diff mbox series

[scarthgap,v2] systemd: patch CVE-2026-4105

Message ID 20261004080143.2383934-1-peter.marko@siemens.com
State New
Headers show
Series [scarthgap,v2] systemd: patch CVE-2026-4105 | expand

Commit Message

Marko, Peter Oct. 4, 2026, 8:01 a.m. UTC
From: Peter Marko <peter.marko@siemens.com>

Pick patch per [1].

machine-varlink.c is not yet present in v255, so drop that hunk.
Same resolution is also done by Debian in [2] for v252.

[1] https://security-tracker.debian.org/tracker/CVE-2026-4105
[2] https://sources.debian.org/src/systemd/252.39-1~deb12u2/debian/patches/CVE-2026-4105.patch

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 .../systemd/systemd/CVE-2026-4105.patch       | 32 +++++++++++++++++++
 meta/recipes-core/systemd/systemd_255.22.bb   |  1 +
 2 files changed, 33 insertions(+)
 create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-4105.patch
diff mbox series

Patch

diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-4105.patch b/meta/recipes-core/systemd/systemd/CVE-2026-4105.patch
new file mode 100644
index 00000000000..5b5c8e621e8
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-4105.patch
@@ -0,0 +1,32 @@ 
+From 6941d92dc299667036cbe264435971cec59ebc76 Mon Sep 17 00:00:00 2001
+From: Luca Boccassi <luca.boccassi@gmail.com>
+Date: Sun, 8 Mar 2026 14:30:52 +0000
+Subject: [PATCH] machined: reject invalid class types when registering
+ machines
+
+Follow-up for fbe550738d03b178bb004a1390e74115e904118a
+
+(cherry picked from commit 6df5f80bd374be1b45c52d740e88f0236da922c7)
+(cherry picked from commit 497d0172416cbb5b70f96b95399d041407c223bd)
+(cherry picked from commit 749e2eaf7086c91598cf7043a31919854b1c2dfe)
+
+CVE: CVE-2026-4105
+Upstream-Status: Backport [https://github.com/systemd/systemd/commit/6941d92dc299667036cbe264435971cec59ebc76]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/machine/machined-dbus.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/machine/machined-dbus.c b/src/machine/machined-dbus.c
+index f4915f67da..3565836dc8 100644
+--- a/src/machine/machined-dbus.c
++++ b/src/machine/machined-dbus.c
+@@ -271,7 +271,7 @@ static int method_create_or_register_machine(Manager *manager, sd_bus_message *m
+                 c = _MACHINE_CLASS_INVALID;
+         else {
+                 c = machine_class_from_string(class);
+-                if (c < 0)
++                if (c < 0 || !IN_SET(c, MACHINE_CONTAINER, MACHINE_VM))
+                         return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid machine class parameter");
+         }
+ 
diff --git a/meta/recipes-core/systemd/systemd_255.22.bb b/meta/recipes-core/systemd/systemd_255.22.bb
index e5a0fd91700..3c5e59542bf 100644
--- a/meta/recipes-core/systemd/systemd_255.22.bb
+++ b/meta/recipes-core/systemd/systemd_255.22.bb
@@ -37,6 +37,7 @@  SRC_URI += " \
            file://CVE-2026-29111-02.patch \
            file://CVE-2026-29111-03.patch \
            file://CVE-2026-29111-04.patch \
+           file://CVE-2026-4105.patch \
            "
 
 # patches needed by musl