On Tue Sep 29, 2026 at 3:28 PM CEST, João Marcos Costa wrote:
> From: Deepak Rathore <[email protected]>
>
> Analysis:
> - CVE-2026-9547 is tied to the libssh backend. [1]
> - Wrynose curl 8.19.0 does not enable or expose the libssh
>   backend in the recipe. [2]
> - Hence mark this CVE as not-applicable-config for the default
>   Wrynose recipe configuration.
>
> Reference:
> [1] https://curl.se/docs/CVE-2026-9547.html
> [2] 
> https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.19.0.bb?h=wrynose
>
> This is a backport of the change below, from wrynose branch:
> "e32fc16287f0: curl: set CVE_STATUS for CVE-2026-9547"
>
> Signed-off-by: João Marcos Costa (Schneider Electric) 
> <[email protected]>

Hello,

Can you send a reworded patch for scarthgap instead? And please recheck
that the justification done for wrynose is also valid for scarthgap.

NB: we don't usually backport between stable branches but rather do a
backport from master on each stable branches.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247133): 
https://lists.openembedded.org/g/openembedded-core/message/247133
Mute This Topic: https://lists.openembedded.org/mt/121489790/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to