From patchwork Tue Aug 25 10:06:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96260 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E2BD1C61DB4 for ; Tue, 25 Aug 2026 10:07:22 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18277.1787652434442168851 for ; Tue, 25 Aug 2026 03:07:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ibqIVgeS; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-47c2b362ee2so3345533f8f.1 for ; Tue, 25 Aug 2026 03:07:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652433; x=1788257233; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=E+PrP8jTk3f1mED/Ny4BGyz1YyVe+ZMKzGr8rh9JXJY=; b=ibqIVgeSCU3Bu870aJEBTVymD2xGnswz3IRkNMFLD39SOcOwyS6FOfC0PdhUSIjnpO Yoc4WsNgMWqRp+0GMQp+lEh90l6XXQu1bD1FX/aDi4EW498ZKGajuM4GdZZSqR/PNBxu NKwHh/KLdHvjy/bm5Z2ubTR9OtG+PmmvDNSLM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652433; x=1788257233; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=E+PrP8jTk3f1mED/Ny4BGyz1YyVe+ZMKzGr8rh9JXJY=; b=kIFreQ2vGbVqMtEdbS7pm2Wf9QFs+ItwT5EOLEmJT7AC6VtCWTTnpH+waMyDO8ulx2 WsuAiQPveydJWUeFhBKgttGUmchkYZLy0fSbWYbCBE8Z8cOAX9t9hdZ2DRkCU9aB6TgS mBhrhO6mloeJzoofGCXc10GgdoK0Jjx6cRqEgzw+OtU3EJlyF/cWcyzz5rTZ53+YzUGB JB1rsHKTrD96K7lryUQRT6n6mIrtISltBMGYZq/mYTrSlBD0nBzZvdLfY+zbjHzhf3eI t/uGiVpHDINyDRYqxaopy9GYgdPgTN/sof264fidMezDURbRAy+/iouYs3guud8WFdmL Rn8A== X-Gm-Message-State: AFuF++nosxcO3lspUBpQangxWkgaXWRbTgcLZfIOjZIfB3qXnrk2fmPr QA0cxCdGUy56LxaLiJCJAB00xJ0BPYVd4trSp0eaTxWuwK0JeoggwWm2vT0vqecyxW6GRkWd2kA mUEix9aI= X-Gm-Gg: AR+sD139M8m78jcYd5YWc9Zm+QwyGD+WbtjRvFYmYeidH+qEuooDt3oSLGzG0ySJKCL Ew+mTE0lG1I1nKAdK1VOF7A3k+GBb23LrcENlFraf9o5EFvtvJihXFOQKUk66yrQ76+JdMrK7+A 70cjFAOUAtLrfMRf+6NfIpxsJBBAkzqV23OE4iJKpJRbjoOxszD1goEexKRL4B8kEzQin77MX/N EFNkSxhkMUdtETnokmNGataeEvjEzHLXLBv03mwjE/YmEvB1BAsOtDaBQBTR9Fl5QAcJ8NDqaxx u6QCjNk7i7oZoxsr8dtJr3HFdrgGoeO7L1UvquFXxkDlnrEWvjcMruh4fDC5gB4t064QPAKIJBZ 9DcOjbKRhrvdUqe2jxbX9+0vLs35gKWoVioM4FY/TaSRUnGWxi304gHXkCYkcz454BS/p458PQ6 FkkySg964zODR8/iYLDfunNxaB+0wr7i70V7QJLHzp9oet5zqvJYT+4nrdOsi8cPK6LblMe0OR9 /Zq9KtkPBfn2dwtSVugdk6+OZGswCrdOE9/SgWaeQzpnt9KwT0dliHimWsyYr2fsKic7fg= X-Received: by 2002:a05:6000:25c5:b0:481:512b:f0e7 with SMTP id ffacd0b85a97d-482c81c1a8emr29018555f8f.17.1787652432621; Tue, 25 Aug 2026 03:07:12 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Date: Tue, 25 Aug 2026 12:06:39 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244214 From: Deepak Rathore CVE-2026-58055 affects the nghttpx proxy when forwarding HTTP/1.1 Upgrade requests with a Content-Length header and body. The default recipe does not build nghttpx. Add a conditional CVE_STATUS entry so the CVE remains unpatched if app support is enabled, while default builds are marked not-applicable-config. References: https://nvd.nist.gov/vuln/detail/CVE-2026-58055 Signed-off-by: Deepak Rathore Signed-off-by: Fabien Thomas --- meta/recipes-support/nghttp2/nghttp2_1.61.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb index ebba15db282..9ed27b72770 100644 --- a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb +++ b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb @@ -16,6 +16,8 @@ PACKAGECONFIG[manpages] = "" # first place EXTRA_OECMAKE = "-DENABLE_EXAMPLES=OFF -DENABLE_APP=OFF -DENABLE_HPACK_TOOLS=OFF -DENABLE_PYTHON_BINDINGS=OFF" +CVE_STATUS[CVE-2026-58055] = "${@bb.utils.contains('EXTRA_OECMAKE', '-DENABLE_APP=OFF', 'not-applicable-config: nghttpx proxy is not built in the default nghttp2 configuration', 'unpatched', d)}" + PACKAGES =+ "lib${BPN} ${PN}-proxy " RDEPENDS:${PN} = "${PN}-proxy (>= ${PV})" From patchwork Tue Aug 25 10:06:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96269 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E99F0C61DC6 for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18279.1787652436015144796 for ; Tue, 25 Aug 2026 03:07:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=3NlyeLEa; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47de008b020so343646f8f.1 for ; Tue, 25 Aug 2026 03:07:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652434; x=1788257234; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=4wqAFckj7MLT5WIPRnx6Aqa+SGYA7aEILPUbmoY4gak=; b=3NlyeLEaJgKxcOHWrhtRccwRwMrDwqsbxrjUPYG2U0Jp18adkkErhU8envFpMYxgB/ kHc38b1beimlzdxWuGTwlef92QMoLFc6W+VHRwR99QvuZCsBZMt/wxcWNTa/s3ZkkQLZ gg3ahHmYyjQh3qoXH84jF4CX/OEaoabpdxmOw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652434; x=1788257234; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=4wqAFckj7MLT5WIPRnx6Aqa+SGYA7aEILPUbmoY4gak=; b=hEknIwaKoPVG4z3u+M4/984AZUDqmlusC7mtOs78yTtzNEWnLkiy1u967+6gVbTZPo jEhj+y+n/QXmvROHl1ipxAj7GcrOKHrClCRU2PH8yCQGf59EAXVkSMVwGbTrUftNU4FN Ie2dH0W45Qpe8uIgsnxy2DzXxsD7Xl+4/1Zq9h/7OWsnnhhYkhu/doRc9FsrvPoIEMza cWtt4UEZ+3qrzexNBbQ6hfUJExQ8JU9hZa3OACkbQqxSJ+YKAIixkp3wEmqBvZ+PwYhn Dkyoip71kiUNQEGvBHjgt9F3/unYHmM9UU9shvlKT1zyIZkkvSSlJK4eyIU5O3CmWq8v I9kQ== X-Gm-Message-State: AFuF++l4//8N78MvVBCpJ6Z+fxZp81s85f8/GwRJkH0epg25hSqIubrB AfyNMwUtyJdz6mBysqy57NYa0ciE87YT6YtEKAmcHjW2LlSzWbjJ5mr4BT48ArZvUU/j5iAO2Bp o4Vj7CKI= X-Gm-Gg: AR+sD13JDfxq3RPaNyGd+dOv+4R28ZnrPvvz2Ay5L7nVQllOIrO5juEvRgMEXxic9j6 0kDO8bYDXZouyDIgWtbSl6unHkVIpn8pdq6wZNU9zGh8x24/qf4+X88xrrerpiHgzqjg3AxL2wq Kgv2UQFyAct+kpQ0NMeJPf9tuzIe1ecuhHDpdi0Lj1xeDek33kmKN0f1WHhrz7ppuXLdk6iCbT2 kMXC+R3XdI+w3n/hROpmDMo9knypg38BLAURW0UFWPsXOszLp1XUUC+6wToDfQDVlcuIK+Khi1g dK3kWHZLEVipLyowDVqvaptp8BAdhfTrwwAeFIYQ9RCieEzR3SPtLNwoDQ0Q7GUGJLaNlp1I/3H JRz3LSjyYgeHK9P8PXsN3Jx3pebB4/xAtKBQD2AsRT0kXXh1vjjUpNdyjoMl6pxhV8KjZ/0ERXq /tNqdi1fgD4E47y+riFUUsF4AnzI8E+7owUSQyNEYTy0EggdUogEuUWJZMsGVJ51QQwsw8XqeLQ B4WvjsYJojL734DHQkjh8Wsz3WQa8gd6oSV/T583ZGTU14fD+gaxDcoFbqa7d+iGY2UXsc= X-Received: by 2002:adf:e193:0:b0:481:50ae:df9a with SMTP id ffacd0b85a97d-482d996189amr1039850f8f.9.1787652434164; Tue, 25 Aug 2026 03:07:14 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Date: Tue, 25 Aug 2026 12:06:40 +0200 Message-ID: <188efbb43453920a5c4f6c246dd881e7ab67f319.1787652331.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244216 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-1147 https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=7be4186c22f89a87fff048c28910f5d26a0f61ce Test results: binutils-cross-testsuite 2.42 (x86_64-oe-linux): Before: binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported After: binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported (+2 new passes from nm --ifunc-chars=-- tests) gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce] Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2025-1147.patch | 110 ++++++++++++++++++ 2 files changed, 111 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index d455acd7863..063c6cc2a43 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -78,5 +78,6 @@ SRC_URI = "\ file://CVE-2025-69652.patch \ file://CVE-2026-6846.patch \ file://CVE-2025-69645.patch \ + file://CVE-2025-1147.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch new file mode 100644 index 00000000000..9a95775d3f0 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch @@ -0,0 +1,110 @@ +From 7be4186c22f89a87fff048c28910f5d26a0f61ce Mon Sep 17 00:00:00 2001 +From: Dmitry Klochkov +Date: Tue, 9 Sep 2025 12:06:25 +0200 +Subject: [PATCH] nm: fix treating an ifunc symbol as a stab if + '--ifunc-chars=--' is given + +If an ifunc symbol is processed in print_symbol(), a 'type' field of a +'syminfo' structure is set to any character specified by a user with an +'--ifunc-chars' option. But afterwards the 'type' field is used to +check whether a symbol is a stab in print_symbol_info_{bsd,sysv}() +functions in order to print additional stab related data. If the 'type' +field equals '-', a symbol is treated as a stab. If '--ifunc-chars=--' +is given, all ifunc symbols will be treated as stab symbols and +uninitialized stab related fields of the 'syminfo' structure will be +printed which can lead to segmentation fault. + +To fix this, check if a symbol is a stab before override the 'type' +field. Also, add a test case for this fix. + + PR binutils/32556 + * nm.c (extended_symbol_info): Add is_stab. + (print_symbol): Check if a symbol is a stab. + (print_symbol_info_bsd): Use info->is_stab. + (print_symbol_info_sysv): Use info->is_stab. + * testsuite/binutils-all/nm.exp: Test nm --ifunc-chars=--. + +Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=32556 +Fixes: e6f6aa8d184 ("Add option to nm to change the characters displayed for ifunc symbols") +Signed-off-by: Dmitry Klochkov + +CVE: CVE-2025-1147 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce] + +Signed-off-by: Jaipaul Cheernam +--- + binutils/nm.c | 10 +++++++--- + binutils/testsuite/binutils-all/nm.exp | 17 +++++++++++++++++ + 2 files changed, 24 insertions(+), 3 deletions(-) + +diff --git a/binutils/nm.c b/binutils/nm.c +index dce9207f44f..c3d118a93c3 100644 +--- a/binutils/nm.c ++++ b/binutils/nm.c +@@ -70,6 +70,7 @@ struct extended_symbol_info + bfd_vma ssize; + elf_symbol_type *elfinfo; + coff_symbol_type *coffinfo; ++ bool is_stab; + /* FIXME: We should add more fields for Type, Line, Section. */ + }; + #define SYM_VALUE(sym) (sym->sinfo->value) +@@ -1208,8 +1209,11 @@ print_symbol (bfd * abfd, + + bfd_get_symbol_info (abfd, sym, &syminfo); + ++ info.is_stab = false; ++ if (syminfo.type == '-') ++ info.is_stab = true; + /* PR 22967 - Distinguish between local and global ifunc symbols. */ +- if (syminfo.type == 'i' ++ else if (syminfo.type == 'i' + && sym->flags & BSF_GNU_INDIRECT_FUNCTION) + { + if (ifunc_type_chars == NULL || ifunc_type_chars[0] == 0) +@@ -1873,7 +1877,7 @@ print_symbol_info_bsd (struct extended_symbol_info *info, bfd *abfd) + + printf (" %c", SYM_TYPE (info)); + +- if (SYM_TYPE (info) == '-') ++ if (info->is_stab) + { + /* A stab. */ + printf (" "); +@@ -1902,7 +1906,7 @@ print_symbol_info_sysv (struct extended_symbol_info *info, bfd *abfd) + + printf ("| %c |", SYM_TYPE (info)); + +- if (SYM_TYPE (info) == '-') ++ if (info->is_stab) + { + /* A stab. */ + printf ("%18s| ", SYM_STAB_NAME (info)); /* (C) Type. */ +diff --git a/binutils/testsuite/binutils-all/nm.exp b/binutils/testsuite/binutils-all/nm.exp +index fea68bf76bc..1feb8578fba 100644 +--- a/binutils/testsuite/binutils-all/nm.exp ++++ b/binutils/testsuite/binutils-all/nm.exp +@@ -329,6 +329,23 @@ if [is_elf_format] { + fail "$testname (local ifunc)" + } + ++ # PR 32556 ++ # Test nm --ifunc-chars=-- ++ ++ set got [binutils_run $NM "$NMFLAGS --ifunc-chars=-- $tmpfile"] ++ ++ if [regexp -line "^\\S+ - global_foo$" $got] then { ++ pass "$testname=-- (global ifunc)" ++ } else { ++ fail "$testname=-- (global ifunc)" ++ } ++ ++ if [regexp -line "^\\S+ - local_foo$" $got] then { ++ pass "$testname=-- (local ifunc)" ++ } else { ++ fail "$testname=-- (local ifunc)" ++ } ++ + if { $verbose < 1 } { + remote_file host delete "tmpdir/ifunc.o" + } From patchwork Tue Aug 25 10:06:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96262 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3ED36C61DBE for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18581.1787652436560073262 for ; Tue, 25 Aug 2026 03:07:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tXi7dh3d; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-47de008b020so343660f8f.1 