capnproto: upgrade 1.0.2 -> 1.4.0

Contains fix for CVE-2026-32239 and CVE-2026-32240

Also, mark these CVEs explicitly patched, because NVD tracks them
without version info at this time.

Shortlog:
https://github.com/capnproto/capnproto/compare/v1.0.2...v1.4.0

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
This commit is contained in:
Gyorgy Sarvari 2026-03-16 13:21:29 +01:00 committed by Khem Raj
parent 32eb632648
commit c407d8669c
No known key found for this signature in database
GPG Key ID: BB053355919D3314

View File

@ -5,9 +5,9 @@ SECTION = "console/tools"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://../LICENSE;md5=a05663ae6cca874123bf667a60dca8c9"
SRC_URI = "git://github.com/sandstorm-io/capnproto.git;branch=release-${PV};protocol=https \
SRC_URI = "git://github.com/sandstorm-io/capnproto.git;branch=release-${PV};protocol=https;tag=v${PV} \
file://0001-Export-binaries-only-for-native-build.patch"
SRCREV = "1a0e12c0a3ba1f0dbbad45ddfef555166e0a14fc"
SRCREV = "8b892a8a11a632f5d52b877a49728808a142379a"
S = "${UNPACKDIR}/${BP}/c++"
@ -29,3 +29,6 @@ PACKAGE_BEFORE_PN = "${PN}-compiler"
RDEPENDS:${PN}-dev += "${PN}-compiler"
BBCLASSEXTEND = "native nativesdk"
CVE_STATUS[CVE-2026-32239] = "fixed-version: fixed in 1.4.0"
CVE_STATUS[CVE-2026-32240] = "fixed-version: fixed in 1.4.0"