From patchwork Wed Oct 7 11:23:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100149 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A3D08CA5FF1 for ; Wed, 7 Oct 2026 11:24:13 +0000 (UTC) Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7414.1791372244554488336 for ; Wed, 07 Oct 2026 04:24:04 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=gLnaeTjb; spf=pass (domain: cisco.com, ip: 173.37.86.73, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1750; q=dns/txt; s=iport01; t=1791372244; x=1792581844; h=from:to:subject:date:message-id:mime-version: content-transfer-encoding; bh=cdcBlgA3TaPyaGDVlOLoXe/uuY88ZIpPfmxLFGVLRnQ=; b=gLnaeTjb43JCgHkqMnX/AhBetRERECB72J4yYZy/9mi5pcI2GxPjsebk xXCPzrBoZo4O+NfBUmp+pOgZGjmjSBfPRhs4HWQeMFy0chlvr6yjufLYW 8cbCeZxWq+QGrtajc4NTcYIaF/8T0FGdo06JKH4kCVjTv7P6ifxC7uUsc 9KZQWZBZo91UMGiF/XzBR9mxTgdG6aa+gSC68cgfu7BLfUAWTRCq2wAT7 Si4lHbyv3iUptiVcB4YfR9c0Cn5mr8Yv8jvnVn44AuiPPjJIvLSnZBzpR eJx3HGYhWcd1uvNUTimX8d29liVi8s/UGXFAwan26xbCcOeMGqBEijiXm A==; X-CSE-ConnectionGUID: jrBAZvfsQOisz1N/fgySgg== X-CSE-MsgGUID: 02xsDK6ISTy4Z7EW7SkBhA== X-IPAS-Result: A0DBAgAdKsZq/4z/Ja1aglmCV3VhQkmUKYIhnh2Bfg8BAQEPRA0EAQGTEAImNQgOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QSwEYAV1cRIMCAYJ0AgERBrVIgiyBAYMpAT8CAkABUNsxAQsUAYE4hUCII3UBhHwnGxuBcoR+gQWBXAMBGIIThXgEgiKBDIF4ZZJySIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BIIIWIxk2eoEJXoErKWEQF4EJggcCglSCAAIBSUEOB0VTCSVDEkcmIggSCQETGjALgRs4PAkoQRcMKRgNSBEsNxUZBD5uB5BbHoJgWgctKgEBgj2lZaEPCiiDdowilToaM6pvLphajgqVNoEahGmBagM3gVlwFTuCZwkWNBkPjjmIfoEtxXkkNQIBATkBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:tVlLY6xm8fgMmEB8TOp6t+dmxyrEfRIJ4+MujC+fZmUNrF6WrkUGy DYaWWuOPPaCa2T3ft52YYq180gC6sSDnYRmT1c6pVhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCKa/lHyYuCJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 4yaT/H3Ygf/hWcsaj1MsspvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJEMsF6Qq5OhsOEZP7 u5BDncDYQG4iO3jldpXSsE07igiBNPgMIVavjRryivUSK59B5vCWK7No9Rf2V/chOgXQq2YP JVfM2cyKk2cO3WjOX9PYH46tOulmHD5aD1AgFmUvqEwpWPUyWSd1ZCwaYqPK4HVHJ89ckCw/ jjW5EjaXDAhCM3D+2WozS2XhcXPtHauMG4VPPjinhJwu3WU3mEVBRgcWFe3rPX8gUmkVvpbK lcI4WwptaU0+UmhQ9XxUhH+p2SL1iPwQPJKGOE8rQXIwa3O7kPBXS4PTyVKb5ots8peqSEW6 2JlVujBXVRH2IB5g1rEnltIhVte4RQoEFI= IronPort-HdrOrdr: A9a23:I7zQ1av9X6/aIDJSpri4Si7m7skDRtV00zEX/kB9WHVpm6uj5q KTdZsguyMc5Ax9ZJhCo6HiBED/exLhHPdOiOF7V4tKNzOIhILHFu1fBPPZowHIKmnZ6vNX07 tmfuxVDd39CkU/sOPBiTPIdurJBLK8gceVbSC09QYIcT1X X-Talos-CUID: 9a23:ImVPC29zHwdWQ/JBGXKVv0wOMOkXbHPG9VDROF3hLyFnR6yuRlDFrQ== X-Talos-MUID: 9a23:ksVm5QiwudQeJhNzs7PYacMpbJ14+IiNVmE2rYRaiZapCnNLOB2dpWHi X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="518295712" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:03 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id 984CB18000591 for ; Wed, 7 Oct 2026 11:24:03 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 4186CCC1611; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 1/8] curl: set CVE_STATUS for CVE-2026-9547 Date: Wed, 7 Oct 2026 04:23:56 -0700 Message-Id: <20261007112403.486499-1-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247387 From: Devansh Patel Analysis: - CVE-2026-9547 is tied to the libssh backend. [1] - Scarthgap curl 8.7.1 does not enable or expose the libssh backend in the recipe. [2] - Hence mark this CVE as not-applicable-config for the default Scarthgap recipe configuration. Reference: [1] https://curl.se/docs/CVE-2026-9547.html [2] https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.7.1.bb?h=scarthgap Signed-off-by: Devansh Patel --- meta/recipes-support/curl/curl_8.7.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index ade637adf3..f3b1c32e93 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -59,6 +59,7 @@ CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'n CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" +CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe" CVE_STATUS[CVE-2026-82209] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Wed Oct 7 11:23:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100151 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B95BECA600A for ; Wed, 7 Oct 2026 11:24:14 +0000 (UTC) Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7413.1791372244554303592 for ; Wed, 07 Oct 2026 04:24:04 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Divf04dQ; spf=pass (domain: cisco.com, ip: 173.37.86.79, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1619; q=dns/txt; s=iport01; t=1791372244; x=1792581844; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=uJ4vVVah33VxJIzxrfesoSEGXu4lNXizXE/wi8slH1M=; b=Divf04dQr19KGj/vjGYcFi0ebCFO5Uf0m6GDtAd3DbCezytmIuT/Ajn6 GRd1sR6pfayDPQD3BqFnokdMJwFlU120CBH7mSyeIUnmQXolx7kHVNfu2 evZVKiQsFDAnreXnFp3JDxb2uNT5ohVX3HmiqbR/jetwlvtuyQjZgCWHK HmkC9gPvSzewjjG046fs8BMfFPOGs/9Z2Wk/T6X1I/xd3xxfrFZpzbQ5F aaRC5FgzkX/kIcnT2JpyHESeIHjzjbMMq8NTPXIYRnU7y7+uc9FZYHKv3 nPmt45gpHsC+gO0zJeVrOPPWmQDQtLUIjgAmLUp6tudg0GoElVbo9tTX0 g==; X-CSE-ConnectionGUID: UEnQ0k/CR3GMV4/+NiHLcg== X-CSE-MsgGUID: /yxPg/YDRqyZzH7ZFNe03g== X-IPAS-Result: A0DHAgCcKsZq/43/Ja1aglmCV3VhQkmUKYIknhqBfg8BAQEPRA0EAQGFBQKOCQImNQgOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QEwIBAzIBGAE9IDErKxmDAgGCdAIBEQa1ZoIsgQGDKQE/AgJAAVDbMgELFAGBOIVAiCN1AYR8JxsbgXKEfoEFgVwDARiCE4V4BIIiehKBeGWSckiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCFiMZNnqBCV6BKylhEBeBCYIHAoJUggACAUlBDgdFUwklQxJHJiIIEgkBExowC4EbODwJKEEXDCkYDUgRLDcVGQQ+bgeQWx6CYFoHLSoCgj2lZaEPCiiDdowilToaM6pvC5h9jgqVNoEahGmBagI4gVlwFTuCZwkWNBkPjjmIfoEtxXkkNQIBATkBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:MErjX6OVYNNF1gPvrR30lsFynXyQoLVcMsEvi/4bfWQNrUonhDNVm GEbUGDQP/iDMGPxe9l3YY+39EoCsMOEn4VnGnM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeap1yFjmD9k/F3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WVzlV e/a+ZWFZgb9g2Esawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj68hDCnhuPsozwL1YJF8Ss r8+KRApZR/W0opawJrjIgVtrt4oIM+uOMYUvWttiGmFS/0nWpvEBa7N4Le03h9p2ZsIRqmYP ZdEL2MzNXwsYDUXUrsTIJ4zgu6unXnnWzZZs1mS46Ew5gA/ySQsiuS2aYeOIoLiqcN92VeIn m2BzkjDGwAoJvzA+xSj/yr3ibqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++Mv0CSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXOIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:Up+TcKhnN+RH3HIavyUbKW2e9HBQXvYji2hC6mlwRA09TyX+rb HLoB1173HJYVoqNU3I3OrwW5VoIkmskKKdn7NxAV7KZmCP0wGVxcNZnOnfKlbbdBEWmNQw6U 4ZSchDIey1K0RmhsDn5wT9OdMhzN6btJ2Mv47lvhBQpcUAUdAY0++/YTzrdHFLeA== X-Talos-CUID: 9a23:jOuRvmlBUmsy1/Fn0Cfa6fs51HDXOUDwyk6IIAiTMz1GbYPJDhy2+YNAmMU7zg== X-Talos-MUID: 9a23:xgtZ7A5CnlmGr0rz4y7/qE2Vxowv8rSWBwc8va8fqvuWFXNCFRGQ1G+4F9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="524315306" Received: from rcdn-l-core-04.cisco.com ([173.37.255.141]) by rcdn-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:03 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-04.cisco.com (Postfix) with ESMTPS id 9D11218000193 for ; Wed, 7 Oct 2026 11:24:03 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 43C2DCBF201; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 2/8] curl: deferred CVE-2026-12064 Date: Wed, 7 Oct 2026 04:23:57 -0700 Message-Id: <20261007112403.486499-2-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247388 From: Devansh Patel Analysis: - CVE-2026-12064 affects SCP and SFTP support with libssh2. [1] - Scarthgap keeps libssh2 optional and disables it by default. [2] - The status reports unpatched when libssh2 is explicitly enabled. - Hence deferring the CVE for now. Reference: [1] https://curl.se/docs/CVE-2026-12064.html [2] https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.7.1.bb?h=scarthgap Signed-off-by: Devansh Patel --- meta/recipes-support/curl/curl_8.7.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index f3b1c32e93..ba2968fc6c 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -61,6 +61,7 @@ CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', ' CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe" CVE_STATUS[CVE-2026-82209] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl" +CVE_STATUS[CVE-2026-12064] = "${@bb.utils.contains('PACKAGECONFIG', 'libssh2', 'unpatched', 'not-applicable-config: SCP/SFTP support is not enabled in PACKAGECONFIG', d)}" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Wed Oct 7 11:23:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100155 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C6272CA600B for ; Wed, 7 Oct 2026 11:24:14 +0000 (UTC) Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7413.1791372244554303592 for ; Wed, 07 Oct 2026 04:24:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=i6pqJUPC; spf=pass (domain: cisco.com, ip: 173.37.86.79, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3619; q=dns/txt; s=iport01; t=1791372244; x=1792581844; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=sE/faF/GoizlWdEKNR5em8Ju03e0AkbvcwSo/8Z0uog=; b=i6pqJUPCUJbZ7xPm2wjhWwABIPWIJaGa4KtiZ8yUb1NubheTTphWohCa 9hzLsDeIVkwhjeh3f7KbST3Z5FTXb/WP5ZgwRoTD34RH1ZTRReIwsYVFA TSgAGHhALWqETSc0kYlL7fzbWUWzm1JfX96z3rhE6/xk3lzxZITgrVJ9m ExY4XWvUXn+VquDTpScLizCI1eyxiLpzPJZ03PdV6P5G7+iFyWA/EaBgO 33YRal+TuE8H1V8Q1Q6pKNxV24Ociy2cQLssdQ8y6EhlBxYX4xZSK1aGs 105yq/Xjs3XP3nTCgVkulduniYvi5u1rYNqJOLaDhVNE5kvPGmq8vEhpu g==; X-CSE-ConnectionGUID: 49exehSgRZ+d3wcaB36nKw== X-CSE-MsgGUID: +0gshxegRCa6PIhkDTSeVQ== X-IPAS-Result: A0BIAgCcKsZq/4z/Ja1aglmCV3VhQkmUKYIhA54agX4PAQEBD0QNBAEBhQUCjgkCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBIBAgEDJwsBGAE9HAMBAi8rIwgQCYMCAYJ0AgERBrVmgXkzgQGDKQE/AgJAAVDbMgELFAGBOIVAiCNdGAGEfCcbG4FygRWDaYEFgVwCAYFQhlQEgiKBDIFak3VIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEgghYjGTZ6gQlegSspYRAXgQmCBwKCVIIAAgFJQQ4HRVMJJUMSRyYiCBIJARMaMAuBGzg8CShBFwwpGA1IESw3FRkEPm4HkFsegmABLDQtASkBAYIDOgeTIEKRfKEPCiiDdowilToaM6pvmQiOCpVoaIRpgWg8gVlwFYMiCRY0GQ+OOYNrhkDFeSQ1AgkyAQEHAgcOAwuBaJACgXwBAQ IronPort-Data: A9a23:Bz6tw6s7x+8PAXLqQzMIP7YiV+fnVAdfMUV32f8akzHdYApBsoF/q tZmKTiAb66ONzajKNEiPorl8hxVvZ/WztVmSgRtr38xHykTgMeUXt7xwmUckM+xwmwvaGo9s q3yv/GZdJhcokf0/0nrb/656yYsjclkf5KkYMbcICd9WAR4fykojBNnioYRj5Vh6TSDK1vlV eja/YuFZzdJ5xYuajhKsvrb90s21BjPkGpwUmIWNKgjUGD2zxH5PLpHTYmtIn3xRJVjH+LSb 47r0LGj82rFyAwmA9Wjn6yTWhVirmn6ZFXmZtJ+AsBOszAazsAA+v9T2Mk0NS+7vw60c+VZk 72hg3AfpTABZcUgkMxFO/VR/roX0aduoNcrKlDn2SCfItGvn3bEm51T4E8K0YIwprd6EWxOz vMiGnMBNQ+IjsjtnrSYVbw57igjBJGD0II3oHpsy3TdSP0hW52GG/6M7t5D1zB2jcdLdRrcT 5NGMnw0M1KaPkAJYwtPYH49tL/Aan3XfzBGoVSOpbIf6GnIxws327/oWDbQUoHQGZ4Mwx3A+ Qoq+Uy6Wh4BNMySxgCu+yyUp+/MsR/AVbwrQejQGvlCxQf7KnYoIBoOWF22pPO0hkKzV5dUL FYZ0i4vtrQpskuzQ9/wWhe1rHKJslgbQdU4LgEhwBuGxqyR50OSAXIJC2YaLtcnr8QxAzct0 zdlgu/UONCmi5XNIVr1y1tehW/a1fQ9RYPaWRI5cA== IronPort-HdrOrdr: A9a23:vi6rGqooen8O73b5ZgVw+0MaV5oHeYIsimQD101hICG9Ffbo8/ xG88506faZslsssTQb6LO90cq7MBbhHOBOgLX5VI3KNGKNhILrFvAB0WKI+VLd8kPFmtK1rZ 0BT4FOTPvtEFN9kcH2pCO8E9om3Z271ZrAv5a485+oJjsaEp2JKGxCe2CmLnE= X-Talos-CUID: 9a23:0KonP2tp5iQaTSDAqlOGlDbS6It5I3DNwXfrLHWKSmoyV7acYwTO/oB7xp8= X-Talos-MUID: 9a23:9ekCFAUvkJAYWuzq/Hy0iypiJMpn2Y+nVngskZYqh/KJCxUlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="524315307" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:03 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id A06EF180001F0 for ; Wed, 7 Oct 2026 11:24:03 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 486DDCBF202; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 3/8] curl: fix CVE-2026-8286 Date: Wed, 7 Oct 2026 04:23:58 -0700 Message-Id: <20261007112403.486499-3-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247390 From: Devansh Patel This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16 [2] https://curl.se/docs/CVE-2026-8286.html Signed-off-by: Devansh Patel --- .../curl/curl/CVE-2026-8286.patch | 60 +++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8286.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-8286.patch b/meta/recipes-support/curl/curl/CVE-2026-8286.patch new file mode 100644 index 0000000000..f05d399eee --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-8286.patch @@ -0,0 +1,60 @@ +From 9fcd9cead5edb8638d4d767bd0077c405b0390be Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Thu, 7 May 2026 10:30:07 +0200 +Subject: [PATCH] url: fix connection reuse for starttls protocols + +When a connection is tested for reuse in a transfer that *may* upgrade +to TLS (commonly via STARTTLS), the SSL configuration must match the +existing connection. + +Reported-by: Andrew Nesbit +Closes #21522 + +CVE: CVE-2026-8286 +Upstream-Status: Backport [https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16] + +Backport Changes: +- curl 8.7.1 predates the url_conn_match refactor. Carry the upstream + may-TLS and require-TLS distinction in ConnectionExists() and keep + the upstream TLS configuration matching behavior. + +(cherry picked from commit a86efdd7ca5433de9231e650f18247de8319ad16) +Signed-off-by: Devansh Patel +--- + lib/url.c | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/lib/url.c b/lib/url.c +index dfcd6f4841..9e1ca0336c 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -935,7 +935,8 @@ ConnectionExists(struct Curl_easy *data, + /* plain HTTP with upgrade */ + bool h2upgrade = (data->state.httpwant == CURL_HTTP_VERSION_2_0) && + (needle->handler->protocol & CURLPROTO_HTTP); +- bool req_tls = data->set.use_ssl >= CURLUSESSL_CONTROL; ++ bool require_tls = data->set.use_ssl >= CURLUSESSL_CONTROL; ++ bool may_tls = data->set.use_ssl > CURLUSESSL_NONE; + + *usethis = NULL; + *force_reuse = FALSE; +@@ -1054,7 +1055,7 @@ ConnectionExists(struct Curl_easy *data, + continue; + + if(!(needle->handler->flags & PROTOPT_SSL) && +- req_tls && !Curl_conn_is_ssl(check, FIRSTSOCKET)) ++ require_tls && !Curl_conn_is_ssl(check, FIRSTSOCKET)) + continue; + + if(needle->bits.conn_to_host != check->bits.conn_to_host) +@@ -1202,8 +1203,8 @@ ConnectionExists(struct Curl_easy *data, + needle->remote_port != check->remote_port) + continue; + +- /* If talking TLS, check needs to use the same SSL options. */ +- if((needle->handler->flags & PROTOPT_SSL) && ++ /* If talking/upgrading to TLS, check needs the same SSL options. */ ++ if(((needle->handler->flags & PROTOPT_SSL) || may_tls) && + !Curl_ssl_conn_config_match(data, check, FALSE)) { + DEBUGF(infof(data, + "Connection #%" CURL_FORMAT_CURL_OFF_T diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index ba2968fc6c..38083b5842 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -42,6 +42,7 @@ SRC_URI = " \ file://CVE-2026-6253.patch \ file://CVE-2026-4873.patch \ file://CVE-2026-13608.patch \ + file://CVE-2026-8286.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Oct 7 11:23:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100152 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 25CB4CA600C for ; Wed, 7 Oct 2026 11:24:15 +0000 (UTC) Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7415.1791372244657212687 for ; Wed, 07 Oct 2026 04:24:04 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=ekLriJsn; spf=pass (domain: cisco.com, ip: 173.37.86.75, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2398; q=dns/txt; s=iport01; t=1791372244; x=1792581844; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=WZzKJXOXY4NIUu9VP/ejiL27MTGzNM+V+kr6AAMZJc0=; b=ekLriJsnc2bIml3zlW5phBbhCmhlge5EsHpuw4AYLDUimdfvn7MK6yEy CL0N+fINiQa2fh3LpqzKdA+SUVL1KLH/pIm/M6kgP1zKv/feEwLuXyk7Y KsKpFuXzR8jZRv1Z1RhsdDIkDBkheDTtaSJTXoEPLNYEiRImj40QvUbDB JdKzgXr4utATxQ9QGZDT2mYIdScALzz1qW5UxZYvxnX2AgDihOyP+/R3j jiuYcXHmgkR0jXN16FB2Fpr1vSwSkI09lgDU74fqUzaK7IA/kc6KkkaDq pJbBC1tcUD6f26uFkJMn8CT0crLpfjaJFHkX/1tyrW8DwGIqOu2YG/DDu w==; X-CSE-ConnectionGUID: aCrLLA6QSdGTcsivVCp+hA== X-CSE-MsgGUID: bXSYS2XOQMWyeDvAAeCfjw== X-IPAS-Result: A0BFAgCcKsZq/5L/Ja1aglmCV3VhQkmUKYIhA54agX4PAQEBD0QNBAEBhQUCjgkCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBMCAQMyARgBPSAxKysZgwIBgnQCAREGtWaCLIEBgykBPwICQAFQ2zIBCxQBgTiFQIgjdQGEfCcbG4FyhH6BBYFcAgEBGIIThXgEgiKBDIF4ZZJySIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BIIIWIxk2eoEJXoErKWEQF4EJggcCglSCAAIBSUEOB0VTCSVDEkcmIggSCQETGjALgRs4PAkoQRcMKRgNSBEsNxUZBD5uB5BbHoJgAVkHLSoBAQSBUDE4pWWhDwoog3aMIpU6GjOqb5kIjgqVNoEahGmBaDyBWXAVO4JnCRY0GQ+OOYNrhROBLcV5JDUCAQEHMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:ktFUBqlRuxf9M1dA/T4Bp6vo5gzQJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIcWDyAOq3bazSjL49zaYzk/UJQ7JTTndMxHVdt/HtmEFtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4Errav6+/SEUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZK31GONgWYubDtMs/3b8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FYQz4MJTKD93z vA3FDsWbw69rPr1wJvuH4GAhux7RCXqFJkUtnclyXTSCuwrBMiSBa7L/tRfmjw3g6iiH96HO JFfMmUpNkmdJUQTZD/7C7pm9AusrnXybTRes1KNjaE2+GPUigd21dABNfKIIYbXH5wNxxzwS mTu9VTCMypABPum7AWU/16yr8bCti35R9dHfFG/3rsw6LGJ/UQUEBAQWF6xrPW1h0L7UNVFJ mQQ+zEytu417EGtQ9z3UhG0rXLCuQQTM+e8CMUg4w2Lj66R6AGDCy1cH3hKaccts4k9QjlCO kK1ou4FzAdH6NW9IU9xPJ/Nxd9uEUD59VM/WBI= IronPort-HdrOrdr: A9a23:uCfyNaPzBnGHB8BcTu2jsMiBIKoaSvp037BN7TEUdfU7SKKlfq yV8cjzkCWE6wr5O0tQ/OxoRpPgfZq0z/cciuMs1PWZLWvbUQCTQ72Kg7GP/9SZIU3D398Y87 t8eK5jD9C1J117gcHmpDScKb8bsb66GGTCv5am85+rJjsaDZ1d0w== X-Talos-CUID: 9a23:tjGFRmyGMEyX2N3BwXkvBgUdMdoBVlSD9UzcDHOzEmd3dpaNCl+5rfY= X-Talos-MUID: 9a23:RQq5IQnOBf/kx0g5PctudnpoBPxZ2P6eL3koroQLl9etHCFbNTWC2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="532521012" Received: from rcdn-l-core-09.cisco.com ([173.37.255.146]) by rcdn-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:03 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-09.cisco.com (Postfix) with ESMTPS id A5BC418000230 for ; Wed, 7 Oct 2026 11:24:03 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 4EAC0CBF203; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 4/8] curl: ignore CVE-2026-8924 Date: Wed, 7 Oct 2026 04:23:59 -0700 Message-Id: <20261007112403.486499-4-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-09.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247389 From: Devansh Patel Analysis: - curl identifies commit 51beed175dbfc37da3113f6acce60c630c070ce8 as the fix for trailing-dot domains bypassing the PSL cookie check. [1] - The upstream fix changes is_public_suffix() and adds a regression test that requires PSL support. [2] - Scarthgap curl 8.7.1 is configured with --without-libpsl, so the PSL check addressed by this fix is not built. [3] - curl notes that builds without PSL cannot protect against overly broad cookies; this status describes the absent PSL check path. [1] - Hence ignoring the CVE for now. Reference: [1] https://curl.se/docs/CVE-2026-8924.html [2] https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8 [3] https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.7.1.bb?h=scarthgap Signed-off-by: Devansh Patel --- meta/recipes-support/curl/curl_8.7.