for ; Tue, 25 Aug 2026 03:07:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652435; x=1788257235; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZjP9TIe9QVP6mSl04vIUXdfVBXmKWiCNVBGHn1IpbxI=; b=tXi7dh3drWEXTBUmvYgCByhWpzBQ3mRWNBo5a+YCl99SmX6nsXOvlYtQDFRadJNBiC rTml6smy0UztURcehuW0c5aQ4goqGUf4HAAYqGjrdj8hwwnEideCS2wUYdILtUUTxx96 Stnt3wX/o32lkDWIvhFSOwXpFz3pTKXUkX8Gs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652435; x=1788257235; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZjP9TIe9QVP6mSl04vIUXdfVBXmKWiCNVBGHn1IpbxI=; b=sipjSpDlzZdYlpa8bdvicps/njVSFPCzrFwcGjDMczDwUWlnGfFosaIzMQphgXVwZG mdnrS5CqHM85gj7WUkefh45kww465JNxTjEwLB1dABCsMa0mCGusASMjCGd2MrRE5joj 49JdHXqSkR56w6+l8a6LHorcOGhhDuTIlfTHE0L3uXIjmGvGOQyGy+aVfr8araVSe1Sm XGAkqSSxtbhfozHcvyx/4oSO5vFcn174/qRnL1NgJ7U3bw+O8bK5yDHm3zL5IiTY/RDi uub5dp+vN8QLDptEPqFOJUcb4+axrhrO4QsFkJ5Jar32LupYZfQ2v5t2k/OZPk0IV15X KRvA== X-Gm-Message-State: AFuF++kaUs3GyS9mDdvRniWeI9D7sMrMgPih25YRcivvKiFdhXrsrOBR Q3pSlgyw8thOU6gmRfupS4elDD9O10GCqgrxh59gsVV09MPBC5NcOXKSbbyLEFin30XMcvwzVsm mv++IgHo= X-Gm-Gg: AR+sD12Q1eUKfhSCAK9zqVyvyd0XmgoKzfs/3XTogzZ6cCWqMBhVZ2Edv1EiJawnzzr LFGD1SHScuRdGgDBoo6IZB5yoW9uKZbF/eVfNjijs1VRwottiD4OQ98dnYAPN6I0+9fbzcS5JRv qgIVo18OXNIjEdVu30tdcCKGsjMQHMgEj/MSk/+z/b/0zOJVeagTdiJySGXqTR0JaOKe2As2BL0 vbsHJt9pvoWe75oS7UxVoJA8NgOAAsSRYr7JvTs2STZtINqDDKCeeFIDZaREgUPGgbmu4GIWN68 RpK4USah1JXKtS4E/2n1mj88SEa3KCiUUezZ/ce8UI8WF4x/8kkUVflrcVza20+MGUCuS8zUeoC g6S+Rldk2uLTVfu9/XE8XWtgii5hGFCeKeYK7TRXceWC1ErzpvKtX1eCuScCpHntbCSX3IA0vi5 HHc7xVEqk8yRWU3hxI4RkZzrT4HOZeEZ2oGIkhbU8a2/OmCwErv5Vs7E8ORCo9Wspq+ng7y6lIe cVcDddBErhw27/1iGXfeC08tXO48f4CHnrball336x3fbye0SPg8C69pRJ/9bWWnOCzpu0= X-Received: by 2002:a05:6000:4008:b0:47f:71a0:c060 with SMTP id ffacd0b85a97d-482d9934dedmr6277438f8f.2.1787652434725; Tue, 25 Aug 2026 03:07:14 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Date: Tue, 25 Aug 2026 12:06:41 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244217 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-8224 https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=db856d41004301b3a56438efd957ef5cabb91530 [Adapted for binutils 2.42: only the shstrtabsize overflow check in bfd_elf_get_str_section applies. The second upstream hunk (DT_STRTAB) does not apply as 2.42 already unconditionally null-terminates the dynamic string table.] Test results: binutils-cross-testsuite 2.42 (x86_64-oe-linux): Before: binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported After: binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530] Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2025-8224.patch | 54 +++++++++++++++++++ 2 files changed, 55 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 063c6cc2a43..5534ce577f9 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -79,5 +79,6 @@ SRC_URI = "\ file://CVE-2026-6846.patch \ file://CVE-2025-69645.patch \ file://CVE-2025-1147.patch \ + file://CVE-2025-8224.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch new file mode 100644 index 00000000000..914b9084c27 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch @@ -0,0 +1,54 @@ +From db856d41004301b3a56438efd957ef5cabb91530 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Sun, 25 Aug 2024 15:20:21 +0930 +Subject: [PATCH] PR32109, aborting at bfd/bfd.c:1236 in int _bfd_doprnt + +Since bfd_section for .strtab isn't set, print the section index +instead. Also, don't return NULL on this error as that results in +multiple mmap/read of the string table. (We could return NULL if we +arranged to set sh_size zero first, but just what we do with fuzzed +object files is of no concern, and terminating the table might make a +faulty object file usable.) + + PR 32109 + * elf.c (bfd_elf_get_str_section): Remove outdated comment, and + tweak shstrtabsize test to suit. Don't use string tab bfd_section + in error message, use index instead. Don't return NULL on + unterminated string section, terminate it. + (_bfd_elf_get_dynamic_symbols): Similarly terminate string table + section. + +[Backport note: Adapted for binutils 2.42. The upstream commit targets +a newer codebase that uses _bfd_mmap_readonly_persistent and has an +explicit unterminated-string error path with return NULL. In 2.42 the +code uses _bfd_alloc_and_read with shstrtabsize+1 allocation and +unconditionally null-terminates via shstrtab[shstrtabsize] = '\0'. +Only the shstrtabsize overflow check fix applies here (shstrtabsize + 1 <= 1 +changed to shstrtabsize == 0). The second upstream hunk (DT_STRTAB +error_return -> terminate) does not apply as 2.42 already +unconditionally null-terminates the dynamic string table.] + +CVE: CVE-2025-8224 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530] + +Signed-off-by: Jaipaul Cheernam +--- + bfd/elf.c | 4 +--- + 1 file changed, 1 insertion(+), 3 deletions(-) + +diff --git a/bfd/elf.c b/bfd/elf.c +--- a/bfd/elf.c ++++ b/bfd/elf.c +@@ -285,9 +285,7 @@ bfd_elf_get_str_section (bfd *abfd, unsigned int shindex) + offset = i_shdrp[shindex]->sh_offset; + shstrtabsize = i_shdrp[shindex]->sh_size; + +- /* Allocate and clear an extra byte at the end, to prevent crashes +- in case the string table is not terminated. */ +- if (shstrtabsize + 1 <= 1 ++ if (shstrtabsize == 0 + || bfd_seek (abfd, offset, SEEK_SET) != 0 + || (shstrtab = _bfd_alloc_and_read (abfd, shstrtabsize + 1, + shstrtabsize)) == NULL) +-- +2.43.7 From patchwork Tue Aug 25 10:06:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96265 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 986D0C61DC2 for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18281.1787652437992656828 for ; Tue, 25 Aug 2026 03:07:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=MCCD/4kZ; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-47f3b39f2a1so3180324f8f.2 for ; Tue, 25 Aug 2026 03:07:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652436; x=1788257236; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ygFD0dtLycSLXx5aJAPetaaQ9RdjHBSdb9ouPzVcTZc=; b=MCCD/4kZnjQS+p27I7fwM7GYTjanv1Dqe2iKIyPTZb0fEPQptnGt5j6cdmUjJdZSsX eCerG5cYLFl0smRv+yqTUgQ7rSBBfSKNGxOlhdZLPLl7Dp8wRJ2y8I3t61VAjCUCU3tn PJBk1xV9GL0BiNxZZLFpg6FmZRJWNrg1QO+HA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652436; x=1788257236; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ygFD0dtLycSLXx5aJAPetaaQ9RdjHBSdb9ouPzVcTZc=; b=o7ZPrgD/tqdeimTXcKkHBKIvqYglOZCJoP/JWiSPqGBfjcFG6UcdPvxZFnFY8A6PBp C8c5zV7dDN89JxafojF15jp/+spUGVoyI2MmCJ3caqyPs3oiDAJ5VpkGq51l+ptBMBOs uSmCBl7cowMEZGYMuphZcNBFlvdHCHzil0aZGFUkYyh9zvl5nHIvyGT9vrNjd9xdqXIL /ugSLHY2fjYEZoredlXg0mpEvUT6+tE9ETutuMhREaGRj+Ix9WzNm2BNyl5HTO+hTU3O 4YtnoCk1GVJfF9tlTTlwa/WoPddxIrgVJnvtnF2reT/6JCk1gK1hBSkww/hp40zYp1CN Xu4g== X-Gm-Message-State: AFuF++nEgBSjKVCiX9y82M6NEsq2DyL8dKwzDXT+RDpwrZJLViEE8Dlf g3O5asmURKyt7GjpPGqElENxh3HSC89ZcEGlkpf48jsRygShQs7B6VNNS2tsLRut9/iXA7JJHVZ Uihot7CE= X-Gm-Gg: AR+sD13Aue2KICQDiJ4L5C1dJdqLa+oDqGxQVONkS5vKk29KQs2VTqm80ke7KH+MyM0 mwv54Hk7J0ZMgvYTsfyMRmCLxaNBbd3HS4QD5DjF+48Q2aVbv0J9BYyEwMcK71ZI0+p3OfouoOB 3UAt8CMtG43R223cPIba78rD5Vfrpn+FGW1/JvDoM51llPD1tROv4miggYRZgowS6d0Bdes7ta/ UNvD1B3WSHabe482w0LmgcPZkBcV4Fslwxb587l1PMuTWTypUuWfN7G9l6E8fDbKMoqlYqi4K3F 816LB0VFoLAABUqlUjcGJXtAtZztneL76I5Sc5HIAO1D1B9cLds5RvoC1vpw/Y5nD6pzQhnW6Zu hRon4BNSDYKiUPeJPcEegxjeKIAkUyPf+FMgi+WVmA9Jd5XK2SLi09ie14RzrHe31Hu1g0LTH/X dgOadZR9phmnWVJuaroJegR81NX5PkkIZ657+cx9PrMl9ioBgx6l/z328A8vC/299GnNY5Tfy8e 7ZEGN2HEuGkkApZiL7Mx0o1Jn7PV1mdwGRjAxdkR3Pa7Hq3PMMjEWwmLBcsFFSXP8Pg96c= X-Received: by 2002:a05:6000:4909:b0:482:552f:ef68 with SMTP id ffacd0b85a97d-482d9f272b8mr7286332f8f.19.1787652436107; Tue, 25 Aug 2026 03:07:16 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Date: Tue, 25 Aug 2026 12:06:42 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244218 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-15003 https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c Test results: binutils-cross-testsuite 2.42 (x86_64-oe-linux): Before: binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported After: binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c] Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2026-15003.patch | 400 ++++++++++++++++++ 2 files changed, 401 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 5534ce577f9..447529ffa95 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -80,5 +80,6 @@ SRC_URI = "\ file://CVE-2025-69645.patch \ file://CVE-2025-1147.patch \ file://CVE-2025-8224.patch \ + file://CVE-2026-15003.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch new file mode 100644 index 00000000000..2f5c42e1b93 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch @@ -0,0 +1,400 @@ +From 23acf2f003f81b2f8d9d1997ea45d822d33d386c Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Thu, 9 Apr 2026 09:06:27 +0930 +Subject: [PATCH] PR 34053 buffer overflow in xcoff_link_add_symbols + +This patch adds two sanity checks with error reporting in +xcoff_link_add_symbols before reading symbol aux entries, add extends +assertions in later functions. A whole lot of unnecessary casts are +also tidied. + + PR 34053 + * xcofflink.c: Remove unnecessary casts throughout. + (xcoff_link_add_symbols): Sanity check aux entries are within + symbol buffer. + (bfd_xcoff_build_dynamic_sections): Assert the above is true. + (xcoff_link_input_bfd): Likewise. + +CVE: CVE-2026-15003 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c] + +Signed-off-by: Jaipaul Cheernam +--- + bfd/xcofflink.c | 132 +++++++++++++++++++++++------------------------- + 1 file changed, 62 insertions(+), 70 deletions(-) + +diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c +index 7f1c0df760f..cf3b33e7202 100644 +--- a/bfd/xcofflink.c ++++ b/bfd/xcofflink.c +@@ -371,7 +371,7 @@ _bfd_xcoff_canonicalize_dynamic_symtab (bfd *abfd, asymbol **psyms) + { + char *c; + +- c = bfd_alloc (abfd, (bfd_size_type) SYMNMLEN + 1); ++ c = bfd_alloc (abfd, SYMNMLEN + 1); + if (c == NULL) + return -1; + memcpy (c, ldsym._l._l_name, SYMNMLEN); +@@ -1038,7 +1038,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info) + { + char *dsnm; + +- dsnm = bfd_malloc ((bfd_size_type) strlen (name) + 2); ++ dsnm = bfd_malloc (strlen (name) + 2); + if (dsnm == NULL) + return false; + dsnm[0] = '.'; +@@ -1081,7 +1081,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info) + coff_section_data (abfd, lsec)->contents = NULL; + + /* Record this file in the import files. */ +- n = bfd_alloc (abfd, (bfd_size_type) sizeof (struct xcoff_import_file)); ++ n = bfd_alloc (abfd, sizeof (*n)); + if (n == NULL) + return false; + n->next = NULL; +@@ -1477,7 +1477,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + bfd_vma value; + struct xcoff_link_hash_entry *set_toc; + +- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym); ++ bfd_coff_swap_sym_in (abfd, esym, &sym); + + /* In this pass we are only interested in symbols with csect + information. */ +@@ -1523,9 +1523,12 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + { + union internal_auxent auxlin; + +- bfd_coff_swap_aux_in (abfd, (void *) (esym + symesz), ++ if (symesz >= (size_t) (esym_end - esym)) ++ goto badaux; ++ ++ bfd_coff_swap_aux_in (abfd, esym + symesz, + sym.n_type, sym.n_sclass, +- 0, sym.n_numaux, (void *) &auxlin); ++ 0, sym.n_numaux, &auxlin); + + if (auxlin.x_sym.x_fcnary.x_fcn.x_lnnoptr != 0) + { +@@ -1552,7 +1555,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + + linpstart = (reloc_info[enclosing->target_index].linenos + + linoff); +- bfd_coff_swap_lineno_in (abfd, (void *) linpstart, (void *) &lin); ++ bfd_coff_swap_lineno_in (abfd, linpstart, &lin); + if (lin.l_lnno == 0 + && ((bfd_size_type) lin.l_addr.l_symndx + == ((esym +@@ -1567,8 +1570,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + linp < linpend; + linp += linesz) + { +- bfd_coff_swap_lineno_in (abfd, (void *) linp, +- (void *) &lin); ++ bfd_coff_swap_lineno_in (abfd, linp, &lin); + if (lin.l_lnno == 0) + break; + } +@@ -1589,21 +1591,21 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + visibility = sym.n_type & SYM_V_MASK; + + /* Pick up the csect auxiliary information. */ +- if (sym.n_numaux == 0) ++ if (sym.n_numaux < 1 ++ || sym.n_numaux * symesz >= (size_t) (esym_end - esym)) + { ++ badaux: + _bfd_error_handler + /* xgettext:c-format */ +- (_("%pB: class %d symbol `%s' has no aux entries"), ++ (_("%pB: class %d symbol '%s' has missing aux entries"), + abfd, sym.n_sclass, name); + bfd_set_error (bfd_error_bad_value); + goto error_return; + } + +- bfd_coff_swap_aux_in (abfd, +- (void *) (esym + symesz * sym.n_numaux), ++ bfd_coff_swap_aux_in (abfd, esym + symesz * sym.n_numaux, + sym.n_type, sym.n_sclass, +- sym.n_numaux - 1, sym.n_numaux, +- (void *) &aux); ++ sym.n_numaux - 1, sym.n_numaux, &aux); + + smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp); + +@@ -1726,7 +1728,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + + erelsym = ((bfd_byte *) obj_coff_external_syms (abfd) + + rel->r_symndx * symesz); +- bfd_coff_swap_sym_in (abfd, (void *) erelsym, (void *) &relsym); ++ bfd_coff_swap_sym_in (abfd, erelsym, &relsym); + if (EXTERN_SYM_P (relsym.n_sclass)) + { + const char *relname; +@@ -2507,7 +2509,7 @@ xcoff_link_check_ar_symbols (bfd *abfd, + { + struct internal_syment sym; + +- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym); ++ bfd_coff_swap_sym_in (abfd, esym, &sym); + esym += (sym.n_numaux + 1) * symesz; + + if (EXTERN_SYM_P (sym.n_sclass) && sym.n_scnum != N_UNDEF) +@@ -4005,7 +4007,7 @@ bfd_xcoff_size_dynamic_sections (bfd *output_bfd, + return true; + + xcoff_link_hash_traverse (xcoff_hash_table (info), xcoff_post_gc_symbol, +- (void *) ldinfo); ++ ldinfo); + if (ldinfo->failed) + goto error_return; + +@@ -4216,7 +4218,8 @@ bfd_xcoff_build_dynamic_sections (bfd *output_bfd, + /* Read in the csect information, if any. */ + if (CSECT_SYM_P (sym.n_sclass)) + { +- BFD_ASSERT (sym.n_numaux > 0); ++ BFD_ASSERT (sym.n_numaux > 0 ++ && symesz * sym.n_numaux < (size_t) (esymend - esym)); + bfd_coff_swap_aux_in (sub, esym + symesz * sym.n_numaux, + sym.n_type, sym.n_sclass, + sym.n_numaux - 1, sym.n_numaux, &aux); +@@ -4307,7 +4310,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd, + { + struct bfd_in_memory *bim; + +- bim = bfd_malloc ((bfd_size_type) sizeof (* bim)); ++ bim = bfd_malloc (sizeof (*bim)); + if (bim == NULL) + return false; + +@@ -4316,7 +4319,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd, + + abfd->link.next = 0; + abfd->format = bfd_object; +- abfd->iostream = (void *) bim; ++ abfd->iostream = bim; + abfd->flags = BFD_IN_MEMORY; + abfd->iovec = &_bfd_memory_iovec; + abfd->direction = write_direction; +@@ -4876,8 +4879,8 @@ bfd_xcoff_size_stubs (struct bfd_link_info *info) + } + + bfd_coff_swap_sym_in (input_bfd, +- (void *) esyms + irel->r_symndx * symesz, +- (void *) &sym); ++ esyms + irel->r_symndx * symesz, ++ &sym); + + sym_sec = xcoff_data (input_bfd)->csects[irel->r_symndx]; + sym_value = sym.n_value - sym_sec->vma; +@@ -5250,17 +5253,16 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + int smtyp = 0; + int add; + +- bfd_coff_swap_sym_in (input_bfd, (void *) esym, (void *) isymp); ++ bfd_coff_swap_sym_in (input_bfd, esym, isymp); + + /* Read in the csect information, if any. */ + if (CSECT_SYM_P (isymp->n_sclass)) + { +- BFD_ASSERT (isymp->n_numaux > 0); +- bfd_coff_swap_aux_in (input_bfd, +- (void *) (esym + isymesz * isymp->n_numaux), ++ BFD_ASSERT (isymp->n_numaux > 0 ++ && isymesz * isymp->n_numaux < (size_t) (esym_end - esym)); ++ bfd_coff_swap_aux_in (input_bfd, esym + isymesz * isymp->n_numaux, + isymp->n_type, isymp->n_sclass, +- isymp->n_numaux - 1, isymp->n_numaux, +- (void *) &aux); ++ isymp->n_numaux - 1, isymp->n_numaux, &aux); + + smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp); + } +@@ -5475,12 +5477,10 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + if ((bfd_size_type) flinfo->last_file_index >= syment_base) + { + /* The last C_FILE symbol is in this input file. */ +- bfd_coff_swap_sym_out (output_bfd, +- (void *) &flinfo->last_file, +- (void *) (flinfo->outsyms +- + ((flinfo->last_file_index +- - syment_base) +- * osymesz))); ++ bfd_coff_swap_sym_out ++ (output_bfd, &flinfo->last_file, ++ flinfo->outsyms + (flinfo->last_file_index ++ - syment_base) * osymesz); + } + else + { +@@ -5489,9 +5489,8 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + borrow *outsym temporarily. */ + file_ptr pos; + +- bfd_coff_swap_sym_out (output_bfd, +- (void *) &flinfo->last_file, +- (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file, ++ outsym); + + pos = obj_sym_filepos (output_bfd); + pos += flinfo->last_file_index * osymesz; +@@ -5557,7 +5556,7 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + } + + /* Output the symbol. */ +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + + esym += isymesz; + outsym += osymesz; +@@ -5566,9 +5565,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + { + union internal_auxent aux; + +- bfd_coff_swap_aux_in (input_bfd, (void *) esym, isymp->n_type, +- isymp->n_sclass, i, isymp->n_numaux, +- (void *) &aux); ++ bfd_coff_swap_aux_in (input_bfd, esym, ++ isymp->n_type, isymp->n_sclass, i, ++ isymp->n_numaux, &aux); + + if (isymp->n_sclass == C_FILE) + { +@@ -5796,9 +5795,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + } + } + +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, isymp->n_type, ++ bfd_coff_swap_aux_out (output_bfd, &aux, isymp->n_type, + isymp->n_sclass, i, isymp->n_numaux, +- (void *) outsym); ++ outsym); + outsym += osymesz; + esym += isymesz; + } +@@ -5820,10 +5819,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + && (bfd_size_type) flinfo->last_file_index >= syment_base) + { + flinfo->last_file.n_value = output_index; +- bfd_coff_swap_sym_out (output_bfd, (void *) &flinfo->last_file, +- (void *) (flinfo->outsyms +- + ((flinfo->last_file_index - syment_base) +- * osymesz))); ++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file, ++ flinfo->outsyms + (flinfo->last_file_index ++ - syment_base) * osymesz); + } + + /* Write the modified symbols to the output file. */ +@@ -6036,16 +6034,13 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo, + void * auxptr; + union internal_auxent aux; + +- auxptr = ((void *) +- (((bfd_byte *) +- obj_coff_external_syms (input_bfd)) +- + ((r_symndx + is->n_numaux) +- * isymesz))); ++ auxptr = ((bfd_byte *) ++ obj_coff_external_syms (input_bfd) ++ + (r_symndx + is->n_numaux) * isymesz); + bfd_coff_swap_aux_in (input_bfd, auxptr, + is->n_type, is->n_sclass, + is->n_numaux - 1, +- is->n_numaux, +- (void *) &aux); ++ is->n_numaux, &aux); + if (SMTYP_SMTYP (aux.x_csect.x_smtyp) == XTY_SD + && aux.x_csect.x_smclas == XMC_TC0) + indx = flinfo->toc_symindx; +@@ -6564,12 +6559,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + irsym.n_type = T_NULL; + irsym.n_numaux = 1; + +- bfd_coff_swap_sym_out (output_bfd, (void *) &irsym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &irsym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + /* Note : iraux is initialized above. */ +- bfd_coff_swap_aux_out (output_bfd, (void *) &iraux, T_NULL, C_HIDEXT, +- 0, 1, (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &iraux, T_NULL, C_HIDEXT, ++ 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + + if (h->indx >= 0) +@@ -6807,12 +6802,11 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + isym.n_type = T_NULL; + isym.n_numaux = 1; + +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + aux.x_csect.x_smclas = h->smclas; +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, isym.n_sclass, 0, 1, +- (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, isym.n_sclass, 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + + if ((h->root.type == bfd_link_hash_defined +@@ -6827,13 +6821,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf) + isym.n_sclass = C_WEAKEXT; + else + isym.n_sclass = C_EXT; +- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym); ++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym); + outsym += bfd_coff_symesz (output_bfd); + + aux.x_csect.x_smtyp = XTY_LD; + aux.x_csect.x_scnlen.u64 = obj_raw_syment_count (output_bfd); +- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, C_EXT, 0, 1, +- (void *) outsym); ++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, C_EXT, 0, 1, outsym); + outsym += bfd_coff_auxesz (output_bfd); + } + +@@ -6929,8 +6922,8 @@ xcoff_reloc_link_order (bfd *output_bfd, + howto->name, addend, NULL, NULL, (bfd_vma) 0); + break; + } +- ok = bfd_set_section_contents (output_bfd, output_section, (void *) buf, +- (file_ptr) link_order->offset, size); ++ ok = bfd_set_section_contents (output_bfd, output_section, buf, ++ link_order->offset, size); + free (buf); + if (! ok) + return false; +@@ -7395,8 +7388,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + if (flinfo.last_file_index != -1) + { + flinfo.last_file.n_value = -(bfd_vma) 1; +- bfd_coff_swap_sym_out (abfd, (void *) &flinfo.last_file, +- (void *) flinfo.outsyms); ++ bfd_coff_swap_sym_out (abfd, &flinfo.last_file, flinfo.outsyms); + pos = obj_sym_filepos (abfd) + flinfo.last_file_index * symesz; + if (bfd_seek (abfd, pos, SEEK_SET) != 0 + || bfd_write (flinfo.outsyms, symesz, abfd) != symesz) +@@ -7480,7 +7472,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + appear in the symbol table, which is not necessarily by + address. So we sort them here. There may be a better way to + do this. */ +- qsort ((void *) flinfo.section_info[o->target_index].relocs, ++ qsort (flinfo.section_info[o->target_index].relocs, + o->reloc_count, sizeof (struct internal_reloc), + xcoff_sort_relocs); + +@@ -7488,7 +7480,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info) + irelend = irel + o->reloc_count; + erel = external_relocs; + for (; irel < irelend; irel++, rel_hash++, erel += relsz) +- bfd_coff_swap_reloc_out (abfd, (void *) irel, (void *) erel); ++ bfd_coff_swap_reloc_out (abfd, irel, erel); + + rel_size = relsz * o->reloc_count; + if (bfd_seek (abfd, o->rel_filepos, SEEK_SET) != 0 From patchwork Tue Aug 25 10:06:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96263 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 46316C61DC3 for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18282.1787652438925131696 for ; Tue, 25 Aug 2026 