Hello Currently I am trying to fix some CVEs related to curl and figured out that the code base has evolved quite a bit. Which makes makes backporting patches a lot harder especially if used function in the patch are not even there in the 8.7.1 codebase. This in combination with a changed test framework (the last patches for CVE fixes were already without tests) makes it hard to backport and at the same time ensure that the CVE is really fixed.
Now my question would be if it still makes sense to try to backport some CVEs or if there will be a irregular major/minor upgrade anytime soon? An example for such a CVE would be CVE-2026-11856 [1] and the upstream patch [2]. Here the structs like Curl_creds or Curl_peer and the corresponding functions do not even exist. [1] https://curl.se/docs/CVE-2026-11856.html [2] https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45c Patrick
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246749): https://lists.openembedded.org/g/openembedded-core/message/246749 Mute This Topic: https://lists.openembedded.org/mt/121469182/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
