From patchwork Wed Sep 2 05:25:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96991 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6B684C624D3 for ; Wed, 2 Sep 2026 05:26:37 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5530.1788326788285471335 for ; Tue, 01 Sep 2026 22:26:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=au2rStRg; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49b8687630fso4312775e9.3 for ; Tue, 01 Sep 2026 22:26:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326786; x=1788931586; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=KbdGIid5rmMmjiBjla/qzfDqd0vi0hOoX7BorbN2EWM=; b=au2rStRgZSRi0vQWiewuLM/w8KlksYjljkD5Y8aP/wZG19uBXna6I/YcJE6eALgzE7 6b3Cb3uWz9UJzqhDZBO3OocPgC6bauqE242Pn1/KvY/Hr7ecHbAFLWt5urfpH4wuYR9E 6/QBDc7nw7D+2kYR9yM4j7n5dLZw5SUCnHIrA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326786; x=1788931586; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=KbdGIid5rmMmjiBjla/qzfDqd0vi0hOoX7BorbN2EWM=; b=Sj6O3PNjlxc/mXWAd3mYEyMo+/9vVchJACzTcpy4hulId+zAPO1r6Oa51j2uOOaANe GiviexOp42DX42mZ+MSwGLL+jvnUUETeD7MWCYwgg7y01GJNoyu9cSDSrJyy4x84j1J5 +Ylwik7VKprXIE24Xr1fjHubZTLMp6yNAM0HQ5T7xwyCNDzTDCiynR6u3E5EDo9FWlRu myhUhoGuSnp7qizZ6nAhRnbwLhHKFcjCK/x8qG0NK/L/3mqIxqGB57fp3RQ5r1JJup8X b0Ka5H/LIjUTbVuFfBkAwGVzX295ymi+Ej1dlCL51lo++JENw+6BAi3W26KReNVUxRF4 zq4Q== X-Gm-Message-State: AFuF++mPcJJlPHjF/TU/9Q0Z50+dbZDsssqb2pwAvVuhIHNgm+H9nR66 MNB7s2jcRc5GxHvBCbytDnNLz/pjhXWhIW3Es3vppKkbammk2UDD4cj7om1DV0KcPwpqr9+mLs0 FgXzjmUo= X-Gm-Gg: AR+sD10+MXQYq6WshJWjsnZSJw2fyK3chHJXpBlswXIv4zMI4w6P75IEKGX+EXE/oUx Lkt3H4v8TDUR0NKmQS8VIwbE7rvU9JzZRlAPj3vht2DwfFNjNL+fFwO3+P+4MSGr0qmoeNzmo4x EsnW9u+XPusRHdCTby4X7mkYrWH2k/HR2QMVSNdyAljm2dtP8KsfP206AC213qGotegqb9AK8JR TEtS7Exm1CQsnpb/crQlwk4JnBZbzmdGbHrkZzVD5MwcT6O6mVNd0OFq4xFKX5e2WVRvs7WtWlF WdTQLL01nIx2DMcI+NyxSw/mbmxaztpWrmJpa+anixJSC+At1OCqBfkfIypCDvJEEJvnjRNTxLa AwM0Aq9vMmuYXgT6dY4ZnyzOLb3EQ4mVkh3OaPEjUDK8ta6A4BnZKF5hDOJt35GuZC8e10Vb7mz RjwVZ5s0YNAeg4pGyM1BPwZ2sxxky/TIVAmVs+PgapFN0Bz39XX5MUT9j1uf1/bIhfAo8zXIGrd md3SKBTDUbvdGQobQ== X-Received: by 2002:a05:600c:3b07:b0:496:bffb:fb7b with SMTP id 5b1f17b1804b1-49ce5823706mr32025525e9.10.1788326786293; Tue, 01 Sep 2026 22:26:26 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Date: Wed, 2 Sep 2026 07:25:18 +0200 Message-ID: <0cd52c822a9929399fe8840955ff451216182f36.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244852 From: Martin Jansa Fixes: ../socat-1.8.0.0/filan.c: In function ?printtime?: ../socat-1.8.0.0/filan.c:1065:46: error: assignment of read-only location ?*(const char *)strchr(s, 10)? 1065 | if (strchr(s, '\n')) *strchr(s, '\n') = '\0'; | ^ Signed-off-by: Martin Jansa Signed-off-by: Yoann Congal --- ...ixed-strchr-with-const-for-new-glibc.patch | 38 +++++++++++++++++++ .../socat/socat_1.8.0.0.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch diff --git a/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch b/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch new file mode 100644 index 00000000000..5a7c19294c4 --- /dev/null +++ b/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch @@ -0,0 +1,38 @@ +From 3033625d5a67514e3d74021fc39f7fcb542d7f2d Mon Sep 17 00:00:00 2001 +From: Gerhard Rieger +Date: Wed, 11 Feb 2026 14:06:25 +0100 +Subject: [PATCH] Fixed strchr with const for new glibc + +Upstream-Status: Backport [https://repo.or.cz/socat.git/commit/a7058c9340db0bf90bf4372de0ae87ad37f57735] +Signed-off-by: Martin Jansa +--- + filan.c | 2 +- + xio-ip6.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/filan.c b/filan.c +index 36def50..e256f74 100644 +--- a/filan.c ++++ b/filan.c +@@ -1055,7 +1055,7 @@ const char *getfiletypestring(int st_mode) { + } + + static int printtime(FILE *outfile, time_t time) { +- const char *s; ++ char *s; + + if (filan_rawoutput) { + fprintf(outfile, "\t"F_time, time); +diff --git a/xio-ip6.c b/xio-ip6.c +index bd94bdd..09abdd1 100644 +--- a/xio-ip6.c ++++ b/xio-ip6.c +@@ -114,7 +114,7 @@ int xioparsenetwork_ip6( + struct xiorange *range, + const int ai_flags[2]) + { +- char *delimpos; /* absolute address of delimiter */ ++ const char *delimpos; /* absolute address of delimiter */ + size_t delimind; /* index of delimiter in string */ + unsigned int bits; /* netmask bits */ + char *endptr; diff --git a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb index 156fd590aee..1be3a088024 100644 --- a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb +++ b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb @@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ SRC_URI = "http://www.dest-unreach.org/socat/download/socat-${PV}.tar.bz2 \ file://0001-fix-compile-procan.c-failed.patch \ + file://0001-Fixed-strchr-with-const-for-new-glibc.patch \ file://CVE-2024-54661.patch \ file://CVE-2026-56123.patch \ " From patchwork Wed Sep 2 05:25:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96989 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4132CC61DFD for ; Wed, 2 Sep 2026 05:26:37 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5658.1788326792020009548 for ; Tue, 01 Sep 2026 22:26:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0e3gRQnv; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-499b2981a7bso5895155e9.3 for ; Tue, 01 Sep 2026 22:26:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326790; x=1788931590; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=duS4+gbXMLo2NElH0ECFDjn1qgJ/grEllHlvH2IUnH8=; b=0e3gRQnvSrTZNCnxoaRYFMCSrzH94ek8MQ1pnIoBdBlYINbPsGcTmjxL/0dL6JcH84 Z4krIWTgSRii+GAMoNDuiNVk3g0A/vggHjj1I+zk9HdyCaE/8hqaeAaUAqXynah8V0CD D35AMPTf8SDP0N5AdO6CT1OlkjAzbbBnscScA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326790; x=1788931590; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=duS4+gbXMLo2NElH0ECFDjn1qgJ/grEllHlvH2IUnH8=; b=aHS9KoW7SLk1g/oHokMIOlCjAMRGJNrrH+mt6ZU0+1ejefI+OoGX/ESqDA45R88fCr hBFLPCPeYvGXZ2uZjQgH2FTDlfmRWfSTzDPXtGbqwQgtsMXF8isYZYaos3y1vBEs+bsF W3boJ0BcWcbS8lYC8VPCaVUMcoC0n1OoK+IPVit43VBFYdeOVbO9hlza4dPESnVIwH/h FUqfQ/F8189nsTMRPWdjwWPLLJvsoquFUf2qYjFbMalObhxggNijsVyF2/Z2x6lemxi7 A4hPSY/mG/KsAWf7O2z75wGD4k4/VTZDVeWtYHl8J22EcdER9+Cd5ydkmd/4CcI/FIme dkaw== X-Gm-Message-State: AFuF++kksWI/n9qaNHX5Qp5BtTJJDbao4BrgpC1AejizyknBTRWimAeR eM84u48D1M4BaSynLeRVXNegpfwGcEk+s1csVtjD818gjxeQYW51eeaTR0ytqk6E7fC58piMXlp FV/PcjWM= X-Gm-Gg: AR+sD13aRSougLjMlaaFQhEMQyRuD1D7hAB1Grryrz9uI57xIxECaotwkHfdEr8rmwX js/K8GqPasopTFUUwvmbQ+6fRlZKoOrsagTb3DYMgZvzNJq12MV+LY23ga50fwVI1Rr+VFHlQiR DavRdP93xTljMlzE53EbIdY8OlSz+mL2jWb7rfjzn6faAlTAdefeVJvjSciox1IDGrgqdnkMeUC iPtSae93oakrQ5UUP1cOfeh365i0oFF4+GqwKLzDKdSbSk9iGH/IijUMwbCviv6hXzC3xbISUhP 25k97q4V8+rU0MMCH1yhzXSo/WYRVw5zg4SxDO69tgIKPacMa42yN4zOzgY0kSZnx/Oy92u4Cf9 2EQrTKR20qTdBdLdJ7nRVIqQTD3M6eefJOkZ5VatcSnqn+lWk/Na2eYpryXHH2N2/aSDbvuSd9j bCwnphfgwIT9WJI+pqkWQ8NarAan2DPI1EduEbtzTX2DnEsejb5bXpC2t+VjVpR1zckHYX64yWL UrLhxL7RSVNbJ8kLw== X-Received: by 2002:a05:600c:548b:b0:493:f140:c3fb with SMTP id 5b1f17b1804b1-49ce5821208mr31201945e9.7.1788326790206; Tue, 01 Sep 2026 22:26:30 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435 Date: Wed, 2 Sep 2026 07:25:19 +0200 Message-ID: <336e429b4d0048964cf883c187438ca7c5aca2ea.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244853 From: Hemanth Kumar M D resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy implementations of TSIG, fixing bug 34033, and partially fixing bug 34069. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-5435 [2] https://sourceware.org/bugzilla/show_bug.cgi?id=34033 [3] https://sourceware.org/git/?p=glibc.git;a=commit;h=ca44a6609c29a683b03575fa035c6d17aa591e72 Signed-off-by: Hemanth Kumar M D Signed-off-by: Yoann Congal [YC: This patch will change output of a debug and deprecated function. Upstream chose to remove the vulnerable implementation instead of fixing it. See: https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0011 ] --- .../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++++++++++++++++++ meta/recipes-core/glibc/glibc_2.39.bb | 1 + 2 files changed, 138 insertions(+) create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch diff --git a/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch b/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch new file mode 100644 index 00000000000..722ec2129ca --- /dev/null +++ b/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch @@ -0,0 +1,137 @@ +From 5d41b8e5aaec3580e4a05d93c5ff2fc69bb3d5a7 Mon Sep 17 00:00:00 2001 +From: Florian Weimer +Date: Fri, 19 Jun 2026 18:22:20 +0200 +Subject: [PATCH] resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) + +Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy +implementations of TSIG, fixing bug 34033, and partially +fixing bug 34069. + +Reviewed-by: Carlos O'Donell +Reviewed-by: Adhemerval Zanella + +CVE: CVE-2026-5435 +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=ca44a6609c29a683b03575fa035c6d17aa591e72] + +Signed-off-by: Hemanth Kumar M D +--- + resolv/ns_print.c | 96 ----------------------------------------------- + 1 file changed, 96 deletions(-) + +diff --git a/resolv/ns_print.c b/resolv/ns_print.c +index cef2212fd2..882a86e58e 100644 +--- a/resolv/ns_print.c ++++ b/resolv/ns_print.c +@@ -434,96 +434,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, + break; + } + +- case ns_t_cert: { +- u_int c_type, key_tag, alg; +- int n; +- unsigned int siz; +- char base64_cert[8192], tmp[40]; +- const char *leader; +- +- c_type = ns_get16(rdata); rdata += NS_INT16SZ; +- key_tag = ns_get16(rdata); rdata += NS_INT16SZ; +- alg = (u_int) *rdata++; +- +- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg)); +- T(addstr(tmp, len, &buf, &buflen)); +- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */ +- if (siz > sizeof(base64_cert) * 3/4) { +- const char *str = "record too long to print"; +- T(addstr(str, strlen(str), &buf, &buflen)); +- } +- else { +- len = b64_ntop(rdata, edata-rdata, base64_cert, siz); +- +- if (len < 0) +- goto formerr; +- else if (len > 15) { +- T(addstr(" (", 2, &buf, &buflen)); +- leader = "\n\t\t"; +- spaced = 0; +- } +- else +- leader = " "; +- +- for (n = 0; n < len; n += 48) { +- T(addstr(leader, strlen(leader), +- &buf, &buflen)); +- T(addstr(base64_cert + n, MIN(len - n, 48), +- &buf, &buflen)); +- } +- if (len > 15) +- T(addstr(" )", 2, &buf, &buflen)); +- } +- break; +- } +- +- case ns_t_tkey: { +- /* KJD - need to complete this */ +- u_long t; +- int mode, err, keysize; +- +- /* Algorithm name. */ +- T(addname(msg, msglen, &rdata, origin, &buf, &buflen)); +- T(addstr(" ", 1, &buf, &buflen)); +- +- /* Inception. */ +- t = ns_get32(rdata); rdata += NS_INT32SZ; +- len = SPRINTF((tmp, "%lu ", t)); +- T(addstr(tmp, len, &buf, &buflen)); +- +- /* Expiration. */ +- t = ns_get32(rdata); rdata += NS_INT32SZ; +- len = SPRINTF((tmp, "%lu ", t)); +- T(addstr(tmp, len, &buf, &buflen)); +- +- /* Mode , Error, Key Size. */ +- /* Priority, Weight, Port. */ +- mode = ns_get16(rdata); rdata += NS_INT16SZ; +- err = ns_get16(rdata); rdata += NS_INT16SZ; +- keysize = ns_get16(rdata); rdata += NS_INT16SZ; +- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize)); +- T(addstr(tmp, len, &buf, &buflen)); +- +- /* XXX need to dump key, print otherdata length & other data */ +- break; +- } +- +- case ns_t_tsig: { +- /* BEW - need to complete this */ +- int n; +- +- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen)); +- T(addstr(" ", 1, &buf, &buflen)); +- rdata += 8; /*%< time */ +- n = ns_get16(rdata); rdata += INT16SZ; +- rdata += n; /*%< sig */ +- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */ +- sprintf(buf, "%d", ns_get16(rdata)); +- rdata += INT16SZ; +- addlen(strlen(buf), &buf, &buflen); +- break; +- } +- + case ns_t_a6: { + struct in6_addr a; + int pbyte, pbit; +@@ -557,12 +467,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, + break; + } + +- case ns_t_opt: { +- len = SPRINTF((tmp, "%u bytes", class)); +- T(addstr(tmp, len, &buf, &buflen)); +- break; +- } +- + default: + snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type); + comment = errbuf; +-- +2.49.0 + diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb index f6be1b5fc93..88ad5e44e80 100644 --- a/meta/recipes-core/glibc/glibc_2.39.bb +++ b/meta/recipes-core/glibc/glibc_2.39.bb @@ -56,6 +56,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \ file://0022-Avoid-hardcoded-build-time-paths-in-the-output-binar.patch \ file://0023-qemu-stale-process.patch \ file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \ + file://0024-CVE-2026-5435.patch \ " S = "${WORKDIR}/git" B = "${WORKDIR}/build-${TARGET_SYS}" From patchwork Wed Sep 2 05:25:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96990 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B251C61DD6 for ; Wed, 2 Sep 2026 05:26:37 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5660.1788326795143817383 for ; Tue, 01 Sep 2026 22:26:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eRfzn4fJ; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so6487985e9.2 for ; Tue, 01 Sep 2026 22:26:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326793; x=1788931593; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gbVcnJdm4/owagy8QOaxVab6tjsTGheXxvfGDAHog18=; b=eRfzn4fJRAqv8BYmoxmq5qCKUVJtzfABmnci49WvibawxLYRWAgRtsAOAW6sKGqAQ2 PnW/aIrpTpPRUGCzUzvyNlbQkRKJEcvKLK1mava0nTPTkadAeJpfi24La62OxyfQmOaE vW2Z2WnxSepKNSN6vEIVGHF5EH/hPVUdRp23Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326793; x=1788931593; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gbVcnJdm4/owagy8QOaxVab6tjsTGheXxvfGDAHog18=; b=feMQQ2VMWaTpIxlqmuWTn+G9IHmksfEZdBJLsemxldpMmsMbTTm9LWVWKn9Df7tVFd uFofHDV80x7dYQMaLvwBU2Ek8j5g4mU2hp7FZjCqpdhP8UBod/p37+M8RWfDAsYQxUzp xlol0KBCtc0yEFDJ4KE/IdKwWYcff9UBT/C8OSBR9LHCm0pfA5uUeLg0iDUUVvYBOMUO 3h2MG0c+Sj6lHFpv+smirt2EcaIAGD6A0wucJ/HkBH9rDXK8aAD7W5BMiY9LRt3Kofra 0667KbY4qLWmDvPUO+Xf8udRHSdQyBVShqOGx+DotoKESsBetifVYH3vxoOM9iU0T2h5 7EYQ== X-Gm-Message-State: AFuF++m1UbCAvD3YPxvj4fsTdcQyNV0yZsrFDftLDLpwqgfNUuUtmuog ImVk3Gmg8xiADm7tvKCKDHGFZ3YB668vkItxRfMx9bzu11REcVcXmVZ3MvlLtJp/SWCRl6gtOBE ZHjSVGiQ= X-Gm-Gg: AR+sD10sKv/gJnsrzfp00KIHixyMLanrK+z+hrciv2PswBCgp45BivooqqKLl/obV4Y ff0VBtSl6uzUz/fq8tburm4aFJ9XOVmIzPgEjw0Lskw2/bm+EGgtUrdavaM4ejGXKi9FcT5V3Lz WW6Tgu0nwJ8iT3DlzNEUI/Jm6FeBWDAp2QRK4elpB5FRIqOKrfa3txA5dzSVPvHiVMQxdLgGgNU QWJn166hWYeFOc3raI8hQQHB9eqkirOF0ePCuLstabdkj7bRVX1GCtZR29BBHHXxt5+OUHXwKbA TUvF3mWxe/Ifp0jdlPMQdB/y00Kmw/EhK6Z2FPgAjgBRpN7CerKISFfri1N9SH92DYVbiwcmY/Q qoMS8Plvmz3AdO5LNFptaWXodV0NXiMy/GBps79Q+js/IXxBwm6p3rb1PJKBgg3nQG0VkCd8ARR iBa6EioaFfaFh4DbsgFYoX32LGLckDJNYFb88Fz/jdjVkjuD4KFiM2hiqIl72cGlaUR4doN1VGG A0CX6LILWeN7ncTEA== X-Received: by 2002:a05:600c:1986:b0:499:be2d:c290 with SMTP id 5b1f17b1804b1-49ce5812c8amr29271195e9.9.1788326793250; Tue, 01 Sep 2026 22:26:33 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111 Date: Wed, 2 Sep 2026 07:25:20 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244854 From: Jaipaul Cheernam Backport patches from upstream systemd to fix CVE-2026-29111, where systemd (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. Pick patches from [1], [2], [3] and [4] as referenced in [5]. Note: As scarthgap is using 255 version picked fixes from 257 [1] https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6 [2] https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69 [3] https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412 [4] https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f [5] https://security-tracker.debian.org/tracker/CVE-2026-29111 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../systemd/systemd/CVE-2026-29111-01.patch | 170 ++++++++++++++++++ .../systemd/systemd/CVE-2026-29111-02.patch | 85 +++++++++ .../systemd/systemd/CVE-2026-29111-03.patch | 106 +++++++++++ .../systemd/systemd/CVE-2026-29111-04.patch | 35 ++++ meta/recipes-core/systemd/systemd_255.21.bb | 4 + 5 files changed, 400 insertions(+) create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch new file mode 100644 index 00000000000..4f6ef76aa98 --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch @@ -0,0 +1,170 @@ +From 284fd279f9e9c199982aea51aee59a02e90a2eda Mon Sep 17 00:00:00 2001 +From: Lennart Poettering +Date: Mon, 19 May 2025 12:58:52 +0200 +Subject: [PATCH 1/4] path-util: add flavour of path_startswith() that leaves a + leading slash in place + +(cherry picked from commit ee19edbb9f3455db3f750089082f3e5a925e3a0c) + +Note: The test uses assert_se(streq_ptr()) instead of the upstream +ASSERT_STREQ() macro because ASSERT_STREQ was introduced in systemd v256 +and is not available in v255. + +CVE: CVE-2026-29111 +Upstream-Status: Backport [https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6] +Signed-off-by: Jaipaul Cheernam +--- + src/basic/fs-util.c | 2 +- + src/basic/mkdir.c | 2 +- + src/basic/path-util.c | 39 ++++++++++++++++++++++++++++----------- + src/basic/path-util.h | 10 ++++++++-- + src/test/test-path-util.c | 16 ++++++++++++++++ + 5 files changed, 54 insertions(+), 15 deletions(-) + +diff --git a/src/basic/fs-util.c b/src/basic/fs-util.c +index 5bc7d2f95b..4633a5cd72 100644 +--- a/src/basic/fs-util.c ++++ b/src/basic/fs-util.c +@@ -65,7 +65,7 @@ int rmdir_parents(const char *path, const char *stop) { + assert(*slash == '/'); + *slash = '\0'; + +- if (path_startswith_full(stop, p, /* accept_dot_dot= */ false)) ++ if (path_startswith_full(stop, p, /* flags= */ 0)) + return 0; + + if (rmdir(p) < 0 && errno != ENOENT) +diff --git a/src/basic/mkdir.c b/src/basic/mkdir.c +index c770e5ed32..7bc73361a5 100644 +--- a/src/basic/mkdir.c ++++ b/src/basic/mkdir.c +@@ -155,7 +155,7 @@ int mkdir_parents_internal(const char *prefix, const char *path, mode_t mode, ui + assert(_mkdirat != mkdirat); + + if (prefix) { +- p = path_startswith_full(path, prefix, /* accept_dot_dot= */ false); ++ p = path_startswith_full(path, prefix, /* flags= */ 0); + if (!p) + return -ENOTDIR; + } else +diff --git a/src/basic/path-util.c b/src/basic/path-util.c +index 6810bf66aa..e73f5d708e 100644 +--- a/src/basic/path-util.c ++++ b/src/basic/path-util.c +@@ -403,8 +403,8 @@ char* path_simplify_full(char *path, PathSimplifyFlags flags) { + return path; + } + +-char* path_startswith_full(const char *path, const char *prefix, bool accept_dot_dot) { +- assert(path); ++char* path_startswith_full(const char *original_path, const char *prefix, PathStartWithFlags flags) { ++ assert(original_path); + assert(prefix); + + /* Returns a pointer to the start of the first component after the parts matched by +@@ -417,28 +417,45 @@ char* path_startswith_full(const char *path, const char *prefix, bool accept_dot + * Returns NULL otherwise. + */ + ++ const char *path = original_path; ++ + if ((path[0] == '/') != (prefix[0] == '/')) + return NULL; + + for (;;) { + const char *p, *q; +- int r, k; ++ int m, n; + +- r = path_find_first_component(&path, accept_dot_dot, &p); +- if (r < 0) ++ m = path_find_first_component(&path, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &p); ++ if (m < 0) + return NULL; + +- k = path_find_first_component(&prefix, accept_dot_dot, &q); +- if (k < 0) ++ n = path_find_first_component(&prefix, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &q); ++ if (n < 0) + return NULL; + +- if (k == 0) +- return (char*) (p ?: path); ++ if (n == 0) { ++ if (!p) ++ p = path; ++ ++ if (FLAGS_SET(flags, PATH_STARTSWITH_RETURN_LEADING_SLASH)) { ++ ++ if (p <= original_path) ++ return NULL; ++ ++ p--; ++ ++ if (*p != '/') ++ return NULL; ++ } ++ ++ return (char*) p; ++ } + +- if (r != k) ++ if (m != n) + return NULL; + +- if (!strneq(p, q, r)) ++ if (!strneq(p, q, m)) + return NULL; + } + } +diff --git a/src/basic/path-util.h b/src/basic/path-util.h +index 6d943e967f..e0ec05f4db 100644 +--- a/src/basic/path-util.h ++++ b/src/basic/path-util.h +@@ -53,9 +53,15 @@ int safe_getcwd(char **ret); + int path_make_absolute_cwd(const char *p, char **ret); + int path_make_relative(const char *from, const char *to, char **ret); + int path_make_relative_parent(const char *from_child, const char *to, char **ret); +-char* path_startswith_full(const char *path, const char *prefix, bool accept_dot_dot) _pure_; ++ ++typedef enum PathStartWithFlags { ++ PATH_STARTSWITH_ACCEPT_DOT_DOT = 1U << 0, ++ PATH_STARTSWITH_RETURN_LEADING_SLASH = 1U << 1, ++} PathStartWithFlags; ++ ++char* path_startswith_full(const char *path, const char *prefix, PathStartWithFlags flags) _pure_; + static inline char* path_startswith(const char *path, const char *prefix) { +- return path_startswith_full(path, prefix, true); ++ return path_startswith_full(path, prefix, PATH_STARTSWITH_ACCEPT_DOT_DOT); + } + + int path_compare(const char *a, const char *b) _pure_; +diff --git a/src/test/test-path-util.c b/src/test/test-path-util.c +index f5a425689a..71056b08c1 100644 +--- a/src/test/test-path-util.c ++++ b/src/test/test-path-util.c +@@ -754,6 +754,22 @@ TEST(path_startswith) { + test_path_startswith_one("/foo/bar/barfoo/", "/fo", NULL, NULL); + } + ++static void test_path_startswith_return_leading_slash_one(const char *path, const char *prefix, const char *expected) { ++ const char *p; ++ ++ log_debug("/* %s(%s, %s) */", __func__, path, prefix); ++ ++ p = path_startswith_full(path, prefix, PATH_STARTSWITH_RETURN_LEADING_SLASH); ++ assert_se(streq_ptr(p, expected)); ++} ++ ++TEST(path_startswith_return_leading_slash) { ++ test_path_startswith_return_leading_slash_one("/foo/bar", "/", "/foo/bar"); ++ test_path_startswith_return_leading_slash_one("/foo/bar", "/foo", "/bar"); ++ test_path_startswith_return_leading_slash_one("/foo/bar", "/foo/bar", NULL); ++ test_path_startswith_return_leading_slash_one("/foo/bar/", "/foo/bar", "/"); ++} ++ + static void test_prefix_root_one(const char *r, const char *p, const char *expected) { + _cleanup_free_ char *s = NULL; + const char *t; +-- +2.43.0 diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch new file mode 100644 index 00000000000..9ab94000e65 --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch @@ -0,0 +1,85 @@ +From ed86ee8a7cc82fe1c68e3fb17be71c9c8e62ca87 Mon Sep 17 00:00:00 2001 +From: Lennart Poettering +Date: Fri, 23 May 2025 06:45:40 +0200 +Subject: [PATCH 2/4] path-util: invert PATH_STARTSWITH_ACCEPT_DOT_DOT flag + +As requested: https://github.com/systemd/systemd/pull/37572#pullrequestreview-2861928094 + +(cherry picked from commit ceed11e465f1c8efff1931412a85924d9de7c08d) + +CVE: CVE-2026-29111 +Upstream-Status: Backport [https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69] +Signed-off-by: Jaipaul Cheernam +--- + src/basic/fs-util.c | 2 +- + src/basic/mkdir.c | 2 +- + src/basic/path-util.c | 4 ++-- + src/basic/path-util.h | 4 ++-- + 4 files changed, 6 insertions(+), 6 deletions(-) + +diff --git a/src/basic/fs-util.c b/src/basic/fs-util.c +index 4633a5cd72..21cd6ddcde 100644 +--- a/src/basic/fs-util.c ++++ b/src/basic/fs-util.c +@@ -65,7 +65,7 @@ int rmdir_parents(const char *path, const char *stop) { + assert(*slash == '/'); + *slash = '\0'; + +- if (path_startswith_full(stop, p, /* flags= */ 0)) ++ if (path_startswith_full(stop, p, PATH_STARTSWITH_REFUSE_DOT_DOT)) + return 0; + + if (rmdir(p) < 0 && errno != ENOENT) +diff --git a/src/basic/mkdir.c b/src/basic/mkdir.c +index 7bc73361a5..8f14c47214 100644 +--- a/src/basic/mkdir.c ++++ b/src/basic/mkdir.c +@@ -155,7 +155,7 @@ int mkdir_parents_internal(const char *prefix, const char *path, mode_t mode, ui + assert(_mkdirat != mkdirat); + + if (prefix) { +- p = path_startswith_full(path, prefix, /* flags= */ 0); ++ p = path_startswith_full(path, prefix, PATH_STARTSWITH_REFUSE_DOT_DOT); + if (!p) + return -ENOTDIR; + } else +diff --git a/src/basic/path-util.c b/src/basic/path-util.c +index e73f5d708e..a65a5c32f6 100644 +--- a/src/basic/path-util.c ++++ b/src/basic/path-util.c +@@ -426,11 +426,11 @@ char* path_startswith_full(const char *original_path, const char *prefix, PathSt + const char *p, *q; + int m, n; + +- m = path_find_first_component(&path, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &p); ++ m = path_find_first_component(&path, !FLAGS_SET(flags, PATH_STARTSWITH_REFUSE_DOT_DOT), &p); + if (m < 0) + return NULL; + +- n = path_find_first_component(&prefix, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &q); ++ n = path_find_first_component(&prefix, !FLAGS_SET(flags, PATH_STARTSWITH_REFUSE_DOT_DOT), &q); + if (n < 0) + return NULL; + +diff --git a/src/basic/path-util.h b/src/basic/path-util.h +index e0ec05f4db..11a1078df9 100644 +--- a/src/basic/path-util.h ++++ b/src/basic/path-util.h +@@ -55,13 +55,13 @@ int path_make_relative(const char *from, const char *to, char **ret); + int path_make_relative_parent(const char *from_child, const char *to, char **ret); + + typedef enum PathStartWithFlags { +- PATH_STARTSWITH_ACCEPT_DOT_DOT = 1U << 0, ++ PATH_STARTSWITH_REFUSE_DOT_DOT = 1U << 0, + PATH_STARTSWITH_RETURN_LEADING_SLASH = 1U << 1, + } PathStartWithFlags; + + char* path_startswith_full(const char *path, const char *prefix, PathStartWithFlags flags) _pure_; + static inline char* path_startswith(const char *path, const char *prefix) { +- return path_startswith_full(path, prefix, PATH_STARTSWITH_ACCEPT_DOT_DOT); ++ return path_startswith_full(path, prefix, 0); + } + + int path_compare(const char *a, const char *b) _pure_; +-- +2.43.0 diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch new file mode 100644 index 00000000000..8b9b4d4075c --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch @@ -0,0 +1,106 @@ +From 7a1749753b4853866f90ef25d48192e4d1563543 Mon Sep 17 00:00:00 2001 +From: Mike Yuan +Date: Thu, 26 Feb 2026 11:06:00 +0100 +Subject: [PATCH 3/4] core/cgroup: avoid one unnecessary strjoina() + +(cherry picked from commit 42aee39107fbdd7db1ccd402a2151822b2805e9f) +(cherry picked from commit 80acea4ef80a4bb78560ed970c34952299b890d6) +(cherry picked from commit b5fd14693057e5f2c9b4a49603be64ec3608ff6c) + +Note: This backport uses u->cgroup_path directly instead of the upstream +CGroupRuntime *crt / crt->cgroup_path pattern because the CGroupRuntime +struct was introduced in systemd v256 (commit 1d9cc876). In v255, the +cgroup_path is still a direct member of the Unit struct. + +CVE: CVE-2026-29111 +Upstream-Status: Backport [https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412] +Signed-off-by: Jaipaul Cheernam +--- + src/core/cgroup.c | 27 +++++++++++++-------------- + 1 file changed, 13 insertions(+), 14 deletions(-) + +diff --git a/src/core/cgroup.c b/src/core/cgroup.c +index d398655b0a..e5e7f032c2 100644 +--- a/src/core/cgroup.c ++++ b/src/core/cgroup.c +@@ -2568,12 +2568,13 @@ static int unit_update_cgroup( + return 0; + } + +-static int unit_attach_pid_to_cgroup_via_bus(Unit *u, pid_t pid, const char *suffix_path) { ++static int unit_attach_pid_to_cgroup_via_bus(Unit *u, const char *cgroup_path, pid_t pid) { + _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL; +- char *pp; + int r; + + assert(u); ++ assert(cgroup_path); ++ assert(pid_is_valid(pid)); + + if (MANAGER_IS_SYSTEM(u->manager)) + return -EINVAL; +@@ -2581,17 +2582,13 @@ static int unit_attach_pid_to_cgroup_via_bus(Unit *u, pid_t pid, const char *suf + if (!u->manager->system_bus) + return -EIO; + +- if (!u->cgroup_path) +- return -EINVAL; +- + /* Determine this unit's cgroup path relative to our cgroup root */ +- pp = path_startswith(u->cgroup_path, u->manager->cgroup_root); ++ const char *pp = path_startswith_full(cgroup_path, ++ u->manager->cgroup_root, ++ PATH_STARTSWITH_RETURN_LEADING_SLASH|PATH_STARTSWITH_REFUSE_DOT_DOT); + if (!pp) + return -EINVAL; + +- pp = strjoina("/", pp, suffix_path); +- path_simplify(pp); +- + r = bus_call_method(u->manager->system_bus, + bus_systemd_mgr, + "AttachProcessesToUnit", +@@ -2630,8 +2627,10 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) { + return r; + + if (isempty(suffix_path)) +- p = u->cgroup_path; ++ p = empty_to_root(u->cgroup_path); + else { ++ assert(path_is_absolute(suffix_path)); ++ + joined = path_join(u->cgroup_path, suffix_path); + if (!joined) + return -ENOMEM; +@@ -2649,7 +2648,7 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) { + * before we use it */ + r = pidref_verify(pid); + if (r < 0) { +- log_unit_info_errno(u, r, "PID " PID_FMT " vanished before we could move it to target cgroup '%s', skipping: %m", pid->pid, empty_to_root(p)); ++ log_unit_info_errno(u, r, "PID " PID_FMT " vanished before we could move it to target cgroup '%s', skipping: %m", pid->pid, p); + continue; + } + +@@ -2660,7 +2659,7 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) { + + log_unit_full_errno(u, again ? LOG_DEBUG : LOG_INFO, r, + "Couldn't move process "PID_FMT" to%s requested cgroup '%s': %m", +- pid->pid, again ? " directly" : "", empty_to_root(p)); ++ pid->pid, again ? " directly" : "", p); + + if (again) { + int z; +@@ -2670,9 +2669,9 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) { + * Since it's more privileged it might be able to move the process across the + * leaves of a subtree whose top node is not owned by us. */ + +- z = unit_attach_pid_to_cgroup_via_bus(u, pid->pid, suffix_path); ++ z = unit_attach_pid_to_cgroup_via_bus(u, p, pid->pid); + if (z < 0) +- log_unit_info_errno(u, z, "Couldn't move process "PID_FMT" to requested cgroup '%s' (directly or via the system bus): %m", pid->pid, empty_to_root(p)); ++ log_unit_info_errno(u, z, "Couldn't move process "PID_FMT" to requested cgroup '%s' (directly or via the system bus): %m", pid->pid, p); + else { + if (ret >= 0) + ret++; /* Count successful additions */ +-- +2.43.0 diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch new file mode 100644 index 00000000000..ebf2ba9d5b2 --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch @@ -0,0 +1,35 @@ +From 0d2c41d0f024088a275ac0c02d50205c800dec8a Mon Sep 17 00:00:00 2001 +From: Mike Yuan +Date: Thu, 26 Feb 2026 11:06:34 +0100 +Subject: [PATCH 4/4] core: validate input cgroup path more prudently + +(cherry picked from commit efa6ba2ab625aaa160ac435a09e6482fc63bdbe8) +(cherry picked from commit 3cee294fe8cf4fa0eff933ab21416d099942cabd) +(cherry picked from commit 1d22f706bd04f45f8422e17fbde3f56ece17758a) + +CVE: CVE-2026-29111 +Upstream-Status: Backport [https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f] +Signed-off-by: Jaipaul Cheernam +--- + src/core/dbus-manager.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/core/dbus-manager.c b/src/core/dbus-manager.c +index c7372ca033..cb84ba9866 100644 +--- a/src/core/dbus-manager.c ++++ b/src/core/dbus-manager.c +@@ -646,6 +646,12 @@ static int method_get_unit_by_control_group(sd_bus_message *message, void *userd + if (r < 0) + return r; + ++ if (!path_is_absolute(cgroup)) ++ return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Control group path is not absolute: %s", cgroup); ++ ++ if (!path_is_normalized(cgroup)) ++ return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Control group path is not normalized: %s", cgroup); ++ + u = manager_get_unit_by_cgroup(m, cgroup); + if (!u) + return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_UNIT, +-- +2.43.0 diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.21.bb index 9c5f8af240a..e5a0fd91700 100644 --- a/meta/recipes-core/systemd/systemd_255.21.bb +++ b/meta/recipes-core/systemd/systemd_255.21.bb @@ -33,6 +33,10 @@ SRC_URI += " \ file://CVE-2026-40225-02.patch \ file://CVE-2026-40226-01.patch \ file://CVE-2026-40226-02.patch \ + file://CVE-2026-29111-01.patch \ + file://CVE-2026-29111-02.patch \ + file://CVE-2026-29111-03.patch \ + file://CVE-2026-29111-04.patch \ " # patches needed by musl From patchwork Wed Sep 2 05:25:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96994 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 92ED3C624D7 for ; Wed, 2 Sep 2026 05:26:47 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5664.1788326797932268783 for ; Tue, 01 Sep 2026 22:26:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ucWENmrw; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4956869750eso3476675e9.2 for ; Tue, 01 Sep 2026 22:26:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326796; x=1788931596; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=zxFdS8NvSPpssBJNW0ub8csbCQgk5CGHv3afFwCrAng=; b=ucWENmrwphL7W1YixLcSg4ImeRvhRTVq3KrhLnVofRZqANpbmUgpfpWoXyR0iposgg AhpBDNL5BYPW9Sh42mhY9d4Rw0N/ZeqWh7JiTtOMjzEYYLRVDFTzDFQTXCU8QYhKr9aD T3oz/lsVk+Li+Xnf37P85f4lGYltc0G3pBtdo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326796; x=1788931596; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=zxFdS8NvSPpssBJNW0ub8csbCQgk5CGHv3afFwCrAng=; b=Ly2G9KtY2iQXBjmuxY32SEZYmcpyrhZfiZVXstmHaSBlfni2IMpWu5YFtZj0XzkLhg wUIRbz/gzGP9j7ggEo+Opcnm2LsLSh3Gf3g0LTzdOO/kMicyKFhHpCpLPjIEs5nmV1W5 RFshpwSLgaFIG+iVBbEVo8OBWcxK3s6BftlHjgt8xykRpbR6SwBKLB6v+YeA5Q0p0SWX T9c35osEIkoQPhjXDXCN/+1ONG4VFjosjFafKxOjd120XQs1rWAM/Wr86N3NFpehFmS/ TuxCi6n4clmCD82dZVZZDaoQ5h1ZkOtN1vrWbI8O97O95ytvDSv5s8+5FN3nutcaKZ+G mCUg== X-Gm-Message-State: AFuF++lihbmyfd1ytzjadzTcwPCeIXYpq8REsMWwe3cFJSKlm1wdtslM wp5An7NBMaNxFAwxtUpETZnB0oC6SjSBCKbtzqmp2bazsrOZDFG9r9pSJt/RUDIPGj4mQNIATkW eDfLSZDc= X-Gm-Gg: AR+sD10CfSeT6U7xMgCUKfUcYhlmGadVX5m8XrCJLdKIBFL7DxJu8664QPXKB9O+Cbo ZhrE7+l2nMr++YpCFOLSuSoHkgYzUnmTdfhvAq01mWaVcqumh0bpDDRLrmjTv6+w0vLrucAA8gV 3ATlg2X1KaKn1CzgKitJlK/XNmI+RcBCaQo0eHEW934y8AU5BmJH+txIsTugKapiGcHFx1LvoY2 GzN44m3FZYw1gN6VB6SUYTdKpP2kRSvLbuA1p5D2eyE1lVfE28fuEeoafWBVaBDw7AqebGe2tfz gnNkPTrrUoLfDsztRcWfqBuMPk489+0eYZahScIvCkmAwlvy8EfQV/ZEoBsh4LoiLqnSh8hVAmX ZWFAV7xkMhaqCfkETi0yf8MMXEkcVzzOqxvLwIuoLIdDlCFVXUlCTMmltrPlBUWEgVFz7Dme9nn so2TFkSq0zU5siHsF5Qu7XcfcVq1AeQI/JXMHut8Vpu81UE5o8PCIRVWiin5KwlOZDIaPmQ77bS BUuE2nKf/yyTadG9w== X-Received: by 2002:a05:600c:530f:b0:499:bdf1:7578 with SMTP id 5b1f17b1804b1-49ce55ecdf2mr37825015e9.3.1788326796106; Tue, 01 Sep 2026 22:26:36 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:35 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886 Date: Wed, 2 Sep 2026 07:25:21 +0200 Message-ID: <24991f7383dbe229a696ad209ae7d58115a051a1.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244855 From: Emily Vekariya The univ.Real type converts its mantissa, base, and exponent to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects. scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in all versions before 0.6.4. Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59886 Signed-off-by: Emily Vekariya Signed-off-by: Yoann Congal --- .../recipes-devtools/python/python-pyasn1.inc | 1 + .../python3-pyasn1/CVE-2026-59886.patch | 252 ++++++++++++++++++ 2 files changed, 253 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc index 96b4a3b52a6..1780ee1d888 100644 --- a/meta/recipes-devtools/python/python-pyasn1.inc +++ b/meta/recipes-devtools/python/python-pyasn1.inc @@ -19,6 +19,7 @@ inherit ptest SRC_URI += " \ file://run-ptest \ file://CVE-2026-23490.patch \ + file://CVE-2026-59886.patch \ " RDEPENDS:${PN}-ptest += " \ diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch new file mode 100644 index 00000000000..80468c6a5e8 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch @@ -0,0 +1,252 @@ +From 9b89b511a7284f17ef3a2de6d05fbf6030133abb Mon Sep 17 00:00:00 2001 +From: Simon Pichugin +Date: Wed, 8 Jul 2026 17:32:09 -0700 +Subject: [PATCH] Merge commit from fork + +CVE: CVE-2026-59886 +Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886] + +(cherry picked from commit e60c691cb91addb8fcefa2f537e85ede6fb1e886) +Signed-off-by: Emily Vekariya +--- + pyasn1/type/univ.py | 21 +++++++++---- + tests/codec/ber/test_decoder.py | 53 +++++++++++++++++++++++++++------ + tests/codec/cer/test_decoder.py | 10 +++++++ + tests/codec/der/test_decoder.py | 19 ++++++++++++ + tests/type/test_univ.py | 40 +++++++++++++++++++++++++ + 5 files changed, 129 insertions(+), 14 deletions(-) + +diff --git a/pyasn1/type/univ.py b/pyasn1/type/univ.py +index c5d0778..adff2df 100644 +--- a/pyasn1/type/univ.py ++++ b/pyasn1/type/univ.py +@@ -1318,7 +1318,7 @@ class Real(base.SimpleAsn1Type): + def __normalizeBase10(value): + m, b, e = value + while m and m % 10 == 0: +- m /= 10 ++ m //= 10 + e += 1 + return m, b, e + +@@ -1457,10 +1457,21 @@ class Real(base.SimpleAsn1Type): + def __float__(self): + if self._value in self._inf: + return self._value +- else: +- return float( +- self._value[0] * pow(self._value[1], self._value[2]) +- ) ++ ++ mantissa, base, exponent = self._value ++ ++ if not mantissa: ++ return 0.0 ++ ++ if base == 2: ++ return math.ldexp(float(mantissa), exponent) ++ ++ # base is 10 (prettyIn() rejects everything else); refuse to ++ # materialize astronomically large integers via pow() ++ if exponent > sys.float_info.max_10_exp: ++ raise OverflowError('Real value too large to convert to float') ++ ++ return float(mantissa * pow(base, exponent)) + + def __abs__(self): + return self.clone(abs(float(self))) +diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py +index f033dfd..f6ff7b0 100644 +--- a/tests/codec/ber/test_decoder.py ++++ b/tests/codec/ber/test_decoder.py +@@ -21,6 +21,7 @@ from pyasn1.type import univ + from pyasn1.type import char + from pyasn1.codec import streaming + from pyasn1.codec.ber import decoder ++from pyasn1.codec.ber import encoder + from pyasn1.codec.ber import eoo + from pyasn1.compat.octets import ints2octs, str2octs, null + from pyasn1 import error +@@ -547,17 +548,51 @@ class RealDecoderTestCase(BaseTestCase): + ints2octs((9, 4, 161, 255, 1, 3)) + ) == (univ.Real((3, 2, -1020)), null) + +-# TODO: this requires Real type comparison fix ++ def testBin6(self): # large exponent, base = 16 ++ value, rest = decoder.decode( ++ bytes((9, 5, 162, 0, 255, 255, 1)) ++ ) ++ ++ assert tuple(value) == (1, 2, 262140) ++ assert rest == b'' ++ ++ def testBin7(self): # large exponent in 4-octet form, base = 16 ++ value, rest = decoder.decode( ++ bytes((9, 7, 227, 4, 1, 35, 69, 103, 1)) ++ ) + +-# def testBin6(self): +-# assert decoder.decode( +-# ints2octs((9, 5, 162, 0, 255, 255, 1)) +-# ) == (univ.Real((1, 2, 262140)), null) ++ assert tuple(value) == (-1, 2, 76354972) ++ assert rest == b'' ++ ++ def testLargeBinaryRoundTrip(self): ++ substrate = encoder.encode(univ.Real((-1, 2, 76354972))) ++ value, rest = decoder.decode(substrate) ++ ++ assert tuple(value) == (-1, 2, 76354972) ++ assert rest == b'' ++ ++ def testLongFormBinaryRealExponentLength(self): ++ value, rest = decoder.decode( ++ bytes((9, 6, 0x83, 3, 0x0f, 0x42, 0x40, 1)) ++ ) + +-# def testBin7(self): +-# assert decoder.decode( +-# ints2octs((9, 7, 227, 4, 1, 35, 69, 103, 1)) +-# ) == (univ.Real((-1, 2, 76354972)), null) ++ assert tuple(value) == (1, 2, 1000000) ++ assert rest == b'' ++ ++ def testLargeBinaryPrettyPrintOverflow(self): ++ value, rest = decoder.decode( ++ b'\t\t\xeb\x060662.666\xd0B\x00\x00\x00\x00\x00\x00\x00' ++ ) ++ ++ assert value.prettyPrint() == '' ++ assert rest == b'6\xd0B\x00\x00\x00\x00\x00\x00\x00' ++ ++ try: ++ float(value) ++ except OverflowError: ++ pass ++ else: ++ assert 0, '__float__() tolerated overflow' + + def testPlusInf(self): + assert decoder.decode( +diff --git a/tests/codec/cer/test_decoder.py b/tests/codec/cer/test_decoder.py +index 133affd..3d27194 100644 +--- a/tests/codec/cer/test_decoder.py ++++ b/tests/codec/cer/test_decoder.py +@@ -15,6 +15,7 @@ from pyasn1.type import opentype + from pyasn1.type import univ + from pyasn1.codec.cer import decoder + from pyasn1.compat.octets import ints2octs, str2octs, null ++from pyasn1.codec.cer import encoder + from pyasn1.error import PyAsn1Error + + +@@ -66,6 +67,15 @@ class OctetStringDecoderTestCase(BaseTestCase): + # TODO: test failures on short chunked and long unchunked substrate samples + + ++class RealDecoderTestCase(BaseTestCase): ++ def testLargeBinaryRoundTrip(self): ++ substrate = encoder.encode(univ.Real((-1, 2, 76354972))) ++ value, rest = decoder.decode(substrate) ++ ++ assert tuple(value) == (-1, 2, 76354972) ++ assert rest == b'' ++ ++ + class SequenceDecoderWithUntaggedOpenTypesTestCase(BaseTestCase): + def setUp(self): + openType = opentype.OpenType( +diff --git a/tests/codec/der/test_decoder.py b/tests/codec/der/test_decoder.py +index 5bc9deb..553563c 100644 +--- a/tests/codec/der/test_decoder.py ++++ b/tests/codec/der/test_decoder.py +@@ -15,6 +15,7 @@ from pyasn1.type import opentype + from pyasn1.type import univ + from pyasn1.codec.der import decoder + from pyasn1.compat.octets import ints2octs, null ++from pyasn1.codec.der import encoder + from pyasn1.error import PyAsn1Error + + +@@ -72,6 +73,24 @@ class OctetStringDecoderTestCase(BaseTestCase): + assert 0, 'chunked encoding tolerated' + + ++class RealDecoderTestCase(BaseTestCase): ++ def testCanonicalLargeBinaryReal(self): ++ substrate = encoder.encode(univ.Real((1, 2, 1000000))) ++ assert substrate == bytes((9, 5, 0x82, 0x0f, 0x42, 0x40, 1)) ++ ++ value, rest = decoder.decode(substrate) ++ ++ assert tuple(value) == (1, 2, 1000000) ++ assert rest == b'' ++ ++ def testLargeBinaryRoundTrip(self): ++ substrate = encoder.encode(univ.Real((-1, 2, 76354972))) ++ value, rest = decoder.decode(substrate) ++ ++ assert tuple(value) == (-1, 2, 76354972) ++ assert rest == b'' ++ ++ + class SequenceDecoderWithUntaggedOpenTypesTestCase(BaseTestCase): + def setUp(self): + openType = opentype.OpenType( +diff --git a/tests/type/test_univ.py b/tests/type/test_univ.py +index 8aec183..bc21c37 100644 +--- a/tests/type/test_univ.py ++++ b/tests/type/test_univ.py +@@ -780,9 +780,49 @@ class RealTestCase(BaseTestCase): + def testFloat(self): + assert float(univ.Real(4.0)) == 4.0, '__float__() fails' + ++ def testFloatBase10Precision(self): ++ assert float(univ.Real((3, 10, 23))) == 3e23, '__float__() lost base-10 behavior' ++ ++ def testFloatOverflow(self): ++ try: ++ float(univ.Real((1, 2, 1000000))) ++ except OverflowError: ++ pass ++ else: ++ assert 0, '__float__() tolerated overflow' ++ ++ assert univ.Real((1, 2, 1000000)).prettyPrint() == '' ++ ++ def testFloatUnderflow(self): ++ assert float(univ.Real((1, 2, -1000000))) == 0.0, '__float__() failed underflow' ++ ++ def testFloatZeroMantissa(self): ++ assert float(univ.Real((0, 10, 1000000000))) == 0.0, '__float__() failed zero mantissa' ++ assert float(univ.Real((0, 2, 1000000000))) == 0.0, '__float__() failed zero mantissa' ++ ++ def testFloatBase10Overflow(self): ++ try: ++ float(univ.Real((1, 10, sys.float_info.max_10_exp + 1))) ++ except OverflowError: ++ pass ++ else: ++ assert 0, '__float__() tolerated base-10 overflow' ++ ++ def testFloatBase10NormalizedOverflow(self): ++ try: ++ float(univ.Real((10, 10, sys.float_info.max_10_exp))) ++ except OverflowError: ++ pass ++ else: ++ assert 0, '__float__() tolerated normalized base-10 overflow' ++ + def testPrettyIn(self): + assert univ.Real((3, 10, 0)) == 3, 'prettyIn() fails' + ++ def testPrettyInBigBase10Mantissa(self): ++ assert tuple(univ.Real((10 ** 400, 10, 0))) == (1, 10, 400), \ ++ 'prettyIn() big mantissa normalization fails' ++ + # infinite float values + def testStrInf(self): + assert str(univ.Real('inf')) == 'inf', 'str() fails' +-- +2.34.1 + From patchwork Wed Sep 2 05:25:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96993 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 69B12C61DFD for ; Wed, 2 Sep 2026 05:26:47 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5534.1788326800676521095 for ; Tue, 01 Sep 2026 22:26:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=vwIJhgvb; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49cd77e0f95so6284335e9.3 for ; Tue, 01 Sep 2026 22:26:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326799; x=1788931599; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tN7R5Bk+iMhD5tQkk6d3W3kEfJdA9cJJCkHIZi7EGRQ=; b=vwIJhgvbTdFQ0ImBEtxOBNEjQ4JNbWbLUNJS0Qj7HNrcIpnTTOQgVokl3FPzw/JBo9 myRKmZz5WI9+4jQY4iN/3JxImaQTWCISzYvRyCuf8Pf6Nj5VK+MHFitiVkdyQ9zbhve9 Toz351nGyess5PwPNzVqZ+o83WdW7B9OwL0ec= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326799; x=1788931599; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tN7R5Bk+iMhD5tQkk6d3W3kEfJdA9cJJCkHIZi7EGRQ=; b=EVEWunq+kdzI7voK8XZBzrvcUhh/nv/yTHOxF3aecmuiEKxYGqBTLB4Fo6V0qbIHhJ HTKJdSSEBMY6MLWtqooHdzNPF64R/bpOjWoocXWi52HiM1odYo9ZGadllDHBwkJCaJsG D/g6rBR9OkibbwhCgArZqrLFoBhVmol1ezYHOMRiKIWinYsl3nA83kFVR07m4QRj/jIe 0st3HMGhTgWnmw+A1IFj64qe26wNxM2SJfFP7LC/bFT62S7IhVPnnVQHYRevh9Vill02 4llRI9ehTqx6TzxBn59Mk9YrsEpdVUmYeoNE0d2fxfsKTzQ+AXAetBkN+s996nZDi9sY RGfw== X-Gm-Message-State: AFuF++n9TLsax/ultcrsxuFeqi/hmi1p3wSREoJNs424Mk16sPEowcLa QKyhXCG2Sa/DZ/wdsA1XErLzp6fpvI7+TIQWj6WYdRWlZgVRzFy+bijVQyiarbsWt2R7Bf4Qxk9 +FIl0Bc0= X-Gm-Gg: AR+sD13KTQpb7AUU2QD/V9EQ5dZepJvXkM2NBl3JhcFf9tAtxZHnFjseqamcBkDAKoa 5D884KCUwOS0u6yMpW0+x4HwSRo44otM7ryq1y8QHVCxHOu9vey8qFnoJC12hqoUR1dKv7adP4t YT6VjZsYdPfLq45zhj8wHnBNusW8ikZcb+mH9i2lVE7gABzaARqQ9TKvuVkYVHlq9xQVLHfaX9D h1WT1qMG2xT/F3GYXfuboPP34qdPaGy4zPsFFdimnXdpFmYwO7DpPtnBX7pIun4KELK6pAwwfQC o0C8I4vZfIbWIivhpDy6OTfuIhly600vBOeFJosnqsxeeUs4bGDJdvK+ieXrDQOMXnftnOFSxKN b7jwiSQg5jVSIulHvty5CHm0g/+V/rMiGWaSlm1vSWeQH71cftTLPGBJTEfVyWc3I7kl3glraOt +g82BPPI2JKBlw5bvUMcdV3OlnIgkoVJo684+1O6rhXWBKKPb82l1YO57ZH7aj1lhfyvJngzD7L o44YiheA8qkPDpLfhqhDslwIy7v X-Received: by 2002:a05:600c:3b13:b0:499:bf8c:cfd1 with SMTP id 5b1f17b1804b1-49ce580a8cbmr27677855e9.2.1788326798836; Tue, 01 Sep 2026 22:26:38 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884 Date: Wed, 2 Sep 2026 07:25:22 +0200 Message-ID: <75ff4b187cf1b5e4e874cab8273ea84377b3c873.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244856 From: Emily Vekariya The BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size. A crafted input can force construction of an arbitrarily large integer with CPU cost growing quadratically, and can trigger unhandled ValueError exceptions in the Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in all versions before 0.6.4. Pick the upstream patch [1] as mentioned in [2]. [1] https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59884 Signed-off-by: Emily Vekariya Signed-off-by: Yoann Congal --- .../recipes-devtools/python/python-pyasn1.inc | 1 + .../python3-pyasn1/CVE-2026-59884.patch | 245 ++++++++++++++++++ 2 files changed, 246 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc index 1780ee1d888..ae96f09fb1d 100644 --- a/meta/recipes-devtools/python/python-pyasn1.inc +++ b/meta/recipes-devtools/python/python-pyasn1.inc @@ -20,6 +20,7 @@ SRC_URI += " \ file://run-ptest \ file://CVE-2026-23490.patch \ file://CVE-2026-59886.patch \ + file://CVE-2026-59884.patch \ " RDEPENDS:${PN}-ptest += " \ diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch new file mode 100644 index 00000000000..dd897e2d758 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch @@ -0,0 +1,245 @@ +From 38e8ae286160eb27620e7cb42108b3b28d1f299f Mon Sep 17 00:00:00 2001 +From: Simon Pichugin +Date: Wed, 8 Jul 2026 17:36:30 -0700 +Subject: [PATCH] Merge commit from fork + +CVE: CVE-2026-59884 +Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5] + +(cherry picked from commit 628e36ecbb5277a3f01572ce418ef54271b165a5) +Signed-off-by: Emily Vekariya +--- + pyasn1/codec/ber/decoder.py | 13 +++++++++++-- + pyasn1/type/tag.py | 20 ++++++++++++++++---- + tests/codec/ber/test_decoder.py | 25 +++++++++++++++++++++++++ + tests/codec/cer/test_decoder.py | 15 +++++++++++++++ + tests/codec/der/test_decoder.py | 15 +++++++++++++++ + tests/type/test_tag.py | 20 ++++++++++++++++++++ + 6 files changed, 102 insertions(+), 6 deletions(-) + +diff --git a/pyasn1/codec/ber/decoder.py b/pyasn1/codec/ber/decoder.py +index be8ba65..18865c2 100644 +--- a/pyasn1/codec/ber/decoder.py ++++ b/pyasn1/codec/ber/decoder.py +@@ -39,6 +39,10 @@ SubstrateUnderrunError = error.SubstrateUnderrunError + # 20 octets allows up to 140-bit integers, supporting UUID-based OIDs + MAX_OID_ARC_CONTINUATION_OCTETS = 20 + ++# Maximum number of octets in a long-form tag ID (20 octets = up to ++# 140-bit tag IDs, matching the OID arc limit) ++MAX_TAG_OCTETS = 20 ++ + + class AbstractPayloadDecoder(object): + protoComponent = None +@@ -1570,7 +1574,7 @@ class SingleItemDecoder(object): + + if tagId == 0x1F: + isShortTag = False +- lengthOctetIdx = 0 ++ tagOctetCount = 0 + tagId = 0 + + while True: +@@ -1584,7 +1588,12 @@ class SingleItemDecoder(object): + ) + + integerTag = ord(integerByte) +- lengthOctetIdx += 1 ++ tagOctetCount += 1 ++ if tagOctetCount > MAX_TAG_OCTETS: ++ raise error.PyAsn1Error( ++ 'Tag ID octet count exceeds limit (%d)' % ( ++ MAX_TAG_OCTETS,) ++ ) + tagId <<= 7 + tagId |= (integerTag & 0x7F) + +diff --git a/pyasn1/type/tag.py b/pyasn1/type/tag.py +index a21a405..bbbdd85 100644 +--- a/pyasn1/type/tag.py ++++ b/pyasn1/type/tag.py +@@ -34,6 +34,16 @@ tagCategoryExplicit = 0x02 + tagCategoryUntagged = 0x04 + + ++def _tagIdToStr(tagId): ++ # Decimal rendering of a huge tag ID can exceed the interpreter's ++ # integer-to-string conversion limit (sys.get_int_max_str_digits(), ++ # Python 3.11+) and raise ValueError; hexadecimal is not limited ++ try: ++ return str(tagId) ++ except ValueError: ++ return hex(tagId) ++ ++ + class Tag(object): + """Create ASN.1 tag + +@@ -56,7 +66,8 @@ class Tag(object): + """ + def __init__(self, tagClass, tagFormat, tagId): + if tagId < 0: +- raise error.PyAsn1Error('Negative tag ID (%s) not allowed' % tagId) ++ raise error.PyAsn1Error( ++ 'Negative tag ID (%s) not allowed' % _tagIdToStr(tagId)) + self.