From patchwork Tue Jul 21 17:42:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93066 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C58FC4452D for ; Tue, 21 Jul 2026 17:42:38 +0000 (UTC) Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.29035.1784655748905206779 for ; Tue, 21 Jul 2026 10:42:29 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=DqgMRgey; spf=pass (domain: cisco.com, ip: 173.37.86.76, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=9855; q=dns/txt; s=iport01; t=1784655748; x=1785865348; h=from:to:subject:date:message-id:mime-version: content-transfer-encoding; bh=2gAfCFzTEHFhNb3NwX4tJUgnVbWdEhCzIFAZjl3RTwc=; b=DqgMRgeySFg2DJiTewB3xEufU3MQL4B+PX9RZaVMbJrSBQrZ8PYimCyy bAgQRokFEWzFjwqO1juxbienvXWtbabT4aV+HcM7uY5oZM0jDD6XVVoV3 wR29S1Kbu2nFXMEaQhmHUnNo21CX6bRvrQo1XIMyMue4w2T6/CEJJ9/5P 1hX1E2mT2mgZUZzISa1pxhcHq3rXhaCFiNeQRnGdva4MJUOp994qj5ECL 2CC126kR3ooyAGktYf3bHtCaOxv1OcsDwVbJFYAzVNcZol8TGz10gYaSc dA/+0sEr0YjJemzAUZgSTqeEYpRP45comD11+zOjZ4Jz8SYP3SvF3tQkm Q==; X-CSE-ConnectionGUID: A+bbFt8mSUCXLd0Ce1BZMA== X-CSE-MsgGUID: +lVFJ67nQlmPDUM2rIk19Q== X-IPAS-Result: A0BHAgD/rl9q/5L/Ja1aHgEBCxIMggULgld0X0JJA4RUj1KCIYEWnQgUgWoPAQEBD0QNBAEBghKQTAImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaASkECwE0PgMBAgMCJgItIxkIgwIBgnQDEahnlxcaN3p/M4EBg2gCQ1DbLgELFAGBCi6FP4MdAYUCXBgBhHwnGxuBcoEVgnN2gQWBXAKBIwQhg3OCagSCIoEMgVoYBoJ7gXSCBokaSIECHANZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPhc0WBsHBYEdgS6BAoRuIx8DOX+BL3VKdy1qEheBJoIUgToCVQMLGA1IESw3FBkEPQFuB41UI4E8NUgHATxRASsgAmMUgRMcAZMIGiqPbIIeoRIKKIN1jCGVOhozhVulEQuYfY4KllCEaYFoPIFZcBWDIglKGQ+OOINrhAeBDMcmPDULAy8BAQcCBw4DC4FokACBfgEB IronPort-Data: A9a23:C5E7xq8pOKGgv6JiCE79DrUD0X+TJUtcMsCJ2f8bNWPcYEJGY0x3m jBNDG6DPqrYYGr9c48gPYWz9EMAucfdy4VkQQVk/C9EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsbThNs/jrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kffocS1PonBFpz3 sw8JGgmY0mptceflefTpulE3qzPLeHxN48Z/3UlxjbDALN+ENbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZP0Mn1lQ/UPrSmM+ki3TleiFYr3qepLE85C7YywkZPL3FbYOOJIbRHpwJ9qqej iHCwUrbXE4cDdia8Ra41yi2p+yWzBquDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjlCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:IBlk2Kqhu4W83rzLqF8pHXwaV5odeYIsimQD101hICG9Ffbo8v xG/c5rtyMc5wx+ZJhNo7290cq7MBDhHOBOgLX5VI3KNGKNhILCFu5fBOXZrwEIYxefysdtkY F9bqN5FNr8SXJ+jcr8/U2ENuxI+qjizEht7t2uqUuEimpRGsZd0zs= X-Talos-CUID: 9a23:CMj4XmBSExAho9D6EwAk/kQ6BpAgSUD2/FPce2S1UExbbZTAHA== X-Talos-MUID: 9a23:yj5OYgyJjbABg0JLpDCAGXVVxFmaqOeqNm4vz8oAgs2BDQBNHm2HrTfuE7Zyfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="513623314" Received: from rcdn-l-core-09.cisco.com ([173.37.255.146]) by rcdn-iport-5.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:27 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-09.cisco.com (Postfix) with ESMTPS id 691F918000203 for ; Tue, 21 Jul 2026 17:42:27 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 82A85CC037D; Tue, 21 Jul 2026 23:12:25 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 1/8] cups: fix CVE-2026-27447 Date: Tue, 21 Jul 2026 23:12:10 +0530 Message-Id: <20260721174217.229620-1-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-09.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241559 From: Deepak Rathore Pick the upstream backport [1] for CVE-2026-27447 as mentioned in [2], where the scheduler treated local user and group names as case-insensitive. Also include the two upstream regression fixes that followed the CVE fix: - CVE-2026-27447-regression_p1.patch [3] fixes a cupsd crash when the referenced user does not exist on the server. This regression was reported in OpenPrinting/cups Issue [5]. - CVE-2026-27447-regression_p2.patch [4] fixes unauthenticated print policies for non-local accounts. This regression was reported in OpenPrinting/cups Issue [6]. [1] https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb [2] https://security-tracker.debian.org/tracker/CVE-2026-27447 [3] https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562 [4] https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0 [5] https://github.com/OpenPrinting/cups/issues/1555 [6] https://github.com/OpenPrinting/cups/issues/1557 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 3 + .../cups/CVE-2026-27447-regression_p1.patch | 33 ++++++ .../cups/CVE-2026-27447-regression_p2.patch | 46 ++++++++ .../cups/cups/CVE-2026-27447.patch | 108 ++++++++++++++++++ 4 files changed, 190 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index c7475d2b81..ec9392b73d 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -20,6 +20,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2025-58436.patch \ file://CVE-2025-61915.patch \ file://0001-conf.c-Fix-stopping-scheduler-on-unknown-directive.patch \ + file://CVE-2026-27447.patch \ + file://CVE-2026-27447-regression_p1.patch \ + file://CVE-2026-27447-regression_p2.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch new file mode 100644 index 0000000000..d581ee36fd --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch @@ -0,0 +1,33 @@ +From 6d97ee39fedf12a7a5429a74f4156ef9bb67f562 Mon Sep 17 00:00:00 2001 +From: Zdenek Dohnal +Date: Wed, 22 Apr 2026 12:40:14 +0200 +Subject: [PATCH] Fix cupsd crash if user does not exist on server + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562] + +Backport Changes: +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 6d97ee39fedf12a7a5429a74f4156ef9bb67f562) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 1678a29..4798e86 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1810,7 +1810,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name; + name = (char *)cupsArrayNext(best->names)) + { +- if (!_cups_strcasecmp(name, "@OWNER") && owner && ++ if (!_cups_strcasecmp(name, "@OWNER") && owner && pw && + !strcmp(pw->pw_name, ownername)) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) +-- +2.43.7 diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch new file mode 100644 index 0000000000..e46db92c76 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch @@ -0,0 +1,46 @@ +From 849fba7d7a1144e48d45c5e6ba2504765912ece0 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Fri, 24 Apr 2026 14:06:06 -0400 +Subject: [PATCH] Fix unauthenticated print policies (Issue #1557) + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0] + +Backport Changes: +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 849fba7d7a1144e48d45c5e6ba2504765912ece0) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 7 +++++-- + 1 file changed, 5 insertions(+), 2 deletions(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 4798e86..1dd520d 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1810,8 +1810,9 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name; + name = (char *)cupsArrayNext(best->names)) + { +- if (!_cups_strcasecmp(name, "@OWNER") && owner && pw && +- !strcmp(pw->pw_name, ownername)) ++ if (!_cups_strcasecmp(name, "@OWNER") && owner && ++ ((pw && !strcmp(pw->pw_name, ownername)) || ++ (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, ownername)))) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) + { +@@ -1825,6 +1826,8 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + } + else if (pw && !strcmp(pw->pw_name, name)) + return (HTTP_OK); ++ else if (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, name)) ++ return (HTTP_STATUS_OK); + } + + for (name = (char *)cupsArrayFirst(best->names); +-- +2.43.7 + diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch new file mode 100644 index 0000000000..1614faa7f1 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch @@ -0,0 +1,108 @@ +From 37b8a4387864eded1a15a45db8950a23e5c610d2 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:04:21 -0400 +Subject: [PATCH] CVE-2026-27447: The scheduler treated local user and group + names as case-insensitive. + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb] + +Backport Changes: +- Rebase scheduler/auth.c context to the CUPS 2.4.11 source carried by this + recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit a0c62c1e69604ff061089b750073199fab5a1beb) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 31 +++++++++++++++---------------- + 1 file changed, 15 insertions(+), 16 deletions(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index d0430b4..1678a29 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1,7 +1,7 @@ + /* + * Authorization routines for the CUPS scheduler. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 1997-2007 by Easy Software Products, all rights reserved. + * +@@ -1159,7 +1159,7 @@ cupsdCheckGroup( + group = getgrnam(groupname); + endgrent(); + +- if (group != NULL) ++ if (user && group) + { + /* + * Group exists, check it... +@@ -1173,7 +1173,7 @@ cupsdCheckGroup( + * User appears in the group membership... + */ + +- if (!_cups_strcasecmp(username, group->gr_mem[i])) ++ if (!strcmp(user->pw_name, group->gr_mem[i])) + return (1); + } + +@@ -1184,25 +1184,24 @@ cupsdCheckGroup( + * belongs to... + */ + +- if (user) +- { +- int ngroups; /* Number of groups */ ++ int ngroups; /* Number of groups */ + # ifdef __APPLE__ +- int groups[2048]; /* Groups that user belongs to */ ++ int groups[2048]; /* Groups that user belongs to */ + # else +- gid_t groups[2048]; /* Groups that user belongs to */ ++ gid_t groups[2048]; /* Groups that user belongs to */ + # endif /* __APPLE__ */ + +- ngroups = (int)(sizeof(groups) / sizeof(groups[0])); ++ ngroups = (int)(sizeof(groups) / sizeof(groups[0])); + # ifdef __APPLE__ +- getgrouplist(username, (int)user->pw_gid, groups, &ngroups); ++ getgrouplist(user->pw_name, (int)user->pw_gid, groups, &ngroups); + # else +- getgrouplist(username, user->pw_gid, groups, &ngroups); ++ getgrouplist(user->pw_name, user->pw_gid, groups, &ngroups); + #endif /* __APPLE__ */ + +- for (i = 0; i < ngroups; i ++) +- if ((int)groupid == (int)groups[i]) +- return (1); ++ for (i = 0; i < ngroups; i ++) ++ { ++ if ((int)groupid == (int)groups[i]) ++ return (1); + } + #endif /* HAVE_GETGROUPLIST */ + } +@@ -1812,7 +1811,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name = (char *)cupsArrayNext(best->names)) + { + if (!_cups_strcasecmp(name, "@OWNER") && owner && +- !_cups_strcasecmp(username, ownername)) ++ !strcmp(pw->pw_name, ownername)) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) + { +@@ -1824,7 +1823,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + if (cupsdCheckGroup(username, pw, name + 1)) + return (HTTP_OK); + } +- else if (!_cups_strcasecmp(username, name)) ++ else if (pw && !strcmp(pw->pw_name, name)) + return (HTTP_OK); + } + +-- +2.43.7 From patchwork Tue Jul 21 17:42:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93065 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 06913C4452B for ; Tue, 21 Jul 2026 17:42:38 +0000 (UTC) Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.29038.1784655753035930417 for ; Tue, 21 Jul 2026 10:42:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=KpOA2Vn4; spf=pass (domain: cisco.com, ip: 173.37.86.78, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=4064; q=dns/txt; s=iport01; t=1784655753; x=1785865353; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=5Hq/M8PWr5i98Y7LrY/pQn/gSb9YXPZLFN2a7S/n1go=; b=KpOA2Vn42JS8T9YipTQvl9elHNwIt2XIcyU3Dnk++cAoxGnetJUouZ7x J8x32xiT2sSMYZKhTvQC+aBWXIl0QORVEDuP4DXhevTwxhtK2oIoAJ/l4 9P7rz6thprP6EAUD0RWmq4EfHKoSX0Clfc0+V0QmPK1HIGIPnuZXzAcSv /6Ib7U0GPYk3qIMwgRXqkrENxCdi/rkENkbwwTR76YEp4UYyZ8SVup3EA Twb0cBOAjj4ucoFum864yV0keUvpJOcDxWykhB5H41s16eVu7hDs2LoNp nVXI5o5N24bfdjZ3Uqj+hpsitXu2VpXa4uvgpGbDXNz52USIr6ksO8pxh w==; X-CSE-ConnectionGUID: OwLDT1XQTm21q+jJxzeFew== X-CSE-MsgGUID: wN+zys6gTkuDAgzUW0bypQ== X-IPAS-Result: A0BLAgCXrl9q/4r/Ja1aHgEBCxIMggULgld0X0JJA4RUj1KCIQOeGxSBag8BAQEPRA0EAQGCEoJzAo1XAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDIwQLAVYcAwECAwImAgIrIwgRCIMCAYJ0AxGoeZcXGjd6fzOBAYNoAkNQ2y4BBQYUAYEKLoU/gx0BhQJcGAGEfCcbG4FygRWDaYEFgVwCgSMVhAOCagSCIoEMgVoYBoNXgRiLIEiBAhwDWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XNFgbBwWBHYEugQKEbiMfAzl/gS91SnctahIXgSaCFIE6AlUDCxgNSBEsNxQZBD0BbgeNVCOBcUgHPVEBK4EFgSeTaZIKoRIKKIN1jCGVOhozqmwLmH2OCpYAUIRpgWg8gVlwFYMiUxkPjioOC4NghRPHJjw1CwMvAQEHAgcOAwuBaJABgX0BAQ IronPort-Data: A9a23:XpF1tq6yfMhlkWZkTQAIcwxRtGnGchMFZxGqfqrLsTDasY5as4F+v jZKDWGDbveCZmvzKdF2Ot+19E1UsZ6AyNMwHAJl+Xo9Zn8b8sCt6fZ1gavT04J+CuWZESqLO u1HMoGowPgcFyGa/lH2dOC98RGQ7InQLpLkEunIJyttcgFtTSYlmHpLlvUw6mJSqYDR7zil5 5Wo/qUzBHf/g2Qqaj1OsvrZwP9SlK2aVA0w7wRWic9j5Dcyp1FNZLoDKKe4KWfPQ4U8NoaSW +bZwbilyXjS9hErB8nNuu6TnpoiG+O60aCm0xK6aoD66vRwjnVaPpUTaJLwXXxqZwChxLid/ jniWauYEm/FNoWU8AgUvoIx/ytWZcWq85efSZSzXFD6I0DuKxPRL/tS4E4eGpI81touMVhy8 KZBMXMPTACRisy73+fuIgVsrpxLwMjDJogTvDRkiDreF/tjGcmFSKTR7tge1zA17ixMNa+BP IxCNnw1MUmGOkYfUrsUIMpWcOOAinTyaTREqFW9rqss6G+Vxwt0uFToGIeMIILUGZsLxS50o ErZ2SfrEwpEO+Cc1Bas/WCRubfFjDvCDdd6+LqQs6QCbEeo7msLBRsbUFG2rfW0hgu1XMhSA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO/cx5AfIzu/f5ByUQzBdCDVAc9ch8sQxQFTGy 2O0oj8gPhQ32JX9dJ5X3u38Qe+aUcTNEVI/WA== IronPort-HdrOrdr: A9a23:nm+fIavgsdYMQifvDIUIzVB57skDVNV00zEX/kB9WHVpm6uj5q eTdZUgpHvJYVkqNk3I9ersBEDEewK+yXcX2/h1AV7dZmjbUQKTRekIh7cKgQeQeREWndQz6U 4PScRD4aXLbWRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaDZ2JK2xCe36m+oocfng+OaYE X-Talos-CUID: 9a23:ju0iL2j0SlcF5AE2Ss/wMoashjJuVWL54EuJE3aEDDwwUf6Xa0+C9Y1pjJ87 X-Talos-MUID: 9a23:Xw5aZgXxNmIMZuDq/CDKxyNzL5ln36ezJGkCg6g548OVLRUlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="512664663" Received: from rcdn-l-core-01.cisco.com ([173.37.255.138]) by rcdn-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:32 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-01.cisco.com (Postfix) with ESMTPS id DBAF9180001DF for ; Tue, 21 Jul 2026 17:42:31 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 0AC9ECC037D; Tue, 21 Jul 2026 23:12:30 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 2/8] cups: fix CVE-2026-41079 Date: Tue, 21 Jul 2026 23:12:11 +0530 Message-Id: <20260721174217.229620-2-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241560 From: Deepak Rathore Pick the upstream fix [1] for CVE-2026-41079 as referenced by Debian [2]. [1] https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080 [2] https://security-tracker.debian.org/tracker/CVE-2026-41079 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Corrected the SRC_URI placement so CVE-2026-41079 is added before the later CUPS CVE patches in the series. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-41079.patch | 71 +++++++++++++++++++ 2 files changed, 72 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index ec9392b73d..f74bcaffab 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -23,6 +23,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447.patch \ file://CVE-2026-27447-regression_p1.patch \ file://CVE-2026-27447-regression_p2.patch \ + file://CVE-2026-41079.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-41079.patch b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch new file mode 100644 index 0000000000..a04d956afc --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch @@ -0,0 +1,71 @@ +From a331e93e2f9baf411715ef69ae19b73827da23d7 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Mon, 13 Apr 2026 11:50:23 -0400 +Subject: [PATCH] Limit num_bytes for SNMP string values. + +CVE: CVE-2026-41079 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080] + +(cherry picked from commit b7c2525a885f528d243c3a92197ca99609b3f080) +Signed-off-by: Deepak Rathore +--- + cups/snmp-private.h | 6 +++--- + cups/snmp.c | 8 ++++++-- + 2 files changed, 9 insertions(+), 5 deletions(-) + +diff --git a/cups/snmp-private.h b/cups/snmp-private.h +index 52b8740..015f53e 100644 +--- a/cups/snmp-private.h ++++ b/cups/snmp-private.h +@@ -1,7 +1,7 @@ + /* + * Private SNMP definitions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2014 by Apple Inc. + * Copyright © 2006-2007 by Easy Software Products, all rights reserved. + * +@@ -58,9 +58,9 @@ typedef enum cups_asn1_e cups_asn1_t; /**** ASN1 request/object types ****/ + + typedef struct cups_snmp_string_s /**** String value ****/ + { +- unsigned char bytes[CUPS_SNMP_MAX_STRING]; +- /* Bytes in string */ + unsigned num_bytes; /* Number of bytes */ ++ unsigned char bytes[CUPS_SNMP_MAX_STRING + 1]; ++ /* Bytes in string */ + } cups_snmp_string_t; + + union cups_snmp_value_u /**** Object value ****/ +diff --git a/cups/snmp.c b/cups/snmp.c +index 54e348f..2fcb38d 100644 +--- a/cups/snmp.c ++++ b/cups/snmp.c +@@ -1,7 +1,7 @@ + /* + * SNMP functions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 2006-2007 by Easy Software Products, all rights reserved. + * +@@ -1042,10 +1042,14 @@ asn1_decode_snmp(unsigned char *buffer, /* I - Buffer */ + case CUPS_ASN1_OCTET_STRING : + case CUPS_ASN1_BIT_STRING : + case CUPS_ASN1_HEX_STRING : +- packet->object_value.string.num_bytes = length; + asn1_get_string(&bufptr, bufend, length, + (char *)packet->object_value.string.bytes, + sizeof(packet->object_value.string.bytes)); ++ ++ if (length >= sizeof(packet->object_value.string.bytes)) ++ packet->object_value.string.num_bytes = sizeof(packet->object_value.string.bytes) - 1; ++ else ++ packet->object_value.string.num_bytes = length; + break; + + case CUPS_ASN1_OID : +-- +2.43.7 From patchwork Tue Jul 21 17:42:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93070 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3BB5DC44537 for ; Tue, 21 Jul 2026 17:42:48 +0000 (UTC) Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.29022.1784655757297440321 for ; Tue, 21 Jul 2026 10:42:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=O9TZ30yb; spf=pass (domain: cisco.com, ip: 173.37.86.73, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=5893; q=dns/txt; s=iport01; t=1784655757; x=1785865357; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=IyOgVwZSjFD/XTBAjkRmiNyjySLkpTwvcHBEdTYHutE=; b=O9TZ30ybMlTmiDJzq1EHq1w63G9VYwyD03hRsqNjjZzRfx6Mm9phD5mN PUcssz46eF+/mq2YBZS9WZYe7rcSDQGw0NthfthPhiESL6MT1KiVi4rkX UH/2vIprsqk6MagfcwNG9tfSdyE/YOOLpAg9GyCHYgL4n3gVfQA0SfeKx AQhDWDnT1v0etIFY2jkmXojeuuPMQMMXXyzJDTkqGdyz3/wUe3uz/hJ/Z k57TaTOus3w036mCsC/inPYPC4K0M0zfEE/c3SLf1dpYJwtCYnZyNjFBU NCxuyLzW8oNwuqCdmU+RsmUps55LmdDnoCldhnnbpSPEvduN2wZa1PVSu g==; X-CSE-ConnectionGUID: BY84AUbQSTiGK2KieFwAsA== X-CSE-MsgGUID: t62VkU0mT7i15qV1U50hdA== X-IPAS-Result: A0BNAgAVrl9q/4z/Ja1aglmCGD90X0JJA4RUj1KCIQOBE50IFIFqDwEBAQ9EDQQBAYISgnMCjVcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMjBAsBNCIcAwECAwIJHQICKyMIEQiCKlgBgnQDEah5lxcaN3p/M4EBg2gCQ1DbLgELFAGBCi6FP4MdAYUCXBgBhHwnGxuBcoEVgnN2gQWBXAKBI4QYgmoEgiKBDIFaGAZPgiyBdCmBXYkaSIECHANZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPhc0WBsHBYEdgS6BAoRuIx8DOX+BL3VKdy1qEheBJoIUgToCVQMLGA1IESw3FBkEPQFuB41UI4FxTz0+EwEqAYEDAoEnHZMIRI9sgh6hEgoog3WMIZU6GjOEBIFXnWGHMAuYfYJZizGWUIRpgWg8gVlwFYMiCUoZD444g2uEB4EMxyY8NQsDLwEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:mPtgAq+j1pbB/XrzHUM+DrUD0X+TJUtcMsCJ2f8bNWPcYEJGY0x3z jROCmvXa/bYZ2Ojc9p+YIi0/UkH7ZOHydc2GgZkpH9EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsbThNs/jrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kcDN1E09t9OFpy9 NM7chMMYz6crvmflefTpulE3qzPLeHxN48Z/3UlxjbDALN+GtbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZP0Un1lQ/UPrSmM+ki3TleiFYr3qepLE85C7YywkZPL3FbIuEIo3bH5UN9qqej n6YpVr6P0kfCIOekGeczCuR27fPkQquDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjNCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:Za/OsKnkf5vjRj83Sz01SPb8uSTpDfIO3DAbv31ZSRFFG/Fw8P re+8jztCWE7Ar5N0tPpTntAsS9qDbnhP1ICOoqTNKftXfd2VdARbsKheCJ/9SjIVydygc378 hdmsZFZOEYdWIbse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAH0++8YTzranGfg2J9dOMEKK Y= X-Talos-CUID: 9a23:JAJZrW2PeiLbPP6d/It8gbxfMPF1LlTgxk7rH06XKjxKSbC7VnaL0fYx X-Talos-MUID: 9a23:SyZdswQ1jUzW5DhHRXTw2mtcN/ow5pjxCRlQiKtfhpTcNSBZbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="499099280" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:35 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id EEB0518000617 for ; Tue, 21 Jul 2026 17:42:34 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 19F7DCC037D; Tue, 21 Jul 2026 23:12:33 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 3/8] cups: fix CVE-2026-34978 Date: Tue, 21 Jul 2026 23:12:12 +0530 Message-Id: <20260721174217.229620-3-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:48 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241561 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568 [2] https://security-tracker.debian.org/tracker/CVE-2026-34978 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34978.patch | 107 ++++++++++++++++++ 2 files changed, 108 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index f74bcaffab..5e272dbcf6 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -24,6 +24,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447-regression_p1.patch \ file://CVE-2026-27447-regression_p2.patch \ file://CVE-2026-41079.patch \ + file://CVE-2026-34978.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34978.patch b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch new file mode 100644 index 0000000000..cabcfe257a --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch @@ -0,0 +1,107 @@ +From ab6ab965de6890aed4df39c97f7cd708fd5cb00c Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:18:26 -0400 +Subject: [PATCH] Fix RSS notifier. + +CVE: CVE-2026-34978 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568] + +Backport Changes: +- Rebase scheduler/ipp.c subscription context to the CUPS 2.4.11 source + carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. +- Omit the upstream scheduler/ipp.c copyright-year-only header update because + this backport carries only the functional changes needed for CUPS 2.4.11. + +(cherry picked from commit 730347c5bbd5e1271149c6739aa858c0c83a7568) +Signed-off-by: Deepak Rathore +--- + notifier/rss.c | 20 ++++++++++++++------ + scheduler/ipp.c | 12 ++++++++++++ + 2 files changed, 26 insertions(+), 6 deletions(-) + +diff --git a/notifier/rss.c b/notifier/rss.c +index f17e1494c..250ad877e 100644 +--- a/notifier/rss.c ++++ b/notifier/rss.c +@@ -1,11 +1,12 @@ + /* + * RSS notifier for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. +- * Copyright 2007-2015 by Apple Inc. +- * Copyright 2007 by Easy Software Products. ++ * Copyright © 2020-2026 by OpenPrinting. ++ * Copyright © 2007-2015 by Apple Inc. ++ * Copyright © 2007 by Easy Software Products. + * +- * Licensed under Apache License v2.0. See the file "LICENSE" for more information. ++ * Licensed under Apache License v2.0. See the file "LICENSE" for more ++ * information. + */ + + /* +@@ -80,6 +81,7 @@ main(int argc, /* I - Number of command-line arguments */ + http_status_t status; /* HTTP GET/PUT status code */ + char filename[1024], /* Local filename */ + newname[1024]; /* filename.N */ ++ struct stat fileinfo; /* Local file information */ + cups_lang_t *language; /* Language information */ + ipp_attribute_t *printer_up_time, /* Timestamp on event */ + *notify_sequence_number,/* Sequence number */ +@@ -111,9 +113,9 @@ main(int argc, /* I - Number of command-line arguments */ + + if (httpSeparateURI(HTTP_URI_CODING_ALL, argv[1], scheme, sizeof(scheme), + username, sizeof(username), host, sizeof(host), &port, +- resource, sizeof(resource)) < HTTP_URI_OK) ++ resource, sizeof(resource)) < HTTP_URI_OK || strstr(resource, "../") != NULL) + { +- fprintf(stderr, "ERROR: Bad RSS URI \"%s\"!\n", argv[1]); ++ fprintf(stderr, "ERROR: Bad RSS URI \"%s\".\n", argv[1]); + return (1); + } + +@@ -209,6 +211,12 @@ main(int argc, /* I - Number of command-line arguments */ + snprintf(filename, sizeof(filename), "%s/rss%s", cachedir, resource); + snprintf(newname, sizeof(newname), "%s.N", filename); + ++ if (!lstat(filename, &fileinfo) && !S_ISREG(fileinfo.st_mode)) ++ { ++ fprintf(stderr, "ERROR: Local RSS path \"%s\" is not a file.\n", filename); ++ return (1); ++ } ++ + httpAssembleURIf(HTTP_URI_CODING_ALL, baseurl, sizeof(baseurl), "http", + NULL, server_name, atoi(server_port), "/rss%s", resource); + } +diff --git a/scheduler/ipp.c b/scheduler/ipp.c +index 2d80a960e..2dc7376c1 100644 +--- a/scheduler/ipp.c ++++ b/scheduler/ipp.c +@@ -1985,6 +1985,12 @@ add_job_subscriptions( + "notify-status-code", IPP_ATTRIBUTES); + return; + } ++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient); ++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES); ++ return; ++ } + } + else if (!strcmp(attr->name, "notify-pull-method") && + attr->value_tag == IPP_TAG_KEYWORD) +@@ -6010,6 +6016,12 @@ create_subscriptions( + "notify-status-code", IPP_ATTRIBUTES); + return; + } ++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient); ++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES); ++ return; ++ } + } + else if (!strcmp(attr->name, "notify-pull-method") && + attr->value_tag == IPP_TAG_KEYWORD) From patchwork Tue Jul 21 17:42:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93071 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 334FDC4452D for ; Tue, 21 Jul 2026 17:42:48 +0000 (UTC) Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.29023.1784655759379911644 for ; Tue, 21 Jul 2026 10:42:39 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=NQlBo5jX; spf=pass (domain: cisco.com, ip: 173.37.86.77, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=10065; q=dns/txt; s=iport01; t=1784655759; x=1785865359; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=UMvmSJeQegijvV2PdNSMeoBTCgKhkuwCNgBH5c/20LY=; b=NQlBo5jXJMTz4+XSxUWx1klv6H7vQHDNY6ncupGb7bvYT5AyNaon5lgH +TbaZyHFhBaq+/e1XDBtV1ahJSpEv6haNsOgLa8NjnQYxoBdGCzgu9wi0 KWI4DdMUWsSZLk5vlEZMIa18ulhGAnPyg9mpWATKgN/OeOTIlKtoDXvBc VWWTka1zW336ddggMWc8S3f2eWETABfnT/yVm/iW9CsYJPxpNka1ABSO9 5wjNRcNNTt+Y7164YUsbBigvU9hJdM/wt/nFpXvnNidN+YmkykZ2Sta6Q 