From patchwork Mon Aug 24 15:20:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Jakub Szczudlo (Nokia)" X-Patchwork-Id: 96190 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3CE0C5DF94 for ; Mon, 24 Aug 2026 15:20:43 +0000 (UTC) Received: from MRWPR03CU001.outbound.protection.outlook.com (MRWPR03CU001.outbound.protection.outlook.com [40.107.130.69]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.68.1787584836945385871 for ; Mon, 24 Aug 2026 08:20:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@nokia.com header.s=selector1 header.b=AFeBsIat; spf=permerror, err=parse error for token &{10 18 %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email}: invalid domain name (domain: nokia.com, ip: 40.107.130.69, mailfrom: jakub.szczudlo@nokia.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=UdNmvmcvzsaiqKup8oqnEBLD00qIO2LTqG97zKy1EgwNg02d/fgc3EXLecOnc6PMvlIXXQonloPTOA/akIF+/VYhHFUisPysIX3O1HJpOB8r3XdiJyptl0PxKv87v8nUsIsrCGrSrjYqiKfaxNupwpa359PBfDp4F7kiH8djlyI5gX0C81m/7FdMQdXWm0wNFSFBP2cqn2BupVGVyN9zU9tVnWgTTUGd3jpWkpFWstnFiUrGZJNJnQaLw8WpWS7zIgrbqDMQkJThzNLssur8mQlD7A15lpJwMK5GR99CGOq1+0Cv+r4f+WeZfPErR3LPncOpfejunpTkvyw6KMHEsg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=S+m6X3RVa95/Ds19dMDuqXyDNG14qOzesRCl/MGcYQU=; b=QVTe2mU761ksZbkY6S/7v7HKKkJS/0CKwhdoWg0ZVXNoXmIAoYjIk3pcFOAvHfGjgyw1vOt3cyPHI3L20Krzil3Meqg/Tc7f0A/Ee9NYcJcDBNDFUcmC5jwU/whi8LfMvlNcJEOOUyoUYvq3WPR/dhmslNLMfI1zaifH7EAOEiX1MdS5EgqeA5MdZTzu8CPfVnmZEJlGY+jZBhsfeVyUZGKAxhQuXM49VPBHOio/x3KCwVOoeMwE4gPe8xkioYXL1wZhkq0lfaOxBdZ3975bynz2XOJcKjChI2PduVfmGKXLI+MTijO6m3HvCKUZDrZd1X2sM4a4VdhbuA5SqCwyFg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=S+m6X3RVa95/Ds19dMDuqXyDNG14qOzesRCl/MGcYQU=; b=AFeBsIatmoi1rdirBSAC31/I+92Gme20IsnH3Wt1K/g4MP1NrFN3i8iqhwWBrEdOw2i5jpYadbr1Dt/4oDec4xv6DzWy1tBgKzHNGvLOCM7CGn/SetVKvYMjdTX8cgI8NNutM26VNxkie/jaH7Hx9GKx1E8lhePxtJXcv8CDCpJPyxYJJfl3gxnIUKUXwGzU/LwEMuwZc1RycRjL9L1tJfzxMv7RnEV8cOPREU9NermYUOoQgKUjm9nndZcSCb4Is8/0TF7s/Gcx4nN7iDtrAwrskdL0tDY8TyyDrTow0CYoibmMZHoOXAluPELqFzCb2jw9cW+X69ByIxZdXUuQFg== Received: from GV2PR07MB11919.eurprd07.prod.outlook.com (2603:10a6:150:357::20) by DUZPR07MB9935.eurprd07.prod.outlook.com (2603:10a6:10:4ae::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.6; Mon, 24 Aug 2026 15:20:31 +0000 Received: from GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680]) by GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680%3]) with mapi id 15.21.0360.005; Mon, 24 Aug 2026 15:20:31 +0000 From: "Jakub Szczudlo (Nokia)" To: "openembedded-core@lists.openembedded.org" CC: "yoann.congal@smile.fr" , "Jakub Szczudlo (Nokia)" Subject: [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Thread-Topic: [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Thread-Index: AQHdM9wasgM8lRQayEO+yrXfZ8u0UA== Date: Mon, 24 Aug 2026 15:20:31 +0000 Message-ID: <20260824152023.19501-1-jakub.szczudlo@nokia.com> Accept-Language: en-US, en-150 Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nokia.com; x-ms-publictraffictype: Email x-ms-traffictypediagnostic: GV2PR07MB11919:EE_|DUZPR07MB9935:EE_ x-ms-office365-filtering-correlation-id: 2e346509-b292-475c-69bb-08df01f33cca x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|366016|23010399003|376014|1800799024|38070700021|6133799003|56012099006|11063799006|10067099003|3023799007|18002099003; x-microsoft-antispam-message-info: un+FkloRxPLIyra+QG6yZOeaa/6yTR6kRpDmWtdqHMqabHzw7Za/heYJGpDtM4aqfDPLj6Y99TEPsxUDUnmqS8fEQBt0CCrGPFgVqrJU/CT1Lss81V2tEwZnV/ptet4JrBuJ9Z8J5F8xRuRj10+NVsAoK6j0lmCv9vG9khsOrCSXcxh+kOJJVjAtdObajV9W496lbrwSKeLqEoiRZrALezxDRfcJNONbEzwi1WGLSlbpm0UO1ujL2ur8Bpd9vFPcwFFsQ1UbfGLvF1AoAR/ChEbNQZASosuk8YGE+G4YlE5LwcGWVrtWv/narNPXUtkMuYawjAm0qwPKh+H09+BghegmEpVX9X3ReiyvVagmBHZkJ9gldh5cTWD7bbdFoI+HufNvuPxgH44L67yZ1m6LCVdJ73dUNWB/sgMmdS+gEC+wKzTXxGjMNARWbZA69lJ+Eeq+f5IdH1XMcVzv9Eph3C7qqsR+mzWZ3DzBrEdTWRaF6sxpIM3dtPhORWpQnMMafggpfsBDyk/ESxFPbQxKHlULMLnDikt/aivX6ZGsULTie4qVQuN1Wgna2mZq9mD1A7fQ3RLylPw3qnhZah9T86YJI6Z9qz13GtJPospYjDbYmTGsl/wdgIfSkjzkkFZ88wBzi03RDZE6qYOVU4c33qlpl7fM0N7/+BtgY/0yKt4= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GV2PR07MB11919.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(376014)(1800799024)(38070700021)(6133799003)(56012099006)(11063799006)(10067099003)(3023799007)(18002099003);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?q?r0U0yic2W8fP077Dd9Ga+sl?= =?iso-8859-1?q?xHuR/5jNRNZn1GR9aCFrM3CNgC8w5c1AaQlbqccsWnysWNy1lm3tvH0LOAir?= =?iso-8859-1?q?kSptgV4DV6n0iMWpiF7sJwiFjWX6ZTGFORteotlXlTHosL7oRk63uWcMBsz4?= =?iso-8859-1?q?R/gnqDPZI2aIRfdXSsTc0MTcqiLCdrQTUuxDdkNwYqM5gkIkl6+E2wZ0NprO?= =?iso-8859-1?q?hcRrXKi/4RdFt+9o9vwBQ67kPNy904hDyaoPgNAq1QFZonU6pB2YVSFtVwmB?= =?iso-8859-1?q?EK6rF28rgkYa2whLEwwwpUuIH8gFdvjB8e6BBKR9TOO0QJXuG8pd/TcKs0+G?= =?iso-8859-1?q?Q5vMFBuZKoYKh2lHkAESK3A8CWUjOguC4+Fhxe0QpQ2v5H55ubyAu3h3QJvi?= =?iso-8859-1?q?Uz91RduICdSR56SDt+aCSdmtp8F1Uw9Ygd5pSyaWvdpJChR1KvYLDywm5uhB?= =?iso-8859-1?q?wCosI56Fd8WxheO3a1kB6oPO8Y0cglBvQKATozm1IxB9hmzdzA11i52oHPPa?= =?iso-8859-1?q?uwmB8spHxg3AU1eCBzBANekQlt30qH12C0iYymBKQ1Sb/k/YK0Jk+QBN3O+z?= =?iso-8859-1?q?ok92DS1AhBRfJzEa+DT3HmibwM/RtScJ6p39mLuJTOwPpv0fqLE26x4ziLiF?= =?iso-8859-1?q?sOg2vNBgdoY0z9QqiUAalWWGSzxS6GLzbA6iMFp4uLHBh49dT3qnYI+bWTB4?= =?iso-8859-1?q?9gpcZcMMbO1BJX4+8Ouwl8zBgkm9EjT4m1BugLf1HYKiZ6stQa1TLKAqWC5k?= =?iso-8859-1?q?Q4qnBSjxqY8IxJxwA3w4DR5/aFtzxw95l2KbAJEsFudaxiH5bt98LDjJ4RFW?= =?iso-8859-1?q?3IREVg5kTcbHOKRns9iR/Lfnh91+r4vcDf7jiY+O0oMMCehepvwyDARGXOyh?= =?iso-8859-1?q?2awzwGrHw42isIAehsBc6x0JHtARQrzoZ0SmKNBqFM8v9fwqxYAfNBhJdx9j?= =?iso-8859-1?q?CNgsKO0kguGWpDe+WZW6PDqvql0mJ6aMfrqRj8OdWzU56HiOaLKe7PaNrPi/?= =?iso-8859-1?q?zrurbv+nbOpRtDq7nAi1PH3m6j1sG7oyWBeyfceZqcKs4xUYJGyL5r8D3xj2?= =?iso-8859-1?q?XqYa1yb2RYbp2+nvq4r8m7VquFIkhlFUCRL7uTYiI9wedoNRtp4FhCj6ehgs?= =?iso-8859-1?q?AfzZAaNbvXpaSRJziNZQft8r87AxE6mZrQQZO507tJBh1HoLW4KNbv5dF7ML?= =?iso-8859-1?q?F7nwWnOOXb+Mk2LoNENMzTiXCyipvv4DpIurJI27b/aahWNkT6F5owTHfauG?= =?iso-8859-1?q?noZNMjg3V2/oiXDecMeWErQKMmO9+WtljeviJjIqM58ID7SJBLo9qRskHVPl?= =?iso-8859-1?q?Tk68cdsq6P/bVOhJjZwNSy2Pc4wJFASIO6Hw8auJXeFfKh/vSuWAQho6Tv0F?= =?iso-8859-1?q?I1PWwPQ6894Mwn8oT3Q8QlB8RlS5Wju9fsmhWyz3MS6mTDIZ5KBSLM11hyUQ?= =?iso-8859-1?q?FIRpuQUYcrRVeKqqbcEiEt6ZiCVJfyK4dpWgSvZPZs6uzYPejhqe8PEgBFUp?= =?iso-8859-1?q?XOC/nTrd/OJyLM2me5VnDLZU6/pKugREVNv2iPedakfL20dseRJMCub8olQJ?= =?iso-8859-1?q?0r65CUSQhzuGi9PXAkPJyVpVWgvHow/nHdjrZl6sTN/FgfOWv8mXWnHVBYff?= =?iso-8859-1?q?uNTcs400a7yUVd3j5vR/4lKGH8yrIWPdW68V9EOWmDWR8DP6DLrsqpoLluj5?= =?iso-8859-1?q?feU8Urt223q9OKeOgYL1xaNXys7uHY4sti18Dtizta3oJt/LlVJFTtGr1mxs?= =?iso-8859-1?q?KxVNQwcrKqE9yRzusjhu8b0DP15LLHp8uF3NrnBjGwNbc2w=3D=3D?= MIME-Version: 1.0 X-OriginatorOrg: nokia.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: GV2PR07MB11919.eurprd07.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 2e346509-b292-475c-69bb-08df01f33cca X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Aug 2026 15:20:31.8328 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: 6NkpQGtdpL2Xy2lUKUv0hO/oBPZ/o1Q8p2XE5Mk7kDBdnYJz67SFvrcE9P/LTXLu+CTQ++lUM1j3fobI0sIQikfBspVh5pnmF/H28Y0NT8g= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DUZPR07MB9935 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 15:20:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244130 Expat does not track whether its public parser APIs are called from inside a user handler. Re-entering the parser through XML_GetBuffer(), XML_Parse(), XML_ParseBuffer(), XML_ParserFree() or XML_ParserReset() can therefore result in use-after-free and memory corruption. The 32 upstream commits are divided as follows: * 01 introduces the handler call depth counter and the helper functions used to enter, leave and detect handler execution. * 02-04 are preparation patches. They extract handler calls from compound expressions so that depth tracking can be placed before and after each invocation without changing handler return-value semantics. * 05-26 instrument the individual handler types. Each patch covers a distinct callback path; omitting one would leave a route around the API guards. * 27-31 add the actual policy enforcement to XML_GetBuffer(), XML_Parse(), XML_ParseBuffer(), XML_ParserFree() and XML_ParserReset(). * 32 adds regression coverage for all five rejected calls. Documentation and Changes-file commits from the upstream series are dropped because they do not affect the fix or its test coverage. An explicit XML_Parser cast is added to the regression-test handler because handlers.c is also included by handlers_cxx.cpp and compiled as C++ in the OE build. Upstream pull request: https://github.com/libexpat/libexpat/pull/1246 Signed-off-by: Jakub Szczudlo --- .../expat/expat/CVE-2026-50219-01.patch | 61 +++++++ .../expat/expat/CVE-2026-50219-02.patch | 84 ++++++++++ .../expat/expat/CVE-2026-50219-03.patch | 92 +++++++++++ .../expat/expat/CVE-2026-50219-04.patch | 34 ++++ .../expat/expat/CVE-2026-50219-05.patch | 48 ++++++ .../expat/expat/CVE-2026-50219-06.patch | 154 ++++++++++++++++++ .../expat/expat/CVE-2026-50219-07.patch | 32 ++++ .../expat/expat/CVE-2026-50219-08.patch | 44 +++++ .../expat/expat/CVE-2026-50219-09.patch | 44 +++++ .../expat/expat/CVE-2026-50219-10.patch | 35 ++++ .../expat/expat/CVE-2026-50219-11.patch | 32 ++++ .../expat/expat/CVE-2026-50219-12.patch | 42 +++++ .../expat/expat/CVE-2026-50219-13.patch | 49 ++++++ .../expat/expat/CVE-2026-50219-14.patch | 74 +++++++++ .../expat/expat/CVE-2026-50219-15.patch | 82 ++++++++++ .../expat/expat/CVE-2026-50219-16.patch | 46 ++++++ .../expat/expat/CVE-2026-50219-17.patch | 64 ++++++++ .../expat/expat/CVE-2026-50219-18.patch | 32 ++++ .../expat/expat/CVE-2026-50219-19.patch | 87 ++++++++++ .../expat/expat/CVE-2026-50219-20.patch | 62 +++++++ .../expat/expat/CVE-2026-50219-21.patch | 46 ++++++ .../expat/expat/CVE-2026-50219-22.patch | 48 ++++++ .../expat/expat/CVE-2026-50219-23.patch | 36 ++++ .../expat/expat/CVE-2026-50219-24.patch | 33 ++++ .../expat/expat/CVE-2026-50219-25.patch | 35 ++++ .../expat/expat/CVE-2026-50219-26.patch | 33 ++++ .../expat/expat/CVE-2026-50219-27.patch | 30 ++++ .../expat/expat/CVE-2026-50219-28.patch | 30 ++++ .../expat/expat/CVE-2026-50219-29.patch | 31 ++++ .../expat/expat/CVE-2026-50219-30.patch | 31 ++++ .../expat/expat/CVE-2026-50219-31.patch | 31 ++++ .../expat/expat/CVE-2026-50219-32.patch | 100 ++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 32 ++++ 33 files changed, 1714 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-01.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-02.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-03.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-04.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-05.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-06.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-07.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-08.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-09.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-10.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-11.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-12.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-13.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-14.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-15.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-16.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-17.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-18.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-19.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-20.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-21.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-22.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-23.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-24.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-25.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-26.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-27.