From patchwork Mon Aug 24 12:59:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96178 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7ED2BC61DB6 for ; Mon, 24 Aug 2026 13:01:06 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15962.1787576457869716623 for ; Mon, 24 Aug 2026 06:00:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=CJoUkrU3; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-496bb7cdf51so17106795e9.2 for ; Mon, 24 Aug 2026 06:00:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576456; x=1788181256; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FWbEKmMADvDD95n53nMmEHBqFwyuViX0O14VlZE1DBI=; b=CJoUkrU33MDiEW2Z/7VEh8pYhAjNkyUvE+D2q+h6qQ2QhjlGQDJVCHUZ76IsoNBoY3 HOG+oRELQVc7atEYMzGYdGzi1LH3e3d69x3pUNVZKCkPQmuUMpw+NVRu86Rw8IjHW1LV kOyt1v3Pn2I2W5/x/pVGUuMpAxJ6lgPZrVkSQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576456; x=1788181256; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FWbEKmMADvDD95n53nMmEHBqFwyuViX0O14VlZE1DBI=; b=YXRibbt8JPlF0cwyNhlcLvR70G4Qp+flO4HCBoJnQSxIal9NKUikuoFL14KPujPf/t Czv73X1h+IX07NnW6fkU3w8KgFdAqdqJMku4YxHU4S6fngjKkXn702g5U+GW9ld0lzw/ IGN+pd37i2Z3tUDO5v3VVfvmmVpenzqP+eZwYvK1y/ii8iHXIU0Dv6QkqXym81rpI6Om fhFOJI+7GsCY2D36gnGQhJ7LkkXUsS+eIGV0NxWITvLx5Iz1MPYX1WGaDWwWMHQmkUSq NSUcui5RThTscKxvG8udYRPYjQv50ZFwn+F9/SgUSWCvyUkldou4jpKelmKXTBAzF8MN eaTA== X-Gm-Message-State: AFuF++mC3Zf7LP+fkzfSGQ8XtmiM+oCivMq9slGxnupaCUblKyEELnhE Ued4u0obcAist8fbAMrfw6Gn/2nruiILJRbzhqvUCev2ReZj6rHxodZaDWq/4QUYZim2oPUFM5f jypLv1Yc= X-Gm-Gg: AR+sD12fD3AOzYj9nXTGNB2fDfSO/YqXy24XHwMk8ctIDGR8zV+qHnmZVk956Tr2CKo UtQh4sHcRDSBgs0U2Uxh42budyduBzzT+nsAURaN4NSyYS4GkDkYGRGU5wZKGrvNA96VA+ULUPc XhJ5t2anCi2p41LVMnBJEPr3XXwL2xe2HMMmAeU6QAv+K2O9IAbVlMn5p/7uZzDGgSU+e0MDYk8 NF1XoqFYcWI8OAZwu0OHXoh+wIjdFnDXYtvReQ45/nPVA3IAxs6ejD9jkl6gGVc53ah/rZJDzCt RZd1M3vATBDyIl/ZuUxBgDoFniERWIrEHGtGolQhHwMwTQI4PG4jRck6Ad5f33kF8tt0kBDQPTK hpApIDmTPSNCvpXKSVE4OH0SrS1ocjI67M5KCF9fJzlQaYTciZXgZLEnEiWHFcxxBFuLw95fEzR Uonhi/bSvkbSZ3g7qUhmZIfDBbaKvzsOdJN/8JaN9O4c3lisyAzmOgEXpfojl5aCkXG4Xf8HoWi av17KJ4Od5oPUd0oSyqsAPbE4KbAWw6HH4gUJXpxJGwGtuZc2c+imcQax4X3/iDyKD47FpUM7N+ 5QbLEg== X-Received: by 2002:a05:600c:64c6:b0:499:afcb:24c1 with SMTP id 5b1f17b1804b1-499b82e8528mr353012965e9.5.1787576437879; Mon, 24 Aug 2026 06:00:37 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.37 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:37 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/19] busybox: patch CVE-2026-38754 Date: Mon, 24 Aug 2026 14:59:43 +0200 Message-ID: <2ba7a3bef0a1d4e4c687421acc7af82d542e82a9.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244113 From: Peter Marko Pick patch which fixes this CVE as discussed in [1]. [1] https://lists.busybox.net/pipermail/busybox/2026-July/092392.html Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- .../busybox/busybox/CVE-2026-38754.patch | 155 ++++++++++++++++++ meta/recipes-core/busybox/busybox_1.37.0.bb | 1 + 2 files changed, 156 insertions(+) create mode 100644 meta/recipes-core/busybox/busybox/CVE-2026-38754.patch diff --git a/meta/recipes-core/busybox/busybox/CVE-2026-38754.patch b/meta/recipes-core/busybox/busybox/CVE-2026-38754.patch new file mode 100644 index 00000000000..7c7b88f5de7 --- /dev/null +++ b/meta/recipes-core/busybox/busybox/CVE-2026-38754.patch @@ -0,0 +1,155 @@ +From a448b6d5b21e5b21249391389b6f0551d9bea136 Mon Sep 17 00:00:00 2001 +From: Sanghyun Park +Date: Thu, 18 Jun 2026 17:04:20 +0900 +Subject: [PATCH] ash: fix out-of-bounds read in ifsbreakup() + +ifsfree() does not only release allocated ifsregion nodes; it also clears +the global IFS region state used by ifsbreakup(). If argstr() raises an +error while expanding an argument, ash longjmps out of expandarg() before +that cleanup runs, leaving stale IFS split offsets behind. + +A later expansion can reuse the stack for a shorter string. ifsbreakup() +then sees the stale IFS state, trusts the old offsets, and can walk past +the current stack block before dereferencing p. + +Follow dash's root-cause fix: when an expansion-related handler catches +EXERROR and continues, restore the handler and call ifsfree(). Apply +the cleanup to redirectsafe(), expandstr(), and evaltree(). + +Upstream commit: + + Date: Mon Dec 5 23:02:01 2022 +0800 + expand: Add ifsfree to expand to fix a logic error that causes a buffer over-read + + On Mon, Jun 20, 2022 at 02:27:10PM -0400, Alex Gorinson wrote: + > Due to a logic error in the ifsbreakup function in expand.c if a + > heredoc and normal command is run one after the other by means of a + > semi-colon, when the second command drops into ifsbreakup the command + > will be evaluated with the ifslastp/ifsfirst struct that was set when + > the here doc was evaluated. This results in a buffer over-read that + > can leak the program's heap, stack, and arena addresses which can be + > used to beat ASLR. + > + > Steps to Reproduce: + > First bug: + > cmd args: ~/exampleDir/example> dash + > $ M='AAAAAAAAAAAAAAAAA' + > $ q00(){ + > $ <<000;echo + > $ ${D?$M$M$M$M$M$M} + > $ 000 + > $ } + > $ q00 should be echo'd out; this works with ash, busybox ash, and dash and + > with all option args.> + > + > Patch: + > Adding the following to expand.c will fix both bugs in one go. + > (Thank you to Harald van Dijk and Michael Greenberg for doing the + > heavy lifting for this patch!) + > ========================== + > --- a/src/expand.c + > +++ b/src/expand.c + > @@ -859,6 +859,7 @@ + > if (discard) + > return -1; + > + > +ifsfree(); + > sh_error("Bad substitution"); + > } + > + > @@ -1739,6 +1740,7 @@ + > } else + > msg = umsg; + > } + > +ifsfree(); + > sh_error("%.*s: %s%s", end - var - 1, var, msg, tail); + > } + > ========================== + + Thanks for the report! + + I think it's better to add the ifsfree() call to the exception + handling path as other sh_error calls may trigger this too. + +function old new delta +restore_handler_expandarg - 33 +33 +evaltree 725 711 -14 +static.redirectsafe 141 124 -17 +expandstr 262 242 -20 +------------------------------------------------------------------------------ +(add/remove: 1/0 grow/shrink: 0/3 up/down: 36/-45) Total: -18 bytes + +Signed-off-by: Sanghyun Park +Signed-off-by: Denys Vlasenko + +CVE: CVE-2026-38754 +Upstream-Status: Backport [https://github.com/vda-linux/busybox_mirror/commit/a448b6d5b21e5b21249391389b6f0551d9bea136] +Signed-off-by: Peter Marko +--- + shell/ash.c | 24 +++++++++++++++--------- + 1 file changed, 15 insertions(+), 9 deletions(-) + +diff --git a/shell/ash.c b/shell/ash.c +index fb887f31b..b8ff67b16 100644 +--- a/shell/ash.c ++++ b/shell/ash.c +@@ -5472,6 +5472,7 @@ stoppedjobs(void) + */ + /* openhere needs this forward reference */ + static void expandhere(union node *arg); ++static void ifsfree(void); + static int + openhere(union node *redir) + { +@@ -5913,6 +5914,17 @@ redirect(union node *redir, int flags) + // preverrout_fd = copied_fd2; + } + ++static void ++restore_handler_expandarg(struct jmploc *savehandler, int err) ++{ ++ exception_handler = savehandler; ++ if (err) { ++ if (exception_type != EXERROR) ++ longjmp(exception_handler->loc, 1); ++ ifsfree(); ++ } ++} ++ + static int + redirectsafe(union node *redir, int flags) + { +@@ -5928,9 +5940,7 @@ redirectsafe(union node *redir, int flags) + exception_handler = &jmploc; + redirect(redir, flags); + } +- exception_handler = savehandler; +- if (err && exception_type != EXERROR) +- longjmp(exception_handler->loc, 1); ++ restore_handler_expandarg(savehandler, err); + RESTORE_INT(saveint); + return err; + } +@@ -9445,9 +9455,7 @@ evaltree(union node *n, int flags) + trap_depth--; + in_trap_ERR = 0; + +- exception_handler = savehandler; +- if (err && exception_type != EXERROR) +- longjmp(exception_handler->loc, 1); ++ restore_handler_expandarg(savehandler, err); + + exitstatus = savestatus; + } +@@ -13487,9 +13495,7 @@ expandstr(const char *ps, int syntax_type) + result = stackblock(); + + out: +- exception_handler = savehandler; +- if (err && exception_type != EXERROR) +- longjmp(exception_handler->loc, 1); ++ restore_handler_expandarg(savehandler, err); + + doprompt = saveprompt; + /* Try: PS1='`xxx(`' */ diff --git a/meta/recipes-core/busybox/busybox_1.37.0.bb b/meta/recipes-core/busybox/busybox_1.37.0.bb index a6abfa25984..b020c923be3 100644 --- a/meta/recipes-core/busybox/busybox_1.37.0.bb +++ b/meta/recipes-core/busybox/busybox_1.37.0.bb @@ -66,6 +66,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \ file://CVE-2024-58251.patch \ file://CVE-2026-29004-01.patch \ file://CVE-2026-29004-02.patch \ + file://CVE-2026-38754.patch \ " SRC_URI:append:libc-musl = " file://musl.cfg" SRC_URI:append:x86-64 = " file://sha_accel.cfg" From patchwork Mon Aug 24 12:59:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96164 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 95FDDC5DF81 for ; Mon, 24 Aug 2026 13:00:45 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16149.1787576440668814926 for ; Mon, 24 Aug 2026 06:00:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=It3eeDbP; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4956869750eso19626045e9.2 for ; Mon, 24 Aug 2026 06:00:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576439; x=1788181239; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vb3I4Ohhr0SmaHeYlyvoWVduqUmt5y0yK4UDMz7eKm4=; b=It3eeDbPvqaENSvBSR3Oh45r+6846+hxcTvmCG5VGaIqiTaWcfp7f9PO7VatxoKU/G INlX9sPQZBiBJWPruzUQq7D3azmd0jNyuAUHPvd0wF3MNmWebFHTglB4LDMbyoJjYH7W fCBfl+DDz8kqjTKz/GoAkJZMbzDV6S0qhIJWU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576439; x=1788181239; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vb3I4Ohhr0SmaHeYlyvoWVduqUmt5y0yK4UDMz7eKm4=; b=mY9n2ty2O0++Ah6gYdzG6dp0D2pHgKNR+hPlqmqS8jNKyYwqXaXjbyY6DE3cr7EAjU KSAx6JVC3qi5imgX5TGKwwUPlvU/fVtXKts3lnLIv+txRBs22DtyT3lpGb954rFcmBZ0 ICm9MqDEY/+/Amc7meiJFo5zLhlk3lTYnII6dsHg36rhcSs55olszJWLAKrxarqztxCH P3YYayaNeum8EbAkSyyjnKmtsO3bZSiKfF8zhToKujLLxpeJZSF4ozI1Bg1BQSZt9NtB cNHfXgWaupMNCvPDkC/jtQag3dOK5gNCvlneJJOlbnIR9ZP3/DPDVhI8n1/0Hw4IR8HY uSPg== X-Gm-Message-State: AFuF++kBozNHDKlZ+8BC88H4fdRKFfqBG8L8dy7Qa+fZm7E+Y2W6C1hH YS0SUL12OPmJDYlEKHj3GBCUUCoFA5H5C4MQu1YL4acPReigZxwmg9a/dGVw0ZT1e9AWr1eGF+7 ubPkHiIc= X-Gm-Gg: AR+sD13zu7OGPTZoIkG3WfnAcb5CAMJ6AOIyjZSwmcThNW0J1c1Y8hLoUSUPxVKR82Y c8n/JblrtALBYfslwpgWGGIiKAMEraa1bXUpq4VNTLVArK+vUOgZcL8MDT0jqaNi5deRgQ/kzH1 251ncjpucDnHV/bDZUKbjjgPAnM+N8F7J4J0lY7V/QgSYe78dBVpO3/W/EPs6mPmDtZtkCkqvhg O/T7F/qHTPvasyPhAlGyc2nGfLps6lx2ehY9DGze8x9Aa8OFewktelsyd4ctNQwa1W16T5oc3pv 4/1GEe1FjCozw+el2HmrSyRm/2zPIIu1hLqke9WIQhGfAsO+k7Oik6zKxu4pLye2silfr5f+pmO WPSECeLyZ1lOBFIVcZsXmkYVAEZ/9rGOIJKMJkXnobqzuIc+njcd9PGnORzZVgFT9v2XBjwhH28 fLyKcZXTV8mwy/ahRG0QA9jIgJaA6wMgRPHP8pe8+TqoWiadfEJ+L0TsvtpDnC+OgYdEhhgehK3 gDEfWA2C2rMnbE3WNf6nKKs6Exq1S4q5Nf1GewcEAhh+28Yj7iCLOsaTFY7NIVNeXMHsa4= X-Received: by 2002:a05:600c:a01:b0:499:bdf1:7578 with SMTP id 5b1f17b1804b1-499c19bfd2dmr173562375e9.3.1787576438716; Mon, 24 Aug 2026 06:00:38 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/19] curl: fix CVE-2026-4873 Date: Mon, 24 Aug 2026 14:59:44 +0200 Message-ID: <7e44b94a57a1b7d9ec043554fb7f1f4c3fbfbbaf.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244100 From: Deepak Rathore This patch applies the upstream backport for CVE-2026-4873. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865 [2] https://curl.se/docs/CVE-2026-4873.html Signed-off-by: Deepak Rathore Signed-off-by: Fabien Thomas --- .../curl/curl/CVE-2026-4873.patch | 52 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-4873.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-4873.patch b/meta/recipes-support/curl/curl/CVE-2026-4873.patch new file mode 100644 index 00000000000..b288de93066 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-4873.patch @@ -0,0 +1,52 @@ +From 4d13e431d26c3097e6dff49ba069061b588461af Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Tue, 24 Mar 2026 08:35:08 +0100 +Subject: [PATCH] url: do not reuse a non-tls starttls connection if new + requires TLS + +Reported-by: Arkadi Vainbrand + +Closes #21082 + +CVE: CVE-2026-4873 +Upstream-Status: Backport [https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865] + +(cherry picked from commit 507e7be573b0a76fca597b75ff7cb27a66e7d865) +Signed-off-by: Deepak Rathore +--- + lib/url.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +diff --git a/lib/url.c b/lib/url.c +index 7c24f1a002..4ebff50ef1 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -745,7 +745,7 @@ struct url_conn_match { + BIT(want_proxy_ntlm_http); + BIT(want_nego_http); + BIT(want_proxy_nego_http); +- ++ BIT(req_tls); /* require TLS use from a clear-text start */ + BIT(wait_pipe); + BIT(force_reuse); + BIT(seen_pending_conn); +@@ -897,6 +897,9 @@ static bool url_match_ssl_use(struct connectdata *conn, + (get_protocol_family(conn->scheme) != m->needle->scheme->protocol)) + return FALSE; + } ++ else if(m->req_tls) ++ /* a clear-text STARTTLS protocol with required TLS */ ++ return FALSE; + return TRUE; + } + +@@ -1361,6 +1364,7 @@ static bool url_attach_existing(struct Curl_easy *data, + (needle->scheme->protocol & PROTO_FAMILY_HTTP); + #endif + #endif ++ match.req_tls = data->set.use_ssl >= CURLUSESSL_CONTROL; + + /* Find a connection in the pool that matches what "data + needle" + * requires. If a suitable candidate is found, it is attached to "data". */ +-- +2.35.6 diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 097b3056d8e..5ba881bd762 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -22,6 +22,7 @@ SRC_URI = " \ file://CVE-2026-6429-dependent.patch \ file://CVE-2026-6429.patch \ file://CVE-2026-7168.patch \ + file://CVE-2026-4873.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Mon Aug 24 12:59:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96163 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 891EFC5DF94 for ; Mon, 24 Aug 2026 13:00:45 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15946.1787576441583175784 for ; Mon, 24 Aug 2026 06:00:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=w47yGrdJ; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4956869750eso19626155e9.2 for ; Mon, 24 Aug 2026 06:00:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576440; x=1788181240; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cSN6PIj4MghZZpurqTWU93YGYgIx6i9wc9iCra0BGC8=; b=w47yGrdJI4vkbxq0p8rbEu0xmsoy34Go4Tz4zOBHVKy0yTfDCJkLMqJvsM5mRzyrWS dPpVS+hn9zSza8LHAdZA7nVSFpJ2mg6m09N1vvjyjMN5a3XH4PJ31UwfrMtR5ZBdRDqc IVKD4PRYiioLjUrU2Bal0KQEyll+IrrDyVOZk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576440; x=1788181240; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cSN6PIj4MghZZpurqTWU93YGYgIx6i9wc9iCra0BGC8=; b=kNS1qIwvYQoFCH0G890LyiIcyltfGQm59Qs3hNfie54dmq/m99vfjPceycTqEm46Oz 9u2Ms5QBqvfG3Nca37YDKD2jFTRTjfRStGkfjiCuZw5G/PB82rgYJ107jw0j+rLmJ1ms LZloOP918t4na8UKqr5d6qZGRmtHTNld9nXhvuiRhIijq/NTTXKmyom5wcupCeyfSJuS djje0Kl9XBKhTep1wWtTSzzRatTJfMIrlShFG+Trk3kvMu55wC9n8FWehUM8mHd2SXiX z85B5Mo8Xu5D4hhY1L7NqQ99KeTi/GJavwRvqOqbMj7M+2/TtDyrzYlds+T9edr4SsXp nwtw== X-Gm-Message-State: AFuF++m2dTlHjDl6w0OShUKUQB3MEw3ejPz0qzCnsEuyGsCS3kMvtGgo slfl7gM5QuCQp4kpPKvW+Ier8OSe5FUxef+/FP90mbCPTPwGSlTLc9uWPsE3x3wIg69T0U//gcX f4+tJ3D0= X-Gm-Gg: AR+sD12PuwHBm6uBFd2UMRUTpNSKZZyXI0kffFeTfgdfEc0TfObDxd9FpfW5ehHbw4i z7jW4M8rD08ogc/ve/+yzwDR6lOMyky1rnBnKUTVbNnts1io6iHefHrEvOndDGRK/O1KrFM1aVg 3RB2pZ8i9mN5jW6AMKmNLBMfY56K/yuR0FOFGgg9041Gt+1VvOxltkldrdo2owEw1SJJQjaWOsf IXp8+1QGGbisfxRHWkfYcZstG5f8ZxW9mLZPSLzW7M0L1RKpjTITVA4FFy2fkVK1HZu3hJM4Nv9 OcoCr2qOoil1yTN3u7jzgwy/a1BVQsLLxstJBj+rFjOUa5OFQ1y4+/DaeFkFhpiuPBe83hH4NAr PCgmEeLjeJUc3r5FktJMkiWq6NVln6AlqnmCWn88cThZdQ4M75+q9z+MpZNlSsQaeSFFvB44n4O cva3wgquJT2HR0YstwbsxP45mMYp+GX4tZc3bZMPw2TCVhZq0KrjnwySnoBdyJnxTWS/3XJwNkG EnU9czdLNvWJR1BUJ71rExxT1Z2VwSqEySEktJqd30AGmCh3DkC7DL5PjXpLsVuw2E4kIE= X-Received: by 2002:a05:600c:5309:b0:493:f5bf:4dc6 with SMTP id 5b1f17b1804b1-499c19d020cmr203893185e9.7.1787576439609; Mon, 24 Aug 2026 06:00:39 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/19] libssh2: fix CVE-2026-66032 Date: Mon, 24 Aug 2026 14:59:45 +0200 Message-ID: <4eee848e3817b6f3ffd11bf5758087643c89128f.