Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
198 commits
Select commit Hold shift + click to select a range
0ab4c82
app-admin/logrotate: Sync with Gentoo
Aug 3, 2026
8509553
app-admin/perl-cleaner: Sync with Gentoo
Aug 3, 2026
efeed6e
app-arch/libarchive: Sync with Gentoo
Aug 3, 2026
eefd71d
app-containers/aardvark-dns: Sync with Gentoo
Aug 3, 2026
175bab8
app-containers/conmon: Sync with Gentoo
Aug 3, 2026
49a8940
app-containers/containerd: Sync with Gentoo
Aug 3, 2026
14fab9b
app-containers/incus: Sync with Gentoo
Aug 3, 2026
80e5204
app-containers/lxc: Sync with Gentoo
Aug 3, 2026
6d60800
app-containers/netavark: Sync with Gentoo
Aug 3, 2026
386ea88
app-containers/podman: Sync with Gentoo
Aug 3, 2026
079291e
app-containers/runc: Sync with Gentoo
Aug 3, 2026
f027aae
app-crypt/gpgme: Sync with Gentoo
Aug 3, 2026
4222a57
app-crypt/p11-kit: Sync with Gentoo
Aug 3, 2026
6f38dfd
app-crypt/pinentry: Sync with Gentoo
Aug 3, 2026
bb43e11
app-crypt/tpm2-tools: Sync with Gentoo
Aug 3, 2026
fb61d7d
app-crypt/tpm2-tss: Sync with Gentoo
Aug 3, 2026
ab1dd3d
app-editors/nano: Sync with Gentoo
Aug 3, 2026
dd2aca1
app-emulation/qemu: Sync with Gentoo
Aug 3, 2026
fa32dae
app-emulation/virt-firmware: Sync with Gentoo
Aug 3, 2026
6cdc0b6
app-misc/jq: Sync with Gentoo
Aug 3, 2026
25f1c9f
app-misc/pax-utils: Sync with Gentoo
Aug 3, 2026
fddadbe
app-portage/gemato: Sync with Gentoo
Aug 3, 2026
6259295
app-portage/gentoolkit: Sync with Gentoo
Aug 3, 2026
be56585
app-shells/bash-completion: Sync with Gentoo
Aug 3, 2026
55151d2
app-text/asciidoc: Sync with Gentoo
Aug 3, 2026
d06928a
app-text/scdoc: Sync with Gentoo
Aug 3, 2026
5dd4698
dev-build/cmake: Sync with Gentoo
Aug 3, 2026
b3f88f6
dev-build/meson: Sync with Gentoo
Aug 3, 2026
9bb9344
dev-debug/strace: Sync with Gentoo
Aug 3, 2026
07df5ca
dev-lang/go: Sync with Gentoo
Aug 3, 2026
9ec44af
dev-lang/nasm: Sync with Gentoo
Aug 3, 2026
d275690
dev-lang/perl: Sync with Gentoo
Aug 3, 2026
0e08bc6
dev-lang/python: Sync with Gentoo
Aug 3, 2026
8892e97
dev-lang/rust: Sync with Gentoo
Aug 3, 2026
0e894a8
dev-lang/rust-bin: Sync with Gentoo
Aug 3, 2026
393cc30
dev-lang/rust-common: Sync with Gentoo
Aug 3, 2026
33fcbb8
dev-libs/expat: Sync with Gentoo
Aug 3, 2026
9938af8
dev-libs/jansson: Sync with Gentoo
Aug 3, 2026
738e6b9
dev-libs/json-c: Sync with Gentoo
Aug 3, 2026
46e016c
dev-libs/jsoncpp: Sync with Gentoo
Aug 3, 2026
a98b0bd
dev-libs/libffi: Sync with Gentoo
Aug 3, 2026
26d5671
dev-libs/libgcrypt: Sync with Gentoo
Aug 3, 2026
7de9b2d
dev-libs/libgpg-error: Sync with Gentoo
Aug 3, 2026
8bbf1f5
dev-libs/libpcre2: Sync with Gentoo
Aug 3, 2026
bd65fcf
dev-libs/libuv: Sync with Gentoo
Aug 3, 2026
42c6589
dev-libs/opensc: Sync with Gentoo
Aug 3, 2026
801ab7c
dev-libs/tree-sitter: Sync with Gentoo
Aug 3, 2026
b4a9e5e
dev-python/certifi: Sync with Gentoo
Aug 3, 2026
2fa7f59
dev-python/cffi: Sync with Gentoo
Aug 3, 2026
9cb4aa1
dev-python/chardet: Sync with Gentoo
Aug 3, 2026
aa8ce5b
dev-python/charset-normalizer: Sync with Gentoo
Aug 3, 2026
00021e5
dev-python/colorama: Sync with Gentoo
Aug 3, 2026
b937b21
dev-python/cryptography: Sync with Gentoo
Aug 3, 2026
4f126d1
dev-python/cython: Sync with Gentoo
Aug 3, 2026
dfee064
dev-python/dependency-groups: Sync with Gentoo
Aug 3, 2026
e1816d4
dev-python/distlib: Sync with Gentoo
Aug 3, 2026
034b848
dev-python/distro: Sync with Gentoo
Aug 3, 2026
6811f2a
dev-python/ensurepip-pip: Sync with Gentoo
Aug 3, 2026
cca5d82
dev-python/ensurepip-setuptools: Sync with Gentoo
Aug 3, 2026
3f323fc
dev-python/fasteners: Sync with Gentoo
Aug 3, 2026
cd30b2f
dev-python/fastjsonschema: Sync with Gentoo
Aug 3, 2026
629fc94
dev-python/gpep517: Sync with Gentoo
Aug 3, 2026
bcdac11
dev-python/hatchling: Sync with Gentoo
Aug 3, 2026
96ddd44
dev-python/jaraco-functools: Sync with Gentoo
Aug 3, 2026
429d810
dev-python/jaraco-text: Sync with Gentoo
Aug 3, 2026
b4d7b69
