new file mode 100644
@@ -0,0 +1,36 @@
+From cc006a1d57bebb6ea49db488539a1613014c062f Mon Sep 17 00:00:00 2001
+From: Nick Clifton <nickclifton@github.com>
+Date: Mon, 29 Jun 2026 13:53:14 -0700
+Subject: [PATCH] outobj: fix buffer overflow when too many segments in a group
+
+The number of entries in a group was hard-coded, but not enforced.
+
+CVE: CVE-2026-6067
+Upstream-Status: Backport [https://github.com/netwide-assembler/nasm/commit/8890d723d0aa9ed1a790e2ce1c55eee8dfa0cf94]
+
+Reported-by: <BreakingBad6@github.com>
+Fixes: https://github.com/netwide-assembler/nasm/issues/203
+Signed-off-by: H. Peter Anvin (Intel) <hpa@zytor.com>
+Signed-off-by: Kris Gavvala <kris.gavvala@windriver.com>
+---
+ output/outobj.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/output/outobj.c b/output/outobj.c
+index 685c5933e..9d8bf83c5 100644
+--- a/output/outobj.c
++++ b/output/outobj.c
+@@ -1736,6 +1736,10 @@ obj_directive(enum directive directive, char *value)
+ */
+ continue;
+ }
++ if (grp->nentries >= GROUP_MAX) {
++ nasm_nonfatal("too many segments in a group");
++ return DIRR_ERROR;
++ }
+ for (seg = seghead; seg; seg = seg->next)
+ if (!strcmp(seg->name, p))
+ break;
+--
+2.43.0
+
@@ -10,6 +10,7 @@ DEPENDS = "zlib"
SRC_URI = "http://www.nasm.us/pub/nasm/releasebuilds/${PV}/nasm-${PV}.tar.bz2 \
file://0001-stdlib-Add-strlcat.patch \
file://0002-Add-debug-prefix-map-option.patch \
+ file://CVE-2026-6067.patch \
"
SRC_URI[sha256sum] = "ce7ed93281615379e4a9d4e76503c64a79c1d5ca696dbe148f16cf0b93e239af"
When using obj output format, specifying more than 256 segments in the GROUP directive of the .asm file causes a heap-buffer-overflow. This patch applies the upstream fix given by the commit in [1] to address the issue in [2]. [1] https://github.com/netwide-assembler/nasm/commit/8890d723d0aa9ed1a790e2ce1c55eee8dfa0cf94 [2] https://github.com/netwide-assembler/nasm/issues/203 [3] https://nvd.nist.gov/vuln/detail/cve-2026-6067 Signed-off-by: Kris Gavvala <kris.gavvala@windriver.com> --- .../nasm/nasm/CVE-2026-6067.patch | 36 +++++++++++++++++++ meta/recipes-devtools/nasm/nasm_3.02.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-devtools/nasm/nasm/CVE-2026-6067.patch