On Mon Aug 31, 2026 at 11:13 PM CEST, Jason Stasiak via lists.openembedded.org wrote: > From: Jason Stasiak <[email protected]> > > Backport fix for CVE-2026-1467 from meta-oe to OE-core. > Update CVE patch to address a use case where a uri validation > failure was not handled. > > (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d) > > Signed-off-by: Jason Stasiak <[email protected]> > --- > .../libsoup/libsoup-2.4/CVE-2026-1467.patch | 276 ++++++++++++++++++ > .../libsoup/libsoup-2.4_2.74.3.bb | 1 + > 2 files changed, 277 insertions(+) > create mode 100644 > meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1467.patch
Hello, Isn't that the patch Colin McAllister "colin-pm" (CC'd) asked about on IRC #yocto? https://libera.catirclogs.org/yocto/2026-08-28#1787933879-1787935062; Is the trouble he mentioned fixed in this version of the patch? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244808): https://lists.openembedded.org/g/openembedded-core/message/244808 Mute This Topic: https://lists.openembedded.org/mt/121021787/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
