On Tue Sep 29, 2026 at 10:50 PM CEST, Jason Stasiak via lists.openembedded.org 
wrote:
> Backport fix for CVE-2026-1539 from meta-oe to OE-core.
> Update CVE patch to restore the auth-redirect proxy validation
> unit test from the upstream libsoup3 patch.
>
> (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d)
>
> Signed-off-by: Jason Stasiak <[email protected]>
> ---
>  .../libsoup/libsoup-2.4/CVE-2026-1539.patch   | 104 ++++++++++++++++++
>  .../libsoup/libsoup-2.4_2.74.3.bb             |   1 +
>  2 files changed, 105 insertions(+)
>  create mode 100644 
> meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch
>
> diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch 
> b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch
> new file mode 100644
> index 0000000000..e8c9ee0583
> --- /dev/null
> +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch
> @@ -0,0 +1,104 @@
> +From 285faea567e1e2a95226201175dbf745a64a2439 Mon Sep 17 00:00:00 2001
> +From: Changqing Li <[email protected]>
> +Date: Fri, 20 Mar 2026 15:04:22 +0800
> +Subject: [PATCH 4/4] Also remove Proxy-Authorization header on cross origin
> + redirect
> +
> +Closes #489
> +
> +Upstream-Status: Backport 
> [https://gitlab.gnome.org/GNOME/libsoup/-/commit/98c1285d9d78662c38bf14b4a128af01ccfdb446]
> +CVE: CVE-2026-1539
> +
> +Signed-off-by: Changqing Li <[email protected]>
> +
> +Backport the auth-redirect proxy validation unit tests from the upstream
> +libsoup3 patch
> +
> +Signed-off-by: Jason Stasiak <[email protected]>

Hello,

This patch has formatting issues (see below):
> +---
> + libsoup/soup-session.c |  1 +
> + tests/httpd.conf.in    |  1 +
> + tests/proxy-test.c     | 36 ++++++++++++++++++++++++++++++++++++
> + 3 files changed, 38 insertions(+)
> +
> +diff --git a/libsoup/soup-session.c b/libsoup/soup-session.c
> +index fadd5cd2..4cad0946 100644
> +--- a/libsoup/soup-session.c
> ++++ b/libsoup/soup-session.c
> +@@ -1192,6 +1192,7 @@ soup_session_redirect_message (SoupSession *session, 
> SoupMessage *msg)
> +     /* Strip all credentials on cross-origin redirect. */
> +     if (!soup_uri_host_equal (soup_message_get_uri (msg), new_uri)) {
> +             soup_message_headers_remove (msg->request_headers, 
> "Authorization");
> ++            soup_message_headers_remove (msg->request_headers, 
> "Proxy-Authorization");
> +             soup_message_set_auth (msg, NULL);
> +     }
> +
   ^ Context lines must start with exactly one space. This line is missing its 
prefix.

Other issues:
Error: Malformed patch line at 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch:35
Line content: '\n'
Context lines must start with exactly one space. This line is missing its 
prefix.
Error: Malformed patch line at 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch:45
Line content: '\n'
Context lines must start with exactly one space. This line is missing its 
prefix.
Error: Malformed patch line at 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch:55
Line content: '\n'
Context lines must start with exactly one space. This line is missing its 
prefix.
Error: Malformed patch line at 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch:95
Line content: '\n'
Context lines must start with exactly one space. This line is missing its 
prefix.
Error: Malformed patch line at 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch:100
Line content: '\n'
Context lines must start with exactly one space. This line is missing its 
prefix.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247020): 
https://lists.openembedded.org/g/openembedded-core/message/247020
Mute This Topic: https://lists.openembedded.org/mt/121498015/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to