From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Wed, 12 Feb 2025 20:19:33 +0100 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1tiIGk-001YHn-17 for lore@lore.pengutronix.de; Wed, 12 Feb 2025 20:19:33 +0100 Received: from localhost ([127.0.0.1] helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1tiIGj-0006bc-8j; Wed, 12 Feb 2025 20:19:33 +0100 Received: from mail-vi1eur05on2091.outbound.protection.outlook.com ([40.107.21.91] helo=EUR05-VI1-obe.outbound.protection.outlook.com) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1tiIGP-0006Zy-Nj for ptxdist@pengutronix.de; Wed, 12 Feb 2025 20:19:14 +0100 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=nSvrN47gpKB+/JbxJ73F00pj1F+LuZUAgAiSm5AY/9qYlOihzmNumUY2kv7bm3zZETiJcbRmZDhs7XmzPCxlYpPu8Hmgg+GGx+F06PzZb2KhyExx9S0gekSEjTWaqHPV5GKgnnMounzvddFDUYDyeHeN6kqsylMPjQsgnIkzT9YSivDLWUrTJy0S2S8oiQUHi+kshgVR68SwbJ4MONls3d3gURmc28vcBXwDacx3ZjVONwzCi2U1dXZx3dtToacSF3r85GUT5du0ZDEMlzZuwAGE5q/4ht7ykqttxcXSCSukwhMoxu4LLlS11AVjFNXfRQ9K+jyTMvWb+Uuxwf9RKQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=QMG+pPCZebYMSNN4WmeNeYQzLFqmbiTJgetEjPclMj8=; b=JQZHbaAOZ0Pdw+rltnR+DPcHbmDcTM23ZOy8tGUHfaVzjtTRPp2xYj+mE+wisMeEikCr0wXdGvNEutUTkOAhBVc7J+DhYe/ovMHOa2SQk1ZRiBlFvMpyOm9kDm5kctwKkV+YXc+XmBSxNst/XjxWDLQkn5ZL4T2H2mPCE3Hcj7y71F6HNwkz92HMsgz+Kwd47s1mnc4hoBassQ4QvYKtR6Y5JKTuix1VygsBJNB6u/sKSbVlW0n8D/CdkD8kBhbx4H2iIm5MOAnQ3s0rUvprbPeqkNxCChV8yg3JyQaJI/cfsWKmPFtNAVfjLB4njnupwyAZWR3oJQZLD/rW7j+XQw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=t2data.com; dmarc=pass action=none header.from=t2data.com; dkim=pass header.d=t2data.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=t2datacom.onmicrosoft.com; s=selector1-t2datacom-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QMG+pPCZebYMSNN4WmeNeYQzLFqmbiTJgetEjPclMj8=; b=BSmjM+T7Cz8t1biPweXeMQxf33iA0TJ8Hg07SnHvqwCKz9bODpjx7VCp7SDEOiGOBxm58WLpnTToqIcTZJbjj8NnDsNEPsm6zkV3Yh4A8dde5CqvLjwtABLJOj0aAf1pGHKnk/0h+dygGgXd1SEtZdYMXXruCheWdZv+oaXrLU4= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t2data.com; Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) by GV2P251MB0948.EURP251.PROD.OUTLOOK.COM (2603:10a6:150:7e::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8445.13; Wed, 12 Feb 2025 19:19:09 +0000 Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::fe8d:f825:5b29:2903]) by DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::fe8d:f825:5b29:2903%4]) with mapi id 15.20.8422.015; Wed, 12 Feb 2025 19:19:09 +0000 From: Christian Melki To: ptxdist@pengutronix.de Date: Wed, 12 Feb 2025 20:18:56 +0100 Message-Id: <20250212191856.2665183-1-christian.melki@t2data.com> X-Mailer: git-send-email 2.34.1 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: GV3P280CA0067.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:a::32) To DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB9P251MB0618:EE_|GV2P251MB0948:EE_ X-MS-Office365-Filtering-Correlation-Id: 8b71fbc9-68d8-4008-5579-08dd4b9a2010 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|1800799024|52116014|376014|366016|38350700014; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?AKUjwTSez6jXLpSIJXLOFmtNxoJ2P4nAeGkHBjOMPWBc2ROQpRxwQFBNSRTw?= =?us-ascii?Q?A+XhpMUhJsj+8ViRsoP+w9ljrYynrf1F+Cwhd1Ms4cq+97eC6ZZk0GGkpZvw?= =?us-ascii?Q?H7GGr/e4gr6FWqbmScWR4eZ4XcVZ6fxSZ09akf7MM8WfLFHp3jrUKiG1YATC?= =?us-ascii?Q?JoupNa9WaEb25RHHJhI0v2m52UmkbXrqN4XjhBaqtRGwdobcHcAU0lUkytCh?= =?us-ascii?Q?Iq05vbSJxJ+kCqd92MFrYoHhGT4inVsbioRffKxrQYgXPYdymM2j+o//LjZn?= =?us-ascii?Q?XlU0N61B93Lzh/z1gId/tmFfW03AZ8NizvjdmttCk5Nlna48J8OVchG0AnXR?= =?us-ascii?Q?ySIVZrkZHFc5Blr2bfaZx2vblNda8J8b1VSS/WfpLJc1W3cCVJQZtX5aAaI9?= =?us-ascii?Q?3W9SVFiT0OY8fmVqM3qC/PLOgxkm42VBbhxW0sb8Yn7bTHhcCx8Sk0qqFd1X?= =?us-ascii?Q?8Fd9pBc4LWen/bu9UZZjGunPKKYfWOC/Q2kAzKiSS7VwK3ULAW5JW1p0+hr2?= =?us-ascii?Q?SPV9njQ50tBSQLTarqgGG44H7Z3JlFcN2rBTqzX35pQO/DXAU6D2s5GbG7v0?= =?us-ascii?Q?kmSDLF5OMz/l1LFSk83ra2s1FFSu5tjujqKzelHkuNzQaJ+yc9CmNaT0cB6o?= =?us-ascii?Q?Q4YUJFh1LAipuNu71mASYzK8TyYeKmHAWhDqW3es8P2U3dqLQut+lDvtquYq?= =?us-ascii?Q?a6eVF4Hc3/tKGmzCwv0CXAhGQXlbDXYsOxMnyVI9VON8MeUSAqckLYWtA7eA?= =?us-ascii?Q?BKSREQiGWHEOaG6CY1Dd9/DTpnacZbYfKn7DjVk0kpvLSdNVx9G0hJj3eT2E?= =?us-ascii?Q?OZOIhR0yNZLeq3lJrRq/LlWc+sB7+5jRW0oXr0nv+anm3fzTpOxdLAodF1r3?= =?us-ascii?Q?vfdXhnm1MZUGV1sArMeC3++K00SqoxlTGcQK7Ad6oshOBUhj+7/dugIlAZeS?= =?us-ascii?Q?mwJ0PNB91K3oxmyDkGFtePM/geMbB8HKddWj3Jz5xEoUpe1OAh0f9q9pwWQw?= =?us-ascii?Q?bdvvuIHLtrAIzWr9mXTn00JxtY57STZT+Pu8s1x1Et73UwY2tgS6VMTi5s6R?= =?us-ascii?Q?X5rqm183sjmVs/qiAVGxOEj5yTrZQgZjFQ/0HY4K9NUTUnyi82lCIk//tPaX?= =?us-ascii?Q?1Wssw/cnOpwW8CpD3jlX6DVK08+9ectJHkaM9eliQF+c119s6CcSAdV91lJp?= =?us-ascii?Q?UxVb5RJo419RYvXxRy2ZWNtMxm6wvWxwYWbyMPVJOuNHICrEWncEk15IM3ma?= =?us-ascii?Q?qAMtGKs1c6y5pKwhf/ELBh01PYr9DveW+pf4VEE019dTpVGBPpkd90Q1E1sx?= =?us-ascii?Q?TvoPONe+XDLFoJ1+5PxlEjnZexOiTrAQmg1Z1t8w7C0PUGyztv2m/tvTzT9M?= =?us-ascii?Q?/mSeecNckEF0wZQllLRPXJfUVGGn?= X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P251MB0618.EURP251.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230040)(1800799024)(52116014)(376014)(366016)(38350700014); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?hyw+ekvVS6zQQRCMc/ocJmBin7KxlLFX5SgTohwbAkCz6nhf6Aw/VuOlxibj?= =?us-ascii?Q?w2hl6evvL01vnjlMG3O9YzwESjXg8okm3jst8B6zvOH5KDNIxxqqvApb0o0H?= =?us-ascii?Q?gh065ciT0dLMsAUxiE0mWnLkeWg0123K5XtdqLx4eqd5b1AJ53vnSF2CJ1Oa?= =?us-ascii?Q?htDcgMCXg3zrIzYhbblnIHhVBn1g6Lo5XKvIH0MZjvqwiEWBEZg/7CbYFdhz?= =?us-ascii?Q?gMUjE0deU2Ais3v5hOGp8yngrJzYtZmIyOVBYIPUBE/7pvB5hJPsvMszttLH?= =?us-ascii?Q?eR3uxF3SOLIWdpUl3Mf6d7NyFKmYPuugx+pv54F3VO26p5rC6ChPRTtq5eUT?= =?us-ascii?Q?tqSxY9R2YuZHQo+5Ht19nEcRjV4DpPXjUHELLWfLwekH68HgXnde7IwY6zBL?= =?us-ascii?Q?O/lCf8kLfMKv9c+V0BlEQTbBVE/xaVl2wrt0vjXPiYDu1CZlGz2h+lvRzIKJ?= =?us-ascii?Q?WzoC4fmO5KDN47grBrCBUSBcTPJ3eYy2tScZzgfhK813EE5qqt/BZEvKQD+o?= =?us-ascii?Q?ol6m1bZRxKoN0//JiVppm5fJBw390BMk6utCNTgQtx3PN8TFCZrA2YdJO7KS?= =?us-ascii?Q?fR+HNqsCO0eM6Cl46J+AHEdUyg0fPp9yTeb3ky3SJJ0ehJkt+ViOzFW5KKgz?= =?us-ascii?Q?9VYOjG59UVLJ2CXOsjKQmGquW203RZzXRr4rEsnT666qLlJI0m42M6MVxW4u?= =?us-ascii?Q?SebPg9sNhEyEXMWFMuE5HUqrKRytqMassZrUisYG3548txg7mjO30BCHYC5v?= =?us-ascii?Q?O5KAcQLBskLYIoUkqj5q/isUWQP+ooBlEq1Z9JZxaVZmj8phf2KPHFTdfYLu?= =?us-ascii?Q?JXPhtaAFe4cAo/9CdQpIKRNaXy7kY4Cr72N5cL4nQnCm88su+lzdydzHGYNG?= =?us-ascii?Q?w2A+Bgq0oalhhJsnlr+YfoO+EeOb05/QQDc3J1Lf83i0lVhbwwfRucYoTGTn?= =?us-ascii?Q?ksPNgXJlT91akTwc3Zj8BmGWO49CZyoZM6XFFWYrv2M1WgYaWvvr6oJIv6UY?= =?us-ascii?Q?438gwGU2Z8K7gJggg2GNEglS9PnTHPgk4SvE8piXDH2jt3ON7XnZpkf7u8WI?= =?us-ascii?Q?O5Xp93P/7oCgk0JwEwJCrLOTHNZ5AYnougYITUVKb2umc5QXO+YiUypPWHnl?= =?us-ascii?Q?gvd0jcX5LtfT6fJAT0wnJArGx06a2PS9dFj6xpUY/BbSubLRcyzW89f/Z/6x?= =?us-ascii?Q?dVHKHy6z36E4K+8AJLRXDuky/ZutRWb4eGtwfMtVN9QBkrAOsQ0fw7bEQ8iU?= =?us-ascii?Q?IroVQMw/IAFkJSy/JExaeKdAgrQvB6cUDNNRnt9G8SebuvCndcKVbvMqUdMJ?= =?us-ascii?Q?A5YX/fnDFr7czCwoDIM0YWCAWOMFsQJTigOXzf9qxaxYQ2ZJlPaEiYWkl2kq?= =?us-ascii?Q?R7FiPdJMHMCfezKP6TZiEhWKvR+8OueIRNqgY7U5SQyk/jO9BJFY0npfEe65?= =?us-ascii?Q?ajsfoSVmHHenoMtXR5ELTat4Le7KsVJoVEhD5FB8zj4XGHpJ5uLoeS0rkbd/?= =?us-ascii?Q?aoO0XnbixSNW/s4LigxeLlZai+3D5TuEYl4ca4T2FxcE7W0C16wJ4UFHhxFz?= =?us-ascii?Q?9cICyVl1u12EYeAKe0ccx7eIQZQzZ78sV89fwL4B8UVZ4XhH9C1+5VgrutCQ?= =?us-ascii?Q?ww=3D=3D?= X-OriginatorOrg: t2data.com X-MS-Exchange-CrossTenant-Network-Message-Id: 8b71fbc9-68d8-4008-5579-08dd4b9a2010 X-MS-Exchange-CrossTenant-AuthSource: DB9P251MB0618.EURP251.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Feb 2025 19:19:09.3682 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 27928da5-aacd-4ba1-9566-c748a6863e6c X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: DSHlZAtXnVPfz/Z1ARUQpk8wvwplEVfd33YOwflw7XrwnW6PVRsTetRZC3Me26D/2BgqdtDNrjoVz8vaDwVPRcg7jh/3bC+FQHYp1YUeMc0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2P251MB0948 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-2.1 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_MSPIKE_H2,RCVD_IN_VALIDITY_CERTIFIED_BLOCKED, RCVD_IN_VALIDITY_RPBL_BLOCKED,SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH] libcurl: Version bump. 8.11.1 -> 8.12.0 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Mostly fixes. https://curl.se/changes.html#8_12_0 Plugs CVEs: CVE-2025-0725: gzip integer overflow CVE-2025-0665: eventfd double close CVE-2025-0167: netrc and default credential leak * Copyright year changed in license file. * Remove deprecated options. Signed-off-by: Christian Melki --- rules/libcurl.make | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/rules/libcurl.make b/rules/libcurl.make index 4ce6fe031..87dc7d488 100644 --- a/rules/libcurl.make +++ b/rules/libcurl.make @@ -15,15 +15,15 @@ PACKAGES-$(PTXCONF_LIBCURL) += libcurl # # Paths and names # -LIBCURL_VERSION := 8.11.1 -LIBCURL_MD5 := 25e65a5156ca4928060b61cb051813db +LIBCURL_VERSION := 8.12.0 +LIBCURL_MD5 := 3005f775ce65b301a27f8d43a8c85511 LIBCURL := curl-$(LIBCURL_VERSION) LIBCURL_SUFFIX := tar.xz LIBCURL_URL := https://curl.se/download/$(LIBCURL).$(LIBCURL_SUFFIX) LIBCURL_SOURCE := $(SRCDIR)/$(LIBCURL).$(LIBCURL_SUFFIX) LIBCURL_DIR := $(BUILDDIR)/$(LIBCURL) LIBCURL_LICENSE := curl -LIBCURL_LICENSE_FILES := file://COPYING;md5=eed2e5088e1ac619c9a1c747da291d75 +LIBCURL_LICENSE_FILES := file://COPYING;md5=72f4e9890e99e68d77b7e40703d789b8 # ---------------------------------------------------------------------------- # Prepare @@ -75,7 +75,6 @@ LIBCURL_CONF_OPT := \ --disable-versioned-symbols \ --disable-windows-unicode \ --$(call ptx/disen, PTXCONF_LIBCURL_C_ARES)-threaded-resolver \ - --enable-pthreads \ --$(call ptx/endis, PTXCONF_LIBCURL_VERBOSE)-verbose \ --disable-sspi \ --enable-basic-auth \ @@ -114,7 +113,6 @@ LIBCURL_CONF_OPT := \ --without-wolfssl \ --without-bearssl \ --without-rustls \ - --without-hyper \ --with-zlib=$(SYSROOT) \ --without-brotli \ --without-zstd \ -- 2.34.1