__tagClass = tagClass + self.__tagFormat = tagFormat + self.__tagId = tagId +@@ -65,7 +76,7 @@ class Tag(object): + + def __repr__(self): + representation = '[%s:%s:%s]' % ( +- self.__tagClass, self.__tagFormat, self.__tagId) ++ self.__tagClass, self.__tagFormat, _tagIdToStr(self.__tagId)) + return '<%s object, tag %s>' % ( + self.__class__.__name__, representation) + +@@ -194,8 +205,9 @@ class TagSet(object): + self.__hash = hash(self.__superTagsClassId) + + def __repr__(self): +- representation = '-'.join(['%s:%s:%s' % (x.tagClass, x.tagFormat, x.tagId) +- for x in self.__superTags]) ++ representation = '-'.join( ++ ['%s:%s:%s' % (x.tagClass, x.tagFormat, _tagIdToStr(x.tagId)) ++ for x in self.__superTags]) + if representation: + representation = 'tags ' + representation + else: +diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py +index f6ff7b0..0152027 100644 +--- a/tests/codec/ber/test_decoder.py ++++ b/tests/codec/ber/test_decoder.py +@@ -34,6 +34,31 @@ class LargeTagDecoderTestCase(BaseTestCase): + def testLongTag(self): + assert decoder.decode(ints2octs((0x1f, 2, 1, 0)))[0].tagSet == univ.Integer.tagSet + ++ def testVeryLongTagRoundTrip(self): ++ # (1 << 140) - 1 is the largest tag ID fitting the 20 octet limit ++ for tagId in (1 << 77, (1 << 140) - 1): ++ largeTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, tagId) ++ asn1Spec = univ.Integer().subtype(implicitTag=largeTag) ++ value = univ.Integer(1).subtype(implicitTag=largeTag) ++ ++ decoded, rest = decoder.decode(encoder.encode(value), asn1Spec=asn1Spec) ++ ++ assert rest == b'' ++ assert decoded == 1 ++ ++ def testExcessiveLongTag(self): ++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit ++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140) ++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag) ++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag)) ++ ++ try: ++ decoder.decode(substrate, asn1Spec=asn1Spec) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert 0, 'excessive long tag tolerated' ++ + def testTagsEquivalence(self): + integer = univ.Integer(2).subtype(implicitTag=tag.Tag(tag.tagClassContext, 0, 0)) + assert decoder.decode(ints2octs((0x9f, 0x80, 0x00, 0x02, 0x01, 0x02)), asn1Spec=integer) == decoder.decode( +diff --git a/tests/codec/cer/test_decoder.py b/tests/codec/cer/test_decoder.py +index 3d27194..d759f76 100644 +--- a/tests/codec/cer/test_decoder.py ++++ b/tests/codec/cer/test_decoder.py +@@ -67,6 +67,21 @@ class OctetStringDecoderTestCase(BaseTestCase): + # TODO: test failures on short chunked and long unchunked substrate samples + + ++class LargeTagDecoderTestCase(BaseTestCase): ++ def testExcessiveLongTag(self): ++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit ++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140) ++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag) ++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag)) ++ ++ try: ++ decoder.decode(substrate, asn1Spec=asn1Spec) ++ except PyAsn1Error: ++ pass ++ else: ++ assert 0, 'excessive long tag tolerated' ++ ++ + class RealDecoderTestCase(BaseTestCase): + def testLargeBinaryRoundTrip(self): + substrate = encoder.encode(univ.Real((-1, 2, 76354972))) +diff --git a/tests/codec/der/test_decoder.py b/tests/codec/der/test_decoder.py +index 553563c..726c999 100644 +--- a/tests/codec/der/test_decoder.py ++++ b/tests/codec/der/test_decoder.py +@@ -73,6 +73,21 @@ class OctetStringDecoderTestCase(BaseTestCase): + assert 0, 'chunked encoding tolerated' + + ++class LargeTagDecoderTestCase(BaseTestCase): ++ def testExcessiveLongTag(self): ++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit ++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140) ++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag) ++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag)) ++ ++ try: ++ decoder.decode(substrate, asn1Spec=asn1Spec) ++ except PyAsn1Error: ++ pass ++ else: ++ assert 0, 'excessive long tag tolerated' ++ ++ + class RealDecoderTestCase(BaseTestCase): + def testCanonicalLargeBinaryReal(self): + substrate = encoder.encode(univ.Real((1, 2, 1000000))) +diff --git a/tests/type/test_tag.py b/tests/type/test_tag.py +index d0ffa07..ab9b8b1 100644 +--- a/tests/type/test_tag.py ++++ b/tests/type/test_tag.py +@@ -9,6 +9,7 @@ import unittest + + from tests.base import BaseTestCase + ++from pyasn1 import error + from pyasn1.type import tag + + +@@ -23,6 +24,19 @@ class TagReprTestCase(TagTestCaseBase): + def testRepr(self): + assert 'Tag' in repr(self.t1) + ++ def testReprHugeTagId(self): ++ # must not hit the interpreter's int-to-str conversion limit ++ hugeTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 100000) ++ assert 'Tag' in repr(hugeTag) ++ ++ def testNegativeHugeTagId(self): ++ try: ++ tag.Tag(tag.tagClassContext, tag.tagFormatSimple, -(1 << 100000)) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert 0, 'negative tag ID tolerated' ++ + + class TagCmpTestCase(TagTestCaseBase): + def testCmp(self): +@@ -54,6 +68,12 @@ class TagSetReprTestCase(TagSetTestCaseBase): + def testRepr(self): + assert 'TagSet' in repr(self.ts1) + ++ def testReprHugeTagId(self): ++ # must not hit the interpreter's int-to-str conversion limit ++ hugeTagSet = self.ts1.tagImplicitly( ++ tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 100000)) ++ assert 'TagSet' in repr(hugeTagSet) ++ + + class TagSetCmpTestCase(TagSetTestCaseBase): + def testCmp(self): +-- +2.34.1 + From patchwork Wed Sep 2 05:25:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96995 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7CBAEC624D3 for ; Wed, 2 Sep 2026 05:26:47 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5666.1788326802450467241 for ; Tue, 01 Sep 2026 22:26:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=J+9bEuUe; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49b0eab380eso5793995e9.0 for ; Tue, 01 Sep 2026 22:26:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326801; x=1788931601; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=o6791HY/cZXdUTiz14qxSulGq9/66HGHNGZUZNQf2JE=; b=J+9bEuUeCdkges9qwiWjE5ZINL9kBQmH/DBHcLMAFnFsD/uM38IseixDYtDE24Gqo8 c6WDjGYnh5CIAYXDvmVS3eRLSzSdtaTVnak+40K8vdn0jkU3E1FNz+u1EMtBxv+LSCC+ 0bIumtbliePdoybu40D+27Rdh94aEdTrb+Toc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326801; x=1788931601; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=o6791HY/cZXdUTiz14qxSulGq9/66HGHNGZUZNQf2JE=; b=PCCY78fiTrwYI4vQmc3KpX2f+hPWm+FrPLS3U3mMamGIr5Ih/xLXyDdq7ZLwvpvTF1 CgqwCovQMTPeAQxcrjk81AwsE0K9JSufkVzAh5bg4frlKmrpALIzHdELxsix9iAiL36Q 0zz73lrd2bq2BHClQtUdRuxVs6SB+xj1H7N+DN8pArP0z08jLcoMJOLSdZ2u5wwreLqE Xn8xgEcW6OTyPbRn9tXtMJzstqGN94F0OYj8nsFpG5NGriD5SDN0OlqY2HP7TfbnDtkQ /648SSIyU55h8iman5av7kudl9GhKeXLbKUzSvawx2OrVJx+rvQIHoWpW4GvqBGygRzV bSww== X-Gm-Message-State: AFuF++n8YDhop9wlVf2gpmxGj/8IH/5hU3jPcSnqpY6+lHYq0U6LVkfb pEL8Cl+itUHciaqgJepgK7XQmQahU2XFWhqOSOmOMxzqjhl+aSwDfnFm9J8yew+4DJ7xLmMRs0t p3KNJ58s= X-Gm-Gg: AR+sD13WH+4Q9i17Ndt3u65giE/RZejvgOMf43TprRukDav/kmMw48UDILqUKLnD0wT DzS1mamgEOajjYNk6wO3Hq/dc+0p3I5EbfoaKS+Z9kx+tTXM0eRkD2WdGt5uKkU2o1Ar/Bgh4cR B/2tZhSiAhyxlT7nxKY8fuTSc351tAccSl9j81/QviEgXd7DYPvHxvqHZNDinb15mp5GQNndJ2G TwTNTSNWKBJ2bzJle6oUS8ezWB2vNlhSvMLZkjUyrJ3pH8X0tDibQfqYddLNX4eP+CrSXcsA0zi PFls3NDXwOBMW3aaqcghki01AHE350NlGvHNPDBvyLUPqIWXBbBqdwFmWdQPt7fqwzTK8s0z/87 og/G+mPu/qH47TysRdu5hKN5VwxXFyl2DHiJbOMjn3HctKKYZ6zOgGvXRTLB4Xvr5uEIQLPcEVX d+gh6OPuVT81fFf6N1qqWU8h+iZ1E0m89jxQeoTgWJd7w05Fekh2xD2/AM/BksmocQVJWJlE6XT BTnCUyGmW8ON3x3QQ== X-Received: by 2002:a05:600c:8718:b0:49b:8f5e:51fb with SMTP id 5b1f17b1804b1-49ce7c03f46mr8588625e9.3.1788326800202; Tue, 01 Sep 2026 22:26:40 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14 Date: Wed, 2 Sep 2026 07:25:23 +0200 Message-ID: <57549d561886972b733952a4e4077cd8889d12ed.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244857 From: Peter Marko This is a security release of Python 3.12 Release information: [1] * drop CVE patches included in this release * refresh all remaining patches via devtool * remove some tab style in SRC_URI. * add CVE_STATUS entries for CVEs fixed in this release but still reported as Unpatched by cve-check (including 2 fixed already in previous release) [1] https://www.python.org/downloads/release/python-31214/ Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...shebang-overflow-on-python-config.py.patch | 2 +- ...-qemu-wrapper-when-gathering-profile.patch | 2 +- ...e-treat-overflow-in-UID-GID-as-failu.patch | 2 +- .../python/python3/CVE-2025-13462.patch | 142 ---------------- .../python/python3/CVE-2026-11940.patch | 66 -------- .../python/python3/CVE-2026-11972.patch | 60 ------- .../python/python3/CVE-2026-1502.patch | 113 ------------- .../python3/CVE-2026-3644_CVE-2026-0672.patch | 154 ----------------- .../python/python3/CVE-2026-4224.patch | 121 ------------- .../python3/CVE-2026-4519_CVE-2026-4786.patch | 66 -------- .../python/python3/CVE-2026-4519_p1.patch | 107 ------------ .../python/python3/CVE-2026-4519_p2.patch | 159 ------------------ .../python/python3/CVE-2026-6100.patch | 75 --------- .../python/python3/CVE-2026-7210.patch | 148 ---------------- .../python/python3/CVE-2026-9669.patch | 96 ----------- .../python/python3/makerace.patch | 2 +- ...{python3_3.12.13.bb => python3_3.12.14.bb} | 24 +-- 17 files changed, 13 insertions(+), 1326 deletions(-) delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%) diff --git a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch index a8f98d873e8..6c8b1bf6cd9 100644 --- a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch +++ b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch @@ -19,7 +19,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in index 2d235d2..1ac2263 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2356,6 +2356,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh +@@ -2361,6 +2361,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh @ # Substitution happens here, as the completely-expanded BINDIR @ # is not available in configure sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py diff --git a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch index b78f6199580..6066b26e38f 100644 --- a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch +++ b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch @@ -13,7 +13,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in index 083f4c7..dce36a5 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -660,8 +660,7 @@ profile-run-stamp: +@@ -663,8 +663,7 @@ profile-run-stamp: # enabled. $(MAKE) profile-gen-stamp # Next, run the profile task to generate the profile information. diff --git a/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch b/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch index 98b3aa42d21..5fdf5f4514e 100644 --- a/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch +++ b/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch @@ -16,7 +16,7 @@ diff --git a/Lib/tarfile.py b/Lib/tarfile.py index 0a0f31e..4dfb67d 100755 --- a/Lib/tarfile.py +++ b/Lib/tarfile.py -@@ -2688,7 +2688,8 @@ class TarFile(object): +@@ -2721,7 +2721,8 @@ class TarFile(object): os.lchown(targetpath, u, g) else: os.chown(targetpath, u, g) diff --git a/meta/recipes-devtools/python/python3/CVE-2025-13462.patch b/meta/recipes-devtools/python/python3/CVE-2025-13462.patch deleted file mode 100644 index 36d492338ba..