systemd's README ("STABLE BRANCHES AND BACKPORTS") documents per-release
stable branches carrying backported patches. The current one, v261-stable,
is branched in the main repository; the README still points at the
systemd-stable repository, which holds the branches up to v255. The major
is a single version part (261 -> 261.1), so upgrades within a major
are stable point upgrades per the OE-Core stable release policy
(ref-manual, "Stable Point Release Upgrades"). STABLE_VERSION_PARTS is
set to 1 accordingly.
https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades
https://github.com/systemd/systemd/blob/v261.1/README#L460
https://github.com/systemd/systemd/tree/v261-stable
Checked the last point release for feature creep:
261.2 (Jul 23 2026), against 261.1 (Jun 26 2026): 277 commits, mostly
fixes. NEWS files both releases under "CHANGES WITH 261" and gives
neither its own entry. Four items are feature-shaped: refcounting,
argument handling and JSON output additions, plus one new internal
string-util flag.
Those are small internal additions on a real, diverged stable branch
rather than mainline drift, and none introduce a new subsystem: closer in
scope to a security-hardening batch than a feature release, though
broader than a pure bugfix release.
These bumps are not free: the scarthgap 255.4 -> 255.13 bump was held for a
v2 because TCLIBC=musl broke, and was merged once fixed. A point release
being fixes-only upstream does not remove the need to build and test it.
Already tracked this way on the OE stable branches, counting only bumps
made since each branch forked from master: kirkstone 250.4 -> 250.14 and
scarthgap 255.4 -> 255.21. wrynose has had no point-release bump yet.
AI-Generated: Kiro with Claude Opus 5
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
CVE_PRODUCT = "systemd"
+# systemd publishes bugfix/security-only releases on its stable/v<major>-stable
+# branches (e.g. 261 -> 261.1). The major is a single version part.
+STABLE_VERSION_PARTS = "1"
+inherit upstream-stable-release-point
+
CVE_STATUS[CVE-2019-3815] = "not-applicable-platform: only applied to RHEL"