Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
134 commits
Select commit Hold shift + click to select a range
2840487
app-arch/gzip: Sync with Gentoo
Aug 24, 2026
1bad6d1
app-arch/tar: Sync with Gentoo
Aug 24, 2026
3b42d85
app-arch/unzip: Sync with Gentoo
Aug 24, 2026
1230f98
app-arch/zip: Sync with Gentoo
Aug 24, 2026
53194de
app-containers/aardvark-dns: Sync with Gentoo
Aug 24, 2026
8caaebe
app-containers/containerd: Sync with Gentoo
Aug 24, 2026
e75b154
app-containers/crun: Sync with Gentoo
Aug 24, 2026
d05c007
app-containers/docker: Sync with Gentoo
Aug 24, 2026
a5d3718
app-containers/docker-buildx: Sync with Gentoo
Aug 24, 2026
498da53
app-containers/docker-cli: Sync with Gentoo
Aug 24, 2026
7f41833
app-containers/incus: Sync with Gentoo
Aug 24, 2026
29a2d04
app-containers/netavark: Sync with Gentoo
Aug 24, 2026
3f9a606
app-containers/podman: Sync with Gentoo
Aug 24, 2026
25b2021
app-containers/runc: Sync with Gentoo
Aug 24, 2026
ec8cdcb
app-crypt/gnupg: Sync with Gentoo
Aug 24, 2026
5e75420
app-crypt/gpgme: Sync with Gentoo
Aug 24, 2026
d53de36
app-emulation/qemu: Sync with Gentoo
Aug 24, 2026
f10bb74
app-emulation/qemu-guest-agent: Sync with Gentoo
Aug 24, 2026
bb759bd
app-misc/jq: Sync with Gentoo
Aug 24, 2026
0d83585
app-portage/gentoolkit: Sync with Gentoo
Aug 24, 2026
1e1047d
app-shells/bash: Sync with Gentoo
Aug 24, 2026
414e7ea
app-shells/bash-completion: Sync with Gentoo
Aug 24, 2026
c97dad5
app-text/scdoc: Sync with Gentoo
Aug 24, 2026
9aed381
dev-build/meson: Sync with Gentoo
Aug 24, 2026
e0025b4
dev-db/etcd: Sync with Gentoo
Aug 24, 2026
f4eb21e
dev-db/sqlite: Sync with Gentoo
Aug 24, 2026
6f05bc2
dev-lang/go: Sync with Gentoo
Aug 24, 2026
22b813a
dev-lang/python: Sync with Gentoo
Aug 24, 2026
af0e726
dev-lang/rust: Sync with Gentoo
Aug 24, 2026
4d79b89
dev-lang/rust-bin: Sync with Gentoo
Aug 24, 2026
3ad7665
dev-lang/rust-common: Sync with Gentoo
Aug 24, 2026
9b86f18
dev-libs/expat: Sync with Gentoo
Aug 24, 2026
8e3f9ad
dev-libs/glib: Sync with Gentoo
Aug 24, 2026
9d8d790
dev-libs/leancrypto: Sync with Gentoo
Aug 24, 2026
9b38a87
dev-libs/libevent: Sync with Gentoo
Aug 24, 2026
ef2c74d
dev-libs/libffi: Sync with Gentoo
Aug 24, 2026
fbe6d7d
dev-libs/libksba: Sync with Gentoo
Aug 24, 2026
6ef1a84
dev-libs/nspr: Sync with Gentoo
Aug 24, 2026
832efa0
dev-libs/opensc: Sync with Gentoo
Aug 24, 2026
0dfb765
dev-libs/openssl: Sync with Gentoo
Aug 24, 2026
0ad6e6f
dev-libs/tree-sitter: Sync with Gentoo
Aug 24, 2026
9e42c80
dev-python/cffi: Sync with Gentoo
Aug 24, 2026
7b3e93b
dev-python/charset-normalizer: Sync with Gentoo
Aug 24, 2026
f6fb54a
dev-python/cython: Sync with Gentoo
Aug 24, 2026
4a6e31c
dev-python/dependency-groups: Sync with Gentoo
Aug 24, 2026
b3e9177
dev-python/ensurepip-setuptools: Sync with Gentoo
Aug 24, 2026
4891a0b
dev-python/fastjsonschema: Sync with Gentoo
Aug 24, 2026
86122c1
dev-python/flit-core: Sync with Gentoo
Aug 24, 2026
ae6e7a3
dev-python/gpep517: Sync with Gentoo
Aug 24, 2026
d60027c
dev-python/hatchling: Sync with Gentoo
Aug 24, 2026
f9384b4
dev-python/idna: Sync with Gentoo
Aug 24, 2026
9e20452
dev-python/jaraco-functools: Sync with Gentoo
Aug 24, 2026
e9461f1
dev-python/jaraco-text: Sync with Gentoo
Aug 24, 2026
263b354
dev-python/lxml: Sync with Gentoo
Aug 24, 2026
05ebe79
dev-python/packaging: Sync with Gentoo
Aug 24, 2026
95c4114
dev-python/pip: Sync with Gentoo
Aug 24, 2026
7521f22
dev-python/pkg-resources: Sync with Gentoo
Aug 24, 2026
f252bf8
dev-python/platformdirs: Sync with Gentoo
Aug 24, 2026
f912d22
dev-python/pygments: Sync with Gentoo
Aug 24, 2026
8d4e12b
dev-python/setuptools: Sync with Gentoo
Aug 24, 2026
e1034d2
dev-python/setuptools-scm: Sync with Gentoo
Aug 24, 2026
1f176fa
dev-python/snakeoil: Sync with Gentoo
Aug 24, 2026
5fc0bfc
dev-python/tree-sitter: Sync with Gentoo
Aug 24, 2026
088f33b
dev-python/vcs-versioning: Sync with Gentoo
Aug 24, 2026
edebda2
dev-python/wheel: Sync with Gentoo
Aug 24, 2026
749dc75
dev-util/gdbus-codegen: Sync with Gentoo
Aug 24, 2026
937eef4
dev-util/glib-utils: Sync with Gentoo
Aug 24, 2026
945b3cd
dev-util/pahole: Sync with Gentoo
Aug 24, 2026
8c360aa
dev-util/perf: Sync with Gentoo
Aug 24, 2026
1a40bde
dev-util/pkgcheck: Sync with Gentoo
Aug 24, 2026
090d054
dev-util/pkgconf: Sync with Gentoo
Aug 24, 2026
