On Mon, 2026-07-27 at 17:31 +0530, Deepak Rathore via lists.openembedded.org wrote: > From: Deepak Rathore <[email protected]> > > This patch applies the upstream backport for CVE-2026-4873. > The upstream fix commit is referenced in [1], and the public > CVE advisory is referenced in [2]. > > [1] > https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865 > [2] https://curl.se/docs/CVE-2026-4873.html > > Signed-off-by: Deepak Rathore <[email protected]> > --- > - Changes from v2 to v3: > - Updated the patch to include the fixed commit instead of CVE_STATUS as per > Paul's suggestion. > .../curl/curl/CVE-2026-4873.patch | 32 +++++++++++++++++++ > meta/recipes-support/curl/curl_8.19.0.bb | 1 + > 2 files changed, 33 insertions(+) > create mode 100644 meta/recipes-support/curl/curl/CVE-2026-4873.patch > > diff --git a/meta/recipes-support/curl/curl/CVE-2026-4873.patch > b/meta/recipes-support/curl/curl/CVE-2026-4873.patch > new file mode 100644 > index 0000000000..cd9d81a25f > --- /dev/null > +++ b/meta/recipes-support/curl/curl/CVE-2026-4873.patch > @@ -0,0 +1,32 @@ > +From 507e7be573b0a76fca597b75ff7cb27a66e7d865 Mon Sep 17 00:00:00 2001 > +From: Daniel Stenberg <[email protected]> > +Date: Tue, 24 Mar 2026 08:35:08 +0100 > +Subject: [PATCH] url: do not reuse a non-tls starttls connection if new > + requires TLS > + > +Reported-by: Arkadi Vainbrand > + > +Closes #21082 > + > +CVE: CVE-2026-4873 > +Upstream-Status: Backport > [https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865] > + > +(cherry picked from commit 507e7be573b0a76fca597b75ff7cb27a66e7d865) > +Signed-off-by: Deepak Rathore <[email protected]> > +--- > + lib/url.c | 6 +++++- > + 1 file changed, 5 insertions(+), 1 deletion(-) > + > +diff --git a/lib/url.c b/lib/url.c > +index ec0457b..cc60468 100644 > +--- a/lib/url.c > ++++ b/lib/url.c > +@@ -748 +748 @@ struct url_conn_match { > +- > ++ BIT(req_tls); /* require TLS use from a clear-text start */ > +@@ -899,0 +900,3 @@ static bool url_match_ssl_use(struct connectdata *conn, > ++ else if(m->req_tls) > ++ /* a clear-text STARTTLS protocol with required TLS */ > ++ return FALSE; > +@@ -1357,0 +1361 @@ static bool url_attach_existing(struct Curl_easy *data, > ++ match.req_tls = data->set.use_ssl >= CURLUSESSL_CONTROL;
Hi Deepak, This patch file has no context lines, which makes it brittle. Please send a v3 with the usual 3 lines of context (that should be the default for git format-patch). Best regards, -- Paul Barker
signature.asc
Description: This is a digitally signed message part
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242096): https://lists.openembedded.org/g/openembedded-core/message/242096 Mute This Topic: https://lists.openembedded.org/mt/120465499/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
