- All Emacs users should upgrade to the latest version: + All GNU Emacs users should upgrade to the latest version:
# emerge --sync
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml
index 9fb9874f912..00bc45eb7e1 100644
--- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml
+++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml
@@ -1,11 +1,11 @@
- Emacs, org-mode: Command Execution Vulnerability
- A vulnerability has been found in Emacs and org-mode which could result in arbitrary code execution.
+ GNU Emacs, org-mode: Command Execution Vulnerability
+ A vulnerability has been found in GNU Emacs and org-mode which could result in arbitrary code execution.
emacs,org-mode
2024-09-22
- 2024-09-22
+ 2026-08-20
934736
local
@@ -25,7 +25,7 @@
- Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.
+ GNU Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.
%(...) link abbreviations could specify unsafe functions.
@@ -37,7 +37,7 @@
There is no known workaround at this time.
- All Emacs users should upgrade to the latest version according to the installed slot, one of:
+ All GNU Emacs users should upgrade to the latest version according to the installed slot, one of:
# emerge --sync
@@ -69,4 +69,4 @@
ajak
graaff
-
\ No newline at end of file
+Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.
+GNU Emacs is the extensible, customizable, self-documenting real-time display editor.
Multiple vulnerabilities have been discovered in Emacs, org-mode. Please review the CVE identifiers referenced below for details.
+Multiple vulnerabilities have been discovered in GNU Emacs. Please review the CVE identifiers referenced below for details.
Please review the referenced CVE identifiers for details.
@@ -34,7 +34,7 @@There is no known workaround at this time.
All Emacs, org-mode users should upgrade to the latest version:
+All GNU Emacs users should upgrade to the latest version:
# emerge --sync
@@ -50,4 +50,4 @@
graaff
graaff
-The following vulnerabilities have been discovered in Exiv2: 2 out of bounds reads, an integer overflow, and an uncaught exception. The worst of which can lead to a Denial of Service via a crash of the program. Please review the CVE identifiers referenced below for details.
The following is a possible outcome: data leakage via an out-of-bounds read or a Denial of Service via a crash of the program.
FreeType is a software font engine that is designed to be small, efficient, highly customizable, and portable while capable of producing high-quality output (glyph images).
+Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details.
+One of the possible outcomes allows for an out-of-bounds read. Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All FreeType users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3"
+
+ rsync is a server and client utility that provides fast incremental file transfers. It is used to efficiently synchronize files between hosts and is used by emerge to fetch Gentoo's Portage tree.
+Multiple vulnerabilities have been discovered in rsync. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All rsync users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.4.3"
+
+ Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP server.
+Multiple vulnerabilities have been discovered in Dnsmasq. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Dnsmasq users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.92_p2"
+
+ The Apache HTTP server is one of the most popular web servers on the Internet.
+Multiple vulnerabilities have been discovered in Apache HTTPD. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Apache HTTPD users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.68"
+
+ Flatpak is a Linux application sandboxing and distribution framework.
+Multiple vulnerabilities have been discovered in Flatpak. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Flatpak users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/flatpak-1.16.4"
+
+ Exim is a message transfer agent (MTA) designed to be a a highly configurable, drop-in replacement for sendmail.
+Multiple vulnerabilities have been discovered in Exim. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Exim users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=mail-mta/exim-4.99.4"
+
+ A library to handle input devices in Wayland and, via xf86-input-libinput, in X.org.
+Multiple vulnerabilities have been discovered in libinput. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All libinput users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-libs/libinput-1.31.3"
+
+ Bubblewrap is an unprivileged sandboxing tool namespaces-powered chroot-like solution.
+A vulnerability has been discovered in Bubblewrap. Please review the CVE identifier referenced below for details.
+An attacker could achieve root privilege escalation if Bubblewrap is used in its suid mode.
+There is no known workaround at this time.
+All Bubblewrap users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/bubblewrap-0.11.2"
+
+ HTTP-Daemon provides a base class for simple HTTP servers.
+Inconsistent Interpretation of HTTP Requests.
+The bug could potentially be exploited to gain privileged access to APIs or poison intermediate caches.
+There is no known workaround at this time.
+All HTTP-Daemon users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-perl/HTTP-Daemon-6.160.0"
+
+ haveged is a simple entropy daemon using the HAVEGE algorithm.
+A vulnerability has been discovered in haveged. Please review the CVE identifier referenced below for details.
+Root privilege escalation may be achieved by an attacker.
+There is no known workaround at this time.
+All haveged users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/haveged-1.9.21"
+
+
+ Alternatively, consider not using haveged anymore on modern Linux kernel versions, per https://www.openwall.com/lists/oss-security/2026/05/19/4
+Portage is the default Gentoo package management system.
+Multiple vulnerabilities have been discovered in Portage. Please review the bugs referenced below for details. + +The first bug (bug 978478) allows a malicious ebuild (including a build system it uses indirectly) to write outside of the work directory. While malicious artifacts could be installed by a package itself, this is still unexpected if one only ran the configure phrase during development. + +The second bug (bug 979026) is regarding insufficient sandboxing in global scope. Untrusted ebuilds, even if not emerged, may have the opportunity to run code in global scope depending on whether the repository has metadata available. Additional sandboxing has been added.
+Please review the referenced bugs for details.
+Avoid using untrusted repositories or ebuilds, even without installing them.
+All Portage users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/portage-3.0.81.2"
+
+
+ In general, we recommend users add external repositories with caution. If using external repositories, it is good practice to mask all packages by default from that repository, and unmask only needed packages.
+NTFS-3G is a stable, full-featured, read-write NTFS driver for various operating systems.
+Multiple vulnerabilities have been discovered in NTFS-3G. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All NTFS-3G users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-fs/ntfs3g-2026.7.7"
+
+ The X Window System is a graphical windowing system based on a client/server model.
+Multiple vulnerabilities have been discovered in X.Org X server, XWayland. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All X.Org X server, XWayland users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.24"
+
+
+ All X.Org X server, XWayland users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=x11-base/xwayland-24.1.13"
+
+ PostgreSQL is an open source object-relational database management system.
+Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All PostgreSQL 14 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.23-r1:14"
+
+
+ All PostgreSQL 15 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.18-r1:15"
+
+
+ All PostgreSQL 16 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.14-r1:16"
+
+
+ All PostgreSQL 17 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.10:17"
+
+
+ All PostgreSQL 18 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-db/postgresql-18.4:18"
+
+ nginx is a robust, small, and high performance HTTP and reverse proxy server.
+Multiple vulnerabilities have been discovered in nginx. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All nginx users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.30.4-r1"
+
+ libssh2 is a library implementing the SSH2 protocol.
+Multiple vulnerabilities have been discovered in libssh2. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All libssh2 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-libs/libssh2-1.11.1-r2"
+
+ GNU Emacs is the extensible, customizable, self-documenting real-time display editor.
+A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details.
+An attacker could achieve arbitrary code execution by tricking a user into opening a file with malicious content. No other action by the user is required.
+Avoid opening any untrusted files.
+All GNU Emacs 28 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r21:28"
+
+
+ All GNU Emacs 29 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r9:29"
+
+
+ All GNU Emacs 30 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r5:30"
+
+ quickjs-ng is a small and embeddable JavaScript engine. It aims to support the latest ECMAScript specification. It is a fork of QuickJS.
+Multiple vulnerabilities have been discovered in quickjs-ng. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All quickjs-ng users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-libs/quickjs-ng-0.12.0"
+
+ For more information on the packages listed in this GLSA, please see their homepage referenced in the ebuild.
+Multiple vulnerabilities have been discovered in acl and attr. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All acl users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/acl-2.4.0"
+
+
+ All attr users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-apps/attr-2.6.0"
+
+ GNU Emacs is the extensible, customizable, self-documenting real-time display editor.
+A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details.
+An attacker could achieve arbitrary code execution by tricking a user into opening a file or directory with a malicious filename via TRAMP.
+There is no known workaround at this time.