38d08a8
eclass/acct-group: Sync with Gentoo
Aug 24, 2026
706b314
eclass/acct-user: Sync with Gentoo
Aug 24, 2026
4701afa
eclass/git-r3: Sync with Gentoo
Aug 24, 2026
f89caae
eclass/perl-module: Sync with Gentoo
Aug 24, 2026
44b9ee0
eclass/prefix: Sync with Gentoo
Aug 24, 2026
4e5f1f4
eclass/toolchain: Sync with Gentoo
Aug 24, 2026
e8f76b5
eclass/user-info: Sync with Gentoo
Aug 24, 2026
4f20282
licenses: Sync with Gentoo
Aug 24, 2026
0e8d7f0
net-analyzer/openbsd-netcat: Sync with Gentoo
Aug 24, 2026
be7761c
net-dns/bind: Sync with Gentoo
Aug 24, 2026
1486095
net-fs/samba: Sync with Gentoo
Aug 24, 2026
376be0a
net-libs/gnutls: Sync with Gentoo
Aug 24, 2026
063e055
net-libs/nghttp2: Sync with Gentoo
Aug 24, 2026
ede2d39
net-libs/ngtcp2: Sync with Gentoo
Aug 24, 2026
b2de23d
net-misc/curl: Sync with Gentoo
Aug 24, 2026
24ee869
net-misc/openssh: Sync with Gentoo
Aug 24, 2026
f035446
net-misc/passt: Sync with Gentoo
Aug 24, 2026
88176dc
net-misc/rsync: Sync with Gentoo
Aug 24, 2026
efb1288
net-nds/openldap: Sync with Gentoo
Aug 24, 2026
79c2c9d
profiles: Sync with Gentoo
Aug 24, 2026
ab963c4
sys-apps/acl: Sync with Gentoo
Aug 24, 2026
fa6e665
sys-apps/attr: Sync with Gentoo
Aug 24, 2026
e29b8a8
sys-apps/findutils: Sync with Gentoo
Aug 24, 2026
923c5d1
sys-apps/gawk: Sync with Gentoo
Aug 24, 2026
3e897d3
sys-apps/pkgcore: Sync with Gentoo
Aug 24, 2026
c308564
sys-apps/portage: Sync with Gentoo
Aug 24, 2026
5d14932
sys-apps/shadow: Sync with Gentoo
Aug 24, 2026
a2fc82c
sys-apps/util-linux: Sync with Gentoo
Aug 24, 2026
55194d3
sys-auth/pambase: Sync with Gentoo
Aug 24, 2026
e1258f5
sys-auth/sssd: Sync with Gentoo
Aug 24, 2026
a1a6238
sys-devel/binutils: Sync with Gentoo
Aug 24, 2026
04d59e9
sys-devel/gcc: Sync with Gentoo
Aug 24, 2026
aa7c9fc
sys-devel/gnuconfig: Sync with Gentoo
Aug 24, 2026
3990f2d
sys-firmware/intel-microcode: Sync with Gentoo
Aug 24, 2026
ea5e077
sys-fs/cryptsetup: Sync with Gentoo
Aug 24, 2026
8988eb0
sys-fs/zfs: Sync with Gentoo
Aug 24, 2026
c569b62
sys-fs/zfs-kmod: Sync with Gentoo
Aug 24, 2026
287c12c
sys-kernel/dracut: Sync with Gentoo
Aug 24, 2026
a34d329
sys-libs/binutils-libs: Sync with Gentoo
Aug 24, 2026
4629ab6
sys-libs/glibc: Sync with Gentoo
Aug 24, 2026
ffd4941
sys-libs/libcap-ng: Sync with Gentoo
Aug 24, 2026
4537138
sys-process/audit: Sync with Gentoo
Aug 24, 2026
f3ec936
virtual/acl: Sync with Gentoo
Aug 24, 2026
c188605
x11-drivers/nvidia-drivers: Sync with Gentoo
Aug 24, 2026
3678de6
x11-misc/makedepend: Sync with Gentoo
Aug 24, 2026
f1a9f31
eclass/xorg-meson: Add from Gentoo
krnowak Aug 25, 2026
c8aac1d
overlay profiles: Add accept keywords for binutils
krnowak Aug 25, 2026
3bd5aeb
.github: Add eclass/xorg-meson.eclass to automation
krnowak Aug 25, 2026
ec3df50
overlay coreos/user-patches: Backport a patch for dev-libs/openssl
krnowak Aug 25, 2026
fdad352
overlay coreos/user-patches: Add a patch for sys-block/open-iscsi
krnowak Aug 25, 2026
5d4d229
overlay coreos/user-patches: Add a patch for net-nds/rpcbind
krnowak Aug 25, 2026
9169224
overlay profiles: Add accept keywords to address some security issues
krnowak Aug 25, 2026
75121ce
overlay profiles: Add accept keywords for virtual/acl
krnowak Aug 25, 2026
c68f671
overlay profiles: Drop obsolete accept keywords
krnowak Aug 26, 2026
1cc00ba
overlay profiles: Temporarily mask dev-db/etcd >=3.6
krnowak Aug 26, 2026
79c25c8
net-dns/bind: Reinstate our modifications
krnowak Aug 10, 2026
40282db
dev-libs/openssl: Sync with Gentoo
krnowak Aug 28, 2026
a8f99ad
overlay profiles: Add accept keywords for dev-libs/openssl
krnowak Aug 28, 2026
6a3c604
overlay coreos/user-patches: Drop patch for dev-libs/openssl
krnowak Aug 28, 2026
f6f7dff
overlay profiles: Pick up latest 3.5 version of dev-db/etcd
krnowak Aug 28, 2026
9a8027a
overlay app-admin/etcd-wrapper: Sync version to match dev-db/etcd
krnowak Aug 28, 2026
ff95a16
overlay profiles: Keep accept keyword entries sorted
krnowak Aug 28, 2026
6384317
changelog: Add entries
krnowak Aug 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .github/workflows/portage-stable-packages-list
Original file line number Diff line number Diff line change
Expand Up @@ -516,6 +516,7 @@ eclass/wrapper.eclass
eclass/xdg-utils.eclass
eclass/xdg.eclass
eclass/xorg-3.eclass
eclass/xorg-meson.eclass

