new file mode 100644
@@ -0,0 +1,217 @@
+From f9c933e258e9ef2f221cca6395f8092a1c4b93dd Mon Sep 17 00:00:00 2001
+From: Changqing Li <changqing.li@windriver.com>
+Date: Thu, 19 Mar 2026 17:10:36 +0800
+Subject: [PATCH 2/4] Fix CVE-2026-1801
+
+This patch merges 3 upstream patches
+
+Chery-pick the first two patches to make the context is the same as the
+third patch that fix CVE-2026-1801
+
+Upstream-Status: Backport
+[https://gitlab.gnome.org/GNOME/libsoup/-/commit/1e32b5e123aa1689505472bdbfcbd897eac41977,
+https://gitlab.gnome.org/GNOME/libsoup/-/commit/8a2e15c88512ae4517d2c2c887d39299725b22da,
+https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9a1c0663ff8ab6e79715db4b35b54f560416ddd]
+CVE: CVE-2026-1801
+
+Signed-off-by: Changqing Li <changqing.li@windriver.com>
+
+Backport the chunked server validation unit test from the upstream
+libsoup3 patch (b9a1c0663ff8ab6e79715db4b35b54f560416ddd).
+
+Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
+---
+ libsoup/soup-body-input-stream.c | 66 +++++++++++++++++++------------
+ tests/server-test.c | 67 ++++++++++++++++++++++++++++++++
+ 2 files changed, 108 insertions(+), 25 deletions(-)
+
+diff --git a/libsoup/soup-body-input-stream.c b/libsoup/soup-body-input-stream.c
+index 6b95884..25d9312 100644
+--- a/libsoup/soup-body-input-stream.c
++++ b/libsoup/soup-body-input-stream.c
+@@ -159,15 +159,18 @@ soup_body_input_stream_read_chunked (SoupBodyInputStream *bistream,
+ again:
+ switch (bistream->priv->chunked_state) {
+ case SOUP_BODY_INPUT_STREAM_STATE_CHUNK_SIZE:
+- nread = soup_filter_input_stream_read_line (
+- fstream, metabuf, sizeof (metabuf), blocking,
+- &got_line, cancellable, error);
+- if (nread <= 0)
++ nread = soup_filter_input_stream_read_until (
++ fstream, metabuf, sizeof (metabuf),
++ "\r\n", 2, blocking, TRUE,
++ &got_line, cancellable, error);
++ if (nread < 0)
+ return nread;
+- if (!got_line) {
+- g_set_error_literal (error, G_IO_ERROR,
+- G_IO_ERROR_PARTIAL_INPUT,
+- _("Connection terminated unexpectedly"));
++ if (nread == 0 || !got_line) {
++ if (error && *error == NULL) {
++ g_set_error_literal (error, G_IO_ERROR,
++ G_IO_ERROR_PARTIAL_INPUT,
++ ("Connection terminated unexpectedly"));
++ }
+ return -1;
+ }
+
+@@ -180,9 +183,9 @@ again:
+
+ case SOUP_BODY_INPUT_STREAM_STATE_CHUNK:
+ nread = soup_body_input_stream_read_raw (
+- bistream, buffer,
+- MIN (count, bistream->priv->read_length),
+- blocking, cancellable, error);
++ bistream, buffer,
++ MIN (count, bistream->priv->read_length),
++ blocking, cancellable, error);
+ if (nread > 0) {
+ bistream->priv->read_length -= nread;
+ if (bistream->priv->read_length == 0)
+@@ -191,16 +194,19 @@ again:
+ return nread;
+
+ case SOUP_BODY_INPUT_STREAM_STATE_CHUNK_END:
+- nread = soup_filter_input_stream_read_line (
+- SOUP_FILTER_INPUT_STREAM (bistream->priv->base_stream),
+- metabuf, sizeof (metabuf), blocking,
+- &got_line, cancellable, error);
+- if (nread <= 0)
++ nread = soup_filter_input_stream_read_until (
++ SOUP_FILTER_INPUT_STREAM (bistream->priv->base_stream),
++ metabuf, sizeof (metabuf),
++ "\r\n", 2, blocking, TRUE,
++ &got_line, cancellable, error);
++ if (nread < 0)
+ return nread;
+- if (!got_line) {
+- g_set_error_literal (error, G_IO_ERROR,
+- G_IO_ERROR_PARTIAL_INPUT,
+- _("Connection terminated unexpectedly"));
++ if (nread == 0 || !got_line) {
++ if (error && *error == NULL) {
++ g_set_error_literal (error, G_IO_ERROR,
++ G_IO_ERROR_PARTIAL_INPUT,
++ _("Connection terminated unexpectedly"));
++ }
+ return -1;
+ }
+
+@@ -208,13 +214,23 @@ again:
+ break;
+
+ case SOUP_BODY_INPUT_STREAM_STATE_TRAILERS:
+- nread = soup_filter_input_stream_read_line (
+- fstream, buffer, count, blocking,
+- &got_line, cancellable, error);
+- if (nread <= 0)
++ nread = soup_filter_input_stream_read_until (
++ fstream, metabuf, sizeof (metabuf),
++ "\r\n", 2, blocking, TRUE,
++ &got_line, cancellable, error);
++ if (nread < 0)
+ return nread;
+