9w1IbcP+rWldbPWScwoNudLOkof5+1+P31iQUO2VTttx+IUn7cXyrF0Ob Q==; X-CSE-ConnectionGUID: BLVW0MLHRoqGmROTi3gPFA== X-CSE-MsgGUID: R4xoHP1lShS7UE6yFlCJ6A== X-IPAS-Result: A0BNAgD/rl9q/5D/Ja1aglmCV3RfQkkDhFSPUoIhA4ETnQgUgWoPAQEBD0QNBAEBghKCcwKNVwImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAyMECwE0IhwCAQECAwImAgIrIwgRCIMCAYJ0AxGoZ5cXGjd6fzOBAYNoAkNQ2y4BCxQBgQouhT+DHQGFAlwYAYR8JxsbgXKBFYJzdoEFgVwCgSMEhBSCagSCIoEMgVoYBjKEPYIGiRpIgQIcA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+FzRYGwcFgR2BLoEChG4jHwM5f4EvdUp3LWoSF4EmghSBOgJVAwsYDUgRLDcUGQQ9AW4HjVQjgXFIBwE8UQErIAJjgSeTJUSPbIIeinaWHAoog3WMIZU6GjOFW6URC5h9jgqWUIRpgWg8gVlwFYMiCUoZD44tCwuDYIQHgQyBPcVpPDULAy8BAQcCBw4DC4FokAAsgVIBAQ IronPort-Data: A9a23:jM2g5K+TQpUTFvNdIuQiDrUD0X+TJUtcMsCJ2f8bNWPcYEJGY0x3n TEYDDqEbKuDZ2Lwc4h+bY/j9RlT7ZaAm9VlQANurS9EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsbThNs/jrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kcGbMnosNTIVtJ7 NMdEhcxb0uMv8yflefTpulE3qzPLeHxN48Z/3UlxjbDALN+HtbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZP0En1lQ/UPrSmM+ki3TleiFYr3qepLE85C7YywkZPL3FbYOOIYLXHpkM9qqej lia72PZOkgeD9yklgeorGOCgsTtwwquDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjdCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1r994cRva1fApEFI/ IronPort-HdrOrdr: A9a23:DAzHQqkbEfXD0n+sgOPXur5Duk/pDfIO3DAbv31ZSRFFG/Fw8P re+8jztCWE7Ar5N0tPpTntAsS9qDbnhP1ICOoqTNKftXfd2VdARbsKheCJ/9SjIVydygc378 hdmsZFZOEYdWIbse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAH0++8YTzranGfg2J9dOMEKK Y= X-Talos-CUID: 9a23:z3g34259Z2Lli2pG3Nss3moqJZgAVl3ny27/JnWfNWcyR4W7YArF X-Talos-MUID: 9a23:SiQB7w49lsQJ61Ff3N4cHqykxoxSv7SpKHhUla4GgJa5GHJhFTO2rmqeF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="513365341" Received: from rcdn-l-core-07.cisco.com ([173.37.255.144]) by rcdn-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:38 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-07.cisco.com (Postfix) with ESMTPS id 1585B1800022E for ; Tue, 21 Jul 2026 17:42:38 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 36EE1CC037D; Tue, 21 Jul 2026 23:12:36 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 4/8] cups: fix CVE-2026-34980 Date: Tue, 21 Jul 2026 23:12:13 +0530 Message-Id: <20260721174217.229620-4-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:48 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241562 From: Deepak Rathore Pick the upstream fix [1] for CVE-2026-34980 as mentioned in [2], where the scheduler did not filter control characters from option values. Also include the upstream regression fixes that followed the CVE fix: - CVE-2026-34980-regression_p1.patch [3] fixes filter PPD keyword processing. The CVE fix parsed PPD keywords into a temporary array, but the loop did not advance the keyword pointer. This regression was reported in OpenPrinting/cups Issue [4]. - CVE-2026-34980-regression_p2.patch [5] fixes a get_options() regression where the option-value parser did not advance the input pointer for whitespace/control-character paths. [1] https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3 [2] https://security-tracker.debian.org/tracker/CVE-2026-34980 [3] https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629 [4] https://github.com/OpenPrinting/cups/issues/1562 [5] https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the regression-p2 reference to the equivalent 2.4.x upstream commit. meta/recipes-extended/cups/cups.inc | 3 + .../cups/CVE-2026-34980-regression_p1.patch | 31 +++++++ .../cups/CVE-2026-34980-regression_p2.patch | 75 ++++++++++++++++ .../cups/cups/CVE-2026-34980.patch | 85 +++++++++++++++++++ 4 files changed, 194 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 5e272dbcf6..7a8b845953 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -25,6 +25,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447-regression_p2.patch \ file://CVE-2026-41079.patch \ file://CVE-2026-34978.patch \ + file://CVE-2026-34980.patch \ + file://CVE-2026-34980-regression_p1.patch \ + file://CVE-2026-34980-regression_p2.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch new file mode 100644 index 0000000000..483d695a93 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch @@ -0,0 +1,31 @@ +From 3f2bdc293243bca938c6de23ba50e6d783189629 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 28 Apr 2026 17:42:41 -0400 +Subject: [PATCH] Fix filter PPD keyword processing (Issue #1562) + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629] + +(cherry picked from commit 3f2bdc293243bca938c6de23ba50e6d783189629) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 895b2d9..915ba94 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -5419,7 +5419,7 @@ update_job(cupsd_job_t *job) /* I - Job to check */ + keywords = NULL; + num_keywords = cupsParseOptions(message, 0, &keywords); + +- for (i = 0, keyword = keywords; i < num_keywords; i ++) ++ for (i = 0, keyword = keywords; i < num_keywords; i ++, keyword ++) + { + /* + * Filter out "special" PPD keywords... +-- +2.43.7 + + diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch new file mode 100644 index 0000000000..739938c9a5 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch @@ -0,0 +1,75 @@ +From da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Wed, 8 Apr 2026 16:42:48 -0400 +Subject: [PATCH] Fix get_options regression (Issue #1532) + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a] + +(cherry picked from commit da0ff58c041f7ee129c3c2c72fb14df1f1e4069a) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 4 ++-- + test/5.5-lp.sh | 10 +++++----- + 2 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 6b9d366..cf019e1 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4144,7 +4144,7 @@ get_options(cupsd_job_t *job, /* I - Job */ + case IPP_TAG_CHARSET : + case IPP_TAG_LANGUAGE : + case IPP_TAG_URI : +- for (valptr = attr->values[i].string.text; *valptr;) ++ for (valptr = attr->values[i].string.text; *valptr; valptr ++) + { + /* + * Convert tabs and newlines to spaces, filter out control chars, +@@ -4159,7 +4159,7 @@ get_options(cupsd_job_t *job, /* I - Job */ + { + if (strchr("\\\'\"", *valptr)) + *optptr++ = '\\'; +- *optptr++ = *valptr++; ++ *optptr++ = *valptr; + } + } + +diff --git a/test/5.5-lp.sh b/test/5.5-lp.sh +index 25e9d65..fe60890 100644 +--- a/test/5.5-lp.sh ++++ b/test/5.5-lp.sh +@@ -2,7 +2,7 @@ + # + # Test the lp command. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2019 by Apple Inc. + # Copyright © 1997-2005 by Easy Software Products, all rights reserved. + # +@@ -72,8 +72,8 @@ echo "" + + echo "LP Flood Test ($1 times in parallel)" + echo "" +-echo " lp -d Test1 testfile.jpg" +-echo " lp -d Test2 testfile.jpg" ++echo " lp -d Test1 -t 'Flood Test N' testfile.jpg" ++echo " lp -d Test2 -t 'Flood Test N' testfile.jpg" + i=0 + pids="" + while test $i -lt $1; do +@@ -83,9 +83,9 @@ while test $i -lt $1; do + j=`expr $j + 1` + done + +- $runcups $VALGRIND ../systemv/lp -d Test1 ../examples/testfile.jpg 2>&1 & ++ $runcups $VALGRIND ../systemv/lp -d Test1 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 & + pids="$pids $!" +- $runcups $VALGRIND ../systemv/lp -d Test2 ../examples/testfile.jpg 2>&1 & ++ $runcups $VALGRIND ../systemv/lp -d Test2 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 & + pids="$pids $!" + + i=`expr $i + 1` +-- +2.43.7 diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch new file mode 100644 index 0000000000..c38cc2c9e3 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch @@ -0,0 +1,85 @@ +From e206c7643a7574cab2e9457eac4c9f755dbf44ff Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:45:13 -0400 +Subject: [PATCH] Filter out control characters from option values. + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3] + +Backport Changes: +- Rebase scheduler/job.c option-handling context to the CUPS 2.4.11 + source carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 8d0f51cac24cb5bf949c5b6a221e51a150d982e3) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 41 +++++++++++++++++++++++++++++++++++------ + 1 file changed, 35 insertions(+), 6 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 822a247..895b2d9 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4121,9 +4121,21 @@ get_options(cupsd_job_t *job, /* I - Job */ + case IPP_TAG_URI : + for (valptr = attr->values[i].string.text; *valptr;) + { +- if (strchr(" \t\n\\\'\"", *valptr)) +- *optptr++ = '\\'; +- *optptr++ = *valptr++; ++ /* ++ * Convert tabs and newlines to spaces, filter out control chars, ++ * and escape \, ', and ". ++ */ ++ ++ if (isspace(*valptr & 255)) ++ { ++ *optptr++ = ' '; ++ } ++ else if ((*valptr & 255) >= ' ' && *valptr != 0x7f) ++ { ++ if (strchr("\\\'\"", *valptr)) ++ *optptr++ = '\\'; ++ *optptr++ = *valptr++; ++ } + } + + *optptr = '\0'; +@@ -5394,13 +5409,30 @@ update_job(cupsd_job_t *job) /* I - Job to check */ + else if (loglevel == CUPSD_LOG_PPD) + { + /* +- * Set attribute(s)... ++ * Set PPD keyword(s)/value(s)... + */ + ++ int i, /* Looping var */ ++ num_keywords; /* Number of keywords */ ++ cups_option_t *keywords, /* Keywords */ ++ *keyword; /* Current keyword */ ++ + cupsdLogJob(job, CUPSD_LOG_DEBUG, "PPD: %s", message); + +- job->num_keywords = cupsParseOptions(message, job->num_keywords, +- &job->keywords); ++ keywords = NULL; ++ num_keywords = cupsParseOptions(message, 0, &keywords); ++ ++ for (i = 0, keyword = keywords; i < num_keywords; i ++) ++ { ++ /* ++ * Filter out "special" PPD keywords... ++ */ ++ ++ if (strcmp(keyword->name, "cupsFilter") && strcmp(keyword->name, "cupsFilter2") && strcmp(keyword->name, "cupsFinishingTemplate") && strcmp(keyword->name, "cupsIPPFinishings") && strcmp(keyword->name, "cupsIPPReason") && strcmp(keyword->name, "cupsMarkerName") && strcmp(keyword->name, "cupsMaxSize") && strncmp(keyword->name, "cupsMediaQualifier", 18) && strcmp(keyword->name, "cupsMinSize") && strcmp(keyword->name, "cupsPageSizeCategory") && strcmp(keyword->name, "cupsPortMonitor") && strcmp(keyword->name, "cupsPreFilter") && strcmp(keyword->name, "cupsPrintQuality") && strcmp(keyword->name, "APPrinterPreset")) ++ job->num_keywords = cupsAddOption(keyword->name, keyword->value, job->num_keywords, &job->keywords); ++ } ++ ++ cupsFreeOptions(num_keywords, keywords); + } + else + { +-- +2.43.7 From patchwork Tue Jul 21 17:42:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93067 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EACF4C4452B for ; Tue, 21 Jul 2026 17:42:47 +0000 (UTC) Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.29044.1784655765073749438 for ; Tue, 21 Jul 2026 10:42:45 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=jNEiwnPU; spf=pass (domain: cisco.com, ip: 173.37.86.76, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3588; q=dns/txt; s=iport01; t=1784655765; x=1785865365; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=1OvmNXfoge7dcFxLqoa8kim7Z7TtUmFXtWGY9Q+RYeU=; b=jNEiwnPU7ZXgyYIdhyFaxi6uJyCB+Sq941NNAhoIJlDNexR5WX2oP6ew Cdk60h8EeNCYKVC1gFM9ckTG03+bv2z8b60C6xVwiIeGeKMxJNLzT1EIS /LbkHmYUfvYsoH0kzDvbCiLg6RdtMdOQTgohLYXv9MEOvKCeIZLQbW+KI oJIjetUN4fTtd4Vlu3wEg2XwF9G/JRf9rMrO55WIf15ZZXvvEPV2p39ez EJPhH34JmFPIgjwzeYKPWqbzyKuWJK2Rhlzytz8CtBExp9ySxP2O/BYh6 D2dA80iNlVdrPDxMDrzwR+ywxtCfVuSSMfut4jJmT8sKDjpZ0q2NXpp4t Q==; X-CSE-ConnectionGUID: 7y0CsWR3TSGiLgBb47TS2w== X-CSE-MsgGUID: 3OqQxumPTSCZa/DYGbIBIw== X-IPAS-Result: A0BIAgD/rl9q/4v/Ja1aglmCV3RfQkkDlCaCIQOBE50IgX4PAQEBD0QNBAEBhQUCjVcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMnCwE0IhwDAQIvKyMIEQiDAgGCdAMRv34aN4F5M4EBg2gCQ1DbLgELFAGBOIU/iCBcGAGEfCcbG4FygRWCc3aBBYFcAoglBIIigQyBWhgGhG+CBokaSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EMGwcFgR2BLoEChG4jHwM5f4EvdUp3LWoSF4EmghSBOgJVAwsYDUgRLDcUGQQ+bgeNVCOCOQctEEIPASuCLJMlGpI0oRIKKIN1jCGVOhozhVulEQuYfY4KlgBQhGmBaDyBWXAVgyIJShkPjjiDa4QHgQzHJjw1CwMvAQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:WVNdrK9LqJjwCL5I8Qj3DrUD0X+TJUtcMsCJ2f8bNWPcYEJGY0x3z GcfWjyEMvyOM2vxeI1+adm1oB5Q7cOGyYIwHlRrqytEQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsbThNs/jrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2lpLNUz4dlNWl112 v08JxoHMk+/vLiplefTpulE3qzPLeHxN48Z/3UlxjbDALN+G9bIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZOEwn1lQ/UPrSmM+ki3TleiFYr3qepLE85C7YywkZPL3FbYOOJIbRHpgJ9qqej jnh5l3pHxQiCOe0+zPC3kODjM7lvDyuDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjJCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1rd94cRva1fApEFI/ IronPort-HdrOrdr: A9a23:bpUn7KpNBwtAoVpttmgOWOUaV5oHeYIsimQD101hICG9Ffbo8/ xG88506faZslsssTQb6LO90cq7MBbhHOBOgLX5VI3KNGKNhILrFvAB0WKI+VLd8kPFmtK1rZ 0BT4FOTPvtEFN9kcH2pCO8E9om3Z271ZrAv5a485+oJjsaEp2JKGxCe2CmLnE= X-Talos-CUID: 9a23:XFqMumtTQIoAGNw2Fa3XU5to6It6YyX210jqeHODJmdNR5efFQCsw/l7xp8= X-Talos-MUID: 9a23:+yviRwYVXZYTx+BT7Bj1vSF/Mf9U2I+cAQchoLoMmuOlKnkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="513623354" Received: from rcdn-l-core-02.cisco.com ([173.37.255.139]) by rcdn-iport-5.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:42 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-02.cisco.com (Postfix) with ESMTPS id 3310018000200 for ; Tue, 21 Jul 2026 17:42:42 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 537D0CC037D; Tue, 21 Jul 2026 23:12:40 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 5/8] cups: fix CVE-2026-34979 Date: Tue, 21 Jul 2026 23:12:14 +0530 Message-Id: <20260721174217.229620-5-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-02.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241563 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214 [2] https://security-tracker.debian.org/tracker/CVE-2026-34979 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34979.patch | 61 +++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 7a8b845953..a0ac1a2612 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980.patch \ file://CVE-2026-34980-regression_p1.patch \ file://CVE-2026-34980-regression_p2.patch \ + file://CVE-2026-34979.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34979.patch b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch new file mode 100644 index 0000000000..38ac7b6e91 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch @@ -0,0 +1,61 @@ +From 471b4dc802455c7c59f9fd594fec8b6f3acb0db5 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:50:06 -0400 +Subject: [PATCH] Expand allocation of options string. + +CVE: CVE-2026-34979 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214] + +Backport Changes: +- Rebase scheduler/job.c IPP length context to the CUPS 2.4.11 source + carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 0ff8897367c7341f2500770c3977038cdd7c0214) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 16 ++++------------ + 1 file changed, 4 insertions(+), 12 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 915ba94..880c25f 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4195,18 +4195,6 @@ ipp_length(ipp_t *ipp) /* I - IPP request */ + + for (attr = ipp->attrs; attr != NULL; attr = attr->next) + { +- /* +- * Skip attributes that won't be sent to filters... +- */ +- +- if (attr->value_tag == IPP_TAG_NOVALUE || +- attr->value_tag == IPP_TAG_MIMETYPE || +- attr->value_tag == IPP_TAG_NAMELANG || +- attr->value_tag == IPP_TAG_TEXTLANG || +- attr->value_tag == IPP_TAG_URI || +- attr->value_tag == IPP_TAG_URISCHEME) +- continue; +- + /* + * Add space for a leading space and commas between each value. + * For the first attribute, the leading space isn't used, so the +@@ -4282,10 +4270,14 @@ ipp_length(ipp_t *ipp) /* I - IPP request */ + + case IPP_TAG_TEXT : + case IPP_TAG_NAME : ++ case IPP_TAG_TEXTLANG : ++ case IPP_TAG_NAMELANG : ++ case IPP_TAG_MIMETYPE : + case IPP_TAG_KEYWORD : + case IPP_TAG_CHARSET : + case IPP_TAG_LANGUAGE : + case IPP_TAG_URI : ++ case IPP_TAG_URISCHEME : + /* + * Strings can contain characters that need quoting. We need + * at least 2 * len + 2 characters to cover the quotes and +-- +2.43.7 + From patchwork Tue Jul 21 17:42:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93068 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27B98C4451C for ; Tue, 21 Jul 2026 17:42:48 +0000 (UTC) Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.29045.1784655765919296911 for ; Tue, 21 Jul 2026 10:42:46 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=GERFCnHw; spf=pass (domain: cisco.com, ip: 173.37.86.80, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14348; q=dns/txt; s=iport01; t=1784655765; x=1785865365; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=4dFuVj4L/qGsQ5JdbLDeph/fGoPSsD69/HoLW+rii2o=; b=GERFCnHw8gsJW6/cpu74SYhF5Fzk3LxVLP+a0DDI/GpMwfiT3PIgohgb pzQtT366bY2ESBRRkvBbeGux6AqmajixUCXSSvxfuOqAyuodFRPu0l8bw oYiL6HOT6lLnltleFGWjcVzBLsrrhONMkhFQ9DIBfAef05zD677xBf8mr 5Y803hwypDXaNrYRgGUnXbEN6uy6FCJ0h/lXWMqxJ4Em9wQOGVQEssmjp plBwgo1MZ0tqrbp4ojfyaFlDKKJ0JJTPZbSHXEuxknMpjfqZ+z94VmQ4J 3brRNpmSYvoangt/JY38VSFQzEbBE5dj6loiBdd1F3jbcHUzkIzSh5dyp g==; X-CSE-ConnectionGUID: T4JGvNv+Q6qqNAvXzF6n/w== X-CSE-MsgGUID: z5ZemjI1RiyXf9hfFUc1Bw== X-IPAS-Result: A0AnAAAVrl9q/4v/Ja1aHQEBAQEJARIBBQUBgXwIAQsBglZ0X0JJA4RUiBuHN4IhA4ETkDeMURSBag8BAQEPRA0EAQGCEoJzAo1XAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDIwQLATQiHAIBAQIDAhQSAgIrIwgRCIMCAYJ0AxGoeZcXGjd6fzOBAYNoAkNQ2y4BCxQBgQouAYU+gx0BhQJcGAGEfCcbG4FygRWCc3aBBYFcAoEYCyVogwuCagSCIoEMgVoYBoRvggaJGkiBAhwDWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XNFgbBwWBHYEugQKEbiMfAzl/gS91SnctahIXgSaCFIE6AlUDCxgNSBEsNxQZBD0BbgeNVCOBcRc2Aj0cASETASoBgQUMPDYpEQwBHBGSWgkKByqSCoE4n1oKKIN1jCGVOhozhVulEQuYfY4KlTQCMhhQhGmBaDyBWXAVgyIJShkPji0LC4NghAeBDIE9xWk8NQcEAy8BAQcCBw4DC4FokAIPFQIHgU8BAQ IronPort-Data: A9a23:Rk8hgatNNr/cv+G4lW8TBTf4vufnVAdfMUV32f8akzHdYApBsoF/q tZmKWuPM/bfMGX1eNkgPtyz8E5TsZeBmoU2SAVkqSAzFi4RgMeUXt7xwmUckM+xwmwvaGo9s q3yv/GZdJhcokf0/0nrav666yEgiclkf5KkYMbcICd9WAR4fykojBNnioYRj5Vh6TSDK1vlV eja/YuFZTdJ5xYuajhKs/3Z8Us11BjPkGpwUmIWNKgjUGD2zxH5PLpHTYmtIn3xRJVjH+LSb 47r0LGj82rFyAwmA9Wjn6yTWhVirmn6ZFXmZtJ+AsBOszAazsAA+v9T2Mk0NS+7vw60c+VZk 72hg3AfpTABZcUgkMxFO/VR/roX0aduoNcrKlDn2SCfItGvn3bEm51T4E8K0YIwxrpVLn9o6 78hdikUSDmdt/CYnrT8Vbw57igjBJGD0II3oHpsy3TdSP0hW52GG/+M7t5D1zB2jcdLdRrcT 5NGMnw0M1KaPkAJYwxGYH49tL/Aan3XfzBVsluJpa0f6GnIxws327/oWDbQUoHTH5kEzxvJ/ goq+UzrXyMXMd6+kACE40Ki1+/Bsx7wAagNQejQGvlCxQf7KnYoIBoOWF22pPO0hkKzV5dUL FYZ0i4vtrQpskuzQ9/wWhe1rHKJslgbQdU4LgEhwBuGxqyR50OSAXIJC2YbLtcnr8QxAzct0 zdlgu/UONCmi5XNIVr1y1tehWra1fQ9RYPaWRI5cA== IronPort-HdrOrdr: A9a23:duMewKh3WAxXWiLEToUoRlh1l3BQXvgji2hC6mlwRA09TyX+rb HIoB17726RtN9/Yh8dcLy7VZVoBEmslqKdgrNhWItKIjOGhILAFugLhuHfKn/bak/DH4Vmup uIHZITNDSJNzhHpPe/xhWkGNA9x9TC2qWpieDCi0pJd2hRGsddB8MTMHfiLqWwLzM2fKYEKA == X-Talos-CUID: 9a23:GBlFZmOeTdTgnO5DZHVF21AyBIMcLGTE6l7OE12WV2AuV+jA X-Talos-MUID: 9a23:Pt2q9gYodIEGB+BTpWLeiTRgFZ5S4rWeBhENn7s7sJCuKnkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="512499590" Received: from rcdn-l-core-02.cisco.com ([173.37.255.139]) by rcdn-iport-9.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:44 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-02.cisco.com (Postfix) with ESMTPS id 52D2518000200 for ; Tue, 21 Jul 2026 17:42:44 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 6FC94CBEFAA; Tue, 21 Jul 2026 23:12:42 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 6/8] cups: fix CVE-2026-34990 Date: Tue, 21 Jul 2026 23:12:15 +0530 Message-Id: <20260721174217.229620-6-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-02.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:48 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241564 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356 [2] https://security-tracker.debian.org/tracker/CVE-2026-34990 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34990.patch | 351 ++++++++++++++++++ 2 files changed, 352 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index a0ac1a2612..1cef1e71fe 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -29,6 +29,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980-regression_p1.patch \ file://CVE-2026-34980-regression_p2.patch \ file://CVE-2026-34979.patch \ + file://CVE-2026-34990.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34990.patch b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch new file mode 100644 index 0000000000..0a8c093065 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch @@ -0,0 +1,351 @@ +From 48648896ca7faa8f105eee7b7a8d86c42e0fa796 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 15:55:50 -0400 +Subject: [PATCH] Don't allow local certificates over the loopback + interface, drop support for writing to plain files. + +CVE: CVE-2026-34990 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356] + +Backport Changes: +- Preserve the existing CVE-2025-61915 PeerCred disable guard while changing + localhost checks to AF_LOCAL. +- Keep the CUPS 2.4.11 empty device-uri validation path separate and add a + dedicated rejection for non-IPP/IPPS schemes instead of folding both checks + into one upstream condition. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit e052dc44da9d12adfbebc51de4975fbadb2ce356) +Signed-off-by: Deepak Rathore +--- + cups/auth.c | 30 ++++++-------------------- + scheduler/auth.c | 9 ++++---- + scheduler/client.c | 4 +-- + scheduler/ipp.c | 8 ++++++- + scheduler/job.c | 46 ++++++++++++++++++++++------------------- + test/4.2-cups-printer-ops.test | 6 ++--- + test/5.1-lpadmin.sh | 14 ++++++------ + 7 files changed, 56 insertions(+), 61 deletions(-) + +diff --git a/cups/auth.c b/cups/auth.c +index 5cb4194..14661c7 100644 +--- a/cups/auth.c ++++ b/cups/auth.c +@@ -1,7 +1,7 @@ + /* + * Authentication functions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 1997-2007 by Easy Software Products. + * +@@ -92,7 +92,6 @@ static void cups_gss_printf(OM_uint32 major_status, OM_uint32 minor_status, + # define cups_gss_printf(major, minor, message) + # endif /* DEBUG */ + #endif /* HAVE_GSSAPI */ +-static int cups_is_local_connection(http_t *http); + static int cups_local_auth(http_t *http); + + +@@ -948,14 +947,6 @@ cups_gss_printf(OM_uint32 major_status,/* I - Major status code */ + # endif /* DEBUG */ + #endif /* HAVE_GSSAPI */ + +-static int /* O - 0 if not a local connection */ +- /* 1 if local connection */ +-cups_is_local_connection(http_t *http) /* I - HTTP connection to server */ +-{ +- if (!httpAddrLocalhost(http->hostaddr) && _cups_strcasecmp(http->hostname, "localhost") != 0) +- return 0; +- return 1; +-} + + /* + * 'cups_local_auth()' - Get the local authorization certificate if +@@ -967,13 +958,7 @@ static int /* O - 0 if available */ + /* -1 error */ + cups_local_auth(http_t *http) /* I - HTTP connection to server */ + { +-#if defined(_WIN32) || defined(__EMX__) +- /* +- * Currently _WIN32 and OS-2 do not support the CUPS server... +- */ +- +- return (1); +-#else ++#if !_WIN32 && !__EMX__ && defined(AF_LOCAL) + int pid; /* Current process ID */ + FILE *fp; /* Certificate file */ + char trc[16], /* Try Root Certificate parameter */ +@@ -998,7 +983,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + * See if we are accessing localhost... + */ + +- if (!cups_is_local_connection(http)) ++ if (httpAddrFamily(httpGetAddress(http)) != AF_LOCAL) + { + DEBUG_puts("8cups_local_auth: Not a local connection!"); + return (1); +@@ -1072,15 +1057,14 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + } + # endif /* HAVE_AUTHORIZATION_H */ + +-# if defined(SO_PEERCRED) && defined(AF_LOCAL) ++# ifdef SO_PEERCRED + /* + * See if we can authenticate using the peer credentials provided over a + * domain socket; if so, specify "PeerCred username" as the authentication + * information... + */ + +- if (http->hostaddr->addr.sa_family == AF_LOCAL && +- !getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */ ++ if (!getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */ + cups_auth_find(www_auth, "PeerCred")) + { + /* +@@ -1104,7 +1088,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + return (0); + } + } +-# endif /* SO_PEERCRED && AF_LOCAL */ ++# endif /* SO_PEERCRED */ + + if ((schemedata = cups_auth_find(www_auth, "Local")) == NULL) + return (1); +@@ -1164,7 +1148,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + return (0); + } + } ++#endif /* !_WIN32 && !__EMX__ && AF_LOCAL */ + + return (1); +-#endif /* _WIN32 || __EMX__ */ + } +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 1dd520d..56855fc 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -318,7 +318,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + } + #ifdef HAVE_AUTHORIZATION_H + else if (!strncmp(authorization, "AuthRef ", 8) && +- httpAddrLocalhost(httpGetAddress(con->http))) ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + OSStatus status; /* Status */ + char authdata[HTTP_MAX_VALUE]; +@@ -399,7 +399,8 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + #endif /* HAVE_AUTHORIZATION_H */ + #if defined(SO_PEERCRED) && defined(AF_LOCAL) +- else if (PeerCred != CUPSD_PEERCRED_OFF && !strncmp(authorization, "PeerCred ", 9) && +- con->http->hostaddr->addr.sa_family == AF_LOCAL && con->best) ++ else if (PeerCred != CUPSD_PEERCRED_OFF && ++ !strncmp(authorization, "PeerCred ", 9) && ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL && con->best) + { + /* + * Use peer credentials from domain socket connection... +@@ -483,7 +483,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + } + #endif /* SO_PEERCRED && AF_LOCAL */ + else if (!strncmp(authorization, "Local", 5) && +- httpAddrLocalhost(httpGetAddress(con->http))) ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + /* + * Get Local certificate authentication data... +diff --git a/scheduler/client.c b/scheduler/client.c +index 779404c..dea9da0 100644 +--- a/scheduler/client.c ++++ b/scheduler/client.c +@@ -2173,7 +2173,7 @@ cupsdSendHeader( + strlcpy(auth_str, "Negotiate", sizeof(auth_str)); + } + +- if (con->best && !con->is_browser && !