licenses

Expand Down
12 changes: 12 additions & 0 deletions changelog/security/2026-08-28-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
- expat ([CVE-2026-72522](https://www.cve.org/CVERecord?id=CVE-2026-72522))
- glib ([CVE-2026-15588](https://www.cve.org/CVERecord?id=CVE-2026-15588))
- go ([CVE-2026-33818](https://www.cve.org/CVERecord/?id=CVE-2026-33818), [CVE-2026-39821](https://www.cve.org/CVERecord/?id=CVE-2026-39821), [CVE-2026-46600](https://www.cve.org/CVERecord/?id=CVE-2026-46600), [CVE-2026-56853](https://www.cve.org/CVERecord/?id=CVE-2026-56853), [CVE-2026-56858](https://www.cve.org/CVERecord/?id=CVE-2026-56858), [CVE-2026-56859](https://www.cve.org/CVERecord/?id=CVE-2026-56859), [CVE-2026-56860](https://www.cve.org/CVERecord/?id=CVE-2026-56860), [CVE-2026-56862](https://www.cve.org/CVERecord/?id=CVE-2026-56862), [CVE-2026-56864](https://www.cve.org/CVERecord/?id=CVE-2026-56864), [CVE-2026-56865](https://www.cve.org/CVERecord/?id=CVE-2026-56865))
- incus ([CVE-2026-62867](https://www.cve.org/CVERecord?id=CVE-2026-62867), [CVE-2026-62940](https://www.cve.org/CVERecord?id=CVE-2026-62940), [CVE-2026-62941](https://www.cve.org/CVERecord?id=CVE-2026-62941), [CVE-2026-63125](https://www.cve.org/CVERecord?id=CVE-2026-63125), [CVE-2026-63343](https://www.cve.org/CVERecord?id=CVE-2026-63343), [GHSA-26gp-p5fw-3r2h](https://github.com/lxc/incus/security/advisories/GHSA-26gp-p5fw-3r2h), [GHSA-67qw-68v3-36h6](https://github.com/lxc/incus/security/advisories/GHSA-67qw-68v3-36h6), [GHSA-7fj9-65v4-rp7h](https://github.com/lxc/incus/security/advisories/GHSA-7fj9-65v4-rp7h), [GHSA-p2v3-6wvc-cv3p](https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p), [GHSA-4qxq-p5hm-3q3p](https://github.com/lxc/incus/security/advisories/GHSA-4qxq-p5hm-3q3p), [GHSA-m3j6-p3v3-qmjv](https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv), [CVE-2026-62313](https://www.cve.org/CVERecord/?id=CVE-2026-62313), [GHSA-6v6x-387m-rj4w](https://github.com/lxc/incus/security/advisories/GHSA-6v6x-387m-rj4w))
- intel-microcode ([CVE-2025-31936](https://www.cve.org/CVERecord?id=CVE-2025-31936), [CVE-2025-31938](https://www.cve.org/CVERecord?id=CVE-2025-31938), [CVE-2025-35973](https://www.cve.org/CVERecord?id=CVE-2025-35973), [CVE-2026-20707](https://www.cve.org/CVERecord?id=CVE-2026-20707), [CVE-2026-20713](https://www.cve.org/CVERecord?id=CVE-2026-20713), [CVE-2026-20716](https://www.cve.org/CVERecord?id=CVE-2026-20716), [CVE-2026-20760](https://www.cve.org/CVERecord?id=CVE-2026-20760), [CVE-2026-20917](https://www.cve.org/CVERecord?id=CVE-2026-20917))
- open-iscsi ([CVE-2026-44943](https://www.cve.org/CVERecord?id=CVE-2026-44943), [CVE-2026-44944](https://www.cve.org/CVERecord?id=CVE-2026-44944))
- openssh ([CVE-2026-73281](https://www.cve.org/CVERecord?id=CVE-2026-73281), [CVE-2026-73282](https://www.cve.org/CVERecord?id=CVE-2026-73282), [CVE-2026-73283](https://www.cve.org/CVERecord?id=CVE-2026-73283))
- openssl ([CVE-2026-14456](https://www.cve.org/CVERecord?id=CVE-2026-14456), [CVE-2026-14457](https://www.cve.org/CVERecord?id=CVE-2026-14457), [CVE-2026-18798](https://www.cve.org/CVERecord?id=CVE-2026-18798), [CVE-2026-54874](https://www.cve.org/CVERecord?id=CVE-2026-54874), [CVE-2026-63072](https://www.cve.org/CVERecord?id=CVE-2026-63072), [CVE-2026-63073](https://www.cve.org/CVERecord?id=CVE-2026-63073), [CVE-2026-63074](https://www.cve.org/CVERecord?id=CVE-2026-63074), [CVE-2026-63075](https://www.cve.org/CVERecord?id=CVE-2026-63075), [CVE-2026-63076](https://www.cve.org/CVERecord?id=CVE-2026-63076), [CVE-2026-75803](https://www.cve.org/CVERecord?id=CVE-2026-75803))
