mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-09 07:51:59 -09:00
https://curl.se/ch/8.21.0.html
https://daniel.haxx.se/blog/2026/06/24/curl-8-21-0/
Fixes the following CVEs:
Severity Medium
CVE-2026-8925: SASL double-free
CVE-2026-8927: env-set cross-proxy Digest auth state leak
CVE-2026-9079: stale proxy password leak
CVE-2026-11856: cross-origin Digest auth state leak
Severity Low
CVE-2026-8286: wrong STARTTLS connection reuse
CVE-2026-8458: wrong reuse for different services
CVE-2026-8924: trailing dot domain super cookie
CVE-2026-8926: password leak with netrc and user in URL
CVE-2026-8932: incomplete mTLS config matching in conn reuse
CVE-2026-9080: UAF after pause in socket callback
CVE-2026-9545: exposing HTTP/3 early data
CVE-2026-9546: sending old referer
CVE-2026-9547: SSH improper host validation
CVE-2026-10536: HTTP/2 stream-dependency tree UAF
CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop
CVE-2026-11564: Native CA trust persist
CVE-2026-11586: WS Auto-PONG memory exhaustion
CVE-2026-12064: proto-default skips SSH verification
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
(cherry picked from commit be2789d084)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>