From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 55963C5DF82 for ; Thu, 20 Aug 2026 10:23:17 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.3979.1787221395745030296 for ; Thu, 20 Aug 2026 03:23:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=IsxJDkAb; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: fabien.thomas@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47f93b2fe4cso1169500f8f.0 for ; Thu, 20 Aug 2026 03:23:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787221394; x=1787826194; darn=lists.openembedded.org; h=in-reply-to:references:to:from:subject:message-id:date:content-type :content-transfer-encoding:mime-version:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uAooJe8IOTNNcI/1xuBIt4eyMj6pUn2Z6a9xRLWlKx4=; b=IsxJDkAbE54iErxrXAvdhwyDLUvaOVZpjYCRsUgzhsVt3YXO28Nw1iq/O+OPWj6mJP hDGt9f1Fp6jGJxzep1X7qBzdcoyRXAFUtFiSxbJ3W88dYeuu3qBRGWGP6/dHPw5xZAnO TgN38N1toF+OxLfqYdgcOiV8RtnMMUySOElP4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787221394; x=1787826194; h=in-reply-to:references:to:from:subject:message-id:date:content-type :content-transfer-encoding:mime-version:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to:content-type; bh=uAooJe8IOTNNcI/1xuBIt4eyMj6pUn2Z6a9xRLWlKx4=; b=BVcTf3GR5VsVs8JnLDsWS37PT1+IMXTeE5m+SDLaOBoGPSmrRr09uJdbdQ0Uv8qcQ8 iahYNdXyQs+CsGbHAwsHCCASneg5t77daXubj601nfVIPwzecYY+qMBjx5whIiGxku5Z K3PB8yDkGD4po+aVqxdAtGp7xkpY6ZwlBb5YbvpPIM4iqGROsZuCtmcZzrDshuATLxfF 4gOu8mWAK8+aU6insWvo39pozfxjYmwYHlp2LJg/2DudAQACDb/kbVIhDr8+vngVMl8G G+fbNNG7DgpNI5Fcz+Fi3CuslzBTvN1enDb1XIHyM9dgbP/IA2eGIQiP8XHzDZ1heilh HjRA== X-Forwarded-Encrypted: i=1; AHgh+RqgJ3sEZSo8Syq9novBmpMT10zvnAVznoDSMckzmeiqXLcxgBJuhUDzSNDbOgHyX3zbpNkMr/mHvSPWbeHFKd1HGA==@lists.openembedded.org X-Gm-Message-State: AFuF++mGFKn5ZILp+lwjXD+1DYXkzJurggJuygFi1AkUygsJtWtwKgl6 DKAqLaJaxvLtBjatCTQwVAoV6hYlFaSKtwbjI5UfpcIlPAtfnH1hvpGQEtqbMieMqcI= X-Gm-Gg: AR+sD11aQOVCQs/h/5k0UWSUHvMnmDpsMPBrKVabVHiaZg1q4XEzMr/FEkOOnjw4ALQ i7OjNCWuZtPWpxyKASCS7S8NHZYdDqpxPewyP855U1ZJduyDlv+6PBfLPY/Z7yiB8KLscPDyWdb sWzAIbvYOrRWhsfy/ar7yxAwZgQZ8aG5zr80TbKx29fI2MXT/YF7ysMjMa1SpIdrIGuZBK7AayE LTnShmm+42ReoWooDlF7UVnLpIANgH2E4/OvsXbxoOOsJTlIoRcvkS/PIpCAHTdobbHjbLyiOae eTXMexqHp8tUGGYK792OrhJ9ssZmAHqAqnUhjXbXiupv9oetfwpgjN7gBg7qLffayCOblze+sKA 8rJiKQGvKMqLYYxXcLH4eYubSgnycETb5kyq4NUf/+0sTPoXZAJilzZEdw/egnHjxis17HEPZma WljxRsUBOL77RskQWlSL8iISxqnIdv08Sv7N6GdcgYenQDhZGsh2IU/plGgSmWkdbAsbCpXMZDN 6YzRYY8IGY9m3Aazas5SyZVTWRSmopARWKv3dExSxa+/qTzAmJAwKzXH2G2YDHskpKc2wo+pHE5 4quy1TABx2jS89O1rnnzndMOXJP3tkLU2iE= X-Received: by 2002:a05:6000:468c:b0:482:b813:8315 with SMTP id ffacd0b85a97d-482b8138536mr5802837f8f.21.1787221393848; Thu, 20 Aug 2026 03:23:13 -0700 (PDT) Received: from localhost (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482b1450fb9sm11843923f8f.14.2026.08.20.03.23.13 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 20 Aug 2026 03:23:13 -0700 (PDT) Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Thu, 20 Aug 2026 12:23:13 +0200 Message-Id: Subject: Re: [OE-core][scarthgap 22/37] curl: fix CVE-2026-6429 From: "Fabien Thomas" To: , X-Mailer: aerc 0.22.0 References: <18CD40121B3B9CC0.2965692@lists.openembedded.org> In-Reply-To: <18CD40121B3B9CC0.2965692@lists.openembedded.org> List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 20 Aug 2026 10:23:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243848 On Wed Aug 19, 2026 at 5:56 PM CEST, Fabien Thomas via lists.openembedded.o= rg wrote: > From: Deepak Rathore > > This patch applies the upstream backport for CVE-2026-6429. > The upstream fix commit is referenced in [1], and the public > CVE advisory is referenced in [2]. > > [1] https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f19= 9ace306 > [2] https://curl.se/docs/CVE-2026-6429.html > [3] https://nvd.nist.gov/vuln/detail/CVE-2026-6429 > > (From OE-Core rev: 0cbfae83eebf9076f7b22d07b48cb5cef1536989) > > Signed-off-by: Deepak Rathore > Signed-off-by: Fabien Thomas > --- > .../curl/curl/CVE-2026-6429.patch | 367 ++++++++++++++++++ > meta/recipes-support/curl/curl_8.7.1.bb | 1 + > 2 files changed, 368 insertions(+) > create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6429.patch > > diff --git a/meta/recipes-support/curl/curl/CVE-2026-6429.patch b/meta/re= cipes-support/curl/curl/CVE-2026-6429.patch > new file mode 100644 > index 00000000000..f4df441aa2b > --- /dev/null > +++ b/meta/recipes-support/curl/curl/CVE-2026-6429.patch > @@ -0,0 +1,367 @@ > +From 8191fd6d5677c30579c09a8d0988b47bbf33f65f Mon Sep 17 00:00:00 2001 > +From: Daniel Stenberg > +Date: Fri, 5 Jun 2026 01:20:50 -0700 > +Subject: [PATCH] http: clear credentials better on redirect > + > +Verify with test 2506: netrc with redirect using proxy > + > +Updated test 998 which was wrong. > + > +Reported-by: Muhamad Arga Reksapati > + > +Closes #21345 > + > +CVE: CVE-2026-6429 > +Upstream-Status: Backport [https://github.com/curl/curl/commit/b4024bf80= 8bd558026fdc6096e8457f199ace306] > + > +Backport Changes: > +- The upstream lib/http.c hunk adds the same-origin credential clearing = to > + Curl_http_follow(). curl-8.7.1 predates that protocol-specific redirec= t > + handler and carries the equivalent redirect logic in lib/transfer.c vi= a > + Curl_follow(), so the full upstream lib/http.c hunk was adapted there. > +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc > + instead of the upstream tests/data/Makefile.am and > + tests/libtest/Makefile.am lists. > +- curl-8.7.1 does not contain test2504/lib2504, so the new > + test2506/lib2506 entries were registered after the nearest existing > + test2503/lib2502 entries in the target-version test lists. > +- curl-8.7.1 uses the older libtest harness, so first.h, > + test_lib2506(), and CURLcode result handling were adapted to test.h, > + test(), and int res. > +- Scarthgap curl-8.7.1 keeps the same incorrect redirected-request > + Authorization expectation in tests/data/test998, so this backport remo= ves > + that expectation with an equivalent target-version hunk. > + > +(cherry picked from commit b4024bf808bd558026fdc6096e8457f199ace306) > +Signed-off-by: Deepak Rathore > +--- > + lib/transfer.c | 103 +++++++++++++++++++++---------------- > + tests/data/Makefile.inc | 2 +- > + tests/data/test2506 | 64 +++++++++++++++++++++++ > + tests/data/test998 | 1 - > + tests/libtest/Makefile.inc | 5 +- > + tests/libtest/lib2506.c | 71 +++++++++++++++++++++++++ > + 6 files changed, 198 insertions(+), 48 deletions(-) > + create mode 100644 tests/data/test2506 > + create mode 100644 tests/libtest/lib2506.c > + > +diff --git a/lib/transfer.c b/lib/transfer.c > +index a73462928d..0f5bd8ce59 100644 > +--- a/lib/transfer.c > ++++ b/lib/transfer.c > +@@ -865,49 +865,62 @@ CURLcode Curl_follow(struct Curl_easy *data, > + if(uc) > + return Curl_uc_to_curlcode(uc); > + > +- /* Clear auth if this redirects to a different port number or proto= col, > +- unless permitted */ > +- if(!data->set.allow_auth_to_other_hosts && (type !=3D FOLLOW_FAKE))= { > +- char *portnum; > +- int port; > +- bool clear =3D FALSE; > +- > +- if(data->set.use_port && data->state.allow_port) > +- /* a custom port is used */ > +- port =3D (int)data->set.use_port; > +- else { > +- uc =3D curl_url_get(data->state.uh, CURLUPART_PORT, &portnum, > +- CURLU_DEFAULT_PORT); > +- if(uc) { > +- free(newurl); > +- return Curl_uc_to_curlcode(uc); > +- } > +- port =3D atoi(portnum); > +- free(portnum); > +- } > +- if(port !=3D data->info.conn_remote_port) { > +- infof(data, "Clear auth, redirects to port from %u to %u", > +- data->info.conn_remote_port, port); > +- clear =3D TRUE; > ++ { > ++ bool same_origin; > ++ CURLU *u; > ++ char *oldscheme =3D NULL; > ++ char *oldhost =3D NULL; > ++ char *oldport =3D NULL; > ++ char *newscheme =3D NULL; > ++ char *newhost =3D NULL; > ++ char *newport =3D NULL; > ++ > ++ u =3D curl_url(); > ++ if(!u) { > ++ free(newurl); > ++ return CURLE_OUT_OF_MEMORY; > + } > +- else { > +- char *scheme; > +- const struct Curl_handler *p; > +- uc =3D curl_url_get(data->state.uh, CURLUPART_SCHEME, &scheme, = 0); > +- if(uc) { > +- free(newurl); > +- return Curl_uc_to_curlcode(uc); > +- } > + > +- p =3D Curl_get_scheme_handler(scheme); > +- if(p && (p->protocol !=3D data->info.conn_protocol)) { > +- infof(data, "Clear auth, redirects scheme from %s to %s", > +- data->info.conn_scheme, scheme); > +- clear =3D TRUE; > +- } > +- free(scheme); > ++ uc =3D curl_url_set(u, CURLUPART_URL, data->state.url, 0); > ++ if(!uc) > ++ uc =3D curl_url_get(u, CURLUPART_SCHEME, &oldscheme, 0); > ++ if(!uc) > ++ uc =3D curl_url_get(u, CURLUPART_HOST, &oldhost, 0); > ++ if(!uc) > ++ uc =3D curl_url_get(u, CURLUPART_PORT, &oldport, CURLU_DEFAULT_= PORT); > ++ if(!uc) > ++ uc =3D curl_url_get(data->state.uh, CURLUPART_SCHEME, &newschem= e, 0); > ++ if(!uc) > ++ uc =3D curl_url_get(data->state.uh, CURLUPART_HOST, &newhost, 0= ); > ++ if(!uc) > ++ uc =3D curl_url_get(data->state.uh, CURLUPART_PORT, &newport, > ++ CURLU_DEFAULT_PORT); > ++ if(uc) { > ++ curl_url_cleanup(u); > ++ free(oldscheme); > ++ free(oldhost); > ++ free(oldport); > ++ free(newscheme); > ++ free(newhost); > ++ free(newport); > ++ free(newurl); > ++ return Curl_uc_to_curlcode(uc); > + } > +- if(clear) { > ++ > ++ same_origin =3D strcasecompare(oldscheme, newscheme) && > ++ strcasecompare(oldhost, newhost) && > ++ !strcmp(oldport, newport); > ++ > ++ curl_url_cleanup(u); > ++ free(oldscheme); > ++ free(oldhost); > ++ free(oldport); > ++ free(newscheme); > ++ free(newhost); > ++ free(newport); > ++ > ++ if((!same_origin && !data->set.allow_auth_to_other_hosts) || > ++ !data->set.str[STRING_USERNAME]) { > + result =3D Curl_reset_userpwd(data); > + if(result) { > + free(newurl); > +@@ -917,12 +930,12 @@ CURLcode Curl_follow(struct Curl_easy *data, > + Curl_safefree(data->state.aptr.passwd); > + } > + } > +- } > + > +- result =3D Curl_reset_proxypwd(data); > +- if(result) { > +- free(newurl); > +- return result; > ++ result =3D Curl_reset_proxypwd(data); > ++ if(result) { > ++ free(newurl); > ++ return result; > ++ } > + } > + > + if(type =3D=3D FOLLOW_FAKE) { > +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc > +index aafd309a9d..f673f86384 100644 > +--- a/tests/data/Makefile.inc > ++++ b/tests/data/Makefile.inc > +@@ -251,7 +251,7 @@ test2300 test2301 test2302 test2303 test2304 test230= 5 test2306 test2307 \ > + \ > + test2400 test2401 test2402 test2403 test2404 \ > + \ > +-test2500 test2501 test2502 test2503 \ > ++test2500 test2501 test2502 test2503 test2506 \ > + \ > + test2600 test2601 test2602 test2603 \ > + \ > +diff --git a/tests/data/test2506 b/tests/data/test2506 > +new file mode 100644 > +index 0000000000..9c65002496 > +--- /dev/null > ++++ b/tests/data/test2506 > +@@ -0,0 +1,64 @@ > ++ > ++ > ++ > ++ > ++HTTP > ++cookies > ++ > ++ > ++ > ++ > ++ > ++HTTP/1.1 301 redirect > ++Date: Tue, 09 Nov 2010 14:49:00 GMT > ++Content-Length: 3 > ++Location: http://numbertwo.example/%TESTNUMBER0002 > ++ > ++ok > ++ > ++ > ++HTTP/1.1 200 OK > ++Date: Tue, 09 Nov 2010 14:49:00 GMT > ++Content-Length: 4 > ++ > ++yes > ++ > ++ > ++ > ++ > ++ > ++http > ++ > ++ > ++proxy > ++ > ++ > ++lib%TESTNUMBER > ++ > ++ > ++netrc with redirect using proxy > ++ > ++ > ++machine site.example login batman password robin > ++ > ++ > ++http://%HOSTIP:%HTTPPORT http://site.example/ %LOGDIR/netrc2506 > ++ > ++ > ++ > ++ > ++ > ++GET http://site.example/ HTTP/1.1 > ++Host: site.example > ++Authorization: Basic %b64[batman:robin]b64% > ++Accept: */* > ++Proxy-Connection: Keep-Alive > ++ > ++GET http://numbertwo.example/25060002 HTTP/1.1 > ++Host: numbertwo.example > ++Accept: */* > ++Proxy-Connection: Keep-Alive > ++ > ++ > ++ > ++ > +diff --git a/tests/data/test998 b/tests/data/test998 > +index 0969d4704b..17c0a0e150 100644 > +--- a/tests/data/test998 > ++++ b/tests/data/test998 > +@@ -82,7 +82,6 @@ Proxy-Connection: Keep-Alive > +=20 > + GET http://somewhere.else.example/a/path/9980002 HTTP/1.1 > + Host: somewhere.else.example > +- Authorization: Basic YWxiZXJ0bzplaW5zdGVpbg=3D=3D > + User-Agent: curl/%VERSION > + Accept: */* > + Proxy-Connection: Keep-Alive > +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc > +index 9f7cec6027..9d3356aaf5 100644 > +--- a/tests/libtest/Makefile.inc > ++++ b/tests/libtest/Makefile.inc > +@@ -75,7 +75,7 @@ noinst_PROGRAMS =3D chkhostname libauthretry libntlmco= nnect libprereq \ > + lib1970 lib1971 lib1972 lib1973 lib1974 lib1975 \ > + lib2301 lib2302 lib2304 lib2305 lib2306 \ > + lib2402 lib2404 \ > +- lib2502 \ > ++ lib2502 lib2506 \ > + lib3010 lib3025 lib3026 lib3027 \ > + lib3100 lib3101 lib3102 lib3103 > + > +@@ -684,6 +684,9 @@ lib2404_LDADD =3D $(TESTUTIL_LIBS) > + lib2502_SOURCES =3D lib2502.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) > + lib2502_LDADD =3D $(TESTUTIL_LIBS) > + > ++lib2506_SOURCES =3D lib2506.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) > ++lib2506_LDADD =3D $(TESTUTIL_LIBS) > ++ > + lib3010_SOURCES =3D lib3010.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) > + lib3010_LDADD =3D $(TESTUTIL_LIBS) > + > +diff --git a/tests/libtest/lib2506.c b/tests/libtest/lib2506.c > +new file mode 100644 > +index 0000000000..e6dde18507 > +--- /dev/null > ++++ b/tests/libtest/lib2506.c > +@@ -0,0 +1,71 @@ > ++/**********************************************************************= ***** > ++ * _ _ ____ _ > ++ * Project ___| | | | _ \| | > ++ * / __| | | | |_) | | > ++ * | (__| |_| | _ <| |___ > ++ * \___|\___/|_| \_\_____| > ++ * > ++ * Copyright (C) Linus Nielsen Feltzing > ++ * > ++ * This software is licensed as described in the file COPYING, which > ++ * you should have received as part of this distribution. The terms > ++ * are also available at https://curl.se/docs/copyright.html. > ++ * > ++ * You may opt to use, copy, modify, merge, publish, distribute and/or = sell > ++ * copies of the Software, and permit persons to whom the Software is > ++ * furnished to do so, under the terms of the COPYING file. > ++ * > ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY O= F ANY > ++ * KIND, either express or implied. > ++ * > ++ * SPDX-License-Identifier: curl > ++ * > ++ **********************************************************************= *****/ > ++#include "test.h" > ++ > ++#include "testtrace.h" > ++ > ++static size_t sink2506(char *ptr, size_t size, size_t nmemb, void *ud) > ++{ > ++ (void)ptr; > ++ (void)ud; > ++ return size * nmemb; > ++} > ++ > ++int test(char *URL) > ++{ > ++ CURL *curl; > ++ int res =3D CURLE_OUT_OF_MEMORY; > ++ > ++ if(curl_global_init(CURL_GLOBAL_ALL) !=3D CURLE_OK) { > ++ curl_mfprintf(stderr, "curl_global_init() failed\n"); > ++ return TEST_ERR_MAJOR_BAD; > ++ } > ++ > ++ curl =3D curl_easy_init(); > ++ if(!curl) { > ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); > ++ curl_global_cleanup(); > ++ return TEST_ERR_MAJOR_BAD; > ++ } > ++ > ++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2506); > ++ test_setopt(curl, CURLOPT_PROXY, URL); > ++ test_setopt(curl, CURLOPT_URL, libtest_arg2); > ++ test_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL); > ++ test_setopt(curl, CURLOPT_NETRC_FILE, libtest_arg3); > ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); > ++ test_setopt(curl, CURLOPT_VERBOSE, 1L); > ++ > ++ /* CURLOPT_UNRESTRICTED_AUTH should not make a difference because the > ++ credentials come from netrc */ > ++ test_setopt(curl, CURLOPT_UNRESTRICTED_AUTH, 1L); > ++ > ++ res =3D curl_easy_perform(curl); > ++ > ++test_cleanup: > ++ curl_easy_cleanup(curl); > ++ curl_global_cleanup(); > ++ > ++ return res; > ++} > diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-suppo= rt/curl/curl_8.7.1.bb > index 2b988654c41..8e39d821626 100644 > --- a/meta/recipes-support/curl/curl_8.7.1.bb > +++ b/meta/recipes-support/curl/curl_8.7.1.bb > @@ -40,6 +40,7 @@ SRC_URI =3D " \ > file://CVE-2026-6276.patch \ > file://CVE-2026-5545.patch \ > file://CVE-2026-6253.patch \ > + file://CVE-2026-6429.patch \ > " > =20 > SRC_URI:append:class-nativesdk =3D " \ I'll have to drop this patch because it is triggering a warning in the autobuilder's ptest jobs qemuarm64-ptest[1] and qemux86-64-ptest[2]. It causes curl ptests 1159 & 1543 to fail : `FAIL: 1159 - HTTP Location: and 'redirect_url' with non-supported scheme` `FAIL: 1543 - CURLOPT_CURLU, URL with space and CURLINFO_EFFECTIVE_URL` I'll drop the next patch of the series too (curl: fix CVE-2026-7168), because it not applied anymore without this one. [1] https://autobuilder.yoctoproject.org/valkyrie/#/builders/61/builds/4320 [2] https://autobuilder.yoctoproject.org/valkyrie/#/builders/73/builds/4336 --=20 Fabien Thomas Smile ECS