On Mon Jul 20, 2026 at 12:56 PM CEST, Deepak Rathore via lists.openembedded.org wrote: > From: Deepak Rathore <[email protected]> > > - CVE-2026-4873 affects curl before 8.20.0 when a connection negotiated with > clear-text IMAP, POP3, or SMTP can later be reused for a TLS-required > transfer. > - In wrynose, these protocols are optional PACKAGECONFIG entries and are not > enabled by default in curl_8.19.0.bb, so record this CVE as > configuration-not-applicable > for the default recipe configuration. > > Reference: > - https://curl.se/docs/CVE-2026-4873.html > - https://nvd.nist.gov/vuln/detail/CVE-2026-4873 > > Signed-off-by: Deepak Rathore <[email protected]>
Hello, All that series should be tagged v2 with a changelog where appropriate: https://docs.yoctoproject.org/dev/contributor-guide/submit-changes.html#taking-patch-review-into-account Can you resend it with the v2 tag? You can use -v2 if you use git-send-email. Adding these tags/changelog helps me a lot when tracking patch status. Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241362): https://lists.openembedded.org/g/openembedded-core/message/241362 Mute This Topic: https://lists.openembedded.org/mt/120356772/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
