Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
197 commits
Select commit Hold shift + click to select a range
29ee9cf
app-admin/logrotate: Sync with Gentoo
Aug 3, 2026
a47972a
app-admin/perl-cleaner: Sync with Gentoo
Aug 3, 2026
d948a36
app-arch/libarchive: Sync with Gentoo
Aug 3, 2026
fbc1eb5
app-containers/aardvark-dns: Sync with Gentoo
Aug 3, 2026
1f2d9c9
app-containers/conmon: Sync with Gentoo
Aug 3, 2026
b68aef0
app-containers/containerd: Sync with Gentoo
Aug 3, 2026
45c26c6
app-containers/incus: Sync with Gentoo
Aug 3, 2026
426d1b8
app-containers/lxc: Sync with Gentoo
Aug 3, 2026
47d8c7e
app-containers/netavark: Sync with Gentoo
Aug 3, 2026
1495c4a
app-containers/podman: Sync with Gentoo
Aug 3, 2026
569a574
app-containers/runc: Sync with Gentoo
Aug 3, 2026
fb6101d
app-crypt/gpgme: Sync with Gentoo
Aug 3, 2026
4130c0b
app-crypt/p11-kit: Sync with Gentoo
Aug 3, 2026
7984594
app-crypt/pinentry: Sync with Gentoo
Aug 3, 2026
453f99f
app-crypt/tpm2-tools: Sync with Gentoo
Aug 3, 2026
98cab02
app-crypt/tpm2-tss: Sync with Gentoo
Aug 3, 2026
b1d3ecb
app-editors/nano: Sync with Gentoo
Aug 3, 2026
cbd5a9e
app-emulation/qemu: Sync with Gentoo
Aug 3, 2026
184de80
app-emulation/virt-firmware: Sync with Gentoo
Aug 3, 2026
e8cb51e
app-misc/jq: Sync with Gentoo
Aug 3, 2026
75cfd10
app-misc/pax-utils: Sync with Gentoo
Aug 3, 2026
ab9dadb
app-portage/gemato: Sync with Gentoo
Aug 3, 2026
723af03
app-portage/gentoolkit: Sync with Gentoo
Aug 3, 2026
b9ccab0
app-shells/bash-completion: Sync with Gentoo
Aug 3, 2026
457d1cd
app-text/asciidoc: Sync with Gentoo
Aug 3, 2026
45d8fea
app-text/scdoc: Sync with Gentoo
Aug 3, 2026
ccbe36f
dev-build/cmake: Sync with Gentoo
Aug 3, 2026
6a9b082
dev-build/meson: Sync with Gentoo
Aug 3, 2026
186fba9
dev-debug/strace: Sync with Gentoo
Aug 3, 2026
e8e4b74
dev-lang/go: Sync with Gentoo
Aug 3, 2026
987b46b
dev-lang/nasm: Sync with Gentoo
Aug 3, 2026
7ae9d08
dev-lang/perl: Sync with Gentoo
Aug 3, 2026
5aa65fd
dev-lang/python: Sync with Gentoo
Aug 3, 2026
e384c15
dev-lang/rust: Sync with Gentoo
Aug 3, 2026
a7b1184
dev-lang/rust-bin: Sync with Gentoo
Aug 3, 2026
8df6310
dev-lang/rust-common: Sync with Gentoo
Aug 3, 2026
94b4838
dev-libs/expat: Sync with Gentoo
Aug 3, 2026
8bef1e9
dev-libs/jansson: Sync with Gentoo
Aug 3, 2026
7227acc
dev-libs/json-c: Sync with Gentoo
Aug 3, 2026
232e85d
dev-libs/jsoncpp: Sync with Gentoo
Aug 3, 2026
2236cbc
dev-libs/libffi: Sync with Gentoo
Aug 3, 2026
a62f9f1
dev-libs/libgcrypt: Sync with Gentoo
Aug 3, 2026
df80a9a
dev-libs/libgpg-error: Sync with Gentoo
Aug 3, 2026
d91cb37
dev-libs/libpcre2: Sync with Gentoo
Aug 3, 2026
34169e7
dev-libs/libuv: Sync with Gentoo
Aug 3, 2026
08a4582
dev-libs/opensc: Sync with Gentoo
Aug 3, 2026
7588827
dev-libs/tree-sitter: Sync with Gentoo
Aug 3, 2026
a9ede7c
dev-python/certifi: Sync with Gentoo
Aug 3, 2026
8146a6c
dev-python/cffi: Sync with Gentoo
Aug 3, 2026
ce845bd
dev-python/chardet: Sync with Gentoo
Aug 3, 2026
fe90e16
dev-python/charset-normalizer: Sync with Gentoo
Aug 3, 2026
f675f48
dev-python/colorama: Sync with Gentoo
Aug 3, 2026
7b881fc
dev-python/cryptography: Sync with Gentoo
Aug 3, 2026
79ccbe1
dev-python/cython: Sync with Gentoo
Aug 3, 2026
09e9f8f
dev-python/dependency-groups: Sync with Gentoo
Aug 3, 2026
8432edf
dev-python/distlib: Sync with Gentoo
Aug 3, 2026
119d5f4
dev-python/distro: Sync with Gentoo
Aug 3, 2026
630e0d3
dev-python/ensurepip-pip: Sync with Gentoo
Aug 3, 2026
ea9c7ed
dev-python/ensurepip-setuptools: Sync with Gentoo
Aug 3, 2026
fb6a76e
dev-python/fasteners: Sync with Gentoo
Aug 3, 2026
7d1e831
dev-python/fastjsonschema: Sync with Gentoo
Aug 3, 2026
3be3aec
dev-python/gpep517: Sync with Gentoo
Aug 3, 2026
d1d5c98
dev-python/hatchling: Sync with Gentoo
Aug 3, 2026
dfa5394
dev-python/jaraco-functools: Sync with Gentoo
Aug 3, 2026
70b3235
dev-python/jaraco-text: Sync with Gentoo
Aug 3, 2026
7fc62e6
dev-python/jinja2: Sync with Gentoo
Aug 3, 2026
20bc399
dev-python/lark: Sync with Gentoo
Aug 3, 2026
c05315c
dev-python/lazy-object-proxy: Sync with Gentoo
Aug 3, 2026
c00996b
dev-python/linkify-it-py: Sync with Gentoo
Aug 3, 2026
af33a22
dev-python/lxml: Sync with Gentoo
Aug 3, 2026
9833a2e
dev-python/markdown-it-py: Sync with Gentoo
Aug 3, 2026
0ddf062
dev-python/mdurl: Sync with Gentoo
Aug 3, 2026
b24fce1
dev-python/msgpack: Sync with Gentoo
Aug 3, 2026
f5ac080
dev-python/pip: Sync with Gentoo
Aug 3, 2026
3e163e0
dev-python/pkg-resources: Sync with Gentoo
Aug 3, 2026
8229d24
dev-python/platformdirs: Sync with Gentoo
Aug 3, 2026
15c5c33
dev-python/poetry-core: Sync with Gentoo
Aug 3, 2026
6626250
dev-python/pygments: Sync with Gentoo
Aug 3, 2026
5093ac5
dev-python/pysocks: Sync with Gentoo
Aug 3, 2026
2f2f8b1
dev-python/requests: Sync with Gentoo
Aug 3, 2026
c0f8f20
dev-python/resolvelib: Sync with Gentoo
Aug 3, 2026
4819a66
dev-python/rich: Sync with Gentoo
Aug 3, 2026
83a999d
dev-python/setuptools: Sync with Gentoo
Aug 3, 2026
c5d6697
dev-python/setuptools-scm: Sync with Gentoo
Aug 3, 2026
c54ed12
dev-python/snakeoil: Sync with Gentoo
Aug 3, 2026
c6c60e1
dev-python/truststore: Sync with Gentoo
Aug 3, 2026
baddb2e
dev-python/typing-extensions: Sync with Gentoo
Aug 3, 2026
5397904
dev-python/uc-micro-py: Sync with Gentoo
Aug 3, 2026
7ce9dde
dev-python/urllib3: Sync with Gentoo
Aug 3, 2026
6f5fe39
dev-python/vcs-versioning: Sync with Gentoo
Aug 3, 2026
9b48332
dev-util/maturin: Sync with Gentoo
Aug 3, 2026
8e83fd2
dev-util/patchelf: Sync with Gentoo
Aug 3, 2026
9566bd2
dev-util/pkgcheck: Sync with Gentoo
Aug 3, 2026
5bea78e
dev-util/pkgconf: Sync with Gentoo
Aug 3, 2026
bc34246
dev-util/xdelta: Sync with Gentoo
Aug 3, 2026
263e2a6
eclass/cargo: Sync with Gentoo
Aug 3, 2026
089c32d
eclass/go-module: Sync with Gentoo
Aug 3, 2026
f665d95
eclass/kernel-2: Sync with Gentoo
Aug 3, 2026
c20b22c
eclass/llvm-r1: Sync with Gentoo
Aug 3, 2026
344142a
eclass/llvm-r2: Sync with Gentoo
Aug 3, 2026
57f83c0
eclass/llvm: Sync with Gentoo
Aug 3, 2026
3e57ff0
eclass/python-utils-r1: Sync with Gentoo
Aug 3, 2026
125f2f5
eclass/qmake-utils: Sync with Gentoo
Aug 3, 2026
452a848
eclass/qt-utils: Sync with Gentoo
Aug 3, 2026
e5eb23c
eclass/rust: Sync with Gentoo
Aug 3, 2026
07d0032
eclass/selinux-policy-2: Sync with Gentoo
Aug 3, 2026
16c848f
eclass/xorg-3: Sync with Gentoo
Aug 3, 2026
49373a7
net-dns/bind: Sync with Gentoo
Aug 3, 2026
84cfa0d
net-dns/c-ares: Sync with Gentoo
Aug 3, 2026
a593fef
net-dns/dnsmasq: Sync with Gentoo
Aug 3, 2026
899b3dc
net-firewall/ipset: Sync with Gentoo
Aug 3, 2026
08fdbd5
net-fs/cifs-utils: Sync with Gentoo
Aug 3, 2026
32c6522
net-fs/samba: Sync with Gentoo
Aug 3, 2026
529b9ba
net-libs/nghttp2: Sync with Gentoo
Aug 3, 2026
d903ce9
net-libs/ngtcp2: Sync with Gentoo
Aug 3, 2026
4db3d42
net-misc/curl: Sync with Gentoo
Aug 3, 2026
a7969dc
net-misc/passt: Sync with Gentoo
Aug 3, 2026
bc3a618
net-misc/socat: Sync with Gentoo
Aug 3, 2026
b9fef68
profiles: Sync with Gentoo
Aug 3, 2026
c236868
sec-policy/selinux-base: Sync with Gentoo
Aug 3, 2026
9be8283
sec-policy/selinux-base-policy: Sync with Gentoo
Aug 3, 2026
daa9e5f
sec-policy/selinux-container: Sync with Gentoo
Aug 3, 2026
c5bf26c
sec-policy/selinux-dbus: Sync with Gentoo
Aug 3, 2026
a8f4370
sec-policy/selinux-policykit: Sync with Gentoo
Aug 3, 2026
f37f245
sec-policy/selinux-sssd: Sync with Gentoo
Aug 3, 2026
28fef41
sec-policy/selinux-unconfined: Sync with Gentoo
Aug 3, 2026
2d3a345
sys-apps/acl: Sync with Gentoo
Aug 3, 2026
29ecd68
sys-apps/file: Sync with Gentoo
Aug 3, 2026
4b51677
sys-apps/findutils: Sync with Gentoo
Aug 3, 2026
f82c8b4
sys-apps/gawk: Sync with Gentoo
Aug 3, 2026
5df61ab
sys-apps/less: Sync with Gentoo
Aug 3, 2026
cd6fd40
sys-apps/pkgcore: Sync with Gentoo
Aug 3, 2026
35073c2
sys-apps/portage: Sync with Gentoo
Aug 3, 2026
4916004
sys-apps/sandbox: Sync with Gentoo
Aug 3, 2026
31da57b
sys-apps/sed: Sync with Gentoo
Aug 3, 2026
baa1378
sys-apps/shadow: Sync with Gentoo
Aug 3, 2026
97127e3
sys-apps/util-linux: Sync with Gentoo
Aug 3, 2026
047cbae
sys-auth/pambase: Sync with Gentoo
Aug 3, 2026
bf1c4d9
sys-auth/sssd: Sync with Gentoo
Aug 3, 2026
6183663
sys-block/thin-provisioning-tools: Sync with Gentoo
Aug 3, 2026
decdfe9
sys-devel/dwz: Sync with Gentoo
Aug 3, 2026
e8d644b
sys-devel/gcc: Sync with Gentoo
Aug 3, 2026
81ab530
sys-devel/gettext: Sync with Gentoo
Aug 3, 2026
02fa138
sys-fs/btrfs-progs: Sync with Gentoo
Aug 3, 2026
4c2e3e4
sys-fs/cryptsetup: Sync with Gentoo
Aug 3, 2026
220dedd
sys-fs/fuse-overlayfs: Sync with Gentoo
Aug 3, 2026
56a0310
sys-fs/lxcfs: Sync with Gentoo
Aug 3, 2026
12eb714
sys-fs/zfs: Sync with Gentoo
Aug 3, 2026
d49891c
sys-kernel/dracut: Sync with Gentoo
Aug 3, 2026
e57de54
sys-libs/glibc: Sync with Gentoo
Aug 3, 2026
52e8759
sys-libs/libnvme: Sync with Gentoo
Aug 3, 2026
9211e06
sys-libs/libseccomp: Sync with Gentoo
Aug 3, 2026
fea3157
sys-libs/libxcrypt: Sync with Gentoo
Aug 3, 2026
f7b0e11
sys-libs/timezone-data: Sync with Gentoo
Aug 3, 2026
258670e
sys-process/lsof: Sync with Gentoo
Aug 3, 2026
d79e507
sys-process/time: Sync with Gentoo
Aug 3, 2026
c2e6944
virtual/service-manager: Sync with Gentoo
Aug 3, 2026
09b1371
x11-drivers/nvidia-drivers: Sync with Gentoo
Aug 3, 2026
9aa5264
overlay profiles: Add some accept keywords
krnowak Aug 3, 2026
02a9d8f
dev-libs/blake3: Add from Gentoo
krnowak Aug 3, 2026
824cd8a
.github: Add packages to automation
krnowak Aug 3, 2026
2fcf9e9
overlay profiles: Disable USE=initramfs for sys-fs/zfs
krnowak Aug 3, 2026
cd3fff1
app-containers/container-libs: Sync with Gentoo
krnowak Aug 3, 2026
c7464a7
app-containers/containers-shortnames: Add from Gentoo
krnowak Aug 4, 2026
6a2477d
.github: Add app-containers/containers-shortnames to automation
krnowak Aug 4, 2026
409a03e
overlay profiles: Update accept keywords for app-containers/container…
krnowak Aug 4, 2026
01dfd58
overlay profiles: Add accept keywords to address CVEs
krnowak Aug 4, 2026
88742b0
overlay coreos/user-patches: Add patches for net-misc/wget
krnowak Aug 4, 2026
f56d72f
sys-apps/policycoreutils: Sync with Gentoo
krnowak Aug 4, 2026
e39828e
sys-apps/policycoreutils: Apply Flatcar modifications
tormath1 Jun 12, 2023
df704dc
sys-libs/libsemanage: Sync with Gentoo
krnowak Aug 4, 2026
60c0249
sys-libs/libsemanage: Apply flatcar patches
tormath1 Jun 12, 2023
5d4debd
overlay profiles: Add accept keywords for sys-apps/policycoreutils deps
krnowak Aug 4, 2026
9f38bf3
overlay coreos/user-patches: Add a patch for dev-libs/libxml2
krnowak Aug 4, 2026
65162a0
overlay coreos/user-patches: Add a patch for sys-libs/pam
krnowak Aug 4, 2026
86e12dc
overlay coreos/user-patches: Add patches for sys-auth/sssd
krnowak Aug 5, 2026
5b069f3
overlay coreos/user-patches: Add a patch for app-arch/bzip2
krnowak Aug 5, 2026
60130a0
overlay user-patches: Add a patch for app-crypt/mit-krb5
krnowak Aug 5, 2026
4d6596c
overlay profiles: Add/update accept keywords for security issues
krnowak Aug 6, 2026
788e391
overlay user-patches: Add a patch for sys-apps/diffutils
krnowak Aug 6, 2026
b4c7d33
overlay profiles: Drop accept keywords for app-arch/libarchive
krnowak Aug 6, 2026
c46af11
overlay coreos/user-patches: Add patches for sys-apps/coreutils
krnowak Aug 6, 2026
effba9d
overlay coreos/user-patches: Update some READMEs
krnowak Aug 6, 2026
4b96c18
overlay profiles: Drop accept keywords for net-libs/nghttp2
krnowak Aug 6, 2026
b0d936e
overlay profiles: Drop accept keywords for net-libs/ngtcp2
krnowak Aug 6, 2026
a7258bf
overlay profiles: Drop accept keywords for net-misc/curl
krnowak Aug 6, 2026
6214515
overlay coreos/user-patches: Drop duplicated patches for selinux poli…
krnowak Aug 7, 2026
7bf9d3b
sys-block/thin-provisioning-tool: Move LLVM_COMPAT change from ebuild…
krnowak Aug 7, 2026
5f2a3dd
overlay profiles: Drop settings for sys-fs/zfs-kmod
krnowak Aug 7, 2026
828dfab
overlay coreos/config: Move overrides from sys-fs/zfs-kmod to sys-fs/zfs
krnowak Aug 7, 2026
58723f2
net-dns/bind: Reinstate our modifications
krnowak Aug 10, 2026
fe265d8
overlay coreos/config: Minor cleanups in net-dns/bind modifications
krnowak Aug 11, 2026
47911ff
overlay coreos/user-patches: Drop unnecessary patch
krnowak Aug 11, 2026
7dcf785
overlay coreos/config: Do not build tests and docs in sys-apps/diffutils
krnowak Aug 12, 2026
6a03e4a
overlay coreos/config: Relax perms to tmpfiles config file from sys-f…
krnowak Aug 12, 2026
265b104
build_library/build_image_util: Workaround for a regression in setfil…
krnowak Aug 13, 2026
78e6abc
changelog: Add entries
krnowak Aug 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .github/workflows/portage-stable-packages-list
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,9 @@ app-cdr/cdrtools
app-containers/aardvark-dns
app-containers/catatonit
app-containers/conmon
app-containers/container-libs
app-containers/containerd
app-containers/containers-shortnames
app-containers/cri-tools
app-containers/crun
app-containers/docker
Expand Down Expand Up @@ -239,6 +241,7 @@ dev-lang/swig
dev-lang/tcl
dev-lang/yasm

dev-libs/blake3
dev-libs/cJSON
dev-libs/cowsql
dev-libs/cyrus-sasl
Expand Down
9 changes: 6 additions & 3 deletions build_library/build_image_util.sh
Original file line number Diff line number Diff line change
Expand Up @@ -682,11 +682,14 @@ EOF
# The labeling has to be done before moving /etc to /usr/share/flatcar/etc to prevent wrong labels for these files and as
# the relabeling on boot would cause upcopies in the overlay.
if pkg_use_enabled coreos-base/coreos selinux; then
# setfiles from version 3.11 requires the passed path to have no symlinks
local real_root_fs_dir
real_root_fs_dir=$(realpath "${root_fs_dir}")
# TODO: Breaks the system:
# sudo setfiles -Dv -r "${root_fs_dir}" "${root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${root_fs_dir}"
# sudo setfiles -Dv -r "${root_fs_dir}" "${root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${root_fs_dir}"/usr
# sudo setfiles -Dv -r "${real_root_fs_dir}" "${real_root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${real_root_fs_dir}"
# sudo setfiles -Dv -r "${real_root_fs_dir}" "${real_root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${real_root_fs_dir}"/usr
# For now we only try it with /etc
sudo setfiles -Dv -r "${root_fs_dir}" "${root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${root_fs_dir}"/etc
sudo setfiles -Dv -r "${real_root_fs_dir}" "${real_root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${real_root_fs_dir}"/etc
fi

# Temporary hack: set group ownership of /etc/{g,}shadow to the
Expand Down
27 changes: 27 additions & 0 deletions changelog/security/2026-08-07-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
- bzip2 ([CVE-2026-42250](https://www.cve.org/CVERecord/?id=CVE-2026-42250))
- c-ares ([CVE-2026-33630](https://www.cve.org/CVERecord/?id=CVE-2026-33630), [GHSA-pjmc-gx33-gc76](https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76), [GHSA-jv8r-gqr9-68wj](https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj))
- containerd ([CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186), [CVE-2026-34986](https://www.cve.org/CVERecord/?id=CVE-2026-34986), [CVE-2026-35469](https://www.cve.org/CVERecord/?id=CVE-2026-35469), [CVE-2026-39883](https://www.cve.org/CVERecord/?id=CVE-2026-39883))
- coreutils ([CVE-2026-56391](https://www.cve.org/CVERecord/?id=CVE-2026-56391), [CVE-2026-56392](https://www.cve.org/CVERecord/?id=CVE-2026-56392))
- cri-tools ([CVE-2026-32285](https://www.cve.org/CVERecord/?id=CVE-2026-32285), [CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186))
- diffutils ([CVE-2026-53910](https://www.cve.org/CVERecord/?id=CVE-2026-53910))
- docker ([CVE-2026-24051](https://www.cve.org/CVERecord/?id=CVE-2026-24051), [CVE-2026-33186](https://www.cve.org/CVERecord/?id=CVE-2026-33186), [CVE-2026-33997](https://www.cve.org/CVERecord/?id=CVE-2026-33997), [CVE-2026-34040](https://www.cve.org/CVERecord/?id=CVE-2026-34040), [CVE-2026-39883](https://www.cve.org/CVERecord/?id=CVE-2026-39883), [CVE-2026-41567](https://www.cve.org/CVERecord/?id=CVE-2026-41567), [CVE-2026-42306](https://www.cve.org/CVERecord/?id=CVE-2026-42306), [CVE-2026-33747](https://www.cve.org/CVERecord/?id=CVE-2026-33747), [CVE-2026-33748](https://www.cve.org/CVERecord/?id=CVE-2026-33748))