dev-python/jinja2: Sync with Gentoo
Aug 3, 2026
068e506
dev-python/lark: Sync with Gentoo
Aug 3, 2026
d9896c4
dev-python/lazy-object-proxy: Sync with Gentoo
Aug 3, 2026
df2fb51
dev-python/linkify-it-py: Sync with Gentoo
Aug 3, 2026
239d780
dev-python/lxml: Sync with Gentoo
Aug 3, 2026
e87a4c2
dev-python/markdown-it-py: Sync with Gentoo
Aug 3, 2026
6f5cfe0
dev-python/mdurl: Sync with Gentoo
Aug 3, 2026
d308030
dev-python/msgpack: Sync with Gentoo
Aug 3, 2026
eec09da
dev-python/pip: Sync with Gentoo
Aug 3, 2026
3bd1d3e
dev-python/pkg-resources: Sync with Gentoo
Aug 3, 2026
2ae3225
dev-python/platformdirs: Sync with Gentoo
Aug 3, 2026
f9754d4
dev-python/poetry-core: Sync with Gentoo
Aug 3, 2026
0ae712c
dev-python/pygments: Sync with Gentoo
Aug 3, 2026
cf5f7c8
dev-python/pysocks: Sync with Gentoo
Aug 3, 2026
8fe4836
dev-python/requests: Sync with Gentoo
Aug 3, 2026
2a2fcbe
dev-python/resolvelib: Sync with Gentoo
Aug 3, 2026
5c2b55e
dev-python/rich: Sync with Gentoo
Aug 3, 2026
eba948d
dev-python/setuptools: Sync with Gentoo
Aug 3, 2026
b0c11bc
dev-python/setuptools-scm: Sync with Gentoo
Aug 3, 2026
a1cbe91
dev-python/snakeoil: Sync with Gentoo
Aug 3, 2026
4f78381
dev-python/truststore: Sync with Gentoo
Aug 3, 2026
553693a
dev-python/typing-extensions: Sync with Gentoo
Aug 3, 2026
9dbe674
dev-python/uc-micro-py: Sync with Gentoo
Aug 3, 2026
f7a3651
dev-python/urllib3: Sync with Gentoo
Aug 3, 2026
b3876c6
dev-python/vcs-versioning: Sync with Gentoo
Aug 3, 2026
1fad294
dev-util/maturin: Sync with Gentoo
Aug 3, 2026
cdfbf3a
dev-util/patchelf: Sync with Gentoo
Aug 3, 2026
6718522
dev-util/pkgcheck: Sync with Gentoo
Aug 3, 2026
5c83602
dev-util/pkgconf: Sync with Gentoo
Aug 3, 2026
384db6d
dev-util/xdelta: Sync with Gentoo
Aug 3, 2026
608e603
eclass/cargo: Sync with Gentoo
Aug 3, 2026
02f714a
eclass/go-module: Sync with Gentoo
Aug 3, 2026
c1f8744
eclass/kernel-2: Sync with Gentoo
Aug 3, 2026
997547d
eclass/llvm-r1: Sync with Gentoo
Aug 3, 2026
8f44552
eclass/llvm-r2: Sync with Gentoo
Aug 3, 2026
d29ffcb
eclass/llvm: Sync with Gentoo
Aug 3, 2026
33995f9
eclass/python-utils-r1: Sync with Gentoo
Aug 3, 2026
6918ca1
eclass/qmake-utils: Sync with Gentoo
Aug 3, 2026
122a7d7
eclass/qt-utils: Sync with Gentoo
Aug 3, 2026
2a417d7
eclass/rust: Sync with Gentoo
Aug 3, 2026
e527c61
eclass/selinux-policy-2: Sync with Gentoo
Aug 3, 2026
7ef4363
eclass/xorg-3: Sync with Gentoo
Aug 3, 2026
5ade605
net-dns/bind: Sync with Gentoo
Aug 3, 2026
fe33644
net-dns/c-ares: Sync with Gentoo
Aug 3, 2026
7041bf3
net-dns/dnsmasq: Sync with Gentoo
Aug 3, 2026
2b75bd1
net-firewall/ipset: Sync with Gentoo
Aug 3, 2026
da74039
net-fs/cifs-utils: Sync with Gentoo
Aug 3, 2026
fe080cb
net-fs/samba: Sync with Gentoo
Aug 3, 2026
f04514a
net-libs/nghttp2: Sync with Gentoo
Aug 3, 2026
9645586
net-libs/ngtcp2: Sync with Gentoo
Aug 3, 2026
d2c2040
net-misc/curl: Sync with Gentoo
Aug 3, 2026
974a660
net-misc/passt: Sync with Gentoo
Aug 3, 2026
949a20a
net-misc/socat: Sync with Gentoo
Aug 3, 2026
a08ec3c
profiles: Sync with Gentoo
Aug 3, 2026
971fbcd
sec-policy/selinux-base: Sync with Gentoo
Aug 3, 2026
57e62c9
sec-policy/selinux-base-policy: Sync with Gentoo
Aug 3, 2026
1021e3a
sec-policy/selinux-container: Sync with Gentoo
Aug 3, 2026
4c8aafc
sec-policy/selinux-dbus: Sync with Gentoo
Aug 3, 2026
f49ab25
sec-policy/selinux-policykit: Sync with Gentoo
Aug 3, 2026
2f2f5f3
sec-policy/selinux-sssd: Sync with Gentoo
Aug 3, 2026
8a04452
sec-policy/selinux-unconfined: Sync with Gentoo
Aug 3, 2026
8bc9b29
sys-apps/acl: Sync with Gentoo
Aug 3, 2026
9a1f4a1
sys-apps/file: Sync with Gentoo
Aug 3, 2026
8ed21aa
sys-apps/findutils: Sync with Gentoo
Aug 3, 2026
fcac1e1
sys-apps/gawk: Sync with Gentoo
Aug 3, 2026
88870a3
sys-apps/less: Sync with Gentoo
Aug 3, 2026
403c5e8
sys-apps/pkgcore: Sync with Gentoo
Aug 3, 2026
1292c3e
sys-apps/portage: Sync with Gentoo
Aug 3, 2026
eae3893
