From patchwork Wed Jul 22 17:23:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93257 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3409CC531D0 for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5511.1784741039893629804 for ; Wed, 22 Jul 2026 10:24:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rsCKdJ8g; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4954d383e64so31688725e9.1 for ; Wed, 22 Jul 2026 10:23:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741038; x=1785345838; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=c0PsVqqa5OCF92Yg8rcmiRnrQCytNTQvBWB/iI2jDns=; b=rsCKdJ8gDhy9o5yvD5E1/ILiGx+x6m/Ahuxp8BisV3cTXBVKt617PBbVi4lkgc1M5F SPSTMOPelo2B4O/PT0DWd7WhExkrKiKlcjA3QagnUGI3pUrGort9Xm93hq74132t6tUW Smy5WYTJVe0GpZBo2c0wg04/U/NvsUj2PGM1Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741038; x=1785345838; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=c0PsVqqa5OCF92Yg8rcmiRnrQCytNTQvBWB/iI2jDns=; b=MATmMSh/FsHqVBEriBCChtSSEr1TTVBnTRug9AwsmiXGDRPYFRa0JYt2P7cqiZWnsG msWIPr/xEEAZMwCU4VmJSU/GJn5WIvMehhV6FFILPSpu93hK2pMWAxx0UMJvv7PA53pC OCOicbe6P43YPwsTUjeK5VydOgpUuWEc4N9xajhbkR12k1KVwe+Q7vk3PQV8UeB0I64n X02C3r1aBuYHR6vZsUq5HAG3n2BSURJAaWdE6qLlamfJFVHo6kLQqzxglgECAhq0GPtd Kno8zymPil9pJ4bZMyLnV2VoGLcKQatYng1Xl15g1UIhBWLxSWejZa4N/cq1mrOI3vEX 5F6A== X-Gm-Message-State: AOJu0YxqdW9wV2xXpJwWi37s9UtV+zeegGvmkr/dn3vkIlJWcnx3CCPw iau5YCGWPR1y0cZhNnRerUmR+1WWzFGxnrUbdxGQKY2iWRTv2BVhvnYIaK13JaUVx9pj72FQfKI XJ04htL0= X-Gm-Gg: AR+sD11Tvf1428mOwF2JJ/z+avJ4/UdxDwWV5g1nU/8KPvagL9YRyiQuXnXvRH5Eyhl xL5jrKwy4VCwZ+nosvIoCTgYvthwIA9gQ+fUAymK6m5DxYbUAQznGulCd6cSxrTCRjMapEweU7S gQQM1244lS/z/0iuVcNeJ5+/bX5iNSykjPPW/xNwXl8Uy7cr9kPLvLFZ8CmuSSoFkm+WSiya90d NK6pCCPNZZiR50cvghhdsGJFADSwWVgbnO4q1mbjThA0hLble/ZXjcyvF0MrsV5fZysdkd9xRWD XGMduIedmwa8BsgQGgeblSDyjKOV9pKzhUawzq07Ckbw6+1FiuTf88SYf9CDjmVg8EwKYFsiUmS /6xAK+6uNb1YEv1bu3xfrvqkUfW7BQkJ9aUyo/sT5u0rujjU6FseHEvReKkskIZjQGl7FScZ4Tc +iRNgP1be2uzcNKkn+h7YQZsi7JNT2ifs+ehIDGPRNpj2eZDDmu0hq+Y+FwoYwncJPr6W9t54K0 AnwOnik1w8s X-Received: by 2002:a05:600c:35d5:b0:493:d0f7:69c3 with SMTP id 5b1f17b1804b1-4954a749117mr277451985e9.33.1784741038071; Wed, 22 Jul 2026 10:23:58 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.23.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:23:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/27] expat: fix CVE-2026-56403 Date: Wed, 22 Jul 2026 19:23:14 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241711 From: Deepak Rathore These patches apply the upstream fixes shown in [1] and [2], as referenced by [3]. [1] https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648 [2] https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15 [3] https://nvd.nist.gov/vuln/detail/CVE-2026-56403 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56403_p1.patch | 83 +++++++++++++++++++ .../expat/expat/CVE-2026-56403_p2.patch | 40 +++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 2 + 3 files changed, 125 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch new file mode 100644 index 00000000000..4cf5c3bd54d --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch @@ -0,0 +1,83 @@ +From 4a264be1794368a1acc08476058b6cf087686d11 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Wed, 20 May 2026 12:12:10 +0200 +Subject: [PATCH] lib: Protect function `storeAtts` from signed integer + overflow + +CVE: CVE-2026-56403 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648] + +Backport Changes: +- Retain the Expat 2.7.5 binding URI reallocation and active tag pointer + updates while using the overflow-safe localPartLen calculation. + +(cherry picked from commit 12dc6d8d3d65f79471a94d8565f6bf1cf245f648) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 30 ++++++++++++++++++++---------- + 1 file changed, 20 insertions(+), 10 deletions(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 0248b665..e441ff7f 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -4235,26 +4235,32 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, + return XML_ERROR_NONE; + prefixLen = 0; + if (parser->m_ns_triplets && binding->prefix->name) { +- while (binding->prefix->name[prefixLen++]) +- ; /* prefixLen includes null terminator */ ++ size_t candidateLen = 0; ++ while (binding->prefix->name[candidateLen++]) ++ ; /* candidateLen includes null terminator */ ++ /* Detect and prevent integer overflow */ ++ if (candidateLen > INT_MAX) ++ return XML_ERROR_NO_MEMORY; ++ prefixLen = (int)candidateLen; + } + tagNamePtr->localPart = localPart; + tagNamePtr->uriLen = binding->uriLen; + tagNamePtr->prefix = binding->prefix->name; + tagNamePtr->prefixLen = prefixLen; +- for (i = 0; localPart[i++];) +- ; /* i includes null terminator */ ++ ++ size_t localPartLen = 0; ++ for (; localPart[localPartLen++];) ++ ; /* localPartLen includes null terminator */ + + /* Detect and prevent integer overflow */ +- if (binding->uriLen > INT_MAX - prefixLen +- || i > INT_MAX - (binding->uriLen + prefixLen)) { ++ if (localPartLen > INT_MAX || binding->uriLen > INT_MAX - prefixLen ++ || localPartLen > (size_t)INT_MAX - (binding->uriLen + prefixLen)) { + return XML_ERROR_NO_MEMORY; + } + +- n = i + binding->uriLen + prefixLen; ++ n = (int)localPartLen + binding->uriLen + prefixLen; + if (n > binding->uriAlloc) { + TAG *p; +- + /* Detect and prevent integer overflow */ + if (n > INT_MAX - EXPAND_SPARE) { + return XML_ERROR_NO_MEMORY; +@@ -4282,10 +4288,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, + } + /* if m_namespaceSeparator != '\0' then uri includes it already */ + uri = binding->uri + binding->uriLen; +- memcpy(uri, localPart, i * sizeof(XML_Char)); ++ /* Detect and prevent integer overflow */ ++ if (localPartLen > SIZE_MAX / sizeof(XML_Char)) { ++ return XML_ERROR_NO_MEMORY; ++ } ++ memcpy(uri, localPart, localPartLen * sizeof(XML_Char)); + /* we always have a namespace separator between localPart and prefix */ + if (prefixLen) { +- uri += i - 1; ++ uri += localPartLen - 1; + *uri = parser->m_namespaceSeparator; /* replace null terminator */ + memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char)); + } +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch new file mode 100644 index 00000000000..62fdff79e3c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch @@ -0,0 +1,40 @@ +From e8100827a4f68c70d8cadf446bb82bec7cbebbac Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Fri, 22 May 2026 00:43:52 +0200 +Subject: [PATCH] xmlwf: Protect function `xcsdup` from signed integer overflow + +CVE: CVE-2026-56403 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15] + +(cherry picked from commit 147c8f36d6277d5c6011c098370a8362aed47b15) +Signed-off-by: Deepak Rathore +--- + expat/xmlwf/xmlwf.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c +index 2d0c4f8e..934473ce 100644 +--- a/expat/xmlwf/xmlwf.c ++++ b/expat/xmlwf/xmlwf.c +@@ -305,13 +305,18 @@ processingInstruction(void *userData, const XML_Char *target, + static XML_Char * + xcsdup(const XML_Char *s) { + XML_Char *result; +- int count = 0; ++ size_t count = 0; + size_t numBytes; + + /* Get the length of the string, including terminator */ + while (s[count++] != 0) { + /* Do nothing */ + } ++ ++ // Detect and prevent integer overflow ++ if (count > SIZE_MAX / sizeof(XML_Char)) ++ return NULL; ++ + numBytes = count * sizeof(XML_Char); + result = malloc(numBytes); + if (result == NULL) +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index ae90ec04e36..423219c726f 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -19,6 +19,8 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-45186-07.patch \ file://CVE-2026-41080-1.patch \ file://CVE-2026-41080-2.patch \ + file://CVE-2026-56403_p1.patch;striplevel=2 \ + file://CVE-2026-56403_p2.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93243 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0B935C4453C for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5513.1784741040402550656 for ; Wed, 22 Jul 2026 10:24:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=lnqvsTst; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49545ba3d4eso34198745e9.3 for ; Wed, 22 Jul 2026 10:24:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741039; x=1785345839; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=8F1r9PMhHafkKhyHGvxsEyt3tI1QI5kkGilOcDEhjDY=; b=lnqvsTstd2OI44N3WNQIclWvNCMS9zV8HEJBa9YoHxa9oRFs9cOVAbjWpSNLX8xqVr 4yW/ChPvQd5oxRkGRN8veiPTHhWnqwaZKDQ4YioK+ifYggeIalK9nVRUry9VrbCNGg6T 6Fz4iRgCDgCobKUYuML5xwLi3P7uyyT+LuKhk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741039; x=1785345839; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=8F1r9PMhHafkKhyHGvxsEyt3tI1QI5kkGilOcDEhjDY=; b=H70W3vAe7U5GcLTKcpy9yt2lOUVhzwxydhkrn6N3aZSJUhq3AINXFl5OAyvkbpydmq 5l9NzqKmCjd0ZK8My/IipQHugS/mHmmNDaVOFSM/hU0UN+Vmk4ez8hakFFxHuTZDQUIA Ev3CxkxVfSIa5Xt4aBPE0DeMbsMRpK3YKSiBAJhxS/dsQKmvTLtMLbSDC5nqNZSLqFI0 bOo0SDdICfFzk8tuOVjwjP5H/NgZ/qnxYfvRw0A7MYaLNnxI+e94Y93OEwWaQd5jiwQF b9lF21YPE5sqNuP8fwiogzTGXGjOqQXf2sEiDTEuw2L0b9c0MuNNyJd7tQePM3Q/8CUZ mHcw== X-Gm-Message-State: AOJu0Yy//XFym9VJwDwpMC4ws9Jsiyzuv3DQGHAQC3+aieQiMOsmP6ZI JD5eBDMuBEWQWxwC6Hn3TWzLEgSwJmzZgOHm8ADYbcKRNs3AdZQAWor2sGybzy/6LU6kTYpRRbx cTp/QnSU= X-Gm-Gg: AR+sD10fqr6Fz+4f1JXVjq0KB+EuKOOGf6NUhhhCRoEp8lESMB8gk3UZv/C9twEp9Xp FEQgKm5qRDf5xGWrSEzw5ujen6tJEBg4x6xN1UKkUMbHuHFZbpL/eGapc2idUv8xYLVVkdcvqvC d77dZTzO9PYH5IIth05vgZe+kjWI9CIlXLwIhjIQ/w/GI1DNhH9iRBpkTbnJG2Rty7wiZKOcXZS nDWVruLXLpH1NwE6Fi+/iIyS39QEAB7uMQtyp5w3VSsOVGbCQw5bG0vzuGjwgOB1xlyC4D7OPdL jlsT40UiRXuPkl90iZznoU2t48Jo9OtOp8L4yw9yh0tHR8wIhVMROYyC5iMEMIDj9tLzPmon2gP x4NE6OBsPUVDMHT63qYHZBDL9GErzrah0XioQNk5sMwo/eGys/SIEmyRRcNBWY/L2RLGddklbZy jKjNFp9ojiiNQm2hG5ukfvoVTwxGIugGI1UyOGQPuy8qI1qWqdlXgTfrpSUDCHnK49R5sGBeCEe AM/kzCM0ETt X-Received: by 2002:a05:600c:4585:b0:492:45a0:dcef with SMTP id 5b1f17b1804b1-4954a3eeb63mr276102885e9.5.1784741038612; Wed, 22 Jul 2026 10:23:58 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.23.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:23:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/27] expat: fix CVE-2026-56408 Date: Wed, 22 Jul 2026 19:23:15 +0200 Message-ID: <34dd4a797ba9600bba27d817702cfc59c69563ea.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241712 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. The fix is adapted to the existing Expat 2.7.5 copyString implementation. [1] https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56408 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56408.patch | 36 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56408.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56408.patch b/meta/recipes-core/expat/expat/CVE-2026-56408.patch new file mode 100644 index 00000000000..b8c43636cc0 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56408.patch @@ -0,0 +1,36 @@ +From b0cf9e9b0f5dfdd938148931a4605a0fd6b917a7 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Thu, 23 Apr 2026 10:31:45 +0200 +Subject: [PATCH] lib: Waterproof `copyString` from integer overflow + +CVE: CVE-2026-56408 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817] + +Backport Changes: +- Adapt the fix to Expat 2.7.5, which calculates charsRequired using + an existing loop instead of xcslen. The upstream string helper + refactoring is not required for the overflow guard. + +(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index e441ff7f..4ff5e33b 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -8505,6 +8505,10 @@ copyString(const XML_Char *s, XML_Parser parser) { + /* Include the terminator */ + charsRequired++; + ++ /* Detect and prevent integer overflow */ ++ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) ++ return NULL; ++ + /* Now allocate space for the copy */ + result = MALLOC(parser, charsRequired * sizeof(XML_Char)); + if (result == NULL) +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 423219c726f..934cde4b1a8 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -21,6 +21,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-41080-2.patch \ file://CVE-2026-56403_p1.patch;striplevel=2 \ file://CVE-2026-56403_p2.patch;striplevel=2 \ + file://CVE-2026-56408.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93248 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9F0F5C531CA for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5514.1784741041013538914 for ; Wed, 22 Jul 2026 10:24:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=X8SToto4; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso28219145e9.1 for ; Wed, 22 Jul 2026 10:24:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741039; x=1785345839; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=y5vHr4uU8lyWWbewqVtVQk/gkousJZ1Kr3cBFou/cug=; b=X8SToto4msLt7UsuGTGKEj3yghlC3VQ7ozHjFi5KCfv3Lgk4chiovOb/vn7DFaXzQM 9wp06Zeg5HLJKeDP6yCEdYPIKEBIW1iVvpTuB6Wd37YfLMfdiYrUctWmtpHqz41oMUOd ZmggwjXq3+Y48bTQltKCdFORwuZd2g590zay8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741039; x=1785345839; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=y5vHr4uU8lyWWbewqVtVQk/gkousJZ1Kr3cBFou/cug=; b=g/cM4r/CguKxOPwHFJ7guDDL9Jk7osyWmQ8x1jMMoOEAOJHTDygr6AyyJHldK1hA9s 568kVXH3L0lANSsJS5Vyz+gWhhf9fbcIIbgCUqI2lVppSQBkn0YJX9jWDuZN6dYMplJ9 eBkGanSD+fLNsQnMP3PKss98ZgIFY1r/88fTJP5jMEp0wdsC37WLwfupP0IntSGGJrJk 5s9VO7F5O2bfxL5Jr9P5BX7LFiFOl725X/7yaHCVGsAzBCEdWgK7zbacYU9sY3WM7alr bKb9XeBbTOgA/9XaSMqujanXf/qjXReQiSJZTvAqVeKjPxDyo1uHLDkJrLHW6VN//Zqq NE3g== X-Gm-Message-State: AOJu0YxWRS7eOS/gQky/JGtMzMe81cCZonoQZGavaGT0EtUnVGm9EMty FGbgCsOYAhjF6LnmeTjbqEg67f6KuVoPJNj0tj/5q+XPmn27ojVY8n3g34dVi0/mhIbTWRbQ4Qs iDnxk5To= X-Gm-Gg: AR+sD10rtyQQgv390eUTqJhstT8AGmqkVtKEcEgomUWQMexexneF2hQd7h9EP0bHHZS 5W33JleKPHPnOf1nLUVJEW6Mq+yUedBauIJXU09xusrodVk9eM0XHUfUcUcaTcKGjYfCTs+MyMr u3wiwWOzzy6TivTKOGjU5ilmMi3Kl6s6eKVGLflhH1lnqR6unApv9viZWjTSQ4gRBK/3j7HbuTV IoG8rAM88Xi5cggia/mfIQonVjjPiT3kNwzxvtlcLho04xUDrM1AZDGNJaiiTy4wz4hYxZgpVHL Sf8yHB4tTBrZHfTkvyilY7OH+6QtVgqz2xFWdgz52sDpbI4RnqJ0YXJ7Px7A22o0Qj6C+CkKk6t gWfmPSABuVQaXRaCrAlyTWdoW1tMFa2a0rz6xXaXU85p6sG93/0WRPj9ieLrPFDn28mvDnJoeVX XgXtBNKOLCRn4GyMNWuXBzFgo8Sn7kdM7ytwNDS0nOpayaIMylz6S1gRQTM7bCtK8MUuWcz8oWG D3xFrYw8SsS X-Received: by 2002:a05:600c:6989:b0:495:5d34:e62c with SMTP id 5b1f17b1804b1-4955d34e948mr177656115e9.10.1784741039167; Wed, 22 Jul 2026 10:23:59 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.23.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:23:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/27] expat: fix CVE-2026-56404 Date: Wed, 22 Jul 2026 19:23:16 +0200 Message-ID: <7b5ff0e62348954891add80448ce3c349b8af9a3.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241713 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. [1] https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56404 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56404.patch | 47 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 48 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56404.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56404.patch b/meta/recipes-core/expat/expat/CVE-2026-56404.patch new file mode 100644 index 00000000000..6bca7cf961c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56404.patch @@ -0,0 +1,47 @@ +From 8cb4583ac3204175a03c8ea8e371adee583b0bec Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Thu, 28 May 2026 12:44:11 +0530 +Subject: [PATCH] lib: protect function addBinding from signed integer overflow + +CVE: CVE-2026-56404 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164] + +(cherry picked from commit babfc48090977cbf7be24b2c48f6053dca75c164) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 53f842d1..33b92c9c 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -4485,6 +4485,10 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, + } + + for (len = 0; uri[len]; len++) { ++ /* Detect and prevent signed integer overflow */ ++ if (len == INT_MAX) { ++ return XML_ERROR_NO_MEMORY; ++ } + if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len])) + isXML = XML_FALSE; + +@@ -4525,8 +4529,13 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, + if (isXMLNS) + return XML_ERROR_RESERVED_NAMESPACE_URI; + +- if (parser->m_namespaceSeparator) ++ if (parser->m_namespaceSeparator) { ++ /* Detect and prevent signed integer overflow */ ++ if (len == INT_MAX) { ++ return XML_ERROR_NO_MEMORY; ++ } + len++; ++ } + if (parser->m_freeBindingList) { + b = parser->m_freeBindingList; + if (len > b->uriAlloc) { +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 934cde4b1a8..d15e0232077 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -22,6 +22,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56403_p1.patch;striplevel=2 \ file://CVE-2026-56403_p2.patch;striplevel=2 \ file://CVE-2026-56408.patch;striplevel=2 \ + file://CVE-2026-56404.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93253 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 295F8C531CF for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5454.1784741041451461715 for ; Wed, 22 Jul 2026 10:24:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SsxhvL4r; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49555a0e68bso21952075e9.2 for ; Wed, 22 Jul 2026 10:24:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741040; x=1785345840; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gYNKfQMvkxX8aHOGUOXE/vsrkWMY1rKLE2u2G9ghR/0=; b=SsxhvL4rcOr3LyPaJNMfeJUROQbVtDXm2C+xNM2xRM4Rs6dm/rvGzFVdtVXNFjC3E4 KsjaucSBTmHB79P3A36MYlxaQtu5ZngxADCsX44QCmdXm1qnc4IkPiUVyz6KhvGFUDvJ rG2himhC+GAnSS1oz7PNBFBcQMfhHHIal09Mo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741040; x=1785345840; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gYNKfQMvkxX8aHOGUOXE/vsrkWMY1rKLE2u2G9ghR/0=; b=GnsJvPeJlCF8XhQ8ALX/6g5ztaEon2NyS5e8TpmwBNtJT7JBXn/E/GmRcWpR0+Oeyj WzQwQVh1a/TVDSQjGY8R86aWIatMds49EHaWCEVzsvmxWriByJKkORSnTd/7klKWbb/Y ObjQOUGKXNAmUapoqMQY4QwxXEgPXFP6LigTUfz2xLLhqrT5nJqSikQBg9RCG1zUJKqy lBLTo0zkBt0q5hdp3an/LNn6uA5A4TDIrcudtDbOYt0oQyw/J4P46Zn3PkxIntj7UL3+ zdg9mNJAUoOHzOmfhiWjl/wptzuSOVG8qemO+sQuDRww1yupo5OpbSv6fYlZpaP3mmeh 88LA== X-Gm-Message-State: AOJu0YxhzNWIZ0urP1zzrzOUY58i4oYleSFZv0kCJUqXqYM0E9pLqkjf SjAYkU9cWYEWLCJo5tTSyNpeh2CWQqZyA39ogABJs+Y2WEINQDi0aa/0fXciPjqTV+fESexhU61 gZ0zs8XU= X-Gm-Gg: AR+sD106gGDyHwZoQb3uJPDE8fjg8QJVTHG3bDEq8GSEyfcLpiSrwgwZwbLGQstcRe/ sq2EJJG/IQAdI46TkQ90Z+p9IAsKF1dIFRRV6pCB5ANihfcsK7WU6BXYoSVkPy/8thQ37XMMdn9 YKp09vaX4CSF/9jYbSjbmVxAOD21HlgGyPieyf8lckVQzwOnUT190k7yJ2ap0LiPa4r8iL/EMOY UmG3rxPeXxc9BJ4wlMem5y1ge4g8s/kUzg27KfG5unmvoX/uf4RPwtGCXdpXcNUEocsyvWVAhT+ LDma5+bzVHxLkSVtMfC8NPGH5WNKuay0uQRP5SGsb4jqSEa2xIqdqRu8366P/ABaH42mHL2v6he yFoNfbiVGqI2Lrih7zkrqD4wQZWgTN9fzGq7ymJOpzB+bMWckR25W2loQM1JecDWHJ7tbmx7gvZ WwedAwwW7tPtsndVIxl92+c4ESf7ojctfgFcOKuaeqgnZrMN48012KLiJmbpDk1iU0y8GgOdLil dCgDpbx3vMSDp5fPdcOyfQ= X-Received: by 2002:a05:600c:3b0a:b0:495:607e:5ed6 with SMTP id 5b1f17b1804b1-495608bdb42mr146787305e9.31.1784741039666; Wed, 22 Jul 2026 10:23:59 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.23.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:23:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/27] expat: fix CVE-2026-56405 Date: Wed, 22 Jul 2026 19:23:17 +0200 Message-ID: <280ff735d740a899926615d91ee4c344a6d5f0bb.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241714 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. [1] https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56405 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56405.patch | 32 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 33 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56405.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56405.patch b/meta/recipes-core/expat/expat/CVE-2026-56405.patch new file mode 100644 index 00000000000..c850801c1ac --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56405.patch @@ -0,0 +1,32 @@ +From 73209f445f0265b203829fa7873caa78ca83cefe Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Fri, 29 May 2026 11:45:17 +0530 +Subject: [PATCH] lib: Protect function getAttributeId from signed integer + overflow + +CVE: CVE-2026-56405 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0] + +(cherry picked from commit 2c6c42d33689f6b266a5267b639e03cde17e53c0) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 1b7e289f..ec707336 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -7324,6 +7324,10 @@ getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start, + } else { + int i; + for (i = 0; name[i]; i++) { ++ /* Detect and prevent signed integer overflow */ ++ if (i == INT_MAX) { ++ return NULL; ++ } + /* attributes without prefix are *not* in the default namespace */ + if (name[i] == XML_T(ASCII_COLON)) { + int j; +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index d15e0232077..789fd7e077b 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -23,6 +23,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56403_p2.patch;striplevel=2 \ file://CVE-2026-56408.patch;striplevel=2 \ file://CVE-2026-56404.patch;striplevel=2 \ + file://CVE-2026-56405.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93254 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3FF4AC531D1 for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5455.1784741041983153472 for ; Wed, 22 Jul 2026 10:24:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=aeHwm21x; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4954d383e64so31688875e9.1 for ; Wed, 22 Jul 2026 10:24:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741040; x=1785345840; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=U0QyTfYaCzszJFLLLSFhTT7QUhHu+dKuo3U2nBrWr8k=; b=aeHwm21xK3w2sbwNhBIZ8IxFO5N6xYgKN1zcJ7ROamfiBpn837YX0TbUGn9aeseNAZ FWXdb1rzc7bRwHMW0TrZPjgtx/PQXuArsr3JQZgnDgkOxF18EyVeqYCx6RGOkKOEu+nr HskkmURrIFfYm1M67sPn88txSUPwABId+UOIM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741040; x=1785345840; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=U0QyTfYaCzszJFLLLSFhTT7QUhHu+dKuo3U2nBrWr8k=; b=V6YMBtO+R1pX49FIcAyRZ0lPcKAGndazvU7xE5s9PdxIsaaW1/z7LahWoxZXxhRPfc ebCQxaJOZGcxKEoOSROgXQ3dAkvQYtl0ZN6V12UHdaMkScabse6hUO+j0irS6OHmBr5v 13ausu6gkilxeYw41Lb3ixpYv5u1hhGwgHt6RfWzvHydtpMA7gB0nWRAoomx/WIwsxZh KzQIQuRbmgdEYNfXELBH2QF76X7JNrL9Oh1R3cjw6l+L5DnXdrsiiSwd47rdjLKmRvHu C8DyE97/p7J6UYJ0FLg0Mc0G5zUFiVNoBc26/GPbvZcS82QO4RUlL4saQKC1jrQAv1YZ PMEA== X-Gm-Message-State: AOJu0YwAIjvxp4fd6b3jyzCgDn60+YCo9FOPgfzQdpd0JlbHyMvsP2tA rG39Fe7YgOuNphSErJq7/D6QjNkFrzmzm+PFWpllAiPfuljg5/9HsNWtiED1VsSYfNeNlX6I1nZ T2kG4u3U= X-Gm-Gg: AR+sD12cri0/uuAZoc1WLm0OkFMDKD0m3MWf3iXhHty5QuQmYzNbWbIkr5d2reDofRY 3Ng252eAUUPesP79cpVfp8iVJ8Rc2iq7G+1BpsrJIDng3phP/2RWVmAMZnixh9C+/ZWsO/tgjaz N/Q53d2ImSuV4tsVXnxvEIffhYDSY9auAl2+0ml3qr5SUga6A9T9JLFu2DWsObBNlOQ5QOcJRuP un6BMJ08SM7wUQCES+Eht8EFQDVnnBCrM7Krya727ViJ0OmAkeF5O01w/kIB6M3w96mmYAJOOHV g6Xa4OoeNJMqJXY5hX8g3YFULynpFGhf0q0R7/7fcrHmxziakQPEU0Z62hbZv6+Rya8Zj7/nW6V A66muSgPuPpHm8MI2Pb1EgyIMLxnusBLxQs+fWttq69oHmsxUB4qqMgTT/NuBREnhtETQ4qNCFo xfYBYuWux8b1rpMc8QOcrZSkeFFrd3xv5bLxVpI9vnnasX4U0LbExN2FiEexkKSyDdDVvWLFGvV evLYmzwXkV4 X-Received: by 2002:a05:600c:524a:b0:495:641a:bd3f with SMTP id 5b1f17b1804b1-495641abe94mr140370045e9.13.1784741040107; Wed, 22 Jul 2026 10:24:00 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.23.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:23:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/27] expat: fix CVE-2026-56410 Date: Wed, 22 Jul 2026 19:23:18 +0200 Message-ID: <63cdc2b7257b31bbb486762aebcd5e42f04dca8e.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241715 From: Deepak Rathore These patches apply the upstream fixes shown in [1] and [2], as referenced by [3]. [1] https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347 [2] https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea [3] https://nvd.nist.gov/vuln/detail/CVE-2026-56410 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56410_p1.patch | 40 ++++++++++++++++++ .../expat/expat/CVE-2026-56410_p2.patch | 41 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 2 + 3 files changed, 83 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch new file mode 100644 index 00000000000..aa4378f1b77 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch @@ -0,0 +1,40 @@ +From 759b77a8439bcbf57c86900bc472d46d8ef70c92 Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Fri, 29 May 2026 17:51:25 +0530 +Subject: [PATCH] xmlwf: protect resolveSystemId from integer overflow + +CVE: CVE-2026-56410 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347] + +Backport Changes: +- Adjust the removed allocation line for Wrynose's explicit malloc cast while + keeping upstream's overflow checks and final allocation logic. + +(cherry picked from commit deeb97f7c88d17a16b0ea2521a13733abc283347) +Signed-off-by: Deepak Rathore +--- + expat/xmlwf/xmlfile.c | 9 +++++++-- + 1 file changed, 7 insertions(+), 2 deletions(-) + +diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c +index c4eb839f..31a40209 100644 +--- a/expat/xmlwf/xmlfile.c ++++ b/expat/xmlwf/xmlfile.c +@@ -138,8 +138,13 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, + #endif + ) + return systemId; +- *toFree = (XML_Char *)malloc((tcslen(base) + tcslen(systemId) + 2) +- * sizeof(XML_Char)); ++ const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; ++ ++ /* Detect and prevent integer overflow */ ++ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) ++ return systemId; ++ ++ *toFree = malloc(charsRequired * sizeof(XML_Char)); + if (! *toFree) + return systemId; + tcscpy(*toFree, base); +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch new file mode 100644 index 00000000000..71f3122602a --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch @@ -0,0 +1,41 @@ +From f16fa442eaa81bfceec5302d977219959eaac7b7 Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Sat, 30 May 2026 11:28:51 +0530 +Subject: [PATCH] xmlwf: guard each operator in resolveSystemId length sum + +CVE: CVE-2026-56410 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea] + +(cherry picked from commit cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea) +Signed-off-by: Deepak Rathore +--- + expat/xmlwf/xmlfile.c | 12 ++++++++++-- + 1 file changed, 10 insertions(+), 2 deletions(-) + +diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c +index 31a40209..15c69217 100644 +--- a/expat/xmlwf/xmlfile.c ++++ b/expat/xmlwf/xmlfile.c +@@ -139,9 +139,17 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, + #endif + ) + return systemId; +- const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; ++ const size_t baseLen = tcslen(base); ++ const size_t systemIdLen = tcslen(systemId); + +- /* Detect and prevent integer overflow */ ++ /* Detect and prevent integer overflow in the addition (without risking ++ underflow) */ ++ if (baseLen > SIZE_MAX - systemIdLen || baseLen > SIZE_MAX - systemIdLen - 2) ++ return systemId; ++ ++ const size_t charsRequired = baseLen + systemIdLen + 2; ++ ++ /* Detect and prevent integer overflow in the multiplication */ + if (charsRequired > SIZE_MAX / sizeof(XML_Char)) + return systemId; + +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 789fd7e077b..5c93b15484e 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -24,6 +24,8 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56408.patch;striplevel=2 \ file://CVE-2026-56404.patch;striplevel=2 \ file://CVE-2026-56405.patch;striplevel=2 \ + file://CVE-2026-56410_p1.patch;striplevel=2 \ + file://CVE-2026-56410_p2.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93256 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 560B8C531D3 for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5518.1784741042713235332 for ; Wed, 22 Jul 2026 10:24:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SZOySTre; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49571fea44eso1857065e9.2 for ; Wed, 22 Jul 2026 10:24:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741041; x=1785345841; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FedGw9YlU6DyYMn2pv6DWCbgb46YqK2SwX4O+hms/kg=; b=SZOySTreL9PcDWnmAHMZ/Pfh8UEM1tEy+2gVwc3+eLIe/sbf0zpPsolE6gvDCmXDIw w0NMNsZlQL/SvBQRGCL1KoVchfZYRu0WLYMOkKWrZiuI3UTffFdMIWUm0lbZZ5I6Iqwr O72RB9CWVWQTBTz0fSrUtBahP4iytDacQq8IY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741041; x=1785345841; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FedGw9YlU6DyYMn2pv6DWCbgb46YqK2SwX4O+hms/kg=; b=fZ1B+VcX0xFO6n0xxJffoi7zvSaskMt64sxv61M8zWLZoFr3drY7xSFEDxhyF2Tt2E by5Hj5gsgaNHSgX14cEMH9uWDVOR49ccVED2XEbv6FQ3ayB93V/Sbt+IMhbD+NqLKiTS RrqV+sxwuNWQmBn6J9JermrPM5XNKuShYylnz9RENUxmysD0COactS8h8Bkj3zIL4SOJ dDEfrsNVQfKSzfZp7stHF+rkCDIA1ONWMypklQiyL/hZc06zJ3EF9sHIdAUpdKrK4SC2 va5a6uPeJRokJGfghU9veNI0rm9vFWXZRt4YZxz18aod+MUIpthDZNwiu8VmQ3g3j+Ha XTew== X-Gm-Message-State: AOJu0YzNnwdbzWt95rmSWDnc/IegevddHCLwLksyL1F6rAwdgtvTFGI/ 2ROH9DLXHwShoTQ8PxiVkbwfrBaCbdmQ/1q2vQQFOekUIkmlGJawQVd1FhugHznigUf7jRqHYxc b7rMzw48= X-Gm-Gg: AR+sD113k5oM58PaeFpX4yVZejqRfzm18ZDtgfZnueqbDbvVZz3x7U9VAjy9JFP6RNv OkncWvK+eebShbAhOImf4fKenaUPn/jLEku4TeuLSpXzrz0sDT+M1Agpz5B5ILTxbePh9tT5SZ2 0hQGRTI+uVXLSVeAZW1sCD4rC5zpJIDcuNDYt5lXhVcNNdOOPhEof+0+IcagxHTod7+89/FTnzy 9bcrZQRNCk9c1/I2eIjezsGVHjfQ2df3P5HebAiOJy6kic0+d8otdQe9lQPMLXnNNUUQuB9c4pi amUePTs9hdrj8yCe+SSS1JHnCqqGP+XZwZuo6FrFCG0BmbJTYxvncPMXfgrm/2JihuYWeJxKNz1 BtJE6W5rnqm7G4ZPBIU28ToPAPlGL6rixRECRe9LLytgMUpPGJVl3Jyf45bgmwD4CCtLGRsCs1C o/+s0hthfCO4AIYRdCW2ZOtw/j0Sg8aiZDUfeeqIkOS8yA5nmkRynCQY9vrlsJFP6I++khlCuYf kQzUSphKRrK X-Received: by 2002:a05:600c:c117:b0:495:4b1d:915f with SMTP id 5b1f17b1804b1-4954b1d91ffmr268741815e9.23.1784741040867; Wed, 22 Jul 2026 10:24:00 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/27] expat: fix CVE-2026-56406 Date: Wed, 22 Jul 2026 19:23:19 +0200 Message-ID: <68c3ae8af4408e98952879c98b7233ca1d2293bb.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241716 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [3]. The prerequisite in [2] provides XML_INDEX_MAX for the Expat 2.7.5 backport. [1] https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d [2] https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd [3] https://nvd.nist.gov/vuln/detail/CVE-2026-56406 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/CVE-2026-56406-dependent.patch | 58 +++++++++++++++++++ .../expat/expat/CVE-2026-56406.patch | 37 ++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 2 + 3 files changed, 97 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch b/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch new file mode 100644 index 00000000000..6ef7c42298c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch @@ -0,0 +1,58 @@ +From 4f828b7ee9d6efef618e8a99a0392acbb95e84f2 Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Wed, 27 May 2026 17:01:44 -0700 +Subject: [PATCH] lib: Make `XML_Index` overflow check more intuitive + +In fixing a bug, 7e5b71b748491b6e459e5c9a1d090820f94544d8 introduced a +magic number `2` in this code that made it difficult to understand the +rationale for this overflow check without reading the commit log. This +change introduces some more readable constants to use in these +situations. + +CVE: CVE-2026-56406 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd] + +(cherry picked from commit 252ff1a307b1490ce0f430632791e7e52d7e43fd) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 96127bf8..5ecea7a8 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -101,7 +101,7 @@ + #include + #include /* memset(), memcpy() */ + #include +-#include /* INT_MAX, UINT_MAX */ ++#include /* INT_MAX, LLONG_MAX, LONG_MAX, UINT_MAX */ + #include /* fprintf */ + #include /* getenv, rand_s */ + #include /* SIZE_MAX, uintptr_t */ +@@ -209,6 +209,12 @@ typedef char ICHAR; + + #endif + ++#ifdef XML_LARGE_SIZE ++# define XML_INDEX_MAX LLONG_MAX ++#else ++# define XML_INDEX_MAX LONG_MAX ++#endif ++ + /* Round up n to be a multiple of sz, where sz is a power of 2. */ + #define ROUND_UP(n, sz) (((n) + ((sz) - 1)) & ~((sz) - 1)) + +@@ -2395,7 +2401,7 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { + int nLeftOver; + enum XML_Status result; + /* Detect overflow (a+b > MAX <==> b > MAX-a) */ +- if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) { ++ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { + parser->m_errorCode = XML_ERROR_NO_MEMORY; + parser->m_eventPtr = parser->m_eventEndPtr = NULL; + parser->m_processor = errorProcessor; +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406.patch b/meta/recipes-core/expat/expat/CVE-2026-56406.patch new file mode 100644 index 00000000000..4077b9946a9 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56406.patch @@ -0,0 +1,37 @@ +From 6e52f18aded0a76cf89f191d7810bc04287f5337 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sun, 31 May 2026 15:18:58 +0200 +Subject: [PATCH] lib: Copy overflow check from `XML_Parse` to + `XML_ParseBuffer` + +CVE: CVE-2026-56406 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d] + +(cherry picked from commit 99d8454fdf900a6d00c2a52748e6c0eeb507574d) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 5ecea7a8..71fe2c79 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -2518,6 +2518,14 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) { + parser->m_parsingStatus.parsing = XML_PARSING; + } + ++ // Detect and avoid integer overflow ++ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { ++ parser->m_errorCode = XML_ERROR_NO_MEMORY; ++ parser->m_eventPtr = parser->m_eventEndPtr = NULL; ++ parser->m_processor = errorProcessor; ++ return XML_STATUS_ERROR; ++ } ++ + start = parser->m_bufferPtr; + parser->m_positionPtr = start; + parser->m_bufferEnd += len; +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 5c93b15484e..f14e39c00b3 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -26,6 +26,8 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56405.patch;striplevel=2 \ file://CVE-2026-56410_p1.patch;striplevel=2 \ file://CVE-2026-56410_p2.patch;striplevel=2 \ + file://CVE-2026-56406-dependent.patch;striplevel=2 \ + file://CVE-2026-56406.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93251 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CD7C1C531CE for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5520.1784741043244001071 for ; Wed, 22 Jul 2026 10:24:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mBaUQBqw; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso48879855e9.0 for ; Wed, 22 Jul 2026 10:24:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741041; x=1785345841; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=3GgEg8TdPXSkd1YBU5G1GH/7KLdouzPpl1d5WWFEdS8=; b=mBaUQBqwsRPG/pL7XRbA66psqmiZxgypZ+0k3kgYEXoJKpDCapvnugYvTL0Y+VpPKG HJnAqCyTJkkuPZgvJ8hpmHYygXFem7ba8sNt5Pqj5U/E6n7Ipi0OFpBdbpBsEXNdpjO5 SK4sdlC784GEd0UkhyT9mJUhKft5hC5BNLXlI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741041; x=1785345841; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=3GgEg8TdPXSkd1YBU5G1GH/7KLdouzPpl1d5WWFEdS8=; b=qrlfnUijmSENZ5RgHaNUcR5j2Cv9dSg1xTqe5RdF+/47/X4/3BmrZS2tzlUvF25Vln c+n64Ve1b7Gta0G29u1JVfknn4chkL7hLWYcQaK/cFINtuagptAPCKJEuNHT/Joh6aYJ heDx1N587eTJCwpa+5lkANFSWghj1m+1XqxcvvitcujxP0Xmfi5XnJSvttAQpPKktj9d HLZSPAzmoFAAGGDJWb64UkkWGtKYXE7AxNys9RuW8kFhU5M4VfuMyDrTlFvFA9n3imN1 OFaqhQFPT/8VpraZ1RtUUuLLVMv5/LhDHbV3BER8KqgCE2VUV1HXdc4peUliq57hhOqH wRMw== X-Gm-Message-State: AOJu0YzmFQhB97/R4w1k8hCZyGJoihihDDKcXbHKgJi4hdvSyA90GdJ6 xud6HM0a3z5Pr/KGx9EBzLPBhMtBTsUWOL8ccWLVgNyvk5IXcw7Kkhd2hKOKYBY45awgdfdpmim Pn2kdeVQ= X-Gm-Gg: AR+sD10dA/l7cjb0t9dpnyAJImXTxWCXtMZeIt62peuU0WJC6Yc9YLedDIBQ1uZFGC6 wBEnWCS4u28qPvLm20R2L9rfA7tEQGcB8yP7xpZWsuOJU+wCRK/rHUaFJAkdPmmchDTvabwy1Qo MIe7uveMEewBJCgOhKWyhAn+c1wlD6vKA79w6rJyoT1Pz1oXuiLcuqztaaNxOrK43oM8hs5CpLj l0kKhxegUrjn/tSGNcpDkC4/BHbPvf58oTxWV33MIP4yaBG3KEHrOI4BXC9AAUzvpCpDQFr/vdp wivixf9VEbAsxq82zgfHTyzRxZv7g+fV1PeO/FZxPZizorNrAJJqFFEaGEWRV95scyMn/ZE+Ams H+YsC1RKpRLJsaMdWzcBKLwEEW2basdSCoI+1sxnY0FQL9xAD6MxGBjG5E9ZQ737/TGntq7ZgTj PpVE4CC0KDp28oERIxggJ+1HwGofCFMFMSt/mx4aoqrVVH9P1xrli3fSzgYB2luRnlz12bqsYVH rXCRPbLRBmJiKoj09B53Xo= X-Received: by 2002:a05:600c:8284:b0:495:5d6d:d4f7 with SMTP id 5b1f17b1804b1-4955d6dd523mr177623365e9.24.1784741041428; Wed, 22 Jul 2026 10:24:01 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/27] expat: fix CVE-2026-56409 Date: Wed, 22 Jul 2026 19:23:20 +0200 Message-ID: <00ba44abd083f009274ba0cebbd2b1fbcde83879.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241717 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. [1] https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56409 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56409.patch | 53 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56409.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56409.patch b/meta/recipes-core/expat/expat/CVE-2026-56409.patch new file mode 100644 index 00000000000..ff0e650a2ab --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56409.patch @@ -0,0 +1,53 @@ +From 10938bc2cef7573087566b5b1c948061baa68b98 Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Mon, 1 Jun 2026 11:53:19 +0530 +Subject: [PATCH] xmlwf: protect output path join from integer overflow + +CVE: CVE-2026-56409 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e] + +Backport Changes: +- Adapt the allocation hunk to the explicit cast used by Expat 2.7.5. + +(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e) +Signed-off-by: Deepak Rathore +--- + expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++-- + 1 file changed, 20 insertions(+), 2 deletions(-) + +diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c +index 06416454..6a0a707a 100644 +--- a/expat/xmlwf/xmlwf.c ++++ b/expat/xmlwf/xmlwf.c +@@ -1236,8 +1236,26 @@ tmain(int argc, XML_Char **argv) { + } + #endif + } +- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2) +- * sizeof(XML_Char)); ++ const size_t outputDirLen = tcslen(outputDir); ++ const size_t fileLen = tcslen(file); ++ ++ /* Detect and prevent integer overflow in the addition (without ++ risking underflow) and the multiplication, mirroring the guards ++ in xcsdup() and resolveSystemId() */ ++ if (outputDirLen > SIZE_MAX - fileLen ++ || outputDirLen > SIZE_MAX - fileLen - 2) { ++ tperror(T("Could not allocate memory")); ++ exit(XMLWF_EXIT_INTERNAL_ERROR); ++ } ++ ++ const size_t charsRequired = outputDirLen + fileLen + 2; ++ ++ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) { ++ tperror(T("Could not allocate memory")); ++ exit(XMLWF_EXIT_INTERNAL_ERROR); ++ } ++ ++ outName = malloc(charsRequired * sizeof(XML_Char)); + if (! outName) { + tperror(T("Could not allocate memory")); + exit(XMLWF_EXIT_INTERNAL_ERROR); +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index f14e39c00b3..cb8f9dd1acd 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56410_p2.patch;striplevel=2 \ file://CVE-2026-56406-dependent.patch;striplevel=2 \ file://CVE-2026-56406.patch;striplevel=2 \ + file://CVE-2026-56409.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93244 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 61E86C4453F for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5460.1784741043660125545 for ; Wed, 22 Jul 2026 10:24:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GlqIDTtT; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49557167508so44134195e9.1 for ; Wed, 22 Jul 2026 10:24:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741042; x=1785345842; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tb/+ErvddBwcbpwomc8S6/N7bFmxUyu3E5hND3nQplE=; b=GlqIDTtTwVSvMtxJceekW0xjOqg/cVYLpFki14JuLJBxdt9UTMeOhRbZmEi/XP/JrN n4s605z0zplC8qBkw6JL6DV7SoBPe3eOHJhrv0fyQFca0U/wuMKGpQl90h56ZgEB0rvb beoicKOSTZMTpb2Y/28R/K04Nw6sY162HX2+k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741042; x=1785345842; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tb/+ErvddBwcbpwomc8S6/N7bFmxUyu3E5hND3nQplE=; b=bNfnEiF5WQ49t1cqYuheSruancBzS9n+sndM8gkzd1DFi9yOLGp9MA+w5vweRBEZNr fc4r+6nd/KGIOKNRSqme67EneKUpjfie3dXto12LSWvC36KOtD6eVKmkAfKs6TWDhKT8 Ybn5CMC0MaF0wNjFynkfZq2apAZvTclXzQUi2m9/B3Yv612nxomGvvwZ83x7bVBPC/pm fWjWKnECroBSPIio1AIurOgVU/Ms4geazBXsSEsdlq2PMkfFIKHEIBCDO+XCslCJJQWO AwmR80ZNwyIGQ3dGhMoRGaI6ABtcbb4GLTH0zxYoZET05emgW+jlzCbq5C0reT4lHkco UtEQ== X-Gm-Message-State: AOJu0Yyj+gk1au/GQR7QqcXT1wAadmGS6vWqVDNHzjNEYtHKjAc8zfKv Ftwf5LmqUDANZfJPD9bn1MMo5j+kSg8qmJTupRwXckPfJuQB1BvK66W7bXpHB8x109ckbR63hJn FvPF1Eq0= X-Gm-Gg: AR+sD13mezAq7NjXjD7g46r8Y0yPFQIQofa4E01mUk6WJepOmPU9V1gqQpTRD1S3Eec jl7m3bT5u/sOsFHQhoaZskPFL2r7tz54yBk6RmHy/M847jLri3i1Ovc6XvKGTOWs8apJEaCc/ER Le+O3vIF4rw97Jw5M+1AXOk9T+XU9qk/6UVdR9bo/qajqrLiQI359zlvAFgZ/a53bCileWiwtO2 jOxKH+7o7DqcSWjVQZPNWGp1h785qeJB2SYKrSxJINyclaF0GB5FWrYuVJJNGRsQknIvN1UfLvL MvqN/UzSRc+KURRcgnJuQi/x/0biaOW1d6U+a6Wb4CgBZ6aGdnmZ8lLN8lgxQCwbwRNV/69sP26 aDQQIvYUwWUO1TS7cfSqQAp1w8psW6uT81Dreelycc/JDtDN6VThYxlk96gh47Gup9lCTq2F6qa w2Wp2+9B0di0Jic1XZaTS/oLHeAcrX13dO6FtRIYWxMNfXBxt+J7WzhnBLIYFVdy7jXRiYgT9vQ cMzM2HJ/owq5msGxohbrVM= X-Received: by 2002:a05:600c:4f44:b0:495:5b02:23a8 with SMTP id 5b1f17b1804b1-4955b022588mr171765865e9.34.1784741041897; Wed, 22 Jul 2026 10:24:01 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/27] expat: fix CVE-2026-56411 Date: Wed, 22 Jul 2026 19:23:21 +0200 Message-ID: <2fb21d414bf0def272ca40a69246c01fb983b72a.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241718 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. [1] https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56411 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56411.patch | 47 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 48 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56411.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56411.patch b/meta/recipes-core/expat/expat/CVE-2026-56411.patch new file mode 100644 index 00000000000..884837b61e1 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56411.patch @@ -0,0 +1,47 @@ +From e447d5d72884a1246894f111a5b72de4e479152e Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Tue, 2 Jun 2026 13:13:34 +0530 +Subject: [PATCH] xmlwf: protect notation list allocation from integer overflow + +CVE: CVE-2026-56411 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5] + +(cherry picked from commit 528a4e5017e1bd3b48b689fd0c131df940ae3ea5) +Signed-off-by: Deepak Rathore +--- + expat/xmlwf/xmlwf.c | 11 +++++++++-- + 1 file changed, 9 insertions(+), 2 deletions(-) + +diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c +index 6a0a707a..a9640190 100644 +--- a/expat/xmlwf/xmlwf.c ++++ b/expat/xmlwf/xmlwf.c +@@ -383,9 +383,9 @@ static void XMLCALL + endDoctypeDecl(void *userData) { + XmlwfUserData *data = (XmlwfUserData *)userData; + NotationList **notations; +- int notationCount = 0; ++ size_t notationCount = 0; + NotationList *p; +- int i; ++ size_t i; + + /* How many notations do we have? */ + for (p = data->notationListHead; p != NULL; p = p->next) +@@ -395,6 +395,13 @@ endDoctypeDecl(void *userData) { + goto cleanUp; + } + ++ /* Detect and prevent integer overflow in the multiplication, mirroring ++ the guards in xcsdup() and resolveSystemId() */ ++ if (notationCount > SIZE_MAX / sizeof(NotationList *)) { ++ fprintf(stderr, "Unable to sort notations"); ++ goto cleanUp; ++ } ++ + notations = malloc(notationCount * sizeof(NotationList *)); + if (notations == NULL) { + fprintf(stderr, "Unable to sort notations"); +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index cb8f9dd1acd..bd6656c6e06 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -29,6 +29,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56406-dependent.patch;striplevel=2 \ file://CVE-2026-56406.patch;striplevel=2 \ file://CVE-2026-56409.patch;striplevel=2 \ + file://CVE-2026-56411.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93247 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 92BC7C531CB for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5524.1784741044530150175 for ; Wed, 22 Jul 2026 10:24:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hza50Rqy; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-4799b3f7c83so9235334f8f.2 for ; Wed, 22 Jul 2026 10:24:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741042; x=1785345842; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=kxR1yjOH4BwWpQ+AJ+Q+4RErbAd6zOoaJ+wBpt0yIrE=; b=hza50RqyKIj62B8sRtAWdXKGyC6cbYSxI6zDj6ydQo2zBfbuuTho5qgLKoF5V9pJRh C2JWwRT0m5vex7O61X83rjgKiutRMadePMLXxg/PRcYosltpi1NN6cB6CrP5PE0xg08Y cc8CFT7pPpGdoYhVYhMfecLZdby0FQRtYx4ro= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741042; x=1785345842; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=kxR1yjOH4BwWpQ+AJ+Q+4RErbAd6zOoaJ+wBpt0yIrE=; b=GEmfWV36jmdX63wsF74zQiKe8YmLKNDCVql0ZeyztSeA+t0W2I0l2ZkRArZbdyFcVd 8LChNnkXmVxIKyuTj0iMGUTRAX/GxCEkOzsYgQaMxILM44v9lH/l7cgj9xb/JciuUH15 t4MIMAO+nmOZejevy//3AmzPYwM2TSNU1xgMUKjblDEvQgs9SZk9N12mP5u9zlk7Ecoj 96cICbIjAgYwiy1woNLSDxlZW8MDgbUeRv/6r106vh9wG3TEF35hFekrvOTGbpSRts8z q9Ms+5JCv3sa9XLXXLZRGaELL3jTxTxo5+figCcRBRGNkPpB6MjA5R84W0NYE+6BpSvO bA0w== X-Gm-Message-State: AOJu0YzxjC45N4S6XGsHwxT08XsdzC9MuU0iBnlCkXYp/UMOg9799iBU abGef+CpN2KlrwxODoGonBX226vqxyB79pcIaDwvw3VSbPhJWYz6+vkMNKlGM0mgXf9AgjjCje5 UjXUtuFI= X-Gm-Gg: AR+sD12z4RkzxDZ87WUIyQ5CjeqT37GGPfgXOIXT4bqJZNcfKX/1KZVjuw7zDwRPCKK W+QYiAOESNdJ+RCz+4wrXbTozyYE0qrb8YClN2e0UE4KssWALnMJEYhqBalw7DpL2hzW6EXcBVs G//95y5tNsXdarRmtFXe227F0b+eWGegq0v0LdNe4zBibvlpB/ROcURnFoEkLG1Ac8LR3sobo0T VDMBA9Ssib+oK1vKHD1z2JW48SwHpZ34IEeDQMhCsgqJcAFGPJi/VIUue75i5u4sNHIUHu+Vb2P qnr7pFvPzQraqBV7KBLZz7npXcVmrETsfe4S/VAru0cJiKx8oNgZT5L02rF+lu1iPzDAs1DXmvW idOr8XLLz2ZeQnfGyZKauiHwUBBOCdkJNptW9ZNvrnaVBF4S/7C3V+mFC+ajZR8WsyOPyyAt5Cg HgwyA1IeYg6sZdfCGhXZkAqcOTJ2+3PDK9WwQvnyS7judAinMcwSip2c2CJZpK87Ib6pPFvy0Nk JZxGjmv5oiH X-Received: by 2002:a05:600c:1989:b0:495:52db:7e8 with SMTP id 5b1f17b1804b1-49552db09bfmr216421915e9.19.1784741042452; Wed, 22 Jul 2026 10:24:02 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/27] expat: fix CVE-2026-56407 Date: Wed, 22 Jul 2026 19:23:22 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241719 From: Deepak Rathore This patch applies the upstream fix shown in [1] as referenced by [2]. [1] https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56407 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56407.patch | 44 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56407.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56407.patch b/meta/recipes-core/expat/expat/CVE-2026-56407.patch new file mode 100644 index 00000000000..5a2a22e0172 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56407.patch @@ -0,0 +1,44 @@ +From 7216b3584bcfb2d415026d16b8902ee7eacad5ca Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Tue, 2 Jun 2026 11:59:01 +0530 +Subject: [PATCH] cap entity textLen against signed integer overflow + +CVE: CVE-2026-56407 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13] + +(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 71fe2c79..8e90fea8 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -5684,6 +5684,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar, + XML_ACCOUNT_NONE); + if (parser->m_declEntity) { ++ /* Detect and prevent signed integer overflow */ ++ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) { ++ return XML_ERROR_NO_MEMORY; ++ } + parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool); + parser->m_declEntity->textLen + = (int)(poolLength(&dtd->entityValuePool)); +@@ -7099,6 +7103,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) { + return XML_ERROR_NO_MEMORY; + } + ++ /* Detect and prevent signed integer overflow */ ++ if ((size_t)poolLength(pool) > (size_t)INT_MAX) { ++ poolDiscard(pool); ++ return XML_ERROR_NO_MEMORY; ++ } + entity->textPtr = poolStart(pool); + entity->textLen = (int)(poolLength(pool)); + poolFinish(pool); +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index bd6656c6e06..9f519b482ec 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -30,6 +30,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56406.patch;striplevel=2 \ file://CVE-2026-56409.patch;striplevel=2 \ file://CVE-2026-56411.patch;striplevel=2 \ + file://CVE-2026-56407.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93252 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CBEB2C531CC for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5525.1784741045151581695 for ; Wed, 22 Jul 2026 10:24:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BBp85EAW; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-495590dde14so38694385e9.0 for ; Wed, 22 Jul 2026 10:24:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741043; x=1785345843; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uxBTUh2KhkrjCmjWkcXYejhJpV30+ctBQaKzx44hKT0=; b=BBp85EAWeB8Px/qmkBA3S30vXJEN6MHtHnZCh498FgLJG+f4NHa1Zooc2UgFBvzgSv v7ALgQ4+aeRcSv9tVg8ExdlBSAM6persV8Qpb/rYFlcv2Yq5W/zEUeEQfoJqf4b+2lG/ ZeBxzLzURdHPG1SirIv22FOJqopUKwPKtONdE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741043; x=1785345843; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=uxBTUh2KhkrjCmjWkcXYejhJpV30+ctBQaKzx44hKT0=; b=cG25Tc9omt0CxWb1LS/2MMfdUKzMsy5dBt0Ia5zlSrpGEl6kjzj5ZKWzkz+XniyL9/ 3Re14WnggSwAgyEMzMdxqcaLlZLVIL1e1Zl34fvEnUcWAHzrrFHFyCYxe4yjCn9816KX e0jd5vT3cFqMJTFL3ClwNdWoxSOt2I4T+6jNDtp7/LIuNGB/WKyEoZAbgPxCbw6rc1+K 9IUqUDz/u6YX7laCm/aZWtRM+X5EvSpsDAIhPYeYZxiwxaBEFsxhlbhhKsVa/+c2cN2m cRS3zvTzSWdwq/Za9a9QvAjlp33+DTaHRBcZX2Q3Jui4Pa+PMUErc9Z72BBHlIllqPCT EsTg== X-Gm-Message-State: AOJu0YzGq+jwx8xgXW6GmIYxK2BWJEytH8NOfJJkSJjshsFg+iAiGU+o z8oG7l8kJc1ht2OP7n0hZSjEg/JxItLVobINlcPqHlLkH88qKo9QXdZBRz1CX2pjXTKoIXL/ftY EwtMj14Q= X-Gm-Gg: AR+sD13dyitSxYK4qEfvGOlLa/utCghmGLOcRBudXIuRlK9xkBdPWDGJe4MwjCbwwP5 dWsE9qUdBkLDYq3CcghWNtZJIvvwd2KSKN/p3+fb8Y3wSZJ/lTQnl93oMagvcgGrCLaYQ3jifsD qfQJRFaGD3IKDoQ9ujXv1n0rGD0qKKXEErkIX78q0nV70m+un2VqK4txao6U/XXPfMSKovRywta V3In5Nayh7fh1N4Y16rrQTDiTRmg07+vIKXs32RaY180ZhpdodV1xTXyzP/92W9SRDW8ZI5koXp oNzGBByqSUQRRGfYlFUnTuGiirTc5pc9i8Z4reeT8PkwYyNFVoDOS+uai7FQ5YZ1uIjlSoxL+nH +WRiKmp/LL+fHMohZMdbAFjyjX2nJElDFvOXHTwX/N/IFdh/yCimMsFJRX9DA2jBCNZUFpC8f7D 7GhRhnngNchxzNUT2E2pWkq+QnawDMmi8lBxZ/gXjnLvO/PiOd23smCSz6iFu3eo5R4cfbXb2Wt 7dZMYmAgw9u X-Received: by 2002:a05:600c:4f4b:b0:495:7379:17b1 with SMTP id 5b1f17b1804b1-495737919eemr2315135e9.30.1784741043112; Wed, 22 Jul 2026 10:24:03 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/27] expat: fix CVE-2026-56132 Date: Wed, 22 Jul 2026 19:23:23 +0200 Message-ID: <2303076e946496149bc6424a5c7b65eb73292db4.