03:07:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZPvSohQQ; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso44591665e9.1 for ; Tue, 25 Aug 2026 03:07:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652437; x=1788257237; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TAEuWjiSCgjMzI0WVyKJJmQ+FjRXIbjRBwYvwH0EKuQ=; b=ZPvSohQQrQF4xvkn3M60q2mBaL5JFdrZBsAoheAwDps3Py36jvXZc9sy+zkYpTybja y0pn+W647fefKULAQlB0XeKriyMvp4gW97KEga0DRs2n7Q6icQ0P/cK0YRLkukgnkca+ WicOk2Knd84ASCGL6Iohrp763b3KdfwBYDGdg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652437; x=1788257237; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TAEuWjiSCgjMzI0WVyKJJmQ+FjRXIbjRBwYvwH0EKuQ=; b=i1OHhAjOo6EfpqohgdQrbLACSgMRzoniRl8xTVbe1+tFg2rehQPw4JTNaEgejNB4tO kcr0Na5UIPt9jRkmZC4OOdpPgv/8Noul5P6nnjw24j3J2OYRWLqNqR3jGU8zL2JxPeK5 KrBuTH4WtXySHY9N+cj0/g7voFVtNweY/qTvbqD0N/dNlJpVPSauUArNI4erLBLqk0OB mh5+//qVxX6QhJaXzCyzA7gqZKeMu/mu+cQgG9cJcuVLGN4ftaH0lsNJe9xPDRwwl4kg qt8HZw0tHjm9FpZWKhz7kpq4vPS8WdI9rQtpcRSoF6Tx+o2yTvZapAya8xOru+Gsyc/B z37w== X-Gm-Message-State: AFuF++m1HU75wkF6JKrI+bbB/j0S4KTwfm3H3F4bGUORIe0GJvAqBOln ZLUX4ZPmBOvy2mVQi2YK9TkPq08PrjL23967oh46SK/TD5DUXxFRYzR0dzsmZOL472Le272ezYl GGOi//GQ= X-Gm-Gg: AR+sD13/V4NCYBvpV+wxfq5hVf0jlmhVhdFISGuzDjleeO9HeSexPd+szqNqrNcr2Mj DEYnZyGp1nefByXREgG/banTYlLGOik4Y7U2uO/YHvRTJnWvEVQgYmrzdYcd2VR5wDEH+KMhqQH x2iKdnrWneDX6OcuJgdgWs9KK6yH8x6esZt6vyyszqGYcOCVjQz0BVCXSox2UmhJBtqw6h4KFrI 4uvPg6gHqKWuYr5zk8efe3uSDyqbV8QWXAmDQPDiCLmMKvqCwEMiP6nzW+vOe7W6dwlsWRrISG8 vwQvOnqnbshgdaFAlVnt59FmvyJaZu5OxU6WIybqat+1j6czGW23aodw2KJ9JVWo3tw1js9nUPE kqByQXakAZTD98SswPjAJrkDiV4BczKTvuC3rWAMeWF8W1rKEYZON7WW9+gDDOTBaVuKDIYCxj0 xV4K+SXCdREsr+3+r18pvhGukwMfHn8ihZvyF0tE5ovKn3iApo7bzIi/fGh3QAiPM59nWE+lk7Y bRghhoXv/Hk9R64UTbEwiJyaaiOzFh2+WqSy5QrHwjVhORboLHslTnm6VHJeaKBoQfMlF0= X-Received: by 2002:a05:600c:46d1:b0:492:4e09:9fc1 with SMTP id 5b1f17b1804b1-499c19dcc4fmr296386615e9.15.1787652436933; Tue, 25 Aug 2026 03:07:16 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Date: Tue, 25 Aug 2026 12:06:43 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244219 From: Jaipaul Cheernam Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-18220 https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=114e3aae2b7e34057c8909301eaf78c15687e8e5 Test results: binutils-cross-testsuite 2.42 (x86_64-oe-linux): Before: binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported After: binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported gas: 1871 passed, 4 unexpected failures, 2 unsupported ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5] Signed-off-by: Jaipaul Cheernam Signed-off-by: Fabien Thomas --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2026-18220.patch | 65 +++++++++++++++++++ 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 447529ffa95..d395ae1b1e0 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -81,5 +81,6 @@ SRC_URI = "\ file://CVE-2025-1147.patch \ file://CVE-2025-8224.patch \ file://CVE-2026-15003.patch \ + file://CVE-2026-18220.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch new file mode 100644 index 00000000000..e915fb223a1 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch @@ -0,0 +1,65 @@ +From 114e3aae2b7e34057c8909301eaf78c15687e8e5 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Sun, 28 Jun 2026 09:11:46 +0930 +Subject: [PATCH] asan: buffer overflow in elf32_dlx_relocate26 + + * elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset. + (elf32_dlx_relocate16): Likewise. + (_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective + existing check. + +CVE: CVE-2026-18220 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5] + +Signed-off-by: Jaipaul Cheernam +--- + bfd/elf32-dlx.c | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c +index 2dfeb4d7390..0f9a49695d7 100644 +--- a/bfd/elf32-dlx.c ++++ b/bfd/elf32-dlx.c +@@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, + return bfd_reloc_ok; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + ret = bfd_reloc_ok; + + if (bfd_is_und_section (symbol->section) +@@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, + relocation += reloc_entry->addend; + relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address); + +- if (reloc_entry->address > bfd_get_section_limit (abfd, input_section)) +- return bfd_reloc_outofrange; +- + bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF), + (bfd_byte *)data + reloc_entry->address); + +@@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd, + return bfd_reloc_undefined; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); + allignment = 1 << (input_section->output_section->alignment_power - 1); + vallo = insn & 0x0000FFFF; +@@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd, + return bfd_reloc_undefined; + } + ++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, ++ input_section, reloc_entry->address)) ++ return bfd_reloc_outofrange; ++ + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); + allignment = 1 << (input_section->output_section->alignment_power - 1); + vallo = insn & 0x03FFFFFF; From patchwork Tue Aug 25 10:06:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96266 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AB1DCC61DC4 for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18583.1787652439904299132 for ; Tue, 25 Aug 2026 03:07:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VWio1hlI; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47fecbb7000so1707433f8f.2 for ; Tue, 25 Aug 2026 03:07:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652438; x=1788257238; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=d1l7xXHuZwbTHaCUGibyuw8SRx5ibqekv06PbzwZtAA=; b=VWio1hlIvrPrRy31r+Flc6lMcqvTLTJQEU0i5DmDLJVID+kKNreCav+OaUKJG1RwOV gz89yCbAZbtbNIEAgeut+iTqJ6RQMywvScrFMR4wzf7z0NEgJ2GN5LmA05rpxf59gAWg JU/CHQsf2Mgg6OKzJ4pmzquCVaJ7BW25k3VlQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652438; x=1788257238; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=d1l7xXHuZwbTHaCUGibyuw8SRx5ibqekv06PbzwZtAA=; b=tX2yV2g6vI4k+zqsKv8180iepbcN5qS90TfHhSxqb/dsaPEuTi4FoBnA/YNhP+rUDB 6xAhaGUZo3Yco6XgyYsWE1baV1Vz/Nm5IiBGjkQZUPtUwvnOVQiP49zxz90Y/UIxObvx 64uWT5u0lzkJ5CABINUdW407Ip01WLVnJ3kpRMjTV4jTqTclJap9Gf3o3wZxVJhrwjLe W8MbPfmwOKzsttfG3rOYbHkLutgPIbbgwAVbGiZ+8Z0roqTap330G7d0wuVcoOXT1jKp 0JC1241KBYsZ68h8srcZK9y7cz0FGe5w3rleB2U15nfBJ9pAs0gFzYIm/7oqQYlCVzUL mqXQ== X-Gm-Message-State: AFuF++lIX5G18xYgLeqpPP0gKWlnzrPqwNeOeWgsud08k25H8G0G0dmL 1CyNPFHnuux3+UeXDxpdsMjn8y2PPVfJ1cdlNUWeF4qMEZ28FvQ2sjhRAW3Wu7pA7nA0lgx0Te7 mfZDDewo= X-Gm-Gg: AR+sD12yqC5kw1TYxAmf48ZzkdF+rPsjmjB9XKGArfj9zDvjJrx1TNu8+z3YX+7yj8j xShzUKfB8v5hNTOxumwdJeQRYglP8ZReEHiPtUIKUu7Ble6pLf/Oec40LYCdejcTDyvUWIAzBzn KJTqH8HSrlRU3HSP864SUEoaJiY+eMnsdTVMRJhZbQoyCv37BXXshLc/ez7Y94bbo1vqG6W3DyO OTBAebQg+gk0dI0hXQppi/XK5Tritx3N1xHobB+pIAcpIj0bjvmqtqpdUU3H6QeVMtlykWBvLWy unmovAjJ82CK/KqnQJnypcyjDEXBjwzXlrBXJLMf2rLmoQmsq5ufsLUHFgy2j5+pe1GG/wj++P3 cAHbgQZeOP/TWzpI0NBCdnyHfZiZm2gDMwG/dGvmnLuI5SEeJZmv9XAASjdOZpdr4bvcd3F3Ls7 T4obCdv4adlqbVbnrekgqXyoRfc/Ziqk/O29PdqafghK7Z6r8za4GKDeOHgWdtDi82qdcqX7Hyw +rWc6ykSbBtxETAyfs1Fbiy0KUnqBmyer+zmaegFQMQr5dmjuxeHC87d3GTxjwNi1+cKvcqKmgc eJv+bg== X-Received: by 2002:a05:6000:22c7:b0:482:a36c:a5cd with SMTP id ffacd0b85a97d-482c81cb5a6mr29585121f8f.20.1787652438060; Tue, 25 Aug 2026 03:07:18 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Date: Tue, 25 Aug 2026 12:06:44 +0200 Message-ID: <4b86de3333748d41785365fc62f6afabb454b62b.1787652331.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244220 From: Adarsh Jagadish Kamini Backport patch to fix CVE-2026-58050. References: https://nvd.nist.gov/vuln/detail/CVE-2026-58050 Upstream fix: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12 Signed-off-by: Adarsh Jagadish Kamini Signed-off-by: Fabien Thomas --- .../libssh2/libssh2/CVE-2026-58050.patch | 45 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch new file mode 100644 index 00000000000..0163b379f35 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch @@ -0,0 +1,45 @@ +From 05b2fb4ec89d75235dbd97c5965dc0e46b405a7c Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 28 Jun 2026 02:12:52 +0200 +Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit + `libssh2_publickey_list_fetch()` + +Cap list size at 1024 elements. + +Reported-and-initial-patch-by: Mateusz Gierblinski +Reported-and-initial-patch-by: Behzod Abdullayev +Reported-by: Sharique Raza + +Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9 + +Closes #2128 + +src/publickey.c: replaced ssh2_err() with _libssh2_error() to match +the stable branch's error-reporting convention. + +Assisted-by: kiro:claude-sonnet-5 + +CVE: CVE-2026-58050 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12] + +Signed-off-by: Adarsh Jagadish Kamini +--- + src/publickey.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/src/publickey.c b/src/publickey.c +index 9c9fa618..196d2f9f 100644 +--- a/src/publickey.c ++++ b/src/publickey.c +@@ -1114,6 +1114,11 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys, + } + + if(list[keys].num_attrs) { ++ if(list[keys].num_attrs > 1024) { ++ _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY, ++ "Too many publickey attributes"); ++ goto err_exit; ++ } + list[keys].attrs = + LIBSSH2_ALLOC(session, + list[keys].num_attrs * diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index d14a27f3dc3..d3f39050474 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -20,6 +20,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-66033.patch \ file://CVE-2026-66034.patch \ file://CVE-2026-66035.patch \ + file://CVE-2026-58050.