Hello,

This patch conflict with other patches in my branch. Because this one
has issues, I will hold it for another cycle, you will have to
refresh/rebase on top of the next merge (or send me a new version that
applies on top of the -nut branch I will push/test later today)

Details of the issues below:

On Mon Aug 24, 2026 at 11:47 AM CEST, Deepak Rathore via lists.openembedded.org 
wrote:
> From: Deepak Rathore <[email protected]>
>
> This patch applies the upstream backport for CVE-2026-7168.
> The upstream fix commit is referenced in [1], and the public
> CVE advisory is referenced in [2].
>
> [1] 
> https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507
> [2] https://curl.se/docs/CVE-2026-7168.html
>
> Signed-off-by: Deepak Rathore <[email protected]>
> ---
> Changes in v3:
> - Rebase on top of the revised CVE-2026-6429 patch.
>
> Changes from v1 to v2:
> - Rebase the patches on top of the latest Scarthgap branch.
>
>  .../curl/curl/CVE-2026-7168.patch             | 425 ++++++++++++++++++
>  meta/recipes-support/curl/curl_8.7.1.bb       |   1 +
>  2 files changed, 426 insertions(+)
>  create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7168.patch
>
> diff --git a/meta/recipes-support/curl/curl/CVE-2026-7168.patch 
> b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> new file mode 100644
> index 0000000000..0669be6546
> --- /dev/null
> +++ b/meta/recipes-support/curl/curl/CVE-2026-7168.patch
> @@ -0,0 +1,425 @@
> +From 0f0bb5efbd1e4f2199eeb98e6c62a7a67242cad2 Mon Sep 17 00:00:00 2001
> +From: Daniel Stenberg <[email protected]>
> +Date: Fri, 5 Jun 2026 01:22:37 -0700
> +Subject: [PATCH] setopt: clear proxy auth properties when switching
> +
> +Verify with test 1588
> +
> +Closes #21453
> +
> +CVE: CVE-2026-7168
> +Upstream-Status: Backport 
> [https://github.com/curl/curl/commit/c1cfdf59acbaf9504c4578d4cf56cdd7c8594507]
> +
> +Backport Changes:
> +- The upstream lib/setopt.c hunk reuses Curl_auth_digest_cleanup() from the
> +  newer tree. curl-8.7.1 does not expose that helper to setopt.c in the same
> +  way, so this backport adds the vauth/vauth.h include before applying the
> +  upstream setproxy() cleanup logic.
> +- The upstream tree already provides a CURL_DISABLE_DIGEST_AUTH fallback for
> +  Curl_auth_digest_cleanup(). curl-8.7.1 does not, so this backport adds the
> +  equivalent no-op macro in lib/vauth/vauth.h.
> +- curl-8.7.1 uses tests/data/Makefile.inc and tests/libtest/Makefile.inc
> +  instead of the upstream tests/data/Makefile.am and
> +  tests/libtest/Makefile.am lists.
> +- curl-8.7.1 uses the older libtest harness, so first.h,
> +  test_lib1588(), libtest_arg4, and CURLcode result handling were adapted to
> +  test.h, test(), test_argv[4], and int res.
> +- curl-8.7.1 does not define the newer digest test feature in runtests.pl.
> +  This backport defines the target harness feature as digest-auth, matching
> +  tests/server/disabled.c, and makes test 1588 require digest-auth.
> +- The curl-8.7.1 server harness does not handle crlf="headers" correctly on
> +  response data sections for this test, so those attributes were removed from
> +  the two server response blocks and datacheck. The protocol block keeps
> +  crlf="headers" because runtests.pl normalizes protocol verification when 
> any
> +  crlf attribute is present.

Related to what really changed, the above is mostly noise :-( You have
to filter/check/edit whatever the LLM generates.