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241720 From: Deepak Rathore These patches apply the upstream fix shown in [2], its prerequisite [1], the regression test in [3], and the follow-up cleanups in [4] and [5], as referenced by [6]. [1] https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3 [2] https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e [3] https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf [4] https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4 [5] https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5 [6] https://nvd.nist.gov/vuln/detail/CVE-2026-56132 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-56132_p1.patch | 90 +++++++++++++++++++ .../expat/expat/CVE-2026-56132_p2.patch | 63 +++++++++++++ .../expat/expat/CVE-2026-56132_p3.patch | 77 ++++++++++++++++ .../expat/expat/CVE-2026-56132_p4.patch | 63 +++++++++++++ .../expat/expat/CVE-2026-56132_p5.patch | 58 ++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 5 ++ 6 files changed, 356 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch new file mode 100644 index 00000000000..a413bf0acd0 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch @@ -0,0 +1,90 @@ +From 2e5920edcbc77bf29ce8575bd38ed2886408f4af Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Thu, 4 Jun 2026 17:01:02 -0700 +Subject: [PATCH] lib: Remove reuse of `m_groupSize` to count `m_scaffIndex` + allocation + +The sizes of the two arrays `m_groupConnector` and `scaffIndex` need to +vary independently. This change is a step towards allowing this. + +Anthropic: ANT-2026-00037 +Anthropic: ANT-2026-03621 +Anthropic: ANT-2026-03867 +Co-authored-by: Alessandro Gario + +CVE: CVE-2026-56132 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3] + +(cherry picked from commit 3a4eaf47af8fd7abda38ea2c08308c91152061f3) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index 8e90fea8..d4864af8 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -424,6 +424,7 @@ typedef struct { + unsigned scaffCount; + int scaffLevel; + int *scaffIndex; ++ size_t scaffIndexSize; + } DTD; + + enum EntityType { +@@ -5995,7 +5996,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */ + #if UINT_MAX >= SIZE_MAX + if (parser->m_groupSize > SIZE_MAX / sizeof(int)) { +- parser->m_groupSize /= 2; + return XML_ERROR_NO_MEMORY; + } + #endif +@@ -6003,10 +6003,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + int *const new_scaff_index = REALLOC( + parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); + if (new_scaff_index == NULL) { +- parser->m_groupSize /= 2; + return XML_ERROR_NO_MEMORY; + } + dtd->scaffIndex = new_scaff_index; ++ dtd->scaffIndexSize = parser->m_groupSize; + } + } else { + parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); +@@ -7587,6 +7587,7 @@ dtdCreate(XML_Parser parser) { + + p->in_eldecl = XML_FALSE; + p->scaffIndex = NULL; ++ p->scaffIndexSize = 0; + p->scaffold = NULL; + p->scaffLevel = 0; + p->scaffSize = 0; +@@ -7627,6 +7628,7 @@ dtdReset(DTD *p, XML_Parser parser) { + + FREE(parser, p->scaffIndex); + p->scaffIndex = NULL; ++ p->scaffIndexSize = 0; + FREE(parser, p->scaffold); + p->scaffold = NULL; + +@@ -7801,6 +7803,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, + newDtd->scaffSize = oldDtd->scaffSize; + newDtd->scaffLevel = oldDtd->scaffLevel; + newDtd->scaffIndex = oldDtd->scaffIndex; ++ newDtd->scaffIndexSize = oldDtd->scaffIndexSize; + + return 1; + } /* End dtdCopy */ +@@ -8331,6 +8334,7 @@ nextScaffoldPart(XML_Parser parser) { + dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int)); + if (! dtd->scaffIndex) + return -1; ++ dtd->scaffIndexSize = parser->m_groupSize; + dtd->scaffIndex[0] = 0; + } + +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch new file mode 100644 index 00000000000..6fb8f6078ba --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch @@ -0,0 +1,63 @@ +From 2b6ebe08e4b6b3dd4d0f4f197dac18eecef16e6e Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Thu, 4 Jun 2026 17:01:02 -0700 +Subject: [PATCH] lib: doProlog: Fix out-of-bound scaffolding index store +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The scaffold backing array is reallocated using the caller parser’s +per-parser `m_groupSize`, but the DTD struct (which carries +`scaffIndex`) is shared between a parent parser and any external +parameter-entity sub-parser created via +`XML_ExternalEntityParserCreate(parent, NULL, …)`. A sub-parser whose +group nesting is shallower than the parent’s can `REALLOC` the shared +`scaffIndex` down to its own size; when the parent resumes and parses a +deeper element content model, its bounds check passes (its private +`m_groupSize` is still large enough), the doubling-grow path is skipped, +and the next write lands past the shrunken buffer. + +Anthropic: ANT-2026-00037 +Anthropic: ANT-2026-03621 +Anthropic: ANT-2026-03867 +Co-authored-by: Alessandro Gario +Reported-by: Trail of Bits, in collaboration with Anthropic + +CVE: CVE-2026-56132 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e] + +(cherry picked from commit 58400483d7c97be316d7a77739c0a6af5d55932e) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 15 +++++++++++++++ + 1 file changed, 15 insertions(+) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index d4864af8..b528c9bc 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -6022,6 +6022,21 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (myindex < 0) + return XML_ERROR_NO_MEMORY; + assert(dtd->scaffIndex != NULL); ++ if ((size_t)dtd->scaffLevel >= dtd->scaffIndexSize) { ++ /* Detect and prevent integer overflow */ ++ if (dtd->scaffIndexSize > SIZE_MAX / 2 / sizeof(int)) { ++ return XML_ERROR_NO_MEMORY; ++ } ++ assert(dtd->scaffIndexSize > 0); ++ const size_t new_size = dtd->scaffIndexSize * 2; ++ int *const new_scaff_index ++ = REALLOC(parser, dtd->scaffIndex, new_size * sizeof(int)); ++ if (new_scaff_index == NULL) { ++ return XML_ERROR_NO_MEMORY; ++ } ++ dtd->scaffIndex = new_scaff_index; ++ dtd->scaffIndexSize = new_size; ++ } + dtd->scaffIndex[dtd->scaffLevel] = myindex; + dtd->scaffLevel++; + dtd->scaffold[myindex].type = XML_CTYPE_SEQ; +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch new file mode 100644 index 00000000000..5405224ec38 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch @@ -0,0 +1,77 @@ +From 22805ecc87ba8f66b693220442408a6f7c7e741d Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Thu, 4 Jun 2026 17:01:02 -0700 +Subject: [PATCH] tests: Add a test case for scaffolding array limits in shared + DTDs + +This test case provokes the bug fixed in the previous commit. + +Anthropic: ANT-2026-00037 +Anthropic: ANT-2026-03621 +Anthropic: ANT-2026-03867 +Co-authored-by: Alessandro Gario +Reported-by: Trail of Bits, in collaboration with Anthropic + +CVE: CVE-2026-56132 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf] + +(cherry picked from commit 353919b3b9f2174073a557ac7d517a5f3cd0cbbf) +Signed-off-by: Deepak Rathore +--- + expat/tests/basic_tests.c | 33 +++++++++++++++++++++++++++++++++ + 1 file changed, 33 insertions(+) + +diff --git a/expat/tests/basic_tests.c b/expat/tests/basic_tests.c +index 02d1d5fd..53b920da 100644 +--- a/expat/tests/basic_tests.c ++++ b/expat/tests/basic_tests.c +@@ -4091,6 +4091,37 @@ START_TEST(test_skipped_external_entity) { + } + END_TEST + ++START_TEST(test_scaff_index_shared_across_external_entity_parser) { ++ const char text[] ++ = "\n" ++ "\n" ++ "%e;\n" ++ "\n" ++ "]>\n" ++ ""; ++ ExtOption options[] ++ = {{XCS("ext"), ++ ""}, ++ {NULL, NULL}}; ++ ++ XML_Parser parser = XML_ParserCreate(NULL); ++ XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS); ++ XML_SetUserData(parser, options); ++ XML_SetExternalEntityRefHandler(parser, external_entity_optioner); ++ XML_SetElementDeclHandler(parser, dummy_element_decl_handler); ++ ++ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) ++ == XML_STATUS_ERROR) ++ xml_failure(parser); ++ ++ XML_ParserFree(parser); ++} ++END_TEST ++ + /* Test a different form of unknown external entity */ + START_TEST(test_skipped_null_loaded_ext_entity) { + const char *text = "\n" +@@ -6448,6 +6479,8 @@ make_basic_test_case(Suite *s) { + tcase_add_test(tc_basic, test_trailing_cr_in_att_value); + tcase_add_test(tc_basic, test_standalone_internal_entity); + tcase_add_test(tc_basic, test_skipped_external_entity); ++ tcase_add_test__ifdef_xml_dtd( ++ tc_basic, test_scaff_index_shared_across_external_entity_parser); + tcase_add_test(tc_basic, test_skipped_null_loaded_ext_entity); + tcase_add_test(tc_basic, test_skipped_unloaded_ext_entity); + tcase_add_test__ifdef_xml_dtd(tc_basic, test_param_entity_with_trailing_cr); +-- +2.43.7 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch new file mode 100644 index 00000000000..0cef4df4527 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch @@ -0,0 +1,63 @@ +From 36df125531dab7e0dc640b341d07b4b1f5ede37b Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Thu, 4 Jun 2026 17:01:02 -0700 +Subject: [PATCH] lib: Remove unnecessary `scaffIndex` expansion + +Following the previous changes, all locations that append entries to +`scaffIndex` handle expanding the array if it is not already large +enough. So this extra expansion code is no longer necessary. In some +cases such as processing siblings with alternating scaffolding counts, +this logic would actually _shrink_ the array only to then later +re-expand it. + +Anthropic: ANT-2026-00037 +Anthropic: ANT-2026-03621 +Anthropic: ANT-2026-03867 +Co-authored-by: Alessandro Gario + +CVE: CVE-2026-56132 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4] + +Backport Changes: +- Remove the expanded Expat 2.7.5 scaffIndex resize block, including its + branch-specific integer overflow guard. + +(cherry picked from commit bca93b4ba9e15fd84425568d772b69baebf790e4) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 20 -------------------- + 1 file changed, 20 deletions(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index b528c9bc..e59ad556 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -5988,26 +5988,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + } + parser->m_groupConnector = new_connector; + } +- +- if (dtd->scaffIndex) { +- /* Detect and prevent integer overflow. +- * The preprocessor guard addresses the "always false" warning +- * from -Wtype-limits on platforms where +- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */ +-#if UINT_MAX >= SIZE_MAX +- if (parser->m_groupSize > SIZE_MAX / sizeof(int)) { +- return XML_ERROR_NO_MEMORY; +- } +-#endif +- +- int *const new_scaff_index = REALLOC( +- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); +- if (new_scaff_index == NULL) { +- return XML_ERROR_NO_MEMORY; +- } +- dtd->scaffIndex = new_scaff_index; +- dtd->scaffIndexSize = parser->m_groupSize; +- } + } else { + parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); + if (! parser->m_groupConnector) { +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch new file mode 100644 index 00000000000..8655298b65f --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch @@ -0,0 +1,58 @@ +From c6256eca63fe36d4ef26fd59cbcaab7b72e1d6f2 Mon Sep 17 00:00:00 2001 +From: Matthew Fernandez +Date: Thu, 4 Jun 2026 17:01:02 -0700 +Subject: [PATCH] lib: Remove indented scoping of `new_connector` local + +Following the previous change, the lifetime of `new_connector` as +constrained by this introduced scope was identical to the parent scope. + +CVE: CVE-2026-56132 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5] + +Backport Changes: +- Keep the Expat 2.7.5 unsigned-int overflow guard while removing the + redundant new_connector scope. + +(cherry picked from commit 08baa7ef9d168b99094249998fd78f8d190526e5) +Signed-off-by: Deepak Rathore +--- + expat/lib/xmlparse.c | 22 ++++++++++------------ + 1 file changed, 10 insertions(+), 12 deletions(-) + +diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c +index e59ad556..e8d6fc3a 100644 +--- a/expat/lib/xmlparse.c ++++ b/expat/lib/xmlparse.c +@@ -5974,20 +5974,18 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + case XML_ROLE_GROUP_OPEN: + if (parser->m_prologState.level >= parser->m_groupSize) { + if (parser->m_groupSize) { +- { +- /* Detect and prevent integer overflow */ +- if (parser->m_groupSize > (unsigned int)(-1) / 2u) { +- return XML_ERROR_NO_MEMORY; +- } ++ /* Detect and prevent integer overflow */ ++ if (parser->m_groupSize > (unsigned int)(-1) / 2u) { ++ return XML_ERROR_NO_MEMORY; ++ } + +- char *const new_connector = REALLOC( +- parser, parser->m_groupConnector, parser->m_groupSize *= 2); +- if (new_connector == NULL) { +- parser->m_groupSize /= 2; +- return XML_ERROR_NO_MEMORY; +- } +- parser->m_groupConnector = new_connector; ++ char *const new_connector = REALLOC(parser, parser->m_groupConnector, ++ parser->m_groupSize *= 2); ++ if (new_connector == NULL) { ++ parser->m_groupSize /= 2; ++ return XML_ERROR_NO_MEMORY; + } ++ parser->m_groupConnector = new_connector; + } else { + parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); + if (! parser->m_groupConnector) { +-- +2.43.7 diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 9f519b482ec..890ee5b7d34 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -31,6 +31,11 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56409.patch;striplevel=2 \ file://CVE-2026-56411.patch;striplevel=2 \ file://CVE-2026-56407.patch;striplevel=2 \ + file://CVE-2026-56132_p1.patch;striplevel=2 \ + file://CVE-2026-56132_p2.patch;striplevel=2 \ + file://CVE-2026-56132_p3.patch;striplevel=2 \ + file://CVE-2026-56132_p4.patch;striplevel=2 \ + file://CVE-2026-56132_p5.patch;striplevel=2 \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Wed Jul 22 17:23:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93249 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6A7A0C531C9 for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5463.1784741045686506217 for ; Wed, 22 Jul 2026 10:24:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KgJgIZMP; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49548aebcd8so38904215e9.3 for ; Wed, 22 Jul 2026 10:24:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741044; x=1785345844; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hkReuRC1N4+X0sunsm+8dJxzMC36TKs2HtimOp1MD+g=; b=KgJgIZMPn21qlsiE8IdvmeSSHu+wj5PKT4EVi/KAymvoYMfkX51Mu5XWaRuW+i9DcP 9fH//grhzNs1bijUSHu7JmBNjOppPgW2srrs8CW4+i07Pf+y+fl7Jv6j5ijB9ZUFtkMG dX79uXPhpSv11h7cX362OmEalo4esPKJ95XU0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741044; x=1785345844; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hkReuRC1N4+X0sunsm+8dJxzMC36TKs2HtimOp1MD+g=; b=RGcefCsCIB5rFKcBb9TUwMefCtIypVY4lZBKT+yhgsH1M53drf9uJtjGMPlkC4j1Fn CSXAEXCh9KaoZouJFeuJahWhezpKUK4k3pd/lZUxsHi5LEuu/s6V2ntyAkqLqjkWca/9 Urz/VnrWN8QZ3EIn1e/DNMhNjiN7fwvfjmGB2cwSRn4ZlhBsGWLJMTN68MDhkccgAYRU I5cTMgh78NxoJlV12pDAtAxEHYlU3SVdrl26CSFtpD+YMUgO2X3rRqKIzTsV8FW/kfNc R5ZEwOlwR3zoDmVACIoTxY7abj00UUmV6+zX9yobVsE6WgkjovNCezhejCiq5KBlskdB wZHA== X-Gm-Message-State: AOJu0YwvCcOtv4DMqGzRamvromoC8zcXTCIisfI+TWIfTFejFy4hax/L FDAzgJJX6yLvGRDt0ocdB5Ha3Th++5g/tHDux8du3RFi3FCvPMhz/tN8mPOllOrQXNQdnSsHY2Q LueiXRyM= X-Gm-Gg: AR+sD12Da4Vvp5KW9/e3Lj4kZaf+XdM91E0d5cIl9bAm/KjpHIFcGdQFhxvNJIQxxXu BD4L4TNuan7P+OaKmPiSmJ5TfjdJiI7okosYLw81JyEYhCoszJ/GeUvpFVCU/WAr5z/cbP7G8bn aaky5H6mxPfliefclLgnCcubKn7BQ61U6vyy/c0IGEhRKBCEUAapFgOi0z5DCCFTgFnlB3G0Ij3 WGlgSEzjGKBJhWPN3vQOY+kMQxK1KmNTdQ/KxvkEQwB0JvNozG2EHCbIZHWH9dJ4GQMWUFUMJjx AniraIHchjyUtYOrHVexKsqc/jVvQvm+pyTpwZpZtYgofG9dfoBFuFs4c7g4TedQXW39WWaYT4W TzA8QXnhCdA1xTqZu+YCOk4pdMpn8yjXlCJHgQTYbu1CCe/dPWom4MAMO+3ChqZFq7ttR9Bkr0V 8ZMXEBas3VoDAWaw9JqmSv5tDHsubW0pKVwktQ1Yts8NyY05+CmrUnLJQ8dD+DgWfpJ3Byyk9kK sQi2lFmd4Uw X-Received: by 2002:a05:600c:3112:b0:495:472c:208d with SMTP id 5b1f17b1804b1-4954a41307cmr268246435e9.38.1784741043815; Wed, 22 Jul 2026 10:24:03 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/27] gnutls: Fix CVE-2026-3832 Date: Wed, 22 Jul 2026 19:23:24 +0200 Message-ID: <1ca2345a93c623689563fca1b3d4101344222fe2.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241721 From: Deepak Rathore This patch applies the upstream fix [1] and test coverage [2], as referenced in [3], to address multi-record OCSP response handling where GnuTLS could check revocation status from the wrong OCSP entry. [1] https://gitlab.com/gnutls/gnutls/-/commit/731861b9de8dccaf7d3b0c1446833051e48670c2 [2] https://gitlab.com/gnutls/gnutls/-/commit/d52d5f4f383e8c5d8e9a03334f2421ff35d37d2e [3] https://security-tracker.debian.org/tracker/CVE-2026-3832 Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3832 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-3832_p1.patch | 52 ++++++++ .../gnutls/gnutls/CVE-2026-3832_p2.patch | 114 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 + 3 files changed, 168 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p1.patch new file mode 100644 index 00000000000..344a1d241a2 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p1.patch @@ -0,0 +1,52 @@ +From 141c9b6015fc56cd05db3a853f08d03fcbd9b0f4 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Thu, 12 Mar 2026 09:48:57 +0100 +Subject: [PATCH] cert-session: fix multi-entry OCSP revocation bypass + +In check_ocsp_response(), the code first searched +for the SingleResponse that matches the certificate being validated. +But later, the status was retrieved from entry 0 unconditionally, +rather than from the matched resp_indx. +As a result, if entry 0 corresponded to a different certificate and was good, +while the matched entry for the peer certificate is revoked, +the revocation check could've mistakenly accept the certificate. + +Reported-by: Oleh Konko (1seal) +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1801 +Fixes: #1812 +Fixes: CVE-2026-3832 +Fixes: GNUTLS-SA-2026-04-29-12 +CVSS: 3.7 Low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N +Introduced-in: ae404fe8488dee424876b5963c00d7e041672415 3.8.9 + +CVE: CVE-2026-3832 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/731861b9de8dccaf7d3b0c1446833051e48670c2] + +Signed-off-by: Alexander Sosedkin +(cherry picked from commit 731861b9de8dccaf7d3b0c1446833051e48670c2) +Signed-off-by: Deepak Rathore +--- + lib/cert-session.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/lib/cert-session.c b/lib/cert-session.c +index 963f797ee..f48c7a1fb 100644 +--- a/lib/cert-session.c ++++ b/lib/cert-session.c +@@ -343,9 +343,9 @@ static int check_ocsp_response(gnutls_session_t session, gnutls_x509_crt_t cert, + goto cleanup; + } + +- ret = gnutls_ocsp_resp_get_single(resp, 0, NULL, NULL, NULL, NULL, +- &cert_status, &vtime, &ntime, &rtime, +- NULL); ++ ret = gnutls_ocsp_resp_get_single(resp, resp_indx, NULL, NULL, NULL, ++ NULL, &cert_status, &vtime, &ntime, ++ &rtime, NULL); + if (ret < 0) { + _gnutls_audit_log( + session, +-- +2.51.0 + diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p2.patch new file mode 100644 index 00000000000..4b8288ae54a --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-3832_p2.patch @@ -0,0 +1,114 @@ +From ac357f76abeaf59429bc15b8764ad01920df0ef1 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Thu, 12 Mar 2026 15:25:24 +0100 +Subject: [PATCH] tests/ocsp-tests/ocsp-must-staple-connection: test + CVE-2026-3832 + +CVE: CVE-2026-3832 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/d52d5f4f383e8c5d8e9a03334f2421ff35d37d2e] + +Signed-off-by: Alexander Sosedkin +(cherry picked from commit d52d5f4f383e8c5d8e9a03334f2421ff35d37d2e) +Signed-off-by: Deepak Rathore +--- + .../ocsp-tests/ocsp-must-staple-connection.sh | 70 +++++++++++++++++++ + 1 file changed, 70 insertions(+) + +diff --git a/tests/ocsp-tests/ocsp-must-staple-connection.sh b/tests/ocsp-tests/ocsp-must-staple-connection.sh +index 94d41ce24..5e100b9d9 100755 +--- a/tests/ocsp-tests/ocsp-must-staple-connection.sh ++++ b/tests/ocsp-tests/ocsp-must-staple-connection.sh +@@ -85,6 +85,7 @@ OCSP_RESPONSE_FILE="$testdir/ms-resp.tmp" + OCSP_REQ_FILE="$testdir/ms-req.tmp" + INDEXFILE="$testdir/ocsp_index.txt" + ATTRFILE="${INDEXFILE}.attr" ++SERVER_CERT_BAD_FILE="$testdir/ms-cert-bad.pem.tmp" + + stop_servers () + { +@@ -118,6 +119,20 @@ ${CERTTOOL} \ + --load-privkey "${srcdir}/ocsp-tests/certs/server_good.key" \ + --template "${TEMPLATE_FILE}" --outfile "${SERVER_CERT_FILE}" 2>/dev/null + ++echo "=== Generating bad server certificate ===" ++ ++rm -f "$TEMPLATE_FILE" ++cp "${srcdir}/ocsp-tests/certs/server_bad.template" "$TEMPLATE_FILE" ++chmod u+w "$TEMPLATE_FILE" ++echo "ocsp_uri=http://localhost:${OCSP_PORT}/ocsp/" >>"$TEMPLATE_FILE" ++ ++${CERTTOOL} \ ++ --attime "${CERTDATE}" \ ++ --generate-certificate --load-ca-privkey "${srcdir}/ocsp-tests/certs/ca.key" \ ++ --load-ca-certificate "${srcdir}/ocsp-tests/certs/ca.pem" \ ++ --load-privkey "${srcdir}/ocsp-tests/certs/server_bad.key" \ ++ --template "${TEMPLATE_FILE}" --outfile "${SERVER_CERT_BAD_FILE}" 2>/dev/null ++ + echo "=== Bringing OCSP server up ===" + + cp "${srcdir}/ocsp-tests/certs/ocsp_index.txt" ${INDEXFILE} +@@ -486,6 +501,61 @@ kill "${TLS_SERVER_PID}" + wait "${TLS_SERVER_PID}" + unset TLS_SERVER_PID + ++echo "=== Test 10: Server with revoked certificate - CVE-2026-3832 ===" ++ ++# The revocation status was always mistakenly checked for the first cert. ++# Check a pair of responses: (irrelevant good unrevoked, relevant bad revoked). ++ ++rm -f "${OCSP_RESPONSE_FILE}" ++ ++"$FAKETIME" "${TESTDATE}" \ ++ ${OPENSSL} ocsp -index "${INDEXFILE}" \ ++ -issuer "${srcdir}/ocsp-tests/certs/ca.pem" \ ++ -CA "${srcdir}/ocsp-tests/certs/ca.pem" \ ++ -rsigner "${srcdir}/ocsp-tests/certs/ocsp-server.pem" \ ++ -rkey "${srcdir}/ocsp-tests/certs/ocsp-server.key" \ ++ -cert "${SERVER_CERT_FILE}" \ ++ -cert "${SERVER_CERT_BAD_FILE}" \ ++ -respout "${OCSP_RESPONSE_FILE}" ++ ++eval "${GETPORT}" ++# Port for gnutls-serv ++TLS_SERVER_PORT=$PORT ++PORT=${TLS_SERVER_PORT} ++launch_bare_server \ ++ "${SERV}" --attime "${TESTDATE}" --echo --disable-client-cert \ ++ --x509keyfile="${srcdir}/ocsp-tests/certs/server_bad.key" \ ++ --x509certfile="${SERVER_CERT_BAD_FILE}" \ ++ --port="${TLS_SERVER_PORT}" \ ++ --ocsp-response="${OCSP_RESPONSE_FILE}" --ignore-ocsp-response-errors ++TLS_SERVER_PID="${!}" ++wait_server $TLS_SERVER_PID ++ ++wait_for_port "${TLS_SERVER_PORT}" ++ ++out=$( ++ echo "test 123456" | \ ++ "${CLI}" -d1 --attime "${TESTDATE}" --ocsp \ ++ --x509cafile "${srcdir}/ocsp-tests/certs/ca.pem" \ ++ --port "${TLS_SERVER_PORT}" localhost \ ++ 2>&1 ++ rc=$? ++) ++printf '%s\n' "$out" ++ ++if test "${rc}" = "0"; then ++ echo 'ERROR: client accepted a revoked leaf (CVE-2026-3832)' ++ exit 1 ++fi ++if ! echo "${out}" | grep "The certificate was revoked via OCSP" >/dev/null ++then ++ echo '"The certificate was revoked via OCSP" not found in output' ++ exit 1 ++fi ++ ++kill "${TLS_SERVER_PID}" ++wait "${TLS_SERVER_PID}" ++unset TLS_SERVER_PID + + kill ${OCSP_PID} + wait ${OCSP_PID} +-- +2.51.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index b92470768c2..03eee5c50e9 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -32,6 +32,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://0006-buffers-match-DTLS-datagrams-by-sequence-number.patch \ file://0007-tests-mini-dtls-fragments-1839-mismatching-message_s.patch \ file://0008-tests-mini-dtls-framents-link-to-gnulib.patch \ + file://CVE-2026-3832_p1.patch \ + file://CVE-2026-3832_p2.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Wed Jul 22 17:23:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93245 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 50050C531C8 for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5526.1784741046477470958 for ; Wed, 22 Jul 2026 10:24:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=dBJthZxf; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4956869750eso14381265e9.2 for ; Wed, 22 Jul 2026 10:24:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741045; x=1785345845; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hQdxzCmPw+AZsm8mOT3l9VKapbbWIaFhv9ieF2rK/14=; b=dBJthZxfhYldrA/6YEFxncAkswKbXd1fpqbOnKgYdkw9cowAs8O7z01zDH897p0Lm4 2wo6xLIlph0fh3pc66B+UAxtIL58Gx5YHOMhec5ppcytcP7Xmag5kaHovhHNG+LEYsHR fLlLPAXECRD9enCk61Kz4Wf8lDATXKpQoVGK8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741045; x=1785345845; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hQdxzCmPw+AZsm8mOT3l9VKapbbWIaFhv9ieF2rK/14=; b=QtiE2idzHzKzNYyjhDhBJQcRH6vVOxIBVwp9VnVN98cZcsu5mPy5pkSJh5sUIPjVTy bUSFqqPlRpi8ABsDfQ+KLmo5xFUxAxKJ9Zx4zWA7ZpbKvvHlYBMC3DX4FzMogMphhm9y 9L8ZMmaJCO+cBWoj+o1QuSFrK+D2WzVe1X9GjP8zU3qQ7v3sXCouxLkiiF9mc/Dw+9FT 8vZAVah1c90e+SYxOS6uVSHL9wUnIIQ7ki2F35O7KdD4IlVZJavZN9Xab5QPi+k9bVto LVZooczwDYQOL1tnNLnYvSKSYAKo29EtvLBvCqJMZ0VFPKsv2xo+w2qJCd2HPd5WuRq3 chvA== X-Gm-Message-State: AOJu0YxxSkYABh5M/9KhmVyBiAmqNG9/PmwNSlgc9N7CO4EpKLsA/ksy 33nHCy0eTNzur8pTWRwm2pRqE0Zo+KQAM8rnJ/LW25uGsupUUTiZf3JjWAh+dVpALc7AS+GVU+o 8zpqcagw= X-Gm-Gg: AR+sD10hXn5ArbsKJGyGl4uQZY5Fq6NbfU7eVdN0DA9sK8w2oMOOQePLcI0bn1ouvqj QOy6lBPWr3FVs45g0m/aoMfFZwlaQSXjJUoi+WkrhtmvO0XoNpLC/w/oNUVgm4gAWhpOk912RL9 RkhvlLn0cry7kHJMO9op4y6HISjD2ivUvFR7m8KBNJIHKh10P6ioqVM/4Jip3u4pWLn6qJ0i73Z zUaHv3CNv8zpL7yf00zdBAXaOvSnAWsB8HOumO1l0D8sa1eivRZPxmHa5zP+FYxgIPYJ7LQZ64l 5ZHKl48GyuY0rXpoqKqza8WNrU+6i85FN9Xc0yF348GK+JEzn7ibG9k+Jy3y5q5NrzWUPt6WEPe fhqtWOgkefNJj/fPb+CD6ja/V/2YRS5AVrmlPhSIsAKRZe36OHUmolKOzY0bsA0U6xgW+8bjWv5 wQQKBAy/DLz/ODrgYlQgCPkxTLgD3+rKErMgCE1p/tB+D+2QPgT+6BrAYU/m8ipOGgnXcD9QCiE CQ7vmQdvlZv5W74IZ6ORa8UvVNH6f15qQ== X-Received: by 2002:a05:600c:4fc2:b0:495:5b02:23b0 with SMTP id 5b1f17b1804b1-4955b0224c7mr215196185e9.26.1784741044594; Wed, 22 Jul 2026 10:24:04 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/27] gnutls: Fix CVE-2026-42009 Date: Wed, 22 Jul 2026 19:23:25 +0200 Message-ID: <864ca75b27e3b080286ba4c97cdbed9d540a83de.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241722 From: Deepak Rathore This patch applies upstream fixes [1] and [2], as referenced in [3], to address a DTLS packet reordering flaw where duplicate sequence numbers could lead to unstable ordering or undefined behavior. Rebase CVE-2026-42009_p1.patch on top of the Wrynose CVE-2026-33846 backport stack, which already includes the recv_buf helper from upstream commit 9deffca528c23bbb218f5ec3bd4bb1bf4cbd1fc0. [1] https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d [2] https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f [3] https://security-tracker.debian.org/tracker/CVE-2026-42009 Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42009 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42009_p1.patch | 62 +++++++++++++++++++ .../gnutls/gnutls/CVE-2026-42009_p2.patch | 48 ++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 + 3 files changed, 112 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch new file mode 100644 index 00000000000..e01fcc19acc --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch @@ -0,0 +1,62 @@ +From d1191b910e63149a10647a089995d3cd85e16400 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 21 Apr 2026 16:52:48 +0200 +Subject: [PATCH] lib/buffers: ensure packets have differing sequence + numbers + +There should normally be no packets with same sequence number and +differing handshake type, unless an adversary crafts them. +Discarding them allows to get rid of packets +with duplicate sequence ID in the buffer, +relieving us from the question of how to sort them later. + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1848 +Fixes: CVE-2026-42009 +Fixes: GNUTLS-SA-2026-04-29-2 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H + +CVE: CVE-2026-42009 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d] + +Backport Changes: +- Rebased on top of the Wrynose CVE-2026-33846 backport stack, which + already includes the recv_buf helper and sequence-number matching + prerequisite patches. + +Signed-off-by: Alexander Sosedkin +(cherry picked from commit f01e21441e29052a6f0963840794c41d3b3ee66d) +Signed-off-by: Deepak Rathore +--- + lib/buffers.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index 62f140ed3..e7f08b5625 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -971,8 +971,20 @@ static int merge_handshake_packet(gnutls_session_t session, + session->internals.handshake_recv_buffer; + + for (i = 0; i < session->internals.handshake_recv_buffer_size; i++) { +- if (recv_buf[i].htype == hsk->htype && +- recv_buf[i].sequence == hsk->sequence) { ++ if (recv_buf[i].sequence == hsk->sequence) { ++ if (recv_buf[i].htype != hsk->htype) { ++ _gnutls_audit_log( ++ session, ++ "Discarded unexpected handshake packet " ++ "with duplicate sequence %d, but " ++ "mismatched type %s (previously %s)\n", ++ hsk->sequence, ++ _gnutls_handshake2str(hsk->htype), ++ _gnutls_handshake2str( ++ recv_buf[i].htype)); ++ _gnutls_handshake_buffer_clear(hsk); ++ return 0; ++ } + exists = 1; + pos = i; + break; +-- +2.51.0 diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch new file mode 100644 index 00000000000..d834d3da203 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch @@ -0,0 +1,48 @@ +From 5374a6d584b8598511f7880b4e64ee52ee1f0cc5 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Tue, 21 Apr 2026 18:11:39 +0200 +Subject: [PATCH] buffers: fix handshake_compare when sequence numbers + match + +The comparator function used for ordering DTLS packets +by sequence numbers did not follow qsort comparator contracts +in case of packets with duplicate sequence numbers, +which could lead to unstable ordering or undefined behaviour. +Returning 0 in such cases makes the sorting stable. + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1848 +Fixes: CVE-2026-42009 +Fixes: GNUTLS-SA-2026-04-29-2 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H + +CVE: CVE-2026-42009 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f] + +Signed-off-by: Joshua Rogers +(cherry picked from commit f341441fad91142897d83b44a175ffc8f925b76f) +Signed-off-by: Deepak Rathore +--- + lib/buffers.c | 6 +----- + 1 file changed, 1 insertion(+), 5 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index e7f08b5625..1ac27e4e96 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -844,11 +844,7 @@ static int handshake_compare(const void *_e1, const void *_e2) + { + const handshake_buffer_st *e1 = _e1; + const handshake_buffer_st *e2 = _e2; +- +- if (e1->sequence <= e2->sequence) +- return 1; +- else +- return -1; ++ return (e1->sequence < e2->sequence) - (e1->sequence > e2->sequence); + } + + #define SSL2_HEADERS 1 +-- +2.51.