Skip to content

Commit 541bab1

Browse files
authored
Merge pull request #3366 from flatcar/buildbot/weekly-portage-stable-package-updates-2025-10-13
Weekly portage-stable package updates 2025-10-13
2 parents e807b7f + c04d694 commit 541bab1

File tree

509 files changed

+25683
-9814
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

509 files changed

+25683
-9814
lines changed
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
- expat ([CVE-2025-59375](https://www.cve.org/CVERecord?id=CVE-2025-59375))
2+
- intel-microcode ([CVE-2024-28956](https://www.cve.org/CVERecord?id=CVE-2024-28956), [CVE-2024-43420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43420), [CVE-2024-45332](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45332), [CVE-2025-20012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20012), [CVE-2025-20054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20054), [CVE-2025-20103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20103), [CVE-2025-20623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20623), [CVE-2025-24495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24495), [CVE-2025-20053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20053), [CVE-2025-20109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-20109), [CVE-2025-22839](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22839), [CVE-2025-22840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22840), [CVE-2025-22889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22889), [CVE-2025-26403](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-26403))
3+
- nvidia-drivers ([CVE-2025-23280](https://www.cve.org/CVERecord?id=CVE-2025-23280), [CVE-2025-23282](https://www.cve.org/CVERecord?id=CVE-2025-23282), [CVE-2025-23300](https://www.cve.org/CVERecord?id=CVE-2025-23300), [CVE-2025-23330](https://www.cve.org/CVERecord?id=CVE-2025-23330), [CVE-2025-23332](https://www.cve.org/CVERecord?id=CVE-2025-23332), [CVE-2025-23345](https://www.cve.org/CVERecord?id=CVE-2025-23345))
4+
- openssh ([CVE-2025-61984](https://www.cve.org/CVERecord?id=CVE-2025-61984), [CVE-2025-61985](https://www.cve.org/CVERecord?id=CVE-2025-61985))
5+
- openssl ([CVE-2025-9230](https://www.cve.org/CVERecord?id=CVE-2025-9230), [CVE-2025-9231](https://www.cve.org/CVERecord?id=CVE-2025-9231), [CVE-2025-9232](https://www.cve.org/CVERecord?id=CVE-2025-9232))
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
- SDK: cmake ([3.31.9](https://cmake.org/cmake/help/v3.31/release/3.31.html#id1))
2+
- SDK: go ([1.25.1](https://go.dev/doc/devel/release#go1.25.minor) (includes [1.25](https://go.dev/doc/go1.25)))
3+
- SDK: qemu ([10.0.5](https://wiki.qemu.org/ChangeLog/10.0))
4+
- azure, dev: inotify-tools ([4.25.9.0](https://github.com/inotify-tools/inotify-tools/releases/tag/4.25.9.0))
5+
- azure, stackit: chrony ([4.8](https://gitlab.com/chrony/chrony/-/raw/4.8/NEWS))
6+
- base, dev: bind ([9.18.38](https://bind9.readthedocs.io/en/v9.18.38/notes.html#notes-for-bind-9-18-38))
7+
- base, dev: bpftool ([7.6.0](https://github.com/libbpf/bpftool/releases/tag/v7.6.0))
8+
- base, dev: btrfs-progs ([6.16.1](https://github.com/kdave/btrfs-progs/releases/tag/v6.16.1))
9+
- base, dev: expat ([2.7.3](https://raw.githubusercontent.com/libexpat/libexpat/refs/tags/R_2_7_3/expat/Changes))
10+
- base, dev: gettext ([0.23.2](https://gitweb.git.savannah.gnu.org/gitweb/?p=gettext.git;a=blob_plain;f=NEWS;h=a5cc8a63eb4f06e4a1171afda862812feb67d693;hb=e8e6cb71aec0de1f5758ac21327bb8cd69e33731) (includes [0.23.1](https://gitweb.git.savannah.gnu.org/gitweb/?p=gettext.git;a=blob_plain;f=NEWS;h=4aafedf9b10a66891838e1f35c7af020c6124ee0;hb=d9b0432a825bfe3fc72f9a081d295a9528cd8aac), [0.23.0](https://gitweb.git.savannah.gnu.org/gitweb/?p=gettext.git;a=blob_plain;f=NEWS;h=9d87d45408f510d15856a1dda8a9376573f0a9c5;hb=c12b25dc82104691ca80c4da1cbc538fcab42bf5)))
11+
- base, dev: git ([2.51.0](https://github.com/git/git/blob/v2.51.0/Documentation/RelNotes/2.51.0.adoc) (includes [2.50.0](https://github.com/git/git/blob/v2.50.0/Documentation/RelNotes/2.50.0.adoc)))
12+
- base, dev: intel-microcode ([20250812](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250812) (includes [20250512](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512)))
13+
- base, dev: libxml2 ([2.14.6](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.6) (includes [2.14.5](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.5), [2.14.4](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.4), [2.14.3](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.3), [2.14.2](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.2), [2.14.1](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.1), [2.14.0](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.0)))
14+
- base, dev: nftables ([1.1.5](https://www.netfilter.org/projects/nftables/files/changes-nftables-1.1.5.txt))
15+
- base, dev: nvidia-drivers-service (amd64) ([535.274.02](https://docs.nvidia.com/datacenter/tesla/tesla-release-notes-535-274-02/index.html))
16+
- base, dev: nvidia-drivers-service (arm64) ([570.195.03](https://docs.nvidia.com/datacenter/tesla/tesla-release-notes-570-195-03/index.html))
17+
- base, dev: openssh ([10.2_p1](https://www.openssh.com/txt/release-10.2) (includes [10.1](https://www.openssh.com/txt/release-10.1)))
18+
- base, dev: openssl ([3.4.3](https://github.com/openssl/openssl/releases/tag/openssl-3.4.3))
19+
- base, dev: xfsprogs ([6.16.0](https://web.git.kernel.org/pub/scm/fs/xfs/xfsprogs-dev.git/tree/doc/CHANGES?h=v6.16.0) (includes [6.15.0](https://web.git.kernel.org/pub/scm/fs/xfs/xfsprogs-dev.git/tree/doc/CHANGES?h=v6.15.0)))
20+
- sysext-nvidia-drivers-535, sysext-nvidia-drivers-535-open: nvidia-drivers ([535.274.02](https://docs.nvidia.com/datacenter/tesla/tesla-release-notes-535-274-02/index.html))
21+
- sysext-nvidia-drivers-570, sysext-nvidia-drivers-570-open: nvidia-drivers ([570.195.03](https://docs.nvidia.com/datacenter/tesla/tesla-release-notes-570-195-03/index.html))
22+
- sysext-podman: crun ([1.21](https://github.com/containers/crun/releases/tag/1.21))
23+
- sysext-podman: netavark ([1.15.2](https://github.com/containers/netavark/releases/tag/v1.15.2) (includes [1.15.1](https://github.com/containers/netavark/releases/tag/v1.15.1), [1.15.0](https://github.com/containers/netavark/releases/tag/v1.15.0)))
24+
- sysext-podman: passt ([2025.06.11](https://archives.passt.top/passt-user/20250611175947.7d540ddc@elisabeth/T/#u))
25+
- sysext-python: platformdirs ([4.4.0](https://github.com/tox-dev/platformdirs/releases/tag/4.4.0))
26+
- sysext-python: typing-extensions ([4.15.0](https://raw.githubusercontent.com/python/typing_extensions/refs/tags/4.15.0/CHANGELOG.md))
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
From 2478055bf48a54c0fcb518bbd48a30b307db0009 Mon Sep 17 00:00:00 2001
2+
From: Kerin Millar <[email protected]>
3+
Date: Mon, 18 Aug 2025 14:25:20 +0200
4+
Subject: [PATCH 1/2] Support locale-gen-3 (the perl version)
5+
MIME-Version: 1.0
6+
Content-Type: text/plain; charset=UTF-8
7+
Content-Transfer-Encoding: 8bit
8+
9+
Signed-off-by: Andreas K. Hüttel <[email protected]>
10+
---
11+
targets/stage1/chroot.sh | 6 +++++-
12+
targets/support/chroot-functions.sh | 2 +-
13+
2 files changed, 6 insertions(+), 2 deletions(-)
14+
15+
diff --git a/targets/stage1/chroot.sh b/targets/stage1/chroot.sh
16+
index e0587b59..541c060f 100755
17+
--- a/targets/stage1/chroot.sh
18+
+++ b/targets/stage1/chroot.sh
19+
@@ -91,7 +91,11 @@ run_merge --implicit-system-deps=n --oneshot "${buildpkgs[@]}"
20+
# not run locale-gen when ROOT is set. Since we've set LANG, we need to run
21+
# locale-gen explicitly.
22+
if [ -x "$(command -v locale-gen)" ]; then
23+
- locale-gen --destdir "$ROOT"/ || die "locale-gen failed"
24+
+ if ! locale-gen -V | grep -q '^locale-gen-2\.'; then
25+
+ locale-gen --config /etc/locale.gen --prefix "$ROOT"/
26+
+ else
27+
+ locale-gen --destdir "$ROOT"/
28+
+ fi || die "locale-gen failed"
29+
fi
30+
31+
# Why are we removing these? Don't we need them for final make.conf?
32+
diff --git a/targets/support/chroot-functions.sh b/targets/support/chroot-functions.sh
33+
index d8472d46..08738d0a 100755
34+
--- a/targets/support/chroot-functions.sh
35+
+++ b/targets/support/chroot-functions.sh
36+
@@ -284,7 +284,7 @@ show_debug() {
37+
}
38+
39+
readonly locales="
40+
-C.UTF8 UTF-8
41+
+C.UTF-8 UTF-8
42+
"
43+
44+
if [[ ${RUN_DEFAULT_FUNCS} != no ]]
45+
--
46+
2.51.0
47+
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
From 8f3dad52ef6b7360f69f93554172d76aa5d59d8a Mon Sep 17 00:00:00 2001
2+
From: Sam James <[email protected]>
3+
Date: Mon, 15 Sep 2025 12:35:43 +0100
4+
Subject: [PATCH 2/2] Fix UTF-8 spelling
5+
6+
Bug: https://bugs.gentoo.org/962878
7+
Signed-off-by: Sam James <[email protected]>
8+
---
9+
catalyst/base/stagebase.py | 2 +-
10+
targets/stage1/chroot.sh | 2 +-
11+
2 files changed, 2 insertions(+), 2 deletions(-)
12+
13+
diff --git a/catalyst/base/stagebase.py b/catalyst/base/stagebase.py
14+
index 8a3d2af6..d09b3aad 100644
15+
--- a/catalyst/base/stagebase.py
16+
+++ b/catalyst/base/stagebase.py
17+
@@ -1252,7 +1252,7 @@ class StageBase(TargetBase, ClearBase, GenBase):
18+
'\n'
19+
'# This sets the language of build output to English.\n'
20+
'# Please keep this setting intact when reporting bugs.\n'
21+
- 'LC_MESSAGES=C.utf8\n')
22+
+ 'LC_MESSAGES=C.UTF-8\n')
23+
24+
def write_binrepos_conf(self):
25+
# only if catalyst.conf defines the host and the spec defines the path...
26+
diff --git a/targets/stage1/chroot.sh b/targets/stage1/chroot.sh
27+
index 541c060f..dc8571bd 100755
28+
--- a/targets/stage1/chroot.sh
29+
+++ b/targets/stage1/chroot.sh
30+
@@ -67,7 +67,7 @@ sed -i "/USE=\"${USE} build\"/d" ${clst_make_conf}
31+
32+
echo "$locales" > /etc/locale.gen
33+
for etc in /etc "$ROOT"/etc; do
34+
- echo "LANG=C.UTF8" > ${etc}/env.d/02locale
35+
+ echo "LANG=C.UTF-8" > ${etc}/env.d/02locale
36+
done
37+
update_env_settings
38+
39+
--
40+
2.51.0
41+
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
The patches fix some locale generation issues in catalyst - they are
2+
currently a part of the master branch, so there is no release that
3+
contain those fixes yet.

sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.accept_keywords

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@ app-crypt/azure-keyvault-pkcs11
4040
=app-emulation/open-vmdk-1.0 *
4141

4242
# Keep versions on both arches in sync.
43+
=app-emulation/qemu-10.0.5 ~arm64
4344
=app-emulation/qemu-guest-agent-9.2.0 ~arm64
4445

4546
# Packages are in Gentoo but not expected to be used outside Flatcar, so they
@@ -50,26 +51,17 @@ dev-cpp/azure-identity
5051
dev-cpp/azure-security-keyvault-certificates
5152
dev-cpp/azure-security-keyvault-keys
5253

53-
# CVE-2025-47910
54-
=dev-lang/go-1.24.7 ~amd64 ~arm64
55-
5654
# Keep versions on both arches in sync.
5755
=dev-lang/yasm-1.3.0-r1 ~arm64
5856
=dev-libs/cowsql-1.15.9 ~arm64
5957
=dev-libs/ding-libs-0.6.2-r1 ~arm64
6058

61-
# CVE-2025-59375
62-
=dev-libs/expat-2.7.2 ~amd64 ~arm64
63-
6459
# CVE-2025-7039
6560
=dev-libs/glib-2.84.4 ~amd64 ~arm64
6661

6762
# The only available ebuild (from GURU) has ~amd64 and no keyword for arm64 yet.
6863
=dev-libs/jose-12 **
6964

70-
# CVE-2025-58050
71-
=dev-libs/libpcre2-10.46 ~amd64 ~arm64
72-
7365
# The only available ebuild (from GURU) has ~amd64 and no keyword for arm64 yet.
7466
=dev-libs/luksmeta-9-r1 **
7567

@@ -97,7 +89,10 @@ dev-cpp/azure-security-keyvault-keys
9789
=net-libs/libnetfilter_cttimeout-1.0.1 ~arm64
9890

9991
# CVE-2025-9086, CVE-2025-10148
100-
=net-misc/curl-8.16.0-r1 ~amd64 ~arm64
92+
=net-misc/curl-8.16.0-r1 ~arm64
93+
94+
# CVE-2025-61984, CVE-2025-61985
95+
=net-misc/openssh-10.2_p1 ~amd64 ~arm64
10196

10297
# Packages are in Gentoo but not expected to be used outside Flatcar, so they
10398
# are generally never stabilised. Thus an unusual form is used to pick up the

sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.mask

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,3 @@
2020

2121
# Pulls in LLVM and clang.
2222
>=sys-block/thin-provisioning-tools-1.0.14
23-
24-
# Too large to fit into our /boot partition - the size grew by 3MB. We
25-
# mask a specific version in hope that the future update may be smaller,
26-
# who knows.
27-
=sys-firmware/intel-microcode-20250512_p20250513
28-
=sys-firmware/intel-microcode-20250812_p20250813

sdk_container/src/third_party/portage-stable/app-containers/containerd/Manifest

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,4 @@ DIST containerd-2.0.4.tar.gz 10450939 BLAKE2B f82ed40eab0f1d186f4fb04217b8f75a9d
44
DIST containerd-2.0.5.tar.gz 10452563 BLAKE2B bf03316c9211eaa17a3b40b1fc9f9aca42fe3e621e086e612eb07c286c6b62bc7a0a2426ce7b6742dce2924d570ab599aefb43463c4fa6be277e562bad79668f SHA512 af89a5c9ad5f931c5fee33c75c13c296fc9ec966f2c64ec244897695eebb365bcb542f6b431e60d4ef7213f0ea11d3a8896d1b7f033ed445e6b521b7ddbffe6f
55
DIST containerd-2.1.0.tar.gz 10610618 BLAKE2B 147c21b4650543af9b0e533e381a0505ba927d6e9270b9b03a09016eb3ccf29875db7fa274944fea2ff7b029b6a05a17d14c61e24b5f3426b31f320831eeb46a SHA512 e9bb128917bb6b2e21a8e05344af3fdcdda8620be20e54407bc2c73046278a88a77bcbed6ef7a59099c9ee3303283db46b90b71afdd45236d3c534749ba844e0
66
DIST containerd-2.1.1.tar.gz 10610787 BLAKE2B acc2d769752c783643795d228c0d267b0802e09166dc783e84087da0029a822a64688f5e59c047c47b25f50ca2a1ccb7f5b6216ad6beeb4489df308e525e9716 SHA512 542f7cae61e1ef2e1b529b0bea66d7ad9016d4605de73de9c9c8a738e50ec6f470b939d1546482320515b77424bffe1cf24b721173ac0c0ecd0100c92817cfb1
7+
DIST containerd-2.1.4.tar.gz 10614131 BLAKE2B b8f4007b4bb368a1fa04c913d606f65d2ea4a17a6419ce12f2b6112eee2574d7a09fb8e2500d1c2f21bef8792dc047df4d63446211ae006662e616facda91f24 SHA512 a9f84784e917621ee5ea38ad20b8106e642fbf463a00d319b73a1a8e4d1fdd5be2fba0789b6a5d31107ef239d3713eced99ce979d4b2764714271a63c0936c15

0 commit comments

Comments
 (0)