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-28.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-29.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-30.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-31.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-50219-32.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-01.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-01.patch new file mode 100644 index 0000000000..1d3a8cbba2 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-01.patch @@ -0,0 +1,61 @@ +From 8da7b772a31155083a37796f96e622f6dce25454 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:15:10 +0200 +Subject: [PATCH] lib: Introduce handler call depth tracking + +(cherry picked from commit f69d0719bf01596f1d95c9e902f4a279e62c6305) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/f69d0719bf01596f1d95c9e902f4a279e62c6305] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 19 +++++++++++++++++++ + 1 file changed, 19 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 2a5ebb7..38617a6 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -793,6 +793,7 @@ struct XML_ParserStruct { + ENTITY_STATS m_entity_stats; + #endif + XML_Bool m_reenter; ++ unsigned m_handlerCallDepth; + }; + + #if XML_GE == 1 +@@ -1260,6 +1261,23 @@ generate_hash_secret_salt(void) { + #endif + } + ++static void ++beforeHandler(XML_Parser parser) { ++ assert(parser->m_handlerCallDepth < UINT_MAX); ++ parser->m_handlerCallDepth++; ++} ++ ++static void ++afterHandler(XML_Parser parser) { ++ assert(parser->m_handlerCallDepth > 0); ++ parser->m_handlerCallDepth--; ++} ++ ++static bool ++isCalledFromInsideHandler(XML_Parser parser) { ++ return parser->m_handlerCallDepth > 0; ++} ++ + static enum XML_Error + callProcessor(XML_Parser parser, const char *start, const char *end, + const char **endPtr) { +@@ -1614,6 +1632,7 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) { + parser->m_parsingStatus.parsing = XML_INITIALIZED; + // Reentry can only be triggered inside m_processor calls + parser->m_reenter = XML_FALSE; ++ parser->m_handlerCallDepth = 0; + #ifdef XML_DTD + parser->m_isParamEntity = XML_FALSE; + parser->m_useForeignDTD = XML_FALSE; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-02.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-02.patch new file mode 100644 index 0000000000..bb9335381a --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-02.patch @@ -0,0 +1,84 @@ +From 3832d4080d50d5aeeeaae32688ba3bf4af2042a2 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:33:26 +0200 +Subject: [PATCH] lib: Prepare `m_notStandaloneHandler` calls for upcoming + wrapping + +(cherry picked from commit cdd21e84e150cc2ca961533e157bd52e3cbb4aa4) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/cdd21e84e150cc2ca961533e157bd52e3cbb4aa4] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 34 ++++++++++++++++++++++------------ + 1 file changed, 22 insertions(+), 12 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 38617a6..65df026 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5537,9 +5537,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + entity->systemId, entity->publicId)) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { +- if (! dtd->standalone && parser->m_notStandaloneHandler +- && ! parser->m_notStandaloneHandler(parser->m_handlerArg)) +- return XML_ERROR_NOT_STANDALONE; ++ if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ const int handlerStatus ++ = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ if (! handlerStatus) ++ return XML_ERROR_NOT_STANDALONE; ++ } + } + /* if we didn't read the foreign DTD then this means that there + is no external subset and we must reset dtd->hasParamEntityRefs +@@ -5577,9 +5580,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + entity->systemId, entity->publicId)) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { +- if (! dtd->standalone && parser->m_notStandaloneHandler +- && ! parser->m_notStandaloneHandler(parser->m_handlerArg)) +- return XML_ERROR_NOT_STANDALONE; ++ if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ const int handlerStatus ++ = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ if (! handlerStatus) ++ return XML_ERROR_NOT_STANDALONE; ++ } + } + /* if we didn't read the foreign DTD then this means that there + is no external subset and we must reset dtd->hasParamEntityRefs +@@ -5793,9 +5799,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + #ifdef XML_DTD + && ! parser->m_paramEntityParsing + #endif /* XML_DTD */ +- && parser->m_notStandaloneHandler +- && ! parser->m_notStandaloneHandler(parser->m_handlerArg)) +- return XML_ERROR_NOT_STANDALONE; ++ && parser->m_notStandaloneHandler) { ++ const int status = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ if (! status) ++ return XML_ERROR_NOT_STANDALONE; ++ } + #ifndef XML_DTD + break; + #else /* XML_DTD */ +@@ -6179,9 +6187,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + } + } + #endif /* XML_DTD */ +- if (! dtd->standalone && parser->m_notStandaloneHandler +- && ! parser->m_notStandaloneHandler(parser->m_handlerArg)) +- return XML_ERROR_NOT_STANDALONE; ++ if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ const int status = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ if (! status) ++ return XML_ERROR_NOT_STANDALONE; ++ } + break; + + /* Element declaration stuff */ +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-03.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-03.patch new file mode 100644 index 0000000000..dca99968ae --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-03.patch @@ -0,0 +1,92 @@ +From 3fd5635fac887f161ab02adf749c2bab1d2ee904 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sat, 30 May 2026 00:45:34 +0200 +Subject: [PATCH] lib: Prepare `m_externalEntityRefHandler` calls for upcoming + wrapping + +(cherry picked from commit 1ffe852fe1d8e1d73eb4eb5798456aefc8300299) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/1ffe852fe1d8e1d73eb4eb5798456aefc8300299] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 35 ++++++++++++++++++++--------------- + 1 file changed, 20 insertions(+), 15 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 65df026..eb8e803 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3533,9 +3533,10 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + entity->open = XML_FALSE; + if (! context) + return XML_ERROR_NO_MEMORY; +- if (! parser->m_externalEntityRefHandler( +- parser->m_externalEntityRefHandlerArg, context, entity->base, +- entity->systemId, entity->publicId)) ++ const int status = parser->m_externalEntityRefHandler( ++ parser->m_externalEntityRefHandlerArg, context, entity->base, ++ entity->systemId, entity->publicId); ++ if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + poolDiscard(&parser->m_tempPool); + } else if (parser->m_defaultHandler) +@@ -5532,9 +5533,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (parser->m_useForeignDTD) + entity->base = parser->m_curBase; + dtd->paramEntityRead = XML_FALSE; +- if (! parser->m_externalEntityRefHandler( +- parser->m_externalEntityRefHandlerArg, 0, entity->base, +- entity->systemId, entity->publicId)) ++ const int status = parser->m_externalEntityRefHandler( ++ parser->m_externalEntityRefHandlerArg, 0, entity->base, ++ entity->systemId, entity->publicId); ++ if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { + if (! dtd->standalone && parser->m_notStandaloneHandler) { +@@ -5575,9 +5577,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + return XML_ERROR_NO_MEMORY; + entity->base = parser->m_curBase; + dtd->paramEntityRead = XML_FALSE; +- if (! parser->m_externalEntityRefHandler( +- parser->m_externalEntityRefHandlerArg, 0, entity->base, +- entity->systemId, entity->publicId)) ++ const int status = parser->m_externalEntityRefHandler( ++ parser->m_externalEntityRefHandlerArg, 0, entity->base, ++ entity->systemId, entity->publicId); ++ if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { + if (! dtd->standalone && parser->m_notStandaloneHandler) { +@@ -6167,9 +6170,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + dtd->paramEntityRead = XML_FALSE; + entity->open = XML_TRUE; + entityTrackingOnOpen(parser, entity, __LINE__); +- if (! parser->m_externalEntityRefHandler( +- parser->m_externalEntityRefHandlerArg, 0, entity->base, +- entity->systemId, entity->publicId)) { ++ const int status = parser->m_externalEntityRefHandler( ++ parser->m_externalEntityRefHandlerArg, 0, entity->base, ++ entity->systemId, entity->publicId); ++ if (! status) { + entityTrackingOnClose(parser, entity, __LINE__); + entity->open = XML_FALSE; + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; +@@ -6959,9 +6963,10 @@ storeEntityValue(XML_Parser parser, const ENCODING *enc, + dtd->paramEntityRead = XML_FALSE; + entity->open = XML_TRUE; + entityTrackingOnOpen(parser, entity, __LINE__); +- if (! parser->m_externalEntityRefHandler( +- parser->m_externalEntityRefHandlerArg, 0, entity->base, +- entity->systemId, entity->publicId)) { ++ const int status = parser->m_externalEntityRefHandler( ++ parser->m_externalEntityRefHandlerArg, 0, entity->base, ++ entity->systemId, entity->publicId); ++ if (! status) { + entityTrackingOnClose(parser, entity, __LINE__); + entity->open = XML_FALSE; + result = XML_ERROR_EXTERNAL_ENTITY_HANDLING; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-04.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-04.patch new file mode 100644 index 0000000000..3f4070e6e6 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-04.patch @@ -0,0 +1,34 @@ +From 9a13084051f0dbff8f980db7aca46b02111cb6d5 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sat, 30 May 2026 00:46:36 +0200 +Subject: [PATCH] lib: Prepare `m_unknownEncodingHandler` calls for upcoming + wrapping + +(cherry picked from commit adcafd4316259ef48b1763e584733a7bff4a8db0) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/adcafd4316259ef48b1763e584733a7bff4a8db0] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index eb8e803..dddcb47 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5057,8 +5057,9 @@ handleUnknownEncoding(XML_Parser parser, const XML_Char *encodingName) { + info.convert = NULL; + info.data = NULL; + info.release = NULL; +- if (parser->m_unknownEncodingHandler(parser->m_unknownEncodingHandlerData, +- encodingName, &info)) { ++ const int status = parser->m_unknownEncodingHandler( ++ parser->m_unknownEncodingHandlerData, encodingName, &info); ++ if (status) { + ENCODING *enc; + parser->m_unknownEncodingMem = MALLOC(parser, XmlSizeOfUnknownEncoding()); + if (! parser->m_unknownEncodingMem) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-05.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-05.patch new file mode 100644 index 0000000000..29f9a0afcc --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-05.patch @@ -0,0 +1,48 @@ +From 6e755a1e9c3e4cc7c1ed60c96e9d2e1659daf5da Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:05:19 +0200 +Subject: [PATCH] lib: Register `m_attlistDeclHandler` with handler call depth + tracking + +(cherry picked from commit 781092f189a8c8e8be6640258829a7f783864282) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/781092f189a8c8e8be6640258829a7f783864282] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index dddcb47..16ab984 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5682,10 +5682,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + poolFinish(&parser->m_tempPool); + } + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_attlistDeclHandler( + parser->m_handlerArg, parser->m_declElementType->name, + parser->m_declAttributeId->name, parser->m_declAttributeType, 0, + role == XML_ROLE_REQUIRED_ATTRIBUTE_VALUE); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + } +@@ -5720,10 +5722,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + poolFinish(&parser->m_tempPool); + } + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_attlistDeclHandler( + parser->m_handlerArg, parser->m_declElementType->name, + parser->m_declAttributeId->name, parser->m_declAttributeType, + attVal, role == XML_ROLE_FIXED_ATTRIBUTE_VALUE); ++ afterHandler(parser); + poolClear(&parser->m_tempPool); + handleDefault = XML_FALSE; + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-06.