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 38083b5842..e361e6d6b1 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -58,6 +58,7 @@ CVE_STATUS[CVE-2024-32928] = "ignored: CURLOPT_SSL_VERIFYPEER was disabled on go CVE_STATUS[CVE-2025-0725] = "not-applicable-config: gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, using zlib 1.2.0.3 or older" CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" +CVE_STATUS[CVE-2026-8924] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl" CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe" From patchwork Wed Oct 7 11:24:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100156 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8AE1DCA600E for ; Wed, 7 Oct 2026 11:24:15 +0000 (UTC) Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7101.1791372244886186877 for ; Wed, 07 Oct 2026 04:24:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=d+TPxpOK; spf=pass (domain: cisco.com, ip: 173.37.86.80, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14642; q=dns/txt; s=iport01; t=1791372244; x=1792581844; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=DdyBkpyl/P+EZnrPuda4F5M8gs15i+rUaQS8r4quRt8=; b=d+TPxpOKaHxNkqJjVGKQzGTW18NmcFPc2mC1znQ0/in0fDFVQcXZHYN3 8HRFNq0ipiJtszA3smYovcNybA3fep/1k0sWgPI94Xj+JA1VOMBcLkqiu rb6gHkhwdi/qOPWQQ7yYq34y+vpk/jhdewJYb07aBYEnrM4JlTSq+4eoH a0x01bgGC0prLdPKFgQH0vq9rVG5q0g99i/8yQEJzqJFvkUTS9HII8oSR TpmCPuio6PPCnjEN6nlgJtPnBNLE5f+04BUuiwyegoiunA7dxKyyva3B1 wmTCRn+m8OpfRR0GD4pnZF0oNBPtvVCE1Ia6CJk5JSUucavfeJGPEmwNy w==; X-CSE-ConnectionGUID: FncppNKRTmODZeIEpKRytA== X-CSE-MsgGUID: SMiOuU8tRHSpvn3YZ1J/HQ== X-IPAS-Result: A0BKAgCcKsZq/4z/Ja1aglmCV3VhQkmUKYIhA4ETnQcUgWoPAQEBD0QNBAEBgXEBIIJzAo4JAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDZASAQIBAycLARgBPRwDAQIvKyMIGYMCAYJ0AgERBrVmgXkzgQGDKQE/AgJAAVDbMgELFAGBOIVAiCNdGAGDXYEfJxsbgXKBFYJzdoEFgVwCAQGBIQMBERCGXQSCDRWBDIFaHmVKg0GOZ0iBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCFiMZNnqBCV6BKylhEBeBCYIHAoJUggACAUlBDgdFUwklQxJHJiIIEgkBExowC4EbODwJKEEXDCkYDUgRLDcVGQQ+bgeQWx6CKDcBMSkGASECCgETFgEBBCtxYgEBNwIMFQgUklQMJJADgiGBNZ9aCiiDdowilToaM4QEgVeSQJJUmQiOCpU0NBtNhGmBaDyBWXAVO4JnCQkNNBkPji4LC4NghUF/xXkkNQIJMgEBBwIHDgMLgWiQAAEngVYBAQ IronPort-Data: A9a23:Z12zdqkE3mjU33ZZxrZ8Imro5gzQJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIcWzyHM/yPYWX2Kt9zPdm/8B5V6pCBmIJrQAdq+Xo8RVtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4Errav6+/SEUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZK31GONgWYubDtMs/3b8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FaMe8f5vJ0J0y fk/BAIATz2bpNin3JvuH4GAhux7RCXqFJkUtnclyXTSCuwrBMiYBa7L/tRfmjw3g6iiH96HO JFfMmUpNkmdJUQTYj/7C7pm9AusrnXybTRes1KNjaE2+GPUigd21dABNfKIIYXXFJkEwBnwS mTuxEH4JQwnZMCl6QGd7HT3t92Wv2TbYddHfFG/3rsw6LGJ/UQUEBAQWF6xrPW1h0L7UNVFJ mQQ+zEytu417EGtQ9z3UhG0rXLCuQQTM+e8CMUg4w2Lj66R6AGDCy1cFXhKaccts4k9QjlCO kK1ou4FzAdH6NW9IU9xPJ/Nxd9uEUD59VM/WBI= IronPort-HdrOrdr: A9a23:LwJwhqlGlJc70jMHWAT1cE6etkTpDfIA3DAbv31ZSRFFG/Fw8P re+MjzuiWbtN98YhwdcJW7Scq9qBDnhPtICPcqXItKNTOO0ADDEGgh1/qB/9SKIULDH4BmuZ uIC5IfNPTASX5nkM39/A60V/wkwNWB7eSUoN229QYLcemvAJsQljuQzW2gYytLeDU= X-Talos-CUID: 9a23:fQ05UmC2CLWgvKv6Ewdh/1YMPOMfTnj64EXdAmKgKlx4VJTAHA== X-Talos-MUID: 9a23:TmwydQlV1Kq/UO+iOzPmdnpZEcZP/pn+FHotqo0YvZK1B3VSfBek2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="531594967" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-9.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:03 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id AB788180005A6 for ; Wed, 7 Oct 2026 11:24:03 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 53A89CBF204; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 5/8] curl: fix CVE-2026-8927 Date: Wed, 7 Oct 2026 04:24:00 -0700 Message-Id: <20261007112403.486499-5-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247391 From: Devansh Patel This patch applies the upstream fix as referenced in [3], using the commits shown in [1] and [2]. [1] https://github.com/curl/curl/commit/1968b32afd8e41fbb87f8911d15c552c6b705385 [2] https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567 [3] https://curl.se/docs/CVE-2026-8927.html Signed-off-by: Devansh Patel --- .../curl/curl/CVE-2026-8927-dependent.patch | 41 ++ .../curl/curl/CVE-2026-8927.patch | 378 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 2 + 3 files changed, 421 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8927-dependent.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8927.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-8927-dependent.patch b/meta/recipes-support/curl/curl/CVE-2026-8927-dependent.patch new file mode 100644 index 0000000000..20eb2c1c5c --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-8927-dependent.patch @@ -0,0 +1,41 @@ +From a07fc9a9855848da48a4533b85153c681ae1b1a0 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Fri, 25 Apr 2025 08:16:13 +0200 +Subject: [PATCH] tests/buildinfo: former "disabled" now provides more info + +This tool now contains ON/OFF information about features in the build. +This way, runtests gets both positive and negative feature presence with +this. Allows for more flexibility and avoids having to duplicate the +names. + +Closes #17180 + +CVE: CVE-2026-8927 +Upstream-Status: Backport [https://github.com/curl/curl/commit/1968b32afd8e41fbb87f8911d15c552c6b705385] + +Backport Changes: +- curl 8.7.1 uses the older disabled helper instead of buildinfo. + Initialize digest-auth in runtests.pl, then retain the disabled list + pass that clears it when CURL_DISABLE_DIGEST_AUTH is configured. +- Limit this dependency to the digest-auth detection required by the + CVE tests. Omit the buildinfo rename and unrelated feature reports. + +(cherry picked from commit 1968b32afd8e41fbb87f8911d15c552c6b705385) +Signed-off-by: Devansh Patel +--- + tests/runtests.pl | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/tests/runtests.pl b/tests/runtests.pl +index ddfab20e86..b40df554b2 100755 +--- a/tests/runtests.pl ++++ b/tests/runtests.pl +@@ -637,6 +637,8 @@ sub checksystemfeatures { + $feature{"Kerberos"} = $feat =~ /Kerberos/i; + # SPNEGO enabled + $feature{"SPNEGO"} = $feat =~ /SPNEGO/i; ++ # Digest auth enabled unless disabled by build ++ $feature{"digest-auth"} = 1; + # CharConv enabled + $feature{"CharConv"} = $feat =~ /CharConv/i; + # TLS-SRP enabled diff --git a/meta/recipes-support/curl/curl/CVE-2026-8927.patch b/meta/recipes-support/curl/curl/CVE-2026-8927.patch new file mode 100644 index 0000000000..97c25a71f7 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-8927.patch @@ -0,0 +1,378 @@ +From 5f9ea43cf1266112a388673ced1bce30b9a3767d Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 18 May 2026 23:47:11 +0200 +Subject: [PATCH] url: detect proxy changes read from environment + +When a proxy is set from an environment variable, detect if that proxy +is not the same as previously and flush state. + +Verified by test1647: verify changing proxy with env variables and make +sure Digest state is flushed in the second use + +Closes #21666 + +CVE: CVE-2026-8927 +Upstream-Status: Backport [https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567] + +Backport Changes: +- curl 8.7.1 predates the curlx allocation aliases, so use free() + and strdup() for the new envproxy state. +- Keep the parsed proxy string until the shared cleanup path so the + Digest state comparison can use it safely. +- Include vauth/vauth.h because curl 8.7.1 does not otherwise declare + Curl_auth_digest_cleanup(). +- Register test1647 and lib1647 in the target Makefile.inc files. +- Replace first.h and test_lib1647() with test.h and test(). The old + harness has no libtest_arg4, so use test_argv[4] and require five + argv entries before reading it. +- The curl 8.7.1 test macros write to a variable named res. Use + CURLcode res in init1647() and int res in test(); retain upstream + CURLcode result in run1647(), which uses no harness macro. +- Use the curl 8.7.1 feature names digest-auth and lowercase debug. + The dependency patch supplies positive digest-auth detection. + +(cherry picked from commit 5c225384b8d52c67ce8259c6e4203bc57aacb567) +Signed-off-by: Devansh Patel +--- + lib/url.c | 13 +++- + lib/urldata.h | 1 + + tests/data/Makefile.inc | 2 + + tests/data/test1647 | 103 ++++++++++++++++++++++++++++++ + tests/libtest/Makefile.inc | 5 ++ + tests/libtest/lib1647.c | 124 +++++++++++++++++++++++++++++++++++++ + 6 files changed, 247 insertions(+), 1 deletion(-) + create mode 100644 tests/data/test1647 + create mode 100644 tests/libtest/lib1647.c + +diff --git a/lib/url.c b/lib/url.c +index 9e1ca0336c..fe7639713a 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -79,6 +79,7 @@ + #include "share.h" + #include "content_encoding.h" + #include "http_digest.h" ++#include "vauth/vauth.h" + #include "http_negotiate.h" + #include "select.h" + #include "multiif.h" +@@ -331,6 +332,9 @@ CURLcode Curl_close(struct Curl_easy **datap) + Curl_wildcard_dtor(&data->wildcard); + Curl_freeset(data); + Curl_headers_cleanup(data); ++#ifndef CURL_DISABLE_DIGEST_AUTH ++ free(data->state.envproxy); ++#endif + free(data); + return CURLE_OK; + } +@@ -2535,7 +2539,6 @@ static CURLcode create_conn_helper_init_proxy(struct Curl_easy *data, + curl_proxytype ptype = (curl_proxytype)conn->http_proxy.proxytype; + if(proxy) { + result = parse_proxy(data, conn, proxy, ptype); +- Curl_safefree(proxy); /* parse_proxy copies the proxy string */ + if(result) + goto out; + } +@@ -2554,6 +2557,14 @@ static CURLcode create_conn_helper_init_proxy(struct Curl_easy *data, + result = CURLE_UNSUPPORTED_PROTOCOL; + goto out; + #else ++#ifndef CURL_DISABLE_DIGEST_AUTH ++ if(!Curl_safecmp(data->state.envproxy, proxy)) { ++ /* proxy changed */ ++ Curl_auth_digest_cleanup(&data->state.proxydigest); ++ free(data->state.envproxy); ++ data->state.envproxy = strdup(proxy); ++ } ++#endif + /* force this connection's protocol to become HTTP if compatible */ + if(!(conn->handler->protocol & PROTO_FAMILY_HTTP)) { + if((conn->handler->flags & PROTOPT_PROXY_AS_HTTP) && +diff --git a/lib/urldata.h b/lib/urldata.h +index 4fc595a639..d2d9424197 100644 +--- a/lib/urldata.h ++++ b/lib/urldata.h +@@ -1247,6 +1247,7 @@ struct UrlState { + void (*prev_signal)(int sig); + #endif + #ifndef CURL_DISABLE_DIGEST_AUTH ++ char *envproxy; /* last proxy string used for proxy-related state */ + struct digestdata digest; /* state data for host Digest auth */ + struct digestdata proxydigest; /* state data for proxy Digest auth */ + #endif +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index aafd309a9d..f420a8a4f5 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -210,6 +210,8 @@ test1620 test1621 \ + \ + test1630 test1631 test1632 test1633 test1634 test1635 \ + \ ++test1647 \ ++\ + test1650 test1651 test1652 test1653 test1654 test1655 test1656 \ + test1660 test1661 test1662 \ + \ +diff --git a/tests/data/test1647 b/tests/data/test1647 +new file mode 100644 +index 0000000000..ecd1cf01c7 +--- /dev/null ++++ b/tests/data/test1647 +@@ -0,0 +1,103 @@ ++ ++ ++ ++ ++HTTP ++HTTP GET ++HTTP proxy ++HTTP proxy Digest auth ++multi ++ ++ ++ ++# Server-side ++ ++ ++# this is returned first since we get no proxy-auth ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++And you should ignore this data. ++ ++ ++# then this is returned when we get proxy-auth ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++ ++ ++ ++HTTP/1.1 401 OK ++Content-Length: 21 ++Server: no ++ ++Denied access. Leave ++ ++ ++ ++ ++# Client-side ++ ++ ++http ++https-proxy ++https ++ ++# tool is what to use instead of 'curl' ++ ++lib%TESTNUMBER ++ ++ ++!SSPI ++crypto ++proxy ++digest-auth ++debug ++ ++ ++http_proxy=%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPROXYPORT ++CURL_ENTROPY=99376 ++ ++ ++HTTP proxy auth Digest, then change proxy with env var and do it again ++ ++ ++http://test.remote.example.com/path/%TESTNUMBER https://another.example.com:%HTTPSPORT/ daniel:monkey123 another:bump456 ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://test.remote.example.com/path/%TESTNUMBER HTTP/1.1 ++Host: test.remote.example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/%TESTNUMBER HTTP/1.1 ++Host: test.remote.example.com ++Proxy-Authorization: Digest username="daniel", realm="weirdorealm", nonce="12345", uri="/path/%TESTNUMBER", response="7a1672891aff03248887b1a6674b8096" ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ ++CONNECT another.example.com:%HTTPSPORT HTTP/1.1 ++Host: another.example.com:%HTTPSPORT ++Proxy-Connection: Keep-Alive ++ ++ ++ ++# CONNECT fails ++ ++7 ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 9f7cec6027..78e16b0428 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -64,6 +64,8 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq \ + lib1558 lib1559 lib1560 lib1564 lib1565 lib1567 lib1568 lib1569 \ + lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \ + \ ++ lib1647 \ ++ \ + lib1662 \ + \ + lib1900 \ +@@ -540,6 +542,9 @@ lib1597_LDADD = $(TESTUTIL_LIBS) + lib1598_SOURCES = lib1598.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib1598_LDADD = $(TESTUTIL_LIBS) + ++lib1647_SOURCES = lib1647.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) ++lib1647_LDADD = $(TESTUTIL_LIBS) ++ + lib1662_SOURCES = lib1662.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib1662_LDADD = $(TESTUTIL_LIBS) + +diff --git a/tests/libtest/lib1647.c b/tests/libtest/lib1647.c +new file mode 100644 +index 0000000000..16dc9d711c +--- /dev/null ++++ b/tests/libtest/lib1647.c +@@ -0,0 +1,124 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++/* ++ * argv1 = the first URL ++ * argv2 = URL2 ++ * argv3 = credentials 1 ++ * argv4 = credentials 2 ++ */ ++ ++#include "test.h" ++#include "testutil.h" ++ ++/* this is meant to pick up the proxy from the environment variable */ ++static CURLcode init1647(CURL *curl, const char *url, const char *userpwd) ++{ ++ CURLcode res = CURLE_OK; ++ ++ res_easy_setopt(curl, CURLOPT_URL, url); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYUSERPWD, userpwd); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYAUTH, CURLAUTH_DIGEST); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0L); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0L); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXY_SSL_VERIFYPEER, 0L); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXY_SSL_VERIFYHOST, 0L); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L); ++ if(res) ++ goto init_failed; ++ ++ return CURLE_OK; /* success */ ++ ++init_failed: ++ return res; /* failure */ ++} ++ ++static CURLcode run1647(CURL *curl, const char *url, const char *userpwd) ++{ ++ CURLcode result = CURLE_OK; ++ ++ result = init1647(curl, url, userpwd); ++ if(result) ++ return result; ++ ++ return curl_easy_perform(curl); ++} ++ ++int test(char *URL) ++{ ++ int res = CURLE_OK; ++ CURL *curl = NULL; ++ ++ if(test_argc < 5) ++ return TEST_ERR_MAJOR_BAD; ++ ++ res_global_init(CURL_GLOBAL_ALL); ++ if(res) ++ return res; ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ start_test_timing(); ++ ++ curl_mprintf("--- First get '%s'\n", URL); ++ res = run1647(curl, URL, libtest_arg3); ++ if(res) ++ goto test_cleanup; ++ ++ curl_mprintf("--- Then get '%s'\n", libtest_arg2); ++ res = run1647(curl, libtest_arg2, test_argv[4]); ++ ++test_cleanup: ++ ++ /* proper cleanup sequence - type PB */ ++ ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ return res; ++} diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index e361e6d6b1..9f261955ff 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -43,6 +43,8 @@ SRC_URI = " \ file://CVE-2026-4873.patch \ file://CVE-2026-13608.patch \ file://CVE-2026-8286.patch \ + file://CVE-2026-8927-dependent.patch \ + file://CVE-2026-8927.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Oct 7 11:24:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100150 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7E13CA5FFF for ; Wed, 7 Oct 2026 11:24:13 +0000 (UTC) Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7418.1791372245153739668 for ; Wed, 07 Oct 2026 04:24:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=OaptspmH; spf=pass (domain: cisco.com, ip: 173.37.86.77, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=17299; q=dns/txt; s=iport01; t=1791372245; x=1792581845; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=VYfZQEuIjXZKZyIVkm8IsnG0KBZwc54SWggluT+tMcY=; b=OaptspmHfhV7Co0lzb3wXV/WzczeH9uc/o9c5D6N/h1tBiCeZICgmc8z m61tbopExSJuhvu7Qvsycn2xk52Pb1oR+hHixSjG3xLGS3A6GDkAgtIWk 1Tm8NRu5zpk7b++8Qsb2hj7bcRIn8t/kXMmKSQVlws//qPUqGy0Zn3oNH XXcFsVL23Z/lDGFh7tv/u4ncRCjyQXChyboUCLcLZ+G41rs1oSb9o06CW UHG+A0OV2CZmP8hNJBc27mXptWP2UqEEcvIN5oUWyMCp2pnMk4/e1JIT9 eP3HEuKCsBKulYKZfMp3bMoftrJDRzCSyRDeQ7L69BUDdZUtFk7CV4Gz7 Q==; X-CSE-ConnectionGUID: BCpVuS6LS9SyVnpZdU8Lqg== X-CSE-MsgGUID: cFsKAgBTTXK30GiGGvTgBw== X-IPAS-Result: A0BLAgCcKsZq/4//Ja1RCYJZgld1YUJJlCmCIQOeGhSBag8BAQEPRA0EAQGBcQEggnMCjgkCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBIBAgEDJwsBGAE9HAMBAhkWKyMIGYMCAYJ0AgERBrVmgXkzgQGDKQE/AgJAAVDbMgELFAGBOIVAiCNdGAGEfCcbG4FygRWDaYEFgVwCAYEiERRohXUEgg0VgQyBWh5lSoNBiQuFXEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCFiMZNnqBCV6BKylhEBeBCYIHAoJUggACAUlBDgdFUwklQxJHJiIIEgkBExowC4EbODwJKEEXDCkYDUgRLDcVGQQ+bgeQWx6CWQUCFhsvASEMARMWAQEvUIE7AQIMARQIknQHkCCCIYE1n1oKKIN2jCKVOhozhVulFJkIizeCU5U0NGiEaYFoPIFZcBU7gmcJFjQZD44uCwuDYIZAxVghJDUCCTIBAQcCBw4DC4FokCaBWAEB IronPort-Data: A9a23:HJsitaPXsh+7V0TvrR30lsFynXyQoLVcMsEvi/4bfWQNrUp2hTUEy zZMC26Da66Kamegfth0O42wo0IGvcPRyoRlQXM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeap1yFjmD9k/F3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WVzlV e/a+ZWFZgb9g2Esawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj699FFH8rBtM8wbdMEF9I7 c4UFWApdx/W0opawJrjIgVtrt4oIM+uOMYUvWttiGmHS/0nWpvEBa7N4Le03h9p2ZsIRqmYP ZdEL2MzN3wsYDUXUrsTIJ4zgu6unXnnWzZZs1mS46Ew5gA/ySQsi+Kxb4WNJITiqcN9lWiDh UvJ1VjFMjJBbPOe5hWbzn2Gmbqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++MvUCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXMIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:kaXwr6GUYHMLYycJpLqExMeALOsnbusQ8zAXPidKOHhom6Oj+f xG8M536fawskdzZJhCo6HkBED/exLhHPdOiOF7V4tKHjOW2ldAR7sM0WKN+VHd8lXFltJ15O NHb7V0DsH2ABxRiMb35xT9LvMbqeP3l5xBQYzlvg5QpcYAUdAH0ztE X-Talos-CUID: 9a23:+1n4MW0IdpRD7xfnE26Wl7xfMOs9TGDmklPrcnSpN2BxerGoGXuJ9/Yx X-Talos-MUID: 9a23:pXqWkgXO8t0JH6Xq/DTCnxJLO+1U35SNUxgikLoppfWLHzMlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="532477060" Received: from rcdn-l-core-06.cisco.com ([173.37.255.143]) by rcdn-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:04 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-06.cisco.com (Postfix) with ESMTPS id 05D411800026C for ; Wed, 7 Oct 2026 11:24:04 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 5BCDBCBF21E; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 6/8] curl: fix CVE-2026-8932 Date: Wed, 7 Oct 2026 04:24:01 -0700 Message-Id: <20261007112403.486499-6-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247394 From: Devansh Patel This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/curl/curl/commit/7541ae569d82fb308a5e2d94916027da4fa3ba3e [2] https://curl.se/docs/CVE-2026-8932.html Signed-off-by: Devansh Patel --- .../curl/curl/CVE-2026-8932.patch | 427 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 428 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8932.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-8932.patch b/meta/recipes-support/curl/curl/CVE-2026-8932.patch new file mode 100644 index 0000000000..0b539c54ab --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-8932.patch @@ -0,0 +1,427 @@ +From c25faf128bba57a64da636f126773b858b35bc27 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Tue, 19 May 2026 11:47:50 +0200 +Subject: [PATCH] tls: fix incomplete mTLS config in conn reuse and session + cache + +cert_type, key, key_type, key_passwd and key_blob lived in +ssl_config_data but not in ssl_primary_config, so they were invisible to +match_ssl_primary_config() and to the TLS session cache peer key. + +Two easy handles sharing a connection pool could reuse each other's +authenticated connections when they differed only on SSLKEY, SSLKEYTYPE, +KEYPASSWD, SSLCERTTYPE or SSLKEYBLOB. The second handle would silently +inherit the first handle's authenticated identity. + +Promote all five fields into ssl_primary_config so the conn-reuse +predicate and session cache key cover the complete client credential +set. Also replace the fixed ":CCERT" session cache marker with the +actual clientcert path so sessions are not shared across different +client certificates. + +Verified by test 3303 and 3304 + +Reported-By: Joshua Rogers (AISLE Research) +Closes #21667 + +CVE: CVE-2026-8932 +Upstream-Status: Backport [https://github.com/curl/curl/commit/7541ae569d82fb308a5e2d94916027da4fa3ba3e] + +Backport Changes: +- curl 8.7.1 keeps the session cache in vtls.c and stores backend key + properties outside ssl_primary_config. Duplicate those pointers into + the primary configuration so matching and cloning cover reuse. +- Keep the old backend members as aliases, so omit backend-only access + moves in ldap.c, vssh, and the TLS backend files. +- Adapt unit3303 to the curl 8.7.1 harness and allocation helpers. + Include memdebug.h last so cleanup uses the debug allocator's free() + hook. Fold unit3304's case-insensitive cert_type and