Public bug reported:

Scheduled-For: ubuntu-25.06
Ubuntu: 8.13.0-5ubuntu1
Debian Unstable: 8.14.1-1

A new release of curl is available for merging from Debian Unstable.

If it turns out this needs a sync rather than a merge, please change the
tag 'dcr-merge' to 'dcr-sync', and (optionally) update the title as
desired.

### New Debian Changes ###

curl (8.14.1-1) unstable; urgency=medium

  * New upstream version 8.14.1
    - Fix CVE-2025-5399: WebSocket endless loop
  * d/p/multi_fix_add_handle_resizing: Drop patch, merged in 8.14.1

 -- Samuel Henrique <samuel...@debian.org>  Wed, 04 Jun 2025 08:21:05
+0100

curl (8.14.0-1) unstable; urgency=medium

  * New upstream version 8.14.0
  * Drop vendored wcurl now that it's in the upstream tarball
  * d/copyright: Update for upstream moved files:
    - They were moved from lib/ to lib/curlx/:
       ~ lib/curlx/version_win32.c
       ~ lib/curlx/version_win32.h
       ~ lib/curlx/inet_pton.c
  * d/patches:
    - Refresh patches
    - ZZZgnutls-build.patch: Update to also work with tests/tunit makefile
    - multi_fix_add_handle_resizing.patch: New patch to fix regression
    - Drop patches merged upstream:
      ~ autotools_install_shell_completion_files_on_cross_build.patch
      ~ scripts_completion_pl_sort_the_completion_file_for_all_shells.patch

 -- Samuel Henrique <samuel...@debian.org>  Wed, 28 May 2025 19:26:28
+0100

### Old Ubuntu Delta ###

curl (8.13.0-5ubuntu1) questing; urgency=medium

  * Merge with Debian unstable (LP: #2111373). Remaining changes:
    - d/rules: use libssh2-dev as it is in main (LP #2076865)
    - d/{control,rules}: drop nghttp3 and ngtcp2 dependencies in universe
    - d/{control,rules}: do not use gnutls for the curl binary
    - debian/control: don't build-depend on python3-impacket and stunnel4 on 
i386

 -- Ural Tunaboyu <ural.tunab...@canonical.com>  Sun, 18 May 2025
19:46:02 -0700

** Affects: curl (Ubuntu)
     Importance: Undecided
     Assignee: Ural Tunaboyu (uralt)
         Status: In Progress


** Tags: dcr-merge

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2113994

Title:
  Merge curl 8.14.1-1 from Debian Unstable for questing

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/curl/+bug/2113994/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to