From patchwork Thu Aug 27 07:35:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 96546 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2243CC61DB9 for ; Thu, 27 Aug 2026 07:35:47 +0000 (UTC) Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.31232.1787816137004701396 for ; Thu, 27 Aug 2026 00:35:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=HlSNt6F9; spf=pass (domain: mvista.com, ip: 209.85.214.177, mailfrom: vanusuri@mvista.com) Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2caed617615so19972275ad.3 for ; Thu, 27 Aug 2026 00:35:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1787816136; x=1788420936; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=JRNkQ6OtAlms1an8mczNjXuO/+OdiK+Ro/kF/+MJ9bY=; b=HlSNt6F9PLhN6OB98EU7bZardJDGERpHOLdEAJnyc28kaDDZSbQRo4gScSSvv/V2+Q DGVnPLOiqIdEBTIE77AniKpbuEBj/bgy2J23XJLn3db87XlS147QiaetXVABi6J+f6KD AVZGAiBL+fqYbn3WALLILp1dN2YU4kTb6EhdY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787816136; x=1788420936; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JRNkQ6OtAlms1an8mczNjXuO/+OdiK+Ro/kF/+MJ9bY=; b=daQpiiELJbVACsVYR5YI+DOd41wFEvgP0GjmOwroReqCGocfoMs4yL6AwZYETT4Wut blHlt1dGj30T9kR2HTA3NanhZ7WL1enKz9g3aR4bzaQqcDeH3Cw57ATpD4V6cRAhgkth CLDB0I0ayCcgXNaugTDGOZAnzdZV6yd/LgbTUVGNJwbMNi6xazk+dByWkshfe+zzv/wB R6hjEQ8oWUpNFlpmIoopYXTLrLjeQ93UEqj5la6SRAbhZVpE5ma3qSpW3ROtbhdsBa+u GK2hcZlfEvpY6EHpbqgx+42+6ZZ+/jPO5dIzqOLjOhq60EFSqNhtBI09uFCw/FsaVJr+ ZdsA== X-Gm-Message-State: AFuF++mlp6r3bxzEb3U4QPAh1daiNw8yOejrFo/FCgoJakGO8k0O9dgv lmUVVx465o1V84iTY1cxg7p7WdtG3HIT3gt2laT77NCrmANSYn84bVrTC1yRqIsQihycn17+Cin c4eNj X-Gm-Gg: AR+sD11G04seCLekkT5qCTlkPLFdO7PiMDFSnV7QE0DrVtA8oV1zKx609I5IISMklnK d0AvCFGxc8b6rRclal37F1V1lKjIZ0CrNgtbqUeV4NrBIwIpYLQ8D2J4u84Oyx0xqUwe0/Wno95 T9rHDpD1JbPEyu/tJztU5N/sarlPcvJhjbZRYVq2iV3CHcMEDF8B/fRbC+wC2tMX1LVCwb0H3sB XYm5Vpbx8QxJkzxEqFIGLP6bjSzXQBskXK4u/nlYp1SwmgyyXPz2XQgabg2E+n0W7ldEINiSUtq Hqm64BFFddfrChYpr1R5aZZ2zx5ICKLGeK3R4uE1N1+LVNOV0fRuyox2t/yVvkTMru18r5ejAAP 3zVAiMecxMFJPYLY/LzZZ1E0d3j3EcM05cDev3E25QwyLrtEQWo20llSf0jmQc1qyHo81FaVbJl AcmhqtxguRNMkVweSNnZXW9uOMel+zc1pwz+jc9ljORQP6h8Rsf76PVDv623FLupWGxGq6WG0= X-Received: by 2002:a17:903:8cc:b0:2d7:b5a:b1bb with SMTP id d9443c01a7336-2d70b5ab28dmr244386315ad.8.1787816136232; Thu, 27 Aug 2026 00:35:36 -0700 (PDT) Received: from MVIN00352.mvista.com ([182.74.28.237]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3283fa89e8fsm23139110eec.8.2026.08.27.00.35.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 00:35:34 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 1/3] perl: Fix CVE-2026-13221 Date: Thu, 27 Aug 2026 13:05:23 +0530 Message-ID: <20260827073525.640848-1-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 27 Aug 2026 07:35:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244465 Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-13221 [2] https://security-tracker.debian.org/tracker/CVE-2026-13221 Signed-off-by: Vijay Anusuri --- .../perl/files/CVE-2026-13221.patch | 76 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.42.0.bb | 1 + 2 files changed, 77 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch new file mode 100644 index 0000000000..211aabd7ef --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch @@ -0,0 +1,76 @@ +From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001 +From: Karl Williamson +Date: Thu, 26 Mar 2026 10:13:49 -0600 +Subject: [PATCH] regcomp_study: Don't create a trie that would overflow + +This addresses GH #23388 + +The design of the trie compiling code