- docker-buildx ([CVE-2025-0495](https://www.cve.org/CVERecord/?id=CVE-2025-0495))
- go ([CVE-2026-27145](https://www.cve.org/CVERecord/?id=CVE-2026-27145), [CVE-2026-39822](https://www.cve.org/CVERecord/?id=CVE-2026-39822), [CVE-2026-42504](https://www.cve.org/CVERecord/?id=CVE-2026-42504), [CVE-2026-42505](https://www.cve.org/CVERecord/?id=CVE-2026-42505), [CVE-2026-42507](https://www.cve.org/CVERecord/?id=CVE-2026-42507))
- gzip ([CVE-2026-41991](https://www.cve.org/CVERecord/?id=CVE-2026-41991))
- jq ([CVE-2026-32316](https://www.cve.org/CVERecord/?id=CVE-2026-32316), [CVE-2026-33947](https://www.cve.org/CVERecord/?id=CVE-2026-33947), [CVE-2026-33948](https://www.cve.org/CVERecord/?id=CVE-2026-33948), [CVE-2026-39956](https://www.cve.org/CVERecord/?id=CVE-2026-39956), [CVE-2026-39979](https://www.cve.org/CVERecord/?id=CVE-2026-39979), [CVE-2026-40164](https://www.cve.org/CVERecord/?id=CVE-2026-40164), [CVE-2026-41256](https://www.cve.org/CVERecord/?id=CVE-2026-41256), [CVE-2026-41257](https://www.cve.org/CVERecord/?id=CVE-2026-41257), [CVE-2026-43894](https://www.cve.org/CVERecord/?id=CVE-2026-43894), [CVE-2026-43895](https://www.cve.org/CVERecord/?id=CVE-2026-43895), [CVE-2026-43896](https://www.cve.org/CVERecord/?id=CVE-2026-43896), [CVE-2026-44777](https://www.cve.org/CVERecord/?id=CVE-2026-44777), [CVE-2026-47770](https://www.cve.org/CVERecord/?id=CVE-2026-47770), [CVE-2026-49839](https://www.cve.org/CVERecord/?id=CVE-2026-49839), [CVE-2026-54679](https://www.cve.org/CVERecord/?id=CVE-2026-54679))
- json-c ([CVE-2026-9146](https://www.cve.org/CVERecord/?id=CVE-2026-9146))
- libxml2 ([CVE-2026-11979](https://www.cve.org/CVERecord/?id=CVE-2026-11979))
- mit-krb5 ([CVE-2026-40355](https://www.cve.org/CVERecord/?id=CVE-2026-40355), [CVE-2026-40356](https://www.cve.org/CVERecord/?id=CVE-2026-40356))
- opensc ([CVE-2025-13763](https://www.cve.org/CVERecord/?id=CVE-2025-13763), [CVE-2025-49010](https://www.cve.org/CVERecord/?id=CVE-2025-49010), [CVE-2025-66037](https://www.cve.org/CVERecord/?id=CVE-2025-66037), [CVE-2025-66038](https://www.cve.org/CVERecord/?id=CVE-2025-66038), [CVE-2025-66215](https://www.cve.org/CVERecord/?id=CVE-2025-66215))
- p11-kit ([CVE-2026-13757](https://www.cve.org/CVERecord/?id=CVE-2026-13757))
- pam ([CVE-2026-54411](https://www.cve.org/CVERecord/?id=CVE-2026-54411))
- policycoreutils ([CVE-2026-59676](https://www.cve.org/CVERecord/?id=CVE-2026-59676), [CVE-2026-59677](https://www.cve.org/CVERecord/?id=CVE-2026-59677))
- qemu ([CVE-2026-3886](https://www.cve.org/CVERecord/?id=CVE-2026-3886))
- socat ([CVE-2026-56123](https://www.cve.org/CVERecord/?id=CVE-2026-56123))
- sssd ([CVE-2026-12610](https://www.cve.org/CVERecord/?id=CVE-2026-12610), [CVE-2026-14474](https://www.cve.org/CVERecord/?id=CVE-2026-14474), [CVE-2026-14476](https://www.cve.org/CVERecord/?id=CVE-2026-14476))
- util-linux ([CVE-2026-13595](https://www.cve.org/CVERecord/?id=CVE-2026-13595), [CVE-2026-53612](https://www.cve.org/CVERecord/?id=CVE-2026-53612), [CVE-2026-53613](https://www.cve.org/CVERecord/?id=CVE-2026-53613), [CVE-2026-53614](https://www.cve.org/CVERecord/?id=CVE-2026-53614))
- wget ([CVE-2026-15146](https://www.cve.org/CVERecord/?id=CVE-2026-15146), [CVE-2026-58469](https://www.cve.org/CVERecord/?id=CVE-2026-58469), [CVE-2026-58470](https://www.cve.org/CVERecord/?id=CVE-2026-58470), [CVE-2026-58471](https://www.cve.org/CVERecord/?id=CVE-2026-58471), [CVE-2026-58472](https://www.cve.org/CVERecord/?id=CVE-2026-58472))
- tpm2-tools (GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66, GHSA-qp88-8f4j-wv7q)
- tpm2-tss (GHSA-q759-vqg7-8rc5, GHSA-7638-f8gq-c475, GHSA-p3px-r4mm-jpw5, GHSA-x5j2-26fc-hhc3, GHSA-gf8g-2r5c-74c7, GHSA-mj78-pj5v-wvjx, GHSA-v2qp-xh5m-44mf, GHSA-2q5v-c7hv-fvpf, GHSA-pcpw-8625-jqcp, GHSA-6grq-c24j-xcjr)
- less ([less-20260606](https://greenwoodsoftware.com/less/news.704.html))
