From: "Yoann Congal" <yoann.congal@smile.fr>
To: <deeratho@cisco.com>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][scarthgap][PATCH v3 5/5] curl: fix CVE-2026-7168
Date: Fri, 18 Sep 2026 11:19:39 +0200 [thread overview]
Message-ID: <DLIBX22WN2SX.1MVF74KFYR0Q1@smile.fr> (raw)
In-Reply-To: <20260824094720.2194782-1-deeratho@cisco.com>
Hello,
This patch conflict with other patches in my branch. Because this one
has issues, I will hold it for another cycle, you will have to
refresh/rebase on top of the next merge (or send me a new version that
applies on top of the -nut branch I will push/test later today)
Details of the issues below:
On Mon Aug 24, 2026 at 11:47 AM CEST, Deepak Rathore via lists.openembedded.org wrote:
> From: Deepak Rathore <deeratho@cisco.com>
>
> This patch applies the upstream backport for CVE-2026-7168.
> The upstream fix commit is referenced in [1], and the public
> CVE advisory is referenced in [2].
>
> [1] https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507
> [2] https://curl.se/docs/CVE-2026-7168.html
>
> Signed-off-by: Deepak Rathore <deeratho@cisco.com>
> ---
> Changes in v3:
> - Rebase on top of the revised CVE-2026-6429 patch.
>
> Changes from v1 to v2:
> - Rebase the patches on top of the latest Scarthgap branch.
>
> .../curl/curl/CVE-2026-7168.patch | 425 ++++++++++++++++++
> meta/recipes-support/curl/curl_8.7.1.bb | 1 +
> 2 files changed, 426 insertions(+)
> create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch
>
> diff --git a/meta/recipes-support/curl/curl/CVE-2026-7168.patch b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> new file mode 100644
> index 0000000000..0669be6546
> --- /dev/null
> +++ b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> @@ -0,0 +1,425 @@
> +From 0f0bb5efbd1e4f2199eeb98e6c62a7a67242cad2 Mon Sep 17 00:00:00 2001
> +From: Daniel Stenberg <daniel@haxx.se>
> +Date: Fri, 5 Jun 2026 01:22:37 -0700
> +Subject: [PATCH] setopt: clear proxy auth properties when switching
> +
> +Verify with test 1588
> +
> +Closes #21453
> +
> +CVE: CVE-2026-7168
> +Upstream-Status: Backport [https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507]
> +
> +Backport Changes:
> +- The upstream lib/setopt.c hunk reuses Curl_auth_digest_cleanup() from the
> + newer tree. curl-8.7.1 does not expose that helper to setopt.c in the same
> + way, so this backport adds the vauth/vauth.h include before applying the
> + upstream setproxy() cleanup logic.
> +- The upstream tree already provides a CURL_DISABLE_DIGEST_AUTH fallback for
> + Curl_auth_digest_cleanup(). curl-8.7.1 does not, so this backport adds the
> + equivalent no-op macro in lib/vauth/vauth.h.
> +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc
> + instead of the upstream tests/data/Makefile.am and
> + tests/libtest/Makefile.am lists.
> +- curl-8.7.1 uses the older libtest harness, so first.h,
> + test_lib1588(), libtest_arg4, and CURLcode result handling were adapted to
> + test.h, test(), test_argv[4], and int res.
> +- curl-8.7.1 does not define the newer digest test feature in runtests.pl.
> + This backport defines the target harness feature as digest-auth, matching
> + tests/server/disabled.c, and makes test 1588 require digest-auth.
> +- The curl-8.7.1 server harness does not handle crlf="headers" correctly on
> + response data sections for this test, so those attributes were removed from
> + the two server response blocks and datacheck. The protocol block keeps
> + crlf="headers" because runtests.pl normalizes protocol verification when any
> + crlf attribute is present.
Related to what really changed, the above is mostly noise :-( You have
to filter/check/edit whatever the LLM generates.
