mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 00:04:06 -09:00
package/libcurl: security bump to version 8.19.0
https://curl.se/ch/8.19.0.html https://curl.se/docs/security.html Fixes the following CVEs: CVE-2026-3805: use after free in SMB connection reuse CVE-2026-3784: wrong proxy connection reuse with credentials CVE-2026-3783: token leak with redirect and netrc CVE-2026-1965: bad reuse of HTTP Negotiate connection Switch to sha256 tarball hash provided by upstream. Updated license hash due to copyright year bump:e83c82f05fSigned-off-by: Bernd Kuhls <bernd@kuhls.net> [Julien: add back pgp signature info in hash file] Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit3a5e071e4f) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
committed by
Thomas Perale
parent
cab7c3734e
commit
cfb1f63448
@@ -1,5 +1,7 @@
|
||||
# Locally calculated after checking pgp signature
|
||||
# https://curl.se/download/curl-8.18.0.tar.xz.asc
|
||||
# From https://github.com/curl/curl/releases/tag/curl-8_19_0
|
||||
# after checking pgp signature:
|
||||
# https://curl.se/download/curl-8.19.0.tar.xz.asc
|
||||
# signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2
|
||||
sha256 40df79166e74aa20149365e11ee4c798a46ad57c34e4f68fd13100e2c9a91946 curl-8.18.0.tar.xz
|
||||
sha256 e18f1989333b70044b2adfb7dc2f905d0119dbdcac3bc9f4bc9d540e3a29de5b COPYING
|
||||
sha256 4eb41489790d19e190d7ac7e18e82857cdd68af8f4e66b292ced562d333f11df curl-8.19.0.tar.xz
|
||||
# Locally computed
|
||||
sha256 82f2f4427d6545ee5aaac4f0b80428da6cc8ba41c2cf5da3a03680ec327b9681 COPYING
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBCURL_VERSION = 8.18.0
|
||||
LIBCURL_VERSION = 8.19.0
|
||||
LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz
|
||||
LIBCURL_SITE = https://curl.se/download
|
||||
LIBCURL_DEPENDENCIES = host-pkgconf \
|
||||
|
||||
Reference in New Issue
Block a user