[yocto] [Recipe reporting system] Upgradable recipe name list

recipe-report at yoctoproject.org recipe-report at yoctoproject.org
Sun Jul 15 21:36:53 PDT 2018


This mail was sent out by Recipe reporting system.

This message list those recipes which need to be upgraded. If maintainers
believe some of them needn't to upgrade at this time, they can fill
RECIPE_NO_UPDATE_REASON in respective recipe file to ignore this remainder
until newer upstream version was detected.

Example:
RECIPE_NO_UPDATE_REASON = "Version 2.0 is unstable"

You can check the detail information at:

http://recipes.yoctoproject.org/

Package               Version          Upstream version      Maintainer           NoUpgradeReason
--------------------  ---------------  --------------------  -------------------  ------------------------------
libgloss              3.0.0            3.0.0.20180226        Alejandro Hernandez
newlib                3.0.0            3.0.0.20180226        Alejandro Hernandez
usbutils              009              010                   Alexander Kanavin
librepo               1.8.1            1.9.0                 Alexander Kanavin
gdbm                  1.14.1           1.16                  Alexander Kanavin
vala                  0.40.4           0.40.7                Alexander Kanavin
createrepo-c          0.10.0+gitX      0.11.0                Alexander Kanavin
dnf                   2.7.5            3.0.3                 Alexander Kanavin
libyaml               0.1.7            0.2.1                 Alexander Kanavin
meson                 0.46.1           0.47.1                Alexander Kanavin
ffmpeg                4.0              4.0.1                 Alexander Kanavin
icu                   61.1             62.1                  Alexander Kanavin
gptfdisk              1.0.3            1.0.4                 Alexander Kanavin
btrfs-tools           4.16.1           4.17                  Alexander Kanavin
babeltrace            1.5.5            1.5.6                 Alexander Kanavin
sysprof               3.26.1           3.28.1                Alexander Kanavin    Waiting for resolution of h...
cantarell-fonts       0.0.24           0.0.25                Alexander Kanavin
libdnf                0.11.1           0.15.2                Alexander Kanavin
epiphany              3.28.1.1         3.28.3.1              Alexander Kanavin
ca-certificates       20170717         20180409              Alexander Kanavin
busybox               1.27.2           1.29.1                Andrej Valek
apt                   1.2.24           1.6.3                 Aníbal Limón
apt-native            1.2.24           1.6.3                 Aníbal Limón
dpkg                  1.18.24          1.19.0.5              Aníbal Limón
libva-utils           2.1.0            2.2.0                 Anuj Mittal
libva                 2.1.0            2.2.0                 Anuj Mittal
gst-examples          0.0.1+gitX       0.0.1-new-commits...  Anuj Mittal
bind                  9.11.3           9.13.2                Armin Kuster
xf86-video-fbdev      0.4.4            0.5.0                 Armin Kuster
curl                  7.60.0           7.61.0                Armin Kuster
xf86-input-libinput   0.27.1           0.28.0                Armin Kuster
xserver-xorg          1.19.6           1.20.0                Armin Kuster
linux-libc-headers    4.15.7           4.17.6                Bruce Ashfield
connman               1.35             1.36                  Changhyeok Bae
iptables              1.6.2            1.8.0                 Changhyeok Bae
iputils               s20161105        s20180629             Changhyeok Bae
pciutils              3.5.6            3.6.1                 Chen Qi
acl                   2.2.52           2.2.53                Chen Qi
attr                  2.4.47           2.4.48                Chen Qi
systemd-boot          237              239                   Chen Qi
cups                  2.2.6            2.2.8                 Chen Qi
systemd               237              239                   Chen Qi
bison                 3.0.4            3.0.5                 Chen Qi
sed                   4.2.2            4.5                   Chen Qi
shadow                4.2.1            4.6                   Chen Qi
sysstat               11.7.3           11.7.4                Chen Qi
flex                  2.6.0            2.6.4                 Chen Qi
coreutils             8.29             8.30                  Chen Qi
weston                4.0.0            4.0.91                Denys Dmytriyenko
wayland               1.15.0           1.15.91               Denys Dmytriyenko
lzop                  1.03             1.04                  Denys Dmytriyenko
xz                    5.2.3            5.2.4                 Denys Dmytriyenko
python3               3.5.5            3.7.0                 Derek Straka
python3-git           2.1.10           2.1.11                Derek Straka
python3-gitdb         2.0.3            2.0.4                 Derek Straka
python3-pycairo       1.15.6           1.17.1                Derek Straka
python3-native        3.5.5            3.7.0                 Derek Straka
acpica                20180508         20180629              Fathi Boudra
gnupg                 2.2.8            2.2.9                 Hongxu Jia
elfutils              0.172            0.173                 Hongxu Jia
libgpg-error          1.31             1.32                  Hongxu Jia
llvm                  6.0              6.0-new-commits-a...  Khem Raj
mpfr                  3.1.5            4.0.1                 Khem Raj
re2c                  0.16             1.0.1                 Khem Raj
binutils              2.30             2.31                  Khem Raj
u-boot-fw-utils       2018.05          2018.07               Marek Vasut
u-boot-mkimage        2018.05          2018.07               Marek Vasut
u-boot                2018.05          2018.07               Marek Vasut
pango                 1.40.14          1.42.1                Maxin B. John
piglit                1.0+gitrX        1.0-new-commits-a...  Maxin B. John
libinput              1.11.0           1.11.2                Maxin B. John
vulkan-demos          git              git-new-commits-a...  Maxin B. John
perl                  5.24.1           5.28.0                Maxin B. John
matchbox-terminal     0.1              0.2                   Maxin B. John
puzzles               0.0+gitX         0.0-new-commits-a...  Maxin B. John
ifupdown              0.8.16           0.8.33                Maxin B. John
glib-networking       2.54.1           2.56.1                Maxin B. John
harfbuzz              1.7.5            1.8.3                 Maxin B. John
fontconfig            2.12.6           2.13.0                Maxin B. John
shared-mime-info      1.9              1.10                  Maxin B. John
vulkan                1.0.65.2         1.1.73.0              Maxin B. John
gdk-pixbuf            2.36.11          2.36.12               Maxin B. John
librsvg               2.40.20          2.42.5                Maxin B. John        Versions from 2.41.0 requir...
pkgconf               1.4.2            1.5.1                 Maxin B. John
sqlite3               3.23.1           3.24.0                Maxin B. John
freetype              2.9              2.9.1                 Maxin B. John
libical               2.0.0            3.0.3                 Maxin B. John
perl-native           5.24.1           5.28.0                Maxin B. John
binutils-cross-ca...  2.30             2.31                  No maintainer
binutils-cross-i586   2.30             2.31                  No maintainer
binutils-crosssdk...  2.30             2.31                  No maintainer
libxcrypt             4.0.1            4.1.0                 No maintainer
gcc-source-7.3.0      7.3.0            8.1.0                 No maintainer
systemtap-native      3.2              3.3                   No maintainer
nativesdk-meson       0.46.1           0.47.1                No maintainer
mesa                  18.1.3           18.1.4                Otavio Salvador
linux-firmware        0.0+gitX         0.0-new-commits-a...  Otavio Salvador
mesa-gl               18.1.3           18.1.4                Otavio Salvador
build-compare         2015.02.10+gitX  2015.02.10-new-co...  Paul Eggleton
build-appliance-i...  15.0.0           19.0.0                Richard Purdie
lttng-tools           2.9.5            2.10.4                Richard Purdie
qemu                  2.12.0           3.0.0-rc0             Richard Purdie
gnu-config            20150728+gitX    20150728-new-comm...  Robert Yang
nfs-utils             2.3.1            2.3.2                 Robert Yang
squashfs-tools        4.3+gitrX        4.3-new-commits-a...  Robert Yang
strace                4.22             4.23                  Robert Yang
e2fsprogs             1.44.2           1.44.3                Robert Yang
base-passwd           3.5.29           3.5.45                Ross Burton          Version 3.5.38 requires cde...
tcf-agent             1.4.0+gitX       1.7.0                 Ross Burton
bc                    1.06             1.07.1                Ross Burton
lsbinitscripts        9.79             10.00.0               Ross Burton
sysvinit              2.88dsf          2.90                  Ross Burton
pulseaudio            11.1             12.1                  Tanu Kaskinen
systemtap-uprobes     3.2              3.3                   Victor Kamensky
systemtap             3.2              3.3                   Victor Kamensky
chkconfig             1.3.58           1.8                   Yi Zhao              Version 1.5 requires selinux

Upgradable count: 112
Upgradable total count: 116

The based commit is:

commit 22886cf6f37d9a5c6ff90e10e0c17ed7f6321305
Author: Yi Zhao <yi.zhao at windriver.com>
Date:   Wed Jul 11 11:23:44 2018 +0800

    file: Security fix CVE-2018-10360
    
    CVE-2018-10360: The do_core_note function in readelf.c in libmagic.a in
    file 5.33 allows remote attackers to cause a denial of service
    (out-of-bounds read and application crash) via a crafted ELF file.
    
    References:
    https://nvd.nist.gov/vuln/detail/CVE-2018-10360
    
    Patch from:
    https://github.com/file/file/commit/a642587a9c9e2dd7feacdf513c3643ce26ad3c22
    
    Signed-off-by: Yi Zhao <yi.zhao at windriver.com>
    Signed-off-by: Ross Burton <ross.burton at intel.com>

Any problem, please contact Jose Lamego <jose.a.lamego at intel.com> 



More information about the yocto mailing list