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Tue Aug 25 10:06:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96264 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1B0E8C61CE2 for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18584.1787652440682242623 for ; Tue, 25 Aug 2026 03:07:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YuA6/EUz; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-47f84023916so3180112f8f.3 for ; Tue, 25 Aug 2026 03:07:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652439; x=1788257239; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+JUIvUjOLR6AGSFoxGDFYQ3kyfssuer1zk4F9tspsJM=; b=YuA6/EUzojIXPGMnBD8B6BCJnJojYUyujMfsHsf6lqmy5WENh8nXgvlpLhypbt1ypu umNI2TnhxywH/goIWB1gwibzDDNXf7Jr9TUTEkR3HpfalCaLNGCKN7MD6smETpjeH9Tn g1LGT0ZeHuqtaPaAOcAtbFgUKPOFvMKfpPT50= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652439; x=1788257239; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=+JUIvUjOLR6AGSFoxGDFYQ3kyfssuer1zk4F9tspsJM=; b=IyE6sQx724HhNbewYYtUaXIKok/udgzTRsjySFact2qCviNOmiJkHNMnP0GnSx+UPV y9I9oeK3ZjWaPKFT3E+gIquWsUHTRibVv97M1We0EzjTvTdZUddZA2WlYMkDw1dg1VYM ouFV+9oTCDmTEvUwCP0NIOdv/J53GKLlRQXLPczrMdBNTcxXMae/ZA3K0Nxro+hO6bYW NZVS+MRhJqL5xxyjlpwx8ylOGngpUaFirOYC7oGNusdiCLuQ3KjtYV2XBj7UlsBBzhwx UqT7JErH3HshA72dW/nHVrzZyPAhYD3fM4y7p+eNT9g2Ki5cdRfaOkGFpRyOb5QFRM5w 7G5Q== X-Gm-Message-State: AFuF++nr9tgn39TQ/fleHCWuERL5z9IGgvht7mQ3mvavjQ1SJ1j2NJZ/ 0SNT1fBvOKqrVTu9MqE63kXV7+X2H65CyjcP2JWR+nTeBMlIXY9ak6hfW4PW9kKlvIGONZu0OQ8 hyPjkbpQ= X-Gm-Gg: AR+sD10QQMx489Z1Cm9Vp7RXjCjhvHDsJ2omiQ4/R9TbKEhzrTcMf2onyAFCjl5N669 GYq3yIFLibPkWdQbzFtxvIbY6hRI1Wyeq6M56j2SgBAqNeT+i9ykSDHU/5IiAyO52zD9mBnMGgs YNIBTCS9cD/Kp91aqm/GnE0b22y8lBV1+msvSmbIqC/LY7Zu+5EbDdn3X6NI77TjVgXjrIF+Ljl gskOQvARMeqgZrfViWCJShE7gVYq2Wnh3HVuEv3Y/DqOmtzjaTrz4nMOfSd9ZDVfTQ97tc4dq8x kxpmN2qfLiBxZBlIhvPoBH5ZZDqtNlyBSK6RL83Yls60U1KhFXg8OO19T49LRkORtvcpst2O4FB bGghqcLerv9UyxpvQeQtnx60emH1d5uCiG7ncsbsxNncnjhdMDJ8dYag2f1JpMAcJmaQ4VjpnJ6 SDByqaglRg1bP3SEourbyAZUKdBFrdjnQrubAmmfBEGVhblEE27OdEjrqs4hdf8t4RRUMjAVjga 6cKibPhmK33ac5ZPKWChDc7yfts2c3L2Fl6JhxSnPNqaO1ubjUayhWx8vMAvjagZDg7djM= X-Received: by 2002:a05:6000:2dc9:b0:482:9a18:d753 with SMTP id ffacd0b85a97d-482c0b44acbmr41023656f8f.5.1787652438639; Tue, 25 Aug 2026 03:07:18 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Date: Tue, 25 Aug 2026 12:06:45 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244221 From: Deepak Rathore This patch applies the upstream glib-2-88 stable backport chain for CVE-2026-58015. The issue is in the D-Bus SHA-1 authentication mechanism, where a malicious peer could provide an unchecked cookie context and cause the client to access unintended files while resolving the cookie challenge. Backport the upstream GLib fix chain from the glib-2-88 stable branch: - db9c8fae398b validates cookie_context before keyring lookup. This is the primary security fix for CVE-2026-58015 [1]. - c0531125344b tightens cookie ID parsing so empty, negative, and out-of-range values are rejected. This hardens the same SHA-1 cookie challenge parser and is covered by the upstream regression test [2]. - 060aea67de75 exposes the private client reject-reason vfunc. This is test-support plumbing required by the upstream regression test [3]. - 091930196229 adds the upstream regression test for SHA-1 cookie challenge parsing [4]. Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon when building the new installed D-Bus regression test for ptest. This is kept as a native-only test dependency to avoid adding a target dbus dependency to glib. [1] https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a [2] https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb [3] https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22 [4] https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277 [5] https://nvd.nist.gov/vuln/detail/CVE-2026-58015 Signed-off-by: Deepak Rathore Signed-off-by: Fabien Thomas --- .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch | 97 ++++++++ .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch | 55 +++++ .../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 ++++++++++++++++ .../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++++++++++ meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 4 + meta/recipes-core/glib-2.0/glib.inc | 2 +- 6 files changed, 577 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch new file mode 100644 index 00000000000..1216e1a12b1 --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch @@ -0,0 +1,97 @@ +From 1d0d0dc891399e8572a6c96b116149d076e2de28 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 28 Apr 2026 15:47:30 +0100 +Subject: [PATCH 1/4] gdbusauthmechanismsha1: Validate cookie context +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Without validation, the server could send a malicious context which +contains path traversal characters, allowing it to exfiltrate a SHA-1 +hashed copy of arbitrary data from the client’s file system. + +To exploit this successfully would require the client to choose to +connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1 +authentication mechanism in preference to all the other mechanisms. This +is vanishingly unlikely. + +CVE: CVE-2026-58015 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a] + +Backport Changes: +- Added include because the target branch does not otherwise + expose uint8_t used by the upstream validation code during native builds. + +Signed-off-by: Philip Withnall + +Fixes: #3931 +(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a) +Signed-off-by: Deepak Rathore +--- + gio/gdbusauthmechanismsha1.c | 37 ++++++++++++++++++++++++++++++++++++ + 1 file changed, 37 insertions(+) + +diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c +index c8aa08977..7d8fc1922 100644 +--- a/gio/gdbusauthmechanismsha1.c ++++ b/gio/gdbusauthmechanismsha1.c +@@ -22,6 +22,7 @@ + + #include "config.h" + ++#include + #include + #include + #include +@@ -1198,6 +1199,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism, + return initial_response; + } + ++/* Context names must be valid ASCII, nonzero length, and may not contain the ++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"), ++ * carriage return ("\r"), tab ("\t"), or period ("."). ++ * ++ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */ ++static gboolean ++validate_cookie_context (const char *cookie_context) ++{ ++ size_t i = 0; ++ ++ g_return_val_if_fail (cookie_context != NULL, FALSE); ++ ++ for (i = 0; cookie_context[i] != '\0'; i++) ++ { ++ if ((uint8_t) cookie_context[i] >= 128 || ++ cookie_context[i] == '/' || ++ cookie_context[i] == '\\' || ++ cookie_context[i] == ' ' || ++ cookie_context[i] == '\n' || ++ cookie_context[i] == '\r' || ++ cookie_context[i] == '\t' || ++ cookie_context[i] == '.') ++ return FALSE; ++ } ++ ++ return (i > 0); ++} ++ + static void + mechanism_client_data_receive (GDBusAuthMechanism *mechanism, + const gchar *data, +@@ -1232,6 +1261,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism, + } + + cookie_context = tokens[0]; ++ if (!validate_cookie_context (tokens[0])) ++ { ++ g_free (m->priv->reject_reason); ++ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]); ++ m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED; ++ goto out; ++ } ++ + cookie_id = g_ascii_strtoll (tokens[1], &endp, 10); + if (*endp != '\0') + { +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch new file mode 100644 index 00000000000..28f496734a5 --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch @@ -0,0 +1,55 @@ +From a94b2df7e2bc5f49661e53c2781ce99ae48d18aa Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 28 Apr 2026 15:49:54 +0100 +Subject: [PATCH 2/4] gdbusauthmechanismsha1: Improve validation of cookie ID +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The D-Bus specification says the cookie ID has to be non-negative, but +we weren’t checking that (or checking that it was non-empty). + +CVE: CVE-2026-58015 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb] + +Signed-off-by: Philip Withnall +(cherry picked from commit c0531125344bb25fd66ffb7435ed6c285de09aeb) +Signed-off-by: Deepak Rathore +--- + gio/gdbusauthmechanismsha1.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c +index 7d8fc1922..e753d139d 100644 +--- a/gio/gdbusauthmechanismsha1.c ++++ b/gio/gdbusauthmechanismsha1.c +@@ -1235,7 +1235,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism, + GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism); + gchar **tokens; + const gchar *cookie_context; +- guint cookie_id; ++ int64_t cookie_id; + const gchar *server_challenge; + gchar *client_challenge; + gchar *endp; +@@ -1270,7 +1270,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism, + } + + cookie_id = g_ascii_strtoll (tokens[1], &endp, 10); +- if (*endp != '\0') ++ if (*endp != '\0' || endp == tokens[1] || cookie_id < 0 || cookie_id > UINT32_MAX) + { + g_free (m->priv->reject_reason); + m->priv->reject_reason = g_strdup_printf ("Malformed cookie_id '%s'", tokens[1]); +@@ -1280,7 +1280,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism, + server_challenge = tokens[2]; + + error = NULL; +- cookie = keyring_lookup_entry (cookie_context, cookie_id, &error); ++ cookie = keyring_lookup_entry (cookie_context, (unsigned int) cookie_id, &error); + if (cookie == NULL) + { + g_free (m->priv->reject_reason); +-- +2.35.6 + diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch new file mode 100644 index 00000000000..b6bd2baeb3f --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch @@ -0,0 +1,198 @@ +From 99c7abffbd1d549f6c625de6f2028efcdeea5c49 Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 28 Apr 2026 15:51:00 +0100 +Subject: [PATCH 3/4] gdbusauthmechanism: Expose client reject reason as a new + vfunc + +We can do this because `gdbusauthmechanism.h` is a private header. + +Hook it up to the existing `reject_reason` code in each +`GDBusAuthMechanism` implementation, as all three implementations +currently intermingle reject reasons from the server and client code, so +there would currently be no benefit to having a separate server and +client implementation of `*_get_reject_reason()`. + +This new private API will be used in a new unit test in the following +commit. + +CVE: CVE-2026-58015 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22] + +Signed-off-by: Philip Withnall +(cherry picked from commit 060aea67de7517d531b8fe2cdc07aa1a00ddeb22) +Signed-off-by: Deepak Rathore +--- + gio/gdbusauthmechanism.c | 7 +++++++ + gio/gdbusauthmechanism.h | 2 ++ + gio/gdbusauthmechanismanon.c | 8 ++++---- + gio/gdbusauthmechanismexternal.c | 8 ++++---- + gio/gdbusauthmechanismsha1.c | 8 ++++---- + 5 files changed, 21 insertions(+), 12 deletions(-) + +diff --git a/gio/gdbusauthmechanism.c b/gio/gdbusauthmechanism.c +index 6e494dbd9..0d4ef4389 100644 +--- a/gio/gdbusauthmechanism.c ++++ b/gio/gdbusauthmechanism.c +@@ -328,6 +328,13 @@ _g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism, + return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_send (mechanism, out_data_len); + } + ++gchar * ++_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism) ++{ ++ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM (mechanism), NULL); ++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism); ++} ++ + void + _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism) + { +diff --git a/gio/gdbusauthmechanism.h b/gio/gdbusauthmechanism.h +index f0edd19a3..e906a47ac 100644 +--- a/gio/gdbusauthmechanism.h ++++ b/gio/gdbusauthmechanism.h +@@ -100,6 +100,7 @@ struct _GDBusAuthMechanismClass + gsize data_len); + gchar *(*client_data_send) (GDBusAuthMechanism *mechanism, + gsize *out_data_len); ++ gchar *(*client_get_reject_reason) (GDBusAuthMechanism *mechanism); + void (*client_shutdown) (GDBusAuthMechanism *mechanism); + }; + +@@ -148,6 +149,7 @@ void _g_dbus_auth_mechanism_client_data_receive (GDBus + gsize data_len); + gchar *_g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism, + gsize *out_data_len); ++gchar *_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism); + void _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism); + + +diff --git a/gio/gdbusauthmechanismanon.c b/gio/gdbusauthmechanismanon.c +index 5f59d4a61..3d80ec15f 100644 +--- a/gio/gdbusauthmechanismanon.c ++++ b/gio/gdbusauthmechanismanon.c +@@ -56,7 +56,7 @@ static void mechanism_server_data_receive (GDBusAuthMe + gsize data_len); + static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism, + gsize *out_data_len); +-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism); ++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism); + static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism); + static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism); + static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism, +@@ -103,12 +103,13 @@ _g_dbus_auth_mechanism_anon_class_init (GDBusAuthMechanismAnonClass *klass) + mechanism_class->server_initiate = mechanism_server_initiate; + mechanism_class->server_data_receive = mechanism_server_data_receive; + mechanism_class->server_data_send = mechanism_server_data_send; +- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason; ++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->server_shutdown = mechanism_server_shutdown; + mechanism_class->client_get_state = mechanism_client_get_state; + mechanism_class->client_initiate = mechanism_client_initiate; + mechanism_class->client_data_receive = mechanism_client_data_receive; + mechanism_class->client_data_send = mechanism_client_data_send; ++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->client_shutdown = mechanism_client_shutdown; + } + +@@ -222,12 +223,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism, + } + + static gchar * +-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism) ++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism) + { + GDBusAuthMechanismAnon *m = G_DBUS_AUTH_MECHANISM_ANON (mechanism); + + g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_ANON (mechanism), NULL); +- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL); + g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL); + + /* can never end up here because we are never in the REJECTED state */ +diff --git a/gio/gdbusauthmechanismexternal.c b/gio/gdbusauthmechanismexternal.c +index 6fe8b1bed..b223ead04 100644 +--- a/gio/gdbusauthmechanismexternal.c ++++ b/gio/gdbusauthmechanismexternal.c +@@ -64,7 +64,7 @@ static void mechanism_server_data_receive (GDBusAuthMe + gsize data_len); + static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism, + gsize *out_data_len); +-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism); ++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism); + static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism); + static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism); + static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism, +@@ -111,12 +111,13 @@ _g_dbus_auth_mechanism_external_class_init (GDBusAuthMechanismExternalClass *kla + mechanism_class->server_initiate = mechanism_server_initiate; + mechanism_class->server_data_receive = mechanism_server_data_receive; + mechanism_class->server_data_send = mechanism_server_data_send; +- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason; ++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->server_shutdown = mechanism_server_shutdown; + mechanism_class->client_get_state = mechanism_client_get_state; + mechanism_class->client_initiate = mechanism_client_initiate; + mechanism_class->client_data_receive = mechanism_client_data_receive; + mechanism_class->client_data_send = mechanism_client_data_send; ++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->client_shutdown = mechanism_client_shutdown; + } + +@@ -321,12 +322,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism, + } + + static gchar * +-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism) ++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism) + { + GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism); + + g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL); +- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL); + g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL); + + /* can never end up here because we are never in the REJECTED state */ +diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c +index e753d139d..6c1682d3a 100644 +--- a/gio/gdbusauthmechanismsha1.c ++++ b/gio/gdbusauthmechanismsha1.c +@@ -120,7 +120,7 @@ static void mechanism_server_data_receive (GDBusAuthMe + gsize data_len); + static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism, + gsize *out_data_len); +-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism); ++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism); + static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism); + static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism); + static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism, +@@ -173,12 +173,13 @@ _g_dbus_auth_mechanism_sha1_class_init (GDBusAuthMechanismSha1Class *klass) + mechanism_class->server_initiate = mechanism_server_initiate; + mechanism_class->server_data_receive = mechanism_server_data_receive; + mechanism_class->server_data_send = mechanism_server_data_send; +- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason; ++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->server_shutdown = mechanism_server_shutdown; + mechanism_class->client_get_state = mechanism_client_get_state; + mechanism_class->client_initiate = mechanism_client_initiate; + mechanism_class->client_data_receive = mechanism_client_data_receive; + mechanism_class->client_data_send = mechanism_client_data_send; ++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason; + mechanism_class->client_shutdown = mechanism_client_shutdown; + } + +@@ -1129,12 +1130,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism, + } + + static gchar * +-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism) ++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism) + { + GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism); + + g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_SHA1 (mechanism), NULL); +- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL); + g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL); + + return g_strdup (m->priv->reject_reason); +-- +2.35.6 + diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch new file mode 100644 index 00000000000..0785ad3c3a6 --- /dev/null +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch @@ -0,0 +1,222 @@ +From 80d2edcc14f476d0ec82dc0733964afa6e9ca74d Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Tue, 28 Apr 2026 15:52:53 +0100 +Subject: [PATCH 4/4] tests: Add a unit test for GDBusAuthMechanismSha1 cookie + context parsing + +This checks for regressions in the fixes from the previous few commits. + +CVE: CVE-2026-58015 +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277] + +Backport Changes: +- Replaced the literal U+1F600 test string with its UTF-8 byte escapes to + avoid the observed Patchwork mbox truncation. The test input is unchanged. + +Signed-off-by: Philip Withnall +Helps: #3931 +(cherry picked from commit 0919301962291a712067ee0c5d273cc392f33277) +Signed-off-by: Deepak Rathore +--- + gio/tests/gdbus-auth-mechanism-sha1.c | 177 ++++++++++++++++++++++++++ + gio/tests/meson.build | 1 + + 2 files changed, 178 insertions(+) + create mode 100644 gio/tests/gdbus-auth-mechanism-sha1.c + +diff --git a/gio/tests/gdbus-auth-mechanism-sha1.c b/gio/tests/gdbus-auth-mechanism-sha1.c +new file mode 100644 +index 000000000..abcdb4e3e +--- /dev/null ++++ b/gio/tests/gdbus-auth-mechanism-sha1.c +@@ -0,0 +1,177 @@ ++/* GLib testing framework examples and tests ++ * ++ * Copyright (C) 2026 Philip Withnall ++ * ++ * SPDX-License-Identifier: LGPL-2.1-or-later ++ * ++ * This library is free software; you can redistribute it and/or ++ * modify it under the terms of the GNU Lesser General Public ++ * License as published by the Free Software Foundation; either ++ * version 2.1 of the License, or (at your option) any later version. ++ * ++ * This library is distributed in the hope that it will be useful, ++ * but WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ * Lesser General Public License for more details. ++ * ++ * You should have received a copy of the GNU Lesser General ++ * Public License along with this library; if not, see . ++ * ++ * Author: Philip Withnall ++ */ ++ ++#include ++#include ++ ++#include ++#include ++ ++#include "gdbus-tests.h" ++ ++#ifdef G_OS_UNIX ++#include ++#include ++#include ++#include ++#endif ++ ++#define GIO_COMPILATION 1 ++#include "gdbusauthmechanism.h" ++#include "gdbusauthmechanismsha1.h" ++ ++/* Vfunc wrappers copied from gdbusauthmechanism.c as they are not public. */ ++static gboolean ++dbus_auth_mechanism_is_supported (GDBusAuthMechanism *mechanism) ++{ ++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->is_supported (mechanism); ++} ++ ++static GDBusAuthMechanismState ++dbus_auth_mechanism_client_get_state (GDBusAuthMechanism *mechanism) ++{ ++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_state (mechanism); ++} ++ ++static gchar * ++dbus_auth_mechanism_client_initiate (GDBusAuthMechanism *mechanism, ++ GDBusConnectionFlags conn_flags, ++ size_t *out_initial_response_len) ++{ ++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_initiate (mechanism, ++ conn_flags, ++ out_initial_response_len); ++} ++ ++static void ++dbus_auth_mechanism_client_data_receive (GDBusAuthMechanism *mechanism, ++ const char *data, ++ size_t data_len) ++{ ++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_receive (mechanism, data, data_len); ++} ++ ++static char * ++dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism) ++{ ++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism); ++} ++ ++static void ++dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism) ++{ ++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_shutdown (mechanism); ++} ++ ++static void ++test_server_challenge_validation (void) ++{ ++ const struct ++ { ++ const char *server_challenge; ++ const char *expected_reject_reason_prefix; ++ } ++ vectors[] = { ++ { "valid_context 123 456", "Problems looking up entry in keyring" }, ++ { "invalid/context 123 456", "Malformed cookie_context" }, ++ { "invalid.context 123 456", "Malformed cookie_context" }, ++ { " 123 456", "Malformed cookie_context" }, ++ { "\xF0\x9F\x98\x80" " 123 456", "Malformed cookie_context" }, ++ { "invalid\ncontext 123 456", "Malformed cookie_context" }, ++ { "invalid\rcontext 123 456", "Malformed cookie_context" }, ++ { "invalid\tcontext 123 456", "Malformed cookie_context" }, ++ { "invalid\\context 123 456", "Malformed cookie_context" }, ++ { "valid_context 456", "Malformed cookie_id" }, ++ { "valid_context 123notanumber 456", "Malformed cookie_id" }, ++ { "valid_context -1 456", "Malformed cookie_id" }, ++ { "valid_context 4294967296 456", "Malformed cookie_id" }, ++ { "valid_context 123 ", "Malformed data" }, ++ { "valid_context ", "Malformed data" }, ++ }; ++ GType mechanism_type; ++ GDBusConnection *connection = NULL; ++ ++ g_test_summary ("Test that GDBusAuthMechanismSha1 rejects various malformed server data lines"); ++ ++ /* Briefly connect to the actual bus to ensure the GDBusAuth mechanisms are ++ * all registered. */ ++ session_bus_up (); ++ ++ connection = g_bus_get_sync (G_BUS_TYPE_SESSION, NULL, NULL); ++ g_assert_nonnull (connection); ++ g_clear_object (&connection); ++ ++ session_bus_down (); ++ ++ /* Check that we now have the type ID for GDBusAuthMechanismSha1 */ ++ mechanism_type = g_type_from_name ("GDBusAuthMechanismSha1"); ++ g_assert_cmpint (mechanism_type, !