Hello

Currently I am trying to fix some CVEs related to curl and figured out that the 
code base has evolved quite a bit. Which makes makes backporting patches a lot 
harder especially if used function in the patch are not even there in the 8.7.1 
codebase. This in combination with a changed test framework (the last patches 
for CVE fixes were already without tests) makes it hard to backport and at the 
same time ensure that the CVE is really fixed. 

Now my question would be if it still makes sense to try to backport some CVEs 
or if there will be a irregular major/minor upgrade anytime soon?

An example for such a CVE would be CVE-2026-11856 [1] and the upstream patch 
[2]. Here the structs like Curl_creds or Curl_peer and the corresponding 
functions do not even exist.

[1] https://curl.se/docs/CVE-2026-11856.html
[2] https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45c

Patrick
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246749): 
https://lists.openembedded.org/g/openembedded-core/message/246749
Mute This Topic: https://lists.openembedded.org/mt/121469182/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • [OE-core] [scarthgap] strategy... Patrick Vogelaar via lists.openembedded.org

Reply via email to