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index 03eee5c50e9..3085a62310a 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -34,6 +34,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://0008-tests-mini-dtls-framents-link-to-gnulib.patch \ file://CVE-2026-3832_p1.patch \ file://CVE-2026-3832_p2.patch \ + file://CVE-2026-42009_p1.patch \ + file://CVE-2026-42009_p2.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Wed Jul 22 17:23:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93242 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3B02BC531C7 for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5527.1784741046924850642 for ; Wed, 22 Jul 2026 10:24:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Jxj5dMrL; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4954a9e8490so28732605e9.1 for ; Wed, 22 Jul 2026 10:24:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741045; x=1785345845; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=YeE4hTvZZE1z6dOCpnXSSFnb8hRh6l+8ObjSDf/O8DU=; b=Jxj5dMrLFHIKL0yOlsJuYnYuSEcILzYQEQFiPqKTpnkaP6jOU/yTBjju/XVcjpFd0d 6HOZN+fbmFrjGRHK3onM5gjxS6QrcXJOQABfj5mgZ/gysjW1j4/WZoA28YaG5O+CjhIb NaaCQmfXn/XSrrRs6fih1AgI7e3HtD0m7JuJw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741045; x=1785345845; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YeE4hTvZZE1z6dOCpnXSSFnb8hRh6l+8ObjSDf/O8DU=; b=sPZofE62QiC8g6FGbYE6kgpC46j2aOvSF90CJ3gViBvuD7YE6LUNpjXU+NBPZkGLmk D/TKQNnT/VAOGk0XQwqWO7LTmiCvorRMmaz9qHviVTYz/7eqhNgS/nk2ws7ijs2jeBCn yI73Tu9GCBxdgpOYOoTs+Oe3fc/7D42ithJdTTDb5W3i+mOfErZM7WDKzwuQI6OLGWWY ldXFlmOHWmPiMkRoccKCg4yyKH5RLgrGSpOH0nDxP9Dyo9apteyrNHXe6LkcCHNfYNxv 9soO6UhTDobKeNaEQXU0RF/EKKIKGdrzlxHhGYd9U17zGF8GOFD8H6+GbvKPEHglE68b 7YZA== X-Gm-Message-State: AOJu0YyCAQ9R3fLhVK5lIpcMkErBnJyLP5id4aO+FOfMrgAVI5sBOkjD hVsjDWLTja8etgmsXJGHuS8gdBsa0j01CtKmWdPiKkbr1FW2eLEgm+NFhZLp1Cq5ZQ5c6FTdrTR GuqXqeuo= X-Gm-Gg: AR+sD122ULgaDZhC5KMf11i+87ifYixbmZ17Df3jRWtcpqOHQaTAF9HEC+9HilaiZ4S yxIfvVUWEi8Ri3VI51yqHEr/M3FLg4bKDFlojgd6TyuoOQgyHSKb8Mp6PCvHLB6O2fOTxUAa08y 8vWTun9YTIBVrux67zEt0ZivA+MKmuMgD216ALa3tBBPiTseeAA7DYOBYxcjOV3GmTwu7Deobka Lzsqii48/v54FMGy0rDKuazxySmBWbXj0yCP5vu5kkxoA7pFcZbm+cGihMxhYrhuLEyOTx8FXlx rboueqznpyVBiQ60hyAewLVt4FHETr2JMenDqZ9hSwIqD4z+CX/N7GmFF36Euj4cWErXIrpMNwG MNACdKfdq/J0avzUesEX1fBx/v029oU1z4jqZ2li/4sqgRCirCc4qTZLcUeDEjmvGFcTY7Sd7Hm je5mFQrra7BCPKaRboV6MPNz+bzKzcqeiDUt65otCqt8PvIEowsb5B69Y2WbYsyuuumFI8ZbcWs sA5qHiF5h/tE0L+UEfyPX4= X-Received: by 2002:a05:600c:3b98:b0:495:495f:bc30 with SMTP id 5b1f17b1804b1-4956a4fff26mr56334925e9.12.1784741045155; Wed, 22 Jul 2026 10:24:05 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/27] curl: ignore CVE-2026-4873 Date: Wed, 22 Jul 2026 19:23:26 +0200 Message-ID: <3f4ccfb2028c1be88a5c82ea9df557150dd9e542.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241723 From: Deepak Rathore - CVE-2026-4873 affects curl before 8.20.0 when a connection negotiated with clear-text IMAP, POP3, or SMTP can later be reused for a TLS-required transfer. - In wrynose, these protocols are optional PACKAGECONFIG entries and are not enabled by default in curl_8.19.0.bb, so record this CVE as configuration-not-applicable for the default recipe configuration. Reference: - https://curl.se/docs/CVE-2026-4873.html - https://nvd.nist.gov/vuln/detail/CVE-2026-4873 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.19.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 3326f478b5c..1cda69401bc 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -28,6 +28,7 @@ SRC_URI[sha256sum] = "4eb41489790d19e190d7ac7e18e82857cdd68af8f4e66b292ced562d33 # Curl has used many names over the years... CVE_PRODUCT = "haxx:curl haxx:libcurl curl:curl curl:libcurl libcurl:libcurl daniel_stenberg:curl" CVE_STATUS[CVE-2024-32928] = "ignored: CURLOPT_SSL_VERIFYPEER was disabled on google cloud services causing a potential man in the middle attack" +CVE_STATUS[CVE-2026-4873] = "${@bb.utils.contains_any('PACKAGECONFIG', 'imap pop3 smtp', 'unpatched', 'not-applicable-config: clear-text imap/pop3/smtp support is not enabled in PACKAGECONFIG', d)}" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Wed Jul 22 17:23:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93250 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F385FC531CD for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5466.1784741047471534740 for ; Wed, 22 Jul 2026 10:24:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FouVbe/S; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49571fea44eso1857445e9.2 for ; Wed, 22 Jul 2026 10:24:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741046; x=1785345846; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FuZ5ctE9tcxm/+B6DuH0pf2kZVX2gM+jbnvauP5Sqno=; b=FouVbe/SnExvHkzPz2Kj4wQOD6eRE425no2kMh0dtgLlUYX4pKnxt12tEj/rzIX/eg up+TMQ+EonSGaFP+sH9p09acjRRd8PFiYYZwkWOLfBFD9H50H+V9kT+vinQcr/O/P8w+ Z1xNqgLfTJCNGjRJmN+1Edmq/J10Q9auMzWY4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741046; x=1785345846; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FuZ5ctE9tcxm/+B6DuH0pf2kZVX2gM+jbnvauP5Sqno=; b=R6g6LR8NYmlvaL4Qyr1WF3+MjbaYMbBTqGv9Vcx9IHaw3oOJHyYttVYRO9hlzIgCXz Rgfztf+bPGL4mnefh0QweFPIZ7Sl8QwBIkcHBCebwKfa00yBwUSZ1VwSKBKVtnN8dc0l Y7hNQt3+Jq6U3Lm22XA8Dz47eb6vEwS5D3VV6Q1U7TLuwo2aMKxoYiJeJAJ5RCFEXsNs h08zx8Qbu3wop6nyVXC+WyBAoLvNI9yP96iEtxieXwvY56BePiwCFrqolL6cW7lWAT1K N4nWMZgq0gtY3xUkETA5FcySGhNMsxwxNxRrMIWvptpwnGPIFixdj3Lut2PhIvNMlUI7 XXzw== X-Gm-Message-State: AOJu0YxpLAiSl00AyFGOgud30x3EXxvsagVEImYigErVzAo7jVFW/LYg 2Fo9zahPs/wqemvXpioKvDvrAK0ObgQOxgyG8pyhC0Ttr826lzHLafbbZ4p5qDNM0ozZzBq71YX UO2/PYpw= X-Gm-Gg: AR+sD12tHHkpxMJSq06F9khnBJwAxQH8kAbKk2nqDC5tNPajVUQKu5MSpFuH1F810Iy iqhQ0SvPiIqdlouwSBzJNp3iSYCfS04sEktPSmPfQUO1rFZgVbcTUjjCuow4srZJgmjY9JLzN1X Ul7DLDB9MiqAx7axgLd4glRrkUGiArzMBJFSlot5wb7O69bO8QyJWxZTdlXkfq9vI63OBXNOVs/ SydoQZLqbBxRrlpCpwaNfySx2DydV/Ou5rEv7LErtzsRdIzDK+Nld6Je7mui34L43VvFGGVBfOf Ozj9ySlK5VTtfGSgTbLYqsU1pEwC5+nDxElZ9LLWnwA9VBw6mTghwLE5SeSRPSUufGI7Zal4wk+ 8qL6rJL29euE2GJrfpNoJ0aT5XVvqXlGR2y+KayWkrCb78cJytGMbfMAPAfBx3urN8LEY1OP3wA HZ+nE3eRL/2gOZvhzrtbxXCQD85jg7FwAJdQQdqjBnMuCWxREgeNjVJap9CIBBRJnGTDZt8eBLh 8Mf3S8/K/T0 X-Received: by 2002:a05:600c:3515:b0:495:6788:c21b with SMTP id 5b1f17b1804b1-4956788c2b1mr83769195e9.27.1784741045603; Wed, 22 Jul 2026 10:24:05 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/27] curl: fix CVE-2026-5545 Date: Wed, 22 Jul 2026 19:23:27 +0200 Message-ID: <75a294ff9b5f67fd25abf9755c1270b619a8cdab.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241724 From: Deepak Rathore Backport the upstream fix [1] for the Negotiate-authenticated connection reuse issue described in [2] and tracked by [3]. [1] https://github.com/curl/curl/commit/33e43985b8f3b9e66691d06e70be0395849856cd [2] https://curl.se/docs/CVE-2026-5545.html [3] https://nvd.nist.gov/vuln/detail/CVE-2026-5545 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-5545.patch | 43 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 44 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-5545.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-5545.patch b/meta/recipes-support/curl/curl/CVE-2026-5545.patch new file mode 100644 index 00000000000..bb3b1407d47 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-5545.patch @@ -0,0 +1,43 @@ +From 33e43985b8f3b9e66691d06e70be0395849856cd Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Thu, 2 Apr 2026 11:33:39 +0200 +Subject: [PATCH] url: improve connection reuse on negotiate + +Check state of negotiate to allow proper connection reuse. + +Closes #21203 + +CVE: CVE-2026-5545 +Upstream-Status: Backport [https://github.com/curl/curl/commit/33e43985b8f3b9e66691d06e70be0395849856cd] + +(cherry picked from commit 33e43985b8f3b9e66691d06e70be0395849856cd) +Signed-off-by: Deepak Rathore +--- + lib/url.c | 12 +++++++++--- + 1 file changed, 9 insertions(+), 3 deletions(-) + +diff --git a/lib/url.c b/lib/url.c +index b9e308a..7c24f1a 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -1110,11 +1110,17 @@ static bool url_match_auth_ntlm(struct connectdata *conn, + if(m->want_ntlm_http) { + if(Curl_timestrcmp(m->needle->user, conn->user) || + Curl_timestrcmp(m->needle->passwd, conn->passwd)) { +- + /* we prefer a credential match, but this is at least a connection +- that can be reused and "upgraded" to NTLM */ +- if(conn->http_ntlm_state == NTLMSTATE_NONE) ++ that can be reused and "upgraded" to NTLM if it does ++ not have any auth ongoing. */ ++#ifdef USE_SPNEGO ++ if((conn->http_ntlm_state == NTLMSTATE_NONE) ++ && (conn->http_negotiate_state == GSS_AUTHNONE)) { ++#else ++ if(conn->http_ntlm_state == NTLMSTATE_NONE) { ++#endif + m->found = conn; ++ } + return FALSE; + } + } diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 1cda69401bc..558a2d311e4 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -17,6 +17,7 @@ SRC_URI = " \ file://CVE-2026-6276.patch \ file://CVE-2026-5773.patch \ file://mbedtls.patch \ + file://CVE-2026-5545.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Jul 22 17:23:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93246 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0CD33C531BC for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5467.1784741048077849641 for ; Wed, 22 Jul 2026 10:24:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=dPqzHvy9; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495635a85d2so27814975e9.0 for ; Wed, 22 Jul 2026 10:24:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741046; x=1785345846; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=s5U72hCelqwwH0R1XRJ6k0zGPeqO/dneePdOID4oNlU=; b=dPqzHvy9GLYxXbvC7QscaJ1Oq0kD9nKQnmlK4YgKNsUbhCDRHE2hmEI84TlKfVFkAo zS1EqqPuorqTsA3C+R1PcMXxAhPvq+Ek1/mwKuvyWmMQ4/p68MpWSelV2F0iIf9b3m2o oAIFml1Py3zBSiVKkbq8Zx+Fl8Pxy/Dg4i2Mw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741046; x=1785345846; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=s5U72hCelqwwH0R1XRJ6k0zGPeqO/dneePdOID4oNlU=; b=LJGX+pSKxrTvUd7Zo/JMmJSDaRCtY0c3i+tRu0p7VwLAjlFJtuWu4WIlUchGH74EVf N/WPN3SD9ilI13hxTa2ZXLBk5edkXvEEHrmmU9QK44HPR4izXqchGgwn1bioEzrlVNcJ sx4RSDOHDEkZy3zKld9HXlkcLiDuYu5CbA2k5BjEhcDzjemypjn+TSjaDd60OHJNmIG6 GIBEh8tfjc50T2S7Fk15INolNbDZeWTHW3xT5KXPpGpZJ27ETVgslIPIlEo02xlgkVpf ZHbkGAfxzeEa1YzDyxvM0EM14sHS2h+j2eDydU3vopekd7IkfzQ8HLiLAZ4Z7paDv+Aj UAuQ== X-Gm-Message-State: AOJu0YzYuSgZZFRCtovsFJHYjFQak/0ihscOpoWiH6D+8z//4HIrWfbw K05NdSzVZvG1h2M4+dzjlecCNZJqf9q/M7VYuAhtIyFvW3sicZBwYTmjYwaTZEPwJuUw6yIFpi6 RA8B7xD4= X-Gm-Gg: AR+sD10rHbbC30VOxPY4zlnaO33PaC1eqZ6VhcECwC+7cpqwH+sI3bcPXRAwoBeUdz3 pOhMz7o+/zVUGjOD/frzhBvsfTnzLnt0ERFRaKrPjFH5H7P8iP29U79piooq2nDWFbutZRbCQwC Rv9kPsur+zTMgylEoeM3ig4NT8KD6ASALJXQmpNI0pSaNKlCDn2w9qvl2vWNq/UvG2rkWkw+Gpq qPvMn0bJwVTw2p/W5A2oRSqciKTWJCpzK0PwHopGMpN70w7RXoq8LGz/b2YEYbZ7EOtyPTmjlfc JjoaNarAI2Rc6Kjne19R/55IBEIxuFLraphxkye/n+P+x+Glh84oCbz/oGgLH7Y/yznWPxPvofX H2gZGHaOUGRuFdbLvVC6T1v2yMNrA64W91d44KwMBsgTJeA8bTJ7mIYZTZQycDt7W3+yX4I2Zpz 2lcyvz1JGgEMa4aWnPPX49dNEHzCpedfsSP9b4lkrZcaskmmOiEQ4ZW4iojdMPvClZsqeJ8YJ/J nU8mm9ZMkEALXLjAYh1b84= X-Received: by 2002:a05:600c:b85:b0:495:5365:c0d1 with SMTP id 5b1f17b1804b1-49553d85ea0mr229285005e9.14.1784741046188; Wed, 22 Jul 2026 10:24:06 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/27] curl: fix CVE-2026-6253 Date: Wed, 22 Jul 2026 19:23:28 +0200 Message-ID: <31dac2d3108bf2b86ba7e349123351742ac6effb.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241725 From: Deepak Rathore Backport the upstream fix [1] for the proxy credential leak on redirect described in [2] and tracked by [3]. [1] https://github.com/curl/curl/commit/188c2f166a20fa97c2325b2da7d0e5cecc13725f [2] https://curl.se/docs/CVE-2026-6253.html [3] https://nvd.nist.gov/vuln/detail/CVE-2026-6253 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-6253.patch | 389 ++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 390 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6253.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-6253.patch b/meta/recipes-support/curl/curl/CVE-2026-6253.patch new file mode 100644 index 00000000000..0e7dd72612a --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6253.patch @@ -0,0 +1,389 @@ +From 188c2f166a20fa97c2325b2da7d0e5cecc13725f Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 13 Apr 2026 17:17:23 +0200 +Subject: [PATCH] http: clear the proxy credentials as well on port or scheme + change + +Add tests 2009-2011 to verify switching between proxies with credentials +when the switch is driven by a redirect + +Reported-by: Dwij Mehta + +Closes #21304 + +CVE: CVE-2026-6253 +Upstream-Status: Backport [https://github.com/curl/curl/commit/188c2f166a20fa97c2325b2da7d0e5cecc13725f] + +Backport Changes: +- Adapted the redirect credential reset hunk to curl 8.19.0 Curl_http_follow() after the existing wrynose CVE-2026-6276 backport. +- Adapted tests/data/Makefile.am placement for the wrynose test list. + +(cherry picked from commit 188c2f166a20fa97c2325b2da7d0e5cecc13725f) +Signed-off-by: Deepak Rathore +--- + lib/http.c | 12 +++++++ + lib/transfer.c | 51 +++++++++++++++++++++--------- + lib/transfer.h | 2 ++ + tests/data/Makefile.am | 1 + + tests/data/test2009 | 70 +++++++++++++++++++++++++++++++++++++++++ + tests/data/test2010 | 71 ++++++++++++++++++++++++++++++++++++++++++ + tests/data/test2011 | 70 +++++++++++++++++++++++++++++++++++++++++ + 7 files changed, 262 insertions(+), 15 deletions(-) + create mode 100644 tests/data/test2009 + create mode 100644 tests/data/test2010 + create mode 100644 tests/data/test2011 + +diff --git a/lib/http.c b/lib/http.c +index 7ebbdfa..b960d79 100644 +--- a/lib/http.c ++++ b/lib/http.c +@@ -1252,12 +1252,24 @@ CURLcode Curl_http_follow(struct Curl_easy *data, const char *newurl, + curlx_free(scheme); + } + if(clear) { ++ CURLcode result = Curl_reset_userpwd(data); ++ if(result) { ++ curlx_free(follow_url); ++ return result; ++ } + Curl_safefree(data->state.aptr.user); + Curl_safefree(data->state.aptr.passwd); + } + } + } + DEBUGASSERT(follow_url); ++ { ++ CURLcode result = Curl_reset_proxypwd(data); ++ if(result) { ++ curlx_free(follow_url); ++ return result; ++ } ++ } + + if(type == FOLLOW_FAKE) { + /* we are only figuring out the new URL if we would have followed locations +diff --git a/lib/transfer.c b/lib/transfer.c +index 6dd2f52..af5bee2 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -439,6 +439,40 @@ void Curl_init_CONNECT(struct Curl_easy *data) + data->state.upload = (data->state.httpreq == HTTPREQ_PUT); + } + ++/* ++ * Restore the user credentials to those set in options. ++ */ ++CURLcode Curl_reset_userpwd(struct Curl_easy *data) ++{ ++ CURLcode result; ++ if(data->set.str[STRING_USERNAME] || data->set.str[STRING_PASSWORD]) ++ data->state.creds_from = CREDS_OPTION; ++ result = Curl_setstropt(&data->state.aptr.user, ++ data->set.str[STRING_USERNAME]); ++ if(!result) ++ result = Curl_setstropt(&data->state.aptr.passwd, ++ data->set.str[STRING_PASSWORD]); ++ return result; ++} ++ ++/* ++ * Restore the proxy credentials to those set in options. ++ */ ++CURLcode Curl_reset_proxypwd(struct Curl_easy *data) ++{ ++#ifndef CURL_DISABLE_PROXY ++ CURLcode result = Curl_setstropt(&data->state.aptr.proxyuser, ++ data->set.str[STRING_PROXYUSERNAME]); ++ if(!result) ++ result = Curl_setstropt(&data->state.aptr.proxypasswd, ++ data->set.str[STRING_PROXYPASSWORD]); ++ return result; ++#else ++ (void)data; ++ return CURLE_OK; ++#endif ++} ++ + /* + * Curl_pretransfer() is called immediately before a transfer starts, and only + * once for one transfer no matter if it has redirects or do multi-pass +@@ -584,23 +618,10 @@ CURLcode Curl_pretransfer(struct Curl_easy *data) + return CURLE_OUT_OF_MEMORY; + } + +- if(data->set.str[STRING_USERNAME] || +- data->set.str[STRING_PASSWORD]) +- data->state.creds_from = CREDS_OPTION; + if(!result) +- result = Curl_setstropt(&data->state.aptr.user, +- data->set.str[STRING_USERNAME]); ++ result = Curl_reset_userpwd(data); + if(!result) +- result = Curl_setstropt(&data->state.aptr.passwd, +- data->set.str[STRING_PASSWORD]); +-#ifndef CURL_DISABLE_PROXY +- if(!result) +- result = Curl_setstropt(&data->state.aptr.proxyuser, +- data->set.str[STRING_PROXYUSERNAME]); +- if(!result) +- result = Curl_setstropt(&data->state.aptr.proxypasswd, +- data->set.str[STRING_PROXYPASSWORD]); +-#endif ++ result = Curl_reset_proxypwd(data); + + data->req.headerbytecount = 0; + Curl_headers_cleanup(data); +diff --git a/lib/transfer.h b/lib/transfer.h +index 05a5f89..131e31a 100644 +--- a/lib/transfer.h ++++ b/lib/transfer.h +@@ -31,6 +31,8 @@ char *Curl_checkheaders(const struct Curl_easy *data, + + void Curl_init_CONNECT(struct Curl_easy *data); + ++CURLcode Curl_reset_userpwd(struct Curl_easy *data); ++CURLcode Curl_reset_proxypwd(struct Curl_easy *data); + CURLcode Curl_pretransfer(struct Curl_easy *data); + + CURLcode Curl_sendrecv(struct Curl_easy *data); +diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am +index da0f8f5..00a5221 100644 +--- a/tests/data/Makefile.am ++++ b/tests/data/Makefile.am +@@ -244,6 +244,7 @@ test1970 test1971 test1972 test1973 test1974 test1975 test1976 test1977 \ + test1978 test1979 test1980 test1981 \ + \ + test2000 test2001 test2002 test2003 test2004 test2005 test2006 \ ++test2009 test2010 test2011 \ + \ + test2023 \ + test2024 test2025 test2026 test2027 test2028 test2029 test2030 test2031 \ +diff --git a/tests/data/test2009 b/tests/data/test2009 +new file mode 100644 +index 0000000..d2fd79e +--- /dev/null ++++ b/tests/data/test2009 +@@ -0,0 +1,70 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy credentials via env variables, redirect from http to https ++ ++ ++ ++http_proxy=http://user:secret@%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++http://somewhere.example/ --follow --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[user:secret]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ +diff --git a/tests/data/test2010 b/tests/data/test2010 +new file mode 100644 +index 0000000..443ae9d +--- /dev/null ++++ b/tests/data/test2010 +@@ -0,0 +1,71 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy credentials via options for two proxies, redirect from http to https ++ ++ ++ ++http_proxy=http://%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++--proxy-user batman:robin http://somewhere.example/ --follow --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[batman:robin]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++Proxy-Authorization: Basic %b64[batman:robin]b64% ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ +diff --git a/tests/data/test2011 b/tests/data/test2011 +new file mode 100644 +index 0000000..dd4e534 +--- /dev/null ++++ b/tests/data/test2011 +@@ -0,0 +1,70 @@ ++ ++ ++ ++ ++HTTP ++HTTP proxy ++http_proxy ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 407 Denied ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: test-server/fake ++Content-Length: 4 ++Content-Type: text/html ++Location: https://another.example/%TESTNUMBER0002 ++ ++boo ++ ++ ++ ++# Client-side ++ ++ ++proxy ++ ++ ++http ++https ++ ++ ++proxy creds via env, cross-scheme redirect, --location-trusted ++ ++ ++ ++http_proxy=http://user:secret@%HOSTIP:%HTTPPORT ++https_proxy=https://%HOSTIP:%HTTPSPORT/ ++ ++ ++http://somewhere.example/ --location-trusted --proxy-insecure ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://somewhere.example/ HTTP/1.1 ++Host: somewhere.example ++Proxy-Authorization: Basic %b64[user:secret]b64% ++User-Agent: curl/%VERSION ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++CONNECT another.example:443 HTTP/1.1 ++Host: another.example:443 ++User-Agent: curl/%VERSION ++Proxy-Connection: Keep-Alive ++ ++ ++ ++7 ++ ++ ++ diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 558a2d311e4..b1ee0f8b9ba 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -18,6 +18,7 @@ SRC_URI = " \ file://CVE-2026-5773.patch \ file://mbedtls.patch \ file://CVE-2026-5545.patch \ + file://CVE-2026-6253.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Jul 22 17:23:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93241 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01335C4453D for ; Wed, 22 Jul 2026 17:24:10 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5528.1784741048772402006 for ; Wed, 22 Jul 2026 10:24:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wWETIodu; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-495590dde14so38694875e9.0 for ; Wed, 22 Jul 2026 10:24:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741047; x=1785345847; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=+lf9EfFez7rZ8mXLwNVnIpXc5tQQrGR5PD9K89CSwP4=; b=wWETIoduZPRXWwcNQ9lpK0DjRxV3g0vh4tKxuOjtSpwVwhtBSo9Iq0VoWArV7awzN/ G52AZCKHqGez2HVBWRoFITawlmGbaRMWXe8AOBDzbhOPDhnKgQz/bXenJP5WUjNF2q8G 7iD8PdvDvoxI7beb7Tl3cE3M/JI2kTbfPt8Lk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741047; x=1785345847; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=+lf9EfFez7rZ8mXLwNVnIpXc5tQQrGR5PD9K89CSwP4=; b=jnqzVmhlWmCMGy/J1rueP/psLpqBi98h4gauQVFJmHQps8DkVaPvJcofaCruuL8awo jgstQ2os0YIkMH0v8dHJGFfLLdXVOgdbAfR0qdUpIktu+lPBkZihOaKUdWjMXP8NYSFw M+ev095syX0rm69THwqZHYc0LUzqj6sSLTO45y0HH39AzgevKAtL1PynlGWAd2sFdKBe XA88hiRmwfutjUuZoY44u7G3YF5KhDhWL4smJEtSJs25SJ95KmRHNOi75Sn00gK6C1SF BwIJ2olf5sm+uAJVt8ztskQ8CzfeiuqdmH66HZvZusxbskyIg5Tm1iIcmldhp5p9Lekg 7GAw== X-Gm-Message-State: AOJu0YzTTQkWaWq6ZFoKYbbJfwT+rQHobo+tRj6dW3+eL97NbK+Vor0/ rHx4HPWzlLlRgC4LYcN2MQnHizlbjS51VDGsXkzC95fE+3azF5bMsCF4IGFvWUx0LADCqNg6HDk NalFKkKc= X-Gm-Gg: AR+sD1301+iyFiPWi9SqKjcnuiQKoLzEwMrIPxuNsiVmP+nNE5Ev65IXaX6l9ujRtpa XTshkwzfNoj1WwPo5Nwju3KyX5KLYkEjRgS9D4Yh61Yx60aGD+DwjhynDUDZq53UjOkNMwBf5ZW RzJi37+8q3HWov0G0LHr7P4VD1FSiUcnruZI1SEMxMLhUvb5DHjEoZPTga9WIUVukarGyKzIaXy jsMkXX4+W0oXE+8LJthHgUL/jrYC5ubjn3AYVHJdfp8JecdnRqooNWmSbK33lz1z0/Rmz9XsAgE IiyrpXjZL9lP6/BkDYCoWfDiKaSoN/Clj+9EharIggxR0DTwbnN9T1CWNu4kQjCPsVvOYOMKXC2 eKa/XaWsEKEA1LLQxflCrhgECQVm3s2HZyW/HANwjMb3qleEeq9J+iK4SQm4HbXvIuazBMBNdfa lDfNjDgzcPWafqO2nObzllJBXWrGVXthTEjrsM3zyqPfKRK9A1nHXLe4X8RFGUw1wFYfQQrRjtj x7Ld0VAAviCkKivZQdivGQ= X-Received: by 2002:a05:600c:3b01:b0:495:4fd4:144b with SMTP id 5b1f17b1804b1-4954fd419e8mr233995735e9.21.1784741046762; Wed, 22 Jul 2026 10:24:06 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/27] curl: fix CVE-2026-6429 Date: Wed, 22 Jul 2026 19:23:29 +0200 Message-ID: <7e491ba091f3a0cc15ce2c29accdaec84c0ef46a.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241726 From: Deepak Rathore Backport the upstream fix [1] and the required dependent change [2] to address the netrc credential leak across redirects, as mentioned in [3] and tracked by [4]. [1] https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 [2] https://github.com/curl/curl/commit/32a513e180ce83d5e9b708211306045407074134 [3] https://curl.se/docs/CVE-2026-6429.html [4] https://nvd.nist.gov/vuln/detail/CVE-2026-6429 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-6429-dependent.patch | 81 +++++ .../curl/curl/CVE-2026-6429.patch | 325 ++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 2 + 3 files changed, 408 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6429-dependent.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2026-6429.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-6429-dependent.patch b/meta/recipes-support/curl/curl/CVE-2026-6429-dependent.patch new file mode 100644 index 00000000000..a3f68ae5392 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6429-dependent.patch @@ -0,0 +1,81 @@ +From 6b1769c54659f1e6d6323891cb45c682c22182b7 Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Wed, 15 Apr 2026 10:43:12 +0200 +Subject: [PATCH] urlapi: same origin tests + +Add new internal `curl_url_same_origin()` to check if a href has the +same origin as a base URL. Add test cases in test1675 and use this in +http2 push handling. + +Closes #21328 + +CVE: CVE-2026-6429 +Upstream-Status: Backport [https://github.com/curl/curl/commit/32a513e180ce83d5e9b708211306045407074134] + +Backport Changes: +- curl 8.19.0 does not provide Curl_url_same_origin(), but the CVE-2026-6429 + fix from https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 + uses it in lib/http.c. +- kept only the helper declaration and implementation of + lib/urlapi-int.h and lib/urlapi.c. +- Excluded unrelated upstream test and HTTP/2 changes from that commit. + +(cherry picked from commit 32a513e180ce83d5e9b708211306045407074134) +Signed-off-by: Deepak Rathore +--- + lib/urlapi-int.h | 2 ++ + lib/urlapi.c | 33 +++++++++++++++++++++++++++++++++ + 2 files changed, 35 insertions(+) + +diff --git a/lib/urlapi-int.h b/lib/urlapi-int.h +index 29d4fe5f39..591062035b 100644 +--- a/lib/urlapi-int.h ++++ b/lib/urlapi-int.h +@@ -40,4 +40,6 @@ UNITTEST CURLUcode Curl_parse_port(struct Curl_URL *u, struct dynbuf *host, + #define U_CURLU_URLDECODE (unsigned int)CURLU_URLDECODE + #define U_CURLU_PATH_AS_IS (unsigned int)CURLU_PATH_AS_IS + ++bool Curl_url_same_origin(CURLU *base, CURLU *href); ++ + #endif /* HEADER_CURL_URLAPI_INT_H */ +diff --git a/lib/urlapi.c b/lib/urlapi.c +index a4b82f31bd..20c6585b55 100644 +--- a/lib/urlapi.c ++++ b/lib/urlapi.c +@@ -1996,3 +1996,36 @@ nomem: + } + return CURLUE_OK; + } ++ ++bool Curl_url_same_origin(CURLU *base, CURLU *href) ++{ ++ const struct Curl_scheme *s = NULL; ++ ++ /* base must be an absolute URL */ ++ if(!base->scheme || !base->host) ++ return FALSE; ++ if(href->scheme && !curl_strequal(base->scheme, href->scheme)) ++ return FALSE; ++ if(href->host) { ++ if(!curl_strequal(base->host, href->host)) ++ return FALSE; ++ if(!curl_strequal(base->port, href->port)) { ++ /* This may still match if only one has an explicit port ++ * and it is the default for the scheme. */ ++ if(base->port && href->port) ++ return FALSE; ++ ++ s = Curl_get_scheme(base->scheme); ++ if(!s) /* Cannot match default port for unknown scheme */ ++ return FALSE; ++ ++ /* The port which is set must be the default one */ ++ if((base->port && (base->portnum != s->defport)) || ++ (href->port && (href->portnum != s->defport))) ++ return FALSE; ++ } ++ } ++ else if(href->port) /* no host in href, then there must be no port */ ++ return FALSE; ++ return TRUE; ++} diff --git a/meta/recipes-support/curl/curl/CVE-2026-6429.patch b/meta/recipes-support/curl/curl/CVE-2026-6429.patch new file mode 100644 index 00000000000..76711aafc0b --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-6429.patch @@ -0,0 +1,325 @@ +From 1d36681ca0e453faf199f44c483077d929899906 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Thu, 16 Apr 2026 14:26:20 +0200 +Subject: [PATCH] http: clear credentials better on redirect + +Verify with test 2506: netrc with redirect using proxy + +Updated test 998 which was wrong. + +Reported-by: Muhamad Arga Reksapati + +Closes #21345 + +CVE: CVE-2026-6429 +Upstream-Status: Backport [https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306] + +Backport Changes: +- Aligned with curl 8.19.0 by using the existing + Curl_safefree() instead of the curlx_safefree() macro. +- The curlx_safefree() macro was introduced in curl 8.20.0 by: + https://github.com/curl/curl/commit/0df6c01db398f5e25d00a062aae56f2a89d8ff55 + +(cherry picked from commit b4024bf808bd558026fdc6096e8457f199ace306) +Signed-off-by: Deepak Rathore +--- + lib/http.c | 84 ++++++++++++-------------------------- + tests/data/Makefile.am | 2 +- + tests/data/test2506 | 64 +++++++++++++++++++++++++++++ + tests/data/test998 | 1 - + tests/libtest/Makefile.inc | 2 +- + tests/libtest/lib2506.c | 71 ++++++++++++++++++++++++++++++++ + 6 files changed, 162 insertions(+), 62 deletions(-) + create mode 100644 tests/data/test2506 + create mode 100644 tests/libtest/lib2506.c + +diff --git a/lib/http.c b/lib/http.c +index b960d790a4..2596b4b3a2 100644 +--- a/lib/http.c ++++ b/lib/http.c +@@ -1201,75 +1201,41 @@ CURLcode Curl_http_follow(struct Curl_easy *data, const char *newurl, + return CURLE_OUT_OF_MEMORY; + } + else { +- uc = curl_url_get(data->state.uh, CURLUPART_URL, &follow_url, 0); +- if(uc) ++ bool same_origin; ++ CURLcode result; ++ CURLU *u = curl_url(); ++ if(!u) ++ return CURLE_OUT_OF_MEMORY; ++ uc = curl_url_set(u, CURLUPART_URL, ++ Curl_bufref_ptr(&data->state.url), ++ CURLU_URLENCODE | CURLU_ALLOW_SPACE); ++ if(!uc) ++ uc = curl_url_get(data->state.uh, CURLUPART_URL, &follow_url, 0); ++ if(uc) { ++ curl_url_cleanup(u); + return Curl_uc_to_curlcode(uc); ++ } + +- /* Clear auth if this redirects to a different port number or protocol, +- unless permitted */ +- if(!data->set.allow_auth_to_other_hosts && (type != FOLLOW_FAKE)) { +- int port; +- bool clear = FALSE; +- +- if(data->set.use_port && data->state.allow_port) +- /* a custom port is used */ +- port = (int)data->set.use_port; +- else { +- curl_off_t value; +- char *portnum; +- const char *p; +- uc = curl_url_get(data->state.uh, CURLUPART_PORT, &portnum, +- CURLU_DEFAULT_PORT); +- if(uc) { +- curlx_free(follow_url); +- return Curl_uc_to_curlcode(uc); +- } +- p = portnum; +- curlx_str_number(&p, &value, 0xffff); +- port = (int)value; +- curlx_free(portnum); +- } +- if(port != data->info.conn_remote_port) { +- infof(data, "Clear auth, redirects to port from %u to %u", +- data->info.conn_remote_port, port); +- clear = TRUE; +- } +- else { +- char *scheme; +- const struct Curl_scheme *p; +- uc = curl_url_get(data->state.uh, CURLUPART_SCHEME, &scheme, 0); +- if(uc) { +- curlx_free(follow_url); +- return Curl_uc_to_curlcode(uc); +- } ++ same_origin = Curl_url_same_origin(u, data->state.uh); ++ curl_url_cleanup(u); + +- p = Curl_get_scheme(scheme); +- if(p && (p->protocol != data->info.conn_protocol)) { +- infof(data, "Clear auth, redirects scheme from %s to %s", +- data->info.conn_scheme, scheme); +- clear = TRUE; +- } +- curlx_free(scheme); +- } +- if(clear) { +- CURLcode result = Curl_reset_userpwd(data); +- if(result) { +- curlx_free(follow_url); +- return result; +- } +- Curl_safefree(data->state.aptr.user); +- Curl_safefree(data->state.aptr.passwd); ++ if((!same_origin && !data->set.allow_auth_to_other_hosts) || ++ !data->set.str[STRING_USERNAME]) { ++ result = Curl_reset_userpwd(data); ++ if(result) { ++ curlx_free(follow_url); ++ return result; + } ++ Curl_safefree(data->state.aptr.user); ++ Curl_safefree(data->state.aptr.passwd); + } +- } +- DEBUGASSERT(follow_url); +- { +- CURLcode result = Curl_reset_proxypwd(data); ++ result = Curl_reset_proxypwd(data); + if(result) { + curlx_free(follow_url); + return result; + } + } ++ DEBUGASSERT(follow_url); + + if(type == FOLLOW_FAKE) { + /* we are only figuring out the new URL if we would have followed locations +diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am +index 00a5221d1f..1b76b01a8c 100644 +--- a/tests/data/Makefile.am ++++ b/tests/data/Makefile.am +@@ -265,7 +265,7 @@ test2309 \ + \ + test2400 test2401 test2402 test2403 test2404 test2405 test2406 test2407 \ + \ +-test2500 test2501 test2502 test2503 test2504 \ ++test2500 test2501 test2502 test2503 test2504 test2506 \ + \ + test2600 test2601 test2602 test2603 test2604 test2605 \ + \ +diff --git a/tests/data/test2506 b/tests/data/test2506 +new file mode 100644 +index 0000000000..9c65002496 +--- /dev/null ++++ b/tests/data/test2506 +@@ -0,0 +1,64 @@ ++ ++ ++ ++ ++HTTP ++cookies ++ ++ ++ ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 3 ++Location: http://numbertwo.example/%TESTNUMBER0002 ++ ++ok ++ ++ ++HTTP/1.1 200 OK ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Content-Length: 4 ++ ++yes ++ ++ ++ ++ ++ ++http ++ ++ ++proxy ++ ++ ++lib%TESTNUMBER ++ ++ ++netrc with redirect using proxy ++ ++ ++machine site.example login batman password robin ++ ++ ++http://%HOSTIP:%HTTPPORT http://site.example/ %LOGDIR/netrc2506 ++ ++ ++ ++ ++ ++GET http://site.example/ HTTP/1.1 ++Host: site.example ++Authorization: Basic %b64[batman:robin]b64% ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://numbertwo.example/25060002 HTTP/1.1 ++Host: numbertwo.example ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ +diff --git a/tests/data/test998 b/tests/data/test998 +index 24d1d3dd4e..56dbc0c891 100644 +--- a/tests/data/test998 ++++ b/tests/data/test998 +@@ -77,7 +77,6 @@ Proxy-Connection: Keep-Alive + + GET http://somewhere.else.example/a/path/9980002 HTTP/1.1 + Host: somewhere.else.example +-Authorization: Basic %b64[alberto:einstein]b64% + User-Agent: curl/%VERSION + Accept: */* + Proxy-Connection: Keep-Alive +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 2319bafe72..2f77c16975 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -113,7 +113,7 @@ TESTS_C = \ + lib2023.c lib2032.c lib2082.c \ + lib2301.c lib2302.c lib2304.c lib2306.c lib2308.c lib2309.c \ + lib2402.c lib2404.c lib2405.c \ +- lib2502.c lib2504.c \ ++ lib2502.c lib2504.c lib2506.c \ + lib2700.c \ + lib3010.c lib3025.c lib3026.c lib3027.c lib3033.c lib3034.c \ + lib3100.c lib3101.c lib3102.c lib3103.c lib3104.c lib3105.c \ +diff --git a/tests/libtest/lib2506.c b/tests/libtest/lib2506.c +new file mode 100644 +index 0000000000..8b3b3429f9 +--- /dev/null ++++ b/tests/libtest/lib2506.c +@@ -0,0 +1,71 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Linus Nielsen Feltzing ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++#include "first.h" ++ ++#include "testtrace.h" ++ ++static size_t sink2506(char *ptr, size_t size, size_t nmemb, void *ud) ++{ ++ (void)ptr; ++ (void)ud; ++ return size * nmemb; ++} ++ ++static CURLcode test_lib2506(const char *URL) ++{ ++ CURL *curl; ++ CURLcode result = CURLE_OUT_OF_MEMORY; ++ ++ if(curl_global_init(CURL_GLOBAL_ALL) != CURLE_OK) { ++ curl_mfprintf(stderr, "curl_global_init() failed\n"); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2506); ++ test_setopt(curl, CURLOPT_PROXY, URL); ++ test_setopt(curl, CURLOPT_URL, libtest_arg2); ++ test_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL); ++ test_setopt(curl, CURLOPT_NETRC_FILE, libtest_arg3); ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); ++ test_setopt(curl, CURLOPT_VERBOSE, 1L); ++ ++ /* CURLOPT_UNRESTRICTED_AUTH should not make a difference because the ++ credentials come from netrc */ ++ test_setopt(curl, CURLOPT_UNRESTRICTED_AUTH, 1L); ++ ++ result = curl_easy_perform(curl); ++ ++test_cleanup: ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ ++ return result; ++} diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index b1ee0f8b9ba..683163bfa61 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -19,6 +19,8 @@ SRC_URI = " \ file://mbedtls.patch \ file://CVE-2026-5545.patch \ file://CVE-2026-6253.patch \ + file://CVE-2026-6429-dependent.patch \ + file://CVE-2026-6429.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Jul 22 17:23:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93240 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E1CE4C44536 for ; Wed, 22 Jul 2026 17:24:09 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5529.1784741049297245757 for ; Wed, 22 Jul 2026 10:24:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2QhO+nCG; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso28219835e9.1 for ; Wed, 22 Jul 2026 10:24:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741047; x=1785345847; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=virqmaFyh7gltWeL6kh56gomAQqICHGvI0tRV0Ayueo=; b=2QhO+nCG2R9DJ35T/ktV7a9XIv3Go5O/m17Y3mBM6Sccm/A6nkxCvPgho7elKTPEX1 Dn4SSyoNqd6yVcqEBRsbnKZPWsN6AxEOPkNW8sC0VpPaWqM5dhizYbUVY5cOQfi7Tsx/ 2e93SqQ8ntsvLFeHhLU3mv1ooW8KTLLicHesE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741047; x=1785345847; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=virqmaFyh7gltWeL6kh56gomAQqICHGvI0tRV0Ayueo=; b=DkkhrdxTbERWalz2+ohhl9RW7+Kl6vMX1RjMItETq0xdec0xviLikBNzWqs4wkEsW2 hkK9rZL8ymlTBEXewoW3jBB9OzRQyXtc/+WMJohiQgGc7E5tr50Ad6NY1id1pcp24ymN e+knUpV5pGAZPlY2mT0jL22PxJPA6F0CeeIaVqso9ADROfxhZdPoI567NyTmSBP+gMTK l4lE1MChIU5zNyw4zddpFc+4BwxGjygyWyYAEsfna7OtypNTIai8KgHvutKnLAwZ6F5D VQTnT8GXUFia5O5iqRtglE0GzHNmBTuSVXg0QtCkI+ANca9BEhJB8jP0QS7h3mQ9grGU kDBg== X-Gm-Message-State: AOJu0Yz95ncsSDFZxXk8XA2AfQn6qKxoHfaIdFkXB/oDE3f3m5KYT7TA +WRJlqwWYczz6oUgIGNSUvSPD26uOatnuFQyaavFnqdnxR9zOwFw1zCV8miKqnyJNrfB/WoqBvd fziSx/bA= X-Gm-Gg: AR+sD12ZpYumtJOcHNofiq0iyGrF6nps1sGKclZZiaiXjsZBb5CuChOLTBzrkPN03ok q0VWzrpMJrVV6ULZBkzkxBQ65hzfZ7B33Ex6mqZU/j1Vu9yPka4pYanWfzXDKVH/TTcBtXDcTzW TkX6/QJ2BZibOXiczsy8Z2lqs6PGAc38PL2T0JNwC71CMG1gtV5VQeV4v8pVU9xFpjf5NkoEYtH QuQ1hddFDKyNQwLYjYuL2A1iPCRIHDg1jv28YKEUfaij6msmzXC4E+uO6SxhNsKTajBa7TsNs28 MpyTapGmn0GbNneG7CvmsuuCHElEl8/sklSVGDMza3E2WSRr9bVvEgUUeFxlAbHSY6CBSWPxvk2 J6Wm99vYhkn21mGm1TxZJiM75wXrPAfceSx5OrEV5okwyY9HA6zdeYY7h0VLBDLu6S/qbH28sdi e3Z8ynrdDPtapN8UMjH/Zn/DPO3T9SX9rqxl/sxnP09cse+Enrr/V/VBJ+0hDg0Av6dItswJBpZ jll8Upw86PG X-Received: by 2002:a05:600c:1549:b0:493:c601:3e23 with SMTP id 5b1f17b1804b1-4954a3d08c0mr266553915e9.5.1784741047422; Wed, 22 Jul 2026 10:24:07 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/27] glib-2.0: upgrade 2.88.0 -> 2.88.2 Date: Wed, 22 Jul 2026 19:23:30 +0200 Message-ID: <145aa7ee15e5eb73a6e6f12ac721305142b16848.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241727 From: Peter Marko Refresh patches via devtool. Release notes: [1] and [2]. 2.88.1: Fix various minor (low severity) security issues CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014 and CVE-2026-58015 [1] https://gitlab.gnome.org/GNOME/glib/-/releases/2.88.1 [2] https://gitlab.gnome.org/GNOME/glib/-/releases/2.88.2 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../glib-2.0/files/CVE-2026-58016-1.patch | 12 ++++---- .../glib-2.0/files/CVE-2026-58016-2.patch | 30 +++++++++---------- ...l_2.88.0.bb => glib-2.0-initial_2.88.2.bb} | 0 ...{glib-2.0_2.88.0.bb => glib-2.0_2.88.2.bb} | 0 meta/recipes-core/glib-2.0/glib.inc | 2 +- 5 files changed, 22 insertions(+), 22 deletions(-) rename meta/recipes-core/glib-2.0/{glib-2.0-initial_2.88.0.bb => glib-2.0-initial_2.88.2.bb} (100%) rename meta/recipes-core/glib-2.0/{glib-2.0_2.88.0.bb => glib-2.0_2.88.2.bb} (100%) diff --git a/meta/recipes-core/glib-2.0/files/CVE-2026-58016-1.patch b/meta/recipes-core/glib-2.0/files/CVE-2026-58016-1.patch index 2c4b248b97b..9beafd106d1 100644 --- a/meta/recipes-core/glib-2.0/files/CVE-2026-58016-1.patch +++ b/meta/recipes-core/glib-2.0/files/CVE-2026-58016-1.patch @@ -30,7 +30,7 @@ diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c index c7be334ce2f7..6f722ee6153d 100644 --- a/gio/gdbusintrospection.c +++ b/gio/gdbusintrospection.c -@@ -1272,7 +1272,7 @@ parser_start_element (GMarkupParseContext *context, +@@ -1258,7 +1258,7 @@ parser_start_element (GMarkupParseContext *context, /* ---------------------------------------------------------------------------------------------------- */ if (strcmp (element_name, "node") == 0) { @@ -43,10 +43,10 @@ diff --git a/gio/tests/gdbus-introspection.c b/gio/tests/gdbus-introspection.c index 44cb7a96af45..daca313f77e7 100644 --- a/gio/tests/gdbus-introspection.c +++ b/gio/tests/gdbus-introspection.c -@@ -299,6 +299,38 @@ test_extra_data (void) +@@ -300,6 +300,38 @@ test_extra_data (void) g_dbus_node_info_unref (info); } - + +static void +test_invalid (void) +{ @@ -80,14 +80,14 @@ index 44cb7a96af45..daca313f77e7 100644 +} + /* ---------------------------------------------------------------------------------------------------- */ - + int -@@ -316,6 +348,7 @@ main (int argc, +@@ -317,6 +349,7 @@ main (int argc, g_test_add_func ("/gdbus/introspection-generate", test_generate); g_test_add_func ("/gdbus/introspection-default-direction", test_default_direction); g_test_add_func ("/gdbus/introspection-extra-data", test_extra_data); + g_test_add_func ("/gdbus/introspection/invalid", test_invalid); - + ret = session_bus_run (); -- diff --git a/meta/recipes-core/glib-2.0/files/CVE-2026-58016-2.patch b/meta/recipes-core/glib-2.0/files/CVE-2026-58016-2.patch index a61e35ad8a7..a07aa529ae8 100644 --- a/meta/recipes-core/glib-2.0/files/CVE-2026-58016-2.patch +++ b/meta/recipes-core/glib-2.0/files/CVE-2026-58016-2.patch @@ -30,63 +30,63 @@ diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c index 6f722ee6153d..ed0d291f99f0 100644 --- a/gio/gdbusintrospection.c +++ b/gio/gdbusintrospection.c -@@ -1110,6 +1110,7 @@ parse_data_get_annotation (ParseData *data, +@@ -1096,6 +1096,7 @@ parse_data_get_annotation (ParseData *data, { if (create_new) g_ptr_array_add (data->annotations, g_new0 (GDBusAnnotationInfo, 1)); + g_assert (data->annotations->len > 0); return data->annotations->pdata[data->annotations->len - 1]; } - -@@ -1119,6 +1120,7 @@ parse_data_get_arg (ParseData *data, + +@@ -1105,6 +1106,7 @@ parse_data_get_arg (ParseData *data, { if (create_new) g_ptr_array_add (data->args, g_new0 (GDBusArgInfo, 1)); + g_assert (data->args->len > 0); return data->args->pdata[data->args->len - 1]; } - -@@ -1128,6 +1130,7 @@ parse_data_get_out_arg (ParseData *data, + +@@ -1114,6 +1116,7 @@ parse_data_get_out_arg (ParseData *data, { if (create_new) g_ptr_array_add (data->out_args, g_new0 (GDBusArgInfo, 1)); + g_assert (data->out_args->len > 0); return data->out_args->pdata[data->out_args->len - 1]; } - -@@ -1137,6 +1140,7 @@ parse_data_get_method (ParseData *data, + +@@ -1123,6 +1126,7 @@ parse_data_get_method (ParseData *data, { if (create_new) g_ptr_array_add (data->methods, g_new0 (GDBusMethodInfo, 1)); + g_assert (data->methods->len > 0); return data->methods->pdata[data->methods->len - 1]; } - -@@ -1146,6 +1150,7 @@ parse_data_get_signal (ParseData *data, + +@@ -1132,6 +1136,7 @@ parse_data_get_signal (ParseData *data, { if (create_new) g_ptr_array_add (data->signals, g_new0 (GDBusSignalInfo, 1)); + g_assert (data->signals->len > 0); return data->signals->pdata[data->signals->len - 1]; } - -@@ -1155,6 +1160,7 @@ parse_data_get_property (ParseData *data, + +@@ -1141,6 +1146,7 @@ parse_data_get_property (ParseData *data, { if (create_new) g_ptr_array_add (data->properties, g_new0 (GDBusPropertyInfo, 1)); + g_assert (data->properties->len > 0); return data->properties->pdata[data->properties->len - 1]; } - -@@ -1164,6 +1170,7 @@ parse_data_get_interface (ParseData *data, + +@@ -1150,6 +1156,7 @@ parse_data_get_interface (ParseData *data, { if (create_new) g_ptr_array_add (data->interfaces, g_new0 (GDBusInterfaceInfo, 1)); + g_assert (data->interfaces->len > 0); return data->interfaces->pdata[data->interfaces->len - 1]; } - -@@ -1173,6 +1180,7 @@ parse_data_get_node (ParseData *data, + +@@ -1159,6 +1166,7 @@ parse_data_get_node (ParseData *data, { if (create_new) g_ptr_array_add (data->nodes, g_new0 (GDBusNodeInfo, 1)); diff --git a/meta/recipes-core/glib-2.0/glib-2.0-initial_2.88.0.bb b/meta/recipes-core/glib-2.0/glib-2.0-initial_2.88.2.bb similarity index 100% rename from meta/recipes-core/glib-2.0/glib-2.0-initial_2.88.0.bb rename to meta/recipes-core/glib-2.0/glib-2.0-initial_2.88.2.bb diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.88.0.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.88.2.bb similarity index 100% rename from meta/recipes-core/glib-2.0/glib-2.0_2.88.0.bb rename to meta/recipes-core/glib-2.0/glib-2.0_2.88.2.bb diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc index fb35f84eec5..d49ae131685 100644 --- a/meta/recipes-core/glib-2.0/glib.inc +++ b/meta/recipes-core/glib-2.0/glib.inc @@ -240,7 +240,7 @@ SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ " -SRC_URI[archive.sha256sum] = "3546251ccbb3744d4bc4eb48354540e1f6200846572bab68e3a2b7b2b64dfd07" +SRC_URI[archive.sha256sum] = "cf3f215a640c8a4257f14317586b8f1fdd25a10a93cb4bdda147c0f9ad88e74f" # Find any meson cross files in FILESPATH that are relevant for the current # build (using siteinfo) and add them to EXTRA_OEMESON. From patchwork Wed Jul 22 17:23:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93258 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 62E83C531D2 for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5468.1784741049954866984 for ; Wed, 22 Jul 2026 10:24:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bUPjPaJl; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495590dde14so38695105e9.0 for ; Wed, 22 Jul 2026 10:24:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741048; x=1785345848; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tqy5oXj0/qKDqh8r/KhL33pNnTyv4YSibRwVAx/19QU=; b=bUPjPaJl3KwXXWDalfop9ndiEv8C9dTke4WFhk6qysynCbvh6yiGohaPXxhPBqUrHz cdy87kdwj3aVZY7yzbHUw6Fn3jsBuoS2TjPO1P5lhTmQ52EOW5SqWA9y97YLrhw0paKe ystib9PMQsQUMsymEnlN3KEAdJRuC2Vzrm1P0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741048; x=1785345848; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=tqy5oXj0/qKDqh8r/KhL33pNnTyv4YSibRwVAx/19QU=; b=fZCA4YDBNKfosZ4dfdFp5jwvYMpTWC6baruGrWGEaxI4u0jHG5dovHOQ8xe60T6qK7 FEkSiQ2O20i40CtGEmOJZHYVeQL4RpuLm2kUv9KcLTNATx7BU3Q2H6BLj/eQ/Pa7SCrA a+rjcnUeUcGRXvPSIiNJ4oy5Ba4YSDtAUPEYF+g8ncmmQoKbSJHcYbN/auH01mVjXy+A GittT2ruXlPwEAR5KF6Aq/CUvbE0uPpe9rMLEQitEw+TPEQDhh1f6sieJSl99fVeCoo/ epPJzH5fMflv+U54lGVyj3whm3q8U6ftBSnejG9UDoV5JCfmandKON+kImNbGvFJrxIX NCpQ== X-Gm-Message-State: AOJu0YysG0FDIWlVkYYvY9sN91kh2e5Up3JfCNMIrOkd0MtDgJ0631nz Njet50VdfV5/7OWbrWyFXlz70xdoTnNrhwu0Uq4fGVbmY9IPPeEERzVUeK+bhwqWWOk4A1W9mFM Rjn4DAEI= X-Gm-Gg: AR+sD114GdU8MJMnlpug7Ov7m12PZ75eKeoSH77Tp7lP7L4VVHs78ENRSFNqCZ/JOoe s9U4IS2kf8WvLHGzkLFDXwGmQNVaDTDaJyByJHkbfcw/P8fGLoCbEUb0ihU9wPi7loAtflSVRmh diSPjFKAnyWI18HpDKre9wxE9iqwKNkPqyRWissExjIXMZQEC4vrbIXlF+mK5GquRoofg+NquSF tWjbeUkjtFImSayTqd7gxGhV7UDU+7tynD6PHDbKHQF5HnLmi79SHtkRSrZSxdgUJl0N8qqb7TF kfP9NkqBtb7Ag+fb8RC487BIOK3ZGIjEDFXwfemq32S3iUcodVM9B9hbLkgVctoVWdBASmkKcKV R8u5cEGhJS3jDK84HIHY2LNi/d4OWMuzuskC06+QtGj+a5V3wC2QjJ7KylRynCG44Ur+jnBAwV4 sPon5cgKVwEAj47G12o5VAW3XtBwj8nL8WkgTd3s7il3MoXGisHLmwaJcsaOIlVqt0v294CPYE/ kaSwQ9Rm+BLgZs9KAM5J+yEMsxI3mLZYw== X-Received: by 2002:a05:600c:4e8d:b0:495:54e9:c080 with SMTP id 5b1f17b1804b1-49554e9c2bbmr86835825e9.31.1784741048005; Wed, 22 Jul 2026 10:24:08 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/27] libssh2: Fix CVE-2025-15661 Date: Wed, 22 Jul 2026 19:23:31 +0200 Message-ID: <525ecf7f753566bcf8f9918ca7dd56b1fc946b0a.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241728 From: David Nyström Fix CVE-2025-15661[1] similiar to debian[2], two first commits identical, third commit fixes a return code regression introduced by CVE fix commit. [1] https://nvd.nist.gov/vuln/detail/CVE-2025-15661 [2] https://sources.debian.org/patches/libssh2/1.11.1-4/ Signed-off-by: David Nyström [YC: fixed stray whitespaces at EOL] Signed-off-by: Yoann Congal --- .../libssh2/libssh2/CVE-2025-15661-1.patch | 45 ++++++ .../libssh2/libssh2/CVE-2025-15661-2.patch | 131 ++++++++++++++++++ .../libssh2/libssh2/CVE-2025-15661-3.patch | 57 ++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 3 + 4 files changed, 236 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2025-15661-1.patch create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2025-15661-2.patch create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2025-15661-3.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-1.patch b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-1.patch new file mode 100644 index 00000000000..93a9e6eb596 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-1.patch @@ -0,0 +1,45 @@ +From 95028b06d1875e07c99918145234a473e5e8521f Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?David=20Nystr=C3=B6m?= +Date: Thu, 9 Jul 2026 12:36:24 +0000 +Subject: [PATCH 1/3] sftp: add LIBSSH2_UNCONST() macro needed by + CVE-2025-15661 fix +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Needed by the fix for CVE-2025-15661. + +Extracted from upstream commit 606c102e52f8447de2b745dd6c5ddf418defc519 +(build: enable -Wcast-qual, fix fallouts) by Viktor Szakats. +Only the LIBSSH2_UNCONST() macro definition in libssh2_priv.h is +included; the remainder of that commit is not applicable to this +stable branch. + +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/606c102e52f8447de2b745dd6c5ddf418defc519] +Signed-off-by: David Nyström +--- + src/libssh2_priv.h | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/src/libssh2_priv.h b/src/libssh2_priv.h +index 9b8866dc..bb1f8ad3 100644 +--- a/src/libssh2_priv.h ++++ b/src/libssh2_priv.h +@@ -117,6 +117,14 @@ + #define UINT32_MAX 0xffffffffU + #endif + ++#ifdef _WIN64 ++#define LIBSSH2_UNCONST(p) ((void *)(libssh2_uint64_t)(const void *)(p)) ++#elif defined(_MSC_VER) ++#define LIBSSH2_UNCONST(p) ((void *)(unsigned int)(const void *)(p)) ++#else ++#define LIBSSH2_UNCONST(p) ((void *)(uintptr_t)(const void *)(p)) ++#endif ++ + #if (defined(__GNUC__) || defined(__clang__)) && \ + defined(__STDC_VERSION__) && (__STDC_VERSION__ >= 199901L) && \ + !defined(LIBSSH2_NO_FMT_CHECKS) +-- +2.43.0 + diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-2.patch b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-2.patch new file mode 100644 index 00000000000..40096d3318d --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-2.patch @@ -0,0 +1,131 @@ +From 72e8f8dd812503e07fecd775e7f88183e005d9ae Mon Sep 17 00:00:00 2001 +From: Will Cosgrove +Date: Fri, 10 Oct 2025 08:26:20 -0700 +Subject: [PATCH 2/3] Update sftp_symlink to avoid out of bounds read on + malformed packet #1705 (#1717) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Use buffer struct to guard against out of bounds reads and invalid packets. + +Discovery Credit: +Joshua Rogers + +CVE: CVE-2025-15661 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d] +Signed-off-by: David Nyström +--- + src/sftp.c | 66 ++++++++++++++++++++++++++++++++++++++---------------- + 1 file changed, 47 insertions(+), 19 deletions(-) + +diff --git a/src/sftp.c b/src/sftp.c +index 6ede3111..43b6ff90 100644 +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -3795,15 +3795,19 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path, + { + LIBSSH2_CHANNEL *channel = sftp->channel; + LIBSSH2_SESSION *session = channel->session; +- size_t data_len = 0, link_len; ++ size_t data_len = 0, lk_len; + /* 13 = packet_len(4) + packet_type(1) + request_id(4) + path_len(4) */ + ssize_t packet_len = + path_len + 13 + + ((link_type == LIBSSH2_SFTP_SYMLINK) ? (4 + target_len) : 0); + unsigned char *s, *data = NULL; ++ struct string_buf buf; + static const unsigned char link_responses[2] = + { SSH_FXP_NAME, SSH_FXP_STATUS }; + int retcode; ++ unsigned char packet_type; ++ uint32_t tmp_u32; ++ unsigned char *lk_target; + + if(sftp->symlink_state == libssh2_NB_state_idle) { + sftp->last_errno = LIBSSH2_FX_OK; +@@ -3891,8 +3895,25 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path, + + sftp->symlink_state = libssh2_NB_state_idle; + +- if(data[0] == SSH_FXP_STATUS) { +- retcode = _libssh2_ntohu32(data + 5); ++ buf.data = (unsigned char *)LIBSSH2_UNCONST(data); ++ buf.dataptr = buf.data; ++ buf.len = data_len; ++ ++ if(_libssh2_get_byte(&buf, &packet_type)) { ++ LIBSSH2_FREE(session, data); ++ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, ++ "SFTP Protocol Error (type)"); ++ } ++ ++ if(packet_type == SSH_FXP_STATUS) { ++ if(_libssh2_get_u32(&buf, &tmp_u32)) { ++ LIBSSH2_FREE(session, data); ++ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, ++ "SFTP Protocol Error (code)"); ++ } ++ ++ retcode = (int)tmp_u32; ++ + LIBSSH2_FREE(session, data); + if(retcode == LIBSSH2_FX_OK) + return LIBSSH2_ERROR_NONE; +@@ -3903,30 +3924,37 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path, + } + } + +- if(_libssh2_ntohu32(data + 5) < 1) { ++ /* advance past id */ ++ if(_libssh2_get_u32(&buf, &tmp_u32)) { + LIBSSH2_FREE(session, data); + return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, +- "Invalid READLINK/REALPATH response, " +- "no name entries"); ++ "SFTP Protocol Error (id)"); + } + +- if(data_len < 13) { +- if(data_len > 0) { +- LIBSSH2_FREE(session, data); +- } ++ /* look for at least one link */ ++ if(_libssh2_get_u32(&buf, &tmp_u32) || tmp_u32 < 1) { ++ LIBSSH2_FREE(session, data); + return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, +- "SFTP stat packet too short"); ++ "Invalid READLINK/REALPATH response, " ++ "no name entries"); + } + +- /* this reads a u32 and stores it into a signed 32bit value */ +- link_len = _libssh2_ntohu32(data + 9); +- if(link_len < target_len) { +- memcpy(target, data + 13, link_len); +- target[link_len] = 0; +- retcode = (int)link_len; ++ if(_libssh2_get_string(&buf, &lk_target, &lk_len) == LIBSSH2_ERROR_NONE) { ++ if(lk_len < target_len) { ++ memcpy(target, lk_target, lk_len); ++ target[lk_len] = '\0'; ++ retcode = (int)lk_len; ++ } ++ else { ++ retcode = LIBSSH2_ERROR_BUFFER_TOO_SMALL; ++ } + } +- else +- retcode = LIBSSH2_ERROR_BUFFER_TOO_SMALL; ++ else { ++ LIBSSH2_FREE(session, data); ++ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, ++ "SFTP Protocol Error (filename)"); ++ } ++ + LIBSSH2_FREE(session, data); + + return retcode; +-- +2.43.0 + diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-3.patch b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-3.patch new file mode 100644 index 00000000000..f34a8778080 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2025-15661-3.patch @@ -0,0 +1,57 @@ +From 09a4a795b051c8c39957a85b36abba5d8dbd7230 Mon Sep 17 00:00:00 2001 +From: Will Cosgrove +Date: Mon, 20 Oct 2025 14:04:52 -0700 +Subject: [PATCH 3/3] Fix sftp_symlink when getting SSH_FXP_STATUS response + (#1731) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Move advancing past packet ID before reading the FXP_STATUS response. + +Note: +Fixes return code regression introduced by: +"Update sftp_symlink to avoid out of bounds read on malformed packet #1705 (#1717)" + +CVE: CVE-2025-15661 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/4ed26f5740bdd409269ed9fb48a28bf8f565b681] +Signed-off-by: David Nyström +--- + src/sftp.c | 14 +++++++------- + 1 file changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/sftp.c b/src/sftp.c +index 43b6ff90..0a6d15de 100644 +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -3905,6 +3905,13 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path, + "SFTP Protocol Error (type)"); + } + ++ /* advance past id */ ++ if(_libssh2_get_u32(&buf, &tmp_u32)) { ++ LIBSSH2_FREE(session, data); ++ return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, ++ "SFTP Protocol Error (id)"); ++ } ++ + if(packet_type == SSH_FXP_STATUS) { + if(_libssh2_get_u32(&buf, &tmp_u32)) { + LIBSSH2_FREE(session, data); +@@ -3924,13 +3931,6 @@ static int sftp_symlink(LIBSSH2_SFTP *sftp, const char *path, + } + } + +- /* advance past id */ +- if(_libssh2_get_u32(&buf, &tmp_u32)) { +- LIBSSH2_FREE(session, data); +- return _libssh2_error(session, LIBSSH2_ERROR_SFTP_PROTOCOL, +- "SFTP Protocol Error (id)"); +- } +- + /* look for at least one link */ + if(_libssh2_get_u32(&buf, &tmp_u32) || tmp_u32 < 1) { + LIBSSH2_FREE(session, data); +-- +2.43.0 + diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index 2407ed34d94..32e1ad6c16c 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -13,6 +13,9 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-7598.patch \ file://CVE-2026-55200.patch \ file://CVE-2026-55199.patch \ + file://CVE-2025-15661-1.patch \ + file://CVE-2025-15661-2.patch \ + file://CVE-2025-15661-3.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Wed Jul 22 17:23:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93266 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F0A39C531BC for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5470.1784741051168930108 for ; Wed, 22 Jul 2026 10:24:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=csVwTrgV; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-495635a85d2so27815375e9.0 for ; Wed, 22 Jul 2026 10:24:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741049; x=1785345849; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=L54W2JjbpHCr1mR/qCrRc4K+piUqZCsRXzoCkM1GJIw=; b=csVwTrgVoe6GanmlxBDFH5/8b5RUurLF8l8IRAt0/OD2euaMeHTIPb8oqqD0Uj4F0h q5V/75jlipU73OSAFU5uVz9uoJNV+/iE6Xqum79IDLN88F0x0DQmGwV/4AQdh25kdC7u GS7K/plqCdLGjZiLMx6xaXfyGrhPxTCWgfybk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741049; x=1785345849; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=L54W2JjbpHCr1mR/qCrRc4K+piUqZCsRXzoCkM1GJIw=; b=Oqm7idz2ijdab/cYI1LfEzlnQD32GU9YFPKfL7LFXQoHW5Xm3adwpkwrhga2NPymg9 Tc0h3gzKEQg/XPviXtCdqir3YAmvygvpdA1LVjsvBGFcl3RQYorIO2dEyu7S4g9Jngug G0VCnXWmUf8AA7na2V10ExJKC//TccJjhj96pcpgnRvoWngM7tlqjAzjzT5a6u0A2ipw /11ZsPR3RYiWcUw2Bgurm2BDfylYkAZOusw95ozrr8A6vyHW6HLv/MEfPJIP+giZBmEQ xNviYXp1fr4OK9heMaH909y2Yw8Mrv6TPUT/xOjAWZFceinYCXgA3QiExyang6VbRkWI 5hOQ== X-Gm-Message-State: AOJu0Yymz//zyoQ/tC9mJE4o35jq1Dhsf13BIzBrHSFTRbBerMkLVtLC wZ9k2hUbW4xnCKtwpfOE3I1ykU8W3x2Qq2nmpXZlMJa7eY2CJd91g81kb+CqaErpVYEb8AERvQw MmmAOWp0= X-Gm-Gg: AR+sD113+P6kEGscLsd9bYhkTJQsc2NyggiUjEtDaugcmBXQEP3Hj6IYAoFlbFW3+Qx 30RIqxasDE7eRNPqtvlPkSZfbZsz08nqmzzSP58UAhWxep+5TYiT3oKkKZ7PDW7gY9uv+hJ7o+v gtUeTd9aJ25q9e0SRsY0CLhckYOvF4hZ4O+0XYerelTOLUb1E73wrSgxG3wydmK6I9pYaY2RhCN 4RgepmgK4MkpECep7C+sMRp+VG3vluggwgqsZw2zWndg0z2Jp+XQm2RiOKokhWTRi2ggdV01u5w sTgclaKiBHgxRCvZdt+UoKg523rhv+91WFGgIrQNfix3VaZWF3crYuLVLfhhj3IEW7/QOQcWl+B DC+kpxcmQcqAAW9oIk8e7UrB6tRssk95lG4V1sVkMweVcF/dce53vKXtRkpkuSTHbX+D5hZXEqq sGXC2ILqNK+2Uvl3EslOT4CKlXF/oHVGO9lNF5z/7k9aCOvu5IzEmFZ3/dtroE5ObUL5zseonsF MT6zhtdxMkd X-Received: by 2002:a05:600c:4e88:b0:495:636b:e519 with SMTP id 5b1f17b1804b1-495636bea4dmr136929795e9.21.1784741048576; Wed, 22 Jul 2026 10:24:08 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/27] libpng: fix CVE-2026-34757 Date: Wed, 22 Jul 2026 19:23:32 +0200 Message-ID: <351f2b39a85fdf2d2b4140535ffcdfb213b552a3.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241730 From: Deepak Rathore This patch applies the upstream fixes for libpng 1.6.57 for CVE-2026-34757. The upstream fix commit is referenced in [1] & [2] and the public CVE advisory is referenced in [3]. [1] https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a [2] https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc [3] https://github.com/pnggroup/libpng/issues/836 Reference: https://security-tracker.debian.org/tracker/CVE-2026-34757 https://nvd.nist.gov/vuln/detail/CVE-2026-34757 Test results on qemux86-64 using ptest-runner: ==================================================================== Testsuite summary for libpng 1.6.56 ==================================================================== # TOTAL: 36 # PASS: 36 # SKIP: 0 # XFAIL: 0 # FAIL: 0 # XPASS: 0 # ERROR: 0 ===================================================================== Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../libpng/files/CVE-2026-34757_p1.patch | 518 ++++++++++++++++++ .../libpng/files/CVE-2026-34757_p2.patch | 481 ++++++++++++++++ .../libpng/libpng_1.6.56.bb | 4 +- 3 files changed, 1002 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch new file mode 100644 index 00000000000..7b5ebb18b7e --- /dev/null +++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch @@ -0,0 +1,518 @@ +From e621c40a46aa748608d5392f6a5c0278f77573d3 Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Mon, 30 Mar 2026 17:35:30 +0300 +Subject: [PATCH] fix: Handle self-referencing pointers in getter-to-setter + aliasing + +Apply a robustness fix for a caller-side API usage pattern involving +the getters and the setters for PLTE, tRNS, and hIST. + +Passing a pointer returned by the PLTE, tRNS, or hIST getters back +into the corresponding setters used to cause the setters to read from +a stale pointer. The fix consists in snapshotting the caller's data +into a stack-local buffer before freeing the old internal storage. + +Fixes pnggroup/libpng#836 + +Reported-by: Iv4n +CVE: CVE-2026-34757 +Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a] + +(cherry picked from commit 398cbe3df03f4e11bb031e07f416dfdde3684e8a) +Signed-off-by: Deepak Rathore +--- + CMakeLists.txt | 12 ++ + Makefile.am | 9 +- + contrib/libtests/pnggetset.c | 328 +++++++++++++++++++++++++++++++++++ + pngset.c | 29 +++- + tests/pnggetset | 5 + + 5 files changed, 380 insertions(+), 3 deletions(-) + create mode 100644 contrib/libtests/pnggetset.c + create mode 100755 tests/pnggetset + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index fde2a323c..6401b7bd3 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -624,6 +624,9 @@ set(pngvalid_sources + set(pngstest_sources + contrib/libtests/pngstest.c + ) ++set(pnggetset_sources ++ contrib/libtests/pnggetset.c ++) + set(pngunknown_sources + contrib/libtests/pngunknown.c + ) +@@ -786,6 +789,15 @@ if(PNG_TESTS AND PNG_SHARED) + COMMAND pngtest + FILES "${TEST_PNG3_PNGS}") + ++ # pnggetset test: ++ # Getter-to-setter roundtrips for various chunk types. ++ add_executable(pnggetset ${pnggetset_sources}) ++ target_link_libraries(pnggetset ++ PRIVATE png_shared) ++ ++ png_add_test(NAME pnggetset ++ COMMAND pnggetset) ++ + # pngvalid tests: + # Internal validation of standard and progressive reading, + # transforms, and gamma handling. +diff --git a/Makefile.am b/Makefile.am +index 88f7ab628..fa5bbeb61 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -13,7 +13,7 @@ ACLOCAL_AMFLAGS = -I scripts/autoconf + + # test programs - run on make check, make distcheck + if ENABLE_TESTS +-check_PROGRAMS= pngtest pngunknown pngstest pngvalid pngimage pngcp ++check_PROGRAMS= pngtest pnggetset pngunknown pngstest pngvalid pngimage pngcp + if HAVE_CLOCK_GETTIME + check_PROGRAMS += timepng + endif +@@ -42,6 +42,9 @@ if ENABLE_TESTS + pngtest_SOURCES = pngtest.c + pngtest_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la + ++pnggetset_SOURCES = contrib/libtests/pnggetset.c ++pnggetset_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la ++ + pngvalid_SOURCES = contrib/libtests/pngvalid.c + pngvalid_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la + +@@ -73,6 +76,7 @@ endif + if ENABLE_TESTS + TESTS =\ + tests/pngtest-all\ ++ tests/pnggetset\ + tests/pngvalid-gamma-16-to-8\ + tests/pngvalid-gamma-alpha-mode\ + tests/pngvalid-gamma-background\ +@@ -303,9 +307,10 @@ $(srcdir)/scripts/pnglibconf.h.prebuilt: + pngtest.o: pnglibconf.h + + contrib/libtests/makepng.o: pnglibconf.h ++contrib/libtests/pnggetset.o: pnglibconf.h ++contrib/libtests/pngimage.o: pnglibconf.h + contrib/libtests/pngstest.o: pnglibconf.h + contrib/libtests/pngunknown.o: pnglibconf.h +-contrib/libtests/pngimage.o: pnglibconf.h + contrib/libtests/pngvalid.o: pnglibconf.h + contrib/libtests/readpng.o: pnglibconf.h + contrib/libtests/tarith.o: pnglibconf.h +diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c +new file mode 100644 +index 000000000..b42508094 +--- /dev/null ++++ b/contrib/libtests/pnggetset.c +@@ -0,0 +1,328 @@ ++/* pnggetset.c ++ * ++ * Copyright (c) 2026 Cosmin Truta ++ * ++ * This code is released under the libpng license. ++ * For conditions of distribution and use, see the disclaimer ++ * and license in png.h ++ * ++ * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. ++ * ++ * Passing the internal pointer returned by a getter back into the ++ * corresponding setter is a natural API usage pattern. A previous ++ * version had a use-after-free on this path because the setter freed ++ * the internal buffer before copying from the caller-supplied pointer. ++ */ ++ ++#include ++#include ++#include ++ ++#if defined(HAVE_CONFIG_H) && !defined(PNG_NO_CONFIG_H) ++# include ++#endif ++ ++#ifdef PNG_FREESTANDING_TESTS ++# include ++#else ++# include "../../png.h" ++#endif ++ ++/* Test: get the PLTE, pass it straight back to set, verify roundtrip. */ ++static int ++test_plte_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_colorp got_palette = NULL; ++ int num_palette = 0; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_plte_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image header. */ ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ ++ /* Populate with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ { ++ palette[i].red = (png_byte)(i * 10); ++ palette[i].green = (png_byte)(i * 20); ++ palette[i].blue = (png_byte)(i * 30); ++ } ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); ++ if (got_palette == NULL || num_palette != 4) ++ { ++ fprintf(stderr, "pnggetset: png_get_PLTE returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->palette. */ ++ png_set_PLTE(png_ptr, info_ptr, got_palette, num_palette); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_palette = NULL; ++ num_palette = 0; ++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); ++ if (got_palette == NULL || num_palette != 4) ++ { ++ fprintf(stderr, "pnggetset: PLTE lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_palette[i].red != (png_byte)(i * 10) || ++ got_palette[i].green != (png_byte)(i * 20) || ++ got_palette[i].blue != (png_byte)(i * 30)) ++ { ++ fprintf(stderr, ++ "pnggetset: PLTE entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++ ++#ifdef PNG_hIST_SUPPORTED ++/* Test: get the hIST, pass it straight back to set, verify roundtrip. */ ++static int ++test_hist_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_uint_16 hist[4]; ++ png_uint_16p got_hist = NULL; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_hist_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image header. */ ++ memset(palette, 0, sizeof palette); ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Populate with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ hist[i] = (png_uint_16)(i * 100 + 42); ++ ++ png_set_hIST(png_ptr, info_ptr, hist); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_get_hIST returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->hist. */ ++ png_set_hIST(png_ptr, info_ptr, got_hist); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_hist = NULL; ++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) ++ { ++ fprintf(stderr, "pnggetset: hIST lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_hist[i] != (png_uint_16)(i * 100 + 42)) ++ { ++ fprintf(stderr, ++ "pnggetset: hIST entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_hIST_SUPPORTED */ ++ ++#ifdef PNG_tRNS_SUPPORTED ++/* Test: get the tRNS, pass it straight back to set, verify roundtrip. */ ++static int ++test_trns_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_byte trans_alpha[4]; ++ png_color_16 trans_color; ++ png_bytep got_alpha = NULL; ++ png_color_16p got_color = NULL; ++ int num_trans = 0; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_trns_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image. */ ++ memset(palette, 0, sizeof palette); ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Populate tRNS with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ trans_alpha[i] = (png_byte)(0xff - i * 0x11); ++ memset(&trans_color, 0, sizeof trans_color); ++ ++ png_set_tRNS(png_ptr, info_ptr, trans_alpha, 4, &trans_color); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); ++ if (got_alpha == NULL || num_trans != 4) ++ { ++ fprintf(stderr, "pnggetset: png_get_tRNS returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->trans_alpha. */ ++ png_set_tRNS(png_ptr, info_ptr, got_alpha, num_trans, got_color); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_alpha = NULL; ++ num_trans = 0; ++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); ++ if (got_alpha == NULL || num_trans != 4) ++ { ++ fprintf(stderr, "pnggetset: tRNS lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_alpha[i] != (png_byte)(0xff - i * 0x11)) ++ { ++ fprintf(stderr, ++ "pnggetset: tRNS entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_tRNS_SUPPORTED */ ++ ++int ++main(void) ++{ ++ int result = 0; ++ ++ printf("Testing PLTE get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_plte_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++ ++#ifdef PNG_hIST_SUPPORTED ++ printf("Testing hIST get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_hist_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_tRNS_SUPPORTED ++ printf("Testing tRNS get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_trns_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++ return result; ++} +diff --git a/pngset.c b/pngset.c +index b9ccb7fb1..a6f20123e 100644 +--- a/pngset.c ++++ b/pngset.c +@@ -385,6 +385,7 @@ void PNGAPI + png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, + png_const_uint_16p hist) + { ++ png_uint_16 safe_hist[PNG_MAX_PALETTE_LENGTH]; + int i; + + png_debug1(1, "in %s storage function", "hIST"); +@@ -401,6 +402,13 @@ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, + return; + } + ++ /* Snapshot the caller's hist before freeing, in case it points to ++ * info_ptr->hist (getter-to-setter aliasing). ++ */ ++ memcpy(safe_hist, hist, (unsigned int)info_ptr->num_palette * ++ (sizeof (png_uint_16))); ++ hist = safe_hist; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_HIST, 0); + + /* Changed from info->num_palette to PNG_MAX_PALETTE_LENGTH in +@@ -742,7 +750,7 @@ void PNGAPI + png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, + png_const_colorp palette, int num_palette) + { +- ++ png_color safe_palette[PNG_MAX_PALETTE_LENGTH]; + png_uint_32 max_palette_length; + + png_debug1(1, "in %s storage function", "PLTE"); +@@ -776,6 +784,15 @@ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, + png_error(png_ptr, "Invalid palette"); + } + ++ /* Snapshot the caller's palette before freeing, in case it points to ++ * info_ptr->palette (getter-to-setter aliasing). ++ */ ++ if (num_palette > 0) ++ memcpy(safe_palette, palette, (unsigned int)num_palette * ++ (sizeof (png_color))); ++ ++ palette = safe_palette; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_PLTE, 0); + + /* Changed in libpng-1.2.1 to allocate PNG_MAX_PALETTE_LENGTH instead +@@ -1165,6 +1182,16 @@ png_set_tRNS(png_structrp png_ptr, png_inforp info_ptr, + + if (trans_alpha != NULL) + { ++ /* Snapshot the caller's trans_alpha before freeing, in case it ++ * points to info_ptr->trans_alpha (getter-to-setter aliasing). ++ */ ++ png_byte safe_trans[PNG_MAX_PALETTE_LENGTH]; ++ ++ if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) ++ memcpy(safe_trans, trans_alpha, (size_t)num_trans); ++ ++ trans_alpha = safe_trans; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_TRNS, 0); + + if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) +diff --git a/tests/pnggetset b/tests/pnggetset +new file mode 100755 +index 000000000..57ef731a5 +--- /dev/null ++++ b/tests/pnggetset +@@ -0,0 +1,5 @@ ++#!/bin/sh ++ ++# pnggetset test: ++# Getter-to-setter roundtrips for various chunk types. ++exec ./pnggetset diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch new file mode 100644 index 00000000000..894f9d618be --- /dev/null +++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch @@ -0,0 +1,481 @@ +From 815fdfc8dba0603abc26523d0b7e37f7ad21988b Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Mon, 30 Mar 2026 17:43:05 +0300 +Subject: [PATCH] fix: Handle getter-to-setter aliasing in append-style chunk + setters + +Apply the same class of robustness fix from the previous commit to +`png_set_text`, `png_set_sPLT` and `png_set_unknown_chunks`. These +append-style setters used `png_realloc_array` to grow the internal +array, then freed the old array before copying from the caller's +input. If the caller's pointer was obtained from the corresponding +getter, it aliased the freed array. + +The fix defers the freeing of the old array until after the copy loop. + +Also extend the pnggetset regression test to cover all three setters. + +CVE: CVE-2026-34757 +Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc] + +(cherry picked from commit 55d20aaa322c9274491cda82c5cd4f99b48c6bcc) +Signed-off-by: Deepak Rathore +--- + contrib/libtests/pnggetset.c | 330 ++++++++++++++++++++++++++++++++++- + pngset.c | 25 ++- + 2 files changed, 347 insertions(+), 8 deletions(-) + +diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c +index b42508094..6ae43dc66 100644 +--- a/contrib/libtests/pnggetset.c ++++ b/contrib/libtests/pnggetset.c +@@ -6,12 +6,12 @@ + * For conditions of distribution and use, see the disclaimer + * and license in png.h + * +- * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. ++ * Test the get-then-set roundtrip for chunk types whose getters return ++ * a pointer to internal storage. + * +- * Passing the internal pointer returned by a getter back into the +- * corresponding setter is a natural API usage pattern. A previous +- * version had a use-after-free on this path because the setter freed +- * the internal buffer before copying from the caller-supplied pointer. ++ * Passing such a pointer back into the corresponding setter must not ++ * cause a use-after-free. A previous version freed the internal buffer ++ * before copying from the caller-supplied pointer. + */ + + #include +@@ -285,6 +285,290 @@ test_trns_roundtrip(void) + } + #endif /* PNG_tRNS_SUPPORTED */ + ++#ifdef PNG_TEXT_SUPPORTED ++/* Test: get the text array, pass it straight back to set, verify data. */ ++#define TEXT_COUNT 6 /* enough to trigger reallocation on the second set */ ++static int ++test_text_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_text text_entries[TEXT_COUNT]; ++ png_textp got_text = NULL; ++ int got_num_text = 0; ++ int i; ++ ++ /* Recognizable keys and values. */ ++ static const char *keys[TEXT_COUNT] = { ++ "Title", "Author", "Desc", "Copyright", "Source", "Comment" ++ }; ++ static const char *vals[TEXT_COUNT] = { ++ "t0", "t1", "t2", "t3", "t4", "t5" ++ }; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_text_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Populate the text entries. */ ++ memset(text_entries, 0, sizeof text_entries); ++ for (i = 0; i < TEXT_COUNT; i++) ++ { ++ text_entries[i].compression = PNG_TEXT_COMPRESSION_NONE; ++ text_entries[i].key = (png_charp)keys[i]; ++ text_entries[i].text = (png_charp)vals[i]; ++ } ++ png_set_text(png_ptr, info_ptr, text_entries, TEXT_COUNT); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); ++ if (got_text == NULL || got_num_text != TEXT_COUNT) ++ { ++ fprintf(stderr, "pnggetset: png_get_text returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_text aliases info_ptr->text. */ ++ png_set_text(png_ptr, info_ptr, got_text, got_num_text); ++ ++ /* Verify the original entries survived. */ ++ got_text = NULL; ++ got_num_text = 0; ++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); ++ if (got_text == NULL || got_num_text != TEXT_COUNT * 2) ++ { ++ fprintf(stderr, "pnggetset: text count %d, expected %d after roundtrip\n", ++ got_num_text, TEXT_COUNT * 2); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < TEXT_COUNT; i++) ++ { ++ if (got_text[i].key == NULL || ++ strcmp(got_text[i].key, keys[i]) != 0 || ++ got_text[i].text == NULL || ++ strcmp(got_text[i].text, vals[i]) != 0) ++ { ++ fprintf(stderr, ++ "pnggetset: text entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#undef TEXT_COUNT ++#endif /* PNG_TEXT_SUPPORTED */ ++ ++#ifdef PNG_sPLT_SUPPORTED ++/* Test: get the sPLT array, pass it straight back to set, verify data. */ ++static int ++test_splt_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_sPLT_t splt; ++ png_sPLT_entry splt_entries[4]; ++ png_sPLT_tp got_spalettes = NULL; ++ int got_num, i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_splt_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Populate with recognizable values. */ ++ memset(splt_entries, 0, sizeof splt_entries); ++ for (i = 0; i < 4; i++) ++ { ++ splt_entries[i].red = (png_uint_16)(i * 1000); ++ splt_entries[i].green = (png_uint_16)(i * 2000); ++ splt_entries[i].blue = (png_uint_16)(i * 3000); ++ splt_entries[i].alpha = 0xffffU; ++ splt_entries[i].frequency = (png_uint_16)(i + 1); ++ } ++ memset(&splt, 0, sizeof splt); ++ splt.name = (png_charp)"test_sPLT"; ++ splt.depth = 16; ++ splt.entries = splt_entries; ++ splt.nentries = 4; ++ ++ png_set_sPLT(png_ptr, info_ptr, &splt, 1); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); ++ if (got_spalettes == NULL || got_num != 1) ++ { ++ fprintf(stderr, "pnggetset: png_get_sPLT returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_spalettes aliases internal storage. */ ++ png_set_sPLT(png_ptr, info_ptr, got_spalettes, got_num); ++ ++ /* Verify the original entry survived. */ ++ got_spalettes = NULL; ++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); ++ if (got_spalettes == NULL || got_num != 2) ++ { ++ fprintf(stderr, "pnggetset: sPLT count %d, expected 2 after roundtrip\n", ++ got_num); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ if (strcmp(got_spalettes[0].name, "test_sPLT") != 0 || ++ got_spalettes[0].nentries != 4 || ++ got_spalettes[0].depth != 16) ++ { ++ fprintf(stderr, ++ "pnggetset: sPLT entry 0 corrupted after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_spalettes[0].entries[i].red != (png_uint_16)(i * 1000) || ++ got_spalettes[0].entries[i].green != (png_uint_16)(i * 2000) || ++ got_spalettes[0].entries[i].blue != (png_uint_16)(i * 3000)) ++ { ++ fprintf(stderr, ++ "pnggetset: sPLT[0] entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_sPLT_SUPPORTED */ ++ ++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED ++/* Test: get unknown chunks, pass them straight back to set, verify data. */ ++static int ++test_unknown_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_unknown_chunk unk; ++ png_unknown_chunkp got_unknowns = NULL; ++ int got_num; ++ static const png_byte test_data[] = {0xde, 0xad, 0xbe, 0xef}; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, ++ "pnggetset: libpng error in test_unknown_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up an unknown chunk with recognizable data. */ ++ memset(&unk, 0, sizeof unk); ++ memcpy(unk.name, "teSt", 5); ++ unk.data = (png_bytep)test_data; ++ unk.size = sizeof test_data; ++ unk.location = PNG_HAVE_IHDR; ++ ++ png_set_keep_unknown_chunks(png_ptr, PNG_HANDLE_CHUNK_ALWAYS, NULL, 0); ++ png_set_unknown_chunks(png_ptr, info_ptr, &unk, 1); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); ++ if (got_unknowns == NULL || got_num != 1) ++ { ++ fprintf(stderr, ++ "pnggetset: png_get_unknown_chunks returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_unknowns aliases internal storage. */ ++ png_set_unknown_chunks(png_ptr, info_ptr, got_unknowns, got_num); ++ ++ /* Verify the original entry survived. */ ++ got_unknowns = NULL; ++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); ++ if (got_unknowns == NULL || got_num != 2) ++ { ++ fprintf(stderr, ++ "pnggetset: unknown_chunks count %d, expected 2 after roundtrip\n", ++ got_num); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ if (memcmp(got_unknowns[0].name, "teSt", 4) != 0 || ++ got_unknowns[0].size != sizeof test_data || ++ memcmp(got_unknowns[0].data, test_data, sizeof test_data) != 0) ++ { ++ fprintf(stderr, ++ "pnggetset: unknown chunk 0 corrupted after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED */ ++ + int + main(void) + { +@@ -324,5 +608,41 @@ main(void) + printf("PASS\n"); + #endif + ++#ifdef PNG_TEXT_SUPPORTED ++ printf("Testing tEXt get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_text_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_sPLT_SUPPORTED ++ printf("Testing sPLT get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_splt_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED ++ printf("Testing unknown chunks get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_unknown_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ + return result; + } +diff --git a/pngset.c b/pngset.c +index a6f20123e..513c51eb4 100644 +--- a/pngset.c ++++ b/pngset.c +@@ -954,6 +954,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + png_const_textp text_ptr, int num_text) + { + int i; ++ png_textp old_text = NULL; + + png_debug1(1, "in text storage function, chunk typeid = 0x%lx", + png_ptr == NULL ? 