{"id":2230806,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2230806/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/patch/20260430044747.27619-1-bernd@kuhls.net/","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.1/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260430044747.27619-1-bernd@kuhls.net>","date":"2026-04-30T04:47:46","name":"[1/1] package/libcurl: security bump to version 8.20.0","commit_ref":null,"pull_url":null,"state":"accepted","archived":false,"hash":"bf62a3c4176bd5c8633ff749fc14f6ec083bd454","submitter":{"id":86624,"url":"http://patchwork.ozlabs.org/api/1.1/people/86624/?format=json","name":"Bernd Kuhls","email":"bernd@kuhls.net"},"delegate":{"id":89618,"url":"http://patchwork.ozlabs.org/api/1.1/users/89618/?format=json","username":"juju","first_name":"Julien","last_name":"Olivain","email":"juju@cotds.org"},"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260430044747.27619-1-bernd@kuhls.net/mbox/","series":[{"id":502190,"url":"http://patchwork.ozlabs.org/api/1.1/series/502190/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/list/?series=502190","date":"2026-04-30T04:47:46","name":"[1/1] package/libcurl: security bump to version 8.20.0","version":1,"mbox":"http://patchwork.ozlabs.org/series/502190/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2230806/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2230806/checks/","tags":{},"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=NMw044nc;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::136; helo=smtp3.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g5hVz5vnSz1yHv\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Thu, 30 Apr 2026 14:47:55 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id 2017B61B48;\n\tThu, 30 Apr 2026 04:47:53 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id o5ZRvkgUTU_5; Thu, 30 Apr 2026 04:47:51 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id 59C1161B41;\n\tThu, 30 Apr 2026 04:47:51 +0000 (UTC)","from smtp1.osuosl.org (smtp1.osuosl.org [IPv6:2605:bc80:3010::138])\n by lists1.osuosl.org (Postfix) with ESMTP id 7B4D918E\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:47:50 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp1.osuosl.org (Postfix) with ESMTP id 60C0C849F6\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:47:50 +0000 (UTC)","from smtp1.osuosl.org ([127.0.0.1])\n by localhost (smtp1.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id DJv_apBmT0z3 for <buildroot@buildroot.org>;\n Thu, 30 Apr 2026 04:47:49 +0000 (UTC)","from dd20012.kasserver.com (dd20012.kasserver.com [85.13.140.57])\n by smtp1.osuosl.org (Postfix) with ESMTPS id 5DBFC849F5\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:47:49 +0000 (UTC)","from fli4l.lan.fli4l (p54a1bb47.dip0.t-ipconnect.de [84.161.187.71])\n by dd20012.kasserver.com (Postfix) with ESMTPSA id 64F60A4C1429;\n Thu, 30 Apr 2026 06:47:47 +0200 (CEST)","from bruckner.lan.fli4l ([192.168.1.1]:57304)\n by fli4l.lan.fli4l with esmtp (Exim 4.99.2)\n (envelope-from <bernd@kuhls.net>) id 1wIJJS-00000000884-2ilN;\n Thu, 30 Apr 2026 04:47:47 +0000"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp3.osuosl.org 59C1161B41","OpenDKIM Filter v2.11.0 smtp1.osuosl.org 5DBFC849F5"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1777524471;\n\tbh=OeKbZ4fjtFE5CaeyAD+LcP4nLbWlE8hV+fCwftxjrfw=;\n\th=From:To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:\n\t List-Post:List-Help:List-Subscribe:From;\n\tb=NMw044ncvjgOOUfztcFtNWkOBShA9Nfalk/pPLtppwTlWOLx9XV5XepSaWFweNZVK\n\t LY+jgtE7r328/YhLD1IBXJgK9Rl3IoHihs3mBYlNZ+TrwMgNJ/trldgU3r+xdnMCPI\n\t YPl848G8TD0wx1XYoLtMsyguwE9XW/M7zti2QZA2LQMdaYen0XfhSASzlXW/sp0DRt\n\t UbRsYhrOkLojo47tRE/6SRyy8abaNw7bCvtXqqijPGNh4/qBRfHMJpQ0n4OMyKCWBz\n\t EYhVbAKS5lnI8nRFuKORTScaTEwhpymJezSAb/I0yWS1VoGsA+3b43X4z8N2K19meL\n\t bdYbTt4i82V+Q==","Received-SPF":"Pass (mailfrom) identity=mailfrom; client-ip=85.13.140.57;\n helo=dd20012.kasserver.com; envelope-from=bernd@kuhls.net;\n receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp1.osuosl.org 5DBFC849F5","From":"Bernd Kuhls <bernd@kuhls.net>","To":"buildroot@buildroot.org","Date":"Thu, 30 Apr 2026 06:47:46 +0200","Message-ID":"<20260430044747.27619-1-bernd@kuhls.net>","X-Mailer":"git-send-email 2.47.3","MIME-Version":"1.0","X-Spamd-Bar":"+","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=kuhls.net;\n s=kas202511301023; t=1777524467;\n bh=gFEr7KQlDNasOHxT+UOQOhA4nChq7ZDtrkN0SiaDcYU=;\n h=From:To:Cc:Subject:Date:From;\n b=ODJxqxb3zr9L9xOZ57caqi+097nrapD7GA0QQ6hZ9tAUPPraTj+3ph17wNvBsTAQe\n tzgAtNDmJLVouwh8Wp4dshKnrWPoLSUJ0Iwv2tpUsV+45z+IjcKD5osDOEPnGEs4KK\n M/DfIrTRHN9UWadAOQQen6ztH3TgwDm7fxhZ79K4NwSUDigc3ej+4EoDuisdCVbdgN\n ru28yZ+f2VFpdUdarNmoe3Cvo1+ExgrsLM1qG8MD8M7U6EFwSQ2y1hCJAfX0JG0NRQ\n lgQDtg2mKhU7BtBaWJfs3yxCvX+NI5N5zh17367YNjQdL2/fq9ZiAYJ9JQ4YRoi1bl\n Cn4f39IOf/+6g==","X-Mailman-Original-Authentication-Results":["smtp1.osuosl.org;\n dmarc=pass (p=none dis=none)\n header.from=kuhls.net","smtp1.osuosl.org;\n dkim=pass (2048-bit key) header.d=kuhls.net header.i=@kuhls.net\n header.a=rsa-sha256 header.s=kas202511301023 header.b=ODJxqxb3"],"Subject":"[Buildroot] [PATCH 1/1] package/libcurl: security bump to version\n 8.20.0","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"https://curl.se/ch/8.20.0.html\nhttps://curl.se/docs/security.html\n\nFixes the following CVEs:\nhttps://curl.se/docs/CVE-2026-7168.html\nhttps://curl.se/docs/CVE-2026-7009.html\nhttps://curl.se/docs/CVE-2026-6429.html\nhttps://curl.se/docs/CVE-2026-6276.html\nhttps://curl.se/docs/CVE-2026-6253.html\nhttps://curl.se/docs/CVE-2026-5773.html\nhttps://curl.se/docs/CVE-2026-5545.html\nhttps://curl.se/docs/CVE-2026-4873.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n---\n package/libcurl/libcurl.hash | 6 +++---\n package/libcurl/libcurl.mk   | 2 +-\n 2 files changed, 4 insertions(+), 4 deletions(-)","diff":"diff --git a/package/libcurl/libcurl.hash b/package/libcurl/libcurl.hash\nindex ad34083745..549527b1af 100644\n--- a/package/libcurl/libcurl.hash\n+++ b/package/libcurl/libcurl.hash\n@@ -1,7 +1,7 @@\n-# From https://github.com/curl/curl/releases/tag/curl-8_19_0\n+# From https://github.com/curl/curl/releases/tag/curl-8_20_0\n # after checking pgp signature:\n-# https://curl.se/download/curl-8.19.0.tar.xz.asc\n+# https://curl.se/download/curl-8.20.0.tar.xz.asc\n # signed with key 27EDEAF22F3ABCEB50DB9A125CC908FDB71E12C2\n-sha256  4eb41489790d19e190d7ac7e18e82857cdd68af8f4e66b292ced562d333f11df  curl-8.19.0.tar.xz\n+sha256  63fe2dc148ba0ceae89922ef838f7e5c946272c2e78b7c59fab4b79d3ce2b896  curl-8.20.0.tar.xz\n # Locally computed\n sha256  82f2f4427d6545ee5aaac4f0b80428da6cc8ba41c2cf5da3a03680ec327b9681  COPYING\ndiff --git a/package/libcurl/libcurl.mk b/package/libcurl/libcurl.mk\nindex 3d00a4a33a..94d7ec677c 100644\n--- a/package/libcurl/libcurl.mk\n+++ b/package/libcurl/libcurl.mk\n@@ -4,7 +4,7 @@\n #\n ################################################################################\n \n-LIBCURL_VERSION = 8.19.0\n+LIBCURL_VERSION = 8.20.0\n LIBCURL_SOURCE = curl-$(LIBCURL_VERSION).tar.xz\n LIBCURL_SITE = https://curl.se/download\n LIBCURL_DEPENDENCIES = host-pkgconf \\\n","prefixes":["1/1"]}