> +
> +(cherry picked from commit c1cfdf59acbaf9504c4578d4cf56cdd7c8594507)
> +Signed-off-by: Deepak Rathore <[email protected]>
> +---
> + lib/setopt.c               |  18 ++++-
> + lib/vauth/vauth.h          |   2 +
> + tests/data/Makefile.inc    |   1 +
> + tests/data/test1588        | 106 ++++++++++++++++++++++++++
> + tests/libtest/Makefile.inc |   5 +-
> + tests/libtest/lib1588.c    | 152 +++++++++++++++++++++++++++++++++++++
> + tests/runtests.pl          |   2 +
> + 7 files changed, 283 insertions(+), 3 deletions(-)
> + create mode 100644 tests/data/test1588
> + create mode 100644 tests/libtest/lib1588.c
> +
> +diff --git a/lib/setopt.c b/lib/setopt.c
> +index 8a5a5d7..7eaf309 100644
> +--- a/lib/setopt.c
> ++++ b/lib/setopt.c
> +@@ -51,6 +51,7 @@
> + #include "altsvc.h"
> + #include "hsts.h"
> + #include "tftp.h"
> ++#include "vauth/vauth.h"
> + #include "strdup.h"
> + /* The last 3 #include files should be in this order */
> + #include "curl_printf.h"
> +@@ -76,6 +77,20 @@ CURLcode Curl_setstropt(char **charp, const char *s)
> +   return CURLE_OK;
> + }
> + 
> ++#ifndef CURL_DISABLE_PROXY
            ^ This line is new and not explained in the changes
> ++static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
> ++{
> ++  if((data->set.str[STRING_PROXY] && proxy) &&
> ++     /* there was one set, is this a new one? */
> ++     !strcmp(data->set.str[STRING_PROXY], proxy))
> ++    return CURLE_OK; /* same one as before */
> ++
> ++  Curl_auth_digest_cleanup(&data->state.proxydigest);
> ++  memset(&data->state.authproxy, 0, sizeof(data->state.authproxy));
> ++  return Curl_setstropt(&data->set.str[STRING_PROXY], proxy);
> ++}
> ++#endif
> ++
> + CURLcode Curl_setblobopt(struct curl_blob **blobp,
> +                          const struct curl_blob *blob)
> + {
> [...]
> +diff --git a/tests/libtest/lib1588.c b/tests/libtest/lib1588.c
> +new file mode 100644
> +index 0000000..00c6b35
> +--- /dev/null
> ++++ b/tests/libtest/lib1588.c
> +@@ -0,0 +1,152 @@
> ++ * argv1 = URL
> ++ * argv2 = proxy host
> ++ * argv3 = proxy port
> ++ * argv4 = proxyuser:password
> ++ */
> ++
> ++#include "test.h"
> ++#include "testutil.h"
> ++
> ++static CURLcode init1588(CURL *curl, const char *url,
> ++                         const char *userpwd, const char *proxy)
> ++{
> ++  int res = CURLE_OK;
The upstream line is "CURLcode result = CURLE_OK"
why did the type changed? CURLcode is supported and used the line above.
Why did the variable name changed? This create a lot of noise in the
comparison.

> ++
> ++  res_easy_setopt(curl, CURLOPT_URL, url);
> ++  if(res)
> ++    goto init_failed;
> ++
> [...]
> ++int test(char *URL)
> ++{
> ++  int res = CURLE_OK;
> ++  CURL *curl = NULL;
> ++  const char *proxyuserpws;
> ++  struct curl_slist *host = NULL;
> ++  struct curl_slist *host2 = NULL;
> ++  char proxy1_resolve[128];
> ++  char proxy2_resolve[128];
> ++  char proxy1_connect[128];
> ++  char proxy2_connect[128];
> ++
> ++  if(test_argc < 5)
> ++    return TEST_ERR_MAJOR_BAD;
> ++  proxyuserpws = test_argv[4];

Upstream code compares argc to 3 not 5. proxyuserpws is added. Why?
Again, this is important and not explained in the changes (or not clear
enough)

> +diff --git a/tests/runtests.pl b/tests/runtests.pl
> +index ddfab20..b40df55 100755
> +--- a/tests/runtests.pl
> ++++ b/tests/runtests.pl
> +@@ -637,6 +637,8 @@ sub checksystemfeatures {
> +             $feature{"Kerberos"} = $feat =~ /Kerberos/i;
> +             # SPNEGO enabled
> +             $feature{"SPNEGO"} = $feat =~ /SPNEGO/i;
> ++            # Digest auth enabled unless disabled by build
> ++            $feature{"digest-auth"} = 1;
                ^ This is not part of the upstream commit but is from
                  another one.
Please don't squash commits like this or when code is needed try to find
the proper commit to backport (even partially).

> +             # CharConv enabled
> +             $feature{"CharConv"} = $feat =~ /CharConv/i;
> +             # TLS-SRP enabled
> +--
> +2.35.6
> diff --git a/meta/recipes-support/curl/curl_8.7.1.bb 
> b/meta/recipes-support/curl/curl_8.7.1.bb
> index 882ab67aae..6b7f6f6f51 100644
> --- a/meta/recipes-support/curl/curl_8.7.1.bb
> +++ b/meta/recipes-support/curl/curl_8.7.1.bb
> @@ -42,6 +42,7 @@ SRC_URI = " \
>      file://CVE-2026-5545.patch \
>      file://CVE-2026-6253.patch \
>      file://CVE-2026-6429.patch \
> +    file://CVE-2026-7168.patch \
>  "
>  
>  SRC_URI:append:class-nativesdk = " \


Try to use the interdiff tool to compare the upstream patch and yours,
changes highlighted should be documented (the obvious ones can be
omitted).

Regard,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246202): 
https://lists.openembedded.org/g/openembedded-core/message/246202
Mute This Topic: https://lists.openembedded.org/mt/120900349/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to