key_type checks + into it. +- Extend unit3303 with key_blob deep-copy, connection reuse, and TLS + session cache matching checks. +- Omit vtls_scache.c, vtls_scache.h, and unit3304 because their peer + key API does not exist in curl 8.7.1. The vtls.c cache uses the + updated clone and match functions exercised by unit3303. + +(cherry picked from commit 7541ae569d82fb308a5e2d94916027da4fa3ba3e) +Signed-off-by: Devansh Patel +--- + lib/urldata.h | 5 + + lib/vtls/vtls.c | 25 +++++ + tests/data/Makefile.inc | 3 +- + tests/data/test3303 | 23 +++++ + tests/unit/Makefile.inc | 4 +- + tests/unit/unit3303.c | 210 ++++++++++++++++++++++++++++++++++++++++ + 6 files changed, 268 insertions(+), 2 deletions(-) + create mode 100644 tests/data/test3303 + create mode 100644 tests/unit/unit3303.c + +diff --git a/lib/urldata.h b/lib/urldata.h +index d2d9424197..9015515e17 100644 +--- a/lib/urldata.h ++++ b/lib/urldata.h +@@ -286,6 +286,11 @@ struct ssl_primary_config { + char *CAfile; /* certificate to verify peer against */ + char *issuercert; /* optional issuer certificate filename */ + char *clientcert; ++ char *cert_type; /* format for certificate (default: PEM) */ ++ char *key; /* private key file name */ ++ struct curl_blob *key_blob; ++ char *key_type; /* format for private key (default: PEM) */ ++ char *key_passwd; /* plain text private key password */ + char *cipher_list; /* list of ciphers to use */ + char *cipher_list13; /* list of TLS 1.3 cipher suites to use */ + char *pinned_key; +diff --git a/lib/vtls/vtls.c b/lib/vtls/vtls.c +index d13a3cb1b7..c89e8abcc6 100644 +--- a/lib/vtls/vtls.c ++++ b/lib/vtls/vtls.c +@@ -187,10 +187,15 @@ match_ssl_primary_config(struct Curl_easy *data, + blobcmp(c1->cert_blob, c2->cert_blob) && + blobcmp(c1->ca_info_blob, c2->ca_info_blob) && + blobcmp(c1->issuercert_blob, c2->issuercert_blob) && ++ blobcmp(c1->key_blob, c2->key_blob) && + Curl_safecmp(c1->CApath, c2->CApath) && + Curl_safecmp(c1->CAfile, c2->CAfile) && + Curl_safecmp(c1->issuercert, c2->issuercert) && + Curl_safecmp(c1->clientcert, c2->clientcert) && ++ curl_strequal(c1->cert_type, c2->cert_type) && ++ Curl_safecmp(c1->key, c2->key) && ++ curl_strequal(c1->key_type, c2->key_type) && ++ !Curl_timestrcmp(c1->key_passwd, c2->key_passwd) && + #ifdef USE_TLS_SRP + !Curl_timestrcmp(c1->username, c2->username) && + !Curl_timestrcmp(c1->password, c2->password) && +@@ -234,10 +239,15 @@ static bool clone_ssl_primary_config(struct ssl_primary_config *source, + CLONE_BLOB(cert_blob); + CLONE_BLOB(ca_info_blob); + CLONE_BLOB(issuercert_blob); ++ CLONE_BLOB(key_blob); + CLONE_STRING(CApath); + CLONE_STRING(CAfile); + CLONE_STRING(issuercert); + CLONE_STRING(clientcert); ++ CLONE_STRING(cert_type); ++ CLONE_STRING(key); ++ CLONE_STRING(key_type); ++ CLONE_STRING(key_passwd); + CLONE_STRING(cipher_list); + CLONE_STRING(cipher_list13); + CLONE_STRING(pinned_key); +@@ -257,12 +267,17 @@ static void Curl_free_primary_ssl_config(struct ssl_primary_config *sslc) + Curl_safefree(sslc->CAfile); + Curl_safefree(sslc->issuercert); + Curl_safefree(sslc->clientcert); ++ Curl_safefree(sslc->cert_type); ++ Curl_safefree(sslc->key); ++ Curl_safefree(sslc->key_type); ++ Curl_safefree(sslc->key_passwd); + Curl_safefree(sslc->cipher_list); + Curl_safefree(sslc->cipher_list13); + Curl_safefree(sslc->pinned_key); + Curl_safefree(sslc->cert_blob); + Curl_safefree(sslc->ca_info_blob); + Curl_safefree(sslc->issuercert_blob); ++ Curl_safefree(sslc->key_blob); + Curl_safefree(sslc->curves); + Curl_safefree(sslc->CRLfile); + #ifdef USE_TLS_SRP +@@ -297,6 +312,11 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data) + data->set.ssl.key_passwd = data->set.str[STRING_KEY_PASSWD]; + data->set.ssl.primary.clientcert = data->set.str[STRING_CERT]; + data->set.ssl.key_blob = data->set.blobs[BLOB_KEY]; ++ data->set.ssl.primary.cert_type = data->set.ssl.cert_type; ++ data->set.ssl.primary.key = data->set.ssl.key; ++ data->set.ssl.primary.key_type = data->set.ssl.key_type; ++ data->set.ssl.primary.key_passwd = data->set.ssl.key_passwd; ++ data->set.ssl.primary.key_blob = data->set.ssl.key_blob; + + #ifndef CURL_DISABLE_PROXY + data->set.proxy_ssl.primary.CApath = data->set.str[STRING_SSL_CAPATH_PROXY]; +@@ -322,6 +342,11 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data) + data->set.proxy_ssl.key_passwd = data->set.str[STRING_KEY_PASSWD_PROXY]; + data->set.proxy_ssl.primary.clientcert = data->set.str[STRING_CERT_PROXY]; + data->set.proxy_ssl.key_blob = data->set.blobs[BLOB_KEY_PROXY]; ++ data->set.proxy_ssl.primary.cert_type = data->set.proxy_ssl.cert_type; ++ data->set.proxy_ssl.primary.key = data->set.proxy_ssl.key; ++ data->set.proxy_ssl.primary.key_type = data->set.proxy_ssl.key_type; ++ data->set.proxy_ssl.primary.key_passwd = data->set.proxy_ssl.key_passwd; ++ data->set.proxy_ssl.primary.key_blob = data->set.proxy_ssl.key_blob; + #ifdef USE_TLS_SRP + data->set.proxy_ssl.primary.username = + data->set.str[STRING_TLSAUTH_USERNAME_PROXY]; +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index f420a8a4f5..27b1b52a10 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -264,4 +264,5 @@ test3024 test3025 test3026 test3027 test3028 test3029 test3030 \ + \ + test3100 test3101 test3102 test3103 \ + test3200 \ +-test3201 test3202 ++test3201 test3202 \ ++test3303 +diff --git a/tests/data/test3303 b/tests/data/test3303 +new file mode 100644 +index 0000000000..9b52bcb817 +--- /dev/null ++++ b/tests/data/test3303 +@@ -0,0 +1,23 @@ ++ ++ ++ ++ ++unittest ++TLS ++mTLS ++ ++ ++ ++# Client-side ++ ++ ++none ++ ++ ++unittest ++ ++ ++conn-reuse match distinguishes mTLS key, cert_type, key_type and key_passwd fields ++ ++ ++ +diff --git a/tests/unit/Makefile.inc b/tests/unit/Makefile.inc +index 1926b49b3a..afbe29d2b7 100644 +--- a/tests/unit/Makefile.inc ++++ b/tests/unit/Makefile.inc +@@ -39,7 +39,7 @@ UNITPROGS = unit1300 unit1302 unit1303 unit1304 unit1305 unit1307 \ + unit1650 unit1651 unit1652 unit1653 unit1654 unit1655 unit1656 \ + unit1660 unit1661 \ + unit2600 unit2601 unit2602 unit2603 \ +- unit3200 ++ unit3200 unit3303 + + unit1300_SOURCES = unit1300.c $(UNITFILES) + +@@ -134,3 +134,5 @@ unit2602_SOURCES = unit2602.c $(UNITFILES) + unit2603_SOURCES = unit2603.c $(UNITFILES) + + unit3200_SOURCES = unit3200.c $(UNITFILES) ++ ++unit3303_SOURCES = unit3303.c $(UNITFILES) +diff --git a/tests/unit/unit3303.c b/tests/unit/unit3303.c +new file mode 100644 +index 0000000000..f9928b638a +--- /dev/null ++++ b/tests/unit/unit3303.c +@@ -0,0 +1,210 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++#include "curlcheck.h" ++#include "cfilters.h" ++#include "http.h" ++#include "urldata.h" ++ ++#ifdef USE_SSL ++#include "vtls/vtls.h" ++#include "vtls/vtls_int.h" ++#endif ++#include "memdebug.h" /* LAST include file */ ++ ++static CURLcode unit_setup(void) ++{ ++ return curl_global_init(CURL_GLOBAL_ALL); ++} ++ ++static void unit_stop(void) ++{ ++ curl_global_cleanup(); ++} ++ ++UNITTEST_START ++#ifdef USE_SSL ++{ ++ CURL *curl; ++ struct Curl_easy *data; ++ struct connectdata *conn; ++ struct Curl_cfilter cf; ++ struct ssl_connect_data sslctx; ++ struct ssl_primary_config *primary; ++ struct curl_blob key_blob; ++ struct curl_blob alt_key_blob; ++ struct curl_blob *saved_blob; ++ struct curl_blob *saved_conn_blob; ++ void *sessionid; ++ size_t idsize = 0; ++ bool added = FALSE; ++ char fake_session; ++ char *saved; ++ static char alt_passwd[] = "wrong"; ++ static char alt_key[] = "other.key"; ++ static char alt_ktype[] = "DER"; ++ static char alt_ctype[] = "P12"; ++ static char lc_ctype[] = "pem"; ++ static char lc_ktype[] = "pem"; ++ ++ curl = curl_easy_init(); ++ abort_unless(curl, "curl_easy_init failed"); ++ data = (struct Curl_easy *)curl; ++ ++ key_blob.data = (void *)"first private key"; ++ key_blob.len = sizeof("first private key") - 1; ++ key_blob.flags = CURL_BLOB_COPY; ++ alt_key_blob.data = (void *)"second private key"; ++ alt_key_blob.len = sizeof("second private key") - 1; ++ alt_key_blob.flags = CURL_BLOB_NOCOPY; ++ ++ curl_easy_setopt(curl, CURLOPT_SSLCERT, "client.pem"); ++ curl_easy_setopt(curl, CURLOPT_SSLKEY, "client.key"); ++ curl_easy_setopt(curl, CURLOPT_SSLKEY_BLOB, &key_blob); ++ curl_easy_setopt(curl, CURLOPT_KEYPASSWD, "secret"); ++ curl_easy_setopt(curl, CURLOPT_SSLCERTTYPE, "PEM"); ++ curl_easy_setopt(curl, CURLOPT_SSLKEYTYPE, "PEM"); ++ ++ abort_unless(!Curl_ssl_easy_config_complete(data), ++ "Curl_ssl_easy_config_complete failed"); ++ ++ conn = calloc(1, sizeof(*conn)); ++ abort_unless(conn, "connection allocation failed"); ++ abort_unless(!Curl_ssl_conn_config_init(data, conn), ++ "Curl_ssl_conn_config_init failed"); ++ ++ fail_unless(Curl_ssl_conn_config_match(data, conn, FALSE), ++ "identical mTLS config should match"); ++ ++ primary = &data->set.ssl.primary; ++ ++ fail_unless(conn->ssl_config.key_blob && ++ conn->ssl_config.key_blob != primary->key_blob && ++ conn->ssl_config.key_blob->len == primary->key_blob->len && ++ !memcmp(conn->ssl_config.key_blob->data, ++ primary->key_blob->data, primary->key_blob->len), ++ "key_blob must be cloned into the connection config"); ++ ++ saved_blob = primary->key_blob; ++ primary->key_blob = &alt_key_blob; ++ fail_unless(!Curl_ssl_conn_config_match(data, conn, FALSE), ++ "different key_blob must not reuse conn"); ++ primary->key_blob = saved_blob; ++ ++ saved = primary->key_passwd; ++ primary->key_passwd = alt_passwd; ++ fail_unless(!Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "different key_passwd must not reuse conn"); ++ primary->key_passwd = saved; ++ ++ saved = primary->key; ++ primary->key = alt_key; ++ fail_unless(!Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "different key must not reuse conn"); ++ primary->key = saved; ++ ++ saved = primary->key_type; ++ primary->key_type = alt_ktype; ++ fail_unless(!Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "different key_type must not reuse conn"); ++ primary->key_type = saved; ++ ++ saved = primary->cert_type; ++ primary->cert_type = alt_ctype; ++ fail_unless(!Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "different cert_type must not reuse conn"); ++ primary->cert_type = saved; ++ ++ primary->cert_type = lc_ctype; ++ fail_unless(Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "cert_type comparison must be case-insensitive"); ++ primary->cert_type = saved; ++ ++ primary->key_type = lc_ktype; ++ fail_unless(Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "key_type comparison must be case-insensitive"); ++ primary->key_type = saved; ++ ++ fail_unless(Curl_ssl_conn_config_match((struct Curl_easy *)curl, conn, ++ FALSE), ++ "restored mTLS config should match"); ++ ++ memset(&cf, 0, sizeof(cf)); ++ memset(&sslctx, 0, sizeof(sslctx)); ++ conn->handler = &Curl_handler_https; ++ sslctx.peer.hostname = "example.com"; ++ sslctx.port = 443; ++ cf.cft = &Curl_cft_ssl; ++ cf.ctx = &sslctx; ++ cf.conn = conn; ++ ++ abort_unless(!Curl_ssl_initsessions(data, 1), ++ "Curl_ssl_initsessions failed"); ++ abort_unless(!Curl_ssl_addsessionid(&cf, data, &fake_session, 1, ++ &added), ++ "Curl_ssl_addsessionid failed"); ++ fail_unless(added, "session was not added to the cache"); ++ fail_unless(data->state.session[0].ssl_config.key_blob && ++ data->state.session[0].ssl_config.key_blob != ++ conn->ssl_config.key_blob, ++ "key_blob must be cloned into the session cache"); ++ ++ sessionid = NULL; ++ fail_unless(!Curl_ssl_getsessionid(&cf, data, &sessionid, &idsize) && ++ sessionid == &fake_session, ++ "identical key_blob should reuse the TLS session"); ++ ++ saved_conn_blob = conn->ssl_config.key_blob; ++ conn->ssl_config.key_blob = &alt_key_blob; ++ sessionid = NULL; ++ fail_unless(Curl_ssl_getsessionid(&cf, data, &sessionid, &idsize) && ++ !sessionid, ++ "different key_blob must not reuse the TLS session"); ++ conn->ssl_config.key_blob = saved_conn_blob; ++ ++ sessionid = NULL; ++ fail_unless(!Curl_ssl_getsessionid(&cf, data, &sessionid, &idsize) && ++ sessionid == &fake_session, ++ "restored key_blob should reuse the TLS session"); ++ ++ Curl_ssl_conn_config_cleanup(conn); ++ conn->ssl_config = data->state.session[0].ssl_config; ++ memset(&data->state.session[0].ssl_config, 0, ++ sizeof(data->state.session[0].ssl_config)); ++ free(data->state.session[0].name); ++ data->state.session[0].name = NULL; ++ free(data->state.session[0].conn_to_host); ++ data->state.session[0].conn_to_host = NULL; ++ data->state.session[0].sessionid = NULL; ++ Curl_ssl_conn_config_cleanup(conn); ++ free(conn); ++ curl_easy_cleanup(curl); ++} ++#endif /* USE_SSL */ ++UNITTEST_STOP diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 9f261955ff..6f9a814457 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -45,6 +45,7 @@ SRC_URI = " \ file://CVE-2026-8286.patch \ file://CVE-2026-8927-dependent.patch \ file://CVE-2026-8927.patch \ + file://CVE-2026-8932.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Oct 7 11:24:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100154 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BCD31CA5FFC for ; Wed, 7 Oct 2026 11:24:13 +0000 (UTC) Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7417.1791372245128017974 for ; Wed, 07 Oct 2026 04:24:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=LdT6Xv+P; spf=pass (domain: cisco.com, ip: 173.37.86.74, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=12030; q=dns/txt; s=iport01; t=1791372245; x=1792581845; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=p/hpJJV+7xlhytj9O17kW1VwztZ+Ovblud+wC0jCwdA=; b=LdT6Xv+PJlHLXIkVRk/BWozxX49AGVcelQRXTocTcbsTQLSoiXMJiknT 1eAsvTOs/W7Qd+hEWMHWTbVzVItyxn77UThgqlkxrjia93Kag6UzzXLue 4UkydFODf1tM/9Y3rNH1FlYnz6flovYCKOffRoNqTb5gkERcv122d+Si2 Xm2n/6a6RvoMgGHfxdCcaRm/GsgUNYv33dksG16Gy2Lr1xreFb59Qp2s+ tP9MT2E4X4zo46Y+zlsZseda1660hhhFAW4Wm1hX6/Kd7uHbEuUCrY3Vw XYUFN6Dm4QyQ7AYU/oE/G2sDh2+DebDneCJ/g+yNq6rewkzH5AkPeaGGp A==; X-CSE-ConnectionGUID: TWMQwmluS5mHKLmYpzNeJQ== X-CSE-MsgGUID: Jlg0VhyNS1evK9FQ4J9YEw== X-IPAS-Result: A0BLAgCcKsZq/4r/Ja1aglmCV3VhQkmUKYIhA54aFIFqDwEBAQ9EDQQBAYFxASCCcwKOCQImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QEgECAQMnCwEYAT0cAwECFwEBFisjCBAJgwIBgnQCAREGtWaBeTOBAYMpAT8CAkABUNsyAQsUAYE4hUCII10YAYR8JxsbgXKBFYNpgQWBXAIBgSIlYAIGhXUEgiKBDIFaHoEvjEyFXEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCFiMZNnqBCV6BKylhEBeBCYIHAoJUggACAUlBDgdFUwklQxJHJiIIEgkBExowC4EbODwJKEEXDCkYDUgRLDcVGQQ+bgeQWx6CMy0xLwEhDAETFgEBL1Z4BTsLHpJ0CQEHkBaCIYE1n1oKKIN2jCKODYctGjOqb5kIjgqVaBhQhGmBaDyBWXAVgyIJFjQZD44uCwuDYIZAxXkkNQIJMgEBBwIHDgMLgWiQAiSBWAEB IronPort-Data: A9a23:QtPMe6+p2rY3fuXYPaV1DrUD0X+TJUtcMsCJ2f8bNWPcYEJGY0x3n GYWUGmCP/aNNDfxKYgnPd++oxwCusfcxoQ1HgBlqn1EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmB4E/rbei5xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mtyyHjEAX9gWAtajpLs/vrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kKAqgh5eNzHFoT8 Nw7DDU8dgKlisCPlefTpulE3qzPLeHxN48Z/3UlxjbDALN+GNbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZOE0n1lQ/UPrSmM+ki2f2dSZYsHqepLE85C7YywkZPL3FbYGPK43SGZ0P9qqej kDC8DzHAgA8D4WS1xnU3EvwpL7+sDyuDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjFCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:F7Fz46BE0cB87GjlHemA55DYdb4zR+YMi2TDsHoBLSC9Hfb3qy nDppkmPFrP+VUssRIb6LW90de7IE80nKQdieJ6AV7hZniFhILCFu5fBOXZrwEIYxefysdtkY F9bqN5FNr8SXJ+jcr8/U2ENuxI+qjhzEht7t2utkuEimpRGsdd0zs= X-Talos-CUID: 9a23:ykW9vmBVh2YkC8n6ExVY0XcLH8Q4SSDY7FT0Jn6gG0BkaoTAHA== X-Talos-MUID: 9a23:eEdinATr29YA1s5yRXTOgD46Csd5xZ/3BV4uwLs/5+vVBAFvbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="532990402" Received: from rcdn-l-core-01.cisco.com ([173.37.255.138]) by rcdn-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:04 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-01.cisco.com (Postfix) with ESMTPS id 07E6B180001C4 for ; Wed, 7 Oct 2026 11:24:04 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 6162DCBEF8A; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 7/8] curl: fix CVE-2026-6429 Date: Wed, 7 Oct 2026 04:24:02 -0700 Message-Id: <20261007112403.486499-7-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247392 From: Devansh Patel This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 [2] https://curl.se/docs/CVE-2026-6429.html Signed-off-by: Devansh Patel --- .../curl/curl/CVE-2026-6429.patch | 365 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 366 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6429.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-6429.patch b/meta/recipes-support/curl/curl/CVE-2026-6429.patch new file mode 100644 index 0000000000..f7801ff758 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6429.patch @@ -0,0 +1,365 @@ +From 8f82af313dcce59c7343b3a4f849aa7e35e066f5 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Thu, 16 Apr 2026 14:26:20 +0200 +Subject: [PATCH] http: clear credentials better on redirect + +Verify with test 2506: netrc with redirect using proxy + +Updated test 998 which was wrong. + +Reported-by: Muhamad Arga Reksapati + +Closes #21345 + +CVE: CVE-2026-6429 +Upstream-Status: Backport [https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306] + +Backport Changes: +- curl 8.7.1 keeps redirect handling in Curl_follow() in transfer.c. + Apply the upstream credential clearing behavior there. +- Inline the same-origin comparison used by the upstream fix because + curl 8.7.1 predates Curl_url_same_origin(). Preserve URL spaces and + treat unsupported redirect schemes as a different origin. +- Register test2506 and lib2506 in the curl 8.7.1 Makefile.inc files. + Adapt the newer libtest entry point to the older test harness. +- Test 998 in curl 8.7.1 stores the expected Basic auth header as + literal Base64. Upstream later used %b64[...]b64%; remove the + equivalent literal header from the second request expectation. + +(cherry picked from commit b4024bf808bd558026fdc6096e8457f199ace306) +Signed-off-by: Devansh Patel +--- + lib/transfer.c | 106 ++++++++++++++++++++++--------------- + tests/data/Makefile.inc | 2 +- + tests/data/test2506 | 64 ++++++++++++++++++++++ + tests/data/test998 | 1 - + tests/libtest/Makefile.inc | 5 +- + tests/libtest/lib2506.c | 71 +++++++++++++++++++++++++ + 6 files changed, 202 insertions(+), 47 deletions(-) + create mode 100644 tests/data/test2506 + create mode 100644 tests/libtest/lib2506.c + +diff --git a/lib/transfer.c b/lib/transfer.c +index a73462928d..9103a66865 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -865,49 +865,67 @@ CURLcode Curl_follow(struct Curl_easy *data, + if(uc) + return Curl_uc_to_curlcode(uc); + +- /* Clear auth if this redirects to a different port number or protocol, +- unless permitted */ +- if(!data->set.allow_auth_to_other_hosts && (type != FOLLOW_FAKE)) { +- char *portnum; +- int port; +- bool clear = FALSE; +- +- if(data->set.use_port && data->state.allow_port) +- /* a custom port is used */ +- port = (int)data->set.use_port; +- else { +- uc = curl_url_get(data->state.uh, CURLUPART_PORT, &portnum, +- CURLU_DEFAULT_PORT); +- if(uc) { +- free(newurl); +- return Curl_uc_to_curlcode(uc); +- } +- port = atoi(portnum); +- free(portnum); +- } +- if(port != data->info.conn_remote_port) { +- infof(data, "Clear auth, redirects to port from %u to %u", +- data->info.conn_remote_port, port); +- clear = TRUE; ++ { ++ bool same_origin = FALSE; ++ CURLU *u; ++ char *oldscheme = NULL; ++ char *oldhost = NULL; ++ char *oldport = NULL; ++ char *newscheme = NULL; ++ char *newhost = NULL; ++ char *newport = NULL; ++ ++ u = curl_url(); ++ if(!u) { ++ free(newurl); ++ return CURLE_OUT_OF_MEMORY; + } +- else { +- char *scheme; +- const struct Curl_handler *p; +- uc = curl_url_get(data->state.uh, CURLUPART_SCHEME, &scheme, 0); +- if(uc) { +- free(newurl); +- return Curl_uc_to_curlcode(uc); +- } + +- p = Curl_get_scheme_handler(scheme); +- if(p && (p->protocol != data->info.conn_protocol)) { +- infof(data, "Clear auth, redirects scheme from %s to %s", +- data->info.conn_scheme, scheme); +- clear = TRUE; ++ uc = curl_url_set(u, CURLUPART_URL, data->state.url, ++ CURLU_URLENCODE | CURLU_ALLOW_SPACE); ++ if(!uc) ++ uc = curl_url_get(u, CURLUPART_SCHEME, &oldscheme, 0); ++ if(!uc) ++ uc = curl_url_get(u, CURLUPART_HOST, &oldhost, 0); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_SCHEME, &newscheme, 0); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_HOST, &newhost, 0); ++ if(!uc) { ++ same_origin = strcasecompare(oldscheme, newscheme) && ++ strcasecompare(oldhost, newhost); ++ if(same_origin) { ++ uc = curl_url_get(u, CURLUPART_PORT, &oldport, ++ CURLU_DEFAULT_PORT); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_PORT, &newport, ++ CURLU_DEFAULT_PORT); ++ if(!uc) ++ same_origin = !strcmp(oldport, newport); + } +- free(scheme); + } +- if(clear) { ++ if(uc) { ++ curl_url_cleanup(u); ++ free(oldscheme); ++ free(oldhost); ++ free(oldport); ++ free(newscheme); ++ free(newhost); ++ free(newport); ++ free(newurl); ++ return Curl_uc_to_curlcode(uc); ++ } ++ ++ curl_url_cleanup(u); ++ free(oldscheme); ++ free(oldhost); ++ free(oldport); ++ free(newscheme); ++ free(newhost); ++ free(newport); ++ ++ if((!same_origin && !data->set.allow_auth_to_other_hosts) || ++ !data->set.str[STRING_USERNAME]) { + result = Curl_reset_userpwd(data); + if(result) { + free(newurl); +@@ -917,12 +935,12 @@ CURLcode Curl_follow(struct Curl_easy *data, + Curl_safefree(data->state.aptr.passwd); + } + } +- } + +- result = Curl_reset_proxypwd(data); +- if(result) { +- free(newurl); +- return result; ++ result = Curl_reset_proxypwd(data); ++ if(result) { ++ free(newurl); ++ return result; ++ } + } + + if(type == FOLLOW_FAKE) { +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index 27b1b52a10..7c0ef24554 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -253,7 +253,7 @@ test2300 test2301 test2302 test2303 test2304 test2305 test2306 test2307 \ + \ + test2400 test2401 test2402 test2403 test2404 \ + \ +-test2500 test2501 test2502 test2503 \ ++test2500 test2501 test2502 test2503 test2506 \ + \ + test2600 test2601 test2602 test2603 \ + \ +diff --git a/tests/data/test2506 b/tests/data/test2506 +new file mode 100644 +index 0000000000..9c65002496 +--- /dev/null ++++ b/tests/data/test2506 +@@ -0,0 +1,64 @@ ++ ++ ++ ++ ++HTTP ++cookies ++ ++ ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 3 ++Location: http://numbertwo.example/%TESTNUMBER0002 ++ ++ok ++ ++ ++HTTP/1.1 200 OK ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 4 ++ ++yes ++ ++ ++ ++ ++ ++http ++ ++ ++proxy ++ ++ ++lib%TESTNUMBER ++ ++ ++netrc with redirect using proxy ++ ++ ++machine site.example login batman password robin ++ ++ ++http://%HOSTIP:%HTTPPORT http://site.example/ %LOGDIR/netrc2506 ++ ++ ++ ++ ++ ++GET http://site.example/ HTTP/1.1 ++Host: site.example ++Authorization: Basic %b64[batman:robin]b64% ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://numbertwo.example/25060002 HTTP/1.1 ++Host: numbertwo.example ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ +diff --git a/tests/data/test998 b/tests/data/test998 +index 9b44223845..205179fac3 100644 +--- a/tests/data/test998 ++++ b/tests/data/test998 +@@ -82,7 +82,6 @@ + + GET http://somewhere.else.example/a/path/9980002 HTTP/1.1 + Host: somewhere.else.example +- Authorization: Basic YWxiZXJ0bzplaW5zdGVpbg== + User-Agent: curl/%VERSION + Accept: */* + Proxy-Connection: Keep-Alive +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 78e16b0428..639d010a00 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -77,7 +77,7 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq \ + lib1970 lib1971 lib1972 lib1973 lib1974 lib1975 \ + lib2301 lib2302 lib2304 lib2305 lib2306 \ + lib2402 lib2404 \ +- lib2502 \ ++ lib2502 lib2506 \ + lib3010 lib3025 lib3026 lib3027 \ + lib3100 lib3101 lib3102 lib3103 + +@@ -689,6 +689,9 @@ lib2404_LDADD = $(TESTUTIL_LIBS) + lib2502_SOURCES = lib2502.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib2502_LDADD = $(TESTUTIL_LIBS) + ++lib2506_SOURCES = lib2506.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) ++lib2506_LDADD = $(TESTUTIL_LIBS) ++ + lib3010_SOURCES = lib3010.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib3010_LDADD = $(TESTUTIL_LIBS) + +diff --git a/tests/libtest/lib2506.c b/tests/libtest/lib2506.c +new file mode 100644 +index 0000000000..e6dde18507 +--- /dev/null ++++ b/tests/libtest/lib2506.c +@@ -0,0 +1,71 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Linus Nielsen Feltzing ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++#include "test.h" ++ ++#include "testtrace.h" ++ ++static size_t sink2506(char *ptr, size_t size, size_t nmemb, void *ud) ++{ ++ (void)ptr; ++ (void)ud; ++ return size * nmemb; ++} ++ ++int test(char *URL) ++{ ++ CURL *curl; ++ int res = CURLE_OUT_OF_MEMORY; ++ ++ if(curl_global_init(CURL_GLOBAL_ALL) != CURLE_OK) { ++ curl_mfprintf(stderr, "curl_global_init() failed\n"); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2506); ++ test_setopt(curl, CURLOPT_PROXY, URL); ++ test_setopt(curl, CURLOPT_URL, libtest_arg2); ++ test_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL); ++ test_setopt(curl, CURLOPT_NETRC_FILE, libtest_arg3); ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); ++ test_setopt(curl, CURLOPT_VERBOSE, 1L); ++ ++ /* CURLOPT_UNRESTRICTED_AUTH should not make a difference because the ++ credentials come from netrc */ ++ test_setopt(curl, CURLOPT_UNRESTRICTED_AUTH, 1L); ++ ++ res = curl_easy_perform(curl); ++ ++test_cleanup: ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ ++ return res; ++} diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 6f9a814457..00a92d82d4 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -46,6 +46,7 @@ SRC_URI = " \ file://CVE-2026-8927-dependent.patch \ file://CVE-2026-8927.patch \ file://CVE-2026-8932.patch \ + file://CVE-2026-6429.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Oct 7 11:24:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Devansh Patel X-Patchwork-Id: 100153 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E8E53CA6007 for ; Wed, 7 Oct 2026 11:24:13 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7419.1791372245224751971 for ; Wed, 07 Oct 2026 04:24:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=C/I1Rgeq; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: devanshp@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=13680; q=dns/txt; s=iport01; t=1791372245; x=1792581845; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=0osEExs/2zzmmVT+883UqmYCShpJme4K+QvwbceaGmI=; b=C/I1RgeqCRjnSC7pFa2R4xFFIhCsHu8bzzf4DvzH4ufkNiTkJmXNw4if N40Uu7EL7+0Emh+nFX7DY/UJJJeXB4DY6/42Krsb4HxV8SIoHNV0VvRFh NbWo/2UpICDVy7TmuN/eeBJCnEJIHPqkwM1MTs9SCL1aO+UOOt4djXvyQ F1e3D1PvQlFipXuTsJNXMxk81jBQkTbf2U+r+EnD7z5rdUBLrQy3CpXEA 4Gf2Ayp4Jn2xONQJ3BCFYU2+/8BIbzXFGloevW2vXfMAGijvSUtKzQQ0J NT6syGsA0pg/VSOSfg+vxcSNES2DuiBS/y5BejhpQSKD3x2ZImzWrQM/0 Q==; X-CSE-ConnectionGUID: gpM/v+kaT7+fb+PSoVm5pg== X-CSE-MsgGUID: 1rdN4U8jTyapCpL0Cw/4LQ== X-IPAS-Result: A0BLAgCcKsZq/5X/Ja1aHgEBCxIMggULgld1YUJJlCmBNWwDkUmMURSBag8BAQEPRA0EAQGBcQEggnMCjgkCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBIBAgEDJwsBGAE9HAMBAhkWKyMIGYMCAYJ0AgERBrVmgXkzgQGDKQE/AgJAAVDbMgELFAGBOIVAiCNdGAGDXYEfJxsbgXKBFYNpgQWBXAIBAYEhAyJohXUEgiKBDIFaHoEvjEyFXEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCFiMZNnqBCV6BKylhEBeBCYIHAoJUggACAUlBDgdFUwklQxJHJiIIEgkBExowC4EbODwJKEEXDCkYDUgRLDcVGQQ+bgeQWx6CKDEGATEvASECAQkBKQEBBCtWfQEBOQwdFJJgkCeCIYE1n1oKKIN2jCKVOhozhVulFJkIjgqVaBgDTYRpgWg8gVlwFYMiCQkNNBkPji4LC4NghFCBcMV5JDUCCTIBAQcCBw4DC4FokCaBWAEB IronPort-Data: A9a23:0m04PanBIv9BwK5VFjI5dUDo5gzQJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xJMUWzQPfeDa2GjfIsibt7k8R4GupeHm9AxTQU4+Ck3RFtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4Errav6+/SEUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZK31GONgWYubDtMs/3b8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FYIA36FpQmJHy aNbJjpOViuEuefr2L3uH4GAhux7RCXqFJkUtnclyXTSCuwrBMmZBa7L/tRfmjw3g6iiH96HO JFfMmUpNkmdJUQTaz/7C7pm9AusrnXybTRes1KNjaE2+GPUigd21dABNfKIIYbQFJQMxRbwS mTupn71JE0nZN6j2DOd2WqI3sTQ2n/fYddHfFG/3rsw6LGJ/UQUEBAQWF6xrPW1h0L7UNVFJ mQQ+zEytu417EGtQ9z3UhG0rXLCuQQTM+e8CMUg4w2Lj66R6AGDCy1dFHhKaccts4k9QjlCO kK1ou4FzAdH6NW9IU9xPJ/Nxd9uEUD59VM/WBI= IronPort-HdrOrdr: A9a23:eZCQ06u4ByjnsiLHfbAvuXlL7skDWtV00zEX/kB9WHVpm6uj5q STdZsguyMc5Ax9ZJhko6HiBEDiewK4yXcK2+gs1N6ZNWGM0ldAbrsSj7cKqAeOJ8SRzIJgPN 9bE5RWOZnXEUVwi9r87U2TFtYtx8TCzYWT7N2uqEuEiWpRGthdB8ATMHf8LnFL X-Talos-CUID: 9a23:AUFrTGjIz72t9t/pPc/hujIXRDJufWX4i2mTIEaEViVnQv6tcliu/f58nJ87 X-Talos-MUID: 9a23:1CkrUwVz6pur8kTq/Gb2iBc+CZdq37WnEGsVtc0tpI7YERUlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,144,1787011200"; d="scan'208";a="532299138" Received: from rcdn-l-core-12.cisco.com ([173.37.255.149]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 07 Oct 2026 11:24:04 +0000 Received: from sjc-ads-20746.cisco.com (sjc-ads-20746.cisco.com [171.70.189.