- rpcbind ([CVE-2026-16277](https://www.cve.org/CVERecord?id=CVE-2026-16277), [CVE-2026-16461](https://www.cve.org/CVERecord?id=CVE-2026-16461))
- rsync ([CVE-2026-53783](https://www.cve.org/CVERecord?id=CVE-2026-53783), [CVE-2026-53784](https://www.cve.org/CVERecord?id=CVE-2026-53784), [CVE-2026-53785](https://www.cve.org/CVERecord?id=CVE-2026-53785), [CVE-2026-53786](https://www.cve.org/CVERecord?id=CVE-2026-53786), [CVE-2026-53788](https://www.cve.org/CVERecord?id=CVE-2026-53788), [CVE-2026-53789](https://www.cve.org/CVERecord?id=CVE-2026-53789), [CVE-2026-53790](https://www.cve.org/CVERecord?id=CVE-2026-53790), [CVE-2026-53791](https://www.cve.org/CVERecord?id=CVE-2026-53791), [CVE-2026-53792](https://www.cve.org/CVERecord?id=CVE-2026-53792), [CVE-2026-53793](https://www.cve.org/CVERecord?id=CVE-2026-53793), [CVE-2026-53794](https://www.cve.org/CVERecord?id=CVE-2026-53794), [CVE-2026-53795](https://www.cve.org/CVERecord?id=CVE-2026-53795), [CVE-2026-53796](https://www.cve.org/CVERecord?id=CVE-2026-53796), [CVE-2026-53797](https://www.cve.org/CVERecord?id=CVE-2026-53797), [CVE-2026-53798](https://www.cve.org/CVERecord?id=CVE-2026-53798), [CVE-2026-53799](https://www.cve.org/CVERecord?id=CVE-2026-53799), [CVE-2026-53800](https://www.cve.org/CVERecord?id=CVE-2026-53800), [CVE-2026-53801](https://www.cve.org/CVERecord?id=CVE-2026-53801), [CVE-2026-53802](https://www.cve.org/CVERecord?id=CVE-2026-53802), [CVE-2026-53803](https://www.cve.org/CVERecord?id=CVE-2026-53803), [CVE-2026-70452](https://www.cve.org/CVERecord?id=CVE-2026-70452), [CVE-2026-70453](https://www.cve.org/CVERecord?id=CVE-2026-70453), [CVE-2026-70454](https://www.cve.org/CVERecord?id=CVE-2026-70454), [CVE-2026-70455](https://www.cve.org/CVERecord?id=CVE-2026-70455), [CVE-2026-70456](https://www.cve.org/CVERecord?id=CVE-2026-70456), [CVE-2026-70457](https://www.cve.org/CVERecord?id=CVE-2026-70457), [CVE-2026-70458](https://www.cve.org/CVERecord?id=CVE-2026-70458), [CVE-2026-70459](https://www.cve.org/CVERecord?id=CVE-2026-70459), [CVE-2026-70460](https://www.cve.org/CVERecord?id=CVE-2026-70460), [CVE-2026-70461](https://www.cve.org/CVERecord?id=CVE-2026-70461), [CVE-2026-70462](https://www.cve.org/CVERecord?id=CVE-2026-70462), [CVE-2026-70463](https://www.cve.org/CVERecord?id=CVE-2026-70463), [CVE-2026-70464](https://www.cve.org/CVERecord?id=CVE-2026-70464))
- unzip (CAN-2026-2034440, CAN-2026-2034442, CAN-2026-2034443)
- zip ([zip-20260814](https://sintonen.fi/advisories/infozip-test-option-command-injection.txt))
32 changes: 32 additions & 0 deletions changelog/updates/2026-08-28-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
- SDK: go ([1.26.7](https://go.dev/doc/devel/release#go1.26.7) (includes [1.26.6](https://go.dev/doc/devel/release#go1.26.6)))
- SDK: meson ([1.11.2](https://github.com/mesonbuild/meson/commits/1.11.2/))
- SDK: pkgcheck ([0.10.42](https://github.com/pkgcore/pkgcheck/releases/tag/v0.10.42) (includes [0.10.41](https://github.com/pkgcore/pkgcheck/releases/tag/v0.10.41)))
- SDK: rust ([1.96.1](https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/) (includes [1.96.0](https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/)))
- base, dev: bash ([5.3_p15](https://cgit.git.savannah.gnu.org/cgit/bash.git/log/?id=b460816602167718f78a6233164e8875f49b75b2))
- base, dev: bind ([9.20.26](https://bind9.readthedocs.io/en/v9.20.26/notes.html#notes-for-bind-9-20-26) (includes [9.20.25](https://bind9.readthedocs.io/en/v9.20.25/notes.html#notes-for-bind-9-20-25), [9.20.24](https://bind9.readthedocs.io/en/v9.20.24/notes.html#notes-for-bind-9-20-24)))
- base, dev: etcd ([3.5.26](https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md#v3526-2025-12-17))
- base, dev: expat ([2.8.3](https://blog.hartwork.org/posts/expat-2-8-3-released/))
- base, dev: findutils ([4.11.0](https://cgit.git.savannah.gnu.org/cgit/findutils.git/tree/NEWS?h=v4.11.0))
- base, dev: glib ([2.88.3](https://gitlab.gnome.org/GNOME/glib/-/releases/2.88.3))
- base, dev: gnupg ([2.5.21](https://dev.gnupg.org/T8262.html))
- base, dev: intel-microcode ([20260812_p20260813](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812) (includes [20260811_p20260811](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811)))
- base, dev: leancrypto ([1.8.0](https://leancrypto.org/leancrypto/releases/leancrypto-1.8.0/index.html))
- base, dev: libevent ([2.1.13](https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable))
- base, dev: openssh ([10.5_p1](https://www.openssh.org/txt/release-10.5))
- base, dev: rsync ([3.5.0](https://download.samba.org/pub/rsync/NEWS#3.5.0))
- base, dev: sqlite ([3.53.3](https://sqlite.org/releaselog/3_53_3.html))
- base, dev: unzip ([6.0_p31](https://metadata.ftp-master.debian.org/changelogs//main/u/unzip/unzip_6.0-31_changelog))
- base, dev: zip ([3.0_p16](https://metadata.ftp-master.debian.org/changelogs//main/z/zip/zip_3.0-16_changelog))
- dev: bash-completion ([2.18.0](https://cgit.git.savannah.gnu.org/cgit/bash.git/log/?id=b460816602167718f78a6233164e8875f49b75b2))
- dev: binutils ([2.46.1](https://lists.gnu.org/archive/html/info-gnu/2026-06/msg00003.html))
- dev: gentoolkit ([0.8.0](https://gitweb.gentoo.org/proj/gentoolkit.git/log/?h=gentoolkit-0.8.0))
- dev: pahole ([1.31](https://git.kernel.org/pub/scm/devel/pahole/pahole.git/tag/?h=v1.31))
- dev: portage ([3.0.81.3](https://raw.githubusercontent.com/gentoo/portage/refs/tags/portage-3.0.81.3/NEWS))
- sysext-containerd: containerd ([2.3.4](https://github.com/containerd/containerd/releases/tag/v2.3.4))
- sysext-incus: incus ([7.3](https://discuss.linuxcontainers.org/t/incus-7-3-has-been-released/27033))
- sysext-podman: gpgme ([2.1.2](https://raw.githubusercontent.com/gpg/gpgme/refs/tags/gpgme-2.1.2/NEWS))
- sysext-python: charset-normalizer ([3.4.9](https://github.com/jawah/charset_normalizer/releases/tag/3.4.9))
- sysext-python: jaraco-functools ([4.6.0](https://raw.githubusercontent.com/jaraco/jaraco.functools/refs/tags/v4.6.0/NEWS.rst))
- sysext-python: jaraco-text ([4.3.0](https://raw.githubusercontent.com/jaraco/jaraco.text/refs/tags/v4.3.0/NEWS.rst))
- sysext-python: platformdirs ([4.10.1](https://github.com/tox-dev/platformdirs/releases/tag/4.10.1))
- sysext-python: setuptools ([83.0.0](https://raw.githubusercontent.com/pypa/setuptools/refs/tags/v83.0.0/NEWS.rst))
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
From bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d Mon Sep 17 00:00:00 2001
From: Steve Dickson <steved@redhat.com>
Date: Wed, 27 May 2026 11:42:11 -0400
Subject: [PATCH] rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()

rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR strings into a fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind server overflows it when a user runs:
rpcinfo -l <host> <prognum> <versnum>

Reported-by: Michalis Vasileiadis <vmihalis.tmd@gmail.com>
Signed-off-by: Steve Dickson <steved@redhat.com>
---
src/rpcinfo.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/rpcinfo.c b/src/rpcinfo.c
index c59e8b4..30d535e 100644
--- a/src/rpcinfo.c
+++ b/src/rpcinfo.c
@@ -1104,7 +1104,7 @@ rpcbaddrlist (

re = &head->rpcb_entry_map;
printf ("%10u%3u ", parms.r_prog, parms.r_vers);
- sprintf (buf, "%s/%s/%s ",
+ snprintf (buf, sizeof(buf), "%s/%s/%s ",
re->r_nc_protofmly, re->r_nc_proto,
re->r_nc_semantics == NC_TPI_CLTS ? "clts" :
re->r_nc_semantics == NC_TPI_COTS ? "cots" : "cots_ord");
--
2.54.0

Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
From 62371b84babbc2f3546edb44d7d2b1ba62429d03 Mon Sep 17 00:00:00 2001
From: Krzesimir Nowak <knowak@microsoft.com>
Date: Tue, 25 Aug 2026 20:19:01 +0200
Subject: [PATCH] rpcinfo: stack buffer overflow in rpcinfo rpcbdump()

rpcinfo's rpcbdump() formats a server-controlled list of versions into
a fixed size buffer with sprintf(). A malicious server returning a
large number of versions may overflow it.

