diff mbox series

[scarthgap,5/5] libsoup-2.4: fix CVE-2026-3633

Message ID 20260929205055.2403390-6-jason.stasiak@garmin.com
State New
Headers show
Series libsoup-2.4: Fix several CVEs | expand

Commit Message

Jason Stasiak Sept. 29, 2026, 8:50 p.m. UTC
Backport fix for CVE-2026-3633 [1] and additional supporting patches
[2][3][4] from the upstream libsoup 3 repo.

[1] https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926
[2] https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf
[3] https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa
[4] https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8

Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
---
 .../libsoup/libsoup-2.4/CVE-2026-3633-1.patch |  51 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-2.patch |  53 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-3.patch |  49 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-4.patch | 113 ++++++++++++++++++
 .../libsoup/libsoup-2.4_2.74.3.bb             |   4 +
 5 files changed, 270 insertions(+)
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch
diff mbox series

Patch

diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
new file mode 100644
index 0000000000..37eeb24409
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
@@ -0,0 +1,51 @@ 
+From 5d61da4e261fab02d07dc74bb3049bbd13535247 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <jason.stasiak@garmin.com>
+Date: Fri, 25 Sep 2026 10:17:05 -0700
+Subject: [PATCH 1/4] CVE-2026-3633: Make SoupMessage a private and final type
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf ]
+
+Backport the introduction of soup_message_set_method() from upstream
+libsoup 3 patch to begin alignment of libsoup 2.4 code with that needed
+to address CVE-2026-3633.
+
+Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
+---
+ libsoup/soup-message-private.h |  2 ++
+ libsoup/soup-message.c         | 10 ++++++++++
+ 2 files changed, 12 insertions(+)
+
+diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h
+index c30361c0..ee73112f 100644
+--- a/libsoup/soup-message-private.h
++++ b/libsoup/soup-message-private.h
+@@ -179,4 +179,6 @@ gboolean    soup_message_has_chunk_allocator (SoupMessage *msg);
+ SoupBuffer *soup_message_allocate_chunk      (SoupMessage *msg,
+ 					      goffset      read_length);
+ 
++void	soup_message_set_method (SoupMessage        *msg,
++		                         const char         *method);
+ #endif /* __SOUP_MESSAGE_PRIVATE_H__ */
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index cc4f22b6..eae11eea 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -2394,3 +2394,13 @@ soup_message_allocate_chunk (SoupMessage *msg,
+ 
+ 	return priv->chunk_allocator (msg, read_length, priv->chunk_allocator_data);
+ }
++
++
++void
++soup_message_set_method (SoupMessage *msg,
++                         const char  *method)
++{
++	g_return_if_fail (method != NULL);
++
++	msg->method = g_intern_string (method);
++}
+\ No newline at end of file
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
new file mode 100644
index 0000000000..c98a26ee6a
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
@@ -0,0 +1,53 @@ 
+From ef7fb85f6bda553c37f50606205396b1a3b363a7 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <jason.stasiak@garmin.com>
+Date: Fri, 25 Sep 2026 10:23:14 -0700
+Subject: [PATCH 2/4] CVE-2026-3633: message: ensure GObject::notify signal is
+ always emitted when properties change
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa ]
+
+Backport the following portions of the libsoup 3 patch to align
+libsoup 2.4 code with that needed to address CVE-2026-3633:
+- Calling of soup_message_set_property() within soup_message_set_method()
+  for a method property change
+- Update of soup_message_set_property() which triggers the GObject::notify
+  signal when the method property changes
+
+Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
+---
+ libsoup/soup-message.c | 11 ++++++++---
+ 1 file changed, 8 insertions(+), 3 deletions(-)
+
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index eae11eea..ff8aaab5 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -205,7 +205,7 @@ soup_message_set_property (GObject *object, guint prop_id,
+ 
+ 	switch (prop_id) {
+ 	case PROP_METHOD:
+-		msg->method = g_intern_string (g_value_get_string (value));
++		soup_message_set_method (msg, g_value_get_string (value));
+ 		break;
+ 	case PROP_URI:
+ 		soup_message_set_uri (msg, g_value_get_boxed (value));
+@@ -2400,7 +2400,12 @@ void
+ soup_message_set_method (SoupMessage *msg,
+                          const char  *method)
+ {
+-	g_return_if_fail (method != NULL);
++	const char *new_method = g_intern_string (method);
+ 
+-	msg->method = g_intern_string (method);
++	if (msg->method == new_method)
++		return;
++
++	msg->method = new_method;
++
++	g_object_notify (G_OBJECT (msg), "method");
+ }
+\ No newline at end of file
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
new file mode 100644
index 0000000000..825d7f0436
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
@@ -0,0 +1,49 @@ 
+From ac0de649ae76b073c8c405f141e6509eb624ee89 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <jason.stasiak@garmin.com>
+Date: Fri, 25 Sep 2026 10:32:36 -0700
+Subject: [PATCH 3/4] CVE-2026-3633: message: make soup_message_set_method
+ public
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8 ]
+
+Backport the portion of the libsoup 3 patch that transitions
+soup_message_set_method() from being a private getter to a public
+getter to align the libsoup 2.4 code with that needed to address
