@@ -69,5 +69,6 @@ SRC_URI = "\
file://0028-CVE-2025-11494.patch \
file://0029-CVE-2025-11839.patch \
file://0030-CVE-2025-11840.patch \
+ file://CVE-2026-3441_CVE-2026-3442.patch \
"
S = "${WORKDIR}/git"
new file mode 100644
@@ -0,0 +1,50 @@
+From 88a051b765a7684b24250907c2dad9fa8cd4124a Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Sat, 28 Feb 2026 13:16:40 +1030
+Subject: [PATCH] xcofflink buffer overflows
+
+This fixes two fuzzed object file out-of-bounds accesses.
+
+ * xcofflink.c (xcoff_link_add_symbols): Properly bounds check
+ XTY_LD x_scnlen index. Sanity check r_symndx before using it
+ to index sym hashes.
+
+CVE: CVE-2026-3441 CVE-2026-3442
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=c2bf7de1eb77a91d7a3c86d56408bf57de540faf]
+
+(cherry picked from commit c2bf7de1eb77a91d7a3c86d56408bf57de540faf)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ bfd/xcofflink.c | 10 ++++------
+ 1 file changed, 4 insertions(+), 6 deletions(-)
+
+diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c
+index e0165d202a9..88c49755c64 100644
+--- a/bfd/xcofflink.c
++++ b/bfd/xcofflink.c
+@@ -1873,12 +1873,9 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ follow its appropriate XTY_SD symbol. The .set pseudo op can
+ cause the XTY_LD to not follow the XTY_SD symbol. */
+ {
+- bool bad;
+-
+- bad = false;
+- if (aux.x_csect.x_scnlen.u64
+- >= (size_t) (esym - (bfd_byte *) obj_coff_external_syms (abfd)))
+- bad = true;
++ bool bad = (aux.x_csect.x_scnlen.u64
++ >= ((esym - (bfd_byte *) obj_coff_external_syms (abfd))
++ / symesz));
+ if (! bad)
+ {
+ section = xcoff_data (abfd)->csects[aux.x_csect.x_scnlen.u64];
+@@ -2244,6 +2241,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ functions imported from dynamic objects. */
+ if (info->output_bfd->xvec == abfd->xvec
+ && *rel_csect != bfd_und_section_ptr
++ && (unsigned long) rel->r_symndx < obj_raw_syment_count (abfd)
+ && obj_xcoff_sym_hashes (abfd)[rel->r_symndx] != NULL)
+ {
+ struct xcoff_link_hash_entry *h;
+--
+2.44.4