Reported-by: Michalis Vasileiadis <vmihalis.tmd@gmail.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
---
src/rpcinfo.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/src/rpcinfo.c b/src/rpcinfo.c
index 30d535e..9917913 100644
--- a/src/rpcinfo.c
+++ b/src/rpcinfo.c
@@ -958,17 +958,19 @@ rpcbdump (
for (rs = rs_head; rs; rs = rs->next)
{
size_t netidmax = sizeof(buf) - 1;
- char *p = buf;
+ int l = 0;

printf ("%10ld ", rs->prog);
for (vl = rs->vlist; vl; vl = vl->next)
{
- sprintf (p, "%d", vl->vers);
- p = p + strlen (p);
+ l += printf ("%d", vl->vers);
if (vl->next)
- sprintf (p++, ",");
+ l += printf (",");
}
- printf ("%-10s", buf);
+ if (l < 10)
+ printf("%*s", 10 - l, " ");
+ else
+ printf(" ");
buf[0] = '\0';

for (nl = rs->nlist; nl; nl = nl->next)
--
2.54.0

Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
The patch
`0001-rpcinfo-stack-buffer-overflow-in-rpcinfo-rpcbaddrlis.patch`
fixes CVE-2026-16277 and can be dropped when updating to rpcbind
1.2.9. The patch
`0002-rpcinfo-stack-buffer-overflow-in-rpcinfo-rpcbdump.patch` fixes
CVE-2026-16461 and, as of 2026-08-25, this hasn't been yet fixed by
upstream.
Original file line number Diff line number Diff line change
@@ -0,0 +1,209 @@
From 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e Mon Sep 17 00:00:00 2001
From: Lee Duncan <lduncan@suse.com>
Date: Tue, 14 Jul 2026 12:16:58 -0700
Subject: [PATCH] Fix security issues recently discovered by Keith at Linneman
Labs (#535)

* Fix iscsiuio control-socket credential verification.

Prevent unprivilidged user from driving the isscsiuio control socket,
by validating connection against correct file descriptor.

Reference: CVE-2026-44944
Found-by: <keith@linnemanlabs.com>

* Improve iscsid discovery handling of IQN names.

Currently, IQN names received via discovery are assumed to be valid up
to the NULL character, i.e. the end of the supplied string. But this
may not be correct.

The ASCII characters allowed in an IQN are detailed in RFC 3722, section
6.2: "Currently Prohibited ASCII Characters".

Disallowing such characters should not break current usage, since the
disallowed characters should not be in an IQN anyway. For example, they
include characters like forward slashes, backward slashes, spaces,
control characters, etc..

Open-iscsi uses target names as directory names in the "database"
directory (typically /var/lib/iscsi), so fixing this eliminates discovery
target name containing sequences like "../../../*" from being allowed.

Reference: CVE-2026-44943
Found-by: <keith@linnemanlabs.com>
---
iscsiuio/src/unix/iscsid_ipc.c | 4 ++--
usr/discovery.c | 18 ++++++++++++++++++
usr/initiator.h | 3 +++
usr/initiator_common.c | 33 +++++++++++++++++++++++++++++++++
usr/iscsiadm.c | 4 ++++
usr/iscsistart.c | 5 ++++-
6 files changed, 64 insertions(+), 3 deletions(-)

diff --git a/iscsiuio/src/unix/iscsid_ipc.c b/iscsiuio/src/unix/iscsid_ipc.c
index bcd6437c..c4740fa0 100644
--- a/iscsiuio/src/unix/iscsid_ipc.c
+++ b/iscsiuio/src/unix/iscsid_ipc.c
@@ -1120,10 +1120,10 @@ static void *iscsid_loop(void *arg)
continue;
}

- if (!mgmt_peeruser(iscsid_opts.fd, user) || strncmp(user, "root", PEERUSER_MAX)) {
+ if (!mgmt_peeruser(s2, user) || strncmp(user, "root", PEERUSER_MAX)) {
close(s2);
ILOG_ERR(PFX "Access error: non-administrative connection rejected");
- break;
+ continue;
}

/* this closes the file descriptor s2 */
diff --git a/usr/discovery.c b/usr/discovery.c
index 9936630a..da9957f5 100644
--- a/usr/discovery.c
+++ b/usr/discovery.c
@@ -137,7 +137,9 @@ int discovery_isns_query(struct discovery_rec *drec, const char *iname,
uint32_t status;
int rc;

+
isns_config.ic_security = 0;
+
source = isns_source_create_iscsi(iname);
if (!source)
return ISCSI_ERR_NOMEM;
@@ -215,6 +217,11 @@ int discovery_isns_query(struct discovery_rec *drec, const char *iname,
continue;
}

+ if (!iqn_name_valid(pg_tgt)) {
+ log_error("iSNS discovery Target Name invalid: ignoring it");
+ continue;
+ }
+
if (!isns_object_get_ipaddr(obj, ISNS_TAG_PG_PORTAL_IP_ADDR,
&in_addr)) {
log_debug(1, "Missing addr");
@@ -293,6 +300,11 @@ static int discovery_isns_reg_node(const char *iname, int op_reg)
log_debug(1, "trying to %s %s with iSNS server.",
op_reg ? "register" : "deregister", iname);

