From patchwork Sun Jul 26 08:29:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93513 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D1D6FC54F52 for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7134.1785054611714022738 for ; Sun, 26 Jul 2026 01:30:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=05OrAwqY; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4955de8797cso10339975e9.3 for ; Sun, 26 Jul 2026 01:30:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054610; x=1785659410; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=CDl7RmghXFPX+21Wq+ylkiU9SfrKs6osndR0u+9BAJs=; b=05OrAwqYt+Zj2yWud8c4QznKB5WH8syHe8vDyyl4CvWFDVwvkR0+upOs1ry5cCsp0R lr1sDiV81+xGGtB/WAkx/hUshgsDAidvy6OZbgUYcRZrKjOHFxHNSRZN0e0cU3ntsYxk xMAdYZjX4X+n4n7ge1RsHpDDxr2MP3dgfmNXc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054610; x=1785659410; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=CDl7RmghXFPX+21Wq+ylkiU9SfrKs6osndR0u+9BAJs=; b=Fg1bYb/Z+nwxzA5W7vjA+67RJ1I0y1YE04MRt3xuxRmViDfifsWJBb2t2aWfxo8FLf vewa0T3ivbvrkcNg/h1QrMOol0v3mjJ+j5VedAHAffKPXf3OXVaGQM9J4RudbTxagMIP FK9u5xIFlMIrgl23VQRW/ebJ9OPAAn8tZRCdIn0DZrSBXnzZGPEj/vgSqL6Xw3m0nK9j IO/JQKcjb4HN2tXFpuMeaxCtRB2uty/heEIRB1ruqriMAjxWCz4Z/lNl8h1ieDz/hZ4y bWPZyt2Gap6KzEZJFbXrfAFyztcJRzo+G+XdC/GWQK7GXhVlKG/K6cm81jwdBn1kYJk/ j0FA== X-Gm-Message-State: AOJu0YygxlCSkmu0M5mk6O/SWiPvTsGLjlKsx579lfkL+O1xkkYOo7HD CNXYTwTrqqER4PcDM1cZn9RYZKGrNmG1eQwJgjkHuE6jERL4YJwprUFTYWjdDCD297Be/TZ8XHF IRG/mCFw= X-Gm-Gg: AR+sD121TOZMgfTMn3KjP//g6Gz1QbeTrMKY3QRufLUSQ/2WYbPgTVrZQGBlYI9pBBu f0jM7Y/N+2XZAioQo0Xj/5/ep53tBD7pB+tKZcqOKqcytqaE5AuNxo+pFvLwacgtvSQURB5yHj3 OUD/O63yG2FIL58T3qLbPA4dg950YWwVBtyjWr/dkpI4g1rSfDuNNmovCzCdVLpmVHxL2BK/ok4 Hv9+8yBmIpomQK4lJ2S71ANV46cF8txenDyHdSgAZGRmVDRFZeYx3+J2cCh7bvRckUtZqMndRQo uQxaaQjxTXswvP7NazDMnU+5EFJpjWL+mbg8aJ3LL2qHtE8WTlibUK3GnxkpEo79tb5e+DsV0D8 ji+h5q7aJge470K6GQ8rBXPr21IhXB66qEJIxmK6ruEN0hfz25FvMXEDTD4IAAj9wxwjLJvNP7l uYuCzVgKnuFv6lNRTJctppUPPGm9/GFo47jjA65xhcYZutHxOYEermeUB+fxFZOTq8PFfNISF5v eu65Q== X-Received: by 2002:a05:600c:a20d:b0:493:bc4b:b8c with SMTP id 5b1f17b1804b1-496b5735154mr38473575e9.38.1785054609962; Sun, 26 Jul 2026 01:30:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Date: Sun, 26 Jul 2026 10:29:25 +0200 Message-ID: <250d7a18a7a1478f4bce0be8b07a12654059727d.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241983 From: Yoann Congal Update to the 5.0.19 release of the 5.0 series for buildtools Signed-off-by: Yoann Congal --- scripts/install-buildtools | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/install-buildtools b/scripts/install-buildtools index 24cb3099453..65200e0cf49 100755 --- a/scripts/install-buildtools +++ b/scripts/install-buildtools @@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout) DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools') DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto' -DEFAULT_RELEASE = 'yocto-5.0.18' -DEFAULT_INSTALLER_VERSION = '5.0.18' +DEFAULT_RELEASE = 'yocto-5.0.19' +DEFAULT_INSTALLER_VERSION = '5.0.19' DEFAULT_BUILDDATE = '202110XX' # Python version sanity check From patchwork Sun Jul 26 08:29:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93521 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AD11DC54F50 for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7369.1785054612772905189 for ; Sun, 26 Jul 2026 01:30:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oomO4DX1; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso11692105e9.1 for ; Sun, 26 Jul 2026 01:30:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054611; x=1785659411; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=uDMl4hdGuhtLAvXfAIP/c7ce7etG9ZguKetgQo9YirY=; b=oomO4DX1BgCUU+yapFW3Sifi4+N+R76f+EC96kvHKwoXZlU8pz3tAqFct/3j+a86bp U2XtrA0ZJMYY8YCsGUUjnZ8jT1iHksLHvI22eJWnfVI0S20k4wEWYuDwlqcP+fbElsvl fEa9Eps1eu+lZocpt9qOiCVr373uiKXFPXO7s= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054611; x=1785659411; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uDMl4hdGuhtLAvXfAIP/c7ce7etG9ZguKetgQo9YirY=; b=hmePVe6xuu1dcJn3atp0uLRwX/6ndgMitHLpeAKoBXUTSumIDpeUXHH+CwnqLwtPNE 7yUx5KjO4RpGWS65mGP08YbkoH/63Zw1in1XY/EdOxLVjtrAon1fNBo0k/yaGhGy1Cac mYcY82DqczuVUQfEVULYAYV1Dg3OsvCHOsvccgV5RG8wdSmaPgOUSUr5Dh32qikUCpYi NovjmAd3pj8fXjipMnNSVsNGJBMVfRR8gYJsZN2Un60p8IgYtsZ2DrDdhhDxBqxPyYNy tBRDUsHE9jfNRJD4yK3dsqqGIpYh45VPRgsZ3qQans0abySS5g1opFn5hEaFh/Eu/R/V kJCg== X-Gm-Message-State: AOJu0YzHNZ6iBgxOr3TzQpvqPEyNpCi4p/WkJULn5ogcC7jApRCEQBjg KPwEF6ujRK7Nb6tx+d5rYuO8y3fBXpRcAIPaAIQPCp+Phm3IOMDN+2LB9F61xjGZ1mKmaRAImwn btJHngSg= X-Gm-Gg: AR+sD12lGvHbr0rbJCADceAsTAi4OByqRWTn8cKWdkEwVJULnSQ4mi3f7IWPSp02E25 tvsFxJ0ozAA3RB2W9GO/LiPQT5fvfxR05GQzk2jQCgeEKfpZfdhlO5kK6iaOH+iecKDknDYokBE SS6EDLf+1xBRsJFxsxXqT3iPDWZ2z3KllCwtEyzrRpMh0DYBwmNmcoCBf47Otxk5yomj9rkhkfU HkdJkcXoCf1i88jY8ezHSaf/o+B2RiNwqwx8Ah4rVHLolT1k2KcLoxcaZpNEXvtxuBlwSRfuaBl 7iSawsk56KnHhLr5klTXhhYkGyjXIeYa1BJS3JtDFVzB9UYSMB7PAAnopM/ubDn8e/cNZR7LL8H UwkR4fcgmMXlJxqTUzD3xsKN6IPdpp0/vY2paH5fvrI9TE8oEiL+8zw8DdEfiNaUiHQSeYfXg0s giR4vo/zDS5yTXKbjW3IxZhcmbVwq/5Dc5U6BPiBPsbGbme3KJVqEhUAO4Z5PPm6ypMN8jgqN72 ruWGEAGkvidfzi+ X-Received: by 2002:a05:600c:1d0d:b0:493:c194:4e7a with SMTP id 5b1f17b1804b1-496b56da6d6mr52545795e9.3.1785054610466; Sun, 26 Jul 2026 01:30:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Date: Sun, 26 Jul 2026 10:29:26 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241984 From: Bruce Ashfield Updating linux-yocto/6.6 to the latest korg -stable release that comprises the following commits: d1cfde2d5d15 Linux 6.6.143 726abf975668 netfilter: require Ethernet MAC header before using eth_hdr() 05bd072e97fe x86/CPU/AMD: Rename init_amd_zn() to init_amd_zen_common() 4a83b435acf8 x86/CPU/AMD: Call the spectral chicken in the Zen2 init function 5e0c93dca433 x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function 217f53b5e3c6 Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" 189c7e57826f mptcp: fix missing wakeups in edge scenarios c12e67a0ef93 mptcp: add-addr: always drop other suboptions 1111ab94fd49 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU e5b6bdc3d8b8 arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU e717a4d08779 arm64: errata: Mitigate TLBI errata on various Arm CPUs baf63e6a6435 arm64: cputype: Add C1-Premium definitions 1e4a5225b4d3 arm64: cputype: Add C1-Ultra definitions f58e88f8653f arm64: cputype: Add NVIDIA Olympus definitions 2602d4b53925 ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 9aa7edc1347b ipvs: skip ipv6 extension headers for csum checks 2de5c8eea0a9 net: bonding: fix use-after-free in bond_xmit_broadcast() 8fe0231adebe RDMA/umem: Fix truncation for block sizes >= 4G 3faebd387ed1 RDMA: Move DMA block iterator logic into dedicated files a7c6be320c0e RDMA/umem: fix kernel-doc warnings 09dc18894148 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible 09b8a7aa5a34 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf 77b73b54801a mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison 252bb328b36f mm/memory-failure: fix missing ->mf_stats count in hugetlb poison 05f1ad6d62a3 mm/hugetlb: rename folio_putback_active_hugetlb() to folio_putback_hugetlb() 471f5d78ea4b mm/migrate: don't call folio_putback_active_hugetlb() on dst hugetlb folio 411fa5113da0 mm/hugetlb: rename isolate_hugetlb() to folio_isolate_hugetlb() eb8a8124484d netfilter: nft_fib: fix stale stack leak via the OIFNAME register 46582b0fd381 usb: typec: ucsi: Don't update power_supply on power role change if not connected c91ea13375f7 serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ d3e9b79aa794 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() b4621e5ef634 thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() 078c11224c7f usb: typec: ucsi: Check if power role change actually happened before handling e15c414092b3 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind 5542d2c35930 usb: dwc3: xilinx: fix error handling in zynqmp init error paths b987f380620b usb: musb: omap2430: Fix use-after-free in omap2430_probe() a9c22e0f93ba tty: serial: samsung: Remove redundant port lock acquisition in rx helpers 8809b7941c4a tty: serial: samsung: use u32 for register interactions 33da47d4a003 serial: samsung_tty: Use port lock wrappers 1cdb07d8946c ALSA: firewire-motu: Protect register DSP event queue positions b3f4f82d1315 memfd: deny writeable mappings when implying SEAL_WRITE 2619d9d2aac3 iio: dac: ad5686: fix ref bit initialization for single-channel parts f8dcef820161 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure e85bc501947f iio: chemical: scd30: fix division by zero in write_raw 73d8bf36f217 iio: chemical: scd30: Use guard(mutex) to allow early returns 86298fb6829c iio: gyro: adis16260: fix division by zero in write_raw b35e71b7cc7a mptcp: handle first subflow closing consistently 792fa6eee73e Bluetooth: hci_qca: Convert timeout from jiffies to ms c3fc351d256c Bluetooth: hci_qca: Migrate to serdev specific shutdown function 123724bb6ee5 serdev: Provide a bustype shutdown function ca2f48b9c03d serdev: make serdev_bus_type const c0e37017a452 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() e7af1b15c884 mm/memory: fix spurious warning when unmapping device-private/exclusive pages fe76413677e7 mptcp: do not drop partial packets 293b0e63136b mptcp: introduce the mptcp_init_skb helper 681d14ef45b1 iio: adc: npcm: fix unbalanced clk_disable_unprepare() 4ed1366f9f90 iio: adc: npcm: Convert to platform remove callback returning void d766a49d9b55 arm64: tlb: Flush walk cache when unsharing PMD tables 4c29603498b0 octeontx2-pf: avoid double free of pool->stack on AQ init failure 26342087fac9 af_unix: Fix UAF read of tail->len in unix_stream_data_wait() db9389042db4 af_unix: Cache state->msg in unix_stream_read_generic(). c2c764b00c0f rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer a05bf6d9e621 rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg 7713f4aafb57 net: hsr: defer node table free until after RCU readers 1dca7e491f07 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() dcc42d701529 ipv6/addrconf: annotate data-races around devconf fields (II) ada8dcfd5298 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient 04318e252c58 ice: fix VF queue configuration with low MTU values d37a60086ee7 selftests: mptcp: drop nanoseconds width specifier 00ffe9893f4b mptcp: reset rcv wnd on disconnect 1521fecf44fc mptcp: cleanup fallback dummy mapping generation 78f9d747f386 mptcp: use plain bool instead of custom binary enum e043017ac429 octeontx2-af: CGX: add bounds check to cgx_speed_mbps index 1132ca7a1ba8 octeontx2-af: replace deprecated strncpy with strscpy 557edaf01062 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery 969bc6370334 smb: client: require net admin for CIFS SWN netlink e19eff331240 genetlink: Use internal flags for multicast groups 14897ef9341c cgroup/cpuset: Reset DL migration state on can_attach() failure 850452af77f5 ksmbd: fix OOB write in QUERY_INFO for compound requests 6d8f52f3f80a fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros 666bd0598f37 ipmi:ssif: NULL thread on error 318a0403b270 ipmi:ssif: Remove unnecessary indention ae9d4caf6f13 mm/huge_memory: update file PMD counter before folio_put() 310a8cc74612 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() 428a33573dcb mm/hugetlb: avoid false positive lockdep assertion 000e8f55fbc7 driver core: reject devices with unregistered buses b5fa9e32fb67 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling 201151e120f0 drm/amd/display: Use krealloc_array() in dal_vector_reserve() 7fc4fab4acc3 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs 4d1c3c26c2ab drm/amd/display: Clamp VBIOS HDMI retimer register count to array size 79e0273272a0 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size 3fe2c6af3f51 drm/amdgpu: restart the CS if some parts of the VM are still invalidated 16dad1fb0d78 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 62bd09e23a23 drm/amdkfd: fix NULL dereference in get_queue_ids() d54a221b0f3c slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock 9f4a76c7e9fa slimbus: qcom-ngd-ctrl: fix OF node refcount fc261397295b thunderbolt: Limit XDomain response copy to actual frame size 0dd61ba03d05 thunderbolt: Validate XDomain request packet size before type cast 5db10c8ad8c0 thunderbolt: Clamp XDomain response data copy to allocation size 4d0b1524caad thunderbolt: Bound root directory content to block size 5f56bc6bddff thunderbolt: Reject zero-length property entries in validator 7dd9a42b044a sctp: stream: fully roll back denied add-stream state e97c2a535e23 sctp: diag: reject stale associations in dump_one path 7e60d675288d mmc: sdhci: add signal voltage switch in sdhci_resume_host b46521877611 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC 6dc14b9b431e mmc: litex_mmc: Set mandatory idle clocks before CMD0 30e727657185 mmc: core: Fix host controller programming for fixed driver type 8d6e1dd3ad13 mm/hugetlb: restore reservation on error in hugetlb folio copy paths f0ca9c7f44a9 octeontx2-af: fix memory leak in rvu_setup_hw_resources() 033d498b0f47 nvmem: layouts: onie-tlv: fix hang on unknown types e7cf30aa5f1f net: rds: clear i_sends on setup unwind 1ccad3ee7998 net: mv643xx: fix OF node refcount a629418d463f net: bonding: fix NULL pointer dereference in bond_do_ioctl() c090df5be6bc net/mlx5: Reorder completion before putting command entry in cmd_work_handler 8fb4a23df5b7 misc: fastrpc: Fix NULL pointer dereference in rpmsg callback d3e26df2e8eb misc: fastrpc: fix DMA address corruption due to find_vma misuse 8b080c891831 misc: fastrpc: fix use-after-free race in fastrpc_map_create df08fadcf0e5 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context 6560be3f6a5b ipc/shm: serialize orphan cleanup with shm_nattch updates 7a395a147f06 Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard 81d60181ed55 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) 2d175d6aae9c i2c: tegra: Fix NOIRQ suspend/resume 5bebff5e8492 i2c: stm32f7: fix timing computation ignoring i2c-analog-filter 7107627b8b35 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() dd92773d4d9c fuse: reject fuse_notify() pagecache ops on directories 254c469a404a pidfd: refuse access to tasks that have started exiting harder 0e823ca0e739 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush c1234229399f IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN 1a418ad0e5e5 bnxt_en: Fix NULL pointer dereference 6f5285a6054a ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write dfd853197615 vsock/vmci: fix sk_ack_backlog leak on failed handshake 688fcac7054a wifi: nl80211: reject oversized EMA RNR lists eb13ab2f66e2 selftests: mptcp: add test for extra_subflows underflow on userspace PM 026c4a70e2a9 mptcp: sockopt: check timestamping ret value b1fd13074f22 mptcp: allow subflow rcv wnd to shrink 907ac6b1658e mptcp: close TOCTOU race while computing rcv_wnd f2c9012fc115 mptcp: fix retransmission loop when csum is enabled c2e3aadc8fef ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow b6290cc96dc8 ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O c35c0763af34 ARM: socfpga: Fix OF node refcount leak in SMP setup 1b585673a224 udp: clear skb->dev before running a sockmap verdict 0c2821665ff7 zram: fix use-after-free in zram_bvec_write_partial() 0d64bc200ebe RDMA/srp: bound SRP_RSP sense copy by the received length 5c97ae9382de mm/damon/ops-common: call folio_test_lru() after folio_get() 5242b5f3c77f drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() 898bd0ccfed7 drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() e2331730175f ALSA: timer: Fix UAF at snd_timer_user_params() a1288cd700f7 USB: serial: kl5kusb105: fix bulk-out buffer overflow f71f8f99a9cd USB: serial: option: add usb-id for Dell Wireless DW5826e-m 4cb722747ed2 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() d92f17af7097 USB: serial: io_ti: fix heap overflow in get_manuf_info() aa82a078f70f xfrm: espintcp: do not reuse an in-progress partial send 0da2e073f9cb ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL 07c33be968d9 drm/i915/gem: Fix phys BO pread/pwrite with offset 033d39e41fc3 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying 88520b2fecc4 mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation 1e927a468500 tracing/probes: Point the error offset correctly for eprobe argument error 214a2042b16b Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig 1338ee049a89 Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend 8767fe4079af netfilter: nft_tunnel: fix use-after-free on object destroy e0ce103e89d6 drm/vc4: fix krealloc() memory leak ed3e134700a2 drm/virtio: Fix driver removal with disabled KMS c5f438dd2fd8 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time 5e1c1d22268a netfilter: ctnetlink: ensure safe access to master conntrack 5f82b02b4059 ipv6: Fix a potential NPD in cleanup_prefix_route() ccdd7f1949bb net: mvpp2: build skb from XDP-adjusted data on XDP_PASS 580f92f27cb8 net: mvpp2: refill RX buffers before XDP or skb use 26c0986cb613 net: mvpp2: Add metadata support for xdp mode 3b8b0c3631b1 net: mvpp2: limit XDP frame size to the RX buffer bede0f481b91 net: mvpp2: sync RX data at the hardware packet offset cd513e43b4b2 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag 8a81e336da68 netfilter: nf_log: validate MAC header was set before dumping it a0d16941adf3 netfilter: x_tables: avoid leaking percpu counter pointers 29d8cc44bbdf netfilter: nf_conntrack: destroy stale expectfn expectations on unregister eb7e77342e3e rds: mark snapshot pages dirty in rds_info_getsockopt() f513f308cc4b ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() 0f22412a2f4f net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion b903e9b5629e net: guard timestamp cmsgs to real error queue skbs 8ce96f118264 sctp: fix uninit-value in __sctp_rcv_asconf_lookup() 22f4ee66614e r8152: handle the return value of usb_reset_device() 25fdf5369853 net: openvswitch: fix possible kfree_skb of ERR_PTR 0bfa7bba1f41 ipv6: sit: reload inner IPv6 header after GSO offloads 41781f278930 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list 2047c2aa0963 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove 12fb84dc4dc8 net: phy: clean the sfp upstream if phy probing fails 838f411b8ef8 net/mlx4: avoid GCC 10 __bad_copy_from() false positive ecfe9171b26a tcp: restrict SO_ATTACH_FILTER to priv users 10def23b67b4 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls 7db09011ce62 gpio: mvebu: fix NULL pointer dereference in suspend/resume 07a18f5c90dd netlabel: validate unlabeled address and mask attribute lengths 42827d03f800 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() f4e4b98cee82 iomap: don't revert iov_iter on partially completed buffered writes fed65bc9de8e arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI b7d3add1884c arm64: tlb: Allow XZR argument to TLBI ops 523bc49979b9 KVM: arm64: Remove VPIPT I-cache handling d30aac0fa00c tap: free page on error paths in tap_get_user_xdp() ceafb893b12f net: skbuff: fix missing zerocopy reference in pskb_carve helpers 9eaa4e8d5561 tools/rv: Fix cleanup after failed trace setup 7fce959e9be3 usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo 36c41e9724c9 usb: gadget: f_ncm: Fix net_device lifecycle with device_move d68b621bb5a4 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams c12c4cae0cd7 time: Fix off-by-one in settimeofday() usec validation f4aae11abb44 signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() 6e39863cefe4 ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp 2afc9e684dc7 sctp: purge outqueue on stale COOKIE-ECHO handling 6d6e42e8e17f net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr 1a827b95e62b ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() 9db4dd019a6b vxlan: vnifilter: fix spurious notification on VNI update 5a7ad529fd53 vxlan: vnifilter: send notification on VNI add e4e7428349d9 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow 72775977e89c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown cecdc6574a82 ptp: vclock: Switch from RCU to SRCU 8ff85dbabbbf ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options ba760c38b38b Bluetooth: MGMT: Fix backward compatibility with userspace 0622e527a31d Bluetooth: fix memory leak in error path of hci_alloc_dev() 691f14b6a48b Bluetooth: bnep: reject short frames before parsing 10e90715e68f Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling 98377e6b1a1a Bluetooth: RFCOMM: validate skb length in MCC handlers 74c08e4db35a Bluetooth: MGMT: validate advertising TLV before type checks de31973ef00e Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() 28a6a3762796 net: fec: fix pinctrl default state restore order on resume caeb42f28f00 net: lan743x: permit VLAN-tagged packets up to configured MTU 74e02121be1d net: garp: fix unsigned integer underflow in garp_pdu_parse_attr 271355c2ef61 hsr: Remove WARN_ONCE() in hsr_addr_is_self(). 91cdbb9b308f net: Annotate sk->sk_write_space() for UDP SOCKMAP. daf5a9eef894 pcnet32: stop holding device spin lock during napi_complete_done e732c4444bcf drm/imx: Fix three kernel-doc warnings in dcss-scaler.c 06ce6fc106b1 6lowpan: fix off-by-one in multicast context address compression 8b136f18ac4b net/sched: act_api: use RCU with deferred freeing for action lifecycle b4892561552d dm cache policy smq: check allocation under invalidate lock afd64b59c3de netfilter: bridge: make ebt_snat ARP rewrite writable af80f78ce984 netfilter: nft_ct: bail out on template ct in get eval 7c34f9130529 netfilter: conntrack_irc: fix possible out-of-bounds read 0f8ba5e4c53d netfilter: synproxy: add mutex to guard hook reference counting c6376b9b1b4d ipvs: clear the svc scheduler ptr early on edit 8122abd4fd92 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id 945a86b21b40 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers 9a0dc9279d09 tee: optee: prevent use-after-free when the client exits before the supplicant 5d27d2ffe487 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS 2a613bf49702 ipv6: mcast: Fix use-after-free when processing MLD queries aa6ef7340169 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl 067579d5cf8c Disable -Wattribute-alias for clang-23 and newer b26849cffaa7 hwmon: (pmbus/core) Protect regulator operations with mutex d859e53596d1 RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug 7502c1cf303b Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync 90dbad14b109 USB: serial: mct_u232: fix memory corruption with small endpoint f8b8f1d4bb76 bpf: Free reuseport cBPF prog after RCU grace period. 37f488be2a82 usb: core: Fix SuperSpeed root hub wMaxPacketSize ff3c2b623bfa HID: core: Fix size_t specifier in hid_report_raw_event() 9e36568e67f8 HID: pass the buffer size to hid_report_raw_event 20a816422e98 HID: core: Add printk_ratelimited variants to hid_warn() etc bb2040484f90 serial: zs: Convert to use a platform device c9e78361fe92 serial: dz: Convert to use a platform device 5fc2943ad6a1 serial: dz: Fix bootconsole handover lockup bef9e8bdbc60 xhci: tegra: Fix ghost USB device on dual-role port unplug 8a65db5edd7b USB: serial: digi_acceleport: fix memory corruption with small endpoints fbf718d5afe2 landlock: Fix handling of disconnected directories 0e96cd314c0d x86/kexec: Disable KCOV instrumentation after load_segments() a55618c0f4ce Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync 4bcaa59f403d USB: serial: cypress_m8: fix memory corruption with small endpoint 36f07474f2b9 serial: zs: Switch to using channel reset 633a33fe1a34 serial: zs: Fix bootconsole handover lockup 6f22119afe53 serial: dz: Fix bootconsole message clobbering at chip reset a8bd09d3d843 drm/amdkfd: Check for pdd drm file first in CRIU restore path 4e5f808b4541 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger 6495cc09f7e6 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr c33322ef3ce5 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma ea7bdbee9fc3 serial: zs: Fix swapped RI/DSR modem line transition counting 4860f9821baf serial: sh-sci: fix memory region release in error path 70982b7ac673 serial: qcom-geni: fix UART_RX_PAR_EN bit position 3c29f8af029b serial: altera_jtaguart: handle uart_add_one_port() failures a1b9535768ed drm/amd/pm/si: Disregard vblank time when no displays are connected 28b22dbaf407 drm/i915: Fix potential UAF in TTM object purge 049a6b474823 drm/hyperv: validate VMBus packet size in receive callback 1fb565b77b8f drm/hyperv: validate resolution_count and fix WIN8 fallback edd06675a023 scsi: target: iscsi: Validate CHAP_R length before base64 decode 4e9f0c4a645c scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 163bd704d751 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 0e3c6e5a8fc1 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker 5506c825f14d thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow 8d4a758b407a thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() e835bf9a055f usb: gadget: f_fs: copy only received bytes on short ep0 read a183b47fee46 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports 046870ff6b6f usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling 5d39924ae38c usb: gadget: f_hid: fix device reference leak in hidg_alloc() 085652fda7f3 usb: gadget: net2280: Fix double free in probe error path 70bb9a2661d3 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check be3a1ed4ae51 USB: serial: mxuport: fix memory corruption with small endpoint 0bde5431037a USB: serial: keyspan: fix missing indat transfer sanity check be50533fe706 USB: serial: cypress_m8: validate interrupt packet headers ffb739a49186 USB: serial: belkin_sa: validate interrupt status length 37a2ac9f5125 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL 5a0e65d56ffd USB: serial: option: add MeiG SRM813Q 17587492179c usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize 5de7df75ef3a usb: usbtmc: check URB actual_length for interrupt-IN notifications a0638db2340e usbip: vudc: Fix use after free bug in vudc_remove due to race condition 02c76e026c06 usb: storage: Add quirks for PNY Elite Portable SSD aec4d38ac605 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers e21f5abf80ad usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval 028cc2555eca usb: chipidea: core: convert ci_role_switch to local variable 6dd5c0ea139b tty: serial: pch_uart: add check for dma_alloc_coherent() 68f603bb8622 counter: Fix refcount leak in counter_alloc() error path 9fa854ea4318 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() 422af0f9ce0c comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() 2ad3397f3cc5 Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 e9b62996ba53 Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem 0fe08c5776a7 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops ba451cf21f1d Input: xpad - add support for ASUS ROG RAIKIRI II 6e6de3eba8e4 Input: xpad - add "Nova 2 Lite" from GameSir 322e48187e02 xfrm: esp: restore combined single-frag length gate d780c61bd2ef ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks ed4e2ff1ddd1 ASoC: qcom: q6asm-dai: close stream only when running 2bb6d82b586e netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check 32aa292fbcb9 xfrm: ah: use skb_to_full_sk in async output callbacks 00f2c451e57d xfrm: route MIGRATE notifications to caller's netns c4cc6b3b0013 nfc: hci: fix out-of-bounds read in HCP header parsing 1552b979a0b6 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings ed598de9f615 HID: wacom: Fix OOB write in wacom_hid_set_device_mode() f1e89a943ee5 ip6: vti: Use ip6_tnl.net in vti6_changelink(). 48ce101cd630 xfrm: input: hold netns during deferred transport reinjection a29768d56eb3 ipv6: validate extension header length before copying to cmsg 1acfb7d9c6fc ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). 12d957979e4a ipv6: exthdrs: refresh nh after handling HAO option f21a9285147a ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params bddaa4dfc7f3 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 679e13a65e68 macsec: fix replay protection at XPN lower-PN wrap 96b72672ce84 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data 48b0aa9c08a3 Input: elan_i2c - validate firmware size before use 0584af4fe40f usb: dwc2: Fix use after free in debug code c28bfafa9d70 usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles 96291794d162 usb: cdns3: gadget: fix request skipping after clearing halt 9a3860454bdf USB: serial: omninet: fix memory corruption with small endpoint 29783e6b6ec0 iio: buffer: hw-consumer: fix use-after-free in error path d291f76e4231 iio: light: cm3323: fix reg_conf not being initialized correctly d534936cf3ac iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL c43741113cd6 iio: temperature: tsys01: fix broken PROM checksum validation b5d9befff543 iio: ssp_sensors: cancel delayed work_refresh on remove 31bbd4b87dd6 iio: gyro: itg3200: fix i2c read into the wrong stack location d434a6abd101 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw 1c375f2c4a7a iio: dac: ad5686: acquire lock when doing powerdown control 99d8feee7560 iio: dac: ad5686: fix input raw value check 9a8fca2af3aa iio: dac: max5821: fix return value check in powerdown sync baff1f00d8b5 iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux 7b9dcbe89d7a wireguard: send: append trailer after expanding head a452ca80b7ad KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC c881af73ae98 KVM: arm64: PMU: Preserve AArch32 counter low bits ecc9635e7501 USB: cdc-acm: Fix bit overlap and move quirk definitions to header 15b1723c1472 parport: Fix race between port and client registration bcfb4833cd40 Input: xpad - fix out-of-bounds access for Share button 35f68f36d988 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock 119fb6f80c44 Bluetooth: ISO: fix UAF in iso_recv_frame d313683d6ccd Bluetooth: HIDP: fix missing length checks in hidp_input_report() 63cd225cc13d Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn 89dec9204171 Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() 8776032fe989 auxdisplay: line-display: fix OOB read on zero-length message_store() 157ce2c6836c ipc: limit next_id allocation to the valid ID range 7c58c55a2a16 hpfs: fix a crash if hpfs_map_dnode_bitmap fails dcd2b02b095f Bluetooth: btusb: Allow firmware re-download when version matches 4c52e31e9ea6 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse 0cd7b3a15a49 Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() 060fca8e0983 media: rc: igorplugusb: fix control request setup packet 9b3145b3001f USB: serial: safe_serial: fix memory corruption with small endpoint 156b6f0aec61 usb: typec: ucsi: validate connector number in ucsi_connector_change() 0af00f1459f5 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT 5cd0e7ac4eef usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() 70e7045849e9 usb: typec: altmodes/displayport: validate count before reading Status Update VDO 592cbdc644c6 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO 3f432b820306 usb: typec: ucsi: ccg: reject firmware images without a ':' record header d42ac0bfb6a1 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer d1c9c79eb06e soc/tegra: pmc: Fix unsafe generic_handle_irq() call 0bb1522d3081 hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock 96852c116071 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock 7e2476057950 x86/kexec: add a sanity check on previous kernel's ima kexec buffer 566db3370f12 of/kexec: refactor ima_get_kexec_buffer() to use ima_validate_range() 43308106a176 ima: verify the previous kernel's IMA buffer lies in addressable RAM e1d839efc1e4 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X 64858b76ec67 arm64: io: Extract user memory type in ioremap_prot() 4356c4d85050 arm64: io: Rename ioremap_prot() to __ioremap_prot() 05ff52238039 drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used 45e27857b24e drm/dp: Add eDP 1.5 bit definition ac7045d3f6d3 drm/i915/psr: Read Intel DPCD workaround register 28557e9deb23 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register 22ee4010866d inet: frags: flush pending skbs in fqdir_pre_exit() e0fc5427d6a8 inet: frags: add inet_frag_queue_flush() 711ebd961190 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup f707f53f9ff5 drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info 228cc232079d media: rc: ttusbir: fix inverted error logic a7becb58f6b8 media: rc: fix race between unregister and urb/irq callbacks 3edb8ebbf79b mm/page_alloc: clear page->private in free_pages_prepare() a9393751ecf7 batman-adv: bla: avoid double decrement of bla.num_requests 99f17d1cdb37 batman-adv: tt: avoid empty VLAN responses 65a1e67339aa batman-adv: tt: fix TOCTOU race for reported vlans 5bc2d50fb66b batman-adv: tp_meter: directly shut down timer on cleanup 3c19cb8a84ef net: af_key: zero aligned sockaddr tail in PF_KEY exports 100953b5011d batman-adv: tp_meter: avoid role confusion in tp_list cf12f8881832 batman-adv: iv: recover OGM scheduling after forward packet error 13493b00dd1e batman-adv: tvlv: reject oversized TVLV packets 2a8c9e865291 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface a5904f2c92b0 batman-adv: tt: reject oversized local TVLV buffers fcedc98bd03c batman-adv: tvlv: abort OGM send on tvlv append failure 31dcb9711abd batman-adv: v: stop OGMv2 on disabled interface ae1ada0af162 perf: Fix dangling cgroup pointer in cpuctx 1488367423a6 net: skbuff: fix pskb_carve leaking zcopy pages c87cd3cb3096 ipv6: fix possible infinite loop in fib6_select_path() 279853aec9f5 ipv6: fix possible infinite loop in rt6_fill_node() 634a9af8a26a sctp: fix race between sctp_wait_for_connect and peeloff 95e414f83243 net: mana: Add NULL guards in teardown path to prevent panic on attach failure 88403b42faa8 gpio: rockchip: convert bank->clk to devm_clk_get_enabled() 6319b38fe69f Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp cc2b4f749de0 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success 97e06791368c ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() 65674d2489a1 ethtool: eeprom: add more safeties to EEPROM Netlink fallback 091b58d9a65b ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback f4d78a81f57d bonding: refuse to enslave CAN devices b06203ac5f12 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() 5fe860af8630 ASoC: codecs: simple-mux: Fix enum control bounds check 3127a884525d ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE e917d0c69f01 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() dc3bfa050f87 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 76cd9398a047 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 5165922a8b5c gpio: mxc: fix irq_high handling a4b64f3e9c7b net: hsr: fix potential OOB access in supervision frame handling e9e1dbdee16e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors 8e59d4d0dcde ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() 15fb19af49f2 scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues cd691beafea0 net/iucv: fix locking in .getsockopt ed7a75831301 net/smc: Do not re-initialize smc hashtables e523bb6d1de3 net: netlink: don't set nsid on local notifications 490a6ef32ab2 net: netlink: fix sending unassigned nsid after assigned one 20f977a75333 vsock: keep poll shutdown state consistent 60d9c0d6cdde tun: free page on build_skb failure in tun_xdp_one() 5b34f9e4fe2f tun: free page on short-frame rejection in tun_xdp_one() b80ef316e978 netfilter: nf_tables: fix dst corruption in same register operation ce0712149e21 netfilter: bitwise: add support for doing AND, OR and XOR directly 45cb4821021e netfilter: bitwise: rename some boolean operation functions a27cb7325a6c netfilter: ebtables: fix OOB read in compat_mtw_from_user 21994d11461b netfilter: xt_cpu: prefer raw_smp_processor_id af2c22ccb1f6 netfilter: synproxy: refresh tcphdr after skb_ensure_writable d0cbeaa85b58 nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems fccd685b32df xfrm: Check for underflow in xfrm_state_mtu ee2d1a8a1833 nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() e00f50f86977 nfc: llcp: Fix use-after-free in llcp_sock_release() 67cca9df4d17 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet 4f33d74ccf69 bcache: fix uninitialized closure object b4a659bae3b8 drm: Remove plane hsub/vsub alignment requirement for core helpers 6c153d97c100 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked 963537a26fd8 net: mctp: ensure our nlmsg responses are initialised 5df49f0579f7 net/sched: cls_fw: fix NULL dereference of "old" filters before change() d883312061cc Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size Signed-off-by: Bruce Ashfield Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.6.bb | 6 ++-- .../linux/linux-yocto-tiny_6.6.bb | 6 ++-- meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++---------- 3 files changed, 20 insertions(+), 20 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb index c3200cfd3fe..e5a3882efea 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb @@ -14,13 +14,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "1ceada58731a98237f70384921758a4df3951960" -SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98" +SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24" +SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.6.142" +LINUX_VERSION ?= "6.6.143" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb index 563598a2bde..ed4b0c67ae7 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.6.inc -LINUX_VERSION ?= "6.6.142" +LINUX_VERSION ?= "6.6.143" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "66e051144e21d531fa26ef67476dfdefbfc119a2" -SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98" +SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d" +SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb index 07a06f18529..c682d6ff17a 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base" KBRANCH:qemuloongarch64 ?= "v6.6/standard/base" KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "d81ffd8843535762fecf5aa5fb2ca7d2c4343038" -SRCREV_machine:qemuarm64 ?= "1f7f3a52dacadfcc75863f25252a534b06fdaeeb" -SRCREV_machine:qemuloongarch64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_machine:qemumips ?= "4410226fddf113b89cceb26e7ee5ca5bb70c55fb" -SRCREV_machine:qemuppc ?= "8f8faf1fe9183f295901f8f2b8916ff54f4a4bfb" -SRCREV_machine:qemuriscv64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_machine:qemuriscv32 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_machine:qemux86 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_machine:qemux86-64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_machine:qemumips64 ?= "14ca63e9f1ce2090e189c16b1024ed3df8f833f0" -SRCREV_machine ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9" -SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98" +SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c" +SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b" +SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4" +SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806" +SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee" +SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" +SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "924b4a879cbb75aef37c160b955b92f6894b11a4" +SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.6/base" @@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.6.142" +LINUX_VERSION ?= "6.6.143" PV = "${LINUX_VERSION}+git" From patchwork Sun Jul 26 08:29:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93515 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 909EAC54F4E for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7140.1785054613513637922 for ; Sun, 26 Jul 2026 01:30:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PczPwVwy; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-47f93b2fe4cso1280055f8f.0 for ; Sun, 26 Jul 2026 01:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054611; x=1785659411; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=uTpxFsdhpBqL01Fv30SdUQulFkZV/BNavPp/nzL4XL0=; b=PczPwVwyJ9jyzHowN3Ihz60ZHGNG75Bv5O8K6yOMmbYpYbufRWUrjDxvXlKFxM5LAI slQ0SnqFKm1a3yFcLQh6VDjIeCvZ+Zz2R7hvEX9Y0LRdMAckwSbgss5Oa771KS6EURI8 fNJllWnidB3YTRWZjf8oaApYtFDNGDpjXEGac= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054611; x=1785659411; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uTpxFsdhpBqL01Fv30SdUQulFkZV/BNavPp/nzL4XL0=; b=NMN46lYFJXekduCuJ6XHry2QQzP24TM4bF/4Bk/mTWCrmyVMwxSJ2MZC/oamoEEdQE NMXshAiXoYAPT4VEGVDTZ1Ct7UVoqjxoNK6DVbCJDKJx23VFYD9j+Y57wBlCE3rrTdUu 3dS5KEvCMreiwf+KrrLCnlEUCGBd+wg/h7lrLRT4G4JEzG31mgD748iuiquJMlVpJ/cw 8G7uUan6c9SKWocO3U2RUrDbFE54GU0Q4r20Xbfl1sl3JP0alpEKmP6mtFza7iVQk/IJ qm+YZrUSoerufS8091aN2UK1MjgSNcxYT2gmthCK447+1HaxoVVNHKCsofI5DVRtPLE7 0kvQ== X-Gm-Message-State: AOJu0Yy9xGit9c1WNz9yrGvmy1gRos10LM5Dl/h/+u1j7WiR9Pbr8cZG DNRn6NVsomcL4BaaGhq+3x45eKjbIRAmGLcHBQIglEa/mPNF299ghBt2BsZ/1hrFxss+RQbZkPO qUpzWReo= X-Gm-Gg: AR+sD13X02mMI0WVfGCAR4i2bJ5S/RlcDfVqWonuLtH5wDY+iYv8yeMH2/cmcK5qdDz ZZFTN0ZZWxIM9De7oXgDDRStRfn6kVoXGPSnfg1yhRX0dE/Ampfa8/bAq3PYR1dB3yWJbZhmTi4 zLfxaU54HXXH2j6MSV5d1EiJ3//JiDC+1m32KtYgweUv/pHzuaN0l1PLFjMx8uRHlMYZUGPURQF qvhoB2IFFTKbbdzKYUkTqveZRpkkZsjYhOwx5JQsArVQ277WxDGDd1FQegl7AsaAN0qJVXuH7ul yPHDCNdnUF8KHHnt8GzMsZLLnP6ljcqHz85S3l8j5yL3lAMqRqdYBMgQdu4YhthroFKbsb3TxSs ZxgFlJo2PJh2gc42ZlOMiMu6Ks0Eg3qay3Ul7AQw19bmmQI87KjhplL8fPn7OxuEmCcg1mJtcRw sMNKMjvPT9gTAGBHQAW00Qt4IwA3wFvtEHo+CJE3+51m1QyfKwr7zVmfUc2qrjJJlAxmZJyAZQJ jUrYgf7lSF15vYG X-Received: by 2002:a05:600c:a49:b0:495:4e12:6ae5 with SMTP id 5b1f17b1804b1-496b5754379mr58784665e9.26.1785054611066; Sun, 26 Jul 2026 01:30:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Date: Sun, 26 Jul 2026 10:29:27 +0200 Message-ID: <6eeed0e2fee69c3c13f3b20f419d0ca25c9d8def.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241985 From: Bruce Ashfield Updating linux-yocto/6.6 to the latest korg -stable release that comprises the following commits: da47cbc254661 Linux 6.6.144 6848a6e39cac4 crypto: qat - remove unused character device and IOCTLs 1a42f84b0f6b5 crypto: qat - Return pointer directly in adf_ctl_alloc_resources 30d648e225447 crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() c0b8e6eea1b2b Documentation: ioctl-number: Extend "Include File" column width 802e113cf120d drivers/base/memory: set mem->altmap after successful device registration 511d2b92f8d20 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails 851e1847f881e serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero 36599894fa853 ksmbd: fix out-of-bounds read in smb_check_perm_dacl() 2ef8f2a5695ae NFS: Prevent resource leak in nfs_alloc_server() 6c344fff2feff NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr abc978daffd26 nfsd: check get_user() return when reading princhashlen 1e96239fddcef nfsd: fix posix_acl leak on SETACL decode failure 1e04be34cafae NFSD: Fix SECINFO_NO_NAME decode error cleanup 1a7ee9f9f3957 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode c7dc382439f7b fbdev: modedb: fix a possible UAF in fb_find_mode() 7640b4f68acb5 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var c04d606f8b35e power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() 889c2a9c59897 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path d18756b12aab3 KVM: x86: hyper-v: Bound the bank index when querying sparse banks b84f46179c806 9p: avoid putting oldfid in p9_client_walk() error path c5a125eadba05 ocfs2: reject oversized group bitmap descriptors ddf13f91ca82c rpmsg: char: Fix use-after-free on probe error path fbaf509ad7cb2 fpga: region: fix use-after-free in child_regions_with_firmware() 44567537a2623 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove 7e37e9b3e82ad pNFS: Fix use-after-free in pnfs_update_layout() eaca7dae02fab tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done 96e545410c4f7 blk-cgroup: fix UAF in __blkcg_rstat_flush() 508a0139d3bf6 hdlc_ppp: sync per-proto timers before freeing hdlc state 4fe388218826d gfs2: fix use-after-free in gfs2_qd_dealloc 8e0abc17fbd7e exfat: fix potential use-after-free in exfat_find_dir_entry() ab465495b1ed5 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS 81fc9a13acae9 bpf: use kvfree() for replaced sysctl write buffer fda128096fc84 f2fs: keep atomic write retry from zeroing original data 7e4d8f98be63f f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() 1ddf3fd21c4c6 f2fs: validate ACL entry sizes in f2fs_acl_from_disk() 24f8c87070c3e f2fs: fix to round down start offset of fallocate for pin file 13e4b59d3a941 f2fs: validate compress cache inode only when enabled bd499f138ccf7 wifi: iwlwifi: mvm: fix race condition in PTP removal 2b2060c2075a7 wifi: rtw88: usb: fix memory leaks on USB write failures 6579dcb5e0f74 wifi: rtw88: increase TX report timeout to fix race condition 16eef2a52687b wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor 318703b6f71d1 wifi: ath11k: fix warning when unbinding a2e631fa91bb2 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S 35ab4db86774d keys: Pin request_key_auth payload in instantiate paths 5966e4e2ba213 KEYS: fix overflow in keyctl_pkey_params_get_2() 03ef56495f0be err.h: use __always_inline on all error pointer helpers 5267eab88fa4c fbdev: fix use-after-free in store_modes() 06f6dd2ff2bd0 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR 15fd83a1e42ed apparmor: fix use-after-free in rawdata dedup loop faea60deaa05c apparmor: mediate the implicit connect of TCP fast open sendmsg 0eb4c16c4adb2 net: skmsg: preserve sg.copy across SG transforms e28e7fd34c449 mac802154: llsec: add skb_cow_data() before in-place crypto 82c17e13d404f af_unix: Set gc_in_progress to true in unix_gc(). 5f0b95ef68ab9 nvmet-tcp: fix race between ICReq handling and queue teardown e8852ae29868e ntfs3: reject direct userspace writes to reserved $LX* xattrs ce494707a9c07 ipv4: account for fraggap on the paged allocation path f79f0db614160 inet: add indirect call wrapper for getfrag() calls 65fb14cbebb0c ipv6: account for fraggap on the paged allocation path 2660bd8333ab6 batman-adv: tvlv: avoid race of cifsnotfound handler state 9c9f4e69368a4 batman-adv: tvlv: enforce 2-byte alignment d7fdbab25eae6 batman-adv: dat: prevent false sharing between VLANs a8da361cdd929 batman-adv: tt: track roam count per VID e82a02a0c1aa2 batman-adv: tt: don't merge change entries with different VIDs 0e868200cf042 batman-adv: tp_meter: handle overlapping packets 31dec4dc86cf6 batman-adv: tp_meter: prevent parallel modifications of last_recv be3af0c705a13 batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE f8c499fd275e5 batman-adv: tp_meter: restrict number of unacked list entries 97644fdaaf644 batman-adv: v: prevent OGM aggregation on disabled hardif 3af7f10d5fe44 batman-adv: frag: avoid underflow of TTL cb96aa1737200 batman-adv: frag: ensure fragment is writable before modifying TTL 5263ff0bbd132 batman-adv: fix (m|b)cast csum after decrementing TTL 4741001ca0b04 batman-adv: ensure bcast is writable before modifying TTL 29f59324e61fc batman-adv: tp_meter: initialize last_recv_time during init b88f8f4e5e78e batman-adv: prevent ELP transmission interval underflow b5cf66cdc49b1 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE 75445cf501ac7 batman-adv: tp_meter: add only finished tp_vars to lists 4774a32baec46 batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection ec8ef37fea33c batman-adv: tp_meter: fix fast recovery precondition cd74176cf1685 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd f58e5df92180e batman-adv: tp_meter: avoid window underflow 774d22045a8fa batman-adv: tp_meter: initialize dec_cwnd explicitly 0c610db91bbde batman-adv: tp_meter: initialize dup_acks explicitly edae04afb11f6 batman-adv: tp_meter: keep unacked list in ascending ordered bc6c380c1159d selinux: fix overlayfs mmap() and mprotect() access checks 41c5b269af8b1 lsm: add backing_file LSM hooks ba3ebdd89fa20 fs: prepare for adding LSM blob to backing_file 922a03b26e354 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events 36c85f7029484 Bluetooth: btmtk: validate WMT event SKB length before struct access 7536ebe0473d9 Revert "ptp: add testptp mask test" 48b91ed7e22bb KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level 9291654d69e08 KVM: x86: Fix shadow paging use-after-free due to unexpected role 2de4db145b299 eventpoll: fix ep_remove struct eventpoll / struct file UAF a0e685da1efe0 eventpoll: move epi_fget() up 20423e2c1c84a eventpoll: rename ep_remove_safe() back to ep_remove() 0a4a2db528b0e eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() f484ab90b2290 eventpoll: kill __ep_remove() 903070f8f3552 eventpoll: split __ep_remove() ff4fe83a9aabb eventpoll: use hlist_is_singular_node() in __ep_remove() 44e8907b81fea file: add fput() cleanup helper 2181a09ba980f virtiofs: fix UAF on submount umount cd923dadefadb media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si d2bbbb6c55812 ksmbd: reject non-VALID session in compound request branch 8232fca738011 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write 08fbcba06e968 scripts/sorttable: Fix endianness handling in build-time mcount sort 80514e97c50ab scripts/sorttable: Allow matches to functions before function entry 9ba53f9808e1e scripts/sorttable: Use normal sort if theres no relocs in the mcount section e115e9fa69b48 ftrace: Check against is_kernel_text() instead of kaslr_offset() 379e755ec2c54 ftrace: Test mcount_loc addr before calling ftrace_call_addr() bf802b936a7b2 ftrace: Do not over-allocate ftrace memory 4c30b173b6176 ftrace: Have ftrace pages output reflect freed pages dc06779d338de ftrace: Update the mcount_loc check of skipped entries 4893af6318fe8 scripts/sorttable: Zero out weak functions in mcount_loc table bbfbacec9e000 scripts/sorttable: Always use an array for the mcount_loc sorting 38be2ffe9808b scripts/sorttable: Have mcount rela sort use direct values fe0434d604a94 arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 8297f13962063 scripts/sorttable: Use a structure of function pointers for elf helpers ff7e015d63849 scripts/sorttable: Get start/stop_mcount_loc from ELF file directly ecbb09356560c scripts/sorttable: Move code from sorttable.h into sorttable.c 7fbddce9a2685 scripts/sorttable: Use uint64_t for mcount sorting 23b5a9659a27d scripts/sorttable: Add helper functions for Elf_Sym 8cd6caaa4a244 scripts/sorttable: Add helper functions for Elf_Shdr a03240485cf57 scripts/sorttable: Add helper functions for Elf_Ehdr 1dd7def1ae877 scripts/sorttable: Convert Elf_Sym MACRO over to a union 1afca399cc4d5 scripts/sorttable: Replace Elf_Shdr Macro with a union 7ce5ed40d976e scripts/sorttable: Convert Elf_Ehdr to union e6bb2482b5b17 scripts/sorttable: Make compare_extable() into two functions d5e14532a8b86 scripts/sorttable: Have the ORC code use the _r() functions to read 4f2fba2de0620 scripts/sorttable: Remove unneeded Elf_Rel c13a4c1fd1b74 scripts/sorttable: Remove unused write functions d9e259e63b36b scripts/sorttable: Remove unused macro defines 030fe3e9d8abd fuse: re-lock request before replacing page cache folio fe95e90559bce slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD e65ae7c948640 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration 5d1ae4e17a3ec rxrpc: Fix the ACK parser to extract the SACK table for parsing 09c9b92c20104 net: phonet: free phonet_device after RCU grace period 210ac54bdd8df phonet: Pass net and ifindex to phonet_address_notify(). cf30797ea8cea phonet: Pass ifindex to fill_addr(). 6707d7e0b7174 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued 67fde21e4522e Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs 5df8310a41391 hv: utils: handle and propagate errors in kvp_register 23e5a1b9ae954 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation 4830fb44d12f5 netfilter: nf_tables: always walk all pending catchall elements 7109d69bec6ed dlm: prevent NPD when writing a positive value to event_done c84860dac7af7 regulator: core: fix locking in regulator_resolve_supply() error path c2716362ec335 ring-buffer: Remove ring_buffer_read_prepare_sync() f155b8f1c9576 selftests/bpf: Update comments find_equal_scalars->sync_linked_regs 8e655dbef4c9e selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking 78da8e1be90c5 bpf: Remove mark_precise_scalar_ids() 0252b9d262222 bpf: Track equal scalars history on per-instruction level b741c9c6ef59f af_unix: Reject SIOCATMARK on non-stream sockets f68f34033d403 selftests/bpf: Add test to ensure kprobe_multi is not sleepable 89327ed787746 bpf: Reject sleepable kprobe_multi programs at attach time eb045714bc6a2 agp/amd64: Fix broken error propagation in agp_amd64_probe() 1078ae8175777 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() 1c4ffe6b4f043 i2c: stub: Reject I2C block transfers with invalid length c19b360fa10c5 RDMA/bnxt_re: zero shared page before exposing to userspace 218c24bfc3334 KVM: VMX: Update SVI during runtime APICv activation de1ba6c93868f ARM: fix branch predictor hardening 1f7cc85046f1c ARM: fix hash_name() fault 98b209cd62ef9 ARM: allow __do_kernel_fault() to report execution of memory faults 89b37df6f805f ARM: group is_permission_fault() with is_translation_fault() 5d95f6b267f3d debugobjects: Dont call fill_pool() in early boot hardirq context a3383df76f0d7 debugobjects: Do not fill_pool() if pi_blocked_on c8cd2ca8f085c debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP 0d2a64411b097 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING 40fe77146137b batman-adv: tt: prevent TVLV entry number overflow abb069fdf51a9 drm/v3d: Skip CSD when it has zeroed workgroups 756724002c5a6 drm/v3d: Store the active job inside the queue's state f4b6b4af7ef06 ip6_vti: set netns_immutable on the fallback device. 499c6b43a79dd drm/amd/display: Bound VBIOS record-chain walk loops b685d6ef6f07a net/sched: fix pedit partial COW leading to page cache corruption 8bef2f840b43e fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios Signed-off-by: Bruce Ashfield Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.6.bb | 6 ++-- .../linux/linux-yocto-tiny_6.6.bb | 6 ++-- meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++---------- 3 files changed, 20 insertions(+), 20 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb index e5a3882efea..cb8d8c418f1 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb @@ -14,13 +14,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24" -SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" +SRCREV_machine ?= "d7fbdb4e5e7a35bdb8bb87d159204d74ef130a32" +SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.6.143" +LINUX_VERSION ?= "6.6.144" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb index ed4b0c67ae7..73d971f7eee 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.6.inc -LINUX_VERSION ?= "6.6.143" +LINUX_VERSION ?= "6.6.144" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d" -SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" +SRCREV_machine ?= "25b07b85b558f3587c11c9363cccd9cb93fcef45" +SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb index c682d6ff17a..64609554ee2 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base" KBRANCH:qemuloongarch64 ?= "v6.6/standard/base" KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c" -SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b" -SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4" -SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806" -SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee" -SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1" -SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f" +SRCREV_machine:qemuarm ?= "3adc19c1e1e3ee865f9b0d7bc0fedd0e4aeee995" +SRCREV_machine:qemuarm64 ?= "39a4fe09d3d795042cc14eb3c78f6a03874c48df" +SRCREV_machine:qemuloongarch64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_machine:qemumips ?= "ba0b8f925ec8b5926c6c2ddbc2c2c77305324bab" +SRCREV_machine:qemuppc ?= "66c01b44545110249c940f865c4ed10d4d315b29" +SRCREV_machine:qemuriscv64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_machine:qemuriscv32 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_machine:qemux86 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_machine:qemux86-64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_machine:qemumips64 ?= "1793417d6568e244579278e6f1fc7107987946f5" +SRCREV_machine ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec" +SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90" +SRCREV_machine:class-devupstream ?= "da47cbc254661aa66d61ef061485a7080305c4be" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.6/base" @@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.6.143" +LINUX_VERSION ?= "6.6.144" PV = "${LINUX_VERSION}+git" From patchwork Sun Jul 26 08:29:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93522 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 645B7C54F4D for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7375.1785054613943754572 for ; Sun, 26 Jul 2026 01:30:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bfnZlbHl; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-4954d383e64so11184435e9.1 for ; Sun, 26 Jul 2026 01:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054612; x=1785659412; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eEQnw+yZG4u6FjxMXAZ3NwGd//BVqR4DTYUckOUkmuE=; b=bfnZlbHlJ9CHoNFJn3+4ND3zOYLFfLzmQNSIN5RM0vL+Un7PibSapE4NYaVMZbVY/E QmPDbZOTRxmz8h1zMI3Uv2Z4pEFcGwQmb/r2WwzyjPyNFFtzVsf08ruWccgG+D2W8rK0 XZjJ4erdkIGELdKC/pjRziapPrj9RsjMdZeKw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054612; x=1785659412; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=eEQnw+yZG4u6FjxMXAZ3NwGd//BVqR4DTYUckOUkmuE=; b=oheHmSGXm3e0XDirYLhgi6s74QA/Zocp53LxmiCURPRVY4k4kl3g/tfRaaY+EvhfjV ctbyJh57PU9hmAfo+OwZbiQfZtcyZCu4y7dedIJCKppKoEYYPg9NwWDxzL9bSCGDZd8l pGNtMAlhgWrcXFg0xtuSdQmKxCRnmOYoevOmTEwMC15/M48FnsGQBp2h9scIJvRMhfoK szmRHJAaS8t7D4yl4fARtsq8C6ATsAGVSh4Gdmkhw+1Fby2RHhdse8VDlGJTqURNbiJe PLsjpX3LZXFxUnlRA2Ahkpu8Ismn7qEHAtBTYJA9bIBRbRc8/5oZHvif5w9KDHjJvViM fRtw== X-Gm-Message-State: AOJu0YzuyYULgSM5bMuOpYbWqr0wwUMjrgLbL4GTGXhiT3oiGl+g2A5J X2bri4QidJ8WQzrOQpNsauf2RNZT320pb90kgvCBQK0r2HNCL3nn8r/MyuP33CPDwC8u+LEBZd2 QtB85H58= X-Gm-Gg: AR+sD13bTJIcpRcyVmUdTYEGy2ee+8JEoLo2kmzxRv/RA4pAp15R3ox/O2JBwkJ9sKH AALzCuL/jTYigUTyR9elUpTxG9CPK19Fems5npc5PUOwpoB7ZP4YqB2Xsvc6im7axPPb4UNNukq c5X7JDFHn/fBNXkz3qRRpHlW4GVrqMDNwx7VQ0ojv+4Tp6IJE+QNkBGYKSBImFiTN1MVAQP6+fv /mNcBS2K1bbgMaGCPANARqQ3WFuiSszfT/R3W47l5tgCEe3bhkBfwwp9eyQw7jxj9ZXcaKXODHM Jw12Q83NhkLGs/4luogQvkTCwYlA+rK2pCrHDG46WFpVOg03/dYnCAFv1jhQ1jF4dNnhPYgbA3O CcuBs6ZG5RuLNkTptGeoVuT+50yq6mel7sezzOsSq1BR0ikf+fviNeIZlEmxvjQu/ItOWt6POG0 ltKavA3ZHOD28X7f/UhoVQaMXk28ORMyN9ZO7zSghTjMbjJtqLsx7RMamv6IK1REIFflxEQlPwA omUEw== X-Received: by 2002:a05:600c:1553:b0:492:6f6f:fa42 with SMTP id 5b1f17b1804b1-496b5711f19mr57421015e9.37.1785054611642; Sun, 26 Jul 2026 01:30:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Date: Sun, 26 Jul 2026 10:29:28 +0200 Message-ID: <9b5c90be9cd6dfa5ed42f2e05935068ba31bac1b.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241987 From: Yoann Congal $ ./meta/recipes-kernel/linux/generate-cve-exclusions.py .../cvelistV5/ 6.6.144 > meta/recipes-kernel/linux/cve-exclusion_6.6.inc Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144 From cvelistV5 cve_2026-07-23_0700Z Signed-off-by: Yoann Congal --- .../linux/cve-exclusion_6.6.inc | 1216 ++++++++++++++--- 1 file changed, 1052 insertions(+), 164 deletions(-) diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc index 2a194e7c84d..fd17e611a4b 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc @@ -1,11 +1,11 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2026-07-07 17:39:10.952928+00:00 for kernel version 6.6.142 -# From cvelistV5 cve_2026-07-07_1600Z +# Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144 +# From cvelistV5 cve_2026-07-23_0700Z python check_kernel_cve_status_version() { - this_version = "6.6.142" + this_version = "6.6.144" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -15132,7 +15132,7 @@ CVE_STATUS[CVE-2024-58091] = "fixed-version: only affects 6.11 onwards" CVE_STATUS[CVE-2024-58092] = "fixed-version: only affects 6.8 onwards" -# CVE-2024-58093 needs backporting (fixed from 6.15) +CVE_STATUS[CVE-2024-58093] = "cpe-stable-backport: Backported in 6.6.87" # CVE-2024-58094 needs backporting (fixed from 6.15) @@ -15520,7 +15520,7 @@ CVE_STATUS[CVE-2025-21815] = "fixed-version: only affects 6.7 onwards" CVE_STATUS[CVE-2025-21816] = "cpe-stable-backport: Backported in 6.6.93" -CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.13.2 onwards" +CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.12.96 onwards" CVE_STATUS[CVE-2025-21819] = "cpe-stable-backport: Backported in 6.6.78" @@ -16142,7 +16142,7 @@ CVE_STATUS[CVE-2025-22128] = "fixed-version: only affects 6.8 onwards" # CVE-2025-23130 needs backporting (fixed from 6.15) -# CVE-2025-23131 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2025-23131] = "cpe-stable-backport: Backported in 6.6.144" # CVE-2025-23132 needs backporting (fixed from 6.15) @@ -19764,7 +19764,7 @@ CVE_STATUS[CVE-2025-68294] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2025-68295] = "cpe-stable-backport: Backported in 6.6.119" -# CVE-2025-68296 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2025-68296] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2025-68297] = "cpe-stable-backport: Backported in 6.6.119" @@ -19958,7 +19958,7 @@ CVE_STATUS[CVE-2025-68734] = "cpe-stable-backport: Backported in 6.6.117" CVE_STATUS[CVE-2025-68735] = "fixed-version: only affects 6.10 onwards" -# CVE-2025-68736 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2025-68736] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2025-68737] = "fixed-version: only affects 6.18 onwards" @@ -20022,7 +20022,7 @@ CVE_STATUS[CVE-2025-68766] = "cpe-stable-backport: Backported in 6.6.120" CVE_STATUS[CVE-2025-68767] = "cpe-stable-backport: Backported in 6.6.120" -# CVE-2025-68768 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2025-68768] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2025-68769] = "cpe-stable-backport: Backported in 6.6.120" @@ -21098,7 +21098,7 @@ CVE_STATUS[CVE-2026-23275] = "fixed-version: only affects 6.13 onwards" CVE_STATUS[CVE-2026-23277] = "cpe-stable-backport: Backported in 6.6.130" -# CVE-2026-23278 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-23278] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-23279] = "cpe-stable-backport: Backported in 6.6.130" @@ -21230,7 +21230,7 @@ CVE_STATUS[CVE-2026-23344] = "fixed-version: only affects 6.19 onwards" CVE_STATUS[CVE-2026-23345] = "fixed-version: only affects 6.13 onwards" -# CVE-2026-23346 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-23346] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-23347] = "cpe-stable-backport: Backported in 6.6.130" @@ -21546,7 +21546,7 @@ CVE_STATUS[CVE-2026-31417] = "cpe-stable-backport: Backported in 6.6.134" CVE_STATUS[CVE-2026-31418] = "cpe-stable-backport: Backported in 6.6.134" -# CVE-2026-31419 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-31419] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-31420 needs backporting (fixed from 7.0) @@ -21572,7 +21572,7 @@ CVE_STATUS[CVE-2026-31430] = "cpe-stable-backport: Backported in 6.6.135" CVE_STATUS[CVE-2026-31431] = "cpe-stable-backport: Backported in 6.6.137" -# CVE-2026-31432 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-31432] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-31433] = "cpe-stable-backport: Backported in 6.6.131" @@ -21680,7 +21680,7 @@ CVE_STATUS[CVE-2026-31484] = "fixed-version: only affects 6.19 onwards" CVE_STATUS[CVE-2026-31485] = "cpe-stable-backport: Backported in 6.6.131" -# CVE-2026-31486 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-31486] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-31487 needs backporting (fixed from 7.0) @@ -22294,7 +22294,7 @@ CVE_STATUS[CVE-2026-43008] = "fixed-version: only affects 6.19 onwards" # CVE-2026-43009 needs backporting (fixed from 7.0) -# CVE-2026-43010 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-43010] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-43011] = "cpe-stable-backport: Backported in 6.6.134" @@ -22312,7 +22312,7 @@ CVE_STATUS[CVE-2026-43017] = "cpe-stable-backport: Backported in 6.6.134" CVE_STATUS[CVE-2026-43018] = "cpe-stable-backport: Backported in 6.6.134" -# CVE-2026-43019 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43019] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43020] = "cpe-stable-backport: Backported in 6.6.134" @@ -22450,7 +22450,7 @@ CVE_STATUS[CVE-2026-43086] = "cpe-stable-backport: Backported in 6.6.136" CVE_STATUS[CVE-2026-43087] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-43088 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43088] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43089] = "cpe-stable-backport: Backported in 6.6.136" @@ -22506,7 +22506,7 @@ CVE_STATUS[CVE-2026-43114] = "cpe-stable-backport: Backported in 6.6.136" # CVE-2026-43115 needs backporting (fixed from 7.0) -# CVE-2026-43116 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43116] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43117] = "cpe-stable-backport: Backported in 6.6.136" @@ -22530,7 +22530,7 @@ CVE_STATUS[CVE-2026-43124] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-43128] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-43129 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43129] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43130] = "cpe-stable-backport: Backported in 6.6.128" @@ -22710,7 +22710,7 @@ CVE_STATUS[CVE-2026-43217] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2026-43218] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-43219 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43219] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43220] = "cpe-stable-backport: Backported in 6.6.140" @@ -22752,7 +22752,7 @@ CVE_STATUS[CVE-2026-43238] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-43239] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-43240 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43240] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43241] = "cpe-stable-backport: Backported in 6.6.128" @@ -22878,7 +22878,7 @@ CVE_STATUS[CVE-2026-43301] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2026-43302] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-43303 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43303] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43304] = "cpe-stable-backport: Backported in 6.6.128" @@ -22894,7 +22894,7 @@ CVE_STATUS[CVE-2026-43307] = "fixed-version: only affects 6.12 onwards" # CVE-2026-43310 needs backporting (fixed from 7.0) -# CVE-2026-43311 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43311] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43312] = "cpe-stable-backport: Backported in 6.6.128" @@ -22934,7 +22934,7 @@ CVE_STATUS[CVE-2026-43329] = "cpe-stable-backport: Backported in 6.6.134" CVE_STATUS[CVE-2026-43330] = "cpe-stable-backport: Backported in 6.6.134" -# CVE-2026-43331 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43331] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43332] = "cpe-stable-backport: Backported in 6.6.134" @@ -23114,7 +23114,7 @@ CVE_STATUS[CVE-2026-43419] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2026-43420] = "cpe-stable-backport: Backported in 6.6.130" -# CVE-2026-43421 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-43421] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-43424] = "cpe-stable-backport: Backported in 6.6.130" @@ -23308,7 +23308,7 @@ CVE_STATUS[CVE-2026-45848] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-45849] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-45850 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-45850] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-45851] = "cpe-stable-backport: Backported in 6.6.128" @@ -23468,7 +23468,7 @@ CVE_STATUS[CVE-2026-45928] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2026-45929] = "fixed-version: only affects 6.16 onwards" -# CVE-2026-45930 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-45930] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-45931] = "fixed-version: only affects 6.14 onwards" @@ -23714,7 +23714,7 @@ CVE_STATUS[CVE-2026-46052] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46053] = "cpe-stable-backport: Backported in 6.6.140" -# CVE-2026-46054 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46054] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46055] = "fixed-version: only affects 7.0 onwards" @@ -23790,7 +23790,7 @@ CVE_STATUS[CVE-2026-46089] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46091] = "cpe-stable-backport: Backported in 6.6.140" -# CVE-2026-46092 needs backporting (fixed from 7.1) +CVE_STATUS[CVE-2026-46092] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46093] = "fixed-version: only affects 6.9 onwards" @@ -23876,7 +23876,7 @@ CVE_STATUS[CVE-2026-46133] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46134] = "fixed-version: only affects 6.14 onwards" -# CVE-2026-46135 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46135] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46136] = "cpe-stable-backport: Backported in 6.6.140" @@ -23886,7 +23886,7 @@ CVE_STATUS[CVE-2026-46138] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46139] = "fixed-version: only affects 6.12.23 onwards" -# CVE-2026-46140 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46140] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46141] = "fixed-version: only affects 6.18 onwards" @@ -24086,7 +24086,7 @@ CVE_STATUS[CVE-2026-46240] = "fixed-version: only affects 6.18.16 onwards" # CVE-2026-46241 needs backporting (fixed from 7.1) -# CVE-2026-46242 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46242] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46243] = "cpe-stable-backport: Backported in 6.6.142" @@ -24106,7 +24106,7 @@ CVE_STATUS[CVE-2026-46250] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-46251] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-46252 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46252] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46253] = "cpe-stable-backport: Backported in 6.6.128" @@ -24242,11 +24242,11 @@ CVE_STATUS[CVE-2026-46318] = "fixed-version: only affects 6.19 onwards" CVE_STATUS[CVE-2026-46319] = "cpe-stable-backport: Backported in 6.6.141" -# CVE-2026-46320 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-46320] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-46321 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-46321] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-46322 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-46322] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-46323] = "cpe-stable-backport: Backported in 6.6.142" @@ -24264,7 +24264,7 @@ CVE_STATUS[CVE-2026-46329] = "fixed-version: only affects 6.12 onwards" # CVE-2026-46330 needs backporting (fixed from 7.0) -# CVE-2026-46331 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-46331] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-46332] = "fixed-version: only affects 6.12 onwards" @@ -24278,17 +24278,17 @@ CVE_STATUS[CVE-2026-52906] = "fixed-version: only affects 6.19 onwards" CVE_STATUS[CVE-2026-52907] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-52908 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52908] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52909 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-52909] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-52910 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52910] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52911] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-52912] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-52913 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52913] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52914] = "cpe-stable-backport: Backported in 6.6.142" @@ -24296,7 +24296,7 @@ CVE_STATUS[CVE-2026-52915] = "cpe-stable-backport: Backported in 6.6.142" CVE_STATUS[CVE-2026-52916] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-52917 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52917] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52918] = "cpe-stable-backport: Backported in 6.6.142" @@ -24308,21 +24308,21 @@ CVE_STATUS[CVE-2026-52921] = "cpe-stable-backport: Backported in 6.6.142" CVE_STATUS[CVE-2026-52922] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-52923 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52923] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52924 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52924] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52925] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-52926] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-52927 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52927] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52928 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-52928] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-52929 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52929] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52930 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52930] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52931] = "cpe-stable-backport: Backported in 6.6.142" @@ -24330,9 +24330,9 @@ CVE_STATUS[CVE-2026-52932] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2026-52933] = "cpe-stable-backport: Backported in 6.6.140" -# CVE-2026-52934 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52934] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52935 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52935] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141" @@ -24340,25 +24340,25 @@ CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-52938] = "fixed-version: only affects 7.0 onwards" -# CVE-2026-52939 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52939] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52940] = "fixed-version: only affects 6.17 onwards" CVE_STATUS[CVE-2026-52941] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-52942 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52942] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52943 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52943] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52944 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52944] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52945] = "fixed-version: only affects 6.15.3 onwards" -# CVE-2026-52946 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52946] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52947 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52947] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-52948 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-52948] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-52949] = "fixed-version: only affects 6.15 onwards" @@ -24622,7 +24622,7 @@ CVE_STATUS[CVE-2026-53077] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-53079] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-53080 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53080] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53081] = "fixed-version: only affects 6.11 onwards" @@ -24724,23 +24724,23 @@ CVE_STATUS[CVE-2026-53128] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-53130] = "cpe-stable-backport: Backported in 6.6.141" -# CVE-2026-53131 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53131] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53132 needs backporting (fixed from 7.1) -# CVE-2026-53133 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53133] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53134 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53134] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53135 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53135] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53136 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53136] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53137 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53137] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53138 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53138] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-53139 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53139] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53140] = "fixed-version: only affects 6.8 onwards" @@ -24748,57 +24748,55 @@ CVE_STATUS[CVE-2026-53141] = "fixed-version: only affects 6.14 onwards" CVE_STATUS[CVE-2026-53142] = "fixed-version: only affects 6.8 onwards" -# CVE-2026-53143 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53143] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53144 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53144] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53145] = "fixed-version: only affects 6.18.32 onwards" -# CVE-2026-53146 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53146] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53147 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53147] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53148 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53148] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53149 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53149] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53150 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53150] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53151 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53151] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53152] = "fixed-version: only affects 6.12.78 onwards" CVE_STATUS[CVE-2026-53153] = "fixed-version: only affects 6.13 onwards" -# CVE-2026-53154 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53154] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53155] = "fixed-version: only affects 6.19 onwards" # CVE-2026-53156 needs backporting (fixed from 7.1) -# CVE-2026-53157 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53157] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-53158 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53158] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53159 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53159] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53160 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53160] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53161 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53161] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53162] = "fixed-version: only affects 6.16 onwards" -# CVE-2026-53163 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53163] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53164] = "fixed-version: only affects 6.16 onwards" CVE_STATUS[CVE-2026-53165] = "fixed-version: only affects 7.0 onwards" -# CVE-2026-53166 may need backporting (fixed from 6.7) +CVE_STATUS[CVE-2026-53167] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-53167 may need backporting (fixed from 6.6.144) - -# CVE-2026-53168 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53168] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53169] = "fixed-version: only affects 6.19 onwards" @@ -24814,9 +24812,9 @@ CVE_STATUS[CVE-2026-53174] = "fixed-version: only affects 6.19 onwards" CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards" -# CVE-2026-53176 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53176] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53177 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53177] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53178 needs backporting (fixed from 7.1) @@ -24824,25 +24822,25 @@ CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards" CVE_STATUS[CVE-2026-53180] = "fixed-version: only affects 6.9 onwards" -# CVE-2026-53181 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53181] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53182 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53182] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53183 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53183] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53184 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53184] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53185 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53185] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53186 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53186] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53187] = "fixed-version: only affects 6.17 onwards" CVE_STATUS[CVE-2026-53188] = "fixed-version: only affects 6.15 onwards" -# CVE-2026-53189 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53189] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53190 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53190] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53191] = "fixed-version: only affects 6.12 onwards" @@ -24850,17 +24848,17 @@ CVE_STATUS[CVE-2026-53192] = "fixed-version: only affects 6.12 onwards" CVE_STATUS[CVE-2026-53193] = "fixed-version: only affects 6.12 onwards" -# CVE-2026-53194 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53194] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53195 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53195] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53196 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53196] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53197] = "fixed-version: only affects 6.14 onwards" -# CVE-2026-53198 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53198] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53199 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53199] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53200] = "fixed-version: only affects 6.19 onwards" @@ -24876,57 +24874,57 @@ CVE_STATUS[CVE-2026-53205] = "fixed-version: only affects 6.12.30 onwards" CVE_STATUS[CVE-2026-53206] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-53207 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53207] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53208 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53208] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53209 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53209] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53210] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2026-53211] = "fixed-version: only affects 6.18 onwards" -# CVE-2026-53212 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53212] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53213 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53213] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53214 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53214] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53215 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53215] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53216 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53216] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53217 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53217] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53218 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53218] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53219 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53219] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53220 needs backporting (fixed from 7.1) -# CVE-2026-53221 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53221] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53222] = "fixed-version: only affects 6.18 onwards" -# CVE-2026-53223 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53223] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53224 needs backporting (fixed from 7.1) -# CVE-2026-53225 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53225] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53226 needs backporting (fixed from 7.1) -# CVE-2026-53227 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53227] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53228 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53228] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53229 needs backporting (fixed from 7.1) -# CVE-2026-53230 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53230] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53231] = "fixed-version: only affects 7.0 onwards" -# CVE-2026-53232 needs backporting (fixed from 7.1) +CVE_STATUS[CVE-2026-53232] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53233] = "fixed-version: only affects 6.12 onwards" @@ -24934,47 +24932,47 @@ CVE_STATUS[CVE-2026-53234] = "fixed-version: only affects 6.12 onwards" CVE_STATUS[CVE-2026-53235] = "fixed-version: only affects 6.10 onwards" -# CVE-2026-53236 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53236] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53237 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53237] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53238 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53238] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53239 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53239] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53240] = "fixed-version: only affects 6.14 onwards" CVE_STATUS[CVE-2026-53241] = "fixed-version: only affects 6.10 onwards" -# CVE-2026-53242 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53242] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53243] = "fixed-version: only affects 7.0.10 onwards" CVE_STATUS[CVE-2026-53244] = "fixed-version: only affects 7.0 onwards" -# CVE-2026-53245 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53245] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53246 needs backporting (fixed from 7.1) -# CVE-2026-53247 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53247] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53248] = "fixed-version: only affects 6.15 onwards" -# CVE-2026-53249 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53249] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53250] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2026-53251] = "fixed-version: only affects 6.12.2 onwards" -# CVE-2026-53252 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53252] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53253 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53253] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53254 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53254] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53255 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53255] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53256 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53256] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53257] = "fixed-version: only affects 6.16 onwards" @@ -24988,31 +24986,31 @@ CVE_STATUS[CVE-2026-53261] = "fixed-version: only affects 6.7 onwards" # CVE-2026-53262 needs backporting (fixed from 7.1) -# CVE-2026-53263 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53263] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53264 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53264] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53265 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53265] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53266 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53266] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53267 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53267] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53268 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53268] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53269 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53269] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53270 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53270] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53271 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53271] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53272 needs backporting (fixed from 7.1) -# CVE-2026-53273 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53273] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53274 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53274] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53275 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53275] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53276] = "fixed-version: only affects 6.19 onwards" @@ -25112,19 +25110,19 @@ CVE_STATUS[CVE-2026-53323] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2026-53324] = "fixed-version: only affects 6.13 onwards" -# CVE-2026-53325 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53325] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53326] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-53327 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53327] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53328] = "fixed-version: only affects 6.12 onwards" -# CVE-2026-53329 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53329] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53330 needs backporting (fixed from 7.1) -# CVE-2026-53331 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53331] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-53332 needs backporting (fixed from 7.1) @@ -25134,13 +25132,13 @@ CVE_STATUS[CVE-2026-53334] = "fixed-version: only affects 6.18 onwards" CVE_STATUS[CVE-2026-53335] = "fixed-version: only affects 6.18 onwards" -# CVE-2026-53336 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53336] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53337 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53337] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53338] = "fixed-version: only affects 6.16 onwards" -# CVE-2026-53339 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53339] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53340] = "fixed-version: only affects 6.14 onwards" @@ -25148,43 +25146,933 @@ CVE_STATUS[CVE-2026-53341] = "fixed-version: only affects 6.11 onwards" CVE_STATUS[CVE-2026-53342] = "fixed-version: only affects 6.16 onwards" -# CVE-2026-53343 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53343] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53344] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-53345 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53345] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53346] = "fixed-version: only affects 6.12 onwards" -# CVE-2026-53347 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53347] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53348] = "fixed-version: only affects 6.19 onwards" -# CVE-2026-53349 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53349] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53350 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53350] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53351] = "fixed-version: only affects 7.0 onwards" -# CVE-2026-53352 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53352] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53353 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53353] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53354 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53354] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53355 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53355] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53356 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53356] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53357] = "cpe-stable-backport: Backported in 6.6.142" -# CVE-2026-53358 may need backporting (fixed from 6.6.143) +CVE_STATUS[CVE-2026-53358] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53359 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53359] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53360] = "fixed-version: only affects 6.10 onwards" -# CVE-2026-53361 may need backporting (fixed from 6.6.144) +CVE_STATUS[CVE-2026-53361] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53362] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53363] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-53364] = "fixed-version: only affects 6.16.4 onwards" + +CVE_STATUS[CVE-2026-53365] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-53366] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53367] = "fixed-version: only affects 6.17.10 onwards" + +# CVE-2026-53368 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-53369] = "cpe-stable-backport: Backported in 6.6.140" + +CVE_STATUS[CVE-2026-53370] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-53371] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-53372] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-53373] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-53374] = "cpe-stable-backport: Backported in 6.6.140" + +CVE_STATUS[CVE-2026-53375] = "cpe-stable-backport: Backported in 6.6.140" + +CVE_STATUS[CVE-2026-53376] = "cpe-stable-backport: Backported in 6.6.140" + +# CVE-2026-53377 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-53378] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-53379] = "cpe-stable-backport: Backported in 6.6.140" + +CVE_STATUS[CVE-2026-53380] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-53381] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53382] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53383] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53384] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53385] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53386] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-53387] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-53388] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53389] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-53390] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53391] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-53392 needs backporting (fixed from 7.2rc1) + +# CVE-2026-53393 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-53394] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-53395] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-53396] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-53397] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-53398] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-53399 needs backporting (fixed from 7.2rc1) + +# CVE-2026-53400 needs backporting (fixed from 7.2rc1) + +# CVE-2026-53401 needs backporting (fixed from 7.2rc1) + +# CVE-2026-53402 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-53403] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63793] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-63794] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63795] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63796] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63797] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63798] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63799] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63800] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63801] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63802] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63803] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63804] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63805 needs backporting (fixed from 7.2rc1) + +# CVE-2026-63806 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63807] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63808] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63809] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63810 needs backporting (fixed from 7.2rc1) + +# CVE-2026-63811 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63812] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63813] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63814] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63815 needs backporting (fixed from 7.2rc1) + +# CVE-2026-63816 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63817] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63818 needs backporting (fixed from 7.2rc1) + +# CVE-2026-63819 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63820] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63821] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63822] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63823] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63824] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63825 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63826] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63827] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63828] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-63829 needs backporting (fixed from 7.2rc1) + +CVE_STATUS[CVE-2026-63830] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63831] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63832] = "fixed-version: only affects 6.12.13 onwards" + +CVE_STATUS[CVE-2026-63833] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63834] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63835] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63836] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-63837] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-63838] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63839] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-63840] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63841] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-63842] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-63843] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-63844] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63845] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63846] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63847] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63848] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63849] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-63850] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-63851] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-63852] = "cpe-stable-backport: Backported in 6.6.141" + +# CVE-2026-63853 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63854] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63855] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63856] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63857] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-63858 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63859] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63860] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63861] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63862] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63863] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63864] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63865] = "cpe-stable-backport: Backported in 6.6.141" + +CVE_STATUS[CVE-2026-63866] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63867] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63868] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63869] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-63870] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-63871 needs backporting (fixed from 7.1) + +# CVE-2026-63872 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63873] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-63874] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63875] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63876] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63877] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63878] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-63879 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63880] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-63881] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63882] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63883] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63884] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63885] = "fixed-version: only affects 6.18.32 onwards" + +CVE_STATUS[CVE-2026-63886] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63887] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63888] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63889] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63890] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63891] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63892] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63893] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63894] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-63895] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63896] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63897] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63898] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63899] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63900] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63901] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63902] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63903] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63904] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63905] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63906] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63907] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63908] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63909] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63910] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63911] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-63912] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63913] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63914] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63915] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63916] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63917] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63918] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-63919] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63920] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63921] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63922] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63923] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-63924] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63925] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63926] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63927] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63928] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63929] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63930] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63931] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63932] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-63933] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63934] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63935] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-63936] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63937] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63938] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63939] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-63940 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63941] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63942] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63943] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63944] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63945] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63946] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63947] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63948] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63949] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63950] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63951] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63952] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63953] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63954] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63955] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63956] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63957] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63958] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63959] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63960] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63961] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-63962 needs backporting (fixed from 7.1) + +# CVE-2026-63963 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63964] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63965] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-63966] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63967] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63968] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63969] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63970] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-63971] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63972] = "fixed-version: only affects 6.18.33 onwards" + +CVE_STATUS[CVE-2026-63973] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-63974 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63975] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63976] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63977] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-63978 needs backporting (fixed from 7.1) + +# CVE-2026-63979 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63980] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-63981] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-63982] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-63983 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-63984] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63985] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63986] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-63987] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63988] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63989] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-63990] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63991] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63992] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63993] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63994] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-63995] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63996] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63997] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-63998] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-63999 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-64000] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-64001 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64002] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64003] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64004] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64005] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64006] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64007] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64008] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64009] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64010] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64011] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64012] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64013] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64014] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64015] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64016] = "fixed-version: only affects 6.18.33 onwards" + +# CVE-2026-64017 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-64018] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64019] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64020] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64021] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64022] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64023] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64024] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64025] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64026] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64027] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64028] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64029] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64030] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64031] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64032] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64033] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64034] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64035] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-64036 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64037] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-64038 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64039] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64040] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64041] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64042] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64043] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64044] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64045] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64046] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64047] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64048] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64049] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64050] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64051] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64052] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64053] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64054] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64055] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64056] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64057] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64058] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64059] = "fixed-version: only affects 6.12 onwards" + +# CVE-2026-64060 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64061] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64062] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64063] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64064] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64065] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64066] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64067] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64068] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64069] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-64070 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64071] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64072] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64073] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64074] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64075] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-64076 needs backporting (fixed from 7.1) + +# CVE-2026-64077 needs backporting (fixed from 7.1) + +# CVE-2026-64078 needs backporting (fixed from 7.1) + +# CVE-2026-64079 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64080] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64081] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-64082 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64083] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64084] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64085] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64086] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64087] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64088] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64089] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64090] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64091] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64092] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64093] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64094] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64095] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64096] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64097] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64098] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64099] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64100] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64101] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64102] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64103] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64104] = "fixed-version: only affects 6.13.8 onwards" + +CVE_STATUS[CVE-2026-64105] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64106] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64107] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64108] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64109] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64110] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64111] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-64112 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64113] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64114] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64115] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64116] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-64117 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64118] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64119] = "fixed-version: only affects 6.11.3 onwards" + +CVE_STATUS[CVE-2026-64120] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64121] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64122] = "fixed-version: only affects 6.18.14 onwards" + +CVE_STATUS[CVE-2026-64123] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64124] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64125] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64126] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64127] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64128] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64129] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64130] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64131] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64132] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64133] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64134] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64135] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64136] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64137] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-64138 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64139] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64140] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-64141] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64142] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64143] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64144] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64145] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-64146 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64147] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64148] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64149] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64150] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64151] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64152] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-64153] = "cpe-stable-backport: Backported in 6.6.142" + +# CVE-2026-64154 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64155] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64156] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64157] = "fixed-version: only affects 6.10.8 onwards" + +CVE_STATUS[CVE-2026-64158] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64159] = "fixed-version: only affects 6.10.8 onwards" + +# CVE-2026-64160 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64161] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64162] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64163] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64164] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64165] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64166] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64167] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64168] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64169] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64170] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64171] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-64172] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64173] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64174] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64175] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64176] = "fixed-version: only affects 6.17.9 onwards" + +CVE_STATUS[CVE-2026-64177] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64178] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64179] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64180] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64181] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64182] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64183] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64184] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64185] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64186] = "fixed-version: only affects 6.17 onwards" + +# CVE-2026-64187 needs backporting (fixed from 7.2rc4) + +CVE_STATUS[CVE-2026-64188] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-64189 needs backporting (fixed from 7.2rc2) + +# CVE-2026-64190 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64191] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-64192 needs backporting (fixed from 7.2rc2) + +# CVE-2026-64205 needs backporting (fixed from 7.2rc1) + +# CVE-2026-64206 needs backporting (fixed from 7.2rc3) + +CVE_STATUS[CVE-2026-64207] = "fixed-version: only affects 6.17 onwards" -# CVE-2026-53362 may need backporting (fixed from 6.6.144) +# CVE-2026-64600 needs backporting (fixed from 7.2rc4) From patchwork Sun Jul 26 08:29:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93512 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 79B71C54F4C for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7374.1785054613920877252 for ; Sun, 26 Jul 2026 01:30:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BBxTUhvh; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so13019325e9.1 for ; Sun, 26 Jul 2026 01:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054612; x=1785659412; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fYWIlcCfPF8HEzUIF3LN7y3/8rTSGSRfaqyvv1BIPJM=; b=BBxTUhvhZ6EN3Ig5pTDFN4vPjSufhq1wqX+7U2MaZwpoKYmfGYqlVBtL06I4PmRRaf 0k8PU0UAerWuskObr4HRwLD3tzM9rwZ3MRFl7po10UckcY+pCvFcOO0UPv625D+p02h/ 7hf6/cDe6NPEpWFTKTKew+ck+cHTiUTiG/FQM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054612; x=1785659412; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fYWIlcCfPF8HEzUIF3LN7y3/8rTSGSRfaqyvv1BIPJM=; b=lhI+tyoCg2urb9MUse6N3ScWSDMGTifKgXMHEQZwrupUHYTwrKa/FIaHQDqpK5rVs5 z+/aivczrIBlkdS1yqTPA02xqwye7e51pksZOempt3FQd29dGbhUqJEj9iiIK1seH5f8 NWP22C62jfUvWjlzEEiPueOd76zGt79nJbgsA1+OV/o/0pAdoeg8wtonrO43mh2ydZLH +/HdTG7HAsQ1Uk/rLA/XzZfa1mxzLM9amasLDMQBSf8PB1a6t/1Y6DA4dp4Ig7XrS8f/ D8rTUKyg1I8YaQ8OUV/sVinRkG/tNbH/97BjLSDjWgAo3vE7RsKCLsSFProVVSrtQvjE NelQ== X-Gm-Message-State: AOJu0Ywn7pkadQI5tbos15ttr8Y4lHz27pBlq4LmRDX3RG8bupdtiOSW lgTko6KkhYqiNahSyikot8God4CVQVasWrja6r1bZzYH+3VE4ExH9IzqEqoqzctWoiBTgyiq8My T+r/v8CI= X-Gm-Gg: AR+sD12CHz83qB3vbMS+d4s+odehfgkAPigKgFltEKOw/5Tb9prFsd4LzM3zw/1Jus8 B1iyIM+0TifP0QmISWx1S3HjT2f9eM8eujEsx/zhwDY9w/swKguUc84/gvU366mQ5mvVONLqJ15 Tpssf/gXIryo78sIxDgjhF7tr0pPhLLz4+kJcSwvbotH7AK1pOYpHHtLomO8s4quu3QzMl2BwqD r2OKy5Y39Cm8wriI4Ves5C/quQ2WXHhTduCTImRIE+W/2MZXxWAbVjGbWJ/sSTNc9WUPnlzDkyD xlaZeKurIYoA5/tI015u7Tz05AujeDHqnjTg/pmouTIbFHoJ3/JCKyAyo6OUVGrwjRPoFQ1OliT BRm5pynISXhImJbGFAcztiFSwrW1aiO3t29B+fom0+JKCufHODe/owjNVaxKQbvlf0fspt8azQD dXMZuPk/CPbf5G6NJtWaTxwD/ni42jZQQDf9fLcjkuVfV6ly6zTEw0YBxs8nT0yee0DaiATb5+g m7T2A== X-Received: by 2002:a05:600c:3e10:b0:495:443b:1bbb with SMTP id 5b1f17b1804b1-496b57160dcmr50820475e9.25.1785054612063; Sun, 26 Jul 2026 01:30:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Date: Sun, 26 Jul 2026 10:29:29 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241986 From: Devansh Patel This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-11979 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../libxml/libxml2/CVE-2026-11979.patch | 70 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 71 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch new file mode 100644 index 00000000000..427026b345f --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch @@ -0,0 +1,70 @@ +From d8566dd918c612078dfb3ee1a95d7bb6f0656bfe Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Fri, 22 May 2026 12:21:20 +0200 +Subject: [PATCH] xmlcatalog: overflow check for large --shell commands + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124 + +CVE: CVE-2026-11979 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e] + +Backport Changes: +- The commit modifies test/catalogs/test.sh. +- test/catalogs/test.sh does not exist in the libxml2 v2.12.10 + source used in Scarthgap and was introduced later version + libxml2 v2.14.0 [1]. +- The test changes were omitted; only the required fix in + xmlcatalog.c was backported. + +[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/f06fc933cdaea2ce8e9cea275fdbf4edb85f9837 + +(cherry picked from commit c2e233fc1b341685fc99621b2768b503f777a72e) +Signed-off-by: Devansh Patel +--- + xmlcatalog.c | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/xmlcatalog.c b/xmlcatalog.c +index 588802b41..51569b879 100644 +--- a/xmlcatalog.c ++++ b/xmlcatalog.c +@@ -114,6 +114,12 @@ static void usershell(void) { + (*cur != '\n') && (*cur != '\r')) { + if (*cur == 0) + break; ++ /* Do not read beyond the command array capacity */ ++ if (i >= (int)sizeof(command) - 2) { ++ printf("Invalid command %s\n", cur); ++ i = 0; ++ break; ++ } + command[i++] = *cur++; + } + command[i] = 0; +@@ -131,6 +137,11 @@ static void usershell(void) { + while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) { + if (*cur == 0) + break; ++ if (i >= (int)sizeof(arg) - 2) { ++ printf("Invalid arg %s\n", arg); ++ i = 0; ++ break; ++ } + arg[i++] = *cur++; + } + arg[i] = 0; +@@ -143,6 +154,11 @@ static void usershell(void) { + cur = arg; + memset(argv, 0, sizeof(argv)); + while (*cur != 0) { ++ if (i >= (int)sizeof(argv) / (int)sizeof(char*)) { ++ printf("Too much arguments\n"); ++ break; ++ } ++ + while ((*cur == ' ') || (*cur == '\t')) cur++; + if (*cur == '\'') { + cur++; +-- +2.35.6 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 2bfa78324f6..d476ba14b6e 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -31,6 +31,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-0992-02.patch \ file://CVE-2026-0992-03.patch \ file://CVE-2026-1757.patch \ + file://CVE-2026-11979.