From patchwork Tue Aug 4 10:33:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Rathore X-Patchwork-Id: 94419 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1DA6AC5518F for ; Tue, 4 Aug 2026 10:33:41 +0000 (UTC) Received: from aer-iport-2.cisco.com (aer-iport-2.cisco.com [173.38.203.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13358.1785839617522410577 for ; Tue, 04 Aug 2026 03:33:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=BVx2g6uS; spf=pass (domain: cisco.com, ip: 173.38.203.52, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3877; q=dns/txt; s=iport01; t=1785839617; x=1787049217; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=+Cuo21ozdDdcvbLYrgjR7XCRvQyd4Dpbf6j0BQ8c3uY=; b=BVx2g6uSwjhClGn8K/OVrmE+hRyRdt5Y69lP0MJa8KZsKL1JZb6uyaRz g+YQ89pkFSI6leZS1dUfkw0QZI351zNxcI9wzu3AeVoFzFTs/ApRzlsKs zov6qqG5/RaetdRmCQwVdOmKPy3mWqJTh20DPABCHOisjrihQFyisu0Hf biA2n4kca70v2iiM7YaNHnq8RUBqCjgohYXSi9v5sihjuF1L9gOsKkHQx YXMwYKtAUP4OR0xfBy2ftdb8FrNX6vyoT9STR42O4M7674CrjRxxs54ZZ choCi7OnruMi5Sj/WBbgNLZZY7YdVXQyPDwboMJXEJknsOAiy64GySdO9 Q==; X-CSE-ConnectionGUID: 6g4HRCLoTACw+pEY8GbDgg== X-CSE-MsgGUID: MbaU1vVpRmSoW26Nc3V6WQ== X-IPAS-Result: A0BHAgCJv3Fq/9BK/pBaHgEBCxIMggULgld0X0JJlCmCIQOeG4F+DwEBAQ9EDQQBAYUFAo1nAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDJwsBGAE9HAMBAi8rIwgRCIMCAYJ0AxEGvmiBeTOBAYMoAT8CAkABUNsuAQsUAYE4hT+IIV0YAYR8JxsbgXKBFYNpgQWBXAIBgVCGVASCIoEMgVqQeUiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsHBYEdgSsshFMjGTZ8gS91SnUtahIXgRqDFQKCekMLGA1IESw3FBkEPm4HjgYggkQBLDQtASkBAYIFOAUMkxZCkXmhEgoog3WMIZU6GjOqbJkIjgqWAAFPhGmBaDyBWXAVgyIJFjQZD444g2uGQMVhPDUCCTIBAQcCBw4DC4FokAKBfAEB IronPort-Data: A9a23:F1tDdapOL5Gh+L7uRHh9YshUwCBeBmJMZBIvgKrLsJaIsI4StFCzt garIBnSa6nbY2Ghed4lOo2woxwFvcfSnNc3HgRr+3g3ES8Xo+PIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOCn9j8kif3gqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrT8E835ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0rh4XUF03 tgfFBkmcVObqtPm77iXReY506zPLOGzVG8eknht13TdSP0hW52GG/qM7t5D1zB2jcdLdRrcT 5NFNXw1MUiGPEEJYA9HYH49tL/Aan3XfzBVsluJpa0f6GnIxws327/oWDbQUoHbGZwFxx3Iz o7A10HzCyxDKuKH8z++9U322MnExh2lZ7tHQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS4QyXj66R6AGDCy1cEXhKaccts4k9QjlCO kK1ou4FzAdH6NW9IU9xPJ/Nxd9uEUD59VM/WBI= IronPort-HdrOrdr: A9a23:waA9nKlHXK9eyUwVoKC50039oWvpDfIA3DAbv31ZSRFFG/Fw8P re+MjzuiWbtN98YhwdcJW7Scq9qBDnhPtICPcqXItKNTOO0ADDEGgh1/qB/9SKIULDH4BmuZ uIC5IfNPTASX5nkM39/A60V/wkwNWB7eSUoN229QYLcemvAJsQljuQzW2gYytLeDU= X-Talos-CUID: 9a23:Qda4zWgcGBLv7DVVqiVEFYFNUDJuLHKB7E37B0iEIE12C6W4eA+/8o9rnJ87 X-Talos-MUID: 9a23:+LZdHA6lyL1rgLYQLmigHnq9xoxN6a2TUV4zia8DgM67b3JWMGyj0guOF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,204,1779148800"; d="scan'208";a="59418138" Received: from aer-l-core-07.cisco.com ([144.254.74.208]) by aer-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Aug 2026 10:33:13 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by aer-l-core-07.cisco.com (Postfix) with ESMTPS id 585A918000215 for ; Tue, 4 Aug 2026 10:33:13 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 163ADCC037D; Tue, 4 Aug 2026 16:03:12 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 1/5] curl: fix CVE-2026-4873 Date: Tue, 4 Aug 2026 16:03:01 +0530 Message-Id: <20260804103305.1180770-1-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260629104801.972184-1-adongare@cisco.com> References: <20260629104801.972184-1-adongare@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: aer-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 10:33:41 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242710 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-4873. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865 [2] https://curl.se/docs/CVE-2026-4873.html Signed-off-by: Deepak Rathore --- - Changes from v1 to v2: Rebase the patches on top of scarthgap latest fixes and updated the patch to include the fixed commit instead of CVE_STATUS as per Paul's suggestion in Wrynose series. .../curl/curl/CVE-2026-4873.patch | 58 +++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 59 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-4873.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-4873.patch b/meta/recipes-support/curl/curl/CVE-2026-4873.patch new file mode 100644 index 0000000000..bc6268da7d --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-4873.patch @@ -0,0 +1,58 @@ +From a7e6dd14ee3900226066819a0334defb58c52486 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Tue, 28 Jul 2026 04:35:55 -0700 +Subject: [PATCH] url: do not reuse a non-tls starttls connection if new + requires TLS + +Reported-by: Arkadi Vainbrand + +Closes #21082 + +CVE: CVE-2026-4873 +Upstream-Status: Backport [https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865] + +Backport Changes: +- Upstream adds req_tls to struct url_conn_match, sets match.req_tls in + url_attach_existing(), and enforces it in url_match_ssl_use() when a + clear-text requested scheme is matched with a candidate connection + that is not actually using TLS. +- Scarthgap curl 8.7.1 does not have struct url_conn_match or the + url_attach_existing()/url_match_ssl_use() split. The equivalent reuse + matching still happens directly in ConnectionExists(), so this backport + keeps the same state in a local req_tls variable derived from + data->set.use_ssl. +- The rejection check is placed after the general SSL compatibility + check and uses Curl_conn_is_ssl(check, FIRSTSOCKET). This preserves + valid implicit-TLS IMAPS/POP3S/SMTPS reuse while still rejecting a + clear-text STARTTLS-capable cached connection for a request that + requires TLS. + +(cherry picked from commit 507e7be573b0a76fca597b75ff7cb27a66e7d865) +Signed-off-by: Deepak Rathore +--- + lib/url.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/lib/url.c b/lib/url.c +index 30f215f..c4c5982 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -935,6 +935,7 @@ ConnectionExists(struct Curl_easy *data, + /* plain HTTP with upgrade */ + bool h2upgrade = (data->state.httpwant == CURL_HTTP_VERSION_2_0) && + (needle->handler->protocol & CURLPROTO_HTTP); ++ bool req_tls = data->set.use_ssl >= CURLUSESSL_CONTROL; + + *usethis = NULL; + *force_reuse = FALSE; +@@ -1052,6 +1053,10 @@ ConnectionExists(struct Curl_easy *data, + /* except protocols that have been upgraded via TLS */ + continue; + ++ if(!(needle->handler->flags & PROTOPT_SSL) && ++ req_tls && !Curl_conn_is_ssl(check, FIRSTSOCKET)) ++ continue; ++ + if(needle->bits.conn_to_host != check->bits.conn_to_host) + /* don't mix connections that use the "connect to host" feature and + * connections that don't use this feature */ diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 276526f01e..043143d30d 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -38,6 +38,7 @@ SRC_URI = " \ file://CVE-2026-3784.patch \ file://CVE-2026-5773.patch \ file://CVE-2026-6276.patch \ + file://CVE-2026-4873.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Tue Aug 4 10:33:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Rathore X-Patchwork-Id: 94420 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F21A2C5518F for ; Tue, 4 Aug 2026 10:34:10 +0000 (UTC) Received: from aer-iport-1.cisco.com (aer-iport-1.cisco.com [173.38.203.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13364.1785839645611966325 for ; Tue, 04 Aug 2026 03:34:06 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=itFXgLmy; spf=pass (domain: cisco.com, ip: 173.38.203.51, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2868; q=dns/txt; s=iport01; t=1785839645; x=1787049245; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=xSdb9kKlNXpe8B0ska/QX/MZsUFpiQmJAnObsKaPKOI=; b=itFXgLmyJxpDOFifCAjsiJHR4XS9nsYwqc97rQD7op6awTVkKcWX8KBf JN9pIYC/ww8E82OxjfOXsjuR0MORouLy13vlXKcyWJEGn75Gg2AA0MMtj NotbrBnenxRACn4r/IaRehU/3S2N2VoZ6zjeimpH2z9i3HxnYsGC9BZ+t bFV/atEnMfjcYlGIZ9+m1K3EUX2uunlSDUjPjqdc0zogK9Cf7tZZKbkdu F0/bEZ175y/hXIfcEXfaIU2L9AVDriPP0yrWGfNUURkNMsgjF5TpG/j6Q RZ97QdDKoCLko+2thNE0kFtkl6KHvnO6wX2ZSsYokFu+bNDn7NpymQAlg A==; X-CSE-ConnectionGUID: dJ1oQoVxTSq+hxVyfv+v4w== X-CSE-MsgGUID: DUurKn9uT0SLKiqUi8rbGw== X-IPAS-Result: A0BIAgA4v3Fq/9NK/pBaglmCV3RfQkmUKYIhA54bgX4PAQEBD0QNBAEBhQUCjWcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMnCwEYAT0cAwECLysjCBEIgwIBgnQDEQa+cYF5M4EBgygBPwICQAFQ2y4BCxQBgTiFP4ghXRgBhHwnGxuBcoEVg2mBBYFcAgGBJipchXgEgiKBDIFakHlIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBwWBHYErLIRTIxk2fIEvdUp1LWoSF4EagxUCgnpDCxgNSBEsNxQZBD5uB44GIIJEAQUnNC0BKQKCPQWlXaESCiiDdYwhlToaM6psmQiOCpZQhGmBaDyBWXAVgyIJFjQZD444g2uGQMVhPDUCCTIBAQcCBw4DC4FokAACJoFWAQE IronPort-Data: A9a23:p3ErMaIi2LXZ7b8RFE+RhZQlxSXFcZb7ZxGr2PjKsXjdYENS0mBVm 2YdWD+Ea/neYWrwfI1wPdvl/B5V75XWmoJiSVYd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZsCCSa/kvxWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9i2Yoajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1iLhgxBIom6tpMGCJO5 cIJJi5OcEyc0rfeLLKTEoGAh+wqIdOuOMYUvWttiGiBS/0nWpvEBa7N4Le03h9p2pwIR6uCI ZVFL2A2NXwsYDUXUrsTIJ4zkf2hmnn4WzZZs1mS46Ew5gA/ySQsgeSzbYONKrRmQ+15o1uCh WSX4lihOTU5NcWiyGqf+F2z07qncSTTHdh6+KeD3vlyjVuew2YeBBEbWR6wpuO0okq/QM5Eb UsM9ywjqKI/+ECmQp/6RRLQnZKflhcRQZ9UVuY98gzIk/KS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH6dV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:8C+x0a0FEXg++OcLNPQ82QqjBJ4kLtp133Aq2lEZdPUzSL39qy nAppomPHPP5Qr5HUtQ+uxoW5PwJE80i6QV3WB5B97LN2PbUSmTXeNfBODZrAEIdReTygck78 ddWpk7LsHsBl5nisu/ygy5H9E8hOSjysmT9IDjJ7MHd3ASV0mmhD0JbDqmLg== X-Talos-CUID: 9a23:p46mRG8RCrYfbsd2O6GVv0I2Q8ccdUPN8EzJYE+oN3dnVv6LFUDFrQ== X-Talos-MUID: 9a23:hV0V8QSE/wRoxzHKRXTAuSx4F8E5/pj2M2QukIw7upmePwNvbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,204,1779148800"; d="scan'208";a="59465108" Received: from aer-l-core-10.cisco.com ([144.254.74.211]) by aer-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Aug 2026 10:34:03 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by aer-l-core-10.cisco.com (Postfix) with ESMTPS id 170CC180001F0 for ; Tue, 4 Aug 2026 10:34:03 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id D1F02CC037D; Tue, 4 Aug 2026 16:04:01 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 2/5] curl: fix CVE-2026-5545 Date: Tue, 4 Aug 2026 16:03:02 +0530 Message-Id: <20260804103305.1180770-2-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260804103305.1180770-1-deeratho@cisco.com> References: <20260629104801.972184-1-adongare@cisco.com> <20260804103305.1180770-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: aer-l-core-10.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 10:34:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242711 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-5545. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/33e43985b8f3b9e66691d06e70be0395849856cd [2] https://curl.se/docs/CVE-2026-5545.html Signed-off-by: Deepak Rathore --- - Changes from v1 to v2: Rebase the patches on top of scarthgap latest fixes. .../curl/curl/CVE-2026-5545.patch | 42 +++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 43 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-5545.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-5545.patch b/meta/recipes-support/curl/curl/CVE-2026-5545.patch new file mode 100644 index 0000000000..d012f39b07 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-5545.patch @@ -0,0 +1,42 @@ +From ab96b09b1163659b83b0716abe42662d1e1630ea Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Fri, 5 Jun 2026 01:17:44 -0700 +Subject: [PATCH] url: improve connection reuse on negotiate + +Check state of negotiate to allow proper connection reuse. + +Closes #21203 + +CVE: CVE-2026-5545 +Upstream-Status: Backport [https://github.com/curl/curl/commit/33e43985b8f3b9e66691d06e70be0395849856cd] + +Backport Changes: +- curl-8.7.1 still performs the NTLM/Negotiate reuse logic inline in + ConnectionExists(), so the upstream guard was adapted there. + +(cherry picked from commit 33e43985b8f3b9e66691d06e70be0395849856cd) +Signed-off-by: Deepak Rathore +--- + lib/url.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/lib/url.c b/lib/url.c +index 30f215fd48..1d6e3309f5 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -1219,8 +1219,14 @@ ConnectionExists(struct Curl_easy *data, + Curl_timestrcmp(needle->passwd, check->passwd)) { + + /* we prefer a credential match, but this is at least a connection +- that can be reused and "upgraded" to NTLM */ ++ that can be reused and "upgraded" to NTLM if it does ++ not have any auth ongoing. */ ++#ifdef USE_SPNEGO ++ if((check->http_ntlm_state == NTLMSTATE_NONE) && ++ (check->http_negotiate_state == GSS_AUTHNONE)) ++#else + if(check->http_ntlm_state == NTLMSTATE_NONE) ++#endif + chosen = check; + continue; + } diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 043143d30d..296507eef8 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -39,6 +39,7 @@ SRC_URI = " \ file://CVE-2026-5773.patch \ file://CVE-2026-6276.patch \ file://CVE-2026-4873.patch \ + file://CVE-2026-5545.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Tue Aug 4 10:33:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Rathore X-Patchwork-Id: 94421 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00073C55172 for ; Tue, 4 Aug 2026 10:34:20 +0000 (UTC) Received: from aer-iport-5.cisco.com (aer-iport-5.cisco.com [173.38.203.67]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13365.1785839652625183509 for ; Tue, 04 Aug 2026 03:34:13 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=eAuJlrbw; spf=pass (domain: cisco.com, ip: 173.38.203.67, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=12043; q=dns/txt; s=iport01; t=1785839652; x=1787049252; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=IKNUarulDxKf52w0kY7+ixAKMUIUldV3YWIq9RprboI=; b=eAuJlrbwXOLIo6NAS7tFLQESh/2IxzhfmxlcyX5MNsF23blSGN9ki9mc nHP9OzRcX0Ju820s+CQP7sa9dL/6MaE5wGv3AALjfXXueC6h4klU03GCb b4YX+Pp07o4jn8PBj+/zrxETRQM7bhycFaNFzIXKHgV/gGVRdpcG0O4PY fIx+BHaopvJmHBeqfJYkpvbfO7Gg+rQkBlX908l6zC/fRgvTIq4pamidp 9JjdkteI2l+hj8gEExph+1ZC6UDQraW5/qxAg524kz0K+OHyqhxVAb5zF VbSEd9a2+bQbPD7j9keAH3gzCO68OO6a3pLypeIsVGZGqh9PjgalVj6HN Q==; X-CSE-ConnectionGUID: YJv7LUj7SK6rm/b4ETmAuQ== X-CSE-MsgGUID: 5N0xYWe0T7qTuCgkjKN0gA== X-IPAS-Result: A0BIAgA4v3Fq/85K/pBaHgEBCxIMggULgld0X0JJlCmCIQOeG4F+DwEBAQ9EDQQBAYUFAo1nAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDJwsBGAEbIhwDAQIvKyMIEAEIgwIBgnQDEQa+cYF5M4EBgygBPwICQAFQ2y4BCxQBgTiFP4ghXRgBhHwnGxuBcoQIdoEFgVwCAYFHhl0EgiKBDIFagU2PLEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsHBYEdgSsshFMjGTZ8gS91SnUtahIXgRqDFQKCekMLGA1IESw3FBkEPm4HjgYggkMBYSQJAQcMFgEBgSBiCTILHpJoFQEakAOCHoE4n1oKKIN1jCGVOhozhVulEZkIjgqVaGiEaYFoPIFZcBU7gmcJFjQZD44tCwuBeIFohkDFYTw1AgkyAQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:gTt3h6i091NrjbcY/IBvEo7lX161NBEKZh0ujC45NGQN5FlHY01je htvWmGBPv/bZmT8fNpxa9vl90oA68WDmtM1QQJv+y8wEyNjpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+FH1dOOn9SUgvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZeCULOZ82QsaDxMu/rf8EoHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqUp2PgoJVxMq sc7dioIKRrfqt6z6a+CH7wEasQLdKEHPasWt2slyXTSCuwrBMieBa7L/tRfmjw3g6iiH96HO 5ZfM2czKkucJUcXZD/7C7pm9AusrnXyfidRtFKSjaE2+GPUigd21dABNfKIJIzRGpUFxi50o Eqb2TzpMy4XbODA0AaY2X2vhMzpxSzSDdd6+LqQs6QCbEeo7msLBRsbUFG2rfW0hgu1XMhSA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO+Q38kSJj6HT+QvcXjVCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:v/vWuKs3gZxspXcqo7loGHWw7skDWtV00zEX/kB9WHVpm6uj5q STdZsguyMc5Ax9ZJhko6HiBEDiewK4yXcK2+gs1N6ZNWGM0ldAbrsSj7cKqAeOJ8SRzIJgPN 9bE5RWOZnXEUVwi9r87U2TFtYtx8TCzYWT7N2uqEuEiWpRGthdB8ATMHf8LnFL X-Talos-CUID: 9a23:Ibk2kWDwhcN4YH36ExhF6hEwJ8J6SV6D1nKXKROVNWNAVYTAHA== X-Talos-MUID: 9a23:CmMy9gnY1fNhTnvO3jFLdno/Ep940pujUHxSiKkbkMaHNw9WYzi02WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,204,1779148800"; d="scan'208";a="56837880" Received: from aer-l-core-05.cisco.com ([144.254.74.206]) by aer-iport-5.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Aug 2026 10:34:10 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by aer-l-core-05.cisco.com (Postfix) with ESMTPS id 07D6E180003AA for ; Tue, 4 Aug 2026 10:34:10 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id B49C0CC037D; Tue, 4 Aug 2026 16:04:08 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 3/5] curl: fix CVE-2026-6253 Date: Tue, 4 Aug 2026 16:03:03 +0530 Message-Id: <20260804103305.1180770-3-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260804103305.1180770-1-deeratho@cisco.com> References: <20260629104801.972184-1-adongare@cisco.com> <20260804103305.1180770-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: aer-l-core-05.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 10:34:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242712 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-6253. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/188c2f166a20fa97c2325b2da7d0e5cecc13725f [2] https://curl.se/docs/CVE-2026-6253.html Signed-off-by: Deepak Rathore --- - Changes from v1 to v2: Rebase the patches on top of scarthgap latest fixes. .../curl/curl/CVE-2026-6253.patch | 392 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 393 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6253.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-6253.patch b/meta/recipes-support/curl/curl/CVE-2026-6253.patch new file mode 100644 index 0000000000..956beac27b --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6253.patch @@ -0,0 +1,392 @@ +From eb175878ffa07392d6654127f3d4637d4d335c78 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Fri, 5 Jun 2026 01:18:43 -0700 +Subject: [PATCH] http: clear the proxy credentials as well on port or scheme + change + +Add tests 2009-2011 to verify switching between proxies with credentials +when the switch is driven by a redirect + +Reported-by: Dwij Mehta + +Closes #21304 + +CVE: CVE-2026-6253 +Upstream-Status: Backport [https://github.com/curl/curl/commit/188c2f166a20fa97c2325b2da7d0e5cecc13725f] + +Backport Changes: +- The upstream lib/http.c hunk adds the credential resets to + Curl_http_follow(). curl-8.7.1 predates that protocol-specific redirect + handler and carries the equivalent logic in lib/transfer.c via + Curl_follow(), so the full upstream lib/http.c hunk was adapted there. +- The upstream Curl_reset_proxypwd() helper includes a CURL_DISABLE_PROXY + fallback. In curl-8.7.1, the proxy credential fields and string slots are + unconditional and the pre-existing code accesses them without that guard, + so this backport retains the target-version behavior instead. +- curl-8.7.1 uses tests/data/Makefile.inc instead of the upstream + tests/data/Makefile.am list. + +(cherry picked from commit 188c2f166a20fa97c2325b2da7d0e5cecc13725f) +Signed-off-by: Deepak Rathore +--- + lib/transfer.c | 56 ++++++++++++++++++++++++-------- + lib/transfer.h | 2 ++ + tests/data/Makefile.inc | 1 + + tests/data/test2009 | 70 ++++++++++++++++++++++++++++++++++++++++ + tests/data/test2010 | 71 +++++++++++++++++++++++++++++++++++++++++ + tests/data/test2011 | 70 ++++++++++++++++++++++++++++++++++++++++ + 6 files changed, 257 insertions(+), 13 deletions(-) + create mode 100644 tests/data/test2009 + create mode 100644 tests/data/test2010 + create mode 100644 tests/data/test2011 + +diff --git a/lib/transfer.c b/lib/transfer.c +index ccd042b80d..a73462928d 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -553,6 +553,35 @@ void Curl_init_CONNECT(struct Curl_easy *data) + data->state.upload = (data->state.httpreq == HTTPREQ_PUT); + } + ++/* ++ * Restore the user credentials to those set in options. ++ */ ++CURLcode Curl_reset_userpwd(struct Curl_easy *data) ++{ ++ CURLcode result; ++ if(data->set.str[STRING_USERNAME] || data->set.str[STRING_PASSWORD]) ++ data->state.creds_from = CREDS_OPTION; ++ result = Curl_setstropt(&data->state.aptr.user, ++ data->set.str[STRING_USERNAME]); ++ if(!result) ++ result = Curl_setstropt(&data->state.aptr.passwd, ++ data->set.str[STRING_PASSWORD]); ++ return result; ++} ++ ++/* ++ * Restore the proxy credentials to those set in options. ++ */ ++CURLcode Curl_reset_proxypwd(struct Curl_easy *data) ++{ ++ CURLcode result = Curl_setstropt(&data->state.aptr.proxyuser, ++ data->set.str[STRING_PROXYUSERNAME]); ++ if(!result) ++ result = Curl_setstropt(&data->state.aptr.proxypasswd, ++ data->set.str[STRING_PROXYPASSWORD]); ++ return result; ++} ++ + /* + * Curl_pretransfer() is called immediately before a transfer starts, and only + * once for one transfer no matter if it has redirects or do multi-pass +@@ -700,21 +729,10 @@ CURLcode Curl_pretransfer(struct Curl_easy *data) + return CURLE_OUT_OF_MEMORY; + } + +- if(data->set.str[STRING_USERNAME] || +- data->set.str[STRING_PASSWORD]) +- data->state.creds_from = CREDS_OPTION; +- if(!result) +- result = Curl_setstropt(&data->state.aptr.user, +- data->set.str[STRING_USERNAME]); +- if(!result) +- result = Curl_setstropt(&data->state.aptr.passwd, +- data->set.str[STRING_PASSWORD]); + if(!result) +- result = Curl_setstropt(&data->state.aptr.proxyuser, +- data->set.str[STRING_PROXYUSERNAME]); ++ result = Curl_reset_userpwd(data); + if(!result) +- result = Curl_setstropt(&data->state.aptr.proxypasswd, +- data->set.str[STRING_PROXYPASSWORD]); ++ result = Curl_reset_proxypwd(data); + + data->req.headerbytecount = 0; + Curl_headers_cleanup(data); +@@ -759,6 +777,7 @@ CURLcode Curl_follow(struct Curl_easy *data, + bool disallowport = FALSE; + bool reachedmax = FALSE; + CURLUcode uc; ++ CURLcode result; + + DEBUGASSERT(type != FOLLOW_NONE); + +@@ -889,12 +908,23 @@ CURLcode Curl_follow(struct Curl_easy *data, + free(scheme); + } + if(clear) { ++ result = Curl_reset_userpwd(data); ++ if(result) { ++ free(newurl); ++ return result; ++ } + Curl_safefree(data->state.aptr.user); + Curl_safefree(data->state.aptr.passwd); + } + } + } + ++ result = Curl_reset_proxypwd(data); ++ if(result) { ++ free(newurl); ++ return result; ++ } ++ + if(type == FOLLOW_FAKE) { + /* we're only figuring out the new url if we would've followed locations + but now we're done so we can get out! */ +diff --git a/lib/transfer.h b/lib/transfer.h +index e65b2b1472..f1a791f1cf 100644 +--- a/lib/transfer.h ++++ b/lib/transfer.h +@@ -31,6 +31,8 @@ char *Curl_checkheaders(const struct Curl_easy *data, + + void Curl_init_CONNECT(struct Curl_easy *data); + ++CURLcode Curl_reset_userpwd(struct Curl_easy *data); ++CURLcode Curl_reset_proxypwd(struct Curl_easy *data); + CURLcode Curl_pretransfer(struct Curl_easy *data); + CURLcode Curl_posttransfer(struct Curl_easy *data); + +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index 9fb92742ee..aafd309a9d 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -231,6 +231,7 @@ test1955 test1956 test1957 test1958 test1959 test1960 test1964 \ + test1970 test1971 test1972 test1973 test1974 test1975 \ + \ + test2000 test2001 test2002 test2003 test2004 test2005 test2006 \ ++test2009 test2010 test2011 \ + \ + test2023 \ + test2024 test2025 test2026 test2027 test2028 test2029 test2030 test2031 \ +diff --git a/tests/data/test2009 b/tests/data/test2009 +new file mode 100644 +index 0000000000..d2fd79e0d6 +--- /dev/null ++++ b/tests/data/test2009 +@@ -0,0 +1,70 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy credentials via env variables, redirect from http to https ++ ++ ++ ++http_proxy=http://user:secret@%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++http://somewhere.example/ --follow --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[user:secret]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ +diff --git a/tests/data/test2010 b/tests/data/test2010 +new file mode 100644 +index 0000000000..443ae9d2f9 +--- /dev/null ++++ b/tests/data/test2010 +@@ -0,0 +1,71 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy credentials via options for two proxies, redirect from http to https ++ ++ ++ ++http_proxy=http://%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++--proxy-user batman:robin http://somewhere.example/ --follow --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[batman:robin]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++Proxy-Authorization: Basic %b64[batman:robin]b64% ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ +diff --git a/tests/data/test2011 b/tests/data/test2011 +new file mode 100644 +index 0000000000..dd4e534248 +--- /dev/null ++++ b/tests/data/test2011 +@@ -0,0 +1,70 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy creds via env, cross-scheme redirect, --location-trusted ++ ++ ++ ++http_proxy=http://user:secret@%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++http://somewhere.example/ --location-trusted --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[user:secret]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 296507eef8..19f24c3205 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -40,6 +40,7 @@ SRC_URI = " \ file://CVE-2026-6276.patch \ file://CVE-2026-4873.patch \ file://CVE-2026-5545.patch \ + file://CVE-2026-6253.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Tue Aug 4 10:33:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Rathore X-Patchwork-Id: 94422 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 144DCC5518F for ; Tue, 4 Aug 2026 10:34:31 +0000 (UTC) Received: from aer-iport-1.cisco.com (aer-iport-1.cisco.com [173.38.203.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13522.1785839669727750299 for ; Tue, 04 Aug 2026 03:34:30 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=i9iRKKpo; spf=pass (domain: cisco.com, ip: 173.38.203.51, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=12505; q=dns/txt; s=iport01; t=1785839669; x=1787049269; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=BOxoMAa9KP2gW30Iuq4Wa6MmD1fQq4qiB0WGACBJOd0=; b=i9iRKKpoH1LxA6XbhniBDB0b/R79NwhBLZUxo3syh5nQXv+L/njQYbEP UYiY4b+MwAQxcrNxaookPQygflrzJ76zlmyRymBljqDc2+zwThx2yMvYc Zq5oV5w53lWQD4MYslcB5UX6KfMKS8Bg5e9Q9d45uy/b4+ylimswWCKOz qCC0iXvAiJ2mTq+yW+K56/OOs9fSr880kBhM6QzeF+U8LLk2+aw5g+lD6 R1OAaWsTzH4W8pMu8BXm5RvlYWQWXRCzIIcQnMjF3inF5lb2ej22MdCJd HoAyYAh4OD/Sj/bfwMun4jStsuTantMdA5fmVQ1p7D1R8RNqIWPEifocA Q==; X-CSE-ConnectionGUID: GlqrE9FBROuSYW3ps9AKgA== X-CSE-MsgGUID: jukT//cjSsKcNXk1yjEAgA== X-IPAS-Result: A0AaAAA4v3Fq/85K/pBaHAEBAQEBAQcBARIBAQQEAQGBfAcBAQsBglZ0X0JJjHKHN4IhA4ETkDeMURSBag8BAQEPRA0EAQGBcQEggnMCjWcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMnCwEYARsiHAMBAhcBARYrIwgQAQiDAgGCdAMRBr5xgXkzgQGDKAExBQkCAkABUNsuAQsUAYE4AYU+iCFdGAGEfCcbG4FygRWCc3aBBYFcAQEBgSIlYAIGhXUEgiKBDIFaHoEKJYFhjUtIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBwWBHYErLIRTIxk2fIEvdUp1LWoSF4EagxUCgnpDCxgNSBEsNxQZBD5uB44GIIJEMS8BIQwBExYBAS9WfTsLHpJ0CQEHkBaCHoE4n1oKKIN1jCGODYctGjOFW6URmQiOCpVnARhQhGmBaDyBRwsHcBWDIgkWNBkPji0LC4F4gWiBf4RBxWE8NQIJMgEBBwIHDgMLgWiQAiSBWAEB IronPort-Data: A9a23:r7DwnKgtIGQntS5OYtkvh2J5X161NBEKZh0ujC45NGQN5FlHY01je