sys-apps/sandbox: Sync with Gentoo
Aug 3, 2026
9721281
sys-apps/sed: Sync with Gentoo
Aug 3, 2026
9823d32
sys-apps/shadow: Sync with Gentoo
Aug 3, 2026
1353954
sys-apps/util-linux: Sync with Gentoo
Aug 3, 2026
6b5d564
sys-auth/pambase: Sync with Gentoo
Aug 3, 2026
78f7e5e
sys-auth/sssd: Sync with Gentoo
Aug 3, 2026
4747f47
sys-block/thin-provisioning-tools: Sync with Gentoo
Aug 3, 2026
d693bdf
sys-devel/dwz: Sync with Gentoo
Aug 3, 2026
ae7491f
sys-devel/gcc: Sync with Gentoo
Aug 3, 2026
2eb56a6
sys-devel/gettext: Sync with Gentoo
Aug 3, 2026
eaf9540
sys-fs/btrfs-progs: Sync with Gentoo
Aug 3, 2026
2e2c2da
sys-fs/cryptsetup: Sync with Gentoo
Aug 3, 2026
5ec6e04
sys-fs/fuse-overlayfs: Sync with Gentoo
Aug 3, 2026
89d2a96
sys-fs/lxcfs: Sync with Gentoo
Aug 3, 2026
1bac441
sys-fs/zfs: Sync with Gentoo
Aug 3, 2026
9eeb4e7
sys-kernel/dracut: Sync with Gentoo
Aug 3, 2026
2361481
sys-libs/glibc: Sync with Gentoo
Aug 3, 2026
e8732ee
sys-libs/libnvme: Sync with Gentoo
Aug 3, 2026
67258ae
sys-libs/libseccomp: Sync with Gentoo
Aug 3, 2026
c93644d
sys-libs/libxcrypt: Sync with Gentoo
Aug 3, 2026
a722345
sys-libs/timezone-data: Sync with Gentoo
Aug 3, 2026
111e123
sys-process/lsof: Sync with Gentoo
Aug 3, 2026
9f4f0b6
sys-process/time: Sync with Gentoo
Aug 3, 2026
0c687b9
virtual/service-manager: Sync with Gentoo
Aug 3, 2026
b245035
x11-drivers/nvidia-drivers: Sync with Gentoo
Aug 3, 2026
00761d0
overlay profiles: Add some accept keywords
krnowak Aug 3, 2026
00d38da
dev-libs/blake3: Add from Gentoo
krnowak Aug 3, 2026
97abd8d
.github: Add packages to automation
krnowak Aug 3, 2026
83d380e
overlay profiles: Disable USE=initramfs for sys-fs/zfs
krnowak Aug 3, 2026
0a92698
app-containers/container-libs: Sync with Gentoo
krnowak Aug 3, 2026
e8276f4
app-containers/containers-shortnames: Add from Gentoo
krnowak Aug 4, 2026
0f1cd8c
.github: Add app-containers/containers-shortnames to automation
krnowak Aug 4, 2026
b594022
overlay profiles: Update accept keywords for app-containers/container…
krnowak Aug 4, 2026
07b377a
overlay profiles: Add accept keywords to address CVEs
krnowak Aug 4, 2026
0b15d72
overlay coreos/user-patches: Add patches for net-misc/wget
krnowak Aug 4, 2026
7fb5df4
sys-apps/policycoreutils: Sync with Gentoo
krnowak Aug 4, 2026
9cbeb6a
sys-apps/policycoreutils: Apply Flatcar modifications
tormath1 Jun 12, 2023
222c425
sys-libs/libsemanage: Sync with Gentoo
krnowak Aug 4, 2026
3bdd4f8
sys-libs/libsemanage: Apply flatcar patches
tormath1 Jun 12, 2023
ab2941d
overlay profiles: Add accept keywords for sys-apps/policycoreutils deps
krnowak Aug 4, 2026
5174ae7
overlay coreos/user-patches: Add a patch for dev-libs/libxml2
krnowak Aug 4, 2026
ca4bec5
overlay coreos/user-patches: Add a patch for sys-libs/pam
krnowak Aug 4, 2026
4488223
overlay coreos/user-patches: Add patches for sys-auth/sssd
krnowak Aug 5, 2026
5356b37
overlay coreos/user-patches: Add a patch for app-arch/bzip2
krnowak Aug 5, 2026
99de4f3
overlay app-admin/etcd-wrapper: Bump to 3.6.11 to match dev-db/etcd
krnowak Aug 5, 2026
6e4025a
overlay user-patches: Add a patch for app-crypt/mit-krb5
krnowak Aug 5, 2026
661ba75
overlay profiles: Add/update accept keywords for security issues
krnowak Aug 6, 2026
760a72d
overlay user-patches: Add a patch for sys-apps/diffutils
krnowak Aug 6, 2026
7d22832
overlay profiles: Drop accept keywords for app-arch/libarchive
krnowak Aug 6, 2026
9a40dbd
overlay coreos/user-patches: Add patches for sys-apps/coreutils
krnowak Aug 6, 2026
48c1822
overlay coreos/user-patches: Update some READMEs
krnowak Aug 6, 2026
fd5695c
overlay profiles: Drop accept keywords for net-libs/nghttp2
krnowak Aug 6, 2026
25e3cd6
overlay profiles: Drop accept keywords for net-libs/ngtcp2
krnowak Aug 6, 2026
81ff123
overlay profiles: Drop accept keywords for net-misc/curl
krnowak Aug 6, 2026
52f645a
overlay coreos/user-patches: Drop duplicated patches for selinux poli…