0xabadca11UL : (unsigned long)png_ptr->chunk_name); +@@ -1001,7 +1002,10 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + return 1; + } + +- png_free(png_ptr, info_ptr->text); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case text_ptr aliases info_ptr->text (getter-to-setter). ++ */ ++ old_text = info_ptr->text; + + info_ptr->text = new_text; + info_ptr->free_me |= PNG_FREE_TEXT; +@@ -1086,6 +1090,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + { + png_chunk_report(png_ptr, "text chunk: out of memory", + PNG_CHUNK_WRITE_ERROR); ++ png_free(png_ptr, old_text); + + return 1; + } +@@ -1139,6 +1144,8 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + png_debug1(3, "transferred text chunk %d", info_ptr->num_text); + } + ++ png_free(png_ptr, old_text); ++ + return 0; + } + #endif +@@ -1276,6 +1283,7 @@ png_set_sPLT(png_const_structrp png_ptr, + */ + { + png_sPLT_tp np; ++ png_sPLT_tp old_spalettes; + + png_debug1(1, "in %s storage function", "sPLT"); + +@@ -1296,7 +1304,10 @@ png_set_sPLT(png_const_structrp png_ptr, + return; + } + +- png_free(png_ptr, info_ptr->splt_palettes); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case entries aliases info_ptr->splt_palettes (getter-to-setter). ++ */ ++ old_spalettes = info_ptr->splt_palettes; + + info_ptr->splt_palettes = np; + info_ptr->free_me |= PNG_FREE_SPLT; +@@ -1360,6 +1371,8 @@ png_set_sPLT(png_const_structrp png_ptr, + } + while (--nentries); + ++ png_free(png_ptr, old_spalettes); ++ + if (nentries > 0) + png_chunk_report(png_ptr, "sPLT out of memory", PNG_CHUNK_WRITE_ERROR); + } +@@ -1408,6 +1421,7 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + png_inforp info_ptr, png_const_unknown_chunkp unknowns, int num_unknowns) + { + png_unknown_chunkp np; ++ png_unknown_chunkp old_unknowns; + + if (png_ptr == NULL || info_ptr == NULL || num_unknowns <= 0 || + unknowns == NULL) +@@ -1454,7 +1468,10 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + return; + } + +- png_free(png_ptr, info_ptr->unknown_chunks); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case unknowns aliases info_ptr->unknown_chunks (getter-to-setter). ++ */ ++ old_unknowns = info_ptr->unknown_chunks; + + info_ptr->unknown_chunks = np; /* safe because it is initialized */ + info_ptr->free_me |= PNG_FREE_UNKN; +@@ -1500,6 +1517,8 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + ++np; + ++(info_ptr->unknown_chunks_num); + } ++ ++ png_free(png_ptr, old_unknowns); + } + + void PNGAPI diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.56.bb b/meta/recipes-multimedia/libpng/libpng_1.6.56.bb index 7ede0a6c8b7..9dbd0d26e06 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.56.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.56.bb @@ -12,7 +12,9 @@ LIBV = "16" SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}${LIBV}/${BP}.tar.xz \ file://run-ptest \ -" + file://CVE-2026-34757_p1.patch \ + file://CVE-2026-34757_p2.patch \ + " SRC_URI[sha256sum] = "f7d8bf1601b7804f583a254ab343a6549ca6cf27d255c302c47af2d9d36a6f18" From patchwork Wed Jul 22 17:23:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93255 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 765CFC531D4 for ; Wed, 22 Jul 2026 17:24:11 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5531.1784741050970209589 for ; Wed, 22 Jul 2026 10:24:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hwSgtiIh; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-495590dde14so38695265e9.0 for ; Wed, 22 Jul 2026 10:24:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741049; x=1785345849; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hxcUQ+JLXYcAmNC661rjRNPor+j/9u+doopY7l+xCI0=; b=hwSgtiIhmki2+7rB2jU9mKR30778O6/SrsOgVD9vbf5v96gduFt9mc27s66GuE8usV /xyCeapEZhfJfe1+OaqWwKLmaVWE20q+2qgIVHKgmyhpKWkjmWJpsK4kMxDpP6FGFp/V 1oITa/VOeM/8270FiNTTVFpuIfgsQui5u2fTA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741049; x=1785345849; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hxcUQ+JLXYcAmNC661rjRNPor+j/9u+doopY7l+xCI0=; b=gtLRH9H1Y2fGneNXPoWU47G78PsZ4RgK+VZ5CDRQcmChurlr93RxaAac8r6OWKEVxf FMUxrg/oJNuP2d1ZlY+Ssi0K3umw5+/5+sARH9vKpbNFij33NGYP5CSgBrL3oGXHq3LC hyPCGWA7Sk2JTU8RIYU96jTxInJVS7teL/SA3xM87kuB/vCyGrLQsCDOmG/+VCzm1Y/C 7LuqrjV3FOX9f1S8VxbWBXoXrWhfxXIrbx0E07Q1kH0YyvaaFc68YnVoY4HAJ8oMzJQh AbIf3TmRuVBbcRFai/nnYmdr+NyMIag2ZOanJkNqcdCIkXAjAWpthxh2j8ipVpchwYwD m23A== X-Gm-Message-State: AOJu0YxaEizKuJsMcxzVOP/IkdaV+QfpznSdMBscTxQp4KNInuRBSnCC Rxnf8WTx5vOnSp6IWG2Mc61kuroiX4lSNVZqKVculOpMoh+3/ftCWlZVOV6RfpM8byg90OxtpYH ggcbRzQw= X-Gm-Gg: AR+sD13ViU/O1bW5za1hIcQeQVyZtkBFsoVf52d+Ot78mP5D3sMTns3xtxklYi2cOdy OEaGXjtWDdxMCDLDIPDpRjUh59DIyzWEH8zuGfS1ZkKAKdW7sLxXyk3eEXnm3wkvmW+vcU5L5Iz WuzNgWJeozirGeRzwi5tMcHHytyzMEg41Bt2YqZXxwz7WKbTVh7Ev5H1lTWpv3l0cxOyI1ldoZG ItZAP/t7p76CnQbDPxj1oJjZXYrVCHf1TT2qwfz2x+Lveg76DQCjH5u8X9wqaB0Fg2rIJH/Q+bi Bnvt7cQ+9a4CaVmc8ftTVgGL8FpBda6uXzHnm7E3kIadI9h38HcVTQLKOTpBrEzJ/LoLIJjDUgG ht9b+00DLQb+VlF/QbvXXM4Q+C/J9PXn9dMXPQRTw7BWNH6rQOQJRUObq5I6XgWYfCkX7wnjQuD 6wD/c9OKqARbck7GfF8WQTJL8cFqr1dVbQI12XFVRJXO0gSkBjkOsZLkNjfun+hE8pG6eqNUp23 BoU65qDxbzg X-Received: by 2002:a05:600c:138c:b0:495:6788:c229 with SMTP id 5b1f17b1804b1-4956788c359mr84542665e9.4.1784741049213; Wed, 22 Jul 2026 10:24:09 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/27] openssh: Fix CVE-2026-59999 Date: Wed, 22 Jul 2026 19:23:33 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241729 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-59999. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753 [2] https://www.cve.org/CVERecord?id=CVE-2026-59999 Signed-off-by: Devansh Patel [YC: patch referenced at https://ubuntu.com/security/CVE-2026-59999] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59999.patch | 38 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch new file mode 100644 index 00000000000..5907a991b9a --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch @@ -0,0 +1,38 @@ +From a83dd105dc407d95c42140ea6f04a1e247aaf2f9 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Sun, 31 May 2026 04:47:29 +0000 +Subject: [PATCH] upstream: DisableForwarding=yes didn't override + PermitTunnel=yes + +Reported independently by Huzaifa Sidhpurwala of Redhat and Marko +Jevtic; ok markus@ + +OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c + +CVE: CVE-2026-59999 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in serverloop.c and + retained the Wrynose OpenSSH 10.3p1 revision because this stable + backport carries only the functional security change. + +(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753) +Signed-off-by: Devansh Patel +--- + serverloop.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/serverloop.c b/serverloop.c +index 8e63480ec..42c3ce9fe 100644 +--- a/serverloop.c ++++ b/serverloop.c +@@ -523,7 +523,7 @@ server_request_tun(struct ssh *ssh) + ssh_packet_send_debug(ssh, "Unsupported tunnel device mode."); + return NULL; + } +- if ((options.permit_tun & mode) == 0) { ++ if ((options.permit_tun & mode) == 0 || options.disable_forwarding) { + ssh_packet_send_debug(ssh, "Server has rejected tunnel device " + "forwarding"); + return NULL; diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 8669d080b6e..53704a0cc7e 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -24,6 +24,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://run-ptest \ file://sshd_check_keys \ file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ + file://CVE-2026-59999.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93259 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6EF5DC44536 for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5533.1784741051628790818 for ; Wed, 22 Jul 2026 10:24:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=NhzU7EIn; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4921eed3fa2so98841505e9.0 for ; Wed, 22 Jul 2026 10:24:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741050; x=1785345850; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GjhlxKXHEOqwNm8TX4wZmjSkj8BB/aAtbAQTOf4dpWc=; b=NhzU7EIndq7obIWZeWqRQ2LmGiVZB13PLSQwP3ArE/Ceh9ls5GSPTfEBDysyK8rBb0 Ol5LuE51llkD4G12+jCCOifhKabNGzcWmEjsAODyW+HujoG0MpzdqRXc/I2xTFEeOjk0 AecSXKYk3VC119ddPdT3xQ2+bT+e/DMbdubsk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741050; x=1785345850; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GjhlxKXHEOqwNm8TX4wZmjSkj8BB/aAtbAQTOf4dpWc=; b=AUPs82hoMa3H1GcZkViUeRQphtvFuEHXs4VlmYRLP0yHu17wvEGsfk420VvTyAS3AS jrk81Hv/izC8r/8igUZF+hbABeloMZNgBGnMWO/HuvkF9jZfeHy3BDN3TKE5G9IUeBIR 2FvPzcLIjhKqZXCpmqGXNpt5BnDB6qhxdcrcX06z2zLxYFWsPlZYtoXipNJSojAxtpH9 LQmwesZIeftkqm+YwqXT7p/FQ8uH7SIdTime8i+Zo1nYCWOnxNXdRm3b4FNgSyBDHyw/ K4/hH8PcQPSLEXuFNFEqIEizdmX7SMO+mHSS82o4G4Z6fo6tkPw0dYBGv/cPqxi31Lha 4XeQ== X-Gm-Message-State: AOJu0Yw+lVStF3Tkbckrx0ELJnCKsi4o8VyD28cOf2+OXpbSo9jljDJh vqiBbgb27vHTtEeHgGOM9zCr+CrJUDXrx7lXYvZdllmJyf4kamicZLd28TLPigfCvGinskmO3Mk x0i5sUOw= X-Gm-Gg: AR+sD1170OaAHBZ6ZskjwPd82MeeztW6qOsoGfO2GTtwRLRvf/e51ATR282vfANFRsM QFOV26AygU+5ErcbTMOvo98Wjc99quk6uWLiGpE1LYzwfn/Uk2BG7nOcioMEAQ/mVNyqh4dbQ7L sLk2/a2CTFTQsqvJK5BXDpI0NBXHdk6tr4mgfkdqs80q7c4tcr0NZ1ufin/mVfYJhGZoE7O7WIg vr9nTL3smhYSWQym9Ql/1j+0CSXITHrhWa/Ly21XvtXB2cbUV7ZRGZHCRZLpDikJBV874i6bNQd +eS31ZoasMPLH6PO07zYGadKenduOum2WUhhL+idNxgBKjFvQNe9Q6BmptB5sLtBc46+Dggh/Dq lMnRX/dkbMqiXVP8LLa2ViOB+gkHdbpXpiPlLLrqOyZuytWoUFs/mH5ii/QvS/YanwRDeHLznob aZbcc2C2D8/AD45kdyLvqlGPicvm+XgY4lPbx6yv8H95fMTLqMwZj4VtKcGAnQXdt8WCsz/bluj GB8+XtXKJ5W X-Received: by 2002:a05:600d:9:b0:495:5e07:649b with SMTP id 5b1f17b1804b1-4955e16aca3mr165429335e9.24.1784741049798; Wed, 22 Jul 2026 10:24:09 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/27] openssh: Fix CVE-2026-59997 Date: Wed, 22 Jul 2026 19:23:34 +0200 Message-ID: <66bc605a9ae474b9e0f794cf1e3f4cd1294b8647.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241731 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-59997. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014 [2] https://www.cve.org/CVERecord?id=CVE-2026-59997 Signed-off-by: Devansh Patel [YC: patch referenced at https://ubuntu.com/security/CVE-2026-59997] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59997.patch | 60 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch new file mode 100644 index 00000000000..7d77fbcc9eb --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch @@ -0,0 +1,60 @@ +From 91ce99061c78d0ae84dafc96409c8ea9746f70c0 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Fri, 5 Jun 2026 08:53:07 +0000 +Subject: [PATCH] upstream: pass >9 commandline arguments to the internal-sftp + server, + +previously they were silently dropped; reported by Steve Caffrey ok deraadt@ + +OpenBSD-Commit-ID: ee6cd5430a3ca027c3223af54b58ad3cc7ccd624 + +CVE: CVE-2026-59997 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in session.c and + retained the Wrynose OpenSSH 10.3p1 revision because this stable + backport carries only the functional security change. + +(cherry picked from commit e9916c44c1324ab9ab022719e4df08a390a83014) +Signed-off-by: Devansh Patel +--- + session.c | 19 ++++++++++--------- + 1 file changed, 10 insertions(+), 9 deletions(-) + +diff --git a/session.c b/session.c +index 93de35d7c..b1f125a3c 100644 +--- a/session.c ++++ b/session.c +@@ -1607,21 +1607,22 @@ do_child(struct ssh *ssh, Session *s, const char *command) + exit(1); + } else if (s->is_subsystem == SUBSYSTEM_INT_SFTP) { + extern int optind, optreset; +- int i; +- char *p, *args; ++ int sftp_argc; ++ char **sftp_argv; + + setproctitle("%s@%s", s->pw->pw_name, INTERNAL_SFTP_NAME); +- args = xstrdup(command ? command : "sftp-server"); +- for (i = 0, (p = strtok(args, " ")); p; (p = strtok(NULL, " "))) +- if (i < ARGV_MAX - 1) +- argv[i++] = p; +- argv[i] = NULL; ++ if (argv_split(command == NULL ? "sftp-server" : command, ++ &sftp_argc, &sftp_argv, 1) != 0) { ++ error("internal error: can't split internal-sftp " ++ "arguments"); ++ exit(1); ++ } + optind = optreset = 1; +- __progname = argv[0]; ++ __progname = sftp_argv[0]; + #ifdef WITH_SELINUX + ssh_selinux_change_context("sftpd_t"); + #endif +- exit(sftp_server_main(i, argv, s->pw)); ++ exit(sftp_server_main(sftp_argc, sftp_argv, s->pw)); + } + + fflush(NULL); diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 53704a0cc7e..e611db65ff8 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -25,6 +25,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://sshd_check_keys \ file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ file://CVE-2026-59999.patch \ + file://CVE-2026-59997.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93260 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B891DC4453F for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5471.1784741052214063493 for ; Wed, 22 Jul 2026 10:24:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mvP5HjLz; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49558ce01afso32091135e9.1 for ; Wed, 22 Jul 2026 10:24:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741050; x=1785345850; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5iHMV6z+cX0dECL8KCeDCsatkSxLzMJHYGqcPuJJsZ0=; b=mvP5HjLzieovt7EYZmS5N/u+jzcNQYakQRNMK8pqf5Szu3t/jKoQ+TZSSI3+0m7hmv KbCfPfQ/AFrgGSvTmlEDTTVWf0rSsWLizFx/2s0nWhYLDvKSZVCTVF8712ubDHSC4sVu PNPm65AkmV9NZpHFpkPlkPqvscRE/eQfI4DWU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741050; x=1785345850; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5iHMV6z+cX0dECL8KCeDCsatkSxLzMJHYGqcPuJJsZ0=; b=Vg1aa6/1t0b1jq+pI+d63qDW3/1fAiBAcTB2pkKMZiTOUfT3zRG12o1sXweuNrfCTH KQKr3jiF6AJ3tWyaWHncvxzdt1ThwXLvobp3fln4a0Cm+248BTumQyHxhL90jf2OpaSM H1gQ6TvNjoJx68LVZSiZ2kPXybYWKw1XxJ1GlCxmx17YVslcrDKot9IiKUBnIuZBnQhx lOYI82muSET5nVK7eh2+IP4nkLtnet0/hY7IOOnxT/uyCLnfcfsftralSoXTuPX8PIVh A8NNZoEgcXANZriwtgm/9OpnkjNxJ7wbS9HyCA18MkQx7pnme2Y5r2Ax6fMbDXrHQcTj 7zGw== X-Gm-Message-State: AOJu0YzkJSwxawd+j0LN+n8emyMkGDIvIxpg86K4C7ly2JXmExQZpImn ObsE/S6iId8gv3Vc3WCu8pkdcpKrTxi1xszyECqmgGp9CtlvxkbADm303WwO69su/1kYUg3l6Uv VNbBMIkA= X-Gm-Gg: AR+sD10gta1W3cNscyUh8hRH0sqM/IOJXn8T0cNLjVD/KAvkliu2Hm+SU126YGnVxFH FPIYIvXuhZRvNGgVOB8PL0LMKqZrZapOLWZISDbn5NS9BZzhwnOHtuwikErhMF12HKXaj1Rqtqi 2kRimoRP2tWn52IVS72MfeyLChUS+Ix2H8/1TBI4HiGbGXoZ53cuTesb8vDjQdKxXv5z+ZPhKuH KfmAMcOhXG3xidMHfBeejXgIJQ+a60S1Nta5bSRiXreNzSn74ML/HUzA7U27L6G90uZnoQ8o/0g Q7qxJf/6Xz3d29RIncIsBzzUfn5lalpkIZMnUePK4sLjf98NkZdxWU3DRxEJtYCZwZB12yXdMsz mMPoSi3MMHI9HbcyREWvkdA13wGDrBoRze7GpdWTcne8mV4eOEFTJUF+2d3Cn0AFCr7Ul9X9qX9 7TnLKz2LzrAbJ0IVqS9A0lLuBw+vghf1CNB/6Mx7oY2oB71STf4l0zHrt87majqH/BgqZonKAKW RBROvfc9njRPYKQjToizf8= X-Received: by 2002:a05:600c:1384:b0:495:6840:9728 with SMTP id 5b1f17b1804b1-49568409783mr89783905e9.38.1784741050394; Wed, 22 Jul 2026 10:24:10 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/27] openssh: Fix CVE-2026-59996 Date: Wed, 22 Jul 2026 19:23:35 +0200 Message-ID: <4c87dbf8523cfd8dd603e77ed2dc1c4b2c9dfde1.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241732 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-59996. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78 [2] https://www.cve.org/CVERecord?id=CVE-2026-59996 Signed-off-by: Devansh Patel [YC: patch referenced in https://ubuntu.com/security/CVE-2026-59996] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59996.patch | 39 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch new file mode 100644 index 00000000000..9db9988690b --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch @@ -0,0 +1,39 @@ +From f479595f7498e8c83d3df9d3eddb6e555497ff5b Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Sun, 28 Jun 2026 23:47:16 +0000 +Subject: [PATCH] upstream: resist that return ".." via remote glob during + +remote/remote copies, similar to fixes for bz3871 for remote/local copies. +From Swival scanner + +OpenBSD-Commit-ID: c0c20a1b746db55c08e53658bf21ea9405b300a5 + +CVE: CVE-2026-59996 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in scp.c and retained + the Wrynose OpenSSH 10.3p1 revision because this stable backport carries + only the functional security change. + +(cherry picked from commit 36480181fa22f98e180b4f9e10203480c0346c78) +Signed-off-by: Devansh Patel +--- + scp.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/scp.c b/scp.c +index 1faa9a555..bd01ebffd 100644 +--- a/scp.c ++++ b/scp.c +@@ -2039,6 +2039,10 @@ throughlocal_sftp(struct sftp_conn *from, struct sftp_conn *to, + goto out; + } + ++ /* Special handling for source of '..' */ ++ if (strcmp(filename, "..") == 0) ++ filename = "."; /* Download to dest, not dest/.. */ ++ + if (targetisdir) + abs_dst = sftp_path_append(target, filename); + else diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index e611db65ff8..0f4839f7675 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -26,6 +26,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ file://CVE-2026-59999.patch \ file://CVE-2026-59997.patch \ + file://CVE-2026-59996.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93261 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DDF37C531C7 for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5472.1784741052975332234 for ; Wed, 22 Jul 2026 10:24:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=T4qMDpTc; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4954aff6088so37724325e9.3 for ; Wed, 22 Jul 2026 10:24:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741051; x=1785345851; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=+vczk8CvcY4aL8g5YbXn0iT24zJtlAf/6DTKKazpNOw=; b=T4qMDpTcwaWYnrW0OFw59CzE4alpBR+gPNMgTCJohoF2eIyE8vUdKOo4oo8sfXH5gg ewlDlOCESIGSwqwv4EqlIX9Bpkj8DdLgXc7TFEFtgCbYGII3EpiuCMMlziMQkLVx1ORg u86eKIaSsyMToY5xKq/pomDu9SW1ny33/s4sk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741051; x=1785345851; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=+vczk8CvcY4aL8g5YbXn0iT24zJtlAf/6DTKKazpNOw=; b=k2zHnaz0pncw2YOVsSBKQs0C4LnsCN2ohxNgCTy/GO2kZzJ7p/VKO2b/ZN0mkqyv1b Rn01OEQsmSIQihgs2nKePPvDjjK6TSVUa35wZXj2H3mtGKWQyKUrysF/IAlWE8/z28zs ixgMfNADgZPjCMxo+EPQLo8HGLDOXht5+JkHwGLhOsxi0lEdP8TBVFSZV3klUiHpx2bw Pkg0+qR3HieQn1pD0NSXez+dUOcJTfpspS96eBr/1k64J14xg/1bqRWQryoK+5gORZ9s qdiCfWYwOgMpa4bHAB63Ed69xJNYoxqZeYJszoN9JSzRGuO8wWUbnVI0klmWfGSGwXY3 FFxA== X-Gm-Message-State: AOJu0YyFpgTBUMhPJfV6cazTI9x5ER5dH26e2bfsM1xdW7lTmd5DWbaY cSDuEKtoE89EY9CsvmIvGQFqZtuzwLPGjxTCJm447132a4Yq2n3LGNIQjOfB47mwqRaW0VKr+y7 4A4agnkA= X-Gm-Gg: AR+sD1122ULAwEaWh3S8UMm88AVtiTTlwqBXkB20xYBO3rFQo+r4h6lmVzcBuVgr93f dVl0uxYPSQOL+QZwZp22f8Znwf4Mxhp6RWw/cxnRzWTZOV6d8WtGWS6Q709SQisofsucarq5ydK ZxinU4JVk/uG8OS83vSUY34nkcqgkfoZhN+6UJKsPr1GLbGMZJ9eVf50ZJ5eYO1sDpBw014g7ZD t5egd1V+MiVrcrbyTY9NFinCNFVQxkzQJl0K/3SwhBiRQFJ09VTQ7k8bs6FfTUcNOCOmQol/kmg C6RDZ9B+QaXxRfcMo/5xJMoFgLbpRw66PmWZxd94v2ZAXyAWUSa78NFpFCdIKAeIHORezPKkq/8 nI117ySk/vQLHmxtwqQn9tYlYQUlU2LwmIUmu97eZ5mpOQLNGnLNjGEXtkb41r936UMrtN2DbdZ R27vOurXcbsynEvGsLLFFzI3+Oii4Kodz7dkMq7nb5B0Y5yeEoMdWDJxX9ldCoXPHlVZeA6JmOw VaV68k/HET7 X-Received: by 2002:a7b:c8c7:0:b0:493:bfad:9d99 with SMTP id 5b1f17b1804b1-4954a3dc36dmr190017475e9.13.1784741051101; Wed, 22 Jul 2026 10:24:11 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/27] openssh: Fix CVE-2026-59995 Date: Wed, 22 Jul 2026 19:23:36 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241733 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-59995. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b [2] https://www.cve.org/CVERecord?id=CVE-2026-59995 Signed-off-by: Devansh Patel [YC: patch referenced in https://ubuntu.com/security/CVE-2026-59995] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59995.patch | 44 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch new file mode 100644 index 00000000000..ac1712eec2f --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch @@ -0,0 +1,44 @@ +From 02e4b3cfd0bef64381921cdb9d6a21b1f50fdb74 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 29 Jun 2026 01:47:21 +0000 +Subject: [PATCH] upstream: avoid download to server-controlled path when + performing + +download on the commandline. From Swival scanner + +OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f + +CVE: CVE-2026-59995 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in sftp.c and retained + the Wrynose OpenSSH 10.3p1 revision because this stable backport carries + only the functional security change. + +(cherry picked from commit 1b39f39657d2e58f8ec57341581a39bbf0be645b) +Signed-off-by: Devansh Patel +--- + sftp.c | 9 ++------- + 1 file changed, 2 insertions(+), 7 deletions(-) + +diff --git a/sftp.c b/sftp.c +index eebb166e8..33c8364e3 100644 +--- a/sftp.c ++++ b/sftp.c +@@ -2287,13 +2287,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2) + return (-1); + } + } else { +- /* XXX this is wrong wrt quoting */ +- snprintf(cmd, sizeof cmd, "get%s %s%s%s", +- global_aflag ? " -a" : "", dir, +- file2 == NULL ? "" : " ", +- file2 == NULL ? "" : file2); +- err = parse_dispatch_command(conn, cmd, +- &remote_path, startdir, 1, 0); ++ err = process_get(conn, dir, file2, remote_path, 0, 0, ++ global_aflag, 0); + free(dir); + free(startdir); + free(remote_path); diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 0f4839f7675..c3b8d910dd7 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -27,6 +27,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-59999.patch \ file://CVE-2026-59997.patch \ file://CVE-2026-59996.patch \ + file://CVE-2026-59995.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93262 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C36BC531C8 for ; Wed, 22 Jul 2026 17:24:22 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5473.1784741053727829341 for ; Wed, 22 Jul 2026 10:24:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GyUroSo7; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-495590dde14so38695865e9.0 for ; Wed, 22 Jul 2026 10:24:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741052; x=1785345852; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Psk7Yrq+Xj8viEqrOi/gL4fAJ6pLQTCo2rj91DROkTA=; b=GyUroSo7uy25FtV2yZcnB9sOO9i5Dr06DIj6RRSOvcr95i11UU9S8zGqu3IoUBkNDx SiiBw/fWq/cGN4SAec9JoFvLFxMxjfz/j22VQiA+3fL+Ld+/DeZtX95jliLS7T6o9yLQ cAaOhuwTXA1QwJ867ODqPMQgFpyJWWTCkTcjo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741052; x=1785345852; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Psk7Yrq+Xj8viEqrOi/gL4fAJ6pLQTCo2rj91DROkTA=; b=Zuv7+N4xLEtJCP/Gr5XEUDMiQdEODNHVvL4dxj4RB3KpnIVf1zek8DQPZ5D1AeQrVW NWjMrUu/l8feADGQQbKxq09rVgOYdbbv4f8PYXqSf9Yn4SebY3c3wDf3nFqniyboc1pM Ay1sr/SAc2rQ7IqtRSvZjvxN9n+XVymT2+uRiICp6lngBrbt/p33dkmaed64izib0oLR Ub61W1i00laKUGCi78ZHm6Hjc6wxifz1mJvKQ21ZXyQtRY3+yQ2QIldKijCJDlAoKXvx 6IhDnxEIENHEeoI+Rkp/iAY8sA0T728VrvmTQXbrNYU8DTU7ui0ACi1CJbvV/JJVdPWY TKFQ== X-Gm-Message-State: AOJu0YwbhXpHQUHQuXh+he21Zh2Ogy6srY/hKrSOmoywLSiuICiYYZJb De204pt4YZqGnXYjoFQTFvIo+JMulqQn/p9sYgCcw68Y31ASoE+kPMAYDEZNWQpUGXhP0Lq8syV YoiRSDHA= X-Gm-Gg: AR+sD12mL0OmmbHUYyfsOtcM9OaD3WGr0VygQ2OhQ4xDBkWUV2kFUG3taFMh95qBXex 2IJ1XMKaa/fGyw0zwuYFnMSKuzzomuV3F591Tj/maiG1jxjuEUTfupm7B3eVWQ4pdf/AL8iciBE DX4Uy1e39MhyeWzo2mH+VP7jKJrYBP9wXdojFVsU6ej5rz5bKsQvTNPQIDDGUxlSUV9m8z9ItkO kYnwMu/XQw6TqRTVxxMWU4kTSso+zWmLqSV0SC/im5mnS9BQu6Xm9iBHaDDWZoeIA0pzii7aNGW ry0DvqtXtXhspMLYLdG+9HBG5YiZADsrAMrAoPAjX5lkITnVmRfuHQDFDh5rvyBhVe8dadJmSDS 8054HffQUhx57/geVEfdSeuJNsJAjGKo7qwYDhkKE5/KE72UdVSqWGK/QQm2pWICDWTGzAnZDI9 lgjyi41qdKC9r91dVhV+psyIVJDF9Fb474Wk2Z0Jvus0burglX8GgxfTyED7ETC/K048a9Xgc0z WjGjPUgnfle X-Received: by 2002:a05:600c:310b:b0:495:7287:293d with SMTP id 5b1f17b1804b1-495728736b3mr10656585e9.27.1784741051880; Wed, 22 Jul 2026 10:24:11 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/27] openssh: Fix CVE-2026-60001 Date: Wed, 22 Jul 2026 19:23:37 +0200 Message-ID: <90d9e72af4a20f0e69bfe2a43f4cbb46c00a26de.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241734 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-60001. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454 [2] https://www.cve.org/CVERecord?id=CVE-2026-60001 Signed-off-by: Devansh Patel [YC: patch referenced in https://ubuntu.com/security/CVE-2026-60001] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60001.patch | 130 ++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 131 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch new file mode 100644 index 00000000000..aa32484b17d --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch @@ -0,0 +1,130 @@ +From 6bc7dd87d543c882994f95c8309846dfda9ab503 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:44:48 +0000 +Subject: [PATCH] upstream: Fix cases in GSSAPI and keyboard-interactive + +authentication where the minimum per-attempt delay was not being enforced. + +Reported by Orange Cyberdefense Vulnerability Team + +OpenBSD-Commit-ID: c40bd35cc2428fcaccad7a141703c28baa6da01e + +CVE: CVE-2026-60001 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunks in auth.h, + auth2-chall.c, auth2-gss.c, and auth2.c and retained the Wrynose + OpenSSH 10.3p1 revisions because this stable backport carries only the + functional security changes. + +(cherry picked from commit d43ba60c91cb323ca921049b7d43b1908c318454) +Signed-off-by: Devansh Patel +--- + auth.h | 1 + + auth2-chall.c | 4 ++++ + auth2-gss.c | 7 +++++++ + auth2.c | 10 ++++++++-- + 4 files changed, 20 insertions(+), 2 deletions(-) + +diff --git a/auth.h b/auth.h +index 634a84aa8..c2cfa5ed8 100644 +--- a/auth.h ++++ b/auth.h +@@ -175,6 +175,7 @@ void auth_log(struct ssh *, int, int, const char *, const char *); + void auth_maxtries_exceeded(struct ssh *) __attribute__((noreturn)); + void userauth_finish(struct ssh *, int, const char *, const char *); + int auth_root_allowed(struct ssh *, const char *); ++void auth_failure_delay(Authctxt *, double); + + char *auth2_read_banner(void); + int auth2_methods_valid(const char *, int); +diff --git a/auth2-chall.c b/auth2-chall.c +index f3889079b..4687ca8e2 100644 +--- a/auth2-chall.c ++++ b/auth2-chall.c +@@ -300,6 +300,7 @@ input_userauth_info_response(int type, uint32_t seq, struct ssh *ssh) + u_int i, nresp; + const char *devicename = NULL; + char **response = NULL; ++ double tstart = monotime_double(); + + if (authctxt == NULL) + fatal_f("no authctxt"); +@@ -358,6 +359,9 @@ input_userauth_info_response(int type, uint32_t seq, struct ssh *ssh) + auth2_challenge_start(ssh); + } + } ++ ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); + userauth_finish(ssh, authenticated, "keyboard-interactive", + devicename); + return 0; +diff --git a/auth2-gss.c b/auth2-gss.c +index 053548527..f27ac9221 100644 +--- a/auth2-gss.c ++++ b/auth2-gss.c +@@ -255,6 +255,7 @@ input_gssapi_exchange_complete(int type, uint32_t plen, struct ssh *ssh) + { + Authctxt *authctxt = ssh->authctxt; + int r, authenticated; ++ double tstart = monotime_double(); + + if (authctxt == NULL) + fatal("No authentication or GSSAPI context"); +@@ -268,6 +269,8 @@ input_gssapi_exchange_complete(int type, uint32_t plen, struct ssh *ssh) + fatal_fr(r, "parse packet"); + + authenticated = mm_ssh_gssapi_userok(authctxt->user); ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); + + authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); +@@ -288,6 +291,7 @@ input_gssapi_mic(int type, uint32_t plen, struct ssh *ssh) + gss_buffer_desc mic, gssbuf; + u_char *p; + size_t len; ++ double tstart = monotime_double(); + + if (authctxt == NULL) + fatal("No authentication or GSSAPI context"); +@@ -315,6 +319,9 @@ input_gssapi_mic(int type, uint32_t plen, struct ssh *ssh) + sshbuf_free(b); + free(mic.value); + ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); ++ + authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL); +diff --git a/auth2.c b/auth2.c +index 3a1682746..7ba611c02 100644 +--- a/auth2.c ++++ b/auth2.c +@@ -265,6 +265,12 @@ ensure_minimum_time_since(double start, double seconds) + nanosleep(&ts, NULL); + } + ++void ++auth_failure_delay(Authctxt *authctxt, double tstart) ++{ ++ ensure_minimum_time_since(tstart, user_specific_delay(authctxt->user)); ++} ++ + static int + input_userauth_request(int type, uint32_t seq, struct ssh *ssh) + { +@@ -346,8 +352,8 @@ input_userauth_request(int type, uint32_t seq, struct ssh *ssh) + authenticated = m->userauth(ssh, method); + } + if (!authctxt->authenticated && strcmp(method, "none") != 0) +- ensure_minimum_time_since(tstart, +- user_specific_delay(authctxt->user)); ++ auth_failure_delay(authctxt, tstart); ++ + userauth_finish(ssh, authenticated, method, NULL); + r = 0; + out: diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index c3b8d910dd7..d8d73ee5dd0 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -28,6 +28,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-59997.patch \ file://CVE-2026-59996.patch \ file://CVE-2026-59995.patch \ + file://CVE-2026-60001.