From cbea6f21d8fd96b0d7475fb3946ecaf666aec79d Mon Sep 17 00:00:00 2001 From: Peter Marko Date: Wed, 9 Apr 2025 22:21:41 +0200 Subject: [PATCH] xz: upgrade 5.6.4 -> 5.8.1 Handle CVE-2025-31115 License-Update: add help note [1] and remove note for old releases [2] [1] https://github.com/tukaani-project/xz/commit/6bbec3bda02bf87d24fa095074456e723589921f [2] https://github.com/tukaani-project/xz/commit/70f1f203789433b5d7b8b22e1655abc465d659f7 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand --- meta/recipes-extended/xz/{xz_5.6.4.bb => xz_5.8.1.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-extended/xz/{xz_5.6.4.bb => xz_5.8.1.bb} (94%) diff --git a/meta/recipes-extended/xz/xz_5.6.4.bb b/meta/recipes-extended/xz/xz_5.8.1.bb similarity index 94% rename from meta/recipes-extended/xz/xz_5.6.4.bb rename to meta/recipes-extended/xz/xz_5.8.1.bb index e48f4dbd7f..406ecbbec4 100644 --- a/meta/recipes-extended/xz/xz_5.6.4.bb +++ b/meta/recipes-extended/xz/xz_5.8.1.bb @@ -17,7 +17,7 @@ LICENSE:${PN}-dbg = "GPL-2.0-or-later" LICENSE:${PN}-locale = "GPL-2.0-or-later" LICENSE:liblzma = "0BSD" -LIC_FILES_CHKSUM = "file://COPYING;md5=c02de712b028a5cc7e22472e8f2b3db1 \ +LIC_FILES_CHKSUM = "file://COPYING;md5=d38d562f6112174de93a9677682231b2 \ file://COPYING.0BSD;md5=0672c210ce80c83444339b9aa31fee2f \ file://COPYING.GPLv2;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ file://COPYING.GPLv3;md5=1ebbd3e34237af26da5dc08a4e440464 \ @@ -28,7 +28,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=c02de712b028a5cc7e22472e8f2b3db1 \ SRC_URI = "https://github.com/tukaani-project/xz/releases/download/v${PV}/xz-${PV}.tar.gz \ file://run-ptest \ " -SRC_URI[sha256sum] = "269e3f2e512cbd3314849982014dc199a7b2148cf5c91cedc6db629acdf5e09b" +SRC_URI[sha256sum] = "507825b599356c10dca1cd720c9d0d0c9d5400b9de300af00e4d1ea150795543" UPSTREAM_CHECK_REGEX = "releases/tag/v(?P\d+(\.\d+)+)" UPSTREAM_CHECK_URI = "https://github.com/tukaani-project/xz/releases/" -- 2.47.3