+CVE-2026-3633.
+
+Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
+---
+ libsoup/soup-message-private.h | 2 --
+ libsoup/soup-message.h         | 4 ++++
+ 2 files changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h
+index ee73112f..c30361c0 100644
+--- a/libsoup/soup-message-private.h
++++ b/libsoup/soup-message-private.h
+@@ -179,6 +179,4 @@ gboolean    soup_message_has_chunk_allocator (SoupMessage *msg);
+ SoupBuffer *soup_message_allocate_chunk      (SoupMessage *msg,
+ 					      goffset      read_length);
+ 
+-void	soup_message_set_method (SoupMessage        *msg,
+-		                         const char         *method);
+ #endif /* __SOUP_MESSAGE_PRIVATE_H__ */
+diff --git a/libsoup/soup-message.h b/libsoup/soup-message.h
+index 42379a4b..18066d35 100644
+--- a/libsoup/soup-message.h
++++ b/libsoup/soup-message.h
+@@ -115,6 +115,10 @@ SoupHTTPVersion  soup_message_get_http_version    (SoupMessage       *msg);
+ SOUP_AVAILABLE_IN_2_4
+ gboolean         soup_message_is_keepalive        (SoupMessage       *msg);
+ 
++SOUP_AVAILABLE_IN_2_4
++void             soup_message_set_method          (SoupMessage        *msg,
++						   const char       *method);
++
+ SOUP_AVAILABLE_IN_2_4
+ SoupURI         *soup_message_get_uri             (SoupMessage       *msg);
+ SOUP_AVAILABLE_IN_2_4
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch
new file mode 100644
index 0000000000..471df33ec9
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch
@@ -0,0 +1,113 @@ 
+From bd9d3c8c6af2783fed2745834f6623a2df70f75d Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <jason.stasiak@garmin.com>
+Date: Fri, 25 Sep 2026 10:39:16 -0700
+Subject: [PATCH 4/4] Fix CVE-2026-3633
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926 ]
+
+Backport the upstream libsoup 3 fix for CVE-2026-3633 to
+libsoup 2.4.
+
+Signed-off-by: Jason Stasiak <jason.stasiak@gmail.com>
+---
+ libsoup/soup-message.c | 32 ++++++++++++++++++++++++++++++--
+ tests/misc-test.c      | 22 ++++++++++++++++++++++
+ 2 files changed, 52 insertions(+), 2 deletions(-)
+
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index ff8aaab5..08f22c19 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -2395,17 +2395,45 @@ soup_message_allocate_chunk (SoupMessage *msg,
+ 	return priv->chunk_allocator (msg, read_length, priv->chunk_allocator_data);
+ }
+ 
++/* Validates that a method string conforms to the RFC 9110 'token' specification. */
++static gboolean
++method_is_valid (const char *method)
++{
++	const char *p;
++
++	if (method == NULL || *method == '\0')
++		return FALSE;
++
++	for (p = method; *p != '\0'; p++) {
++	char c = *p;
++
++	if (g_ascii_isalnum (c))
++		continue;
++
++	if (strchr ("!#$%&\'*+-.^_`|~", c) == NULL)
++		return FALSE;
++	}
++
++	return TRUE;
++}
+ 
+ void
+ soup_message_set_method (SoupMessage *msg,
+                          const char  *method)
+ {
+-	const char *new_method = g_intern_string (method);
++	const char *new_method;
++
++	g_return_if_fail (method != NULL);
+ 
++	if (!method_is_valid (method)) {
++		g_warning ("soup_message_set_method: Rejecting invalid method '%s'", method);
++		return;
++	}
++
++	new_method = g_intern_string (method);
+ 	if (msg->method == new_method)
+ 		return;
+ 
+ 	msg->method = new_method;
+-
+ 	g_object_notify (G_OBJECT (msg), "method");
+ }
+\ No newline at end of file
+diff --git a/tests/misc-test.c b/tests/misc-test.c
+index 0f9b0d33..afb7bb30 100644
+--- a/tests/misc-test.c
++++ b/tests/misc-test.c
+@@ -89,6 +89,27 @@ server_callback (SoupServer *server, SoupMessage *msg,
+ 	}
+ }
+ 
++static void
++do_method_injection_test (void)
++{
++	SoupMessage *msg;
++
++	g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING,
++	                       "soup_message_set_method: Rejecting invalid method*");
++	msg = soup_message_new_from_uri ("GET / HTTP/1.1\r\nX-Injected: evil", base_uri);
++	g_assert_null (msg->method);
++	g_test_assert_expected_messages ();
++	g_object_unref (msg);
++
++	g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING,
++	                       "soup_message_set_method: Rejecting invalid method*");
++	msg = soup_message_new_from_uri (SOUP_METHOD_GET, base_uri);
++	soup_message_set_method (msg, "POST /evil HTTP/1.1\r\nHost: attacker\r\n\r\nGET");
++	g_assert_cmpstr (msg->method, ==, SOUP_METHOD_GET);
++	g_test_assert_expected_messages ();
++	g_object_unref (msg);
++}
++
+ /* Host header handling: client must be able to override the default
+  * value, server must be able to recognize different Host values.
+  */
+@@ -1276,6 +1297,7 @@ main (int argc, char **argv)
+ 
+ 	g_test_add_func ("/misc/bigheader", do_host_big_header);
+ 	g_test_add_func ("/misc/host", do_host_test);
++	g_test_add_func ("/misc/method-injection", do_method_injection_test);
+ 	g_test_add_func ("/misc/callback-unref/msg", do_callback_unref_test);
+ 	g_test_add_func ("/misc/callback-unref/req", do_callback_unref_req_test);
+ 	g_test_add_func ("/misc/msg-reuse", do_msg_reuse_test);
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
index c79bced69d..19a2d96b91 100644
--- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
+++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
@@ -45,6 +45,10 @@  SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \
            file://CVE-2026-1801.patch \
            file://CVE-2026-2443.patch \
            file://CVE-2026-5119.patch \
+           file://CVE-2026-3633-1.patch \
+           file://CVE-2026-3633-2.patch \
+           file://CVE-2026-3633-3.patch \
+           file://CVE-2026-3633-4.patch \
 "
 SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"