_cups_strcasecmp(httpGetHostname(con->http, NULL, 0), "localhost")) ++ if (con->best && !con->is_browser && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + /* + * Add a "trc" (try root certification) parameter for local +@@ -2193,7 +2193,7 @@ cupsdSendHeader( + auth_size = sizeof(auth_str) - (size_t)(auth_key - auth_str); + + #if defined(SO_PEERCRED) && defined(AF_LOCAL) +- if (PeerCred != CUPSD_PEERCRED_OFF && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) ++ if (PeerCred != CUPSD_PEERCRED_OFF) + { + strlcpy(auth_key, ", PeerCred", auth_size); + auth_key += 10; +diff --git a/scheduler/ipp.c b/scheduler/ipp.c +index b0d1f5b..11dcd39 100644 +--- a/scheduler/ipp.c ++++ b/scheduler/ipp.c +@@ -5561,7 +5561,7 @@ create_local_printer( + * Require local access to create a local printer... + */ + +- if (!httpAddrLocalhost(httpGetAddress(con->http))) ++ if (httpAddrFamily(httpGetAddress(con->http)) != AF_LOCAL) + { + send_ipp_status(con, IPP_STATUS_ERROR_FORBIDDEN, _("Only local users can create a local printer.")); + return; +@@ -5634,6 +5634,12 @@ create_local_printer( + + return; + } ++ else if (strncmp(ptr, "ipp://", 6) && strncmp(ptr, "ipps://", 7)) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad device-uri \"%s\"."), ptr); ++ ++ return; ++ } + + printer_geo_location = ippFindAttribute(con->request, "printer-geo-location", IPP_TAG_URI); + printer_info = ippFindAttribute(con->request, "printer-info", IPP_TAG_TEXT); +diff --git a/scheduler/job.c b/scheduler/job.c +index 880c25f..6c033de 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -1164,35 +1164,39 @@ cupsdContinueJob(cupsd_job_t *job) /* I - Job */ + } + else + { ++ char scheme[32], /* URI scheme */ ++ userpass[32], /* URI username:password */ ++ host[256], /* URI hostname */ ++ resource[1024]; /* URI resource path (filename) */ ++ int port; /* URI port number */ ++ ++ httpSeparateURI(HTTP_URI_CODING_ALL, job->printer->device_uri, scheme, sizeof(scheme), userpass, sizeof(userpass), host, sizeof(host), &port, resource, sizeof(resource)); ++ + job->print_pipes[0] = -1; +- if (!strcmp(job->printer->device_uri, "file:/dev/null") || +- !strcmp(job->printer->device_uri, "file:///dev/null")) +- job->print_pipes[1] = -1; +- else ++ job->print_pipes[1] = -1; ++ ++ if (strcmp(resource, "/dev/null")) + { +- if (!strncmp(job->printer->device_uri, "file:/dev/", 10)) +- job->print_pipes[1] = open(job->printer->device_uri + 5, +- O_WRONLY | O_EXCL); +- else if (!strncmp(job->printer->device_uri, "file:///dev/", 12)) +- job->print_pipes[1] = open(job->printer->device_uri + 7, +- O_WRONLY | O_EXCL); +- else if (!strncmp(job->printer->device_uri, "file:///", 8)) +- job->print_pipes[1] = open(job->printer->device_uri + 7, +- O_WRONLY | O_CREAT | O_TRUNC, 0600); +- else +- job->print_pipes[1] = open(job->printer->device_uri + 5, +- O_WRONLY | O_CREAT | O_TRUNC, 0600); ++ if (!FileDevice) ++ { ++ abort_message = "Stopping job because file: output is disabled."; + +- if (job->print_pipes[1] < 0) ++ goto abort_job; ++ } ++ else if ((job->print_pipes[1] = open(resource, O_WRONLY | O_EXCL)) < 0) + { +- abort_message = "Stopping job because the scheduler could not " +- "open the output file."; ++ abort_message = "Stopping job because the scheduler could not open the output file."; + + goto abort_job; + } ++ else ++ { ++ /* ++ * Close this file on execute... ++ */ + +- fcntl(job->print_pipes[1], F_SETFD, +- fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC); ++ fcntl(job->print_pipes[1], F_SETFD, fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC); ++ } + } + } + } +diff --git a/test/4.2-cups-printer-ops.test b/test/4.2-cups-printer-ops.test +index 1a011e0..945a9bb 100644 +--- a/test/4.2-cups-printer-ops.test ++++ b/test/4.2-cups-printer-ops.test +@@ -1,7 +1,7 @@ + # + # Verify that the CUPS printer operations work. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2019 by Apple Inc. + # Copyright © 2001-2006 by Easy Software Products. All rights reserved. + # +@@ -180,7 +180,7 @@ + ATTR uri printer-uri $method://$hostname:$port/printers/Test2 + + GROUP printer +- ATTR uri device-uri file:/tmp/Test2 ++ ATTR uri device-uri file:///dev/null + ATTR enum printer-state 3 + ATTR boolean printer-is-accepting-jobs true + +@@ -206,7 +206,7 @@ + ATTR uri printer-uri $method://$hostname:$port/printers/Test1 + + GROUP printer +- ATTR uri device-uri file:/tmp/Test1 ++ ATTR uri device-uri file:///dev/null + ATTR enum printer-state 3 + ATTR boolean printer-is-accepting-jobs true + ATTR text printer-info "Test Printer 1" +diff --git a/test/5.1-lpadmin.sh b/test/5.1-lpadmin.sh +index aa39800..36f2822 100644 +--- a/test/5.1-lpadmin.sh ++++ b/test/5.1-lpadmin.sh +@@ -2,7 +2,7 @@ + # + # Test the lpadmin command. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2018 by Apple Inc. + # Copyright © 1997-2005 by Easy Software Products, all rights reserved. + # +@@ -12,8 +12,8 @@ + + echo "Add Printer Test" + echo "" +-echo " lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd" +-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1 ++echo " lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd" ++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +@@ -29,8 +29,8 @@ echo "" + + echo "Modify Printer Test" + echo "" +-echo " lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4" +-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4 2>&1 ++echo " lpadmin -p Test3 -v file:///dev/null -o PageSize=A4" ++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -o PageSize=A4 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +@@ -65,8 +65,8 @@ echo "" + + echo "Add a printer for cupSNMP/IPPSupplies test" + echo "" +-echo " lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd" +-$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd 2>&1 ++echo " lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd" ++$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +-- +2.43.7 From patchwork Tue Jul 21 17:42:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93069 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67C5FC44536 for ; Tue, 21 Jul 2026 17:42:48 +0000 (UTC) Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.29029.1784655767761020105 for ; Tue, 21 Jul 2026 10:42:47 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=JZeOdTWv; spf=pass (domain: cisco.com, ip: 173.37.86.77, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3144; q=dns/txt; s=iport01; t=1784655767; x=1785865367; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=UdTF08qPa//LT7srbfR7kRrnQQWD4jRXXmqXSE5A5go=; b=JZeOdTWv9hPVT1bs0IxWaQNpswrjn7NB8TpyQi6/+W0XYINJsVCtU10W d8j3QuygIxKn+Nawez+T2MfXuN3acD3eFub1jjvDVIVGTPdQXs4LN95nR wYEkdXvl7ngWfUpfIRHU8oaAghDc5IeqQ0R6/4By63qf5FWRaRTm1O/Db 3MaCo+2IHn3IpvO0nYuyDZTURLPiSEApvgeyh4+0RB0TJThkjR8zz04tF JPoU7dtCGX6dPVhiEOMakdrNmDZS340KSzL8UtB+VQ7ObuJE4Aa09yKOG AuY39Tuk4uKhyD28e3uqPU/dRX+W4SWvsCcr5j4dbXMJYM/j45d5UbRDK g==; X-CSE-ConnectionGUID: fbqEEhZZRvmUJdpUHkTYgQ== X-CSE-MsgGUID: VVCiEqm2SMGfRbRH58S+4A== X-IPAS-Result: A0BLAgD/rl9q/5T/Ja1aglmCV3RfQkkDhFSPUoIhA4ETnQgUgWoPAQEBD0QNBAEBhQUCjVcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMjDwE0IhwDAQIDAhQSAgIrIwgRCIMCAYJ0AxGoZ5cXGjd6gTKBAYNoAkNQ2y4BCxQBgQouhT+DHQGFAlwYAYR8JxsbgXKBFYJzdoEFgVwCgSOBDYMLgmoEgiKBDIFaGAaEb4IGg2+FK0iBAhwDWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XNFgbBwWBHYEugQKEbiMfAzl/gS91SnctahIXgSaCFIE6AlUDCxgNSBEsNxQZBD0BbgeNVCOBcU8BPFEBK4IskyWSTqESCiiDdYwhlToaM4VbnWGHMAuYfY4KllCEaYFoPIFZcBWDIglKGQ+OOINrhAeBDMcmPDULAy8BAQcCBw4DC4FokCaBWAEB IronPort-Data: A9a23:ymcYDaOwJSICdXzvrR30lsFynXyQoLVcMsEvi/4bfWQNrUok0jNSy zQeX2CPa6mMZWH9KIgibNvi8U0GuJ6AyYVhG3M5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf6gWcsaAr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj6/tkFWwbPb8qwPhyPENC7 cE4Kww8YSnW0opawJrjIgVtrt4oIM+uOMYUvWttiGiAS/0nWpvEBa7N4Le03h9p2ZsIRqmYP ZdEL2MzPHwsYDUXUrsTIJ4zkf2hmnn4WzZZs1mS46Ew5gA/ySQsieO2boeOJYTiqcN9oHizp 0/f+j7CJz4UDtal6WfVyTHwr7qa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++NukCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXPIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:6ByGm6ilH+JcNxIRSUEMPtHGNHBQXvgji2hC6mlwRA09TyX+rb HIoB17726RtN9/Yh8dcLy7VZVoBEmslqKdgrNhWItKIjOGhILAFugLhuHfKn/bak/DH4Vmup uIHZITNDSJNzhHpPe/xhWkGNA9x9TC2qWpieDCi0pJd2hRGsddB8MTMHfiLqWwLzM2fKYEKA == X-Talos-CUID: 9a23:b5xyuWq5zfGPINcb8lf0ZNfmUc4va1DwzEXiGVG9NERlUIC1SmOh95oxxg== X-Talos-MUID: 9a23:E6USIwzNPg7c8d21ZV0gmPuPd1yaqJqQI0EgiJBcgOyrOxZ6ARfA3A/0HqZyfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="513365370" Received: from rcdn-l-core-11.cisco.com ([173.37.255.148]) by rcdn-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:46 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-11.cisco.com (Postfix) with ESMTPS id 8F7F51800014A for ; Tue, 21 Jul 2026 17:42:46 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id B1867CC037D; Tue, 21 Jul 2026 23:12:44 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 7/8] cups: fix CVE-2026-39314 Date: Tue, 21 Jul 2026 23:12:16 +0530 Message-Id: <20260721174217.229620-7-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-11.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:48 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241565 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4 [2] https://security-tracker.debian.org/tracker/CVE-2026-39314 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-39314.patch | 45 +++++++++++++++++++ 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 1cef1e71fe..575dbf9c57 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -30,6 +30,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980-regression_p2.patch \ file://CVE-2026-34979.patch \ file://CVE-2026-34990.patch \ + file://CVE-2026-39314.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39314.patch b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch new file mode 100644 index 0000000000..f8d1a69f56 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch @@ -0,0 +1,45 @@ +From 65c463ada188915d6700d92ce48a9a14949ca413 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Sun, 5 Apr 2026 10:45:25 -0400 +Subject: [PATCH] Range check job-password-supported. + +CVE: CVE-2026-39314 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4] + +Backport Changes: +- Rebase cups/ppd-cache.c context to the CUPS 2.4.11 source carried by + this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 928a86b1b794f738f0a3dc87561b2e054bff7ce4) +Signed-off-by: Deepak Rathore +--- + cups/ppd-cache.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/cups/ppd-cache.c b/cups/ppd-cache.c +index e750fcc..08e0db8 100644 +--- a/cups/ppd-cache.c ++++ b/cups/ppd-cache.c +@@ -1,7 +1,7 @@ + /* + * PPD cache implementation for CUPS. + * +- * Copyright © 2022-2024 by OpenPrinting. ++ * Copyright © 2022-2026 by OpenPrinting. + * Copyright © 2010-2021 by Apple Inc. + * + * Licensed under Apache License v2.0. See the file "LICENSE" for more +@@ -3432,7 +3432,7 @@ _ppdCreateFromIPP2( + * Password/PIN printing... + */ + +- if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL) ++ if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL && ippGetInteger(attr, 0) > 0) + { + char pattern[33]; /* Password pattern */ + int maxlen = ippGetInteger(attr, 0); +-- +2.43.7 + From patchwork Tue Jul 21 17:42:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93075 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 50139C4451C for ; Tue, 21 Jul 2026 17:42:58 +0000 (UTC) Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.29034.1784655770118670418 for ; Tue, 21 Jul 2026 10:42:50 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=TRPhNRs9; spf=pass (domain: cisco.com, ip: 173.37.86.78, mailfrom: deeratho@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2781; q=dns/txt; s=iport01; t=1784655770; x=1785865370; h=from:to:subject:date:message-id:in-reply-to:references: mime-version:content-transfer-encoding; bh=mwFg5EfugCKNkA183oA04Y2VflF7RVNm9yPLw/0bnIM=; b=TRPhNRs9gUmdQJ5I0nGmFMfscD43y+Uil87l0FKW23q5ZE/67qlULZrS 0m0jx1pbC14+5d5SEGleOPlgMQAvtCtiAhdk35N5ahevtCzXBn6yj+nWf fWsxcNM15W1TXddc04jP63tKD45XdYlfZpRHFkxX4bxR+jGKutpTwk/nB ek5hxow8rQomiKZeW87Mc9Ij5uqdE0QYxX4AWPspfVW4taEZRyoBSf4fa BFooGG+giqlVkAIlf9GgGZKbaeXSW6G3ec88gP2YCOKN8hAa6gq88hUgP gxGuKdRoULCjdnasMNXUWNW1aS8xkm5XeTeb0ZRZGPklwFigdbzLloIbH w==; X-CSE-ConnectionGUID: 3SICc0PoQYuvmg3w9EjOmA== X-CSE-MsgGUID: OpJE5NmQRHaOrTFfK4QjKA== X-IPAS-Result: A0BIAgCXrl9q/47/Ja1aglmCV3RfQkkDlCaCIQOBE50IgX4PAQEBD0QNBAEBhQUCjVcCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMyATQiHAMBAi8rIwgRCIMCAYJ0AxHAEBo3giyBAYNoAkNQ2y4BCxQBgTiFP4ggXBgBhHwnGxuBcoEVgnN2gQWBXAKCLYV4BIIigQyBWhgGgXaCeYIGiRpIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQwbBwWBHYEugQKEbiMfAzl/gS91SnctahIXgSaCFIE6AlUDCxgNSBEsNxQZBD5uB41UI4JAPQ1EASuBfS+TJZJOoRIKKIN1jCGVOhozhASBV6URC5h9glmLMZZQhGmBaDyBWXAVO4JnCUoZD444g2uEB4EMxyY8NQsDLwEBBwIHDgMLgWiRHmABAQ IronPort-Data: A9a23:bmGzYqgEYB31ESVHf0AAZvY5X161MREKZh0ujC45NGQN5FlHY01je htvUWiCbvneN2GgeIsiO42+8B8DvJbSm9VmHFBspCAzECpjpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+FH1dOOn9SUgvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZeCULOZ82QsaDxMtPja8EkHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqVDwcdcCjl28 sUpNS4IYUuc1s+057eSH7wEasQLdKEHPasFsX1miDWcBvE8TNWbHuPB5MRT23E7gcUm8fT2P pVCL2EwKk6dPlsWZg1/5JEWxI9EglHzfjBCoU6VooI84nPYy0p6172F3N/9J4XQG5sJwR7Cz o7A10PhIDxHEtmm8xqM1WiQqOHswRr5e6tHQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS8gqBzO/Qpg2eHGVBFmMHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289Fte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:pKP2kaz6+zWIQkY3TIdRKrPwAL1zdoMgy1knxilNoHtuA6ilfq +V8sjzuSWYtN9VYgBCpTniAtjkfZqjz/9ICOAqVN/INjUO+lHYTr2KhrGM/9SPIUHDH5ZmtZ tIQuxZFMD6C0R8gILR5Qm1FMtl/fy8mZrY4ts3CxxWPHhXg2YK1XYeNjqm X-Talos-CUID: 9a23:2FUXwGAiEXpezev6E3Jc1WUfQvgiS0zA0nLfeFDpJGROTZTAHA== X-Talos-MUID: 9a23:II6r4AWtUml0Fnfq/Bj0phw/EsJR2YSnL1oxv5sl5/CGFgUlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,177,1779148800"; d="scan'208";a="512664702" Received: from rcdn-l-core-05.cisco.com ([173.37.255.142]) by rcdn-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 21 Jul 2026 17:42:49 +0000 Received: from bgl-ads-3413.cisco.com (bgl-ads-3413.cisco.com [173.39.60.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-05.cisco.com (Postfix) with ESMTPS id 09B5318000201 for ; Tue, 21 Jul 2026 17:42:49 +0000 (GMT) Received: by bgl-ads-3413.cisco.com (Postfix, from userid 1795984) id 2D89ACC037D; Tue, 21 Jul 2026 23:12:47 +0530 (IST) From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap][PATCH v2 8/8] cups: fix CVE-2026-39316 Date: Tue, 21 Jul 2026 23:12:17 +0530 Message-Id: <20260721174217.229620-8-deeratho@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260721174217.229620-1-deeratho@cisco.com> References: <20260721174217.229620-1-deeratho@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: VERIFIED;bgl-ads-3413.cisco.com [173.39.60.50];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 173.39.60.50, bgl-ads-3413.cisco.com X-Outbound-Node: rcdn-l-core-05.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 21 Jul 2026 17:42:58 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241566 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f [2] https://security-tracker.debian.org/tracker/CVE-2026-39316 Signed-off-by: Deepak Rathore --- Changes in v2: - Rebased the patch on current Scarthgap CUPS recipe context. - Refreshed the embedded source patch context; no CVE logic changes. meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-39316.patch | 40 +++++++++++++++++++ 2 files changed, 41 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 575dbf9c57..4c158aaee1 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -31,6 +31,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34979.patch \ file://CVE-2026-34990.patch \ file://CVE-2026-39314.patch \ + file://CVE-2026-39316.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39316.patch b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch new file mode 100644 index 0000000000..d3c9edf974 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch @@ -0,0 +1,40 @@ +From 7c4d7951d189e931563f21086196d5a55fb2fa15 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Sun, 5 Apr 2026 11:33:23 -0400 +Subject: [PATCH] Expire per-printer subscriptions before deleting. + +CVE: CVE-2026-39316 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f] + +Backport Changes: +- Rebase scheduler/printers.c delete-printer context to the CUPS 2.4.11 + source carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f) +Signed-off-by: Deepak Rathore +--- + scheduler/printers.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/scheduler/printers.c b/scheduler/printers.c +index bf493a3..ca983f9 100644 +--- a/scheduler/printers.c ++++ b/scheduler/printers.c +@@ -641,6 +641,12 @@ cupsdDeletePrinter( + update ? "Job stopped due to printer being deleted." : + "Job stopped."); + ++ /* ++ * Expire subscriptions on the printer... ++ */ ++ ++ cupsdExpireSubscriptions(p, /*job*/NULL); ++ + /* + * Remove the printer from the list... + */ +-- +2.43.7 +