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-06.patch new file mode 100644 index 0000000000..c5ca02b37a --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-06.patch @@ -0,0 +1,154 @@ +From 80765c36bc9b272d0141fa8c3ea3da59a16c443e Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:08:02 +0200 +Subject: [PATCH] lib: Register `m_characterDataHandler` with handler call + depth tracking + +(cherry picked from commit 5ee607587a997220a48e78b5f6c55a05e50e5b20) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/5ee607587a997220a48e78b5f6c55a05e50e5b20] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 44 ++++++++++++++++++++++++++++++++++---------- + 1 file changed, 34 insertions(+), 10 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 16ab984..4556805 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3428,7 +3428,9 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + *eventEndPP = end; + if (parser->m_characterDataHandler) { + XML_Char c = 0xA; ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, &c, 1); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, end); + /* We are at the end of the final buffer, should we check for +@@ -3481,9 +3483,11 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + ((char *)&ch) + sizeof(XML_Char), __LINE__, + XML_ACCOUNT_ENTITY_EXPANSION); + #endif /* XML_GE == 1 */ +- if (parser->m_characterDataHandler) ++ if (parser->m_characterDataHandler) { ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, &ch, 1); +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + break; + } +@@ -3729,8 +3733,10 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + return XML_ERROR_BAD_CHAR_REF; + if (parser->m_characterDataHandler) { + XML_Char buf[XML_ENCODE_MAX]; ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, buf, + XmlEncode(n, (ICHAR *)buf)); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + } break; +@@ -3739,7 +3745,9 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + case XML_TOK_DATA_NEWLINE: + if (parser->m_characterDataHandler) { + XML_Char c = 0xA; ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, &c, 1); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + break; +@@ -3760,11 +3768,13 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + However, now we have a start/endCdataSectionHandler, so it seems + easier to let the user deal with this. + */ +- else if ((0) && parser->m_characterDataHandler) ++ else if ((0) && parser->m_characterDataHandler) { ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, parser->m_dataBuf, + 0); +- /* END disabled code */ +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ /* END disabled code */ ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + result + = doCdataSection(parser, enc, &next, end, nextPtr, haveMore, account); +@@ -3784,13 +3794,18 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + if (MUST_CONVERT(enc, s)) { + ICHAR *dataPtr = (ICHAR *)parser->m_dataBuf; + XmlConvert(enc, &s, end, &dataPtr, (ICHAR *)parser->m_dataBufEnd); ++ beforeHandler(parser); + parser->m_characterDataHandler( + parser->m_handlerArg, parser->m_dataBuf, + (int)(dataPtr - (ICHAR *)parser->m_dataBuf)); +- } else ++ afterHandler(parser); ++ } else { ++ beforeHandler(parser); + parser->m_characterDataHandler( + parser->m_handlerArg, (const XML_Char *)s, + (int)((const XML_Char *)end - (const XML_Char *)s)); ++ afterHandler(parser); ++ } + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, end); + /* We are at the end of the final buffer, should we check for +@@ -3815,16 +3830,21 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + const enum XML_Convert_Result convert_res = XmlConvert( + enc, &s, next, &dataPtr, (ICHAR *)parser->m_dataBufEnd); + *eventEndPP = s; ++ beforeHandler(parser); + charDataHandler(parser->m_handlerArg, parser->m_dataBuf, + (int)(dataPtr - (ICHAR *)parser->m_dataBuf)); ++ afterHandler(parser); + if ((convert_res == XML_CONVERT_COMPLETED) + || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) + break; + *eventPP = s; + } +- } else ++ } else { ++ beforeHandler(parser); + charDataHandler(parser->m_handlerArg, (const XML_Char *)s, + (int)((const XML_Char *)next - (const XML_Char *)s)); ++ afterHandler(parser); ++ } + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + } break; +@@ -4730,11 +4750,13 @@ doCdataSection(XML_Parser parser, const ENCODING *enc, const char **startPtr, + parser->m_endCdataSectionHandler(parser->m_handlerArg); + /* BEGIN disabled code */ + /* see comment under XML_TOK_CDATA_SECT_OPEN */ +- else if ((0) && parser->m_characterDataHandler) ++ else if ((0) && parser->m_characterDataHandler) { ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, parser->m_dataBuf, + 0); +- /* END disabled code */ +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ /* END disabled code */ ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + *startPtr = next; + *nextPtr = next; +@@ -4745,7 +4767,9 @@ doCdataSection(XML_Parser parser, const ENCODING *enc, const char **startPtr, + case XML_TOK_DATA_NEWLINE: + if (parser->m_characterDataHandler) { + XML_Char c = 0xA; ++ beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, &c, 1); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + break; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-07.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-07.patch new file mode 100644 index 0000000000..1bf15cdd01 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-07.patch @@ -0,0 +1,32 @@ +From bba681b574c9675f331e79db0513bb9df1fec523 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:08:40 +0200 +Subject: [PATCH] lib: Register `m_commentHandler` with handler call depth + tracking + +(cherry picked from commit 0e7dbfee7912a8e25aace775be47e5ad570b9cc3) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/0e7dbfee7912a8e25aace775be47e5ad570b9cc3] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 4556805..98ffe5a 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -7269,7 +7269,9 @@ reportComment(XML_Parser parser, const ENCODING *enc, const char *start, + if (! data) + return 0; + normalizeLines(data); ++ beforeHandler(parser); + parser->m_commentHandler(parser->m_handlerArg, data); ++ afterHandler(parser); + poolClear(&parser->m_tempPool); + return 1; + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-08.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-08.patch new file mode 100644 index 0000000000..7a21357ae7 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-08.patch @@ -0,0 +1,44 @@ +From c6e96e6a5ec4afc710f4aee2b81bda4baca71a25 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:14:10 +0200 +Subject: [PATCH] lib: Register `m_defaultHandler` with handler call depth + tracking + +(cherry picked from commit e5b76bd58dd9984cef46c2a66a98b03c95a3c774) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/e5b76bd58dd9984cef46c2a66a98b03c95a3c774] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 98ffe5a..ed9628f 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -7312,15 +7312,20 @@ reportDefault(XML_Parser parser, const ENCODING *enc, const char *s, + convert_res + = XmlConvert(enc, &s, end, &dataPtr, (ICHAR *)parser->m_dataBufEnd); + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_defaultHandler(parser->m_handlerArg, parser->m_dataBuf, + (int)(dataPtr - (ICHAR *)parser->m_dataBuf)); ++ afterHandler(parser); + *eventPP = s; + } while ((convert_res != XML_CONVERT_COMPLETED) + && (convert_res != XML_CONVERT_INPUT_INCOMPLETE)); +- } else ++ } else { ++ beforeHandler(parser); + parser->m_defaultHandler( + parser->m_handlerArg, (const XML_Char *)s, + (int)((const XML_Char *)end - (const XML_Char *)s)); ++ afterHandler(parser); ++ } + } + + static int +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-09.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-09.patch new file mode 100644 index 0000000000..9d87b20d7c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-09.patch @@ -0,0 +1,44 @@ +From 8f2979090e01719c7f0c005816943d93bfda2754 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:15:01 +0200 +Subject: [PATCH] lib: Register `m_elementDeclHandler` with handler call depth + tracking + +(cherry picked from commit b4a711a33591c0d45d6e630ed6448dcbc5534700) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/b4a711a33591c0d45d6e630ed6448dcbc5534700] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index ed9628f..03bc212 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -6259,8 +6259,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + content->type = ((role == XML_ROLE_CONTENT_ANY) ? XML_CTYPE_ANY + : XML_CTYPE_EMPTY); + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_elementDeclHandler( + parser->m_handlerArg, parser->m_declElementType->name, content); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + dtd->in_eldecl = XML_FALSE; +@@ -6342,8 +6344,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (! model) + return XML_ERROR_NO_MEMORY; + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_elementDeclHandler( + parser->m_handlerArg, parser->m_declElementType->name, model); ++ afterHandler(parser); + } + dtd->in_eldecl = XML_FALSE; + dtd->contentStringLen = 0; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-10.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-10.patch new file mode 100644 index 0000000000..97c0975217 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-10.patch @@ -0,0 +1,35 @@ +From 8849de56e9789089103114f472d68f3a37f5ab53 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:15:40 +0200 +Subject: [PATCH] lib: Register `m_endCdataSectionHandler` with handler call + depth tracking + +(cherry picked from commit b08e08c0558152a4180597a3e880dc70040c2b2a) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/b08e08c0558152a4180597a3e880dc70040c2b2a] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 03bc212..a894538 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -4746,8 +4746,11 @@ doCdataSection(XML_Parser parser, const ENCODING *enc, const char **startPtr, + *eventEndPP = next; + switch (tok) { + case XML_TOK_CDATA_SECT_CLOSE: +- if (parser->m_endCdataSectionHandler) ++ if (parser->m_endCdataSectionHandler) { ++ beforeHandler(parser); + parser->m_endCdataSectionHandler(parser->m_handlerArg); ++ afterHandler(parser); ++ } + /* BEGIN disabled code */ + /* see comment under XML_TOK_CDATA_SECT_OPEN */ + else if ((0) && parser->m_characterDataHandler) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-11.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-11.patch new file mode 100644 index 0000000000..64c95c02e8 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-11.patch @@ -0,0 +1,32 @@ +From 8114f635922a0c22ad11630aa953ca1545d23044 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:16:13 +0200 +Subject: [PATCH] lib: Register `m_endDoctypeDeclHandler` with handler call + depth tracking + +(cherry picked from commit bd454febe07b931e638f2186755585b67a738d31) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/bd454febe07b931e638f2186755585b67a738d31] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index a894538..2fe2f71 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5585,7 +5585,9 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + } + #endif /* XML_DTD */ + if (parser->m_endDoctypeDeclHandler) { ++ beforeHandler(parser); + parser->m_endDoctypeDeclHandler(parser->m_handlerArg); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + break; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-12.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-12.patch new file mode 100644 index 0000000000..5fb7b7dcf1 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-12.patch @@ -0,0 +1,42 @@ +From 1d95acdeab736c3b4e08477b958b6f7296a75607 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:17:10 +0200 +Subject: [PATCH] lib: Register `m_endElementHandler` with handler call depth + tracking + +(cherry picked from commit e411d9907b8addb334d1ed5db1afd5b5bf625f24) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/e411d9907b8addb334d1ed5db1afd5b5bf625f24] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 2fe2f71..37aaabc 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3645,7 +3645,9 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + if (parser->m_endElementHandler) { + if (parser->m_startElementHandler) + *eventPP = *eventEndPP; ++ beforeHandler(parser); + parser->m_endElementHandler(parser->m_handlerArg, name.str); ++ afterHandler(parser); + noElmHandlers = XML_FALSE; + } + if (noElmHandlers && parser->m_defaultHandler) +@@ -3703,7 +3705,9 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + } + *uri = XML_T('\0'); + } ++ beforeHandler(parser); + parser->m_endElementHandler(parser->m_handlerArg, tag->name.str); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + while (tag->bindings) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-13.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-13.patch new file mode 100644 index 0000000000..f74de674b0 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-13.patch @@ -0,0 +1,49 @@ +From 3e9e33361aeaa853f16fd85bf30a71f0ac0b2791 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:23:59 +0200 +Subject: [PATCH] lib: Register `m_endNamespaceDeclHandler` with handler call + depth tracking + +(cherry picked from commit 274aa82340fe1b2205e8e3ae1cd35e2168cd42e8) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/274aa82340fe1b2205e8e3ae1cd35e2168cd42e8] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 37aaabc..ad72001 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3712,9 +3712,12 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + reportDefault(parser, enc, s, next); + while (tag->bindings) { + BINDING *b = tag->bindings; +- if (parser->m_endNamespaceDeclHandler) ++ if (parser->m_endNamespaceDeclHandler) { ++ beforeHandler(parser); + parser->m_endNamespaceDeclHandler(parser->m_handlerArg, + b->prefix->name); ++ afterHandler(parser); ++ } + tag->bindings = tag->bindings->nextTagBinding; + b->nextTagBinding = parser->m_freeBindingList; + parser->m_freeBindingList = b; +@@ -3906,8 +3909,11 @@ freeBindings(XML_Parser parser, BINDING *bindings) { + /* m_startNamespaceDeclHandler will have been called for this + * binding in addBindings(), so call the end handler now. + */ +- if (parser->m_endNamespaceDeclHandler) ++ if (parser->m_endNamespaceDeclHandler) { ++ beforeHandler(parser); + parser->m_endNamespaceDeclHandler(parser->m_handlerArg, b->prefix->name); ++ afterHandler(parser); ++ } + + bindings = bindings->nextTagBinding; + b->nextTagBinding = parser->m_freeBindingList; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-14.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-14.patch new file mode 100644 index 0000000000..4d37cd6f0c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-14.patch @@ -0,0 +1,74 @@ +From 13084e0a4473dcea40fc0173a2c54fbf9fd3eece Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:25:42 +0200 +Subject: [PATCH] lib: Register `m_entityDeclHandler` with handler call depth + tracking + +(cherry picked from commit 6e62649e6b25eb789166b9131dfadfe9d806f5ce) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/6e62649e6b25eb789166b9131dfadfe9d806f5ce] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index ad72001..e9466d5 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5791,10 +5791,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + poolFinish(&dtd->entityValuePool); + if (parser->m_entityDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_entityDeclHandler( + parser->m_handlerArg, parser->m_declEntity->name, + parser->m_declEntity->is_param, parser->m_declEntity->textPtr, + parser->m_declEntity->textLen, parser->m_curBase, 0, 0, 0); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + } else +@@ -5812,10 +5814,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + + if (parser->m_entityDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_entityDeclHandler( + parser->m_handlerArg, parser->m_declEntity->name, + parser->m_declEntity->is_param, parser->m_declEntity->textPtr, + parser->m_declEntity->textLen, parser->m_curBase, 0, 0, 0); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + } +@@ -5893,10 +5897,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (dtd->keepProcessing && parser->m_declEntity + && parser->m_entityDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_entityDeclHandler( + parser->m_handlerArg, parser->m_declEntity->name, + parser->m_declEntity->is_param, 0, 0, parser->m_declEntity->base, + parser->m_declEntity->systemId, parser->m_declEntity->publicId, 0); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + break; +@@ -5916,10 +5922,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + handleDefault = XML_FALSE; + } else if (parser->m_entityDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_entityDeclHandler( + parser->m_handlerArg, parser->m_declEntity->name, 0, 0, 0, + parser->m_declEntity->base, parser->m_declEntity->systemId, + parser->m_declEntity->publicId, parser->m_declEntity->notation); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-15.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-15.patch new file mode 100644 index 0000000000..07e69cb772 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-15.patch @@ -0,0 +1,82 @@ +From e5035de264c3102b33891570bdff7c6313a9d2b5 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sat, 30 May 2026 00:45:50 +0200 +Subject: [PATCH] lib: Register `m_externalEntityRefHandler` with handler call + depth tracking + +(cherry picked from commit d4ba1c29165de39605b799223392dfb28bed85d5) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/d4ba1c29165de39605b799223392dfb28bed85d5] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index e9466d5..7909490 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3537,9 +3537,11 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + entity->open = XML_FALSE; + if (! context) + return XML_ERROR_NO_MEMORY; ++ beforeHandler(parser); + const int status = parser->m_externalEntityRefHandler( + parser->m_externalEntityRefHandlerArg, context, entity->base, + entity->systemId, entity->publicId); ++ afterHandler(parser); + if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + poolDiscard(&parser->m_tempPool); +@@ -5571,9 +5573,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (parser->m_useForeignDTD) + entity->base = parser->m_curBase; + dtd->paramEntityRead = XML_FALSE; ++ beforeHandler(parser); + const int status = parser->m_externalEntityRefHandler( + parser->m_externalEntityRefHandlerArg, 0, entity->base, + entity->systemId, entity->publicId); ++ afterHandler(parser); + if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { +@@ -5617,9 +5621,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + return XML_ERROR_NO_MEMORY; + entity->base = parser->m_curBase; + dtd->paramEntityRead = XML_FALSE; ++ beforeHandler(parser); + const int status = parser->m_externalEntityRefHandler( + parser->m_externalEntityRefHandlerArg, 0, entity->base, + entity->systemId, entity->publicId); ++ afterHandler(parser); + if (! status) + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { +@@ -6222,9 +6228,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + dtd->paramEntityRead = XML_FALSE; + entity->open = XML_TRUE; + entityTrackingOnOpen(parser, entity, __LINE__); ++ beforeHandler(parser); + const int status = parser->m_externalEntityRefHandler( + parser->m_externalEntityRefHandlerArg, 0, entity->base, + entity->systemId, entity->publicId); ++ afterHandler(parser); + if (! status) { + entityTrackingOnClose(parser, entity, __LINE__); + entity->open = XML_FALSE; +@@ -7019,9 +7027,11 @@ storeEntityValue(XML_Parser parser, const ENCODING *enc, + dtd->paramEntityRead = XML_FALSE; + entity->open = XML_TRUE; + entityTrackingOnOpen(parser, entity, __LINE__); ++ beforeHandler(parser); + const int status = parser->m_externalEntityRefHandler( + parser->m_externalEntityRefHandlerArg, 0, entity->base, + entity->systemId, entity->publicId); ++ afterHandler(parser); + if (! status) { + entityTrackingOnClose(parser, entity, __LINE__); + entity->open = XML_FALSE; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-16.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-16.patch new file mode 100644 index 0000000000..3cc3f7faaf --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-16.patch @@ -0,0 +1,46 @@ +From 24ec73df3f099032fb66638685c296c18d914f84 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:27:13 +0200 +Subject: [PATCH] lib: Register `m_notationDeclHandler` with handler call depth + tracking + +(cherry picked from commit 4739ad3fda250cf458d396d9c17a0e0fef571bdd) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/4739ad3fda250cf458d396d9c17a0e0fef571bdd] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 7909490..5a0f063 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -6040,9 +6040,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + if (! systemId) + return XML_ERROR_NO_MEMORY; + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_notationDeclHandler( + parser->m_handlerArg, parser->m_declNotationName, parser->m_curBase, + systemId, parser->m_declNotationPublicId); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + poolClear(&parser->m_tempPool); +@@ -6050,9 +6052,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + case XML_ROLE_NOTATION_NO_SYSTEM_ID: + if (parser->m_declNotationPublicId && parser->m_notationDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_notationDeclHandler( + parser->m_handlerArg, parser->m_declNotationName, parser->m_curBase, + 0, parser->m_declNotationPublicId); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + poolClear(&parser->m_tempPool); +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-17.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-17.patch new file mode 100644 index 0000000000..992ae93d6e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-17.patch @@ -0,0 +1,64 @@ +From 08eea37057ebc8f6dafcec601b0ff923d221e205 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:34:29 +0200 +Subject: [PATCH] lib: Register `m_notStandaloneHandler` with handler call + depth tracking + +(cherry picked from commit d7a9c975ceeaa24c730e50fef2bedff5f99d2172) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/d7a9c975ceeaa24c730e50fef2bedff5f99d2172] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 5a0f063..93110fe 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5582,8 +5582,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { + if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ beforeHandler(parser); + const int handlerStatus + = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ afterHandler(parser); + if (! handlerStatus) + return XML_ERROR_NOT_STANDALONE; + } +@@ -5630,8 +5632,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + return XML_ERROR_EXTERNAL_ENTITY_HANDLING; + if (dtd->paramEntityRead) { + if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ beforeHandler(parser); + const int handlerStatus + = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ afterHandler(parser); + if (! handlerStatus) + return XML_ERROR_NOT_STANDALONE; + } +@@ -5857,7 +5861,9 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + && ! parser->m_paramEntityParsing + #endif /* XML_DTD */ + && parser->m_notStandaloneHandler) { ++ beforeHandler(parser); + const int status = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ afterHandler(parser); + if (! status) + return XML_ERROR_NOT_STANDALONE; + } +@@ -6256,7 +6262,9 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + } + #endif /* XML_DTD */ + if (! dtd->standalone && parser->m_notStandaloneHandler) { ++ beforeHandler(parser); + const int status = parser->m_notStandaloneHandler(parser->m_handlerArg); ++ afterHandler(parser); + if (! status) + return XML_ERROR_NOT_STANDALONE; + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-18.