From patchwork Wed Aug 26 05:36:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96366 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9772AC5DF97 for ; Wed, 26 Aug 2026 05:40:36 +0000 (UTC) Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6233.1787722832274057503 for ; Tue, 25 Aug 2026 22:40:32 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=QvMZVGnl; spf=pass (domain: cisco.com, ip: 173.37.142.95, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14107; q=dns/txt; s=iport01; t=1787722832; x=1788932432; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=OrAfwIc884CP6YwwaTSDxUwnHKzw+9x5vTJ4FjyKbtM=; b=QvMZVGnlYLbW+cYJ6/tUucivKJ7zQD3UkQRRDpV11/kxTDk/Vvue5iws 1djZ9gk2dDHQ7uhzcKVkZRqULYhD0zbe7K0PQ1vT3V8cJdQK/qXbqggMO cUp9prD65/2vybepXJzvlYu4D3+NdKpL7+U4RzjpYLOecxTT3Gqizz2Cl 2v+tqrEL7gIWNAWE4kAYn9t3uGNjOg+8km/GjWkYOv6yz6pfSbNuD0oJw PB2RWgYAOUQnpTvd/wxx0S5MGZ8yXhdyl7YokhbT5xF9sipZUCF1l9EQ9 4Y5+wpLsTcnqUdROXREvquER/s6BYggFJ0CxYGckF/ZRzLe9OebucaiGu g==; X-CSE-ConnectionGUID: sbqMMwtLQe+jEE5VkBLLiQ== X-CSE-MsgGUID: 3g3ovjm1Qmq0h1uzL/IqKw== X-IPAS-Result: A0BFAgDpeo5q/48QJK1aglmCV3RfQkmWSp4egX4PAQEBD0QNBAEBhQWNbgImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBATQBGAEtLAMBAlojIYMCAYJ0AgERBr5BgiyBAYMoATEHBwJDUNswAQsUAQWBM4U/iCJdGAGDXYEfJxsbgXKBFYNpgQWBXAEBAYgkBIIiehKBWh4ygjOPBUiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsGBYEdgSiEECMZNnyBCV6BKylgARIXgQmCBwKCWoIFAgFJQw4HRz4LGA1IESw3FBkEPm4HjmsfgikZBwEsYQEHDBggLkoFJlEppWWhDwoog3aMIpU6GjOpVYEXC5h9jgqVaGiEaYFoPIEoHwsHcBVIAYJZCUoZD44sAQsLg2CBf4MUgkHEZSQ1AgEIMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:k0SsUKOe/6mLK4PvrR3ylsFynXyQoLVcMsEvi/4bfWQNrUog0TIGx mpOW2jXPqqCZmamL411aYu09kgHvsfXx9cyTnM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf1gWAsawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj6+5kFWQTIpE8w+s0A0xjq MIbAhQpbynW0opawJrjIgVtrs0nKM+uOMYUvWttiGmHS/0nWpvEBa7N4Le03h9p2ZsIRqiYP pRfMGY0BPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237nFYpgeKwYISOEjCMbZ5axUGGp GefxmHgWhFDKc67jhuc0W3504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFC8u/SRjk+lR8kZL FQZ/Ccrp6U++EGnCN7nUHWFTGWstxoYXZ9UVuY98gzIkvSS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH7tV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:ExN72an0Zz0sQx5fN8E1yyZcgkTpDfIA3DAbv31ZSRFFG/FwWf rAoB19726QtN9/YhAdcLy7VZVoIkmsl6Kdn7NwAV7KZmCP0wGVxepZg7cKrQeNJ8TWzJ846U 4ZSdkcNPTASX5nkM39/A60V/wkwNWB7eSUoN229QYLcemvAJsQljuQzW2gYytLeDU= X-Talos-CUID: 9a23:CqAMWWrUIQnbMpqj0Wo7alLmUdsva1j402v0GkL7C0tEFYOWY3u0+Zoxxg== X-Talos-MUID: 9a23:FdnpJg3Kv2Kali3a5I2hp9foBDUjuKv1D14PlMw/vtDcNXVtKRParS2UXdpy X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="820925863" Received: from alln-l-core-06.cisco.com ([173.36.16.143]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 05:36:51 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-06.cisco.com (Postfix) with ESMTPS id BB6BD1800027A; Wed, 26 Aug 2026 05:36:51 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 50C6FCE1BBD; Tue, 25 Aug 2026 22:36:51 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Date: Tue, 25 Aug 2026 22:36:23 -0700 Message-Id: <20260826053627.1798620-1-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 05:40:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244295 From: Hetvi Thakar Backport the upstream timing-safe comparison fix [1] and its XLC compatibility follow-up [2]. APR-util 1.6.4 identifies this issue as fixed [3]. [1] https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e [2] https://github.com/apache/apr-util/commit/e35eee2ea9e1f77bdec26c3bfdb5caca457acd66 [3] https://nvd.nist.gov/vuln/detail/CVE-2025-49506 Signed-off-by: Hetvi Thakar --- .../apr/apr-util/CVE-2025-49506_p1.patch | 310 ++++++++++++++++++ .../apr/apr-util/CVE-2025-49506_p2.patch | 42 +++ meta/recipes-support/apr/apr-util_1.6.3.bb | 2 + 3 files changed, 354 insertions(+) create mode 100644 meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch create mode 100644 meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch diff --git a/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch new file mode 100644 index 0000000000..0ab5cf0648 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch @@ -0,0 +1,310 @@ +From f77a20761cb15686f8d4de5b5eafc534ae24b19e Mon Sep 17 00:00:00 2001 +From: Eric Covener +Date: Mon, 3 Aug 2026 12:10:13 +0000 +Subject: [PATCH] Merge r1936804 from aprutil 1.7.x: + +use timing safe comparison + +Submitted By: ylavic +Reviewed By: ylavic, rpluem, covener + + + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936805 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2025-49506 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e] + +(cherry picked from commit f77a20761cb15686f8d4de5b5eafc534ae24b19e) +Signed-off-by: Hetvi Thakar +--- + crypto/apr_crypto.c | 60 +++++++++++++++++--- + crypto/apr_passwd.c | 135 ++++++++++++++++++++++++++++++++++++++++---- + 2 files changed, 176 insertions(+), 19 deletions(-) + +diff --git a/crypto/apr_crypto.c b/crypto/apr_crypto.c +index 9ba190ef..ca3f0887 100644 +--- a/crypto/apr_crypto.c ++++ b/crypto/apr_crypto.c +@@ -21,6 +21,7 @@ + #include "apu.h" + #include "apr_pools.h" + #include "apr_dso.h" ++#include "apr_version.h" + #include "apr_strings.h" + #include "apr_hash.h" + #include "apr_thread_mutex.h" +@@ -173,19 +174,64 @@ APU_DECLARE(apr_status_t) apr_crypto_memzero(void *buffer, apr_size_t size) + return APR_SUCCESS; + } + ++/* Borrow this from APR-1.8 if not available */ ++#if !APR_VERSION_AT_LEAST(1,8,0) ++ ++/* A volatile variable which is always zero but allows to block the compiler ++ * from optimizing or eliding code using it. Volatile forces the compiler to ++ * emit a memory load for which no value can be assumed, so for instance an ++ * add/sub/xor/or with "optblocker" is a noop that will hide the result to ++ * the optimizer. ++ */ ++static volatile const apr_uint32_t optblocker; ++ ++/* Return whether x is not zero, with no branching controlled by x. ++ * ++ * Taken from the cryptoint library (public domain) by