+- if (strncmp (buffer, "\r\n", nread) || strncmp (buffer, "\n", nread)) {
++ if (nread == 0) {
++ if (error && *error == NULL) {
++ g_set_error_literal (error, G_IO_ERROR,
++ G_IO_ERROR_PARTIAL_INPUT,
++ _("Connection terminated unexpectedly"));
++ }
++ return -1;
++ }
++
++ if (nread == 2 && strncmp (metabuf, "\r\n", nread) == 0) {
+ bistream->priv->chunked_state = SOUP_BODY_INPUT_STREAM_STATE_DONE;
+ bistream->priv->eof = TRUE;
+ }
+diff --git a/tests/server-test.c b/tests/server-test.c
+index 8976103e..fbe8bdcc 100644
+--- a/tests/server-test.c
++++ b/tests/server-test.c
+@@ -1373,6 +1373,71 @@ do_steal_connect_test (ServerData *sd, gconstpointer test_data)
+ soup_uri_free (proxy_uri);
+ }
+
++static void
++server_chunked_hundler (SoupServer *server,
++ SoupMessage *msg,
++ const char *path,
++ GHashTable *query,
++ gpointer data)
++{
++ g_assert_true (msg->method == SOUP_METHOD_POST);
++ g_assert_cmpstr (path, ==, "/valid");
++
++ soup_message_set_status (msg, SOUP_STATUS_OK);
++ soup_message_set_response (msg, "text/plain", SOUP_MEMORY_STATIC, "index", 5);
++}
++
++#define CHUNKED_FORMAT_REQUEST "POST /valid HTTP/1.1\r\nHost: 127.0.0.1\r\n%sGET /invalid HTTP/1.1\r\nHost: 127.0.0.1\r\n\r\n"
++
++static void
++do_chunked_test (ServerData *sd, gconstpointer test_data)
++{
++ gint i;
++ struct {
++ const char *description;
++ const char *test;
++ } tests[] = {
++ { "Lone LF", "Transfer-Encoding: chunked\r\n\r\n5;ext\n data\r\n0\r\n\r\n" },
++ };
++
++ sd->server = soup_test_server_new (SOUP_TEST_SERVER_IN_THREAD);
++ sd->base_uri = soup_test_server_get_uri (sd->server, "http", NULL);
++ server_add_handler (sd, NULL, server_chunked_hundler, NULL, NULL);
++
++ for (i = 0; i < G_N_ELEMENTS (tests); i++) {
++ GSocketClient *client;
++ GSocketConnection *conn;
++ GInputStream *input;
++ GOutputStream *output;
++ char *request;
++ char buffer[4096];
++ gssize nread;
++ GError *error = NULL;
++
++ debug_printf (1, " %s\n", tests[i].description);
++
++ client = g_socket_client_new ();
++ conn = g_socket_client_connect_to_host (client, sd->base_uri->host, sd->base_uri->port, NULL, &error);
++ g_assert_no_error (error);
++
++ request = g_strdup_printf (CHUNKED_FORMAT_REQUEST, tests[i].test);
++
++ output = g_io_stream_get_output_stream (G_IO_STREAM (conn));
++ g_output_stream_write_all (output, request, strlen (request), NULL, NULL, NULL);
++ g_output_stream_close (output, NULL, NULL);
++ g_socket_shutdown (g_socket_connection_get_socket (G_SOCKET_CONNECTION (conn)), FALSE, TRUE, &error);
++
++ input = g_io_stream_get_input_stream (G_IO_STREAM (conn));
++ do {
++ nread = g_input_stream_read (input, buffer, sizeof(buffer), NULL, NULL);
++ } while (nread > 0);
++
++ g_free (request);
++ g_object_unref (conn);
++ g_object_unref (client);
++ }
++}
++
+ int
+ main (int argc, char **argv)
+ {
+@@ -1411,6 +1476,8 @@ main (int argc, char **argv)
+ server_setup_nohandler, do_early_multi_test, server_teardown);
+ g_test_add ("/server/steal/CONNECT", ServerData, NULL,
+ server_setup, do_steal_connect_test, server_teardown);
++ g_test_add ("/server/chunked", ServerData, NULL,
++ NULL, do_chunked_test, server_teardown);
+
+ ret = g_test_run ();
+
+--
+2.55.0
+
@@ -42,6 +42,7 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \
file://CVE-2025-2784.patch \
file://CVE-2025-4945.patch \
file://CVE-2026-1539.patch \
+ file://CVE-2026-1801.patch \
"
SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"
Backport fix for CVE-2026-1801 from meta-oe to OE-core. Update CVE patch to restore the chunked server validation unit test from the upstream libsoup3 patch (b9a1c0663ff8ab6e79715db4b35b54f560416ddd). (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d) Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com> --- .../libsoup/libsoup-2.4/CVE-2026-1801.patch | 217 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 1 + 2 files changed, 218 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1801.patch