is to batch extra long tries into +smaller chunks that fit into whatever limitations there are. However, +this ticket shows that that isn't always being done. + +In this case, a bunch of branches that have TAIL operands can be +combined together, and the final TAIL is used. And the code requires +that the delta between the first branch and this final TAIL fit into a +16-bit field. That is the root cause of this bug. + +I'm not familiar enough with the trie construction code to easily +understand why the final tail needs to be used here. So this patch +simply doesn't optimize a sequence of branches into a trie that would +overflow. + +This could be revisited by someone who knows more about this than I, or +earlier in the development cycle. + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7] +CVE: CVE-2026-13221 +Signed-off-by: Vijay Anusuri +--- + regcomp_study.c | 10 ++++++++++ + t/re/pat_advanced.t | 9 +++++++++ + 2 files changed, 19 insertions(+) + +diff --git a/regcomp_study.c b/regcomp_study.c +index 05f1b01..644fbfe 100644 +--- a/regcomp_study.c ++++ b/regcomp_study.c +@@ -1841,6 +1841,16 @@ Perl_study_chunk(pTHX_ + tail = regnext( tail ); + } + ++ /* The code below currently saves the difference from ++ * start to finish in a 16-bit field, causing ++ * GH #23388. This defeats the design of batching ++ * tries into chunks that each fit. khw thinks it is ++ * too late in the 5.44 cycle to relook at the design, ++ * so for now anyway, don't make a trie that would ++ * overflow */ ++ if (tail - startbranch >= U16_MAX) { ++ continue; ++ } + + DEBUG_TRIE_COMPILE_r({ + regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state); +diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t +index 4d62f62..a3460fc 100644 +--- a/t/re/pat_advanced.t ++++ b/t/re/pat_advanced.t +@@ -2713,6 +2713,15 @@ EOF_DEBUG_OUT + $x =~ s/^[\x{0301}\x{030C}]+//; + } + ++ { # GH #23388 ++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow"); ++ my $x = join "|", "aaa".."mzz"; ++ my $y = join "|", "naa".."zzz"; ++ use re 'Debug'; ++ "fnord" =~ m/(?:$x)|(?:$y)/; ++ PROG ++ } ++ + + # !!! NOTE that tests that aren't at all likely to crash perl should go + # a ways above, above these last ones. There's a comment there that, like +-- +2.43.0 + diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 1833b7a352..1a3451b747 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://0001-cpan-Sys-Syslog-Makefile.PL-Fix-_PATH_LOG-for-determ.patch \ file://CVE-2026-8376-01.patch \ file://CVE-2026-8376-02.patch \ + file://CVE-2026-13221.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Thu Aug 27 07:35:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 96547 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 235C8C61DC7 for ; Thu, 27 Aug 2026 07:35:47 +0000 (UTC) Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.30860.1787816141377263383 for ; Thu, 27 Aug 2026 00:35:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=LBHVek5P; spf=pass (domain: mvista.com, ip: 209.85.214.175, mailfrom: vanusuri@mvista.com) Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2ccf2360620so18262335ad.3 for ; Thu, 27 Aug 2026 00:35:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1787816141; x=1788420941; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QrLpcmrYfpfO1CRFQdsbX2ZRHvO7uhPorDRYUighpLc=; b=LBHVek5PzsaWFZJfGf9Px+lqc7Cbpzmn1WRHTIOuN0XabM4VnAh3ZNQHfS3sAFogtu RVKRV2+ZjfcuKvmzqa9hulGZbIdOOAIFZIj187gri908Fk12Yl5ZMbHZWRcvP+JoZz4W i5sxgKHbzmeTaakuA/gg+oTViNe5v7nw5/Kfc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787816141; x=1788420941; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QrLpcmrYfpfO1CRFQdsbX2ZRHvO7uhPorDRYUighpLc=; b=ZWQtzsXcAKzAnIqhKVYDiArxQBfZEbDs+NxHfRrcK6PnUVdZ7jrVl5Mld0xuKQyqMf JvZR2PHq7iJyZpLZ/WEnIT8FwCdJOkkvgIuB2ExLYr1Qe26AdtQ31klMBIUphP3VR65i /CAZvxn5jpn2WxD3oUddw6nNrzCpJ+5Svkx+EI8786Ig5ZSmAP7CIHGVtQAVMPjWk1Pd 38XVMzcUNp9MCwsJ8hX91ygsXpdc3R3BD3M5SgO++nfv2AUk5eII4N0gEBF5ZGf0/3uv fgylEcx8AGeQ671FuLHrKPSLc+xn2Khjjwpos0OlR0PoWrga9SUBuU6j+Z/cNq6PKzwE x3QQ== X-Gm-Message-State: AFuF++mK6rj4xvPQ71ttlEZbgjjn7fLZSAHjie0fwKWEqZqsOdqmil4Y tBRXOvZBI42IEIvzgglVEQYqpZ/24z1FaSU/7Kutekh6PfhHjOwDCotocSfx7OU5ipG41hGgWxM UwvbR X-Gm-Gg: AR+sD112RUS+tTmwt1czL5slIm/r2GVne+xInPHwArcnwGENWFJOG6J8CFGb0OemrCV B+RirQr9rfIYc8ouET7ia7Y62QlCGGQVYbMZL0hUnYkp3JgeylTgKrWefHgSt2B/LecywgXzyp9 1jnCNweKp3BvTrvtA4zABAq8RZhihVUuEoMOIUeHOi453hPP6iFwutavOcby3PKI+YHwBwGWKRC jkFOT8AV+lZhIEqHAf4l507YEoBWHZ+DS7G2pbZYtl9Uyu1XLmbHfI+x82WUgX78MoWCyRCFsdg wBY58e3lf44cq8yaT2xW+w6nFsM1pO+nec2lyUKY4Ag1O837SXQhL+j37ODqHk5rHi8sqF6zJeo RwJv5OuuPpGdgZZ/HUqCPoT3YLYshuIRYk/BuG+qxm2U/27cv8+98TA3dAZMhdht11V/ab7unlR 8ENmWg0x0zYsV6SM9PO369T4h9QdbwsovYzwI3ARGNN07fwD60vTsrqE2hZILpZcHhbfLsJJqx8 PhsLOTfVg== X-Received: by 2002:a17:90b:4a01:b0:381:25ce:bcc2 with SMTP id 98e67ed59e1d1-3966d1bae93mr22833157a91.6.1787816140634; Thu, 27 Aug 2026 00:35:40 -0700 (PDT) Received: from MVIN00352.mvista.com ([182.74.28.237]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3283fa89e8fsm23139110eec.8.2026.08.27.00.35.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 00:35:39 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 2/3] perl: Fix CVE-2026-57432 Date: Thu, 27 Aug 2026 13:05:24 +0530 Message-ID: <20260827073525.640848-2-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260827073525.640848-1-vanusuri@mvista.com> References: <20260827073525.640848-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 27 Aug 2026 07:35:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244466 Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-57432 [2] https://security-tracker.debian.org/tracker/CVE-2026-57432 Signed-off-by: Vijay Anusuri --- .../perl/files/CVE-2026-57432-1.patch | 53 +++++++++++++++++++ .../perl/files/CVE-2026-57432-2.patch | 35 ++++++++++++ meta/recipes-devtools/perl/perl_5.42.0.bb | 2 + 3 files changed, 90 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-1.patch create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-2.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-1.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-1.patch new file mode 100644 index 0000000000..6112516b67 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-1.patch @@ -0,0 +1,53 @@ +From 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Sat, 9 May 2026 17:18:43 +0100 +Subject: [PATCH] pp_pack.c: Avoid ssize_t overflow when calculating the size + of a structure + +If the user has requested a size that would overflow a SSize_t, then the +only sensible thing to do is throw an exception, because the structure +this implies couldn't possibly fit into memory anyway. + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55] +CVE: CVE-2026-57432 +Signed-off-by: Vijay Anusuri +--- + pod/perldiag.pod | 6 ++++++ + pp_pack.c | 4 ++++ + 2 files changed, 10 insertions(+) + +diff --git a/pod/perldiag.pod b/pod/perldiag.pod +index 6c9948f..83a1b96 100644 +--- a/pod/perldiag.pod ++++ b/pod/perldiag.pod +@@ -5027,6 +5027,12 @@ mixed-case attribute name, instead. See L. + (F) You