Add CVE-2025-13836-http-resp-cont-len.patch (bsc#1254400, CVE-2025-13836)

Prevent reading an HTTP response from a server, if no read amount is
specified, with using Content-Length per default as the length.
This commit is contained in:
2025-12-18 16:07:31 +01:00
parent 39c4b2a029
commit 2544c41d2e
3 changed files with 165 additions and 0 deletions

View File

@@ -1,3 +1,11 @@
-------------------------------------------------------------------
Thu Dec 18 10:33:44 UTC 2025 - Matej Cepl <mcepl@cepl.eu>
- Add CVE-2025-13836-http-resp-cont-len.patch (bsc#1254400,
CVE-2025-13836) to prevent reading an HTTP response from
a server, if no read amount is specified, with using
Content-Length per default as the length.
-------------------------------------------------------------------
Wed Dec 10 03:48:24 UTC 2025 - Steve Kowalik <steven.kowalik@suse.com>