htvXm/TOf6CZWKjeowiaNmzpxwFuZbVmNQxTQE5q3xnEnljpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+FH1dOOn9SUgvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZeCULOZ82QsaDxMu/rf8EoHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqU3/v9tLDBg3 8Y/NQs8UUubnLOf472SH7wEasQLdKEHPasWt2slyXTSCuwrBMieBa7L/tRfmjw3g6iiH96HO 5ZfM2czKkucJUcXZD/7C7pm9AusrnXyfidRtFKSjaE2+GPUigd21dABNfKIK4DUGJwPwi50o ErE4mfFRVYRNueE6jGjwnH1l+3itCzSDdd6+LqQs6QCbEeo7msLBRsbUFG2rfW0hgu1XMhSA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO+Q38kSJj6HT+QvcXjVCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:X6mETKnZYXMdeSHvgMyVLJjTv9vpDfIA3DAbv31ZSRFFG/Fw8P re+MjzuiWbtN98YhwdcJW7Scq9qBDnhPtICPcqXItKNTOO0ADDEGgh1/qB/9SKIULDH4BmuZ uIC5IfNPTASX5nkM39/A60V/wkwNWB7eSUoN229QYLcemvAJsQljuQzW2gYytLeDU= X-Talos-CUID: 9a23:ZHu+o2kD0VXXfEYt3TDBwrs1H9nXOVLZ1W39cmGSM0F0c4yqEkeLqYpHnOM7zg== X-Talos-MUID: 9a23:l5NfZQta1lAvGht2782nhixhCIAv6KaVE2MGt6UF4tiGGAV/EmLI X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,204,1779148800"; d="scan'208";a="59465124" Received: from aer-l-core-05.cisco.com ([144.254.74.206]) by aer-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Aug 2026 10:34:27 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by aer-l-core-05.cisco.com (Postfix) with ESMTPS id 5C267180003AA for ; Tue, 4 Aug 2026 10:34:27 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 15A0CCC037D; Tue, 4 Aug 2026 16:04:26 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 4/5] curl: fix CVE-2026-6429 Date: Tue, 4 Aug 2026 16:03:04 +0530 Message-Id: <20260804103305.1180770-4-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260804103305.1180770-1-deeratho@cisco.com> References: <20260629104801.972184-1-adongare@cisco.com> <20260804103305.1180770-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: aer-l-core-05.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 10:34:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242713 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-6429. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 [2] https://curl.se/docs/CVE-2026-6429.html [3] https://nvd.nist.gov/vuln/detail/CVE-2026-6429 Signed-off-by: Deepak Rathore --- - Changes from v1 to v2: Rebase the patches on top of scarthgap latest fixes. .../curl/curl/CVE-2026-6429.patch | 367 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 368 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6429.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-6429.patch b/meta/recipes-support/curl/curl/CVE-2026-6429.patch new file mode 100644 index 0000000000..f4df441aa2 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6429.patch @@ -0,0 +1,367 @@ +From 8191fd6d5677c30579c09a8d0988b47bbf33f65f Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Fri, 5 Jun 2026 01:20:50 -0700 +Subject: [PATCH] http: clear credentials better on redirect + +Verify with test 2506: netrc with redirect using proxy + +Updated test 998 which was wrong. + +Reported-by: Muhamad Arga Reksapati + +Closes #21345 + +CVE: CVE-2026-6429 +Upstream-Status: Backport [https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306] + +Backport Changes: +- The upstream lib/http.c hunk adds the same-origin credential clearing to + Curl_http_follow(). curl-8.7.1 predates that protocol-specific redirect + handler and carries the equivalent redirect logic in lib/transfer.c via + Curl_follow(), so the full upstream lib/http.c hunk was adapted there. +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc + instead of the upstream tests/data/Makefile.am and + tests/libtest/Makefile.am lists. +- curl-8.7.1 does not contain test2504/lib2504, so the new + test2506/lib2506 entries were registered after the nearest existing + test2503/lib2502 entries in the target-version test lists. +- curl-8.7.1 uses the older libtest harness, so first.h, + test_lib2506(), and CURLcode result handling were adapted to test.h, + test(), and int res. +- Scarthgap curl-8.7.1 keeps the same incorrect redirected-request + Authorization expectation in tests/data/test998, so this backport removes + that expectation with an equivalent target-version hunk. + +(cherry picked from commit b4024bf808bd558026fdc6096e8457f199ace306) +Signed-off-by: Deepak Rathore +--- + lib/transfer.c | 103 +++++++++++++++++++++---------------- + tests/data/Makefile.inc | 2 +- + tests/data/test2506 | 64 +++++++++++++++++++++++ + tests/data/test998 | 1 - + tests/libtest/Makefile.inc | 5 +- + tests/libtest/lib2506.c | 71 +++++++++++++++++++++++++ + 6 files changed, 198 insertions(+), 48 deletions(-) + create mode 100644 tests/data/test2506 + create mode 100644 tests/libtest/lib2506.c + +diff --git a/lib/transfer.c b/lib/transfer.c +index a73462928d..0f5bd8ce59 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -865,49 +865,62 @@ CURLcode Curl_follow(struct Curl_easy *data, + if(uc) + return Curl_uc_to_curlcode(uc); + +- /* Clear auth if this redirects to a different port number or protocol, +- unless permitted */ +- if(!data->set.allow_auth_to_other_hosts && (type != FOLLOW_FAKE)) { +- char *portnum; +- int port; +- bool clear = FALSE; +- +- if(data->set.use_port && data->state.allow_port) +- /* a custom port is used */ +- port = (int)data->set.use_port; +- else { +- uc = curl_url_get(data->state.uh, CURLUPART_PORT, &portnum, +- CURLU_DEFAULT_PORT); +- if(uc) { +- free(newurl); +- return Curl_uc_to_curlcode(uc); +- } +- port = atoi(portnum); +- free(portnum); +- } +- if(port != data->info.conn_remote_port) { +- infof(data, "Clear auth, redirects to port from %u to %u", +- data->info.conn_remote_port, port); +- clear = TRUE; ++ { ++ bool same_origin; ++ CURLU *u; ++ char *oldscheme = NULL; ++ char *oldhost = NULL; ++ char *oldport = NULL; ++ char *newscheme = NULL; ++ char *newhost = NULL; ++ char *newport = NULL; ++ ++ u = curl_url(); ++ if(!u) { ++ free(newurl); ++ return CURLE_OUT_OF_MEMORY; + } +- else { +- char *scheme; +- const struct Curl_handler *p; +- uc = curl_url_get(data->state.uh, CURLUPART_SCHEME, &scheme, 0); +- if(uc) { +- free(newurl); +- return Curl_uc_to_curlcode(uc); +- } + +- p = Curl_get_scheme_handler(scheme); +- if(p && (p->protocol != data->info.conn_protocol)) { +- infof(data, "Clear auth, redirects scheme from %s to %s", +- data->info.conn_scheme, scheme); +- clear = TRUE; +- } +- free(scheme); ++ uc = curl_url_set(u, CURLUPART_URL, data->state.url, 0); ++ if(!uc) ++ uc = curl_url_get(u, CURLUPART_SCHEME, &oldscheme, 0); ++ if(!uc) ++ uc = curl_url_get(u, CURLUPART_HOST, &oldhost, 0); ++ if(!uc) ++ uc = curl_url_get(u, CURLUPART_PORT, &oldport, CURLU_DEFAULT_PORT); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_SCHEME, &newscheme, 0); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_HOST, &newhost, 0); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_PORT, &newport, ++ CURLU_DEFAULT_PORT); ++ if(uc) { ++ curl_url_cleanup(u); ++ free(oldscheme); ++ free(oldhost); ++ free(oldport); ++ free(newscheme); ++ free(newhost); ++ free(newport); ++ free(newurl); ++ return Curl_uc_to_curlcode(uc); + } +- if(clear) { ++ ++ same_origin = strcasecompare(oldscheme, newscheme) && ++ strcasecompare(oldhost, newhost) && ++ !strcmp(oldport, newport); ++ ++ curl_url_cleanup(u); ++ free(oldscheme); ++ free(oldhost); ++ free(oldport); ++ free(newscheme); ++ free(newhost); ++ free(newport); ++ ++ if((!same_origin && !data->set.allow_auth_to_other_hosts) || ++ !data->set.str[STRING_USERNAME]) { + result = Curl_reset_userpwd(data); + if(result) { + free(newurl); +@@ -917,12 +930,12 @@ CURLcode Curl_follow(struct Curl_easy *data, + Curl_safefree(data->state.aptr.passwd); + } + } +- } + +- result = Curl_reset_proxypwd(data); +- if(result) { +- free(newurl); +- return result; ++ result = Curl_reset_proxypwd(data); ++ if(result) { ++ free(newurl); ++ return result; ++ } + } + + if(type == FOLLOW_FAKE) { +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index aafd309a9d..f673f86384 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -251,7 +251,7 @@ test2300 test2301 test2302 test2303 test2304 test2305 test2306 test2307 \ + \ + test2400 test2401 test2402 test2403 test2404 \ + \ +-test2500 test2501 test2502 test2503 \ ++test2500 test2501 test2502 test2503 test2506 \ + \ + test2600 test2601 test2602 test2603 \ + \ +diff --git a/tests/data/test2506 b/tests/data/test2506 +new file mode 100644 +index 0000000000..9c65002496 +--- /dev/null ++++ b/tests/data/test2506 +@@ -0,0 +1,64 @@ ++ ++ ++ ++ ++HTTP ++cookies ++ ++ ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 3 ++Location: http://numbertwo.example/%TESTNUMBER0002 ++ ++ok ++ ++ ++HTTP/1.1 200 OK ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 4 ++ ++yes ++ ++ ++ ++ ++ ++http ++ ++ ++proxy ++ ++ ++lib%TESTNUMBER ++ ++ ++netrc with redirect using proxy ++ ++ ++machine site.example login batman password robin ++ ++ ++http://%HOSTIP:%HTTPPORT http://site.example/ %LOGDIR/netrc2506 ++ ++ ++ ++ ++ ++GET http://site.example/ HTTP/1.1 ++Host: site.example ++Authorization: Basic %b64[batman:robin]b64% ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://numbertwo.example/25060002 HTTP/1.1 ++Host: numbertwo.example ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ +diff --git a/tests/data/test998 b/tests/data/test998 +index 0969d4704b..17c0a0e150 100644 +--- a/tests/data/test998 ++++ b/tests/data/test998 +@@ -82,7 +82,6 @@ Proxy-Connection: Keep-Alive + + GET http://somewhere.else.example/a/path/9980002 HTTP/1.1 + Host: somewhere.else.example +- Authorization: Basic YWxiZXJ0bzplaW5zdGVpbg== + User-Agent: curl/%VERSION + Accept: */* + Proxy-Connection: Keep-Alive +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 9f7cec6027..9d3356aaf5 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -75,7 +75,7 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq \ + lib1970 lib1971 lib1972 lib1973 lib1974 lib1975 \ + lib2301 lib2302 lib2304 lib2305 lib2306 \ + lib2402 lib2404 \ +- lib2502 \ ++ lib2502 lib2506 \ + lib3010 lib3025 lib3026 lib3027 \ + lib3100 lib3101 lib3102 lib3103 + +@@ -684,6 +684,9 @@ lib2404_LDADD = $(TESTUTIL_LIBS) + lib2502_SOURCES = lib2502.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib2502_LDADD = $(TESTUTIL_LIBS) + ++lib2506_SOURCES = lib2506.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) ++lib2506_LDADD = $(TESTUTIL_LIBS) ++ + lib3010_SOURCES = lib3010.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib3010_LDADD = $(TESTUTIL_LIBS) + +diff --git a/tests/libtest/lib2506.c b/tests/libtest/lib2506.c +new file mode 100644 +index 0000000000..e6dde18507 +--- /dev/null ++++ b/tests/libtest/lib2506.c +@@ -0,0 +1,71 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Linus Nielsen Feltzing ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++#include "test.h" ++ ++#include "testtrace.h" ++ ++static size_t sink2506(char *ptr, size_t size, size_t nmemb, void *ud) ++{ ++ (void)ptr; ++ (void)ud; ++ return size * nmemb; ++} ++ ++int test(char *URL) ++{ ++ CURL *curl; ++ int res = CURLE_OUT_OF_MEMORY; ++ ++ if(curl_global_init(CURL_GLOBAL_ALL) != CURLE_OK) { ++ curl_mfprintf(stderr, "curl_global_init() failed\n"); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2506); ++ test_setopt(curl, CURLOPT_PROXY, URL); ++ test_setopt(curl, CURLOPT_URL, libtest_arg2); ++ test_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL); ++ test_setopt(curl, CURLOPT_NETRC_FILE, libtest_arg3); ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); ++ test_setopt(curl, CURLOPT_VERBOSE, 1L); ++ ++ /* CURLOPT_UNRESTRICTED_AUTH should not make a difference because the ++ credentials come from netrc */ ++ test_setopt(curl, CURLOPT_UNRESTRICTED_AUTH, 1L); ++ ++ res = curl_easy_perform(curl); ++ ++test_cleanup: ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ ++ return res; ++} diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 19f24c3205..882ab67aae 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -41,6 +41,7 @@ SRC_URI = " \ file://CVE-2026-4873.patch \ file://CVE-2026-5545.patch \ file://CVE-2026-6253.patch \ + file://CVE-2026-6429.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Tue Aug 4 10:33:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Rathore X-Patchwork-Id: 94423 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F2CE7C5518F for ; Tue, 4 Aug 2026 10:34:40 +0000 (UTC) Received: from aer-iport-7.cisco.com (aer-iport-7.cisco.com [173.38.203.69]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13374.1785839676179820818 for ; Tue, 04 Aug 2026 03:34:36 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=MSFEL1BH; spf=pass (domain: cisco.com, ip: 173.38.203.69, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14778; q=dns/txt; s=iport01; t=1785839676; x=1787049276; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=mqIq+mxTVPuVuQUZrSM6+9wvI3Yqo5tAxdvLg5o/j7w=; b=MSFEL1BHvMAs86ob1L3T4BPoqKnByFxC9oard4nnCBgCmAinhO30A12q J0YAb4sf5ECrmT6FB3XXP8CtJUQykFLllXG5ecI3RU7oTNWlnbWE1JUYs GIlbB7epQrl8HHjLgL9YfSVCi50RHQ7dy83HAJzgEfnKTr9DKzOqm4pHr KOUUq6l3E4t0hZzyHKjsN/oxFHjfmweKhAXS+l5+0+7SqOrZax4CfbrVl /VGn30kt/jyVhcGN7trPrD23WHmTNxQ2ahU7oyJMSGPrr2AE+GRO/96E0 +wOmIr4fTV+5LUoudzWR1pn+BgOqtS7WJXVL6WY0ghXhTJ4yZq4f99CGd A==; X-CSE-ConnectionGUID: M8bPsIXjQS6G8Q8aCQadeQ== X-CSE-MsgGUID: x/BRE4ywQTiAIC1MtdUGNg== X-IPAS-Result: A0ACAACZvnFq/8xK/pBaGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQGBfAQBAQEBAQsBglZ0X0JJjHKHN4E1bAOBE50IFIFqDwEBAQ9EDQQBAYFxASCCcwKNZwImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAycLARgBPRwDAQIZFisjCBEIgwIBgnQDEQa+Z4F5M4EBgygBPwICQAFQ2y4BCxQBgTgBhT6IIV0YAYNdgR8nGxuBcoEVgnN2gQWBXAIBAYEhAyACaIV1BIIigQyBWh6BCiWBYY1LSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwcFgR2BKyyEUyMZNnyBL3VKdS1qEheBGoMVAoJ6QwsYDUgRLDcUGQQ+bgeOBiCCDBgZBgExKQYBIQIBCQEpAQEEK1Z9AQE5DB2SdAeQIIIegTiJepVgCiiDdYwhlToaM4VblhKOf5kIjgqVaBhQhGmBaDyBWXAVgyIJCQ00GQ+OLQsLgXiBaIRQcX/FYTw1AgkyAQEHAgcOAwuBaJAmgVgBAQ IronPort-Data: A9a23:d+pLEauAtEd1VFLrY0X/d2UJNufnVAJfMUV32f8akzHdYApBsoF/q tZmKWmPOP3famX2ftp+b4ni9UIP65fdyNRlSwRsq3g9EC5AgMeUXt7xwmUckM+xwmwvaGo9s q3yv/GZdJhcokf0/0nrav666yEgiclkf5KkYMbcICd9WAR4fykojBNnioYRj5Vh6TSDK1vlV eja/YuFZTdJ5xYuajhKs/Lb9Es21BjPkGpwUmIWNKgjUGD2zxH5PLpHTYmtIn3xRJVjH+LSb 47r0LGj82rFyAwmA9Wjn6yTWhVirmn6ZFXmZtJ+AsBOszAazsAA+v9T2Mk0NS+7vw60c+VZk 72hg3AfpTABZcUgkMxFO/VR/roX0aduoNcrKlDn2SCfItGvn3bEm51T4E8K0YIw37Z9OXpvx f4hE24iPinTjsmPyb62c7w57igjBJGD0II3s3x6iDWcBvE8TNWbGOPB5MRT23E7gcUm8fT2P pZFL2AyMFKfP1sVYgt/5JEWxI9EglHzfjBCoU6VooI84nPYy0p6172F3N/9JITTGJwOzh7wS mTu7yPTODxGJcOm9Tus01n1o/PDoAzdV9dHfFG/3rsw6LGJ/UQUEBAQWF6xrPW1h0L7UNVFJ mQQ+zEytu417EGtQ9z3UhG0rXLCuQQTM+e8CMUz5RvIzu/f5ByUQzBfCDVAc9ch8sQxQFTGy 2O0oj8gPhQ32JX9dJ5X3u78Qe+aUcTNEVI/WA== IronPort-HdrOrdr: A9a23:CaUNla25JUENqOElT1AufAqjBJ4kLtp133Aq2lEZdPUzSL39qy nAppomPHPP5Qr5HUtQ+uxoW5PwJE80i6QV3WB5B97LN2PbUSmTXeNfBODZrAEIdReTygck78 ddWpk7LsHsBl5nisu/ygy5H9E8hOSjysmT9IDjJ7MHd3ASV0mmhD0JbDqmLg== X-Talos-CUID: 9a23:wBzozWgUqIE8hOQ3eIS4qAGbQDJuVy3X9GzxE02BMjhGGITFQHSp8a9pqp87 X-Talos-MUID: 9a23:HGwvzQ254bCfySV9crWNZHmWmzUj8+OEMm1RgIo/h8itFAcpHiuRsRuRTdpy X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,204,1779148800"; d="scan'208";a="60151380" Received: from aer-l-core-03.cisco.com ([144.254.74.204]) by aer-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Aug 2026 10:34:33 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by aer-l-core-03.cisco.com (Postfix) with ESMTPS id 7CA3C180006F3 for ; Tue, 4 Aug 2026 10:34:33 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 44238CC037D; Tue, 4 Aug 2026 16:04:32 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 5/5] curl: fix CVE-2026-7168 Date: Tue, 4 Aug 2026 16:03:05 +0530 Message-Id: <20260804103305.1180770-5-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260804103305.1180770-1-deeratho@cisco.com> References: <20260629104801.972184-1-adongare@cisco.com> <20260804103305.1180770-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: aer-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 10:34:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242714 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-7168. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507 [2] https://curl.se/docs/CVE-2026-7168.html Signed-off-by: Deepak Rathore --- - Changes from v1 to v2: Rebase the patches on top of scarthgap latest fixes. .../curl/curl/CVE-2026-7168.patch | 425 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 426 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-7168.patch b/meta/recipes-support/curl/curl/CVE-2026-7168.patch new file mode 100644 index 0000000000..0669be6546 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-7168.patch @@ -0,0 +1,425 @@ +From 0f0bb5efbd1e4f2199eeb98e6c62a7a67242cad2 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Fri, 5 Jun 2026 01:22:37 -0700 +Subject: [PATCH] setopt: clear proxy auth properties when switching + +Verify with test 1588 + +Closes #21453 + +CVE: CVE-2026-7168 +Upstream-Status: Backport [https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507] + +Backport Changes: +- The upstream lib/setopt.c hunk reuses Curl_auth_digest_cleanup() from the + newer tree. curl-8.7.1 does not expose that helper to setopt.c in the same + way, so this backport adds the vauth/vauth.h include before applying the + upstream setproxy() cleanup logic. +- The upstream tree already provides a CURL_DISABLE_DIGEST_AUTH fallback for + Curl_auth_digest_cleanup(). curl-8.7.1 does not, so this backport adds the + equivalent no-op macro in lib/vauth/vauth.h. +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc + instead of the upstream tests/data/Makefile.am and + tests/libtest/Makefile.am lists. +- curl-8.7.1 uses the older libtest harness, so first.h, + test_lib1588(), libtest_arg4, and CURLcode result handling were adapted to + test.h, test(), test_argv[4], and int res. +- curl-8.7.1 does not define the newer digest test feature in runtests.pl. + This backport defines the target harness feature as digest-auth, matching + tests/server/disabled.c, and makes test 1588 require digest-auth. +- The curl-8.7.1 server harness does not handle crlf="headers" correctly on + response data sections for this test, so those attributes were removed from + the two server response blocks and datacheck. The protocol block keeps + crlf="headers" because runtests.pl normalizes protocol verification when any + crlf attribute is present. + +(cherry picked from commit c1cfdf59acbaf9504c4578d4cf56cdd7c8594507) +Signed-off-by: Deepak Rathore +--- + lib/setopt.c | 18 ++++- + lib/vauth/vauth.h | 2 + + tests/data/Makefile.inc | 1 + + tests/data/test1588 | 106 ++++++++++++++++++++++++++ + tests/libtest/Makefile.inc | 5 +- + tests/libtest/lib1588.c | 152 +++++++++++++++++++++++++++++++++++++ + tests/runtests.pl | 2 + + 7 files changed, 283 insertions(+), 3 deletions(-) + create mode 100644 tests/data/test1588 + create mode 100644 tests/libtest/lib1588.c + +diff --git a/lib/setopt.c b/lib/setopt.c +index 8a5a5d7..7eaf309 100644 +--- a/lib/setopt.c ++++ b/lib/setopt.c +@@ -51,6 +51,7 @@ + #include "altsvc.h" + #include "hsts.h" + #include "tftp.h" ++#include "vauth/vauth.h" + #include "strdup.h" + /* The last 3 #include files should be in this order */ + #include "curl_printf.h" +@@ -76,6 +77,20 @@ CURLcode Curl_setstropt(char **charp, const char *s) + return CURLE_OK; + } + ++#ifndef CURL_DISABLE_PROXY ++static CURLcode setproxy(struct Curl_easy *data, const char *proxy) ++{ ++ if((data->set.str[STRING_PROXY] && proxy) && ++ /* there was one set, is this a new one? */ ++ !strcmp(data->set.str[STRING_PROXY], proxy)) ++ return CURLE_OK; /* same one as before */ ++ ++ Curl_auth_digest_cleanup(&data->state.proxydigest); ++ memset(&data->state.authproxy, 0, sizeof(data->state.authproxy)); ++ return Curl_setstropt(&data->set.str[STRING_PROXY], proxy); ++} ++#endif ++ + CURLcode Curl_setblobopt(struct curl_blob **blobp, + const struct curl_blob *blob) + { +@@ -1139,8 +1154,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option, va_list param) + * Setting it to NULL, means no proxy but allows the environment variables + * to decide for us (if CURLOPT_SOCKS_PROXY setting it to NULL). + */ +- result = Curl_setstropt(&data->set.str[STRING_PROXY], +- va_arg(param, char *)); ++ result = setproxy(data, va_arg(param, char *)); + break; + + case CURLOPT_PRE_PROXY: +diff --git a/lib/vauth/vauth.h b/lib/vauth/vauth.h +index 9da0540..bf5c7a3 100644 +--- a/lib/vauth/vauth.h ++++ b/lib/vauth/vauth.h +@@ -119,6 +119,8 @@ CURLcode Curl_auth_create_digest_http_message(struct Curl_easy *data, + + /* This is used to clean up the digest specific data */ + void Curl_auth_digest_cleanup(struct digestdata *digest); ++#else ++#define Curl_auth_digest_cleanup(x) + #endif /* !CURL_DISABLE_DIGEST_AUTH */ + + #ifdef USE_GSASL +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index f673f86..461eb37 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -200,6 +200,7 @@ test1540 test1541 test1542 test1543 test1544 test1545 \ + test1550 test1551 test1552 test1553 test1554 test1555 test1556 test1557 \ + test1558 test1559 test1560 test1561 test1562 test1563 test1564 test1565 \ + test1566 test1567 test1568 test1569 test1570 \ ++test1588 \ + \ + test1590 test1591 test1592 test1593 test1594 test1595 test1596 test1597 \ + test1598 \ +diff --git a/tests/data/test1588 b/tests/data/test1588 +new file mode 100644 +index 0000000..8a3bf81 +--- /dev/null ++++ b/tests/data/test1588 +@@ -0,0 +1,106 @@ ++ ++ ++ ++ ++HTTP ++HTTP GET ++HTTP proxy ++HTTP proxy Digest auth ++multi ++ ++ ++ ++# Server-side ++ ++ ++# this is returned first since we get no proxy-auth ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++And you should ignore this data. ++ ++ ++# then this is returned when we get proxy-auth ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++ ++ ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++ ++ ++ ++# Client-side ++ ++ ++http ++ ++# tool is what to use instead of 'curl' ++ ++lib%TESTNUMBER ++ ++ ++!SSPI ++crypto ++proxy ++digest-auth ++ ++ ++HTTP proxy auth Digest, then change proxy and do it again ++ ++ ++http://test.remote.example.com/path/%TESTNUMBER %HOSTIP %HTTPPORT silly:person custom.set.host.name ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a" ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a" ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 9d3356a..4c42d34 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -62,7 +62,7 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq \ + lib1540 lib1541 lib1542 lib1543 lib1545 \ + lib1550 lib1551 lib1552 lib1553 lib1554 lib1555 lib1556 lib1557 \ + lib1558 lib1559 lib1560 lib1564 lib1565 lib1567 lib1568 lib1569 \ +- lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \ ++ lib1588 lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \ + \ + lib1662 \ + \ +@@ -687,6 +687,9 @@ lib2502_LDADD = $(TESTUTIL_LIBS) + lib2506_SOURCES = lib2506.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib2506_LDADD = $(TESTUTIL_LIBS) + ++lib1588_SOURCES = lib1588.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) ++lib1588_LDADD = $(TESTUTIL_LIBS) ++ + lib3010_SOURCES = lib3010.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib3010_LDADD = $(TESTUTIL_LIBS) + +diff --git a/tests/libtest/lib1588.c b/tests/libtest/lib1588.c +new file mode 100644 +index 0000000..00c6b35 +--- /dev/null ++++ b/tests/libtest/lib1588.c +@@ -0,0 +1,152 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++/* ++ * argv1 = URL ++ * argv2 = proxy host ++ * argv3 = proxy port ++ * argv4 = proxyuser:password ++ */ ++ ++#include "test.h" ++#include "testutil.h" ++ ++static CURLcode init1588(CURL *curl, const char *url, ++ const char *userpwd, const char *proxy) ++{ ++ int res = CURLE_OK; ++ ++ res_easy_setopt(curl, CURLOPT_URL, url); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXY, proxy); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYUSERPWD, userpwd); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYAUTH, CURLAUTH_DIGEST); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L); ++ if(res) ++ goto init_failed; ++#if 0 ++ res_easy_setopt(curl, CURLOPT_HTTPPROXYTUNNEL, 1L); ++ if(res) ++ goto init_failed; ++#endif ++ ++ res_easy_setopt(curl, CURLOPT_HEADER, 1L); ++ if(res) ++ goto init_failed; ++ ++ return CURLE_OK; /* success */ ++ ++init_failed: ++ return (CURLcode)res; /* failure */ ++} ++ ++static CURLcode run1588(CURL *curl, const char *url, const char *userpwd, ++ const char *proxy) ++{ ++ CURLcode res = CURLE_OK; ++ ++ res = init1588(curl, url, userpwd, proxy); ++ if(res) ++ return res; ++ ++ return curl_easy_perform(curl); ++} ++ ++int test(char *URL) ++{ ++ int res = CURLE_OK; ++ CURL *curl = NULL; ++ const char *proxyuserpws; ++ struct curl_slist *host = NULL; ++ struct curl_slist *host2 = NULL; ++ char proxy1_resolve[128]; ++ char proxy2_resolve[128]; ++ char proxy1_connect[128]; ++ char proxy2_connect[128]; ++ ++ if(test_argc < 5) ++ return TEST_ERR_MAJOR_BAD; ++ proxyuserpws = test_argv[4]; ++ ++ curl_msnprintf(proxy1_resolve, sizeof(proxy1_resolve), ++ "firstproxy:%s:%s", libtest_arg3, libtest_arg2); ++ curl_msnprintf(proxy2_resolve, sizeof(proxy2_resolve), ++ "secondproxy:%s:%s", libtest_arg3, libtest_arg2); ++ ++ /* we connect to the fake host name but the right port number */ ++ curl_msnprintf(proxy1_connect, sizeof(proxy1_connect), ++ "firstproxy:%s", libtest_arg3); ++ curl_msnprintf(proxy2_connect, sizeof(proxy2_connect), ++ "secondproxy:%s", libtest_arg3); ++ ++ res_global_init(CURL_GLOBAL_ALL); ++ if(res) ++ return res; ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ host = curl_slist_append(NULL, proxy1_resolve); ++ if(!host) ++ goto test_cleanup; ++ host2 = curl_slist_append(host, proxy2_resolve); ++ if(!host2) ++ goto test_cleanup; ++ host = host2; ++ ++ start_test_timing(); ++ ++ easy_setopt(curl, CURLOPT_RESOLVE, host); ++ ++ res = run1588(curl, URL, proxyuserpws, proxy1_connect); ++ if(res) ++ goto test_cleanup; ++ ++ curl_mfprintf(stderr, "lib1588: now we do the request again\n"); ++ ++ res = run1588(curl, URL, proxyuserpws, proxy2_connect); ++ ++test_cleanup: ++ ++ /* proper cleanup sequence - type PB */ ++ ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ curl_slist_free_all(host); ++ return res; ++} +diff --git a/tests/runtests.pl b/tests/runtests.pl +index ddfab20..b40df55 100755 +--- a/tests/runtests.pl ++++ b/tests/runtests.pl +@@ -637,6 +637,8 @@ sub checksystemfeatures { + $feature{"Kerberos"} = $feat =~ /Kerberos/i; + # SPNEGO enabled + $feature{"SPNEGO"} = $feat =~ /SPNEGO/i; ++ # Digest auth enabled unless disabled by build ++ $feature{"digest-auth"} = 1; + # CharConv enabled + $feature{"CharConv"} = $feat =~ /CharConv/i; + # TLS-SRP enabled +-- +2.35.6 diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 882ab67aae..6b7f6f6f51 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -42,6 +42,7 @@ SRC_URI = " \ file://CVE-2026-5545.patch \ file://CVE-2026-6253.patch \ file://CVE-2026-6429.patch \ + file://CVE-2026-7168.patch \ " SRC_URI:append:class-nativesdk = " \