Add CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch

Reject control characters in http cookies (bsc#1257031, CVE-2026-0672).
This commit is contained in:
2026-01-29 14:05:31 +01:00
parent 3a0658eda4
commit 902b37d5bd
3 changed files with 189 additions and 0 deletions

View File

@@ -7,6 +7,9 @@ Thu Jan 29 12:58:15 UTC 2026 - Matej Cepl <mcepl@cepl.eu>
- Add CVE-2025-11468-email-hdr-fold-comment.patch preserving
parens when folding comments in email headers (bsc#1257029,
CVE-2025-11468).
- Add CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch, which
rejects control characters in http cookies (bsc#1257031,
CVE-2026-0672).
-------------------------------------------------------------------
Thu Dec 11 17:37:09 UTC 2025 - Matej Cepl <mcepl@cepl.eu>