From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Sat, 14 Mar 2026 19:04:01 +0100 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1w1TLE-000lBW-33 for lore@lore.pengutronix.de; Sat, 14 Mar 2026 19:04:01 +0100 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1w1TLE-000672-R1; Sat, 14 Mar 2026 19:04:00 +0100 Received: from mail-francesouthazon11021077.outbound.protection.outlook.com ([40.107.130.77] helo=MRWPR03CU001.outbound.protection.outlook.com) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1w1TKx-00066d-QI for ptxdist@pengutronix.de; Sat, 14 Mar 2026 19:03:45 +0100 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=H4ztIPYcRiyYWj3oaqJH/0BefoutJl65VoK/YYk0FG39jO7QM635mN/+np8+LDK6bF37mdL5tu+/K+94okuaqmdHyt6MYpqkeqSK+XS12IQAtVx/VrKRpw5V+hg5KQhIpGRgzLr8elQguED+ISkkbt0pemTxXgL+OrUY2Dxd8wF92FIvBZI1611hjwagTI+tfm0KBL2SCrWzawTwfbyVk4/ER6WRFB/AF/1VUztcDD3g1pjp5CiyQXu8u5HK11AaZ/YS8zUBdBRf1jdcKA827mCUcV5YF+PlScdXqLJNr2opxSks0uI5g+JQm5O7CkE4aCft7M27HcNdZDM/5+qCWg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=fPolZ3SaB1Z7ZCn48yXa2LWwD0Uo+Ex5boA3XKQq+v4=; b=L04yl0fIn/2w7daw8aolrlQ0rRyDcXdr6BIpQSoNv0cj1pH+am91shPpW3nyRjdd/iGiwHBdG/EXm1cBVbc8P3D5wvn0Ri3VqTzS47U18z6DVJ+03zyY24gS5XzAgiBwo3/JBm2lCNY6PuhoDKWmKo9lLV/ydlNtOQLachlspVUKdiZTbVmqIfoyIJKARZatptDmKfXbxAkrMbdZteSQxjGezmRjLeKSGda9W0T7XTEW7sEzUbdBqH/xTvfdrdSoVS6NYU3VSu9ppRZJ/Zo9qPFhRmspGc2INhQmtW83+CJg1gJOCxKpjNcfpV+7GgsskfANNtGgnY/sB4TjmqDKYw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=t2data.com; dmarc=pass action=none header.from=t2data.com; dkim=pass header.d=t2data.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=t2datacom.onmicrosoft.com; s=selector1-t2datacom-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fPolZ3SaB1Z7ZCn48yXa2LWwD0Uo+Ex5boA3XKQq+v4=; b=NL5N7NjwrXn8LX2GpEjeHAWeV/rEqJl8ycz4hZcwY5t/1hOARhUJU1jHKFX2n0Ybwt9OPAqDxgBE1PaADwzJDMioXTQBiyOG6e7uG161AOn7TcMDKNUuWNY95MqKVSa0QUXLGxUi6lSmDU69Oc5Pqw40Xeg8A5u210lhr/wATDc= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t2data.com; Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) by GV2PPF034246F94.EURP251.PROD.OUTLOOK.COM (2603:10a6:158:401::b45) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9678.25; Sat, 14 Mar 2026 18:03:40 +0000 Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19]) by DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19%4]) with mapi id 15.20.9700.018; Sat, 14 Mar 2026 18:03:40 +0000 From: Christian Melki To: ptxdist@pengutronix.de Date: Sat, 14 Mar 2026 19:03:22 +0100 Message-ID: <20260314180323.2055033-1-christian.melki@t2data.com> X-Mailer: git-send-email 2.43.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: GV2PEPF0001A333.SWEP280.PROD.OUTLOOK.COM (2603:10a6:158:401::68e) To DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB9P251MB0618:EE_|GV2PPF034246F94:EE_ X-MS-Office365-Filtering-Correlation-Id: d27a6df2-21ff-499b-1bf3-08de81f40583 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|366016|52116014|1800799024|376014|56012099003|18002099003|38350700014; X-Microsoft-Antispam-Message-Info: iAYvMaeMXfbYAZmZ+8Z4oCSh0iP8yzyUOimck5TCmujDYLVM/G6EKdj+FWms1tuXVgX+Bp7eFDWKJ2byAx0sw+NgJMPMJiphrfEwwuAesLd0xMnkaq1odeUBy5Kl/vUj7sWre52Ek2X99wZyH5GaIs0U26bPKp7oQT5pruKSYBkF8vD4dVrE5GZGcJsRSXVKSqtcL+fjM3Fi7uC7N0eG1RExgDv1rYPnaa1Pcy8k+S9AiOK7EbmPk6DkR/QOmuQJXBPnp751tRIQD4DnYCKWFcIuBPr9+/5ndZaxnAlHlZPBh462rNuaMJLNOSGldpSUQeyQ5VUx44pIZHBV7Wv8wl5E7z8Eud2qRgDu/bq6yzGEtBNi6YmUvMlBKUEySQd/LIb0wXN7rRGlkoHN1NASiWyJ3cuGj3jD0nE1pthL3jJ8M8vDRTv8Jxdmc5yK83ThHh8ecicghAhxzZviJEYpC3/uxTlZ84QaCnJ635HInihXpd/ImVaCLrIuyrtdILtXKosmR1DYGccgzIZ83G9u7XFYJ9vclOcIp4xhmghIGsB2QUchwe0ItAMv1WN5kmjirn4EQDuyrlAf4cQJaPvdiltisW85VAJOCDaERyzEZHI/1wRoulkuR6KHHd7PjTanVnI0toFdMysRLfXXOHloWVH3R/C042QNrSVC6BEeGisuYenuXEVQdemNE4Q+j/wJSXeAQuYxG6BF4qFbVEEV7sdK6ISishkJLQYPd3sLeOSTfWLGUjHJbOiM6U6Kh1Tc X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P251MB0618.EURP251.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230040)(366016)(52116014)(1800799024)(376014)(56012099003)(18002099003)(38350700014); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?7DsVvrNkfH7JvlL988Br2p7JtPMtcqdBgibvatfLMPEwxe4uKET5fAVGXkUl?= =?us-ascii?Q?EP1dM4MIgywaiBiyqCvEjx+WVBYaYUz3IHm4+zNe44Mxc6FcmzbQ2vptfdNQ?= =?us-ascii?Q?7As4uVfOGehbjd/AikAmp9zQyQKq7qzDR/WQWm0up+1KpkGUMiNozwBs0nHZ?= =?us-ascii?Q?ppYKMZix2uT1aLuq7v/WECiq8ZAUcqIBSoIcaupiLKQt/tAOXi6zJMimaplT?= =?us-ascii?Q?9kKPmT0HCnx1Pe5K5GJvluoNMKDImMJbc2lKnowF1YI/jGCK+O0LyK9ZlTZ7?= =?us-ascii?Q?WyrSqepHzqYn/10HJRrcfVlCNfTPkD4obhGzQdbQOtu9zAsujNN4BOhTeAXv?= =?us-ascii?Q?IWZpBuK23aN1VIe4kalkKvd3ThRk3eCknnXKWslC3jadj3gCeH6xX0TQsol9?= =?us-ascii?Q?CwifKNDlPOq0RXgjFw7h1wuloCmcdbDTOD3zYTk4Sn0PrtKAvbqov0+ufkUm?= =?us-ascii?Q?xLHhdl2B+Y0u2lg92Ag7EqSkO19yM7ubxMuCwp+DmG0pVS8rzTaTX+plrMOm?= =?us-ascii?Q?tQt8c58A9NbyNlCm7VhI2qOjhm8RlHH5/l3RSbahJH7nvqkIoKuC0jVsQWDM?= =?us-ascii?Q?AGvarToX1DGld1E9ZJn1WBAAkUkGVNfuklqKiFCOINnHEgkDIJn7C6U8A74+?= =?us-ascii?Q?AmRRVuUbzH3tqSLpI3y8cgnB+zlZ7+G/YRvveAhJh429egtw9qcgKaXCkkG3?= =?us-ascii?Q?dGMJSpBcDjFnd9BQLICIgRSZPZjJ0uDIrpIrT1Ba9A/oqbQ+pk+LaixocTzT?= =?us-ascii?Q?VL8+t+Q9OdrU8GMG0zNgMHU8y+Z33B0H95cc3ob9wkXIxqPdaoedH3rd62KQ?= =?us-ascii?Q?QDD72ThnPE90XiBi+El0CMIqGBLPeHXVrPOeujJUAZ79Ax/0UQGxcqzF+0Jo?= =?us-ascii?Q?T/K3OK1UNGksKHISHAWYowr3jfCHdpTmPvVa7TNzIei7MofzagsULqKWEw8E?= =?us-ascii?Q?hYwYZR/Ddy8VBI53XwIrIFTuY0AmdMbUTO3vrCNCENbMCC8ecGJTOpLirTFN?= =?us-ascii?Q?8FSpay/9PK18hMZI6tT+mJsCTJnDkirpZ168bMjM5HAoCY/x5CqEpUbH/ztI?= =?us-ascii?Q?tRNsJJewTLzoQFnihMXLKsRpF03/YCFEoPC6LgBLgljwi3Mq+bMPQtkqlSnQ?= =?us-ascii?Q?APG/PtQJYFpmA2MBzLXcQkro+BdvHIGFJumNmWAOW6WphLzmUtW3cUlYrp02?= =?us-ascii?Q?MHWpTI7a1Ief+xm5oifem9ysGDy9xb8OtbuyHe+MSFy9SPpXRQ+SSO03fBlG?= =?us-ascii?Q?Ys1utFjyWkmVFPucrays/p1r6brFm5ZlEVDbz0i0WMOReRlF/IDXeLA8lDhS?= =?us-ascii?Q?vdSNzBBoCme62MG0WSEA1gqCkjsfxgDm19lQA5u3TGNdWK8HlDbl47OnkwKH?= =?us-ascii?Q?SOVs3tONn1SyoMlEeEgL7aSuAvS+E04wUTf7KIn6KDUiwy4Hbq7vrQtRrJj/?= =?us-ascii?Q?uMCj7DmNJTbjon9RE9kUsrHKH/EyCWZTZ6HcEec7M/kfQFvlaJeGUuMRd2Ka?= =?us-ascii?Q?bX7KL99UROPOWKdUB85YcXP0BJIhCeipssNRiF6yYrcnZBIobDA7zD5Syl63?= =?us-ascii?Q?wF5TrSvEGiBUHLzg/WhEa4iTCa0W1LIza0UfxGdk9cN247jZjBjBR29GzR5m?