new file mode 100644
@@ -0,0 +1,93 @@
+From db957b8cdc980e4226b6cd6f18061eabfc8f409e Mon Sep 17 00:00:00 2001
+From: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+Date: Fri, 9 Oct 2026 07:02:33 +0000
+Subject: [PATCH] rabbitmq-c: patch CVE-2026-44235
+
+size_t underflow in AMQP frame length computation leads to an
+out-of-bounds read in rabbitmq-c.
+
+A malicious AMQP server can send an AMQP frame whose stated body is
+shorter than the per-frame-type header it claims to carry.
+amqp_handle_input() then computed encoded.len without a lower-bound
+check on target_size. Because encoded.len is a size_t, the
+subtraction wrapped to a value near SIZE_MAX. The bogus length was
+passed to the method/properties and table decoders, whose bounds
+checks could no longer constrain the parser, causing an
+out-of-bounds read and client-side crash during amqp_login.
+
+Validate target_size against the minimum required for each frame
+type and return AMQP_STATUS_BAD_AMQP_DATA when the frame is too
+small, before computing encoded.len.
+
+Details:
+https://nvd.nist.gov/vuln/detail/CVE-2026-44235
+
+CVE: CVE-2026-44235
+
+Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1d3afbb056fee5cc9ea05680bf32288715d0d802]
+
+Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+---
+ .../input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw | Bin 0 -> 113 bytes
+ librabbitmq/amqp_connection.c | 19 ++++++++++++++++++
+ 2 files changed, 19 insertions(+)
+ create mode 100644 fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw
+
+diff --git a/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw b/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw
+new file mode 100644
+index 0000000000000000000000000000000000000000..558e9f5bff6b24ad3104b8a3038ab5b271257dcc
+GIT binary patch
+literal 113
+zcmZQ%0D&+DE+FItvaHO#6&U^l0azR#5qxj8*#?Ay5=J1KHNeNw(+|W*&5I8WKF0)>
+L=Vq{ht2+k({(TL>
+
+literal 0
+HcmV?d00001
+
+diff --git a/librabbitmq/amqp_connection.c b/librabbitmq/amqp_connection.c
+index 56ab8a8..4326ef7 100644
+--- a/librabbitmq/amqp_connection.c
++++ b/librabbitmq/amqp_connection.c
+@@ -320,6 +320,13 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+
+ switch (decoded_frame->frame_type) {
+ case AMQP_FRAME_METHOD:
++ /* A METHOD frame body must contain at least the 4-byte method id.
++ * Reject undersized frames before subtracting from target_size to
++ * avoid an unsigned underflow that would yield a huge encoded.len
++ * and cause out-of-bounds reads in amqp_decode_method(). */
++ if (state->target_size < HEADER_SIZE + 4 + FOOTER_SIZE) {
++ return AMQP_STATUS_BAD_AMQP_DATA;
++ }
+ decoded_frame->payload.method.id =
+ amqp_d32(amqp_offset(raw_frame, HEADER_SIZE));
+ encoded.bytes = amqp_offset(raw_frame, HEADER_SIZE + 4);
+@@ -335,6 +342,15 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+ break;
+
+ case AMQP_FRAME_HEADER:
++ /* A HEADER frame body must contain at least 12 bytes (class_id,
++ * weight, body_size). Reject undersized frames before subtracting
++ * from target_size to avoid an unsigned underflow that would yield
++ * a huge encoded.len and cause out-of-bounds reads in
++ * amqp_decode_properties() / the table decoder
++ * (CVE: GHSA-9mmv-r8g3-qp46). */
++ if (state->target_size < HEADER_SIZE + 12 + FOOTER_SIZE) {
++ return AMQP_STATUS_BAD_AMQP_DATA;
++ }
+ decoded_frame->payload.properties.class_id =
+ amqp_d16(amqp_offset(raw_frame, HEADER_SIZE));
+ /* unused 2-byte weight field goes here */
+@@ -354,6 +370,9 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+ break;
+
+ case AMQP_FRAME_BODY:
++ if (state->target_size < HEADER_SIZE + FOOTER_SIZE) {
++ return AMQP_STATUS_BAD_AMQP_DATA;
++ }
+ decoded_frame->payload.body_fragment.len =
+ state->target_size - HEADER_SIZE - FOOTER_SIZE;
+ decoded_frame->payload.body_fragment.bytes =
+--
+2.35.5
+
@@ -5,6 +5,7 @@ LICENSE = "MIT"
SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \
file://CVE-2026-61547.patch \
+ file://CVE-2026-44235.patch \
"
SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8"
size_t underflow in AMQP frame length computation leads to an out-of-bounds read in rabbitmq-c. A malicious AMQP server can send an AMQP frame whose stated body is shorter than the per-frame-type header it claims to carry. amqp_handle_input() then computed encoded.len without a lower-bound check on target_size. Because encoded.len is a size_t, the subtraction wrapped to a value near SIZE_MAX. The bogus length was passed to the method/properties and table decoders, whose bounds checks could no longer constrain the parser, causing an out-of-bounds read and client-side crash during amqp_login. Validate target_size against the minimum required for each frame type and return AMQP_STATUS_BAD_AMQP_DATA when the frame is too small, before computing encoded.len. Details: https://nvd.nist.gov/vuln/detail/CVE-2026-44235 CVE: CVE-2026-44235 Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1d3afbb056fee5cc9ea05680bf32288715d0d802] Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com> --- .../rabbitmq-c/CVE-2026-44235.patch | 93 +++++++++++++++++++ .../rabbitmq-c/rabbitmq-c_0.15.0.bb | 1 + 2 files changed, 94 insertions(+) create mode 100644 meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch