs from GitHub 2024-11-26 06:11:30 -08:00
subversion subversion: ignore CVE-2024-45720 2025-02-21 06:25:05 -08:00
swig swig: upgrade 4.2.0 -> 4.2.1 2024-03-01 09:28:52 +00:00
syslinux syslinux: Disable error on implicit-function-declaration 2024-02-05 14:06:10 +00:00
systemd-bootchart systemd-bootchart: upgrade from 234 to 235 2024-01-07 12:24:57 +00:00
tcf-agent tcf-agent: correct the SRC_URI 2025-07-07 07:42:58 -07:00
tcltk tcl: skip io-13.6 test case 2024-11-26 06:11:30 -08:00
unfs3
unifdef unifdef: Don't use C23 constexpr keyword 2025-09-01 08:30:56 -07:00
vala vala: fix for gtk4 prior to 4.14 2024-03-18 12:21:45 +00:00
valgrind valgrind: Backport fixes from 3.22 branch 2024-03-30 22:22:19 +00:00
xmlto recipes/classes/scripts: Drop SRCPV usage in OE-Core 2023-08-24 16:50:24 +01:00