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Sun Jul 26 08:29:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93510 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A38AC54F40 for ; Sun, 26 Jul 2026 08:30:21 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7376.1785054614590844262 for ; Sun, 26 Jul 2026 01:30:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QMusxMdi; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-493f75f7172so15434935e9.1 for ; Sun, 26 Jul 2026 01:30:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054613; x=1785659413; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=07/2U+sr4eb5Xq4uWNibPdyoTbkoMkj7GXBE5GjIiuo=; b=QMusxMdi4DRHW/OtWkW4WdXidhU+m9RedHzxE7vnykltyIqreeqsPN3a0i6dNh5Xw9 pQMgwJ0KcfELeFmXiKXa41gspHEf6F/n+s5+VNPfzG2cd7Qubr02IzFKeAgOqodFHzuC UYnCzei3H3Q4xwOCv5xQt/rFxx7M7KIbY6dMQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054613; x=1785659413; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=07/2U+sr4eb5Xq4uWNibPdyoTbkoMkj7GXBE5GjIiuo=; b=XCG/BLeXuFOQU+rLfcJSEVZvLkYaKdadAqIzq7XCVmKkv4qIsJYfRrtKbc2jvM7JVP gJcJGFKnsB5wgiBlBRCJN3eS2jbMpUYfFcDtOZKSYYfTEMYPBf8mZro8HTZES99cH0GA nfnWAM3bB7zA/zBRPkemfaSRtKlc4pzkfOhApefzwmQjQK9V8wZ2LaYxHI+hHa6JD6kb i1YR1/97pa4216huWDX7Mrz+dzsHCE9eUIuYMjk7ib9fALawgu6J+rBdnF1mPmEDSOvv lyQfXwQ1ZHHa3kFqphKGFpkkvLG9XPSou7jP25Ickj+dF/IINCh9dCPl/s+Wd1C0uj+y VZyA== X-Gm-Message-State: AOJu0YxwPzQ+K4x33GuJUU9S/u5dvHBXFwGtc48di43cJ0NTl7JhKh1c 0ldi1KNoE1meyh/oP/Drh5P40oFDCNJcnWRAnq8+004cLL1Prs3p0Eu2g1qnJRoZj130a/TRabC X5oSCnTc= X-Gm-Gg: AR+sD10u2n2dv6B32sZmDww+VovHfoaygfWjLzkVlsie4r55ctikud7E6boJcVF7uKZ 8Uvi7O3kuSfXhPd5284DD5jRU9bid7xPT8gkBr+KQCX/JYbvvMwinjG4gP3FcsKSsRJPC8F5vZi PxFn6DT0exObL8+gJeVahvax5mKlsJbOXb0NOlA68DutV4VNVleSw8lA1XmgaqNXrLSMeu/N7nl OqbjIFnXy9OGkJ7MWti+LS0/0sDVB/EYrRyVmqB07PZnj0DSJ2YOnUVR4h8wdhce846I1s+KEu/ 1IHkL//gCO07x8Adovumo516vgAftpRwP2fDGsmJG3lilNPVdQpHYV/Vc67qBVAKq39bu7l1tiy /BLISdE9QRCQtGTCkZrJXd8A6sH2iI5cg31kzOL1WzXNJNPg6ksToQDCgMwPDrymE5MCN0yYM/Q CdF1iij9SyelN6XnabbXjy760lHWvKef9qU16pjP5gsLyB17g7dC/Q7c8U/aFLpKHavcDEQea1j ekmrQ== X-Received: by 2002:a05:600c:a4f:b0:493:d741:5d72 with SMTP id 5b1f17b1804b1-496b57116e2mr67632775e9.38.1785054612800; Sun, 26 Jul 2026 01:30:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Date: Sun, 26 Jul 2026 10:29:30 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241988 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-59999. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59999 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59999.patch | 36 +++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch new file mode 100644 index 00000000000..89b7aa9c7f4 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch @@ -0,0 +1,36 @@ +From 1c719fa7d0fb0aa335f0e8d5db5d5e5d01c894e5 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Sun, 31 May 2026 04:47:29 +0000 +Subject: [PATCH] upstream: DisableForwarding=yes didn't override + PermitTunnel=yes + +Reported independently by Huzaifa Sidhpurwala of Redhat and Marko +Jevtic; ok markus@ + +CVE: CVE-2026-59999 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753] + +Backport Changes: +- Retained the Scarthgap serverloop.c OpenBSD revision identifier because + the 10.4 identifier does not describe the older source baseline. + +OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c +(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753) +Signed-off-by: Devansh Patel +--- + serverloop.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/serverloop.c b/serverloop.c +index f3683c2e4..c1fe99d12 100644 +--- a/serverloop.c ++++ b/serverloop.c +@@ -531,7 +531,7 @@ server_request_tun(struct ssh *ssh) + ssh_packet_send_debug(ssh, "Unsupported tunnel device mode."); + return NULL; + } +- if ((options.permit_tun & mode) == 0) { ++ if ((options.permit_tun & mode) == 0 || options.disable_forwarding) { + ssh_packet_send_debug(ssh, "Server has rejected tunnel device " + "forwarding"); + return NULL; diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 4ab3174924c..b6eda3607a9 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -37,6 +37,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-35385.patch \ file://CVE-2026-35414-CVE-2026-35387.patch \ file://CVE-2026-35388.patch \ + file://CVE-2026-59999.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93508 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90260C54EFC for ; Sun, 26 Jul 2026 08:30:20 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7377.1785054615269944905 for ; Sun, 26 Jul 2026 01:30:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kolUsvll; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-4957eefd361so13244225e9.1 for ; Sun, 26 Jul 2026 01:30:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054613; x=1785659413; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=C+gYTYrA5k1zeACyQgVfAOqc+0ndLjMjbrGAoYan9Cc=; b=kolUsvll4g6hNVU3eCo0qnQIw4EvUAK8nXPuP+h4QDsmFZkMYIFggm8t4sbYvRNyn3 K+CH2EsN/EGPZj+UoCutq2krtWL69SUDyg0YRQq7EU7pVQpnustJx0bUpGoNO/TG8lKQ Xaspd8C3vsBjH9kqs3WfDQqZcFPRylr1/BjeY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054613; x=1785659413; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=C+gYTYrA5k1zeACyQgVfAOqc+0ndLjMjbrGAoYan9Cc=; b=KIIrLSALLaN3XH1d6EnujnsVXDSeVVaxYyaqWMT0FJVRbANL+u6GlYChVE/rUx0GpE UYQTTkHdmx3qODks2cQKfpuSSdA6fNhmG0ihJ5HTwaZBpc3K79z4LF2uKSnB2izPyYdV kP7C+qtPazxP0XjIskVE2cR0BnTL4T9hWZesuKPypcta+hsmCgDue/QUW1Tv/R+cCQLu AV+PSleii35nSgP0TZnbdqytANyOPBpQwHtxM4FrJb5wU4o7n23SQJ/J0/e9GZOi1PwN 0VL78yJp1+38VfKV5GSQlHysvR/o12bDOfB7nwp7Gmh898BkpZs0+sZDMUZskGYOOzP0 +pRg== X-Gm-Message-State: AOJu0YzH20/PySnktakAKVko12yKiWCTdQs0lf5+ZrqGlFWQDJIySIXL odjQRg1AEPRWTX0JcyLQTNG23xzSkSslBf6L28F8aZW5qo6WE2KyUdcclpogkzVQFlBT7Sbvblg 9GhcWXi4= X-Gm-Gg: AR+sD12dmrgeAfTL/IfKcFbYzubJ+b9Yasbe/Wo2Fj5HV/99mmzPkRuhnqvQcZsLcIm 6fAbcSkXMxLJMh0e2EFmOifoNVXMtMs1woNiUxHFgyCnETROPmh0aqqRxA7eo7gfuKIjDqlHvOq wQvpqRDb5dAp1gfzn9cpqVRoaMVTElgshLolU9VVy76BNZpQyUifrdgc36iEaZ7YwjiJLXfkvSv ZLvyLUYiELPRSRYxJQgclG5DdY3GZ0OjsZ6lQ6FX0H+BMhBaw2rA9ijurIH+XaIVp9wbovW+Lgd 2u22VEqmGMpBZV48GrKofZgRa4Vjpu0HJTPC05ut/YmmuyCQHXKZJKUdRKycyESdgU8fAoaVy3Z fe5ry7t7um10h7nYTWm+NeACvOZBhKcml3UXAPSW9t0vUEekCCbAjLtiQ9JljdfaAAv75abw24M R9WOr+ddFUuCHCtszllDXras5z9pzXIeJn7DXMZ/JA9kgEMVJxGlVnE26Kyqlt/YaN1JAYAs7Px zNhsw== X-Received: by 2002:a05:600c:1d0d:b0:495:3de8:33a6 with SMTP id 5b1f17b1804b1-496b56ffdecmr61848815e9.16.1785054613391; Sun, 26 Jul 2026 01:30:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Date: Sun, 26 Jul 2026 10:29:31 +0200 Message-ID: <171530a1066afd2d420c33d063238af7e73ee784.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241989 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-59997. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59997 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59997.patch | 58 +++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 59 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch new file mode 100644 index 00000000000..aa171def018 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch @@ -0,0 +1,58 @@ +From 3011cbb6bb73f3f3dc90fa1d48736803fa407509 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Fri, 5 Jun 2026 08:53:07 +0000 +Subject: [PATCH] upstream: pass >9 commandline arguments to the internal-sftp + server, + +previously they were silently dropped; reported by Steve Caffrey ok deraadt@ + +CVE: CVE-2026-59997 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014] + +Backport Changes: +- Retained the Scarthgap session.c OpenBSD revision identifier because the + 10.4 identifier does not describe the older source baseline. + +OpenBSD-Commit-ID: ee6cd5430a3ca027c3223af54b58ad3cc7ccd624 +(cherry picked from commit e9916c44c1324ab9ab022719e4df08a390a83014) +Signed-off-by: Devansh Patel +--- + session.c | 19 ++++++++++--------- + 1 file changed, 10 insertions(+), 9 deletions(-) + +diff --git a/session.c b/session.c +index eb932b8bf..1a01ecf74 100644 +--- a/session.c ++++ b/session.c +@@ -1650,21 +1650,22 @@ do_child(struct ssh *ssh, Session *s, const char *command) + exit(1); + } else if (s->is_subsystem == SUBSYSTEM_INT_SFTP) { + extern int optind, optreset; +- int i; +- char *p, *args; ++ int sftp_argc; ++ char **sftp_argv; + + setproctitle("%s@%s", s->pw->pw_name, INTERNAL_SFTP_NAME); +- args = xstrdup(command ? command : "sftp-server"); +- for (i = 0, (p = strtok(args, " ")); p; (p = strtok(NULL, " "))) +- if (i < ARGV_MAX - 1) +- argv[i++] = p; +- argv[i] = NULL; ++ if (argv_split(command == NULL ? "sftp-server" : command, ++ &sftp_argc, &sftp_argv, 1) != 0) { ++ error("internal error: can't split internal-sftp " ++ "arguments"); ++ exit(1); ++ } + optind = optreset = 1; +- __progname = argv[0]; ++ __progname = sftp_argv[0]; + #ifdef WITH_SELINUX + ssh_selinux_change_context("sftpd_t"); + #endif +- exit(sftp_server_main(i, argv, s->pw)); ++ exit(sftp_server_main(sftp_argc, sftp_argv, s->pw)); + } + + fflush(NULL); diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index b6eda3607a9..4c8604f4b74 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -38,6 +38,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-35414-CVE-2026-35387.patch \ file://CVE-2026-35388.patch \ file://CVE-2026-59999.patch \ + file://CVE-2026-59997.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93507 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3C8FEC5321C for ; Sun, 26 Jul 2026 08:30:20 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7142.1785054615757643681 for ; Sun, 26 Jul 2026 01:30:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GzS3OhVD; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49550ec592cso17330295e9.0 for ; Sun, 26 Jul 2026 01:30:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054614; x=1785659414; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=yD5QazPs+etgQNlHA8Ujuia13fmc6M31bvjDi2XbffY=; b=GzS3OhVDx1C7Z5rDDoRJwa65CUZda4ISbGT55z052S6PcLAmyx9EFFZdgOjDCKMYy9 bMJgYk2pbMsGi/LbHF8QYKXBnTkBkyzIf4M8I9+mZ6aKhYtLpaysqWza8lgekvLsSQ4+ JoJLpmiVhINEWUDZhcoGZcpshG3N1sKBrw++Y= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054614; x=1785659414; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=yD5QazPs+etgQNlHA8Ujuia13fmc6M31bvjDi2XbffY=; b=qIcgAHy6Bp2OXhmzmnx0rA7AAs+vurtGny2LW46KuX8D4LhdF7F6TpEltM9owCfgd+ UTs0Z4TRKxIqtnfI82wlz5lRdvGUGhqhy9rOiiZCyr5zN6Ic+XoXQYriGUxVg0DO6VNj iZ3tXc0TLhS47h/mqHpReKYlwu7VcTU8MxA/oW1WgcPrfojxntqDAFunmiG6o7lfZBZK e2tkXb+YXVzEMkAE54reAJnLxe1+GoIz4NLCsx11CAm8376Ja6s+iolNdjugmgYru61o v97SvSLpVN3J/KeJs8dLhuGNfdODpHOIaXTjuz2RUKkqRPuIcdFNHsPYXQM7VK9z4RfG q8pA== X-Gm-Message-State: AOJu0YyEsRh2jk70ZJuWg/+fMV95SEvF+zEZnlgLbpe1W669CZ8JSFBD 9SwA+aKMG8jKw8Ul39rLD+l7ocDvSBqdiVibA++4MB6hzbxFweSxPHuNnDzrTlXjVJcbkSHCm8H jNi8WfRM= X-Gm-Gg: AR+sD13nuHmHpGSlmEVqZnTkCNkQjtW+ZB911Zgl6jap0P7VjrzPaBSYtID8BSuIOx9 oppGxDa+v+Kn57oNBomys97RHkXSVEsetWC2wnA7FQvt/htOqBjnC9q0OK7veoarbXYjvHumn/m wXH9P2XB5DLYmXqve5QHakwQquvJyfZsEIsQV1WF+PRSwdOHAqjEjXAP60fkjLIHnN/A1LgVVll 8anMB7dX8zAP4WhMy4mHUhdaiz2xENbdT//wnBJnAtw2v6ArRaiksZIllfKK1/j8TCLpMjx2rb9 Epf52EmkHAJgMQcoZV2IBb1CAc9foTQhHXXctV0UG5/HYfYzhAPxF0e6N1nAle5WEFDdSN2OMGR LPe+HMq5/ANgShghx/DTiZmQD370rnBWLwwUrH5imaPocav9A9QGtSagKqZ1MnliOIE3P6T/DiS if6vtLCsbxP7cQI1qOI0WmXvXwzX4nJAqh1XRilQOIWvis1Vtm4cRg2JD4Zm33Lc6VfLfhYLq/S VTh2A== X-Received: by 2002:a05:600c:4585:b0:495:69eb:27d3 with SMTP id 5b1f17b1804b1-496b5b59658mr57009165e9.8.1785054613976; Sun, 26 Jul 2026 01:30:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Date: Sun, 26 Jul 2026 10:29:32 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241990 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-59996. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59996 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59996.patch | 37 +++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch new file mode 100644 index 00000000000..b13390b25b7 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch @@ -0,0 +1,37 @@ +From 762b3d438547893d62ce3e147dce6cef14697b09 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Sun, 28 Jun 2026 23:47:16 +0000 +Subject: [PATCH] upstream: resist that return ".." via remote glob during + +remote/remote copies, similar to fixes for bz3871 for remote/local copies. +From Swival scanner + +CVE: CVE-2026-59996 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78] + +Backport Changes: +- Retained the Scarthgap scp.c OpenBSD revision identifier because the + 10.4 identifier does not describe the older source baseline. + +OpenBSD-Commit-ID: c0c20a1b746db55c08e53658bf21ea9405b300a5 +(cherry picked from commit 36480181fa22f98e180b4f9e10203480c0346c78) +Signed-off-by: Devansh Patel +--- + scp.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/scp.c b/scp.c +index 2c21fa19a..00d87517d 100644 +--- a/scp.c ++++ b/scp.c +@@ -2043,6 +2043,10 @@ throughlocal_sftp(struct sftp_conn *from, struct sftp_conn *to, + goto out; + } + ++ /* Special handling for source of '..' */ ++ if (strcmp(filename, "..") == 0) ++ filename = "."; /* Download to dest, not dest/.. */ ++ + if (targetisdir) + abs_dst = sftp_path_append(target, filename); + else diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 4c8604f4b74..8f44d4b9878 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -39,6 +39,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-35388.patch \ file://CVE-2026-59999.patch \ file://CVE-2026-59997.patch \ + file://CVE-2026-59996.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93511 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0DBC2C53200 for ; Sun, 26 Jul 2026 08:30:20 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7143.1785054616611097516 for ; Sun, 26 Jul 2026 01:30:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1+vyXFmQ; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-4953e04ef16so19392985e9.2 for ; Sun, 26 Jul 2026 01:30:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054615; x=1785659415; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/bmvOhS7hWuDqtZKpL4QQxP4IG4heKQ8vH6ILyZrl9c=; b=1+vyXFmQLNOTxxwCf9rvNz9whlLjOwoQIQoBQlcfPkSHK909EZWqiYF47o6gge1hlx Mq4MeMkc+f9JxpMGWP/nZ2Zce+yr3RSnYcxvFcHgb7nqC+j4SeRNU4D0xDnC5+qjXmG1 47nUiMAGSp7SIAlysTcaC1I0g8AYb3SKKKYZE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054615; x=1785659415; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/bmvOhS7hWuDqtZKpL4QQxP4IG4heKQ8vH6ILyZrl9c=; b=SBg4xQfC9N2uSmySvzA7/UwhydTl6XvywndzFhfU7Q0Wmp+Lr+NO0T5MRxTvZjcUxB CJnmmq0HvW16S0KGsQxSXChB/7OL+aDjLp///jZk1ikXmH0zA/iNfEV7YpOKcnmeDCet 5+Dz1bMX0ZoUtyn7lXneV0QmFtSXvC2naJa/MC28LQU7fVQqN2ZaLb6BVMpKNoVJd4ev DvZoJiMh7UdAqwRXzxDT27OqtM/hqlfrYD5TgJ+qLaU5OgwgTLi7jMDh96T4/WGPMdPh H3JjuacZ/wb5jIZfcEwauzdd9xcVu9p0sPcy5jFaoZQ4xm7o3hntxgNPHQPzhEgmQLO8 +mEQ== X-Gm-Message-State: AOJu0YyY7juvTazFNM/CFLn0DouowZk4aLzMF/SpS5vcnl8njXj8KKk4 D3cS11CY0T6d8TKBwvlDgmbzMBbjLDVTpMduyzQh7AbwJtTha5G7vpcfCvpRdPoOPZnNicx2Xap 05HxZrJ4= X-Gm-Gg: AR+sD13LNfW3f4CgJCHZajbrTvkOxLLIlxUK4rK4iSmg2ZjeqvdlB9VNtlF//h5Pluo AvXP0IotEpRXXjnj4FEFk0aTjRD0KWRBC0MnVN+BntiNPANuCexqCgyTx8QmiO3Tu0pRJ1tcaVb UxwTgnICD++LMyTkknqwIR1xGkBb+QSK0FXZFUc9Itoab+eJa+fVLzRkY5GVuSjovkk9kNgng0k Nv9A8K2mQoVXreLZ2nlACnr1qmzcmz2egrhuNZrHFZnJ5lROIazUu0JGeWsQA77TkmDP2dWfPSH VcwBC4N62yIYUOedd7UI5HtPo0cq0LoV6fJ6oj0Rw9zhs12olqYyNGnaO79u2EIsHDNsPAsdwaa fZ21lBa7211FemPnta933Zejbjl2guOGKkWLbbb11Ts1+GCwu0T1IZ3OMMXK9e2Gi0c71hVPifA V9GSwqbwZfeyDqTmp1cCajGLXoI9MguDzeOxh2d3sqDBbiaXQKqaer7aNeHHRDDovPe6ZtDrr30 h8VlQ== X-Received: by 2002:a05:600c:3216:b0:495:4d2e:53d9 with SMTP id 5b1f17b1804b1-496b56f323fmr30036065e9.12.1785054614814; Sun, 26 Jul 2026 01:30:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Date: Sun, 26 Jul 2026 10:29:33 +0200 Message-ID: <9967952fbfcb130477521324bc9899dafc277439.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241991 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-59995. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59995 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-59995.patch | 42 +++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 43 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch new file mode 100644 index 00000000000..9b6fee198ff --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch @@ -0,0 +1,42 @@ +From b340eaa274a7e7dffea03bcb62169249bbddab37 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 29 Jun 2026 01:47:21 +0000 +Subject: [PATCH] upstream: avoid download to server-controlled path when + performing + +download on the commandline. From Swival scanner + +CVE: CVE-2026-59995 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b] + +Backport Changes: +- Retained the Scarthgap sftp.c OpenBSD revision identifier because the + 10.4 identifier does not describe the older source baseline. + +OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f +(cherry picked from commit 1b39f39657d2e58f8ec57341581a39bbf0be645b) +Signed-off-by: Devansh Patel +--- + sftp.c | 9 ++------- + 1 file changed, 2 insertions(+), 7 deletions(-) + +diff --git a/sftp.c b/sftp.c +index c609b4153..487e53976 100644 +--- a/sftp.c ++++ b/sftp.c +@@ -2268,13 +2268,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2) + return (-1); + } + } else { +- /* XXX this is wrong wrt quoting */ +- snprintf(cmd, sizeof cmd, "get%s %s%s%s", +- global_aflag ? " -a" : "", dir, +- file2 == NULL ? "" : " ", +- file2 == NULL ? "" : file2); +- err = parse_dispatch_command(conn, cmd, +- &remote_path, startdir, 1, 0); ++ err = process_get(conn, dir, file2, remote_path, 0, 0, ++ global_aflag, 0); + free(dir); + free(startdir); + free(remote_path); diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 8f44d4b9878..37f4dc20dd9 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -40,6 +40,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-59999.patch \ file://CVE-2026-59997.patch \ file://CVE-2026-59996.patch \ + file://CVE-2026-59995.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93509 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DBB6FC53219 for ; Sun, 26 Jul 2026 08:30:19 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7379.1785054617481542265 for ; Sun, 26 Jul 2026 01:30:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZnNCEttw; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4956242332dso15443465e9.2 for ; Sun, 26 Jul 2026 01:30:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054616; x=1785659416; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=F9bzdUKOj8JVtnRpSbTmPxZBEghQshYdZPxsnfjYRqU=; b=ZnNCEttwV/L28U4BMNawIGMssmUwMK6/4gWWH7gFuMro6V+5ZfLf54KCo0sMIJMkrY UlOuzZryChqu9Ye9jKHCHJB1NvGbVdvgddoiZUiutiEyHWeZC5nNK98bzqdDmHAsvWyW Hh1HZoVjIKQ9CUXmSxuOU+MQA4q+1JYN5zEbs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054616; x=1785659416; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=F9bzdUKOj8JVtnRpSbTmPxZBEghQshYdZPxsnfjYRqU=; b=Wqx+WkMbc87UBqBgAyENex0HrgxQc1sCRcFXq5Udb6joO8vLDBoZnaumb0wPQ4Az/v MIXAiqBVa51o2tv2n8vyafltaITJXS6IHlCHhrRvm71McqjH8UiZkXikaI3/aBlZcMBs 7HVi/XGI8mH3XOP3o01zathhYebPJSeMmXIR0ILEi1a1WT/CkwbA/A8EVARuNRISKNhi tmdbKcZJzyA+Dk+6oVTJzAzigH5qgdB/GyGwcem63L5aXCRhz8anPRKPm+Fg+56B7tfm PZ0DsqhlaJlgAzgWeJNghyxj2+u8U73wAiYjYwrbR3ThxOn06wNo1UESrFF4UhhH4pvi NNqQ== X-Gm-Message-State: AOJu0YxTioZZXn01917H5tvH5kfBbPfRa0NXE66yMlY8YVpOC+qxQUlj 43C73M9P3ShlAEsnMyWlBNjify/Z9isZ0mnBMplwbJaLeKHQMhgYnPGBPd0qB97/12u8po1k+Y/ jOgvZYkw= X-Gm-Gg: AR+sD13yYIbU+ZwerHmw2MGAgOQYVkulnFyBPIiYJvQxJKbWEoK0tVXfusE1JMunkLH GvFW9rmZ2x2LradpU4fNqA5dqnbyS4I04QjfHK6PYLX7Q9f6z20j2hdJYz58iUzOSVWPr35g6cm qbX7OQANRiGQvzq1j03x18NLAZswgh8p2Mj398UefFT00u+SPlZGMYr2lwZxi20LvapHZzfNQk9 3z+iwx2X490LmuRicCQpSA/ZWiE9VhCVuwCkj3MNRlUQyFOARj4Q/qgAz32lwrzBlbdQ0bsEEG/ 6PtlFht/COOdETXFmOgmMI0S/YLv46eoh+DmEuATsHiZUwlNuFVN48aH7PBq4JreX7/UmGGoO2a 47kvghK6Qu/JjPkITPL/Pnqp+I/Ozv3Cv0dXo3GSYc5s3RaNHNLBdIDYbxKtvJkXPcrcWQyszTA kJQubdKx29Exe03Nfkg0j7hzsPT1aPfFcNZNvOpuJlGb9H/9sLy6Rm9DfzFCWh/+PiKoaOwLXF1 I0yKU+4crLCdOP/ X-Received: by 2002:a05:600c:630d:b0:495:4d00:2fc0 with SMTP id 5b1f17b1804b1-496b56bec0cmr61052995e9.12.1785054615601; Sun, 26 Jul 2026 01:30:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Date: Sun, 26 Jul 2026 10:29:34 +0200 Message-ID: <11cf9397c6ca0d8c080fbceb190d2a2b72b40da6.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241992 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-60001. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-60001 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60001.patch | 130 ++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 131 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch new file mode 100644 index 00000000000..ff1d14c7c9b --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch @@ -0,0 +1,130 @@ +From ef41798b35a53757f8aa08ad14ee1463b0fe9b15 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:44:48 +0000 +Subject: [PATCH] upstream: Fix cases in GSSAPI and keyboard-interactive + +authentication where the minimum per-attempt delay was not being enforced. + +Reported by Orange Cyberdefense Vulnerability Team + +CVE: CVE-2026-60001 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454] + +Backport Changes: +- Kept Scarthgap's PRIVSEP(ssh_gssapi_userok()) interface and GSSAPI + display-name recording while adding the upstream failure-delay calls; + mm_ssh_gssapi_userok() belongs to the later split-sshd architecture. +- Retained the Scarthgap OpenBSD revision identifiers in auth.h, + auth2-chall.c, auth2-gss.c, and auth2.c. + +OpenBSD-Commit-ID: c40bd35cc2428fcaccad7a141703c28baa6da01e +(cherry picked from commit d43ba60c91cb323ca921049b7d43b1908c318454) +Signed-off-by: Devansh Patel +--- + auth.h | 1 + + auth2-chall.c | 4 ++++ + auth2-gss.c | 7 +++++++ + auth2.c | 10 ++++++++-- + 4 files changed, 20 insertions(+), 2 deletions(-) + +diff --git a/auth.h b/auth.h +index 6d2d39762..9ad4898c5 100644 +--- a/auth.h ++++ b/auth.h +@@ -173,6 +173,7 @@ void auth_log(struct ssh *, int, int, const char *, const char *); + void auth_maxtries_exceeded(struct ssh *) __attribute__((noreturn)); + void userauth_finish(struct ssh *, int, const char *, const char *); + int auth_root_allowed(struct ssh *, const char *); ++void auth_failure_delay(Authctxt *, double); + + char *auth2_read_banner(void); + int auth2_methods_valid(const char *, int); +diff --git a/auth2-chall.c b/auth2-chall.c +index 021df8291..20e70d222 100644 +--- a/auth2-chall.c ++++ b/auth2-chall.c +@@ -296,6 +296,7 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh) + u_int i, nresp; + const char *devicename = NULL; + char **response = NULL; ++ double tstart = monotime_double(); + + if (authctxt == NULL) + fatal_f("no authctxt"); +@@ -354,6 +355,9 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh) + auth2_challenge_start(ssh); + } + } ++ ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); + userauth_finish(ssh, authenticated, "keyboard-interactive", + devicename); + return 0; +diff --git a/auth2-gss.c b/auth2-gss.c +index f72a38998..195578bcf 100644 +--- a/auth2-gss.c ++++ b/auth2-gss.c +@@ -255,6 +255,7 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh) + Authctxt *authctxt = ssh->authctxt; + int r, authenticated; + const char *displayname; ++ double tstart = monotime_double(); + + if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep)) + fatal("No authentication or GSSAPI context"); +@@ -268,6 +269,8 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh) + fatal_fr(r, "parse packet"); + + authenticated = PRIVSEP(ssh_gssapi_userok(authctxt->user)); ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); + + if ((!use_privsep || mm_is_monitor()) && + (displayname = ssh_gssapi_displayname()) != NULL) +@@ -293,6 +296,7 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh) + const char *displayname; + u_char *p; + size_t len; ++ double tstart = monotime_double(); + + if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep)) + fatal("No authentication or GSSAPI context"); +@@ -320,6 +324,9 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh) + sshbuf_free(b); + free(mic.value); + ++ if (!authenticated) ++ auth_failure_delay(authctxt, tstart); ++ + if ((!use_privsep || mm_is_monitor()) && + (displayname = ssh_gssapi_displayname()) != NULL) + auth2_record_info(authctxt, "%s", displayname); +diff --git a/auth2.c b/auth2.c +index 271789a77..18077d625 100644 +--- a/auth2.c ++++ b/auth2.c +@@ -265,6 +265,12 @@ ensure_minimum_time_since(double start, double seconds) + nanosleep(&ts, NULL); + } + ++void ++auth_failure_delay(Authctxt *authctxt, double tstart) ++{ ++ ensure_minimum_time_since(tstart, user_specific_delay(authctxt->user)); ++} ++ + static int + input_userauth_request(int type, u_int32_t seq, struct ssh *ssh) + { +@@ -348,8 +354,8 @@ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh) + authenticated = m->userauth(ssh, method); + } + if (!authctxt->authenticated && strcmp(method, "none") != 0) +- ensure_minimum_time_since(tstart, +- user_specific_delay(authctxt->user)); ++ auth_failure_delay(authctxt, tstart); ++ + userauth_finish(ssh, authenticated, method, NULL); + r = 0; + out: diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 37f4dc20dd9..0d9d33c4597 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -41,6 +41,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-59997.patch \ file://CVE-2026-59996.patch \ file://CVE-2026-59995.patch \ + file://CVE-2026-60001.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93506 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C22DBC531F9 for ; Sun, 26 Jul 2026 08:30:19 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7380.1785054618201952158 for ; Sun, 26 Jul 2026 01:30:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=in2JW9aK; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so18641125e9.0 for ; Sun, 26 Jul 2026 01:30:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054616; x=1785659416; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=apZ3VK40LjVAjHexBZKCnow9Trv/S8NpL2OrVXORVSU=; b=in2JW9aKWevQKmO7pcSZ+2leL1cSEGJ2/S+5B7MaO6ISpqYAknYwIhAkYSs5juoaNQ qhHX07FGBCH9SWKwm+NhWgH1SNvpLeLbJiCKmYr+/yzm0XyqHJFVJNGITmASdXRVCo95 +nutZKCEWr9hM8cOAxEDOLzo3y8JeHkzCg3Bk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054616; x=1785659416; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=apZ3VK40LjVAjHexBZKCnow9Trv/S8NpL2OrVXORVSU=; b=rBOePzUg8oCnxwPMG0AnSGubtU+suFt1cP2sSLonlwt+zjnwkLwvrcyVUGCMY9f4Ei cCXcREZEt1vbGNaYM6jn/MpJT0QAP9VvTeNfyhChPK0/UiKjbgdd98KJrzJ8I6EZkHnn Vldt17hEg2bY+DvBMdEQ5sVABhUnrZ5uFVfj0cyb8bYqYD2tQU/Z9cquFHdUNAOJgK2B pa5JKHuxJ1+IqTRXBIwFq3N5RCGbBrxbdlXAKGQB8iBU0z9hZ3QrKPWHM1HU5zRmGFNO POn5xxTIMm1gsGC6ZNEY0dcTOki0YMQ9IXqTNhxCyG/1QUbY/heBGHux6HLdvgZGzoPS VSiA== X-Gm-Message-State: AOJu0YyqXVYNSg0SKNBDBWRgt2BMyYEmj1scIU/GaxyCVZZH3J0Jv0La xzVV49JNBrjPRBmwQNvPh8h7f4m3S3flMNzTCtPiLDvMak3avWjJEKS3/W0vk2P1N466amuqQhW OpNNu6+c= X-Gm-Gg: AR+sD12byzNx1JToUmrUk87O0mWxUywqhTcmxqq1NgWRn4NPw37a51jizZ8AMUcnY6V u+WDLKFsqAzDnhwpapxPYMH17x+V95P2dOaufehkKKYKIlqGebDBGSmWSSKpMW4GlCw16lyIFhB BbAQthTT/3yGgjbON6UBt9gpyRtv3l/rtRIt5vYatPmyvuSMzZJ8uIbLoG8Pf2cFBa5hUVr6D1G VyzJPUDXrMQt4G2LMChXR+Ifq2wmrEmOn4dhkyIbbO8pMPXDY9WlE2dOT/6ppquDBXXBb3TQ8sq +jC6SpBfog3yPHrc32qlUtj/mnS6+bXR3Kq54g0bRZCOeJjJO8CrtdAjEL9UsyeFgs5iz0AhfxQ vJsYLrsTjCHoWo2qG0wPM3uo4s8u+Atyzlh6AxDEIiiNXoefH5ZeSVrWHBHixJECT2FOJ1+0CTC IuH3PAB3H9hYkUsZGtg7bZAttqY/Cy731pJIHpisfTj7hqXu6I+3/PttHWoMJt3eNjlomRTpiua xq/2vvaanO1Gi4w X-Received: by 2002:a05:600c:8b23:b0:493:e404:3727 with SMTP id 5b1f17b1804b1-496b56f9b21mr53928495e9.23.1785054616296; Sun, 26 Jul 2026 01:30:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Date: Sun, 26 Jul 2026 10:29:35 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241993 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-60002. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-60002 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60002.patch | 226 ++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 227 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch new file mode 100644 index 00000000000..9e94e772618 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch @@ -0,0 +1,226 @@ +From 767104acedd68c317b9d8fb603561e1a8be9e76a Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:49:58 +0000 +Subject: [PATCH] upstream: fix ownership and lifetime of several bits of + client + +state that need to persist for the life of the connection, especially the +cached hostkey that was being incorrectly freed early on some paths, possibly +allowing its use after free. + +Reported by Zhenpeng (Leo) Lin from depthfirst.com + +CVE: CVE-2026-60002 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23] + +Backport Changes: +- Retained Scarthgap's valid_hostname() and valid_ruser() helpers when + relocating ssh_conn_info_free() from ssh.c to sshconnect.c. +- Retained Scarthgap's ext-info-c proposal handling while applying the + upstream connection-state ownership and lifetime changes. +- Retained the Scarthgap OpenBSD revision identifiers in ssh.c, + sshconnect.c, sshconnect.h, and sshconnect2.c. + +OpenBSD-Commit-ID: faaa6ad72e7d69d41fa8b197b606265b7d9bc73f +(cherry picked from commit e8bdfb151a356d0171fea4194dd205fbb252be23) +Signed-off-by: Devansh Patel +--- + ssh.c | 24 ++---------------------- + sshconnect.c | 47 +++++++++++++++++++++++++++++++++++++++++++++-- + sshconnect.h | 7 +++++-- + sshconnect2.c | 20 +++++++++++--------- + 4 files changed, 63 insertions(+), 35 deletions(-) + +diff --git a/ssh.c b/ssh.c +index 9c49f98a8..aecdb79ea 100644 +--- a/ssh.c ++++ b/ssh.c +@@ -606,26 +606,6 @@ set_addrinfo_port(struct addrinfo *addrs, int port) + } + } + +-static void +-ssh_conn_info_free(struct ssh_conn_info *cinfo) +-{ +- if (cinfo == NULL) +- return; +- free(cinfo->conn_hash_hex); +- free(cinfo->shorthost); +- free(cinfo->uidstr); +- free(cinfo->keyalias); +- free(cinfo->thishost); +- free(cinfo->host_arg); +- free(cinfo->portstr); +- free(cinfo->remhost); +- free(cinfo->remuser); +- free(cinfo->homedir); +- free(cinfo->locuser); +- free(cinfo->jmphost); +- free(cinfo); +-} +- + static int + valid_hostname(const char *s) + { +@@ -1771,8 +1751,8 @@ main(int ac, char **av) + ssh_signal(SIGCHLD, main_sigchld_handler); + + /* Log into the remote system. Never returns if the login fails. */ +- ssh_login(ssh, &sensitive_data, host, (struct sockaddr *)&hostaddr, +- options.port, pw, timeout_ms, cinfo); ++ ssh_login(ssh, &sensitive_data, host, &hostaddr, options.port, ++ pw, timeout_ms, cinfo); + + /* We no longer need the private host keys. Clear them now. */ + if (sensitive_data.nkeys != 0) { +diff --git a/sshconnect.c b/sshconnect.c +index bd077c75c..7823b6782 100644 +--- a/sshconnect.c ++++ b/sshconnect.c +@@ -83,6 +83,49 @@ extern char *__progname; + static int show_other_keys(struct hostkeys *, struct sshkey *); + static void warn_changed_key(struct sshkey *); + ++void ++ssh_conn_info_free(struct ssh_conn_info *cinfo) ++{ ++ if (cinfo == NULL) ++ return; ++ free(cinfo->conn_hash_hex); ++ free(cinfo->shorthost); ++ free(cinfo->uidstr); ++ free(cinfo->keyalias); ++ free(cinfo->thishost); ++ free(cinfo->host_arg); ++ free(cinfo->portstr); ++ free(cinfo->remhost); ++ free(cinfo->remuser); ++ free(cinfo->homedir); ++ free(cinfo->locuser); ++ free(cinfo->jmphost); ++ freezero(cinfo, sizeof(*cinfo)); ++} ++ ++struct ssh_conn_info * ++ssh_conn_info_dup(const struct ssh_conn_info *cinfo) ++{ ++ struct ssh_conn_info *ret; ++ ++ if (cinfo == NULL) ++ return NULL; ++ ret = xcalloc(1, sizeof(*ret)); ++ ret->conn_hash_hex = xstrdup(cinfo->conn_hash_hex); ++ ret->shorthost = xstrdup(cinfo->shorthost); ++ ret->uidstr = xstrdup(cinfo->uidstr); ++ ret->keyalias = xstrdup(cinfo->keyalias); ++ ret->thishost = xstrdup(cinfo->thishost); ++ ret->host_arg = xstrdup(cinfo->host_arg); ++ ret->portstr = xstrdup(cinfo->portstr); ++ ret->remhost = xstrdup(cinfo->remhost); ++ ret->remuser = xstrdup(cinfo->remuser); ++ ret->homedir = xstrdup(cinfo->homedir); ++ ret->locuser = xstrdup(cinfo->locuser); ++ ret->jmphost = xstrdup(cinfo->jmphost); ++ return ret; ++} ++ + /* Expand a proxy command */ + static char * + expand_proxy_command(const char *proxy_command, const char *user, +@@ -1559,8 +1602,8 @@ out: + */ + void + ssh_login(struct ssh *ssh, Sensitive *sensitive, const char *orighost, +- struct sockaddr *hostaddr, u_short port, struct passwd *pw, int timeout_ms, +- const struct ssh_conn_info *cinfo) ++ struct sockaddr_storage *hostaddr, u_short port, struct passwd *pw, ++ int timeout_ms, const struct ssh_conn_info *cinfo) + { + char *host; + char *server_user, *local_user; +diff --git a/sshconnect.h b/sshconnect.h +index 79d35cc19..da2a73f5a 100644 +--- a/sshconnect.h ++++ b/sshconnect.h +@@ -71,7 +71,7 @@ int ssh_connect(struct ssh *, const char *, const char *, + void ssh_kill_proxy_command(void); + + void ssh_login(struct ssh *, Sensitive *, const char *, +- struct sockaddr *, u_short, struct passwd *, int, ++ struct sockaddr_storage *, u_short, struct passwd *, int, + const struct ssh_conn_info *); + + int verify_host_key(char *, struct sockaddr *, struct sshkey *, +@@ -80,7 +80,7 @@ int verify_host_key(char *, struct sockaddr *, struct sshkey *, + void get_hostfile_hostname_ipaddr(char *, struct sockaddr *, u_short, + char **, char **); + +-void ssh_kex2(struct ssh *ssh, char *, struct sockaddr *, u_short, ++void ssh_kex2(struct ssh *ssh, char *, struct sockaddr_storage *, u_short, + const struct ssh_conn_info *); + + void ssh_userauth2(struct ssh *ssh, const char *, const char *, +@@ -94,3 +94,6 @@ void maybe_add_key_to_agent(const char *, struct sshkey *, + void load_hostkeys_command(struct hostkeys *, const char *, + const char *, const struct ssh_conn_info *, + const struct sshkey *, const char *); ++ ++void ssh_conn_info_free(struct ssh_conn_info *); ++struct ssh_conn_info *ssh_conn_info_dup(const struct ssh_conn_info *); +diff --git a/sshconnect2.c b/sshconnect2.c +index a296c9b8c..9efb3da8a 100644 +--- a/sshconnect2.c ++++ b/sshconnect2.c +@@ -89,7 +89,7 @@ extern Options options; + */ + + static char *xxx_host; +-static struct sockaddr *xxx_hostaddr; ++static struct sockaddr_storage xxx_hostaddr; + static const struct ssh_conn_info *xxx_conn_info; + static int key_type_allowed(struct sshkey *, const char *); + +@@ -105,7 +105,7 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh) + fatal("Server host key %s not in HostKeyAlgorithms", + sshkey_ssh_name(hostkey)); + } +- if (verify_host_key(xxx_host, xxx_hostaddr, hostkey, ++ if (verify_host_key(xxx_host, (struct sockaddr *)&xxx_hostaddr, hostkey, + xxx_conn_info) != 0) + fatal("Host key verification failed."); + return 0; +@@ -222,16 +222,16 @@ order_hostkeyalgs(char *host, struct sockaddr *hostaddr, u_short port, + } + + void +-ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port, +- const struct ssh_conn_info *cinfo) ++ssh_kex2(struct ssh *ssh, char *host, struct sockaddr_storage *hostaddr, ++ u_short port, const struct ssh_conn_info *cinfo) + { + char *myproposal[PROPOSAL_MAX]; + char *s, *all_key, *hkalgs = NULL; + int r, use_known_hosts_order = 0; + +- xxx_host = host; +- xxx_hostaddr = hostaddr; +- xxx_conn_info = cinfo; ++ xxx_host = xstrdup(host); ++ xxx_hostaddr = *hostaddr; ++ xxx_conn_info = ssh_conn_info_dup(cinfo); + + if (options.rekey_limit || options.rekey_interval) + ssh_packet_set_rekey_limits(ssh, options.rekey_limit, +@@ -257,8 +257,10 @@ ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port, + if ((s = kex_names_cat(options.kex_algorithms, "ext-info-c")) == NULL) + fatal_f("kex_names_cat"); + +- if (use_known_hosts_order) +- hkalgs = order_hostkeyalgs(host, hostaddr, port, cinfo); ++ if (use_known_hosts_order) { ++ hkalgs = order_hostkeyalgs(host, (struct sockaddr *)hostaddr, ++ port, cinfo); ++ } + + kex_proposal_populate_entries(ssh, myproposal, s, options.ciphers, + options.macs, compression_alg_list(options.compression), diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 0d9d33c4597..708399e8022 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -42,6 +42,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-59996.patch \ file://CVE-2026-59995.patch \ file://CVE-2026-60001.patch \ + file://CVE-2026-60002.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93505 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B36ACC531CC for ; Sun, 26 Jul 2026 08:30:19 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7381.1785054618641967893 for ; Sun, 26 Jul 2026 01:30:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OTkaQU8U; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4954aff6088so14425015e9.3 for ; Sun, 26 Jul 2026 01:30:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054617; x=1785659417; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZJhsfO5px4G6PvoB/OWdc5qtbS9034gyKSuUEVGMeg8=; b=OTkaQU8UEIzfpWOQD2WeDjuarAQsBwmE3oZYtzvnCew4JViH9Lw9/dzzP6xaI7eWoI L+3OEtJ+J3Elu+035d/9jpPCi2j0T9gtHzXbqGzpgSAQ0E3q1HxrQkTOxbHUdiq5+lTe QOIXW0nNwTEFKEXi0fkMsnC/IQJrJhYWNDZkY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054617; x=1785659417; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZJhsfO5px4G6PvoB/OWdc5qtbS9034gyKSuUEVGMeg8=; b=nGt1iMw5Y0FI53UtJWycWhPU5pIIMOzwrZyjMQh56TiXKgjHfcLREAwr5rYFCJsExB b5Dd34MrhZchVdp53hvCj8ARQWJJk5VCNdP9DXBRn99NWa/f+SWXPQEo/04yjjUc2VJ3 TwWNJ4mo0tgj6s+m+Dfw0HTl9U2zZxlCjBWKoWKTWVvwF2QXJLYTFnJLwk1oML+mFWRn WCuQ0s43aVFo1+QTL0bHIbttPz9v5F892aYOM933BoPgcmBZfJ3XLsF140BNs5mRdBi/ yu8unpSrIrxTWQrnzhys6ODzENswmv11TF3xaPfhiij63D1V1BeHpIRqN27KeAUsVLi7 YxBw== X-Gm-Message-State: AOJu0Yw9+7BQK3CDXiz7caTN75Ju5YJ1q3xKvNLNAfaGDJiRIqJYTxNA EwHjIo4vi/mBEZkaY21BOQQcHefg84OL6jDKY1o9dyuPB9rJIj134JVVq+jEWabEJFChga9MqjC ljxcJUy4= X-Gm-Gg: AR+sD12brjyNsVkWoqixxvAUxilgRM2mXhCsIWbOl6y+ep8ohmIcJoBQER5G+j3R3it 4JoGIG2GosvZkY+wqDo5HelRAny4Ena7H4fBMeggmMEN1uTHXXSCiHhVvCtFiefgVfxAvd+9Bxr obqMNJwVVbDXvK+ehwEiU66r8iOXGci26jaILKmr5+hImqx0qptImmgpv/xIycmxIPnHZZ2un8z rJPFojKl5C0YW5skwWa8lm40lSwZ450xTJBMJKZo3qjBrZpjtHD1wKlVHngzEpq+aZCmwuMOJnY xyX7C0G9FqzyAvVlye7kS1blHXwghghIRaGpGIx0yHEm0bjTzSzNPhzVSFfQXgZNsDWFOrjO8Hr 3aur/1muZTp+stdAYzuHOdygU3AypMTZI0vRHmEX4sDrb0m02C0oGqeRBasK1b7hpVRoNJjIfAg 8zeakdVmqlxKLxKiUrtKz7YqSbDJgolI6xNczG/VQCO3llRFBx5arvihI3VYt8t/CAuTM3pT6tV UPbjw== X-Received: by 2002:a05:600c:4455:b0:495:4b24:1b64 with SMTP id 5b1f17b1804b1-496b566b0edmr53744305e9.0.1785054616797; Sun, 26 Jul 2026 01:30:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Date: Sun, 26 Jul 2026 10:29:36 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241994 From: Devansh Patel This patch applies the upstream OpenSSH 10.4 backport for CVE-2026-60000. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-60000 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-60000.patch | 140 ++++++++++++++++++ .../openssh/openssh_9.6p1.bb | 1 + 2 files changed, 141 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch new file mode 100644 index 00000000000..9c25786ced0 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch @@ -0,0 +1,140 @@ +From 055316632809a2e2e58eac2020699b52187d1b11 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Mon, 6 Jul 2026 07:53:30 +0000 +Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication) + compliance + +problems + +1) Remove an early failure return for GSSAPI authentication attempts +made for invalid accounts that yielded different behaviour for +valid vs invalid accounts. + +2) Fix a situation where some GSSAPI requestes were not correctly +subjected to MaxAuthTries. + +3) Fix a moderate pre-authentication resource DoS related to #2. + +Add missing logging for error cases. + +Report and fixes from Manfred Kaiser, milCERT AT + +CVE: CVE-2026-60000 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192] + +Backport Changes: +- Kept Scarthgap's PRIVSEP(ssh_gssapi_server_ctx()) interface and its + authentication-context guard while applying the upstream RFC 4462 state, + failure, logging, and MaxAuthTries changes. +- Retained the Scarthgap auth2-gss.c OpenBSD revision identifier. + +OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3 +(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192) +Signed-off-by: Devansh Patel +--- + auth2-gss.c | 53 ++++++++++++++++++++++++----------------------------- + 1 file changed, 24 insertions(+), 29 deletions(-) + +diff --git a/auth2-gss.c b/auth2-gss.c +index 195578bcf..6846eae5b 100644 +--- a/auth2-gss.c ++++ b/auth2-gss.c +@@ -110,12 +110,6 @@ userauth_gssapi(struct ssh *ssh, const char *method) + return (0); + } + +- if (!authctxt->valid || authctxt->user == NULL) { +- debug2_f("disabled because of invalid user"); +- free(doid); +- return (0); +- } +- + if (GSS_ERROR(PRIVSEP(ssh_gssapi_server_ctx(&ctxt, &goid)))) { + if (ctxt != NULL) + ssh_gssapi_delete_ctx(&ctxt); +@@ -177,8 +171,14 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh) + (r = sshpkt_send(ssh)) != 0) + fatal_fr(r, "send ERRTOK packet"); + } ++ logit("Failed gssapi-with-mic for %s%.100s " ++ "from %.200s port %d ssh2", ++ authctxt->valid ? "" : "invalid user ", ++ authctxt->user, ++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh)); + authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL); + userauth_finish(ssh, 0, "gssapi-with-mic", NULL); + } else { + if (send_tok.length != 0) { +@@ -190,14 +190,18 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh) + fatal_fr(r, "send TOKEN packet"); + } + if (maj_status == GSS_S_COMPLETE) { +- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); +- if (flags & GSS_C_INTEG_FLAG) +- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, ++ ssh_dispatch_set(ssh, ++ SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); ++ /* note: keep ERRTOK handler as per RFC 4462 s3.4 */ ++ if (flags & GSS_C_INTEG_FLAG) { ++ ssh_dispatch_set(ssh, ++ SSH2_MSG_USERAUTH_GSSAPI_MIC, + &input_gssapi_mic); +- else ++ } else { + ssh_dispatch_set(ssh, + SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, + &input_gssapi_exchange_complete); ++ } + } + } + +@@ -209,10 +213,6 @@ static int + input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh) + { + Authctxt *authctxt = ssh->authctxt; +- Gssctxt *gssctxt; +- gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER; +- gss_buffer_desc recv_tok; +- OM_uint32 maj_status; + int r; + u_char *p; + size_t len; +@@ -220,26 +220,21 @@ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh) + if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep)) + fatal("No authentication or GSSAPI context"); + +- gssctxt = authctxt->methoddata; +- if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 || ++ /* Minimal error handling - just cancel auth and return FAILURE */ ++ if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 || + (r = sshpkt_get_end(ssh)) != 0) + fatal_fr(r, "parse packet"); +- recv_tok.value = p; +- recv_tok.length = len; +- +- /* Push the error token into GSSAPI to see what it says */ +- maj_status = PRIVSEP(ssh_gssapi_accept_ctx(gssctxt, &recv_tok, +- &send_tok, NULL)); +- +- free(recv_tok.value); + +- /* We can't return anything to the client, even if we wanted to */ ++ logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2", ++ authctxt->valid ? "" : "invalid user ", ++ authctxt->user, ++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh)); ++ authctxt->postponed = 0; + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL); + ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL); +- +- /* The client will have already moved on to the next auth */ +- +- gss_release_buffer(&maj_status, &send_tok); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL); ++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL); ++ userauth_finish(ssh, 0, "gssapi-with-mic", NULL); + return 0; + } + diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index 708399e8022..ba8aaad9bbb 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -43,6 +43,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar file://CVE-2026-59995.patch \ file://CVE-2026-60001.patch \ file://CVE-2026-60002.patch \ + file://CVE-2026-60000.patch \ " SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" From patchwork Sun Jul 26 08:29:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93520 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9701BC54F56 for ; Sun, 26 Jul 2026 08:30:22 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7382.1785054619349341971 for ; Sun, 26 Jul 2026 01:30:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=t8rQpCWw; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so13019635e9.1 for ; Sun, 26 Jul 2026 01:30:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054617; x=1785659417; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uU4ngZ8vQXBZJAg1zBzDox7LCG+wlQN+2Hnxi2OI80k=; b=t8rQpCWw5zbvsT8DYYA84Jx7x2zWdx3wXMibhv/n97UAa0dMzLvF3vDRri2G1EqeUr uYW4feDI8Q42QrY0ynsATNNf2lrjwQ4M1TcGa1rHb31fgr1emeFa2iyIX6FNMgFMDvpE iqGhXhk47k9ylfkhaV2w9mGUxPUeMXHsEFw6U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054617; x=1785659417; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=uU4ngZ8vQXBZJAg1zBzDox7LCG+wlQN+2Hnxi2OI80k=; b=U+l+oIcdipYjJjusLZQJpA4wtTywChQx64CmrqSbM02fOZ5oljieTtWpHuivvu01wB KjyN5upOXVOAhVHxiLiiHUGM/ab9sW+VEnnlYgIxyNtbVO05BsUKbnyMk8LAPbjkqFFE iqMaEYwwHAlGxQZNDVifIY+P8fAufgw//SL24KKxLp6lDa2IZICYL5RQHYTIjyYpU+jc BKEFqa9jTlGJHVzYJvWiKqg4v3ZUmjSc/4uBCGRniijOTfNT61BmxdQAs5Mb2z7fJC3v 1N/dpCD98Sf9GsmSvzxn9OlwMYew0bRCl1vQl+9dx7bpenRNfmV5h3vFmwRLxszj3/Lg +83A== X-Gm-Message-State: AOJu0YxnUj5dMiYrUL+iwrBzCRvnLNjNhs8McTgwybe5juwaV+KuYNSF V+IGffUpOVfMgFLgmgEdlD1gPYHPMDGPPJW5y/ru5A23P3o4PW+F5qpAGJBHOV4MFyF1cAgGcI8 LqnLAgG0= X-Gm-Gg: AR+sD11D7SWP8iXqTJQFpTDw3HRcc1U6og7g70yigisQRDdXdwv5DHmFBq+7nZAi+cK TJdh2Ou3H5YGSNuQeHSIrP6X1aRQGNp76onoLNoVc4MRimQkZSYTQk7ecKaYM2OsYKctW+MoIU1 T2tCQbsG5p+nyMiOvPC73/GwuqxfbOYuLEL/hJEISdJm1SPaMpVhqDRvVDA3zT8yKYW+U3ESyRL IB4JWeEnV2FIIcuIwbOBZDvqHXfcZ/mSc2YeYeNuSd1d3ufiyz+/zno9JfjTg8iLnyd+JSeqRqq eWxCY7uDyepdzzwgz15nP8Q3p1fkb+7UorkQhyfk0cuJY2HbCn/RmAC6SJrCYkmkIshQUnP5YKY IV5jn31GoeLq9W3jxrY4bGO3GCzccIVYeWZ9QLWO+WniIZkzp8ZqV4G6EJFEjZ/PbPWzcELQP82 JwdXXWHeXLWAwfle5Qp99o/dnfjbvI9a3MU/SjBZ92zCQruQYBhaa8EFxtx/Wxxuy8MbIHeP8JR ToLIw== X-Received: by 2002:a05:600c:1f8c:b0:496:bbcb:b0bb with SMTP id 5b1f17b1804b1-496bbcbb36emr17192885e9.18.1785054617490; Sun, 26 Jul 2026 01:30:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Date: Sun, 26 Jul 2026 10:29:37 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241995 From: Deepak Rathore Pick the upstream backport [1] for CVE-2026-27447 as mentioned in [2], where the scheduler treated local user and group names as case-insensitive. Also include the two upstream regression fixes that followed the CVE fix: - CVE-2026-27447-regression_p1.patch [3] fixes a cupsd crash when the referenced user does not exist on the server. This regression was reported in OpenPrinting/cups Issue [5]. - CVE-2026-27447-regression_p2.patch [4] fixes unauthenticated print policies for non-local accounts. This regression was reported in OpenPrinting/cups Issue [6]. [1] https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb [2] https://security-tracker.debian.org/tracker/CVE-2026-27447 [3] https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562 [4] https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0 [5] https://github.com/OpenPrinting/cups/issues/1555 [6] https://github.com/OpenPrinting/cups/issues/1557 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 3 + .../cups/CVE-2026-27447-regression_p1.patch | 33 ++++++ .../cups/CVE-2026-27447-regression_p2.patch | 46 ++++++++ .../cups/cups/CVE-2026-27447.patch | 108 ++++++++++++++++++ 4 files changed, 190 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index c7475d2b813..ec9392b73dd 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -20,6 +20,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2025-58436.patch \ file://CVE-2025-61915.patch \ file://0001-conf.c-Fix-stopping-scheduler-on-unknown-directive.patch \ + file://CVE-2026-27447.patch \ + file://CVE-2026-27447-regression_p1.patch \ + file://CVE-2026-27447-regression_p2.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch new file mode 100644 index 00000000000..d581ee36fdf --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch @@ -0,0 +1,33 @@ +From 6d97ee39fedf12a7a5429a74f4156ef9bb67f562 Mon Sep 17 00:00:00 2001 +From: Zdenek Dohnal +Date: Wed, 22 Apr 2026 12:40:14 +0200 +Subject: [PATCH] Fix cupsd crash if user does not exist on server + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562] + +Backport Changes: +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 6d97ee39fedf12a7a5429a74f4156ef9bb67f562) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 1678a29..4798e86 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1810,7 +1810,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name; + name = (char *)cupsArrayNext(best->names)) + { +- if (!_cups_strcasecmp(name, "@OWNER") && owner && ++ if (!_cups_strcasecmp(name, "@OWNER") && owner && pw && + !strcmp(pw->pw_name, ownername)) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) +-- +2.43.7 diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch new file mode 100644 index 00000000000..e46db92c760 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch @@ -0,0 +1,46 @@ +From 849fba7d7a1144e48d45c5e6ba2504765912ece0 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Fri, 24 Apr 2026 14:06:06 -0400 +Subject: [PATCH] Fix unauthenticated print policies (Issue #1557) + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0] + +Backport Changes: +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 849fba7d7a1144e48d45c5e6ba2504765912ece0) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 7 +++++-- + 1 file changed, 5 insertions(+), 2 deletions(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 4798e86..1dd520d 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1810,8 +1810,9 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name; + name = (char *)cupsArrayNext(best->names)) + { +- if (!_cups_strcasecmp(name, "@OWNER") && owner && pw && +- !strcmp(pw->pw_name, ownername)) ++ if (!_cups_strcasecmp(name, "@OWNER") && owner && ++ ((pw && !strcmp(pw->pw_name, ownername)) || ++ (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, ownername)))) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) + { +@@ -1825,6 +1826,8 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + } + else if (pw && !strcmp(pw->pw_name, name)) + return (HTTP_OK); ++ else if (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, name)) ++ return (HTTP_STATUS_OK); + } + + for (name = (char *)cupsArrayFirst(best->names); +-- +2.43.7 + diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch new file mode 100644 index 00000000000..1614faa7f17 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch @@ -0,0 +1,108 @@ +From 37b8a4387864eded1a15a45db8950a23e5c610d2 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:04:21 -0400 +Subject: [PATCH] CVE-2026-27447: The scheduler treated local user and group + names as case-insensitive. + +CVE: CVE-2026-27447 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb] + +Backport Changes: +- Rebase scheduler/auth.c context to the CUPS 2.4.11 source carried by this + recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit a0c62c1e69604ff061089b750073199fab5a1beb) +Signed-off-by: Deepak Rathore +--- + scheduler/auth.c | 31 +++++++++++++++---------------- + 1 file changed, 15 insertions(+), 16 deletions(-) + +diff --git a/scheduler/auth.c b/scheduler/auth.c +index d0430b4..1678a29 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -1,7 +1,7 @@ + /* + * Authorization routines for the CUPS scheduler. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 1997-2007 by Easy Software Products, all rights reserved. + * +@@ -1159,7 +1159,7 @@ cupsdCheckGroup( + group = getgrnam(groupname); + endgrent(); + +- if (group != NULL) ++ if (user && group) + { + /* + * Group exists, check it... +@@ -1173,7 +1173,7 @@ cupsdCheckGroup( + * User appears in the group membership... + */ + +- if (!_cups_strcasecmp(username, group->gr_mem[i])) ++ if (!strcmp(user->pw_name, group->gr_mem[i])) + return (1); + } + +@@ -1184,25 +1184,24 @@ cupsdCheckGroup( + * belongs to... + */ + +- if (user) +- { +- int ngroups; /* Number of groups */ ++ int ngroups; /* Number of groups */ + # ifdef __APPLE__ +- int groups[2048]; /* Groups that user belongs to */ ++ int groups[2048]; /* Groups that user belongs to */ + # else +- gid_t groups[2048]; /* Groups that user belongs to */ ++ gid_t groups[2048]; /* Groups that user belongs to */ + # endif /* __APPLE__ */ + +- ngroups = (int)(sizeof(groups) / sizeof(groups[0])); ++ ngroups = (int)(sizeof(groups) / sizeof(groups[0])); + # ifdef __APPLE__ +- getgrouplist(username, (int)user->pw_gid, groups, &ngroups); ++ getgrouplist(user->pw_name, (int)user->pw_gid, groups, &ngroups); + # else +- getgrouplist(username, user->pw_gid, groups, &ngroups); ++ getgrouplist(user->pw_name, user->pw_gid, groups, &ngroups); + #endif /* __APPLE__ */ + +- for (i = 0; i < ngroups; i ++) +- if ((int)groupid == (int)groups[i]) +- return (1); ++ for (i = 0; i < ngroups; i ++) ++ { ++ if ((int)groupid == (int)groups[i]) ++ return (1); + } + #endif /* HAVE_GETGROUPLIST */ + } +@@ -1812,7 +1811,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + name = (char *)cupsArrayNext(best->names)) + { + if (!_cups_strcasecmp(name, "@OWNER") && owner && +- !_cups_strcasecmp(username, ownername)) ++ !strcmp(pw->pw_name, ownername)) + return (HTTP_OK); + else if (!_cups_strcasecmp(name, "@SYSTEM")) + { +@@ -1824,7 +1823,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */ + if (cupsdCheckGroup(username, pw, name + 1)) + return (HTTP_OK); + } +- else if (!_cups_strcasecmp(username, name)) ++ else if (pw && !strcmp(pw->pw_name, name)) + return (HTTP_OK); + } + +-- +2.43.7 From patchwork Sun Jul 26 08:29:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93518 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 88876C54F54 for ; Sun, 26 Jul 2026 08:30:22 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7383.1785054619717742711 for ; Sun, 26 Jul 2026 01:30:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xznm/IcN; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4954aff6088so14425045e9.3 for ; Sun, 26 Jul 2026 01:30:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054618; x=1785659418; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DO0UCDvA8DKIfRnK095G3X5vbsFR3/TpwECtuG44dVs=; b=xznm/IcNuGWMdYa5J3KRh8csIPdUy24WH9iNZpIs5PPXvZDg86/0Vvy+n0i/pYtwoV K2hQXmRySGbHs7LklQNXZEtnTLGU9KHz0XaRGfv/Lh9wWRfLES2DYLNg2lVtiCJyoaKY eNxp2QGJGSd3JNQnvLN0Javqt9ycnCgQvlscI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054618; x=1785659418; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DO0UCDvA8DKIfRnK095G3X5vbsFR3/TpwECtuG44dVs=; b=VmDIpPiXKDHZspo5rcvTyb2OYvjFz+iIs4R/XBMWA7905OMP2Bh+EXQJNVWh6pnR1Y F3WhhgnwK0HQ/nAyXnTgxz8A5Wg6kCVPuKpBfljQFTKYTJEAnP7/st+cfKqVV94pvQET ois+wYte7X/s8eO2OF2bhfl/FZOFA41/xSb/QF/aX+5uf1GWdaxw965mSj08gkUGEYJd h27L/MBQlATT2SgHQfg020RuPmd7y617uhrMCb3eZAAZc+rOeDzkwwsNW38R33qQ2h5s Ir/9NfOPMMHUgOMFvNuRjUj9Tb5LYISRp94ZojSxbB1ZzspTPxOaQggm1AdfYDRemrTr jzrA== X-Gm-Message-State: AOJu0YyJYEfV4RbThgt1JsqI6eA+Jb+7WEfAMF9FGXTxqurWrfDQ3JTV l1w/IdY/5C+zsgv7cPIuph7eGx2CYEu+s5Kp/qIJwAMvT8VZbiAXWTkSirz1qtY4yfy7nQHaPGl HVdg8iSI= X-Gm-Gg: AR+sD12GWp0FbhKB0aOpooCE/8u4QAIuNeIl3ny0LLFObsUhUWouBMGU70rvvxvjzwt GEkTghmEkA2ajtHRKDTZ11LBIa1+bBkmnnjcN7I96RlS+hPsu2DowRjlAFK6tIX/HKY8ggeX3PQ jnStwV06cGUQ66SuHBRknCfXQvnCz7QxTu4A86jvJ1TrI9UEgfDupwtFyKRYuE8hNznlqApoJFv jxtyAFsYm3Ze3McMwm10mIQlzWTIOh78zKr4GypO6s4Gn2CCXO73htu/iqt9/w+zr0I1zlxiJRx /KCPePf0E7tvJem8YjZmUYIEKw3jUAAkhzp0IIsPoDNbV3/+oYWlONOxCiIHbUwGeS8rqzO5fqh I3keytoK5Yyf7Z4GNCU3kNZuV3p5w4llqfpDQhPdzxrGyxOLHhfH2TACQlPCLRkZMvplz4ZNtLa pTYJ1lsvtAlaNeFD6gsAw2G4o7KAcowmUDLzZgZACMN22I+X5Td9xT+nI5aF4ldQwDmnsYB2wGm pPxIw== X-Received: by 2002:a05:600c:190b:b0:493:bcba:46a4 with SMTP id 5b1f17b1804b1-496b570dbb0mr55243515e9.20.1785054617958; Sun, 26 Jul 2026 01:30:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Date: Sun, 26 Jul 2026 10:29:38 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241996 From: Deepak Rathore Pick the upstream fix [1] for CVE-2026-41079 as referenced by Debian [2]. [1] https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080 [2] https://security-tracker.debian.org/tracker/CVE-2026-41079 Signed-off-by: Deepak Rathore [YC: reverted modified indentation in imported patch] Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-41079.patch | 71 +++++++++++++++++++ 2 files changed, 72 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index ec9392b73dd..f74bcaffab5 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -23,6 +23,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447.patch \ file://CVE-2026-27447-regression_p1.patch \ file://CVE-2026-27447-regression_p2.patch \ + file://CVE-2026-41079.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-41079.patch b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch new file mode 100644 index 00000000000..87a7e42316b --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch @@ -0,0 +1,71 @@ +From a331e93e2f9baf411715ef69ae19b73827da23d7 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Mon, 13 Apr 2026 11:50:23 -0400 +Subject: [PATCH] Limit num_bytes for SNMP string values. + +CVE: CVE-2026-41079 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080] + +(cherry picked from commit b7c2525a885f528d243c3a92197ca99609b3f080) +Signed-off-by: Deepak Rathore +--- + cups/snmp-private.h | 6 +++--- + cups/snmp.c | 8 ++++++-- + 2 files changed, 9 insertions(+), 5 deletions(-) + +diff --git a/cups/snmp-private.h b/cups/snmp-private.h +index 52b8740..015f53e 100644 +--- a/cups/snmp-private.h ++++ b/cups/snmp-private.h +@@ -1,7 +1,7 @@ + /* + * Private SNMP definitions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2014 by Apple Inc. + * Copyright © 2006-2007 by Easy Software Products, all rights reserved. + * +@@ -58,9 +58,9 @@ typedef enum cups_asn1_e cups_asn1_t; /**** ASN1 request/object types ****/ + + typedef struct cups_snmp_string_s /**** String value ****/ + { +- unsigned char bytes[CUPS_SNMP_MAX_STRING]; +- /* Bytes in string */ + unsigned num_bytes; /* Number of bytes */ ++ unsigned char bytes[CUPS_SNMP_MAX_STRING + 1]; ++ /* Bytes in string */ + } cups_snmp_string_t; + + union cups_snmp_value_u /**** Object value ****/ +diff --git a/cups/snmp.c b/cups/snmp.c +index 54e348f..2fcb38d 100644 +--- a/cups/snmp.c ++++ b/cups/snmp.c +@@ -1,7 +1,7 @@ + /* + * SNMP functions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 2006-2007 by Easy Software Products, all rights reserved. + * +@@ -1042,10 +1042,14 @@ asn1_decode_snmp(unsigned char *buffer, /* I - Buffer */ + case CUPS_ASN1_OCTET_STRING : + case CUPS_ASN1_BIT_STRING : + case CUPS_ASN1_HEX_STRING : +- packet->object_value.string.num_bytes = length; + asn1_get_string(&bufptr, bufend, length, + (char *)packet->object_value.string.bytes, + sizeof(packet->object_value.string.bytes)); ++ ++ if (length >= sizeof(packet->object_value.string.bytes)) ++ packet->object_value.string.num_bytes = sizeof(packet->object_value.string.bytes) - 1; ++ else ++ packet->object_value.string.num_bytes = length; + break; + + case CUPS_ASN1_OID : +-- +2.43.7 From patchwork Sun Jul 26 08:29:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93516 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 79208C531F9 for ; Sun, 26 Jul 2026 08:30:22 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7384.1785054620184312504 for ; Sun, 26 Jul 2026 01:30:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Fz0Xi8tU; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4954afac04bso19460085e9.0 for ; Sun, 26 Jul 2026 01:30:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054618; x=1785659418; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KGXeUg5L8UOgL7piB0gZRD/R2RscXqa9ZStXe0MJr8M=; b=Fz0Xi8tUJTA83R43ZZx1VtVHOHBrRwyGYKdZjtyHWmzbJRmcLLTb+q0JeCgU77x4Q0 YedL0ZeQ8OjVjdNV50QwwzR91c/GlMy6vRKDoYfZkrNInf0zoXyHyPRi3U4AfNthu/eE tivm0xgeLRY6KpMUe+7oyCEocPWrs+g57x+Pc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054618; x=1785659418; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=KGXeUg5L8UOgL7piB0gZRD/R2RscXqa9ZStXe0MJr8M=; b=cn8Kv7IRVmITInUDTPuGD0lsPtAQ8YgwhNoeMNAKb8MGmLzCikeBLVM4Xpdvmk9Q/2 ha3+r8GDE12gRp21VmNSjzVVD6F5MHltz4JFxchBQQfnMCtvgxyiLjw2U/dmTgLcKO7c au9RVlA5A1drDtc4TwWNJyvojqmgAyL1hiZpBbrfRjLIkDeBTRU6Ed6rzdnD34FnoqHQ MlS0m/8i+1SLOkr8rxZg5xaljO63S9FOm9ok1i/+b3yzxhe7hl2OvBon1X/tMt5Z2U2w ItwJ+2fE5+9ng15e7Xz5J0BcS02HHsQ16sXPeMhARrb3KPK/RZRRW3NY/gkkyL2MaxAE lZqg== X-Gm-Message-State: AOJu0YwKqxxAGDl++sSPRioh2LA+XOk2TRUdiXbPbj4EDtootoyU7yXc NPw+yCG1pLsAGl2ZHXICo94d0TUFtd4zMlo+y/tSJCKOEImOIB9oxMVzMmYFFg5k91sHLPFf6pJ mnoUeXZ4= X-Gm-Gg: AR+sD11+ww7/USV5kxn0NFkGIrqMRRSpWVau2bKEWCyQOrvGZbThDUXmhy06oTv2qfz c8vQFA514ljOGTXP6cNFn4oyNuA/FmlbCENl8SMy8T27FjdG9BgneMoFD3D9i05VCwHGgBr3Rvq aWVByX0m337tX3yfFCix/a/9ytjhTpc6WyqrjvpT8sQAX2PajDUgStwJREKgaQxkavoP/j8S9ue aJJQMG2rdMJmBMddhXQKL1yDflQ51q/ugWpKRhtUjuTiDvsbUvr2aZjebstlFQWNYkFEs2H4kRS KP5JTM+B8IXNg9aKQano6/At0VHpPv3pLcG2hQaCAvyhg00fd8XIMKPM0zE5J7Cw/tp+sT43DZh H2JraG9VigBQykMi33++LwYLayDQKVul6WXl6406aBRJOvMX0osDAqPHyQgpgEY1WMa6jsFuGlk E63NBFWsreGnQBHnfiveU942MTl+5wKsIg7asAcmO8kZqfGKaABAnl9BxvG0i/cAIg8kliBGHu7 sp/Nw== X-Received: by 2002:a05:600c:4eca:b0:493:c42e:5be0 with SMTP id 5b1f17b1804b1-496b563fd7emr62601985e9.0.1785054618425; Sun, 26 Jul 2026 01:30:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Date: Sun, 26 Jul 2026 10:29:39 +0200 Message-ID: <511d976c70fb591f3bc72b750df1542c4ee84d6a.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241997 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568 [2] https://security-tracker.debian.org/tracker/CVE-2026-34978 Signed-off-by: Deepak Rathore [YC: reverted upstream patch indentation] Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34978.patch | 107 ++++++++++++++++++ 2 files changed, 108 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index f74bcaffab5..5e272dbcf6b 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -24,6 +24,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447-regression_p1.patch \ file://CVE-2026-27447-regression_p2.patch \ file://CVE-2026-41079.patch \ + file://CVE-2026-34978.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34978.patch b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch new file mode 100644 index 00000000000..5929268f4fa --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch @@ -0,0 +1,107 @@ +From ab6ab965de6890aed4df39c97f7cd708fd5cb00c Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:18:26 -0400 +Subject: [PATCH] Fix RSS notifier. + +CVE: CVE-2026-34978 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568] + +Backport Changes: +- Rebase scheduler/ipp.c subscription context to the CUPS 2.4.11 source + carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. +- Omit the upstream scheduler/ipp.c copyright-year-only header update because + this backport carries only the functional changes needed for CUPS 2.4.11. + +(cherry picked from commit 730347c5bbd5e1271149c6739aa858c0c83a7568) +Signed-off-by: Deepak Rathore +--- + notifier/rss.c | 20 ++++++++++++++------ + scheduler/ipp.c | 12 ++++++++++++ + 2 files changed, 26 insertions(+), 6 deletions(-) + +diff --git a/notifier/rss.c b/notifier/rss.c +index f17e1494c..250ad877e 100644 +--- a/notifier/rss.c ++++ b/notifier/rss.c +@@ -1,11 +1,12 @@ + /* + * RSS notifier for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. +- * Copyright 2007-2015 by Apple Inc. +- * Copyright 2007 by Easy Software Products. ++ * Copyright © 2020-2026 by OpenPrinting. ++ * Copyright © 2007-2015 by Apple Inc. ++ * Copyright © 2007 by Easy Software Products. + * +- * Licensed under Apache License v2.0. See the file "LICENSE" for more information. ++ * Licensed under Apache License v2.0. See the file "LICENSE" for more ++ * information. + */ + + /* +@@ -80,6 +81,7 @@ main(int argc, /* I - Number of command-line arguments */ + http_status_t status; /* HTTP GET/PUT status code */ + char filename[1024], /* Local filename */ + newname[1024]; /* filename.N */ ++ struct stat fileinfo; /* Local file information */ + cups_lang_t *language; /* Language information */ + ipp_attribute_t *printer_up_time, /* Timestamp on event */ + *notify_sequence_number,/* Sequence number */ +@@ -111,9 +113,9 @@ main(int argc, /* I - Number of command-line arguments */ + + if (httpSeparateURI(HTTP_URI_CODING_ALL, argv[1], scheme, sizeof(scheme), + username, sizeof(username), host, sizeof(host), &port, +- resource, sizeof(resource)) < HTTP_URI_OK) ++ resource, sizeof(resource)) < HTTP_URI_OK || strstr(resource, "../") != NULL) + { +- fprintf(stderr, "ERROR: Bad RSS URI \"%s\"!\n", argv[1]); ++ fprintf(stderr, "ERROR: Bad RSS URI \"%s\".\n", argv[1]); + return (1); + } + +@@ -209,6 +211,12 @@ main(int argc, /* I - Number of command-line arguments */ + snprintf(filename, sizeof(filename), "%s/rss%s", cachedir, resource); + snprintf(newname, sizeof(newname), "%s.N", filename); + ++ if (!lstat(filename, &fileinfo) && !S_ISREG(fileinfo.st_mode)) ++ { ++ fprintf(stderr, "ERROR: Local RSS path \"%s\" is not a file.\n", filename); ++ return (1); ++ } ++ + httpAssembleURIf(HTTP_URI_CODING_ALL, baseurl, sizeof(baseurl), "http", + NULL, server_name, atoi(server_port), "/rss%s", resource); + } +diff --git a/scheduler/ipp.c b/scheduler/ipp.c +index 2d80a960e..2dc7376c1 100644 +--- a/scheduler/ipp.c ++++ b/scheduler/ipp.c +@@ -1985,6 +1985,12 @@ add_job_subscriptions( + "notify-status-code", IPP_ATTRIBUTES); + return; + } ++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient); ++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES); ++ return; ++ } + } + else if (!strcmp(attr->name, "notify-pull-method") && + attr->value_tag == IPP_TAG_KEYWORD) +@@ -6010,6 +6016,12 @@ create_subscriptions( + "notify-status-code", IPP_ATTRIBUTES); + return; + } ++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient); ++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES); ++ return; ++ } + } + else if (!strcmp(attr->name, "notify-pull-method") && + attr->value_tag == IPP_TAG_KEYWORD) From patchwork Sun Jul 26 08:29:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93519 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5E0E1C54F53 for ; Sun, 26 Jul 2026 08:30:22 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7148.1785054620921831331 for ; Sun, 26 Jul 2026 01:30:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EwYccXCc; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so18641335e9.0 for ; Sun, 26 Jul 2026 01:30:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054619; x=1785659419; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=G7GJ9ADxTDfoJ5/8ZDYdpwGhPf+espZn+LgTLPzPG2s=; b=EwYccXCcYrsw8g0sf3A3Uv+fF2ei40y/Zfs7RvVXPMUHUzo/H5wWT2/zxZaERnbNWq EbbqWqoneaq8MDHxowKIuaRlFQe0tXMy4bH/hKdWvAGy1U7ueUFgMhoc9QVo3CpjtQpf 8Kq3B+qRJDDgbscjO5CFeLUYaQU6h2aqamv88= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054619; x=1785659419; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=G7GJ9ADxTDfoJ5/8ZDYdpwGhPf+espZn+LgTLPzPG2s=; b=NsQyjPIsqdBE1HvNAiCVYJbN2nI1Sj3xxfEnzOFM8u+ZmkSBY2cPf1uDWkZqdPYkP/ zfhIbfb+LkTGgp1aQYRKd1W0/8sMNCWKa5fY3kEFrIu6Y4JXk3Su+LmKGfSo2kQjD/Il neD1Qq41BSw/eyY1pmriroszP7xEmn76X76X7mx/bRjq1/QHbHN4uRiDAFl/pN7PiJfh Az6TJDvEYCC2blJnzHZiaR2JYYNN1ppElukl1Of6ufE46QvKm8Hhj+jfJ1mASdAmFVub EXzDBCaQoCD/8jTwgqt+6iYlibiOEIZ0wgRBTJQRxhumlJSZGgxCfJ6YXxJfF0I0QQMr Vk7g== X-Gm-Message-State: AOJu0YzEsGBRjZ77xXqYsVRVBZ7hSb0yKJf967x7YPhbu92n+Fxkd1th AuuNgqe4Wnx84aCxlJ0S4QMqMQj9K5kqLSSGQuZZzSHchLi6Sn9RvDv4oCQ6otxGEe7V515jG8n 1N1bqWl8= X-Gm-Gg: AR+sD12Ha59iMy6CFBO6OlhoWMO2r0INzIxbz1qJlMUj+ucgIAJJVv4y8eObiWOsKh9 p9GtamG5W6BtwsNOd54nwAgvpoVq4pkCgyBQihhriaeYW/Up4ytxJuMhkYUfbBZGkVXl1HSpjbi J3tv1O3WyMog1p/9Yf77EZS6oIKO8In1zOtRvPoL57mFrO9fxPqKNiPkWIextVVU/u4OkXH5nLW 1ECTyGIftOr1xn3uKBND1XkVrwreOTUFef2wXklMxsLCTyqTPwfRMj1scjB13ahaiANUdltlRcK qSH7q8CoJV7Meb35H5i9HjRoF1GXLJIJ4+z8kiyR678tCZ7sX8UsCvT9nKdR39iehWbi2xBAn4z KCJ3OUijI8WY5TLMoRzP4sVXFtZd9a0L6gRKUc6xrdfr7MaKhoqr2L/T4F0rEnj41ZuwF3UVcpK KmKJTamGd/PceI+Y+lgn/utEZXCFp0vRpQQIwFxBiP4q53+rFJX83XQgoyOXZLBL/kXUnietNs/ e5cIQ== X-Received: by 2002:a05:600c:8b08:b0:495:4df2:b8c1 with SMTP id 5b1f17b1804b1-496b5709b9amr57833345e9.35.1785054619122; Sun, 26 Jul 2026 01:30:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Date: Sun, 26 Jul 2026 10:29:40 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241998 From: Deepak Rathore Pick the upstream fix [1] for CVE-2026-34980 as mentioned in [2], where the scheduler did not filter control characters from option values. Also include the upstream regression fixes that followed the CVE fix: - CVE-2026-34980-regression_p1.patch [3] fixes filter PPD keyword processing. The CVE fix parsed PPD keywords into a temporary array, but the loop did not advance the keyword pointer. This regression was reported in OpenPrinting/cups Issue [4]. - CVE-2026-34980-regression_p2.patch [5] fixes a get_options() regression where the option-value parser did not advance the input pointer for whitespace/control-character paths. [1] https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3 [2] https://security-tracker.debian.org/tracker/CVE-2026-34980 [3] https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629 [4] https://github.com/OpenPrinting/cups/issues/1562 [5] https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 3 + .../cups/CVE-2026-34980-regression_p1.patch | 31 +++++++ .../cups/CVE-2026-34980-regression_p2.patch | 75 ++++++++++++++++ .../cups/cups/CVE-2026-34980.patch | 85 +++++++++++++++++++ 4 files changed, 194 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 5e272dbcf6b..7a8b845953c 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -25,6 +25,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-27447-regression_p2.patch \ file://CVE-2026-41079.patch \ file://CVE-2026-34978.patch \ + file://CVE-2026-34980.patch \ + file://CVE-2026-34980-regression_p1.patch \ + file://CVE-2026-34980-regression_p2.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch new file mode 100644 index 00000000000..483d695a93a --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch @@ -0,0 +1,31 @@ +From 3f2bdc293243bca938c6de23ba50e6d783189629 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 28 Apr 2026 17:42:41 -0400 +Subject: [PATCH] Fix filter PPD keyword processing (Issue #1562) + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629] + +(cherry picked from commit 3f2bdc293243bca938c6de23ba50e6d783189629) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 895b2d9..915ba94 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -5419,7 +5419,7 @@ update_job(cupsd_job_t *job) /* I - Job to check */ + keywords = NULL; + num_keywords = cupsParseOptions(message, 0, &keywords); + +- for (i = 0, keyword = keywords; i < num_keywords; i ++) ++ for (i = 0, keyword = keywords; i < num_keywords; i ++, keyword ++) + { + /* + * Filter out "special" PPD keywords... +-- +2.43.7 + + diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch new file mode 100644 index 00000000000..739938c9a59 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch @@ -0,0 +1,75 @@ +From da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Wed, 8 Apr 2026 16:42:48 -0400 +Subject: [PATCH] Fix get_options regression (Issue #1532) + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a] + +(cherry picked from commit da0ff58c041f7ee129c3c2c72fb14df1f1e4069a) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 4 ++-- + test/5.5-lp.sh | 10 +++++----- + 2 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 6b9d366..cf019e1 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4144,7 +4144,7 @@ get_options(cupsd_job_t *job, /* I - Job */ + case IPP_TAG_CHARSET : + case IPP_TAG_LANGUAGE : + case IPP_TAG_URI : +- for (valptr = attr->values[i].string.text; *valptr;) ++ for (valptr = attr->values[i].string.text; *valptr; valptr ++) + { + /* + * Convert tabs and newlines to spaces, filter out control chars, +@@ -4159,7 +4159,7 @@ get_options(cupsd_job_t *job, /* I - Job */ + { + if (strchr("\\\'\"", *valptr)) + *optptr++ = '\\'; +- *optptr++ = *valptr++; ++ *optptr++ = *valptr; + } + } + +diff --git a/test/5.5-lp.sh b/test/5.5-lp.sh +index 25e9d65..fe60890 100644 +--- a/test/5.5-lp.sh ++++ b/test/5.5-lp.sh +@@ -2,7 +2,7 @@ + # + # Test the lp command. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2019 by Apple Inc. + # Copyright © 1997-2005 by Easy Software Products, all rights reserved. + # +@@ -72,8 +72,8 @@ echo "" + + echo "LP Flood Test ($1 times in parallel)" + echo "" +-echo " lp -d Test1 testfile.jpg" +-echo " lp -d Test2 testfile.jpg" ++echo " lp -d Test1 -t 'Flood Test N' testfile.jpg" ++echo " lp -d Test2 -t 'Flood Test N' testfile.jpg" + i=0 + pids="" + while test $i -lt $1; do +@@ -83,9 +83,9 @@ while test $i -lt $1; do + j=`expr $j + 1` + done + +- $runcups $VALGRIND ../systemv/lp -d Test1 ../examples/testfile.jpg 2>&1 & ++ $runcups $VALGRIND ../systemv/lp -d Test1 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 & + pids="$pids $!" +- $runcups $VALGRIND ../systemv/lp -d Test2 ../examples/testfile.jpg 2>&1 & ++ $runcups $VALGRIND ../systemv/lp -d Test2 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 & + pids="$pids $!" + + i=`expr $i + 1` +-- +2.43.7 diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch new file mode 100644 index 00000000000..c38cc2c9e38 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch @@ -0,0 +1,85 @@ +From e206c7643a7574cab2e9457eac4c9f755dbf44ff Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:45:13 -0400 +Subject: [PATCH] Filter out control characters from option values. + +CVE: CVE-2026-34980 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3] + +Backport Changes: +- Rebase scheduler/job.c option-handling context to the CUPS 2.4.11 + source carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 8d0f51cac24cb5bf949c5b6a221e51a150d982e3) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 41 +++++++++++++++++++++++++++++++++++------ + 1 file changed, 35 insertions(+), 6 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 822a247..895b2d9 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4121,9 +4121,21 @@ get_options(cupsd_job_t *job, /* I - Job */ + case IPP_TAG_URI : + for (valptr = attr->values[i].string.text; *valptr;) + { +- if (strchr(" \t\n\\\'\"", *valptr)) +- *optptr++ = '\\'; +- *optptr++ = *valptr++; ++ /* ++ * Convert tabs and newlines to spaces, filter out control chars, ++ * and escape \, ', and ". ++ */ ++ ++ if (isspace(*valptr & 255)) ++ { ++ *optptr++ = ' '; ++ } ++ else if ((*valptr & 255) >= ' ' && *valptr != 0x7f) ++ { ++ if (strchr("\\\'\"", *valptr)) ++ *optptr++ = '\\'; ++ *optptr++ = *valptr++; ++ } + } + + *optptr = '\0'; +@@ -5394,13 +5409,30 @@ update_job(cupsd_job_t *job) /* I - Job to check */ + else if (loglevel == CUPSD_LOG_PPD) + { + /* +- * Set attribute(s)... ++ * Set PPD keyword(s)/value(s)... + */ + ++ int i, /* Looping var */ ++ num_keywords; /* Number of keywords */ ++ cups_option_t *keywords, /* Keywords */ ++ *keyword; /* Current keyword */ ++ + cupsdLogJob(job, CUPSD_LOG_DEBUG, "PPD: %s", message); + +- job->num_keywords = cupsParseOptions(message, job->num_keywords, +- &job->keywords); ++ keywords = NULL; ++ num_keywords = cupsParseOptions(message, 0, &keywords); ++ ++ for (i = 0, keyword = keywords; i < num_keywords; i ++) ++ { ++ /* ++ * Filter out "special" PPD keywords... ++ */ ++ ++ if (strcmp(keyword->name, "cupsFilter") && strcmp(keyword->name, "cupsFilter2") && strcmp(keyword->name, "cupsFinishingTemplate") && strcmp(keyword->name, "cupsIPPFinishings") && strcmp(keyword->name, "cupsIPPReason") && strcmp(keyword->name, "cupsMarkerName") && strcmp(keyword->name, "cupsMaxSize") && strncmp(keyword->name, "cupsMediaQualifier", 18) && strcmp(keyword->name, "cupsMinSize") && strcmp(keyword->name, "cupsPageSizeCategory") && strcmp(keyword->name, "cupsPortMonitor") && strcmp(keyword->name, "cupsPreFilter") && strcmp(keyword->name, "cupsPrintQuality") && strcmp(keyword->name, "APPrinterPreset")) ++ job->num_keywords = cupsAddOption(keyword->name, keyword->value, job->num_keywords, &job->keywords); ++ } ++ ++ cupsFreeOptions(num_keywords, keywords); + } + else + { +-- +2.43.7 From patchwork Sun Jul 26 08:29:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93517 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3DDB8C54F51 for ; Sun, 26 Jul 2026 08:30:22 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7385.1785054621367517200 for ; Sun, 26 Jul 2026 01:30:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VIVB7dZ7; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49553515a8bso20823605e9.1 for ; Sun, 26 Jul 2026 01:30:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054620; x=1785659420; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Gjq2aOZaq76IevpkTF/w1892rKfhTFgPax/xdbx00TY=; b=VIVB7dZ7Qh/J37heaTo6TKaLEN8QbnNIwRQQW0peGH9qp2M9XX9jWw41tLLrP9MxEC a0Nz3WTPdsWqLXKJA6CSyIjFj2OwoAr7OzwA4Gg/NyZtoSYtxBe6GFEVGh7xHXH/IVe1 YAxDi0zxWwT02jiE7F15mwd+iylUbatsSiItw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054620; x=1785659420; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Gjq2aOZaq76IevpkTF/w1892rKfhTFgPax/xdbx00TY=; b=VFu7T3uWhmbgYDXn2UMwfyAuzb7feSitdIMPf6bF1f/73pMvOiSDjvk90nASwwCKZy xPzxJK0j72OaU4qDNvsfk9Z8p2EyeUg6SiCFl1npj3Vp7Nhcvu//OFEKYYKwUcuUiTJJ pqeqIQgYjjG6A0R2J9E5CfyApyUzaaYtcVQ0/zuHBGd2tEpbA2/KDeKe76+V+swkMbXK AMdxxLbTjs1X/N3/HKHQey+YIfWHtQtQYglGJpNI7f8z0LeBmHQF23pMuNQxrnn0VEBC fzMFR/hiTrQMYqtktEuXDMOhL1VPyFegW0wI301oYANVU1fcU7daB4/aT8XzRWv3c0EU 8BjQ== X-Gm-Message-State: AOJu0YwSsTCo8fugfhizq0eNox1ZfXKDzFBangfwKx+JslzI3R6g2ZXt 5NKYOBhrdw2kEOaj43ONKSmuewhCkEI/TXSGAcEZMy5HIKqcN/0Gg1C1Mh8OGxMf8bRaBPZc4CY mqJsisws= X-Gm-Gg: AR+sD102Jq3gcIq5aadMlXzezOMnfXrmo3JHKQYUeH5YTVxBAxeroWFkMDh0oYgI2OT 0sdgFEOJqdh60sYrmCGDJ5pxSS/wglnIwJTiA4D5xrgEKvEJXhg7MGoQcOGvrtcJ5EwC39kwkLH O/qFI4dFbVeLSZ7PpiumHIbk9FIMcrH0QMb0ljVO33XidUtU3kjrLEw77t3GF1/Yu1w/N7pHg/u 6nYAb2ESX8IGP2LHPa2cjhF1O5nR6UzxYtlqdN9Ubjk14kM6qclaYNab/835jTtJSTlf7W2dxaz YIrbCRUd2p9rcg7ajs9ZLLqVJCa2h3zqmGfIi4oc3F2ZeAK96FVZ8kM8XTeY3Z5u+tEEWLoa88D FCGlU83z55FWT0UYvTQUmj8uu7zOtMzVcrnoSa1UUJyrJrrIE5d/6dsFlrUdaVpWx2KiS9Rnock AAFxoOnhpaMhjGKC54uAcZYvI15xGJYp53zgYA9T0TnGhUQNNbae7xG3EhYR9/po3vBfVVJHZ/k GpUfg== X-Received: by 2002:a05:600c:3b27:b0:495:3c6d:f294 with SMTP id 5b1f17b1804b1-496b5717d1bmr55835925e9.23.1785054619589; Sun, 26 Jul 2026 01:30:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Date: Sun, 26 Jul 2026 10:29:41 +0200 Message-ID: <7aaebb1682f0ea5f75860523efdef6fefda16307.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241999 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214 [2] https://security-tracker.debian.org/tracker/CVE-2026-34979 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34979.patch | 61 +++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 7a8b845953c..a0ac1a26129 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980.patch \ file://CVE-2026-34980-regression_p1.patch \ file://CVE-2026-34980-regression_p2.patch \ + file://CVE-2026-34979.