=, 0); ++ ++ for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++) ++ { ++ GDBusAuthMechanism *mechanism = NULL; ++ char *data = NULL; ++ size_t data_len = 0; ++ char *reject_reason = NULL; ++ ++ mechanism = g_object_new (mechanism_type, NULL); ++ ++ if (!dbus_auth_mechanism_is_supported (mechanism)) ++ { ++ g_test_skip ("Mechanism not supported"); ++ g_clear_object (&mechanism); ++ return; ++ } ++ ++ data = dbus_auth_mechanism_client_initiate (mechanism, ++ G_DBUS_CONNECTION_FLAGS_AUTHENTICATION_CLIENT, ++ &data_len); ++ g_free (data); ++ ++ dbus_auth_mechanism_client_data_receive (mechanism, vectors[i].server_challenge, strlen (vectors[i].server_challenge)); ++ ++ g_assert_cmpint (dbus_auth_mechanism_client_get_state (mechanism), ==, G_DBUS_AUTH_MECHANISM_STATE_REJECTED); ++ ++ reject_reason = dbus_auth_mechanism_client_get_reject_reason (mechanism); ++ g_assert_true (g_str_has_prefix (reject_reason, vectors[i].expected_reject_reason_prefix)); ++ g_free (reject_reason); ++ ++ dbus_auth_mechanism_client_shutdown (mechanism); ++ ++ g_clear_object (&mechanism); ++ } ++} ++ ++int ++main (int argc, ++ char *argv[]) ++{ ++ setlocale (LC_ALL, "C"); ++ ++ g_test_init (&argc, &argv, G_TEST_OPTION_ISOLATE_DIRS, NULL); ++ ++ g_test_dbus_unset (); ++ ++ g_test_add_func ("/gdbus/auth-mechanism-sha1/server-challenge-validation", test_server_challenge_validation); ++ ++ return g_test_run (); ++} +diff --git a/gio/tests/meson.build b/gio/tests/meson.build +index e7699c336..74ea481ff 100644 +--- a/gio/tests/meson.build ++++ b/gio/tests/meson.build +@@ -418,6 +418,7 @@ if host_system != 'windows' + }, + 'fdo-notification-backend': {}, + 'gdbus-auth' : {'extra_sources' : extra_sources}, ++ 'gdbus-auth-mechanism-sha1': {'extra_sources' : extra_sources}, + 'gdbus-bz627724' : {'extra_sources' : extra_sources}, + 'gdbus-close-pending' : {'extra_sources' : extra_sources}, + 'gdbus-connection' : { +-- +2.35.6 diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb index e15aa1fe206..70b0b74e881 100644 --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb @@ -54,6 +54,10 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \ file://CVE-2026-58012.patch \ file://CVE-2026-58013.patch \ file://CVE-2026-58014.patch \ + file://CVE-2026-58015_p1.patch \ + file://CVE-2026-58015_p2.patch \ + file://CVE-2026-58015_p3.patch \ + file://CVE-2026-58015_p4.patch \ " SRC_URI:append:class-native = " file://relocate-modules.patch \ file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc index fac8875d844..5b69c9d7d3e 100644 --- a/meta/recipes-core/glib-2.0/glib.inc +++ b/meta/recipes-core/glib-2.0/glib.inc @@ -39,7 +39,7 @@ PACKAGECONFIG ??= "libmount \ PACKAGECONFIG[libmount] = "-Dlibmount=enabled,-Dlibmount=disabled,util-linux" PACKAGECONFIG[manpages] = "-Dman=true, -Dman=false, libxslt-native xmlto-native" PACKAGECONFIG[libelf] = "-Dlibelf=enabled,-Dlibelf=disabled,elfutils" -PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false," +PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,dbus-native" PACKAGECONFIG[selinux] = "-Dselinux=enabled,-Dselinux=disabled,libselinux" EXTRA_OEMESON = "-Ddtrace=false -Dsystemtap=false" From patchwork Tue Aug 25 10:06:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96261 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1F76EC61DBD for ; Tue, 25 Aug 2026 10:07:23 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18284.1787652441085495023 for ; Tue, 25 Aug 2026 03:07:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Y8wcFi8Y; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-482db627cd8so174776f8f.1 for ; Tue, 25 Aug 2026 03:07:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652439; x=1788257239; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=zbzCIWdwroEPHNGBRA7/XSSOoaYdbOzoMfGhi97ifq4=; b=Y8wcFi8YHPSMAHTT8cNR3mVOXEodSDWFVgb9T03xmFyLh+6+S+MXpmSeBiHxJtLpj4 TQwhGj4OWhUwMUWjVp9ZVxE2lkPaCCFRlgIJbiVwPTRvc91MS3dOrP5KgdQE/gnBWrw1 b0IkUpcbgHQrV4Yk0705XGLE5OWnO/eLjywgk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652439; x=1788257239; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=zbzCIWdwroEPHNGBRA7/XSSOoaYdbOzoMfGhi97ifq4=; b=rc6db4LzzX5jY2sxmfJZwYkWnaBoHZY5ZN8ZY4+hHBTr1GlpaaxLxjJu6UvTFUJbE9 qgzErqCxgOOMoiSFOIukouzkgzSpJ+A8bcyejdveI/db/UpCGu5iIz/SQTEsogcYttSD oiNy90ugahEbk3VzIm8ueEL3nFRJaQQ/CqXVcDX/B6rLepkpvGTAY1QHEtcCqC6rcYNd vQsyeltIkQlHz3sI4B3UVA3TuGAF36wejhMoHqTTEl7WDZe4FFB2VnwTE6z2wjvWxL0z 4WoXR1ieahpkENb4eGMd0nZUYP12zKlRQHARY5Way0G9EErSRq1yciSjGtb2hMuSW1PG HBTA== X-Gm-Message-State: AFuF++kQZ4+DDEMbmGJ1k7Vv5wbWjdpDT/yOUAYz+houe58VgEygb8Sj kJukCUWZCNE3gGsXvM3HagYXQeHkGNF00fZ3t8cBA8tee1zN9xyDr4MdbkBdL3H1BQHrZev6HxH lmBhTrO4= X-Gm-Gg: AR+sD10+IPbNRVNX7/DRwHuKFAxRLKaTf+R66by1Diwo7Tkt3d8CzLquyqpnmgKSy6V Hmo3Vnd5t6+zugQFjYHPlhrMYqQRSpwJdvObGWeQWXfr+xhCPw2tLXQg5hzRSoX4MsbGya3VaMC LNtzUiTdGGrO4wpP/aruRDpW+i/F8mRPSHOKX4dkuLxyonbP2xnALF4+jjDkDhwXMRpKGF9Y6wD 95r2gF+lFkUP5urbwDJ+7jSlzmgSIVlBECcXXGVaqSzJaRc5Yf5myGaNQ7MaHwR+jL/tmZHK5W5 QEGOFmHZ37i9Wz/vYTFazd5JtnUhKdPeWUceMhmN52hGHWCMRdiQqRPna1vuBwyZOEmYhu26dk5 AGxZNOr4vgwcv9aHGYfG0xuQTZFcTwkwHy8HZWz0wAL7kwRh7Rosdwve+v+HYbcB6TxAUDCUvtB xyin/v//N+txL5djxtzOSDUroFfUFEt3+r7pB9OKWGFfifAts8CfJrh8QUZPKQ227QDr3lcArDR 46X0SgkSTi/lIpSoWPW+sAjBmAWMSQyHrw8LYOUWAl/05Ekf9kJWb4vNApx3TpKNrF/yYw= X-Received: by 2002:a05:6000:461c:b0:47f:86d5:d1d7 with SMTP id ffacd0b85a97d-482c0b63396mr48770807f8f.6.1787652439168; Tue, 25 Aug 2026 03:07:19 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Date: Tue, 25 Aug 2026 12:06:46 +0200 Message-ID: <152c139de6b1ad00d904b5fd16b4abc9852459a4.1787652331.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244222 From: Etienne Cordonnier The original backport applied upstream's CURLcode return path into ssize_t ws_enc_write_head(), which uses an undeclared result and is invalid for curl 8.7.1's API. Builds with --enable-websockets fail. Adapt Curl_rand() error handling to set *err and return -1. AI-Generated: Claude Sonnet 4.6 Signed-off-by: Etienne Cordonnier Signed-off-by: Fabien Thomas --- .../curl/curl/CVE-2025-10148.patch | 24 +++++++++++-------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/meta/recipes-support/curl/curl/CVE-2025-10148.patch b/meta/recipes-support/curl/curl/CVE-2025-10148.patch index d37497febe9..654f4151e99 100644 --- a/meta/recipes-support/curl/curl/CVE-2025-10148.patch +++ b/meta/recipes-support/curl/curl/CVE-2025-10148.patch @@ -9,23 +9,28 @@ Closes #18496 CVE: CVE-2025-10148 Upstream-Status: Backport [https://github.com/curl/curl/commit/84db7a9eae8468c0445b15aa806fa] Signed-off-by: Hitendra Prajapati +Signed-off-by: Etienne Cordonnier --- - lib/ws.c | 21 +++++++++++++-------- - 1 file changed, 13 insertions(+), 8 deletions(-) + lib/ws.c | 25 +++++++++++++++++-------- + 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/lib/ws.c b/lib/ws.c index 5bc5ecc..02e0ef0 100644 --- a/lib/ws.c +++ b/lib/ws.c -@@ -614,6 +614,18 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data, +@@ -614,6 +614,22 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data, enc->payload_remain = enc->payload_len = payload_len; ws_enc_info(enc, data, "sending"); -+ /* 4 bytes random */ -+ -+ result = Curl_rand(data, (unsigned char *)&enc->mask, sizeof(enc->mask)); -+ if(result) -+ return result; ++ /* 4 bytes random */ ++ { ++ CURLcode result = Curl_rand(data, (unsigned char *)&enc->mask, ++ sizeof(enc->mask)); ++ if(result) { ++ *err = result; ++ return -1; ++ } ++ } + +#ifdef DEBUGBUILD + if(getenv("CURL_WS_FORCE_ZERO_MASK")) @@ -36,7 +41,7 @@ index 5bc5ecc..02e0ef0 100644 /* add 4 bytes mask */ memcpy(&head[hlen], &enc->mask, 4); hlen += 4; -@@ -802,14 +814,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data, +@@ -802,14 +818,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data, subprotocol not requested by the client), the client MUST Fail the WebSocket Connection. */ @@ -54,4 +59,3 @@ index 5bc5ecc..02e0ef0 100644 result = Curl_cwriter_create(&ws_dec_writer, data, &ws_cw_decode, -- 2.50.1 - From patchwork Tue Aug 25 10:06:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96259 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E40A8C61DB6 for ; Tue, 25 Aug 2026 10:07:22 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18285.1787652441718470520 for ; Tue, 25 Aug 2026 03:07:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QclSr3dn; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-47fecbb7000so1707453f8f.2 for ; Tue, 25 Aug 2026 03:07:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652440; x=1788257240; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IX3x/QEoev3p98aTF9AxHVSWjGME4MgvRZA8po6mNbI=; b=QclSr3dnwGKedVjvm7NGVV2oiQl0TeCTAvWh0En6X29PNJt1brnKlXUrNhcAcbJIxv 7bUFJ/VyhIIlKWtmRkynwXvGbUYg5PsTnZnk1XXRs2Uo+v3Q3/+qxPvdO0rYxj676gyz dIBvakTj+oLlhLmDSP8KcbuTGFn38IspUZgh8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652440; x=1788257240; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IX3x/QEoev3p98aTF9AxHVSWjGME4MgvRZA8po6mNbI=; b=bm/XRFOaPnekus4NwxVLMQgqGc9ffV7ZGkUJFnYk9SvD91ReimDOwA4CDmJ7eTUjIv XnQo+M5OjPzauZaxY3pnoQAJRVx5tjQ0qoPqy4bFjdxu3nLdWhsII2A8D/0aPpaOaMod aAvl9FyRMWNw89lt8rZUMOVpqE83x1N7WhQpMgBBudJZpw8hDUGDERpopQxEtGU7yOXX Y89tGpIaR8EFKVwHf3Fs4qe8MqEgXoPaWoAJzZ2lYA6ra2BVb+qmU8AYaH7ZTP4TkE6v rOpM+VXF5OsdQh83S+iE7Kojaic8beuImHhCSDTMN7/r+awAiUZO5Wr6LG0bZ7Z+QsfA +CBw== X-Gm-Message-State: AFuF++nI3qsItNGav8iQvDuqH1zhyyGKpev0a7Ub6LMV+4vnFqjL4Xi0 T4Y/fwlCkCBTmBveHFVnDeeggSWtP0p+VQIr5/dbf5GzD2CGOsYIH8Bl14flwi9r0bty/jr5RQK MN7gK9PA= X-Gm-Gg: AR+sD11r//MUm7/IsDMO57fNAQDXNcINbm++4T9SZc+Bdl/6turEMajUrx1/IwDe8ha 2Tcx1LsINyYuE/d9aqSXZ2Lz9HXiu4v6parG/CyELdkqZ6/JlXE9x3UQa9hMid/8Lj+fjaKNnKA aVtlZlMV1rxxcT5Y2rvSoQQUPLTlpJZV6KP7Zaw5bG+9BR0fUEgw90gqDOEoGsAAOaRlZ87o3dk w0xlPjgNbibf2/x2L0ElCBa4c5yVnCj5vTPpv6MLK/QLYGz0hcFOV/WSxXbKRP726bWYe+MAcAF f/zsWq5RpgRnyprXvJP0ywIu3K2Ubx75boeOI8jz/59t3FHmV6azTsgIhKkT+PV9zmyL6gfNZaR aWR1ZQB8Za0ynHVpZ0R+HACG1in61sZRaMV30rHTPXKPgbB3uNlkPnZ7QGG48+L92SjZDa0akeq obrgtrPf6PaaY4CN0gFh/xmPFUmHi124ZR8FL6AMOCMQPnA0RGyndfjdlWSAJBEsLpoRjt/LMRP KK4nubVAT62KbP3BIMmMxN1PBCRgUjHoIzihauh5eL6AofkdNaIwwa7rF4fuAOjGKDWHLzTwqeX hGIuKg== X-Received: by 2002:a5d:64c8:0:b0:47f:83ee:e56f with SMTP id ffacd0b85a97d-482c81ca417mr29938896f8f.18.1787652439834; Tue, 25 Aug 2026 03:07:19 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Date: Tue, 25 Aug 2026 12:06:47 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244223 From: Ross Burton We export GIT_CEILING_DIRECTORIES=WORKDIR to ensure that git calls inside the builds don't find oe-core when they're meant to be looking for the git repository of the source code. However, this breaks for recipes that use work-shared (such as llvm), as their working directory is outside of WORKDIR. Solve this by adding TMPDIR to the list as a final catch, but keeping WORKDIR first so that git will stop sooner in the general case. This solves reproduciblity problems in LLVM, where for example lld's version string would contain the URL and commit hash of the poky repo being built. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (cherry picked from commit f42f0185bd00e68ecc86a930487f21fc86214cfa) Signed-off-by: Etienne Cordonnier [fatho: edit commit message by adding "cherry picked from"] Signed-off-by: Fabien Thomas --- meta/conf/bitbake.conf | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/meta/conf/bitbake.conf b/meta/conf/bitbake.conf index e20b17fad6f..3fd442edbdd 100644 --- a/meta/conf/bitbake.conf +++ b/meta/conf/bitbake.conf @@ -786,9 +786,9 @@ export PKG_CONFIG_DISABLE_UNINSTALLED = "yes" export PKG_CONFIG_SYSTEM_LIBRARY_PATH = "${base_libdir}:${libdir}" export PKG_CONFIG_SYSTEM_INCLUDE_PATH = "${includedir}" -# Don't allow git to chdir up past WORKDIR so that it doesn't detect the OE -# repository when building a recipe -export GIT_CEILING_DIRECTORIES = "${WORKDIR}" +# Don't allow git to chdir up past WORKDIR or TMPDIR so that it doesn't detect the OE +# repository when building a recipe. +export GIT_CEILING_DIRECTORIES = "${WORKDIR}:${TMPDIR}" ### ### Config file processing From patchwork Tue Aug 25 10:06:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96268 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 113D5C61DCA for ; Tue, 25 Aug 2026 10:07:24 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18286.1787652443142539154 for ; Tue, 25 Aug 2026 03:07:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=F1IzGb53; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-47fe2d179e2so2335370f8f.1 for ; Tue, 25 Aug 2026 03:07:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652441; x=1788257241; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=C9bgPkmsOxfT49SglkXgLymGc6XuEtiT1UbArxsqk/k=; b=F1IzGb53AS39eA2JFqLk3dtznXuozIMfxCeK4FMKfecx8TZa+F6FqXFAe+UP+k91GT rBp4D6k6NIc0MEQH+buhp6L7+RzMghHK9NuIbQg+2EPvBoRn+TSD9CATbxKWxT9pl0Jz swKuP65kIkLj0AtOnmPKDMOOqusB5CjS0q2Ms= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652441; x=1788257241; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=C9bgPkmsOxfT49SglkXgLymGc6XuEtiT1UbArxsqk/k=; b=WmdSSwjU26A9zjTxnApzv9VRg7/lUyed2GijkzyalDVnaODsFWiFAZoDyEz5AYMCLB L9jZuX5MC7fys7zoKZTkidnNHBjBdtNPPjqsDc5zbG0lR66WBhByH+a/mHUvo5zl1A/X bBJZ76pC7wVPQXjQDCXBsqLTPWGzLhgZEGTPwmnAPdfMh1cnTKOpyqg/nTQi80Qd6tAZ S0MgUDXOB8+hnG/eNJ8i1nPCV6uxUZPq1sYMoZ1S9BxT1E4NYxRxS86C2AjD8KEWVVIb xwj++rdDt9u3lPeRSVR37V0y9svsQiK5d0sSb/LQXTrQMsSXB81RXm2BoMM/bqcC/AMl ekQQ== X-Gm-Message-State: AFuF++kNkThuAwO4JXTr2sKjwKwwbEy0/5GYT0nys1FVNIiz5a+lYhy9 sFAAdd/PrTqm55o4de6QvJ2K64pmvNP20xtkTR57SVYlAbfO9nsE2uuewoVhftZNpUtVhI933De JkdAz9EE= X-Gm-Gg: AR+sD11ojCI81mWJoi7ZjKcux5HTqHF8ih3ZwOPhkBVm6YoUti2/sCoUIl/riESCNGE xyKwN9qX45mEmN1xwgfkVIvoGOT3OBKuaJshjExAhEnd/KFohOVuFpfRZ6tpv8/dKem5BkyskZV o3AHlW+oZdzDzGBiMFys9T7bvGLGQCXiN2NGQrY4mcgk77L7iHz3PhcVeE2UbaBUZmywEbtRl8w ArPicYsYqZHs2ULWbatbaEDouDLQfrZj6zKTPERQ5wMjErTY1TTta3or1bf4vLwHv6POa8JYam6 1J4EIlpYKlTwb+SQXTtqWhJr0UowMpuTs+RnIX8xYu/27GH9SFR80DE++0xC33SSObzDqocetrr PUIjBEyVHT4PtlurP4dH0AW8+EaVDQGNwbGp0TNUUt1WoMuFxhRYuo14yCGijAcv/yf25+ueUs3 ys/3p+NkiKgoq9hkxkPG0qOX/dqUymlvJOAtTOSjNpP4udenSM/NDQf0PyKe9R8Va38376+WY+P hMNfgHYd0fwnThWFgJ561vlqZ2tqIdWdw/rx7274snqlV/SDoccIaKm8gMfcyR1TkdNKt0= X-Received: by 2002:a05:6000:22c4:b0:481:568e:11b5 with SMTP id ffacd0b85a97d-482c8107859mr27980501f8f.5.1787652441198; Tue, 25 Aug 2026 03:07:21 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Date: Tue, 25 Aug 2026 12:06:48 +0200 Message-ID: <1f3e800a68de0c053e95eed781fbaab567912c06.1787652331.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244224 From: Peter Marko Pick patch mentioned in NVD CVE report. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 6c99410bd7f0bc4e2ed41ef5afe7d6b5fcb99837) Signed-off-by: Peter Marko Signed-off-by: Fabien Thomas --- .../bison/bison/CVE-2026-56389.patch | 56 +++++++++++++++++++ meta/recipes-devtools/bison/bison_3.8.2.bb | 1 + 2 files changed, 57 insertions(+) create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch new file mode 100644 index 00000000000..ac827f6314a --- /dev/null +++ b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch @@ -0,0 +1,56 @@ +From 3169c1e7a2c6acc4c59dfcf8b089896d6881925b Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Thu, 23 Apr 2026 09:20:43 -0700 +Subject: [PATCH] html: use xsltproc from PATH +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +* src/print-xml.c (print_html): +* src/reader.c (prepare_percent_define_front_end_variables): +Drop undocumented support for lines like ‘%define tool.xsltproc +"whatever"’, as this can cause more trouble than it cures. + +CVE: CVE-2026-56389 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b] +Signed-off-by: Peter Marko +--- + src/print-xml.c | 4 +--- + src/reader.c | 1 - + 2 files changed, 1 insertion(+), 4 deletions(-) + +diff --git a/src/print-xml.c b/src/print-xml.c +index 8da6da0d..79bfa88d 100644 +--- a/src/print-xml.c ++++ b/src/print-xml.c +@@ -543,10 +543,9 @@ print_html (void) + assert (xml_flag); + + char *xml2html = xpath_join (pkgdatadir (), "xslt/xml2xhtml.xsl"); +- char *xsltproc = muscle_percent_define_get ("tool.xsltproc"); + char const *argv[11]; + int i = 0; +- argv[i++] = xsltproc; ++ argv[i++] = "xsltproc"; + argv[i++] = "-o"; + argv[i++] = spec_html_file; + argv[i++] = xml2html; +@@ -572,6 +571,5 @@ print_html (void) + /* termsigp */ NULL); + if (status) + complain (NULL, complaint, _("%s failed with status %d"), argv[0], status); +- free (xsltproc); + free (xml2html); + } +diff --git a/src/reader.c b/src/reader.c +index 862d7293..cb2a7f69 100644 +--- a/src/reader.c ++++ b/src/reader.c +@@ -788,7 +788,6 @@ prepare_percent_define_front_end_variables (void) + muscle_percent_define_default ("lr.default-reduction", "accepting"); + free (lr_type); + } +- muscle_percent_define_default ("tool.xsltproc", "xsltproc"); + + /* Check %define front-end variables. */ + { diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes-devtools/bison/bison_3.8.2.bb index da138e35874..9808a96e993 100644 --- a/meta/recipes-devtools/bison/bison_3.8.2.bb +++ b/meta/recipes-devtools/bison/bison_3.8.2.bb @@ -12,6 +12,7 @@ DEPENDS = "bison-native flex-native" SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \ file://autoconf-2.73.patch \ file://add-with-bisonlocaledir.patch \ + file://CVE-2026-56389.patch \ " SRC_URI[sha256sum] = "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2" From patchwork Tue Aug 25 10:06:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96270 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F08C5C61CE2 for ; Tue, 25 Aug 2026 10:07:33 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18585.1787652444008301134 for ; Tue, 25 Aug 2026 03:07:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0MJSheyE; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-47fd4531020so2585396f8f.3 for ; Tue, 25 Aug 2026 03:07:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1787652442; x=1788257242; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NGj2uLe1mPWTYVSjkuCSFBh+JzOttbG1BWRn9k/XkLs=; b=0MJSheyEp5EgGQWwiHbla0SgZHLJpbEAnkHFhakkrTl2grSoSaT6W3nQV7LV+KDYZr 7Z0NdLYq63hov6fs/ELrFGvRVFw6dxRJsBj0Vo1COCC4Oa4xBIvPn22n1rBNUX17YrWp Mph8lBQuvQnBQ6OCn19b7HLX5m2lkjTcaa7dg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787652442; x=1788257242; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NGj2uLe1mPWTYVSjkuCSFBh+JzOttbG1BWRn9k/XkLs=; b=f+Hx0HLB5JFPQj5w8wKmb+ZDuVcbsyR55z50zi2eENz8D2aWkA1J6s31S2qlcCHjJb ZptzNfwHL48cryv8+m01rLlGXZ7rNEsHXTH4topkWQqeBnbl7PCOX2S/uWhvrGqyo4Sk 0R7nXZIz4KeFM7RA7QX7wDtlpu85KvrFgI6cYa/2H4Tw+yxQ8pEQQz3wVWr3NZgxXxzd 0Ui8aQM4tsU9JX2MtiU52gbFnfl7ZQWFqIKN2NTaroOmUfyrCx625uib3KG8IaPKgVXk fHxinrCigu/VqGTkQdIiPS6iBO8zezaHkS3OYyUYYOlQrJCGqv4+usgNdgEiGYcPyvav iWLA== X-Gm-Message-State: AFuF++nxBhqpaa7AfS8aq6T30Ozlg/PYuOZYjqsiX2utciltn9NBQCmN qnhyZVgDGpJd+K7Xqg8pO6WOeErFBiF6WG+gQNiRbv8EoIjvEeRPSqKi5qR8NgM3vsLWqJKCPBJ PG8JHl2c= X-Gm-Gg: AR+sD137fnosiZkYrSf3zGtfW0Mw0L5iazBFIEws8QoiJzljWZf+Do/N8D8FIIvYI+h OXLr6BMUoCwo3xWNu4SjOcdGXSeYYg+0TAC6VnFF/0gwjoe6q0LiDoX9SKtfS7LqVqvse1b99BK y2Z1EfOwh4oLI0C6gRCPSZu9R8mgv1M4HhJiEPb8EANmVMXOtOBi2jGjCkpxDpoQ3cj9brOlzMR Uw8u7ay8dwM7sOQwC5+zzO/qPo7YcvK05Xxn4xV/VgRl1cUEzs6roWufL8/jPsIey3BVJMmn8rW nBeOpynMg4YQMLYV2GYMBuTmDvSfElzRXv7V6/2C/NefbK1D5lbLMLBJezVp2jWx3Ux78Gzuve/ LQx9XQ15niVLlCFOEjE1xBDXISiy8tSG+VZfTCvRdtWGihRgJl7mTTbWEhXxtpp7HCAmggODLgZ jHrJ5Q84+eQL+V4uHCF+rZ7/x8tXUU0oVwTPuy4uV9nRypYc4zx2uPA7MGgjbH98nNwOV9Dgssd lRP24cvn5j81oUo+CvtqCVQiHxjfO4HKgVcvd3cSOEUr4ef7J+VdJ7+IkRYh1OaY1/xrihx9jRn BD4qJMM= X-Received: by 2002:a5d:6f1c:0:b0:47f:6e23:64d6 with SMTP id ffacd0b85a97d-482c814ff04mr35858711f8f.16.1787652442144; Tue, 25 Aug 2026 03:07:22 -0700 (PDT) Received: from FRSMI25-LASER.idf.intranet (static-css-ccs-204145.business.bouyguestelecom.com. [176.157.204.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9bfd865sm10847901f8f.22.2026.08.25.03.07.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:07:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Date: Tue, 25 Aug 2026 12:06:49 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 25 Aug 2026 10:07:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244225 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-16277 [2] https://security-tracker.debian.org/tracker/CVE-2026-16277 Signed-off-by: Vijay Anusuri Signed-off-by: Fabien Thomas --- .../rpcbind/rpcbind/CVE-2026-16277.patch | 34 +++++++++++++++++++ .../recipes-extended/rpcbind/rpcbind_1.2.6.bb | 1 + 2 files changed, 35 insertions(+) create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch diff --git a/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch new file mode 100644 index 00000000000..868e5c3f01c --- /dev/null +++ b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch @@ -0,0 +1,34 @@ +From bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d Mon Sep 17 00:00:00 2001 +From: Steve Dickson +Date: Wed, 27 May 2026 11:42:11 -0400 +Subject: [PATCH] rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() + +rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR strings into a fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind server overflows it when a user runs: +rpcinfo -l + +Reported-by: Michalis Vasileiadis +Signed-off-by: Steve Dickson + +Upstream-Status: Backport [https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d] +CVE: CVE-2026-16277 +Signed-off-by: Vijay Anusuri +--- + src/rpcinfo.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/rpcinfo.c b/src/rpcinfo.c +index 0e14f78..43e8115 100644 +--- a/src/rpcinfo.c ++++ b/src/rpcinfo.c +@@ -1120,7 +1120,7 @@ rpcbaddrlist (netid, argc, argv) + + re = &head->rpcb_entry_map; + printf ("%10u%3u ", parms.r_prog, parms.r_vers); +- sprintf (buf, "%s/%s/%s ", ++ snprintf (buf, sizeof(buf), "%s/%s/%s ", + re->r_nc_protofmly, re->r_nc_proto, + re->r_nc_semantics == NC_TPI_CLTS ? "clts" : + re->r_nc_semantics == NC_TPI_COTS ? "cots" : "cots_ord"); +-- +2.43.0 + diff --git a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb index dbd4d32e0a0..07e2f10c98a 100644 --- a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb +++ b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb @@ -15,6 +15,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/rpcbind/rpcbind-${PV}.tar.bz2 \ file://rpcbind.conf \ file://rpcbind_add_option_to_fix_port_number.patch \ file://0001-systemd-use-EnvironmentFile.patch \ + file://CVE-2026-16277.patch \ " SRC_URI[sha256sum] = "5613746489cae5ae23a443bb85c05a11741a5f12c8f55d2bb5e83b9defeee8de"