On Tue Sep 29, 2026 at 3:28 PM CEST, João Marcos Costa wrote: > From: Deepak Rathore <[email protected]> > > Analysis: > - CVE-2026-9547 is tied to the libssh backend. [1] > - Wrynose curl 8.19.0 does not enable or expose the libssh > backend in the recipe. [2] > - Hence mark this CVE as not-applicable-config for the default > Wrynose recipe configuration. > > Reference: > [1] https://curl.se/docs/CVE-2026-9547.html > [2] > https://git.openembedded.org/openembedded-core/tree/meta/recipes-support/curl/curl_8.19.0.bb?h=wrynose > > This is a backport of the change below, from wrynose branch: > "e32fc16287f0: curl: set CVE_STATUS for CVE-2026-9547" > > Signed-off-by: João Marcos Costa (Schneider Electric) > <[email protected]>
Hello, Can you send a reworded patch for scarthgap instead? And please recheck that the justification done for wrynose is also valid for scarthgap. NB: we don't usually backport between stable branches but rather do a backport from master on each stable branches. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247133): https://lists.openembedded.org/g/openembedded-core/message/247133 Mute This Topic: https://lists.openembedded.org/mt/121489790/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