krnowak Aug 7, 2026
3562683
sys-block/thin-provisioning-tool: Move LLVM_COMPAT change from ebuild…
krnowak Aug 7, 2026
12746b5
overlay profiles: Drop settings for sys-fs/zfs-kmod
krnowak Aug 7, 2026
b7afb7b
overlay coreos/config: Move overrides from sys-fs/zfs-kmod to sys-fs/zfs
krnowak Aug 7, 2026
2196421
net-dns/bind: Reinstate our modifications
krnowak Aug 10, 2026
35d96d6
overlay coreos/config: Minor cleanups in net-dns/bind modifications
krnowak Aug 11, 2026
13c8cf1
overlay coreos/user-patches: Drop unnecessary patch
krnowak Aug 11, 2026
2f8968f
changelog: Add entries
krnowak Aug 7, 2026
496a206
overlay coreos/config: Do not build tests and docs in sys-apps/diffutils
krnowak Aug 12, 2026
934413b
overlay coreos/config: Relax perms to tmpfiles config file from sys-p…
krnowak Aug 12, 2026
85c5ba0
overlay coreos/config: Relax perms to tmpfiles config file from sys-f…
krnowak Aug 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .github/workflows/portage-stable-packages-list
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,9 @@ app-cdr/cdrtools
app-containers/aardvark-dns
app-containers/catatonit
app-containers/conmon
app-containers/container-libs
app-containers/containerd
app-containers/containers-shortnames
app-containers/cri-tools
app-containers/crun
app-containers/docker
Expand Down Expand Up @@ -239,6 +241,7 @@ dev-lang/swig
dev-lang/tcl
dev-lang/yasm

dev-libs/blake3
dev-libs/cJSON
dev-libs/cowsql
dev-libs/cyrus-sasl
Expand Down
28 changes: 28 additions & 0 deletions changelog/security/2026-08-07-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
- bzip2 ([CVE-2026-42250](https://www.cve.org/CVERecord/?id=CVE-2026-42250))
- c-ares ([CVE-2026-33630](https://www.cve.org/CVERecord/?id=CVE-2026-33630), [GHSA-pjmc-gx33-gc76](https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76), [GHSA-jv8r-gqr9-68wj](https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj))
- containerd ([CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186), [CVE-2026-34986](https://www.cve.org/CVERecord/?id=CVE-2026-34986), [CVE-2026-35469](https://www.cve.org/CVERecord/?id=CVE-2026-35469), [CVE-2026-39883](https://www.cve.org/CVERecord/?id=CVE-2026-39883))
- coreutils ([CVE-2026-56391](https://www.cve.org/CVERecord/?id=CVE-2026-56391), [CVE-2026-56392](https://www.cve.org/CVERecord/?id=CVE-2026-56392))
- cri-tools ([CVE-2026-32285](https://www.cve.org/CVERecord/?id=CVE-2026-32285), [CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186))
- diffutils ([CVE-2026-53910](https://www.cve.org/CVERecord/?id=CVE-2026-53910))
- docker ([CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186), [CVE-2026-33997](https://www.cve.org/CVERecord/?id=CVE-2026-33997), [CVE-2026-34040](https://www.cve.org/CVERecord/?id=CVE-2026-34040), [CVE-2026-39883](https://www.cve.org/CVERecord/?id=CVE-2026-39883), [CVE-2026-41567](https://www.cve.org/CVERecord/?id=CVE-2026-41567), [CVE-2026-42306](https://www.cve.org/CVERecord/?id=CVE-2026-42306), [CVE-2026-33747](https://www.cve.org/CVERecord/?id=CVE-2026-33747), [CVE-2026-33748](https://www.cve.org/CVERecord/?id=CVE-2026-33748))
- docker-buildx ([CVE-2025-0495](https://www.cve.org/CVERecord/?id=CVE-2025-0495))
- etcd ([CVE-2025-22869](https://www.cve.org/CVERecord/?id=CVE-2025-22869), [CVE-2025-30204](https://www.cve.org/CVERecord/?id=CVE-2025-30204), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186))
- go ([CVE-2026-27145](https://www.cve.org/CVERecord/?id=CVE-2026-27145), [CVE-2026-39822](https://www.cve.org/CVERecord/?id=CVE-2026-39822), [CVE-2026-42504](https://www.cve.org/CVERecord/?id=CVE-2026-42504), [CVE-2026-42505](https://www.cve.org/CVERecord/?id=CVE-2026-42505), [CVE-2026-42507](https://www.cve.org/CVERecord/?id=CVE-2026-42507))
- gzip ([CVE-2026-41991](https://www.cve.org/CVERecord/?id=CVE-2026-41991))
