From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Sun, 11 Jan 2026 16:33:19 +0100 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1vexRP-000Cqj-2X for lore@lore.pengutronix.de; Sun, 11 Jan 2026 16:33:19 +0100 Received: from localhost ([127.0.0.1] helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1vexRP-0007Fo-5a; Sun, 11 Jan 2026 16:33:19 +0100 Received: from mail-westeuropeazon11021082.outbound.protection.outlook.com ([52.101.70.82] helo=AS8PR04CU009.outbound.protection.outlook.com) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1vexRG-0007FO-U2 for ptxdist@pengutronix.de; Sun, 11 Jan 2026 16:33:11 +0100 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=QEV64sgJ4W/LX7CHSb+7sPg+YKKAJB0VnFB2e1/0j+jcEbibWet0PTyG48YDiTktosuE+/oOLrvc3GETWBdIBZ7BkatxED+enktckqMnnH9hgLTSaKfN3nKoYmBY64NRrm8OU5xboSd/2AgnclH1ScrFXX+tBx2mFjbeaemxmI6JWRxYDJqBiRrpDVW/2J8CIhiqjQehyhvX9MzsyCKnDJAklG5rb3yccICmba2K574eit4MuRRUAT/ZpW2TZ0t78L8b7t43IZ6p/At0zcEwjCkq0qxlWtl12NYK7JGxJl9hMUTXI58frLe0HwisW+kH02Ljrh+X7XVEzVHY0Q0Y+A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Yerq00beXysnZTYAyqmRmK8Mk4kOaHWqmJnx78DHaR4=; b=Zcf4mKv/8KOXugIQ8/RKCGmdk/xVw7MNvSRU6VBu7GP4hJvAic0XFfISd5IJjKoUYE0FDaquNccEZ7M0gbqFZD79hAB6aBOgxn88eNcg5vBFMyeRn6wqDnQSOrCSpWlozKUYKwyIKdosJzg3WKuyDpO8VZAlrRM3ty/YwJnI+otRENURkQq4VUrSyAO8hFDSdqWZA0SRUHxBvaUEtoKJHvVrS9EAO9cxK4w8QTlzPF6lvvyNLcf6eHTnsE2GebEPZ+q0T4p4meaw13PQijVJjz9BecRVhSRkgBP1DO+AEeRZf9GcNXv041ou3f2ZOVjtEozINoM6MnYj53VxnhUZYQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=t2data.com; dmarc=pass action=none header.from=t2data.com; dkim=pass header.d=t2data.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=t2datacom.onmicrosoft.com; s=selector1-t2datacom-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Yerq00beXysnZTYAyqmRmK8Mk4kOaHWqmJnx78DHaR4=; b=NFmWBNRpCqa1keK/K8uRnFb+g/2zlM/0oKtvIhg0dR7RZHCp9LEs/7dCVWh0RF28jwXk7H0l0S0wszsCbinRBDCeBzpRCNuXpJaETM5/TLRgHAGeYP1ZSxGZRo6i5fHcTyjf9bDLl6ZWt4rXVrRz3vlkwNiYNU4x4MNljJN/jI8= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t2data.com; Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) by AM9P251MB0053.EURP251.PROD.OUTLOOK.COM (2603:10a6:20b:418::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9520.4; Sun, 11 Jan 2026 15:33:09 +0000 Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19]) by DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19%6]) with mapi id 15.20.9520.003; Sun, 11 Jan 2026 15:33:09 +0000 From: Christian Melki To: ptxdist@pengutronix.de Date: Sun, 11 Jan 2026 16:33:03 +0100 Message-ID: <20260111153303.2713046-1-christian.melki@t2data.com> X-Mailer: git-send-email 2.43.