All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Fabien Thomas" <fabien.thomas@smile.fr>
To: <fabien.thomas@smile.fr>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][scarthgap 23/37] curl: fix CVE-2026-7168
Date: Thu, 20 Aug 2026 12:23:50 +0200	[thread overview]
Message-ID: <DKTP4ETBSBHF.1LWD2OE8VROP3@smile.fr> (raw)
In-Reply-To: <18CD4012388268D1.189677@lists.openembedded.org>

On Wed Aug 19, 2026 at 5:56 PM CEST, Fabien Thomas via lists.openembedded.org wrote:
> From: Deepak Rathore <deeratho@cisco.com>
>
> This patch applies the upstream backport for CVE-2026-7168.
> The upstream fix commit is referenced in [1], and the public
> CVE advisory is referenced in [2].
>
> [1] https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507
> [2] https://curl.se/docs/CVE-2026-7168.html
>
> (From OE-Core rev: 2fa295fe7473c6df94175de36528736bf32f1e9a)
>
> Signed-off-by: Deepak Rathore <deeratho@cisco.com>
> Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
> ---
>  .../curl/curl/CVE-2026-7168.patch             | 425 ++++++++++++++++++
>  meta/recipes-support/curl/curl_8.7.1.bb       |   1 +
>  2 files changed, 426 insertions(+)
>  create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch
>
> diff --git a/meta/recipes-support/curl/curl/CVE-2026-7168.patch b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> new file mode 100644
> index 00000000000..0669be6546d
> --- /dev/null
> +++ b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> @@ -0,0 +1,425 @@
> +From 0f0bb5efbd1e4f2199eeb98e6c62a7a67242cad2 Mon Sep 17 00:00:00 2001
> +From: Daniel Stenberg <daniel@haxx.se>
> +Date: Fri, 5 Jun 2026 01:22:37 -0700
> +Subject: [PATCH] setopt: clear proxy auth properties when switching
> +
> +Verify with test 1588
> +
> +Closes #21453
> +
> +CVE: CVE-2026-7168
> +Upstream-Status: Backport [https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507]
> +
> +Backport Changes:
> +- The upstream lib/setopt.c hunk reuses Curl_auth_digest_cleanup() from the
> +  newer tree. curl-8.7.1 does not expose that helper to setopt.c in the same
> +  way, so this backport adds the vauth/vauth.h include before applying the
> +  upstream setproxy() cleanup logic.
> +- The upstream tree already provides a CURL_DISABLE_DIGEST_AUTH fallback for
> +  Curl_auth_digest_cleanup(). curl-8.7.1 does not, so this backport adds the
> +  equivalent no-op macro in lib/vauth/vauth.h.
> +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc
> +  instead of the upstream tests/data/Makefile.am and
> +  tests/libtest/Makefile.am lists.
> +- curl-8.7.1 uses the older libtest harness, so first.h,
> +  test_lib1588(), libtest_arg4, and CURLcode result handling were adapted to
> +  test.h, test(), test_argv[4], and int res.
> +- curl-8.7.1 does not define the newer digest test feature in runtests.pl.
> +  This backport defines the target harness feature as digest-auth, matching
> +  tests/server/disabled.c, and makes test 1588 require digest-auth.
> +- The curl-8.7.1 server harness does not handle crlf="headers" correctly on
> +  response data sections for this test, so those attributes were removed from
> +  the two server response blocks and datacheck. The protocol block keeps
> +  crlf="headers" because runtests.pl normalizes protocol verification when any
> +  crlf attribute is present.
> +
> +(cherry picked from commit c1cfdf59acbaf9504c4578d4cf56cdd7c8594507)
> +Signed-off-by: Deepak Rathore <deeratho@cisco.com>
> +---
> + lib/setopt.c               |  18 ++++-
> + lib/vauth/vauth.h          |   2 +
> + tests/data/Makefile.inc    |   1 +
> + tests/data/test1588        | 106 ++++++++++++++++++++++++++
> + tests/libtest/Makefile.inc |   5 +-
> + tests/libtest/lib1588.c    | 152 +++++++++++++++++++++++++++++++++++++
> + tests/runtests.pl          |   2 +
> + 7 files changed, 283 insertions(+), 3 deletions(-)
> + create mode 100644 tests/data/test1588
> + create mode 100644 tests/libtest/lib1588.c
> +
> +diff --git a/lib/setopt.c b/lib/setopt.c
> +index 8a5a5d7..7eaf309 100644
> +--- a/lib/setopt.c
> ++++ b/lib/setopt.c
> +@@ -51,6 +51,7 @@
> + #include "altsvc.h"
> + #include "hsts.h"
> + #include "tftp.h"
> ++#include "vauth/vauth.h"
> + #include "strdup.h"
> + /* The last 3 #include files should be in this order */
> + #include "curl_printf.h"
> +@@ -76,6 +77,20 @@ CURLcode Curl_setstropt(char **charp, const char *s)
> +   return CURLE_OK;
> + }
> + 
> ++#ifndef CURL_DISABLE_PROXY
> ++static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
> ++{
> ++  if((data->set.str[STRING_PROXY] && proxy) &&
> ++     /* there was one set, is this a new one? */
> ++     !strcmp(data->set.str[STRING_PROXY], proxy))
> ++    return CURLE_OK; /* same one as before */
> ++
> ++  Curl_auth_digest_cleanup(&data->state.proxydigest);
> ++  memset(&data->state.authproxy, 0, sizeof(data->state.authproxy));
> ++  return Curl_setstropt(&data->set.str[STRING_PROXY], proxy);
> ++}
> ++#endif
> ++
> + CURLcode Curl_setblobopt(struct curl_blob **blobp,
> +                          const struct curl_blob *blob)
> + {
> +@@ -1139,8 +1154,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option, va_list param)
> +      * Setting it to NULL, means no proxy but allows the environment variables
> +      * to decide for us (if CURLOPT_SOCKS_PROXY setting it to NULL).
> +      */
> +-    result = Curl_setstropt(&data->set.str[STRING_PROXY],
> +-                            va_arg(param, char *));
> ++    result = setproxy(data, va_arg(param, char *));
> +     break;
> + 
> +   case CURLOPT_PRE_PROXY:
> +diff --git a/lib/vauth/vauth.h b/lib/vauth/vauth.h
> +index 9da0540..bf5c7a3 100644
> +--- a/lib/vauth/vauth.h
> ++++ b/lib/vauth/vauth.h
> +@@ -119,6 +119,8 @@ CURLcode Curl_auth_create_digest_http_message(struct Curl_easy *data,
> + 
> + /* This is used to clean up the digest specific data */
> + void Curl_auth_digest_cleanup(struct digestdata *digest);
> ++#else
> ++#define Curl_auth_digest_cleanup(x)
> + #endif /* !CURL_DISABLE_DIGEST_AUTH */
> + 
> + #ifdef USE_GSASL
> +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc
> +index f673f86..461eb37 100644
> +--- a/tests/data/Makefile.inc
> ++++ b/tests/data/Makefile.inc
> +@@ -200,6 +200,7 @@ test1540 test1541 test1542 test1543 test1544 test1545 \
> + test1550 test1551 test1552 test1553 test1554 test1555 test1556 test1557 \
> + test1558 test1559 test1560 test1561 test1562 test1563 test1564 test1565 \
> + test1566 test1567 test1568 test1569 test1570 \
> ++test1588 \
> + \
> + test1590 test1591 test1592 test1593 test1594 test1595 test1596 test1597 \
> + test1598 \
> +diff --git a/tests/data/test1588 b/tests/data/test1588
> +new file mode 100644
> +index 0000000..8a3bf81
> +--- /dev/null
> ++++ b/tests/data/test1588
> +@@ -0,0 +1,106 @@
> ++<?xml version="1.0" encoding="US-ASCII"?>
> ++<testcase>
> ++<info>
> ++<keywords>
> ++HTTP
> ++HTTP GET
> ++HTTP proxy
> ++HTTP proxy Digest auth
> ++multi
> ++</keywords>
> ++</info>
> ++
> ++# Server-side
> ++<reply>
> ++
> ++# this is returned first since we get no proxy-auth
> ++<data>
> ++HTTP/1.1 407 Authorization Required to proxy me my dear
> ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
> ++Content-Length: 33
> ++
> ++And you should ignore this data.
> ++</data>
> ++
> ++# then this is returned when we get proxy-auth
> ++<data1000>
> ++HTTP/1.1 200 OK
> ++Content-Length: 21
> ++Server: no
> ++
> ++Nice proxy auth sir!
> ++</data1000>
> ++
> ++<datacheck>
> ++HTTP/1.1 407 Authorization Required to proxy me my dear
> ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
> ++Content-Length: 33
> ++
> ++HTTP/1.1 200 OK
> ++Content-Length: 21
> ++Server: no
> ++
> ++Nice proxy auth sir!
> ++HTTP/1.1 407 Authorization Required to proxy me my dear
> ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
> ++Content-Length: 33
> ++
> ++HTTP/1.1 200 OK
> ++Content-Length: 21
> ++Server: no
> ++
> ++Nice proxy auth sir!
> ++</datacheck>
> ++</reply>
> ++
> ++# Client-side
> ++<client>
> ++<server>
> ++http
> ++</server>
> ++# tool is what to use instead of 'curl'
> ++<tool>
> ++lib%TESTNUMBER
> ++</tool>
> ++<features>
> ++!SSPI
> ++crypto
> ++proxy
> ++digest-auth
> ++</features>
> ++<name>
> ++HTTP proxy auth Digest, then change proxy and do it again
> ++</name>
> ++<command>
> ++http://test.remote.example.com/path/%TESTNUMBER %HOSTIP %HTTPPORT silly:person custom.set.host.name
> ++</command>
> ++</client>
> ++
> ++# Verify data after the test has been "shot"
> ++<verify>
> ++<protocol crlf="headers">
> ++GET http://test.remote.example.com/path/1588 HTTP/1.1
> ++Host: test.remote.example.com
> ++Accept: */*
> ++Proxy-Connection: Keep-Alive
> ++
> ++GET http://test.remote.example.com/path/1588 HTTP/1.1
> ++Host: test.remote.example.com
> ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a"
> ++Accept: */*
> ++Proxy-Connection: Keep-Alive
> ++
> ++GET http://test.remote.example.com/path/1588 HTTP/1.1
> ++Host: test.remote.example.com
> ++Accept: */*
> ++Proxy-Connection: Keep-Alive
> ++
> ++GET http://test.remote.example.com/path/1588 HTTP/1.1
> ++Host: test.remote.example.com
> ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a"
> ++Accept: */*
> ++Proxy-Connection: Keep-Alive
> ++
> ++</protocol>
> ++</verify>
> ++</testcase>
> +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc
> +index 9d3356a..4c42d34 100644
> +--- a/tests/libtest/Makefile.inc
> ++++ b/tests/libtest/Makefile.inc
> +@@ -62,7 +62,7 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq      \
> +  lib1540 lib1541 lib1542 lib1543         lib1545 \
> +  lib1550 lib1551 lib1552 lib1553 lib1554 lib1555 lib1556 lib1557 \
> +  lib1558 lib1559 lib1560 lib1564 lib1565 lib1567 lib1568 lib1569 \
> +- lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \
> ++ lib1588 lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \
> +  \
> +  lib1662 \
> +  \
> +@@ -687,6 +687,9 @@ lib2502_LDADD = $(TESTUTIL_LIBS)
> + lib2506_SOURCES = lib2506.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS)
> + lib2506_LDADD = $(TESTUTIL_LIBS)
> + 
> ++lib1588_SOURCES = lib1588.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS)
> ++lib1588_LDADD = $(TESTUTIL_LIBS)
> ++
> + lib3010_SOURCES = lib3010.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS)
> + lib3010_LDADD = $(TESTUTIL_LIBS)
> + 
> +diff --git a/tests/libtest/lib1588.c b/tests/libtest/lib1588.c
> +new file mode 100644
> +index 0000000..00c6b35
> +--- /dev/null
> ++++ b/tests/libtest/lib1588.c
> +@@ -0,0 +1,152 @@
> ++/***************************************************************************
> ++ *                                  _   _ ____  _
> ++ *  Project                     ___| | | |  _ \| |
> ++ *                             / __| | | | |_) | |
> ++ *                            | (__| |_| |  _ <| |___
> ++ *                             \___|\___/|_| \_\_____|
> ++ *
> ++ * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
> ++ *
> ++ * This software is licensed as described in the file COPYING, which
> ++ * you should have received as part of this distribution. The terms
> ++ * are also available at https://curl.se/docs/copyright.html.
> ++ *
> ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell
> ++ * copies of the Software, and permit persons to whom the Software is
> ++ * furnished to do so, under the terms of the COPYING file.
> ++ *
> ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
> ++ * KIND, either express or implied.
> ++ *
> ++ * SPDX-License-Identifier: curl
> ++ *
> ++ ***************************************************************************/
> ++/*
> ++ * argv1 = URL
> ++ * argv2 = proxy host
> ++ * argv3 = proxy port
> ++ * argv4 = proxyuser:password
> ++ */
> ++
> ++#include "test.h"
> ++#include "testutil.h"
> ++
> ++static CURLcode init1588(CURL *curl, const char *url,
> ++                         const char *userpwd, const char *proxy)
> ++{
> ++  int res = CURLE_OK;
> ++
> ++  res_easy_setopt(curl, CURLOPT_URL, url);
> ++  if(res)
> ++    goto init_failed;
> ++
> ++  res_easy_setopt(curl, CURLOPT_PROXY, proxy);
> ++  if(res)
> ++    goto init_failed;
> ++
> ++  res_easy_setopt(curl, CURLOPT_PROXYUSERPWD, userpwd);
> ++  if(res)
> ++    goto init_failed;
> ++
> ++  res_easy_setopt(curl, CURLOPT_PROXYAUTH, CURLAUTH_DIGEST);
> ++  if(res)
> ++    goto init_failed;
> ++
> ++  res_easy_setopt(curl, CURLOPT_VERBOSE, 1L);
> ++  if(res)
> ++    goto init_failed;
> ++#if 0
> ++  res_easy_setopt(curl, CURLOPT_HTTPPROXYTUNNEL, 1L);
> ++  if(res)
> ++    goto init_failed;
> ++#endif
> ++
> ++  res_easy_setopt(curl, CURLOPT_HEADER, 1L);
> ++  if(res)
> ++    goto init_failed;
> ++
> ++  return CURLE_OK; /* success */
> ++
> ++init_failed:
> ++  return (CURLcode)res; /* failure */
> ++}
> ++
> ++static CURLcode run1588(CURL *curl, const char *url, const char *userpwd,
> ++                        const char *proxy)
> ++{
> ++  CURLcode res = CURLE_OK;
> ++
> ++  res = init1588(curl, url, userpwd, proxy);
> ++  if(res)
> ++    return res;
> ++
> ++  return curl_easy_perform(curl);
> ++}
> ++
> ++int test(char *URL)
> ++{
> ++  int res = CURLE_OK;
> ++  CURL *curl = NULL;
> ++  const char *proxyuserpws;
> ++  struct curl_slist *host = NULL;
> ++  struct curl_slist *host2 = NULL;
> ++  char proxy1_resolve[128];
> ++  char proxy2_resolve[128];
> ++  char proxy1_connect[128];
> ++  char proxy2_connect[128];
> ++
> ++  if(test_argc < 5)
> ++    return TEST_ERR_MAJOR_BAD;
> ++  proxyuserpws = test_argv[4];
> ++
> ++  curl_msnprintf(proxy1_resolve, sizeof(proxy1_resolve),
> ++                 "firstproxy:%s:%s", libtest_arg3, libtest_arg2);
> ++  curl_msnprintf(proxy2_resolve, sizeof(proxy2_resolve),
> ++                 "secondproxy:%s:%s", libtest_arg3, libtest_arg2);
> ++
> ++  /* we connect to the fake host name but the right port number */
> ++  curl_msnprintf(proxy1_connect, sizeof(proxy1_connect),
> ++                 "firstproxy:%s", libtest_arg3);
> ++  curl_msnprintf(proxy2_connect, sizeof(proxy2_connect),
> ++                 "secondproxy:%s", libtest_arg3);
> ++
> ++  res_global_init(CURL_GLOBAL_ALL);
> ++  if(res)
> ++    return res;
> ++
> ++  curl = curl_easy_init();
> ++  if(!curl) {
> ++    curl_mfprintf(stderr, "curl_easy_init() failed\n");
> ++    curl_global_cleanup();
> ++    return TEST_ERR_MAJOR_BAD;
> ++  }
> ++
> ++  host = curl_slist_append(NULL, proxy1_resolve);
> ++  if(!host)
> ++    goto test_cleanup;
> ++  host2 = curl_slist_append(host, proxy2_resolve);
> ++  if(!host2)
> ++    goto test_cleanup;
> ++  host = host2;
> ++
> ++  start_test_timing();
> ++
> ++  easy_setopt(curl, CURLOPT_RESOLVE, host);
> ++
> ++  res = run1588(curl, URL, proxyuserpws, proxy1_connect);
> ++  if(res)
> ++    goto test_cleanup;
> ++
> ++  curl_mfprintf(stderr, "lib1588: now we do the request again\n");
> ++
> ++  res = run1588(curl, URL, proxyuserpws, proxy2_connect);
> ++
> ++test_cleanup:
> ++
> ++  /* proper cleanup sequence - type PB */
> ++
> ++  curl_easy_cleanup(curl);
> ++  curl_global_cleanup();
> ++  curl_slist_free_all(host);
> ++  return res;
> ++}
> +diff --git a/tests/runtests.pl b/tests/runtests.pl
> +index ddfab20..b40df55 100755
> +--- a/tests/runtests.pl
> ++++ b/tests/runtests.pl
> +@@ -637,6 +637,8 @@ sub checksystemfeatures {
> +             $feature{"Kerberos"} = $feat =~ /Kerberos/i;
> +             # SPNEGO enabled
> +             $feature{"SPNEGO"} = $feat =~ /SPNEGO/i;
> ++            # Digest auth enabled unless disabled by build
> ++            $feature{"digest-auth"} = 1;
> +             # CharConv enabled
> +             $feature{"CharConv"} = $feat =~ /CharConv/i;
> +             # TLS-SRP enabled
> +--
> +2.35.6
> diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb
> index 8e39d821626..7d55f72b03f 100644
> --- a/meta/recipes-support/curl/curl_8.7.1.bb
> +++ b/meta/recipes-support/curl/curl_8.7.1.bb
> @@ -41,6 +41,7 @@ SRC_URI = " \
>      file://CVE-2026-5545.patch \
>      file://CVE-2026-6253.patch \
>      file://CVE-2026-6429.patch \
> +    file://CVE-2026-7168.patch \
>  "
>  
>  SRC_URI:append:class-nativesdk = " \

I'll have to drop this patch too because it doesn't apply anymore without 
the previous patch of the series (curl: fix CVE-2026-6429) which cause some 
ptest faillures.

-- 
Fabien Thomas
Smile ECS



  parent reply	other threads:[~2026-08-20 10:23 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19 15:56 [OE-core][scarthgap 00/37] Patch review Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 01/37] python3-pyopenssl: set CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 02/37] python3-idna: " Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 03/37] python3-certifi: " Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 04/37] python3-xmltodict: " Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 05/37] python3-pyyaml: " Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 06/37] gnutls: fix CVE-2026-3833 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 07/37] expat: fix CVE-2026-56403 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 08/37] expat: fix CVE-2026-56408 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 09/37] expat: fix CVE-2026-56404 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 10/37] expat: fix CVE-2026-56405 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 11/37] expat: fix CVE-2026-56410 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 12/37] expat: fix CVE-2026-56406 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 13/37] expat: fix CVE-2026-56409 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 14/37] expat: fix CVE-2026-56411 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 15/37] expat: fix CVE-2026-56407 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 16/37] expat: fix CVE-2026-56132 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 17/37] python3: fix CVE-2026-7210 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 18/37] python3-pip: set CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 19/37] libssh2: Fix CVE-2025-15661 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 20/37] curl: fix CVE-2026-5545 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 21/37] curl: fix CVE-2026-6253 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 22/37] curl: fix CVE-2026-6429 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 23/37] curl: fix CVE-2026-7168 Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 24/37] u-boot: Set CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 25/37] xserver-org: update CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 26/37] shadow: set CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 27/37] flex: update CVE_PRODUCT Fabien Thomas
2026-08-19 15:56 ` [OE-core][scarthgap 28/37] sudo: set CVE_PRODUCT Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 29/37] perf: drop newt from tui build requirements Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 30/37] busybox: patch CVE-2026-38754 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 31/37] curl: fix CVE-2026-4873 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 32/37] libssh2: fix CVE-2026-66032 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 33/37] libssh2: fix CVE-2026-66033 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 34/37] libssh2: fix CVE-2026-66034 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 35/37] libssh2: fix CVE-2026-66035 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 36/37] libsndfile1: patch CVE-2026-37555 Fabien Thomas
2026-08-19 15:57 ` [OE-core][scarthgap 37/37] linux-yocto/6.6: update to v6.6.147 Fabien Thomas
     [not found] ` <18CD40121B3B9CC0.2965692@lists.openembedded.org>
2026-08-20 10:23   ` [OE-core][scarthgap 22/37] curl: fix CVE-2026-6429 Fabien Thomas
2026-08-24  9:49     ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
     [not found] ` <18CD4012388268D1.189677@lists.openembedded.org>
2026-08-20 10:23   ` Fabien Thomas [this message]
2026-08-24  9:50     ` [OE-core][scarthgap 23/37] curl: fix CVE-2026-7168 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKTP4ETBSBHF.1LWD2OE8VROP3@smile.fr \
    --to=fabien.thomas@smile.fr \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.