= =?us-ascii?Q?KmM7uDKcTfddsbyaTJhP0miPs5Dk0o9LJ8iOUc26Ok7O0RWjLmcv1XzM0V/V?= =?us-ascii?Q?uRkfLT0RKRhouUiR+ijKKKKcemtgGYDsm2XsBJay/pXUQ+ewOwF58DAPD1ir?= =?us-ascii?Q?5G3cmtJ9PfgQahJZzBtzNUcR+xWKgao=3D?= X-OriginatorOrg: t2data.com X-MS-Exchange-CrossTenant-Network-Message-Id: d27a6df2-21ff-499b-1bf3-08de81f40583 X-MS-Exchange-CrossTenant-AuthSource: DB9P251MB0618.EURP251.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Mar 2026 18:03:39.9754 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 27928da5-aacd-4ba1-9566-c748a6863e6c X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: ZiZJGnR2Rz7iMsVFstCHHr2zoB9honFx6bz7Nd3OFjeOa91l+lXq23JsjBEFnDX2fl4MsS1y/CbzOZk4fFtrQIE0zqz+mDL5J1qLzJATVSQ= X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2PPF034246F94 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-1.4 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, SPF_HELO_PASS,SPF_PASS autolearn=no autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH 1/2] libcurl: Version bump. 8.18.0 -> 8.19.0 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Mostly bugfixes. https://curl.se/changes.html#8_19_0 Plugs CVEs: CVE-2026-3805: use after free in SMB connection reuse CVE-2026-3784: wrong proxy connection reuse with credentials CVE-2026-3783: token leak with redirect and netrc CVE-2026-1965: bad reuse of HTTP Negotiate connection * License hash changed. Year updates. * Fix new and removed build options. Signed-off-by: Christian Melki --- rules/libcurl.make | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/rules/libcurl.make b/rules/libcurl.make index 62d9a8ccb..d15ea064f 100644 --- a/rules/libcurl.make +++ b/rules/libcurl.make @@ -15,15 +15,15 @@ PACKAGES-$(PTXCONF_LIBCURL) += libcurl # # Paths and names # -LIBCURL_VERSION := 8.18.0 -LIBCURL_MD5 := dae6088bf7af69d3b0a87c762de92248 +LIBCURL_VERSION := 8.19.0 +LIBCURL_MD5 := d5d3581ba4b4df1140a26a6efcf13e61 LIBCURL := curl-$(LIBCURL_VERSION) LIBCURL_SUFFIX := tar.xz LIBCURL_URL := https://curl.se/download/$(LIBCURL).$(LIBCURL_SUFFIX) LIBCURL_SOURCE := $(SRCDIR)/$(LIBCURL).$(LIBCURL_SUFFIX) LIBCURL_DIR := $(BUILDDIR)/$(LIBCURL) LIBCURL_LICENSE := curl -LIBCURL_LICENSE_FILES := file://COPYING;md5=72f4e9890e99e68d77b7e40703d789b8 +LIBCURL_LICENSE_FILES := file://COPYING;md5=0515352b285b9c3f66464b135c9c0fdc # ---------------------------------------------------------------------------- # Prepare @@ -39,7 +39,6 @@ LIBCURL_CONF_OPT := \ --enable-optimize \ --disable-warnings \ --disable-werror \ - --disable-curldebug \ --enable-symbol-hiding \ --$(call ptx/endis, PTXCONF_LIBCURL_C_ARES)-ares \ --enable-rt \ @@ -110,6 +109,7 @@ LIBCURL_CONF_OPT := \ --without-mbedtls \ --without-wolfssl \ --without-rustls \ + --without-apple-sectrust \ --with-zlib=$(SYSROOT) \ --without-brotli \ --without-zstd \ @@ -128,7 +128,6 @@ LIBCURL_CONF_OPT := \ --without-libidn2 \ --without-nghttp2 \ --without-ngtcp2 \ - --without-openssl-quic \ --without-nghttp3 \ --without-quiche \ --without-zsh-functions-dir \ -- 2.43.0