> +
> +(cherry picked from commit c1cfdf59acbaf9504c4578d4cf56cdd7c8594507)
> +Signed-off-by: Deepak Rathore <deeratho@cisco.com>
> +---
> + lib/setopt.c | 18 ++++-
> + lib/vauth/vauth.h | 2 +
> + tests/data/Makefile.inc | 1 +
> + tests/data/test1588 | 106 ++++++++++++++++++++++++++
> + tests/libtest/Makefile.inc | 5 +-
> + tests/libtest/lib1588.c | 152 +++++++++++++++++++++++++++++++++++++
> + tests/runtests.pl | 2 +
> + 7 files changed, 283 insertions(+), 3 deletions(-)
> + create mode 100644 tests/data/test1588
> + create mode 100644 tests/libtest/lib1588.c
> +
> +diff --git a/lib/setopt.c b/lib/setopt.c
> +index 8a5a5d7..7eaf309 100644
> +--- a/lib/setopt.c
> ++++ b/lib/setopt.c
> +@@ -51,6 +51,7 @@
> + #include "altsvc.h"
> + #include "hsts.h"
> + #include "tftp.h"
> ++#include "vauth/vauth.h"
> + #include "strdup.h"
> + /* The last 3 #include files should be in this order */
> + #include "curl_printf.h"
> +@@ -76,6 +77,20 @@ CURLcode Curl_setstropt(char **charp, const char *s)
> + return CURLE_OK;
> + }
> +
> ++#ifndef CURL_DISABLE_PROXY
^ This line is new and not explained in the changes
> ++static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
> ++{
> ++ if((data->set.str[STRING_PROXY] && proxy) &&
> ++ /* there was one set, is this a new one? */
> ++ !strcmp(data->set.str[STRING_PROXY], proxy))
> ++ return CURLE_OK; /* same one as before */
> ++
> ++ Curl_auth_digest_cleanup(&data->state.proxydigest);
> ++ memset(&data->state.authproxy, 0, sizeof(data->state.authproxy));
> ++ return Curl_setstropt(&data->set.str[STRING_PROXY], proxy);
> ++}
> ++#endif
> ++
> + CURLcode Curl_setblobopt(struct curl_blob **blobp,
> + const struct curl_blob *blob)
> + {
> [...]
> +diff --git a/tests/libtest/lib1588.c b/tests/libtest/lib1588.c
> +new file mode 100644
> +index 0000000..00c6b35
> +--- /dev/null
> ++++ b/tests/libtest/lib1588.c
> +@@ -0,0 +1,152 @@
> ++ * argv1 = URL
> ++ * argv2 = proxy host
> ++ * argv3 = proxy port
> ++ * argv4 = proxyuser:password
> ++ */
> ++
> ++#include "test.h"
> ++#include "testutil.h"
> ++
> ++static CURLcode init1588(CURL *curl, const char *url,
> ++ const char *userpwd, const char *proxy)
> ++{
> ++ int res = CURLE_OK;
The upstream line is "CURLcode result = CURLE_OK"
why did the type changed? CURLcode is supported and used the line above.
Why did the variable name changed? This create a lot of noise in the
comparison.
> ++
> ++ res_easy_setopt(curl, CURLOPT_URL, url);
> ++ if(res)
> ++ goto init_failed;
> ++
> [...]
> ++int test(char *URL)
> ++{
> ++ int res = CURLE_OK;
> ++ CURL *curl = NULL;
> ++ const char *proxyuserpws;
> ++ struct curl_slist *host = NULL;
> ++ struct curl_slist *host2 = NULL;
> ++ char proxy1_resolve[128];
> ++ char proxy2_resolve[128];
> ++ char proxy1_connect[128];
> ++ char proxy2_connect[128];
> ++
> ++ if(test_argc < 5)
> ++ return TEST_ERR_MAJOR_BAD;
> ++ proxyuserpws = test_argv[4];
Upstream code compares argc to 3 not 5. proxyuserpws is added. Why?