+All GNU Emacs 27 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-27.2-r4:27"
+
+
+ All GNU Emacs 28 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r22:28"
+
+
+ All GNU Emacs 29 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r10:29"
+
+
+ All GNU Emacs 30 users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r6:30"
+
+ needrestart is a tool to restart daemons after library updates.
+Multiple vulnerabilities have been discovered in needrestart. Please review the CVE identifier referenced below for details.
+An attacker could achieve root privilege escalation.
+There is no known workaround at this time.
+All needrestart users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-admin/needrestart-3.8"
+
+ Incus is a container and virtual machine manager.
+Multiple vulnerabilities have been discovered in Incus. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Incus users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-containers/incus-7.0.1-r1"
+
+ DTrace is a dynamic tracing tool for analysing or debugging the whole system. Specifically, dtprobed is a component of the DTrace system that keeps track of USDT probes within running processes, parsing and storing the DOF they provide for later consumption by dtrace proper.
+Multiple vulnerabilities have been discovered in DTrace. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All DTrace users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-debug/dtrace-2.0.7"
+
+ UnrealIRCd is an Internet Relay Chat (IRC) daemon.
+A vulnerability has been discovered in UnrealIRCd. Please review the CVE identifier referenced below for details.
+An attacker may be able to achieve denial of service.
+There is no known workaround at this time.
+All UnrealIRCd users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-irc/unrealircd-6.0.2"
+
+ Vinyl Cache is a web application accelerator. Vinyl Cache was previously named Varnish.
+Multiple vulnerabilities have been discovered in Vinyl Cache. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Vinyl Cache users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-servers/vinyl-cache-8.0.2"
+
+ GNU screen is a full-screen window manager that multiplexes a physical terminal between several processes, typically interactive shells.
+Multiple vulnerabilities have been discovered in GNU screen. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All GNU screen users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-misc/screen-4.9.1-r2"
+
+ Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.
+Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Chromium users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/chromium-128.0.6613.84"
+
+
+ All Google Chrome users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/google-chrome-128.0.6613.84"
+
+
+ All Microsoft Edge users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-128.0.2739.42"
+
+
+ All Opera users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/opera-114.0.5282.21"
+
+ Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.
+Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Chromium users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/chromium-131.0.6778.85"
+
+
+ All Google Chrome users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/google-chrome-131.0.6778.85"
+
+
+ All Microsoft Edge users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-131.0.2903.63"
+
+
+ All Opera users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/opera-116.0.5366.21"
+
+ OpenRGB is a cross-platform software suite for controlling RGB LED lighting devices.
+Multiple vulnerabilities have been discovered in OpenRGB. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time. Users are recommended to avoid exposing OpenRGB to the network even with these fixes.
+All OpenRGB users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-misc/openrgb-1.0_rc3_p1"
+
+ Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser. + +Vivaldi is a powerful, personal and private browser that adapts to you.
+Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, Opera, and Vivaldi. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Chromium users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/chromium-145.0.7632.159"
+
+
+ All Google Chrome users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/google-chrome-145.0.7632.159"
+
+
+ All Microsoft Edge users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-145.0.3800.97"
+
+
+ All Opera users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/opera-130.0.5846.0"
+
+
+ All Vivaldi users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/vivaldi-7.8.3925.76"
+
+ Tor is an implementation of second generation Onion Routing, a connection-oriented anonymizing communication service.
+Multiple vulnerabilities have been discovered in Tor. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Tor users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.9.11"
+
+ Freenet is an encrypted network without censorship.
+A vulnerability has been discovered in Freenet. Please review the CVE identifier referenced below for details.
+This release fixes as an XSS vulnerability that may allow an attacker to deanonymize the user.
+There is no known workaround at this time.
+All Freenet users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-p2p/freenet-0.7.5_p1505"
+
+ Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.
+Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Chromium users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/chromium-135.0.7049.95"
+
+
+ All Google Chrome users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/google-chrome-135.0.7049.95"
+
+
+ All Microsoft Edge users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-135.0.3179.85"
+
+
+ All Opera users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/opera-120.0.5543.8"
+
+