- jq ([CVE-2026-32316](https://www.cve.org/CVERecord/?id=CVE-2026-32316), [CVE-2026-33947](https://www.cve.org/CVERecord/?id=CVE-2026-33947), [CVE-2026-33948](https://www.cve.org/CVERecord/?id=CVE-2026-33948), [CVE-2026-39956](https://www.cve.org/CVERecord/?id=CVE-2026-39956), [CVE-2026-39979](https://www.cve.org/CVERecord/?id=CVE-2026-39979), [CVE-2026-40164](https://www.cve.org/CVERecord/?id=CVE-2026-40164), [CVE-2026-41256](https://www.cve.org/CVERecord/?id=CVE-2026-41256), [CVE-2026-41257](https://www.cve.org/CVERecord/?id=CVE-2026-41257), [CVE-2026-43894](https://www.cve.org/CVERecord/?id=CVE-2026-43894), [CVE-2026-43895](https://www.cve.org/CVERecord/?id=CVE-2026-43895), [CVE-2026-43896](https://www.cve.org/CVERecord/?id=CVE-2026-43896), [CVE-2026-44777](https://www.cve.org/CVERecord/?id=CVE-2026-44777), [CVE-2026-47770](https://www.cve.org/CVERecord/?id=CVE-2026-47770), [CVE-2026-49839](https://www.cve.org/CVERecord/?id=CVE-2026-49839), [CVE-2026-54679](https://www.cve.org/CVERecord/?id=CVE-2026-54679))
- json-c ([CVE-2026-9146](https://www.cve.org/CVERecord/?id=CVE-2026-9146))
- libxml2 ([CVE-2026-11979](https://www.cve.org/CVERecord/?id=CVE-2026-11979))
- mit-krb5 ([CVE-2026-40355](https://www.cve.org/CVERecord/?id=CVE-2026-40355), [CVE-2026-40356](https://www.cve.org/CVERecord/?id=CVE-2026-40356))
- opensc ([CVE-2025-13763](https://www.cve.org/CVERecord/?id=CVE-2025-13763), [CVE-2025-49010](https://www.cve.org/CVERecord/?id=CVE-2025-49010), [CVE-2025-66037](https://www.cve.org/CVERecord/?id=CVE-2025-66037), [CVE-2025-66038](https://www.cve.org/CVERecord/?id=CVE-2025-66038), [CVE-2025-66215](https://www.cve.org/CVERecord/?id=CVE-2025-66215))
- p11-kit ([CVE-2026-13757](https://www.cve.org/CVERecord/?id=CVE-2026-13757))
- pam ([CVE-2026-54411](https://www.cve.org/CVERecord/?id=CVE-2026-54411))
- policycoreutils ([CVE-2026-59676](https://www.cve.org/CVERecord/?id=CVE-2026-59676), [CVE-2026-59677](https://www.cve.org/CVERecord/?id=CVE-2026-59677))
- qemu ([CVE-2026-3886](https://www.cve.org/CVERecord/?id=CVE-2026-3886))
- socat ([CVE-2026-56123](https://www.cve.org/CVERecord/?id=CVE-2026-56123))
- sssd ([CVE-2026-12610](https://www.cve.org/CVERecord/?id=CVE-2026-12610), [CVE-2026-14474](https://www.cve.org/CVERecord/?id=CVE-2026-14474), [CVE-2026-14476](https://www.cve.org/CVERecord/?id=CVE-2026-14476))
- util-linux ([CVE-2026-13595](https://www.cve.org/CVERecord/?id=CVE-2026-13595), [CVE-2026-53612](https://www.cve.org/CVERecord/?id=CVE-2026-53612), [CVE-2026-53613](https://www.cve.org/CVERecord/?id=CVE-2026-53613), [CVE-2026-53614](https://www.cve.org/CVERecord/?id=CVE-2026-53614))
- wget ([CVE-2026-15146](https://www.cve.org/CVERecord/?id=CVE-2026-15146), [CVE-2026-58469](https://www.cve.org/CVERecord/?id=CVE-2026-58469), [CVE-2026-58470](https://www.cve.org/CVERecord/?id=CVE-2026-58470), [CVE-2026-58471](https://www.cve.org/CVERecord/?id=CVE-2026-58471), [CVE-2026-58472](https://www.cve.org/CVERecord/?id=CVE-2026-58472))
- tpm2-tools (GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66, GHSA-qp88-8f4j-wv7q)
- tpm2-tss (GHSA-q759-vqg7-8rc5, GHSA-7638-f8gq-c475, GHSA-p3px-r4mm-jpw5, GHSA-x5j2-26fc-hhc3, GHSA-gf8g-2r5c-74c7, GHSA-mj78-pj5v-wvjx, GHSA-v2qp-xh5m-44mf, GHSA-2q5v-c7hv-fvpf, GHSA-pcpw-8625-jqcp, GHSA-6grq-c24j-xcjr)
- less ([less-20260606](https://greenwoodsoftware.com/less/news.704.html))
- libseccomp ([GHSA-2hqh-5c36-grrm](https://github.com/seccomp/libseccomp/security/advisories/GHSA-2hqh-5c36-grrm), [GHSA-46fr-jh49-xvhx](https://github.com/seccomp/libseccomp/security/advisories/GHSA-46fr-jh49-xvhx), [GHSA-4q85-33p6-j5g6](https://github.com/seccomp/libseccomp/security/advisories/GHSA-4q85-33p6-j5g6))
50 changes: 50 additions & 0 deletions changelog/updates/2026-08-07-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
- SDK: cmake ([4.3.4](https://cmake.org/cmake/help/v4.3/release/4.3.html#id4))
- SDK: go ([1.26.5](https://go.dev/doc/devel/release#go1.26.5) (includes [1.26.4](https://go.dev/doc/devel/release#go1.26.4)))
- SDK: nasm ([3.02](https://www.nasm.us/docs/3.02/nasmac.html))
- SDK: opensc ([0.27.1](https://github.com/OpenSC/OpenSC/releases/tag/0.27.1))
- SDK: pkgcheck ([0.10.40](https://github.com/pkgcore/pkgcheck/releases/tag/v0.10.40))
- SDK: qemu ([10.2.3](https://lists.gnu.org/archive/html/qemu-stable/2026-05/msg00654.html))
- base, dev: acl ([2.4.0](https://cgit.git.savannah.nongnu.org/cgit/acl.git/plain/doc/CHANGES?h=v2.4.0))
- base, dev: attr ([2.6.0](https://cgit.git.savannah.nongnu.org/cgit/attr.git/plain/doc/CHANGES?h=v2.6.0))
- base, dev: c-ares ([1.34.8](https://github.com/c-ares/c-ares/releases/tag/v1.34.8) (includes [1.34.7](https://github.com/c-ares/c-ares/releases/tag/v1.34.7)))
- base, dev: cri-tools ([1.36.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.36.0) (includes [1.35.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.35.0), [1.34.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.34.0)))
- base, dev: etcd ([3.6.11](https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.6.md#v3611-2026-05-01))
- base, dev: jq ([1.8.2](https://github.com/jqlang/jq/releases/tag/jq-1.8.2))
- base, dev: json-c ([0.19](https://raw.githubusercontent.com/json-c/json-c/refs/heads/json-c-0.19/ChangeLog))
- base, dev: less ([704](https://greenwoodsoftware.com/less/news.704.html) (includes [702](https://greenwoodsoftware.com/less/news.702.html)))
- base, dev: libarchive ([3.8.9](https://github.com/libarchive/libarchive/releases/tag/v3.8.9))
- base, dev: libgpg-error ([1.61](https://dev.gnupg.org/T8239.html))
- base, dev: libnvme ([1.16.2](https://github.com/linux-nvme/libnvme/releases/tag/v1.16.2))
- base, dev: libseccomp ([2.6.1](https://github.com/seccomp/libseccomp/releases/tag/v2.6.1))
- base, dev: libselinux ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: libsemanage ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11) (includes [3.10](https://github.com/SELinuxProject/selinux/releases/tag/3.10), [3.9](https://github.com/SELinuxProject/selinux/releases/tag/3.9)))
- base, dev: libsepol ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: nghttp2 ([1.69.0](https://github.com/nghttp2/nghttp2/releases/tag/v1.69.0))
- base, dev: ngtcp2 ([1.24.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.2{4,3}.0) (includes [1.23.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.23.0)))
- base, dev: openssh ([10.4_p1](https://www.openssh.org/txt/release-10.4))
- base, dev: p11-kit ([0.26.4](https://github.com/p11-glue/p11-kit/releases/tag/0.26.4) (includes [0.26.3](https://github.com/p11-glue/p11-kit/releases/tag/0.26.3)))
- base, dev: policycoreutils ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11) (includes [3.10](https://github.com/SELinuxProject/selinux/releases/tag/3.10), [3.9](https://github.com/SELinuxProject/selinux/releases/tag/3.9)))
- base, dev: samba ([4.24.4](https://www.samba.org/samba/history/samba-4.24.4.html) (includes [4.24.3](https://www.samba.org/samba/history/samba-4.24.3.html), [4.24.2](https://www.samba.org/samba/history/samba-4.24.2.html), [4.24.1](https://www.samba.org/samba/history/samba-4.24.1.html), [4.24.0](https://www.samba.org/samba/history/samba-4.24.0.html)))
- base, dev: semodule-utils ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: socat ([1.8.1.3](https://repo.or.cz/socat.git/blob/refs/tags/tag-1.8.1.3:/CHANGES))
- base, dev: sssd ([2.13.1](https://sssd.io/release-notes/sssd-2.13.1.html))
- base, dev: strace ([7.1](https://github.com/strace/strace/releases/tag/v7.1))
- base, dev: tpm2-tools ([5.8](https://github.com/tpm2-software/tpm2-tools/releases/tag/5.8))
- base, dev: tpm2-tss ([4.2.0](https://github.com/tpm2-software/tpm2-tss/releases/tag/4.2.0))
- base, dev: util-linux ([2.42.2](https://github.com/util-linux/util-linux/blob/v2.42.2/Documentation/releases/v2.42.2-ReleaseNotes) (includes [2.42.1](https://github.com/util-linux/util-linux/blob/v2.42.1/Documentation/releases/v2.42.1-ReleaseNotes), [2.42](https://github.com/util-linux/util-linux/blob/v2.42/Documentation/releases/v2.42-ReleaseNotes)))
- dev: file ([5.48](https://raw.githubusercontent.com/file/file/refs/tags/FILE5_48/ChangeLog))
- dev: gentoolkit ([0.7.6](https://gitweb.gentoo.org/proj/gentoolkit.git/log/?h=gentoolkit-0.7.6))
- dev: portage ([3.0.81.2](https://gitweb.gentoo.org/proj/portage.git/plain/NEWS?h=portage-3.0.81.2))
- dev: sandbox ([2.49](https://gitweb.gentoo.org/proj/sandbox.git/log/?h=v2.49))
- sysext-containerd: containerd ([2.3.3](https://github.com/containerd/containerd/releases/tag/v2.3.3) (includes [2.3.2](https://github.com/containerd/containerd/releases/tag/v2.3.2), [2.3.1](https://github.com/containerd/containerd/releases/tag/v2.3.1), [2.3.0](https://github.com/containerd/containerd/releases/tag/v2.3.0)))
- sysext-docker: docker ([29.5.2](https://github.com/moby/moby/releases/tag/docker-v29.5.2) (includes [29.5.1](https://github.com/moby/moby/releases/tag/docker-v29.5.1), [29.5.0](https://github.com/moby/moby/releases/tag/docker-v29.5.0), [29.4.0](https://github.com/moby/moby/releases/tag/docker-v29.4.0), [29.3.0](https://github.com/moby/moby/releases/tag/docker-v29.3.0), [29.2.0](https://github.com/moby/moby/releases/tag/docker-v29.2.0)))
- sysext-docker: docker-buildx ([0.35.0](https://github.com/docker/buildx/releases/tag/v0.36.0))
- sysext-docker: docker-cli ([29.5.2](https://github.com/moby/moby/releases/tag/docker-v29.5.2) (includes [29.5.1](https://github.com/moby/moby/releases/tag/docker-v29.5.1), [29.5.0](https://github.com/moby/moby/releases/tag/docker-v29.5.0), [29.4.0](https://github.com/moby/moby/releases/tag/docker-v29.4.0), [29.3.0](https://github.com/moby/moby/releases/tag/docker-v29.3.0), [29.2.0](https://github.com/moby/moby/releases/tag/docker-v29.2.0)))
- sysext-incus: xdelta ([3.2.0](https://github.com/jmacd/xdelta/releases/tag/v3.2.0))
- sysext-podman: container-libs ([0.69.0](https://github.com/podman-container-tools/container-libs/releases/tag/common%2Fv0.69.0))
- sysext-python: distlib ([0.4.3](https://raw.githubusercontent.com/pypa/distlib/refs/tags/0.4.3/CHANGES.rst))
- sysext-python: msgpack ([1.2.1](https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1) (includes [1.2.0](https://github.com/msgpack/msgpack-python/releases/tag/v1.2.0)))
- sysext-python: setuptools-scm ([10.1.2](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.2) (includes [10.1.1](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.1), [10.1.0](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.0)))
- sysext-python: typing-extensions ([4.16.0](https://raw.githubusercontent.com/python/typing_extensions/refs/tags/4.16.0/CHANGELOG.md))
- sysext-python: vcs-versioning ([2.2.2](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.2) (includes [2.2.1](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.1), [2.2.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.0), [2.1.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.1.0), [2.0.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.0.0)))
- sysext-zfs: zfs ([2.4.3](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.3) (includes [2.4.2](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.2), [2.4.1](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.1), [2.4.0](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.0)))
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,7 @@ KEYWORDS="amd64 arm64"
RDEPEND=">=app-admin/sdnotify-proxy-0.1.0"

src_install() {
local tag="v${PV}"
if [[ "${ARCH}" != "amd64" ]]; then
tag+="-${ARCH}"
fi
local tag="v${PV}-${ARCH}"

exeinto /usr/lib/flatcar
doexe "${FILESDIR}"/etcd-wrapper
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Keep only tool binaries and libraries those binaries need.
