diff mbox series

[scarthgap,4/8] curl: ignore CVE-2026-8924

Message ID 20261007112403.486499-4-devanshp@cisco.com
State New
Headers show
Series [scarthgap,1/8] curl: set CVE_STATUS for CVE-2026-9547 | expand

Commit Message

Devansh Patel Oct. 7, 2026, 11:23 a.m. UTC
From: Devansh Patel <devanshp@cisco.com>

Analysis:
- curl identifies commit 51beed175dbfc37da3113f6acce60c630c070ce8 as
  the fix for trailing-dot domains bypassing the PSL cookie check. [1]
- The upstream fix changes is_public_suffix() and adds a regression test
  that requires PSL support. [2]
- Scarthgap curl 8.7.1 is configured with --without-libpsl, so the PSL
  check addressed by this fix is not built. [3]
- curl notes that builds without PSL cannot protect against overly broad
  cookies; this status describes the absent PSL check path. [1]
- Hence ignoring the CVE for now.

Reference:
[1] https://curl.se/docs/CVE-2026-8924.html
[2] https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8
[3] https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.7.1.bb?h=scarthgap

Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
 meta/recipes-support/curl/curl_8.7.1.bb | 1 +
 1 file changed, 1 insertion(+)
diff mbox series

Patch

diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb
index 38083b5842..e361e6d6b1 100644
--- a/meta/recipes-support/curl/curl_8.7.1.bb
+++ b/meta/recipes-support/curl/curl_8.7.1.bb
@@ -58,6 +58,7 @@  CVE_STATUS[CVE-2024-32928] = "ignored: CURLOPT_SSL_VERIFYPEER was disabled on go
 CVE_STATUS[CVE-2025-0725] = "not-applicable-config: gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, using zlib 1.2.0.3 or older"
 CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}"
 CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}"
+CVE_STATUS[CVE-2026-8924] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl"
 CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}"
 CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}"
 CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe"