Skip to content

Commit a76c83a

Browse files
authored
curl: upgrade 8.5.0 -> 8.8.0 to address CVE-2024-2398 (#9832)
Changelog: https://curl.se/changes.html#8_8_0 Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
1 parent e5afaac commit a76c83a

7 files changed

Lines changed: 24 additions & 21 deletions

File tree

SPECS/curl/curl.signatures.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Signatures": {
3-
"curl-8.5.0.tar.gz": "05fc17ff25b793a437a0906e0484b82172a9f4de02be5ed447e0cab8c3475add"
4-
}
2+
"Signatures": {
3+
"curl-8.8.0.tar.gz": "77c0e1cd35ab5b45b659645a93b46d660224d0024f1185e8a95cdb27ae3d787d"
4+
}
55
}

SPECS/curl/curl.spec

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Summary: An URL retrieval utility and library
22
Name: curl
3-
Version: 8.5.0
4-
Release: 2%{?dist}
3+
Version: 8.8.0
4+
Release: 1%{?dist}
55
License: curl
66
Vendor: Microsoft Corporation
77
Distribution: Mariner
@@ -85,6 +85,9 @@ find %{buildroot} -type f -name "*.la" -delete -print
8585
%{_libdir}/libcurl.so.*
8686

8787
%changelog
88+
* Mon Jul 15 2024 Muhammad Falak <mwani@microsoft.com> - 8.8.0-1
89+
- Bump version to 8.8.0 to address CVE-2024-2398
90+
8891
* Wed Jan 17 2024 Harshit Gupta <guptaharshit@microsoft.com> - 8.5.0-2
8992
- Release bump with no changes to force a rebuild and consume new libssh2 build
9093

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2387,8 +2387,8 @@
23872387
"type": "other",
23882388
"other": {
23892389
"name": "curl",
2390-
"version": "8.5.0",
2391-
"downloadUrl": "https://curl.haxx.se/download/curl-8.5.0.tar.gz"
2390+
"version": "8.8.0",
2391+
"downloadUrl": "https://curl.haxx.se/download/curl-8.8.0.tar.gz"
23922392
}
23932393
}
23942394
},

toolkit/resources/manifests/package/pkggen_core_aarch64.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -190,9 +190,9 @@ libssh2-1.9.0-4.cm2.aarch64.rpm
190190
libssh2-devel-1.9.0-4.cm2.aarch64.rpm
191191
krb5-1.21.3-1.cm2.aarch64.rpm
192192
nghttp2-1.57.0-1.cm2.aarch64.rpm
193-
curl-8.5.0-2.cm2.aarch64.rpm
194-
curl-devel-8.5.0-2.cm2.aarch64.rpm
195-
curl-libs-8.5.0-2.cm2.aarch64.rpm
193+
curl-8.8.0-1.cm2.aarch64.rpm
194+
curl-devel-8.8.0-1.cm2.aarch64.rpm
195+
curl-libs-8.8.0-1.cm2.aarch64.rpm
196196
createrepo_c-0.17.5-1.cm2.aarch64.rpm
197197
libxml2-2.10.4-3.cm2.aarch64.rpm
198198
libxml2-devel-2.10.4-3.cm2.aarch64.rpm

toolkit/resources/manifests/package/pkggen_core_x86_64.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -190,9 +190,9 @@ libssh2-1.9.0-4.cm2.x86_64.rpm
190190
libssh2-devel-1.9.0-4.cm2.x86_64.rpm
191191
krb5-1.21.3-1.cm2.x86_64.rpm
192192
nghttp2-1.57.0-1.cm2.x86_64.rpm
193-
curl-8.5.0-2.cm2.x86_64.rpm
194-
curl-devel-8.5.0-2.cm2.x86_64.rpm
195-
curl-libs-8.5.0-2.cm2.x86_64.rpm
193+
curl-8.8.0-1.cm2.x86_64.rpm
194+
curl-devel-8.8.0-1.cm2.x86_64.rpm
195+
curl-libs-8.8.0-1.cm2.x86_64.rpm
196196
createrepo_c-0.17.5-1.cm2.x86_64.rpm
197197
libxml2-2.10.4-3.cm2.x86_64.rpm
198198
libxml2-devel-2.10.4-3.cm2.x86_64.rpm

toolkit/resources/manifests/package/toolchain_aarch64.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -46,10 +46,10 @@ cracklib-lang-2.9.7-5.cm2.aarch64.rpm
4646
createrepo_c-0.17.5-1.cm2.aarch64.rpm
4747
createrepo_c-debuginfo-0.17.5-1.cm2.aarch64.rpm
4848
createrepo_c-devel-0.17.5-1.cm2.aarch64.rpm
49-
curl-8.5.0-2.cm2.aarch64.rpm
50-
curl-debuginfo-8.5.0-2.cm2.aarch64.rpm
51-
curl-devel-8.5.0-2.cm2.aarch64.rpm
52-
curl-libs-8.5.0-2.cm2.aarch64.rpm
49+
curl-8.8.0-1.cm2.aarch64.rpm
50+
curl-debuginfo-8.8.0-1.cm2.aarch64.rpm
51+
curl-devel-8.8.0-1.cm2.aarch64.rpm
52+
curl-libs-8.8.0-1.cm2.aarch64.rpm
5353
Cython-debuginfo-0.29.33-2.cm2.aarch64.rpm
5454
debugedit-5.0-2.cm2.aarch64.rpm
5555
debugedit-debuginfo-5.0-2.cm2.aarch64.rpm

toolkit/resources/manifests/package/toolchain_x86_64.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,10 +49,10 @@ createrepo_c-debuginfo-0.17.5-1.cm2.x86_64.rpm
4949
createrepo_c-devel-0.17.5-1.cm2.x86_64.rpm
5050
cross-binutils-common-2.37-8.cm2.noarch.rpm
5151
cross-gcc-common-11.2.0-8.cm2.noarch.rpm
52-
curl-8.5.0-2.cm2.x86_64.rpm
53-
curl-debuginfo-8.5.0-2.cm2.x86_64.rpm
54-
curl-devel-8.5.0-2.cm2.x86_64.rpm
55-
curl-libs-8.5.0-2.cm2.x86_64.rpm
52+
curl-8.8.0-1.cm2.x86_64.rpm
53+
curl-debuginfo-8.8.0-1.cm2.x86_64.rpm
54+
curl-devel-8.8.0-1.cm2.x86_64.rpm
55+
curl-libs-8.8.0-1.cm2.x86_64.rpm
5656
Cython-debuginfo-0.29.33-2.cm2.x86_64.rpm
5757
debugedit-5.0-2.cm2.x86_64.rpm
5858
debugedit-debuginfo-5.0-2.cm2.x86_64.rpm

0 commit comments

Comments
 (0)