- libseccomp ([GHSA-2hqh-5c36-grrm](https://github.com/seccomp/libseccomp/security/advisories/GHSA-2hqh-5c36-grrm), [GHSA-46fr-jh49-xvhx](https://github.com/seccomp/libseccomp/security/advisories/GHSA-46fr-jh49-xvhx), [GHSA-4q85-33p6-j5g6](https://github.com/seccomp/libseccomp/security/advisories/GHSA-4q85-33p6-j5g6))
49 changes: 49 additions & 0 deletions changelog/updates/2026-08-07-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
- SDK: cmake ([4.3.4](https://cmake.org/cmake/help/v4.3/release/4.3.html#id4))
- SDK: go ([1.26.5](https://go.dev/doc/devel/release#go1.26.5) (includes [1.26.4](https://go.dev/doc/devel/release#go1.26.4)))
- SDK: nasm ([3.02](https://www.nasm.us/docs/3.02/nasmac.html))
- SDK: opensc ([0.27.1](https://github.com/OpenSC/OpenSC/releases/tag/0.27.1))
- SDK: pkgcheck ([0.10.40](https://github.com/pkgcore/pkgcheck/releases/tag/v0.10.40))
- SDK: qemu ([10.2.3](https://lists.gnu.org/archive/html/qemu-stable/2026-05/msg00654.html))
- base, dev: acl ([2.4.0](https://cgit.git.savannah.nongnu.org/cgit/acl.git/plain/doc/CHANGES?h=v2.4.0))
- base, dev: attr ([2.6.0](https://cgit.git.savannah.nongnu.org/cgit/attr.git/plain/doc/CHANGES?h=v2.6.0))
- base, dev: c-ares ([1.34.8](https://github.com/c-ares/c-ares/releases/tag/v1.34.8) (includes [1.34.7](https://github.com/c-ares/c-ares/releases/tag/v1.34.7)))
- base, dev: cri-tools ([1.36.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.36.0) (includes [1.35.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.35.0), [1.34.0](https://github.com/kubernetes-sigs/cri-tools/releases/tag/v1.34.0)))
- base, dev: jq ([1.8.2](https://github.com/jqlang/jq/releases/tag/jq-1.8.2))
- base, dev: json-c ([0.19](https://raw.githubusercontent.com/json-c/json-c/refs/heads/json-c-0.19/ChangeLog))
- base, dev: less ([704](https://greenwoodsoftware.com/less/news.704.html) (includes [702](https://greenwoodsoftware.com/less/news.702.html)))
- base, dev: libarchive ([3.8.9](https://github.com/libarchive/libarchive/releases/tag/v3.8.9))
- base, dev: libgpg-error ([1.61](https://dev.gnupg.org/T8239.html))
- base, dev: libnvme ([1.16.2](https://github.com/linux-nvme/libnvme/releases/tag/v1.16.2))
- base, dev: libseccomp ([2.6.1](https://github.com/seccomp/libseccomp/releases/tag/v2.6.1))
- base, dev: libselinux ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: libsemanage ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11) (includes [3.10](https://github.com/SELinuxProject/selinux/releases/tag/3.10), [3.9](https://github.com/SELinuxProject/selinux/releases/tag/3.9)))
- base, dev: libsepol ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: nghttp2 ([1.69.0](https://github.com/nghttp2/nghttp2/releases/tag/v1.69.0))
- base, dev: ngtcp2 ([1.24.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.24.0) (includes [1.23.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.23.0)))
- base, dev: openssh ([10.4_p1](https://www.openssh.org/txt/release-10.4))
- base, dev: p11-kit ([0.26.4](https://github.com/p11-glue/p11-kit/releases/tag/0.26.4) (includes [0.26.3](https://github.com/p11-glue/p11-kit/releases/tag/0.26.3)))
- base, dev: policycoreutils ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11) (includes [3.10](https://github.com/SELinuxProject/selinux/releases/tag/3.10), [3.9](https://github.com/SELinuxProject/selinux/releases/tag/3.9)))
- base, dev: samba ([4.24.4](https://www.samba.org/samba/history/samba-4.24.4.html) (includes [4.24.3](https://www.samba.org/samba/history/samba-4.24.3.html), [4.24.2](https://www.samba.org/samba/history/samba-4.24.2.html), [4.24.1](https://www.samba.org/samba/history/samba-4.24.1.html), [4.24.0](https://www.samba.org/samba/history/samba-4.24.0.html)))
- base, dev: semodule-utils ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11))
- base, dev: socat ([1.8.1.3](https://repo.or.cz/socat.git/blob/refs/tags/tag-1.8.1.3:/CHANGES))
- base, dev: sssd ([2.13.1](https://sssd.io/release-notes/sssd-2.13.1.html))
