From patchwork Tue Jul 21 09:39:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93029 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B1D67C4452B for ; Tue, 21 Jul 2026 09:39:47 +0000 (UTC) Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18883.1784626783067130151 for ; Tue, 21 Jul 2026 02:39:43 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=dBKQpZxn; spf=pass (domain: cisco.com, ip: 173.37.86.73, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=8977; q=dns/txt; s=iport01; t=1784626783; x=1785836383; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=rH5FnoN9iNN4uY25lekZ6sdH3NyCJ44b0vGEBu2zaiA=; b=dBKQpZxnnL/fcUBmA7JL+UqEPCS4TpdMwx+1Wvw0++01zIJc2EtTa6OK ukUQVagGLemvadnRelhgtmrXAyU24cRpwrB92SgdfMGpYSQI9kM/zFSc4 3qGIwa1xvp0y6bV6JdxeVQUOMcjIAtpskG+CY6jLL6T9xXXg45k2uF5gj jax+QIgJ/KbHEiHzYZ5nQuGdzRauOoOMubyTk6tcknQMZD6NyMy6mOoxp Qjbcf1pyqC5FcaM20iS21NPAKUNkznOnmv9dfUUI5bLAoNGMOeb/ow230 U+e5B5vLSocftWsNGRWU9IamuAqPkm4rZW7m+LJc/blQZCaV/6sEru/G1 A==; X-CSE-ConnectionGUID: 3AlT9fIVSj2SK9tOD29GtA== X-CSE-MsgGUID: KvwkCqVXQx+QhSs1kJ9/jA== X-IPAS-Result: A0BFAgB+PV9q/5T/Ja1aHgEBCxIMggULgld0XkNJA5ZHgRadCIF+DwEBAQ9EDQQBAYUFjVkCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECASoLARgBLSwDAQJaIyGDAgGCdAMRvjoaN4F5M4EBgygBgVTbLgELFAEFgTOFP4ggXBgBhHwnGxuBcoEVgnN2gQWBXAKBN4ZuBIIiehKBWh4yhD2LHkiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDBsHBYEdgS6BAoRuIx8DOX+BL3VKdy1pARIXgSaCFIE6Ak4DCxgNSBEsNxQZBD5uB41QI4FEXBkHexMBExgES0kIWAwoJJMbkBaCIaEPCiiDdYwhlToaM6psC5h9jgqWDkKEaYFoPIFZcBWDIglKGQ+OKg4Lg2DOWicyAgkDLwEBBwIHDgMLgWiQAAImB4FPAQE IronPort-Data: A9a23:XotwvaPdHIr8s+fvrR31lsFynXyQoLVcMsEvi/4bfWQNrUp3hjFSn GYfXm2BP66KYWHyeYpzO9mw8BwEsZfXztJmS3M5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf6gWcsawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj665HCH1nM6wmweQtOkIf6 ds0cmEicjnW0opawJrjIgVtrt4oIM+uOMYUvWttiGiAS/0nWpvEBa7N4Le03h9p2ZsIRqmYP ZdEL2MzPHwsYDUXUrsTIJ49keOhh2j2WzZZs1mS46Ew5gA/ySQtgei8a4qPIoziqcN9vViHp UnfwVTAElIjNOeEkDmnozWur7qa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+rfSnh0qWX9NEN 1dS/TIjq6U3/kGnQtTxGRqirxa5UgU0QdFcFag+rQqK0KeRul/fDWkfRTkHY9sj3CMreQEXO payt4uBLVRSXHe9EBpxKp/8QeuOBBUo IronPort-HdrOrdr: A9a23:GCU3LKHVkqugViZXpLqExMeALOsnbusQ8zAXPo5KJiC9Ffbo8v xG88576faZslsssRIb6LK90de7IU80nKQdieJ6AV7IZmfbUQWTQL2KxLGSpwEIYxeOldJ15O NHb7V0DsH2ABxRiMb35xT9LvMbqeP3l5xBQYzlvg5QpcYAUdAH0ztE X-Talos-CUID: 9a23:dZUp9Go46LrFVrorP0l3wlfmUZsMdkGMwlbuGE3iMkU4VJq5Ew6/5Ioxxg== X-Talos-MUID: 9a23:A4S3EwtDOTQE4zsKkM2npy99N+xx3ZSXGAM0ka4d4sqmZGtyEmLI X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,176,1779148800"; d="scan'208";a="498938208" Received: from rcdn-l-core-11.cisco.com ([173.37.255.148]) by rcdn-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 09:39:42 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-11.cisco.com (Postfix) with ESMTPS id EEB841800016D; Tue, 21 Jul 2026 09:39:41 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id 98421CAEF78; Tue, 21 Jul 2026 02:39:41 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com, Darsh Kelaiya Subject: [meta-OE][scarthgap][PATCH 1/4] jq: Fix CVE-2026-43895 Date: Tue, 21 Jul 2026 02:39:35 -0700 Message-Id: <20260721093938.3983571-1-dkelaiya@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: rcdn-l-core-11.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 09:39:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128348 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/jqlang/jq/commit/9d223f153c3632a207fa071caaa6292da33ae361 [2] https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr Signed-off-by: Darsh Kelaiya --- .../jq/jq/CVE-2026-43895.patch | 206 ++++++++++++++++++ meta-oe/recipes-devtools/jq/jq_1.7.1.bb | 1 + 2 files changed, 207 insertions(+) create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-43895.patch diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2026-43895.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2026-43895.patch new file mode 100644 index 0000000000..efde45c710 --- /dev/null +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2026-43895.patch @@ -0,0 +1,206 @@ +From 5192a59c2c6ca6ab0667cbee608db29c0710f346 Mon Sep 17 00:00:00 2001 +From: itchyny +Date: Sat, 9 May 2026 17:08:43 +0900 +Subject: [PATCH 1/2] Reject embedded NUL bytes in module import paths + +jq accepts embedded NUL bytes at the language level but resolves +module import paths through NUL-terminated C strings, so the path +validated by policy or audit code could differ from the on-disk +path jq actually opens. Pass jv through gen_import so the AST +preserves the original bytes, and reject embedded NULs in +validate_relpath. + +Fixes CVE-2026-43895. + +CVE: CVE-2026-43895 +Upstream-Status: Backport [https://github.com/jqlang/jq/commit/9d223f153c3632a207fa071caaa6292da33ae361] + +Backport Changes: +- Kept jq 1.7.1 HOME lookup in linker.c. + The newer get_home() flow is absent from the target. + Only the jv-based gen_import() call was required. +- Limited parser.c to three import/include