From 4b06935cb01309f874806a173a10f2fccb1eeaa7 Mon Sep 17 00:00:00 2001 From: Arnout Vandecappelle Date: Thu, 10 Sep 2026 21:36:58 +0200 Subject: [PATCH] CHANGES: Update for 2026.05.3 Signed-off-by: Arnout Vandecappelle --- CHANGES | 97 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 97 insertions(+) diff --git a/CHANGES b/CHANGES index 5edf0d2f4e..1fc1a2d40f 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,100 @@ +2026.05.3, released September 10, 2026 + + Important / security related fixes: + + avro-c: (no CVE assigned) + dnsmasq: CVE-2026-12725, CVE-2026-12969 + erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943, + CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790 + exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547, + GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp, + GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q + expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957 + glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117, CVE-2026-80489 + go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, + CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, + CVE-2026-56864, CVE-2026-56865 + haproxy: (no CVE assigned) + hostapd: CVE-2026-58374 + libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, + CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, + CVE-2026-82208, CVE-2026-82209 + libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp + libgit2: CVE-2026-5917 + libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w, + GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r, + GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57, + GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964, + GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg, + GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853, + GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8 + libldns: CVE-2026-10846 + libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, + CVE-2026-54874, CVE-2026-54876, CVE-2026-63072, CVE-2026-63073, + CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803 + libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033, + CVE-2026-66034, CVE-2026-66035 + localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117, + CVE-2026-80489 + mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252, + CVE-2026-73260, CVE-2026-73261 + nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, + CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043, + CVE-2026-58044, CVE-2026-58045 + openvpn: CVE-2026-84732 + proftpd: CVE-2026-44331 + putty: (no CVE assigned) + python-avro: (no CVE assigned) + redis: CVE-2026-62356 + rsyslog: CVE-2026-19654 + udisks: CVE-2026-7867, GHSA-j42g-v9jw-6ph3 + unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622, + CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621, + CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045, + CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251, + CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708, + CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991, + CVE-2026-56416, CVE-2026-56444 + wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471 + wireshark: CVE-2026-15163, CVE-2026-15164, CVE-2026-15166, + CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170, + CVE-2026-15171, CVE-2026-15172, CVE-2026-15174, CVE-2026-76879, + CVE-2026-76880, CVE-2026-76881, CVE-2026-76882, CVE-2026-76883, + CVE-2026-76884, CVE-2026-76885, CVE-2026-76886, CVE-2026-76887, + CVE-2026-76888, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891, + CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920, + CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76924, + CVE-2026-76926, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929 + + Toolchain: + + - linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156, + 6.12.109, 6.18.50 + - powerpc: correctly track libquadmath + + Infrastructure updates/fixes: + + - Fix setting of stack size for FLAT binaries + - Various fixes to the runtime tests + - manual: document the LTS release cadence correctly + - manual: document move of patchwork to patchwork.buildroot.org + + Updated defconfigs: qemu_xtensa_lx60* + + Updated / fixed packages: avro-c, bind, bpftrace, clamav, collectd, + dahdi-linux, dejavu, distribution-registry, dnsmasq, dpdk, dracut, + enscript, erlang, exiv2, expat, gdb, glibc, go, haproxy, hostapd, + igh-ethercat, jpeg-turbo, libbpf, libcurl, libde265, libgit2, + libheif, libldns, libnfs, libopenssl, libssh2, libxkbcommon, + libxml-parser-perl, libxml2, linux, linux-headers, linux-tools, + localedef, mesa3d, mongoose, netsnmp, newt, nodejs, olsr, opencv4, + openssh, openvpn, passt, perl, powerpc, proftpd, putty, python-avro, + python-charset-normalizer, python-gobject, qt5knx, qt6, qt6base, + qt6declarative, redis, rsyslog, taglib, toolchain-external-bootlin, + uclibc, udisks, uhttpd, unbound, vim, webkitgtk, wget, wine, + wireless-regdb, wireshark, xilinx-embeddedsw + + 2026.05.2, released August 23, 2026 Important / security related fixes: