Add CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch

Reject control characters in http cookies (bsc#1257031, CVE-2026-0672).
This commit is contained in:
2026-01-29 14:05:31 +01:00
parent 79a850acd8
commit 350c926ec4
3 changed files with 197 additions and 0 deletions

View File

@@ -7,6 +7,9 @@ Tue Jan 27 16:31:12 UTC 2026 - Matej Cepl <mcepl@cepl.eu>
- Add CVE-2025-11468-email-hdr-fold-comment.patch preserving
parens when folding comments in email headers (bsc#1257029,
CVE-2025-11468).
- Add CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch, which
rejects control characters in http cookies (bsc#1257031,
CVE-2026-0672).
-------------------------------------------------------------------
Thu Dec 11 21:36:09 UTC 2025 - Matej Cepl <mcepl@cepl.eu>