action changes. + The newer grammar caused unrelated generated-parser churn. + Keeping target numbering avoids unrelated generated changes. + +(cherry picked from commit 9d223f153c3632a207fa071caaa6292da33ae361) +Signed-off-by: Darsh Kelaiya +--- + src/compile.c | 12 ++++++++---- + src/compile.h | 2 +- + src/linker.c | 6 +++++- + src/parser.c | 16 +++------------- + src/parser.y | 16 +++------------- + tests/shtest | 17 +++++++++++++++++ + 6 files changed, 37 insertions(+), 32 deletions(-) + +diff --git a/src/compile.c b/src/compile.c +index e5e65f2..27b2cfd 100644 +--- a/src/compile.c ++++ b/src/compile.c +@@ -526,13 +526,17 @@ jv block_module_meta(block b) { + return jv_null(); + } + +-block gen_import(const char* name, const char* as, int is_data) { ++block gen_import(jv name, jv as, int is_data) { ++ assert(jv_get_kind(name) == JV_KIND_STRING); ++ assert(!jv_is_valid(as) || jv_get_kind(as) == JV_KIND_STRING); + inst* i = inst_new(DEPS); + jv meta = jv_object(); +- if (as != NULL) +- meta = jv_object_set(meta, jv_string("as"), jv_string(as)); ++ if (jv_is_valid(as)) ++ meta = jv_object_set(meta, jv_string("as"), as); ++ else ++ jv_free(as); + meta = jv_object_set(meta, jv_string("is_data"), is_data ? jv_true() : jv_false()); +- meta = jv_object_set(meta, jv_string("relpath"), jv_string(name)); ++ meta = jv_object_set(meta, jv_string("relpath"), name); + i->imm.constant = meta; + return inst_block(i); + } +diff --git a/src/compile.h b/src/compile.h +index c1512e6..bac65ef 100644 +--- a/src/compile.h ++++ b/src/compile.h +@@ -33,7 +33,7 @@ block gen_op_pushk_under(jv constant); + + block gen_module(block metadata); + jv block_module_meta(block b); +-block gen_import(const char* name, const char *as, int is_data); ++block gen_import(jv name, jv as, int is_data); + block gen_import_meta(block import, block metadata); + block gen_function(const char* name, block formals, block body); + block gen_param_regular(const char* name); +diff --git a/src/linker.c b/src/linker.c +index e7d1024..4b15008 100644 +--- a/src/linker.c ++++ b/src/linker.c +@@ -93,6 +93,10 @@ static jv build_lib_search_chain(jq_state *jq, jv search_path, jv jq_origin, jv + // in between). + static jv validate_relpath(jv name) { + const char *s = jv_string_value(name); ++ if (strlen(s) != (size_t)jv_string_length_bytes(jv_copy(name))) { ++ jv_free(name); ++ return jv_invalid_with_msg(jv_string("Module path contains a NUL byte")); ++ } + if (strchr(s, '\\')) { + jv res = jv_invalid_with_msg(jv_string_fmt("Modules must be named by relative paths using '/', not '\\' (%s)", s)); + jv_free(name); +@@ -423,7 +427,7 @@ int load_program(jq_state *jq, struct locfile* src, block *out_block) { + char* home = getenv("HOME"); + if (home) { // silently ignore no $HOME + /* Import ~/.jq as a library named "" found in $HOME */ +- block import = gen_import_meta(gen_import("", NULL, 0), ++ block import = gen_import_meta(gen_import(jv_string(""), jv_invalid(), 0), + gen_const(JV_OBJECT( + jv_string("optional"), jv_true(), + jv_string("search"), jv_string(home)))); +diff --git a/src/parser.c b/src/parser.c +index 0599db7..c50f2fb 100644 +--- a/src/parser.c ++++ b/src/parser.c +@@ -3081,13 +3081,8 @@ yyreduce: + case 50: /* ImportWhat: "import" ImportFrom "as" BINDING */ + #line 506 "src/parser.y" + { +- jv v = block_const((yyvsp[-2].blk)); +- // XXX Make gen_import take only blocks and the int is_data so we +- // don't have to free so much stuff here +- (yyval.blk) = gen_import(jv_string_value(v), jv_string_value((yyvsp[0].literal)), 1); ++ (yyval.blk) = gen_import(block_const((yyvsp[-2].blk)), (yyvsp[0].literal), 1); + block_free((yyvsp[-2].blk)); +- jv_free((yyvsp[0].literal)); +- jv_free(v); + } + #line 3093 "src/parser.c" + break; +@@ -3095,11 +3090,8 @@ yyreduce: + case 51: /* ImportWhat: "import" ImportFrom "as" IDENT */ + #line 515 "src/parser.y" + { +- jv v = block_const((yyvsp[-2].blk)); +- (yyval.blk) = gen_import(jv_string_value(v), jv_string_value((yyvsp[0].literal)), 0); ++ (yyval.blk) = gen_import(block_const((yyvsp[-2].blk)), (yyvsp[0].literal), 0); + block_free((yyvsp[-2].blk)); +- jv_free((yyvsp[0].literal)); +- jv_free(v); + } + #line 3105 "src/parser.c" + break; +@@ -3107,10 +3099,8 @@ yyreduce: + case 52: /* ImportWhat: "include" ImportFrom */ + #line 522 "src/parser.y" + { +- jv v = block_const((yyvsp[0].blk)); +- (yyval.blk) = gen_import(jv_string_value(v), NULL, 0); ++ (yyval.blk) = gen_import(block_const((yyvsp[0].blk)), jv_invalid(), 0); + block_free((yyvsp[0].blk)); +- jv_free(v); + } + #line 3116 "src/parser.c" + break; +diff --git a/src/parser.y b/src/parser.y +index 3d24689..2901cab 100644 +--- a/src/parser.y ++++ b/src/parser.y +@@ -504,26 +504,16 @@ ImportWhat Exp ';' { + + ImportWhat: + "import" ImportFrom "as" BINDING { +- jv v = block_const($2); +- // XXX Make gen_import take only blocks and the int is_data so we +- // don't have to free so much stuff here +- $$ = gen_import(jv_string_value(v), jv_string_value($4), 1); ++ $$ = gen_import(block_const($2), $4, 1); + block_free($2); +- jv_free($4); +- jv_free(v); + } | + "import" ImportFrom "as" IDENT { +- jv v = block_const($2); +- $$ = gen_import(jv_string_value(v), jv_string_value($4), 0); ++ $$ = gen_import(block_const($2), $4, 0); + block_free($2); +- jv_free($4); +- jv_free(v); + } | + "include" ImportFrom { +- jv v = block_const($2); +- $$ = gen_import(jv_string_value(v), NULL, 0); ++ $$ = gen_import(block_const($2), jv_invalid(), 0); + block_free($2); +- jv_free(v); + } + + ImportFrom: +diff --git a/tests/shtest b/tests/shtest +index 505d45d..4a5978c 100755 +--- a/tests/shtest ++++ b/tests/shtest +@@ -622,4 +622,21 @@ if echo '42' | $JQ -f "$d/nul_prog.jq" >/dev/null 2>/dev/null; then + exit 1 + fi + ++# CVE-2026-43895: No NUL bytes in module/data import paths ++printf 'import "a\\u0000b" as $x; .' > "$d/nul_import.jq" ++if $JQ -nf "$d/nul_import.jq" >/dev/null 2>/dev/null; then ++ printf 'Error expected for import path with NUL bytes\n' 1>&2 ++ exit 1 ++fi ++printf 'include "a\\u0000b"; .' > "$d/nul_include.jq" ++if $JQ -nf "$d/nul_include.jq" >/dev/null 2>/dev/null; then ++ printf 'Error expected for include path with NUL bytes\n' 1>&2 ++ exit 1 ++fi ++printf '"a\\u0000b" | modulemeta' > "$d/nul_modulemeta.jq" ++if $JQ -nf "$d/nul_modulemeta.jq" >/dev/null 2>/dev/null; then ++ printf 'Error expected for modulemeta with NUL bytes\n' 1>&2 ++ exit 1 ++fi ++ + exit 0 +-- +2.44.4 + diff --git a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb index 2fc47ef92c..2f08f583cc 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb @@ -25,6 +25,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${BPN}-${PV}/${BPN}-${PV}.tar.gz \ file://CVE-2026-41257.patch \ file://CVE-2026-43894.patch \ file://CVE-2026-43896.patch \ + file://CVE-2026-43895.patch \ " SRC_URI[sha256sum] = "478c9ca129fd2e3443fe27314b455e211e0d8c60bc8ff7df703873deeee580c2" From patchwork Tue Jul 21 09:39:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93027 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5166AC4451C for ; Tue, 21 Jul 2026 09:39:47 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18898.1784626783101135656 for ; Tue, 21 Jul 2026 02:39:43 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=azTNCJbs; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=15631; q=dns/txt; s=iport01; t=1784626783; x=1785836383; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Gmu9TpR3zusxB0RL4hYrsyLhzHBWQIGc8rDrRAkzM3I=; b=azTNCJbsElc5aYZrEvwL+CNQuPdaBAHFAQ2pO5S9t8v4rbKeV6n/rrym ta21jpXIcSurHcajajCIGo3tPmpqCxpNCWZKPPfKViz/Fn/2QBvoTt3j9 ZYekiQ7Ei+/NbN//NdmLBstvYqbWQg4+4TZG8scXEuL8hi0cOtUsTyNxe TjvhHeMd9tYjhtrrKJxQJXbsJFkU6bTYAFmU8G4Kcg4CjKvx6lc6vB/ht iTUFiMLub9VwoU4Ps8HsQMSniGeTw2eJc9hLA7h86Q7QcEC8c9+EnKr8R 7V3wWjSsigG/F8+LE7mSA6D9NrfPASpmGyUCa4pXpDxfAevefORP9yJbp A==; X-CSE-ConnectionGUID: wrluRPMVTiqNaCUXZnTEUw== X-CSE-MsgGUID: aywpx5ZeQLacZ3CLnUfM5Q== X-IPAS-Result: A0BIAgB+PV9q/43/Ja1aglmCV3ReQ0kDlkcDgROdCIF+DwEBAQ9EDQQBAYUFAo1XAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDJwsBGAEtEBwDAQIvKyMIGYMCAYJ0AxG+Oho3gXkzgQGDKAGBVNsuAQsUAQWBM4U/iCBcGAGEfCcbG4FygRWCc3aBBYFcAoglBIIiehKBWh6Eb4seSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EMGwcFgR2BLoEChG4jHwM5f4EvdUp3LWkBEheBJoIUgToCTgMLGA1IESw3FBkEPm4HjVAjgiAZBwEwXQEKCRiBBRVqKByTG5I/oQ8KKIN1jCGVOhozqmwLmH2OCokPjUGEaYFoPIFZcBWDIglKGQ+OLQsLg2DOWicyAgkDLwEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:mJ6swqk849GJLPw77RnUwKXo5gzRJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIbCmmGbv3bNzb2Ktx/OY6/9EIF7ZOEydBmTlY5pSkyFVtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4E/raf658SUUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZC31GONgWYubDpLsfvb8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FZIC/vtNOURwy f0BDjkmUyCxgd6b/a3uH4GAhux7RCXqFJkUtnclyXTSCuwrBMifBa7L/tRfmjw3g6iiH96HO JFfMmUpNkmdJUQTYz/7C7pm9AusrnX8fjlRqUOcjaE2+GPUigd21dABNfKII4bbHJ0KxxbwS mTu9nXmGgFHBtGm7TOOwCmHounykwamYddHfFG/3rsw6LGJ/UQUEBAQWF6xrPW1h0L7V99BJ kg8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS8gqBzO/Qpg2eHGVBFmIHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289Fte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:HrEvQ6+JfNMWG63a79Vuk+AAI+orL9Y04lQ7vn2ZhyY7TiX+rb HIoB11737JYVoqNU3I3OrwWpVoIkmskaKdn7NwAV7KZmCP0wGVxcNZnO7fKlbbdREWmNQw6U 5ISdkZNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAY0++8YTzraXGfg2J9dOIEKK Y= X-Talos-CUID: 9a23:gu13yGxPPd3QMZhQnJV5BgULAMQ4SEX48kvROmmxIltZerupZGKPrfY= X-Talos-MUID: 9a23:C3mokw2+F8odjIDmJUjm+oEQBjUj6rWxEFBQo5g/n8CPB3dbHzGgghHqe9py X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,176,1779148800"; d="scan'208";a="512910718" Received: from rcdn-l-core-04.cisco.com ([173.37.255.141]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 09:39:42 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-04.cisco.com (Postfix) with ESMTPS id F087D1800018F; Tue, 21 Jul 2026 09:39:41 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id 9A922CAEF79; Tue, 21 Jul 2026 02:39:41 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com, Darsh Kelaiya Subject: [meta-OE][scarthgap][PATCH 2/4] jq: Fix CVE-2026-47770 Date: Tue, 21 Jul 2026 02:39:36 -0700 Message-Id: <20260721093938.3983571-2-dkelaiya@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721093938.3983571-1-dkelaiya@cisco.com> References: <20260721093938.3983571-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: rcdn-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 09:39:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128346 From: Darsh Kelaiya This patch applies the upstream fix for CVE-2026-47770 as referenced in [2], using the upstream commit identified in [1]. [1] https://github.com/jqlang/jq/commit/7122866869960b55cea3646bc91334ef55787831 [2] https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp Signed-off-by: Darsh Kelaiya --- .../jq/jq/CVE-2026-47770.patch | 449 ++++++++++++++++++ meta-oe/recipes-devtools/jq/jq_1.7.1.bb | 1 + 2 files changed, 450 insertions(+) create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-47770.patch diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2026-47770.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2026-47770.patch new file mode 100644 index 0000000000..7b6fc72a99 --- /dev/null +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2026-47770.patch @@ -0,0 +1,449 @@ +From 0f31d6f32040ed421d8ccb694aaf767865972e88 Mon Sep 17 00:00:00 2001 +From: Yu-Fu Fu +Date: Fri, 22 May 2026 04:07:16 -0700 +Subject: [PATCH 2/2] Guard deep structural equality and comparison recursion + (#3539) + +jv_equal and jv_cmp overflows the C stack on deeply nested +input. Cap recursion at 10000 with -1 / INT_MIN sentinels; +operators that compose user expressions surface this as +"Equality check too deep" / "Comparison too deep". + +Fixes CVE-2026-47770. + +CVE: CVE-2026-47770 +Upstream-Status: Backport [https://github.com/jqlang/jq/commit/7122866869960b55cea3646bc91334ef55787831] + +Backport Changes: +- Omitted the newer f_bsearch C helper. + jq 1.7.1 neither contains nor registers this helper. + Adding it would introduce unrelated newer functionality. +- Omitted the newer jv_unique C helper. + jq 1.7.1 has no matching helper or declaration. + Adding the entire function was unnecessary for the target. +- Preserved jv_array_indexes iterator ownership. + jq 1.7.1 frees belem after each comparison. + Passing a copy prevents a double-free on the normal path. +- Preserved the jq 1.7.1 delpaths_sorted loop. + The target uses a while loop instead of the newer do-while form. + Only the equality sentinel handling was needed. +- Kept existing empty-array handling in sort_items(). + The newer empty-array block was context, not part of the fix. + Only too_deep initialization was required. + +(cherry picked from commit 7122866869960b55cea3646bc91334ef55787831) +Signed-off-by: Darsh Kelaiya +--- + src/builtin.c | 30 +++++++++++++++-- + src/jv.c | 47 +++++++++++++++++++++------ + src/jv_aux.c | 90 +++++++++++++++++++++++++++++++++++++++++++-------- + tests/jq.test | 22 +++++++++++++ + 4 files changed, 163 insertions(+), 26 deletions(-) + +diff --git a/src/builtin.c b/src/builtin.c +index 378be02..08a8a98 100644 +--- a/src/builtin.c ++++ b/src/builtin.c +@@ -336,7 +336,15 @@ jv binop_minus(jv a, jv b) { + jv_array_foreach(a, i, x) { + int include = 1; + jv_array_foreach(b, j, y) { +- if (jv_equal(jv_copy(x), y)) { ++ int equal = jv_equal(jv_copy(x), y); ++ if (equal < 0) { ++ jv_free(out); ++ jv_free(x); ++ jv_free(a); ++ jv_free(b); ++ return jv_invalid_with_msg(jv_string("Equality check too deep")); ++ } ++ if (equal) { + include = 0; + break; + } +@@ -431,11 +439,17 @@ jv binop_mod(jv a, jv b) { + #undef dtoi + + jv binop_equal(jv a, jv b) { +- return jv_bool(jv_equal(a, b)); ++ int r = jv_equal(a, b); ++ if (r < 0) ++ return jv_invalid_with_msg(jv_string("Equality check too deep")); ++ return jv_bool(r); + } + + jv binop_notequal(jv a, jv b) { +- return jv_bool(!jv_equal(a, b)); ++ int r = jv_equal(a, b); ++ if (r < 0) ++ return jv_invalid_with_msg(jv_string("Equality check too deep")); ++ return jv_bool(!r); + } + + enum cmp_op { +@@ -447,6 +461,8 @@ enum cmp_op { + + static jv order_cmp(jv a, jv b, enum cmp_op op) { + int r = jv_cmp(a, b); ++ if (r == INT_MIN) ++ return jv_invalid_with_msg(jv_string("Comparison too deep")); + return jv_bool((op == CMP_OP_LESS && r < 0) || + (op == CMP_OP_LESSEQ && r <= 0) || + (op == CMP_OP_GREATEREQ && r >= 0) || +@@ -1065,6 +1081,14 @@ static jv minmax_by(jv values, jv keys, int is_min) { + for (int i=1; istring); + if (!slot2) return 0; + // FIXME: do less refcounting here +- if (!jv_equal(jv_copy(slot->value), jv_copy(*slot2))) return 0; ++ int r = jvp_equal(jv_copy(slot->value), jv_copy(*slot2), depth); ++ if (r <= 0) return r; + len1++; + } + return len1 == len2; +@@ -2007,7 +2020,16 @@ int jv_get_refcnt(jv j) { + * Higher-level operations + */ + +-int jv_equal(jv a, jv b) { ++#ifndef MAX_EQUAL_DEPTH ++#define MAX_EQUAL_DEPTH (10000) ++#endif ++ ++static int jvp_equal(jv a, jv b, int depth) { ++ if (depth > MAX_EQUAL_DEPTH) { ++ jv_free(a); ++ jv_free(b); ++ return -1; ++ } + int r; + if (jv_get_kind(a) != jv_get_kind(b)) { + r = 0; +@@ -2023,13 +2045,13 @@ int jv_equal(jv a, jv b) { + r = jvp_number_equal(a, b); + break; + case JV_KIND_ARRAY: +- r = jvp_array_equal(a, b); ++ r = jvp_array_equal(a, b, depth + 1); + break; + case JV_KIND_STRING: + r = jvp_string_equal(a, b); + break; + case JV_KIND_OBJECT: +- r = jvp_object_equal(a, b); ++ r = jvp_object_equal(a, b, depth + 1); + break; + default: + r = 1; +@@ -2041,6 +2063,11 @@ int jv_equal(jv a, jv b) { + return r; + } + ++// Returns 1 if equal, 0 if not equal, or -1 if the comparison is too deep ++int jv_equal(jv a, jv b) { ++ return jvp_equal(a, b, 0); ++} ++ + int jv_identical(jv a, jv b) { + int r; + if (a.kind_flags != b.kind_flags +diff --git a/src/jv_aux.c b/src/jv_aux.c +index 0855053..75497c5 100644 +--- a/src/jv_aux.c ++++ b/src/jv_aux.c +@@ -15,6 +15,24 @@ static double jv_number_get_value_and_consume(jv number) { + return value; + } + ++#ifndef MAX_CMP_DEPTH ++#define MAX_CMP_DEPTH (10000) ++#endif ++ ++struct sort_cmp_state { ++ int too_deep; ++}; ++ ++#ifdef _MSC_VER ++static __declspec(thread) struct sort_cmp_state sort_cmp_state; ++#else ++#ifdef HAVE___THREAD ++static __thread struct sort_cmp_state sort_cmp_state; ++#else ++static struct sort_cmp_state sort_cmp_state; ++#endif ++#endif ++ + static jv parse_slice(jv j, jv slice, int* pstart, int* pend) { + // Array slices + jv start_jv = jv_object_get(jv_copy(slice), jv_string("start")); +@@ -471,7 +489,7 @@ static jv delpaths_sorted(jv object, jv paths, int start) { + int delkey = jv_array_length(jv_array_get(jv_copy(paths), i)) == start + 1; + jv key = jv_array_get(jv_array_get(jv_copy(paths), i), start); + while (j < jv_array_length(jv_copy(paths)) && +- jv_equal(jv_copy(key), jv_array_get(jv_array_get(jv_copy(paths), j), start))) ++ jv_equal(jv_copy(key), jv_array_get(jv_array_get(jv_copy(paths), j), start)) == 1) + j++; + // if i <= entry < j, then entry starts with key + if (delkey) { +@@ -602,7 +620,13 @@ jv jv_keys(jv x) { + } + } + +-int jv_cmp(jv a, jv b) { ++static int jvp_cmp(jv a, jv b, int depth) { ++ if (depth > MAX_CMP_DEPTH) { ++ jv_free(a); ++ jv_free(b); ++ return INT_MIN; ++ } ++ + if (jv_get_kind(a) != jv_get_kind(b)) { + int r = (int)jv_get_kind(a) - (int)jv_get_kind(b); + jv_free(a); +@@ -617,14 +641,13 @@ int jv_cmp(jv a, jv b) { + case JV_KIND_FALSE: + case JV_KIND_TRUE: + // there's only one of each of these values +- r = 0; + break; + + case JV_KIND_NUMBER: { + if (jvp_number_is_nan(a)) { +- r = jv_cmp(jv_null(), jv_copy(b)); ++ r = jvp_cmp(jv_null(), jv_copy(b), depth); + } else if (jvp_number_is_nan(b)) { +- r = jv_cmp(jv_copy(a), jv_null()); ++ r = jvp_cmp(jv_copy(a), jv_null(), depth); + } else { + r = jvp_number_cmp(a, b); + } +@@ -648,7 +671,9 @@ int jv_cmp(jv a, jv b) { + } + jv xa = jv_array_get(jv_copy(a), i); + jv xb = jv_array_get(jv_copy(b), i); +- r = jv_cmp(xa, xb); ++ r = jvp_cmp(xa, xb, depth + 1); ++ if (r == INT_MIN) ++ break; + i++; + } + break; +@@ -657,13 +682,14 @@ int jv_cmp(jv a, jv b) { + case JV_KIND_OBJECT: { + jv keys_a = jv_keys(jv_copy(a)); + jv keys_b = jv_keys(jv_copy(b)); +- r = jv_cmp(jv_copy(keys_a), keys_b); ++ r = jvp_cmp(jv_copy(keys_a), keys_b, depth + 1); + if (r == 0) { + jv_array_foreach(keys_a, i, key) { + jv xa = jv_object_get(jv_copy(a), jv_copy(key)); + jv xb = jv_object_get(jv_copy(b), key); +- r = jv_cmp(xa, xb); +- if (r) break; ++ r = jvp_cmp(xa, xb, depth + 1); ++ if (r != 0) ++ break; + } + } + jv_free(keys_a); +@@ -676,6 +702,11 @@ int jv_cmp(jv a, jv b) { + return r; + } + ++// Returns <0, 0, >0 if a is less than, equal to, or greater than b, or ++// INT_MIN if the comparison is too deep ++int jv_cmp(jv a, jv b) { ++ return jvp_cmp(a, b, 0); ++} + + struct sort_entry { + jv object; +@@ -683,19 +714,32 @@ struct sort_entry { + int index; + }; + ++static void sort_entry_array_free(struct sort_entry* entries, int start, int n) { ++ for (int i = start; i < n; i++) { ++ jv_free(entries[i].key); ++ jv_free(entries[i].object); ++ } ++ jv_mem_free(entries); ++} ++ + static int sort_cmp(const void* pa, const void* pb) { + const struct sort_entry* a = pa; + const struct sort_entry* b = pb; + int r = jv_cmp(jv_copy(a->key), jv_copy(b->key)); ++ if (r == INT_MIN) { ++ sort_cmp_state.too_deep = 1; ++ return 0; ++ } + // comparing by index if r == 0 makes the sort stable + return r ? r : (a->index - b->index); + } + +-static struct sort_entry* sort_items(jv objects, jv keys) { ++static struct sort_entry* sort_items(jv objects, jv keys, int *too_deep) { + assert(jv_get_kind(objects) == JV_KIND_ARRAY); + assert(jv_get_kind(keys) == JV_KIND_ARRAY); + assert(jv_array_length(jv_copy(objects)) == jv_array_length(jv_copy(keys))); + int n = jv_array_length(jv_copy(objects)); ++ *too_deep = 0; + struct sort_entry* entries = jv_mem_calloc(n, sizeof(struct sort_entry)); + for (int i=0; i 0) { + jv curr_key = entries[0].key; + jv group = jv_array_append(jv_array(), entries[0].object); + for (int i = 1; i < n; i++) { +- if (jv_equal(jv_copy(curr_key), jv_copy(entries[i].key))) { ++ int equal = jv_equal(jv_copy(curr_key), jv_copy(entries[i].key)); ++ if (equal < 0) { ++ jv_free(curr_key); ++ jv_free(group); ++ sort_entry_array_free(entries, i, n); ++ jv_free(ret); ++ return jv_invalid_with_msg(jv_string("Equality check too deep")); ++ } ++ if (equal) { + jv_free(entries[i].key); + } else { + jv_free(curr_key); +diff --git a/tests/jq.test b/tests/jq.test +index 6d1518d..018d2d0 100644 +--- a/tests/jq.test ++++ b/tests/jq.test +@@ -2172,3 +2172,25 @@ null + try ((reduce range(10001) as $_ ({}; {a: .})) as $x | $x * $x) catch . + null + "Object merge too deep" ++ ++# regression test for deep structural equality recursion ++try ((reduce range(10001) as $_ ([]; [.])) as $x | (reduce range(10001) as $_ ([]; [.])) as $y | $x == $y) catch . ++null ++"Equality check too deep" ++ ++# regression tests for deep ordering comparisons ++try ((reduce range(10001) as $_ ([]; [.])) as $x | [$x, $x] | sort) catch . ++null ++"Comparison too deep" ++ ++try ((reduce range(10001) as $_ ([]; [.])) as $x | [$x, $x] | unique) catch . ++null ++"Comparison too deep" ++ ++try ((reduce range(10001) as $_ ({}; {a: .})) as $x | [$x, $x] | sort) catch . ++null ++"Comparison too deep" ++ ++try ((reduce range(10001) as $_ ({}; {a: .})) as $x | [$x, $x] | unique) catch . ++null ++"Comparison too deep" +-- +2.44.4 + diff --git a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb index 2f08f583cc..f13548ddd3 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb @@ -26,6 +26,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${BPN}-${PV}/${BPN}-${PV}.tar.gz \ file://CVE-2026-43894.patch \ file://CVE-2026-43896.patch \ file://CVE-2026-43895.patch \ + file://CVE-2026-47770.patch \ " SRC_URI[sha256sum] = "478c9ca129fd2e3443fe27314b455e211e0d8c60bc8ff7df703873deeee580c2" From patchwork Tue Jul 21 09:39:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 72B80C44529 for ; Tue, 21 Jul 2026 09:39:47 +0000 (UTC) Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18888.1784626784725967895 for ; Tue, 21 Jul 2026 02:39:44 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=KsixpIRR; spf=pass (domain: cisco.com, ip: 173.37.86.74, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2569; q=dns/txt; s=iport01; t=1784626784; x=1785836384; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=6Qz1Mxh10ACApnDfv9cF6NUv/QKuFoSpTmkuY1ZT+Zk=; b=KsixpIRRpFxTYxwBv10Zi24z7oCc0VX4wKa3cBFVlR4nwnWmv6Ij/S1t RSTUK9BNc/5u7qrk3xYMliB7i3rMPbTrfyas/pN4tBmL9rWwQucW9B0uZ O1YcHhlv571X9MQi2bFxuf3gdT9/PWXPEq7hxyT0ru0OhgX690Z6l/Sys w8qybSMUlo38/22Hu3iHgSIniiqiSKt3/Rq2ZFNxuh6yFBIdRCuN2VwLo edRTiU/nm0fqW1PvMtKoHSlMckgMSmDLp3oqT9vMVU/pmdUA5/Du5MMD/ Qy6eAfu7iu/Gd4vNQchTfeMD4kPeN428R/w+RD0iGk8mHKJY9YqsWjJn4 A==; X-CSE-ConnectionGUID: BGIGxmFMQy2YCv9KT30vsg== X-CSE-MsgGUID: S3VCqIL7Q0OD0zz1QADicQ== X-IPAS-Result: A0BIAgD7PV9q/4//Ja1aglmCV3ReQ0kDlkcDgROdCIF+DwEBAQ9EDQQBAYUFAo1XAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDMgEYAS0QHAMBAi8rIwgZgwIBgnQDEb4uGjeCLIEBgygBgVTbLgELFAEFgTOFP4ggXBgBhHwnGxuBcoEVgnN2gQWBXAKBOHWFeASCInoSgVoehG+LHkiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDBsHBYEdgS6BAoRuIx8DOX+BL3VKdy1pARIXgSaCFIE6Ak4DCxgNSBEsNxQZBD5uB41QI4JAgQ4BKxeCFaV2oQ8KKIN1jCGVOhozqmwLmH2OCpZQhGmBaDyBWXAVgyIJShkPjjiDa85aJzICCQMvAQEHAgcOAwuBaJABgX0BAQ IronPort-Data: A9a23:t/hMG6AVbKOyYBVW/3niw5YqxClBgxIJ4kV8jS/XYbTApGx20mZWm zAcCmvXPfbcNDPweYt3PIWxpkxSu8eEyNRiOVdlrnsFo1CmBibm6XV1Cm+qYkt+++WaFBoPA /02M4eGdIZvCCeA+n9BC5C5xVFkz6aEW7HgP+DNPyF1VGdMRTwo4f5Zs7ZRbrVA357jXmthh fuo+5eBYAD/gmYtWo4pw/vrRC1H7ayaVAww5jTSVdgT1HfCmn8cCo4oJK3ZBxPQXolOE+emc P3Ixbe/83mx109F5gSNy+uTnuUiG9Y+DCDW4pZkc/HKbitq+kTe5p0G2M80Mi+7vdkmc+dZk 72hvbToIesg0zaldO41C3G0GAkmVUFKFSOuzXWX6aSuI0P6n3TE6dpPI1EzE6gh67xGKn8f1 sBDcC4WYUXW7w626OrTpuhEnM8vKozveYgYoHwllW+fBvc9SpeFSKLPjTNa9G5v3YYVQrCEO pdfMGY0BPjDS0Un1lM/BJEzmO6pl3DXeDxDo1XTrq0yi4TW5FEoi+azb4aPJrRmQ+1uxXizv 0PioF2hJT1CJs7G8BOp83mV07qncSTTHdh6+KeD3vlyjVuew2YeBBEbWR63rOe0jma6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++MvUCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXPIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:/UlPy6EQddMOPGhupLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:4cRLYmi9kyl82V08z+pkPrpgxDJuWFL842fVDWqBGDxYY6PEamPLoL1/nJ87 X-Talos-MUID: 9a23:eSyI5Qx7Kh8T6MbySorRLNtVLzOaqJ/1NmsUsLFZgpGjGXRiKW6kpRi2SbZyfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,176,1779148800"; d="scan'208";a="513667424" Received: from rcdn-l-core-06.cisco.com ([173.37.255.143]) by rcdn-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 09:39:42 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-06.cisco.com (Postfix) with ESMTPS id 01BA7180003B5; Tue, 21 Jul 2026 09:39:42 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id 9DA2DCAB20D; Tue, 21 Jul 2026 02:39:41 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com, Darsh Kelaiya Subject: [meta-OE][scarthgap][PATCH 3/4] jq: Fix CVE-2026-49839 Date: Tue, 21 Jul 2026 02:39:37 -0700 Message-Id: <20260721093938.3983571-3-dkelaiya@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721093938.3983571-1-dkelaiya@cisco.com> References: <20260721093938.3983571-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: rcdn-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 09:39:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128349 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/jqlang/jq/commit/e987df0d463d85fd70825e042a082427e8275b86 [2] https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm Signed-off-by: Darsh Kelaiya --- .../jq/jq/CVE-2026-49839.patch | 37 +++++++++++++++++++ meta-oe/recipes-devtools/jq/jq_1.7.1.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-49839.patch diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2026-49839.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2026-49839.patch new file mode 100644 index 0000000000..bd40828373 --- /dev/null +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2026-49839.patch @@ -0,0 +1,37 @@ +From 851544d2a13cf8baca1824196ac15cfe81d63224 Mon Sep 17 00:00:00 2001 +From: itchyny +Date: Mon, 8 Jun 2026 22:14:48 +0900 +Subject: [PATCH] Fix heap-buffer-overflow in raw file loading + +When `jv_string_append_buf` overflows the string length limit, +it returns an invalid `jv`; `jv_load_file` then re-entered it +on the invalid value and overran the heap. Break out of the loop +once the value is invalid. + +Fixes CVE-2026-49839. + +CVE: CVE-2026-49839 +Upstream-Status: Backport [https://github.com/jqlang/jq/commit/e987df0d463d85fd70825e042a082427e8275b86] + +(cherry picked from commit e987df0d463d85fd70825e042a082427e8275b86) +Signed-off-by: Darsh Kelaiya +--- + src/jv_file.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/jv_file.c b/src/jv_file.c +index b10bcc0..40137c3 100644 +--- a/src/jv_file.c ++++ b/src/jv_file.c +@@ -57,6 +57,8 @@ jv jv_load_file(const char* filename, int raw) { + + if (raw) { + data = jv_string_append_buf(data, buf, n); ++ if (!jv_is_valid(data)) ++ break; + } else { + jv_parser_set_buf(parser, buf, n, !feof(file)); + jv value; +-- +2.44.4 + diff --git a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb index f13548ddd3..56ac5b2032 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb @@ -27,6 +27,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${BPN}-${PV}/${BPN}-${PV}.tar.gz \ file://CVE-2026-43896.patch \ file://CVE-2026-43895.patch \ file://CVE-2026-47770.patch \ + file://CVE-2026-49839.patch \ " SRC_URI[sha256sum] = "478c9ca129fd2e3443fe27314b455e211e0d8c60bc8ff7df703873deeee580c2" From patchwork Tue Jul 21 09:39:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93028 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8DFD4C4452D for ; Tue, 21 Jul 2026 09:39:47 +0000 (UTC) Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18897.1784626783041452144 for ; Tue, 21 Jul 2026 02:39:43 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=SOCWrO7f; spf=pass (domain: cisco.com, ip: 173.37.86.77, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=4176; q=dns/txt; s=iport01; t=1784626783; x=1785836383; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=vhya5kcETAqgdZAZ5tY+jO1XVhC6NS1O6Zbi/WjnQpI=; b=SOCWrO7fS9APkHDvvrsKbvuJTqZiF/Wnsfvr15ckqFPLZXxes7IF1yMn LREdo5N9TdwuNRvYu4/KcchPut47NeaubLCW/+WHdr7oDjVJvbgE0muUB 7wrMx5cQdd1xpg9KigPGY/2MQuRml04KqL7CoCCakF0dmrhTyUYzm0G9R 9qpdpALALxNHYKKES3i0HRVhVPqCJ6E8FpOW33BL51K9FqrKPeXVrr7tL s8wTHNwKkT6ICOESrbtH5Hp931JQxyKtsHqvDZK1QM8eGgp28GUyMU88L RRblQTJij+oJDRUhYLSxl+43WPw3Ap3f+6ZrJzFqJ+CVqAwhTJd9Lhk3D A==; X-CSE-ConnectionGUID: SBUn9hPHQPqmBWIaX4dAjg== X-CSE-MsgGUID: Am3LWHSjREaOqyOQyYhKhg== X-IPAS-Result: A0BLAgAGPV9q/4z/Ja1aglmCV3ReQ0kDhFSRcwOBE50IgX4PAQEBD0QNBAEBhQUCjVcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMjDwEYAS0QHAMBAgMCJgICKyMIEAmDAgGCdAMRvkcaN3qBMoEBgygBgVTbLgELFAEFgQUuhT+DHQGFAlwYAYR8JxsbgXKBFYJzdoEFgVwCgSeEFIJqBIIiehKBWh6QEUiBAhwDWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XNFgbBwWBHYE6gQKEdCMfAzl/gS91SnctaQESF4EmghICgTsCTgMLGA1IESw3FBkEPQFuB41bI4I/AYEOASsXghWldqEPCiiDdYwhlToaM6psC5h9jgqWUIRpgWg8gVlwFYMiCUoZD444g2vOWicyAgkDLwEBBwIHAQwBAwuBaJAAgX4BAQ IronPort-Data: A9a23:QFhtqqp1EliulcclbVKYzgxFGsFeBmJIZBIvgKrLsJaIsI4StFCzt garIBnUP6uCZGagfd9yat63oBwOu5bWnNE1QAI4/ys9FXwRpOPIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOCn9j8kif3gqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrc8ko35ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0t1dPGcf9 cQ4EQgUazq8puuGnL6SSOY506zPLOGzVG8ekmtrwTecCbMtRorOBv2Ro9RZxzw3wMtJGJ4yZ eJANmEpN0uGOUASfA5LUPrSn8/w7pX7WzFbpVacpLs+y2PS1wd2lrPqNbI5f/TXHJ4Pxh3G/ j2uE2LRKxRBEOO/8ji/33uLn/7opDLKWKESG+jtnhJtqBjJroAJMzURTVa9rPyzh0KyVt4aJ 0EK9y4Gqakp6FftScHwWRC9qnOIshMQHd1KHIUHBBql0KHY5UOdQ2MDVDMEMIdgv84tTjts3 ViM9z/0OQFSXHSuYSr13t+pQfmaY0D58Udqifc4cDY4 IronPort-HdrOrdr: A9a23:zEg0sqNkm5e2N8BcTh+jsMiBIKoaSvp037Dk7S9MoHtuA6qlfq GV7ZMmPHDP6Qr5NEtMpTnEAtjjfZq+z+8Q3WBuB9eftWDd0QPCRr2Kr7GSpgEIcBeRygcy78 tdmoFFeaTN5CBB/KXHyTj9Nco8y9+a963tr+Lfw3BxCTxOUchbnn9E4sLxKDwNeOGAbqBJb6 ah2g== X-Talos-CUID: 9a23:yvorV2HOrlkh2lSnqmJc3nMSS8AdUkTl1XL6HG6xOTplYb+aHAo= X-Talos-MUID: 9a23:YgUFbApz32Oq/l497uwezxhnb+NXw5+sMm0EtowXnPCVBCxTOzjI2Q== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,176,1779148800"; d="scan'208";a="513203607" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 09:39:42 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id 032D1180001C0; Tue, 21 Jul 2026 09:39:42 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id A2C73CAB20E; Tue, 21 Jul 2026 02:39:41 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com, Darsh Kelaiya Subject: [meta-OE][scarthgap][PATCH 4/4] jq: Fix CVE-2026-54679 Date: Tue, 21 Jul 2026 02:39:38 -0700 Message-Id: <20260721093938.3983571-4-dkelaiya@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721093938.3983571-1-dkelaiya@cisco.com> References: <20260721093938.3983571-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 09:39:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128347 From: Darsh Kelaiya This patch applies the upstream fix for CVE-2026-54679 as referenced in [2], using the upstream commit identified in [1]. [1] https://github.com/jqlang/jq/commit/46d1da30944ce93dd671ac72b6513fc0eb747837 [2] https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx Signed-off-by: Darsh Kelaiya --- .../jq/jq/CVE-2026-54679.patch | 74 +++++++++++++++++++ meta-oe/recipes-devtools/jq/jq_1.7.1.bb | 1 + 2 files changed, 75 insertions(+) create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-54679.patch diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2026-54679.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2026-54679.patch new file mode 100644 index 0000000000..20689e83c6 --- /dev/null +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2026-54679.patch @@ -0,0 +1,74 @@ +From c4f6b269e6d2178c74aac6e82c5285a90c9347a0 Mon Sep 17 00:00:00 2001 +From: itchyny +Date: Tue, 16 Jun 2026 14:31:14 +0900 +Subject: [PATCH] Tighten string length bounds and propagate invalid jv in + implode +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The bound added in CVE-2026-32316 (e47e56d22) still allowed +`sizeof(jvp_string) + (currlen + len) * 2 + 1` to wrap `size_t` on +32-bit platforms. Tighten the threshold so the final allocation +fits in 32-bit `size_t`. + +Also break out of `jv_string_implode` and `f_string_implode` once +`jv_string_append_codepoint` returns an invalid `jv`; otherwise the +next iteration triggers the assertion in `jvp_string_ptr` (or +invokes undefined behavior under `-DNDEBUG`). + +Fixes CVE-2026-54679. + +CVE: CVE-2026-54679 +Upstream-Status: Backport [https://github.com/jqlang/jq/commit/46d1da30944ce93dd671ac72b6513fc0eb747837] + +Backport Changes: +- Omitted the jv_string_repeat() bound change because this function is + not present in the Scarthgap jq source. The applicable + jvp_string_append(), jv_string_implode(), and f_string_implode() + security changes were retained unchanged. + +Co-authored-by: Dirk Müller +(cherry picked from commit 46d1da30944ce93dd671ac72b6513fc0eb747837) +Signed-off-by: Darsh Kelaiya +--- + src/builtin.c | 1 + + src/jv.c | 3 ++- + 2 files changed, 3 insertions(+), 1 deletion(-) + +diff --git a/src/builtin.c b/src/builtin.c +index 08a8a98..46b9077 100644 +--- a/src/builtin.c ++++ b/src/builtin.c +@@ -1264,6 +1264,7 @@ static jv f_string_implode(jq_state *jq, jv a) { + if (nv < 0 || nv > 0x10FFFF || (nv >= 0xD800 && nv <= 0xDFFF)) + nv = 0xFFFD; // U+FFFD REPLACEMENT CHARACTER + s = jv_string_append_codepoint(s, nv); ++ if (!jv_is_valid(s)) break; + } + + jv_free(a); +diff --git a/src/jv.c b/src/jv.c +index fe27168..6f79693 100644 +--- a/src/jv.c ++++ b/src/jv.c +@@ -1175,7 +1175,7 @@ static uint32_t jvp_string_remaining_space(jvp_string* s) { + static jv jvp_string_append(jv string, const char* data, uint32_t len) { + jvp_string* s = jvp_string_ptr(string); + uint32_t currlen = jvp_string_length(s); +- if ((uint64_t)currlen + len >= INT_MAX) { ++ if ((uint64_t)currlen + len >= INT_MAX - sizeof(jvp_string) / 2) { + jv_free(string); + return jv_invalid_with_msg(jv_string("String too long")); + } +@@ -1435,6 +1435,7 @@ jv jv_string_implode(jv j) { + if (nv < 0 || nv > 0x10FFFF || (nv >= 0xD800 && nv <= 0xDFFF)) + nv = 0xFFFD; // U+FFFD REPLACEMENT CHARACTER + s = jv_string_append_codepoint(s, nv); ++ if (!jv_is_valid(s)) break; + } + + jv_free(j); +-- +2.44.4 + diff --git a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb index 56ac5b2032..4327a25311 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.7.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.7.1.bb @@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${BPN}-${PV}/${BPN}-${PV}.tar.gz \ file://CVE-2026-43895.patch \ file://CVE-2026-47770.patch \ file://CVE-2026-49839.patch \ + file://CVE-2026-54679.patch \ " SRC_URI[sha256sum] = "478c9ca129fd2e3443fe27314b455e211e0d8c60bc8ff7df703873deeee580c2"