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-18.patch new file mode 100644 index 0000000000..4520cbd13a --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-18.patch @@ -0,0 +1,32 @@ +From d9ea54153ef454217b8a2a8255b2bd1ead460e83 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:35:08 +0200 +Subject: [PATCH] lib: Register `m_processingInstructionHandler` with handler + call depth tracking + +(cherry picked from commit 8bb00d345d5f92b17a06e01a926ee1dda797e0af) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/8bb00d345d5f92b17a06e01a926ee1dda797e0af] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 93110fe..b2672ae 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -7298,7 +7298,9 @@ reportProcessingInstruction(XML_Parser parser, const ENCODING *enc, + if (! data) + return 0; + normalizeLines(data); ++ beforeHandler(parser); + parser->m_processingInstructionHandler(parser->m_handlerArg, target, data); ++ afterHandler(parser); + poolClear(&parser->m_tempPool); + return 1; + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-19.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-19.patch new file mode 100644 index 0000000000..6d6e2cf2d4 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-19.patch @@ -0,0 +1,87 @@ +From 1cbb5676ee24c03222923f2ce853ffe245a831ad Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:36:39 +0200 +Subject: [PATCH] lib: Register `m_skippedEntityHandler` with handler call + depth tracking + +(cherry picked from commit 64e3adf0c9d7e1846cff784de3159f1067eb5e06) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/64e3adf0c9d7e1846cff784de3159f1067eb5e06] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 24 ++++++++++++++++++------ + 1 file changed, 18 insertions(+), 6 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index b2672ae..1ee7cca 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3507,9 +3507,11 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + else if (! entity->is_internal) + return XML_ERROR_ENTITY_DECLARED_IN_PE; + } else if (! entity) { +- if (parser->m_skippedEntityHandler) ++ if (parser->m_skippedEntityHandler) { ++ beforeHandler(parser); + parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0); +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + break; + } +@@ -3520,10 +3522,12 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + if (entity->textPtr) { + enum XML_Error result; + if (! parser->m_defaultExpandInternalEntities) { +- if (parser->m_skippedEntityHandler) ++ if (parser->m_skippedEntityHandler) { ++ beforeHandler(parser); + parser->m_skippedEntityHandler(parser->m_handlerArg, entity->name, + 0); +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + break; + } +@@ -6217,7 +6221,9 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + /* cannot report skipped entities in declarations */ + if ((role == XML_ROLE_PARAM_ENTITY_REF) + && parser->m_skippedEntityHandler) { ++ beforeHandler(parser); + parser->m_skippedEntityHandler(parser->m_handlerArg, name, 1); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } + break; +@@ -6888,8 +6894,11 @@ appendAttributeValue(XML_Parser parser, const ENCODING *enc, XML_Bool isCdata, + } else if (! entity) { + /* Cannot report skipped entity here - see comments on + parser->m_skippedEntityHandler. +- if (parser->m_skippedEntityHandler) ++ if (parser->m_skippedEntityHandler) { ++ beforeHandler(parser); + parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0); ++ afterHandler(parser); ++ } + */ + /* Cannot call the default handler because this would be + out of sync with the call to the startElementHandler. +@@ -7022,8 +7031,11 @@ storeEntityValue(XML_Parser parser, const ENCODING *enc, + /* not a well-formedness error - see XML 1.0: WFC Entity Declared */ + /* cannot report skipped entity here - see comments on + parser->m_skippedEntityHandler +- if (parser->m_skippedEntityHandler) ++ if (parser->m_skippedEntityHandler) { ++ beforeHandler(parser); + parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0); ++ afterHandler(parser); ++ } + */ + dtd->keepProcessing = dtd->standalone; + goto endEntityValue; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-20.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-20.patch new file mode 100644 index 0000000000..e36403367e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-20.patch @@ -0,0 +1,62 @@ +From 6697406736678ac3f6738f5b171c4c128b66df7d Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:37:49 +0200 +Subject: [PATCH] lib: Register `m_startCdataSectionHandler` with handler call + depth tracking + +(cherry picked from commit 222278ad452d27f8c35ba031be14d6e70aab5ab1) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/222278ad452d27f8c35ba031be14d6e70aab5ab1] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 32 +++++++++++++++++--------------- + 1 file changed, 17 insertions(+), 15 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 1ee7cca..ad8cc44 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3766,22 +3766,24 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + break; + case XML_TOK_CDATA_SECT_OPEN: { + enum XML_Error result; +- if (parser->m_startCdataSectionHandler) ++ if (parser->m_startCdataSectionHandler) { ++ beforeHandler(parser); + parser->m_startCdataSectionHandler(parser->m_handlerArg); +- /* BEGIN disabled code */ +- /* Suppose you doing a transformation on a document that involves +- changing only the character data. You set up a defaultHandler +- and a characterDataHandler. The defaultHandler simply copies +- characters through. The characterDataHandler does the +- transformation and writes the characters out escaping them as +- necessary. This case will fail to work if we leave out the +- following two lines (because & and < inside CDATA sections will +- be incorrectly escaped). +- +- However, now we have a start/endCdataSectionHandler, so it seems +- easier to let the user deal with this. +- */ +- else if ((0) && parser->m_characterDataHandler) { ++ afterHandler(parser); ++ /* BEGIN disabled code */ ++ /* Suppose you doing a transformation on a document that involves ++ changing only the character data. You set up a defaultHandler ++ and a characterDataHandler. The defaultHandler simply copies ++ characters through. The characterDataHandler does the ++ transformation and writes the characters out escaping them as ++ necessary. This case will fail to work if we leave out the ++ following two lines (because & and < inside CDATA sections will ++ be incorrectly escaped). ++ ++ However, now we have a start/endCdataSectionHandler, so it seems ++ easier to let the user deal with this. ++ */ ++ } else if ((0) && parser->m_characterDataHandler) { + beforeHandler(parser); + parser->m_characterDataHandler(parser->m_handlerArg, parser->m_dataBuf, + 0); +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-21.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-21.patch new file mode 100644 index 0000000000..bbeeced76e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-21.patch @@ -0,0 +1,46 @@ +From c7cc71e323ef0afcb115dd1567bf1bdfcbc5f8d2 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:38:47 +0200 +Subject: [PATCH] lib: Register `m_startDoctypeDeclHandler` with handler call + depth tracking + +(cherry picked from commit 82f1d14a033f7c5bd6f658c3cdcd2515efe86745) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/82f1d14a033f7c5bd6f658c3cdcd2515efe86745] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index ad8cc44..0e101af 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5481,9 +5481,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + break; + case XML_ROLE_DOCTYPE_INTERNAL_SUBSET: + if (parser->m_startDoctypeDeclHandler) { ++ beforeHandler(parser); + parser->m_startDoctypeDeclHandler( + parser->m_handlerArg, parser->m_doctypeName, parser->m_doctypeSysid, + parser->m_doctypePubid, 1); ++ afterHandler(parser); + parser->m_doctypeName = NULL; + poolClear(&parser->m_tempPool); + handleDefault = XML_FALSE; +@@ -5550,9 +5552,11 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + } + + if (parser->m_doctypeName) { ++ beforeHandler(parser); + parser->m_startDoctypeDeclHandler( + parser->m_handlerArg, parser->m_doctypeName, parser->m_doctypeSysid, + parser->m_doctypePubid, 0); ++ afterHandler(parser); + poolClear(&parser->m_tempPool); + handleDefault = XML_FALSE; + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-22.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-22.patch new file mode 100644 index 0000000000..931bc06f1a --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-22.patch @@ -0,0 +1,48 @@ +From 355e3aaa79f1b0e6067a8ebbc6fcbac47e98542e Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:39:38 +0200 +Subject: [PATCH] lib: Register `m_startElementHandler` with handler call depth + tracking + +(cherry picked from commit 4f9a8f1cc2ed03cd9e23d281a6abac44dc89e8ab) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/4f9a8f1cc2ed03cd9e23d281a6abac44dc89e8ab] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 0e101af..a222a3f 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -3615,10 +3615,12 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + = storeAtts(parser, enc, s, &(tag->name), &(tag->bindings), account); + if (result) + return result; +- if (parser->m_startElementHandler) ++ if (parser->m_startElementHandler) { ++ beforeHandler(parser); + parser->m_startElementHandler(parser->m_handlerArg, tag->name.str, + (const XML_Char **)parser->m_atts); +- else if (parser->m_defaultHandler) ++ afterHandler(parser); ++ } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + poolClear(&parser->m_tempPool); + break; +@@ -3644,8 +3646,10 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, + } + poolFinish(&parser->m_tempPool); + if (parser->m_startElementHandler) { ++ beforeHandler(parser); + parser->m_startElementHandler(parser->m_handlerArg, name.str, + (const XML_Char **)parser->m_atts); ++ afterHandler(parser); + noElmHandlers = XML_FALSE; + } + if (parser->m_endElementHandler) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-23.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-23.patch new file mode 100644 index 0000000000..7f883faeb1 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-23.patch @@ -0,0 +1,36 @@ +From ac747d83eb8b6d7c71da606a9cb1a65aef50d0c1 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:40:13 +0200 +Subject: [PATCH] lib: Register `m_startNamespaceDeclHandler` with handler call + depth tracking + +(cherry picked from commit ddd0238420113c97594083194e517e8bc742700c) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/ddd0238420113c97594083194e517e8bc742700c] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index a222a3f..267a198 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -4704,9 +4704,12 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, + b->nextTagBinding = *bindingsPtr; + *bindingsPtr = b; + /* if attId == NULL then we are not starting a namespace scope */ +- if (attId && parser->m_startNamespaceDeclHandler) ++ if (attId && parser->m_startNamespaceDeclHandler) { ++ beforeHandler(parser); + parser->m_startNamespaceDeclHandler(parser->m_handlerArg, prefix->name, + prefix->binding ? uri : 0); ++ afterHandler(parser); ++ } + return XML_ERROR_NONE; + } + +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-24.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-24.patch new file mode 100644 index 0000000000..9f4e938218 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-24.patch @@ -0,0 +1,33 @@ +From 36ada7e4ef06aa18765557240fb30a1a669d438a Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sat, 30 May 2026 00:46:47 +0200 +Subject: [PATCH] lib: Register `m_unknownEncodingHandler` with handler call + depth tracking + +(cherry picked from commit f66d83c9aecaa802174f95a1348a89f56e3b9441) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/f66d83c9aecaa802174f95a1348a89f56e3b9441] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 267a198..c76f8ea 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5109,8 +5109,10 @@ handleUnknownEncoding(XML_Parser parser, const XML_Char *encodingName) { + info.convert = NULL; + info.data = NULL; + info.release = NULL; ++ beforeHandler(parser); + const int status = parser->m_unknownEncodingHandler( + parser->m_unknownEncodingHandlerData, encodingName, &info); ++ afterHandler(parser); + if (status) { + ENCODING *enc; + parser->m_unknownEncodingMem = MALLOC(parser, XmlSizeOfUnknownEncoding()); +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-25.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-25.patch new file mode 100644 index 0000000000..ab8a94c02c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-25.patch @@ -0,0 +1,35 @@ +From 002404e9805e4e685ca4c473a9c057a93c5b50e2 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:41:00 +0200 +Subject: [PATCH] lib: Register `m_unparsedEntityDeclHandler` with handler call + depth tracking + +(cherry picked from commit 6e7c5af75a743c609fdb35627554cc7e940e6593) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/6e7c5af75a743c609fdb35627554cc7e940e6593] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index c76f8ea..aebcda3 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5946,10 +5946,12 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, + poolFinish(&dtd->pool); + if (parser->m_unparsedEntityDeclHandler) { + *eventEndPP = s; ++ beforeHandler(parser); + parser->m_unparsedEntityDeclHandler( + parser->m_handlerArg, parser->m_declEntity->name, + parser->m_declEntity->base, parser->m_declEntity->systemId, + parser->m_declEntity->publicId, parser->m_declEntity->notation); ++ afterHandler(parser); + handleDefault = XML_FALSE; + } else if (parser->m_entityDeclHandler) { + *eventEndPP = s; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-26.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-26.patch new file mode 100644 index 0000000000..a40a613eba --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-26.patch @@ -0,0 +1,33 @@ +From 646eb417403a714ecd962f85a2d3c4b198f9b44b Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 21:41:38 +0200 +Subject: [PATCH] lib: Register `m_xmlDeclHandler` with handler call depth + tracking + +(cherry picked from commit 91484ffb98ec138df79265e431a55823bc80c6c4) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/91484ffb98ec138df79265e431a55823bc80c6c4] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index aebcda3..edaf5f8 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -5058,8 +5058,10 @@ processXmlDecl(XML_Parser parser, int isGeneralTextEntity, const char *s, + if (! storedversion) + return XML_ERROR_NO_MEMORY; + } ++ beforeHandler(parser); + parser->m_xmlDeclHandler(parser->m_handlerArg, storedversion, storedEncName, + standalone); ++ afterHandler(parser); + } else if (parser->m_defaultHandler) + reportDefault(parser, parser->m_encoding, s, next); + if (parser->m_protocolEncodingName == NULL) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-27.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-27.patch new file mode 100644 index 0000000000..e3eff545cc --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-27.patch @@ -0,0 +1,30 @@ +From 640fa889d24387ba5ad4e44d89a6440b927f6f45 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:35:27 +0200 +Subject: [PATCH] lib: Protect `XML_GetBuffer` from being called from a handler + +(cherry picked from commit 5d90d1aebfe606af2550e92983cbe121d7eda032) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/5d90d1aebfe606af2550e92983cbe121d7eda032] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index edaf5f8..d729fc7 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -2599,7 +2599,7 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) { + + void *XMLCALL + XML_GetBuffer(XML_Parser parser, int len) { +- if (parser == NULL) ++ if ((parser == NULL) || isCalledFromInsideHandler(parser)) + return NULL; + if (len < 0) { + parser->m_errorCode = XML_ERROR_NO_MEMORY; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-28.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-28.patch new file mode 100644 index 0000000000..1a923a111c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-28.patch @@ -0,0 +1,30 @@ +From b6281b0d445029cad63a2eeb0fda9c6aaa8ad690 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:32:38 +0200 +Subject: [PATCH] lib: Protect `XML_Parse` from being called from a handler + +(cherry picked from commit b59f1865e6c0c0ab2c1623b9dfd53aa6fb85bb96) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/b59f1865e6c0c0ab2c1623b9dfd53aa6fb85bb96] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index d729fc7..f69e32c 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -2414,6 +2414,8 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { + parser->m_errorCode = XML_ERROR_INVALID_ARGUMENT; + return XML_STATUS_ERROR; + } ++ if (isCalledFromInsideHandler(parser)) ++ return XML_STATUS_ERROR; + switch (parser->m_parsingStatus.parsing) { + case XML_SUSPENDED: + parser->m_errorCode = XML_ERROR_SUSPENDED; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-29.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-29.patch new file mode 100644 index 0000000000..02e172bfa9 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-29.patch @@ -0,0 +1,31 @@ +From 3ea9955feaa8db08300c83de24ab8001aef19077 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:33:44 +0200 +Subject: [PATCH] lib: Protect `XML_ParseBuffer` from being called from a + handler + +(cherry picked from commit ef3267d5f8157862e33d87c45c6fe82ac26e557f) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/ef3267d5f8157862e33d87c45c6fe82ac26e557f] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index f69e32c..87c20bf 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -2525,7 +2525,7 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) { + const char *start; + enum XML_Status result = XML_STATUS_OK; + +- if (parser == NULL) ++ if ((parser == NULL) || isCalledFromInsideHandler(parser)) + return XML_STATUS_ERROR; + + if (len < 0) { +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-30.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-30.patch new file mode 100644 index 0000000000..2b7402ae5c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-30.patch @@ -0,0 +1,31 @@ +From 69fc1130413313ecd8728573a254bd26afebd632 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:21:28 +0200 +Subject: [PATCH] lib: Protect `XML_ParserFree` from being called from a + handler + +(cherry picked from commit 827fbddcaaa8ba2171ef76a3223d6f403388635c) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/827fbddcaaa8ba2171ef76a3223d6f403388635c] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 87c20bf..bfa3217 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -1958,7 +1958,7 @@ void XMLCALL + XML_ParserFree(XML_Parser parser) { + TAG *tagList; + OPEN_INTERNAL_ENTITY *entityList; +- if (parser == NULL) ++ if ((parser == NULL) || isCalledFromInsideHandler(parser)) + return; + /* free m_tagStack and m_freeTagList */ + tagList = parser->m_tagStack; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-31.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-31.patch new file mode 100644 index 0000000000..1fc8877a3e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-31.patch @@ -0,0 +1,31 @@ +From e7ea42e0111e697d2de64a94c8fd6bca9d2c99c9 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Tue, 26 May 2026 15:22:41 +0200 +Subject: [PATCH] lib: Protect `XML_ParserReset` from being called from a + handler + +(cherry picked from commit 34bc7e080a1b432ad9d6879a6c718f2d6f12fa22) + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/34bc7e080a1b432ad9d6879a6c718f2d6f12fa22] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index bfa3217..cc1d550 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -1671,7 +1671,7 @@ XML_ParserReset(XML_Parser parser, const XML_Char *encodingName) { + TAG *tStk; + OPEN_INTERNAL_ENTITY *openEntityList; + +- if (parser == NULL) ++ if ((parser == NULL) || isCalledFromInsideHandler(parser)) + return XML_FALSE; + + if (parser->m_parentParser) +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat/CVE-2026-50219-32.patch b/meta/recipes-core/expat/expat/CVE-2026-50219-32.patch new file mode 100644 index 0000000000..30a73f9bf5 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-50219-32.patch @@ -0,0 +1,100 @@ +From 8683ba1631c0467f78f512b16a8dfd1ea9636538 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sun, 31 May 2026 13:37:01 +0200 +Subject: [PATCH] tests: Cover calls forbidden from handlers + +(cherry picked from commit 2e16f4c98f1f28bb9da36108b60c181d77752acb) + +Add an explicit cast for compatibility with Expat's C++ test build, which +includes handlers.c from handlers_cxx.cpp. + +CVE: CVE-2026-50219 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1246/commits/2e16f4c98f1f28bb9da36108b60c181d77752acb] +Signed-off-by: Jakub Szczudlo +--- + tests/handlers.c | 24 ++++++++++++++++++++++++ + tests/handlers.h | 4 ++++ + tests/misc_tests.c | 15 +++++++++++++++ + 3 files changed, 43 insertions(+) + +diff --git a/tests/handlers.c b/tests/handlers.c +index 8cda3a8..c7d6578 100644 +--- a/tests/handlers.c ++++ b/tests/handlers.c +@@ -1991,3 +1991,27 @@ accumulate_and_suspend_comment_handler(void *userData, const XML_Char *data) { + accumulate_comment(parserPlusStorage->storage, data); + XML_StopParser(parserPlusStorage->parser, XML_TRUE); + } ++ ++void XMLCALL ++forbidden_calls_character_handler(void *userData, const XML_Char *s, int len) { ++ UNUSED_P(s); ++ UNUSED_P(len); ++ XML_Parser parser = (XML_Parser)userData; ++ ++ assert_true(parser != NULL); // self-test ++ ++ assert_true(XML_GetBuffer(parser, 123) == NULL); // i.e. rejected ++ ++ assert_true(XML_Parse(parser, "", 0, /*isFinal=*/XML_FALSE) ++ == XML_STATUS_ERROR); // i.e. rejected ++ ++ assert_true(XML_ParseBuffer(parser, 0, /*isFinal=*/XML_FALSE) ++ == XML_STATUS_ERROR); // i.e. rejected ++ ++ XML_ParserFree(parser); // rejected ++ ++ assert_true(XML_ParserReset(parser, /*encodingName=*/NULL) ++ == XML_FALSE); // i.e. rejected ++ ++ assert_true(XML_GetErrorCode(parser) == XML_ERROR_NONE); ++} +diff --git a/tests/handlers.h b/tests/handlers.h +index 27a53f2..de28392 100644 +--- a/tests/handlers.h ++++ b/tests/handlers.h +@@ -612,6 +612,10 @@ typedef struct { + extern void XMLCALL + accumulate_and_suspend_comment_handler(void *userData, const XML_Char *data); + ++extern void XMLCALL forbidden_calls_character_handler(void *userData, ++ const XML_Char *s, ++ int len); ++ + #endif /* XML_HANDLERS_H */ + + #ifdef __cplusplus +diff --git a/tests/misc_tests.c b/tests/misc_tests.c +index 1c508bd..b9053fe 100644 +--- a/tests/misc_tests.c ++++ b/tests/misc_tests.c +@@ -801,6 +801,20 @@ START_TEST(test_misc_no_infinite_loop_issue_1161) { + } + END_TEST + ++START_TEST(test_misc_calls_forbidden_from_handlers) { ++ const char *const doc = "Hello world!"; ++ ++ XML_Parser parser = XML_ParserCreate(NULL); ++ XML_UseParserAsHandlerArg(parser); ++ XML_SetCharacterDataHandler(parser, forbidden_calls_character_handler); ++ ++ assert_true(XML_Parse(parser, doc, (int)strlen(doc), /*isFinal=*/XML_TRUE) ++ == XML_STATUS_OK); ++ ++ XML_ParserFree(parser); ++} ++END_TEST ++ + void + make_miscellaneous_test_case(Suite *s) { + TCase *tc_misc = tcase_create("miscellaneous tests"); +@@ -832,4 +846,5 @@ make_miscellaneous_test_case(Suite *s) { + tcase_add_test(tc_misc, test_misc_sync_entity_tolerated); + tcase_add_test(tc_misc, test_misc_async_entity_rejected); + tcase_add_test(tc_misc, test_misc_no_infinite_loop_issue_1161); ++ tcase_add_test(tc_misc, test_misc_calls_forbidden_from_handlers); + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 890ee5b7d3..7f00c6f90b 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -36,6 +36,38 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-56132_p3.patch;striplevel=2 \ file://CVE-2026-56132_p4.patch;striplevel=2 \ file://CVE-2026-56132_p5.patch;striplevel=2 \ + file://CVE-2026-50219-01.patch \ + file://CVE-2026-50219-02.patch \ + file://CVE-2026-50219-03.patch \ + file://CVE-2026-50219-04.patch \ + file://CVE-2026-50219-05.patch \ + file://CVE-2026-50219-06.patch \ + file://CVE-2026-50219-07.patch \ + file://CVE-2026-50219-08.patch \ + file://CVE-2026-50219-09.patch \ + file://CVE-2026-50219-10.patch \ + file://CVE-2026-50219-11.patch \ + file://CVE-2026-50219-12.patch \ + file://CVE-2026-50219-13.patch \ + file://CVE-2026-50219-14.patch \ + file://CVE-2026-50219-15.patch \ + file://CVE-2026-50219-16.patch \ + file://CVE-2026-50219-17.patch \ + file://CVE-2026-50219-18.patch \ + file://CVE-2026-50219-19.patch \ + file://CVE-2026-50219-20.patch \ + file://CVE-2026-50219-21.patch \ + file://CVE-2026-50219-22.patch \ + file://CVE-2026-50219-23.patch \ + file://CVE-2026-50219-24.patch \ + file://CVE-2026-50219-25.patch \ + file://CVE-2026-50219-26.patch \ + file://CVE-2026-50219-27.patch \ + file://CVE-2026-50219-28.patch \ + file://CVE-2026-50219-29.patch \ + file://CVE-2026-50219-30.patch \ + file://CVE-2026-50219-31.patch \ + file://CVE-2026-50219-32.