[OE-core] [PATCH] webkitgtk: update to 2.18.5 (includes Spectre mitigations; see commit description)

Alexander Kanavin alexander.kanavin at linux.intel.com
Thu Jan 11 15:02:48 UTC 2018


On 01/11/2018 05:00 PM, Alexander Kanavin wrote:
> This is the only available stable version with mitigation fixes for Spectre.
> Webkit upstream developers do not port CVE fixes to earlier stable series,
> no exception was made in this case.

I will now establish whether it's feasible to update currently supported 
YP releases (rocko, pyro, morty) to this version.

Normally we don't do it (even though that leaves dozens of webkit CVEs 
unfixed), but this is special.

Alex



More information about the Openembedded-core mailing list