can't specify a repeat count so large that it overflows your + signed integers. See L. + ++=item Pack template structure size is too large ++ ++(F) You called C or C to operate on a structure, whose ++computed size is too large to fit in memory. This usually happens as a ++result of embedding a large number as the repeat count for an item. ++ + =item page overflow + + (W io) A single call to write() produced more lines than can fit on a +diff --git a/pp_pack.c b/pp_pack.c +index 0b53611..090bdb8 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + } + } ++ if ((size > 0) && ++ ((len > SSize_t_MAX / size) || /* detect overflow of len * size */ ++ (len * size > SSize_t_MAX - total))) /* detect overflow of total + len * size */ ++ croak("Pack template structure size is too large"); + total += len * size; + } + return total; +-- +2.43.0 + diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-2.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-2.patch new file mode 100644 index 0000000000..6e187f2edd --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-2.patch @@ -0,0 +1,35 @@ +From 40754edc72dd3e513d758153c0e2f0215897740e Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Mon, 11 May 2026 12:25:33 +0100 +Subject: [PATCH] pp_pack.c: Avoid some other potential overflows when + calculating sizes + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e] +CVE: CVE-2026-57432 +Signed-off-by: Vijay Anusuri +--- + pp_pack.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/pp_pack.c b/pp_pack.c +index 090bdb8..ac69a71 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -513,12 +513,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + case 'B': + case 'b': +- len = (len + 7)/8; ++ len = (len / 8) + !!(len % 8); + size = 1; + break; + case 'H': + case 'h': +- len = (len + 1)/2; ++ len = (len / 2) + !!(len % 2); + size = 1; + break; + +-- +2.43.0 + diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 1a3451b747..73230ab175 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -19,6 +19,8 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-8376-01.patch \ file://CVE-2026-8376-02.patch \ file://CVE-2026-13221.patch \ + file://CVE-2026-57432-1.patch \ + file://CVE-2026-57432-2.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Thu Aug 27 07:35:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 96548 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 04F2BC61DB9 for ; Thu, 27 Aug 2026 07:36:37 +0000 (UTC) Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.31240.1787816190975572524 for ; Thu, 27 Aug 2026 00:36:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=e46ncAwU; spf=pass (domain: mvista.com, ip: 209.85.210.180, mailfrom: vanusuri@mvista.com) Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-848761b5897so123008b3a.3 for ; Thu, 27 Aug 2026 00:36:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1787816190; x=1788420990; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PQ77aGKAmwkEW3ekkEbVuSAgXHTfXvd4tl+ThMXixCA=; b=e46ncAwUe4hrcii7F6ObtpYwh8ZQTXiPiZIb9v/3JzKaSbrPrwh5hUM/t648LUk8zV PNaYbmoiu30DT8GCb9MF8NUwneZQ50wDKX+zJnfEQoqT70xpw/XRcicP9IWWhwtCW3Sd I9Nl4OeyeG2CmXA/96W6WMtwjd4WEPPu6ZDeQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787816190; x=1788420990; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PQ77aGKAmwkEW3ekkEbVuSAgXHTfXvd4tl+ThMXixCA=; b=Mtb31YBB5mNQl/Tllt7kCBMTtc7Y2Xf/VjH/TP7EQ1rkxXGg3xWmgKSMuM0MO5V12Q VYyySSi1A04Yc7PCPcViTNkXF4JpXHCx4K4J7jBec1RBK2tYmvR5ElZRDmrDxJJ1Nt7J Yf/VnaAVK7ytU920YDMexZ/N7gSabnE+B5o3mNT/jhCovy6v7zZPsWdNw8gkbg1iP8nS VfxZbRWugUgJ/iDv8Unm4D0ew/vbK3ZLBlGDcjrRikK6Zd/DKwFyczvrmJB3mAQfhig6 QlCu1Jr45UrYyuoHzlL41mVaBAR41T6YFFod8YWWyLbyip9CQbnc+sGOEsUQJIXcHEty fRTw== X-Gm-Message-State: AFuF++meu6UH5H0EtxY3ZXnMVkHPwl8N9PAyOZvEU5JnJzbTXy7ZPrlL 2VpJPHfjnDHBYB5rc9/iPmRoBdTJ6X8NAOYIMpcHrnv3TuaxhwcvS31uLUJAwxJDOx8UXIQMBzd P1H6e X-Gm-Gg: AR+sD124/y4p1SLXJKWDd1jIq1S4GE7RaDVWjhPv9dhho8ajenEXX6ZyV1oHyNnCnSE ef3G2H0GIl6IbXp0PS7zfFakehM3rD6Lq8DOJ0Po1rQsvUMp74Q17sg0g3DD3deWUT3zZxbQrrP DJBi7/UpKpSeVzJ2GUJYzUfOFs0qkaHehurFoOSYAyeJye7MbLEjv0j3zwXqgaSilG+gtFyYplB X/8XnbpCIV+zCdbDn9fMJz2xr/CkguI+ZMNffr/tyGGURsPxHdegvCag+9mjwzwLxtYB1Pv+qp5 njGlOQcahZcK6JhXmKksv1AlnBiiW6/DLmS6DZ5C1d7DdugtNvGUKh2o6VIab4fhNxzq4GYDMDf c4RGHci8x2EWI2Mewd6iGSVlkyj0FZ/Jx6oqn3u0Pu/dog33txDhSAIPJI8rep8atNlNtFc99DU qgT/FyN+Q8+R0bsxjPwm7drRPMGh8OMLeRYYkpXYKYyBKFgo7dFFCrlnM8UajMllvJxu9Ea64= X-Received: by 2002:a05:6a21:6817:b0:3d0:e034:a26f with SMTP id adf61e73a8af0-3d0e034b51fmr12743196637.17.1787816144697; Thu, 27 Aug 2026 00:35:44 -0700 (PDT) Received: from MVIN00352.mvista.com ([182.74.28.237]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3283fa89e8fsm23139110eec.8.2026.08.27.00.35.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 00:35:43 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 3/3] perl: Fix CVE-2026-57433 Date: Thu, 27 Aug 2026 13:05:25 +0530 Message-ID: <20260827073525.640848-3-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260827073525.640848-1-vanusuri@mvista.com> References: <20260827073525.640848-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 27 Aug 2026 07:36:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244467 Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-57433 [2] https://security-tracker.debian.org/tracker/CVE-2026-57433 Signed-off-by: Vijay Anusuri --- .../perl/files/CVE-2026-57433.patch | 32 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.42.0.bb | 1 + 2 files changed, 33 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57433.patch b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch new file mode 100644 index 0000000000..f0ea08b1fe --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch @@ -0,0 +1,32 @@ +From e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Sat, 9 May 2026 16:47:14 +0100 +Subject: [PATCH] Storable.xs: Avoid signed int overflow when unpacking a list + of hook data items + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7] +CVE: CVE-2026-57433 +Signed-off-by: Vijay Anusuri +--- + dist/Storable/Storable.xs | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/dist/Storable/Storable.xs b/dist/Storable/Storable.xs +index 3930db6..62a1a6d 100644 +--- a/dist/Storable/Storable.xs ++++ b/dist/Storable/Storable.xs +@@ -5035,7 +5035,10 @@ static SV *retrieve_hook_common(pTHX_ stcxt_t *cxt, const char *cname, int large + } + else + GETMARK(len3); +- if (len3) { ++ if (len3 == I32_MAX) ++ /* If len3 is exactly I32_MAX it will upset av_extend below */ ++ CROAK(("Invalid count of hook data items")); ++ else if (len3) { + av = newAV(); + av_extend(av, len3 + 1); /* Leave room for [0] */ + AvFILLp(av) = len3; /* About to be filled anyway */ +-- +2.43.0 + diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 73230ab175..180c3d1f64 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -21,6 +21,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-13221.patch \ file://CVE-2026-57432-1.patch \ file://CVE-2026-57432-2.patch \ + file://CVE-2026-57433.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \