On Wed Jul 22, 2026 at 10:23 AM CEST, Amaury Couderc via lists.openembedded.org wrote: > From: Amaury Couderc <[email protected]> > > Backport patch to fix CVE-2026-58470. > > References: > https://nvd.nist.gov/vuln/detail/CVE-2026-58470 > https://www.cve.org/CVERecord?id=CVE-2026-58470 > https://security-tracker.debian.org/tracker/CVE-2026-58470 > https://ubuntu.com/security/CVE-2026-58470 > https://osv.dev/list?q=CVE-2026-58470 > > Upstream fix: > > https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf > [nvd] > > Signed-off-by: Amaury Couderc <[email protected]> > --- > .../wget/wget/CVE-2026-58470.patch | 78 +++++++++++++++++++ > meta/recipes-extended/wget/wget_1.21.4.bb | 1 + > 2 files changed, 79 insertions(+) > create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch
Review from Hetvi Thakar: On Thu Jul 23, 2026 at 10:44 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) wrote: > I reviewed the earlier series. > It looks like the follow-up upstream regression fixes for > CVE-2026-58469 and CVE-2026-58472 were not included in the backport. > These follow-up commits are required to complete the backport, and I > have included them in my series . > I kindly request you to review my series as well. -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242022): https://lists.openembedded.org/g/openembedded-core/message/242022 Mute This Topic: https://lists.openembedded.org/mt/120390837/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