+ if (!iqn_name_valid(iname)) {
+ log_error("iSNS initiatorname invalid: ignoring it");
+ return ISCSI_ERR_INVAL;
+ }
+
source = isns_source_create_iscsi(iname);
if (!source)
return ISCSI_ERR_NOMEM;
@@ -612,6 +624,12 @@ add_target_record(char *name, char *end, discovery_rec_t *drec,
log_error("TargetName %s too long, ignoring", name);
return 0;
}
+
+ if (!iqn_name_valid(name)) {
+ log_error("Discovery TargetName invalid, ignoring");
+ return 0;
+ }
+
text = name + length;

/* skip NULs after the name */
diff --git a/usr/initiator.h b/usr/initiator.h
index 9d0264c9..daeebebe 100644
--- a/usr/initiator.h
+++ b/usr/initiator.h
@@ -21,6 +21,7 @@
#define INITIATOR_H

#include <stdint.h>
+#include <stdbool.h>
#include <net/if.h>
#include <sys/time.h>

@@ -412,4 +413,6 @@ extern int iscsi_set_net_config(struct iscsi_transport *t,
extern void iscsi_session_init_params(struct iscsi_session *session);

extern int session_in_use(int sid);
+
+extern bool iqn_name_valid(const char *name);
#endif /* INITIATOR_H */
diff --git a/usr/initiator_common.c b/usr/initiator_common.c
index 80b76522..3d580236 100644
--- a/usr/initiator_common.c
+++ b/usr/initiator_common.c
@@ -24,6 +24,7 @@
#include <stdlib.h>
#include <errno.h>
#include <dirent.h>
+#include <stdbool.h>
#include <libmount/libmount.h>

#include "iface.h"
@@ -749,3 +750,35 @@ int iscsi_host_set_net_params(struct iface_rec *iface,
}
return 0;
}
+
+/**
+ * @brief iqn_name_valid -- return whether or not the supplied
+ * IQN name valid
+ *
+ * @details Checks for invalid characters, using RFC 3722,
+ * section 6.2, "Currently Prohibited ASCII Characters"
+ *
+ * @param name the IQN name we are checking
+ * @return true iff the whole name (string) has valid
+ * charaters
+ */
+bool
+iqn_name_valid(const char *name)
+{
+ unsigned char *cp;
+
+ /* ensure no invalid characters */
+ for (cp = name; *cp != '\0'; cp++)
+ if ((*cp <= '\x2c') ||
+ (*cp == '\x2f') ||
+ ((*cp >= '\x3b') && (*cp <= '\x40')) ||
+ ((*cp >= '\x5b') && (*cp <= '\x60')) ||
+ (*cp >= '\x7b')) {
+ log_debug(8, "IQN name is invalid: \"%s\" (char: '%#02x')",
+ name, *cp);
+ return false;
+ }
+
+ log_debug(8, "IQN name has all valid characters: \"%s\"", name);
+ return true;
+}
diff --git a/usr/iscsiadm.c b/usr/iscsiadm.c
index dafce209..4881eaeb 100644
--- a/usr/iscsiadm.c
+++ b/usr/iscsiadm.c
@@ -1165,6 +1165,10 @@ exec_disc_op_on_recs(discovery_rec_t *drec, struct list_head *rec_list,
if (op & OP_NEW || op & OP_UPDATE) {
/* now add/update records */
list_for_each_entry(new_rec, rec_list, list) {
+ if (!iqn_name_valid(new_rec->name)) {
+ log_error("FW discovery Target Name invalid: ignoring it");
+ continue;
+ }
rc = idbm_add_node(new_rec, drec, op & OP_UPDATE);
if (rc)
log_error("Could not add/update "
diff --git a/usr/iscsistart.c b/usr/iscsistart.c
index df92d247..6f133d6a 100644
--- a/usr/iscsistart.c
+++ b/usr/iscsistart.c
@@ -403,7 +403,10 @@ int main(int argc, char *argv[])
case 't':
check_str_param_len(optarg, TARGET_NAME_MAXLEN,
"targetname");
- strlcpy(config_rec.name, optarg, TARGET_NAME_MAXLEN);
+ if (!iqn_name_valid(optarg))
+ log_error("iscsistart Target Name invalid: ignoring");
+ else
+ strlcpy(config_rec.name, optarg, TARGET_NAME_MAXLEN);
break;
case 'g':
config_rec.tpgt = atoi(optarg);
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
We want nodes to start automatically.
The patch `0001-open-iscsi-startup-automatic.patch` file is because we want
nodes to start automatically. See
https://github.com/flatcar/scripts/commit/8fb48ff69f29e64da3df6a197662904f60af25f5

See: https://github.com/flatcar/scripts/commit/8fb48ff69f29e64da3df6a197662904f60af25f5
The patch `0002-fix-security-issues.patch` fixes CVE-2026-44943 and
CVE-2026-44944, and can be dropped when updating to open-iscsi 2.1.12.
Loading