On Mon Aug 31, 2026 at 11:13 PM CEST, Jason Stasiak via lists.openembedded.org 
wrote:
> From: Jason Stasiak <[email protected]>
>
> Backport fix for CVE-2026-1467 from meta-oe to OE-core.
> Update CVE patch to address a use case where a uri validation
> failure was not handled.
>
> (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d)
>
> Signed-off-by: Jason Stasiak <[email protected]>
> ---
>  .../libsoup/libsoup-2.4/CVE-2026-1467.patch   | 276 ++++++++++++++++++
>  .../libsoup/libsoup-2.4_2.74.3.bb             |   1 +
>  2 files changed, 277 insertions(+)
>  create mode 100644 
> meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1467.patch

Hello,

Isn't that the patch Colin McAllister "colin-pm" (CC'd) asked about on
IRC #yocto?
https://libera.catirclogs.org/yocto/2026-08-28#1787933879-1787935062;

Is the trouble he mentioned fixed in this version of the patch?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244808): 
https://lists.openembedded.org/g/openembedded-core/message/244808
Mute This Topic: https://lists.openembedded.org/mt/121021787/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to