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244101 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-66032 https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 libssh2 ptest results (qemux86-64): before: PASSED: 1 FAILED: 0 SKIPPED: 0 after: PASSED: 1 FAILED: 0 SKIPPED: 0 Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-66032.patch | 36 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66032.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66032.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66032.patch new file mode 100644 index 00000000000..15a52664853 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66032.patch @@ -0,0 +1,36 @@ +From 352341aaebcf91ab16e7fcff158fef4a3b8c32f6 Mon Sep 17 00:00:00 2001 +From: Jaipaul Cheernam +Date: Tue, 4 Aug 2026 12:32:31 +0000 +Subject: [PATCH] Prevent dangling pointer by nullifying data (#2180) + +Set data to NULL after freeing it to avoid dangling pointer. fixes +GHSA-px3w-7g75-hg7w. + +Credit: VladimirEliTokarev + +CVE: CVE-2026-66032 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0] + +Backport adaptations: +- The upstream fix uses SSH2_FREE() which was renamed from + LIBSSH2_FREE() in newer libssh2. Context adjusted to match + the 1.11.1 codebase (different line numbers and surrounding + function/macro names). + +Signed-off-by: Jaipaul Cheernam +--- + src/sftp.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/sftp.c b/src/sftp.c +index 6ede3111..793f267c 100644 +--- a/src/sftp.c ++++ b/src/sftp.c +@@ -1279,6 +1279,7 @@ sftp_open(LIBSSH2_SFTP *sftp, const char *filename, + "got HANDLE FXOK")); + + LIBSSH2_FREE(session, data); ++ data = NULL; + + /* silly situation, but check for a HANDLE */ + rc = sftp_packet_require(sftp, SSH_FXP_HANDLE, diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index 32e1ad6c16c..bd7d1f7b1d1 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -16,6 +16,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2025-15661-1.patch \ file://CVE-2025-15661-2.patch \ file://CVE-2025-15661-3.patch \ + file://CVE-2026-66032.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Aug 24 12:59:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96180 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AFF0AC5DF9C for ; Mon, 24 Aug 2026 13:01:16 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15971.1787576474146464219 for ; Mon, 24 Aug 2026 06:01:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TMWVloVI; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49557167508so13076665e9.1 for ; Mon, 24 Aug 2026 06:01:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576472; x=1788181272; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ev2bAQl1ZGq4ysHJ/OlDeIT3qLeXWbw12vjk3VUTlN8=; b=TMWVloVInm0fJveKMap9hPYrCL0WJfH3ASvTEdt2L9cHwTtFcY5VoIReJezFjqYnDu 19llkTDmCqAddQa5HDKkHQA++KmbdIUBTmUeqWFNzhU8eMbYLZC0+NLP1oMgOpIhIe2N 4Wddhesujh8sNitacZHfzrCg5wx1EoAjCs4+A= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576472; x=1788181272; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ev2bAQl1ZGq4ysHJ/OlDeIT3qLeXWbw12vjk3VUTlN8=; b=kjea5WPmIkfJwOPSzfn69EwY6mfF7q+7WeF2NP42mMGaYp3Zb96zCMrP2ileuLtvSp YngjkGTtu4ci1ploBzBLHh5vFqepuiLttowv+UCeuT/dC2DJz14yO7J22+Irm+J/oLL0 REAEddobuYhAuVrCV14+Z9AvG9K8EXRiV1YT5T6Pw30bTqRZ7s2nSJZwN58BdL5AI29f OYP2+gVaKQox9LTy1RZ/l7gaU2ofbWaP1PhRo6UthjTNMiTVDrBUeCAIRh2ppPwT65ot EvBeXp2Uz6qWqlTmhUKJzFwL44Cm5Ld7O8l6MEhvLMZoQMJVDN3avC7/SaugEM3MA+Ue Sgxg== X-Gm-Message-State: AFuF++nYL7dPaT1Wg26u7JPG6cCgZ31gg91XrDAez8MY3k2wDt3VyGFP t3jBfvNMDxwySdRrwe5YG0VnbbHgJ4oJPEOvDZlWDNPu1O/j2jUmq0xEwuNl1CPY09RdC8f7W0q G3ZKy1yU= X-Gm-Gg: AR+sD11bSWgNHcC5qTm6rt5xfO82rZxkDqXInw9aLWO1NwybEVk9qnJbJNTBXHEqgYQ iTukOj5SeQzyf0k8kaJaqM7ZNilqNZhiiymp5hy9B+PJJO7V/79M113LByhQ2zwqdhxzWX7km1o euS64HcPIWz9FqM2DI453W9D+4nKotW9FmRYdqOSn2wfXu/gifEK3UJwjRlc0uaBt1lH/oPDUNL GHSvpoDbc7pOrYbP1DTg625opLiRjhOI9AkorBaoH810TDvVg8z9+9g3BHrfvMCf7DPScPiOMBU QbGm4JE8GZbUFyz2+ASUih/JDaBt7vKcYUYnXIFYsGUdtm3Oqmfcli2lkDPO7T4pruyA1kzNd4Q 1mq0OHcoJa90LKfzl4owPORNrxew+clbc2AhisaurTtCv1ZE8JgMJxwjh0bdFHKehy5XeVqVTqX UTb6tAR/66U+W9TNWtYXviGDQNXvWmXV6auPLDwuOBjM10jeaU2ikapjWoRwzgw+gni04297GrE 4VaCJNJeD4Z9DBjR9AM8dvywhzAh6N9q2dkPg6V0gk9hiPKrLX2AH+boKN2I53bwzNdzcs= X-Received: by 2002:a05:600c:5486:b0:499:ae94:be05 with SMTP id 5b1f17b1804b1-499b825a4bcmr316744425e9.0.1787576440390; Mon, 24 Aug 2026 06:00:40 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/19] libssh2: fix CVE-2026-66033 Date: Mon, 24 Aug 2026 14:59:46 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244117 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-66033 https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 libssh2 ptest results (qemux86-64): before: PASSED: 1 FAILED: 0 SKIPPED: 0 after: PASSED: 1 FAILED: 0 SKIPPED: 0 Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-66033.patch | 45 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch new file mode 100644 index 00000000000..bb046a6eae2 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66033.patch @@ -0,0 +1,45 @@ +From d1b6996c3b31ce6b60d5a820ecc33880e61ef0ae Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Thu, 23 Jul 2026 10:32:04 +0200 +Subject: [PATCH] openssl: fix potential OOB read/write with AES-GCM in + `ssh2_cipher_crypt()` + +By applying two bounds checks to non-debug builds. + +Reported-by: Vladimir Eli Tokarev +Fixes GHSA-c4f7-cvfc-33j7 +Follow-up to 3c953c05d67eb1ebcfd3316f279f12c4b1d600b4 #797 + +Closes #2401 + +CVE: CVE-2026-66033 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6] +Signed-off-by: Jaipaul Cheernam +--- + src/openssl.c | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +diff --git a/src/openssl.c b/src/openssl.c +index eba05031..28ae1cc0 100644 +--- a/src/openssl.c ++++ b/src/openssl.c +@@ -1042,13 +1042,15 @@ _libssh2_cipher_crypt(_libssh2_cipher_ctx * ctx, + const int aadlen = (is_aesgcm && IS_FIRST(firstlast)) ? 4 : 0; + /* size of AT, if present */ + const int authenticationtag = IS_LAST(firstlast) ? authlen : 0; +- /* length to encrypt */ +- const int cryptlen = (unsigned int)blocksize - aadlen - authenticationtag; ++ unsigned int cryptlen; /* length to encrypt */ + + (void)algo; + +- assert(blocksize <= sizeof(buf)); +- assert(cryptlen >= 0); ++ if(blocksize > sizeof(buf) || ++ blocksize < (size_t)(aadlen + authenticationtag)) ++ return 1; ++ ++ cryptlen = (unsigned int)blocksize - aadlen - authenticationtag; + + #if LIBSSH2_AES_GCM + /* First block */ diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index bd7d1f7b1d1..de435a836db 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -17,6 +17,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2025-15661-2.patch \ file://CVE-2025-15661-3.patch \ file://CVE-2026-66032.patch \ + file://CVE-2026-66033.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Aug 24 12:59:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96182 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8603C61CE3 for ; Mon, 24 Aug 2026 13:01:16 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15970.1787576470179857985 for ; Mon, 24 Aug 2026 06:01:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OcREYWcx; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-47f904e80eeso1260115f8f.1 for ; Mon, 24 Aug 2026 06:01:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576468; x=1788181268; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/oblsceWK6Qa0SInWhYxX5f/Y7oK0JOd+fAZlRk8W3E=; b=OcREYWcxaf1SWANS3nKjvRkCBljLP7JQMh4Hf83Te9y53U6TNhJfoYMiLSEQr7ZnO8 rUpAlsRhLhvSde1UMX1C2Q+WqKZHxM7NEscZrtEipkdOACMGkgVynzUJ0aAlRGfH3k3M DmVW1z0jcKBgRUdrfYN8Xe4zrdOHGgApQ3Dmo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576468; x=1788181268; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/oblsceWK6Qa0SInWhYxX5f/Y7oK0JOd+fAZlRk8W3E=; b=hm7fqInug0Yc+CDBoB2RrUA51NGo+qORqryVs/UKkO+5AYtur1R70NnHfB5fdYwDdv 78CV8ggkq+Q1tcv8bFx3zrBUDLyu9lpcerKfCTg1pHcrfUh93Kit0QuDIAZeCB1FeUFZ B9Qay9K8L+I+1Pmf19XPw/reJ8cYlzJboVJrwF5/rrQyHb20YeeBSCPgLCrvymTX3PIl pJBvH/PyUOn87pRYQOjV/maoFveR9bMZsJlfkSogRxZ6Tq0CApX7Dip24tAlEqc1u4vZ oUbtFCvmLNDU7fR09kqmZk05iN7k6zvpeu+SVXKi81qki9PAp3n3fKIBDCffV77K057b Klaw== X-Gm-Message-State: AFuF++m5qUkmGLPoOstp7HHmJ6IqJYUPK3gXlrbrNRIRbE4n3GGzvvRm xDRH+PnCIVbM2zYiqLssOP97z3IK+lSbjwuhx1KafKqw2LN6lc4dnoqyfn3RdOdAeqtEIz5ZwWG a5L5FEKs= X-Gm-Gg: AR+sD10j+QPdHNawpsFNkAyyM/RlwsO8MlIZlKERQ8lylhQWsRWLZMLeN2PNQKce50O fHDsaYq7/g0M6arVWfi2HTB07tREryQkrRxP/pnXIvF+w4N1dYFXIU02yVmxzVlnlM4W3IokFTk X3v/zSq33SYRXD0PYJUy6xOMy85TGNxbzP5vGGqVDT5Ef3NgoIps/ZMu4oLIr+iM2fWjX7C/a2N Xa+00EKNEClRfVwwHawwANkezfGSq14fFjweJxmFsFeaZ2OFXiC+2jJ1ytNJNp/0r8JawnUFJoq LeQdUHcN/uG2DHdG5CdfEZBgulltyPaC2Wu2XHXdoT4OaPUblkE7BFKaB8EBxAlRpDSWPnW2Xmw mGZu34tHLsQQit1CIu9On+8l9pOGywMF0TTe8aY4m1weZ3quQ6F3kbDWczCnA+ETCN/GzcYKlMr b4v3AFZEkqGBfE9EBf67jqYaW35DrrOvZWhtVQZxSyhpCpTrh8K49vG67gVmoHWj+kr+uauXnrZ Yet4lPMlQ1JGTBJ1fYwlSeI48Z8q7zSyLMm40eYkbycBRbrNUUDGpyo5fqOJUB7ufyj9ak= X-Received: by 2002:a05:600c:b86:b0:499:8156:cd3f with SMTP id 5b1f17b1804b1-499b8301913mr259095755e9.8.1787576441875; Mon, 24 Aug 2026 06:00:41 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:40 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/19] libssh2: fix CVE-2026-66034 Date: Mon, 24 Aug 2026 14:59:47 +0200 Message-ID: <5a34f96f86229734521fe6f90038090d9d8630a7.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244116 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-66034 https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99804cd898d9 libssh2 ptest results (qemux86-64): before: PASSED: 1 FAILED: 0 SKIPPED: 0 after: PASSED: 1 FAILED: 0 SKIPPED: 0 Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-66034.patch | 40 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch new file mode 100644 index 00000000000..906356baf28 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66034.patch @@ -0,0 +1,40 @@ +From 16720054e0b3f02e36f31dd04add534d73d4a18d Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sat, 4 Jul 2026 11:19:49 +0200 +Subject: [PATCH] publickey: fix potential OOB read in + `libssh2_publickey_list_fetch()` + +Reported-by: Vladimir Eli Tokarev +Fixes GHSA-w6g9-cpfp-22gc + +Closes #2202 + +Backport adaptations: +- The upstream fix uses ssh2_err() which is not available in libssh2 + 1.11.1. Replace with the equivalent _libssh2_error() call. + +CVE: CVE-2026-66034 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99804cd898d9] +Signed-off-by: Jaipaul Cheernam +--- + src/publickey.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/src/publickey.c b/src/publickey.c +index 9c9fa618..f3776d2d 100644 +--- a/src/publickey.c ++++ b/src/publickey.c +@@ -988,6 +988,13 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys, + } + + if(comment_len) { ++ if(pkey->listFetch_s + comment_len > ++ pkey->listFetch_data + pkey->listFetch_data_len) { ++ _libssh2_error(session, LIBSSH2_ERROR_BUFFER_TOO_SMALL, ++ "ListFetch data too short"); ++ goto err_exit; ++ } ++ + list[keys].num_attrs = 1; + list[keys].attrs = + LIBSSH2_ALLOC(session, diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index de435a836db..7d3063d9304 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -18,6 +18,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2025-15661-3.patch \ file://CVE-2026-66032.patch \ file://CVE-2026-66033.patch \ + file://CVE-2026-66034.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Aug 24 12:59:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96166 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B78DBC5DF9C for ; Mon, 24 Aug 2026 13:00:55 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15952.1787576445612819860 for ; Mon, 24 Aug 2026 06:00:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ft2HwgQl; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49954b88fffso27397565e9.0 for ; Mon, 24 Aug 2026 06:00:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576444; x=1788181244; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Qb3z6o1JageTw2oNk+bklxaTKI6WQ2zPyas4dnkrCpI=; b=Ft2HwgQluVthqX8ncFtJ8E4DAsyRORBQ1ILOVyPl/hrSsYJ07PiOajRoDIkQAc3qSa pR3Cbk4WfYUKBjwOg4tdpJE23XcVp59jO+atZXGf3cz0Cdt86n55yxVQE6j91fBCh7rX tIh3yKfwpNY/ErMx47gmkR3drkBbIdID6xf+M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576444; x=1788181244; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Qb3z6o1JageTw2oNk+bklxaTKI6WQ2zPyas4dnkrCpI=; b=FfoNmZqkz1G1T1xjMzMQLmMHkAcrvv0QNtegFR+6zV1MNq0urgMenv841Bs8jRlnLr KpWkzyj7g9FBCpR+s3a0T+arhaxZDPCraT9M4d1ieqleJKqo9dusYvS/AaC3WxgqCaOJ OcLmILHxel1DjGj10e0M/fkaUE/RTrzAh1nA/Di3zzQiCPkjKv8e6fseuku3+mTWhex8 zRJMxq6hkeoBLlNfWgD8pTAt3VYxo06EAyHHsrDrokzKeRpsbsb2pj3RKPB2SJLTqEat VFG9AtoC2OSZ1X5KGictxamPH1Fo2dDbYsdQqpVQ3JI+I2gZhlWrhhWTPse7BoIfmg7q fJag== X-Gm-Message-State: AFuF++n32LTXFlubuPcnAKyZBqYfUnEqdewuLfo97TdYoqChegKhA0PJ tO/0wtJE9akeMd9oJuc8ydRXAEHqR2PDD3nyIG0sNGZbt3EW5UttdijMg5CjLUbdUxW7SJVHWej ug1td77A= X-Gm-Gg: AR+sD13Sb0YcpCUkh9Yd+bf+5JFJSinVkQales/e2pDvSJ06rz1YbIf4VICPdR7vQOK fAfE9t81BrMS5X9XteONdTzkQPXSzJH/MrMD2Z1CT2XVwoAAteveauQZKE2u9UCSWiSxV4nF6T9 RnX/+jtsrL00GC8JhjzUk9HCVeod7r3UjL1EAd3ojIG8dxEDoRMLQpETbbNeMvbOY0xVlCr9MhA mc1ytqBACi6blkPP/mzBV9TNYuMdmnim4+CFk3h4zhjkCDa/QHsk5V6I9kXpiS0d33AI03b3R2Z 1MpQiotpnZZnwHm4UPoFVW/0qRNsaEVx6QUzwSCRaEarpsEACNSzwSbVCB/509qH5BOCFgojrCH VaiJSpXe5CU/2Fnk/nVMfqI24h5hLBMtv7+PS7ezQUWGeWiBMaKQV7x8/GGYRGnJRkaVorCndnR Gk1xPQVlj/+GHIA7z9d8Mhb2M02Ar7jbwoQx5CLGPVlLpNa3kGddStQvvAJ84XL+O0Wun1mOcmW vH/NEPellXcISBCt7yKKdCKi8L4xQpYjCgIujb2RDXl91M/Ze0638kpTFs1OB7TbqulRy5eYX64 YV5Zqg== X-Received: by 2002:a05:600c:628d:b0:499:4892:d022 with SMTP id 5b1f17b1804b1-499c19bd51emr191879515e9.8.1787576443740; Mon, 24 Aug 2026 06:00:43 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:42 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/19] libssh2: fix CVE-2026-66035 Date: Mon, 24 Aug 2026 14:59:48 +0200 Message-ID: <5f5c4afa331cf0f4df845092071f712e9ba50fc7.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244102 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-66035 https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 libssh2 ptest results (qemux86-64): before: PASSED: 1 FAILED: 0 SKIPPED: 0 after: PASSED: 1 FAILED: 0 SKIPPED: 0 Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-66035.patch | 56 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 57 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch new file mode 100644 index 00000000000..7c15f92fb6d --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-66035.patch @@ -0,0 +1,56 @@ +From 6671019836476649792eea12868a370133be1abe Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Fri, 3 Jul 2026 18:22:55 +0200 +Subject: [PATCH] transport: fix potential heap overflow on ETM decrypt + +Reported-by: Vladimir Eli Tokarev +Fixes GHSA-6c79-444r-wx26 + +Closes #2198 + +Backport adaptations: +- The upstream fix uses SSH2_SAFEFREE() to safely release allocated + memory and reset the pointer. Since SSH2_SAFEFREE() is not available + in libssh2 1.11.1, replace its usage with the equivalent NULL check, + LIBSSH2_FREE(), and pointer reset sequence. +- The upstream fix renames decrypt() to transport_decrypt(). Since this + rename is not present in libssh2 1.11.1, retain the original + decrypt() function name. + +CVE: CVE-2026-66035 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4] +Signed-off-by: Jaipaul Cheernam +--- + src/transport.c | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/src/transport.c b/src/transport.c +index d147505b..9f386e75 100644 +--- a/src/transport.c ++++ b/src/transport.c +@@ -242,6 +242,17 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ ) + unsigned char *decrypt_buffer; + int blocksize = session->remote.crypt->blocksize; + ++ if(p->total_num < mac_len + 4 + (size_t)blocksize) { ++ if(p->payload) { ++ LIBSSH2_FREE(session, p->payload); ++ p->payload = NULL; ++ } ++ return LIBSSH2_ERROR_DECRYPT; ++ } ++ decrypt_size = (ssize_t)(p->total_num - mac_len - 4); ++ ++ first_block[0] = 0; ++ + rc = decrypt(session, p->payload + 4, + first_block, blocksize, FIRST_BLOCK); + if(rc) { +@@ -249,7 +260,6 @@ fullpacket(LIBSSH2_SESSION * session, int encrypted /* 1 or 0 */ ) + } + + /* we need buffer for decrypt */ +- decrypt_size = p->total_num - mac_len - 4; + decrypt_buffer = LIBSSH2_ALLOC(session, decrypt_size); + if(!decrypt_buffer) { + return LIBSSH2_ERROR_ALLOC; diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index 7d3063d9304..faa34ba3eb6 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -19,6 +19,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-66032.patch \ file://CVE-2026-66033.patch \ file://CVE-2026-66034.patch \ + file://CVE-2026-66035.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Aug 24 12:59:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96177 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5D68EC61DB7 for ; Mon, 24 Aug 2026 13:01:06 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15966.1787576462618295770 for ; Mon, 24 Aug 2026 06:01:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=I7Q7hkM+; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso35020555e9.1 for ; Mon, 24 Aug 2026 06:01:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576461; x=1788181261; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rA4EwgjAvggDCDtg8p1B4xxguIKW7SlTg84bNxmE4Tg=; b=I7Q7hkM+vC16fuorYANAkYoMiTXTwO1JICa84ihVgv+5y3Sf6AZLg9vFRoznBKyf9S OBW94mM3JdphPHBvifSSEqk/ZRxScCz7kYeteg3HSh0rZszp/vBPeoI5UgmsAgPalzx6 3604P8uOKzjbCQ+dWsW693OcivfhbUUuLcRbE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576461; x=1788181261; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rA4EwgjAvggDCDtg8p1B4xxguIKW7SlTg84bNxmE4Tg=; b=ez+VlUY/2cPEmEln1Uzr1uvgseBrYXgBiWda4sgGwzChYDM8aLSd6wIHKC0hWqxEU4 kxxq5s95LOBPLwqeyIGceDKtBuVVNB9IeJC0M0BtKfCH/9rKX0M73etbt8AHtkuL7asi 5R6srPtXQWDRA1/bzUZlRdLB13DUJded0vB8dPVL4X8an7RwcykXtbY946UaNjnxe8iN E6kY1kiOj7GD3OCPcJ0JJ4fniKHJ/UmojvVpBTQRelxPbqI3/JGTuZUXNB1M8IC35RNX mVLn/TqALCyB+34/PEZEwGW7JQm4aFQ7uFeRPIFAMGw0QjsUUenyVvww/qSPHSkXOeRf pNOw== X-Gm-Message-State: AFuF++mwJn3KJSw4CKXs8/iPV2PjnfF513kQXfbskn+7UhtxX95wvDrY NqHlBhidxHhXv+TVYeAA8CcbU6qeeCEG501MIeiE9gakuVp4T8y3/fg0VzV6U99VVZb2nWXBhaK mBRQ/LuU= X-Gm-Gg: AR+sD10f7KAc+NBF9NQ2elVHL+ey9m4XUhmbyBeFd38T+UD6znKJn+9zn4dNQu/jfUz Kz9T8jxBxsAtDx9WRF8oHEa5WA+Ln0SS7pkMCXyrnUy8/2IOa3qxd24rSvFpz8KAwUsaM+1WaAQ CuXjuCc0ukQzYNQQaIesWogCOmpGUj7bstTOT6jW9fomt0DMg70RPfRrs4AFd1n+xtdJKo98JOq 8/mCPndXl9NxXyEN7JIOdhh3ylhCRT2GsUW9LxYZ1Rbzihjr8QEgaNrJmu8YD6lFUoFpuVN+Dc4 YP/nknhCRItJBtxi53szjLYDczJYiMirNAirt4gBv3vtgY5IFhHYcirJSMOXJ+RQadhAjclVNA9 jjFvdnAhAYFhd8ZLpTrIaWB1g1ZNnBbyyjBSkBTOwZCM26nG/9qy6ciMwNiWAoseI2lLnLixGkb g/GBWL5pcSg/LRJ8lU5cKxFfLC15QJblfLl6YL2lwg/SQpAxCbLdAfOIgRu1eCuD9ZEnGO/4xFv t9fT9cfhuwYaY87zZS3y0YSVEcB9aiGOBGfGgv3p+LQO0CNA11ByJDr513ELlvAuzaM35A= X-Received: by 2002:a05:600c:4ecb:b0:499:900c:9c68 with SMTP id 5b1f17b1804b1-499c19a766fmr202534115e9.6.1787576444357; Mon, 24 Aug 2026 06:00:44 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:43 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/19] libsndfile1: patch CVE-2026-37555 Date: Mon, 24 Aug 2026 14:59:49 +0200 Message-ID: <575de444a879e838cd18f583b2a7117debf01d6c.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244114 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-37555 Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- .../libsndfile1/CVE-2026-37555.patch | 44 +++++++++++++++++++ .../libsndfile/libsndfile1_1.2.2.bb | 1 + 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-multimedia/libsndfile/libsndfile1/CVE-2026-37555.patch diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1/CVE-2026-37555.patch b/meta/recipes-multimedia/libsndfile/libsndfile1/CVE-2026-37555.patch new file mode 100644 index 00000000000..bac8476ee8c --- /dev/null +++ b/meta/recipes-multimedia/libsndfile/libsndfile1/CVE-2026-37555.patch @@ -0,0 +1,44 @@ +From c32c090ff9bb45e1dae637957c9c9b47b3967623 Mon Sep 17 00:00:00 2001 +From: Alb3e3 <74142887+Alb3e3@users.noreply.github.com> +Date: Sat, 27 Jun 2026 14:34:16 +0200 +Subject: [PATCH] sds: avoid divide-by-zero in sds_byterate for zero-frame + files + +sds_read_header() sets psf->sf.frames directly from the file's 3-byte +data-length field without a lower bound, so a crafted .sds file can +leave psf->sf.frames == 0. SDS never sets psf->bytewidth, so +sf_current_byterate() falls through to psf->byterate (sds_byterate), +which computes + + (psf->datalength * psf->sf.samplerate) / psf->sf.frames + +dividing by zero -> SIGFPE crash (denial of service) when an +application calls the public sf_current_byterate() on such a file. + +Guard the division with psf->sf.frames > 0, returning -1 (the same +'unknown' value already used for the write path) otherwise. + +Reproduced with a 21-byte crafted .sds (data-length field = 0) under +AddressSanitizer: 'FPE ... in sds_byterate src/sds.c:761' before the +fix; returns -1 cleanly after. + +CVE: CVE-2026-37555 +Upstream-Status: Backport [https://github.com/libsndfile/libsndfile/commit/c32c090ff9bb45e1dae637957c9c9b47b3967623] +Signed-off-by: Peter Marko +--- + src/sds.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/sds.c b/src/sds.c +index 2a0f164c..1070e653 100644 +--- a/src/sds.c ++++ b/src/sds.c +@@ -757,7 +757,7 @@ sds_seek (SF_PRIVATE *psf, int mode, sf_count_t seek_from_start) + static int + sds_byterate (SF_PRIVATE * psf) + { +- if (psf->file.mode == SFM_READ) ++ if (psf->file.mode == SFM_READ && psf->sf.frames > 0) + return (psf->datalength * psf->sf.samplerate) / psf->sf.frames ; + + return -1 ; diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1_1.2.2.bb b/meta/recipes-multimedia/libsndfile/libsndfile1_1.2.2.bb index c1fb5223067..a26f57d7f42 100644 --- a/meta/recipes-multimedia/libsndfile/libsndfile1_1.2.2.bb +++ b/meta/recipes-multimedia/libsndfile/libsndfile1_1.2.2.bb @@ -14,6 +14,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${PV}/libsndfile-${PV}.tar.xz \ file://0001-Include-stdbool.h-instead-of-redefining-bool-true-an.patch \ file://CVE-2025-56226-01.patch \ file://CVE-2025-56226-02.patch \ + file://CVE-2026-37555.patch \ " GITHUB_BASE_URI = "https://github.com/libsndfile/libsndfile/releases/" From patchwork Mon Aug 24 12:59:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96168 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3A6BC61CE3 for ; Mon, 24 Aug 2026 13:00:55 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16156.1787576447049323935 for ; Mon, 24 Aug 2026 06:00:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QQqY7fzr; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47f6609c657so1431075f8f.2 for ; Mon, 24 Aug 2026 06:00:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576445; x=1788181245; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HCfIWH4nLGBbcmgxc9e6wvnxK+RFxYqslpSY+De/l+I=; b=QQqY7fzrwkk9EmMdTOJb9eDyqFVlzBXfHUIiihLlRJ66eL6E0IYv//n5oyhtBhQKSd RkQMvx4quI+J0Amtt1rXf0Gt7TW+xnfNc7dtlKnAzTvxvZeQGTxXbGLXfTyv4nwMVpzX oHRKOxIRFW1Eip1z8YhDq5cJuDvynBzzf3aMw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576445; x=1788181245; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HCfIWH4nLGBbcmgxc9e6wvnxK+RFxYqslpSY+De/l+I=; b=phCbreGNIpueOehot5rvZU9eRUVKkE2s4GlBukhT0V0z9AH5ibsDc3cn95i5PSkF9G 7FQUXgiN2/xYp2GIN/TMIJSDduqV2qBH7lBHDT9Ij87Ew5xi/I1Zm4pUHe1+cXpQ8bWp 28hZxaoNKB6x7a7MxMS+JojU6l+ceLVPJbyy5aZ7XxodMTZSwiYW6aMiJPOVpOnrWuxU UrL3zCaTi/UQP/zHZxcwz/cR5OAsgBeIKDiegJt+Anz77YzpmaA95y59MivPJeup2l92 X51/o312kYwZTJRNOfvGq4j+2S3wDAqGPEDUVrd4FZdn7BUj0m5b3fcpdfwZ5OLW212k lJ8A== X-Gm-Message-State: AFuF++nm47NHFLS8O3iYr28V9+/V8f40RK7uo1Y/SBM8Emv8lr7FHWYm ydqCbbvUtlrkhyvYL7PWX56ZD6TOq3ns8ubWXFpBN6JU13oDsvsSfOUuZIcUCTeIc4vjeahK3y1 gIFW/TaM= X-Gm-Gg: AR+sD11RRjnSSjLUnTL6dC1BUEX3edTl7qiy96JODvMCaFlXbmpyY+Gajn9rMVuNVVS Aku+Nu+DHKd3dd/CtSul9mJqa1e7iuApkuMoWLXv6vRYNjzOLa+qOK4Rw/ZIlrC91gTks75vFLZ C2pPIIQGdF24OsAZrTMNesXCXbI/xNdp28f8DlS6YYWYcH6KPrm7yQ8mrbNta2Xzz6mua5QtHyy Hon5zI0qGhoGO3DZswXoJU9NUOD4QNdLliEordkzEzrg+26cWNmXLt0t98cn0tMsKcNDD2XNuUM DvB5a91iOxbDSo8mgE3gBFE0O63sOwT9cV9voyfQpILxLWRAs0vQB2C7UIhm5LXl1Zhroffr0Tf dmKIufm0mUYo1pzezIcGNG0HUxsCrRTvjeSnaZjKuIzvsrSMB0K3YWgfAEg9hqsMATG7kmqryDl KwLbY07gTjbPH7izXTzrE7n8Mn6E0WpGoYUzj0QYyDwgDSb48zqyyKuA3vUtV+OGYLDqjiR+EfI 1960HdXp7sh9bewRAC4DaLubm4x86zLrHvdiBUBnxd3KKNwsu83h5rsVG1FoRiZcKDZXP4= X-Received: by 2002:a05:600c:1384:b0:499:afe2:e4d0 with SMTP id 5b1f17b1804b1-499b83395d7mr279560305e9.8.1787576445014; Mon, 24 Aug 2026 06:00:45 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.44 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/19] nghttp2: set status for CVE-2026-58055 Date: Mon, 24 Aug 2026 14:59:50 +0200 Message-ID: <3124fe207e927b7bf40bef1d723a77a707935b80.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244103 From: Deepak Rathore CVE-2026-58055 affects the nghttpx proxy when forwarding HTTP/1.1 Upgrade requests with a Content-Length header and body. The default recipe does not build nghttpx. Add a conditional CVE_STATUS entry so the CVE remains unpatched if app support is enabled, while default builds are marked not-applicable-config. References: https://nvd.nist.gov/vuln/detail/CVE-2026-58055 Signed-off-by: Deepak Rathore Signed-off-by: Fabien Thomas --- meta/recipes-support/nghttp2/nghttp2_1.68.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/nghttp2/nghttp2_1.68.1.bb b/meta/recipes-support/nghttp2/nghttp2_1.68.1.bb index 71d5eef8d6b..29a7d26819c 100644 --- a/meta/recipes-support/nghttp2/nghttp2_1.68.1.bb +++ b/meta/recipes-support/nghttp2/nghttp2_1.68.1.bb @@ -17,4 +17,6 @@ PACKAGECONFIG[manpages] = "-DENABLE_DOC=ON,-DENABLE_DOC=OFF" EXTRA_OECMAKE = "-DENABLE_LIB_ONLY=ON -DENABLE_PYTHON_BINDINGS=OFF" +CVE_STATUS[CVE-2026-58055] = "${@bb.utils.contains('EXTRA_OECMAKE', '-DENABLE_LIB_ONLY=ON', 'not-applicable-config: nghttpx proxy is not built in the default nghttp2 configuration', 'unpatched', d)}" + BBCLASSEXTEND = "native nativesdk" From patchwork Mon Aug 24 12:59:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96181 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 96F41C5DF94 for ; Mon, 24 Aug 2026 13:01:16 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16168.1787576474235174311 for ; Mon, 24 Aug 2026 06:01:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PIFeqnKa; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-476a130c138so3401275f8f.0 for ; Mon, 24 Aug 2026 06:01:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576472; x=1788181272; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=iiTdBuFC0jW72uZXKlmO/Ai4IsFeJMxK5PcnD4MiNuk=; b=PIFeqnKaWMU2JnwiarePwW7gt7AA0k4qtpue+slETJk4zNlD6Gl1/YzdYJYRcSTMrn ypt/T5i2hmez4WEJarQqTHIdh1fhPc6PPQZUyNlRvJRvqEpVg9Ok3OTM5oSJlxKsSYPo Hwm/TXq+cWC9muA/GixN0xbJ12YF4RTrViL2k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576472; x=1788181272; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=iiTdBuFC0jW72uZXKlmO/Ai4IsFeJMxK5PcnD4MiNuk=; b=XflQDmzPgGdiaumlhlUQlPTChQlO4pxUkdoWeaUGJifv1IXouz+ACR+NRjbtlnKaZo AHc9EmrR1Xd2dTObIzUS/2OvA9EaGkiDBh+ZKPJgqatmj2gkNh+EFxzuAnmimm8i8c7T 6vXXp3/TVjXNFUn9QslxtsygkRDBTO4X87Fsv5pJ9iC4AiHZw2HjqIt4F9dv39Ln2m1w uo/NelCynI10MekS6n68TRkamnPl/wsIpIHrukb98xwQLleFC6/YVSolwaIRp0D7AwIO imiQXVv2HNKV5052Y1yJmHY0Bowp9FlNVTtRs3rwN2YjD1i77/Jrbco8NNPI7fvX4Zoa /WgQ== X-Gm-Message-State: AFuF++k6n9S96Il8xTvkKHpDNy8wrIUG7yFsU0vvRXLohp/FY+x56PQu EMOmGYg96Xzly8yuyNad7sL6sCijeILlMhNMqSd7PIWZRlNSDKiNN/jWK0bmjPyEpQejHsgu8YX INNrsvE8= X-Gm-Gg: AR+sD13eNhgQ3SjIsCRLQD2dcajOPgRITyPgh7fP4cPfxedh9plfnbwoofJBS3GeQq+ RiqpJ748PDc9ovMNsnyYWOoV38uBuu8Y0bDkW3b1K7rMdjL3cAl7llGZml1TGbPaZGuqHTIaSOS 1Nl8FsNmOuum0D1EL3fqRT2NPX5Bl1iz6HB5dwaG5UwYkdXk0Irkvtlhkj0d6PSHJfTuDXJS6ru t66je6ROJy/usD9UhGobpPVjbg56BEjWcwL2qG74wDWX3aG6gvvog6WI71C53wTQKJMnzWrKNCD y8DEEFOMdQayY53EC719vQ4Gp5ssqpJI2Jm2OWuyp/uComV1ae8Zf1+AfpssLQvnbi8+TewV6b8 IrAncVKiSXepl/is7MfKTFvlhD/jihyZLmfOC+WSOy1ATklK2zDr+MlmKiwqOcfMkUFPemNfLTv zamJ/Hs8LnHdq8AccjO3DH+yxv2P6FiRP2Avmbfs8J4IgFpsCons+pKKvt7Y26qovFi2Thi5CLG ENXCGPwBEL9EDfhb8mEqW7o07t3rFywGs8aG9hFcauRDckAlfj5XZQRBmaqNuWqhbIqisI= X-Received: by 2002:a05:600c:5486:b0:499:a0f3:9d5c with SMTP id 5b1f17b1804b1-499b82f412amr310146465e9.3.1787576445875; Mon, 24 Aug 2026 06:00:45 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/19] binutils: Patch for CVE-2026-15003 Date: Mon, 24 Aug 2026 14:59:51 +0200 Message-ID: <711c77071762f53fe124a78d5049c56d70ad48f1.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244118 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-15003 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c Test results: binutils-testsuite 2.46.1 (x86_64-oe-linux) - All tests PASSED binutils: 327 passed, 5 untested, 9 unsupported gas: 2091 passed, 4 unsupported ld: 1899 passed, 7 expected failures, 20 untested, 109 unsupported Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c] Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.46.inc | 1 + .../binutils/binutils/CVE-2026-15003.patch | 402 ++++++++++++++++++ 2 files changed, 403 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.46.inc b/meta/recipes-devtools/binutils/binutils-2.46.inc index cab270cea5d..177ae04ee3f 100644 --- a/meta/recipes-devtools/binutils/binutils-2.46.inc +++ b/meta/recipes-devtools/binutils/binutils-2.46.inc @@ -40,4 +40,5 @@ SRC_URI = "\ file://0014-Remove-duplicate-pe-dll.o-entry-deom-targ_extra_ofil.patch \ file://CVE-2026-4647.patch \ file://CVE-2026-6846.patch \ + file://CVE-2026-15003.patch \ " diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch new file mode 100644 index 00000000000..016b342c875 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch @@ -0,0 +1,402 @@ +From 8552afe151ef0513d4afe90f809408509ce77d20 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Thu, 9 Apr 2026 09:06:27 +0930 +Subject: [PATCH] PR 34053 buffer overflow in xcoff_link_add_symbols + +This patch adds two sanity checks with error reporting in +xcoff_link_add_symbols before reading symbol aux entries, add extends +assertions in later functions. A whole lot of unnecessary casts are +also tidied. + + PR 34053 + * xcofflink.c: Remove unnecessary casts throughout. + (xcoff_link_add_symbols): Sanity check aux entries are within + symbol buffer. + (bfd_xcoff_build_dynamic_sections): Assert the above is true. + (xcoff_link_input_bfd): Likewise. + +(cherry picked from commit 23acf2f003f81b2f8d9d1997ea45d822d33d386c) + +CVE: CVE-2026-15003 +Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c] + +Signed-off-by: Jaipaul Cheernam +--- + bfd/xcofflink.c | 132 +++++++++++++++++++++++------------------------- + 1 file changed, 62 insertions(+), 70 deletions(-) + +diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c +index 691acc854ae..cb279b9db9d 100644 +--- a/bfd/xcofflink.c ++++ b/bfd/xcofflink.c +@@ -371,7 +371,7 @@ _bfd_xcoff_canonicalize_dynamic_symtab (bfd *abfd, asymbol **psyms) + { + char *c; + +- c = bfd_alloc (abfd, (bfd_size_type) SYMNMLEN + 1); ++ c = bfd_alloc (abfd, SYMNMLEN + 1); + if (c == NULL) + return -1; + memcpy (c, ldsym._l._l_name, SYMNMLEN); +@@ -1038,7 +1038,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info) + { + char *dsnm; + +- dsnm = bfd_malloc ((bfd_size_type) strlen (name) + 2); ++ dsnm = bfd_malloc (strlen (name) + 2); + if (dsnm == NULL) + return false; + dsnm[0] = '.'; +@@ -1081,7 +1081,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info) + coff_section_data (abfd, lsec)->contents = NULL; + + /* Record this file in the import files. */ +- n = bfd_alloc (abfd, (bfd_size_type) sizeof (struct xcoff_import_file)); ++ n = bfd_alloc (abfd, sizeof (*n)); + if (n == NULL) + return false; + n->next = NULL; +@@ -1464,7 +1464,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + bfd_vma value; + struct xcoff_link_hash_entry *set_toc; + +- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym); ++ bfd_coff_swap_sym_in (abfd, esym, &sym); + + /* In this pass we are only interested in symbols with csect + information. */ +@@ -1510,9 +1510,12 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + { + union internal_auxent auxlin; + +- bfd_coff_swap_aux_in (abfd, (void *) (esym + symesz), ++ if (symesz >= (size_t) (esym_end - esym)) ++ goto badaux; ++ ++ bfd_coff_swap_aux_in (abfd, esym + symesz, + sym.n_type, sym.n_sclass, +- 0, sym.n_numaux, (void *) &auxlin); ++ 0, sym.n_numaux, &auxlin); + + if (auxlin.x_sym.x_fcnary.x_fcn.x_lnnoptr != 0) + { +@@ -1539,7 +1542,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + + linpstart = (reloc_info[enclosing->target_index].linenos + + linoff); +- bfd_coff_swap_lineno_in (abfd, (void *) linpstart, (void *) &lin); ++ bfd_coff_swap_lineno_in (abfd, linpstart, &lin); + if (lin.l_lnno == 0 + && ((bfd_size_type) lin.l_addr.l_symndx + == ((esym +@@ -1554,8 +1557,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + linp < linpend; + linp += linesz) + { +- bfd_coff_swap_lineno_in (abfd, (void *) linp, +- (void *) &lin); ++ bfd_coff_swap_lineno_in (abfd, linp, &lin); + if (lin.l_lnno == 0) + break; + } +@@ -1576,21 +1578,21 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + visibility = sym.n_type & SYM_V_MASK; + + /* Pick up the csect auxiliary information. */ +- if (sym.n_numaux == 0) ++ if (sym.n_numaux < 1 ++ || sym.n_numaux * symesz >= (size_t) (esym_end - esym)) + { ++ badaux: + _bfd_error_handler + /* xgettext:c-format */ +- (_("%pB: class %d symbol `%s' has no aux entries"), ++ (_("%pB: class %d symbol '%s' has missing aux entries"), + abfd, sym.n_sclass, name); + bfd_set_error (bfd_error_bad_value); + goto error_return; + } + +- bfd_coff_swap_aux_in (abfd, +- (void *) (esym + symesz * sym.n_numaux), ++ bfd_coff_swap_aux_in (abfd, esym + symesz * sym.n_numaux, + sym.n_type, sym.n_sclass, +- sym.n_numaux - 1, sym.n_numaux, +- (void *) &aux); ++ sym.n_numaux - 1, sym.n_numaux, &aux); + + smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp); + +@@ -1713,7 +1715,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + + erelsym = ((bfd_byte *) obj_coff_external_syms (abfd) + + rel->r_symndx * symesz); +- bfd_coff_swap_sym_in (abfd, (void *) erelsym, (void *) &relsym); ++ bfd_coff_swap_sym_in (abfd, erelsym, &relsym); + if (EXTERN_SYM_P (relsym.n_sclass)) + { + const char *relname; +@@ -2496,7 +2498,7 @@ xcoff_link_check_ar_symbols (bfd *abfd, + { + struct internal_syment sym; + +- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym); ++ bfd_coff_swap_sym_in (abfd, esym, &sym); + esym += (sym.n_numaux + 1) * symesz; + + if (EXTERN_SYM_P (sym.n_sclass) && sym.n_scnum != N_UNDEF) +@@ -3989,7 +3991,7 @@ bfd_xcoff_size_dynamic_sections (bfd *output_bfd, + return true; + + xcoff_link_hash_traverse (xcoff_hash_table (info), xcoff_post_gc_symbol, +- (void *) ldinfo); ++ ldinfo); + if (ldinfo->failed) + goto error_return; + +@@ -4200,7 +4202,8 @@ bfd_xcoff_build_dynamic_sections (bfd *output_bfd, + /* Read in the csect information, if any. */ + if (CSECT_SYM_P (sym.n_sclass)) + { +- BFD_ASSERT (sym.n_numaux > 0); ++ BFD_ASSERT (sym.n_numaux > 0 ++ && symesz * sym.n_numaux < (size_t) (esymend - esym)); + bfd_coff_swap_aux_in (sub, esym + symesz * sym.n_numaux, + sym.n_type, sym.n_sclass, + sym.n_numaux - 1, sym.n_numaux, &aux); +@@ -4291,7 +4294,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd, + { + struct bfd_in_memory *bim; + +- bim = bfd_malloc ((bfd_size_type) sizeof (* bim)); ++ bim = bfd_malloc (sizeof (*bim)); + if (bim == NULL) + return false; + +@@ -4300,7 +4303,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd, + + abfd->link.next = 0; + abfd->format = bfd_object; +- abfd->iostream = (void *) bim; ++ abfd->iostream = bim; + abfd->flags = BFD_IN_MEMORY; + abfd->iovec = &_bfd_memory_iovec; + abfd->direction = write_direction; +@@ -4860,8 +4863,8 @@ bfd_xcoff_size_stubs (struct bfd_link_info *info) + } + + bfd_coff_swap_sym_in (input_bfd, +- (void *) esyms + irel->r_symndx * symesz, +- (void *) &sym); ++ esyms + irel->r_symndx * symesz, ++ &sym); + + sym_sec = xcoff_data (input_bfd)->csects[irel->r_symndx]; + sym_value = sym.n_value - sym_sec->vma; +@@ -5234,17 +5237,16 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + int smtyp = 0; + int add; + +- bfd_coff_swap_sym_in (input_bfd, (void *) esym, (void *) isymp); ++ bfd_coff_swap_sym_in (input_bfd, esym, isymp); + + /* Read in the csect information, if any. */ + if (CSECT_SYM_P (isymp->n_sclass)) + { +- BFD_ASSERT (isymp->n_numaux > 0); +- bfd_coff_swap_aux_in (input_bfd, +- (void *) (esym + isymesz * isymp->n_numaux), ++ BFD_ASSERT (isymp->n_numaux > 0 ++ && isymesz * isymp->n_numaux < (size_t) (esym_end - esym)); ++ bfd_coff_swap_aux_in (input_bfd, esym + isymesz * isymp->n_numaux, + isymp->n_type, isymp->n_sclass, +- isymp->n_numaux - 1, isymp->n_numaux, +- (void *) &aux); ++ isymp->n_numaux - 1, isymp->n_numaux, &aux); + + smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp); + } +@@ -5459,12 +5461,10 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + if ((bfd_size_type) flinfo->last_file_index >= syment_base) + { + /* The last C_FILE symbol is in this input file. */ +- bfd_coff_swap_sym_out (output_bfd, +- (void *) &flinfo->last_file, +- (void *) (flinfo->outsyms +- + ((flinfo->last_file_index +- - syment_base) +- * osymesz))); ++ bfd_coff_swap_sym_out ++ (output_bfd, &flinfo->last_file, ++ flinfo->outsyms + (flinfo->last_file_index ++ - syment_base) * osymesz); + } + else + { +@@ -5473,9 +5473,8 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + borrow *outsym temporarily. */ + file_ptr pos; + +- bfd_coff_swap_sym_out (output_bfd, +- (void *) &flinfo->last_file, +- (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file, ++ outsym); + + pos = obj_sym_filepos (output_bfd); + pos += flinfo->last_file_index * osymesz; +@@ -5541,7 +5540,7 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + } + + /* Output the symbol. */ +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + + esym += isymesz; + outsym += osymesz; +@@ -5550,9 +5549,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + { + union internal_auxent aux; + +- bfd_coff_swap_aux_in (input_bfd, (void *) esym, isymp->n_type, +- isymp->n_sclass, i, isymp->n_numaux, +- (void *) &aux); ++ bfd_coff_swap_aux_in (input_bfd, esym, ++ isymp->n_type, isymp->n_sclass, i, ++ isymp->n_numaux, &aux); + + if (isymp->n_sclass == C_FILE) + { +@@ -5780,9 +5779,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + } + } + +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, isymp->n_type, ++ bfd_coff_swap_aux_out (output_bfd, &aux, isymp->n_type, + isymp->n_sclass, i, isymp->n_numaux, +- (void *) outsym); ++ outsym); + outsym += osymesz; + esym += isymesz; + } +@@ -5804,10 +5803,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + && (bfd_size_type) flinfo->last_file_index >= syment_base) + { + flinfo->last_file.n_value = output_index; +- bfd_coff_swap_sym_out (output_bfd, (void *) &flinfo->last_file, +- (void *) (flinfo->outsyms +- + ((flinfo->last_file_index - syment_base) +- * osymesz))); ++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file, ++ flinfo->outsyms + (flinfo->last_file_index ++ - syment_base) * osymesz); + } + + /* Write the modified symbols to the output file. */ +@@ -6020,16 +6018,13 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + void * auxptr; + union internal_auxent aux; + +- auxptr = ((void *) +- (((bfd_byte *) +- obj_coff_external_syms (input_bfd)) +- + ((r_symndx + is->n_numaux) +- * isymesz))); ++ auxptr = ((bfd_byte *) ++ obj_coff_external_syms (input_bfd) ++ + (r_symndx + is->n_numaux) * isymesz); + bfd_coff_swap_aux_in (input_bfd, auxptr, + is->n_type, is->n_sclass, + is->n_numaux - 1, +- is->n_numaux, +- (void *) &aux); ++ is->n_numaux, &aux); + if (SMTYP_SMTYP (aux.x_csect.x_smtyp) == XTY_SD + && aux.x_csect.x_smclas == XMC_TC0) + indx = flinfo->toc_symindx; +@@ -6548,12 +6543,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + irsym.n_type = T_NULL; + irsym.n_numaux = 1; + +- bfd_coff_swap_sym_out (output_bfd, (void *) &irsym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &irsym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + /* Note : iraux is initialized above. */ +- bfd_coff_swap_aux_out (output_bfd, (void *) &iraux, T_NULL, C_HIDEXT, +- 0, 1, (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &iraux, T_NULL, C_HIDEXT, ++ 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + + if (h->indx >= 0) +@@ -6791,12 +6786,11 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + isym.n_type = T_NULL; + isym.n_numaux = 1; + +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + aux.x_csect.x_smclas = h->smclas; +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, isym.n_sclass, 0, 1, +- (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, isym.n_sclass, 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + + if ((h->root.type == bfd_link_hash_defined +@@ -6811,13 +6805,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + isym.n_sclass = C_WEAKEXT; + else + isym.n_sclass = C_EXT; +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + aux.x_csect.x_smtyp = XTY_LD; + aux.x_csect.x_scnlen.u64 = obj_raw_syment_count (output_bfd); +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, C_EXT, 0, 1, +- (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, C_EXT, 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + } + +@@ -6913,8 +6906,8 @@ xcoff_reloc_link_order (bfd *output_bfd, + howto->name, addend, NULL, NULL, (bfd_vma) 0); + break; + } +- ok = bfd_set_section_contents (output_bfd, output_section, (void *) buf, +- (file_ptr) link_order->offset, size); ++ ok = bfd_set_section_contents (output_bfd, output_section, buf, ++ link_order->offset, size); + free (buf); + if (! ok) + return false; +@@ -7379,8 +7372,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + if (flinfo.last_file_index != -1) + { + flinfo.last_file.n_value = -(bfd_vma) 1; +- bfd_coff_swap_sym_out (abfd, (void *) &flinfo.last_file, +- (void *) flinfo.outsyms); ++ bfd_coff_swap_sym_out (abfd, &flinfo.last_file, flinfo.outsyms); + pos = obj_sym_filepos (abfd) + flinfo.last_file_index * symesz; + if (bfd_seek (abfd, pos, SEEK_SET) != 0 + || bfd_write (flinfo.outsyms, symesz, abfd) != symesz) +@@ -7464,7 +7456,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + appear in the symbol table, which is not necessarily by + address. So we sort them here. There may be a better way to + do this. */ +- qsort ((void *) flinfo.section_info[o->target_index].relocs, ++ qsort (flinfo.section_info[o->target_index].relocs, + o->reloc_count, sizeof (struct internal_reloc), + xcoff_sort_relocs); + +@@ -7472,7 +7464,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + irelend = irel + o->reloc_count; + erel = external_relocs; + for (; irel < irelend; irel++, rel_hash++, erel += relsz) +- bfd_coff_swap_reloc_out (abfd, (void *) irel, (void *) erel); ++ bfd_coff_swap_reloc_out (abfd, irel, erel); + + rel_size = relsz * o->reloc_count; + if (bfd_seek (abfd, o->rel_filepos, SEEK_SET) != 0 From patchwork Mon Aug 24 12:59:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96171 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 16FD9C61DB6 for ; Mon, 24 Aug 2026 13:00:56 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16157.1787576448508675333 for ; Mon, 24 Aug 2026 06:00:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hj88WEcY; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4953e04ef16so31729315e9.2 for ; Mon, 24 Aug 2026 06:00:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576447; x=1788181247; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/lGyfyePXPpNcntmQnLriUuLFv974ZDyD47uzIlKg8A=; b=hj88WEcYaxgpYBx2n9YRv6dzcluyV0+vpB6yU1JWeL2IRMHIBV5bTlVDBaktqfznzJ E45guXOAEZ7ZKnay46TdzEH7rimyR9CEQXUrAMVOw1ihm+GcmDD79L2H3+nAJk3dFIsB XdCYH1kQLRwnGveKiLEk0YAXI5B6j08LwW7tI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576447; x=1788181247; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/lGyfyePXPpNcntmQnLriUuLFv974ZDyD47uzIlKg8A=; b=eXGCVv+zFvYIEIccWXXJ49fPVfjoHBgsUeU/iZ1Pl23c4lUxRo5xHy8CcAcqNaZn7v iGQafFvGetLqeYAvs3AaXqSqLDKPdTHjOR33xv0AwHGe1EwWtJ2MKvyOcJteJ5/2Z4J3 0zIuMj0JjBiD+Ato2WdWL5HbjYWHMqPzQSuIK/OncjJllQ7n0M5Yr+U7QTX1THSfBiKd iads1pQulC4rt258dfY9R/hlu2JnDAE1pReDDd1+pzIcM+6NORDJ89ceP9LN5EMKIlED kWtFLfPhdw3kn7HCESPagHdIHuTXC4oT/M1zFuvNFPydpQ1Ri7O+hAyVxRCG0k+t4jQc ONmw== X-Gm-Message-State: AFuF++kzZGV1RSdNoWNvgUMUWz+Og4ZMBUFJqWMScrLgoDVBpMuNS3oh I5hdq1RlLzXBWayrC0sgefth8Vr101s1FAqaHKI2W0+xgB45Wn8SFjid8Tkr940j5jzHjgGpEod 0Iy7/nHk= X-Gm-Gg: AR+sD12jxgq+tUB+o47Gol8mUUR5Wq5WOOGEIAaXHKpBylWoJIMnJYcpN8PLW8pRWxz ArncJWUdCsxlPNVbXeDt4QlJOVW5yLuztlBz3s+NoAD05c+d8+nQVdahnE8CcXMOgUomQjLEOfq khI1cy3R1KbHIT5INKLta/jRbXLDXCKNzWI0YvARmXAUwl1Fq3sMSBmc8imuz2JrskKOkWRVWvF pry4zLhE9It53C0riOo0ceRdsTf76syLQuYVubSTKzfdKxjZW0Ga0Yms8fGpL1YTwS4UU4rdzCw 0W7ZZ0e1V4VP0s27L6ArXXQMgcQkvZb6z4Ewwli7n6PlIWkv5Re9ln/ug5n71ZThvecK10rdChm dVUn6NAZ9VN/lE6KiQPzRlerCBQx2OFIP8ldHshRZQnjwOh2m0+tGncebvT4mtkhmRetSQ25AYX Se2cx4Oc3qkH0wFCJ7We/ngaqxnfBY4C3Ghd9LT/8az2aE4bNUpeSIxcOWCHkx/L7wpqAr7mOfy bpmPainFincszULcbGXNmdhem4PK2ZAwDasnfjhUEp2I7T9PeAyec31dNPSa6ydii7tm04= X-Received: by 2002:a05:600c:4f81:b0:499:726b:7375 with SMTP id 5b1f17b1804b1-499b8466bf5mr280477195e9.14.1787576446599; Mon, 24 Aug 2026 06:00:46 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/19] binutils: fix CVE-2026-18220 Date: Mon, 24 Aug 2026 14:59:52 +0200 Message-ID: <189e4711da216e970e4fb73cc7ba825e015371ba.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244104 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-18220 https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=114e3aae2b7e34057c8909301eaf78c15687e8e5 Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5] Test results: binutils-testsuite 2.46.1 (x86_64-oe-linux) - All tests PASSED binutils: 327 passed, 5 untested, 9 unsupported gas: 2091 passed, 4 unsupported ld: 1899 passed, 7 expected failures, 20 untested, 109 unsupported Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.46.inc | 1 + .../binutils/binutils/CVE-2026-18220.patch | 65 +++++++++++++++++++ 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.46.inc b/meta/recipes-devtools/binutils/binutils-2.46.inc index 177ae04ee3f..f8d926b22e2 100644 --- a/meta/recipes-devtools/binutils/binutils-2.46.inc +++ b/meta/recipes-devtools/binutils/binutils-2.46.inc @@ -41,4 +41,5 @@ SRC_URI = "\ file://CVE-2026-4647.patch \ file://CVE-2026-6846.patch \ file://CVE-2026-15003.patch \ + file://CVE-2026-18220.patch \ " diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch new file mode 100644 index 00000000000..e915fb223a1 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch @@ -0,0 +1,65 @@ +From 114e3aae2b7e34057c8909301eaf78c15687e8e5 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Sun, 28 Jun 2026 09:11:46 +0930 +Subject: [PATCH] asan: buffer overflow in elf32_dlx_relocate26 + + * elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset. + (elf32_dlx_relocate16): Likewise. + (_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective + existing check. + +CVE: CVE-2026-18220 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5] + +Signed-off-by: Jaipaul Cheernam +--- + bfd/elf32-dlx.c | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c +index 2dfeb4d7390..0f9a49695d7 100644 +--- a/bfd/elf32-dlx.c ++++ b/bfd/elf32-dlx.c +@@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, + return bfd_reloc_ok; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + ret = bfd_reloc_ok; + + if (bfd_is_und_section (symbol->section) +@@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, + relocation += reloc_entry->addend; + relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address); + +- if (reloc_entry->address > bfd_get_section_limit (abfd, input_section)) +- return bfd_reloc_outofrange; +- + bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF), + (bfd_byte *)data + reloc_entry->address); + +@@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd, + return bfd_reloc_undefined; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); + allignment = 1 << (input_section->output_section->alignment_power - 1); + vallo = insn & 0x0000FFFF; +@@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd, + return bfd_reloc_undefined; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); + allignment = 1 << (input_section->output_section->alignment_power - 1); + vallo = insn & 0x03FFFFFF; From patchwork Mon Aug 24 12:59:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96172 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0A3A8C61DB7 for ; Mon, 24 Aug 2026 13:00:56 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16158.1787576449281883487 for ; Mon, 24 Aug 2026 06:00:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kQY4LjWW; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-499b02fc590so21399135e9.2 for ; Mon, 24 Aug 2026 06:00:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576447; x=1788181247; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5GLnUudYtIqEEOcy0Mx3uDgAylfdwRcaTUONVQLEKhI=; b=kQY4LjWWOvpp2ePJM1x5ThltgatHdGiIZo57lDia6G3HBvJeRE4q2GP6n3sl28fyZZ /HMfCLdiSRKCivaZ36PCdSvODV+o8UqWkqthdbOWavFtzoGzgulNjXntDMxq+VacHj0z QKtrEqQZ6v85M4R3y6g42PlaxYWVoVOIG/muY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576447; x=1788181247; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5GLnUudYtIqEEOcy0Mx3uDgAylfdwRcaTUONVQLEKhI=; b=HvVascuaZoTkBkA3/+JOSSm/2ySlz+Rg0g7l10AHuMq1ffGbwbMeqtXrrU55SFtBGh 65iU0zavBqG9dG3lFyNjbBSQoJLfqzzWSe4j6JJ/ZVqk63SQ6iRYGUlV4Apx2aE3KycO xClfmKPCTqbTNiYdzoDdg5YRIYblkbYYeOWh8E7Dtg3WTnmwjJYEi3TvoTqjl/PJCiSB 4RHF4lxK1Wdt1pQj9dFFaoR5irSW2mkp7b7yF4CXuCM2hxgE9qesqmlfZo5fNQjwNhII 2bfORpA/NB2Tgj/eiHJgXIGXso1tz1sNfHQwmHbxqk82gPeBeRwd6viEBEeRhxI2Zo45 FV2Q== X-Gm-Message-State: AFuF++lKUpprgnhSSJQyxBIqOWw3OKftRtO1pHoXR7Lj1wnbVmBREoET QQ+i/O6ENU1AFOj0X6nE+KZIm3/5HGy5Fl+sz2FCkscbbTEgaQU7iCW+JhQLZSxuE2dV5tgy1o6 Zh4l3jTA= X-Gm-Gg: AR+sD13K7805nFkULs19MqHRs4tNR/eqRp1oJySGh91a+t5rg5FNnWc34R7Azz8IlGL AbFPvqPC0A2HGGwE+APGc8lq/OcL2A5TWFIKQhgAGe+z6YGRgf9Gng+a4OZhgkhJHJpl4c4OR71 0k0917HrDDHuGU7YApu+buRPRkV1+LTNMgCN4/cITaD2SJeRknMfUs2y/vtEiVSzoxHIzAD6d0s e/gqTWiwY14Y4WCo3oR1lpqEplBxEk4EhZsJFrO44X1NezOtWvm2FydhoJPe5sajbAWEqmgW0Oz hF5h1UBu8e6XigWmDo+XMKLbGoo/pZLfaz0EW1YE5ydMTuG637hMz8U6yzQZbjWuFdG3t2ESIOa 418929V+bB1fsxy01ILnMizrL6dRg4nU7Q4dB79fPyxaHhIlzHeIUKHoAbYLGpsQIJ0rWEdJgbU nonPYBAS8ITggfRLY2rKtyqXus4YiB9k4LZxehaU46ngvb7x4qRDdwWwbo4R9fTlxlLXA2Dp9nd aaytHEs/0HfIxEPu6DUMG5YC5maW5vju30Kx6vWML0wibBLwE/CAr7T5E2k2pZOzQv4A/vJts56 TQVrGw== X-Received: by 2002:a05:600c:5251:b0:499:8174:9f39 with SMTP id 5b1f17b1804b1-499b8270deamr323521965e9.0.1787576447365; Mon, 24 Aug 2026 06:00:47 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/19] libssh2: fix CVE-2026-58050 Date: Mon, 24 Aug 2026 14:59:53 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244105 From: Adarsh Jagadish Kamini Backport patch to fix CVE-2026-58050. References: https://nvd.nist.gov/vuln/detail/CVE-2026-58050 Upstream fix: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12 Signed-off-by: Adarsh Jagadish Kamini Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-58050.patch | 45 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch new file mode 100644 index 00000000000..0163b379f35 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch @@ -0,0 +1,45 @@ +From 05b2fb4ec89d75235dbd97c5965dc0e46b405a7c Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 28 Jun 2026 02:12:52 +0200 +Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit + `libssh2_publickey_list_fetch()` + +Cap list size at 1024 elements. + +Reported-and-initial-patch-by: Mateusz Gierblinski +Reported-and-initial-patch-by: Behzod Abdullayev +Reported-by: Sharique Raza + +Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9 + +Closes #2128 + +src/publickey.c: replaced ssh2_err() with _libssh2_error() to match +the stable branch's error-reporting convention. + +Assisted-by: kiro:claude-sonnet-5 + +CVE: CVE-2026-58050 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12] + +Signed-off-by: Adarsh Jagadish Kamini +--- + src/publickey.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/src/publickey.c b/src/publickey.c +index 9c9fa618..196d2f9f 100644 +--- a/src/publickey.c ++++ b/src/publickey.c +@@ -1114,6 +1114,11 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys, + } + + if(list[keys].num_attrs) { ++ if(list[keys].num_attrs > 1024) { ++ _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY, ++ "Too many publickey attributes"); ++ goto err_exit; ++ } + list[keys].attrs = + LIBSSH2_ALLOC(session, + list[keys].num_attrs * diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index faa34ba3eb6..52684ae74ef 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -20,6 +20,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-66033.patch \ file://CVE-2026-66034.patch \ file://CVE-2026-66035.patch \ + file://CVE-2026-58050.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Aug 24 12:59:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96174 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1B8D7C61DB9 for ; Mon, 24 Aug 2026 13:00:56 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15956.1787576451342199007 for ; Mon, 24 Aug 2026 06:00:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=h0HLVJt3; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso21612395e9.0 for ; Mon, 24 Aug 2026 06:00:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576449; x=1788181249; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aiiuUIXLyKbRkg+RqxCcfudTBlPqVPCUHne6Va4dLeE=; b=h0HLVJt3AM+NaXbRfgRKlfC60FGrE2fBGU56cDAdOp4iYPcWKD5dTfFx2r3yb5jVs4 0JBG6FJVJm9CEuDRyi5ZpSZLEPWx3hNTjtAj50SdD46KH7JMoIboGxdFdy4tBYxeQdP1 vVX7LDcLMVrqsu6Ownd7Kac0lW4PBE1Q9RfSA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576449; x=1788181249; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=aiiuUIXLyKbRkg+RqxCcfudTBlPqVPCUHne6Va4dLeE=; b=pPawiGVchBZhbMz04t5AJdJQhtCHdNk0Vtr7nBmIMbu+I2jY7c9/437vGy2dxJbhS1 sJgKjPZEFaWe0FbYPUUE5xLFPbGRtXHJuPacoXKrrm3nNAcqlOh9L5bTKyb9svOpZ9An cAYSM1aQ9GX5im+X9m39w0KEMJVv1ydjU17K8U9FcQRIxht4gYtfdBo+HkHUMfp0XvfD NHTvGFr1vJo0550lfITXVliyKW89cT3r7G8PQhsbpk6MznihvUOtTHSTIGDOSlA6bAch 3LHfqtYRGFeWghNXU+XzZrLry5RPvHSQmuJGZR5xzpE69+ZHmtprm2GoOWuwJCQN0hTz AJAA== X-Gm-Message-State: AFuF++nER04ti41ljsJD2TOCOACnYCLMYdGvGXyEiDgTkN4L0aGkJ+2f jHzxLGiGbpnWLWWqTDClBedaFOO94cmOtY2Sr0uyyytJkDgFmFrgyjzpxrBQTtaUQszDh5Urav9 vgMhXjNk= X-Gm-Gg: AR+sD12LGkkL8Px540M99hPoBxv0lhaR24UrLmnqhdMglj2gr2z4m27KdAzy8wAHApu ooUoR+JmPyhwK1ue87yYJh09l+5DapzWumEeEx1sQUEPTvy5+9Rabo4qmgM687Wzpixjia8rTfV Ul+pJ2XMJS2QzSC0fPCX49svGwTJioH1ezTeaFEqdDUEcj5Ki1ym3I6CliFbvPHoTfpA6V09A4O 7cgt+BAnbNDpz0dhHOa4NwIjmKZ5HBESdrhbMNf0mK4k9PlZ2LgJtIccqZ255orLJggn1zqkU3M DpxYyiK8lOIJEfZFfdfC5FrxqrqGez9z72W1V3d6lH2iDcZbVfo9ar7rJnlGuYjftHHrLR0eDw/ WvRRJV/EYDNKOuHRrRI0pLQF73RR5EfLryTIH5Z37VKnay/FEFqDNhZUJHxfbR5Q/2r3TRwjnKi YVv2haFN74lFeLbygfChiOOqopx5T+Fudq0P+VqVuRy0y6Zj8PZLL8yN/KhxxvwvjW4AMXsxiM0 3k+A6SWpXi5AWHPd+rZzBftgPxi6HAvXIT6KmScos9fesGKa4ve2xRWpwMlkjXz/lAl4fc= X-Received: by 2002:a05:600c:4f0c:b0:499:80d0:8b73 with SMTP id 5b1f17b1804b1-499b8324cebmr354774115e9.4.1787576448093; Mon, 24 Aug 2026 06:00:48 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:47 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/19] bison: patch CVE-2026-56389 Date: Mon, 24 Aug 2026 14:59:54 +0200 Message-ID: <917066c3e03cb6f2648c05158cc16aa6cd156737.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244107 From: Peter Marko Pick patch mentioned in NVD CVE report. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 6c99410bd7f0bc4e2ed41ef5afe7d6b5fcb99837) Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- .../bison/bison/CVE-2026-56389.patch | 56 +++++++++++++++++++ meta/recipes-devtools/bison/bison_3.8.2.bb | 1 + 2 files changed, 57 insertions(+) create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch new file mode 100644 index 00000000000..ac827f6314a --- /dev/null +++ b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch @@ -0,0 +1,56 @@ +From 3169c1e7a2c6acc4c59dfcf8b089896d6881925b Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Thu, 23 Apr 2026 09:20:43 -0700 +Subject: [PATCH] html: use xsltproc from PATH +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +* src/print-xml.c (print_html): +* src/reader.c (prepare_percent_define_front_end_variables): +Drop undocumented support for lines like ‘%define tool.xsltproc +"whatever"’, as this can cause more trouble than it cures. + +CVE: CVE-2026-56389 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b] +Signed-off-by: Peter Marko +--- + src/print-xml.c | 4 +--- + src/reader.c | 1 - + 2 files changed, 1 insertion(+), 4 deletions(-) + +diff --git a/src/print-xml.c b/src/print-xml.c +index 8da6da0d..79bfa88d 100644 +--- a/src/print-xml.c ++++ b/src/print-xml.c +@@ -543,10 +543,9 @@ print_html (void) + assert (xml_flag); + + char *xml2html = xpath_join (pkgdatadir (), "xslt/xml2xhtml.xsl"); +- char *xsltproc = muscle_percent_define_get ("tool.xsltproc"); + char const *argv[11]; + int i = 0; +- argv[i++] = xsltproc; ++ argv[i++] = "xsltproc"; + argv[i++] = "-o"; + argv[i++] = spec_html_file; + argv[i++] = xml2html; +@@ -572,6 +571,5 @@ print_html (void) + /* termsigp */ NULL); + if (status) + complain (NULL, complaint, _("%s failed with status %d"), argv[0], status); +- free (xsltproc); + free (xml2html); + } +diff --git a/src/reader.c b/src/reader.c +index 862d7293..cb2a7f69 100644 +--- a/src/reader.c ++++ b/src/reader.c +@@ -788,7 +788,6 @@ prepare_percent_define_front_end_variables (void) + muscle_percent_define_default ("lr.default-reduction", "accepting"); + free (lr_type); + } +- muscle_percent_define_default ("tool.xsltproc", "xsltproc"); + + /* Check %define front-end variables. */ + { diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes-devtools/bison/bison_3.8.2.bb index 513d7ec287d..03d3cffe2ae 100644 --- a/meta/recipes-devtools/bison/bison_3.8.2.bb +++ b/meta/recipes-devtools/bison/bison_3.8.2.bb @@ -12,6 +12,7 @@ DEPENDS = "bison-native flex-native" SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \ file://autoconf-2.73.patch \ file://add-with-bisonlocaledir.patch \ + file://CVE-2026-56389.patch \ " SRC_URI[sha256sum] = "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2" From patchwork Mon Aug 24 12:59:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96170 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ED9C7C61DB4 for ; Mon, 24 Aug 2026 13:00:55 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15955.1787576451029370820 for ; Mon, 24 Aug 2026 06:00:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Vtyi1azY; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4980fe6b3beso29204155e9.0 for ; Mon, 24 Aug 2026 06:00:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576449; x=1788181249; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GFtmF3/Vf6hS61P8VzDdWnF9ZNwo35/dfFC5rCL6fJY=; b=Vtyi1azY3Gn7rXQ/nS5KlowwEvOQjc09D8PB68tOeRCsRqgaXXBH2eig5EQVjBPjG1 OKEjHHB2czUuUTjYDOiDzSSYMtX8Qzktm7ereT6v18Wsu6oW1Hb5Oqpu13Vr7NhzNnt3 ayJNuUNJKK313pNAYAmkMRVXOgnfMnmCBH/0k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576449; x=1788181249; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GFtmF3/Vf6hS61P8VzDdWnF9ZNwo35/dfFC5rCL6fJY=; b=ZUMOtXcoHRmkkhwaqgUCnkS0ZGbcjQIZtPE+ARHaJHppZnxTlYT5UyuljEQcz7745s s/YaYj2W/QMus3qAmaGKfhemfS8YUWKcEmoBWKd8egtVZvj8/KnhzCmW8UwlRB2Mru7G gkz3AqjsQIXDcB6fUL1h21j+fSHbhRoNdVeStQV5Vp2iHc+zQCBnrR3r+X8aqT/bwL0W aEPwb5DxJ1JOPGTUNKibeLnxshGtNAr+cuoA9s2OhkztraZIZPQUxgJdvlEcqaDC9CsJ xbW8mRBsDIBNTNyrFscUnjkAlfRUUuWGVEn04Sey6kZKyBbhKoEJ4ntLFKNcESF3NBrS ZziA== X-Gm-Message-State: AFuF++l9zibE/jBud8ieqT7DHGI2FdTwZfQN9ukG9Y4RgT6RQA/YHRfn 60q8FzsOjVuNTAqRihuW4EMCWv0j2q6BKN0mBtejmyKRYZLL9rU/laE64FPhznchVxuopdprXac hBNAMrj4= X-Gm-Gg: AR+sD10f0cuymZZqW8RQY6yvKYrJX+eCvUTuRcoorptfwadWFcHBleBLSWFW+l7Wfp7 icfxhy5+1XaA7V+HrVmg2RTIw32+DHS53kVG+gRKLfw27hjygNDoL8y28J7RMSiUTQvEEW87pV6 fhUxqCkMq8YHx/JLC6702HV8a4eRapDOLicP2+V+oqxqqPdK3+phYsG8USWt5rQ9BSMQ2ActSMo 3U/VAOFs96hKO+pDbH3f/M/ZrV4+KUnjMhMCeSevIFXF6wr2xtZjCjve3eyAeGaud5hhUCP2+rg 00GYXjoCjD1p1QFGN48jlYZYpESVUga3x20STgBZe4OUT8yHBUDpM2ci24KruQzSNjAd25XcRyF 7cbnrWhng7qkQPoFp++6gxl1wLnwqzhQOHpb17arwstGH6wD3DHymCzG23KTCaaTBkEcsHtpH3i ATmUycFhPO9Lk2Lib7k+yQEPeTl0mS+Q3KcE8csra1azXwFYRKJXrCYfq6xjeR9Rh2477qDiAXo e4OLCEPIDBI0cd5BWfF17Z0b4Xop2li/TWaDWw8zLJfev4AIZThaRlNA4khZ4EP5FxBrL4q3vpf zrGcqOubC6bq7fz2/w== X-Received: by 2002:a05:600c:4e94:b0:493:f783:c46a with SMTP id 5b1f17b1804b1-499b9198005mr220445305e9.6.1787576448844; Mon, 24 Aug 2026 06:00:48 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:48 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/19] cpio: patch CVE-2026-66485 Date: Mon, 24 Aug 2026 14:59:55 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244106 From: Peter Marko Pick patch mentioned in NVD CVE description. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: c105fbf82e2f50b05dc680e0601bf0ea3198e58c) Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + .../cpio/files/CVE-2026-66485.patch | 210 ++++++++++++++++++ 2 files changed, 211 insertions(+) create mode 100644 meta/recipes-extended/cpio/files/CVE-2026-66485.patch diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index fa011251e27..808a1222102 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -9,6 +9,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=f27defe1e96c2e1ecd4e0c9be8967949" SRC_URI = "${GNU_MIRROR}/cpio/cpio-${PV}.tar.gz \ file://run-ptest \ file://test.sh \ + file://CVE-2026-66485.patch \ " SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee4183455499e" diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66485.patch b/meta/recipes-extended/cpio/files/CVE-2026-66485.patch new file mode 100644 index 00000000000..f9c0f48281f --- /dev/null +++ b/meta/recipes-extended/cpio/files/CVE-2026-66485.patch @@ -0,0 +1,210 @@ +From 3cd514031371d8aeeaf2048aa10103e02831aaa9 Mon Sep 17 00:00:00 2001 +From: Sergey Poznyakoff +Date: Fri, 1 May 2026 08:19:41 +0300 +Subject: [PATCH] Minor fixes + +* src/makepath.c: Don't use alloca. +* src/userspec.c: Likewise. + +CVE: CVE-2026-66485 +Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9] +Signed-off-by: Peter Marko +--- + src/makepath.c | 31 ++++++++++++++--------- + src/userspec.c | 67 +++++++++++++++++++++++++------------------------- + 2 files changed, 53 insertions(+), 45 deletions(-) + +diff --git a/src/makepath.c b/src/makepath.c +index 35dbc73..c6329bf 100644 +--- a/src/makepath.c ++++ b/src/makepath.c +@@ -47,24 +47,19 @@ + Return 0 if ARGPATH exists as a directory with the proper + ownership and permissions when done, otherwise 1. */ + +-int +-make_path (char const *argpath, +- uid_t owner, +- gid_t group, +- const char *verbose_fmt_string) ++static int ++make_path0 (char *dirpath, ++ uid_t owner, ++ gid_t group, ++ const char *verbose_fmt_string) + { +- char *dirpath; /* A copy we can scribble NULs on. */ + struct stat stats; +- int retval = 0; + mode_t tmpmode; + mode_t invert_permissions; + int we_are_root = getuid () == 0; +- dirpath = alloca (strlen (argpath) + 1); +- +- strcpy (dirpath, argpath); + + if (stat (dirpath, &stats)) +- { ++ { + tmpmode = MODE_RWX & ~ newdir_umask; + invert_permissions = we_are_root ? 