Hi Yoann, I am working on this and will send v2 of this series after rebase.
Regards, Deepak ________________________________ From: [email protected] <[email protected]> on behalf of Yoann Congal via lists.openembedded.org <[email protected]> Sent: Thursday, July 23, 2026 6:28 PM To: Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco) <[email protected]>; [email protected] <[email protected]> Cc: xe-linux-external (Internal Group) <[email protected]> Subject: Re: [OE-core] [scarthgap] [PATCH 1/7] curl: ignore CVE-2026-4873 On Mon Jun 29, 2026 at 12:47 PM CEST, Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Anil Dongare <[email protected]> > > - CVE-2026-4873 affects curl before 8.20.0 when a connection negotiated with > clear-text IMAP, POP3, or SMTP can later be reused for a TLS-required > transfer. > - In scarthgap, these protocols are optional PACKAGECONFIG entries and are not > enabled by default in `curl_8.7.1.bb`. > - Record this CVE as configuration-not-applicable for the default recipe > configuration instead of carrying the upstream fix unconditionally. > > Reference: > - https://curl.se/docs/CVE-2026-4873.html > - https://nvd.nist.gov/vuln/detail/CVE-2026-4873 > > Signed-off-by: Anil Dongare <[email protected]> Hello, This series fails to apply on the latest scarthgap. Can you rebase and send a v2? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241931): https://lists.openembedded.org/g/openembedded-core/message/241931 Mute This Topic: https://lists.openembedded.org/mt/120028212/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