D. J. Bernstein, ++ * which provides timing attacks safe integer operations/primitives. ++ * Code: ++ * https://lib.mceliece.org/libmceliece-20250507/cryptoint/crypto_uint32.h ++ * Paper: ++ * https://cr.yp.to/papers/cryptoint-20250424.pdf ++ */ ++#if __has_attribute(always_inline) ++__attribute__((always_inline)) ++#endif ++static APR_INLINE int test_nonzero_timingsafe(apr_uint32_t x) ++{ ++ x |= -x; /* sets the most significant bit unless x == 0 */ ++ ++ /* shift bit 31 (MSB) to bit 0 */ ++ x >>= 32-6; /* keep 6 bits */ ++ x += optblocker; /* lose the optimizer */ ++ x >>= 5; /* keep the (original) MSB only */ ++ ++ /* x is now 0 or 1 */ ++ return x & INT_MAX; ++} ++ ++#endif /* !APR_VERSION_AT_LEAST(1,8,0) */ ++ + APU_DECLARE(int) apr_crypto_equals(const void *buf1, const void *buf2, + apr_size_t size) + { +- const unsigned char *p1 = buf1; +- const unsigned char *p2 = buf2; +- unsigned char diff = 0; +- apr_size_t i; ++#if APR_VERSION_AT_LEAST(1,8,0) ++ return apr_memeq_timingsafe(buf1, buf2, size); ++#else ++ apr_uint32_t diff = 0; ++ volatile apr_size_t count = size; /* prevent loop unrolling */ ++ apr_size_t i = 0; + +- for (i = 0; i < size; ++i) { +- diff |= p1[i] ^ p2[i]; ++ for (; i < count; ++i) { ++ const unsigned char c1 = ((volatile const unsigned char *)buf1)[i]; ++ const unsigned char c2 = ((volatile const unsigned char *)buf2)[i]; ++ ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */ + } + +- return 1 & ((diff - 1) >> 8); ++ /* (diff == 0) <=> (diff != 0) ^ 1 */ ++ return test_nonzero_timingsafe(diff) ^ 1; ++#endif + } + + APU_DECLARE(apr_status_t) apr_crypto_get_driver( +diff --git a/crypto/apr_passwd.c b/crypto/apr_passwd.c +index c961de2b..74b5fc17 100644 +--- a/crypto/apr_passwd.c ++++ b/crypto/apr_passwd.c +@@ -14,6 +14,7 @@ + * limitations under the License. + */ + ++#include "apr_version.h" + #include "apr_strings.h" + #include "apr_md5.h" + #include "apr_lib.h" +@@ -39,6 +40,111 @@ + + static const char * const apr1_id = "$apr1$"; + ++#if APR_VERSION_AT_LEAST(1,8,0) ++ ++#define streq_timingsafe apr_streq_timingsafe ++#define strneq_timingsafe apr_strneq_timingsafe ++ ++#else /* borrow code from APR-1.8 if not available */ ++ ++/* A volatile variable which is always zero but allows to block the compiler ++ * from optimizing or eliding code using it. Volatile forces the compiler to ++ * emit a memory load for which no value can be assumed, so for instance an ++ * add/sub/xor/or with "optblocker" is a noop that will hide the result to ++ * the optimizer. ++ */ ++static volatile const apr_uint32_t optblocker; ++ ++/* Return whether x is not zero, with no branching controlled by x. ++ * ++ * Taken from the cryptoint library (public domain) by D. J. Bernstein, ++ * which provides timing attacks safe integer operations/primitives. ++ * Code: ++ * https://lib.mceliece.org/libmceliece-20250507/cryptoint/crypto_uint32.h ++ * Paper: ++ * https://cr.yp.to/papers/cryptoint-20250424.pdf ++ */ ++#if __has_attribute(always_inline) ++__attribute__((always_inline)) ++#endif ++static APR_INLINE int test_nonzero_timingsafe(apr_uint32_t x) ++{ ++ x |= -x; /* sets the most significant bit unless x == 0 */ ++ ++ /* shift bit 31 (MSB) to bit 0 */ ++ x >>= 32-6; /* keep 6 bits */ ++ x += optblocker; /* lose the optimizer */ ++ x >>= 5; /* keep the (original) MSB only */ ++ ++ /* x is now 0 or 1 */ ++ return x & INT_MAX; ++} ++ ++static int streq_timingsafe(const char *sec1, const char *str2) ++{ ++ apr_uint32_t diff = 0; ++ apr_size_t i1 = 0, i2 = 0; ++ ++ for (;; ++i2) { ++ const unsigned char c1 = ((volatile const unsigned char *)sec1)[i1]; ++ const unsigned char c2 = ((volatile const unsigned char *)str2)[i2]; ++ ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */ ++ ++ /* Not a shortest/longest match because an attacker would usually know ++ * one of the strings and could then determine the length of the other. ++ * So assume only sec1 and its length are secret and stop the loop at ++ * the end of str2. If sec1 is shorter than str2 the loop will continue ++ * by comparing the rest of str2 with the trailing NUL byte of sec1. ++ * In any case since the diff above is computed up to and including a ++ * NUL byte, only the same content and length will raise match. ++ */ ++ if (!c2) { ++ break; ++ } ++ ++ /* Don't go above sec1's NUL byte */ ++ i1 += test_nonzero_timingsafe(c1); ++ } ++ ++ /* (diff == 0) <=> (diff != 0) ^ 1 */ ++ return test_nonzero_timingsafe(diff) ^ 1; ++} ++ ++static int strneq_timingsafe(const char *sec1, const char *str2, apr_size_t n) ++{ ++ apr_uint32_t diff = 0; ++ volatile apr_size_t count = n; /* prevent loop unrolling */ ++ apr_size_t i1 = 0, i2 = 0; ++ ++ for (; i2 < count; ++i2) { ++ const unsigned char c1 = ((volatile const unsigned char *)sec1)[i1]; ++ const unsigned char c2 = ((volatile const unsigned char *)str2)[i2]; ++ ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */ ++ ++ /* Not a shortest/longest match because an attacker would usually know ++ * one of the strings and could then determine the length of the other. ++ * So assume only sec1 and its length are secret and stop the loop at ++ * the end of str2. If sec1 is shorter than str2 the loop will continue ++ * by comparing the rest of str2 with the trailing NUL byte of sec1. ++ * In any case since the diff above is computed up to and including a ++ * NUL byte, only the same content and length will raise match. ++ */ ++ if (!c2) { ++ break; ++ } ++ ++ /* Don't go above sec1's NUL byte */ ++ i1 += test_nonzero_timingsafe(c1); ++ } ++ ++ /* (diff == 0) <=> (diff != 0) ^ 1 */ ++ return test_nonzero_timingsafe(diff) ^ 1; ++} ++ ++#endif /* APR_VERSION_AT_LEAST(1,8,0) */ ++ + #if !defined(WIN32) && !defined(BEOS) && !defined(NETWARE) + #if defined(APU_CRYPT_THREADSAFE) || !APR_HAS_THREADS || \ + defined(CRYPT_R_CRYPTD) || defined(CRYPT_R_STRUCT_CRYPT_DATA) +@@ -86,28 +192,33 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd, + #if !CRYPT_MISSING + char *crypt_pw; + #endif +- if (hash[0] == '$' +- && hash[1] == '2' +- && (hash[2] == 'a' || hash[2] == 'y') +- && hash[3] == '$') { ++ ++ if ((strneq_timingsafe(hash, "$2a$", 4) | /* test both */ ++ strneq_timingsafe(hash, "$2y$", 4))) { ++ /* ++ * The hash was created using [apr_]bcrypt encoding. ++ */ + if (_crypt_blowfish_rn(passwd, hash, sample, sizeof(sample)) == NULL) + return APR_FROM_OS_ERROR(errno); + } +- else if (!strncmp(hash, apr1_id, strlen(apr1_id))) { ++ else if (strneq_timingsafe(hash, apr1_id, strlen(apr1_id))) { + /* + * The hash was created using our custom algorithm. + */ + apr_md5_encode(passwd, hash, sample, sizeof(sample)); + } +- else if (!strncmp(hash, APR_SHA1PW_ID, APR_SHA1PW_IDLEN)) { +- apr_sha1_base64(passwd, (int)strlen(passwd), sample); ++ else if (strneq_timingsafe(hash, APR_SHA1PW_ID, APR_SHA1PW_IDLEN)) { ++ /* ++ * The hash is a (naked) SHA1. ++ */ ++ apr_sha1_base64(passwd, (int)strlen(passwd), sample); + } + else { + /* + * It's not our algorithm, so feed it to crypt() if possible. + */ + #if CRYPT_MISSING +- return (strcmp(passwd, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH; ++ return streq_timingsafe(hash, passwd) ? APR_SUCCESS : APR_EMISMATCH; + #elif defined(CRYPT_R_CRYPTD) + apr_status_t rv; + CRYPTD *buffer = malloc(sizeof(*buffer)); +@@ -118,7 +229,7 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd, + if (!crypt_pw) + rv = APR_EMISMATCH; + else +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH; ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH; + free(buffer); + return rv; + #elif defined(CRYPT_R_STRUCT_CRYPT_DATA) +@@ -149,7 +260,7 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd, + if (!crypt_pw) + rv = APR_EMISMATCH; + else +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH; ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH; + free(buffer); + return rv; + #else +@@ -173,14 +284,14 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd, + rv = APR_EMISMATCH; + } + else { +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH; ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH; + } + crypt_mutex_unlock(); + return rv; + } + #endif + } +- return (strcmp(sample, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH; ++ return streq_timingsafe(hash, sample) ? APR_SUCCESS : APR_EMISMATCH; + } + + static const char * const bcrypt_id = "$2y$"; diff --git a/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch new file mode 100644 index 0000000000..b2acaf52d4 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch @@ -0,0 +1,42 @@ +From e35eee2ea9e1f77bdec26c3bfdb5caca457acd66 Mon Sep 17 00:00:00 2001 +From: Eric Covener +Date: Mon, 3 Aug 2026 13:45:25 +0000 +Subject: [PATCH] Merge r1936827 from aprutil 1.7.x: + +hide __has_attribute on traditional xlc platforms + +The backport of 1917748 omitted this in apr.h on purpose, +but this is a new/narrow usage and not in a header +where it would taint anyones use of __has_attribute. + + + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936828 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2025-49506 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/e35eee2ea9e1f77bdec26c3bfdb5caca457acd66] + +(cherry picked from commit e35eee2ea9e1f77bdec26c3bfdb5caca457acd66) +Signed-off-by: Hetvi Thakar +--- + crypto/apr_passwd.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/crypto/apr_passwd.c b/crypto/apr_passwd.c +index 74b5fc17..9231d312 100644 +--- a/crypto/apr_passwd.c ++++ b/crypto/apr_passwd.c +@@ -64,6 +64,12 @@ static volatile const apr_uint32_t optblocker; + * Paper: + * https://cr.yp.to/papers/cryptoint-20250424.pdf + */ ++#if (defined(__xlc__) && !defined(__GNUC__)) ++#ifndef __has_attribute ++#define __has_attribute(__x) 0 ++#endif ++#endif ++ + #if __has_attribute(always_inline) + __attribute__((always_inline)) + #endif diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb index 3a5f52d250..06f13e91ca 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.3.bb @@ -13,6 +13,8 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \ file://configfix.patch \ file://configure_fixes.patch \ file://0001-test_transformation-Check-if-transform-is-supported-.patch \ + file://CVE-2025-49506_p1.patch \ + file://CVE-2025-49506_p2.patch \ file://run-ptest \ " From patchwork Wed Aug 26 05:36:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96369 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0B2FEC5DF97 for ; Wed, 26 Aug 2026 05:41:07 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6160.1787722857287222361 for ; Tue, 25 Aug 2026 22:40:57 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=CNxnMjsf; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=23441; q=dns/txt; s=iport01; t=1787722857; x=1788932457; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=jZLf+EBuo7rJcDeQPLfczKLiq9KSuHrzsAQs9QuwW8A=; b=CNxnMjsfAJ2G8AuB6W9wCUoZ96XhU2+yZvUoSlPWYOMyZK4EkdU1yYJc Dn5tJLslrHbrfrFfaXWLA7vKRnio65fgN5lSdjFuSg1ejY7syeNkww8LB cQLC3nt7ikUu8uVe/VVmWiu0+3NhZob0UckOLoezdFUpA+BcVZIRsBKZu BgDvZrVZiUa9LdJV4u9hjTqoUh6NYimUxSf0QUAo9/cyvXY1XBEFnhUI1 ZY9ySkNvlTK72qF5Nr8ilY++t4JdNsUwNj+vH74y56ZP+Hxv6BvOKaZNs pLGGtgtO6SRXsgsVywrybDh/0QL77R0XfZZhMUbdut+rzn0pGTsOWkjww A==; X-CSE-ConnectionGUID: DrjhZVcFQo+nbYqKL6WpHw== X-CSE-MsgGUID: YqHDR2LtTLizUuQze/q1Yw== X-IPAS-Result: A0BIAgByeo5q/48QJK1aglmCV3RfQkmWSgOeG4F+DwEBAQ9EDQQBAYUFAo1sAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAxoNCwEYAS0QHAMBAi8rIwgZgwIBgnQCARG+RoF5M4EBgygBPwJDUNswAQsUAQWBM4U/iCJdGAGEfCcbG4FygRWDaYEFgVwBAYEnBguGbQSCInoSgVoekWpIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JCBwF6EwErgRFzECmjRIIhoQ8KKIN2jCKVOhozqmwLmH2OCpZQhGmBaDyBKB8LB3AVSAGCWQlKGQ+OLQsLg2CBf4MUxyYkNQIBCDIBAQcCBw4DC4FokAABJ4FWAQE IronPort-Data: A9a23:LrwdVKqKfZo4dDVqBnymBbRvfG1eBmJPZBIvgKrLsJaIsI4StFCzt garIBmFOvreZDPzf91yPY238klXsZbcyoAwHQZu+yE0QiwQouPIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOWn9T8jifHgqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrT8k035ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0sptA2F8y /c2ETdOaBqynsGSno2javY506zPLOGzVG8eknhkyTecCbMtRorOBv2Uo9RZxzw3wMtJGJ4yZ eJANmEpN0qGOkMJYwtMYH49tL/Aan3XcyFYoVGcv4I84nPYy0p6172F3N/9KofUHp8Oxx/Bz o7A11XgIj0gbviD9R6E4E+xv/3C2jqiaZ1HQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS4QWJzO/Qpg2eHGVBFmAHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289Fte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:XoGMoKpGvnmwoa0aXDKA0pkaV5rzeYIsimQD101hICG9vPb2qy nIpoV96faaslcssR0b9OxofZPwI080lqQFhbX5Q43DYOCOggLBR+tfBMnZsljd8kbFmNK1u5 0NT0FWMqyXMbEDt7eY3CCIV/A93dKA7Kekwc3az3trUEVWTpsI1XYBNu5eeXcGPzWvwvECZe Kh2vY= X-Talos-CUID: 9a23:KPX79miZzAsw+zIbq1yWzRaj9DJuXmffzEXuKGGBDiVvQoyManvOx7tEjJ87 X-Talos-MUID: 9a23:E8Eb3gRAONlCMcwiRXTdnRFODp1M/5iKCVIwjKwUto6dbB1vbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="836323111" Received: from alln-l-core-06.cisco.com ([173.36.16.143]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 05:36:55 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-06.cisco.com (Postfix) with ESMTPS id 69E7618000139; Wed, 26 Aug 2026 05:36:55 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 07AC3CE1BBD; Tue, 25 Aug 2026 22:36:55 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][PATCH 2/5] apr-util: Fix CVE-2026-32327 Date: Tue, 25 Aug 2026 22:36:24 -0700 Message-Id: <20260826053627.1798620-2-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260826053627.1798620-1-hthakar@cisco.com> References: <20260826053627.1798620-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 05:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244299 From: Hetvi Thakar Backport the upstream test compatibility prerequisite [1], which is required by the regression tests included with the XML nesting-depth fix [2]. The fix addresses CVE-2026-32327 as described by the advisory [3]. [1] https://github.com/apache/apr-util/commit/dba5d434dba0547478f411d6fa068766455446ce [2] https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8 [3] https://nvd.nist.gov/vuln/detail/CVE-2026-32327 Signed-off-by: Hetvi Thakar --- .../apr-util/CVE-2026-32327-dependent.patch | 34 + .../apr/apr-util/CVE-2026-32327.patch | 2162 +++++++++++++++++ meta/recipes-support/apr/apr-util_1.6.3.bb | 2 + 3 files changed, 2198 insertions(+) create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-32327.patch diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch b/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch new file mode 100644 index 0000000000..c3c570f407 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch @@ -0,0 +1,34 @@ +From dba5d434dba0547478f411d6fa068766455446ce Mon Sep 17 00:00:00 2001 +From: Joe Orton +Date: Tue, 19 Dec 2023 11:20:33 +0000 +Subject: [PATCH] Merge r1914772 from 1.7.x: + +* test/testutil.h: Define APR_ASSERT_SUCCESS for compatibility + with apr trunk. + + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1914774 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2026-32327 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/dba5d434dba0547478f411d6fa068766455446ce] + +(cherry picked from commit dba5d434dba0547478f411d6fa068766455446ce) +Signed-off-by: Hetvi Thakar +--- + test/testutil.h | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/test/testutil.h b/test/testutil.h +index eaa7e759..4c5e30b8 100644 +--- a/test/testutil.h ++++ b/test/testutil.h +@@ -40,6 +40,8 @@ extern apr_pool_t *p; + /* Assert that RV is an APR_SUCCESS value; else fail giving strerror + * for RV and CONTEXT message. */ + void apr_assert_success(abts_case* tc, const char *context, apr_status_t rv); ++#define APR_ASSERT_SUCCESS(tc, ctxt, rv) \ ++ apr_assert_success(tc, ctxt, rv) + + void apr_assert_failure(abts_case* tc, const char *context, + apr_status_t rv, int lineno); diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch b/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch new file mode 100644 index 0000000000..a0c4004709 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch @@ -0,0 +1,2162 @@ +From 414e12e427c89f135d8ee66ab1203feffd3e2bd8 Mon Sep 17 00:00:00 2001 +From: Joe Orton +Date: Mon, 3 Aug 2026 12:34:32 +0000 +Subject: [PATCH] Merge r1936807 from 1.7.x: + +limit XML processing depth + +Submitted By: jorton +Reviewed By: jorton, jfclere, ivan + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936815 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2026-32327 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8] + +(cherry picked from commit 414e12e427c89f135d8ee66ab1203feffd3e2bd8) +Signed-off-by: Hetvi Thakar +--- + CMakeLists.txt | 3 + + test/data/nesting.xml | 2001 +++++++++++++++++++++++++++++++++++++++++ + test/testxml.c | 32 + + xml/apr_xml.c | 21 +- + 4 files changed, 2056 insertions(+), 1 deletion(-) + create mode 100644 test/data/nesting.xml + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index fcbfc582..65b9194d 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -288,6 +288,9 @@ IF(APR_BUILD_TESTAPR) + EXECUTE_PROCESS(COMMAND ${CMAKE_COMMAND} -E copy_if_different + ${PROJECT_SOURCE_DIR}/test/data/billion-laughs.xml + ${PROJECT_BINARY_DIR}/data/billion-laughs.xml) ++ EXECUTE_PROCESS(COMMAND ${CMAKE_COMMAND} -E copy_if_different ++ ${PROJECT_SOURCE_DIR}/test/data/nesting.xml ++ ${PROJECT_BINARY_DIR}/data/nesting.xml) + + IF(TEST_STATIC_LIBS) + SET(whichapr aprutil-1) +diff --git a/test/data/nesting.xml b/test/data/nesting.xml +new file mode 100644 +index 00000000..a4efda86 +--- /dev/null ++++ b/test/data/nesting.xml +@@ -0,0 +1,2001 @@ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ +diff --git a/test/testxml.c b/test/testxml.c +index eed10672..5284f888 100644 +--- a/test/testxml.c ++++ b/test/testxml.c +@@ -20,6 +20,10 @@ + #include "abts.h" + #include "testutil.h" + ++#ifndef APR_XML_MAX_DEPTH ++#define APR_XML_MAX_DEPTH 256 ++#endif ++ + static apr_status_t create_dummy_file_error(abts_case *tc, apr_pool_t *p, + apr_file_t **fd) + { +@@ -166,6 +170,33 @@ static void test_billion_laughs(abts_case *tc, void *data) + apr_file_close(fd); + } + ++static void test_nesting_limit(abts_case *tc, void *data) ++{ ++ apr_file_t *fd; ++ apr_xml_parser *parser = NULL; ++ apr_xml_doc *doc; ++ apr_status_t rv; ++ char errbuf[256], *err; ++ ++ rv = apr_file_open(&fd, "data/nesting.xml", ++ APR_FOPEN_READ, 0, p); ++ APR_ASSERT_SUCCESS(tc, "open nesting.xml", rv); ++ ++ rv = apr_xml_parse_file(p, &parser, &doc, fd, 2000); ++ ABTS_TRUE(tc, rv != APR_SUCCESS); ++ ++ if (parser) { ++ err = apr_xml_parser_geterror(parser, errbuf, sizeof errbuf); ++ ABTS_STR_EQUAL(tc, ++ "The maximum element nesting limit " ++ "(" APR_STRINGIFY(APR_XML_MAX_DEPTH) ")" ++ " was exceeded.", ++ err); ++ } ++ ++ apr_file_close(fd); ++} ++ + static void test_CVE_2009_3720_alpha(abts_case *tc, void *data) + { + apr_xml_parser *xp; +@@ -198,6 +229,7 @@ abts_suite *testxml(abts_suite *suite) + + abts_run_test(suite, test_xml_parser, NULL); + abts_run_test(suite, test_billion_laughs, NULL); ++ abts_run_test(suite, test_nesting_limit, NULL); + abts_run_test(suite, test_CVE_2009_3720_alpha, NULL); + abts_run_test(suite, test_CVE_2009_3720_beta, NULL); + +diff --git a/xml/apr_xml.c b/xml/apr_xml.c +index 2685a9a5..a2535f98 100644 +--- a/xml/apr_xml.c ++++ b/xml/apr_xml.c +@@ -61,12 +61,19 @@ struct apr_xml_parser { + int error; /* an error has occurred */ + #define APR_XML_ERROR_EXPAT 1 + #define APR_XML_ERROR_PARSE_DONE 2 +-/* also: public APR_XML_NS_ERROR_* values (if any) */ ++#define APR_XML_ERROR_DEPTH_LIMIT 3 + ++/* also: public APR_XML_NS_ERROR_* values (if any) */ ++ /** depth of element tree. */ ++ unsigned int depth; + XML_Parser xp; /* the actual (Expat) XML parser */ + enum XML_Error xp_err; /* stored Expat error code */ + }; + ++#ifndef APR_XML_MAX_DEPTH ++#define APR_XML_MAX_DEPTH 256 ++#endif ++ + /* struct for scoping namespace declarations */ + typedef struct apr_xml_ns_scope { + const char *prefix; /* prefix used for this ns */ +@@ -154,6 +161,11 @@ static void start_handler(void *userdata, const char *name, const char **attrs) + if (parser->error) + return; + ++ if (++parser->depth > APR_XML_MAX_DEPTH) { ++ parser->error = APR_XML_ERROR_DEPTH_LIMIT; ++ return; ++ } ++ + elem = apr_pcalloc(parser->p, sizeof(*elem)); + + /* prep the element */ +@@ -327,6 +339,8 @@ static void end_handler(void *userdata, const char *name) + if (parser->error) + return; + ++ parser->depth--; ++ + /* pop up one level */ + parser->cur_elem = parser->cur_elem->parent; + } +@@ -499,6 +513,11 @@ APU_DECLARE(char *) apr_xml_parser_geterror(apr_xml_parser *parser, + XML_ErrorString(parser->xp_err), parser->xp_err); + return errbuf; + ++ case APR_XML_ERROR_DEPTH_LIMIT: ++ msg = "The maximum element nesting limit (" ++ APR_STRINGIFY(APR_XML_MAX_DEPTH) ") was exceeded."; ++ break; ++ + case APR_XML_ERROR_PARSE_DONE: + msg = "The parser is not active."; + break; diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb index 06f13e91ca..e3d6a23fcb 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.3.bb @@ -15,6 +15,8 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \ file://0001-test_transformation-Check-if-transform-is-supported-.patch \ file://CVE-2025-49506_p1.patch \ file://CVE-2025-49506_p2.patch \ + file://CVE-2026-32327-dependent.patch \ + file://CVE-2026-32327.patch \ file://run-ptest \ " From patchwork Wed Aug 26 05:36:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96365 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B6BFEC61DC2 for ; Wed, 26 Aug 2026 05:40:36 +0000 (UTC) Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6234.1787722832586932639 for ; Tue, 25 Aug 2026 22:40:32 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=K1ONTP5G; spf=pass (domain: cisco.com, ip: 173.37.142.91, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1050; q=dns/txt; s=iport01; t=1787722832; x=1788932432; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=vmUni+NmSp0K405iqXtVdBdo4iubEGWXu5Urt42/tYk=; b=K1ONTP5GKv1JMXYOz4Qn+Spxx7dQEOxU2k9vKV8KC0WxElWNhaAztJYG +goXns20683WeGS/+OxGOrXxvEyLbd6sezIcA08L9R2tEMjBZ+1vcpmh7 9fkQXRnTRPwJeZLLNvTulnITD0Ldqx1r23vgKR1nzv5pNIrHS2gSpBgFV hof0OfDh5YI+Qw9MJ/uX2NqvpFLc2f912j8w1EAG1wusPB4HSMuw9WoIw s8ehlspgOQRW2weV5AHYWEwCmiUEl8keBBh/aYIpT1nD7h6QnNvCDGWiW TWgYA3tHe87vMsQGyJjZ4TuPCiIysqeA5poEeupPx0pIIsUb4JwQmDRAl Q==; X-CSE-ConnectionGUID: Kwejy0owRY2f0ysXbFuDRg== X-CSE-MsgGUID: JHQLo4PMTM6PCtd+CsSJMA== X-IPAS-Result: A0BDAgByeo5q/44QJK1aHgEBCxIMggULgld0X0JJlk2eG4F+DwEBAQ89FAQBAYUFAo1sAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhlsCAQMyARgBLRAgMSsrGYMCAYJ0AgERBr5AgiyBAYMoAT8CQ1DbMAELFAEFgTOFP4gidoR8JxsbgXKEfoEFgVwBAYIthXgEgiKBDJNiSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQQIxk2fIEJXoErKWABEheBCYIHAoJaggUCAUlDDgdHPgsYDUgRLDcUGQQ+bgeOax+CSYEOLII9o0SCIaEPCiiDdowilToaM6psmQiOCpZQhGmBaDyBKB8LB3AVSAGCWQlKGQ+OOINrgX/KOiQ1AgE6AQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:WLes+qNQ5cAjnbLvrR3ylsFynXyQoLVcMsEvi/4bfWQNrUp3gWYCy TBOUGzQbKqDY2f0L9B2O4q1/UsP6JCHzNNlTHM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf1gWAsawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj69ZxAUMnZYoHwNctDzlf7 swSBi0hVB/W0opawJrjIgVtrs0nKM+uOMYUvWttiGmES/0nWpvEBa7N4Le03h9p2ZsIRqiYP pRfMGY1BPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237nFUggeSwboWPEjCMbed1p2Kf+ lrjw0GnOjoGOJ+00gGn11v504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFC8u/SRjk+lR8kZL FQZ/Ccrp6U++EGnCN7nUHWFTGWstxoYXZ9UVuY98gzIkveS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH6dV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:fgtxR6G2Oi5u2H9CpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:m2zAImHP37AnpSpPqmJE60MWC5gibUfslnmIMlSIA0h0ZIeaHAo= X-Talos-MUID: 9a23:PrjQuAWMz1wf0BLq/B3MvRVlaP9N34HwMGsRndYtoPKmEAUlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="819945672" Received: from alln-l-core-05.cisco.com ([173.36.16.142]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 05:36:58 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-05.cisco.com (Postfix) with ESMTPS id E677018000220; Wed, 26 Aug 2026 05:36:57 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 84BB2CE1BBD; Tue, 25 Aug 2026 22:36:57 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][PATCH 3/5] apr-util: Mark CVE-2026-34191 not applicable Date: Tue, 25 Aug 2026 22:36:25 -0700 Message-Id: <20260826053627.1798620-3-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260826053627.1798620-1-hthakar@cisco.com> References: <20260826053627.1798620-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-05.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 05:40:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244296 From: Hetvi Thakar CVE-2026-34191 affects only the apr_dbd_oracle provider [1]. The apr-util recipe does not enable --with-oracle, so configure keeps apu_have_oracle=0 [2]. Hence mark the CVE not applicable to this build. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-34191 [2] https://github.com/apache/apr-util/blob/1.6.3/build/dbd.m4 Signed-off-by: Hetvi Thakar --- meta/recipes-support/apr/apr-util_1.6.3.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb index e3d6a23fcb..3051a08eaf 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.3.bb @@ -102,3 +102,5 @@ do_install_ptest() { # Add CVE_PRODUCT to match the NVD CPE product name CVE_PRODUCT = "apache:apr-util apache:portable_runtime_utility" + +CVE_STATUS[CVE-2026-34191] = "not-applicable-config: apr_dbd_oracle is not built because --with-oracle is not enabled" From patchwork Wed Aug 26 05:36:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96368 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F1864C61DBD for ; Wed, 26 Aug 2026 05:40:36 +0000 (UTC) Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6234.1787722832586932639 for ; Tue, 25 Aug 2026 22:40:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=kf6XP5Qj; spf=pass (domain: cisco.com, ip: 173.37.142.91, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=5243; q=dns/txt; s=iport01; t=1787722832; x=1788932432; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=+OGa0xGaB18Pj/rsnf3jZs6S8DOpT/7z+TprJktO3vA=; b=kf6XP5Qj9bA07doTUjf9zYRyNF/BtVVyYXo4TYTEEdv6wK8ctYi+Fqe6 RNPj6c2HPdEcdYwnsvyjiGVLO/5R4RVyAsE4pRoBw9o4NX0t0JaWzDG3c Og2OlUe3F6PDxy2nPOiggo2l1sF7C2KYoHkOmomeXz27yw8C1ycM1phWT mbtlHFkSxH1XoOotvwfwhf8Eqeq4SGenjrvwbp4L7szj0UDl2eR43H83b pIZ08/X0Vj6WBk1FFIT3xfKEgH77NyqqYjf21UC3oUsN+bDtrTApZbyVg zG9rHYXOq4NlKWVS3G/F1VIdaxgQfYeCy0niMjhDZ8uhergqOGJSU9RIE Q==; X-CSE-ConnectionGUID: ZZWOd71HTymXS6LpofGUlA== X-CSE-MsgGUID: ytxu9xopRnyM3p4ttg6g2g== X-IPAS-Result: A0BIAgByeo5q/5AQJK1aglmCV3RfQkmWSgOeG4F+DwEBAQ9EDQQBAYQ/RgKNbAImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAycLARgBLRAcAwECLysjCBmDAgGCdAIBEb5GgXkzgQGDKAE/AgJAAVDbMAELFAEFgTOFP4giXRgBhHwnGxuBcoEVg2mBBYFcAQECgTaGbQSCInoSgVoekWpIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4FXcjEwGhMBK4IUKZMmAQeSN6EPCiiDdowilToaM4QElBeSUQuYfY4KllCEaYFoPIEoHwsHcBVIAYJZCUoZD444g2uBf2WCL8cmJDUCAQgyAQEHAgcOAwuBaJABgX0BAQ IronPort-Data: A9a23:A412I6iHsxI/7uEvRHon9TE6X161NxEKZh0ujC45NGQN5FlHY01je htvXj+PO6zbYjH8ed4iaI7k9UsCvsOBmoJiGVZt/HwwHy9jpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+FH1dOOn9SUgvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZeCULOZ82QsaDxMu/jd8EoHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqUqyNlQDT4X1 cAJLQA2MDSbgOyZ/baSH7wEasQLdKEHPasWvnVmiDWcBvE8TNWbHOPB5MRT23E7gcUm8fT2P pVCL2ExKk2eJUQTZj/7C7pm9AusrnnjczRboUi9rqss6G+Vxwt0uFToGIqMK43WGJsFxi50o ErX43TkUwEdLOaZ2B/e6i6wmuCRknn0Ddd6+LqQs6QCbEeo7msLBRsbUFG2rfW0hgu1XMhSA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO+Q+7AfIzu/f5ByUQzBbCDVAc9ch8sQxQFTGy 2O0oj8gPhQ32JX9dJ5X3u78Qe+aUcTNEVI/WA== IronPort-HdrOrdr: A9a23:SJCFhK8kpAhP0q7Aexxuk+AAI+orL9Y04lQ7vn2ZhyY7TiX+rb HIoB11737JYVoqNU3I3OrwWpVoIkmskaKdn7NwAV7KZmCP0wGVxcNZnO7fKlbbdREWmNQw6U 5ISdkZNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAY0++8YTzraXGfg2J9dOIEKK Y= X-Talos-CUID: 9a23:kHLXTGEeMgVRxN7LqmJVxnEzFp98UkHMyUfrfWugDmhGdbm8HAo= X-Talos-MUID: 9a23:7YRgcw6Jo14VzSRUG37FQdfOxox5/7SzWVAKia8AquzfLXBsJzjDg264F9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="819945680" Received: from alln-l-core-07.cisco.com ([173.36.16.144]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 05:36:59 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-07.cisco.com (Postfix) with ESMTPS id 10338180001DC; Wed, 26 Aug 2026 05:36:59 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id AA505CE1BBD; Tue, 25 Aug 2026 22:36:58 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][PATCH 4/5] apr-util: Fix CVE-2026-34501 Date: Tue, 25 Aug 2026 22:36:26 -0700 Message-Id: <20260826053627.1798620-4-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260826053627.1798620-1-hthakar@cisco.com> References: <20260826053627.1798620-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 05:40:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244297 From: Hetvi Thakar Backport the upstream Redis response-length and error-checking fix [1] to address CVE-2026-34501 [2]. [1] https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-34501 Signed-off-by: Hetvi Thakar --- .../apr/apr-util/CVE-2026-34501.patch | 128 ++++++++++++++++++ meta/recipes-support/apr/apr-util_1.6.3.bb | 1 + 2 files changed, 129 insertions(+) create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34501.patch diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch new file mode 100644 index 0000000000..0056e62171 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch @@ -0,0 +1,128 @@ +From e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2 Mon Sep 17 00:00:00 2001 +From: Eric Covener +Date: Mon, 3 Aug 2026 12:28:37 +0000 +Subject: [PATCH] Merge r1936809 from aprutil 1.7.x: + +Merge r1936808 from apr trunk: + +apr_redis error checking + +Submitted By: jfclere +Reviewed By: jfclere, jorton, covener + + + + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936810 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2026-34501 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2] + +(cherry picked from commit e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2) +Signed-off-by: Hetvi Thakar +--- + redis/apr_redis.c | 54 +++++++++++++++++++++++++++++++++++++---------- + 1 file changed, 43 insertions(+), 11 deletions(-) + +diff --git a/redis/apr_redis.c b/redis/apr_redis.c +index 8d01fdd6..e7fe2071 100644 +--- a/redis/apr_redis.c ++++ b/redis/apr_redis.c +@@ -853,26 +853,42 @@ APU_DECLARE(apr_status_t) apr_redis_setex(apr_redis_t *rc, + return rv; + } + ++/* Redis upstream default is 512Mb. This code will try to read the entire ++ * response into a brigade, and then copy that into a pool, so impose ++ * some reasonable limit since RAM consumption will be double this. ++ * https://redis.io/docs/latest/develop/reference/protocol-spec/#bulk-strings ++ */ ++#ifndef APR_REDIS_MAX_BULK_LEN ++#define APR_REDIS_MAX_BULK_LEN (64 * 1024 * 1024) ++#endif ++ + static apr_status_t grab_bulk_resp(apr_redis_server_t *rs, apr_redis_t *rc, + apr_redis_conn_t *conn, apr_pool_t *p, + char **baton, apr_size_t *new_length) + { +- char *length; ++ /* conn->buffer contains "$\r\n" */ ++ char *length = conn->buffer + 1; + char *last; + apr_status_t rv; + apr_size_t len = 0; ++ long val; ++ + *new_length = 0; ++ *baton = NULL; + +- length = apr_strtok(conn->buffer + 1, " ", &last); +- if (length) { +- len = strtol(length, (char **) NULL, 10); ++ errno = 0; ++ last = NULL; ++ val = strtol(length, &last, 10); ++ if (errno || last == NULL || last == length || *last != '\r' ++ || val < 0 || val > APR_REDIS_MAX_BULK_LEN) { ++ rs_bad_conn(rs, conn); ++ if (rc) ++ apr_redis_disable_server(rc, rs); ++ return val > APR_REDIS_MAX_BULK_LEN ? APR_ENOSPC : APR_EGENERAL; + } ++ len = (apr_size_t)val; + +- if (len == 0) { +- *new_length = 0; +- *baton = NULL; +- } +- else { ++ if (len) { + apr_bucket_brigade *bbb; + apr_bucket *e; + +@@ -907,6 +923,11 @@ static apr_status_t grab_bulk_resp(apr_redis_server_t *rs, apr_redis_t *rc, + + conn->bb = bbb; + ++ if (len < 2) { ++ *baton = NULL; ++ *new_length = 0; ++ return APR_EGENERAL; ++ } + *new_length = len - 2; + (*baton)[*new_length] = '\0'; + } +@@ -992,6 +1013,10 @@ APU_DECLARE(apr_status_t) apr_redis_getp(apr_redis_t *rc, + } + else if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) { + rv = grab_bulk_resp(rs, rc, conn, p, baton, new_length); ++ if (rv != APR_SUCCESS) { ++ /* grab_bulk_resp already called rs_bad_conn; do not also release */ ++ return rv; ++ } + } + else { + rv = APR_EGENERAL; +@@ -1172,12 +1197,19 @@ apr_redis_info(apr_redis_server_t *rs, apr_pool_t *p, char **baton) + return rv; + } + +- if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) { ++ if (strncmp(RS_NOT_FOUND_GET, conn->buffer, RS_NOT_FOUND_GET_LEN) == 0) { ++ rv = APR_NOTFOUND; ++ } ++ else if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) { + apr_size_t nl; + rv = grab_bulk_resp(rs, NULL, conn, p, baton, &nl); ++ if (rv != APR_SUCCESS) { ++ /* grab_bulk_resp already called rs_bad_conn; do not also release */ ++ return rv; ++ } + } else { + rs_bad_conn(rs, conn); +- rv = APR_EGENERAL; ++ return APR_EGENERAL; + } + + rs_release_conn(rs, conn); diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb index 3051a08eaf..341975fbca 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.3.bb @@ -17,6 +17,7 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \ file://CVE-2025-49506_p2.patch \ file://CVE-2026-32327-dependent.patch \ file://CVE-2026-32327.patch \ + file://CVE-2026-34501.patch \ file://run-ptest \ " From patchwork Wed Aug 26 05:36:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96367 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0CE79C61DCB for ; Wed, 26 Aug 2026 05:40:37 +0000 (UTC) Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6235.1787722833686446382 for ; Tue, 25 Aug 2026 22:40:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=dNwp0ADM; spf=pass (domain: cisco.com, ip: 173.37.142.92, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=6278; q=dns/txt; s=iport01; t=1787722833; x=1788932433; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=u8MK/yZtFo2ravxINd8/W1Ib1W35nCxvVL7FhMih8ps=; b=dNwp0ADMlv0/KTLgWCTb2qXDy11MvPze1enBiMPl4feNvy7pxgp62FjT YG3nHhztI5GmqJYxiLRB8Fao8hHwbE20QH7Mq/xi+LBFl4oj/A02tOKDe rd9lEbVWCXsDTgi2yRpZg0N9XpDc+PNvBEqfefVSDOGTgruv0RYHaGw+e PkwLLjb6c6Wm4C5CKKD0R73o7bF5W1KllD/a2pn4U6SBqQuSjrZqSpPqa B7+NMci96lK8bYhTnMYjDbNvo4hV9WUSSnOU1EN4NZWOvRMNnhXe6t9u8 ekXINRQpsAuO5aES1K/qVRfDWScO5sX54hQU6z3Rvsi8cRyXsnbD5Kd9/ A==; X-CSE-ConnectionGUID: wimatMyYRQu9mEyigjDYrA== X-CSE-MsgGUID: xMIcgoehSJOFb5STjHCREQ== X-IPAS-Result: A0BHAgByeo5q/40QJK1aglmCV3RfQkmWSgOeG4F+DwEBAQ9EDQQBAYUFAo1sAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgEDJwsBGAEtEBwDAQIvKyMIGYMCAYJ0AgERvkaBeTOBAYMoAT8CQ1DbMAELFAEFgTOFP4giXRgBhHwnGxuBcoEVgTuCLoEFgVwBAYglBIIiehKBWh6RakiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsGBYEdgSiEECMZNnyBCV6BKylgARIXgQmCBwKCWoIFAgFJQw4HRz4LGA1IESw3FBkEPm4HjmsfgVdyexMBBySBQzoXKaVloQ8KKIN2jCKVOhozqmwLmH2OCpYPQYRpgWg8gSgfCwdwFUgBglkJShkPjjiDa4F/gxTHJiQ1AgEIMgEBBwIHDgMLgWiQAi2BTwEB IronPort-Data: A9a23:5LYmgKgxjo46BsJIBhnmakg5X161NxEKZh0ujC45NGQN5FlHY01je htvDG2POfyNamCjeowgOo2x9BsEuJWEzIVqTQRv/yExFXljpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+FH1dOOn9SUgvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZeCULOZ82QsaDxMu/jd8EoHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqUH++N+HURfx MYhNWEIQwGCiOCa8aiSH7wEasQLdKEHPasWvnVmiDWcBvE8TNWbH+PB5MRT23E7gcUm8fT2P pVCL2ExKk2eJUQTYz/7C7pm9AusrnnjczRboUi9rqss6G+Vxwt0uFToGIqPI4bQFZQEwy50o ErW2kXyDRYXNOe97hSPr0mQhM/kpw7CDdd6+LqQs6QCbEeo7msLBRsbUFG2rfW0hgu1XMhSA 0gV4TY1668q+UqmS9PwUxG1rDiDpBF0ZjZLO+Q+7AfIzu/f5ByUQzBYCDVAc9ch8sQxQFTGy 2O0oj8gPhQ32JX9dJ5X3u78Qe+aUcTNEVI/WA== IronPort-HdrOrdr: A9a23:Oczkz6oolTGWLjfJxFnZ8o0aV5rzeYIsimQD101hICG9vPb2qy nIpoV96faaslcssR0b9OxofZPwI080lqQFhbX5Q43DYOCOggLBR+tfBMnZsljd8kbFmNK1u5 0NT0FWMqyXMbEDt7eY3CCIV/A93dKA7Kekwc3az3trUEVWTpsI1XYBNu5eeXcGPzWvwvECZe Kh2vY= X-Talos-CUID: 9a23:Apwpm2PNy9M3KO5DRyhi/VIxC/EfS2CMyVrBIkC6JVdzYejA X-Talos-MUID: 9a23:s30hMwQhhRsVfOYsRXT8oRBpO8Bl45+ML24HzK46uemvDwFJbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="821228995" Received: from alln-l-core-04.cisco.com ([173.36.16.141]) by alln-iport-5.