Again, this is important and not explained in the changes (or not clear
enough)
> +diff --git a/tests/runtests.pl b/tests/runtests.pl
> +index ddfab20..b40df55 100755
> +--- a/tests/runtests.pl
> ++++ b/tests/runtests.pl
> +@@ -637,6 +637,8 @@ sub checksystemfeatures {
> + $feature{"Kerberos"} = $feat =~ /Kerberos/i;
> + # SPNEGO enabled
> + $feature{"SPNEGO"} = $feat =~ /SPNEGO/i;
> ++ # Digest auth enabled unless disabled by build
> ++ $feature{"digest-auth"} = 1;
^ This is not part of the upstream commit but is from
another one.
Please don't squash commits like this or when code is needed try to find
the proper commit to backport (even partially).
> + # CharConv enabled
> + $feature{"CharConv"} = $feat =~ /CharConv/i;
> + # TLS-SRP enabled
> +--
> +2.35.6
> diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb
> index 882ab67aae..6b7f6f6f51 100644
> --- a/meta/recipes-support/curl/curl_8.7.1.bb
> +++ b/meta/recipes-support/curl/curl_8.7.1.bb
> @@ -42,6 +42,7 @@ SRC_URI = " \
> file://CVE-2026-5545.patch \
> file://CVE-2026-6253.patch \
> file://CVE-2026-6429.patch \
> + file://CVE-2026-7168.patch \
> "
>
> SRC_URI:append:class-nativesdk = " \
Try to use the interdiff tool to compare the upstream patch and yours,
changes highlighted should be documented (the obvious ones can be
omitted).
Regard,
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-18 9:19 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-29 10:47 [OE-core] [scarthgap] [PATCH 1/7] curl: ignore CVE-2026-4873 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 2/7] curl: fix CVE-2026-5545 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 3/7] curl: ignore CVE-2026-5773 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 4/7] curl: fix CVE-2026-6253 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 5/7] curl: fix CVE-2026-6276 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 6/7] curl: fix CVE-2026-6429 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 10:47 ` [OE-core] [scarthgap] [PATCH 7/7] curl: fix CVE-2026-7168 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 11:53 ` [OE-core] [scarthgap] [PATCH 1/7] curl: ignore CVE-2026-4873 Yoann Congal
2026-06-29 12:08 ` Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-29 12:19 ` [OE-core] " Yoann Congal
2026-07-23 12:58 ` Yoann Congal
2026-07-24 12:58 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-04 10:39 ` Deepak Rathore
2026-08-04 10:33 ` [OE-core][scarthgap][PATCH v2 1/5] curl: fix CVE-2026-4873 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-04 10:33 ` [OE-core][scarthgap][PATCH v2 2/5] curl: fix CVE-2026-5545 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-04 10:33 ` [OE-core][scarthgap][PATCH v2 3/5] curl: fix CVE-2026-6253 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-04 10:33 ` [OE-core][scarthgap][PATCH v2 4/5] curl: fix CVE-2026-6429 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-20 10:37 ` Fabien Thomas
2026-08-24 9:46 ` [OE-core][scarthgap][PATCH v3 " Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-09 6:07 ` [scarthgap][PATCH " Deepak Rathore
2026-08-04 10:33 ` [OE-core][scarthgap][PATCH v2 5/5] curl: fix CVE-2026-7168 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-24 9:47 ` [OE-core][scarthgap][PATCH v3 " Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-09 6:08 ` [scarthgap][PATCH " Deepak Rathore
2026-09-18 9:19 ` Yoann Congal [this message]
2026-09-18 9:21 ` [OE-core][scarthgap][PATCH " Yoann Congal
2026-10-07 11:48 ` [scarthgap][PATCH " Devansh Patel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLIBX22WN2SX.1MVF74KFYR0Q1@smile.fr \
--to=yoann.congal@smile.fr \
--cc=deeratho@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox