From: "Yoann Congal" <yoann.congal@smile.fr>
To: <sdoshi@mvista.com>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][wrynose][PATCH 4/6] curl: Security Fix for CVE-2026-80255
Date: Wed, 16 Sep 2026 14:17:10 +0200 [thread overview]
Message-ID: <DLGQFVSIEIYJ.3FPJ3GOIMT0C4@smile.fr> (raw)
In-Reply-To: <20260909203324.765094-4-sdoshi@mvista.com>
On Wed Sep 9, 2026 at 10:33 PM CEST, Siddharth Doshi via lists.openembedded.org wrote:
> From: Siddharth Doshi <sdoshi@mvista.com>
>
> Picking patch as per [1], and same patch is mentioned in [2]
>
> [1] https://curl.se/docs/CVE-2026-80255.html
> [2] https://security-tracker.debian.org/tracker/CVE-2026-80255
>
> Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
> ---
> .../curl/curl/CVE-2026-80255.patch | 106 ++++++++++++++++++
> meta/recipes-support/curl/curl_8.19.0.bb | 1 +
> 2 files changed, 107 insertions(+)
> create mode 100644 meta/recipes-support/curl/curl/CVE-2026-80255.patch
>
> diff --git a/meta/recipes-support/curl/curl/CVE-2026-80255.patch b/meta/recipes-support/curl/curl/CVE-2026-80255.patch
> new file mode 100644
> index 0000000000..964193bcbd
> --- /dev/null
> +++ b/meta/recipes-support/curl/curl/CVE-2026-80255.patch
> @@ -0,0 +1,106 @@
> +From 4f6aa41a0145e930e766775dbe860883d350aa0a Mon Sep 17 00:00:00 2001
> +From: Daniel Stenberg <daniel@haxx.se>
> +Date: Thu, 27 Aug 2026 08:33:30 +0200
> +Subject: [PATCH] cookie: improve TAB handling
> +
> +For entries with a leading tab. Verified in test 2885.
> +
> +Reported-by: Stanislav Fort
> +Closes #22699
> +
> +Upstream-Status: Backport [https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a]
> +CVE: CVE-2026-80255
> +Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
> +---
> + lib/cookie.c | 2 +-
> + tests/data/Makefile.am | 1 +
> + tests/data/test2885 | 52 ++++++++++++++++++++++++++++++++++++++++++
> + 3 files changed, 54 insertions(+), 1 deletion(-)
> + create mode 100644 tests/data/test2885
Hello,
I believe this patch is responsible for ptests failures:
qemux86-64-ptest debian12-vk-8 wrynose completed at 2026-09-14 22:47:23+00:00
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/73/builds/4557
qemuarm64-ptest ubuntu2404-vk-arm2 wrynose completed at 2026-09-14 23:24:50+00:00
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/61/builds/4530
qemuriscv64-ptest alma9-vk-2 wrynose completed at 2026-09-15 00:01:40+00:00
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/56/builds/2408
qemuarm64-musl-ptest stream10-vk-arm1 wrynose completed at 2026-09-14 22:49:53+00:00
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/109/builds/1202
qemux86-64-musl-ptest fedora43-vk-2 wrynose completed at 2026-09-14 22:48:49+00:00
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/110/builds/1185
Failed ptests:
{'curl': ['1105_-_HTTP_with_cookie_parser_and_header_recording_-_output']}
I could reproduce this locally with
bitbake core-image-ptest-curl && bitbake core-image-ptest-curl -c testimage
Can you look into this?
In the meantime, I'll keep 1-3,5-6/6 in my branch.
Regards,
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-16 12:17 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 20:33 [OE-core][wrynose][PATCH 1/6] curl: Security Fix for CVE-2026-13608 Siddharth
2026-09-09 20:33 ` [OE-core][wrynose][PATCH 2/6] curl: Security Fix for CVE-2026-18924 Siddharth
2026-09-27 6:35 ` Yoann Congal
2026-09-09 20:33 ` [OE-core][wrynose][PATCH 3/6] curl: Security Fix for CVE-2026-80229 Siddharth
2026-09-09 20:33 ` [OE-core][wrynose][PATCH 4/6] curl: Security Fix for CVE-2026-80255 Siddharth
2026-09-16 12:17 ` Yoann Congal [this message]
2026-09-17 5:06 ` [wrynose][PATCH " Siddharth Doshi
2026-09-09 20:33 ` [OE-core][wrynose][PATCH 5/6] curl: set CVE_STATUS for CVE-2026-82208 Siddharth
2026-09-16 21:43 ` Yoann Congal
2026-09-17 4:55 ` [wrynose][PATCH " Siddharth Doshi
2026-09-09 20:33 ` [OE-core][wrynose][PATCH 6/6] curl: set CVE_STATUS for CVE-2026-82209 Siddharth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLGQFVSIEIYJ.3FPJ3GOIMT0C4@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
--cc=sdoshi@mvista.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.