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 05:37:00 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-04.cisco.com (Postfix) with ESMTPS id 493621800019B; Wed, 26 Aug 2026 05:37:00 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id E2C71CE1BBD; Tue, 25 Aug 2026 22:36:59 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][PATCH 5/5] apr-util: Fix CVE-2026-34502 Date: Tue, 25 Aug 2026 22:36:27 -0700 Message-Id: <20260826053627.1798620-5-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260826053627.1798620-1-hthakar@cisco.com> References: <20260826053627.1798620-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 05:40:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244298 From: Hetvi Thakar Backport the upstream memcache validation fix [1] and its follow-up parsing correction [2] to address CVE-2026-34502 [3]. [1] https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872 [2] https://github.com/apache/apr-util/commit/997c02ce5b9db44083c580e3e47095f5ac4524ae [3] https://nvd.nist.gov/vuln/detail/CVE-2026-34502 Signed-off-by: Hetvi Thakar --- .../apr/apr-util/CVE-2026-34502_p1.patch | 106 ++++++++++++++++++ .../apr/apr-util/CVE-2026-34502_p2.patch | 38 +++++++ meta/recipes-support/apr/apr-util_1.6.3.bb | 2 + 3 files changed, 146 insertions(+) create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch new file mode 100644 index 0000000000..d4c6cb39b4 --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch @@ -0,0 +1,106 @@ +From f1c98dd0847c43375daf3789c936685adbc6d872 Mon Sep 17 00:00:00 2001 +From: Eric Covener +Date: Mon, 3 Aug 2026 12:33:18 +0000 +Subject: [PATCH] Merge r1936812 from aprutil 1.7.x: + +Merge r1936811 from apr trunk: + +apr_memcache: error checking + +Reviewed By: covener, jorton, jfclere + + + + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936813 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2026-34502 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872] + +(cherry picked from commit f1c98dd0847c43375daf3789c936685adbc6d872) +Signed-off-by: Hetvi Thakar +--- + memcache/apr_memcache.c | 31 ++++++++++++++++++++++++++++--- + 1 file changed, 28 insertions(+), 3 deletions(-) + +diff --git a/memcache/apr_memcache.c b/memcache/apr_memcache.c +index 2c7bd1de..137be778 100644 +--- a/memcache/apr_memcache.c ++++ b/memcache/apr_memcache.c +@@ -595,6 +595,11 @@ static apr_status_t get_server_line(apr_memcache_conn_t *conn) + conn->blen = bsize; + conn->buffer[bsize] = '\0'; + ++ /* Validate CRLF line termination to prevent integer underflow attacks */ ++ if (bsize < 2 || conn->buffer[bsize-2] != '\r' || conn->buffer[bsize-1] != '\n') { ++ return APR_EGENERAL; ++ } ++ + return apr_brigade_cleanup(conn->tb); + } + +@@ -1087,9 +1092,14 @@ apr_memcache_version(apr_memcache_server_t *ms, + } + + if (strncmp(MS_VERSION, conn->buffer, MS_VERSION_LEN) == 0) { +- *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1, +- conn->blen - MS_VERSION_LEN - 2); +- rv = APR_SUCCESS; ++ if (conn->blen < MS_VERSION_LEN + 2) { ++ rv = APR_EGENERAL; ++ } ++ else { ++ *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1, ++ conn->blen - MS_VERSION_LEN - 2); ++ rv = APR_SUCCESS; ++ } + } + else { + rv = APR_EGENERAL; +@@ -1555,23 +1565,35 @@ apr_memcache_multgetp(apr_memcache_t *mc, + static const char *stat_read_string(apr_pool_t *p, char *buf, apr_size_t len) + { + /* remove trailing \r\n and null char */ ++ if (len < 2) { ++ return apr_pstrdup(p, ""); ++ } + return apr_pstrmemdup(p, buf, len-2); + } + + static apr_uint32_t stat_read_uint32(apr_pool_t *p, char *buf, apr_size_t len) + { ++ if (len < 2) { ++ return 0; ++ } + buf[len-2] = '\0'; + return atoi(buf); + } + + static apr_uint64_t stat_read_uint64(apr_pool_t *p, char *buf, apr_size_t len) + { ++ if (len < 2) { ++ return 0; ++ } + buf[len-2] = '\0'; + return apr_atoi64(buf); + } + + static apr_time_t stat_read_time(apr_pool_t *p, char *buf, apr_size_t len) + { ++ if (len < 2) { ++ return 0; ++ } + buf[len-2] = '\0'; + return apr_time_from_sec(atoi(buf)); + } +@@ -1583,6 +1605,9 @@ static apr_time_t stat_read_rtime(apr_pool_t *p, char *buf, apr_size_t len) + char *usecs; + const char *sep = ":."; + ++ if (len < 2) { ++ return apr_time_make(0, 0); ++ } + buf[len-2] = '\0'; + + secs = apr_strtok(buf, sep, &tok); diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch new file mode 100644 index 0000000000..844ad8109d --- /dev/null +++ b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch @@ -0,0 +1,38 @@ +From 997c02ce5b9db44083c580e3e47095f5ac4524ae Mon Sep 17 00:00:00 2001 +From: Eric Covener +Date: Fri, 7 Aug 2026 14:23:29 +0000 +Subject: [PATCH] fix memcache version parsing + +partial port of 1936966 from trunk + + +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936975 13f79535-47bb-0310-9956-ffa450edef68 + +CVE: CVE-2026-34502 +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/997c02ce5b9db44083c580e3e47095f5ac4524ae] + +(cherry picked from commit 997c02ce5b9db44083c580e3e47095f5ac4524ae) +Signed-off-by: Hetvi Thakar +--- + memcache/apr_memcache.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/memcache/apr_memcache.c b/memcache/apr_memcache.c +index 137be778..74146712 100644 +--- a/memcache/apr_memcache.c ++++ b/memcache/apr_memcache.c +@@ -1092,12 +1092,12 @@ apr_memcache_version(apr_memcache_server_t *ms, + } + + if (strncmp(MS_VERSION, conn->buffer, MS_VERSION_LEN) == 0) { +- if (conn->blen < MS_VERSION_LEN + 2) { ++ if (conn->blen < MS_VERSION_LEN + 4) { + rv = APR_EGENERAL; + } + else { + *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1, +- conn->blen - MS_VERSION_LEN - 2); ++ conn->blen - MS_VERSION_LEN - 3); + rv = APR_SUCCESS; + } + } diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb index 341975fbca..9da2da0816 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.3.bb @@ -18,6 +18,8 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \ file://CVE-2026-32327-dependent.patch \ file://CVE-2026-32327.patch \ file://CVE-2026-34501.patch \ + file://CVE-2026-34502_p1.patch \ + file://CVE-2026-34502_p2.patch \ file://run-ptest \ "