diff options
| author | Livin Sunny <livinsunny519@gmail.com> | 2026-02-27 16:38:02 -0600 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2026-03-16 10:22:06 +0000 |
| commit | 04ae2d93de5370e495b5c3ae2f2d5748f05c7360 (patch) | |
| tree | 551eeda0476f1c2c2bbe6e28e40bedb37df4535d /bitbake | |
| parent | da499d6c217a3151a6affb7d56b156e3b7567683 (diff) | |
| download | poky-04ae2d93de5370e495b5c3ae2f2d5748f05c7360.tar.gz | |
busybox: Fixes CVE-2025-60876
This addresses CVE-2025-60876[1], which allows malicious URLs to inject
HTTP headers. It has been accepted by Debian[2] and is tracked here [4].
The upstream fix has been submitted [3] and is pending merge.
[1] https://nvd.nist.gov/vuln/detail/CVE-2025-60876
[2] https://bugs.debian.org/1120795
[3] https://lists.busybox.net/pipermail/busybox/2025-November/091840.html
[4] https://security-tracker.debian.org/tracker/CVE-2025-60876
Upstream-Status: Submitted [https://lists.busybox.net/pipermail/busybox/2025-November/091840.html]
(From OE-Core rev: 077f258eb2125359ffe3982c58433ee14cb21f09)
Signed-off-by: Livin Sunny <livinsunny519@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f12af98df8f627c6d1836d27be48bac542a4f00e)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'bitbake')
0 files changed, 0 insertions, 0 deletions