0 : MODE_WXUSR & ~ tmpmode; + +@@ -157,5 +152,19 @@ make_path (char const *argpath, + + } + ++ return 0; ++} ++ ++int ++make_path (char const *argpath, ++ uid_t owner, ++ gid_t group, ++ const char *verbose_fmt_string) ++{ ++ char *dirpath = xstrdup (argpath); ++ int retval = make_path0 (dirpath, owner, group, verbose_fmt_string); ++ free (dirpath); + return retval; + } ++ ++ +diff --git a/src/userspec.c b/src/userspec.c +index 2a2b324..1a2bfa0 100644 +--- a/src/userspec.c ++++ b/src/userspec.c +@@ -19,7 +19,6 @@ + /* Written by David MacKenzie . */ + + #include +-#include + #include + #include + #include +@@ -33,18 +32,6 @@ + # define endgrent() + #endif + +-/* Perform the equivalent of the statement `dest = strdup (src);', +- but obtaining storage via alloca instead of from the heap. */ +- +-#define V_STRDUP(dest, src) \ +- do \ +- { \ +- int _len = strlen ((src)); \ +- (dest) = (char *) alloca (_len + 1); \ +- strcpy (dest, src); \ +- } \ +- while (0) +- + /* Return nonzero if STR represents an unsigned decimal integer, + otherwise return 0. */ + +@@ -57,6 +44,18 @@ isnumber_p (const char *str) + return 1; + } + ++static void ++store_string (char **bufptr, size_t *buflen, char *str) ++{ ++ size_t len = strlen (str) + 1; ++ if (len > *buflen) ++ { ++ *bufptr = xrealloc (*bufptr, len); ++ *buflen = len; ++ } ++ strcpy (*bufptr, str); ++} ++ + /* Extract from NAME, which has the form "[user][:.][group]", + a USERNAME, UID U, GROUPNAME, and GID G. + Either user or group, or both, must be present. +@@ -70,23 +69,21 @@ isnumber_p (const char *str) + Return NULL if successful, a static error message string if not. */ + + const char * +-parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, +- char **username_arg, char **groupname_arg) ++parse_user_spec0 (char *spec, uid_t *uid, gid_t *gid, ++ char **username_arg, char **groupname_arg) + { + static const char *tired = "virtual memory exhausted"; + const char *error_msg; +- char *spec; /* A copy we can write on. */ + struct passwd *pwd; + struct group *grp; + char *g, *u, *separator; +- char *groupname; ++ char *groupname = NULL; ++ size_t grouplen = 0; + + error_msg = NULL; + *username_arg = *groupname_arg = NULL; + groupname = NULL; + +- V_STRDUP (spec, spec_arg); +- + /* Find the separator if there is one. */ + separator = strchr (spec, ':'); + if (separator == NULL) +@@ -143,11 +140,12 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + if (grp == NULL) + { + char nbuf[UINTMAX_STRSIZE_BOUND]; +- V_STRDUP (groupname, umaxtostr (pwd->pw_gid, nbuf)); ++ store_string (&groupname, &grouplen, ++ umaxtostr (pwd->pw_gid, nbuf)); + } + else + { +- V_STRDUP (groupname, grp->gr_name); ++ store_string (&groupname, &grouplen, grp->gr_name); + } + endgrent (); + } +@@ -178,7 +176,7 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + endgrent (); /* Save a file descriptor. */ + + if (error_msg == NULL) +- V_STRDUP (groupname, g); ++ store_string (&groupname, &grouplen, g); + } + + if (error_msg == NULL) +@@ -191,23 +189,24 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + } + + if (groupname != NULL && error_msg == NULL) +- { +- *groupname_arg = strdup (groupname); +- if (*groupname_arg == NULL) +- { +- if (*username_arg != NULL) +- { +- free (*username_arg); +- *username_arg = NULL; +- } +- error_msg = tired; +- } +- } ++ *groupname_arg = groupname; + } ++ else ++ free (groupname); + + return error_msg; + } + ++const char * ++parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, ++ char **username, char **groupname) ++{ ++ char *spec = xstrdup (spec_arg); ++ const char *retval = parse_user_spec0 (spec, uid, gid, username, groupname); ++ free (spec); ++ return retval; ++} ++ + #ifdef TEST + + #define NULL_CHECK(s) ((s) == NULL ? "(null)" : (s)) From patchwork Mon Aug 24 12:59:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96169 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B60BCC5DF94 for ; Mon, 24 Aug 2026 13:00:55 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15957.1787576451463710869 for ; Mon, 24 Aug 2026 06:00:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ctloGyMO; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso31741295e9.3 for ; Mon, 24 Aug 2026 06:00:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576450; x=1788181250; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=DhixAEf5yQU2VfSddTpF2UUxoGuZTP2p6bjyGGDjNfM=; b=ctloGyMO7U3q6/2Ydw/Xa3SXSq6xiUoBhajQuqZFbpCTokYtyNFC8MIDSf0bnQZVjl J/jZ/sP+cwtsTxOYsM5pKr/98+hMbB04LZZb6RxW2HIttF2/KdoNLDTMXu5JZnv2KTCM nHSD8hwJY9g/oBorMjvvsbp3cZFv1jbnnEOuw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576450; x=1788181250; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=DhixAEf5yQU2VfSddTpF2UUxoGuZTP2p6bjyGGDjNfM=; b=et9HHr86oI5lSBHvs3LJ3Ryl7vbx8Af/vRR5FyQg/9BrJ/e6UaVQ0jsDCUgpnaCEFk uIHWf5ZCuBpqwfoxqdOgR9I6NH6yt8J1wfTtUTpnuMMwcRDHNtsBYNljyCgRHF7STnCY RXi0EJlhF/+gPwplplk5Ea+l/O1n5WzHSJYi8XlCE+uG1FXMgAeCjw1PQIXzOdMeV1Ho pV31QHc5i11hH5w/HDyB4ZectONmS5bM/jcvcxayvUneulD7NQjkYQYgmV8U52dtDiyF D4Ydvtm022pSauOaVsW6F8ZNrFygYhENPbDbMmPhHJS3IwzUSvhPQteX9PHn9ZVlffq2 kxKw== X-Gm-Message-State: AFuF++k9g+eEAQrLV62P2Oh78JdC3wMczhPYPENrHVV2+5dgegEoPrSo bzyPAGYpxbyDAOOIcd1lHC7PJ2gTqFFSJO0HLyz6Fs1zO/zE9KLf+QV5aT1p+bzSKyZqyeyBWU8 tc1uWgOQ= X-Gm-Gg: AR+sD13lP5Yc8f/gOk0QiEXyE8VBTzYTq6YolYRHbm4mkQG5S1jd5lA7RMyaCXxiL60 eG1X/0K8HSc1f0AitScAmbdv7H4qTrK6ERyvqz6UFEYgESCw2NB6v5GXxegTLQ7kF8HCU/M0Rso CAcGZXq5/iOxKcCsrCASZdXnjqbqb+uMxoq+gmIcR0TWIZuUsVElSqkML8kg0FtkA/z9Is7XOTQ D3VLAph9cyBzHOR3hOzvWd+cpb5jLT7vpBTAT/dwLanyTXZUGZa6MCJHI1bSA6KHO2jvs7HnHza yYOGSkuebKx3MFW4zRHOQml1RreNBjJaGz91eKdrnhelYCBMkyzpYMSfLqTMI6xbbV+M7T3hamn yxB+h2O25UO2JfEWY4yhr83uN82faV8KrmIzjZ9k6wBhqMcS5FBFpwmj7d3ZdETyP8lL5Vsqp+o xb1lbIWTZexGQu1jMiy7XGqevWqTptdRwn5lxsEoZFO2b6KRrYAlOClahEmMmRIIFp8wMJTxvRD Sy1i+lK5mh3g8b59NXKGVJ3+9PfiXNjrlGcY0N6mcV/sGr/TL2hXlGaiov6u88yqX6wwSc= X-Received: by 2002:a05:600c:190f:b0:499:873b:471c with SMTP id 5b1f17b1804b1-499b8333889mr306398735e9.6.1787576449495; Mon, 24 Aug 2026 06:00:49 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/19] cpio: patch CVE-2026-66484 Date: Mon, 24 Aug 2026 14:59:56 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244108 From: Peter Marko Pick patch mentioned in NVD CVE description. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: a49025d54fe7723df999710e7a385aaeb42303a2) Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + .../cpio/files/CVE-2026-66484.patch | 28 +++++++++++++++++++ 2 files changed, 29 insertions(+) create mode 100644 meta/recipes-extended/cpio/files/CVE-2026-66484.patch diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index 808a1222102..5ae6dc9ef9f 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -10,6 +10,7 @@ SRC_URI = "${GNU_MIRROR}/cpio/cpio-${PV}.tar.gz \ file://run-ptest \ file://test.sh \ file://CVE-2026-66485.patch \ + file://CVE-2026-66484.patch \ " SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee4183455499e" diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66484.patch b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch new file mode 100644 index 00000000000..97ce9a785cf --- /dev/null +++ b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch @@ -0,0 +1,28 @@ +From e2b9cbdd3354d2b1569b7390d1bc15c1930559ad Mon Sep 17 00:00:00 2001 +From: Sergey Poznyakoff +Date: Thu, 23 Jul 2026 15:55:46 +0300 +Subject: [PATCH] The --no-absolute-filenames option affects hard link targets + too. + +* src/tar.c (stash_tar_linkname): Apply cpio_safer_name_suffix. + +CVE: CVE-2026-66485 +Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad] +Signed-off-by: Peter Marko +--- + src/tar.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/tar.c b/src/tar.c +index 493f299..a1fc60a 100644 +--- a/src/tar.c ++++ b/src/tar.c +@@ -37,6 +37,8 @@ stash_tar_linkname (char *linkname) + + strncpy (hold_tar_linkname, linkname, TARLINKNAMESIZE); + hold_tar_linkname[TARLINKNAMESIZE] = '\0'; ++ cpio_safer_name_suffix (hold_tar_linkname, true, !no_abs_paths_flag, ++ false); + return hold_tar_linkname; + } + From patchwork Mon Aug 24 12:59:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96167 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ABF61C5DF81 for ; Mon, 24 Aug 2026 13:00:55 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15958.1787576454071137566 for ; Mon, 24 Aug 2026 06:00:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Agoakfed; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47c2b362ee2so2601592f8f.1 for ; Mon, 24 Aug 2026 06:00:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576452; x=1788181252; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=1+QoMQY8dS2Guu7esTW3ac55ogiGCgfDkOZK/uRzmtI=; b=AgoakfedQRmcNZnnoAqP9701k6vgodRVK7O/LSMa9PB8bZ/AFnKMRGyx7gqUI2qw4T pk1B0w7E+YnwNj5bE5cXdDVA/JiGFgv62oleLpU2bUTT0w76MD9eOETP1YBBJ8Ryh/gb N5IzCS9za5l/2wWtjRV8XOWWHNUH7NHywPF40= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576452; x=1788181252; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=1+QoMQY8dS2Guu7esTW3ac55ogiGCgfDkOZK/uRzmtI=; b=WPcV1q+hG0eGiUCLzw1vITOS6ZZcKAerOSDCwanwtKBCAozOqsZQ1bYFXYBHYteAX7 47GhTahg5w9DiaPoSZX3SvHvzYqq98bKUuAo9b7xEf/WpFZAh1jBvg9QvETvPeuWDs3f 57rX0Jcjdqw7DwvlcZy0QcQJTRx3/jZY5TxsHFm6djDML56r8IIA6dudi7Kn+elh/rRc G0WHvmCzbR/kbDkPoo0jnb97lAeFD+hQxFVnEzdfXv3KI7357g+OszurYAmrPIO0mmWs gPHs+os8q4nNY2RQV46RKFhO1qbe8M6bJ02TGp+m/S/XFg9BTvOU0dKkjNKUi5EACVY1 515w== X-Gm-Message-State: AFuF++mO+wLnjqNjLrLWpYwu0+5vkcUrqpNsLVjBDyxhfXyUMcDO+PXp MCaEPA1eihI04DnrR1dUNRDa3Yb2dmA8ZRfou1fnAKHDUTu+JM+K2kaW4SsDRLz9XI7iCU4eL+c gG7RidsY= X-Gm-Gg: AR+sD12YOrQw/qPG2rNMdPUZySJLZ3RWmUW4fUsdlQ1y/g1WKqPmxTJ/SJU7rNO6+M4 xyQRprVTVCOVaPWV38jHChsVwq0WO99dvhbv4VKJjlhzwS7s4H++3cdjcsIeiIzD8+pw1v9butp aa8gZsnSeQqHyzNa8F4jiYodGmpG4JhTnBaP50qNywU0yCPHqQ1tpjlxXoUTT54ihQvCqpS3LMS axDsIJ5uoGTPZ2rxjToq1a+EVjy9vF28LVgZKfv8t7Sj++eFOMRFM6iBsjZHXLyYdATf6J6OwQx 7oypMmd9SpcLOvv3FwKUjpP6zR1KLlkdFUthGLP7wVsRF3c67H3nj9TapFMQghYzCigzcZWFyma Y0Sgwi9Xl4lu+LgvQvK+nIJC5qdRy+znKq9LbszNCEcZAOY0SyKQIMK6pI2jZZbuh9sX5HveHTp Virkx/2xEKVZmMrGo8b2snOFd64xTxEfK4eHF4xnYGm7W5XsGQ2wCKnb/7sP/ybtXJFooglg/Eu +561waLY0EjrANgBd8nCi+zmUfnZfmhHZlsj7MjceVbMDxtpfqetGUC3LdHvdXhiSJO0zI= X-Received: by 2002:a05:600c:4f12:b0:499:af7d:b759 with SMTP id 5b1f17b1804b1-499c19cc660mr242746075e9.13.1787576450581; Mon, 24 Aug 2026 06:00:50 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/19] cpio: patch CVE-2026-66486 Date: Mon, 24 Aug 2026 14:59:57 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244109 From: Peter Marko Pick patch mentioned in NVD CVE description. Resolve trivial conflicts. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: e70183674aacaef32e4fd34277ce2482a89a44a7) Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + .../cpio/files/CVE-2026-66486.patch | 497 ++++++++++++++++++ 2 files changed, 498 insertions(+) create mode 100644 meta/recipes-extended/cpio/files/CVE-2026-66486.patch diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index 5ae6dc9ef9f..09fe123a30c 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -11,6 +11,7 @@ SRC_URI = "${GNU_MIRROR}/cpio/cpio-${PV}.tar.gz \ file://test.sh \ file://CVE-2026-66485.patch \ file://CVE-2026-66484.patch \ + file://CVE-2026-66486.patch \ " SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee4183455499e" diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66486.patch b/meta/recipes-extended/cpio/files/CVE-2026-66486.patch new file mode 100644 index 00000000000..93199a337ef --- /dev/null +++ b/meta/recipes-extended/cpio/files/CVE-2026-66486.patch @@ -0,0 +1,497 @@ +From 2ff9600c9ef32e88759843cdbde74c8db5ae9b30 Mon Sep 17 00:00:00 2001 +From: Sergey Poznyakoff +Date: Thu, 23 Jul 2026 17:26:05 +0300 +Subject: [PATCH] Quote file names in error messages and in listings. + +* NEWS: Document changes. +* doc/cpio.texi: Likewise. +* src/copyin.c: Quote file and member names. +* src/copyout.c: Likewise. +* src/copypass.c: Likewise. +* src/main.c: New options: --quoting-style and --quote-chars. +(process_args): Set default quoting style. +* tests/CVE-2019-14866.at: Fix expected output. + +CVE: CVE-2026-66485 +Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=2ff9600c9ef32e88759843cdbde74c8db5ae9b30] +Signed-off-by: Peter Marko +--- + NEWS | 16 ++++++++++++- + doc/cpio.texi | 13 ++++++++++ + src/copyin.c | 39 +++++++++++++++++------------- + src/copyout.c | 26 ++++++++++---------- + src/copypass.c | 11 +++++---- + src/main.c | 53 +++++++++++++++++++++++++++++++++++++++-- + tests/CVE-2019-14866.at | 2 +- + 7 files changed, 123 insertions(+), 37 deletions(-) + +diff --git a/NEWS b/NEWS +index d036665..24d85b5 100644 +--- a/NEWS ++++ b/NEWS +@@ -1,8 +1,22 @@ +-GNU cpio NEWS -- history of user-visible changes. 2024-01-14 ++GNU cpio NEWS -- history of user-visible changes. 2026-07-23 + Copyright (C) 2003-2024 Free Software Foundation, Inc. + See the end of file for copying conditions. + + Please send cpio bug reports to . ++ ++Version 2.15.? (git) ++ ++* New options ++ ++ --quoting-style=STYLE ++ Set name quoting style used when printing file names. Valid styles ++ are: c, c-maybe, clocale, escape, help (displays available styles ++ and exits), literal (default), locale, shell, shell-always, ++ shell-escape, and shell-escape-always. ++ ++ --quote-chars=STRING ++ Additionally quote characters from STRING when printing file names. ++ + + Version 2.15 - Sergey Poznyakoff, 2024-01-14 + +diff --git a/doc/cpio.texi b/doc/cpio.texi +index 8d596fb..dc69a4d 100644 +--- a/doc/cpio.texi ++++ b/doc/cpio.texi +@@ -814,6 +814,19 @@ Run in copy-pass mode. + [@ref{copy-in},@ref{copy-out},@ref{copy-pass}] + @*Do not print the number of blocks copied. + ++@item --quote-chars=@var{string} ++Always quote characters from @var{string}, even if the selected ++quoting style would not quote them (@pxref{quoting styles,,,tar,GNU ++tar}). ++ ++@item --quoting-style=@var{style} ++Set quoting style to use when printing member and file names ++(@pxref{quoting styles,,,tar,GNU tar}). Valid @var{style} values are: ++@code{literal}, @code{shell}, @code{shell-always}, @code{c}, ++@code{escape}, @code{locale}, and @code{clocale}. Default quoting ++style is @code{literal}, unless overridden while configuring the ++package. ++ + @item -r + @itemx --rename + [@ref{copy-in}] +diff --git a/src/copyin.c b/src/copyin.c +index 59ce98b..2afc9d4 100644 +--- a/src/copyin.c ++++ b/src/copyin.c +@@ -114,7 +114,7 @@ get_link_name (struct cpio_file_stat *file_hdr, int in_file_des) + if (file_hdr->c_filesize < 0 || file_hdr->c_filesize > SIZE_MAX-1) + { + error (0, 0, _("%s: stored filename length is out of range"), +- file_hdr->c_name); ++ quote (file_hdr->c_name)); + link_name = NULL; + } + else +@@ -150,7 +150,11 @@ list_file (struct cpio_file_stat* file_hdr, int in_file_des) + } + else + #endif +- long_format (file_hdr, (char *) 0); ++ long_format (file_hdr, NULL); ++ } ++ else if (name_end == '\n' && isatty (fileno (stdout))) ++ { ++ printf ("%s%c", quotearg (file_hdr->c_name), name_end); + } + else + { +@@ -173,7 +177,7 @@ list_file (struct cpio_file_stat* file_hdr, int in_file_des) + if (crc != file_hdr->c_chksum) + { + error (0, 0, _("%s: checksum error (0x%x, should be 0x%x)"), +- file_hdr->c_name, crc, file_hdr->c_chksum); ++ quote (file_hdr->c_name), crc, file_hdr->c_chksum); + } + } + } +@@ -200,7 +204,7 @@ try_existing_file (struct cpio_file_stat* file_hdr, int in_file_des, + && file_hdr->c_mtime <= file_stat.st_mtime) + { + error (0, 0, _("%s not created: newer or same age version exists"), +- file_hdr->c_name); ++ quote (file_hdr->c_name)); + tape_toss_input (in_file_des, file_hdr->c_filesize); + tape_skip_padding (in_file_des, file_hdr->c_filesize); + return -1; /* Go to the next file. */ +@@ -210,7 +214,7 @@ try_existing_file (struct cpio_file_stat* file_hdr, int in_file_des, + : unlink (file_hdr->c_name)) + { + error (0, errno, _("cannot remove current %s"), +- file_hdr->c_name); ++ quote (file_hdr->c_name)); + tape_toss_input (in_file_des, file_hdr->c_filesize); + tape_skip_padding (in_file_des, file_hdr->c_filesize); + return -1; /* Go to the next file. */ +@@ -271,7 +275,8 @@ create_defered_links (struct cpio_file_stat *file_hdr) + if (link_res < 0) + { + error (0, errno, _("cannot link %s to %s"), +- d->header.c_name, file_hdr->c_name); ++ quote_n (0, d->header.c_name), ++ quote_n (1, file_hdr->c_name)); + } + if (d_prev != NULL) + d_prev->next = d->next; +@@ -467,7 +472,8 @@ copyin_regular_file (struct cpio_file_stat* file_hdr, int in_file_des) + if (link_res < 0) + { + error (0, errno, _("cannot link %s to %s"), +- file_hdr->c_tar_linkname, file_hdr->c_name); ++ quote_n (0, file_hdr->c_tar_linkname), ++ quote_n (1, file_hdr->c_name)); + } + return; + } +@@ -500,7 +506,7 @@ copyin_regular_file (struct cpio_file_stat* file_hdr, int in_file_des) + swapping_halfwords = true; + else + error (0, 0, _("cannot swap halfwords of %s: odd number of halfwords"), +- file_hdr->c_name); ++ quote (file_hdr->c_name)); + } + if (swap_bytes_flag) + { +@@ -508,7 +514,7 @@ copyin_regular_file (struct cpio_file_stat* file_hdr, int in_file_des) + swapping_bytes = true; + else + error (0, 0, _("cannot swap bytes of %s: odd number of bytes"), +- file_hdr->c_name); ++ quote (file_hdr->c_name)); + } + copy_files_tape_to_disk (in_file_des, out_file_des, file_hdr->c_filesize); + disk_empty_output_buffer (out_file_des, true); +@@ -519,7 +525,7 @@ copyin_regular_file (struct cpio_file_stat* file_hdr, int in_file_des) + { + if (crc != file_hdr->c_chksum) + error (0, 0, _("%s: checksum error (0x%x, should be 0x%x)"), +- file_hdr->c_name, crc, file_hdr->c_chksum); ++ quote (file_hdr->c_name), crc, file_hdr->c_chksum); + } + tape_skip_padding (in_file_des, file_hdr->c_filesize); + return; +@@ -534,7 +540,7 @@ copyin_regular_file (struct cpio_file_stat* file_hdr, int in_file_des) + { + if (crc != file_hdr->c_chksum) + error (0, 0, _("%s: checksum error (0x%x, should be 0x%x)"), +- file_hdr->c_name, crc, file_hdr->c_chksum); ++ quote (file_hdr->c_name), crc, file_hdr->c_chksum); + } + + tape_skip_padding (in_file_des, file_hdr->c_filesize); +@@ -582,7 +588,8 @@ copyin_device (struct cpio_file_stat* file_hdr) + if (link_res < 0) + { + error (0, errno, _("cannot link %s to %s"), +- file_hdr->c_tar_linkname, file_hdr->c_name); ++ quote_n (0, file_hdr->c_tar_linkname), ++ quote_n (1, file_hdr->c_name)); + /* Something must be wrong, because we couldn't + find the file to link to. But can we assume + that the device maj/min numbers are correct +@@ -855,7 +862,7 @@ copyin_file (struct cpio_file_stat *file_hdr, int in_file_des) + #endif + + default: +- error (0, 0, _("%s: unknown file type"), file_hdr->c_name); ++ error (0, 0, _("%s: unknown file type"), quote (file_hdr->c_name)); + tape_toss_input (in_file_des, file_hdr->c_filesize); + tape_skip_padding (in_file_des, file_hdr->c_filesize); + } +@@ -1550,13 +1557,13 @@ process_copy_in (void) + if (crc != file_hdr.c_chksum) + { + error (0, 0, _("%s: checksum error (0x%x, should be 0x%x)"), +- file_hdr.c_name, crc, file_hdr.c_chksum); ++ quote (file_hdr.c_name), crc, file_hdr.c_chksum); + } + /* Debian hack: -v and -V now work with --only-verify-crc. + (99/11/10) -BEM */ + if (verbose_flag) + { +- fprintf (stderr, "%s\n", file_hdr.c_name); ++ fprintf (stderr, "%s\n", quotearg (file_hdr.c_name)); + } + if (dot_flag) + { +@@ -1581,7 +1588,7 @@ process_copy_in (void) + copyin_file(&file_hdr, in_file_des); + + if (verbose_flag) +- fprintf (stderr, "%s\n", file_hdr.c_name); ++ fprintf (stderr, "%s\n", quotearg (file_hdr.c_name)); + if (dot_flag) + fputc ('.', stderr); + } +diff --git a/src/copyout.c b/src/copyout.c +index fd88080..b9fb676 100644 +--- a/src/copyout.c ++++ b/src/copyout.c +@@ -46,7 +46,8 @@ read_for_checksum (int in_file_des, off_t file_size, char *file_name) + { + bytes_read = read (in_file_des, buf, BUFSIZ); + if (bytes_read < 0) +- error (PAXEXIT_FAILURE, errno, _("cannot read checksum for %s"), file_name); ++ error (PAXEXIT_FAILURE, errno, _("cannot read checksum for %s"), ++ quote (file_name)); + if (bytes_read == 0) + break; + for (i = 0; i < bytes_read; i++) +@@ -54,7 +55,8 @@ read_for_checksum (int in_file_des, off_t file_size, char *file_name) + file_size -= bytes_read; + } + if (lseek (in_file_des, 0L, SEEK_SET)) +- error (PAXEXIT_FAILURE, errno, _("cannot read checksum for %s"), file_name); ++ error (PAXEXIT_FAILURE, errno, _("cannot read checksum for %s"), ++ quote (file_name)); + + return crc; + } +@@ -288,7 +290,7 @@ field_width_error (const char *filename, const char *fieldname, + char valbuf[UINTMAX_STRSIZE_BOUND + 1]; + char maxbuf[UINTMAX_STRSIZE_BOUND + 1]; + error (0, 0, _("%s: value %s %s out of allowed range 0..%s"), +- filename, fieldname, ++ quote (filename), fieldname, + STRINGIFY_BIGINT (value, valbuf), + STRINGIFY_BIGINT (MAX_VAL_WITH_DIGITS (width - nul, LG_8), + maxbuf)); +@@ -298,7 +300,7 @@ static void + field_width_warning (const char *filename, const char *fieldname) + { + if (warn_option & CPIO_WARN_TRUNCATE) +- error (0, 0, _("%s: truncating %s"), filename, fieldname); ++ error (0, 0, _("%s: truncating %s"), quote (filename), fieldname); + } + + void +@@ -466,7 +468,7 @@ write_out_binary_header (dev_t rdev, + short_hdr.c_dev = makedev (file_hdr->c_dev_maj, file_hdr->c_dev_min); + + if ((warn_option & CPIO_WARN_TRUNCATE) && (file_hdr->c_ino >> 16) != 0) +- error (0, 0, _("%s: truncating inode number"), file_hdr->c_name); ++ error (0, 0, _("%s: truncating inode number"), quote (file_hdr->c_name)); + + short_hdr.c_ino = file_hdr->c_ino & 0xFFFF; + if (short_hdr.c_ino != file_hdr->c_ino) +@@ -497,7 +499,7 @@ write_out_binary_header (dev_t rdev, + { + char maxbuf[UINTMAX_STRSIZE_BOUND + 1]; + error (0, 0, _("%s: value %s %s out of allowed range 0..%u"), +- file_hdr->c_name, _("name size"), ++ quote (file_hdr->c_name), _("name size"), + STRINGIFY_BIGINT (file_hdr->c_namesize, maxbuf), 0xFFFFu); + return 1; + } +@@ -510,7 +512,7 @@ write_out_binary_header (dev_t rdev, + { + char maxbuf[UINTMAX_STRSIZE_BOUND + 1]; + error (0, 0, _("%s: value %s %s out of allowed range 0..%lu"), +- file_hdr->c_name, _("file size"), ++ quote (file_hdr->c_name), _("file size"), + STRINGIFY_BIGINT (file_hdr->c_namesize, maxbuf), 0xFFFFFFFFlu); + return 1; + } +@@ -558,7 +560,7 @@ write_out_header (struct cpio_file_stat *file_hdr, int out_des) + case arf_ustar: + if (is_tar_filename_too_long (file_hdr->c_name)) + { +- error (0, 0, _("%s: file name too long"), file_hdr->c_name); ++ error (0, 0, _("%s: file name too long"), quote (file_hdr->c_name)); + return 1; + } + return write_out_tar_header (file_hdr, out_des); +@@ -749,7 +751,7 @@ process_copy_out (void) + if (archive_format == arf_tar) + { + error (0, 0, _("%s not dumped: not a regular file"), +- orig_file_name); ++ quote (orig_file_name)); + continue; + } + else if (archive_format == arf_ustar) +@@ -800,7 +802,7 @@ process_copy_out (void) + if (link_size + 1 > 100) + { + error (0, 0, _("%s: symbolic link too long"), +- file_hdr.c_name); ++ quote (file_hdr.c_name)); + } + else + { +@@ -823,11 +825,11 @@ process_copy_out (void) + #endif + + default: +- error (0, 0, _("%s: unknown file type"), orig_file_name); ++ error (0, 0, _("%s: unknown file type"), quote (orig_file_name)); + } + + if (verbose_flag) +- fprintf (stderr, "%s\n", orig_file_name); ++ fprintf (stderr, "%s\n", quote (orig_file_name)); + if (dot_flag) + fputc ('.', stderr); + } +diff --git a/src/copypass.c b/src/copypass.c +index 7d7e970..928990f 100644 +--- a/src/copypass.c ++++ b/src/copypass.c +@@ -127,7 +127,7 @@ process_copy_pass (void) + && in_file_stat.st_mtime <= out_file_stat.st_mtime) + { + error (0, 0, _("%s not created: newer or same age version exists"), +- output_name.ds_string); ++ quote (output_name.ds_string)); + continue; /* Go to the next file. */ + } + else if (S_ISDIR (out_file_stat.st_mode) +@@ -135,7 +135,7 @@ process_copy_pass (void) + : unlink (output_name.ds_string)) + { + error (0, errno, _("cannot remove current %s"), +- output_name.ds_string); ++ quote (output_name.ds_string)); + continue; /* Go to the next file. */ + } + } +@@ -312,7 +312,8 @@ process_copy_pass (void) + #endif + else + { +- error (0, 0, _("%s: unknown file type"), input_name.ds_string); ++ error (0, 0, _("%s: unknown file type"), ++ quote (input_name.ds_string)); + } + + if (verbose_flag) +@@ -388,12 +389,12 @@ link_to_name (char const *link_name, char const *link_target) + { + if (verbose_flag) + error (0, 0, _("%s linked to %s"), +- link_target, link_name); ++ quote_n (0, link_target), quote_n (1, link_name)); + } + else if (link_flag) + { + error (0, errno, _("cannot link %s to %s"), +- link_target, link_name); ++ quote_n (0, link_target), quote_n (1, link_name)); + } + return res; + } +diff --git a/src/main.c b/src/main.c +index 978dfff..dcd40b8 100644 +--- a/src/main.c ++++ b/src/main.c +@@ -61,7 +61,9 @@ enum cpio_options { + RENUMBER_INODES_OPTION, + IGNORE_DEVNO_OPTION, + IGNORE_DIRNLINK_OPTION, +- DEVICE_INDEPENDENT_OPTION ++ DEVICE_INDEPENDENT_OPTION, ++ QUOTING_STYLE_OPTION, ++ QUOTE_CHARS_OPTION + }; + + const char *program_authors[] = +@@ -141,6 +143,12 @@ static struct argp_option options[] = { + N_("Control warning display. Currently FLAG is one of 'none', 'truncate', 'all'. Multiple options accumulate."), GRID+1 }, + {"owner", 'R', N_("[USER][:.][GROUP]"), 0, + N_("Set the ownership of all files created to the specified USER and/or GROUP"), GRID+1 }, ++ {"quoting-style", QUOTING_STYLE_OPTION, N_("STYLE"), 0, ++ N_("set name quoting style; use --quoting-style=help for a list of valid STYLE values"), ++ GRID+1 }, ++ {"quote-chars", QUOTE_CHARS_OPTION, N_("STRING"), 0, ++ N_("additionally quote characters from STRING"), ++ GRID+1 }, + #undef GRID + + #define GRID 110 +@@ -295,6 +303,36 @@ warn_control (char *arg) + return 1; + } + ++static void ++cpio_list_quoting_styles (int indent) ++{ ++ int i; ++ ++ for (i = 0; quoting_style_args[i]; i++) ++ printf ("%*.*s%s\n", indent, indent, "", quoting_style_args[i]); ++} ++ ++static void ++cpio_set_quoting_style (char *arg) ++{ ++ if (strcmp (arg, "help") == 0) ++ { ++ cpio_list_quoting_styles (0); ++ exit (EXIT_SUCCESS); ++ } ++ ++ for (idx_t i = 0; quoting_style_args[i]; i++) ++ if (strcmp (arg, quoting_style_args[i]) == 0) ++ { ++ set_quoting_style (NULL, i); ++ return; ++ } ++ USAGE_ERROR ((0, 0, ++ _("Unknown quoting style '%s'." ++ " Try '%s --quoting-style=help' to get a list."), ++ arg, program_name)); ++} ++ + static error_t + parse_opt (int key, char *arg, struct argp_state *state) + { +@@ -454,10 +492,19 @@ crc newc odc bin ustar tar (all-caps also recognized)"), arg)); + copy_function = process_copy_pass; + break; + ++ case QUOTE_CHARS_OPTION: ++ for (;*arg; arg++) ++ set_char_quoting (NULL, *arg, 1); ++ break; ++ ++ case QUOTING_STYLE_OPTION: ++ cpio_set_quoting_style (arg); ++ break; ++ + case IGNORE_DEVNO_OPTION: + ignore_devno_option = 1; + break; +- ++ + case RENUMBER_INODES_OPTION: + renumber_inodes_option = 1; + break; +@@ -593,6 +640,8 @@ process_args (int argc, char *argv[]) + + xstat = lstat; + ++ set_quoting_style (NULL, DEFAULT_QUOTING_STYLE); ++ + if (argp_parse (&argp, argc, argv, ARGP_IN_ORDER, &index, NULL)) + exit (PAXEXIT_FAILURE); + +diff --git a/tests/CVE-2019-14866.at b/tests/CVE-2019-14866.at +index 2bfdabc..bdf6a04 100644 +--- a/tests/CVE-2019-14866.at ++++ b/tests/CVE-2019-14866.at +@@ -29,7 +29,7 @@ fi + ], + [0], + [], +-[cpio: file: value size 17179869184 out of allowed range 0..8589934591 ++[cpio: 'file': value size 17179869184 out of allowed range 0..8589934591 + 2 blocks + ]) + AT_CLEANUP From patchwork Mon Aug 24 12:59:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96175 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 45991C61CE3 for ; Mon, 24 Aug 2026 13:01:06 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15968.1787576463311596808 for ; Mon, 24 Aug 2026 06:01:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Puil44Oa; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4995b0343c1so25117735e9.3 for ; Mon, 24 Aug 2026 06:01:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576461; x=1788181261; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jP2qecUDlO0Iot3X34adVv3eBw+Jb0C82RqwdUmmxtA=; b=Puil44Oa+lgoFAXleNMNistexxHYtZefUFCz6FONQLy/zovV2CtimZK3ntdCoyX+pI tjjkc4ud7vBTQouTzNJzY7JC+6KF43oHb7vOSqAbYgO3B33KegmmexVYTlAX7S8044qf azNh9K0XoYBVcHpyG3uOLGJ+rUtYZXyV1d7Zc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576461; x=1788181261; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jP2qecUDlO0Iot3X34adVv3eBw+Jb0C82RqwdUmmxtA=; b=P3BamkxHx6glCEQSEdcS/XUlpoCt0+k9EKVURgQLEWfxpZvOe6T1EU6sGPaGB3pq2V TC0ziCuzgxP4BTMKlaIo6JnnH844WQuir1iBng5ziYKeXGhd/1YLKwzQu7+TdhwoWGEf AtIsM+0rosn3MaWoBs6ZS1Ju1QoYgZI0uEqrxoJo3eLmbUquvinYA61ze1zpWzcIqATW kRnlEMCzcgGKfIxLsEVVCM0DKVrVwl5jZUjXWfxfsf4BpqXeRaXevWknGAd9dWZmdb+V WZ3bpiATdDsyH235mQY8PjnU/hRT6vAhaZeHNTQgmylxRUjkAWp8L7pus/RL5dqlznRU +rKg== X-Gm-Message-State: AFuF++mCQrHY/LyZFsMLbmAVbisV0vUX/1FlJzILb2CIw6oy9RxvRnVr Zc11OzuKVfYEoFwmfm9wX6J8ruvRekLZKdpd2BhQEDFrTfVXKfxlqgOmVwVRJRmLy7yVNxGW5NS IrJmJCTg= X-Gm-Gg: AR+sD13mHqPkxdtOlrz3lmx1uomS5QiiBuoczDm7Egju/LrICE/dtHb0pvWuuBRv3ab 8TvKWh6ISoqWm5iiEoDvit+Tz3g0Xwcufd8cVXPK7p8SA0Ws3kE+uM46KMSmofUOwu2g08wHViv TwiwWX5L0ZpEq3EDCpOJIyVwPl6bieBfQOmvE8jf5WCfx/fEHwhMKDs1cjz4Hey0uGzF8NiI+UB mhFB/znyHsC798EaYVhAh/LBg25rj+Kp3D5qT97dXIFnpzbfK6bJ1tP4PK8BJb98xTwZIPSzs9p TZgsqNIlS+iQh47eOshV8vvmbw7iDO90JhMRd/fywZSjm+EbUm+BWabjjwrwFZaCts23dsAj/Zb YEdjynGd4FxLtwZtocILGN93YB2CjKeaTccDEhZYFSfF8mezYXWHSij/JAmTNctWxz5mdOGIQJ+ nakCmX7t3V0BeYXEmT4l9RTr7HNR9DUZhsYBVHt/rykhlxDUbDaE2wWR92WbVIA95l4y3ULOoHI RJzXMu2E50Tvh1pJ3PQx/b6K3iK+uJDDcshRlDSjmDktAr4O59EPqix63/AU9RbI//as10= X-Received: by 2002:a05:600c:5247:b0:499:8b00:5261 with SMTP id 5b1f17b1804b1-499c19a90a3mr175510805e9.8.1787576452562; Mon, 24 Aug 2026 06:00:52 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/19] rpcbind: upgrade 1.2.8 -> 1.2.9 Date: Mon, 24 Aug 2026 14:59:58 +0200 Message-ID: <26cc79f9371470f5110aa1ce266e98890555d274.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244115 From: Richard Purdie Includes fix for CVE-2026-16277 [1] https://nvd.nist.gov/vuln/detail/CVE-2026-16277 [2] https://security-tracker.debian.org/tracker/CVE-2026-16277 Signed-off-by: Richard Purdie (cherry picked from commit 00f9ac421f1a3c66d2d53b9bffb9a31111239198) Signed-off-by: Vijay Anusuri Signed-off-by: Fabien Thomas --- .../0001-systemd-use-EnvironmentFile.patch | 7 ++---- ...pcbind_add_option_to_fix_port_number.patch | 25 ++++++++----------- .../{rpcbind_1.2.8.bb => rpcbind_1.2.9.bb} | 2 +- 3 files changed, 14 insertions(+), 20 deletions(-) rename meta/recipes-extended/rpcbind/{rpcbind_1.2.8.bb => rpcbind_1.2.9.bb} (96%) diff --git a/meta/recipes-extended/rpcbind/rpcbind/0001-systemd-use-EnvironmentFile.patch b/meta/recipes-extended/rpcbind/rpcbind/0001-systemd-use-EnvironmentFile.patch index 28d83e74f51..621cc343225 100644 --- a/meta/recipes-extended/rpcbind/rpcbind/0001-systemd-use-EnvironmentFile.patch +++ b/meta/recipes-extended/rpcbind/rpcbind/0001-systemd-use-EnvironmentFile.patch @@ -1,4 +1,4 @@ -From 87a9931e4aa97d7b6eb3b25f26444e30e45e3e41 Mon Sep 17 00:00:00 2001 +From 43908891b9344054e23a7d9f4d6fc5b34b2406cf Mon Sep 17 00:00:00 2001 From: Stefan Agner Date: Wed, 27 Aug 2025 11:30:48 +0800 Subject: [PATCH] systemd: use EnvironmentFile @@ -14,7 +14,7 @@ Signed-off-by: Hongxu Jia 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/configure.ac b/configure.ac -index 6ede0af..d1ae5e4 100644 +index c46294c..1566386 100644 --- a/configure.ac +++ b/configure.ac @@ -86,5 +86,7 @@ AC_CHECK_HEADERS([nss.h]) @@ -42,6 +42,3 @@ index 771b944..5992098 100644 ExecStart=@_sbindir@/rpcbind $RPCBIND_OPTIONS @warmstarts_opt@ -f [Install] --- -2.34.1 - diff --git a/meta/recipes-extended/rpcbind/rpcbind/rpcbind_add_option_to_fix_port_number.patch b/meta/recipes-extended/rpcbind/rpcbind/rpcbind_add_option_to_fix_port_number.patch index 3205ff30861..f0a4df04e49 100644 --- a/meta/recipes-extended/rpcbind/rpcbind/rpcbind_add_option_to_fix_port_number.patch +++ b/meta/recipes-extended/rpcbind/rpcbind/rpcbind_add_option_to_fix_port_number.patch @@ -1,4 +1,4 @@ -From 285c193dc94b53763ac8d6f91229eaab37d45fc6 Mon Sep 17 00:00:00 2001 +From fc77df5fed834dd1cffc8c58adb4a13a9b97f5cf Mon Sep 17 00:00:00 2001 From: Roy Li Date: Wed, 27 Aug 2025 11:24:53 +0800 Subject: [PATCH] add option to make users able to use fixed port number @@ -38,18 +38,18 @@ index 15b70f9..4a6ffbc 100644 .Fl h option is specified, diff --git a/src/rpcb_svc_com.c b/src/rpcb_svc_com.c -index 1743dad..07a1c75 100644 +index 6d0d72d..2f10dac 100644 --- a/src/rpcb_svc_com.c +++ b/src/rpcb_svc_com.c -@@ -48,6 +48,7 @@ - #include +@@ -49,6 +49,7 @@ + #include #include #include +#include #include #include #include -@@ -497,6 +498,7 @@ xdr_opaque_parms(XDR *xdrs, struct r_rmtcall_args *cap) +@@ -499,6 +500,7 @@ xdr_opaque_parms(XDR *xdrs, struct r_rmtcall_args *cap) static struct rmtcallfd_list *rmthead; static struct rmtcallfd_list *rmttail; @@ -57,7 +57,7 @@ index 1743dad..07a1c75 100644 int create_rmtcall_fd(struct netconfig *nconf) -@@ -504,6 +506,8 @@ create_rmtcall_fd(struct netconfig *nconf) +@@ -506,6 +508,8 @@ create_rmtcall_fd(struct netconfig *nconf) int fd; struct rmtcallfd_list *rmt; SVCXPRT *xprt; @@ -66,7 +66,7 @@ index 1743dad..07a1c75 100644 if ((fd = __rpc_nconf2fd(nconf)) == -1) { if (debugging) -@@ -512,6 +516,19 @@ create_rmtcall_fd(struct netconfig *nconf) +@@ -514,6 +518,19 @@ create_rmtcall_fd(struct netconfig *nconf) nconf->nc_device, errno); return (-1); } @@ -87,7 +87,7 @@ index 1743dad..07a1c75 100644 if (xprt == NULL) { if (debugging) diff --git a/src/rpcbind.c b/src/rpcbind.c -index bf7b499..7268907 100644 +index 4212377..7e7f79d 100644 --- a/src/rpcbind.c +++ b/src/rpcbind.c @@ -112,6 +112,7 @@ int runasdaemon = 0; @@ -98,7 +98,7 @@ index bf7b499..7268907 100644 char **hosts = NULL; int nhosts = 0; -@@ -959,7 +960,7 @@ parseargs(int argc, char *argv[]) +@@ -963,7 +964,7 @@ parseargs(int argc, char *argv[]) { int c; oldstyle_local = 1; @@ -107,7 +107,7 @@ index bf7b499..7268907 100644 switch (c) { case 'a': doabort = 1; /* when debugging, do an abort on */ -@@ -977,6 +978,9 @@ parseargs(int argc, char *argv[]) +@@ -981,6 +982,9 @@ parseargs(int argc, char *argv[]) if (hosts[nhosts - 1] == NULL) errx(1, "Out of memory"); break; @@ -117,7 +117,7 @@ index bf7b499..7268907 100644 case 'i': insecure = 1; break; -@@ -999,7 +1003,7 @@ parseargs(int argc, char *argv[]) +@@ -1003,7 +1007,7 @@ parseargs(int argc, char *argv[]) break; #endif default: /* error */ @@ -126,6 +126,3 @@ index bf7b499..7268907 100644 exit (1); } } --- -2.34.1 - diff --git a/meta/recipes-extended/rpcbind/rpcbind_1.2.8.bb b/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb similarity index 96% rename from meta/recipes-extended/rpcbind/rpcbind_1.2.8.bb rename to meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb index bd8ba1e88af..692c421cd9a 100644 --- a/meta/recipes-extended/rpcbind/rpcbind_1.2.8.bb +++ b/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb @@ -18,7 +18,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/rpcbind/rpcbind-${PV}.tar.bz2 \ file://rpcbind_add_option_to_fix_port_number.patch \ file://0001-systemd-use-EnvironmentFile.patch \ " -SRC_URI[sha256sum] = "964132c389918e8964d7334936b6dd10ef025b300c6b29e693ba0f29550e3de5" +SRC_URI[sha256sum] = "ce5f1a87c566ef0b2897a28f50a75c1dc23fec413a46a7f4183423b6b6aa991b" inherit autotools update-rc.d systemd pkgconfig update-alternatives sourceforge-releases From patchwork Mon Aug 24 12:59:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96173 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4B27BC61DBD for ; Mon, 24 Aug 2026 13:00:56 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.16159.1787576455397250929 for ; Mon, 24 Aug 2026 06:00:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tbb9cKPX; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-499b57cf2f3so19065405e9.0 for ; Mon, 24 Aug 2026 06:00:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576454; x=1788181254; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Nq4TaHQ1E2/X5v6YRvZUqadvrmZEfBok6U4XiBV4CwQ=; b=tbb9cKPXjShUvldOdkvv7BRUSAjX8VmS02K0d+2NJYalaMNoAs4fPMgrHQKb3Rrf+v FCRw3kaBy10q28gRnuV2OqFLrD19V3Rp16mCzIzzakX8SUKlGaGNNpqGNkLyidMj93WV SBTtzPp5FEPYsurPUiA1Kvnv84ONZEVhyXVxA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576454; x=1788181254; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Nq4TaHQ1E2/X5v6YRvZUqadvrmZEfBok6U4XiBV4CwQ=; b=A7NiFa3N9KLzc+auo0kPypA24TlNO7cS1cD83yacplnygemEpoOZpCSGvhYqiy478L NMLqVChobJKj2HiIESvi0zoy51paQAFnf1AybNWYqHlMbhyTLluDPej7cowltIDrzOW5 66iVKdhAPKciDWxt0kyeiiszAuFGYxhxKE4BKukug+NuIHnJhM8Ga/UupbL9n947yOPc FsxdSyNxi/i/5R078tVBe1MKY4IG5h42uWVe5gjIJsW46m4+wggQsbOo4dOW46YgK3sK CA4xZFOTRfx2NiMI9UD8b5vidJ/ByH2VVgt4lBHSk3PAYtC9nfLJuT/oRHJry1bnLFbf 801g== X-Gm-Message-State: AFuF++kDfMqNMLoAniV6D8zKe/EswyeyoMLECKj6xapJxemdA6Gji3IZ VaMuihYiRkprR/zOIamiB6aMl/iPTAbUln9OU+jSWlNSCBzib41BXUcg1y4U7sQ6MsS2otp8Mi8 0e28lE38= X-Gm-Gg: AR+sD13wtBP3XFXs8qEdc09MdilvyW4voWQJx8ukfOJakugX7STfimzKUNXdIc7Co21 Yl6yn3W0ZeRageraIO4UuNcpquGrAPVJMffuDbkuem8tgmXt4IF6jXS0zzxdkiAudAhEx8DXjP0 YtCnxRWQKYDKqWjXb1R5YFJNdWjanXgkDirlXAiZ5lx8wFSFZay4pG0DAT+foIHLMq6ICn1OenT DZZLjCgv7Rh7WqZxDTuzfJuI1tEeROn3DzaH6eMTnSLYcoNc8zBqWLg1+WZ2ypF04qVtHZX1Tp9 mC4t+HZ68wHfl4Hr/85ZHuWg85jGpVJeANsPk9OTKtgm9AISCEBKsC7jB1TIeLbvb54sB7tnQWZ etM/rKYdLMxh78axKWF5t+qBKGVuNL+BMYR0y7DEB0hkhKWdouJdG8rr6iDh8xPNf4CWpXOFkt0 fR5Fx6y1G3Eo/bmX0LbuZDCAzl+xzgejdOVrwt1a4sJRDrHYrJNBvhtUsM0aSuCzfHvqZLRUddg UYMAMpWw8vW6cqNjzeUEBjXG/yNYZx0xa+y6jnbjqw/+VZKt+2i2IhYE/2cgrntQ4uMqDwe X-Received: by 2002:a05:600c:5490:b0:499:59fd:dbfc with SMTP id 5b1f17b1804b1-499b913eb08mr241109335e9.1.1787576453505; Mon, 24 Aug 2026 06:00:53 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/19] rpcbind: Drop dependency on quota Date: Mon, 24 Aug 2026 14:59:59 +0200 Message-ID: <9704833693c5431c48ad85dd26a57ae9292e54cf.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:00:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244110 From: Michal Sieron Originally added to provide rpcsvc/rquota.h header [1], it is no longer needed since at least v1.2.6 where [2] was merged. Not sure why, but distros like Arch and Ubuntu (possibly others too) did not have this dependency at any point from what I could find. Anyway, this builds just fine without quota present. [1]: https://git.openembedded.org/openembedded-core/commit/?h=4771f4af5926d724958ba7cf46b937c53babfc7c [2]: git://linux-nfs.org/~steved/rpcbind 8bf0ce4a1858b5cd00440e416ecfe0fd74662a01 rpcbind: always use inline rpcsvc constants Signed-off-by: Michal Sieron Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 4339890671f86119f7f85cb23ec84af8141f893d) Signed-off-by: Vijay Anusuri Signed-off-by: Fabien Thomas --- meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb b/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb index 692c421cd9a..000ffe37040 100644 --- a/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb +++ b/meta/recipes-extended/rpcbind/rpcbind_1.2.9.bb @@ -4,7 +4,7 @@ DESCRIPTION = "The rpcbind utility is a server that converts RPC \ SECTION = "console/network" HOMEPAGE = "http://sourceforge.net/projects/rpcbind/" BUGTRACKER = "http://sourceforge.net/tracker/?group_id=201237&atid=976751" -DEPENDS = "libtirpc quota" +DEPENDS = "libtirpc" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://COPYING;md5=b46486e4c4a416602693a711bb5bfa39 \ From patchwork Mon Aug 24 13:00:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96176 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 44096C5DF94 for ; Mon, 24 Aug 2026 13:01:06 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15960.1787576456366370340 for ; Mon, 24 Aug 2026 06:00:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZT7vrFko; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47f703a9d05so1665862f8f.0 for ; Mon, 24 Aug 2026 06:00:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576455; x=1788181255; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Wed56L5O2BaA7/06bNHC1U80Z9kfkxvxhKcYRsc6kMs=; b=ZT7vrFkoFQDha07v/f2fg/w6R9d6rS17FiFwFWpkCCWkxw7mFvuI5lq6geEw9LchDv c46JP1P2TQpBIH4nxFuLpWlbLbqP3DE9O+yMa6zFO7d110nACpM1fs6CV4IQdEyF2IKy wfIBvP432WroVry493yb1MzRXQ1SJgRvo05p0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576455; x=1788181255; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Wed56L5O2BaA7/06bNHC1U80Z9kfkxvxhKcYRsc6kMs=; b=fAiAQrxTD+WmkPiz0HuZtGqsj3HwUXgTxsFZwWO8YaUtyzdZdp3U/PKzMZXrGRqczD 0TMbEKrqz7DwEUWE+VJmd7ChSBGZqZFOF9I7yjFX8v5TXhLmTDEngGa34guNCVRuqMsV nicyG55Er7qFITuRDqpkCpr6+VQw0xf+ismKMYsCeg/9QsQWNEN/V1TJqZZWKWhaYA7l 7LzunmSrNX4Nc8q20ebVab0uZZ8qxqcnYYgSdU+x8qMz0/YgOIxOPLvkNbyjfgtdKZ5Y 63g36igCBo7NFPMlOvwub+sJaihI44KZ4sSMs+wKtll1qxq/VzNBi/TZT4SywQKjE9Iv qsWg== X-Gm-Message-State: AFuF++n5kky69OZLDnR9kMM17biRdzrqEMZwdU4lbmCSetuM47Vn9z9q uQ9NXN1Nz7o4AOIdTG7M610oZ/BR5sPssASmU2AVSmjtOtifxhFY0p6qJZ2o4CbWf87H9TThGoP Csf7GbYI= X-Gm-Gg: AR+sD10WrHfHjdLsJ1AnpBSE/sGao1uT+tInGyWSozVgmyheJzrshackLSdY4j/oPiS NeNN+HkKILhQ48bK1AA4lut+vTdxAslrEFfwvVofiHDRNXsXzQ13nsAKr5XEVslJDFdYAfrBiaD Ey+fjS1lrt4UZKlE8fcwRJQ1MeQbiSb89tP9zEOc+7gtXLFghU0+vb04MNa3bMZRpaxWDwgjY5J hMYL7Ht6WKKnTU2kb82YbYC1A4klL8DdxHJK5U/epanGZGROFftBD7vbq7p5wS/a4XzsBWHlYYI HlJbjCwIWcyrGu3wvfM2Rd5a3p8CLctFcptL+Qlr3Kce6A8tclxiXQ8HUH6D4ShnMRkaOmpxB9e m8nqLz95xpFmJBJY9JQc8yHRrKl4P+qNhD40iZIMbcdMul32vHrqRIHa5Qv72AXK2iIeVsVUIzb Dghhykd1Oi9x6pVh6AlcD2sNlzc4KKiNppGE9ETDEQ2FzmlvZVb3sR7IRlX4+HgBGjxGILlFX6f 7ub9bPvPZPbdbpv4+EJidx8YRY/9socQ0EJvk0/Eo3udz0u69rhuu5pDNaeunwXpQboZ3o91CFg WbVO3E0= X-Received: by 2002:a05:600c:a313:b0:499:bf8c:cfd1 with SMTP id 5b1f17b1804b1-499bf8cd003mr201450245e9.2.1787576454432; Mon, 24 Aug 2026 06:00:54 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/19] oeqa/maturin: Update dependency version Date: Mon, 24 Aug 2026 15:00:00 +0200 Message-ID: <09d9cf2846e96d6b41d7efe7fccb80365411fed7.1787576160.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244111 From: Richard Purdie There are security issues in earlier versions of pyo3, update the minimum version to avoid security warnings. Signed-off-by: Richard Purdie (cherry picked from commit 294409c4bfe392471509d4cb6c1e6fb1063d2b3b) Signed-off-by: Fabien Thomas --- meta/lib/oeqa/files/maturin/guessing-game/Cargo.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/lib/oeqa/files/maturin/guessing-game/Cargo.toml b/meta/lib/oeqa/files/maturin/guessing-game/Cargo.toml index 5c0c06db4bc..0bf83bb6c43 100644 --- a/meta/lib/oeqa/files/maturin/guessing-game/Cargo.toml +++ b/meta/lib/oeqa/files/maturin/guessing-game/Cargo.toml @@ -14,7 +14,7 @@ crate-type = ["cdylib"] rand = "0.9.0" [dependencies.pyo3] -version = "0.27.2" +version = "0.29.0" # "abi3-py39" tells pyo3 (and maturin) to build using the stable ABI with minimum Python version 3.9 features = ["abi3-py39"] From patchwork Mon Aug 24 13:00:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96179 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52503C61DB4 for ; Mon, 24 Aug 2026 13:01:06 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.15961.1787576457405061680 for ; Mon, 24 Aug 2026 06:00:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Hfjtee4M; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4995b0343c1so25117015e9.3 for ; Mon, 24 Aug 2026 06:00:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787576456; x=1788181256; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=W6XMdbZph53Qh3PdLfxcIQHjGL4UJpDCYscD2eSLJak=; b=Hfjtee4MMAbuWF9uHET4vRJrqjsm3CL6cR88p/1iooBmHvKIYvp/X7xUY/P2fZ5qFm u1M0Pft5Aw0Jgnw2qThPU9236ZgEcMceUFeethh6vE35gsZss7CYY5ThpSzvVhwZPpWO EMO2/3fWQv3FzFoWj4GSX1fgJHAI01378sv6c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787576456; x=1788181256; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=W6XMdbZph53Qh3PdLfxcIQHjGL4UJpDCYscD2eSLJak=; b=Vhikj4XXN43v/v/v5NSvud79uOZk9AnuiP3aaMOe0P4jwWD4Qor0gTKgvFxCev/wGq DSb7Wf6k8Pjl9kPQYFu6vSRbRInJWtSNgQsiV3sahVL3lObamQoCPUTjUx/UqxCPmlZ5 7P0zFMUoT6JZxs+iIKZAx8vhIbZfabuOSotEMFNemQMXlORDSi2o7AhiFYsXQldEEAYt 8URdO7tsuEpbpgsFUnsV0TxDuYjk1hnwv0itUr8tcqrDdlPYtkNxsoC5i/cuIZ+4Vw4o JSFLkRFaZXPyIGHph9s1KF7ajstk9qnaN5mcW9KX3XhzkOmxOIHneG+OdpLa9tjPQyyA GpQA== X-Gm-Message-State: AFuF++m8pSMlQ0GG8jkgF56gdGqyNvxICFSVoOQ1pSLwjwVjdWD/pUeL aoxLlByqmVAaxXGBcF+wHNRQ1PBiQ1O6ZzahH1rDmZolD3MYroMB7f3/3qNpx0bd1spcpYaNJwW l9Hz1uRc= X-Gm-Gg: AR+sD1163o2TiHpNkxw9tkIWB4vgvDH4+y7n6abVbUiQXnMvU/FnXuDodMjz6gKNH34 IvMxvso2LujHDREka11gV22CgJoKa6H9Ar4yaZ6WHNveyWAI5l95HwLJ9/Xb3rQ1tqc514HUHMM qbyjisxBcS4syGaz2pVQd9XlLTEerVhsGgrZT763XgUadAKLM4TAmKheDCzZEzxYurMa3XUXyt6 fZsVWQ+zR83eZ6RnOzEFzPXczAocRWp7XbX1/Pkqq2irBxBsbWhBu/0pMa4VubW3tvRbC0XNKwZ MxPjWbud7BFhYFQE/dlpZCJ2lExC2r2+klwJmYtFLkpR62qBGX1R2NK9kECcyjddDLuDrFUzfEy zGVLVBxT91Chv0YRphNMv6MrXgfjE62Hna2WQzANetSbD0cFmAwMKz1dVq/Og7Y9h51FrAiX+aS VQdEgAhwJF56m+gi7att5ZD+qg2cT9m7fmxHSVAem9pBdccb5Xg+XdmshAsq/2A2ELhk4lMojJZ zjcjRowN8ECLRELGDPRak3+1C6+MC3gk6PNs6119e+i9So6eng29lhC6JWXqmeny4UTgUI= X-Received: by 2002:a05:600d:4452:20b0:499:7219:122f with SMTP id 5b1f17b1804b1-499c19a351amr164885495e9.4.1787576455539; Mon, 24 Aug 2026 06:00:55 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499c35935f5sm61379865e9.2.2026.08.24.06.00.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 06:00:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/19] mirrors: Disable YP mirrors on autobuilder Date: Mon, 24 Aug 2026 15:00:01 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 13:01:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244112 From: Richard Purdie The YP mirrors (and hence some bits of kernel.org) are initially populated by the autobuilder, so having it reference itself creates a log of stress and delay when things go wrong (such as a missing kernel revision). Trying to remove those but not the others is hard to maintain, so add a variable specifically to allow it. Use that variable from the autobuilder configuration. Signed-off-by: Richard Purdie (cherry picked from commit 2a7e73e90a66611ce358601b041d5cd81ad61ed2) Signed-off-by: Fabien Thomas --- meta/classes-global/mirrors.bbclass | 19 ++++++++++++------- .../yocto-autobuilder/autobuilder.conf | 1 + 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/meta/classes-global/mirrors.bbclass b/meta/classes-global/mirrors.bbclass index 6f54b257f2c..04b7a25106e 100644 --- a/meta/classes-global/mirrors.bbclass +++ b/meta/classes-global/mirrors.bbclass @@ -5,6 +5,7 @@ # MIRRORS += "\ +${YOCTO_MIRRORS} \ ${DEBIAN_MIRROR} http://snapshot.debian.org/archive/debian/20180310T215105Z/pool \ ${DEBIAN_MIRROR} http://snapshot.debian.org/archive/debian/20250101T023759Z/pool \ ${DEBIAN_MIRROR} http://snapshot.debian.org/archive/debian-archive/20120328T092752Z/debian/pool \ @@ -29,14 +30,18 @@ ${SAVANNAH_NONGNU_MIRROR} http://download-mirror.savannah.nongnu.org/releases \ ftp://sourceware.org/pub http://mirrors.edge.kernel.org/sourceware \ ftp://sourceware.org/pub http://gd.tuwien.ac.at/gnu/sourceware \ ftp://sourceware.org/pub http://ftp.gwdg.de/pub/linux/sources.redhat.com/sourceware \ -svn://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -git://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -gitsm://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -hg://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -https?://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -ftp://.*/.* http://downloads.yoctoproject.org/mirror/sources/ \ -npm://.*/?.* http://downloads.yoctoproject.org/mirror/sources/ \ ${CPAN_MIRROR} https://cpan.metacpan.org/ \ +" + +# Having a way to disable the Yocto Project related mirrors for YP CI purposes is valuable. +YOCTO_MIRRORS ??= "\ +svn://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +git://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +gitsm://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +hg://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +https?://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +ftp://.*/.* https://downloads.yoctoproject.org/mirror/sources/ \ +npm://.*/?.* https://downloads.yoctoproject.org/mirror/sources/ \ https?://downloads.yoctoproject.org/releases/uninative/ https://mirrors.edge.kernel.org/yocto/uninative/ \ https?://downloads.yoctoproject.org/mirror/sources/ https://mirrors.edge.kernel.org/yocto-sources/ \ " diff --git a/meta/conf/fragments/yocto-autobuilder/autobuilder.conf b/meta/conf/fragments/yocto-autobuilder/autobuilder.conf index a9ae99a451e..ad874384a9f 100644 --- a/meta/conf/fragments/yocto-autobuilder/autobuilder.conf +++ b/meta/conf/fragments/yocto-autobuilder/autobuilder.conf @@ -11,4 +11,5 @@ SDK_INCLUDE_TOOLCHAIN = '1' ESDK_LOCALCONF_REMOVE:append = 'BB_HASHSERVE' SDK_TOOLCHAIN_LANGS += 'go rust' PTEST_EXPECT_FAILURE = '1' +YOCTO_MIRRORS = ""