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: GV2PEPF000239B6.SWEP280.PROD.OUTLOOK.COM (2603:10a6:158:400::23b) To DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB9P251MB0618:EE_|AM9P251MB0053:EE_ X-MS-Office365-Filtering-Correlation-Id: cc71d8c9-0239-4288-1a32-08de5126b94d X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|52116014|376014|366016|1800799024|38350700014|7142099003; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?1IOrLxKyR/XB/+aUam55iwB/smTr9Jevi3ZYUv35CJaHE03sQydh1wZZvR57?= =?us-ascii?Q?ROEqziQM1cp4MRwFt3b+BDkG/0/yOkj8+t7+lre88/SX71P4cPuwYzns58pu?= =?us-ascii?Q?3Ogkpf0M4esCZF1VHzzw72KOBUsEGlq+TKP7QzN8YDsdG0eRQjCSHUrTtPC4?= =?us-ascii?Q?NzCYrbM4eIWNUM9QvT0cIW2rVsHx4gJ2F/U1yNwPC2TICeDyHJ4KaaFaD8FU?= =?us-ascii?Q?4UG86mdhMfTgTQBh0rJP7yvlqvdpoaeds4b74uWLFf2HZXu51CZVEKqPb7p4?= =?us-ascii?Q?qr5VK+5BTne5yqXoKth8nB8cWPvWZBFcEHAIE2yoE5lKd0aZ18xLYM5LDBg4?= =?us-ascii?Q?dAxr1dslypO2mbCnF5OtklQ/jcKM9lUmpKE9Qeu1lvrvyEjV+1W8KSbnW8Hi?= =?us-ascii?Q?BfUkcpXjKsiBz6igKYTnlVn+d9V+CUWH3QjbGieCvMpptGIkx/A0T7HJ2IRo?= =?us-ascii?Q?C0GmAXZ1E7LTJSYW2FuhTJ+LXxpHdqwg4nwJuo4r5K3CMaTg5Wvnf823dfHR?= =?us-ascii?Q?nAu0Bc6ezhXTJvsenYgU/XJf7kJVry0KqZ5fl+yCIkc+B9MRTPU0XNMLiPbe?= =?us-ascii?Q?hzDqHHT9t2wczNlbVDUo+5E2GUhg0Ul8RQoR69a9ETIT7fsEJG1xRGyp2XAx?= =?us-ascii?Q?lV6lmCJVS5L9DFlHOmaE5c9sI9D0Q15CfR6uUEqYxLKxh7WsSCFcnjtcba5M?= =?us-ascii?Q?DWhJuveIZGfCzxX0HpHhUNvkwWBr5gNzq+MiNrLd9QvvlOH/PZYu9Y0d8bnl?= =?us-ascii?Q?UcJO5XOJvOW/5Z++0xdSksXa1bcG6t126xH5dJOBTWvy8Wk+65wd0ZAZda7r?= =?us-ascii?Q?6UdisWl9/Oub/qYrLMttaRUM7knHpXSP4xwZA4pP6K13qLy/QcJ51I41uEo8?= =?us-ascii?Q?c1nzs8o28GG4XEQIIxVxZR0PRWGFeQvMZ0oscp/Jpd/2YiDtwaMuu2r/gaTZ?= =?us-ascii?Q?jJ0UnXMr0IqRa4If33GMQDwt03YNJt3ion6pi5q0XZHhvqG5lT0/CDxYdwVj?= =?us-ascii?Q?1WA80396C3gnQFCMPtT/LKcfRK7d+lI9B9D5+CR8KwaoTrujWx646Tool1ic?= =?us-ascii?Q?lY0JarCGHCe/5AnGcrYp1/02RvuwPTWMwaUm+XqwA9jSVX5DAZaQd2JgzgN9?= =?us-ascii?Q?2a0y24Pzv3w5Ybd6GbMJrK0NG8PQHw6mYCOm43t8Uil18UTZF51nq7DKpiUR?= =?us-ascii?Q?yE1RF7ohuvqcu4SLQg1Hb0U/Pm0GooUNNXfVctxDdqFdGhmd1JyaDfspfN24?= =?us-ascii?Q?xUJRCc46+QP+BgZ1O+/z28QuR+hnDj0XAHgBKcu8o2XnnUK/1W8972amj886?= =?us-ascii?Q?QGVf80mHPHz8ILJPLYyx7uPHGTVRVnPP1iT28Mv4+/uVbW/e9wZd3CIw8beQ?= =?us-ascii?Q?rw75HO0T7RrEhd6J/Lu6L7Qc1q/YNd8NLDjPa6ZSyECBp+Yfk3etOqTpZhNZ?= =?us-ascii?Q?BavBvBNvcxiaJfj3ZRFo5qPTidFsW9fxGWbK3naVnv9nkrO3HX9Emw=3D=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P251MB0618.EURP251.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230040)(52116014)(376014)(366016)(1800799024)(38350700014)(7142099003); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?gqqwfYHZgo0JjHNaV8Dcl5qPYQ5AoS5Oi70W1lkq5YOOjhlhEvMEF9Nd1qwl?= =?us-ascii?Q?aL+fvKaNc/O4CZLfGzKtMBW/slDKt6TXM4/IeSkUwPsys0aggYzlUiirin1v?= =?us-ascii?Q?t1HYGcMMHBhBXqPcGdi2ZzLyEgQGGjC/wH3EOdunpIpCHdAa/lMMEGrEXP1g?= =?us-ascii?Q?cGJlJ3dsVYs5wguLBZ3t57+4qIP+IMgLxcXe1ln8nsodvF0qQJ57FBNMe5f8?= =?us-ascii?Q?42n6D3yrMSJjBwWhBWuLfiUJoxhPltVxvEMnE6Q8svfO2FB1sAF77L0DYj2E?= =?us-ascii?Q?0cuFXgArTsVBUhrbRpknAYfCKmPcLJCo+K6g/8bRlgbZvH/wnlYHBEhdKpop?= =?us-ascii?Q?zfHPXQaae7PV12lNWCPF3dngZ3kPY92t2xnMQNyRKVbGGtC6Osi/HFBLHdKW?= =?us-ascii?Q?QNiD6Uqvq+bte8Vcx/g6WMm85r3vswYT4LwwHIS4ve5GofDFk/2BrB/I0vXN?= =?us-ascii?Q?zkA88iYkcr/4/LSRTt9MODnLF1FWVBsNySXgpikH7tJb8LIj0si66oWWSfrG?= =?us-ascii?Q?HpcvNXaWjhZP1cRQs/FurRPa6dNgOLCgaAMompJz3YClJnaTFyan3IF0ujqs?= =?us-ascii?Q?aRfoZcrDnF2OuuCZ9J4uzusikM0Cgw4x3SRV37KwzeJIGowMcZkCvshS5NCB?= =?us-ascii?Q?l+FmeumILe0XMq1ZHxO/fa4BwmIu3JIksPjFOqabMz3as7TZYMJWcChUnB+m?= =?us-ascii?Q?jlvdl0BSdx6j4rugsRE33i/kjjHMSo9vbHgqpSy8SdPI8jz6cPzQXpXu86Z1?= =?us-ascii?Q?oiVoyt2S6ODtqMrtRoGAOFFd7N6CVm0Bo5SrVFC1OUB3La5/9P2W5NLZdbwa?= =?us-ascii?Q?UzIok8fX+ED+1pirm8+8RCsIKtCaB7+CjplLipiC/KyMb54llBqWw8EcinGK?= =?us-ascii?Q?Kdu5K9SdXbhYFZwy2DqZlXjfKiDSOvNN7JvyArP0xE9lOYO1iVOPk8LgEf0y?= =?us-ascii?Q?YGiCvljxnxdWhLBmvddScRD6RXxA2mkNZox5GLv/H6yt+wCLxu6Mw06g2Nwo?= =?us-ascii?Q?agtdKjfqUeaOKzK2nl/rrX1DNs2gemfLKwOhoV7BYOJfxEe52PlkyH5OtX68?= =?us-ascii?Q?P4St3DUEwoL3pTur6Cng6g2sqQ5JAMmjPalBlXItkxh8Xm6r+MFVQ+PtChbq?= =?us-ascii?Q?41Wa+2ggfN9RbFAg34FIqq6k0WtYX7LfcW4EYXNWDbcLWHTRZObJY9fTFC3x?= =?us-ascii?Q?4+6KXx61nQLC2/j1vzya7jkKQCc9AEuUHoAXa9osEg6AULpcaQbq60lVazmf?= =?us-ascii?Q?8sbdtkaLddfLv1f8z3Z47nAk7yAQshF1vFYZ9W4hpC8XcFScGfM4I6BMhv1X?= =?us-ascii?Q?86oYxWLYx0mArKxRHMKFDQnTNf+iwHuWZV7/BzdxAHzMDP4JNiLaUIUfyD2i?= =?us-ascii?Q?ndxSj9G4UFOG4Cvk3s25vhh93hGIFArGDgC38OjAFoJt45O0+iV1WZehGAl3?= =?us-ascii?Q?oDhlwE8BvUNV8FTtRTizm71dcxIhMW7qdQqUscnbf4wI0vle8s+0vCtCqbI8?= =?us-ascii?Q?Vtio2WKhvnoZDK3xUXiZ+V8Z3FBKXzO2JBHu0jkGsL3bKgRJfDSmub0oIQq4?= =?us-ascii?Q?LlRLlryf/+j/6vHj7OfGVkQaOzQNQrUZZ5WnvevUl5PRma8122+rqIKdp1aK?= =?us-ascii?Q?ectSz5UmQE9Bh8qi0nkmDk3wy6dIA7ufqb050tHK1Iw9rApmT4FXNRR9NMhW?= =?us-ascii?Q?EJSY64pKk/WXm/1DgokjU/VJeYFhaiosBecMUnClZ2brC0SOh+333XBFshXt?= =?us-ascii?Q?0oX62ZQ53cGcqR0rQEhIC++kU4pO7Yk=3D?= X-OriginatorOrg: t2data.com X-MS-Exchange-CrossTenant-Network-Message-Id: cc71d8c9-0239-4288-1a32-08de5126b94d X-MS-Exchange-CrossTenant-AuthSource: DB9P251MB0618.EURP251.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jan 2026 15:33:09.4219 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 27928da5-aacd-4ba1-9566-c748a6863e6c X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: wq2EVGOg4s4tIUVkd1X7i7A5nUnzyPN36rXSbFWDnMKzcJ41vHbaiZoG9NYGs4DeR+/qN2J3YzqVvNX7qb4syQ7LORucJLOoBnNVc4YpHcU= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9P251MB0053 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-2.1 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH] libcurl: Version bump. 8.17.0 -> 8.18.0 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Bunch of fixes + security + minversion OpenSSL >= 3.0.0. https://curl.se/changes.html#8_18_0 Plugs CVEs: CVE-2025-15224: libssh key passphrase bypass without agent set CVE-2025-15079: libssh global known_hosts override CVE-2025-14819: OpenSSL partial chain store policy bypass CVE-2025-14524: bearer token leak on cross-protocol redirect CVE-2025-14017: broken TLS options for threaded LDAPS CVE-2025-13034: No QUIC certificate pinning with GnuTLS Signed-off-by: Christian Melki --- rules/libcurl.make | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/libcurl.make b/rules/libcurl.make index e16c30cdd..62d9a8ccb 100644 --- a/rules/libcurl.make +++ b/rules/libcurl.make @@ -15,8 +15,8 @@ PACKAGES-$(PTXCONF_LIBCURL) += libcurl # # Paths and names # -LIBCURL_VERSION := 8.17.0 -LIBCURL_MD5 := 7a9d4b772fc56d68479b0416f234105a +LIBCURL_VERSION := 8.18.0 +LIBCURL_MD5 := dae6088bf7af69d3b0a87c762de92248 LIBCURL := curl-$(LIBCURL_VERSION) LIBCURL_SUFFIX := tar.xz LIBCURL_URL := https://curl.se/download/$(LIBCURL).$(LIBCURL_SUFFIX) -- 2.43.0