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34979.patch b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch new file mode 100644 index 00000000000..38ac7b6e918 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch @@ -0,0 +1,61 @@ +From 471b4dc802455c7c59f9fd594fec8b6f3acb0db5 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 14:50:06 -0400 +Subject: [PATCH] Expand allocation of options string. + +CVE: CVE-2026-34979 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214] + +Backport Changes: +- Rebase scheduler/job.c IPP length context to the CUPS 2.4.11 source + carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 0ff8897367c7341f2500770c3977038cdd7c0214) +Signed-off-by: Deepak Rathore +--- + scheduler/job.c | 16 ++++------------ + 1 file changed, 4 insertions(+), 12 deletions(-) + +diff --git a/scheduler/job.c b/scheduler/job.c +index 915ba94..880c25f 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -4195,18 +4195,6 @@ ipp_length(ipp_t *ipp) /* I - IPP request */ + + for (attr = ipp->attrs; attr != NULL; attr = attr->next) + { +- /* +- * Skip attributes that won't be sent to filters... +- */ +- +- if (attr->value_tag == IPP_TAG_NOVALUE || +- attr->value_tag == IPP_TAG_MIMETYPE || +- attr->value_tag == IPP_TAG_NAMELANG || +- attr->value_tag == IPP_TAG_TEXTLANG || +- attr->value_tag == IPP_TAG_URI || +- attr->value_tag == IPP_TAG_URISCHEME) +- continue; +- + /* + * Add space for a leading space and commas between each value. + * For the first attribute, the leading space isn't used, so the +@@ -4282,10 +4270,14 @@ ipp_length(ipp_t *ipp) /* I - IPP request */ + + case IPP_TAG_TEXT : + case IPP_TAG_NAME : ++ case IPP_TAG_TEXTLANG : ++ case IPP_TAG_NAMELANG : ++ case IPP_TAG_MIMETYPE : + case IPP_TAG_KEYWORD : + case IPP_TAG_CHARSET : + case IPP_TAG_LANGUAGE : + case IPP_TAG_URI : ++ case IPP_TAG_URISCHEME : + /* + * Strings can contain characters that need quoting. We need + * at least 2 * len + 2 characters to cover the quotes and +-- +2.43.7 + From patchwork Sun Jul 26 08:29:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93535 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6C92FC54F52 for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7387.1785054622153149768 for ; Sun, 26 Jul 2026 01:30:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=07+xV6ER; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4954f5e8020so8179895e9.2 for ; Sun, 26 Jul 2026 01:30:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054620; x=1785659420; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R0X7Ctif6/N8INzFSkYb8md8POmgq3B8Q2CsT5NVkYQ=; b=07+xV6ERPSmzNjJuFFbQKe8WkJrxDJEYPTi5pveQ4fZfWMbyOY6R18VGM/Q1i3c0DY aUR/oMpKvSsPg1S6AHCVR4TGKNp+E2EDrsQ+Hy3WxQmgZYMbQvqDaAE96H/pZp8263R4 yvJYfio08qyzNDPJV7nXdmKRsbkCeV4MQwySE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054620; x=1785659420; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=R0X7Ctif6/N8INzFSkYb8md8POmgq3B8Q2CsT5NVkYQ=; b=b1R0wkJfTEu5n9FgOwx10LK+VGsAuaGMtet+D2neUo7hGu+ob1iGKRlkrm/cBKEeto qBmsprSPfrty3kcDXireiKc8wldik5uoXTJzZn2XArTjmONQdv0i4QO/FQhd7KrOaTUd po+QMch5427ShS6Wp/7PmmWMBttAL11tVbjqMdVT75BROxnZPGKZemJgNKkhZlUVb3xd omxjOFZJiKP430c2F8JeS6uk8CWDEJSzFIB+hfVMnHLSyNLnSoyFynm7TeC3WwMMmy7N KkH/oieuEres4LkhMwNqvGPInazdpAvf0cK2Vn0ZiwJYBak6hU86US8G3nJsfbhNbFow uN3g== X-Gm-Message-State: AOJu0YyCFugzRZAkmigzL/jEYi+28+MPE7U8OMnSj+QYC1FONKmMekuw XTffu+gBrWnSZa9o/UAg76xagES3L2HpHTR9y5f5BDRZ8Dtr/MtIKGZEir4iJpOIaGgdlfksVXH nAx3gbO4= X-Gm-Gg: AR+sD13/ty03UyEGMIO0RBpag743+51gCJpriLjUcBCRCRfQAe8TZ40AcM7wPKAmDax VFU0EYTV7BA4bE7eTx+edQBElHJXEzIFfV+hYvV/lDRRjnaoApgQAe39BIaEccPQXUKNj3okhwF FFvKnOzSyvb9O1mMR5V6iz7ZVaFTwM2JrK6is7LlrsLger9sT1DXsUAUidyG1vY0CUOr6bSY/Nh hV/bCJyF73CuiONS2H2E3KGIjICkibpiaL7kmEUdCJMX+YV6a+c9DeoPMiKUtKwNyJOXcbmGMXD z1w4nc6wRcMGhRRLvoElm2GunMg34MMSeCCq8+sJ0rGwL3yyUSZ5hP02cUbAz9fxfKLtRActUYg AhWKJ7yfPh4xzBTPBjGXbKTFa0Vgwx7ztaXcZ+F0wGer4fx6+P4lqTDM7WrUVmkrAPBZyOfKK1j I9puOAryvcR+lFfikBPSDp4zkyoavdxhKMNQJu9BV+ugldWnzrNTq+ENKp/4RL0HOG3OW0738Lj Uqn9Q== X-Received: by 2002:a05:600c:3b86:b0:495:665d:75df with SMTP id 5b1f17b1804b1-496b5719f90mr62668515e9.23.1785054620296; Sun, 26 Jul 2026 01:30:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Date: Sun, 26 Jul 2026 10:29:42 +0200 Message-ID: <5bf5d3da45fcc1494e5e6b3acf23880982518a7b.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242000 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356 [2] https://security-tracker.debian.org/tracker/CVE-2026-34990 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-34990.patch | 351 ++++++++++++++++++ 2 files changed, 352 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index a0ac1a26129..1cef1e71fe4 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -29,6 +29,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980-regression_p1.patch \ file://CVE-2026-34980-regression_p2.patch \ file://CVE-2026-34979.patch \ + file://CVE-2026-34990.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34990.patch b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch new file mode 100644 index 00000000000..0a8c0930657 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch @@ -0,0 +1,351 @@ +From 48648896ca7faa8f105eee7b7a8d86c42e0fa796 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Tue, 31 Mar 2026 15:55:50 -0400 +Subject: [PATCH] Don't allow local certificates over the loopback + interface, drop support for writing to plain files. + +CVE: CVE-2026-34990 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356] + +Backport Changes: +- Preserve the existing CVE-2025-61915 PeerCred disable guard while changing + localhost checks to AF_LOCAL. +- Keep the CUPS 2.4.11 empty device-uri validation path separate and add a + dedicated rejection for non-IPP/IPPS schemes instead of folding both checks + into one upstream condition. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit e052dc44da9d12adfbebc51de4975fbadb2ce356) +Signed-off-by: Deepak Rathore +--- + cups/auth.c | 30 ++++++-------------------- + scheduler/auth.c | 9 ++++---- + scheduler/client.c | 4 +-- + scheduler/ipp.c | 8 ++++++- + scheduler/job.c | 46 ++++++++++++++++++++++------------------- + test/4.2-cups-printer-ops.test | 6 ++--- + test/5.1-lpadmin.sh | 14 ++++++------ + 7 files changed, 56 insertions(+), 61 deletions(-) + +diff --git a/cups/auth.c b/cups/auth.c +index 5cb4194..14661c7 100644 +--- a/cups/auth.c ++++ b/cups/auth.c +@@ -1,7 +1,7 @@ + /* + * Authentication functions for CUPS. + * +- * Copyright © 2020-2024 by OpenPrinting. ++ * Copyright © 2020-2026 by OpenPrinting. + * Copyright © 2007-2019 by Apple Inc. + * Copyright © 1997-2007 by Easy Software Products. + * +@@ -92,7 +92,6 @@ static void cups_gss_printf(OM_uint32 major_status, OM_uint32 minor_status, + # define cups_gss_printf(major, minor, message) + # endif /* DEBUG */ + #endif /* HAVE_GSSAPI */ +-static int cups_is_local_connection(http_t *http); + static int cups_local_auth(http_t *http); + + +@@ -948,14 +947,6 @@ cups_gss_printf(OM_uint32 major_status,/* I - Major status code */ + # endif /* DEBUG */ + #endif /* HAVE_GSSAPI */ + +-static int /* O - 0 if not a local connection */ +- /* 1 if local connection */ +-cups_is_local_connection(http_t *http) /* I - HTTP connection to server */ +-{ +- if (!httpAddrLocalhost(http->hostaddr) && _cups_strcasecmp(http->hostname, "localhost") != 0) +- return 0; +- return 1; +-} + + /* + * 'cups_local_auth()' - Get the local authorization certificate if +@@ -967,13 +958,7 @@ static int /* O - 0 if available */ + /* -1 error */ + cups_local_auth(http_t *http) /* I - HTTP connection to server */ + { +-#if defined(_WIN32) || defined(__EMX__) +- /* +- * Currently _WIN32 and OS-2 do not support the CUPS server... +- */ +- +- return (1); +-#else ++#if !_WIN32 && !__EMX__ && defined(AF_LOCAL) + int pid; /* Current process ID */ + FILE *fp; /* Certificate file */ + char trc[16], /* Try Root Certificate parameter */ +@@ -998,7 +983,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + * See if we are accessing localhost... + */ + +- if (!cups_is_local_connection(http)) ++ if (httpAddrFamily(httpGetAddress(http)) != AF_LOCAL) + { + DEBUG_puts("8cups_local_auth: Not a local connection!"); + return (1); +@@ -1072,15 +1057,14 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + } + # endif /* HAVE_AUTHORIZATION_H */ + +-# if defined(SO_PEERCRED) && defined(AF_LOCAL) ++# ifdef SO_PEERCRED + /* + * See if we can authenticate using the peer credentials provided over a + * domain socket; if so, specify "PeerCred username" as the authentication + * information... + */ + +- if (http->hostaddr->addr.sa_family == AF_LOCAL && +- !getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */ ++ if (!getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */ + cups_auth_find(www_auth, "PeerCred")) + { + /* +@@ -1104,7 +1088,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + return (0); + } + } +-# endif /* SO_PEERCRED && AF_LOCAL */ ++# endif /* SO_PEERCRED */ + + if ((schemedata = cups_auth_find(www_auth, "Local")) == NULL) + return (1); +@@ -1164,7 +1148,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */ + return (0); + } + } ++#endif /* !_WIN32 && !__EMX__ && AF_LOCAL */ + + return (1); +-#endif /* _WIN32 || __EMX__ */ + } +diff --git a/scheduler/auth.c b/scheduler/auth.c +index 1dd520d..56855fc 100644 +--- a/scheduler/auth.c ++++ b/scheduler/auth.c +@@ -318,7 +318,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + } + #ifdef HAVE_AUTHORIZATION_H + else if (!strncmp(authorization, "AuthRef ", 8) && +- httpAddrLocalhost(httpGetAddress(con->http))) ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + OSStatus status; /* Status */ + char authdata[HTTP_MAX_VALUE]; +@@ -399,7 +399,8 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + #endif /* HAVE_AUTHORIZATION_H */ + #if defined(SO_PEERCRED) && defined(AF_LOCAL) +- else if (PeerCred != CUPSD_PEERCRED_OFF && !strncmp(authorization, "PeerCred ", 9) && +- con->http->hostaddr->addr.sa_family == AF_LOCAL && con->best) ++ else if (PeerCred != CUPSD_PEERCRED_OFF && ++ !strncmp(authorization, "PeerCred ", 9) && ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL && con->best) + { + /* + * Use peer credentials from domain socket connection... +@@ -483,7 +483,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */ + } + #endif /* SO_PEERCRED && AF_LOCAL */ + else if (!strncmp(authorization, "Local", 5) && +- httpAddrLocalhost(httpGetAddress(con->http))) ++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + /* + * Get Local certificate authentication data... +diff --git a/scheduler/client.c b/scheduler/client.c +index 779404c..dea9da0 100644 +--- a/scheduler/client.c ++++ b/scheduler/client.c +@@ -2173,7 +2173,7 @@ cupsdSendHeader( + strlcpy(auth_str, "Negotiate", sizeof(auth_str)); + } + +- if (con->best && !con->is_browser && !_cups_strcasecmp(httpGetHostname(con->http, NULL, 0), "localhost")) ++ if (con->best && !con->is_browser && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) + { + /* + * Add a "trc" (try root certification) parameter for local +@@ -2193,7 +2193,7 @@ cupsdSendHeader( + auth_size = sizeof(auth_str) - (size_t)(auth_key - auth_str); + + #if defined(SO_PEERCRED) && defined(AF_LOCAL) +- if (PeerCred != CUPSD_PEERCRED_OFF && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL) ++ if (PeerCred != CUPSD_PEERCRED_OFF) + { + strlcpy(auth_key, ", PeerCred", auth_size); + auth_key += 10; +diff --git a/scheduler/ipp.c b/scheduler/ipp.c +index b0d1f5b..11dcd39 100644 +--- a/scheduler/ipp.c ++++ b/scheduler/ipp.c +@@ -5561,7 +5561,7 @@ create_local_printer( + * Require local access to create a local printer... + */ + +- if (!httpAddrLocalhost(httpGetAddress(con->http))) ++ if (httpAddrFamily(httpGetAddress(con->http)) != AF_LOCAL) + { + send_ipp_status(con, IPP_STATUS_ERROR_FORBIDDEN, _("Only local users can create a local printer.")); + return; +@@ -5634,6 +5634,12 @@ create_local_printer( + + return; + } ++ else if (strncmp(ptr, "ipp://", 6) && strncmp(ptr, "ipps://", 7)) ++ { ++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad device-uri \"%s\"."), ptr); ++ ++ return; ++ } + + printer_geo_location = ippFindAttribute(con->request, "printer-geo-location", IPP_TAG_URI); + printer_info = ippFindAttribute(con->request, "printer-info", IPP_TAG_TEXT); +diff --git a/scheduler/job.c b/scheduler/job.c +index 880c25f..6c033de 100644 +--- a/scheduler/job.c ++++ b/scheduler/job.c +@@ -1164,35 +1164,39 @@ cupsdContinueJob(cupsd_job_t *job) /* I - Job */ + } + else + { ++ char scheme[32], /* URI scheme */ ++ userpass[32], /* URI username:password */ ++ host[256], /* URI hostname */ ++ resource[1024]; /* URI resource path (filename) */ ++ int port; /* URI port number */ ++ ++ httpSeparateURI(HTTP_URI_CODING_ALL, job->printer->device_uri, scheme, sizeof(scheme), userpass, sizeof(userpass), host, sizeof(host), &port, resource, sizeof(resource)); ++ + job->print_pipes[0] = -1; +- if (!strcmp(job->printer->device_uri, "file:/dev/null") || +- !strcmp(job->printer->device_uri, "file:///dev/null")) +- job->print_pipes[1] = -1; +- else ++ job->print_pipes[1] = -1; ++ ++ if (strcmp(resource, "/dev/null")) + { +- if (!strncmp(job->printer->device_uri, "file:/dev/", 10)) +- job->print_pipes[1] = open(job->printer->device_uri + 5, +- O_WRONLY | O_EXCL); +- else if (!strncmp(job->printer->device_uri, "file:///dev/", 12)) +- job->print_pipes[1] = open(job->printer->device_uri + 7, +- O_WRONLY | O_EXCL); +- else if (!strncmp(job->printer->device_uri, "file:///", 8)) +- job->print_pipes[1] = open(job->printer->device_uri + 7, +- O_WRONLY | O_CREAT | O_TRUNC, 0600); +- else +- job->print_pipes[1] = open(job->printer->device_uri + 5, +- O_WRONLY | O_CREAT | O_TRUNC, 0600); ++ if (!FileDevice) ++ { ++ abort_message = "Stopping job because file: output is disabled."; + +- if (job->print_pipes[1] < 0) ++ goto abort_job; ++ } ++ else if ((job->print_pipes[1] = open(resource, O_WRONLY | O_EXCL)) < 0) + { +- abort_message = "Stopping job because the scheduler could not " +- "open the output file."; ++ abort_message = "Stopping job because the scheduler could not open the output file."; + + goto abort_job; + } ++ else ++ { ++ /* ++ * Close this file on execute... ++ */ + +- fcntl(job->print_pipes[1], F_SETFD, +- fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC); ++ fcntl(job->print_pipes[1], F_SETFD, fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC); ++ } + } + } + } +diff --git a/test/4.2-cups-printer-ops.test b/test/4.2-cups-printer-ops.test +index 1a011e0..945a9bb 100644 +--- a/test/4.2-cups-printer-ops.test ++++ b/test/4.2-cups-printer-ops.test +@@ -1,7 +1,7 @@ + # + # Verify that the CUPS printer operations work. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2019 by Apple Inc. + # Copyright © 2001-2006 by Easy Software Products. All rights reserved. + # +@@ -180,7 +180,7 @@ + ATTR uri printer-uri $method://$hostname:$port/printers/Test2 + + GROUP printer +- ATTR uri device-uri file:/tmp/Test2 ++ ATTR uri device-uri file:///dev/null + ATTR enum printer-state 3 + ATTR boolean printer-is-accepting-jobs true + +@@ -206,7 +206,7 @@ + ATTR uri printer-uri $method://$hostname:$port/printers/Test1 + + GROUP printer +- ATTR uri device-uri file:/tmp/Test1 ++ ATTR uri device-uri file:///dev/null + ATTR enum printer-state 3 + ATTR boolean printer-is-accepting-jobs true + ATTR text printer-info "Test Printer 1" +diff --git a/test/5.1-lpadmin.sh b/test/5.1-lpadmin.sh +index aa39800..36f2822 100644 +--- a/test/5.1-lpadmin.sh ++++ b/test/5.1-lpadmin.sh +@@ -2,7 +2,7 @@ + # + # Test the lpadmin command. + # +-# Copyright © 2020-2024 by OpenPrinting. ++# Copyright © 2020-2026 by OpenPrinting. + # Copyright © 2007-2018 by Apple Inc. + # Copyright © 1997-2005 by Easy Software Products, all rights reserved. + # +@@ -12,8 +12,8 @@ + + echo "Add Printer Test" + echo "" +-echo " lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd" +-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1 ++echo " lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd" ++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +@@ -29,8 +29,8 @@ echo "" + + echo "Modify Printer Test" + echo "" +-echo " lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4" +-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4 2>&1 ++echo " lpadmin -p Test3 -v file:///dev/null -o PageSize=A4" ++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -o PageSize=A4 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +@@ -65,8 +65,8 @@ echo "" + + echo "Add a printer for cupSNMP/IPPSupplies test" + echo "" +-echo " lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd" +-$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd 2>&1 ++echo " lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd" ++$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd 2>&1 + if test $? != 0; then + echo " FAILED" + exit 1 +-- +2.43.7 From patchwork Sun Jul 26 08:29:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93531 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6121AC54F53 for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7388.1785054622919882709 for ; Sun, 26 Jul 2026 01:30:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TlYq+9qN; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4957eefd361so13244615e9.1 for ; Sun, 26 Jul 2026 01:30:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054621; x=1785659421; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=erc4Bm/eLdzJZu0ess4tcs/Bi/hr+AUxAIfpQGZq7vc=; b=TlYq+9qNBmu3c++N9H94HA0/fM3YqVQhgAUH49qUWzvg4WIus98xxmNXuy4tkkrfLZ vZs3cDGiqh/ufzOZ3Hvh6/KKPg0pR2LiWLTmZRCm5WADS+rVDZxbvRlaclZLW1nKzfWr KfkoX8DydlKdkK1KDz1qFrz++lv1diRHekCgI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054621; x=1785659421; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=erc4Bm/eLdzJZu0ess4tcs/Bi/hr+AUxAIfpQGZq7vc=; b=f16sghSUZjA4qxWb7OgAEnnVLiaIIpcPI86C51aBDc/OBtN1DWfKEXbHh+mZdGb6Rd 4++I7g9AQfrTA/22IUaSXn3lwDR9R478twqXIPPyWOV8PZMaiuBByaQJd5ciKU8LGBAv zCKjU17fVQqCY94nbVoj+mvh3sNquoQSDYGxJClN36R3CIz+VIvYpumLo5SFk0KLGiJb j7d0XTeFxK0QPMH0FFgKrGnSnnaS6YrPaC03Mo0/6zaPsa3uZW2wwVSjG/Wum1OZZIn3 Nv8Jzyt8Spg8n9qPKOan+xAuXTGocrpsuadsHCS5CtcVZVuda2NN2xY4TeFecITvhzXZ 58rg== X-Gm-Message-State: AOJu0YzZ2MFFg7ud2NcnDjGqIsKsmcZ5PMxpLFbItpM6JynFUb9LhWOU eXooHAA4LRQuQ4Qjg+07Hfbd5rpgMWrNXUMU+3roj7NrBloJ2IJgF12gf14D6RUOfGryd8g1+r6 O1Xtpxz8= X-Gm-Gg: AR+sD12CuD0q/zQm7VxuuLqy5VuFeuzsS5C3Pd8KyZ3mt68yjr38xUQWT8z87R8XktJ bVzaduiUKdA7XZQ2I9yWxAKhuccNQgUkF1GHxg+l9NIQVXyHXmDvbFWzdgQw2PoSAVJqOwNjGOr CCOgv9Hl8v73bQa5yhMdtd+vRzRnO9J40mjgAYwR1SVhPLCXvM6usFm+lkbuRRYPQr5RNXK5l2n /1VF6gfFB7pSrarSvDwCOjq9f0FpOGfUIbiBwyW7O3cxDif8ZXTfxKWbEiLOGm4JAvTfLAOKwOp wCpngPaUMgqnnLp2oL46O0+C20QitWyI62vj5UibhIGW7cE7dNjs1oy34eKNOwZUJz5/4VnSBAH btwFxmoIz9LTD1HUrX6VM59UrDNuBvQE4LNd+ilLeri45/mO8VX+cwlc8p1WTH0kDGKBpvt1tIl ORQwcQ3F677Cyl4yi0h3xfyWkeHPvAup8AKoi7O2S+62aHTqLywlsypq95y/DmZTkY9HVf8VVGe LTXZA== X-Received: by 2002:a05:600c:630d:b0:495:3da3:beb with SMTP id 5b1f17b1804b1-496b56f9dddmr61177165e9.10.1785054621147; Sun, 26 Jul 2026 01:30:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Date: Sun, 26 Jul 2026 10:29:43 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242001 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4 [2] https://security-tracker.debian.org/tracker/CVE-2026-39314 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-39314.patch | 45 +++++++++++++++++++ 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 1cef1e71fe4..575dbf9c577 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -30,6 +30,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34980-regression_p2.patch \ file://CVE-2026-34979.patch \ file://CVE-2026-34990.patch \ + file://CVE-2026-39314.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39314.patch b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch new file mode 100644 index 00000000000..f8d1a69f56e --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch @@ -0,0 +1,45 @@ +From 65c463ada188915d6700d92ce48a9a14949ca413 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Sun, 5 Apr 2026 10:45:25 -0400 +Subject: [PATCH] Range check job-password-supported. + +CVE: CVE-2026-39314 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4] + +Backport Changes: +- Rebase cups/ppd-cache.c context to the CUPS 2.4.11 source carried by + this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 928a86b1b794f738f0a3dc87561b2e054bff7ce4) +Signed-off-by: Deepak Rathore +--- + cups/ppd-cache.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/cups/ppd-cache.c b/cups/ppd-cache.c +index e750fcc..08e0db8 100644 +--- a/cups/ppd-cache.c ++++ b/cups/ppd-cache.c +@@ -1,7 +1,7 @@ + /* + * PPD cache implementation for CUPS. + * +- * Copyright © 2022-2024 by OpenPrinting. ++ * Copyright © 2022-2026 by OpenPrinting. + * Copyright © 2010-2021 by Apple Inc. + * + * Licensed under Apache License v2.0. See the file "LICENSE" for more +@@ -3432,7 +3432,7 @@ _ppdCreateFromIPP2( + * Password/PIN printing... + */ + +- if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL) ++ if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL && ippGetInteger(attr, 0) > 0) + { + char pattern[33]; /* Password pattern */ + int maxlen = ippGetInteger(attr, 0); +-- +2.43.7 + From patchwork Sun Jul 26 08:29:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93533 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 49BDDC54F51 for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7389.1785054623602304013 for ; Sun, 26 Jul 2026 01:30:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ib+WD3Tn; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-47db714766aso1407839f8f.0 for ; Sun, 26 Jul 2026 01:30:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054622; x=1785659422; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RethtmsdU4lVPBn5lrWQDY0ZPa09J5re8mxnygao03c=; b=Ib+WD3TnAJK3owKzeACBB301ny1GYomBmjOReXUtKP6iBDoGGsleFWnujma3nnmiXL Hh2hhBG0TK3sNC+imHvnZQTLpP55Eg3n9nhvjq8n98UDYvPPOQ0xhkstF1lprA/q+N4+ 8pxY9QKwPRao2zCjqvhLhb3slI/wQofzMVMtg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054622; x=1785659422; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RethtmsdU4lVPBn5lrWQDY0ZPa09J5re8mxnygao03c=; b=HSqqeq4Az/EKXjBoRJICWWQEE1KXnH4cFTezTU71hBZfnwcJtPm4WHMs0uPmnzfb3m Gl9snfa/dzm9WeaWktS+BUzhYv5RlAKPaNlpjMTXQQZjgGmy//zJCx6bnnmS2w71Pnwg VgGhhPMb5LXLk5rvLxMpc2n+VCLS2CqDaKIorx80aBk83E+qm0Sy4xm3E1C30be48lWk 2hBEd31Mh/rJ31VciF2M8MKPyP8Y/j+w2gzH5dhioMrIQu/aixadGsg60ZwlE86J6/eM 9SAy6WV66mAa4cqfb6ktt9kD2ERhYXNg+/HHSJCq8u9+Nosi054TEeNtaRoQMmudX76I X9vQ== X-Gm-Message-State: AOJu0Yy1sSChg4/0UUSbYErkw9/MRq6vZuhQAa14TwBiZj5uClfGKfHa E9zwqEEgzHO/rHv1JYViWXH8TKbPwDvkpJfzR40yy+LJtRzA482yT1H+0T6x6M9FnJ/DGGI6R95 nAmV3ZYc= X-Gm-Gg: AR+sD12NwfhRcrISClizsRKehexrWJzj2LNz6UIYDUCpfr+NCoIC9s0q8cOGwN7gX2g RUv6rP5uBHx+8zoAUyU+Un1H4fyPl7jlc8KU7Ff/O/xv7MYZ5Nm1maMq2BXG2U6dGvvP0nmgE0W eKt3vGuzRuZnE27CensZDNCLVOvURZMtcyBnpHOl606aaSDDodYtJ4xDHPk3tj3alyIYjuLa32m ecYHmF2mSEBlpAJu6yFr00DIBfj3YpdGbDcBKEfk2FarIBKSeHLe+bc1mI8TByKIeIm0TuMsUMz XOY4eZ/2VG8+13ZlYfu5y1OzI8LCjCetD7KuhM0XAtb3il1XtNEMfjhQifm4a1De4J/3fMp/ISV PxiOeu3VtlIFqjuHosSK+p0Xt/GRs7/nu5+sojAwz0b4apCfZqN7xNdceYH4aTCtCAi59YdjVRN JJE1UVRntZrltEhoonFP8VyCfsu4vGOVqpHDw0Vdzgq9BwJp1ZXO2MeOp871MLP/2/we6e5NJ/r fNRzQ== X-Received: by 2002:a05:600c:8b4c:b0:493:f783:c46a with SMTP id 5b1f17b1804b1-496b5b474e2mr53881705e9.6.1785054621885; Sun, 26 Jul 2026 01:30:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Date: Sun, 26 Jul 2026 10:29:44 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242002 From: Deepak Rathore Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f [2] https://security-tracker.debian.org/tracker/CVE-2026-39316 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-extended/cups/cups.inc | 1 + .../cups/cups/CVE-2026-39316.patch | 40 +++++++++++++++++++ 2 files changed, 41 insertions(+) create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc index 575dbf9c577..4c158aaee1b 100644 --- a/meta/recipes-extended/cups/cups.inc +++ b/meta/recipes-extended/cups/cups.inc @@ -31,6 +31,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \ file://CVE-2026-34979.patch \ file://CVE-2026-34990.patch \ file://CVE-2026-39314.patch \ + file://CVE-2026-39316.patch \ " GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases" diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39316.patch b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch new file mode 100644 index 00000000000..d3c9edf9745 --- /dev/null +++ b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch @@ -0,0 +1,40 @@ +From 7c4d7951d189e931563f21086196d5a55fb2fa15 Mon Sep 17 00:00:00 2001 +From: Michael R Sweet +Date: Sun, 5 Apr 2026 11:33:23 -0400 +Subject: [PATCH] Expire per-printer subscriptions before deleting. + +CVE: CVE-2026-39316 +Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f] + +Backport Changes: +- Rebase scheduler/printers.c delete-printer context to the CUPS 2.4.11 + source carried by this recipe. +- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata + carries the CVE details and the target source release-note sections differ. + +(cherry picked from commit 0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f) +Signed-off-by: Deepak Rathore +--- + scheduler/printers.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/scheduler/printers.c b/scheduler/printers.c +index bf493a3..ca983f9 100644 +--- a/scheduler/printers.c ++++ b/scheduler/printers.c +@@ -641,6 +641,12 @@ cupsdDeletePrinter( + update ? "Job stopped due to printer being deleted." : + "Job stopped."); + ++ /* ++ * Expire subscriptions on the printer... ++ */ ++ ++ cupsdExpireSubscriptions(p, /*job*/NULL); ++ + /* + * Remove the printer from the list... + */ +-- +2.43.7 + From patchwork Sun Jul 26 08:29:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93534 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E306C54F4E for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7390.1785054624195630509 for ; Sun, 26 Jul 2026 01:30:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=CPB/bnTu; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4957eefd361so13244685e9.1 for ; Sun, 26 Jul 2026 01:30:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054622; x=1785659422; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pqFAVZsMIpoCtO9fRRVf5N6nZbeNC9bExTuzcvnepJc=; b=CPB/bnTu2m+uWrEgm2RRnnezf4JLXjfRVvuSophznrDjKJGdL+JtQ3QTzp6n8MmaHB t/IeCrVTqdDrfehzViBCa8zgYbRW/gPx3ZMA4QbBaFFqA8IFePw2g72kJuVlBVhZM8R0 7Q2ui0avlrCf7yCoHLMuSKqIqMvK1/LKX6idw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054622; x=1785659422; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pqFAVZsMIpoCtO9fRRVf5N6nZbeNC9bExTuzcvnepJc=; b=i6qQfKLSQ2K4OW8Db22NpU4pG89SYI1VECjDIQtroOU6JFXjVcL7xtpHKphKjt4NtY Jqh7K9BKO2FUlfdPrDmqPTstjy1zQK0swy0A+80nmCuYwZG+5EyQgSDrzwhky3jKLZbS BFC6F5QrqKc7pILkgD9533Q2HrZ0Yz0vl1D/Rv+t5WumQGFoQY9Wyw9bsQ9un1hj9a4n 1Kqtx+e1gqDVm6vTwLdMZ7H8CW52oFN2qmgLuU7/2N0gjcsy65mwFL9ETycsQRRFyndq 5lhukCBJzfdSK3eBH2wlMwGsgU++A4AbazDHdhjwYhtsm7HQniAiZtUV/0vpTGQvRonF 3oBA== X-Gm-Message-State: AOJu0Ywdh+iyMOKAVtw0cL22OuCDjvr27/oO76wplBV4Fmm0xz/i+Iqd 04Zbj/nWSaTjarkngJdqKa6xqFqfB3nZS2HW76UzPbR8AkDYRSeOxrISB4ji01POyr+XMG3ZHm2 UuREAriI= X-Gm-Gg: AR+sD1344fwJSY2Vg0AS5ZVeOVtdI1HOttKwiM2Xe6bOTqHxl60/sTyrzlfudd0VPCL lH7eBdac7khexqzL6VKKGRcHngGQTaLh1DT/Emn7LBwvvIX/eYfD4tDO8J7yrbNOsQSLz9bECjg iN7L2FwdmW1wIScvUbj6qgWYXeJsrP26d+RvdG7PWT713W5FOanpdHjY+SjttTPZnVWz/9lRpGh uedzGc23qebram3gMcVgZsE8G2LBdmNag1vnzu2LRwFvEpdJJ0WWOI0erA9DPoOk7MzHLBS1JFu d15dQV0rWANhueyrs6v5KwHhhBrc8HUBbIQKw8VvGKu5nUJKSnVq/x3vA8cXy05Zuy3rO6UXE9x +OFWo877BA5KM2PwXVbbux7oci/VH0F+EAZ2XhU0DaWuDm/JwQBIeXUb48QsvjBrfvDA1NpohSW ztFwD6zYg4jLy/MgNptTOdaFl6hltW8su+LAa32aYj7yqSumlxqOCjb9jqZkk6mXWoD2VEMuo6O 2TxAw== X-Received: by 2002:a05:600c:4593:b0:493:bd2a:93bb with SMTP id 5b1f17b1804b1-496b56f0fb5mr57457985e9.3.1785054622372; Sun, 26 Jul 2026 01:30:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Date: Sun, 26 Jul 2026 10:29:45 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242003 From: Enoch Ng Backport the upstream fix for CVE-2026-4367, in which the `xpmNextWord()` function could attempt to read beyond the file's end due to improper validation of file boundaries. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4367 Signed-off-by: Enoch Ng Signed-off-by: Yoann Congal --- ...67-Out-of-bounds-read-in-xpmNextWord.patch | 140 ++++++++++++++++++ .../xorg-lib/libxpm_3.5.17.bb | 1 + 2 files changed, 141 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch diff --git a/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch new file mode 100644 index 00000000000..e9989a5012c --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch @@ -0,0 +1,140 @@ +From 5448e1bd7252780b16db869c2253d24e0fe0ae18 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Tue, 17 Feb 2026 11:59:56 +0100 +Subject: [PATCH libXpm] Fix CVE-2026-4367: Out-of-bounds read in xpmNextWord() + +xpmNextWord() checks for the terminator character to detect the end of +the file, but a very small malformed XPM file may cause the function to +read past the end of the buffer, causing out-of-bound reads: + + == Invalid read of size 1 + == at 0x48AD3A4: xpmParseColors (parse.c:239) + == by 0x48AF9D8: xpmParseData (parse.c:783) + == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101) + == by 0x4005A6: main () + == Address 0x4c413bf is 0 bytes after a block of size 15 alloc'd + == at 0x4841B26: malloc (vg_replace_malloc.c:447) + == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96) + == by 0x400554: main () + == + == Invalid read of size 1 + == at 0x48AC8D5: xpmNextWord.constprop.0 (data.c:262) + == by 0x48AD492: xpmParseColors (parse.c:266) + == by 0x48AF9D8: xpmParseData (parse.c:783) + == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101) + == by 0x4005A6: main () + == Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd + == at 0x4841B26: malloc (vg_replace_malloc.c:447) + == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96) + == by 0x400554: main () + == + == Invalid read of size 1 + == at 0x48AC965: xpmNextWord.constprop.0 (data.c:265) + == by 0x48AD492: xpmParseColors (parse.c:266) + == by 0x48AF9D8: xpmParseData (parse.c:783) + == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101) + == by 0x4005A6: main () + == Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd + == at 0x4841B26: malloc (vg_replace_malloc.c:447) + == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96) + == by 0x400554: main () + +The problem actually comes from xpmNextString() and xpmParseColors(): + +1) xpmNextString() checks for the NULL terminator when looking for the + end of the string (Eos) but not when looking for the beginning of the + next string (Bos). + +2) xpmParseColors() does not check the return value from xpmNextString() + and continues even when xpmNextString() raised an invalid XPM file. + +To avoid the issue, fix xpmNextString() to check for the NULL string +terminator when looking for the beginning of the next string and fix +xpmParseColors() to stop when xpmNextString() reported an invalid XPM +error. + +CVE-2026-4367 + +This vulnerability was discovered by: +Naoki Wakamatsu + +v2: Fix the XPM 1 code path the same. + +Signed-off-by: Olivier Fourdan +Part-of: + +CVE: CVE-2026-4367 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd7252780b16db869c2253d24e0fe0ae18] +Signed-off-by: Enoch Ng + +--- + + src/data.c | 3 +++ + src/parse.c | 19 ++++++++++++++----- + 2 files changed, 17 insertions(+), 5 deletions(-) + +diff --git a/src/data.c b/src/data.c +index 6e87455..a2b4acc 100644 +--- a/src/data.c ++++ b/src/data.c +@@ -210,6 +210,9 @@ xpmNextString(xpmData *data) + while ((c = *data->cptr++) && c != data->Bos && c != '\0') + if (data->Bcmt && c == data->Bcmt[0]) + ParseComment(data); ++ ++ if (c == '\0') ++ return XpmFileInvalid; + } else if (data->Bcmt) { /* XPM2 natural */ + while (((c = *data->cptr++) == data->Bcmt[0]) && c != '\0') + ParseComment(data); +diff --git a/src/parse.c b/src/parse.c +index cd923f9..268954d 100644 +--- a/src/parse.c ++++ b/src/parse.c +@@ -216,7 +216,9 @@ xpmParseColors( + + if (!data->format) { /* XPM 2 or 3 */ + for (a = 0, color = colorTable; a < ncolors; a++, color++) { +- xpmNextString(data); /* skip the line */ ++ ErrorStatus = xpmNextString(data); /* skip the line */ ++ if (ErrorStatus != XpmSuccess) ++ goto error; + + /* + * read pixel value +@@ -314,7 +316,9 @@ xpmParseColors( + /* get to the beginning of the first string */ + data->Bos = '"'; + data->Eos = '\0'; +- xpmNextString(data); ++ ErrorStatus = xpmNextString(data); ++ if (ErrorStatus != XpmSuccess) ++ goto error; + data->Eos = '"'; + for (a = 0, color = colorTable; a < ncolors; a++, color++) { + +@@ -354,7 +358,9 @@ xpmParseColors( + /* + * read color values + */ +- xpmNextString(data); /* get to the next string */ ++ ErrorStatus = xpmNextString(data); /* get to the next string */ ++ if (ErrorStatus != XpmSuccess) ++ goto error; + *curbuf = '\0'; /* init curbuf */ + while ((l = xpmNextWord(data, buf, BUFSIZ))) { + if (*curbuf != '\0') { +@@ -378,8 +384,11 @@ xpmParseColors( + memcpy(s, curbuf, len); + color->c_color = s; + *curbuf = '\0'; /* reset curbuf */ +- if (a < ncolors - 1) /* can we trust ncolors -> leave data's bounds */ +- xpmNextString(data); /* get to the next string */ ++ if (a < ncolors - 1) { /* can we trust ncolors -> leave data's bounds */ ++ ErrorStatus = xpmNextString(data); /* get to the next string */ ++ if (ErrorStatus != XpmSuccess) ++ goto error; ++ } + } + } + *colorTablePtr = colorTable; diff --git a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb index 8e15ecc0d48..9d1dd477429 100644 --- a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb +++ b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb @@ -22,6 +22,7 @@ PACKAGES =+ "sxpm cxpm" FILES:cxpm = "${bindir}/cxpm" FILES:sxpm = "${bindir}/sxpm" +SRC_URI += " file://0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch" SRC_URI[sha256sum] = "64b31f81019e7d388c822b0b28af8d51c4622b83f1f0cb6fa3fc95e271226e43" BBCLASSEXTEND = "native" From patchwork Sun Jul 26 08:29:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93530 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27119C54F50 for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7149.1785054624597975336 for ; Sun, 26 Jul 2026 01:30:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=g1DNM4X1; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49550ec592cso17330825e9.0 for ; Sun, 26 Jul 2026 01:30:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054623; x=1785659423; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=QqtCAIPnnYO0cq/IU7Ir7Gk6NgzmGizJs0CRYuWp4Pc=; b=g1DNM4X1ZSa4UsGGnhAuRJJshBerhLXD39/l6jVD8EvhBvP0D2u3FhiXDpflxO1bQ+ wi7jG5ywVdiBzNpluP9vripoBTHWKWWCYZF1IsDvhMyCHgLe169Pcy95ZMEI8IaQe719 PESEcAqCCC0grVDjYmlDaAf+1gVuL5XDp0kk4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054623; x=1785659423; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QqtCAIPnnYO0cq/IU7Ir7Gk6NgzmGizJs0CRYuWp4Pc=; b=Z9NEJDD/sYBkYopGhHJ7TFM2zniYariOhVD46IP1x2hGHkeTwC0PCB83XL3dW9ssBL 4eTfJtj1RsZfgfp3QQZ0tIdIYpfXg38lydxBfTp8HfWm4Yy6v08xKrISmIiJirdp7z+E jE305zFMsCpoiPjhHLoC1+5qHQjYSwU2cixzjG8OqQj/f/7m2J70Lyt/wvLOd20lG9y8 V3UGdxJAuuqXijMOh6OG0o4roAV+NGrylFltJ53Ai55vRmfYIT3U5MiQcYo21oxQX0e8 axdjRi17egpNxCWf7Mh+s030PUo+dPC6Ba+ml92ytdXI0ZPNpGKKswfGjxfYsy4hZFSZ ikGQ== X-Gm-Message-State: AOJu0YyENkf2ds3cv2jrNy9oDqHcMwih3X0SoShkhAeizGQDAEdLrRgM x4GT7OIF9PPRwkjSYSXibh9LgHVHXBnzChzISh7/dZtOUfdUTxiInb8uNWtpOnIHLspnwks7QKw RCmRFT3E= X-Gm-Gg: AR+sD13MGaqMu6v6AO9d1qX1P8fsZu7XeTXjsVsQnsENygMBJYfuVXGQ62dgKQR75tz IYKO7ry1IjWeRtN5fUI6d7ir0yaCbR/KQJiiICYzMX5aadtsjUbCZf1oRj96XxdmYvL/Qhvs7Mo kzr4n0U6Nc9GODK3Q75vu72y+CaBkGUY9TsiR8mCe7L676bn8apNPaUHixEp8gor3Xpjy7iLd1A C45hE5V9A/clUivVOAnEkUh639/DZb2Tvc+6ZZgAMZtLIGWaHZ4IdwBHF5e2XqpVrVHY/HfFheJ wHLGdGfZp+098qk0IOx53905EwdkcJ4teUMGjSShfBgwMSWbuZRRxoR/YPyDqDvaXy4w88ywshF VlUW/pR02GxBFAQ2IE1oOKmK7irFJJ45uSLyMLcA7X05iCqjJ4+D/xSAnq3yTSNdLNMqZHT+sY4 UpDYzCcVuLibhQgq2yNqjvGZ47LSpI101e1ceNvt+K1cFSGhKJdmOTxIP27NhpNTNoKFIv14SBY 1Vd7A== X-Received: by 2002:a05:600c:3150:b0:495:4f84:7280 with SMTP id 5b1f17b1804b1-496b5b3b1d4mr58204125e9.4.1785054622798; Sun, 26 Jul 2026 01:30:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Date: Sun, 26 Jul 2026 10:29:46 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242004 From: Sudhir Dumbhare Analysis: - CVE-2026-3832 affects GnuTLS OCSP multi-record response handling. - The vulnerable OCSP response handling code was introduced in GnuTLS 3.8.8. - This vulnerable code is not present in the current GnuTLS 3.8.4. - Hence ignoring the CVE for this version. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3832 https://security-tracker.debian.org/tracker/CVE-2026-3832 https://gitlab.com/gnutls/gnutls/-/issues/1801 Signed-off-by: Sudhir Dumbhare Signed-off-by: Yoann Congal --- meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index ccb6a2b4b2d..6d43c58df27 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -124,3 +124,5 @@ pkg_postinst_ontarget:${PN}-fips () { ${bindir}/fipshmac ${libdir}/libhogweed.so.6.* > ${libdir}/.libhogweed.so.6.hmac fi } + +CVE_STATUS[CVE-2026-3832] = "fixed-version: vulnerable multi-record OCSP response handling was introduced in 3.8.8 and is not present in 3.8.4" From patchwork Sun Jul 26 08:29:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93532 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 18310C54F4D for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7392.1785054624995953218 for ; Sun, 26 Jul 2026 01:30:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Hp1XAQnp; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4954a9e8490so13930165e9.1 for ; Sun, 26 Jul 2026 01:30:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054623; x=1785659423; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0KZWUW8CeyYBBfN8dtrvRBiaYH3zE9X3K1gIXRZXtHo=; b=Hp1XAQnpbZSvQSntgn0VI4Tyn8LRy3RIROCsASGrIE8x16F5ifOr0ZxZIw08NBcYjr rMgzCJneiQP/RB8FMSeZCtz4kRC4bvyesTtcaV5by+fHtNKV0vUWOZnBcuqAGUK/qnAs 4JVN+F+Q2pYBVx8EY2CD8Ub0bUyAbP4dKc61s= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054623; x=1785659423; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0KZWUW8CeyYBBfN8dtrvRBiaYH3zE9X3K1gIXRZXtHo=; b=jF6QntyHKwh6CFqNYgW/fdx4Gahe7kOV1RiPOYeC6Zkhcy8kVNEpUEX4JtvD2d0ezl 1RmiTiYLhI3JuJwgdhbnLBeDi00mOjUnOKBZ9F+g2KXeOTmQkj2aKZI+tr3u7w8b40Mn LanFp0sQFn2qFLg3dVsYAFa/SgABSW0/aUz5pOTRoCmQII3xKJ9S5SryY/77dKVBv6QZ DJUY90lPwU8TssrM5DdZY+wtySQcycOvm4GmpHmHnqp/qhEfNbDXXwifUGYkGQUn9hjg hMo8P88SQiPu/JbXjHls5mjRG8Z3Z1QaUcLv7WpuMdywK0I7J06ugLNpQnPdMOWeU/jV gTXw== X-Gm-Message-State: AOJu0YwD2zjb5cVbm3raCk3iOMNZEyHgOR7l4dusxLwrjgggm343N/Ju OWFAxRDKnpaUb1OgQ74TtjEI6Q2cxDshwgY5j1/qZ7iBCmjiWlvpkyVHhyPz4+mpmzWCV2mHDdy X6UcnPgs= X-Gm-Gg: AR+sD10K4bxpdYkPez+OuIWRf8JCXksX7pTaC+novno3tWASKIoW1viF9LUjhFntv7+ XlYfQ85QxEKoeHxRFL3oTTSb5u1oUkBPH1yeMi4+8aG2MUdonRDZAOlqqsI1+S/qxuuDIXIYGvj 6aKoUN1A/Kg77cIZeKGS0imh//qoXoAriroAjEOVQDncA3/3X4caZdJvqyilgX4WQPjJrGOwozu ldPFyQcu0npDssh4cxLrB3lmiuR9RvRRZjRzpUCZ04kkm5p9XLQTtAUTlZrQRR2V2LbtGNdStYI tghT0C8aiXF2b65tUl29sqdXTcahYI4K9P6DY+4wRfzxrCOehSFQhSk2+EyJm4SYEsThH/+ALI/ H2KfFKTwmPN4Q7aKtw+B+Vy8MqC/4hkFPXLfYeI+YJss6I6ILIdfyd3pGkI19oZojq9sTobCSXj dcnnXmj8sb5p/XOgfKdkbbpVvn2bHyEmtyuW4kmqV22GhfEovks7LdVG+rlFnFryFgwtt1lVDZk L8lXw== X-Received: by 2002:a05:600c:5253:b0:495:7016:b875 with SMTP id 5b1f17b1804b1-496b5c7ca38mr52350265e9.13.1785054623207; Sun, 26 Jul 2026 01:30:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Date: Sun, 26 Jul 2026 10:29:47 +0200 Message-ID: <8f3c2010a6bb4b2e7f4508a3ea4c2717294d75a3.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242005 From: Sudhir Dumbhare This patch applies the upstream fix [1] and [2], as referenced in [3], to address a DTLS packet reordering flaw where duplicate sequence numbers could lead to unstable ordering or undefined behavior. [1] https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d [2] https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f [3] https://security-tracker.debian.org/tracker/CVE-2026-42009 Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42009 Signed-off-by: Sudhir Dumbhare Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42009_p1.patch | 66 +++++++++++++++++++ .../gnutls/gnutls/CVE-2026-42009_p2.patch | 47 +++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 + 3 files changed, 115 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch new file mode 100644 index 00000000000..03214bab0ea --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch @@ -0,0 +1,66 @@ +From e1f366666c12f431151a04ada9cf9a30d602751b Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 21 Apr 2026 16:52:48 +0200 +Subject: [PATCH] lib/buffers: ensure packets have differing sequence + numbers + +There should normally be no packets with same sequence number and +differing handshake type, unless an adversary crafts them. +Discarding them allows to get rid of packets +with duplicate sequence ID in the buffer, +relieving us from the question of how to sort them later. + +CVE: CVE-2026-42009 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d] + +Backport Changes: +- Adjusted the upstream hunk to match the GnuTLS 3.8.4 code layout. +- The upstream commit uses the local recv_buf alias introduced later + in v3.8.13 by commit; + https://gitlab.com/gnutls/gnutls/-/commit/9deffca528c23bbb218f5ec3bd4bb1bf4cbd1fc0. +- GnuTLS 3.8.4 does not have that local recv_buf alias in + merge_handshake_packet(), so the backport replaces recv_buf[i] with the + existing session->internals.handshake_recv_buffer[i] access pattern. + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1848 +Fixes: CVE-2026-42009 +Fixes: GNUTLS-SA-2026-04-29-2 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin +(cherry picked from commit f01e21441e29052a6f0963840794c41d3b3ee66d) +Signed-off-by: Sudhir Dumbhare +--- + lib/buffers.