mirror of
https://git.yoctoproject.org/poky
synced 2026-04-26 09:32:14 +02:00
Although the patch was not merged yet, Debian already took it ([1]). Since busybox CVE handling is slow, follow Debian decision. [1] https://sources.debian.org/src/busybox/1:1.37.0-10.1/debian/patches/wget-disallow-control-chars-in-URLs-CVE-2025-60876.patch (From OE-Core rev: 6274e354680db9521d188309cb32d90996ebb3e5) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr> [YC: fixed weird encoding in URL, added "CVE-" to subject] Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>