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-12.cisco.com (Postfix) with ESMTPS id 08799180001CE for ; Wed, 7 Oct 2026 11:24:04 +0000 (GMT) Received: by sjc-ads-20746.cisco.com (Postfix, from userid 1887503) id 65901CBEF98; Wed, 7 Oct 2026 04:24:03 -0700 (PDT) From: "Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH 8/8] curl: fix CVE-2026-7168 Date: Wed, 7 Oct 2026 04:24:03 -0700 Message-Id: <20261007112403.486499-8-devanshp@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20261007112403.486499-1-devanshp@cisco.com> References: <20261007112403.486499-1-devanshp@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-20746.cisco.com [171.70.189.245];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 171.70.189.245, sjc-ads-20746.cisco.com X-Outbound-Node: rcdn-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 07 Oct 2026 11:24:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247393 From: Devansh Patel This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507 [2] https://curl.se/docs/CVE-2026-7168.html Signed-off-by: Devansh Patel --- .../curl/curl/CVE-2026-7168.patch | 404 ++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 405 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-7168.patch b/meta/recipes-support/curl/curl/CVE-2026-7168.patch new file mode 100644 index 0000000000..ef19f89e4c --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-7168.patch @@ -0,0 +1,404 @@ +From 9026628dd5fa02b66cb85606e2121c94f9943efa Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 27 Apr 2026 09:14:51 +0200 +Subject: [PATCH] setopt: clear proxy auth properties when switching + +Verify with test 1588 + +Closes #21453 + +CVE: CVE-2026-7168 +Upstream-Status: Backport [https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507] + +Backport Changes: +- Place setproxy() beside Curl_setstropt() in curl 8.7.1's monolithic + setopt.c and include vauth/vauth.h for its cleanup declaration. +- Add the upstream no-op digest cleanup macro for builds without + Digest. +- Register test1588 and lib1588 in the curl 8.7.1 Makefile.inc files. +- Adapt first.h and test_lib1588() to test.h and test(). The older + harness has no libtest_arg4, so use test_argv[4] and require five + argv entries before reading the fourth test argument. +- The curl 8.7.1 test macros write to a variable named res. Use + CURLcode res in init1588() and int res in test(); retain upstream + CURLcode result in run1588(), which uses no harness macro. +- Use the curl 8.7.1 digest-auth feature name. The separate dependency + patch provides its positive feature detection. +- Change test1588's reply sections to `crlf="yes"` for the same test + server behavior. + +(cherry picked from commit c1cfdf59acbaf9504c4578d4cf56cdd7c8594507) +Signed-off-by: Devansh Patel +--- + lib/setopt.c | 18 ++++- + lib/vauth/vauth.h | 2 + + tests/data/Makefile.inc | 2 + + tests/data/test1588 | 106 ++++++++++++++++++++++++++ + tests/libtest/Makefile.inc | 5 +- + tests/libtest/lib1588.c | 152 +++++++++++++++++++++++++++++++++++++ + 6 files changed, 282 insertions(+), 3 deletions(-) + create mode 100644 tests/data/test1588 + create mode 100644 tests/libtest/lib1588.c + +diff --git a/lib/setopt.c b/lib/setopt.c +index 8a5a5d7c33..7eaf30910f 100644 +--- a/lib/setopt.c ++++ b/lib/setopt.c +@@ -51,6 +51,7 @@ + #include "altsvc.h" + #include "hsts.h" + #include "tftp.h" ++#include "vauth/vauth.h" + #include "strdup.h" + /* The last 3 #include files should be in this order */ + #include "curl_printf.h" +@@ -76,6 +77,20 @@ CURLcode Curl_setstropt(char **charp, const char *s) + return CURLE_OK; + } + ++#ifndef CURL_DISABLE_PROXY ++static CURLcode setproxy(struct Curl_easy *data, const char *proxy) ++{ ++ if((data->set.str[STRING_PROXY] && proxy) && ++ /* there was one set, is this a new one? */ ++ !strcmp(data->set.str[STRING_PROXY], proxy)) ++ return CURLE_OK; /* same one as before */ ++ ++ Curl_auth_digest_cleanup(&data->state.proxydigest); ++ memset(&data->state.authproxy, 0, sizeof(data->state.authproxy)); ++ return Curl_setstropt(&data->set.str[STRING_PROXY], proxy); ++} ++#endif ++ + CURLcode Curl_setblobopt(struct curl_blob **blobp, + const struct curl_blob *blob) + { +@@ -1139,8 +1154,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option, va_list param) + * Setting it to NULL, means no proxy but allows the environment variables + * to decide for us (if CURLOPT_SOCKS_PROXY setting it to NULL). + */ +- result = Curl_setstropt(&data->set.str[STRING_PROXY], +- va_arg(param, char *)); ++ result = setproxy(data, va_arg(param, char *)); + break; + + case CURLOPT_PRE_PROXY: +diff --git a/lib/vauth/vauth.h b/lib/vauth/vauth.h +index 9da0540892..bf5c7a3e12 100644 +--- a/lib/vauth/vauth.h ++++ b/lib/vauth/vauth.h +@@ -119,6 +119,8 @@ CURLcode Curl_auth_create_digest_http_message(struct Curl_easy *data, + + /* This is used to clean up the digest specific data */ + void Curl_auth_digest_cleanup(struct digestdata *digest); ++#else ++#define Curl_auth_digest_cleanup(x) + #endif /* !CURL_DISABLE_DIGEST_AUTH */ + + #ifdef USE_GSASL +diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc +index 7c0ef24554..5e83979417 100644 +--- a/tests/data/Makefile.inc ++++ b/tests/data/Makefile.inc +@@ -201,6 +201,8 @@ test1550 test1551 test1552 test1553 test1554 test1555 test1556 test1557 \ + test1558 test1559 test1560 test1561 test1562 test1563 test1564 test1565 \ + test1566 test1567 test1568 test1569 test1570 \ + \ ++test1588 \ ++\ + test1590 test1591 test1592 test1593 test1594 test1595 test1596 test1597 \ + test1598 \ + test1600 test1601 test1602 test1603 test1604 test1605 test1606 test1607 \ +diff --git a/tests/data/test1588 b/tests/data/test1588 +new file mode 100644 +index 0000000000..ba996fb2ff +--- /dev/null ++++ b/tests/data/test1588 +@@ -0,0 +1,106 @@ ++ ++ ++ ++ ++HTTP ++HTTP GET ++HTTP proxy ++HTTP proxy Digest auth ++multi ++ ++ ++ ++# Server-side ++ ++ ++# this is returned first since we get no proxy-auth ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++And you should ignore this data. ++ ++ ++# then this is returned when we get proxy-auth ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++ ++ ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++HTTP/1.1 200 OK ++Content-Length: 21 ++Server: no ++ ++Nice proxy auth sir! ++ ++ ++ ++# Client-side ++ ++ ++http ++ ++# tool is what to use instead of 'curl' ++ ++lib%TESTNUMBER ++ ++ ++!SSPI ++crypto ++proxy ++digest-auth ++ ++ ++HTTP proxy auth Digest, then change proxy and do it again ++ ++ ++http://test.remote.example.com/path/%TESTNUMBER %HOSTIP %HTTPPORT silly:person custom.set.host.name ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a" ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://test.remote.example.com/path/1588 HTTP/1.1 ++Host: test.remote.example.com ++Proxy-Authorization: Digest username="silly", realm="weirdorealm", nonce="12345", uri="/path/1588", response="d0b2f000c7e3fca24452b5810713404a" ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 639d010a00..3eeaed2f27 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -62,7 +62,7 @@ noinst_PROGRAMS = chkhostname libauthretry libntlmconnect libprereq \ + lib1540 lib1541 lib1542 lib1543 lib1545 \ + lib1550 lib1551 lib1552 lib1553 lib1554 lib1555 lib1556 lib1557 \ + lib1558 lib1559 lib1560 lib1564 lib1565 lib1567 lib1568 lib1569 \ +- lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \ ++ lib1588 lib1591 lib1592 lib1593 lib1594 lib1596 lib1597 lib1598 \ + \ + lib1647 \ + \ +@@ -520,6 +520,9 @@ lib1568_SOURCES = lib1568.c $(SUPPORTFILES) + + lib1569_SOURCES = lib1569.c $(SUPPORTFILES) + ++lib1588_SOURCES = lib1588.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) ++lib1588_LDADD = $(TESTUTIL_LIBS) ++ + lib1591_SOURCES = lib1591.c $(SUPPORTFILES) $(TESTUTIL) $(WARNLESS) + lib1591_LDADD = $(TESTUTIL_LIBS) + +diff --git a/tests/libtest/lib1588.c b/tests/libtest/lib1588.c +new file mode 100644 +index 0000000000..60d0dd43be +--- /dev/null ++++ b/tests/libtest/lib1588.c +@@ -0,0 +1,152 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++/* ++ * argv1 = URL ++ * argv2 = proxy host ++ * argv3 = proxy port ++ * argv4 = proxyuser:password ++ */ ++ ++#include "test.h" ++#include "testutil.h" ++ ++static CURLcode init1588(CURL *curl, const char *url, ++ const char *userpwd, const char *proxy) ++{ ++ CURLcode res = CURLE_OK; ++ ++ res_easy_setopt(curl, CURLOPT_URL, url); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXY, proxy); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYUSERPWD, userpwd); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXYAUTH, CURLAUTH_DIGEST); ++ if(res) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L); ++ if(res) ++ goto init_failed; ++#if 0 ++ res_easy_setopt(curl, CURLOPT_HTTPPROXYTUNNEL, 1L); ++ if(res) ++ goto init_failed; ++#endif ++ ++ res_easy_setopt(curl, CURLOPT_HEADER, 1L); ++ if(res) ++ goto init_failed; ++ ++ return CURLE_OK; /* success */ ++ ++init_failed: ++ return res; /* failure */ ++} ++ ++static CURLcode run1588(CURL *curl, const char *url, const char *userpwd, ++ const char *proxy) ++{ ++ CURLcode result = CURLE_OK; ++ ++ result = init1588(curl, url, userpwd, proxy); ++ if(result) ++ return result; ++ ++ return curl_easy_perform(curl); ++} ++ ++int test(char *URL) ++{ ++ int res = CURLE_OK; ++ CURL *curl = NULL; ++ const char *proxyuserpws; ++ struct curl_slist *host = NULL; ++ struct curl_slist *host2 = NULL; ++ char proxy1_resolve[128]; ++ char proxy2_resolve[128]; ++ char proxy1_connect[128]; ++ char proxy2_connect[128]; ++ ++ if(test_argc < 5) ++ return TEST_ERR_MAJOR_BAD; ++ proxyuserpws = test_argv[4]; ++ ++ curl_msnprintf(proxy1_resolve, sizeof(proxy1_resolve), ++ "firstproxy:%s:%s", libtest_arg3, libtest_arg2); ++ curl_msnprintf(proxy2_resolve, sizeof(proxy2_resolve), ++ "secondproxy:%s:%s", libtest_arg3, libtest_arg2); ++ ++ /* we connect to the fake host name but the right port number */ ++ curl_msnprintf(proxy1_connect, sizeof(proxy1_connect), ++ "firstproxy:%s", libtest_arg3); ++ curl_msnprintf(proxy2_connect, sizeof(proxy2_connect), ++ "secondproxy:%s", libtest_arg3); ++ ++ res_global_init(CURL_GLOBAL_ALL); ++ if(res) ++ return res; ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ host = curl_slist_append(NULL, proxy1_resolve); ++ if(!host) ++ goto test_cleanup; ++ host2 = curl_slist_append(host, proxy2_resolve); ++ if(!host2) ++ goto test_cleanup; ++ host = host2; ++ ++ start_test_timing(); ++ ++ easy_setopt(curl, CURLOPT_RESOLVE, host); ++ ++ res = run1588(curl, URL, proxyuserpws, proxy1_connect); ++ if(res) ++ goto test_cleanup; ++ ++ curl_mfprintf(stderr, "lib1588: now we do the request again\n"); ++ ++ res = run1588(curl, URL, proxyuserpws, proxy2_connect); ++ ++test_cleanup: ++ ++ /* proper cleanup sequence - type PB */ ++ ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ curl_slist_free_all(host); ++ return res; ++} diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 00a92d82d4..4ce564a8bc 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -47,6 +47,7 @@ SRC_URI = " \ file://CVE-2026-8927.patch \ file://CVE-2026-8932.patch \ file://CVE-2026-6429.patch \ + file://CVE-2026-7168.patch \ " SRC_URI:append:class-nativesdk = " \