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index 672380b054..e7f08b5625 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -968,8 +968,20 @@ static int merge_handshake_packet(gnutls_session_t session, + int ret; + + for (i = 0; i < session->internals.handshake_recv_buffer_size; i++) { +- if (session->internals.handshake_recv_buffer[i].htype == +- hsk->htype) { ++ if (session->internals.handshake_recv_buffer[i].sequence == hsk->sequence) { ++ if (session->internals.handshake_recv_buffer[i].htype != hsk->htype) { ++ _gnutls_audit_log( ++ session, ++ "Discarded unexpected handshake packet " ++ "with duplicate sequence %d, but " ++ "mismatched type %s (previously %s)\n", ++ hsk->sequence, ++ _gnutls_handshake2str(hsk->htype), ++ _gnutls_handshake2str( ++ session->internals.handshake_recv_buffer[i].htype)); ++ _gnutls_handshake_buffer_clear(hsk); ++ return 0; ++ } + exists = 1; + pos = i; + break; +-- +2.35.6 + diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch new file mode 100644 index 00000000000..b26491840b5 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch @@ -0,0 +1,47 @@ +From 23fdcec4c6b5669296295ad3a9f87f6467eeb0f3 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Tue, 21 Apr 2026 18:11:39 +0200 +Subject: [PATCH] buffers: fix handshake_compare when sequence numbers + match + +The comparator function used for ordering DTLS packets +by sequence numbers did not follow qsort comparator contracts +in case of packets with duplicate sequence numbers, +which could lead to unstable ordering or undefined behaviour. +Returning 0 in such cases makes the sorting stable. + +CVE: CVE-2026-42009 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f] + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1848 +Fixes: CVE-2026-42009 +Fixes: GNUTLS-SA-2026-04-29-2 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Joshua Rogers +(cherry picked from commit f341441fad91142897d83b44a175ffc8f925b76f) +Signed-off-by: Sudhir Dumbhare +--- + lib/buffers.c | 6 +----- + 1 file changed, 1 insertion(+), 5 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index e7f08b5625..1ac27e4e96 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -844,11 +844,7 @@ static int handshake_compare(const void *_e1, const void *_e2) + { + const handshake_buffer_st *e1 = _e1; + const handshake_buffer_st *e2 = _e2; +- +- if (e1->sequence <= e2->sequence) +- return 1; +- else +- return -1; ++ return (e1->sequence < e2->sequence) - (e1->sequence > e2->sequence); + } + + #define SSL2_HEADERS 1 +-- +2.35.6 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 6d43c58df27..d27d2cfa748 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -43,6 +43,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2025-14831-7.patch \ file://CVE-2025-14831-8.patch \ file://CVE-2025-14831-9.patch \ + file://CVE-2026-42009_p1.patch \ + file://CVE-2026-42009_p2.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b" From patchwork Sun Jul 26 08:29:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93536 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C84AC54F40 for ; Sun, 26 Jul 2026 08:30:33 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7394.1785054626029761816 for ; Sun, 26 Jul 2026 01:30:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0PtHKdVv; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49550ec592cso17330925e9.0 for ; Sun, 26 Jul 2026 01:30:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054624; x=1785659424; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0OlOHcbm0WYtMyvhwXY5bUJOM3LPTYUkaxXJw2a1PAg=; b=0PtHKdVv09yKgVjVoO6UT3U5pnVi/N5Vv4GMhTj/54JkZeB5st/ozecws3ePrCsvu2 eijU8Jd7h+6sIMN0JPIxxgik8yTXvIuGT+yvyrg9VmGS/DuSG63NZk3Nfsqg7aX3djE8 2qlfVOHzXKO/f1TE9VgXSsyMq50YVyC3Jxcjg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054624; x=1785659424; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0OlOHcbm0WYtMyvhwXY5bUJOM3LPTYUkaxXJw2a1PAg=; b=GNyzGo09QDud0A/PtAiA4qrUPtPxi3ArdWq+mKcdu0fCinfIWhIuTOB8f1cRj8/FoG MfOODg6uQugWMZuzcU4VU7RefjGtqBnMqlBNEMQYAwtHKHsaWQQBJc8Y5zMFyLRcI3da mRmhlV9MV9E18nViJi5RxwAWYjeBbfljWvREwChGVzSXzk+wmH+9bwv9qwET4FMViv8i JOzJhQUzkk+5zI9EjgGTd6QK73+/5cwYZcif3Uk+YmkvfPjRbeUa7mbNtBUYsZm8lrfU FY7D91+wf6XPWKYYx0U5H5q1IYVHaKb/PzlCdimvAhnmpC00htKFiDdUGPTEm1CKulW4 lVfw== X-Gm-Message-State: AOJu0YxlCpxEDP5bdcfAYmMELcLIFaTrYq4qwdc0/Lgn1zJkkFwjq0ZI 0lvL7cvTLtOBnnjxLcfn5LILu6g2jT5uQcx+X6tueLCr3SiOWhmzSkoprpCrQvXKe+Kop4g2jhU 5IpRNWj8= X-Gm-Gg: AR+sD11xrJyEFmLtsHmAfo9PSUqCcrLzVCPW7osuqAl619cW/993VilXof830V/fVwv TOo4NrPh2MlAuB+nHrXu2CZPtKB5bL6YMYcld0y7C/S89YBI2P0uvy3j1Z/QKbJh0CcjT1evFo/ uBNlwkvqEWc7CHBCLQRLNYfm0K6thOnw9BqK8rd28SqtcodtJ/gCxdBUhFaNTRDgchgyQx8Y/GS vsToyz+iGIiptU7lL3B6gm347k+oRmetAgqYtZSLfm/6u2AuWsOF7wfOfMQk+4wjpQfxdIlMPut LswbxFNXYMImta123qOPiFgAp9zDt11OuhQe2r+C/srDMhI2GB0BuTEwwE7tWKUrsZiK4Wdfg6Q 3TQClBU8q0ZFW/irxeZzsOWHQvkcbnppf6rdlUhXbYdlb6Nxon2M+Y7Qdb8DTLv4CojDn+mCm+t nPVwnQ6ITseemFxa3Ub8F6qkugPgNHDm7yWG5LfLMLvV5C07K0waZjGCTw7TXPLTcZeF8KM5zqt gy7Y3EkS4O7/ocJ X-Received: by 2002:a05:600c:4444:b0:495:6b4c:fccc with SMTP id 5b1f17b1804b1-496b5c7182amr50509995e9.10.1785054623852; Sun, 26 Jul 2026 01:30:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Date: Sun, 26 Jul 2026 10:29:48 +0200 Message-ID: <392fb4216357fd4eefb6abe3788414f2e60b0889.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242006 From: Sudhir Dumbhare These patches apply the upstream fixes [1][2], which address getter-to-setter aliasing issues in libpng chunk setters that could cause stale-pointer reads, as described in [3]. [1] https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a [2] https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc [3] https://github.com/pnggroup/libpng/issues/836 Reference: https://security-tracker.debian.org/tracker/CVE-2026-34757 https://nvd.nist.gov/vuln/detail/CVE-2026-34757 Test results on qemux86-64 using ptest-runner: START: ptest-runner 2026-06-04T11:29 BEGIN: /usr/lib/libpng/ptest PASS: tests/pnggetset Testsuite summary # TOTAL: 33 # PASS: 33 # SKIP: 0 # XFAIL: 0 # FAIL: 0 # XPASS: 0 # ERROR: 0 DURATION: 80 END: /usr/lib/libpng/ptest 2026-06-04T11:31 STOP: ptest-runner TOTAL: 1 FAIL: 0 Signed-off-by: Sudhir Dumbhare Signed-off-by: Yoann Congal --- .../libpng/files/CVE-2026-34757_p1.patch | 521 ++++++++++++++++++ .../libpng/files/CVE-2026-34757_p2.patch | 484 ++++++++++++++++ .../libpng/libpng_1.6.42.bb | 4 +- 3 files changed, 1008 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch new file mode 100644 index 00000000000..cd8150b1a45 --- /dev/null +++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch @@ -0,0 +1,521 @@ +From 1fb509cdff1f9d83e2bf160259529a742de9285f Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Mon, 30 Mar 2026 17:35:30 +0300 +Subject: [PATCH] fix: Handle self-referencing pointers in getter-to-setter + aliasing + +Apply a robustness fix for a caller-side API usage pattern involving +the getters and the setters for PLTE, tRNS, and hIST. + +Passing a pointer returned by the PLTE, tRNS, or hIST getters back +into the corresponding setters used to cause the setters to read from +a stale pointer. The fix consists in snapshotting the caller's data +into a stack-local buffer before freeing the old internal storage. + +Fixes pnggroup/libpng#836 + +CVE: CVE-2026-34757 +Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a] + +Reported-by: Iv4n +(cherry picked from commit 398cbe3df03f4e11bb031e07f416dfdde3684e8a) +Signed-off-by: Sudhir Dumbhare +--- + CMakeLists.txt | 12 ++ + Makefile.am | 9 +- + contrib/libtests/pnggetset.c | 328 +++++++++++++++++++++++++++++++++++ + pngset.c | 29 +++- + tests/pnggetset | 5 + + 5 files changed, 380 insertions(+), 3 deletions(-) + create mode 100644 contrib/libtests/pnggetset.c + create mode 100755 tests/pnggetset + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 93a2c3434..8888d15cb 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -591,6 +591,9 @@ set(pngvalid_sources + set(pngstest_sources + contrib/libtests/pngstest.c + ) ++set(pnggetset_sources ++ contrib/libtests/pnggetset.c ++) + set(pngunknown_sources + contrib/libtests/pngunknown.c + ) +@@ -758,6 +761,15 @@ if(PNG_TESTS AND PNG_SHARED) + COMMAND pngtest + FILES "${PNGTEST_PNG}") + ++ # pnggetset test: ++ # Getter-to-setter roundtrips for various chunk types. ++ add_executable(pnggetset ${pnggetset_sources}) ++ target_link_libraries(pnggetset ++ PRIVATE png_shared) ++ ++ png_add_test(NAME pnggetset ++ COMMAND pnggetset) ++ + add_executable(pngvalid ${pngvalid_sources}) + target_link_libraries(pngvalid PRIVATE png_shared) + +diff --git a/Makefile.am b/Makefile.am +index 1f06c703a..bdb40c61c 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -13,7 +13,7 @@ ACLOCAL_AMFLAGS = -I scripts/autoconf + + # test programs - run on make check, make distcheck + if ENABLE_TESTS +-check_PROGRAMS= pngtest pngunknown pngstest pngvalid pngimage pngcp ++check_PROGRAMS= pngtest pnggetset pngunknown pngstest pngvalid pngimage pngcp + if HAVE_CLOCK_GETTIME + check_PROGRAMS += timepng + endif +@@ -42,6 +42,9 @@ if ENABLE_TESTS + pngtest_SOURCES = pngtest.c + pngtest_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la + ++pnggetset_SOURCES = contrib/libtests/pnggetset.c ++pnggetset_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la ++ + pngvalid_SOURCES = contrib/libtests/pngvalid.c + pngvalid_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la + +@@ -75,6 +78,7 @@ TESTS =\ + tests/pngtest-all\ + tests/pngvalid-gamma-16-to-8 tests/pngvalid-gamma-alpha-mode\ + tests/pngvalid-gamma-background tests/pngvalid-gamma-expand16-alpha-mode\ ++ tests/pnggetset\ + tests/pngvalid-gamma-expand16-background\ + tests/pngvalid-gamma-expand16-transform tests/pngvalid-gamma-sbit\ + tests/pngvalid-gamma-threshold tests/pngvalid-gamma-transform\ +@@ -273,9 +277,10 @@ $(srcdir)/scripts/pnglibconf.h.prebuilt: + pngtest.o: pnglibconf.h + + contrib/libtests/makepng.o: pnglibconf.h ++contrib/libtests/pnggetset.o: pnglibconf.h ++contrib/libtests/pngimage.o: pnglibconf.h + contrib/libtests/pngstest.o: pnglibconf.h + contrib/libtests/pngunknown.o: pnglibconf.h +-contrib/libtests/pngimage.o: pnglibconf.h + contrib/libtests/pngvalid.o: pnglibconf.h + contrib/libtests/readpng.o: pnglibconf.h + contrib/libtests/tarith.o: pnglibconf.h +diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c +new file mode 100644 +index 000000000..b42508094 +--- /dev/null ++++ b/contrib/libtests/pnggetset.c +@@ -0,0 +1,328 @@ ++/* pnggetset.c ++ * ++ * Copyright (c) 2026 Cosmin Truta ++ * ++ * This code is released under the libpng license. ++ * For conditions of distribution and use, see the disclaimer ++ * and license in png.h ++ * ++ * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. ++ * ++ * Passing the internal pointer returned by a getter back into the ++ * corresponding setter is a natural API usage pattern. A previous ++ * version had a use-after-free on this path because the setter freed ++ * the internal buffer before copying from the caller-supplied pointer. ++ */ ++ ++#include ++#include ++#include ++ ++#if defined(HAVE_CONFIG_H) && !defined(PNG_NO_CONFIG_H) ++# include ++#endif ++ ++#ifdef PNG_FREESTANDING_TESTS ++# include ++#else ++# include "../../png.h" ++#endif ++ ++/* Test: get the PLTE, pass it straight back to set, verify roundtrip. */ ++static int ++test_plte_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_colorp got_palette = NULL; ++ int num_palette = 0; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_plte_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image header. */ ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ ++ /* Populate with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ { ++ palette[i].red = (png_byte)(i * 10); ++ palette[i].green = (png_byte)(i * 20); ++ palette[i].blue = (png_byte)(i * 30); ++ } ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); ++ if (got_palette == NULL || num_palette != 4) ++ { ++ fprintf(stderr, "pnggetset: png_get_PLTE returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->palette. */ ++ png_set_PLTE(png_ptr, info_ptr, got_palette, num_palette); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_palette = NULL; ++ num_palette = 0; ++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); ++ if (got_palette == NULL || num_palette != 4) ++ { ++ fprintf(stderr, "pnggetset: PLTE lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_palette[i].red != (png_byte)(i * 10) || ++ got_palette[i].green != (png_byte)(i * 20) || ++ got_palette[i].blue != (png_byte)(i * 30)) ++ { ++ fprintf(stderr, ++ "pnggetset: PLTE entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++ ++#ifdef PNG_hIST_SUPPORTED ++/* Test: get the hIST, pass it straight back to set, verify roundtrip. */ ++static int ++test_hist_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_uint_16 hist[4]; ++ png_uint_16p got_hist = NULL; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_hist_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image header. */ ++ memset(palette, 0, sizeof palette); ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Populate with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ hist[i] = (png_uint_16)(i * 100 + 42); ++ ++ png_set_hIST(png_ptr, info_ptr, hist); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_get_hIST returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->hist. */ ++ png_set_hIST(png_ptr, info_ptr, got_hist); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_hist = NULL; ++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) ++ { ++ fprintf(stderr, "pnggetset: hIST lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_hist[i] != (png_uint_16)(i * 100 + 42)) ++ { ++ fprintf(stderr, ++ "pnggetset: hIST entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_hIST_SUPPORTED */ ++ ++#ifdef PNG_tRNS_SUPPORTED ++/* Test: get the tRNS, pass it straight back to set, verify roundtrip. */ ++static int ++test_trns_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_color palette[4]; ++ png_byte trans_alpha[4]; ++ png_color_16 trans_color; ++ png_bytep got_alpha = NULL; ++ png_color_16p got_color = NULL; ++ int num_trans = 0; ++ int i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_trns_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up a palette-color image. */ ++ memset(palette, 0, sizeof palette); ++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, ++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); ++ png_set_PLTE(png_ptr, info_ptr, palette, 4); ++ ++ /* Populate tRNS with recognizable values. */ ++ for (i = 0; i < 4; i++) ++ trans_alpha[i] = (png_byte)(0xff - i * 0x11); ++ memset(&trans_color, 0, sizeof trans_color); ++ ++ png_set_tRNS(png_ptr, info_ptr, trans_alpha, 4, &trans_color); ++ ++ /* Get the internal pointer and feed it straight back. */ ++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); ++ if (got_alpha == NULL || num_trans != 4) ++ { ++ fprintf(stderr, "pnggetset: png_get_tRNS returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: the pointer aliases info_ptr->trans_alpha. */ ++ png_set_tRNS(png_ptr, info_ptr, got_alpha, num_trans, got_color); ++ ++ /* Verify the data survived the roundtrip. */ ++ got_alpha = NULL; ++ num_trans = 0; ++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); ++ if (got_alpha == NULL || num_trans != 4) ++ { ++ fprintf(stderr, "pnggetset: tRNS lost after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_alpha[i] != (png_byte)(0xff - i * 0x11)) ++ { ++ fprintf(stderr, ++ "pnggetset: tRNS entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_tRNS_SUPPORTED */ ++ ++int ++main(void) ++{ ++ int result = 0; ++ ++ printf("Testing PLTE get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_plte_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++ ++#ifdef PNG_hIST_SUPPORTED ++ printf("Testing hIST get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_hist_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_tRNS_SUPPORTED ++ printf("Testing tRNS get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_trns_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++ return result; ++} +diff --git a/pngset.c b/pngset.c +index c4a0958aa..9f5c44510 100644 +--- a/pngset.c ++++ b/pngset.c +@@ -204,6 +204,7 @@ void PNGAPI + png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, + png_const_uint_16p hist) + { ++ png_uint_16 safe_hist[PNG_MAX_PALETTE_LENGTH]; + int i; + + png_debug1(1, "in %s storage function", "hIST"); +@@ -220,6 +221,13 @@ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, + return; + } + ++ /* Snapshot the caller's hist before freeing, in case it points to ++ * info_ptr->hist (getter-to-setter aliasing). ++ */ ++ memcpy(safe_hist, hist, (unsigned int)info_ptr->num_palette * ++ (sizeof (png_uint_16))); ++ hist = safe_hist; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_HIST, 0); + + /* Changed from info->num_palette to PNG_MAX_PALETTE_LENGTH in +@@ -561,7 +569,7 @@ void PNGAPI + png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, + png_const_colorp palette, int num_palette) + { +- ++ png_color safe_palette[PNG_MAX_PALETTE_LENGTH]; + png_uint_32 max_palette_length; + + png_debug1(1, "in %s storage function", "PLTE"); +@@ -595,6 +603,15 @@ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, + png_error(png_ptr, "Invalid palette"); + } + ++ /* Snapshot the caller's palette before freeing, in case it points to ++ * info_ptr->palette (getter-to-setter aliasing). ++ */ ++ if (num_palette > 0) ++ memcpy(safe_palette, palette, (unsigned int)num_palette * ++ (sizeof (png_color))); ++ ++ palette = safe_palette; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_PLTE, 0); + + /* Changed in libpng-1.2.1 to allocate PNG_MAX_PALETTE_LENGTH instead +@@ -1000,6 +1017,16 @@ png_set_tRNS(png_structrp png_ptr, png_inforp info_ptr, + + if (trans_alpha != NULL) + { ++ /* Snapshot the caller's trans_alpha before freeing, in case it ++ * points to info_ptr->trans_alpha (getter-to-setter aliasing). ++ */ ++ png_byte safe_trans[PNG_MAX_PALETTE_LENGTH]; ++ ++ if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) ++ memcpy(safe_trans, trans_alpha, (size_t)num_trans); ++ ++ trans_alpha = safe_trans; ++ + png_free_data(png_ptr, info_ptr, PNG_FREE_TRNS, 0); + + if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) +diff --git a/tests/pnggetset b/tests/pnggetset +new file mode 100755 +index 000000000..57ef731a5 +--- /dev/null ++++ b/tests/pnggetset +@@ -0,0 +1,5 @@ ++#!/bin/sh ++ ++# pnggetset test: ++# Getter-to-setter roundtrips for various chunk types. ++exec ./pnggetset +-- +2.51.0 + diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch new file mode 100644 index 00000000000..7d58ead18de --- /dev/null +++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch @@ -0,0 +1,484 @@ +From 2d1c6585d356832bb679ad4d313f5ea542e02064 Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Mon, 30 Mar 2026 17:43:05 +0300 +Subject: [PATCH] fix: Handle getter-to-setter aliasing in append-style + chunk setters + +Apply the same class of robustness fix from the previous commit to +`png_set_text`, `png_set_sPLT` and `png_set_unknown_chunks`. These +append-style setters used `png_realloc_array` to grow the internal +array, then freed the old array before copying from the caller's +input. If the caller's pointer was obtained from the corresponding +getter, it aliased the freed array. + +The fix defers the freeing of the old array until after the copy loop. + +Also extend the pnggetset regression test to cover all three setters. + +CVE: CVE-2026-34757 +Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc] + +(cherry picked from commit 55d20aaa322c9274491cda82c5cd4f99b48c6bcc) +Signed-off-by: Sudhir Dumbhare +--- + contrib/libtests/pnggetset.c | 330 ++++++++++++++++++++++++++++++++++- + pngset.c | 25 ++- + 2 files changed, 347 insertions(+), 8 deletions(-) + +diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c +index b42508094..6ae43dc66 100644 +--- a/contrib/libtests/pnggetset.c ++++ b/contrib/libtests/pnggetset.c +@@ -6,12 +6,12 @@ + * For conditions of distribution and use, see the disclaimer + * and license in png.h + * +- * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. ++ * Test the get-then-set roundtrip for chunk types whose getters return ++ * a pointer to internal storage. + * +- * Passing the internal pointer returned by a getter back into the +- * corresponding setter is a natural API usage pattern. A previous +- * version had a use-after-free on this path because the setter freed +- * the internal buffer before copying from the caller-supplied pointer. ++ * Passing such a pointer back into the corresponding setter must not ++ * cause a use-after-free. A previous version freed the internal buffer ++ * before copying from the caller-supplied pointer. + */ + + #include +@@ -285,6 +285,290 @@ test_trns_roundtrip(void) + } + #endif /* PNG_tRNS_SUPPORTED */ + ++#ifdef PNG_TEXT_SUPPORTED ++/* Test: get the text array, pass it straight back to set, verify data. */ ++#define TEXT_COUNT 6 /* enough to trigger reallocation on the second set */ ++static int ++test_text_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_text text_entries[TEXT_COUNT]; ++ png_textp got_text = NULL; ++ int got_num_text = 0; ++ int i; ++ ++ /* Recognizable keys and values. */ ++ static const char *keys[TEXT_COUNT] = { ++ "Title", "Author", "Desc", "Copyright", "Source", "Comment" ++ }; ++ static const char *vals[TEXT_COUNT] = { ++ "t0", "t1", "t2", "t3", "t4", "t5" ++ }; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_text_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Populate the text entries. */ ++ memset(text_entries, 0, sizeof text_entries); ++ for (i = 0; i < TEXT_COUNT; i++) ++ { ++ text_entries[i].compression = PNG_TEXT_COMPRESSION_NONE; ++ text_entries[i].key = (png_charp)keys[i]; ++ text_entries[i].text = (png_charp)vals[i]; ++ } ++ png_set_text(png_ptr, info_ptr, text_entries, TEXT_COUNT); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); ++ if (got_text == NULL || got_num_text != TEXT_COUNT) ++ { ++ fprintf(stderr, "pnggetset: png_get_text returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_text aliases info_ptr->text. */ ++ png_set_text(png_ptr, info_ptr, got_text, got_num_text); ++ ++ /* Verify the original entries survived. */ ++ got_text = NULL; ++ got_num_text = 0; ++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); ++ if (got_text == NULL || got_num_text != TEXT_COUNT * 2) ++ { ++ fprintf(stderr, "pnggetset: text count %d, expected %d after roundtrip\n", ++ got_num_text, TEXT_COUNT * 2); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < TEXT_COUNT; i++) ++ { ++ if (got_text[i].key == NULL || ++ strcmp(got_text[i].key, keys[i]) != 0 || ++ got_text[i].text == NULL || ++ strcmp(got_text[i].text, vals[i]) != 0) ++ { ++ fprintf(stderr, ++ "pnggetset: text entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#undef TEXT_COUNT ++#endif /* PNG_TEXT_SUPPORTED */ ++ ++#ifdef PNG_sPLT_SUPPORTED ++/* Test: get the sPLT array, pass it straight back to set, verify data. */ ++static int ++test_splt_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_sPLT_t splt; ++ png_sPLT_entry splt_entries[4]; ++ png_sPLT_tp got_spalettes = NULL; ++ int got_num, i; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, "pnggetset: libpng error in test_splt_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Populate with recognizable values. */ ++ memset(splt_entries, 0, sizeof splt_entries); ++ for (i = 0; i < 4; i++) ++ { ++ splt_entries[i].red = (png_uint_16)(i * 1000); ++ splt_entries[i].green = (png_uint_16)(i * 2000); ++ splt_entries[i].blue = (png_uint_16)(i * 3000); ++ splt_entries[i].alpha = 0xffffU; ++ splt_entries[i].frequency = (png_uint_16)(i + 1); ++ } ++ memset(&splt, 0, sizeof splt); ++ splt.name = (png_charp)"test_sPLT"; ++ splt.depth = 16; ++ splt.entries = splt_entries; ++ splt.nentries = 4; ++ ++ png_set_sPLT(png_ptr, info_ptr, &splt, 1); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); ++ if (got_spalettes == NULL || got_num != 1) ++ { ++ fprintf(stderr, "pnggetset: png_get_sPLT returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_spalettes aliases internal storage. */ ++ png_set_sPLT(png_ptr, info_ptr, got_spalettes, got_num); ++ ++ /* Verify the original entry survived. */ ++ got_spalettes = NULL; ++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); ++ if (got_spalettes == NULL || got_num != 2) ++ { ++ fprintf(stderr, "pnggetset: sPLT count %d, expected 2 after roundtrip\n", ++ got_num); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ if (strcmp(got_spalettes[0].name, "test_sPLT") != 0 || ++ got_spalettes[0].nentries != 4 || ++ got_spalettes[0].depth != 16) ++ { ++ fprintf(stderr, ++ "pnggetset: sPLT entry 0 corrupted after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ for (i = 0; i < 4; i++) ++ { ++ if (got_spalettes[0].entries[i].red != (png_uint_16)(i * 1000) || ++ got_spalettes[0].entries[i].green != (png_uint_16)(i * 2000) || ++ got_spalettes[0].entries[i].blue != (png_uint_16)(i * 3000)) ++ { ++ fprintf(stderr, ++ "pnggetset: sPLT[0] entry %d corrupted after roundtrip\n", i); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_sPLT_SUPPORTED */ ++ ++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED ++/* Test: get unknown chunks, pass them straight back to set, verify data. */ ++static int ++test_unknown_roundtrip(void) ++{ ++ png_structp png_ptr; ++ png_infop info_ptr; ++ png_unknown_chunk unk; ++ png_unknown_chunkp got_unknowns = NULL; ++ int got_num; ++ static const png_byte test_data[] = {0xde, 0xad, 0xbe, 0xef}; ++ ++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, ++ NULL, NULL, NULL); ++ if (png_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); ++ return 1; ++ } ++ ++ info_ptr = png_create_info_struct(png_ptr); ++ if (info_ptr == NULL) ++ { ++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); ++ png_destroy_write_struct(&png_ptr, NULL); ++ return 1; ++ } ++ ++ if (setjmp(png_jmpbuf(png_ptr))) ++ { ++ fprintf(stderr, ++ "pnggetset: libpng error in test_unknown_roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* Set up an unknown chunk with recognizable data. */ ++ memset(&unk, 0, sizeof unk); ++ memcpy(unk.name, "teSt", 5); ++ unk.data = (png_bytep)test_data; ++ unk.size = sizeof test_data; ++ unk.location = PNG_HAVE_IHDR; ++ ++ png_set_keep_unknown_chunks(png_ptr, PNG_HANDLE_CHUNK_ALWAYS, NULL, 0); ++ png_set_unknown_chunks(png_ptr, info_ptr, &unk, 1); ++ ++ /* Get the internal pointer and feed it straight back (append). */ ++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); ++ if (got_unknowns == NULL || got_num != 1) ++ { ++ fprintf(stderr, ++ "pnggetset: png_get_unknown_chunks returned unexpected values\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ /* This is the critical call: got_unknowns aliases internal storage. */ ++ png_set_unknown_chunks(png_ptr, info_ptr, got_unknowns, got_num); ++ ++ /* Verify the original entry survived. */ ++ got_unknowns = NULL; ++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); ++ if (got_unknowns == NULL || got_num != 2) ++ { ++ fprintf(stderr, ++ "pnggetset: unknown_chunks count %d, expected 2 after roundtrip\n", ++ got_num); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ if (memcmp(got_unknowns[0].name, "teSt", 4) != 0 || ++ got_unknowns[0].size != sizeof test_data || ++ memcmp(got_unknowns[0].data, test_data, sizeof test_data) != 0) ++ { ++ fprintf(stderr, ++ "pnggetset: unknown chunk 0 corrupted after roundtrip\n"); ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 1; ++ } ++ ++ png_destroy_write_struct(&png_ptr, &info_ptr); ++ return 0; ++} ++#endif /* PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED */ ++ + int + main(void) + { +@@ -324,5 +608,41 @@ main(void) + printf("PASS\n"); + #endif + ++#ifdef PNG_TEXT_SUPPORTED ++ printf("Testing tEXt get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_text_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_sPLT_SUPPORTED ++ printf("Testing sPLT get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_splt_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ ++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED ++ printf("Testing unknown chunks get-then-set roundtrip... "); ++ fflush(stdout); ++ if (test_unknown_roundtrip() != 0) ++ { ++ printf("FAIL\n"); ++ result = 1; ++ } ++ else ++ printf("PASS\n"); ++#endif ++ + return result; + } +diff --git a/pngset.c b/pngset.c +index 9f5c44510..9ffaf2b5a 100644 +--- a/pngset.c ++++ b/pngset.c +@@ -789,6 +789,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + png_const_textp text_ptr, int num_text) + { + int i; ++ png_textp old_text = NULL; + + png_debug1(1, "in text storage function, chunk typeid = 0x%lx", + png_ptr == NULL ? 0xabadca11UL : (unsigned long)png_ptr->chunk_name); +@@ -836,7 +837,10 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + return 1; + } + +- png_free(png_ptr, info_ptr->text); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case text_ptr aliases info_ptr->text (getter-to-setter). ++ */ ++ old_text = info_ptr->text; + + info_ptr->text = new_text; + info_ptr->free_me |= PNG_FREE_TEXT; +@@ -921,6 +925,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + { + png_chunk_report(png_ptr, "text chunk: out of memory", + PNG_CHUNK_WRITE_ERROR); ++ png_free(png_ptr, old_text); + + return 1; + } +@@ -974,6 +979,8 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, + png_debug1(3, "transferred text chunk %d", info_ptr->num_text); + } + ++ png_free(png_ptr, old_text); ++ + return 0; + } + #endif +@@ -1112,6 +1119,7 @@ png_set_sPLT(png_const_structrp png_ptr, + */ + { + png_sPLT_tp np; ++ png_sPLT_tp old_spalettes; + + png_debug1(1, "in %s storage function", "sPLT"); + +@@ -1132,7 +1140,10 @@ png_set_sPLT(png_const_structrp png_ptr, + return; + } + +- png_free(png_ptr, info_ptr->splt_palettes); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case entries aliases info_ptr->splt_palettes (getter-to-setter). ++ */ ++ old_spalettes = info_ptr->splt_palettes; + + info_ptr->splt_palettes = np; + info_ptr->free_me |= PNG_FREE_SPLT; +@@ -1196,6 +1207,8 @@ png_set_sPLT(png_const_structrp png_ptr, + } + while (--nentries); + ++ png_free(png_ptr, old_spalettes); ++ + if (nentries > 0) + png_chunk_report(png_ptr, "sPLT out of memory", PNG_CHUNK_WRITE_ERROR); + } +@@ -1244,6 +1257,7 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + png_inforp info_ptr, png_const_unknown_chunkp unknowns, int num_unknowns) + { + png_unknown_chunkp np; ++ png_unknown_chunkp old_unknowns; + + if (png_ptr == NULL || info_ptr == NULL || num_unknowns <= 0 || + unknowns == NULL) +@@ -1290,7 +1304,10 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + return; + } + +- png_free(png_ptr, info_ptr->unknown_chunks); ++ /* Defer freeing the old array until after the copy loop below, ++ * in case unknowns aliases info_ptr->unknown_chunks (getter-to-setter). ++ */ ++ old_unknowns = info_ptr->unknown_chunks; + + info_ptr->unknown_chunks = np; /* safe because it is initialized */ + info_ptr->free_me |= PNG_FREE_UNKN; +@@ -1336,6 +1353,8 @@ png_set_unknown_chunks(png_const_structrp png_ptr, + ++np; + ++(info_ptr->unknown_chunks_num); + } ++ ++ png_free(png_ptr, old_unknowns); + } + + void PNGAPI +-- +2.51.0 + diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb index e4cc63686e9..b226e327b64 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb @@ -29,6 +29,8 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/${PV}/${BP}.tar.xz file://CVE-2026-33416-02.patch \ file://CVE-2026-33416-03.patch \ file://CVE-2026-33416-04.patch \ + file://CVE-2026-34757_p1.patch \ + file://CVE-2026-34757_p2.patch \ " SRC_URI[sha256sum] = "c919dbc11f4c03b05aba3f8884d8eb7adfe3572ad228af972bb60057bdb48450" @@ -66,7 +68,7 @@ do_install_ptest() { install -m 644 ${S}/contrib/tools/*.c ${S}/contrib/tools/*.h ${D}${PTEST_PATH}/src/contrib/tools # Install .libs directory binaries to ptest path - install -m 755 ${B}/.libs/pngtest ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src + install -m 755 ${B}/.libs/pngtest ${B}/.libs/pnggetset ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src # Copy png files to ptest path cd ${S} && find contrib -name '*.png' | cpio -pd ${D}${PTEST_PATH}/src From patchwork Sun Jul 26 08:29:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93527 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EAE7FC54F4C for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7150.1785054626252425601 for ; Sun, 26 Jul 2026 01:30:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=vFEHowqn; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-493b966dd74so10986195e9.3 for ; Sun, 26 Jul 2026 01:30:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054624; x=1785659424; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=msRv3i1KJxOd+lvq7/uMdm8Oo1epWyntzFnbrODMUxY=; b=vFEHowqnwi1hPh58BUyGfmAkGEx9Y1GILQRwaF8koUiJLyV8Urj3djjEXuONyc9OwI r2+Sy5N3gq0kdmXe184RanXpfqpWs+SfI7YrKRlWoWBqmTT9TJ/4Zvu++YpP9udg2pQU 9uedqRmECkZQQGMvbrf0DD3ltRZOOLn1XM3fU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054624; x=1785659424; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=msRv3i1KJxOd+lvq7/uMdm8Oo1epWyntzFnbrODMUxY=; b=pHBr9q7fkcdMg3m+u7bi2N9soXVqrfn3AuahFka58/AQv2AmqM4july8meaRknfNNo 2lR96A3NZdj7kmgKOyAR/S/2+lF0l0NFlACT46kd6+3pc7f0ZdmTp3kNjZiolCL6Xy2q jRDuR/UQcKXtCKsn8ReVyZqStT06QhbV5ADbM7v/Ufz8e23AHfwE0Gq2UnRPn6Ha7jZW iy3hNqjGADnazd5Vcvdl+FunYfF5LesiIjkDAdgsdPl+PtRn5JyVP7y3xJzpjZ/rstMU 35wSfqFejoRotOjvWFSOaVArXbCxDdrfzwqDmoH/Pk10HCBYgO8IhCg5FFUk+kGek9M2 v6rg== X-Gm-Message-State: AOJu0YzswjsiMkuyVATzSop2pYJ+o+TzBUiXEChnyDitWH14VhkHSGCa zAkvs1JXp/HJ4IQ+wem40lsd4njhxQKWWpgOAmKga0sBNVGHI9jXaHFvTWEZh7sjXEXykEsK31u BQLeFS+E= X-Gm-Gg: AR+sD12k1jw8aUEADKqSV5wcZaDwQ01G3n2uFkBObspZwqJNpxXVMbm6hmk0ogmf7Jh Wkx/Zuw9rUZKHWNWwqSsMu/c7bu6ejnkDRUOnpTclTItk7d/G5ct1P17VvlBxCoI94ZUTMYmKzZ 9uzT+61Zr81nrOeDAu5FNH3/zanKI6n5+gFc54cbrrLztTZJNmE9xti7FTN66dSt89myYccCvtZ 8VZwJ/3GLEkAtD8QSrXipsCotuXHJr96Uh1oLu+vEjg77/lsZ9n0iZDkd0/APn1JOpTbOgMfN75 RtCsACMKIplNKy0O9UpvDyfHWVEWNtjHHW901Oov4tYdKh2UlzXSlljgyh3sbIMZy2Sio6D4c1z jKH49QdNbx63aTqX3ck4BJ8S46pYCJMptFiyrZeGt/tJZcULfXHfYkhxSvtMUOTEYsnElvK8IcK +11+/u6OswZaFuvppGNxxg4+7U2ouIoTMUH9kkvgGjiscaUlqttlwN2VE2g2m0xMdb9V/3TRYhk fa/sg== X-Received: by 2002:a05:600c:4455:b0:493:e460:1f6 with SMTP id 5b1f17b1804b1-496b567b728mr54997125e9.0.1785054624478; Sun, 26 Jul 2026 01:30:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Date: Sun, 26 Jul 2026 10:29:49 +0200 Message-ID: <42905f772f74fd9977bb571380c8512f197a1473.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242007 From: Deepak Rathore This patch applies the upstream 2.86.5 backport for CVE-2026-58010. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../glib-2.0/glib-2.0/CVE-2026-58010.patch | 113 ++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 + 2 files changed, 114 insertions(+) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch new file mode 100644 index 00000000000..842d53af5cf --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch @@ -0,0 +1,113 @@ +From 333f164f00fb874e3c670ce70d2a2a3667b9ebf9 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Sun, 29 Mar 2026 19:10:41 +0100 +Subject: [PATCH] gvariant: Fix an off-by-one error in an offset comparison +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This allows a single byte out-of-bounds read off the end of the +(potentially untrusted) byte array backing a `GVariant` when it’s +being checked for normal form. + +I can’t see how this could practically be exploited, but it’s certainly +a security bug as the `GVariant` normal form checking code is supposed +to be robust to malicious inputs. + +Spotted by linhlhq as #YWH-PGM9867-190, and fix and reproducer provided +by them too, thanks. Confirmed and turned into a unit test by me. + +Fixes: #3915 + +CVE: CVE-2026-58010 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f] + +Signed-off-by: Philip Withnall +(cherry picked from commit aa1cb87d56111ef989811e824f0ac77484cc997f) +Signed-off-by: Deepak Rathore +--- + glib/gvariant-serialiser.c | 2 +- + glib/tests/gvariant.c | 48 ++++++++++++++++++++++++++++++++++++++ + 2 files changed, 49 insertions(+), 1 deletion(-) + +diff --git a/glib/gvariant-serialiser.c b/glib/gvariant-serialiser.c +index 4e4a73ad1..99a1d3fbd 100644 +--- a/glib/gvariant-serialiser.c ++++ b/glib/gvariant-serialiser.c +@@ -1247,7 +1247,7 @@ gvs_tuple_is_normal (GVariantSerialised value) + + while (offset & alignment) + { +- if (offset > value.size || value.data[offset] != '\0') ++ if (offset >= value.size || value.data[offset] != '\0') + return FALSE; + offset++; + } +diff --git a/glib/tests/gvariant.c b/glib/tests/gvariant.c +index c8f13360c..55e2cee00 100644 +--- a/glib/tests/gvariant.c ++++ b/glib/tests/gvariant.c +@@ -5637,6 +5637,52 @@ test_normal_checking_tuple_offsets5 (void) + g_variant_unref (variant); + } + ++/* This is a regression test that looping over the padding bytes in a short ++ * (non-normal) tuple doesn’t overflow the input data. ++ * ++ * See https://gitlab.gnome.org/GNOME/glib/-/issues/3915 */ ++static void ++test_normal_checking_tuple_offsets6 (void) ++{ ++ /* ++ * Type: (ynqiuxthdsog) — 12 members, first member 'y' (byte) has ++ * alignment 0, second 'n' (int16) has alignment 1. ++ * With 1 byte of data (0x28), after reading the first byte member, ++ * offset=1, alignment check for 'n' requires offset to be even, ++ * so the while loop checks value.data[1] — but size is only 1. ++ * ++ * Use heap allocation via GBytes so ASan reports heap-buffer-overflow. ++ */ ++ guint8 *heap_data = NULL; ++ GBytes *bytes = NULL; ++ const GVariantType *data_type = G_VARIANT_TYPE ("(ynqiuxthdsog)"); ++ GVariant *variant = NULL; ++ GVariant *normal_variant = NULL; ++ GVariant *expected = NULL; ++ ++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3915"); ++ ++ heap_data = g_malloc (1); ++ heap_data[0] = 0x28; ++ bytes = g_bytes_new_take (heap_data, 1); ++ ++ variant = g_variant_new_from_bytes (data_type, bytes, FALSE); ++ g_assert_nonnull (variant); ++ ++ g_assert_false (g_variant_is_normal_form (variant)); ++ ++ normal_variant = g_variant_get_normal_form (variant); ++ g_assert_nonnull (normal_variant); ++ ++ expected = g_variant_new_parsed ("(byte 0x28, int16 0, uint16 0, 0, uint32 0, int64 0, uint64 0, handle 0, 0.0, '', objectpath '/', signature '')"); ++ g_assert_cmpvariant (expected, variant); ++ g_assert_cmpvariant (expected, normal_variant); ++ ++ g_variant_unref (expected); ++ g_variant_unref (normal_variant); ++ g_variant_unref (variant); ++} ++ + /* Test that an otherwise-valid serialised GVariant is considered non-normal if + * its offset table entries are too wide. + * +@@ -5890,6 +5936,8 @@ main (int argc, char **argv) + test_normal_checking_tuple_offsets4); + g_test_add_func ("/gvariant/normal-checking/tuple-offsets5", + test_normal_checking_tuple_offsets5); ++ g_test_add_func ("/gvariant/normal-checking/tuple-offsets6", ++ test_normal_checking_tuple_offsets6); + g_test_add_func ("/gvariant/normal-checking/tuple-offsets/minimal-sized", + test_normal_checking_tuple_offsets_minimal_sized); + g_test_add_func ("/gvariant/normal-checking/empty-object-path", +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index 549584f3d8f..54691690117 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -49,6 +49,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-1489-04.patch \ file://CVE-2026-58016-1.patch \ file://CVE-2026-58016-2.patch \ + file://CVE-2026-58010.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ From patchwork Sun Jul 26 08:29:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93529 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DF085C54EFC for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7151.1785054627036495154 for ; Sun, 26 Jul 2026 01:30:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YFUnqmGN; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4954a9e8490so13930275e9.1 for ; Sun, 26 Jul 2026 01:30:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054625; x=1785659425; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w0pjw6kR5NHhqrhjq/hQipYXI03U1dMLr3aOGRROc84=; b=YFUnqmGNgIJieEIWF1HCysrTWeHbCpP45XnkYd5DAqQABt9Vwo/M269pX7+C+9pLMj bvHSHEBB3fobPTMNH4stOcK2zIFu0kyDfkr8QruAmlN92Kjp0V5qllD7YnnKzHqZYEq3 8yv4Y2EiCIQBrTFqtIY5VZFQ4hXIqd/hVyEwc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054625; x=1785659425; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=w0pjw6kR5NHhqrhjq/hQipYXI03U1dMLr3aOGRROc84=; b=kWlpWY3gDtylkFaf5/RS8F5Xj4chRUx/nVHwMz57rGZNBJ/h4+IpbbUxCKapsAp4VA g/7rpzeN4dpZnTRQqAO6fksfXrZ4AYNz4bMHS+DvW5ita9AT8FCm4jGCW7Jxn5eXuSBQ IjAUOPLN6TpeShmP8IFG6Qs3HLz5ZsmtveqExPSNJyS+H5GC2TLQx7ciIgWRt4M7a56E I5BxQoC/XbKsSKQw0WxlcESAF4gxuw+y75ipXgIYzP9qip+y3CZ+PDfKqM7C7T/HOQsA P/7uS0vrCcXVNHc00hIQJp+GoEtPlVa1nGPa0uvcuYiqA5xamzJHccbdmT1CGagA2jdu Iw2Q== X-Gm-Message-State: AOJu0YzNC3GFVY3OUCGopHAfgpJzjDpWuRHLsmR2EIEOaaL14aS3Ih4r Y0TOk69iTjZ7WimEseJi2fgyD0C6HKO0YlBiwA1mte/HArOVDk3XDsol19bC2JQZ7yg2dsnLFoU nvbTfRf0= X-Gm-Gg: AR+sD11VwyTZ6eAvbN8qQJQwfvmAjOBK6XpCYG1x/wkeVFxECBUnqc959HV8+wp8d6w oTuD3yUP1LHxeY/rLWXTcP9DWRi+fLtWsHWvZZ1LhA0lzroTOOLDgkkP0rO2u7aXvjsRkBDHiLM 1tfrQfx4/I6b+iib1uZWaQDlq0LoT1NZfYjWdatn9lEYl2z5Q0RGLhKpH4AOFRWWD3OHTCk0HWo jNed6a6CS0sFOpIEVIQTRkpFlCcp9JkghRrupRMaQfbWEf8xQrOIiSD4k5WV672czVhawDVfoZm /fj5ChCPzYeeRu4MVITzamfqHRaD77lu5TQyXH+qRSk2itPXbF3T2W85WOWWVRASD+JQ8O+A7qP Y4MI0fwSUdH+EdgAbl4j/v+hCL9dQjMSCR66c6HSuYLkqIhj8Acx2XsI+esSZeu7FuDcCiNkl5w EqHtQZGK02oSSTFV6+STeUZwfpfDg4A3+aqAdb70E6SBN2Mx4+g8afIwHPCCYGLMRTkoL2epcJe zWNtg== X-Received: by 2002:a05:600c:c48f:b0:493:f478:4c71 with SMTP id 5b1f17b1804b1-496b5b53259mr55260405e9.7.1785054625183; Sun, 26 Jul 2026 01:30:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Date: Sun, 26 Jul 2026 10:29:50 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242008 From: Deepak Rathore This patch applies the upstream 2.86.5 backport for CVE-2026-58011. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58011 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../glib-2.0/glib-2.0/CVE-2026-58011.patch | 78 +++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 + 2 files changed, 79 insertions(+) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch new file mode 100644 index 00000000000..a8d31c1270c --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch @@ -0,0 +1,78 @@ +From 371dbccb6b9a9a42b93c4b371214b159e7e94792 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Sun, 29 Mar 2026 23:46:17 +0100 +Subject: [PATCH] gdatetime: Add missing range validation to + g_date_time_add_full() +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Otherwise it’s possible to create a non-`NULL` but invalid `GDateTime`, +which breaks all kinds of internal assumptions. + +Spotted by linhlhq as #YWH-PGM9867-191. Thanks to them for providing a +suggested fix and a test case, which I have adapted and validated. + +Fixes: #3917 + +CVE: CVE-2026-58011 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b] + +Backport Changes: +- Used the target branch's existing literal day bounds because it does + not have upstream's MIN_DAYS/MAX_DAYS helper macros. + +Signed-off-by: Philip Withnall +(cherry picked from commit ae27363f025ffc131e2d75ee88a5cd8320dffe3b) +Signed-off-by: Deepak Rathore +--- + glib/gdatetime.c | 4 +++- + glib/tests/gdatetime.c | 18 ++++++++++++++++++ + 2 files changed, 21 insertions(+), 1 deletion(-) + +diff --git a/glib/gdatetime.c b/glib/gdatetime.c +index 2640e3b24..73eea643b 100644 +--- a/glib/gdatetime.c ++++ b/glib/gdatetime.c +@@ -2024,7 +2024,9 @@ g_date_time_add_full (GDateTime *datetime, + new->days = full_time / USEC_PER_DAY; + new->usec = full_time % USEC_PER_DAY; + +- /* XXX validate */ ++ /* Validate it’s still in the range 0001-01-01 to 9999-12-31 */ ++ if (new->days < 1 || new->days > 3652059) ++ g_clear_pointer (&new, g_date_time_unref); + + return new; + } +diff --git a/glib/tests/gdatetime.c b/glib/tests/gdatetime.c +index 49390c900..527d61a11 100644 +--- a/glib/tests/gdatetime.c ++++ b/glib/tests/gdatetime.c +@@ -1117,6 +1117,24 @@ test_GDateTime_add_full (void) + TEST_ADD_FULL (2010, 8, 25, 22, 45, 0, + 0, 1, 6, 1, 25, 0, + 2010, 10, 2, 0, 10, 0); ++ ++#define TEST_ADD_FULL_ERROR(y,m,d,h,mi,s,ay,am,ad,ah,ami,as) G_STMT_START { \ ++ GDateTime *dt; \ ++ dt = g_date_time_new_utc (y, m, d, h, mi, s); \ ++ g_assert_null (g_date_time_add_full (dt, ay, am, ad, ah, ami, as)); \ ++ g_date_time_unref (dt); \ ++} G_STMT_END ++ ++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0, ++ -1, 0, 0, 0, 0, 0); ++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0, ++ 10000, 0, 0, 0, 0, 0); ++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0, ++ -10000, 0, 0, 0, 0, 0); ++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0, ++ 0, 0, 3660001, 0, 0, 0); ++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0, ++ 0, 0, -3660001, 0, 0, 0); + } + + static void +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index 54691690117..a2de973e218 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -50,6 +50,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-58016-1.patch \ file://CVE-2026-58016-2.patch \ file://CVE-2026-58010.patch \ + file://CVE-2026-58011.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ From patchwork Sun Jul 26 08:29:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93528 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2DADC5321C for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7152.1785054627713054731 for ; Sun, 26 Jul 2026 01:30:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mj2U1FWe; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so13019945e9.1 for ; Sun, 26 Jul 2026 01:30:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054626; x=1785659426; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HBhZ2iYfxLI3QbYKW2Xl7jtQhRDm1L1sybvs1qF1UGQ=; b=mj2U1FWe4GtPoJ1eng6QLD+g6IkRx20L0lBYAoNOOvxCYgqwYWX8+hk/y+6LrFmMlv weyj3IEjcNwQXI49AQ/saMD0vJV7MR2codufBEh2EgHOyZfFkHngdpctaoPphRdu69CQ CbOLV8qRe4GIoo5USIj3n+MFkT+18/nnkV6Bw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054626; x=1785659426; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HBhZ2iYfxLI3QbYKW2Xl7jtQhRDm1L1sybvs1qF1UGQ=; b=ay/ixgOKP80cY99xtqLy+28iqfUVBSNVIKYgfb1tWzik+1JW08eM9A69L4LXnvH6VZ lh4hNUyfS8gWTJaSkSY3bUFz8fw3SGfcfwT0IyxuWrn0Pf90vjIQLPxPEIZfUmfzGVkV hImRDKVP+TK4/b96Do/8ndSkpLEXE7RMg7C5rusbVRn+K0JWzN/UGyTm9orhZ/tyAITa Op6FnrdBGX7tvAAXDW+gWRtsCmlAlpTT3rzApzyzJiTAAhVBFLhh+2XYqNCDZH+cVsW/ Deoxgkbl+bEjQeFUmFTJNc5DdC8XtpVh5E0uF79fX2ux3pbpAhFalO0J9Gq/kmCDB9TX UVjQ== X-Gm-Message-State: AOJu0YyRILGqAQVuozqaEev1rbgbYBTYg3AvVGtkQzEz20fY6Me5hM5d q7tlSQp1fSbLDcGN1/JEM2Z4gh0NAHxBaXvZMUF51WZgh8PGQm8BvFQQD3d+q3/cYJ/KD/B0VWU jPWEB21k= X-Gm-Gg: AR+sD12SFTOyYHKIxmyoEEvKlfSOCfaTxpG/VB1jzVpCs8tIzHSAIBGvY7nRFl2ZfCN bzPkNd2e4fFn288b/nwp8PIY5iyOzQAG7FXQ636MMg/aOmh0H4W63jYBWLvh0VRlswgaC3qRsik 1svjbcfplFRnYAoi67CA0oqaoGTldCaQ9xTy4Z7zruKPiALQZAWvmKuWKiA93plJgZevz5rX7Wz woaiqsEin91BukBovpg/ige4nqT0axEgqSsuSOuZG/nkXwFZXW6qu2OVPDYnE3X02UlpWZFTIEa hz/gMapjyUPVsaHt/T1pjPDPM6IphVbZEF5XkTGOpZhn6zjccNc2hSflZ04g98glG1dBS4oD1uL lA1tb0lq4dlWgEhfsjQw1673eIjXSZFdopQmmIgV9/paZ+NXfjhkaZimLN5QXaxhl45oH3O34J1 TJCMHhRb/Wi/dKI4xkJsLZNWdAsWKUB4ml7GeA2+L/CVAw3MI3TmDTtmbtHlBEHMoXQSOwSIozf ytb4840itcuLkrD X-Received: by 2002:a05:600c:4fc6:b0:493:c8a6:b517 with SMTP id 5b1f17b1804b1-496b5735169mr53026835e9.38.1785054625925; Sun, 26 Jul 2026 01:30:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Date: Sun, 26 Jul 2026 10:29:51 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242009 From: Deepak Rathore This patch applies the upstream 2.86.5 backport for CVE-2026-58012. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58012 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../glib-2.0/glib-2.0/CVE-2026-58012.patch | 228 ++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 + 2 files changed, 229 insertions(+) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch new file mode 100644 index 00000000000..7f8435809c6 --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch @@ -0,0 +1,228 @@ +From 74564fefcec22fc1efc187c36aa1fb8dcfe34454 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 31 Mar 2026 16:13:57 +0100 +Subject: [PATCH] gregex: Fix case changing substitutions with G_REGEX_RAW + +In `G_REGEX_RAW` mode, the input string is treated as a byte array +(basically ASCII) rather than a unichar array. Accordingly, the case +changing code for substitutions needs to operate on bytes with +`G_REGEX_RAW`, rather than operating on unichars. + +This fixes a potential buffer overflow when trying to do a case change +on a match of a set of bytes which are a truncated multi-byte UTF-8 +encoding at the end of the input buffer. + +Spotted by linhlhq as #YWH-PGM9867-193. I adapted their reproducer as +the unit test, but implemented the fix in `gregex.c` independently. + +Fixes: #3918 + +CVE: CVE-2026-58012 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f] + +Signed-off-by: Philip Withnall +(cherry picked from commit d337aabd24ee2b8ac2a690dba3ccf26aa70e638f) +Signed-off-by: Deepak Rathore +--- + glib/gregex.c | 59 ++++++++++++++++++++++++++++++++++------------ + glib/tests/regex.c | 53 +++++++++++++++++++++++++++++++++++++++++ + 2 files changed, 97 insertions(+), 15 deletions(-) + +diff --git a/glib/gregex.c b/glib/gregex.c +index 116ecacbb..496b34bbd 100644 +--- a/glib/gregex.c ++++ b/glib/gregex.c +@@ -3147,19 +3147,25 @@ split_replacement (const gchar *replacement, + return g_list_reverse (list); + } + +-/* Change the case of c based on change_case. */ +-#define CHANGE_CASE(c, change_case) \ ++/* Change the case of c based on change_case. ++ * g_ascii_to*() will happily pass through non-ASCII bytes unchanged. */ ++#define UTF8_CHANGE_CASE(c, change_case) \ + (((change_case) & CHANGE_CASE_LOWER_MASK) ? \ + g_unichar_tolower (c) : \ + g_unichar_toupper (c)) ++#define RAW_CHANGE_CASE(c, change_case) \ ++ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \ ++ g_ascii_tolower (c) : \ ++ g_ascii_toupper (c)) + ++/* If @text_is_raw is set, @text might not be valid UTF-8 (but will be ++ * nul-terminated). */ + static void + string_append (GString *string, + const gchar *text, ++ gboolean text_is_raw, + ChangeCase *change_case) + { +- gunichar c; +- + if (text[0] == '\0') + return; + +@@ -3169,22 +3175,44 @@ string_append (GString *string, + } + else if (*change_case & CHANGE_CASE_SINGLE_MASK) + { +- c = g_utf8_get_char (text); +- g_string_append_unichar (string, CHANGE_CASE (c, *change_case)); +- g_string_append (string, g_utf8_next_char (text)); ++ if (!text_is_raw) ++ { ++ gunichar c = g_utf8_get_char (text); ++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case)); ++ g_string_append (string, g_utf8_next_char (text)); ++ } ++ else ++ { ++ g_string_append_c (string, RAW_CHANGE_CASE (text[0], *change_case)); ++ g_string_append (string, text + 1); ++ } ++ + *change_case = CHANGE_CASE_NONE; + } + else + { +- while (*text != '\0') ++ if (!text_is_raw) + { +- c = g_utf8_get_char (text); +- g_string_append_unichar (string, CHANGE_CASE (c, *change_case)); +- text = g_utf8_next_char (text); ++ while (*text != '\0') ++ { ++ gunichar c = g_utf8_get_char (text); ++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case)); ++ text = g_utf8_next_char (text); ++ } ++ } ++ else ++ { ++ while (*text != '\0') ++ { ++ char c = *text; ++ g_string_append_c (string, RAW_CHANGE_CASE (c, *change_case)); ++ text++; ++ } + } + } + } + ++/* @match_info is (nullable) */ + static gboolean + interpolate_replacement (const GMatchInfo *match_info, + GString *result, +@@ -3194,6 +3222,7 @@ interpolate_replacement (const GMatchInfo *match_info, + InterpolationData *idata; + gchar *match; + ChangeCase change_case = CHANGE_CASE_NONE; ++ gboolean is_raw = (match_info != NULL && (match_info->regex->orig_compile_opts & G_REGEX_RAW)); + + for (list = data; list; list = list->next) + { +@@ -3201,10 +3230,10 @@ interpolate_replacement (const GMatchInfo *match_info, + switch (idata->type) + { + case REPL_TYPE_STRING: +- string_append (result, idata->text, &change_case); ++ string_append (result, idata->text, is_raw, &change_case); + break; + case REPL_TYPE_CHARACTER: +- g_string_append_c (result, CHANGE_CASE (idata->c, change_case)); ++ g_string_append_c (result, UTF8_CHANGE_CASE (idata->c, change_case)); + if (change_case & CHANGE_CASE_SINGLE_MASK) + change_case = CHANGE_CASE_NONE; + break; +@@ -3212,7 +3241,7 @@ interpolate_replacement (const GMatchInfo *match_info, + match = g_match_info_fetch (match_info, idata->num); + if (match) + { +- string_append (result, match, &change_case); ++ string_append (result, match, is_raw, &change_case); + g_free (match); + } + break; +@@ -3220,7 +3249,7 @@ interpolate_replacement (const GMatchInfo *match_info, + match = g_match_info_fetch_named (match_info, idata->text); + if (match) + { +- string_append (result, match, &change_case); ++ string_append (result, match, is_raw, &change_case); + g_free (match); + } + break; +diff --git a/glib/tests/regex.c b/glib/tests/regex.c +index d7a698ec6..bffb52a87 100644 +--- a/glib/tests/regex.c ++++ b/glib/tests/regex.c +@@ -2529,6 +2529,58 @@ test_compiled_regex_after_jit_failure (void) + g_regex_unref (regex); + } + ++static void ++test_replace_raw_change_case (void) ++{ ++ GError *local_error = NULL; ++ GRegex *regex = NULL; ++ ++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3918"); ++ g_test_summary ("Test that case changes as part of a replacement are handled correctly in G_REGEX_RAW mode"); ++ ++ /* ++ * Match a multi-byte sequence in RAW mode. The pattern matches ++ * exactly 2 bytes. The subject contains a 4-byte UTF-8 lead (0xF4) ++ * followed by only one continuation byte, then NUL. ++ * ++ * The matched substring will be "\xf4\x80" (2 bytes, heap-allocated ++ * as 3-byte buffer with NUL). If the code regresses and tries to handle ++ * the replacement as UTF-8 then g_utf8_get_char() would see 0xF4 and try ++ * to read 4 bytes, going 1 byte past the NUL into OOB territory. ++ */ ++ regex = g_regex_new ("..", G_REGEX_RAW, 0, &local_error); ++ g_assert_no_error (local_error); ++ ++ /* ++ * Build a subject string with truncated UTF-8. ++ * \xF4 = 4-byte UTF-8 lead byte ++ * \x80 = continuation byte ++ * No 3rd/4th continuation bytes — the match is only 2 bytes. ++ * ++ * \U\0 = uppercase the entire match → triggers string_append() ++ * with case change on the 2-byte non-UTF-8 match. ++ */ ++ char subject[] = "\xf4\x80"; ++ char *result = g_regex_replace (regex, subject, -1, 0, "\\U\\0", 0, &local_error); ++ g_assert_no_error (local_error); ++ ++ g_clear_pointer (&result, g_free); ++ g_clear_pointer (®ex, g_regex_unref); ++ ++ /* ++ * Second variant: single-char case change \u with \0 backreference. ++ */ ++ regex = g_regex_new (".", G_REGEX_RAW, 0, &local_error); ++ g_assert_no_error (local_error); ++ ++ char subject2[] = "\xe6\xb0"; /* 3-byte UTF-8 lead, only 2 bytes */ ++ result = g_regex_replace (regex, subject2, -1, 0, "\\u\\0", 0, &local_error); ++ g_assert_no_error (local_error); ++ ++ g_clear_pointer (&result, g_free); ++ g_clear_pointer (®ex, g_regex_unref); ++} ++ + int + main (int argc, char *argv[]) + { +@@ -2550,6 +2602,7 @@ main (int argc, char *argv[]) + g_test_add_func ("/regex/jit-unsupported-matching", test_jit_unsupported_matching_options); + g_test_add_func ("/regex/unmatched-named-subpattern", test_unmatched_named_subpattern); + g_test_add_func ("/regex/compiled-regex-after-jit-failure", test_compiled_regex_after_jit_failure); ++ g_test_add_func ("/regex/replace-raw-change-case", test_replace_raw_change_case); + + /* TEST_NEW(pattern, compile_opts, match_opts) */ + TEST_NEW("[A-Z]+", G_REGEX_CASELESS | G_REGEX_EXTENDED | G_REGEX_OPTIMIZE, G_REGEX_MATCH_NOTBOL | G_REGEX_MATCH_PARTIAL); +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index a2de973e218..6dc3e0cc9cd 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -51,6 +51,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-58016-2.patch \ file://CVE-2026-58010.patch \ file://CVE-2026-58011.patch \ + file://CVE-2026-58012.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ From patchwork Sun Jul 26 08:29:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93526 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C59D9C53219 for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7153.1785054628129854451 for ; Sun, 26 Jul 2026 01:30:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rzSHUSoo; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-49545ba3d4eso10021705e9.3 for ; Sun, 26 Jul 2026 01:30:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054626; x=1785659426; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=duXZF6Ijywb7aJ6ZIkUoZTm9Jpqk4sI5rCyKqh32JJw=; b=rzSHUSoojCik4Ac/EX8J87PVLe7inTwEPcDjdouFBc538ifEvuwZsfPr/JuBqqO/gD IiTAMn3KOI4cw4Oa7Qt6yVuxtReaOtsShGYBriHLrQVEWQK7E0YUoAoj4njA4yH30WOI PrNmkr8aL7c/seHYUrso22f0QWuK+++C36+94= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054626; x=1785659426; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=duXZF6Ijywb7aJ6ZIkUoZTm9Jpqk4sI5rCyKqh32JJw=; b=byc+iusEMshUf/0r2imb+UYkf+WZrLCnVJWv1rJKz+jIJmH/RmsWhDHXI5hLaYz2/a PI62evcQWel2Hff9y03QACZPd1M3hx2YplwrhXb7KrPdBXg7UNFR+MppERNdFeYcOI5/ N6HBHkyTmnCB01YGVRc8aNUDDS3vJx5RotQzc6MnZ8Yn5Qn1i8uTTD8VH7XZ5AOuMYuU iaCb9GZaQyT6n6TBYAQwZ4YIGx5wTgZsny9y182FNAx8+Nbwfk6lNFNi4PtDGvCZWjcH xyGStsAl5LUqiDEIg52xGRnRru4yrzY4xfHGYXGpKVmR367eRxkVBz3E9GpTWGS85gzg E4Bw== X-Gm-Message-State: AOJu0YznPT++Bo2UjiaFNEuGMb9o35ChnqF6UnlX5/0pWIj80KCvcz0H 2G33t5CnMREPWT2ykkQ/YR50n2DLUmENcSpStRmNUfbv562zHlb/uNBC5TOU0tAsrVqg5SNgRP2 YFZgrYqA= X-Gm-Gg: AR+sD13bLeFdI1lLdIWYmCg9lY+dBzQ7DPN3SePEshkb4QRNUIhOyr9cmwTx/bagMUa Tuj3vSJszOnZyDXeGa1ktC6dc+nafm9+KBqK9NgHT0e3mfLkgxdaedmLVT+zJpzNc99Skr1gyvM LauXDEmioeLknOOS6JNw4tbpx3Qy1QLWe0p+9fGME7f+2rEeT+qTSCV5G9xo06XD+1I5JzqqAPu PU9P95LpGQ4eD60cb3LNQa8IxpjYmK275oByHQ8qz4e5BGzgxg5FpbqpKziOf6zwG16h67Y5tLR U0UPmSOfnBI2oGw4pQiAWXzyd38OTCisz7HgF+PJOrJoKRxkMbSaEcDJwQEFhlcsKJ6yS78VZRv WOnyoPluKfJbNey8EOwo3Sb51adswET9/bDQDPrd4pHr3TeJyd+8zLAKQ2XjeG2VrdnxP1+roRv 27nl2OEHNxd3g3YzRYtFFoWDa8hahzI2176rm2zfZagxOz3dqBmUWYIh3dtrDN1ZtlGDVTilvbp tZ9GA== X-Received: by 2002:a05:600c:1d11:b0:495:4d5c:903e with SMTP id 5b1f17b1804b1-496b56e6e35mr49857965e9.7.1785054626409; Sun, 26 Jul 2026 01:30:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Date: Sun, 26 Jul 2026 10:29:52 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242010 From: Deepak Rathore This patch applies the upstream 2.88.1 backport for CVE-2026-58013. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58013 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../glib-2.0/glib-2.0/CVE-2026-58013.patch | 140 ++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 + 2 files changed, 141 insertions(+) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch new file mode 100644 index 00000000000..fa3db56bdbc --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch @@ -0,0 +1,140 @@ +From cb9d97e1b261d75eb8ea255e0a9f3e846d547af7 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 28 Apr 2026 16:45:14 +0100 +Subject: [PATCH] giochannel: Fix memcmp() off the end of the buffer with long + terminators +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +If the line terminator is longer than a single byte, and the current +line extends to the end of the buffer, and the buffer (which is a +`GString`) is near a power of two in length (as that’s how `GString`s +are allocated) it’s possible for the `memcmp()` which checks the +terminator to read off the end of the string buffer. + +Fix that by checking the terminator length against the last character +before calling `memcmp()`. Add a unit test. + +Spotted by linhlhq as #YWH-PGM9867-199. The fix is theirs (validated by +me), and the unit test is adapted from their proof of concept. + +Fixes: #3925 + +CVE: CVE-2026-58013 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244] + +Backport Changes: +- Added the include for the regression test because these target + branches do not otherwise expose uint8_t in glib/tests/io-channel.c. + +Signed-off-by: Philip Withnall +(cherry picked from commit 6a2583dec39bfe05553b16d9b7419d6c2a257244) +Signed-off-by: Deepak Rathore +--- + glib/giochannel.c | 3 ++- + glib/tests/io-channel.c | 61 +++++++++++++++++++++++++++++++++++++++++ + 2 files changed, 63 insertions(+), 1 deletion(-) + +diff --git a/glib/giochannel.c b/glib/giochannel.c +index 7572c47a2..8d867d0fb 100644 +--- a/glib/giochannel.c ++++ b/glib/giochannel.c +@@ -1833,7 +1833,8 @@ read_again: + { + if (channel->line_term) + { +- if (memcmp (channel->line_term, nextchar, line_term_len) == 0) ++ if ((size_t) (lastchar - nextchar) >= line_term_len && ++ memcmp (channel->line_term, nextchar, line_term_len) == 0) + { + line_length = nextchar - use_buf->str; + got_term_len = line_term_len; +diff --git a/glib/tests/io-channel.c b/glib/tests/io-channel.c +index c5dd01d04..cf81a9f6b 100644 +--- a/glib/tests/io-channel.c ++++ b/glib/tests/io-channel.c +@@ -29,6 +29,7 @@ + + #include + #include ++#include + + static void + test_small_writes (void) +@@ -216,6 +217,65 @@ test_read_line_embedded_nuls (void) + g_free (filename); + } + ++static void ++test_read_line_long_terminator (void) ++{ ++ uint8_t *test_data = NULL; ++ size_t test_data_len = 0; ++ int fd; ++ char *filename = NULL; ++ GIOChannel *channel = NULL; ++ GError *local_error = NULL; ++ char *line = NULL; ++ size_t line_length, terminator_pos; ++ const char *line_term; ++ int line_term_length; ++ GIOStatus status; ++ ++ g_test_summary ("Test that reading a line when using a long terminator doesn’t over-read the buffer."); ++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/work_items/3925"); ++ ++ /* Write out a temporary file containing 2047 bytes. This is enough to make it ++ * near the length of the GString buffer when read back in. */ ++ fd = g_file_open_tmp ("glib-test-io-channel-XXXXXX", &filename, &local_error); ++ g_assert_no_error (local_error); ++ g_close (g_steal_fd (&fd), NULL); ++ ++ test_data_len = 2047; ++ test_data = g_malloc (test_data_len); ++ memset (test_data, 'M', test_data_len); ++ g_file_set_contents (filename, (const gchar *) test_data, test_data_len, &local_error); ++ g_assert_no_error (local_error); ++ ++ /* Create the channel. */ ++ channel = g_io_channel_new_file (filename, "r", &local_error); ++ g_assert_no_error (local_error); ++ ++ /* Use a long line terminator so it could potentially over-read the end of the buffer. */ ++ g_io_channel_set_line_term (channel, "DEADBEEF", 8); ++ ++ line_term = g_io_channel_get_line_term (channel, &line_term_length); ++ g_assert_cmpstr (line_term, ==, "DEADBEEF"); ++ g_assert_cmpint (line_term_length, ==, 8); ++ ++ g_io_channel_set_encoding (channel, "UTF-8", &local_error); ++ g_assert_no_error (local_error); ++ ++ status = g_io_channel_read_line (channel, &line, &line_length, ++ &terminator_pos, &local_error); ++ g_assert_no_error (local_error); ++ g_assert_cmpint (status, ==, G_IO_STATUS_NORMAL); ++ g_assert_cmpuint (line_length, ==, 2047); ++ g_assert_cmpuint (terminator_pos, ==, 2047); ++ g_assert_cmpmem (line, line_length, test_data, test_data_len); ++ ++ g_free (line); ++ g_io_channel_unref (channel); ++ g_free (test_data); ++ g_unlink (filename); ++ g_free (filename); ++} ++ + int + main (int argc, + char *argv[]) +@@ -224,6 +283,7 @@ main (int argc, + + g_test_add_func ("/io-channel/read-write", test_read_write); + g_test_add_func ("/io-channel/read-line/embedded-nuls", test_read_line_embedded_nuls); ++ g_test_add_func ("/io-channel/read-line/long-terminator", test_read_line_long_terminator); + + return g_test_run (); + } +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index 6dc3e0cc9cd..9516231cbad 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -52,6 +52,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-58010.patch \ file://CVE-2026-58011.patch \ file://CVE-2026-58012.patch \ + file://CVE-2026-58013.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ From patchwork Sun Jul 26 08:29:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93525 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AE538C53200 for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7396.1785054628681117926 for ; Sun, 26 Jul 2026 01:30:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TaLDsPjU; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4955de8797cso10340605e9.3 for ; Sun, 26 Jul 2026 01:30:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054627; x=1785659427; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/HYXkCuMlma+ftjn8rIOlMb/NQ0WcxQ3BemwR6arwlw=; b=TaLDsPjUh7uLVK7y/QhyGEXps35+o6u55g/VV9x/1COGNjJJcneoaOx2E0NztmIH4B 8CYKfHQhAWLtj4193hOHxkWKvTb83HDaYP/K8akbMCdRdv9P6kAdGwDpH/J/wbkOlICO rOQDy+BLzuIW42loL9Hy+CyylvR461BBNl2yA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054627; x=1785659427; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/HYXkCuMlma+ftjn8rIOlMb/NQ0WcxQ3BemwR6arwlw=; b=IH9Zjeyt+GhYbBRT0rBP7BuTU0JfzfO4g73hNXNUInRjW956obxV7gmpMtaIADVEhT fR5P5XlC81A2VzxLmoMH4qda8+FmFnzd8M120/PzqTCwgLO02XOS2tLCokN8t9E+B/Kb Y46ZeaTy73xZJVxWwT0+1fS1jcMQ2Z426IjAAN56v4lA2tO29yapQ54AN1EwhGk3x3PD ij8WOrz2+PBowXqqnvtgMERqjtCljrKiIq23WFF62j85e3PetjKFBl6CD8RStwTBIZE5 AQ/Uk996zXrsESzKBlnGDwAGmDIH5/gw2uaR07vPBTN/XMxMHYgCQROtAQjF7uAmWuWz FsFA== X-Gm-Message-State: AOJu0YxBtjUEnFH9y3RogrtKVostTFq6wPWCHiwD1BneakR8waio4VAH lBZ460izlxQWcjE8Yt2zDsjuG6+M2bKtuggCEDtprgomUVyCGvynVE4OAFPimp2MxqQSfEwa4RV wRECduiw= X-Gm-Gg: AR+sD13TNuFe1ogzUHNoUocGii1DjYg+Kqv0BcQWh4TOXwpo8L2VBrWnz7ugDIjEDOg tjtFsdEjZ/Skf2nmmrlZn8pcb7+Kt35PWcS1+uVA4QwBfCgMIs3KaGyVQbY7udiQ0KI+XOPky4l AWvajyd36kDUj7If/1Rccozm3WSACtlK6o3PTkzxmxYomijJ/8UrSQnatuy+IgONM5M2s2pcT4a vxoXmlxXRj2pdnuYg4LrUBGvh0irLjbdZYZJi3iVS+5ExVYh4AVKXlIKpgWsiRijUMPPYnbuG6F STAbrm9i+pfnAMJMWL7XPGoB5DBbiDtZUBilYwOaWoavKAzkp1YPY7eF5xvBAR44EQ+CD1riLgx UY3wwAjMUq23LWasbjeW4THNoSi/78Wnsi0gFnI/bA/1kbE946eTyg96AwT6K/jagRl7+mqI+5y doMoRFYXCzRj8qq3Qc4Zq7UeiB35EIHgTwhKXzWqXvYXDbYVxSh86jJ8mcECtgvE5ZW1fKD4Vrz 7w0iQ== X-Received: by 2002:a05:600c:253:b0:493:df5d:6ca6 with SMTP id 5b1f17b1804b1-496b571c5fdmr43302845e9.25.1785054626802; Sun, 26 Jul 2026 01:30:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Date: Sun, 26 Jul 2026 10:29:53 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242011 From: Deepak Rathore This patch applies the upstream 2.88.1 backport for CVE-2026-58014. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58014 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../glib-2.0/glib-2.0/CVE-2026-58014.patch | 106 ++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 + 2 files changed, 107 insertions(+) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch new file mode 100644 index 00000000000..4e5262b66de --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch @@ -0,0 +1,106 @@ +From ba0478c206bc04542df774343c6c85f77df49f6e Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Sat, 11 Apr 2026 14:42:57 +0100 +Subject: [PATCH] gkeyfile: Fix a one-byte heap under-read with + g_key_file_get_locale_string_list() + +If this method was called on a key file key which has an empty value, +`len == 0` and this leads to a one-byte under-read off the start of the +key file buffer. + +Spotted by linhlhq as #YWH-PGM9867-200. The suggested fix is theirs, and +the unit test is adapted from their report. I added the fuzzing test. + +Fixes: #3930 + +CVE: CVE-2026-58014 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893] + +Signed-off-by: Philip Withnall +(cherry picked from commit 94ecb5b44a1cae09f481dd5e693832f129948893) +Signed-off-by: Deepak Rathore +--- + fuzzing/fuzz_key.c | 9 +++++++++ + glib/gkeyfile.c | 2 +- + glib/tests/keyfile.c | 23 +++++++++++++++++++++++ + 3 files changed, 33 insertions(+), 1 deletion(-) + +diff --git a/fuzzing/fuzz_key.c b/fuzzing/fuzz_key.c +index 77cb684..7d00443 100644 +--- a/fuzzing/fuzz_key.c ++++ b/fuzzing/fuzz_key.c +@@ -26,11 +26,20 @@ test_parse (const gchar *data, + GKeyFileFlags flags) + { + GKeyFile *key = NULL; ++ char *comment = NULL; ++ char **list = NULL; + + key = g_key_file_new (); + g_key_file_load_from_data (key, (const gchar*) data, size, G_KEY_FILE_NONE, + NULL); + ++ /* Also try some additional parsing and see if it crashes */ ++ comment = g_key_file_get_comment (key, "group", "key", NULL); ++ g_free (comment); ++ ++ list = g_key_file_get_locale_string_list (key, "group", "key", "de", NULL, NULL); ++ g_strfreev (list); ++ + g_key_file_free (key); + } + +diff --git a/glib/gkeyfile.c b/glib/gkeyfile.c +index d08a485..54d77a5 100644 +--- a/glib/gkeyfile.c ++++ b/glib/gkeyfile.c +@@ -2421,7 +2421,7 @@ g_key_file_get_locale_string_list (GKeyFile *key_file, + } + + len = strlen (value); +- if (value[len - 1] == key_file->list_separator) ++ if (len > 0 && value[len - 1] == key_file->list_separator) + value[len - 1] = '\0'; + + list_separator[0] = key_file->list_separator; +diff --git a/glib/tests/keyfile.c b/glib/tests/keyfile.c +index bc125c1..289bd2b 100644 +--- a/glib/tests/keyfile.c ++++ b/glib/tests/keyfile.c +@@ -850,6 +850,28 @@ test_locale_string_multiple_loads (void) + g_free (old_locale); + } + ++static void ++test_locale_string_empty (void) ++{ ++ GKeyFile *keyfile = NULL; ++ GError *local_error = NULL; ++ const char *data = ++ "[valid]\n" ++ "key1=\n"; ++ ++ g_test_summary ("Check that loading an empty translatable string works"); ++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3930"); ++ ++ keyfile = g_key_file_new (); ++ ++ g_key_file_load_from_data (keyfile, data, -1, G_KEY_FILE_NONE, &local_error); ++ g_assert_no_error (local_error); ++ ++ check_locale_string_list_value (keyfile, "valid", "key1", NULL, NULL); ++ ++ g_key_file_free (keyfile); ++} ++ + static void + test_lists (void) + { +@@ -1939,6 +1961,7 @@ main (int argc, char *argv[]) + g_test_add_func ("/keyfile/number", test_number); + g_test_add_func ("/keyfile/locale-string", test_locale_string); + g_test_add_func ("/keyfile/locale-string/multiple-loads", test_locale_string_multiple_loads); ++ g_test_add_func ("/keyfile/locale-string/empty", test_locale_string_empty); + g_test_add_func ("/keyfile/lists", test_lists); + g_test_add_func ("/keyfile/lists-set-get", test_lists_set_get); + g_test_add_func ("/keyfile/group-remove", test_group_remove); diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index 9516231cbad..e15aa1fe206 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -53,6 +53,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-58011.patch \ file://CVE-2026-58012.patch \ file://CVE-2026-58013.patch \ + file://CVE-2026-58014.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ From patchwork Sun Jul 26 08:29:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93523 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A3301C531F9 for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7397.1785054629268506939 for ; Sun, 26 Jul 2026 01:30:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Uyp4Dh+7; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so18641815e9.0 for ; Sun, 26 Jul 2026 01:30:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054627; x=1785659427; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yAaRabXWLB9jUGyIe9SmF6R8cUfssHKE6JrCJ9CX11c=; b=Uyp4Dh+7M8WvHNlg9eYCKECqMidrm0C4sODVgqBFPUFFIyYqqKaYYS4UDUqnib39m6 HpvmlTQM9FpfYJKOmow+JG294PcaDLy0bB7bWB3lU4JpfxP7KZoUrcQuj7l3M2h/DSh5 XtBk6M6teYd2m6wc8CIgMhHmLTpA5B8Bvd2CM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054627; x=1785659427; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=yAaRabXWLB9jUGyIe9SmF6R8cUfssHKE6JrCJ9CX11c=; b=lMdIHHE2csOaaBQTQRzFlcytyf7j5PkKf2/SLoK7EaKUzi7YM0TgwUAgKITGDk7fS6 m1HL7BMxuQh/WjQQdqNFCjsLJVkk1TBWN+9OokPwIfmxhPpanCEXx3gcHiOFVWuDphHY jTJozpirXrcUQX4MZOcreBs6Tg8cL7HY6EdmGymVtTwfFcm7lYCJrrcbKj7ENJK1zkhN Ev2B+W7pCJPEFT70wz58DxpGHUD9TxfolxIf10Sl36ORDO0n7hJqyQ/GtFkLmGpOUpzp vJtvn/RYpz6slua6wmAbFtzs8wW+kJM77aGbHNP3rxGuUNzdLTwHRZWDeuSWdka+XjgM GNcg== X-Gm-Message-State: AOJu0YzbkZtJObW37nadvjgw4UTBU2NlBNN3Uu6XhPm+0XvL3XvKZqXe LWPE1zLBIlv1TC1q2k/y7MDxE6HrhW4eoepcH0baoBbr/Ab+uWyBMOsp77GtAXonFI++RcnxQ8L FFXAYsHo= X-Gm-Gg: AR+sD10ekNp9KMl3TzNgk796VEE1AYrpRi4VZoOB9KWZCM93GJoNPTAApUTWk70YXKX soQKyd1RFtDufR5WpUmmHkJ0taeTuzAKtKVj5hgN+YnJkIugvpcZqhii8hIE/p0wT4RVAg8EMc/ xmJYjalqSbxxzvAQShbkE3n4q9gX1MJN57sWalG+2UmzaxGNSQSQLH2waM5BpaojzFL4s0eeANC zuhtt0o5a7q4U6rimKwvfEgdxBoIVo84A1BGDZYJg+5v4GptyoZqxXRZWFdmtpfhEpDyIlf5CUo iNEtyfo9RXpJdva8y1RCk1qcA/YabV1RSQF0r8KsRA0jNGVAXCjJwSzulmz89LAxUSW3b4DAcE5 ll19r4AH0isEqlx4OGuD88lBY0XSJ66i4ZnlyqcO6X8XEJan3/Maa4y2XEGSLzf3myL6CDVXa/I nd9AImVx24naoDCHQyQjaIc09zx+EoOEIsgIfCkHeQJbClVgU45Etsc/593AncU0BmjG+U29luR 808ew== X-Received: by 2002:a05:600c:4f81:b0:493:f528:58ac with SMTP id 5b1f17b1804b1-496b56f9d75mr64085495e9.21.1785054627465; Sun, 26 Jul 2026 01:30:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Date: Sun, 26 Jul 2026 10:29:54 +0200 Message-ID: <756270e9b67b97b276729daba50febe7093d85b3.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242012 From: Darsh Kelaiya This patch applies the upstream fix for CVE-2026-41991 as referenced in [2], using the upstream commit identified in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-41991 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../gzip/gzip-1.13/CVE-2026-41991.patch | 75 +++++++++++++++++++ meta/recipes-extended/gzip/gzip_1.13.bb | 1 + 2 files changed, 76 insertions(+) create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch diff --git a/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch new file mode 100644 index 00000000000..9728b38658d --- /dev/null +++ b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch @@ -0,0 +1,75 @@ +From 0af3a96047fe02690473d4e106c39552e0c1285e Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Thu, 16 Apr 2026 12:11:44 -0700 +Subject: [PATCH] gzexe: use -C if lacking mktemp +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +(Problem reported by Michał Majchrowicz.) +* gzexe.in: If mktemp is needed but not installed, +use ‘set -C’ to avoid a race when creating a temporary file. +* zdiff.in: Use the same pattern here, even though the old +code was probably OK anyway. + +CVE: CVE-2026-41991 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269] + +(cherry picked from commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269) +Signed-off-by: Darsh Kelaiya +--- + NEWS | 5 +++++ + gzexe.in | 1 + + zdiff.in | 7 +++---- + 3 files changed, 9 insertions(+), 4 deletions(-) + +diff --git a/NEWS b/NEWS +index 6a20892..c643b2f 100644 +--- a/NEWS ++++ b/NEWS +@@ -1,5 +1,10 @@ + GNU gzip NEWS -*- outline -*- + ++ On old-fashioned or limited platforms lacking mktemp, gzexe and ++ zdiff no longer have a race when creating a temporary file. ++ [bug present since the beginning] ++ ++ + * Noteworthy changes in release 1.13 (2023-08-19) [stable] + + ** Changes in behavior +diff --git a/gzexe.in b/gzexe.in +index 5e3d4c2..f31b9c8 100644 +--- a/gzexe.in ++++ b/gzexe.in +@@ -128,6 +128,7 @@ for i do + tmp=`mktemp "${dir}gzexeXXXXXXXXX"` + else + tmp=${dir}gzexe$$ ++ (umask 77; set -C; > "$tmp") + fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || { + res=$? + printf >&2 '%s\n' "$0: cannot copy $file" +diff --git a/zdiff.in b/zdiff.in +index e35e6fe..bbcc75b 100644 +--- a/zdiff.in ++++ b/zdiff.in +@@ -157,12 +157,11 @@ case $file2 in + *) TMPDIR=/tmp/;; + esac + if type mktemp >/dev/null 2>&1; then +- tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` || +- exit 2 ++ tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` + else +- set -C + tmp=${TMPDIR}zdiff$$ +- fi ++ (umask 77; set -C; > "$tmp") ++ fi && + 'gzip' -cdfq -- "$file2" > "$tmp" || exit 2 + gzip_status=$( + exec 4>&1 +-- +2.44.4 + diff --git a/meta/recipes-extended/gzip/gzip_1.13.bb b/meta/recipes-extended/gzip/gzip_1.13.bb index 208220867a6..4ab3b1d523c 100644 --- a/meta/recipes-extended/gzip/gzip_1.13.bb +++ b/meta/recipes-extended/gzip/gzip_1.13.bb @@ -7,6 +7,7 @@ LICENSE = "GPL-3.0-or-later" SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \ file://run-ptest \ file://CVE-2026-41992.patch \ + file://CVE-2026-41991.patch \ " SRC_URI:append:class-target = " file://wrong-path-fix.patch" From patchwork Sun Jul 26 08:29:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93524 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90CF2C531CC for ; Sun, 26 Jul 2026 08:30:32 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7398.1785054629947089385 for ; Sun, 26 Jul 2026 01:30:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=A7jpBmqg; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-493b966dd74so10986355e9.3 for ; Sun, 26 Jul 2026 01:30:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785054628; x=1785659428; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rkozmByKv/QMp7pMK+WnzT0CXntBTwyeWlewq+5BGjI=; b=A7jpBmqgaEy4OnDtuJlJTWgYGyHKZGD9yMb38bqGhDDxvo2agriMCShjNdpnkhLgDZ qeuoIlMpN5NVv9HNttI3qQZpxw3M6euNnZTpUWeWjY1CKrbFioqTNX5v1VYhI084PbI2 wMQHyh67fhxbiMCpY8Fn8OZm96aRp6mpzgbTE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785054628; x=1785659428; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rkozmByKv/QMp7pMK+WnzT0CXntBTwyeWlewq+5BGjI=; b=N/WZws5VpabL5Jf/CrT9kzNm57svNlv7Qb51PFvFMzHx0sHug1VU+GeWLy01Y/vAq5 bzHfIZAcqO/9oVv5/trtIJYXXdZS5bkWfCbjiXcxAtSLkzplxVDnsrqg/my3YdJrbCWP 48zH7wHzJ4MLGWRsBhbCuvvvvjqG440x3mb4duNaocMOUlRQXQ/68e7mpTaYqDNbVP6w D/7fO+SmFtBFf+v6n2nE64cOgr4FR+a446o1PI9OE0oClSIa4Hpdta0kqLoiT2BlJbiF GCX94BKGc3Bd9BB3h62ZkTSK2oH9WPrq7aFq2ULbiK9DR/n8hHXaI4MDUjdO42GsmB0k Xg+w== X-Gm-Message-State: AOJu0Yy6sfAvMDfvYLAcABjk/X6LGtX59ORdkf4KvD/+sGOSIU4FnvmX gVJuHq2SmU8o+Z0JfdznytsNQUD1+2IobSI3oUZUljXfRfbyQqQYW8g9QkhYzU5Mjs0JAlRXWWk xih3Rsfg= X-Gm-Gg: AR+sD10Y6YcGqOyQlW9ByAhkG6CAClNMDrlGMpwKL67aU9XnVwm8dXyVO0cx6pkfZcb wY2RInrWNzcEM6xqWJeJvqFJfIX/r0qKkK9897X2pq08vfgZe/bemlItmmEFG0sV4xf++YInxnu f+oeRuQTHRKm/GHZZ4rMqBbWqZq0H2SrV3UKBahLqMal5KoidlyzTGEeVP7BULqE9qxsnt5eoTu gsIHK0WovRQI3Q+kakmGyE9i+nUFNwz3gGbrkmMi3ettMqumJz5OG5/xAdwEXJWygWH3AcWODwM CYLaIchkQqt2XLf1s7GxjPQ3PR546gW60zvkFsdW7oDe5LmSVJ3XUVVQpH1k3FFvo9GRj8vn7+Y UEWfOY6JsUESEmuqbAkrG8FBEkgrdhgEqo0mIbpa6ptNmZu3lbEN5QQIKpKMj8kOKAVtKQXoFUc vDFq6/DIcVkBUSL/iu3BqLecGUNkkeGGTrP2POvzofYx9qZkmWauRO5Z2rcyRDsunFkChT3OFaV X4DtQ== X-Received: by 2002:a05:600c:3b1d:b0:493:f5bf:4dc6 with SMTP id 5b1f17b1804b1-496b56e6e1fmr61027275e9.7.1785054628068; Sun, 26 Jul 2026 01:30:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4f24a93sm142482505e9.11.2026.07.26.01.30.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 01:30:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Date: Sun, 26 Jul 2026 10:29:55 +0200 Message-ID: <762321beb0260b1411c7f98f13458ec99a118280.1785054430.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 26 Jul 2026 08:30:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242013 From: Hongxu Jia According to [1] As of the current version 1.0.8, bzip2 --version will print version info but it will also continue compressing stdin: $ ./bzip2 --version bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019. Copyright (C) 1996-2019 by Julian Seward. This program is free software; [...] bzip2: I won't write compressed data to a terminal. bzip2: For help, type: `bzip2 --help'. This is a long-standing bug, not new to 1.0.8 -- the same code (license() followed by break, with no exit) exists in bzip2 1.0.6 and earlier. The upstream bzip2 master branch on GitLab already includes this fix. Debian (and its downstreams like Ubuntu) will patch this out [2], making the < /dev/null unnecessary, port a part of debian patch to fix the issue [1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2 [2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/ Signed-off-by: Hongxu Jia Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit ae4fe4263ba9d372f9b9e80df4ec4697b51c1f9b) [Jaipaul: backport to scarthgap -- added commit message context that this is a long-standing bug (not new to 1.0.8), updated Upstream-Status in patch to actual mailing list URL in the patch file, this patch is already present on master, wrynose and walnascar branches using the same bzip2 1.0.8] Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- ...-fix-bzip2-version-tmp-aaa-will-hang.patch | 65 +++++++++++++++++++ meta/recipes-extended/bzip2/bzip2_1.0.8.bb | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch diff --git a/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch new file mode 100644 index 00000000000..2d02328d116 --- /dev/null +++ b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch @@ -0,0 +1,65 @@ +From a9dd6acbaca836fc4e943e69a31b2e7acda32045 Mon Sep 17 00:00:00 2001 +From: Hongxu Jia +Date: Wed, 13 Nov 2024 19:49:23 +0800 +Subject: [PATCH] fix 'bzip2 --version > /tmp/aaa 2>&1' hang + +According to [1] + +As of the current version 1.0.8, bzip2 --version will print version +info but it will also continue compressing stdin: + + $ ./bzip2 --version + bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019. + + Copyright (C) 1996-2019 by Julian Seward. + + This program is free software; [...] + + bzip2: I won't write compressed data to a terminal. + bzip2: For help, type: `bzip2 --help'. + +Debian (and its downstreams like Ubuntu) will patch this out [2], +making the < /dev/null unnecessary: + +[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2 +[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/ + +Upstream-Status: Submitted [https://sourceware.org/pipermail/bzip2-devel/2024q4/000234.html] +Note: updated Upstream-Status URL to point to the actual mailing list +archive entry. + +Signed-off-by: Hongxu Jia +Signed-off-by: Jaipaul Cheernam +--- + bzip2.c | 8 +++++--- + 1 file changed, 5 insertions(+), 3 deletions(-) + +diff --git a/bzip2.c b/bzip2.c +index d95d280..6ec9871 100644 +--- a/bzip2.c ++++ b/bzip2.c +@@ -1890,7 +1890,9 @@ IntNative main ( IntNative argc, Char *argv[] ) + case '8': blockSize100k = 8; break; + case '9': blockSize100k = 9; break; + case 'V': +- case 'L': license(); break; ++ case 'L': license(); ++ exit ( 0 ); ++ break; + case 'v': verbosity++; break; + case 'h': usage ( progName ); + exit ( 0 ); +@@ -1916,8 +1918,8 @@ IntNative main ( IntNative argc, Char *argv[] ) + if (ISFLAG("--keep")) keepInputFiles = True; else + if (ISFLAG("--small")) smallMode = True; else + if (ISFLAG("--quiet")) noisy = False; else +- if (ISFLAG("--version")) license(); else +- if (ISFLAG("--license")) license(); else ++ if (ISFLAG("--version")) { license(); exit ( 0 ); } else ++ if (ISFLAG("--license")) { license(); exit ( 0 ); } else + if (ISFLAG("--exponential")) workFactor = 1; else + if (ISFLAG("--repetitive-best")) redundant(aa->name); else + if (ISFLAG("--repetitive-fast")) redundant(aa->name); else +-- +2.34.1 + diff --git a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb index b661bc95465..6c02dc3ed06 100644 --- a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb +++ b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb @@ -27,6 +27,7 @@ SRC_URI = "https://sourceware.org/pub/${BPN}/${BPN}-${PV}.tar.gz \ file://Makefile.am;subdir=${BP} \ file://run-ptest \ file://CVE-2026-42250.patch;subdir=${BP} \ + file://0001-fix-bzip2-version-tmp-aaa-will-hang.patch;subdir=${BP} \ " SRC_URI[md5sum] = "67e051268d0c475ea773822f7500d0e5" SRC_URI[sha256sum] = "ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269"