Public bug reported:

The security upload  8.20.0-2ubuntu4 incorrectly backported various
security fixes, causing both stylistic issues breaking the tests, as
well as the CVE-2026-8927 fix to be ineffective: The test case "HTTP
proxy auth Digest, then change proxy and do it again" is failing when
running as part of upstream-event-based-tests-openssl (after fixing the
checksrc style issues so it gets to actually run the tests).

This security upload has been reverted as per 8.20.0-2ubuntu8 as we are
so close to the beta freeze (upload pending)

Please make sure to correctly backport the security fixes, and prepare
an update with passing tests for either the post-beta or an update for
the -security pocket on release day.

Please double check whether the released security updates for the stable
releases are passing their test suites.

** Affects: curl (Ubuntu)
     Importance: Critical
     Assignee: Ubuntu Security Team (ubuntu-security)
         Status: Triaged

** Changed in: curl (Ubuntu)
   Importance: Undecided => Critical

** Changed in: curl (Ubuntu)
    Milestone: None => ubuntu-26.10

** Changed in: curl (Ubuntu)
       Status: New => Triaged

** Description changed:

  The security upload  8.20.0-2ubuntu4 incorrectly backported various
  security fixes, causing both stylistic issues breaking the tests, as
  well as the CVE-2026-8927 fix to be ineffective: The test case "HTTP
  proxy auth Digest, then change proxy and do it again" is failing when
  running as part of upstream-event-based-tests-openssl (after fixing the
  checksrc style issues so it gets to actually run the tests).
  
  This security upload has been reverted as per 8.20.0-2ubuntu8 as we are
- so close to the beta freeze.
+ so close to the beta freeze (upload pending)
  
  Please make sure to correctly backport the security fixes, and prepare
  an update with passing tests for either the post-beta or an update for
  the -security pocket on release day.
  
  Please double check whether the released security updates for the stable
  releases are passing their test suites.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167779

Title:
  Reverted security upload 8.20.0-2ubuntu4, broken checksrc and
  CVE-2026-8927 backport

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/curl/+bug/2167779/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to