On Mon Sep 28, 2026 at 12:54 PM CEST, Patrick Vogelaar via 
lists.openembedded.org wrote:
> Hello
>
> Currently I am trying to fix some CVEs related to curl and figured out
> that the code base has evolved quite a bit. Which makes makes
> backporting patches a lot harder especially if used function in the
> patch are not even there in the 8.7.1 codebase. This in combination
> with a changed test framework (the last patches for CVE fixes were
> already without tests) makes it hard to backport and at the same time
> ensure that the CVE is really fixed. 
>
> Now my question would be if it still makes sense to try to backport
> some CVEs or if there will be a irregular major/minor upgrade anytime
> soon?
>
> An example for such a CVE would be CVE-2026-11856 [1] and the upstream
> patch [2]. Here the structs like Curl_creds or Curl_peer and the
> corresponding functions do not even exist.
>
> [1] https://curl.se/docs/CVE-2026-11856.html
> [2] https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45c

Hello Patrick,

In OE-core, we do have a quite strict stable policy about what can or
can't be included in stable branches:
https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS#Stable/LTS_Patch_Acceptance_Policies

Since the curl version after the scarthgap curl 8.7.1 is curl 8.8.0. But
this version includes feature addition:
https://curl.se/ch/8.8.0.html
> Changes:
>  curl_version_info: provide librtmp version
>  file: add support for directory listings
>  idn: add native AppleIDN (icucore) support for macOS/iOS
>  lib: add curl_multi_waitfds
>  mbedTLS: implement CURLOPT_SSL_CIPHER_LIST option
>  NTLM_WB: drop support
>  TLS: add support for ECH (Encrypted Client Hello)
>  urlapi: add CURLU_GET_EMPTY for empty queries and fragments

So, I can't accept this upgrade so we have to rely on backports.

IMHO, dropping tests during backport is fair.

So, yes, it still makes sense to try to backport CVE fixes.

Of course, at some point, the difference in codebases will be too much
and the backport will be impossible under our stable policy. Then the
fix will have to come from outside of oe-core (downstream layer, mixin
layers, ...)

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246963): 
https://lists.openembedded.org/g/openembedded-core/message/246963
Mute This Topic: https://lists.openembedded.org/mt/121469182/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to