Skip to content

fix(curl): pin-forward to f43 for 5 CVEs#17278

Draft
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-curl
Draft

fix(curl): pin-forward to f43 for 5 CVEs#17278
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-curl

Conversation

@tobiasb-ms
Copy link
Copy Markdown
Contributor

CVE Pin-Forward: curl

Pins curl to Fedora f43 HEAD (1538b20) to pick up
5 CVE patches added upstream.

CVEs Resolved

CVE Severity Status
CVE-2025-9086 High Tracked
CVE-2026-3805 High Tracked
CVE-2026-1965 Additional
CVE-2026-3783 Additional
CVE-2026-3784 Additional

Fedora Spec Delta

Old commit: 0e4af61
New commit: 1538b20

New patches:

  • 0003-curl-8.15.0-CVE-2026-1965.patch
  • 0004-curl-8.15.0-CVE-2026-3783.patch
  • 0005-curl-8.15.0-CVE-2026-3784.patch
  • 0006-curl-8.15.0-CVE-2026-3805.patch
  • 0007-curl-8.15.0-CVE-2025-9086.patch

Pin locks/curl.lock to Fedora f43 HEAD to pick up
CVE-specific patches added upstream.

CVEs resolved (2 tracked, 3 additional):

  Tracked:
    CVE-2025-9086 (High)
    CVE-2026-3805 (High)

  Additional:
    CVE-2026-1965
    CVE-2026-3783
    CVE-2026-3784

Fedora f43 spec delta (0e4af61..1538b20):
  + 0003-curl-8.15.0-CVE-2026-1965.patch
  + 0004-curl-8.15.0-CVE-2026-3783.patch
  + 0005-curl-8.15.0-CVE-2026-3784.patch
  + 0006-curl-8.15.0-CVE-2026-3805.patch
  + 0007-curl-8.15.0-CVE-2025-9086.patch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant