From patchwork Wed Jul 29 09:25:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93848 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5789DC54F52 for ; Wed, 29 Jul 2026 09:26:00 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7527.1785317157538721519 for ; Wed, 29 Jul 2026 02:25:57 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=aTYsMlgJ; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3369; q=dns/txt; s=iport01; t=1785317157; x=1786526757; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=F534kOnfo9Mrk19iuP1s/rrixLdnyaKW7yNfpYkmC48=; b=aTYsMlgJqaLXM+KdfJ4LYSyCGDOPLmkJSgjijPFonFWkdamp3LB88Hp+ 7NIfJ5zuQcQhllGU+Ru8q05uhpOc2ittGrp74kkIGZNhCE9NHVYTN1Uzn GURrSTnGPN/xscb4D9I1FVbXI7ECJ6+r4SY21UUiBZeOgwC/A5h/96ISR jz8ZYFVXye5te8a7TYa1PCd79SrCxIw0sYztWV1hLqMjBOI9hZwL0e57O hgQsmcJL96MnXBodmyMu3Yds2Z6H7PJoranNsoiKJMSrLIY9feVko4i5M FYPZVjGKo1odr3AFtKSwf+zoF6P/ZBChsTNgTr68eq2cvHFnqyYXtZ6zR g==; X-CSE-ConnectionGUID: J3nSmcb8Sa2Pi4V3A8au7w== X-CSE-MsgGUID: 7NblN7VpTWOrui1WWAhpIg== X-IPAS-Result: A0BFAgC9xmlq/5UQJK1aglmCV3ReQ0mVXmyBFp0IgX4PAQEBD0QNBAEBhQWNaAImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2GWgECATUBRiwDAQJaIyGDAgGCdAMRviiCLIEBg1oFCQJDUNsuAQsUAQWBM4U/iCBcGAGEfCcbG4FygRWCc3aBBYE+HgEBiCUEgiKBDIFaHpA3SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwcFgR2BLD+EVyMZNn+BL3VKdy1pARIXgRqDOQKCQQMLGA1IESw3FBkEPm4HjW8hgkQBgQ4BKgEgggyTLpJIgTWfWgoog3WMIZU6GjOEBIFXpRGZCIJZizGWGTeEaYFoPIFHCwdwFYMiCUoZD44uCguDYIF/gxQuBskSJzILMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:3h4yUa0i+UU+iVF/1fbD5YVwkn2cJEfYwER7XKvMYLTBsI5bpzwCz 2sYWWrUaf2JZjOne4olaN6w90sDuZ7VydJrSAJo3Hw8FHgiRegpqji6wuYcGwvIc6UvmWo+t 512huHodZ5yEzmE4EjxYtANlFEkvYmQXL3wFeXYDS54QA5gWU8JhAlq8wIDqtYAbeORXUXX5 Lsen+WFYAX7g2EuYzpNg06+gEoHUMra6WtwUmMWPZinjHeG/1EJAZQWI72GLneQauF8Au6gS u/f+6qy92Xf8g1FIovNfmHTKxBirhb6ZGBiu1IOM0SQqkEqSh8ajs7XAMEhhXJ/0F1lqTzeJ OJl7vRcQS9xVkHFdX90vxNwS0mSNoUekFPLzOTWXcG7lyX7n3XQL/pGLhowBogT8LZMCDt29 KAmcxldZw3cmLfjqF67YrEEasULJc3vOsYb/3pn1zycVKxgSpHYSKKM7thdtNsyrpkRRrCFO YxAN3w2MEWojx5nYj/7DLo+gOehhXDlWzZZs1mS46Ew5gA/ySQhiOe9b4OFJ43iqcN9wWCSo kSZwXzFPTYAKd3G9gWs8mqNibqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+rfSnh0qWX9NEN 1dS/TIjq6U3/kGnQtTxGRqirxa5UgU0Ut5UFag+rQqK0KeRulzfDWkfRTkHY9sj3CMreQEXO payt4uBLVRSXHe9EBpxKp/8QeuOBBUo IronPort-HdrOrdr: A9a23:VAse+6yH8IhBjesnnSi3KrPwAL1zdoMgy1knxilNoNJuHfBw8P re+cjzuiWUtN98YhwdcLO7Scu9qA3nlaKdiLN5VdzJYOCMggWVxe9ZgbcK6geQfxEWjtQttp tIQuxZFMD6C0R8gILR5Qm1FMtl/fy8mZrY4ts3CxxWPHhXg2YK1XYeNjqm X-Talos-CUID: 9a23:FjbL928/iB6hqCwJ3SWVv2xPHPsgeXeN936KG07kNz1AGLSIFkDFrQ== X-Talos-MUID: 9a23:IU4+ugafE+/mKOBT6BnmgBc9Ct9U3IO0FUFUrqovu9GlOnkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,192,1779148800"; d="scan'208";a="807871859" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Jul 2026 09:25:56 +0000 Received: from sjc-ads-5471.cisco.com (sjc-ads-5471.cisco.com [10.28.23.235]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id 69AB41800016A; Wed, 29 Jul 2026 09:25:56 +0000 (GMT) Received: by sjc-ads-5471.cisco.com (Postfix, from userid 1887505) id 0ADA9CC12A6; Wed, 29 Jul 2026 02:25:56 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [meta-oe][scarthgap][PATCH 1/5] libdbi-perl: Fix CVE-2026-9698 Date: Wed, 29 Jul 2026 02:25:51 -0700 Message-Id: <20260729092556.45457-1-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-5471.cisco.com [10.28.23.235];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 10.28.23.235, sjc-ads-5471.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 29 Jul 2026 09:26:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128557 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-9698 Signed-off-by: Hetvi Thakar --- .../perl/libdbi-perl/CVE-2026-9698.patch | 43 +++++++++++++++++++ .../perl/libdbi-perl_1.643.bb | 1 + 2 files changed, 44 insertions(+) create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-9698.patch diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-9698.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-9698.patch new file mode 100644 index 0000000000..28540c51f4 --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-9698.patch @@ -0,0 +1,43 @@ +From 216bf2cce660265bf7035610fbc67978d65a4ab3 Mon Sep 17 00:00:00 2001 +From: "H.Merijn Brand - Tux" +Date: Wed, 27 May 2026 11:16:50 +0200 +Subject: [PATCH] Fix possible stack overflow (old issue already noted by Tim) + +CVE: CVE-2026-9698 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e] + +Backport Changes: + - Omit ChangeLog, dbixs_rev.h, and lib/DBI/Changes.pm release metadata because the target remains DBI 1.643. + - Omit the unrelated Makefile.PL documentation-generation update; the DBI.xs security hunk is unchanged. + +(cherry picked from commit bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e) +Signed-off-by: Hetvi Thakar +--- + DBI.xs | 7 ++----- + 1 file changed, 2 insertions(+), 5 deletions(-) + +diff --git a/DBI.xs b/DBI.xs +index 2cea4ac..c549d15 100644 +--- a/DBI.xs ++++ b/DBI.xs +@@ -3998,7 +3998,6 @@ XS(XS_DBI_dispatch) + SV **statement_svp = NULL; + const int is_warning = (!SvTRUE(err_sv) && strlen(SvPV_nolen(err_sv))==1); + const char *err_meth_name = meth_name; +- char intro[200]; + + if (meth_type == methtype_set_err) { + SV **sem_svp = hv_fetch((HV*)SvRV(h), "dbi_set_err_method", 18, GV_ADDWARN); +@@ -4006,10 +4005,8 @@ XS(XS_DBI_dispatch) + err_meth_name = SvPV_nolen(*sem_svp); + } + +- /* XXX change to vsprintf into sv directly */ +- sprintf(intro,"%s %s %s: ", HvNAME(DBIc_IMP_STASH(imp_xxh)), err_meth_name, +- SvTRUE(err_sv) ? "failed" : is_warning ? "warning" : "information"); +- msg = sv_2mortal(newSVpv(intro,0)); ++ msg = sv_2mortal(newSVpvf("%s %s %s: ", HvNAME(DBIc_IMP_STASH(imp_xxh)), err_meth_name, ++ SvTRUE(err_sv) ? "failed" : is_warning ? "warning" : "information")); + if (SvOK(DBIc_ERRSTR(imp_xxh))) + sv_catsv(msg, DBIc_ERRSTR(imp_xxh)); + else diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb index 1fee83a8fd..88d5aa3294 100644 --- a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb +++ b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb @@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=10982c7148e0a012c0fd80534522f5c5" SRC_URI = "http://search.cpan.org/CPAN/authors/id/T/TI/TIMB/DBI-${PV}.tar.gz \ file://CVE-2014-10402.patch \ + file://CVE-2026-9698.patch \ " SRC_URI[md5sum] = "352f80b1e23769c116082a90905d7398" SRC_URI[sha256sum] = "8a2b993db560a2c373c174ee976a51027dd780ec766ae17620c20393d2e836fa" From patchwork Wed Jul 29 09:25:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93850 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5CD29C54FCD for ; Wed, 29 Jul 2026 09:26:10 +0000 (UTC) Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7530.1785317162970021642 for ; Wed, 29 Jul 2026 02:26:03 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=h5rDcWsw; spf=pass (domain: cisco.com, ip: 173.37.142.91, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2938; q=dns/txt; s=iport01; t=1785317163; x=1786526763; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=3CAyXnC7SH8bRcTasXWaaO4w/IF2SEAHEuFQy9HItB4=; b=h5rDcWswyoaTRYc/Puu8T+Gpgl6lYXWNXI3UGNWd9qOpYxyOmdRWnhLv hbyB0hSh4DfyG1zLYW6ncTQFLPhRDk/OvDIvGjJpVzyyBupCvl2oaxMMK Ab1XO7yTWhb2gEN+lzS04dsmxpqV83wAmxvliWNAdu+R6zYeIaHqRRZBg myRCUfXincct5PB1ez8SwvZ/s1nMn/x0vBn9SgZc9Pkvq2RwCsVVVOhq+ dIUlXvPG8I6o/yjXJlTH/839eVyJlmwPftH65kfRyVJHU+LlzKBJ3/reI K8NVUZ+9dZVpWqjMRi21Pe+tBc4wIZcuHf6b+Xk8goovSm0SRoe1lRV3J g==; X-CSE-ConnectionGUID: wdREonRsQnK4vzwyVnnThw== X-CSE-MsgGUID: BVaDw/N4SIqGFvW5oiH9Jg== X-IPAS-Result: A0BHAgC9xmlq/5UQJK1aglmCV3ReQ0kDlVtsA4ETnQiBfg8BAQEPRA0EAQGFBQKNZgImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAzIBRhAcAwECLysjCBmDAgGCdAMRviiCLIEBg2gCQ1DbLgELFAEFgTOFP4ggXBgBhHwnGxuBcoEVgnN2gQWBPh4CgSeBBoV4BIIigQyBWh6QN0iBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsHBYEdgSw/hFcjGTZ/gS91SnctaQESF4EagzkCgkEDCxgNSBEsNxQZBD5uB41vIYJFgQ4BKgGCLEulK6EPCiiDdYwhlToaM4VbpRELmH2OCpZQhGmBaDyBWXAVgyIJShkPji0BCguDYIUTNMkSJzILAy8BAQcCBw4DC4FokACBfgEB IronPort-Data: A9a23:64ZyEqz2BVorYYnZKyJ6t+dhxyrEfRIJ4+MujC+fZmUNrF6WrkUPn WAYDz3VPa3YZWWhKN4kO4Sx9kJSusKAnNQ2S1Ztq1hgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCea/VH1buSJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 46aT/H3Ygf/hWYraDNMsspvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJF46B6Af/NxsOGdtq eIKNyEzaBa/h/3jldpXSsE07igiBMDvOIVavjRryivUSK98B5vCWK7No9Rf2V/chOgXQq2YP JRfMGQpNUiRC/FMEg9/5JYWnPuoj3r2aRVTqUmeouw85G27IAlZj+m1YYuJIIbQLSlTtmymr 07ZuEKlOTADG/KB9meC81L9pOCayEsXX6pXTtVU7MVCh0WewGEWAhAaWVa35PW0lEO6c9ZeM FAPvC02oK4/8UamQtXwU1u/unHsg/IHc9NUF+t/7ESGzbDZpl/DQGMFVTVGLtchsafaWAAX6 7NApPuxbRQHjVFfYS31Gmu8xd9qBRUoEA== IronPort-HdrOrdr: A9a23:eXTSEavJhSH7FlHke9PtOoq67skDrtV00zEX/kB9WHVpmwKj+P xG+85rsiMc5wxxZJhNo7290ey7MBHhHP1OkO0s1MmZPDUO0VHAROoJ0WKh+UyEJ8SUzIBgPM lbH5SWIeeAa2SS9fyKgzWQIpIH3MSN9ryuiKP1yndgShwvVoRbhj0Jczpy1iZNNXJ77V1TLu vl2vZ6 X-Talos-CUID: 9a23:ShP9Om8HoBcLCVzFPnSVv1EYIO0idEfG9XHzf1GqFndXTrupSUDFrQ== X-Talos-MUID: 9a23:EkBJaAoThAe7XU1DDUwezxtcPet3pILyM2EUvrsYhJSDNAwhGTjI2Q== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,192,1779148800"; d="scan'208";a="790994222" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Jul 2026 09:25:56 +0000 Received: from sjc-ads-5471.cisco.com (sjc-ads-5471.cisco.com [10.28.23.235]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id 735D318000214; Wed, 29 Jul 2026 09:25:56 +0000 (GMT) Received: by sjc-ads-5471.cisco.com (Postfix, from userid 1887505) id 0D6F7CC12A7; Wed, 29 Jul 2026 02:25:56 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [meta-oe][scarthgap][PATCH 2/5] libdbi-perl: Fix CVE-2026-10879 Date: Wed, 29 Jul 2026 02:25:52 -0700 Message-Id: <20260729092556.45457-2-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260729092556.45457-1-hthakar@cisco.com> References: <20260729092556.45457-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-5471.cisco.com [10.28.23.235];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 10.28.23.235, sjc-ads-5471.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 29 Jul 2026 09:26:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128560 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978 [2] https://security-tracker.debian.org/tracker/CVE-2026-10879 Signed-off-by: Hetvi Thakar --- .../perl/libdbi-perl/CVE-2026-10879.patch | 34 +++++++++++++++++++ .../perl/libdbi-perl_1.643.bb | 1 + 2 files changed, 35 insertions(+) create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-10879.patch diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-10879.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-10879.patch new file mode 100644 index 0000000000..9979f63243 --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-10879.patch @@ -0,0 +1,34 @@ +From 2a69c8a256fa83dee2e532c97d3f60f39795c861 Mon Sep 17 00:00:00 2001 +From: "H.Merijn Brand - Tux" +Date: Thu, 28 May 2026 14:14:50 +0200 +Subject: [PATCH] Replacing `?` with `:p#` in `preparse ()` with more than 9 + `?` causes buffer overflow + +`:p1` is length 3, `?` just 1, but `:p1003` is length 6! + +CVE: CVE-2026-10879 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978] + +Backport Changes: + - Omit ChangeLog, dbixs_rev.h, and lib/DBI/Changes.pm release metadata because the target remains DBI 1.643. + - Omit generated doc/DBI.3 and doc/DBI.man changes; the DBI.xs security hunk is unchanged. + +(cherry picked from commit af79036c07aa9a457971c0f4136e37c85dc20978) +Signed-off-by: Hetvi Thakar +--- + DBI.xs | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/DBI.xs b/DBI.xs +index c549d15..8858e21 100644 +--- a/DBI.xs ++++ b/DBI.xs +@@ -4201,7 +4201,7 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + } + + /* XXX this allocation strategy won't work when we get to more advanced stuff */ +- new_stmt_sv = newSV(strlen(statement) * 3); ++ new_stmt_sv = newSV(strlen(statement) * 6 + 16); + sv_setpv(new_stmt_sv,""); + src = statement; + dest = SvPVX(new_stmt_sv); diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb index 88d5aa3294..99e8c209fe 100644 --- a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb +++ b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb @@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=10982c7148e0a012c0fd80534522f5c5" SRC_URI = "http://search.cpan.org/CPAN/authors/id/T/TI/TIMB/DBI-${PV}.tar.gz \ file://CVE-2014-10402.patch \ file://CVE-2026-9698.patch \ + file://CVE-2026-10879.patch \ " SRC_URI[md5sum] = "352f80b1e23769c116082a90905d7398" SRC_URI[sha256sum] = "8a2b993db560a2c373c174ee976a51027dd780ec766ae17620c20393d2e836fa" From patchwork Wed Jul 29 09:25:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93849 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BF2D2C54FCD for ; Wed, 29 Jul 2026 09:26:00 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7527.1785317157538721519 for ; Wed, 29 Jul 2026 02:25:57 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=jGL8y2LO; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=9828; q=dns/txt; s=iport01; t=1785317157; x=1786526757; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=4pNI5N5fgEhEkAGKPunuVSwLOUK15KFnHdwBw6MS54I=; b=jGL8y2LOmLh8TdYqe+3QhwRFvqToBVCyO39mhTDPB5e8wO5y01ADv8Ba v+u0RQ/QfKf79ziDlPwUzLYM9c+gd0JzHirTXRpcrChu8VBR+d03EOQqv qAVk30upwHx/cWQf5ufVBTgAqF+JwVgqOFNCvH3+ai/MeDE1SwfFFLK8n KkL4X24cwetZvkdWldSmd42PgVdezQePljuVZyVbYNGvfZS6FcFSyl94b yRQ3JZtfj1ZE2H7z6Jc9kU1NKM4G9LgDOLxlx/dRBuZcaoasA9PBmOWqX mGNeWDsYlf4SfEBMZCFWSslLhU8AdodnvhTNZTVJ5Qh0UBfYCuck22E8t g==; X-CSE-ConnectionGUID: Mn7ZPtWaS3mhb2vGyoTSsg== X-CSE-MsgGUID: nCAuaOnOR8KHJUksfnDyFA== X-IPAS-Result: A0BIAgC9xmlq/5IQJK1aglmCV3ReQ0mVXmwDgROdCIF+DwEBAQ9EDQQBAYUFAo1mAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAycLAUYQHAMBAi8rIwgZgwIBgnQDEb4ogXkzgQGDaAJDUNsuAQsUAQWBM4U/iCBcGAFEhDgnGxuBcoEVgnN2gQWBPh4BAYEnhn4EgiKBDIFaHpA3SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwcFgR2BLD+EVyMZNn+BL3VKdy1pARIXgRqDOQKCQQMLGA1IESw3FBkEPm4HjW8hgkWBDgEqAQl8FjUzk1aSSaEPCiiDdYwhlToaM4VbpRELmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OLgoLg2CBf4MUNMkSJzILMgEBBwIHDgMLgWiQAIF+AQE IronPort-Data: A9a23:xErh7aOfqEFIJKHvrR3zlsFynXyQoLVcMsEvi/4bfWQNrUokg2ZSy 2JKCzqCaa6DNzbwKd11OoWxox4HuMDSmNRqHXM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeap1yFjmD+kfF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf6gW8sawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj69BoU3MOIbIRwb1yAWsU6 9MJLww2dR/W0opawJrjIgVtrs0nKM+uOMYUvWttiGmIS/0nWpvEBa7N4Le03h9p2ZsIRqiYP pRfMGYxBPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237nFQugOe0YISMEjCMbcN+t1uRg WThxTTaIjMnN8eRzxaU3Fv504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFe2v/S9okq/QM5Eb UsM9ywjqKI/+ECmQp/6RRLQnZKflhcYX9wVF6gx7xuAj/KFpQ2YHWMDCDVGbbTKqfMLeNDj7 XfR9/uBONClmOb9pa61nltMkQ6PBA== IronPort-HdrOrdr: A9a23:+CRVMKEdmgzTljSUpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:6KPZMmoV/O68EcdURLcLFsDmUeUjLU/l0EjZGBS9CWwzVpKETmOr46wxxg== X-Talos-MUID: 9a23:WzgDFA4hLOs7M9KemWvEi3sExoxuyI2zAWcLtq9WmOmmCC9rNTGxnRqeF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,192,1779148800"; d="scan'208";a="807871861" Received: from alln-l-core-09.cisco.com ([173.36.16.146]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Jul 2026 09:25:56 +0000 Received: from sjc-ads-5471.cisco.com (sjc-ads-5471.cisco.com [10.28.23.235]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-09.cisco.com (Postfix) with ESMTPS id 6F8661800047E; Wed, 29 Jul 2026 09:25:56 +0000 (GMT) Received: by sjc-ads-5471.cisco.com (Postfix, from userid 1887505) id 121A3CC12A8; Wed, 29 Jul 2026 02:25:56 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [meta-oe][scarthgap][PATCH 3/5] libdbi-perl: Fix CVE-2026-14380 Date: Wed, 29 Jul 2026 02:25:53 -0700 Message-Id: <20260729092556.45457-3-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260729092556.45457-1-hthakar@cisco.com> References: <20260729092556.45457-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-5471.cisco.com [10.28.23.235];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 10.28.23.235, sjc-ads-5471.cisco.com X-Outbound-Node: alln-l-core-09.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 29 Jul 2026 09:26:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128558 From: Hetvi Thakar Backport the ordered upstream fix and regression-test chain from DBI 1.650. Add perl-module-load to RDEPENDS to satisfy the runtime dependency introduced by the primary fix's use of Module::Load. [1] https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 [2] https://github.com/perl5-dbi/dbi/commit/d982411aec73b3acfc4e9e465358bca9eb7fede8 [3] https://github.com/perl5-dbi/dbi/commit/f94685f415b08ea4b1f183d48430c4583c1c07d0 [4] https://github.com/perl5-dbi/dbi/commit/7949e551b3c7a8854926b6de84f6cc2ceafb2200 [5] https://nvd.nist.gov/vuln/detail/CVE-2026-14380 Signed-off-by: Hetvi Thakar --- .../perl/libdbi-perl/CVE-2026-14380_p1.patch | 37 +++++++++++ .../perl/libdbi-perl/CVE-2026-14380_p2.patch | 65 +++++++++++++++++++ .../perl/libdbi-perl/CVE-2026-14380_p3.patch | 27 ++++++++ .../perl/libdbi-perl/CVE-2026-14380_p4.patch | 56 ++++++++++++++++ .../perl/libdbi-perl_1.643.bb | 5 ++ 5 files changed, 190 insertions(+) create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p1.patch create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p2.patch create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p3.patch create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p4.patch diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p1.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p1.patch new file mode 100644 index 0000000000..eae236527e --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p1.patch @@ -0,0 +1,37 @@ +From b588d38661f00361bcf62b2665905ade844866ee Mon Sep 17 00:00:00 2001 +From: Robert Rothenberg +Date: Wed, 1 Jul 2026 22:31:56 +0100 +Subject: [PATCH] Load profile packages using Module::Load [CVE-2026-14380] + +CVE: CVE-2026-14380 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259] + +(cherry picked from commit b73d5d9901767fc1d16b6661ef08fbed4532e259) +Signed-off-by: Hetvi Thakar +--- + lib/DBI/Profile.pm | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/lib/DBI/Profile.pm b/lib/DBI/Profile.pm +index f2cc886..4188462 100644 +--- a/lib/DBI/Profile.pm ++++ b/lib/DBI/Profile.pm +@@ -679,6 +679,7 @@ use vars qw(@ISA @EXPORT @EXPORT_OK $VERSION); + use Exporter (); + use UNIVERSAL (); + use Carp; ++use Module::Load (); + + use DBI qw(dbi_time dbi_profile dbi_profile_merge_nodes dbi_profile_merge); + +@@ -758,7 +759,9 @@ sub _auto_new { + } + } + +- eval "require $package" if $package; # silently ignores errors ++ eval { ++ Module::Load::load $package if $package; # silently ignores errors ++ }; + $package ||= $class; + + return $package->new(Path => \@Path, @args); diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p2.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p2.patch new file mode 100644 index 0000000000..5ec8c76ee0 --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p2.patch @@ -0,0 +1,65 @@ +From 54d3e792a236385930e387b28b6c8be779b8d7f7 Mon Sep 17 00:00:00 2001 +From: Robert Rothenberg +Date: Wed, 1 Jul 2026 23:03:34 +0100 +Subject: [PATCH] Add tests for CVE-2026-14380 + +CVE: CVE-2026-14380 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/d982411aec73b3acfc4e9e465358bca9eb7fede8] + +(cherry picked from commit d982411aec73b3acfc4e9e465358bca9eb7fede8) +Signed-off-by: Hetvi Thakar +--- + t/40profile.t | 38 ++++++++++++++++++++++++++++++++++++++ + 1 file changed, 38 insertions(+) + +diff --git a/t/40profile.t b/t/40profile.t +index 7a71b8f..5c72449 100644 +--- a/t/40profile.t ++++ b/t/40profile.t +@@ -458,8 +458,46 @@ is("@$totals", "27.00 2.93 0.11 0.01 0.23 1023110000.00 1023110010.00", + 'merged time foo/bar'); + is($total_time, 2.93, 'merged nodes foo/bar time'); + ++subtest "CVE-2026-14380" => sub { ++ ++ { ++ my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ local $ENV{DBI_PROFILE} = payload_for($marker); ++ my $dbh = eval { ++ DBI->connect("dbi:Sponge:", "", "", { RaiseError => 0 }) ++ }; ++ ok !( -e "/tmp/$marker" ), "ENV DBI_PROFILE payload"; ++ } ++ ++ { ++ my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ my $dbh = DBI->connect("dbi:Sponge:", "", "", { RaiseError => 0 }); ++ eval { ++ $dbh->{Profile} = payload_for($marker); ++ }; ++ ok !( -e "/tmp/$marker" ), "Set Profile payload"; ++ } ++ ++ { ++ my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ my $payload = payload_for($marker); ++ my $dsn = "dbi:Sponge(Profile=>$payload):"; ++ my $dbh = eval { ++ DBI->connect($dsn, "", "", { RaiseError => 0 }) ++ }; ++ ok !( -e "/tmp/$marker" ), "DSN payload"; ++ } ++ ++}; ++ + exit 0; + ++sub payload_for { ++ my ($marker) = @_; ++ # Single-quoted q{...} so \x2f is literal backslash-x-2-f for split; ++ # the inner qq(...) re-interprets \x2f = / at eval-time. ++ return qq{2/system(qq(touch \\x2ftmp\\x2f$marker))}; ++} + + sub sanitize_tree { + my $data = shift; diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p3.