On Sun Jul 19, 2026 at 5:10 PM CEST, Yoann Congal wrote:
> On Mon Jun 29, 2026 at 12:27 AM CEST, Yoann Congal wrote:
>> On Thu Jun 25, 2026 at 2:55 PM CEST, Hitendra Prajapati via 
>> lists.openembedded.org wrote:
>>> Pick patch from [1] & [2] also mentioned at Debian report in [3]
>>>
>>> [1] 
>>> https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83
>>> [2] 
>>> https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84
>>> [3] https://security-tracker.debian.org/tracker/CVE-2026-42011
>>> [4] https://gitlab.com/gnutls/gnutls/-/work_items/1824
>>>
>>> Signed-off-by: Hitendra Prajapati <[email protected]>
>>> ---
>>
>> As far as I know, this fix is also needed on wrynose:
>> CVE-2026-42011 is fixed in 3.8.13 per Debian Security Tracker but wrynose 
>> has 3.8.12.
>>
>> Can you send a fix for wrynose so I can take this one for scarthgap?
>>
>> Thanks!
>

Hello,

> Here the current state of this series: Hold pending an equivalent merge on 
> wrynose.
> v1 series received here:
> [OE-core] [wrynose] [PATCH 1/6] curl: ignore CVE-2026-4873
> https://lore.kernel.org/all/[email protected]/
> but had reviews and no v2.
Self-replying: ^ this is wrong. this gnutls scarthgap patch does not
depend on a wrynose curl patch but on this one (received in the
meantime):
https://lore.kernel.org/all/[email protected]/

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241331): 
https://lists.openembedded.org/g/openembedded-core/message/241331
Mute This Topic: https://lists.openembedded.org/mt/119972753/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to