new file mode 100644
@@ -0,0 +1,92 @@
+From 14c42b415ba0c11640f7d4ee80920452d0287058 Mon Sep 17 00:00:00 2001
+From: Yao Zhang <294772273@qq.com>
+Date: Wed, 5 Aug 2026 14:52:10 +0800
+Subject: [PATCH] Fix CVE-2026-18739: off-by-one error in poptStuffArgs()
+
+The poptStuffArgs function only checks whether (con->os - con->optionStack)
+is equal to POPT_OPTION_DEPTH (10) before incrementing con->os, and does
+not increment the value by 1 to perform boundary pre-checking, as
+handleAlias does.
+
+Add a new test program as a reproducer for this case.
+
+Co-authored-by: Panu Matilainen <pmatilai@redhat.com>
+
+Fixes: CVE-2026-18739
+
+CVE: CVE-2026-18743
+Upstream-Status: Backport [https://github.com/rpm-software-management/popt/commit/14c42b415ba0c11640f7d4ee80920452d0287058]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/popt.c | 2 +-
+ tests/Makefile.am | 5 ++++-
+ tests/testit.sh | 2 ++
+ tests/tstuff.c | 17 +++++++++++++++++
+ 4 files changed, 24 insertions(+), 2 deletions(-)
+ create mode 100644 tests/tstuff.c
+
+diff --git a/src/popt.c b/src/popt.c
+index 9ea3dfe..458aadc 100644
+--- a/src/popt.c
++++ b/src/popt.c
+@@ -1668,7 +1668,7 @@ int poptStuffArgs(poptContext con, const char ** argv)
+ int argc;
+ int rc;
+
+- if ((con->os - con->optionStack) == POPT_OPTION_DEPTH)
++ if ((con->os - con->optionStack + 1) == POPT_OPTION_DEPTH)
+ return POPT_ERROR_OPTSTOODEEP;
+
+ for (argc = 0; argv[argc]; argc++)
+diff --git a/tests/Makefile.am b/tests/Makefile.am
+index c410389..99fbf64 100644
+--- a/tests/Makefile.am
++++ b/tests/Makefile.am
+@@ -11,7 +11,10 @@ EXTRA_DIST = testit.sh \
+
+ AM_CPPFLAGS = -I. -I$(top_srcdir)/src
+
+-noinst_PROGRAMS = test1 test2 tdict test3
++noinst_PROGRAMS = test1 test2 tdict test3 tstuff
++tstuff_SOURCES = tstuff.c
++tstuff_LDFLAGS =
++tstuff_LDADD = $(top_builddir)/src/libpopt.la
+ test1_SOURCES = test1.c
+ test1_LDFLAGS =
+ test1_LDADD = $(top_builddir)/src/libpopt.la
+diff --git a/tests/testit.sh b/tests/testit.sh
+index 4078f51..d26be3a 100755
+--- a/tests/testit.sh
++++ b/tests/testit.sh
+@@ -172,6 +172,8 @@ run test1 "test1 - 61" "" -x=f1
+
+ run test1 "test1 - 62" "arg1: 0 arg2: (none) aInt: 1" --randint=-1
+
++run tstuff "tstuff - 1" "-13"
++
+ if ! [ -e test3-data ]; then
+ # create symlink for running during 'make distcheck'
+ ln -s "${srcdir}/test3-data" test3-data
+diff --git a/tests/tstuff.c b/tests/tstuff.c
+new file mode 100644
+index 0000000..b820c7b
+--- /dev/null
++++ b/tests/tstuff.c
+@@ -0,0 +1,17 @@
++#include <stdio.h>
++#include <popt.h>
++
++int main(int argc, char *argv[])
++{
++ poptContext ctx = poptGetContext(argv[0], argc, (const char **)argv, NULL, 0);
++ int rc = 0;
++ for (int i = 0; i < 100; ++i) {
++ const char *ea[] = { "a", NULL };
++ if ((rc = poptStuffArgs(ctx, ea)))
++ break;
++ }
++ printf("%d\n", rc);
++
++ poptFreeContext(ctx);
++ return rc;
++}
@@ -11,6 +11,7 @@ DEPENDS = "virtual/libiconv"
SRC_URI = "http://ftp.rpm.org/popt/releases/popt-1.x/${BP}.tar.gz \
file://run-ptest \
file://CVE-2026-18743.patch \
+ file://CVE-2026-18739.patch \
"
SRC_URI[sha256sum] = "c25a4838fc8e4c1c8aacb8bd620edb3084a3d63bf8987fdad3ca2758c63240f9"
@@ -25,6 +26,7 @@ do_compile_ptest() {
do_install_ptest() {
install ${B}/tests/.libs/test* ${D}/${PTEST_PATH}
install ${B}/tests/.libs/tdict ${D}/${PTEST_PATH}
+ install ${B}/tests/.libs/tstuff ${D}/${PTEST_PATH}
install ${B}/tests/testit.sh ${D}/${PTEST_PATH}
install ${B}/tests/test-poptrc ${D}/${PTEST_PATH}
}