From: Siddharth Doshi <[email protected]> Picking patch as per [1], and same patch is mentioned in [2]
[1] https://curl.se/docs/CVE-2026-13608.html [2] https://security-tracker.debian.org/tracker/CVE-2026-13608 Signed-off-by: Siddharth Doshi <[email protected]> Signed-off-by: Yoann Congal <[email protected]> --- .../curl/curl/CVE-2026-13608.patch | 48 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 49 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-13608.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-13608.patch b/meta/recipes-support/curl/curl/CVE-2026-13608.patch new file mode 100644 index 00000000000..4df7595c8f0 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-13608.patch @@ -0,0 +1,48 @@ +From 25df759f0f0c1aeaee066a4502bb36a8a86fb22e Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg <[email protected]> +Date: Mon, 29 Jun 2026 10:44:47 +0200 +Subject: [PATCH 1/5] openldap: handle Curl_sasl_continue() returns better + +Similar to how it gets treated already in other protocol handlers. + +Follow-up to eeca818b1e8d1e61c2d4 + +Reported-by: Eunsoo Kim +Closes #22213 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519] +CVE: CVE-2026-13608 +Signed-off-by: Siddharth Doshi <[email protected]> +--- + lib/openldap.c | 15 +++++++++++++-- + 1 file changed, 13 insertions(+), 2 deletions(-) + +diff --git a/lib/openldap.c b/lib/openldap.c +index 95f7681..4a1e93a 100644 +--- a/lib/openldap.c ++++ b/lib/openldap.c +@@ -778,8 +778,19 @@ static CURLcode oldap_state_sasl_resp(struct Curl_easy *data, + } + else { + result = Curl_sasl_continue(&li->sasl, data, code, &progress); +- if(!result && progress != SASL_INPROGRESS) +- oldap_state(data, li, OLDAP_STOP); ++ if(!result) { ++ switch(progress) { ++ case SASL_DONE: ++ oldap_state(data, li, OLDAP_STOP); /* Authenticated */ ++ break; ++ case SASL_IDLE: /* No mechanism left after cancellation */ ++ failf(data, "Authentication cancelled"); ++ result = CURLE_LOGIN_DENIED; ++ break; ++ default: ++ break; ++ } ++ } + } + + if(li->servercred) +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index dfc28539380..21d887cb399 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -35,6 +35,7 @@ SRC_URI = " \ file://CVE-2026-9545-01.patch \ file://CVE-2026-9545-02.patch \ file://CVE-2026-9079.patch \ + file://CVE-2026-13608.patch \ " SRC_URI:append:class-nativesdk = " \
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246152): https://lists.openembedded.org/g/openembedded-core/message/246152 Mute This Topic: https://lists.openembedded.org/mt/121305638/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