ndb_install_mask="
INSTALL_MASK+="
/etc
/var
/usr/bin/arpaname
Expand All @@ -13,15 +13,10 @@ ndb_install_mask="
/usr/sbin
"

INSTALL_MASK+="${ndb_install_mask}"
PKG_INSTALL_MASK+="${ndb_install_mask}"

unset ndb_install_mask

# Override fowners to ignore changing owner or group to named. The
# only files that this happens for are files that we have put into
# {PKG_,}INSTALL_MASK. This will help us avoid installing
# acct-user/named and acct-group/named.
# INSTALL_MASK. This will help us avoid installing acct-user/named and
# acct-group/named.
if [[ -z ${flatcar_hacked_fowners:-} ]]; then
flatcar_hacked_fowners=$(command -v fowners)
fi
Expand All @@ -35,10 +30,10 @@ fowners() {
# The pkg_postinst phase function wants to generate an rndc.key file
# with /usr/sbin/rndc-confgen script if the key file is missing, then
# change the ownership to the named group. We don't need the key file
# at all as it's presumably for named. Also, we masked the installtion
# of the script. Thus we fool the phase function by putting an empty
# key file there, so the function won't trigger the generation. We
# drop the key file later too.
# at all as it's presumably for named. Also, we masked the
# installation of the script. Thus we fool the phase function by
# putting an empty key file there, so the function won't trigger the
# generation. We drop the key file later too.
cros_pre_pkg_postinst_add_fake_rndc_key() {
local dir="${EROOT}/etc/bind"
if [[ ! -d "${dir}" ]]; then
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
cros_post_src_prepare_no_docs_and_tests() {
# Do not build tests nor docs. Building docs involves running the
# built diff3, which is an additional hurdle when cross-compiling.
sed -i -e 's/ tests\b//' -e 's/ doc\b//' -e 's/ man\b//' -e 's/ gnulib-tests\b//' Makefile.in
}
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,11 @@ export ECARGO_EXTRA_ARGS=--no-default-features
# read-only so that it forcibly overrides the ebuild. Note that this doesn't
# avoid pulling in another rust(-bin) version, but it does avoid it being used.
declare -gr RUST_NEEDS_LLVM=

# Avoid using incompatible rust-bin. Our dev-lang/rust build is
# configured for cross-compiling, while dev-lang/rust-bin is not. The
# latter will be pulled in because of RUST_NEEDS_LLVM=1, but we don't
# need LLVM for our build. The env change above avoids using rust-bin,
# but it cannot avoid pulling it in. This change does that. Probably
# makes RUST_NEEDS_LLVM override unnecessary, but whatever.
declare -gra LLVM_COMPAT=( {19..22} )
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
cros_post_src_install_tmpfiles_perms() {
# Upstream installs its tmpfiles config file with unnecessarilly
# restrictive mode, relax it. It could be also fixed by passing
# --enable-write_install option to configure script, but that
# would affect a lot of other files too.
fperms 0644 /usr/lib/tmpfiles.d/lvm2.conf
}
Original file line number Diff line number Diff line change
@@ -1,3 +1,15 @@
# This addresses an issue with the kernel version compatibility check
# when installing zfs modules to /build/<arch> (e.g. via build_packages)
# from its binpkg (i.e. not recompiling it).
SKIP_KERNEL_BINPKG_ENV_RESET=1

# Necessary to prevent KV_FULL & KV_OUT_DIR from being unset
# when building Kernel modules for sysext. See also eclass/linux-info.eclass.
cros_pre_pkg_setup_kernel_version() {
LINUX_INFO_BINARY_RESET=1
get_version
}

cros_post_src_install_rm_systemd_masks() {
rm "${D}$(systemd_get_systemunitdir)"/zfs-load-key.service
rm "${D}$(systemd_get_systemunitdir)"/zfs-import.service
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,12 @@
# Do not install Gentoo-provided audit rules, we will install our own
# in coreos-base/misc-files. Also skip installing legacy initscripts
# stuff in /usr/libexec.
audit_install_mask=" /etc/audit/audit.rules* /usr/libexec "
INSTALL_MASK+="${audit_install_mask}"
PKG_INSTALL_MASK+="${audit_install_mask}"
unset audit_install_mask
INSTALL_MASK+=" /etc/audit/audit.rules* /usr/libexec "

cros_post_src_install_audit_flatcar_modifications() {
# Upstream installs its tmpfiles config file with unnecessarilly
# restrictive mode, relax it.
#
# https://github.com/linux-audit/audit-userspace/pull/547
fperms 0644 /usr/lib/tmpfiles.d/audit.conf
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
From 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 Mon Sep 17 00:00:00 2001
From: Mark Wielaard <mark@klomp.org>
Date: Thu, 28 May 2026 16:15:45 +0200
Subject: [PATCH] bzip2recover: Make sure to not process more than
BZ_MAX_HANDLED_BLOCKS

There is an off-by-one in the check before calling tooManyBlocks. This
causes the scanning loop to run one more time and cause a possible
read or write one past the global bStart, bEnd, rbStart and rbEnd
buffers. There are no known exploits of this issue and you will need
to compile with something like gcc -fsanitize=address (ASAN
AddressSanitizer) to observe the faulty read/write.

This has been assigned CVE-2026-42250.
---
bzip2recover.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/bzip2recover.c b/bzip2recover.c
index a8131e0..4b1c219 100644
--- a/bzip2recover.c
+++ b/bzip2recover.c
@@ -402,7 +402,7 @@ Int32 main ( Int32 argc, Char** argv )
rbEnd[rbCtr] = bEnd[currBlock];
rbCtr++;
}
- if (currBlock >= BZ_MAX_HANDLED_BLOCKS)
+ if (currBlock >= BZ_MAX_HANDLED_BLOCKS - 1)
tooManyBlocks(BZ_MAX_HANDLED_BLOCKS);
currBlock++;

Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
The patch `0001-bzip2recover-CVE-2026-42250.patch` can be dropped when
updating to 1.0.9.
Loading