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p3.patch new file mode 100644 index 0000000000..c88f829bd7 --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p3.patch @@ -0,0 +1,27 @@ +From cbd61112415aaa9db84d1af6d0bb3d0f61de8ce0 Mon Sep 17 00:00:00 2001 +From: Robert Rothenberg +Date: Sat, 4 Jul 2026 13:34:20 +0100 +Subject: [PATCH] t/40profile.t increase number of tests in the plan + +CVE: CVE-2026-14380 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/f94685f415b08ea4b1f183d48430c4583c1c07d0] + +(cherry picked from commit f94685f415b08ea4b1f183d48430c4583c1c07d0) +Signed-off-by: Hetvi Thakar +--- + t/40profile.t | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/t/40profile.t b/t/40profile.t +index d736da7..ba24421 100644 +--- a/t/40profile.t ++++ b/t/40profile.t +@@ -31,7 +31,7 @@ BEGIN { + if $Config{osvers} =~ /xen/ # eg 2.6.18-4-xen-amd64 + and $ENV{AUTOMATED_TESTING}; + +- plan tests => 60; ++ plan tests => 61; + } + + $Data::Dumper::Indent = 1; diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p4.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p4.patch new file mode 100644 index 0000000000..90270e155c --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14380_p4.patch @@ -0,0 +1,56 @@ +From ef28126fbb8d918307b4995030028984ff8796f5 Mon Sep 17 00:00:00 2001 +From: Robert Rothenberg +Date: Mon, 6 Jul 2026 09:13:26 +0100 +Subject: [PATCH] Improve CVE-2026-14380 tests for Profile + +CVE: CVE-2026-14380 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/7949e551b3c7a8854926b6de84f6cc2ceafb2200] + +(cherry picked from commit 7949e551b3c7a8854926b6de84f6cc2ceafb2200) +Signed-off-by: Hetvi Thakar +--- + t/40profile.t | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/t/40profile.t b/t/40profile.t +index 5c72449..d736da7 100644 +--- a/t/40profile.t ++++ b/t/40profile.t +@@ -461,31 +461,34 @@ is($total_time, 2.93, 'merged nodes foo/bar time'); + subtest "CVE-2026-14380" => sub { + + { +- my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ my $marker = sprintf('dbi-test-payload-%1.6f-%u-%u-%u', $], time, $$, 1); + local $ENV{DBI_PROFILE} = payload_for($marker); + my $dbh = eval { + DBI->connect("dbi:Sponge:", "", "", { RaiseError => 0 }) + }; + ok !( -e "/tmp/$marker" ), "ENV DBI_PROFILE payload"; ++ unlink "/tmp/$marker" if -e "/tmp/$marker"; + } + + { +- my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ my $marker = sprintf('dbi-test-payload-%1.6f-%u-%u-%u', $], time, $$, 2); + my $dbh = DBI->connect("dbi:Sponge:", "", "", { RaiseError => 0 }); + eval { + $dbh->{Profile} = payload_for($marker); + }; + ok !( -e "/tmp/$marker" ), "Set Profile payload"; ++ unlink "/tmp/$marker" if -e "/tmp/$marker"; + } + + { +- my $marker = sprintf('dbi-test-payload-%u-%u-%u', time, $$, 1); ++ my $marker = sprintf('dbi-test-payload-%1.6f-%u-%u-%u', $], time, $$, 3); + my $payload = payload_for($marker); + my $dsn = "dbi:Sponge(Profile=>$payload):"; + my $dbh = eval { + DBI->connect($dsn, "", "", { RaiseError => 0 }) + }; + ok !( -e "/tmp/$marker" ), "DSN payload"; ++ unlink "/tmp/$marker" if -e "/tmp/$marker"; + } + + }; diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb index 99e8c209fe..c604e46334 100644 --- a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb +++ b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb @@ -13,6 +13,10 @@ SRC_URI = "http://search.cpan.org/CPAN/authors/id/T/TI/TIMB/DBI-${PV}.tar.gz \ file://CVE-2014-10402.patch \ file://CVE-2026-9698.patch \ file://CVE-2026-10879.patch \ + file://CVE-2026-14380_p1.patch \ + file://CVE-2026-14380_p2.patch \ + file://CVE-2026-14380_p3.patch \ + file://CVE-2026-14380_p4.patch \ " SRC_URI[md5sum] = "352f80b1e23769c116082a90905d7398" SRC_URI[sha256sum] = "8a2b993db560a2c373c174ee976a51027dd780ec766ae17620c20393d2e836fa" @@ -43,6 +47,7 @@ RDEPENDS:${PN}:class-target = " \ perl-module-exporter-heavy \ perl-module-dynaloader \ perl-module-io-dir \ + perl-module-load \ perl-module-scalar-util \ perl-module-universal \ " From patchwork Wed Jul 29 09:25:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93847 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 30C54C53200 for ; Wed, 29 Jul 2026 09:26:00 +0000 (UTC) Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7526.1785317157481227653 for ; Wed, 29 Jul 2026 02:25:57 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=OtEk4NXr; spf=pass (domain: cisco.com, ip: 173.37.142.88, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=8445; q=dns/txt; s=iport01; t=1785317157; x=1786526757; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=p0JIvp4+aJsHe5CqJoE5pBqs8EolVcEMX3fs45RgOKQ=; b=OtEk4NXrnWz6JcXEry/ag4EMUem1SXcY2i8C9x2fk+GJ2tKUOxWUNN5w RXmVB5UJrSGNyVQPrUis0KkPfhVbsOLQVf6CJUvtopeJcdLHX3KKSkW7G hqINa7JY1DYzO+qtt8grM9uRwqY3PwFhIVd6NVYTurW+184k62NBL6N9k YsxH2615fpa58Zh1qnYQqu8mRRativ+/YyoqfOenP8qQCo8WdsZ8BHXXa yAOuFyFG4pkOZOB5Sgr/+oZ2yN+QpKVssUlhwAC0YWpLsNTFw6K9Jm5Uf EJxkbbsNgiImVVY+bTzbUR5oWp680aI/E6tJeFy4P89PzxSrr0xi4QoVX A==; X-CSE-ConnectionGUID: 4FGcXPKWRpWng6jfCueMfA== X-CSE-MsgGUID: dtW9R1Y0Sg6ybKnOqetBZA== X-IPAS-Result: A0BHAgDLxWlq/5UQJK1aHgEBCxIMggULgld0XkNJlV5sA4ETnQiBfg8BAQEPRA0EAQGFBQKNZgImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAycLAUYQHAMBAi8rIwgZgwIBgnQDEb4qgXkzgQGDaAJDUNsuAQsUAQWBM4U/iCBcGAGEfCcbG4FygRWCc3aBBYE+HgEBgS0Lhm0EgiKBDIFaHpA3SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwcFgR2BLD+EVyMZNn+BL3VKdy1pARIXgRqDOQKCQQMLGA1IESw3FBkEPm4HjW8hgkUBLGEBByIBAQl8gSdLknQxj2WCIYE1nhyBPgoog3WMIZU6GjOFW6URC5h9jgqWA02EaYFoPIFHCwdwFYMiCUoZD44sAQEKC4NggX+CCIEMNMkSJzILMgEBBwIHDgMLgWiQAYF9AQE IronPort-Data: A9a23:oN/anKqoPEIPq5ERUXiX4C98R9peBmJOZBIvgKrLsJaIsI4StFCzt garIBnVbKzZZWajeNF/O4y0/BhQsJDTx9VmSgA/+Cg3FnxB8uPIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOCn9j8kif3gqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrc8kI35ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0rpZLmp+z d8nEigyaB/dheyd3b+eRMA506zPLOGzVG8eknhkyTecCbMtRorOBvyQo9RZxzw3wMtJGJ4yZ eJANmEpN0qGOkMJYwtGYH49tL/Aan3XcyFYoVGcv4I84nPYy0p6172F3N/9JY3UH5sOwB7Bz o7A12jlPUAgbe3H8jXb43iPgMjWkD/RaqtHQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHt5SN UEQ0i4vtrQpskuzQ9/wWhe1rHKJslgbQdU4LgEhwAiJzqyR50OSAXIJC2cbLtcnr8QxAzct0 zdlgu/UONCmi5XNIVr1y1tehWna1fQ9RYPaWRI5cA== IronPort-HdrOrdr: A9a23:aTONI6rq38Zq4kYqVd4TUYoaV5rzeYIsimQD101hICG9vPb2qy nIpoV96faaslcssR0b9OxofZPwI080lqQFhbX5Q43DYOCOggLBR+tfBMnZsljd8kbFmNK1u5 0NT0FWMqyXMbEDt7eY3CCIV/A93dKA7Kekwc3az3trUEVWTpsI1XYBNu5eeXcGPzWvwvECZe Kh2vY= X-Talos-CUID: 9a23:DvP94mB5JHmuWhD6E3VJ20UkIuMaSGXiyniOIUGTFGtMRpTAHA== X-Talos-MUID: 9a23:SMiajAh3dEzNa38qJeBk5cMpONtXsp73ORg2nssXseqCEjV9Jx2vpWHi X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,192,1779148800"; d="scan'208";a="796263601" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Jul 2026 09:25:56 +0000 Received: from sjc-ads-5471.cisco.com (sjc-ads-5471.cisco.com [10.28.23.235]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id 7B20A18000982; Wed, 29 Jul 2026 09:25:56 +0000 (GMT) Received: by sjc-ads-5471.cisco.com (Postfix, from userid 1887505) id 16A37CC12A9; Wed, 29 Jul 2026 02:25:56 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [meta-oe][scarthgap][PATCH 4/5] libdbi-perl: Fix CVE-2026-14739 Date: Wed, 29 Jul 2026 02:25:54 -0700 Message-Id: <20260729092556.45457-4-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260729092556.45457-1-hthakar@cisco.com> References: <20260729092556.45457-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-5471.cisco.com [10.28.23.235];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 10.28.23.235, sjc-ads-5471.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 29 Jul 2026 09:26:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128556 From: Hetvi Thakar Backport the upstream hard limit for positional placeholders. This is a follow-up to CVE-2026-10879 and depends on the allocation fix from the preceding libdbi-perl commit. Correct the upstream boundary check so that the documented maximum of 99999 placeholders is accepted and values above it are rejected. Add focused regression coverage for the 99999 and 100000 boundaries. [1] https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 [2] https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978 [3] https://nvd.nist.gov/vuln/detail/CVE-2026-14739 [4] https://nvd.nist.gov/vuln/detail/CVE-2026-10879 Signed-off-by: Hetvi Thakar --- .../perl/libdbi-perl/CVE-2026-14739.patch | 170 ++++++++++++++++++ .../perl/libdbi-perl_1.643.bb | 1 + 2 files changed, 171 insertions(+) create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14739.patch diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14739.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14739.patch new file mode 100644 index 0000000000..b43e3a20ba --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14739.patch @@ -0,0 +1,170 @@ +From 57d0a1f66b9ed1b54f11af661da4719c43409497 Mon Sep 17 00:00:00 2001 +From: "H.Merijn Brand - Tux" +Date: Sat, 4 Jul 2026 11:38:24 +0200 +Subject: [PATCH] Set a hard limit of 99999 on '?' placeholders + (CVE-2026-14739) + +CVE: CVE-2026-14739 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395] + +Backport Changes: + - Omit ChangeLog, dbixs_rev.h, lib/DBI/Changes.pm, and the DBI.pm version-number hunks because the target remains DBI 1.643. + - Omit regenerated doc/DBI.3, doc/DBI.html, doc/DBI.man, and doc/DBI.md files; retain the DBI.pm source-documentation and DBI.xs security changes unchanged. + - Correct the upstream boundary check to accept exactly 99999 placeholders and reject values above that documented limit; add t/60preparse.t regression coverage for 99999 and 100000 placeholders. + +(cherry picked from commit 2b77c88b655e9539a592c71a61fb965fc0075395) +Signed-off-by: Hetvi Thakar +--- + DBI.pm | 6 ++++-- + DBI.xs | 53 +++++++++++++++++++++++++++++++++-------------------- + t/60preparse.t | 13 ++++++++++++- + 3 files changed, 49 insertions(+), 23 deletions(-) + +diff --git a/DBI.pm b/DBI.pm +index d62a32d..b988e40 100644 +--- a/DBI.pm ++++ b/DBI.pm +@@ -7123,7 +7123,8 @@ a ref to an empty hash because they can't pre-determine the names. + It is possible that the keys in the hash returned by C + are not exactly the same as those implied by the prepared statement. + For example, DBD::Oracle translates 'C' placeholders into 'C<:pN>' +-where N is a sequence number starting at 1. ++where N is a sequence number starting at C<1> with a hard limit of ++C<99999>. + + * Values: + +@@ -7225,7 +7226,8 @@ integer. + It is also possible that the keys in the hash returned by + C are not exactly the same as those implied by the + prepared statement. For example, DBD::Oracle translates 'C' +-placeholders into 'C<:pN>' where N is a sequence number starting at 1. ++placeholders into 'C<:pN>' where N is a sequence number starting at ++C<1> with a hard limit of C<99999>. + + =head3 C + +diff --git a/DBI.xs b/DBI.xs +index 8858e21..23ad34a 100644 +--- a/DBI.xs ++++ b/DBI.xs +@@ -4201,7 +4201,14 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + } + + /* XXX this allocation strategy won't work when we get to more advanced stuff */ +- new_stmt_sv = newSV(strlen(statement) * 6 + 16); ++ /* The 7 is for length increase from '?' (length 1) to :p99999 (length 7) ++ * which imposes a limit of 99999 '?' placeholders POSIX style. Actual counts ++ * are a bit higher: ++ * using factor 5: :p1 .. :p1107 ++ * using factor 6: :p1 .. :p11106 ++ * using factor 7: :p1 .. :p111105 ++ * and that count is insane already */ ++ new_stmt_sv = newSV(strlen(statement) * 7 + 16); + sv_setpv(new_stmt_sv,""); + src = statement; + dest = SvPVX(new_stmt_sv); +@@ -4340,9 +4347,9 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + continue; + } + +- if ( !(*src==':' && (PS_accept(DBIpp_ph_cn) || PS_accept(DBIpp_ph_cs))) +- && !(*src=='?' && PS_accept(DBIpp_ph_qm)) +- ){ ++ if ( !(*src==':' && (PS_accept(DBIpp_ph_cn) || PS_accept(DBIpp_ph_cs))) ++ && !(*src=='?' && PS_accept(DBIpp_ph_qm)) ++ ){ + if (*src == '\'' || *src == '"') + in_quote = *src; + *dest++ = *src++; +@@ -4361,12 +4368,18 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + if (PS_return(DBIpp_ph_qm)) + ; + else if (PS_return(DBIpp_ph_cn)) { /* '?' -> ':p1' (etc) */ ++ if (idx > 99999) { ++ char buf[99]; ++ sprintf(buf, "preparse found more than 99999 '?' placeholders. Limit exceeded."); ++ set_err_char(dbh, imp_xxh, "1", 1, buf, 0, "preparse"); ++ return &PL_sv_undef; ++ } + sprintf(start,":p%d", idx++); + dest = start+strlen(start); + } + else if (PS_return(DBIpp_ph_sp)) { /* '?' -> '%s' */ +- *start = '%'; +- *dest++ = 's'; ++ *start = '%'; ++ *dest++ = 's'; + } + } + else if (isDIGIT(*src)) { /* :1 */ +@@ -4374,24 +4387,24 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + style = ":1"; + + if (PS_return(DBIpp_ph_cn)) { /* ':1'->':p1' */ +- idx = pln; +- *dest++ = 'p'; +- while(isDIGIT(*src)) +- *dest++ = *src++; ++ idx = pln; ++ *dest++ = 'p'; ++ while(isDIGIT(*src)) ++ *dest++ = *src++; + } + else if (PS_return(DBIpp_ph_qm) /* ':1' -> '?' */ + || PS_return(DBIpp_ph_sp) /* ':1' -> '%s' */ + ) { +- PS_return(DBIpp_ph_qm) ? sprintf(start,"?") : sprintf(start,"%%s"); +- dest = start + strlen(start); +- if (pln != idx) { +- char buf[99]; +- sprintf(buf, "preparse found placeholder :%d out of sequence, expected :%d", pln, idx); +- set_err_char(dbh, imp_xxh, "1", 1, buf, 0, "preparse"); +- return &PL_sv_undef; +- } +- while(isDIGIT(*src)) src++; +- idx++; ++ PS_return(DBIpp_ph_qm) ? sprintf(start,"?") : sprintf(start,"%%s"); ++ dest = start + strlen(start); ++ if (pln != idx) { ++ char buf[99]; ++ sprintf(buf, "preparse found placeholder :%d out of sequence, expected :%d", pln, idx); ++ set_err_char(dbh, imp_xxh, "1", 1, buf, 0, "preparse"); ++ return &PL_sv_undef; ++ } ++ while(isDIGIT(*src)) src++; ++ idx++; + } + } + else if (isALNUM(*src)) /* :name */ +diff --git a/t/60preparse.t b/t/60preparse.t +index 6432feb..668dfa3 100755 +--- a/t/60preparse.t ++++ b/t/60preparse.t +@@ -11,7 +11,7 @@ BEGIN { + plan skip_all => 'preparse not supported for DBI::PurePerl'; + } + else { +- plan tests => 39; ++ plan tests => 43; + } + } + +@@ -71,6 +71,17 @@ is( pp($dbh, "a = :name", DBIpp_ph_sp, DBIpp_ph_cs), "a = %s" ); + + is( pp($dbh, "a = ? b = ? c = ?", DBIpp_ph_cn, DBIpp_ph_XX), "a = :p1 b = :p2 c = :p3" ); + ++my $max_placeholders = pp( ++ $dbh, "?" x 99999, DBIpp_ph_cn, DBIpp_ph_qm ++); ++ok(defined $max_placeholders, "accepts the documented limit of 99999 placeholders"); ++is(substr($max_placeholders, -7), ":p99999", "numbers the final allowed placeholder"); ++ ++is(pp($dbh, "?" x 100000, DBIpp_ph_cn, DBIpp_ph_qm), undef, ++ "rejects placeholders above the documented limit"); ++is($DBI::errstr, "preparse found more than 99999 '?' placeholders. Limit exceeded.", ++ "reports the placeholder limit"); ++ + ## Placeholders inside comments (should be ignored where comments style is accepted): + + is( pp( $dbh, diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb index c604e46334..4733378700 100644 --- a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb +++ b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb @@ -17,6 +17,7 @@ SRC_URI = "http://search.cpan.org/CPAN/authors/id/T/TI/TIMB/DBI-${PV}.tar.gz \ file://CVE-2026-14380_p2.patch \ file://CVE-2026-14380_p3.patch \ file://CVE-2026-14380_p4.patch \ + file://CVE-2026-14739.patch \ " SRC_URI[md5sum] = "352f80b1e23769c116082a90905d7398" SRC_URI[sha256sum] = "8a2b993db560a2c373c174ee976a51027dd780ec766ae17620c20393d2e836fa" From patchwork Wed Jul 29 09:25:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 93846 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3CCA9C54F51 for ; Wed, 29 Jul 2026 09:26:00 +0000 (UTC) Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7528.1785317159160305076 for ; Wed, 29 Jul 2026 02:25:59 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Ic4HdLOp; spf=pass (domain: cisco.com, ip: 173.37.142.93, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2934; q=dns/txt; s=iport01; t=1785317159; x=1786526759; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=0FL+yU4HxEnbUvvj4ppwxKridKemacSePktTNLfgt/E=; b=Ic4HdLOp9v/8vDrexxFr73P6NHKjBFdMg+4gqf8sPJSJQaRGdteLvfpY sxCGFAD8c9FavpJEgqqFVA3yvr9RHbbMxnN7skujLGK/djcLQYjiHW8zf hcGW5+WuUzbBdAVaXq1AiZI7C7baBAZE+Vt9uJKuCxd1vJd6pVx/lAp4t yMsZ7Lv5A0EJEWuI+YUlR9jzkaiuuRSG/n+4r504slQqCYYZaWbA2wCAJ ppM+2FUmlkn7GrYIqIuJnjAxIVgYqor7iMwvbFptxtJx6YQ867tbrRIkv gdh+fhsRXHxrQ3Zg7RkShZY/Ybya55YgYxky0syEK2FAAztUulrFZKOrZ w==; X-CSE-ConnectionGUID: cSU8rx5MQtuL6hKAo4GzlA== X-CSE-MsgGUID: fG4cGZQESjCFe+r5a59Kqg== X-IPAS-Result: A0BGAgC9xmlq/4wQJK1aglmCV3ReQ0mVXmwDnhuBfg8BAQEPRA0EAQGFBQKNZgImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAzIBRhAcAwECLysjCBmDAgGCdAMRviiCLIEBg2gCQ1DbLgELFAEFgTOFP4ggXBgBhHwnGxuBcoEVg2mBBYE+HgEBgSeBBoV4BIIigQyBWh6QN0iBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsHBYEdgSw/hFcjGTZ/gS91SnctaQESF4EagzkCgkEDCxgNSBEsNxQZBD5uB41vIYJFgQ4BKgF/pyOhDwoog3WMIY9ChXgaM4QEgVeSQJJRC5h9jgqWUIRpgWg8gUcLB3AVgyIJShkPji0BCguDYIF/gxTJRicyCzIBAQcCBw4DC4FokACBHmABAQ IronPort-Data: A9a23:it6e56lrxyPBGZWem4IGKW/o5gzXJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIWXD2OM6qKajf2e9AgO96x90kO78DVn9I3HAZk+HoyF1tH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4E/raf658SUUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZC31GONgWYubDpLsfPb8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FYYjx7ZtETxrz OAFDG4NTTmE282kxJvuH4GAhux7RCXqFIobvnclyXTSCuwrBMiYBa7L/tRfmjw3g6iiH96HO JFfMmQpNUqGOkEXUrsUIMpWcOOAhmX/ej5RsnqepLE85C7YywkZPL3Fb4uNIoXUHJoL9qqej mzpo2/WMCg3D9605zfG6C+l277shCyuDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0KzRd9bA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO+Q+7AfIzu/f5ByUQzBfCDVAc9ch8sQxQFTGy 2O0oj8gPhQ32JX9dJ5X3u78Qe+aUcTNEVI/WA== IronPort-HdrOrdr: A9a23:R86eEqw0NoSfJMSnJj8TKrPw9L1zdoMgy1knxilNoNJuHfBw8P re+8jzuiWUtN98YhwdcJW7Scu9qBDnhPpICPcqXYtKNTOO0ADDEGgh1/qG/9SKIUPDH4BmuZ uIWpIObuEYdWIK7vrS0U2fD8sqxsWB/eSDgOfTyGoocCRRApsQljuQzm2gYzZLrM4sP+tAKK ah X-Talos-CUID: 9a23:5HXxv22hPJ5NvOKK7tZKQLxfEfsYImfNkVLpP1KcV2ZKYbrJZk2U0fYx X-Talos-MUID: 9a23:khiM1Q3X7/vnFJ6v4+qfkA7tyjUj7YvyA28/qLg9ueKqOG9qZj7A3ReuTdpy X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,192,1779148800"; d="scan'208";a="790016176" Received: from alln-l-core-03.cisco.com ([173.36.16.140]) by alln-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Jul 2026 09:25:56 +0000 Received: from sjc-ads-5471.cisco.com (sjc-ads-5471.cisco.com [10.28.23.235]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-03.cisco.com (Postfix) with ESMTPS id 77A7018000427; Wed, 29 Jul 2026 09:25:56 +0000 (GMT) Received: by sjc-ads-5471.cisco.com (Postfix, from userid 1887505) id 1AE4CCC124A; Wed, 29 Jul 2026 02:25:56 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-devel@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [meta-oe][scarthgap][PATCH 5/5] libdbi-perl: Fix CVE-2026-14740 Date: Wed, 29 Jul 2026 02:25:55 -0700 Message-Id: <20260729092556.45457-5-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260729092556.45457-1-hthakar@cisco.com> References: <20260729092556.45457-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-5471.cisco.com [10.28.23.235];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 10.28.23.235, sjc-ads-5471.cisco.com X-Outbound-Node: alln-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 29 Jul 2026 09:26:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/128559 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-14740 Signed-off-by: Hetvi Thakar --- .../perl/libdbi-perl/CVE-2026-14740.patch | 40 +++++++++++++++++++ .../perl/libdbi-perl_1.643.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14740.patch diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14740.patch b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14740.patch new file mode 100644 index 0000000000..7ac0c24a02 --- /dev/null +++ b/meta-oe/recipes-devtools/perl/libdbi-perl/CVE-2026-14740.patch @@ -0,0 +1,40 @@ +From 016bd2b384ed34185a1770312124ceca0086d7a8 Mon Sep 17 00:00:00 2001 +From: Robert Rothenberg +Date: Sat, 4 Jul 2026 10:49:42 +0100 +Subject: [PATCH] Fix out-of-bounds read in preparse when an initial comment is + deleted + +This fixes CVE-2026-14740 + +Co-Authored-By: Claude Opus 4.8 (1M context) + +Signed-off-by: Robert Rothenberg + +CVE: CVE-2026-14740 +Upstream-Status: Backport [https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01] + +(cherry picked from commit fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01) +Signed-off-by: Hetvi Thakar +--- + DBI.xs | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/DBI.xs b/DBI.xs +index 23ad34a..f40c17a 100644 +--- a/DBI.xs ++++ b/DBI.xs +@@ -4237,7 +4237,13 @@ preparse(SV *dbh, const char *statement, IV ps_return, IV ps_accept, void *foo) + } + if (in_comment == '/') + src++; +- src += (*src != '\n' || *(dest-1)=='\n') ? 1 : 0; ++ /* Only inspect the previously-emitted byte if one exists; ++ when an initial line comment is deleted, dest is still at ++ the start of the output buffer and *(dest-1) would read ++ one byte before it (OOB read). */ ++ src += (*src != '\n' ++ || (dest > SvPVX(new_stmt_sv) && *(dest-1)=='\n')) ++ ? 1 : 0; + in_comment = '\0'; + rt_comment = '\0'; + } diff --git a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb index 4733378700..7e3d1a0161 100644 --- a/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb +++ b/meta-oe/recipes-devtools/perl/libdbi-perl_1.643.bb @@ -18,6 +18,7 @@ SRC_URI = "http://search.cpan.org/CPAN/authors/id/T/TI/TIMB/DBI-${PV}.tar.gz \ file://CVE-2026-14380_p3.patch \ file://CVE-2026-14380_p4.patch \ file://CVE-2026-14739.patch \ + file://CVE-2026-14740.patch \ " SRC_URI[md5sum] = "352f80b1e23769c116082a90905d7398" SRC_URI[sha256sum] = "8a2b993db560a2c373c174ee976a51027dd780ec766ae17620c20393d2e836fa"