new file mode 100644
@@ -0,0 +1,173 @@
+From 0977b4326649b323fa3418bec8e46398f18dcc30 Mon Sep 17 00:00:00 2001
+From: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+Date: Fri, 9 Oct 2026 10:37:17 +0000
+Subject: [PATCH] rabbitmq-c: fix CVE-2026-59986
+
+size_t integer overflow in amqp_decode_bytes bypasses a bounds
+check on 32-bit systems, leading to an out-of-bounds read.
+
+The bounds check in amqp_decode_bytes computed (offset + len) and
+compared it against the buffer length. When offset + len exceeds
+SIZE_MAX the addition wraps around, which an attacker can trigger
+on 32-bit platforms by supplying a large BYTES/UTF8 wire length
+(len is read from the AMQP frame as a uint32_t). The wrap made
+the check pass and produced an amqp_bytes_t with a multi-gigabyte
+length pointing into a small frame buffer, leading to an
+out-of-bounds read (information disclosure or crash) when the
+value was later processed.
+
+Rewrite the check to compare len against the remaining space
+(len <= encoded.len - offset) which cannot overflow because
+offset is always <= encoded.len. Apply the same hardening to
+amqp_encode_bytes for consistency. Add a regression test.
+
+Details:
+https://nvd.nist.gov/vuln/detail/CVE-2026-59986
+
+CVE: CVE-2026-59986
+
+Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1bb1b9b1b7bc69eede6295e95fa9527c731f0798]
+
+Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+---
+ librabbitmq/amqp_private.h | 12 +++++-
+ tests/CMakeLists.txt | 4 ++
+ tests/test_decode_bytes.c | 84 ++++++++++++++++++++++++++++++++++++++
+ 3 files changed, 98 insertions(+), 2 deletions(-)
+ create mode 100644 tests/test_decode_bytes.c
+
+diff --git a/librabbitmq/amqp_private.h b/librabbitmq/amqp_private.h
+index 77a6904..93ee7f6 100644
+--- a/librabbitmq/amqp_private.h
++++ b/librabbitmq/amqp_private.h
+@@ -299,7 +299,10 @@ static inline int amqp_encode_bytes(amqp_bytes_t encoded, size_t *offset,
+ if (input.len == 0) {
+ return 1;
+ }
+- if ((*offset = o + input.len) <= encoded.len) {
++ *offset = o + input.len;
++ /* Compare against remaining space rather than o + input.len to avoid size_t
++ * overflow; o <= encoded.len, so encoded.len - o cannot underflow. */
++ if (o <= encoded.len && input.len <= encoded.len - o) {
+ memcpy(amqp_offset(encoded.bytes, o), input.bytes, input.len);
+ return 1;
+ } else {
+@@ -310,7 +313,12 @@ static inline int amqp_encode_bytes(amqp_bytes_t encoded, size_t *offset,
+ static inline int amqp_decode_bytes(amqp_bytes_t encoded, size_t *offset,
+ amqp_bytes_t *output, size_t len) {
+ size_t o = *offset;
+- if ((*offset = o + len) <= encoded.len) {
++ *offset = o + len;
++ /* Compare against remaining space rather than o + len: with len read from the
++ * wire (uint32_t), o + len can overflow size_t on 32-bit platforms and wrap
++ * past the check, yielding an out-of-bounds amqp_bytes_t. o <= encoded.len,
++ * so encoded.len - o cannot underflow. */
++ if (o <= encoded.len && len <= encoded.len - o) {
+ output->bytes = amqp_offset(encoded.bytes, o);
+ output->len = len;
+ return 1;
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index 8c0aee0..edff2e5 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -41,3 +41,7 @@ add_executable(test_merge_capabilities test_merge_capabilities.c)
+ target_link_libraries(test_merge_capabilities rabbitmq-static)
+ add_test(merge_capabilities test_merge_capabilities)
+
++
++add_executable(test_decode_bytes test_decode_bytes.c)
++target_link_libraries(test_decode_bytes rabbitmq-static)
++add_test(decode_bytes test_decode_bytes)
+diff --git a/tests/test_decode_bytes.c b/tests/test_decode_bytes.c
+new file mode 100644
+index 0000000..17309f6
+--- /dev/null
++++ b/tests/test_decode_bytes.c
+@@ -0,0 +1,84 @@
++// Copyright 2007 - 2021, Alan Antonuk and the rabbitmq-c contributors.
++// SPDX-License-Identifier: mit
++
++#include <stdint.h>
++#include <stdio.h>
++#include <stdlib.h>
++
++#include "amqp_private.h"
++
++/* Regression test for GHSA-jgjf-7fwf-f3c7: a size_t integer overflow in
++ * amqp_decode_bytes bypassed the bounds check on 32-bit systems, producing an
++ * out-of-bounds amqp_bytes_t (information disclosure / crash). The check must
++ * reject any (offset, len) pair that would read past the end of the buffer,
++ * including ones where offset + len wraps around SIZE_MAX. */
++
++static int failures = 0;
++
++static void expect_reject(const char *name, amqp_bytes_t encoded, size_t offset,
++ size_t len) {
++ amqp_bytes_t output;
++ size_t off = offset;
++ output.bytes = NULL;
++ output.len = 0;
++ if (amqp_decode_bytes(encoded, &off, &output, len)) {
++ fprintf(stderr,
++ "FAIL %s: amqp_decode_bytes accepted an out-of-bounds length "
++ "(offset=%zu len=%zu buffer=%zu) -> output.len=%zu\n",
++ name, offset, len, encoded.len, output.len);
++ failures++;
++ }
++}
++
++static void expect_accept(const char *name, amqp_bytes_t encoded, size_t offset,
++ size_t len) {
++ amqp_bytes_t output;
++ size_t off = offset;
++ output.bytes = NULL;
++ output.len = 0;
++ if (!amqp_decode_bytes(encoded, &off, &output, len)) {
++ fprintf(stderr,
++ "FAIL %s: amqp_decode_bytes rejected a valid length "
++ "(offset=%zu len=%zu buffer=%zu)\n",
++ name, offset, len, encoded.len);
++ failures++;
++ return;
++ }
++ if (output.len != len || output.bytes != amqp_offset(encoded.bytes, offset)) {
++ fprintf(stderr, "FAIL %s: amqp_decode_bytes produced wrong output\n", name);
++ failures++;
++ }
++}
++
++int main(void) {
++ char buffer[16];
++ amqp_bytes_t encoded;
++ encoded.bytes = buffer;
++ encoded.len = sizeof(buffer);
++
++ /* Normal, in-bounds decodes still work. */
++ expect_accept("full buffer", encoded, 0, sizeof(buffer));
++ expect_accept("partial at offset", encoded, 4, 8);
++ expect_accept("zero length", encoded, 8, 0);
++
++ /* Plain out-of-bounds (no overflow) is rejected. */
++ expect_reject("len past end", encoded, 0, sizeof(buffer) + 1);
++ expect_reject("offset past end", encoded, sizeof(buffer) + 1, 0);
++
++ /* The core of the advisory: a wire length large enough that offset + len
++ * wraps around SIZE_MAX. On 32-bit platforms a uint32_t length of
++ * 0xFFFFFFF5 with a small offset wraps to a tiny value; on any platform we
++ * can force the wrap with a len near SIZE_MAX. Both must be rejected rather
++ * than producing a multi-gigabyte amqp_bytes_t into a small buffer. */
++ expect_reject("overflow to zero", encoded, 11, (size_t)0 - 11);
++ expect_reject("overflow wraps small", encoded, 16, (size_t)0 - 8);
++ expect_reject("max len", encoded, 1, (size_t)-1);
++ expect_reject("32-bit style len", encoded, 11, (size_t)0xFFFFFFF5u);
++
++ if (failures) {
++ fprintf(stderr, "%d test(s) failed\n", failures);
++ return 1;
++ }
++ printf("all amqp_decode_bytes bounds tests passed\n");
++ return 0;
++}
+--
+2.49.1
+
@@ -6,6 +6,7 @@ LICENSE = "MIT"
SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \
file://CVE-2026-61547.patch \
file://CVE-2026-44235.patch \
+ file://CVE-2026-59986.patch \
"
SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8"
size_t integer overflow in amqp_decode_bytes bypasses a bounds check on 32-bit systems, leading to an out-of-bounds read. The bounds check in amqp_decode_bytes computed (offset + len) and compared it against the buffer length. When offset + len exceeds SIZE_MAX the addition wraps around, which an attacker can trigger on 32-bit platforms by supplying a large BYTES/UTF8 wire length (len is read from the AMQP frame as a uint32_t). The wrap made the check pass and produced an amqp_bytes_t with a multi-gigabyte length pointing into a small frame buffer, leading to an out-of-bounds read (information disclosure or crash) when the value was later processed. Rewrite the check to compare len against the remaining space (len <= encoded.len - offset) which cannot overflow because offset is always <= encoded.len. Apply the same hardening to amqp_encode_bytes for consistency. Add a regression test. Details: https://nvd.nist.gov/vuln/detail/CVE-2026-59986 CVE: CVE-2026-59986 Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1bb1b9b1b7bc69eede6295e95fa9527c731f0798] Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com> --- .../rabbitmq-c/CVE-2026-59986.patch | 173 ++++++++++++++++++ .../rabbitmq-c/rabbitmq-c_0.15.0.bb | 1 + 2 files changed, 174 insertions(+) create mode 100644 meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-59986.patch