On Mon Jul 20, 2026 at 12:56 PM CEST, Deepak Rathore via lists.openembedded.org 
wrote:
> From: Deepak Rathore <[email protected]>
>
> - CVE-2026-4873 affects curl before 8.20.0 when a connection negotiated with
>   clear-text IMAP, POP3, or SMTP can later be reused for a TLS-required
>   transfer.
> - In wrynose, these protocols are optional PACKAGECONFIG entries and are not
>   enabled by default in curl_8.19.0.bb, so record this CVE as 
> configuration-not-applicable
>   for the default recipe configuration.
>
> Reference:
> - https://curl.se/docs/CVE-2026-4873.html
> - https://nvd.nist.gov/vuln/detail/CVE-2026-4873
>
> Signed-off-by: Deepak Rathore <[email protected]>

Hello,

All that series should be tagged v2 with a changelog where appropriate:
https://docs.yoctoproject.org/dev/contributor-guide/submit-changes.html#taking-patch-review-into-account

Can you resend it with the v2 tag? You can use -v2 if you use git-send-email.

Adding these tags/changelog helps me a lot when tracking patch status.

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241362): 
https://lists.openembedded.org/g/openembedded-core/message/241362
Mute This Topic: https://lists.openembedded.org/mt/120356772/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to