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93265 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27FAEC531C9 for ; Wed, 22 Jul 2026 17:24:22 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5474.1784741054453270114 for ; Wed, 22 Jul 2026 10:24:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SehE7Lxk; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-495590dde14so38695995e9.0 for ; Wed, 22 Jul 2026 10:24:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741053; x=1785345853; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=2s5a5IVjL7D1G9uuuYTzKJ9TFO7iDt58VxEA7trDunI=; b=SehE7LxkLOWkwgXcHb3OJKnqTrDO22YhYoOCBUZhkwR8xBuhUQqsbEN8BdcwQ/lV0q HgF+k+WlkKv+1/fwcxim53gJYPsYw6NH6OuuyfkU9JonkdHvzDfDjBS9j2bXhgLkCmgo TvVLNfajlXe7bzfR/yIzTa8erkc4C9LzNmoxQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741053; x=1785345853; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=2s5a5IVjL7D1G9uuuYTzKJ9TFO7iDt58VxEA7trDunI=; b=tFeynFXcN5ghI7tJ+QqNZpXbhtfy8B8Ou6KUVBfq+GlCh3VSzRb4IUYHUed60/64a7 rn6iqoMOimI83RmUprSO+iuzEE6uOYxvK/Mhape6cRW2rcjWxhyc+SCTagGa4Z+fBFan hXq0CsMITZUxJ5RmAJIlBF6PMZ2G/unJWUCfshaiGUb1LwPuImGPpiR9D40xpBLCk/7d sQZ1s/XVJzu6LHnIbgV6THkjKqUJKpwh3iHxufIcKbMGLCepLGP9Inal8G+6vW3jGWUY 7K0G3eYXYShCF160XANVr+kEjc54Y1HwEUs/cz3sKIENlTnLW6U7gojgUDX17FK1w6aM t+Yw== X-Gm-Message-State: AOJu0Yz5HIe6TGJ3UTm42OL6cu87QUlm1iSCfn/u/osoYvtPy9Ommx6z 4vnMT4R9CofwF0sv9ir5bZR/VI+EH68DffIYc6isbrlhg0Eg/78fs6lCVd76IOvDjgTfun7nsDY hhwgHRLw= X-Gm-Gg: AR+sD11OVjeyE7Fbz2Q/6eTcuBDQtQnYhb8hvgWMH2lh+wb06skcHPXO5CKpiqtkRjv OIv39UvlQJYgmtyJn5nqXmbZo5rHXjPFvnszdXjIQdptrPdzHbbW8BoKsUGrbPsd9JRe+qeJeui qQUvTrSlBgF1JzwXIfI+TCFFAzxIRKm5n9BAowOruHizMhOlRasmkGGysIrWdq2OO5yywqS9hs2 dgsStiUeq04E8zTVWzffsxUf+swvvcSUFHlJ4chxHP8tl38ebRUOxG5mGN4ca4L66pFqArZZ35k X7gy/oNYyllVhZWpNQgtKDrk5joxY0EFRlq1SylmX3AznZqWp8nTpOounohQ4M4XCiCCsKnWOf7 xuC3Fc9YScgLh/jJ45Er2/q1kRf65NuLasAtKFh1bKTF24OZ6qTNvwHrCfqIX0k0BOVBMF9Jjs5 oFZWvVp4cHtQhQslelKI0jfcPyy3oaa3LbZxAso35sHfSKV9n68jry0QFyWDJXuA0vBPoA+TbXQ 6glEA/rTgic X-Received: by 2002:a05:600c:c4aa:b0:495:6934:414c with SMTP id 5b1f17b1804b1-495693442b8mr71388335e9.19.1784741052585; Wed, 22 Jul 2026 10:24:12 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/27] openssh: Fix CVE-2026-60002 Date: Wed, 22 Jul 2026 19:23:38 +0200 Message-ID: <9350aca86f6a0252156c644370829e944cc628d8.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241735 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-60002. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23 [2] https://www.cve.org/CVERecord?id=CVE-2026-60002 Signed-off-by: Devansh Patel [YC: Patch referenced in https://ubuntu.com/security/CVE-2026-60002] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60002.patch | 225 ++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 226 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch new file mode 100644 index 00000000000..85937279a20 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch @@ -0,0 +1,225 @@ +From b571549bc93e95f0d3d563094f825544228501de Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:49:58 +0000 +Subject: [PATCH] upstream: fix ownership and lifetime of several bits of + client + +state that need to persist for the life of the connection, especially the +cached hostkey that was being incorrectly freed early on some paths, possibly +allowing its use after free. + +Reported by Zhenpeng (Leo) Lin from depthfirst.com + +OpenBSD-Commit-ID: faaa6ad72e7d69d41fa8b197b606265b7d9bc73f + +CVE: CVE-2026-60002 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunks in ssh.c, + sshconnect.c, sshconnect.h, and sshconnect2.c and retained the Wrynose + OpenSSH 10.3p1 revisions because this stable backport carries only the + functional security changes. + +(cherry picked from commit e8bdfb151a356d0171fea4194dd205fbb252be23) +Signed-off-by: Devansh Patel +--- + ssh.c | 24 ++---------------------- + sshconnect.c | 47 +++++++++++++++++++++++++++++++++++++++++++++-- + sshconnect.h | 7 +++++-- + sshconnect2.c | 20 +++++++++++--------- + 4 files changed, 63 insertions(+), 35 deletions(-) + +diff --git a/ssh.c b/ssh.c +index 531f28eb2..efb8930f4 100644 +--- a/ssh.c ++++ b/ssh.c +@@ -612,26 +612,6 @@ set_addrinfo_port(struct addrinfo *addrs, int port) + } + } + +-static void +-ssh_conn_info_free(struct ssh_conn_info *cinfo) +-{ +- if (cinfo == NULL) +- return; +- free(cinfo->conn_hash_hex); +- free(cinfo->shorthost); +- free(cinfo->uidstr); +- free(cinfo->keyalias); +- free(cinfo->thishost); +- free(cinfo->host_arg); +- free(cinfo->portstr); +- free(cinfo->remhost); +- free(cinfo->remuser); +- free(cinfo->homedir); +- free(cinfo->locuser); +- free(cinfo->jmphost); +- free(cinfo); +-} +- + /* + * Main program for the ssh client. + */ +@@ -1799,8 +1779,8 @@ main(int ac, char **av) + ssh_signal(SIGCHLD, main_sigchld_handler); + + /* Log into the remote system. Never returns if the login fails. */ +- ssh_login(ssh, &sensitive_data, host, (struct sockaddr *)&hostaddr, +- options.port, pw, timeout_ms, cinfo); ++ ssh_login(ssh, &sensitive_data, host, &hostaddr, options.port, ++ pw, timeout_ms, cinfo); + + /* We no longer need the private host keys. Clear them now. */ + if (sensitive_data.nkeys != 0) { +diff --git a/sshconnect.c b/sshconnect.c +index 4384277a6..3d338ff23 100644 +--- a/sshconnect.c ++++ b/sshconnect.c +@@ -70,6 +70,49 @@ extern char *__progname; + static int show_other_keys(struct hostkeys *, struct sshkey *); + static void warn_changed_key(struct sshkey *); + ++void ++ssh_conn_info_free(struct ssh_conn_info *cinfo) ++{ ++ if (cinfo == NULL) ++ return; ++ free(cinfo->conn_hash_hex); ++ free(cinfo->shorthost); ++ free(cinfo->uidstr); ++ free(cinfo->keyalias); ++ free(cinfo->thishost); ++ free(cinfo->host_arg); ++ free(cinfo->portstr); ++ free(cinfo->remhost); ++ free(cinfo->remuser); ++ free(cinfo->homedir); ++ free(cinfo->locuser); ++ free(cinfo->jmphost); ++ freezero(cinfo, sizeof(*cinfo)); ++} ++ ++struct ssh_conn_info * ++ssh_conn_info_dup(const struct ssh_conn_info *cinfo) ++{ ++ struct ssh_conn_info *ret; ++ ++ if (cinfo == NULL) ++ return NULL; ++ ret = xcalloc(1, sizeof(*ret)); ++ ret->conn_hash_hex = xstrdup(cinfo->conn_hash_hex); ++ ret->shorthost = xstrdup(cinfo->shorthost); ++ ret->uidstr = xstrdup(cinfo->uidstr); ++ ret->keyalias = xstrdup(cinfo->keyalias); ++ ret->thishost = xstrdup(cinfo->thishost); ++ ret->host_arg = xstrdup(cinfo->host_arg); ++ ret->portstr = xstrdup(cinfo->portstr); ++ ret->remhost = xstrdup(cinfo->remhost); ++ ret->remuser = xstrdup(cinfo->remuser); ++ ret->homedir = xstrdup(cinfo->homedir); ++ ret->locuser = xstrdup(cinfo->locuser); ++ ret->jmphost = xstrdup(cinfo->jmphost); ++ return ret; ++} ++ + /* Expand a proxy command */ + static char * + expand_proxy_command(const char *proxy_command, const char *user, +@@ -1585,8 +1628,8 @@ warn_nonpq_kex(void) + */ + void + ssh_login(struct ssh *ssh, Sensitive *sensitive, const char *orighost, +- struct sockaddr *hostaddr, u_short port, struct passwd *pw, int timeout_ms, +- const struct ssh_conn_info *cinfo) ++ struct sockaddr_storage *hostaddr, u_short port, struct passwd *pw, ++ int timeout_ms, const struct ssh_conn_info *cinfo) + { + char *host; + char *server_user, *local_user; +diff --git a/sshconnect.h b/sshconnect.h +index 4c19490da..8da0e04b9 100644 +--- a/sshconnect.h ++++ b/sshconnect.h +@@ -76,7 +76,7 @@ int ssh_connect(struct ssh *, const char *, const char *, + void ssh_kill_proxy_command(void); + + void ssh_login(struct ssh *, Sensitive *, const char *, +- struct sockaddr *, u_short, struct passwd *, int, ++ struct sockaddr_storage *, u_short, struct passwd *, int, + const struct ssh_conn_info *); + + int verify_host_key(char *, struct sockaddr *, struct sshkey *, +@@ -85,7 +85,7 @@ int verify_host_key(char *, struct sockaddr *, struct sshkey *, + void get_hostfile_hostname_ipaddr(char *, struct sockaddr *, u_short, + char **, char **); + +-void ssh_kex2(struct ssh *ssh, char *, struct sockaddr *, u_short, ++void ssh_kex2(struct ssh *ssh, char *, struct sockaddr_storage *, u_short, + const struct ssh_conn_info *); + + void ssh_userauth2(struct ssh *ssh, const char *, const char *, +@@ -101,3 +101,6 @@ void load_hostkeys_command(struct hostkeys *, const char *, + const struct sshkey *, const char *); + + int hostkey_accepted_by_hostkeyalgs(const struct sshkey *); ++ ++void ssh_conn_info_free(struct ssh_conn_info *); ++struct ssh_conn_info *ssh_conn_info_dup(const struct ssh_conn_info *); +diff --git a/sshconnect2.c b/sshconnect2.c +index 478a9a52f..50ac6b89d 100644 +--- a/sshconnect2.c ++++ b/sshconnect2.c +@@ -83,7 +83,7 @@ extern Options options; + */ + + static char *xxx_host; +-static struct sockaddr *xxx_hostaddr; ++static struct sockaddr_storage xxx_hostaddr; + static const struct ssh_conn_info *xxx_conn_info; + static int key_type_allowed(struct sshkey *, const char *); + +@@ -99,7 +99,7 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh) + fatal("Server host key %s not in HostKeyAlgorithms", + sshkey_ssh_name(hostkey)); + } +- if (verify_host_key(xxx_host, xxx_hostaddr, hostkey, ++ if (verify_host_key(xxx_host, (struct sockaddr *)&xxx_hostaddr, hostkey, + xxx_conn_info) != 0) + fatal("Host key verification failed."); + return 0; +@@ -216,16 +216,16 @@ order_hostkeyalgs(char *host, struct sockaddr *hostaddr, u_short port, + } + + void +-ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port, +- const struct ssh_conn_info *cinfo) ++ssh_kex2(struct ssh *ssh, char *host, struct sockaddr_storage *hostaddr, ++ u_short port, const struct ssh_conn_info *cinfo) + { + char *myproposal[PROPOSAL_MAX]; + char *all_key, *hkalgs = NULL; + int r, use_known_hosts_order = 0; + +- xxx_host = host; +- xxx_hostaddr = hostaddr; +- xxx_conn_info = cinfo; ++ xxx_host = xstrdup(host); ++ xxx_hostaddr = *hostaddr; ++ xxx_conn_info = ssh_conn_info_dup(cinfo); + + if (options.rekey_limit || options.rekey_interval) + ssh_packet_set_rekey_limits(ssh, options.rekey_limit, +@@ -248,8 +248,10 @@ ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port, + fatal_fr(r, "kex_assemble_namelist"); + free(all_key); + +- if (use_known_hosts_order) +- hkalgs = order_hostkeyalgs(host, hostaddr, port, cinfo); ++ if (use_known_hosts_order) { ++ hkalgs = order_hostkeyalgs(host, (struct sockaddr *)hostaddr, ++ port, cinfo); ++ } + + kex_proposal_populate_entries(ssh, myproposal, + options.kex_algorithms, options.ciphers, options.macs, diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index d8d73ee5dd0..8edb1440fe0 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -29,6 +29,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-59996.patch \ file://CVE-2026-59995.patch \ file://CVE-2026-60001.patch \ + file://CVE-2026-60002.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93263 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 896DDC4453D for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5534.1784741055148715277 for ; Wed, 22 Jul 2026 10:24:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FsTeoK3g; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-493b966dd74so57331775e9.3 for ; Wed, 22 Jul 2026 10:24:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741053; x=1785345853; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hIC/W14wqmAWuxK+VKaccwKwKdXtY11Ga4U+fVtG0qY=; b=FsTeoK3gQhU/qopIwkGRouUwOwIkA0J+7O9EfmygoksNR6S2E55boWUGH7I1Jhpj6Z fBIXSm9KMTDIPGQcDT9N+tchr7fNGBp6fGKaAhKwtSAys84rjnpnbtww6RaZoG9j4zpL MFE2CI5mmSOkxjI3Y0PPREyDf8neIJ4iBzUQQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741053; x=1785345853; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hIC/W14wqmAWuxK+VKaccwKwKdXtY11Ga4U+fVtG0qY=; b=qRIHS7GwNMMbvgmECDkDFB24A9+VlZHTHJO82cojsUS9YIi+JtvQdn8vfoP1kU7teV ZxHgi34tl0/tncdkYvusbsuw47jqq5oevqK0Vg9wiCqKMqJPuQ9ViNKRfr+3NxNPKPVu ZP73WjD00ex82gjmSA6WUhXO8DBZX907m19FXaY0JWbckes826JHk0eqHz79SNy3ZRaR aRiFNF2BIfpchKHtRbMXywlroLrqZr9dlKy5FRzblgRJIw1y2pVf3GU88/p52vugb/ai TA7ZB23td22JTp2ItxmwrwmlxEZ1OqVl8Sz2nBHiNFR/BPDGSx86CkcjvT7ji1i8P7nk hLBg== X-Gm-Message-State: AOJu0Yzt/QqhDD3JZvMHPYgpL35Zey5kg0Kt+7J77iCKdaJq+AWY4Zin zj/R8XPpeqaeSb7zw2+EKRxFz9v4lw7nBiAvuu7AnGoJFbqxEYwDUSeyc0+n1n6h7GP7tuOOE2Y Nsy22En0= X-Gm-Gg: AR+sD11lrFmmouEYJzPxRE0EpimSMd3pc/1z0kZYDXFituBg1SthvJmu0YYOISsafqF afjP1rk4hbO0au2+jGwtPUhvxHhv/RQnt06JcfX3fBoyKsQgui87AkbZc3XRW1jh3Q67ZShOSoB d1pFuPSVWSX7qqPPMdqpcF3U4rQUxdpw5UyDi24NVMMl3iDNEguDdQvj/PLCuhfRVqgXOcQzLEA 0bbW1XG4jCht/G9yN+Jhlj8HZ2RdSNE4Q7vHx31aFIEI5aPJUuNJrN5W02x1EgoUAO7oF7Ip0u2 GSwLS41yQzufBgjCz/3tFZV0ih1DfCidy7wYrecC2tQzofjfPzGdcJTHq9yqQaotuC1Od82AMWI Xk/9BuGDDIbV4OFJuvsVNj2iuo5lRJKA03pqvptc5DqenLv7bggZgJdM6dBPjNFUCXCHVweLqOQ BmVXRXhyP8seRapqmPxMcn65a1bh7m0S76mDr8XOHbcY72K/I1bl1YdFHYFYZZw+ILhyUS4efWi FjodU5rYXKP X-Received: by 2002:a05:600c:19c8:b0:495:6134:6d61 with SMTP id 5b1f17b1804b1-4956202554emr144841375e9.19.1784741053281; Wed, 22 Jul 2026 10:24:13 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/27] openssh: Fix CVE-2026-60000 Date: Wed, 22 Jul 2026 19:23:39 +0200 Message-ID: <4c9bd0da0dccaa8a51090c8c172c6b0c5c6fd74c.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241736 From: Devansh Patel This patch applies the upstream OpenSSH 10.4p1 backport for CVE-2026-60000. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192 [2] https://www.cve.org/CVERecord?id=CVE-2026-60000 Signed-off-by: Devansh Patel [YC: Patch referenced in https://ubuntu.com/security/CVE-2026-60000] Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60000.patch | 140 ++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 141 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch new file mode 100644 index 00000000000..e9b62e64545 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch @@ -0,0 +1,140 @@ +From 884e94fafb20259c78bf394611b9929a7683e2b3 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:53:30 +0000 +Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication) + compliance + +problems + +1) Remove an early failure return for GSSAPI authentication attempts +made for invalid accounts that yielded different behaviour for +valid vs invalid accounts. + +2) Fix a situation where some GSSAPI requestes were not correctly +subjected to MaxAuthTries. + +3) Fix a moderate pre-authentication resource DoS related to #2. + +Add missing logging for error cases. + +Report and fixes from Manfred Kaiser, milCERT AT + +OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3 + +CVE: CVE-2026-60000 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk in auth2-gss.c and + retained the Wrynose OpenSSH 10.3p1 revision because this stable + backport carries only the functional security change. + +(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192) +Signed-off-by: Devansh Patel +--- + auth2-gss.c | 53 ++++++++++++++++++++++++----------------------------- + 1 file changed, 24 insertions(+), 29 deletions(-) + +diff --git a/auth2-gss.c b/auth2-gss.c +index f27ac9221..54c96fe4b 100644 +--- a/auth2-gss.c ++++ b/auth2-gss.c +@@ -111,12 +111,6 @@ userauth_gssapi(struct ssh *ssh, const char *method) + return (0); + } + +- if (!authctxt->valid || authctxt->user == NULL) { +- debug2_f("disabled because of invalid user"); +- free(doid); +- return (0); +- } +- + if (GSS_ERROR(mm_ssh_gssapi_server_ctx(&ctxt, &goid))) { + if (ctxt != NULL) + ssh_gssapi_delete_ctx(&ctxt); +@@ -178,8 +172,14 @@ input_gssapi_token(int type, uint32_t plen, struct ssh *ssh) + (r = sshpkt_send(ssh)) != 0) + fatal_fr(r, "send ERRTOK packet"); + } ++ logit("Failed gssapi-with-mic for %s%.100s " ++ "from %.200s port %d ssh2", ++ authctxt->valid ? "" : "invalid user ", ++ authctxt->user, ++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh)); + authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL); + userauth_finish(ssh, 0, "gssapi-with-mic", NULL); + } else { + if (send_tok.length != 0) { +@@ -191,14 +191,18 @@ input_gssapi_token(int type, uint32_t plen, struct ssh *ssh) + fatal_fr(r, "send TOKEN packet"); + } + if (maj_status == GSS_S_COMPLETE) { +- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); +- if (flags & GSS_C_INTEG_FLAG) +- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, ++ ssh_dispatch_set(ssh, ++ SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); ++ /* note: keep ERRTOK handler as per RFC 4462 s3.4 */ ++ if (flags & GSS_C_INTEG_FLAG) { ++ ssh_dispatch_set(ssh, ++ SSH2_MSG_USERAUTH_GSSAPI_MIC, + &input_gssapi_mic); +- else ++ } else { + ssh_dispatch_set(ssh, + SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, + &input_gssapi_exchange_complete); ++ } + } + } + +@@ -210,10 +214,6 @@ static int + input_gssapi_errtok(int type, uint32_t plen, struct ssh *ssh) + { + Authctxt *authctxt = ssh->authctxt; +- Gssctxt *gssctxt; +- gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER; +- gss_buffer_desc recv_tok; +- OM_uint32 maj_status; + int r; + u_char *p; + size_t len; +@@ -221,26 +221,21 @@ input_gssapi_errtok(int type, uint32_t plen, struct ssh *ssh) + if (authctxt == NULL) + fatal("No authentication or GSSAPI context"); + +- gssctxt = authctxt->methoddata; +- if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 || ++ /* Minimal error handling - just cancel auth and return FAILURE */ ++ if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 || + (r = sshpkt_get_end(ssh)) != 0) + fatal_fr(r, "parse packet"); +- recv_tok.value = p; +- recv_tok.length = len; +- +- /* Push the error token into GSSAPI to see what it says */ +- maj_status = mm_ssh_gssapi_accept_ctx(gssctxt, &recv_tok, +- &send_tok, NULL); +- +- free(recv_tok.value); + +- /* We can't return anything to the client, even if we wanted to */ ++ logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2", ++ authctxt->valid ? "" : "invalid user ", ++ authctxt->user, ++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh)); ++ authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL); +- +- /* The client will have already moved on to the next auth */ +- +- gss_release_buffer(&maj_status, &send_tok); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL); ++ userauth_finish(ssh, 0, "gssapi-with-mic", NULL); + return 0; + } + diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 8edb1440fe0..f5184b1fce3 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -30,6 +30,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-59995.patch \ file://CVE-2026-60001.patch \ file://CVE-2026-60002.patch \ + file://CVE-2026-60000.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Wed Jul 22 17:23:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93264 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A9D78C4453C for ; Wed, 22 Jul 2026 17:24:21 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5476.1784741055732349583 for ; Wed, 22 Jul 2026 10:24:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=x7roblTG; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495635a85d2so27815835e9.0 for ; Wed, 22 Jul 2026 10:24:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784741054; x=1785345854; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tSvMhQ3BQ7h2vEz6oZUTYyOYG63Bc4HFxEx06mF6kNU=; b=x7roblTGA/HG3qJldDVqxWdvUW/jfyBvhSt8fL0h/3piOT6Zm473nZfU3USwOXFgSh JHSe6feAHxfv8ab5oNrUy+2uLiKZBs2v92Yb8ZLw15mAmqzcPYIHdfR92QJkaY3hUrfc ogbG6qYbCDj2qva0n55Es8ZkqxekpVhTM32jE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784741054; x=1785345854; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=tSvMhQ3BQ7h2vEz6oZUTYyOYG63Bc4HFxEx06mF6kNU=; b=NkukXG+3eIaLCMlGE2YVpcDJG0lhzPt7ISbnMAmfB6kmcN1nsbXfxDZbZMTGF5Ezsj 7NYPNjmRJIDJ+cUfwjI/MRbfFxT4u1B0gftLsUZFrzogrSw4TSKXFhBros8bt/W8IxX8 3Vp9mukKlVOI61a1wkWhQCr0DMOMEklWbvMt/+35IhWPmsjwV/W/gjGPfQ/nyrEHQg9i A4uoy8p9gbKB84um4pVyu7uh+kgScVZnwbnupJPqQozBVRzS7gdVzBftlRwGQV4b8oVm KBvtOye3fiXikRIxjrMEMWvWNLTkogplBkxk6xNzqCKTn8EE4vOkcbT6f+uQAfdRMMLy 3Krg== X-Gm-Message-State: AOJu0YwUGxZPVHYcq3mlYCsgxnuDwQxvtZts6OoNhqExVEg1QozK68Zh 7f7ZizMiR2TGWv3N4gPZES+eWsT9vDRVyiv9sLCB+Ac4wIm+bT4qi+x2UMo0NwoseSgCLXqsWB2 2+yhs+tE= X-Gm-Gg: AR+sD11SIeYRFi+iGDu0r+26EnMk5CxyVvZCwNb7wJK9nv2ndPTXlNUt9TH8efZglO3 uLYnbkg0LYX/dsKgU5pp9W6jVJs2tv5ZP6kOmtIr2wp0a5GBRsuGIIcSxNHli+q8y/y9YvAQ6U0 3q1I93rTL2LzaslKi9pCOadiL3HyqglU+jMn0JRr7UEqcZLnOROBDdzlJv4GQNw2J32vweNBbjK S9no3R0frHn/vPBIqMO20ZuchjEjJunLMC+zN2hopj/5bPHknWdPfpxuK2RFlrtJxGdZqJnuEJZ vrqJWUpFokCT8kDlosVFUsY5XOWnru9BcYBUedKIWYQEpjFteP+YCuxSk+MC+Q56ztjw/7jkXeV fLHOU9hNPDTtSi0PRb3wUi04pku57DR+zZ2lYWqXQBymTPQqpVljf1U8w2tyq673O/7NC4+YTK0 g5xF7j3q34gvdkpa/BnCNbNDPRoxYfzfGh11BPOnUXjjF5Dt/y7NoII9wk2v6Z1I0ajuh5KL+Mr jarAHjr38qG X-Received: by 2002:a05:600c:4755:b0:493:c2cc:aecb with SMTP id 5b1f17b1804b1-4954a51590fmr296307635e9.38.1784741053913; Wed, 22 Jul 2026 10:24:13 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653c8760sm148275275e9.14.2026.07.22.10.24.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:24:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/27] gzip: Fix CVE-2026-41991 Date: Wed, 22 Jul 2026 19:23:40 +0200 Message-ID: <0dfe86a27167689ded394d72ebb5e22157fb9184.1784740870.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 17:24:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241737 From: Darsh Kelaiya This patch applies the upstream fix for CVE-2026-41991 as referenced in [2], using the upstream commit identified in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-41991 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../gzip/gzip-1.14/CVE-2026-41991.patch | 75 +++++++++++++++++++ meta/recipes-extended/gzip/gzip_1.14.bb | 1 + 2 files changed, 76 insertions(+) create mode 100644 meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch diff --git a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch b/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch new file mode 100644 index 00000000000..20c35fe352e --- /dev/null +++ b/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41991.patch @@ -0,0 +1,75 @@ +From b1545c47cddc9948cb0743b2ceb140a63c88acbc Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Thu, 16 Apr 2026 12:11:44 -0700 +Subject: [PATCH] gzexe: use -C if lacking mktemp +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +(Problem reported by Michał Majchrowicz.) +* gzexe.in: If mktemp is needed but not installed, +use ‘set -C’ to avoid a race when creating a temporary file. +* zdiff.in: Use the same pattern here, even though the old +code was probably OK anyway. + +CVE: CVE-2026-41991 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269] + +(cherry picked from commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269) +Signed-off-by: Darsh Kelaiya +--- + NEWS | 5 +++++ + gzexe.in | 1 + + zdiff.in | 7 +++---- + 3 files changed, 9 insertions(+), 4 deletions(-) + +diff --git a/NEWS b/NEWS +index 53bdf56..2d2eb81 100644 +--- a/NEWS ++++ b/NEWS +@@ -1,5 +1,10 @@ + GNU gzip NEWS -*- outline -*- + ++ On old-fashioned or limited platforms lacking mktemp, gzexe and ++ zdiff no longer have a race when creating a temporary file. ++ [bug present since the beginning] ++ ++ + * Noteworthy changes in release 1.14 (2025-04-09) [stable] + + ** Bug fixes +diff --git a/gzexe.in b/gzexe.in +index 1267d6e..09a2571 100644 +--- a/gzexe.in ++++ b/gzexe.in +@@ -127,6 +127,7 @@ for i do + tmp=`mktemp "${dir}gzexeXXXXXXXXX"` + else + tmp=${dir}gzexe$$ ++ (umask 77; set -C; > "$tmp") + fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || { + res=$? + printf >&2 '%s\n' "$0: cannot copy $file" +diff --git a/zdiff.in b/zdiff.in +index a8689a0..c04a8c0 100644 +--- a/zdiff.in ++++ b/zdiff.in +@@ -156,12 +156,11 @@ case $file2 in + *) TMPDIR=/tmp/;; + esac + if command -v mktemp >/dev/null 2>&1; then +- tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` || +- exit 2 ++ tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` + else +- set -C + tmp=${TMPDIR}zdiff$$ +- fi ++ (umask 77; set -C; > "$tmp") ++ fi && + 'gzip' -cdfq -- "$file2" > "$tmp" || exit 2 + gzip_status=$( + exec 4>&1 +-- +2.53.0 + diff --git a/meta/recipes-extended/gzip/gzip_1.14.bb b/meta/recipes-extended/gzip/gzip_1.14.bb index 99174a58c53..d6bd36f89f9 100644 --- a/meta/recipes-extended/gzip/gzip_1.14.bb +++ b/meta/recipes-extended/gzip/gzip_1.14.bb @@ -7,6 +7,7 @@ LICENSE = "GPL-3.0-or-later" SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \ file://run-ptest \ file://CVE-2026-41992.patch \ + file://CVE-2026-41991.patch \ " SRC_URI:append:class-target = " file://wrong-path-fix.patch"