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Mon Aug 24 15:20:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Jakub Szczudlo (Nokia)" X-Patchwork-Id: 96189 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D8395C5DF9B for ; Mon, 24 Aug 2026 15:20:43 +0000 (UTC) Received: from GVXPR05CU001.outbound.protection.outlook.com (GVXPR05CU001.outbound.protection.outlook.com [52.101.83.30]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.92.1787584841778568195 for ; Mon, 24 Aug 2026 08:20:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@nokia.com header.s=selector1 header.b=lVBuQ++2; spf=permerror, err=parse error for token &{10 18 %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email}: invalid domain name (domain: nokia.com, ip: 52.101.83.30, mailfrom: jakub.szczudlo@nokia.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=UhjEZ7bZLd8ZZjrydLxTMCUf7iFLDYRl0whj1jKdE+5BuWSVDOE8EAnonOarWL+E5AYiq+eym+9o9xLX+jpECBJwDFbQfj67xBip4clqz6v/QCqUVZinFOAtLxiYvdWW4lTzzvtdMRa+tvdde6q3VQnUrJ4Fmg7QCkJD8hu4QMT+vpPwkk1Fw/9YMK/IyD9HWhWEYagrh5HRuLT2p+z76fif8/CFEyiE0c7HLfLYoWkshQa3t82Avth8To+htZ7cIPcpLNpwdoBZ1VKp4CK6NJR6jUxiiVp/cPhDJxtklGrSWy7NRTZ+ktRfDU2c+R/mdwUttI8WMh+VY6Lb97+B+A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=DZ7+oM0Sr7dXlgBaRRaR2jOqoFn4yH2aI3XAI+upIL4=; b=J7LXpZ/CAAB+/lX9zud9aq7IT1F6ZYnEvG5BSuwe9hs8c+1JDwNVJziIz49syRXRFoFv/z6PufGHwlvel4qrpHm26+CMVKMA6Xdq8/hR+//rPLh1dkytDhhbm8SlBChVKE3N5JC7zZIEdvp8n43OEFOPLowlXUBmzOZGwrguzhbp+20p0wsjRDXTh7GI0Gb9FHq94uceIdIIlr9IdDNrnsMBgLW2FBsGf35Dvt594GtfSPP8Re89z9B+FzVgQubp/hmqwShsCflE9AfhzkM43YP6pKaJO3bxo7EaVS6vcrSMZHu1NWOycHL7NBi4VIAjje6gV+YaPx535kOjc0fZ+g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=DZ7+oM0Sr7dXlgBaRRaR2jOqoFn4yH2aI3XAI+upIL4=; b=lVBuQ++28J7+RwjmQWTdF8/bHdOTWP4SuC+gQxbs74QwXbhId7QNzQT0Sr5YbX92c3PA2hxQeaceaawb3e1tOvEhZiyVY+JtOz2i+UYtPVjgN/zfjZw4e9BdIU2dVhPobFMfjm22zq4qg2VkKDn3zLYHhDQ9dEKO86CtP2zGGWE0A2ylLdemRmIR1v/t49TS46Kb0+VXrgOTSnM232Auj+A1C+2ZpgPcqLpcOGjRfUsQnxiD4Jxy2CQk5g2ApM2RUcKH97LyMRbh4j4Fx2amWwBaEIDKVbMeWu4iadwatDimAnmxHAPHdtptL8IFUeXENf896t063sj9VpgOFcSKxQ== Received: from GV2PR07MB11919.eurprd07.prod.outlook.com (2603:10a6:150:357::20) by DUZPR07MB9935.eurprd07.prod.outlook.com (2603:10a6:10:4ae::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.6; Mon, 24 Aug 2026 15:20:37 +0000 Received: from GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680]) by GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680%3]) with mapi id 15.21.0360.005; Mon, 24 Aug 2026 15:20:36 +0000 From: "Jakub Szczudlo (Nokia)" To: "openembedded-core@lists.openembedded.org" CC: "yoann.congal@smile.fr" , "Jakub Szczudlo (Nokia)" Subject: [wrynose][PATCH 2/3] expat: fix CVE-2026-56131 Thread-Topic: [wrynose][PATCH 2/3] expat: fix CVE-2026-56131 Thread-Index: AQHdM9wd/uQf9+gNwEeHqDqyjkjk2g== Date: Mon, 24 Aug 2026 15:20:36 +0000 Message-ID: <20260824152023.19501-2-jakub.szczudlo@nokia.com> References: <20260824152023.19501-1-jakub.szczudlo@nokia.com> In-Reply-To: <20260824152023.19501-1-jakub.szczudlo@nokia.com> Accept-Language: en-US, en-150 Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nokia.com; x-ms-publictraffictype: Email x-ms-traffictypediagnostic: GV2PR07MB11919:EE_|DUZPR07MB9935:EE_ x-ms-office365-filtering-correlation-id: 9310de8b-e530-4064-bb41-08df01f33fd4 x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|366016|23010399003|376014|1800799024|38070700021|56012099006|11063799006|10067099003|18002099003|22082099003; x-microsoft-antispam-message-info: UPcJZ65Z2ntKCCzByB5aFjsxX2eAPUmRs3h1IHBmV8+I/77dtknst9d2l6Gm7i5Zk3RA3wIqK47/EucbB/DwuTR+znXzSuzNw3oTFEUqEongv8LeAuxt9ssCUAsV10AAK+y6wHIbdbMS50eZtJ9cgyMTVGFOB6AGxwyLlCiqInresL6XtTkmjHqZ7Z+xnKABTRc00qtjq+0SymkZ6niV/ewCplCAKihwJqtbFhg8psLPLhxnnQqthiQdR90WFssQnUd/lqY6E+l5muDKc3UAleciRqyy6rYvPz9qu1NgbwcP+8E2D3iu3sr+Fq5+uwmFxqqSujgyxkY2ZYPPO2cev9V+edv9cmT9SsZy3fN/N617KGotC/IWEDFPBRX3wFfS7r8cW75pqv+brHggYEErbRDlPoPfz9QSEe9QNrxeY6OHeMcWC706f6VAuOEOKbDKMoXw98VGV5nZT3N/t+5vUb7y4zqdfsSQdVT+lePp7xzruWw0teSHFiMLJfFPjvq60h504slD1qXzH8/meSe/XTbvuc6tlx0x5ru6hWAHdGv2Bud3p+yb2uWsoaJuvTEa36Vn1t7JGpBvFbhm6yMhIWSnhK1oBWL2V9f+1U9buUQhaY/b6szsTdZb/u90yj69gC0LiVlZ3ZWjLIRW5kv5NJZFIvr8XO0HBXh1gdJ84Ys= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GV2PR07MB11919.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(376014)(1800799024)(38070700021)(56012099006)(11063799006)(10067099003)(18002099003)(22082099003);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?q?337RHDHj1i7nDbXP02CMwYW?= =?iso-8859-1?q?+/Y6Lg3FYsd4LQFM6hJ1ZJIFvg405jZQDC5tVUIDsW7WqAz+rsU8LF6HYhyz?= =?iso-8859-1?q?oawhoPUziOkxdjyTaE2QoGjkxyC3oyJRC3sijm8t8frNiCyHMchZz8KLsdhe?= =?iso-8859-1?q?2yTNtPQJWlMlgVSJD8xPaYoiLLfq48wJC3qTA3nKkoX7CKUWpYIkz3hj29cn?= =?iso-8859-1?q?fXl24ExxDCGhsljqWQoMjwi20/xArWhVAy/of66tM6N0e/0ja8cv2/eaOOHj?= =?iso-8859-1?q?ERLiZPYAvmUXAwrvPBfhCcP+B+/tjGvmuH34F/Lkf2vLDfUX4IuLBLTTuxtw?= =?iso-8859-1?q?cTz5KUBsYKbEyCMc05/fdoDg6CfWO/IwShclrtZ0YR8Kiivl+f7FV7OGs/Pc?= =?iso-8859-1?q?fPOkH5IBDKAhsnZ0UgC8ySzvjCW/F4sDwIznVpuNaOzr0Wr9pS7PkNdxTorZ?= =?iso-8859-1?q?YFC5qmAEk3py9qyDvrL+dGlSPpW2KBGydkBlVHgms6VI3xMT3yOCMkEKvToL?= =?iso-8859-1?q?ldJ7tDV+JScySoSp4KtRo/+hVTja25V+juaNsElYFAHdd4k9bPurofVKlom7?= =?iso-8859-1?q?B0uv+/zE15LXywCm2qYYB73J+rpBwvUmy1sJtegjMxeS/SeuZYhC1MbqE6DW?= =?iso-8859-1?q?NLDpozLYG1Rj/SALyDXd5dS9iAx5+HmhOzAFTsxNc0ZL05d2/fKn/HwExvrl?= =?iso-8859-1?q?KrnXxl8rm8h7U8AjdcNnrYFIkoLfcFKtbjBERutDeqrGUuTz/1ZGTTcO+cCX?= =?iso-8859-1?q?BIq+5yj8sXcChOURDyKseY6DYSJA6qXkuATlx/GVWcKXqEbN+eC6y0MnlBJI?= =?iso-8859-1?q?+LFQbFswEy0c4WqxK+zKRBIJLul6jl/Xuts3qyHSf9JOjX7Jljupd+0bUpK7?= =?iso-8859-1?q?N+QZxQhhMJ79Ytnyb/GPKxPTNYzXxlYS0eswrprA09T2RCc1vf/sz6uNOYvf?= =?iso-8859-1?q?/pO/cLri0BafXQ6LbznwEke7abaJwnA8mLYxMVmn1wygL2/3/qBDdg3m3Pgl?= =?iso-8859-1?q?cvWDJGxHRv67zR5LWbYIIIzoraQNkvtEERRbjpDVjMmUK+++/Nk7c4cS84Hz?= =?iso-8859-1?q?jarjBmE2ABeMXJCXrLIcX3vi2spf6KXlmgdKR4LK31tsDPLofUH3uvpRiaxg?= =?iso-8859-1?q?svD+7KxWgplNX9dPv61QQiUZjx9qVOP6uH1CqSLTpyL6D4tRIFxKUITVEdB6?= =?iso-8859-1?q?i5lO/rJpdvfau3jfUbk+/smJPU8nLlby7i0xEQvponSqDQKY/GxTJuu9U/P1?= =?iso-8859-1?q?Wllhv4kO0iIwpIbWDNtEEWgUeDtYWLaB4oVDyb8jXgoNYyQZMhPwoawXPV9/?= =?iso-8859-1?q?jGgxw00b/p94gyiHts0E1g0hlRHH8zUqF/1arEnWil/8eZSbRQPNBSTr29q/?= =?iso-8859-1?q?xEsZley45CfOoEz7VCOcAsLVGPQHCqtTqA6x+VmQXUvG/GvzEA89ar9eyLwR?= =?iso-8859-1?q?ckbnlIuMxMvUPG2nhN9gLl6Pl2+qd0cJOOj4qfTQDCkkr19tq1I5C+IAf3L4?= =?iso-8859-1?q?7f7Q11DjYnVSzhGm300X5iip4zAfqlBE79+DgXGDtF7mUnxyVhi0bFERKZMY?= =?iso-8859-1?q?JsTINEg1lCjEgJqtoPGVxOIWg0/xCnn9/v5ZNY0yt9Fmqj2mlknMWeL8Hxni?= =?iso-8859-1?q?D28iyFmC5IgxJwmhjkcAZAL8UOjeUkKIL4AFHqoj4z3b5w8SErSUuM8Rb/xQ?= =?iso-8859-1?q?acMeO6dOWKy5X9srx1AtM44A6w12tLfs/tXorAi2/CT/orEK9wFaBdB09LlL?= =?iso-8859-1?q?RS5b56JOkPsnK/pdd7LKwtv9z?= MIME-Version: 1.0 X-OriginatorOrg: nokia.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: GV2PR07MB11919.eurprd07.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 9310de8b-e530-4064-bb41-08df01f33fd4 X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Aug 2026 15:20:36.9460 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: UBAVSBuX2AhdcnB94rA3fycmuLk+tR3O0OlShZqwuTeCbaCv83grI4JxB0aq/e/uN2pDTKSlPOBvZSfbeZMzJkbT04sCLkbIMuOkt/wKbiI= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DUZPR07MB9935 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 15:20:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244131 Backport patch to fix CVE-2026-56131. References: https://nvd.nist.gov/vuln/detail/CVE-2026-56131 Upstream fix: https://github.com/libexpat/libexpat/commit/d5a654b4881f450827af5b3b7b72370a3bbf9a8f Signed-off-by: Jakub Szczudlo --- .../expat/expat/CVE-2026-56131.patch | 124 ++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 125 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56131.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56131.patch b/meta/recipes-core/expat/expat/CVE-2026-56131.patch new file mode 100644 index 0000000000..8691f98f89 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56131.patch @@ -0,0 +1,124 @@ +From 29dfca6ad4d2a9dfd5ce72efd72e1b67d598ab4c Mon Sep 17 00:00:00 2001 +From: netliomax25-code +Date: Sat, 6 Jun 2026 20:03:53 +0530 +Subject: [PATCH] lib: protect XML_ResumeParser from being called from a + handler + +The handler-reentrancy guards from CVE-2026-50219 cover XML_Parse, XML_ParseBuffer, XML_GetBuffer, XML_ParserFree and XML_ParserReset but not XML_ResumeParser, which drives the parser through callProcessor in the same way. + +(cherry picked from commit d5a654b4881f450827af5b3b7b72370a3bbf9a8f) + +CVE: CVE-2026-56131 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1267/commits/d5a654b4881f450827af5b3b7b72370a3bbf9a8f] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 2 +- + tests/handlers.c | 24 ++++++++++++++++++++++++ + tests/handlers.h | 9 +++++++++ + tests/misc_tests.c | 20 ++++++++++++++++++++ + 4 files changed, 54 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index cc1d550..a5fa256 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -2778,7 +2778,7 @@ enum XML_Status XMLCALL + XML_ResumeParser(XML_Parser parser) { + enum XML_Status result = XML_STATUS_OK; + +- if (parser == NULL) ++ if ((parser == NULL) || isCalledFromInsideHandler(parser)) + return XML_STATUS_ERROR; + if (parser->m_parsingStatus.parsing != XML_SUSPENDED) { + parser->m_errorCode = XML_ERROR_NOT_SUSPENDED; +diff --git a/tests/handlers.c b/tests/handlers.c +index c7d6578..5a85f6d 100644 +--- a/tests/handlers.c ++++ b/tests/handlers.c +@@ -2015,3 +2015,27 @@ forbidden_calls_character_handler(void *userData, const XML_Char *s, int len) { + + assert_true(XML_GetErrorCode(parser) == XML_ERROR_NONE); + } ++ ++void XMLCALL ++suspend_then_resume_character_handler(void *userData, const XML_Char *s, ++ int len) { ++ UNUSED_P(s); ++ UNUSED_P(len); ++ ResumeFromHandlerData *const data = (ResumeFromHandlerData *)userData; ++ ++ data->callCount++; ++ if (data->callCount > 1) { ++ // Reached only if the guard under test is missing: XML_ResumeParser would ++ // then have driven the parser re-entrantly and called us again. Bail out ++ // so the test fails by assertion below rather than recursing without bound. ++ return; ++ } ++ ++ // Put the parser into XML_SUSPENDED so that, without the guard, ++ // XML_ResumeParser would proceed into a re-entrant parse. ++ assert_true(XML_StopParser(data->parser, /*resumable=*/XML_TRUE) ++ == XML_STATUS_OK); ++ ++ // Resuming the parser from inside a handler must be rejected. ++ assert_true(XML_ResumeParser(data->parser) == XML_STATUS_ERROR); ++} +diff --git a/tests/handlers.h b/tests/handlers.h +index de28392..507ad8b 100644 +--- a/tests/handlers.h ++++ b/tests/handlers.h +@@ -616,6 +616,15 @@ extern void XMLCALL forbidden_calls_character_handler(void *userData, + const XML_Char *s, + int len); + ++typedef struct { ++ XML_Parser parser; ++ int callCount; ++} ResumeFromHandlerData; ++ ++extern void XMLCALL suspend_then_resume_character_handler(void *userData, ++ const XML_Char *s, ++ int len); ++ + #endif /* XML_HANDLERS_H */ + + #ifdef __cplusplus +diff --git a/tests/misc_tests.c b/tests/misc_tests.c +index b9053fe..265e7cb 100644 +--- a/tests/misc_tests.c ++++ b/tests/misc_tests.c +@@ -815,6 +815,25 @@ START_TEST(test_misc_calls_forbidden_from_handlers) { + } + END_TEST + ++START_TEST(test_misc_resume_parser_forbidden_from_handler) { ++ const char *const doc = "Hello world!"; ++ ++ XML_Parser parser = XML_ParserCreate(NULL); ++ ResumeFromHandlerData data = {parser, 0}; ++ XML_SetUserData(parser, &data); ++ XML_SetCharacterDataHandler(parser, suspend_then_resume_character_handler); ++ ++ // The handler suspends the parser, so the top-level parse reports suspension ++ // rather than completion. The handler also asserts that resuming from inside ++ // itself is rejected. ++ assert_true(XML_Parse(parser, doc, (int)strlen(doc), /*isFinal=*/XML_TRUE) ++ == XML_STATUS_SUSPENDED); ++ assert_true(data.callCount == 1); ++ ++ XML_ParserFree(parser); ++} ++END_TEST ++ + void + make_miscellaneous_test_case(Suite *s) { + TCase *tc_misc = tcase_create("miscellaneous tests"); +@@ -847,4 +866,5 @@ make_miscellaneous_test_case(Suite *s) { + tcase_add_test(tc_misc, test_misc_async_entity_rejected); + tcase_add_test(tc_misc, test_misc_no_infinite_loop_issue_1161); + tcase_add_test(tc_misc, test_misc_calls_forbidden_from_handlers); ++ tcase_add_test(tc_misc, test_misc_resume_parser_forbidden_from_handler); + } +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 7f00c6f90b..78e35243c5 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -68,6 +68,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-50219-30.patch \ file://CVE-2026-50219-31.patch \ file://CVE-2026-50219-32.patch \ + file://CVE-2026-56131.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Mon Aug 24 15:20:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Jakub Szczudlo (Nokia)" X-Patchwork-Id: 96188 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D83EEC5DF9C for ; Mon, 24 Aug 2026 15:20:43 +0000 (UTC) Received: from GVXPR05CU001.outbound.protection.outlook.com (GVXPR05CU001.outbound.protection.outlook.com [52.101.83.30]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.92.1787584841778568195 for ; Mon, 24 Aug 2026 08:20:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@nokia.com header.s=selector1 header.b=g9XUzy8S; spf=permerror, err=parse error for token &{10 18 %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email}: invalid domain name (domain: nokia.com, ip: 52.101.83.30, mailfrom: jakub.szczudlo@nokia.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=uR2DcAkPWznLA74t8fQLabzVtq2NTS6aFuU4y/zO6R39GWRVcPpFA2QSBS8ZCprrjiZogE/FlBiMKkDs2XB21BKmz99PRHvMOhFOym1ZDGu2S76SaxyLWUHkYoCB3sCufZ7cvQubiL7hySmPN1fkAniw0+3O6UzXKhqQvjpl3SufBhoT5rX6USbmMkboHI0XbOiq3ZlT1VrZEOpadb+fbWArKsoXol2qTTy/yPqkUkgtE67VDDv5qpwgyk2e0OZT7nj5YRFe12FC6HQOyMQsl1v3OabvpluELZECmTW+4u1K9rVDaQHjlI9nVgtCSjeOyRH3IJgCvLgZqD/psDgzQA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=9drUwvdeVUlUZzpoPzD0w6RFgtgvE8mubnf4Ycuxavk=; b=PZPDfJiQq2cALvfE0Kch02n8brv5xOSaQ+hX1eEDlx6I/zD6pbnAgb9uvgAP9GMrTk2M1MFLJ3eMZk9q6S5Fx12kceVtrDaGfKg2/qeYx4FY5tm6eJlEgNjKHBCp85OEiS4cZ3PIPH1O7ee/y3nXBZ54S9+LZhJpdWt6k9W0pM0yNfrK+O5hK2Wtf+GyLxy9/TBj7KJRtQnJpPXM2U7W/rkPW4AtbCVYCvvPoqq6ZdQPVZ2PnNoLChQDfZd1wyDUj9vHYZtkNtaBbmTNBp3ALgmtKhZGvb3D7UUWQadSM5LCbvcZN2Yk3pVcNRl4NaTIoKFc3t/MiC2ek1m6FBHXgA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9drUwvdeVUlUZzpoPzD0w6RFgtgvE8mubnf4Ycuxavk=; b=g9XUzy8SttK23AgkySKcEc/v0RtJeADl5zSGfNFnFaFnItfECD6NxzHUhiarDnjX75HjwJNrWsUKbM9fcTQXwS0Qll9ZE6ywD4f3ReVTcOtkFhi1CCdutbJGQlSZF1Qa/WP+63LNWLYBRA4zAH9rD1xyM1bWRbnWGH0B+vSwxkQ6HtO7UJ0jVMhfEHpl2DS/w4p1zZVNJbkgB/h1QWuPo4hUy31SyIEV4Y5mi8Pfnzl9C0GX3bTexjab27h5Rzl9wfpaZWA2f505qiOKziB5XsOBCESCO5ryvk3IF3wGJnCgwznbMGEW4rorYYyisryEhMw5/4kwPmQ02tqNkeNbAQ== Received: from GV2PR07MB11919.eurprd07.prod.outlook.com (2603:10a6:150:357::20) by DUZPR07MB9935.eurprd07.prod.outlook.com (2603:10a6:10:4ae::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.6; Mon, 24 Aug 2026 15:20:40 +0000 Received: from GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680]) by GV2PR07MB11919.eurprd07.prod.outlook.com ([fe80::159a:9a82:1362:e680%3]) with mapi id 15.21.0360.005; Mon, 24 Aug 2026 15:20:40 +0000 From: "Jakub Szczudlo (Nokia)" To: "openembedded-core@lists.openembedded.org" CC: "yoann.congal@smile.fr" , "Jakub Szczudlo (Nokia)" Subject: [wrynose][PATCH 3/3] expat: fix CVE-2026-56412 Thread-Topic: [wrynose][PATCH 3/3] expat: fix CVE-2026-56412 Thread-Index: AQHdM9wf9xefMp8w/kOqGLwOV10IoA== Date: Mon, 24 Aug 2026 15:20:40 +0000 Message-ID: <20260824152023.19501-3-jakub.szczudlo@nokia.com> References: <20260824152023.19501-1-jakub.szczudlo@nokia.com> In-Reply-To: <20260824152023.19501-1-jakub.szczudlo@nokia.com> Accept-Language: en-US, en-150 Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nokia.com; x-ms-publictraffictype: Email x-ms-traffictypediagnostic: GV2PR07MB11919:EE_|DUZPR07MB9935:EE_ x-ms-office365-filtering-correlation-id: 04f4d3e5-177c-4b16-61eb-08df01f341dd x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|366016|23010399003|376014|1800799024|38070700021|56012099006|11063799006|10067099003|18002099003|22082099003; x-microsoft-antispam-message-info: pUfRP9O+Org3+lYuaQD/UtVaXbocaBAgD3Qgo66gdEfkS7/ae6g8iYi5c/HF3OdzyZ8CwoHai5mPDaDPMrJPYNhOJ0Sl5UTCPOl2B76oKGPaqoprvSeGAx0xFmaD+EQWgWYaF4rkzwsWnuHx0e49JWiaNkdI4nqilJY/PZ579GzsrIa0nLwiEysRQhPiKi+3Twt9FwNUkBxz9K1UKa65/vyg0OAxQDphqXZpBSiGExLQwOCZ2f9djCANOgtjfB/vnoqAWRyawEeom1+PTaYxYg7BsZFam0g4wobUog5ls+GPWYtf0Bmap+It0J4Lwaus4B83aPyFGm3YxtUp979hi5/a3/4Ps2Wkt4sN5h7BSkJHTNF/0wetmYJf2dGHYqFQ+ZzApB/bVhFmaAWEfDp4NFMCETViVvQsif75qqVst3phHJ0ogbBHsEPckDVULm/zor/9VjICQ5MZLCL2mL70Xy41juvXbzHR8StuaMyGBEvGKtsc1Lk64uRL747KfprS3IgG7wbxvueQdGlBHUNaT67Fs2Zr9RyyQxRI1nMU1n8ydamPkiJFa2od9nTctH2hqPTcGR0j2LoeFoyHjGm8KOtIyNt6+h+SsxDCaX7JwXdkYe4qR7uzfwmfekOuHX6OoJFWPKA2MWfDWjTLJyl7VvV7xIFcAu1Vu1mm1sv+FQU= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GV2PR07MB11919.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(376014)(1800799024)(38070700021)(56012099006)(11063799006)(10067099003)(18002099003)(22082099003);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?q?0BFMnYi45V8qSUxb191SkuX?= =?iso-8859-1?q?xuHnimRxqz7xXMGW3g6BXSMSlVMFAUlHfojCJ4s+ukUv+Ggn9cYOKhc60NNV?= =?iso-8859-1?q?9Yd27+izA56aQ0d5B7FteO/6Ch1PWDu9VIU1JoiUJIgaKuxpn9qGgEZye+OX?= =?iso-8859-1?q?19R5FyqWtQU3iprHGpdK8mpRXt5nWZMVVsFLEA7kc98rQFT4M/HQEzoY/moU?= =?iso-8859-1?q?IMD6Ti0oeXfJbTV9TZ7byI12QsJpBNPD1nf6m9F4EGql4BreAx76ijtraEiD?= =?iso-8859-1?q?rv11Ts0arvn+n1bsJKJr6rEPoew47QJ11SuqCwyDuSbuV52X5F3gXIeYzpzT?= =?iso-8859-1?q?jKHEWX+PO6yWYDx4Hb2zgdnxm8qVqJfVGFs0ekjBgLG5kTrRzCmU6z1G4k08?= =?iso-8859-1?q?PaJpfpggGXKXmxykG4X0h9mbp32wDClXMdSylXRLzZ48XShs1tDC20k1G3Q4?= =?iso-8859-1?q?lfZd+J48VZ1iBAxvHGdv+1kWBg3cFcNVp7d7RneqE+fcWrcTEkYEz2o4Ev/e?= =?iso-8859-1?q?cMgJsFSoeQ0X7ONVpSkhr7NLV1dJ713NJhFVB9ZzD/kyxuPEVN5rjp8eOe0S?= =?iso-8859-1?q?sE0FQiwUTYW3xeS17s+bDt1usXD7TvIQ7Q4TQrFzUp4gzw2sr1Z1E734TG+j?= =?iso-8859-1?q?lvqhJu8kNPojtfiZ+P7oJeZYf10ftf2TTZf8Tt0NlwQj1yx4IdcRRwhcLXKP?= =?iso-8859-1?q?1jGjf95J8zkLYZlfPDQwcSmT3iEFnXF+jLNfbTYeyK5RKwPkub6ICIn7bk5o?= =?iso-8859-1?q?YgaoVO7E7XYdS+IYkr7llg5UzClWBhoAjZcr8Y60s0JXVnNJrArkQuOMYH+9?= =?iso-8859-1?q?OoPOf83qOWq8zExBTvhPD2ggoqfkWLpl5bfK04Azh6cgd1yZUX41QQizA/3A?= =?iso-8859-1?q?IxetEJae/wwz0/rbFG3AGE0QSVdeo+Blhzf1Qu55zaovntCKlsrN7mgjj9TK?= =?iso-8859-1?q?47W9jpntlHh0F0N+eCSSD0MYoBp5EKl6stPn9zw0GfZofrbvUfYiLq/voURG?= =?iso-8859-1?q?qrFOJwTk0FTztOS4MmFVFqQDp9uPnxIMAwj8MXWXk8GWFINA9t0aPFc20oes?= =?iso-8859-1?q?zKT/7CZlM7M+5OGosSe6HnoHAB8nxcrO8obvajPfVFf8QKMRE8VnRBcHLzqe?= =?iso-8859-1?q?N+G+YJb35ZszCuEf3Qw/cyINaU8tgc6SKr75RAY0x17zkolAzGA/oCCPj8ic?= =?iso-8859-1?q?3k5YboB6HZDqWjRlagZML0WgquIW+ELvd0+mFawJvSyXkP/ezSeFIqKphecA?= =?iso-8859-1?q?eoLzT8LtiyvFdmZzC3rICxgxhMl1RU3NEpQwKaNkqZG503pF/kfR/u5fOy3j?= =?iso-8859-1?q?5AZglUolcSZz3jLGxyRPjyugvdRyZi/xHP4E8bhF7pH6Wi5XCm1B9zIJRaD+?= =?iso-8859-1?q?GWoATHW1PjyH1vfbO43XoDBF/t0iBiBO7Hr33/g39v2C/nNlcqfl/KNd40SK?= =?iso-8859-1?q?1b3FiY4xRS26Rjs5xXi+46eQSHgrHM2CDPQATjJXCeMUMLgk52NOAStM8dqi?= =?iso-8859-1?q?q5ObwMg6ou2fq6CAolZE/B9ZHuCb1uuQTxLSd5kVi2+yeNoIWqd775Xr1Akb?= =?iso-8859-1?q?5RuFpXWOP7GBAe+xNKk3p3NQscZGNTT3nN7JiqnWyg/uz+EEvWz7fDKGst4E?= =?iso-8859-1?q?LwMLNdEiHPEwUi+mDJasFTgjHuvysbyqFiGvXKegS3C+HW/BnfiA8CYVJ1Ui?= =?iso-8859-1?q?qtP+Ep3pNBnP6G6VpkTGN2jiLjzYtzjgQV9fy8v+a4DeWnziqeOTta6C5EpM?= =?iso-8859-1?q?qp8jEzffgXfF0LCSDYTtyta8f?= MIME-Version: 1.0 X-OriginatorOrg: nokia.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: GV2PR07MB11919.eurprd07.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 04f4d3e5-177c-4b16-61eb-08df01f341dd X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Aug 2026 15:20:40.3356 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: rSdHh5QvMyC/WwPRQ0cFlwaPu/IXbteAc1XeHuZr56o04a2VRFlXIV7UB4t9fO9WR5i3lXt6SAMrpZAjzXP37prt9faNCcyySM/l/3lzPWY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DUZPR07MB9935 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 24 Aug 2026 15:20:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244132 Backport patch to fix CVE-2026-56412. References: https://nvd.nist.gov/vuln/detail/CVE-2026-56412 Upstream fix: https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58 Signed-off-by: Jakub Szczudlo --- .../expat/expat/CVE-2026-56412.patch | 45 +++++++++++++++++++ meta/recipes-core/expat/expat_2.7.5.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-56412.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-56412.patch b/meta/recipes-core/expat/expat/CVE-2026-56412.patch new file mode 100644 index 0000000000..8959bdec5c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-56412.patch @@ -0,0 +1,45 @@ +From b94cd5b9a6dc7f938a50db2417e4ff60ed35c4a1 Mon Sep 17 00:00:00 2001 +From: hextheshadow +Date: Sat, 20 Jun 2026 21:07:29 +0500 +Subject: [PATCH] lib: guard XML_TOK_DATA_CHARS handler calls in + doCdataSection() + +(cherry picked from commit d19e834794060d18c061d94452c35d725393ea58) + +CVE: CVE-2026-56412 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1278/commits/d19e834794060d18c061d94452c35d725393ea58] +Signed-off-by: Jakub Szczudlo +--- + lib/xmlparse.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index a5fa256..1476c7e 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -4812,16 +4812,21 @@ doCdataSection(XML_Parser parser, const ENCODING *enc, const char **startPtr, + const enum XML_Convert_Result convert_res = XmlConvert( + enc, &s, next, &dataPtr, (ICHAR *)parser->m_dataBufEnd); + *eventEndPP = next; ++ beforeHandler(parser); + charDataHandler(parser->m_handlerArg, parser->m_dataBuf, + (int)(dataPtr - (ICHAR *)parser->m_dataBuf)); ++ afterHandler(parser); + if ((convert_res == XML_CONVERT_COMPLETED) + || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) + break; + *eventPP = s; + } +- } else ++ } else { ++ beforeHandler(parser); + charDataHandler(parser->m_handlerArg, (const XML_Char *)s, + (int)((const XML_Char *)next - (const XML_Char *)s)); ++ afterHandler(parser); ++ } + } else if (parser->m_defaultHandler) + reportDefault(parser, enc, s, next); + } break; +-- +2.34.1 + diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 78e35243c5..6fdae2458f 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -69,6 +69,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-50219-31.patch \ file://CVE-2026-50219-32.patch \ file://CVE-2026-56131.patch \ + file://CVE-2026-56412.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"