- base, dev: strace ([7.1](https://github.com/strace/strace/releases/tag/v7.1))
- base, dev: tpm2-tools ([5.8](https://github.com/tpm2-software/tpm2-tools/releases/tag/5.8))
- base, dev: tpm2-tss ([4.2.0](https://github.com/tpm2-software/tpm2-tss/releases/tag/4.2.0))
- base, dev: util-linux ([2.42.2](https://github.com/util-linux/util-linux/blob/v2.42.2/Documentation/releases/v2.42.2-ReleaseNotes) (includes [2.42.1](https://github.com/util-linux/util-linux/blob/v2.42.1/Documentation/releases/v2.42.1-ReleaseNotes), [2.42](https://github.com/util-linux/util-linux/blob/v2.42/Documentation/releases/v2.42-ReleaseNotes)))
- dev: file ([5.48](https://raw.githubusercontent.com/file/file/refs/tags/FILE5_48/ChangeLog))
- dev: gentoolkit ([0.7.6](https://gitweb.gentoo.org/proj/gentoolkit.git/log/?h=gentoolkit-0.7.6))
- dev: portage ([3.0.81.2](https://gitweb.gentoo.org/proj/portage.git/plain/NEWS?h=portage-3.0.81.2))
- dev: sandbox ([2.49](https://gitweb.gentoo.org/proj/sandbox.git/log/?h=v2.49))
- sysext-containerd: containerd ([2.3.3](https://github.com/containerd/containerd/releases/tag/v2.3.3) (includes [2.3.2](https://github.com/containerd/containerd/releases/tag/v2.3.2), [2.3.1](https://github.com/containerd/containerd/releases/tag/v2.3.1), [2.3.0](https://github.com/containerd/containerd/releases/tag/v2.3.0)))
- sysext-docker: docker ([29.5.2](https://github.com/moby/moby/releases/tag/docker-v29.5.2) (includes [29.5.1](https://github.com/moby/moby/releases/tag/docker-v29.5.1), [29.5.0](https://github.com/moby/moby/releases/tag/docker-v29.5.0), [29.4.0](https://github.com/moby/moby/releases/tag/docker-v29.4.0), [29.3.0](https://github.com/moby/moby/releases/tag/docker-v29.3.0), [29.2.0](https://github.com/moby/moby/releases/tag/docker-v29.2.0)))
- sysext-docker: docker-buildx ([0.35.0](https://github.com/docker/buildx/releases/tag/v0.35.0))
- sysext-docker: docker-cli ([29.5.2](https://github.com/moby/moby/releases/tag/docker-v29.5.2) (includes [29.5.1](https://github.com/moby/moby/releases/tag/docker-v29.5.1), [29.5.0](https://github.com/moby/moby/releases/tag/docker-v29.5.0), [29.4.0](https://github.com/moby/moby/releases/tag/docker-v29.4.0), [29.3.0](https://github.com/moby/moby/releases/tag/docker-v29.3.0), [29.2.0](https://github.com/moby/moby/releases/tag/docker-v29.2.0)))
- sysext-incus: xdelta ([3.2.0](https://github.com/jmacd/xdelta/releases/tag/v3.2.0))
- sysext-podman: container-libs ([0.69.0](https://github.com/podman-container-tools/container-libs/releases/tag/common%2Fv0.69.0))
- sysext-python: distlib ([0.4.3](https://raw.githubusercontent.com/pypa/distlib/refs/tags/0.4.3/CHANGES.rst))
- sysext-python: msgpack ([1.2.1](https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1) (includes [1.2.0](https://github.com/msgpack/msgpack-python/releases/tag/v1.2.0)))
- sysext-python: setuptools-scm ([10.1.2](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.2) (includes [10.1.1](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.1), [10.1.0](https://github.com/pypa/setuptools-scm/releases/tag/setuptools-scm-v10.1.0)))
- sysext-python: typing-extensions ([4.16.0](https://raw.githubusercontent.com/python/typing_extensions/refs/tags/4.16.0/CHANGELOG.md))
- sysext-python: vcs-versioning ([2.2.2](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.2) (includes [2.2.1](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.1), [2.2.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.2.0), [2.1.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.1.0), [2.0.0](https://github.com/pypa/setuptools-scm/releases/tag/vcs-versioning-v2.0.0)))
- sysext-zfs: zfs ([2.4.3](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.3) (includes [2.4.2](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.2), [2.4.1](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.1), [2.4.0](https://github.com/openzfs/zfs/releases/tag/zfs-2.4.0)))
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Keep only tool binaries and libraries those binaries need.
ndb_install_mask="
INSTALL_MASK+="
/etc
/var
/usr/bin/arpaname
Expand All @@ -13,15 +13,10 @@ ndb_install_mask="
/usr/sbin
"

INSTALL_MASK+="${ndb_install_mask}"
PKG_INSTALL_MASK+="${ndb_install_mask}"

unset ndb_install_mask

# Override fowners to ignore changing owner or group to named. The
# only files that this happens for are files that we have put into
# {PKG_,}INSTALL_MASK. This will help us avoid installing
# acct-user/named and acct-group/named.
# INSTALL_MASK. This will help us avoid installing acct-user/named and
# acct-group/named.
if [[ -z ${flatcar_hacked_fowners:-} ]]; then
flatcar_hacked_fowners=$(command -v fowners)
fi
Expand All @@ -35,10 +30,10 @@ fowners() {
# The pkg_postinst phase function wants to generate an rndc.key file
# with /usr/sbin/rndc-confgen script if the key file is missing, then
# change the ownership to the named group. We don't need the key file
# at all as it's presumably for named. Also, we masked the installtion
# of the script. Thus we fool the phase function by putting an empty
# key file there, so the function won't trigger the generation. We
# drop the key file later too.
# at all as it's presumably for named. Also, we masked the
# installation of the script. Thus we fool the phase function by
# putting an empty key file there, so the function won't trigger the
# generation. We drop the key file later too.
cros_pre_pkg_postinst_add_fake_rndc_key() {
local dir="${EROOT}/etc/bind"
if [[ ! -d "${dir}" ]]; then
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
cros_post_src_prepare_no_docs_and_tests() {
# Do not build tests nor docs. Building docs involves running the
# built diff3, which is an additional hurdle when cross-compiling.
sed -i -e 's/ tests\b//' -e 's/ doc\b//' -e 's/ man\b//' -e 's/ gnulib-tests\b//' Makefile.in
}
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,11 @@ export ECARGO_EXTRA_ARGS=--no-default-features
# read-only so that it forcibly overrides the ebuild. Note that this doesn't
# avoid pulling in another rust(-bin) version, but it does avoid it being used.
declare -gr RUST_NEEDS_LLVM=

# Avoid using incompatible rust-bin. Our dev-lang/rust build is
# configured for cross-compiling, while dev-lang/rust-bin is not. The
# latter will be pulled in because of RUST_NEEDS_LLVM=1, but we don't
# need LLVM for our build. The env change above avoids using rust-bin,
# but it cannot avoid pulling it in. This change does that. Probably
# makes RUST_NEEDS_LLVM override unnecessary, but whatever.
declare -gra LLVM_COMPAT=( {19..22} )
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
cros_post_src_install_tmpfiles_perms() {
if [[ $(flatcar_target) != 'sdk' ]]; then
# Upstream installs its tmpfiles config file with unnecessarilly
# restrictive mode, relax it. It could be also fixed by passing
# --enable-write_install option to configure script, but that
# would affect a lot of other files too.
fperms 0644 /usr/lib/tmpfiles.d/lvm2.conf
fi
}
Original file line number Diff line number Diff line change
@@ -1,3 +1,15 @@
# This addresses an issue with the kernel version compatibility check
# when installing zfs modules to /build/<arch> (e.g. via build_packages)
# from its binpkg (i.e. not recompiling it).
SKIP_KERNEL_BINPKG_ENV_RESET=1

# Necessary to prevent KV_FULL & KV_OUT_DIR from being unset
# when building Kernel modules for sysext. See also eclass/linux-info.eclass.
cros_pre_pkg_setup_kernel_version() {
LINUX_INFO_BINARY_RESET=1
get_version
}

cros_post_src_install_rm_systemd_masks() {
rm "${D}$(systemd_get_systemunitdir)"/zfs-load-key.service
rm "${D}$(systemd_get_systemunitdir)"/zfs-import.service
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
From 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 Mon Sep 17 00:00:00 2001
From: Mark Wielaard <mark@klomp.org>
Date: Thu, 28 May 2026 16:15:45 +0200
Subject: [PATCH] bzip2recover: Make sure to not process more than
BZ_MAX_HANDLED_BLOCKS

There is an off-by-one in the check before calling tooManyBlocks. This
causes the scanning loop to run one more time and cause a possible
read or write one past the global bStart, bEnd, rbStart and rbEnd
buffers. There are no known exploits of this issue and you will need
to compile with something like gcc -fsanitize=address (ASAN
AddressSanitizer) to observe the faulty read/write.

This has been assigned CVE-2026-42250.
---
bzip2recover.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/bzip2recover.c b/bzip2recover.c
index a8131e0..4b1c219 100644
--- a/bzip2recover.c
+++ b/bzip2recover.c
@@ -402,7 +402,7 @@ Int32 main ( Int32 argc, Char** argv )
rbEnd[rbCtr] = bEnd[currBlock];
rbCtr++;
}
- if (currBlock >= BZ_MAX_HANDLED_BLOCKS)
+ if (currBlock >= BZ_MAX_HANDLED_BLOCKS - 1)
tooManyBlocks(BZ_MAX_HANDLED_BLOCKS);
currBlock++;

Loading