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2025-13462.patch +++ /dev/null @@ -1,142 +0,0 @@ -From 14d7d2e8f51a17c23c98f13f33743253a0b7a18a Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Mon, 18 May 2026 19:43:51 +0200 -Subject: [PATCH] [3.12] gh-141707: Skip TarInfo DIRTYPE normalization during - GNU long name handling (#145817) - -gh-141707: Skip TarInfo DIRTYPE normalization during GNU long name handling - -CVE: CVE-2025-13462 -Upstream-Status: Backport [https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084] - -Backport Changes: -- This file is not present in the current version and is therefore omitted - Misc/NEWS.d/next/Library/2025-11-18-06-35-53.gh-issue-141707.DBmQIy.rst - -(cherry picked from commit 42d754e34c06e57ad6b8e7f92f32af679912d8ab) - -Co-authored-by: Seth Michael Larson -Co-authored-by: Eashwar Ranganathan -(cherry picked from commit d10950739a78f54d0718d88fb5a868374603c084) -Signed-off-by: Sudhir Dumbhare ---- - Lib/tarfile.py | 29 +++++++++++++++++++++++++---- - Lib/test/test_tarfile.py | 19 +++++++++++++++++++ - Misc/ACKS | 1 + - 3 files changed, 45 insertions(+), 4 deletions(-) - -diff --git a/Lib/tarfile.py b/Lib/tarfile.py -index 99451aa765..70fdbe85b0 100755 ---- a/Lib/tarfile.py -+++ b/Lib/tarfile.py -@@ -1246,6 +1246,20 @@ class TarInfo(object): - @classmethod - def frombuf(cls, buf, encoding, errors): - """Construct a TarInfo object from a 512 byte bytes object. -+ -+ To support the old v7 tar format AREGTYPE headers are -+ transformed to DIRTYPE headers if their name ends in '/'. -+ """ -+ return cls._frombuf(buf, encoding, errors) -+ -+ @classmethod -+ def _frombuf(cls, buf, encoding, errors, *, dircheck=True): -+ """Construct a TarInfo object from a 512 byte bytes object. -+ -+ If ``dircheck`` is set to ``True`` then ``AREGTYPE`` headers will -+ be normalized to ``DIRTYPE`` if the name ends in a trailing slash. -+ ``dircheck`` must be set to ``False`` if this function is called -+ on a follow-up header such as ``GNUTYPE_LONGNAME``. - """ - if len(buf) == 0: - raise EmptyHeaderError("empty header") -@@ -1276,7 +1290,7 @@ class TarInfo(object): - - # Old V7 tar format represents a directory as a regular - # file with a trailing slash. -- if obj.type == AREGTYPE and obj.name.endswith("/"): -+ if dircheck and obj.type == AREGTYPE and obj.name.endswith("/"): - obj.type = DIRTYPE - - # The old GNU sparse format occupies some of the unused -@@ -1311,8 +1325,15 @@ class TarInfo(object): - """Return the next TarInfo object from TarFile object - tarfile. - """ -+ return cls._fromtarfile(tarfile) -+ -+ @classmethod -+ def _fromtarfile(cls, tarfile, *, dircheck=True): -+ """ -+ See dircheck documentation in _frombuf(). -+ """ - buf = tarfile.fileobj.read(BLOCKSIZE) -- obj = cls.frombuf(buf, tarfile.encoding, tarfile.errors) -+ obj = cls._frombuf(buf, tarfile.encoding, tarfile.errors, dircheck=dircheck) - obj.offset = tarfile.fileobj.tell() - BLOCKSIZE - return obj._proc_member(tarfile) - -@@ -1370,7 +1391,7 @@ class TarInfo(object): - - # Fetch the next header and process it. - try: -- next = self.fromtarfile(tarfile) -+ next = self._fromtarfile(tarfile, dircheck=False) - except HeaderError as e: - raise SubsequentHeaderError(str(e)) from None - -@@ -1505,7 +1526,7 @@ class TarInfo(object): - - # Fetch the next header. - try: -- next = self.fromtarfile(tarfile) -+ next = self._fromtarfile(tarfile, dircheck=False) - except HeaderError as e: - raise SubsequentHeaderError(str(e)) from None - -diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py -index 759fa03ead..82637841ed 100644 ---- a/Lib/test/test_tarfile.py -+++ b/Lib/test/test_tarfile.py -@@ -1134,6 +1134,25 @@ class LongnameTest: - self.assertIsNotNone(tar.getmember(longdir)) - self.assertIsNotNone(tar.getmember(longdir.removesuffix('/'))) - -+ def test_longname_file_not_directory(self): -+ # Test reading a longname file and ensure it is not handled as a directory -+ # Issue #141707 -+ buf = io.BytesIO() -+ with tarfile.open(mode='w', fileobj=buf, format=self.format) as tar: -+ ti = tarfile.TarInfo() -+ ti.type = tarfile.AREGTYPE -+ ti.name = ('a' * 99) + '/' + ('b' * 3) -+ tar.addfile(ti) -+ -+ expected = {t.name: t.type for t in tar.getmembers()} -+ -+ buf.seek(0) -+ with tarfile.open(mode='r', fileobj=buf) as tar: -+ actual = {t.name: t.type for t in tar.getmembers()} -+ -+ self.assertEqual(expected, actual) -+ -+ - class GNUReadTest(LongnameTest, ReadTest, unittest.TestCase): - - subdir = "gnu" -diff --git a/Misc/ACKS b/Misc/ACKS -index a6e63a991f..30d5f99ebb 100644 ---- a/Misc/ACKS -+++ b/Misc/ACKS -@@ -1492,6 +1492,7 @@ Dhushyanth Ramasamy - Ashwin Ramaswami - Jeff Ramnani - Bayard Randel -+Eashwar Ranganathan - Varpu Rantala - Brodie Rao - Rémi Rampin --- -2.35.6 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch deleted file mode 100644 index 0851138ae89..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch +++ /dev/null @@ -1,66 +0,0 @@ -From 91a9bd79cdbab8f8518c4a5e669b3f19680a2f31 Mon Sep 17 00:00:00 2001 -From: Stan Ulbrych -Date: Tue, 23 Jun 2026 14:31:38 +0100 -Subject: [PATCH] gh-151558: Fix symlink escape via `tarfile` - hardlink-extraction fallback (GH-151559) - -CVE: CVE-2026-11940 -Upstream-Status: Backport [https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f] - -Signed-off-by: Benjamin Robin ---- - Lib/tarfile.py | 3 +++ - Lib/test/test_tarfile.py | 24 ++++++++++++++++++++++++ - 2 files changed, 27 insertions(+) - -diff --git a/Lib/tarfile.py b/Lib/tarfile.py -index 59d3f6e5cce1..83226e907e4b 100755 ---- a/Lib/tarfile.py -+++ b/Lib/tarfile.py -@@ -2650,6 +2650,9 @@ def makelink_with_filter(self, tarinfo, targetpath, - "makelink_with_filter: if filter_function is not None, " - + "extraction_root must also not be None") - try: -+ filter_function( -+ unfiltered.replace(name=tarinfo.name, deep=False), -+ extraction_root) - filtered = filter_function(unfiltered, extraction_root) - except _FILTER_ERRORS as cause: - raise LinkFallbackError(tarinfo, unfiltered.name) from cause -diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py -index 759fa03ead70..29719d95b6c1 100644 ---- a/Lib/test/test_tarfile.py -+++ b/Lib/test/test_tarfile.py -@@ -4080,6 +4080,30 @@ def test_sneaky_hardlink_fallback(self): - self.expect_file("boom", symlink_to='../../link_here') - self.expect_file("c", symlink_to='b') - -+ @symlink_test -+ def test_sneaky_hardlink_fallback_deep(self): -+ # (CVE-2026-11940) -+ with ArchiveMaker() as arc: -+ arc.add("a/b/s", symlink_to=os.path.join("..", "escape")) -+ arc.add("s", hardlink_to=os.path.join("a", "b", "s")) -+ -+ with self.check_context(arc.open(), 'data'): -+ e = self.expect_exception( -+ tarfile.LinkFallbackError, -+ "link 's' would be extracted as a copy of " -+ + "'a/b/s', which was rejected") -+ self.assertIsInstance(e.__cause__, -+ tarfile.LinkOutsideDestinationError) -+ -+ for filter in 'tar', 'fully_trusted': -+ with self.subTest(filter), self.check_context(arc.open(), filter): -+ if not os_helper.can_symlink(): -+ self.expect_file("a/") -+ self.expect_file("a/b/") -+ else: -+ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape')) -+ self.expect_file("s", symlink_to=os.path.join('..', 'escape')) -+ - @symlink_test - def test_exfiltration_via_symlink(self): - # (CVE-2025-4138) --- -2.54.0 diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch deleted file mode 100644 index 36334f247e6..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch +++ /dev/null @@ -1,60 +0,0 @@ -From a83ebdb495a9cbd28a03675acdeda235fade90b3 Mon Sep 17 00:00:00 2001 -From: Petr Viktorin -Date: Tue, 23 Jun 2026 15:13:30 +0200 -Subject: [PATCH] gh-151981: Make tarfile._Stream.seek break at EOF (GH-151982) - -Co-authored-by: Stan Ulbrych - -CVE: CVE-2026-11972 -Upstream-Status: Backport [https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896] - -Signed-off-by: Benjamin Robin ---- - Lib/tarfile.py | 4 +++- - Lib/test/test_tarfile.py | 16 ++++++++++++++++ - 2 files changed, 19 insertions(+), 1 deletion(-) - -diff --git a/Lib/tarfile.py b/Lib/tarfile.py -index 83226e907e4b..c0007a78f700 100755 ---- a/Lib/tarfile.py -+++ b/Lib/tarfile.py -@@ -516,7 +516,9 @@ def seek(self, pos=0): - if pos - self.pos >= 0: - blocks, remainder = divmod(pos - self.pos, self.bufsize) - for i in range(blocks): -- self.read(self.bufsize) -+ data = self.read(self.bufsize) -+ if not data: -+ break - self.read(remainder) - else: - raise StreamError("seeking backwards is not allowed") -diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py -index 29719d95b6c1..8aeb2e1b1b9a 100644 ---- a/Lib/test/test_tarfile.py -+++ b/Lib/test/test_tarfile.py -@@ -4480,6 +4480,22 @@ def valueerror_filter(tarinfo, path): - with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter): - self.expect_exception(TypeError) # errorlevel is not int - -+ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT]) -+ def test_getmembers_big_size(self, format): -+ # gh-151981: A loop in seek() for streaming files tried to read the -+ # declared number of blocks even at EOF -+ tinfo = tarfile.TarInfo("huge-file") -+ tinfo.size = 1 << 64 -+ bio = io.BytesIO() -+ # Write header without data -+ bio.write(tinfo.tobuf(format)) -+ -+ # Reset & try to get contents -+ bio.seek(0) -+ with tarfile.open(fileobj=bio, mode="r|") as tar: -+ with self.assertRaises(tarfile.ReadError): -+ tar.getmembers() -+ - - class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase): - testdir = os.path.join(TEMPDIR, "testoverwrite") --- -2.54.0 diff --git a/meta/recipes-devtools/python/python3/CVE-2026-1502.patch b/meta/recipes-devtools/python/python3/CVE-2026-1502.patch deleted file mode 100644 index be6a8379a85..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-1502.patch +++ /dev/null @@ -1,113 +0,0 @@ -From 05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69 Mon Sep 17 00:00:00 2001 -From: Seth Larson -Date: Fri, 10 Apr 2026 10:21:42 -0500 -Subject: [PATCH] gh-146211: Reject CR/LF in HTTP tunnel request headers - (#146212) - -Co-authored-by: Illia Volochii - -CVE: CVE-2026-1502 -Upstream-Status: Backport [https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69] -Signed-off-by: Hitendra Prajapati ---- - Lib/http/client.py | 11 ++++- - Lib/test/test_httplib.py | 45 +++++++++++++++++++ - ...-03-20-09-29-42.gh-issue-146211.PQVbs7.rst | 2 + - 3 files changed, 57 insertions(+), 1 deletion(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst - -diff --git a/Lib/http/client.py b/Lib/http/client.py -index 70451d6..7db4807 100644 ---- a/Lib/http/client.py -+++ b/Lib/http/client.py -@@ -972,13 +972,22 @@ class HTTPConnection: - return ip - - def _tunnel(self): -+ if _contains_disallowed_url_pchar_re.search(self._tunnel_host): -+ raise ValueError('Tunnel host can\'t contain control characters %r' -+ % (self._tunnel_host,)) - connect = b"CONNECT %s:%d %s\r\n" % ( - self._wrap_ipv6(self._tunnel_host.encode("idna")), - self._tunnel_port, - self._http_vsn_str.encode("ascii")) - headers = [connect] - for header, value in self._tunnel_headers.items(): -- headers.append(f"{header}: {value}\r\n".encode("latin-1")) -+ header_bytes = header.encode("latin-1") -+ value_bytes = value.encode("latin-1") -+ if not _is_legal_header_name(header_bytes): -+ raise ValueError('Invalid header name %r' % (header_bytes,)) -+ if _is_illegal_header_value(value_bytes): -+ raise ValueError('Invalid header value %r' % (value_bytes,)) -+ headers.append(b"%s: %s\r\n" % (header_bytes, value_bytes)) - headers.append(b"\r\n") - # Making a single send() call instead of one per line encourages - # the host OS to use a more optimal packet size instead of -diff --git a/Lib/test/test_httplib.py b/Lib/test/test_httplib.py -index e46dac0..e027d93 100644 ---- a/Lib/test/test_httplib.py -+++ b/Lib/test/test_httplib.py -@@ -369,6 +369,51 @@ class HeaderTests(TestCase): - with self.assertRaisesRegex(ValueError, 'Invalid header'): - conn.putheader(name, value) - -+ def test_invalid_tunnel_headers(self): -+ cases = ( -+ ('Invalid\r\nName', 'ValidValue'), -+ ('Invalid\rName', 'ValidValue'), -+ ('Invalid\nName', 'ValidValue'), -+ ('\r\nInvalidName', 'ValidValue'), -+ ('\rInvalidName', 'ValidValue'), -+ ('\nInvalidName', 'ValidValue'), -+ (' InvalidName', 'ValidValue'), -+ ('\tInvalidName', 'ValidValue'), -+ ('Invalid:Name', 'ValidValue'), -+ (':InvalidName', 'ValidValue'), -+ ('ValidName', 'Invalid\r\nValue'), -+ ('ValidName', 'Invalid\rValue'), -+ ('ValidName', 'Invalid\nValue'), -+ ('ValidName', 'InvalidValue\r\n'), -+ ('ValidName', 'InvalidValue\r'), -+ ('ValidName', 'InvalidValue\n'), -+ ) -+ for name, value in cases: -+ with self.subTest((name, value)): -+ conn = client.HTTPConnection('example.com') -+ conn.set_tunnel('tunnel', headers={ -+ name: value -+ }) -+ conn.sock = FakeSocket('') -+ with self.assertRaisesRegex(ValueError, 'Invalid header'): -+ conn._tunnel() # Called in .connect() -+ -+ def test_invalid_tunnel_host(self): -+ cases = ( -+ 'invalid\r.host', -+ '\ninvalid.host', -+ 'invalid.host\r\n', -+ 'invalid.host\x00', -+ 'invalid host', -+ ) -+ for tunnel_host in cases: -+ with self.subTest(tunnel_host): -+ conn = client.HTTPConnection('example.com') -+ conn.set_tunnel(tunnel_host) -+ conn.sock = FakeSocket('') -+ with self.assertRaisesRegex(ValueError, 'Tunnel host can\'t contain control characters'): -+ conn._tunnel() # Called in .connect() -+ - def test_headers_debuglevel(self): - body = ( - b'HTTP/1.1 200 OK\r\n' -diff --git a/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst -new file mode 100644 -index 0000000..4993633 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst -@@ -0,0 +1,2 @@ -+Reject CR/LF characters in tunnel request headers for the -+HTTPConnection.set_tunnel() method. --- -2.50.1 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch b/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch deleted file mode 100644 index 42d8133a183..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch +++ /dev/null @@ -1,154 +0,0 @@ -From 6e291d2eba0b6820bc924e68f1db750328bf6c75 Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Mon, 16 Mar 2026 15:05:13 +0100 -Subject: [PATCH] [3.13] gh-145599, CVE 2026-3644: Reject control - characters in `http.cookies.Morsel.update()` (GH-145600) (#146024) - -gh-145599, CVE 2026-3644: Reject control characters in `http.cookies.Morsel.update()` (GH-145600) - -Reject control characters in `http.cookies.Morsel.update()` and `http.cookies.BaseCookie.js_output`. - -CVE: CVE-2026-3644 CVE-2026-0672 -Upstream-Status: Backport [https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd] - -Backport Changes: -- This file is not present in the current version and is therefore omitted - Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst - -(cherry picked from commit 57e88c1cf95e1481b94ae57abe1010469d47a6b4) - -Co-authored-by: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com> -Co-authored-by: Victor Stinner -Co-authored-by: Victor Stinner -(cherry picked from commit d16ecc6c3626f0e2cc8f08c309c83934e8a979dd) -Signed-off-by: Sudhir Dumbhare ---- - Lib/http/cookies.py | 24 ++++++++++++++++++---- - Lib/test/test_http_cookies.py | 38 +++++++++++++++++++++++++++++++++++ - 2 files changed, 58 insertions(+), 4 deletions(-) - -diff --git a/Lib/http/cookies.py b/Lib/http/cookies.py -index d0a69cbe191..63d119ad46c 100644 ---- a/Lib/http/cookies.py -+++ b/Lib/http/cookies.py -@@ -335,9 +335,16 @@ class Morsel(dict): - key = key.lower() - if key not in self._reserved: - raise CookieError("Invalid attribute %r" % (key,)) -+ if _has_control_character(key, val): -+ raise CookieError("Control characters are not allowed in " -+ f"cookies {key!r} {val!r}") - data[key] = val - dict.update(self, data) - -+ def __ior__(self, values): -+ self.update(values) -+ return self -+ - def isReservedKey(self, K): - return K.lower() in self._reserved - -@@ -363,9 +370,15 @@ class Morsel(dict): - } - - def __setstate__(self, state): -- self._key = state['key'] -- self._value = state['value'] -- self._coded_value = state['coded_value'] -+ key = state['key'] -+ value = state['value'] -+ coded_value = state['coded_value'] -+ if _has_control_character(key, value, coded_value): -+ raise CookieError("Control characters are not allowed in cookies " -+ f"{key!r} {value!r} {coded_value!r}") -+ self._key = key -+ self._value = value -+ self._coded_value = coded_value - - def output(self, attrs=None, header="Set-Cookie:"): - return "%s %s" % (header, self.OutputString(attrs)) -@@ -377,13 +390,16 @@ class Morsel(dict): - - def js_output(self, attrs=None): - # Print javascript -+ output_string = self.OutputString(attrs) -+ if _has_control_character(output_string): -+ raise CookieError("Control characters are not allowed in cookies") - return """ - -- """ % (self.OutputString(attrs).replace('"', r'\"')) -+ """ % (output_string.replace('"', r'\"')) - - def OutputString(self, attrs=None): - # Build up our result -diff --git a/Lib/test/test_http_cookies.py b/Lib/test/test_http_cookies.py -index f196bcc48e3..2478a6c630f 100644 ---- a/Lib/test/test_http_cookies.py -+++ b/Lib/test/test_http_cookies.py -@@ -573,6 +573,14 @@ class MorselTests(unittest.TestCase): - with self.assertRaises(cookies.CookieError): - morsel["path"] = c0 - -+ # .__setstate__() -+ with self.assertRaises(cookies.CookieError): -+ morsel.__setstate__({'key': c0, 'value': 'val', 'coded_value': 'coded'}) -+ with self.assertRaises(cookies.CookieError): -+ morsel.__setstate__({'key': 'key', 'value': c0, 'coded_value': 'coded'}) -+ with self.assertRaises(cookies.CookieError): -+ morsel.__setstate__({'key': 'key', 'value': 'val', 'coded_value': c0}) -+ - # .setdefault() - with self.assertRaises(cookies.CookieError): - morsel.setdefault("path", c0) -@@ -587,6 +595,18 @@ class MorselTests(unittest.TestCase): - with self.assertRaises(cookies.CookieError): - morsel.set("path", "val", c0) - -+ # .update() -+ with self.assertRaises(cookies.CookieError): -+ morsel.update({"path": c0}) -+ with self.assertRaises(cookies.CookieError): -+ morsel.update({c0: "val"}) -+ -+ # .__ior__() -+ with self.assertRaises(cookies.CookieError): -+ morsel |= {"path": c0} -+ with self.assertRaises(cookies.CookieError): -+ morsel |= {c0: "val"} -+ - def test_control_characters_output(self): - # Tests that even if the internals of Morsel are modified - # that a call to .output() has control character safeguards. -@@ -607,6 +627,24 @@ class MorselTests(unittest.TestCase): - with self.assertRaises(cookies.CookieError): - cookie.output() - -+ # Tests that .js_output() also has control character safeguards. -+ for c0 in support.control_characters_c0(): -+ morsel = cookies.Morsel() -+ morsel.set("key", "value", "coded-value") -+ morsel._key = c0 # Override private variable. -+ cookie = cookies.SimpleCookie() -+ cookie["cookie"] = morsel -+ with self.assertRaises(cookies.CookieError): -+ cookie.js_output() -+ -+ morsel = cookies.Morsel() -+ morsel.set("key", "value", "coded-value") -+ morsel._coded_value = c0 # Override private variable. -+ cookie = cookies.SimpleCookie() -+ cookie["cookie"] = morsel -+ with self.assertRaises(cookies.CookieError): -+ cookie.js_output() -+ - - def load_tests(loader, tests, pattern): - tests.addTest(doctest.DocTestSuite(cookies)) --- -2.35.6 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4224.patch b/meta/recipes-devtools/python/python3/CVE-2026-4224.patch deleted file mode 100644 index 09dd2dda003..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-4224.patch +++ /dev/null @@ -1,121 +0,0 @@ -From ca301e24e20d1d9d58bbd432ff103cab2cb87128 Mon Sep 17 00:00:00 2001 -From: Stan Ulbrych -Date: Wed, 8 Apr 2026 11:27:39 +0100 -Subject: [PATCH] gh-145986: Avoid unbound C recursion in `conv_content_model` - in `pyexpat.c` (CVE-2026-4224) (GH-145987) (#146000) -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -* [3.11] gh-145986: Avoid unbound C recursion in `conv_content_model` in `pyexpat.c` (CVE-2026-4224) (GH-145987) - -Fix C stack overflow (CVE-2026-4224) when an Expat parser -with a registered `ElementDeclHandler` parses inline DTD -containing deeply nested content model. - ---------- -(cherry picked from commit eb0e8be3a7e11b87d198a2c3af1ed0eccf532768) -(cherry picked from commit e5caf45faac74b0ed869e3336420cffd3510ce6e) - -Co-authored-by: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com> -Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com> - -* Update Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst - ---------- - -Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com> - -CVE: CVE-2026-4224 -Upstream-Status: Backport [https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785] - -Signed-off-by: Amaury Couderc ---- - Lib/test/test_pyexpat.py | 18 ++++++++++++++++++ - ...6-03-14-17-31-39.gh-issue-145986.ifSSr8.rst | 4 ++++ - Modules/pyexpat.c | 9 ++++++++- - 3 files changed, 30 insertions(+), 1 deletion(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst - -diff --git a/Lib/test/test_pyexpat.py b/Lib/test/test_pyexpat.py -index 38f951573f0..37d9086f40a 100644 ---- a/Lib/test/test_pyexpat.py -+++ b/Lib/test/test_pyexpat.py -@@ -675,6 +675,24 @@ class ChardataBufferTest(unittest.TestCase): - parser.Parse(xml2, True) - self.assertEqual(self.n, 4) - -+class ElementDeclHandlerTest(unittest.TestCase): -+ def test_deeply_nested_content_model(self): -+ # This should raise a RecursionError and not crash. -+ # See https://github.com/python/cpython/issues/145986. -+ N = 500_000 -+ data = ( -+ b'\n]>\n\n' -+ ) -+ -+ parser = expat.ParserCreate() -+ parser.ElementDeclHandler = lambda _1, _2: None -+ with support.infinite_recursion(): -+ with self.assertRaises(RecursionError): -+ parser.Parse(data) -+ -+ - class MalformedInputTest(unittest.TestCase): - def test1(self): - xml = b"\0\r\n" -diff --git a/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst -new file mode 100644 -index 00000000000..cb9dbadb72d ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst -@@ -0,0 +1,4 @@ -+:mod:`xml.parsers.expat`: Fixed a crash caused by unbounded C recursion when -+converting deeply nested XML content models with -+:meth:`~xml.parsers.expat.xmlparser.ElementDeclHandler`. -+This addresses `CVE-2026-4224 `_. -diff --git a/Modules/pyexpat.c b/Modules/pyexpat.c -index 79492ca5c4f..8673540f358 100644 ---- a/Modules/pyexpat.c -+++ b/Modules/pyexpat.c -@@ -3,6 +3,7 @@ - #endif - - #include "Python.h" -+#include "pycore_ceval.h" // _Py_EnterRecursiveCall() - #include "pycore_runtime.h" // _Py_ID() - #include - -@@ -578,6 +579,10 @@ static PyObject * - conv_content_model(XML_Content * const model, - PyObject *(*conv_string)(const XML_Char *)) - { -+ if (_Py_EnterRecursiveCall(" in conv_content_model")) { -+ return NULL; -+ } -+ - PyObject *result = NULL; - PyObject *children = PyTuple_New(model->numchildren); - int i; -@@ -589,7 +594,7 @@ conv_content_model(XML_Content * const model, - conv_string); - if (child == NULL) { - Py_XDECREF(children); -- return NULL; -+ goto done; - } - PyTuple_SET_ITEM(children, i, child); - } -@@ -597,6 +602,8 @@ conv_content_model(XML_Content * const model, - model->type, model->quant, - conv_string,model->name, children); - } -+done: -+ _Py_LeaveRecursiveCall(); - return result; - } - --- -2.34.1 diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch deleted file mode 100644 index 6a4714f25ae..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch +++ /dev/null @@ -1,66 +0,0 @@ -From b9af29b9f2f880cdcdc49a1460743680f59dcb4e Mon Sep 17 00:00:00 2001 -From: Stan Ulbrych -Date: Mon, 13 Apr 2026 22:41:51 +0100 -Subject: [PATCH] [3.11] gh-148169: Fix webbrowser `%action` substitution - bypass of dash-prefix check (GH-148170) (#148520) - -CVE: CVE-2026-4519 CVE-2026-4786 -Upstream-Status: Backport [https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769] - -Backport Changes: -- This file is not present in the current version and is therefore omitted. - Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst - -(cherry picked from commit d22922c8a7958353689dc4763dd72da2dea03fff) -(cherry picked from commit f4654824ae0850ac87227fb270f9057477946769) -Signed-off-by: Sudhir Dumbhare ---- - Lib/test/test_webbrowser.py | 8 ++++++++ - Lib/webbrowser.py | 5 +++-- - 2 files changed, 11 insertions(+), 2 deletions(-) - -diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py -index c9bf525360d..1d21f133725 100644 ---- a/Lib/test/test_webbrowser.py -+++ b/Lib/test/test_webbrowser.py -@@ -103,6 +103,14 @@ class ChromeCommandTest(CommandTestMixin, unittest.TestCase): - options=[], - arguments=[URL]) - -+ def test_reject_action_dash_prefixes(self): -+ browser = self.browser_class(name=CMD_NAME) -+ with self.assertRaises(ValueError): -+ browser.open('%action--incognito') -+ # new=1: action is "--new-window", so "%action" itself expands to -+ # a dash-prefixed flag even with no dash in the original URL. -+ with self.assertRaises(ValueError): -+ browser.open('%action', new=1) - - class EdgeCommandTest(CommandTestMixin, unittest.TestCase): - -diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py -index 000e89275b7..97c4eec9080 100755 ---- a/Lib/webbrowser.py -+++ b/Lib/webbrowser.py -@@ -268,7 +268,6 @@ class UnixBrowser(BaseBrowser): - - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -- self._check_url(url) - if new == 0: - action = self.remote_action - elif new == 1: -@@ -282,7 +281,9 @@ class UnixBrowser(BaseBrowser): - raise Error("Bad 'new' parameter to open(); " + - "expected 0, 1, or 2, got %s" % new) - -- args = [arg.replace("%s", url).replace("%action", action) -+ self._check_url(url.replace("%action", action)) -+ -+ args = [arg.replace("%action", action).replace("%s", url) - for arg in self.remote_args] - args = [arg for arg in args if arg] - success = self._invoke(args, True, autoraise, url) --- -2.35.6 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch deleted file mode 100644 index 1514d2c5414..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch +++ /dev/null @@ -1,107 +0,0 @@ -From 7df48dd3c6330611a04d85a5159c0ea424dc1e62 Mon Sep 17 00:00:00 2001 -From: Pinky -Date: Wed, 25 Mar 2026 01:02:37 +0530 -Subject: [PATCH] [3.12] gh-143930: Reject leading dashes in webbrowser - URLs (GH-146360) - -CVE: CVE-2026-4519 -Upstream-Status: Backport [https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48] - -Backport Changes: -- This file is not present in the current version and is therefore omitted - Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst - -(cherry picked from commit 82a24a4442312bdcfc4c799885e8b3e00990f02b) - -Co-authored-by: Seth Michael Larson -(cherry picked from commit cbba6119391112aba9c5aebf7b94aea447922c48) -Signed-off-by: Sudhir Dumbhare ---- - Lib/test/test_webbrowser.py | 5 +++++ - Lib/webbrowser.py | 12 ++++++++++++ - 2 files changed, 17 insertions(+) - -diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py -index 2d695bc8831..60f094fd6a1 100644 ---- a/Lib/test/test_webbrowser.py -+++ b/Lib/test/test_webbrowser.py -@@ -59,6 +59,11 @@ class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase): - options=[], - arguments=[URL]) - -+ def test_reject_dash_prefixes(self): -+ browser = self.browser_class(name=CMD_NAME) -+ with self.assertRaises(ValueError): -+ browser.open(f"--key=val {URL}") -+ - - class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase): - -diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py -index 13b9e85f9e1..0bdb644d7db 100755 ---- a/Lib/webbrowser.py -+++ b/Lib/webbrowser.py -@@ -158,6 +158,12 @@ class BaseBrowser(object): - def open_new_tab(self, url): - return self.open(url, 2) - -+ @staticmethod -+ def _check_url(url): -+ """Ensures that the URL is safe to pass to subprocesses as a parameter""" -+ if url and url.lstrip().startswith("-"): -+ raise ValueError(f"Invalid URL: {url}") -+ - - class GenericBrowser(BaseBrowser): - """Class for all browsers started with a command -@@ -175,6 +181,7 @@ class GenericBrowser(BaseBrowser): - - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -+ self._check_url(url) - cmdline = [self.name] + [arg.replace("%s", url) - for arg in self.args] - try: -@@ -195,6 +202,7 @@ class BackgroundBrowser(GenericBrowser): - cmdline = [self.name] + [arg.replace("%s", url) - for arg in self.args] - sys.audit("webbrowser.open", url) -+ self._check_url(url) - try: - if sys.platform[:3] == 'win': - p = subprocess.Popen(cmdline) -@@ -260,6 +268,7 @@ class UnixBrowser(BaseBrowser): - - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -+ self._check_url(url) - if new == 0: - action = self.remote_action - elif new == 1: -@@ -350,6 +359,7 @@ class Konqueror(BaseBrowser): - - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -+ self._check_url(url) - # XXX Currently I know no way to prevent KFM from opening a new win. - if new == 2: - action = "newTab" -@@ -554,6 +564,7 @@ if sys.platform[:3] == "win": - class WindowsDefault(BaseBrowser): - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -+ self._check_url(url) - try: - os.startfile(url) - except OSError: -@@ -638,6 +649,7 @@ if sys.platform == 'darwin': - - def open(self, url, new=0, autoraise=True): - sys.audit("webbrowser.open", url) -+ self._check_url(url) - if self.name == 'default': - script = 'open location "%s"' % url.replace('"', '%22') # opens in default browser - else: --- -2.35.6 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch deleted file mode 100644 index 7ee145e5e80..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch +++ /dev/null @@ -1,159 +0,0 @@ -From 3ca64ff1722d2410a4e50e760de70f6279fa99fa Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Sat, 4 Apr 2026 00:53:49 +0200 -Subject: [PATCH] [3.11] gh-143930: Tweak the exception message and - increase test coverage (GH-146476) (GH-148045) (GH-148051) (GH-148052) -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -CVE: CVE-2026-4519 -Upstream-Status: Backport [https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c] - -Backport Changes: -- This file is not present in the current version and is therefore omitted. - Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst -- The file introduced in v3.12 by this commit; - https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48 - -(cherry picked from commit cc023511238ad93ecc8796157c6f9139a2bb2932) -(cherry picked from commit 89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4) -(cherry picked from commit 3681d47a440865aead912a054d4599087b4270dd) - -Co-authored-by: Łukasz Langa -(cherry picked from commit 96fc5048605863c7b6fd6289643feb0e97edd96c) -Signed-off-by: Sudhir Dumbhare ---- - Lib/test/test_webbrowser.py | 81 ++++++++++++++++++++++++++++++++++--- - Lib/webbrowser.py | 2 +- - 2 files changed, 76 insertions(+), 7 deletions(-) - -diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py -index 60f094fd6a1..c9bf525360d 100644 ---- a/Lib/test/test_webbrowser.py -+++ b/Lib/test/test_webbrowser.py -@@ -1,6 +1,7 @@ -+import io -+import os - import webbrowser - import unittest --import os - import sys - import subprocess - from unittest import mock -@@ -49,6 +50,14 @@ class CommandTestMixin: - popen_args.pop(popen_args.index(option)) - self.assertEqual(popen_args, arguments) - -+ def test_reject_dash_prefixes(self): -+ browser = self.browser_class(name=CMD_NAME) -+ with self.assertRaisesRegex( -+ ValueError, -+ r"^Invalid URL \(leading dash disallowed\): '--key=val http.*'$" -+ ): -+ browser.open(f"--key=val {URL}") -+ - - class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase): - -@@ -59,11 +68,6 @@ class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase): - options=[], - arguments=[URL]) - -- def test_reject_dash_prefixes(self): -- browser = self.browser_class(name=CMD_NAME) -- with self.assertRaises(ValueError): -- browser.open(f"--key=val {URL}") -- - - class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase): - -@@ -224,6 +228,71 @@ class ELinksCommandTest(CommandTestMixin, unittest.TestCase): - arguments=['openURL({},new-tab)'.format(URL)]) - - -+class MockPopenPipe: -+ def __init__(self, cmd, mode): -+ self.cmd = cmd -+ self.mode = mode -+ self.pipe = io.StringIO() -+ self._closed = False -+ -+ def write(self, buf): -+ self.pipe.write(buf) -+ -+ def close(self): -+ self._closed = True -+ return None -+ -+ -+@unittest.skipUnless(sys.platform == "darwin", "macOS specific test") -+class MacOSXOSAScriptTest(unittest.TestCase): -+ def setUp(self): -+ # Ensure that 'BROWSER' is not set to 'open' or something else. -+ # See: https://github.com/python/cpython/issues/131254. -+ env = self.enterContext(os_helper.EnvironmentVarGuard()) -+ env.unset("BROWSER") -+ -+ support.patch(self, os, "popen", self.mock_popen) -+ self.browser = webbrowser.MacOSXOSAScript("default") -+ -+ def mock_popen(self, cmd, mode): -+ self.popen_pipe = MockPopenPipe(cmd, mode) -+ return self.popen_pipe -+ -+ def test_default(self): -+ browser = webbrowser.get() -+ assert isinstance(browser, webbrowser.MacOSXOSAScript) -+ self.assertEqual(browser.name, "default") -+ -+ def test_default_open(self): -+ url = "https://python.org" -+ self.browser.open(url) -+ self.assertTrue(self.popen_pipe._closed) -+ self.assertEqual(self.popen_pipe.cmd, "osascript") -+ script = self.popen_pipe.pipe.getvalue() -+ self.assertEqual(script.strip(), f'open location "{url}"') -+ -+ def test_url_quote(self): -+ self.browser.open('https://python.org/"quote"') -+ script = self.popen_pipe.pipe.getvalue() -+ self.assertEqual( -+ script.strip(), 'open location "https://python.org/%22quote%22"' -+ ) -+ -+ def test_explicit_browser(self): -+ browser = webbrowser.MacOSXOSAScript("safari") -+ browser.open("https://python.org") -+ script = self.popen_pipe.pipe.getvalue() -+ self.assertIn('tell application "safari"', script) -+ self.assertIn('open location "https://python.org"', script) -+ -+ def test_reject_dash_prefixes(self): -+ with self.assertRaisesRegex( -+ ValueError, -+ r"^Invalid URL \(leading dash disallowed\): '--key=val http.*'$" -+ ): -+ self.browser.open(f"--key=val {URL}") -+ -+ - class BrowserRegistrationTest(unittest.TestCase): - - def setUp(self): -diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py -index 0bdb644d7db..000e89275b7 100755 ---- a/Lib/webbrowser.py -+++ b/Lib/webbrowser.py -@@ -162,7 +162,7 @@ class BaseBrowser(object): - def _check_url(url): - """Ensures that the URL is safe to pass to subprocesses as a parameter""" - if url and url.lstrip().startswith("-"): -- raise ValueError(f"Invalid URL: {url}") -+ raise ValueError(f"Invalid URL (leading dash disallowed): {url!r}") - - - class GenericBrowser(BaseBrowser): --- -2.35.6 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-6100.patch b/meta/recipes-devtools/python/python3/CVE-2026-6100.patch deleted file mode 100644 index 9084101434b..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-6100.patch +++ /dev/null @@ -1,75 +0,0 @@ -From c3cf71c3366fe49acb776a639405c0eea6169c20 Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Mon, 13 Apr 2026 03:35:24 +0200 -Subject: [PATCH] [3.13] gh-148395: Fix a possible UAF in - `{LZMA,BZ2,_Zlib}Decompressor` (GH-148396) (#148479) - -gh-148395: Fix a possible UAF in `{LZMA,BZ2,_Zlib}Decompressor` (GH-148396) - -Fix dangling input pointer after `MemoryError` in _lzma/_bz2/_ZlibDecompressor.decompress -(cherry picked from commit 8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2) - -Co-authored-by: Stan Ulbrych - -CVE: CVE-2026-6100 -Upstream-Status: Backport [https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20] -Signed-off-by: Hitendra Prajapati ---- - .../Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst | 5 +++++ - Modules/_bz2module.c | 1 + - Modules/_lzmamodule.c | 1 + - Modules/zlibmodule.c | 1 + - 4 files changed, 8 insertions(+) - create mode 100644 Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst - -diff --git a/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst -new file mode 100644 -index 0000000..9502189 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst -@@ -0,0 +1,5 @@ -+Fix a dangling input pointer in :class:`lzma.LZMADecompressor`, -+:class:`bz2.BZ2Decompressor`, and internal :class:`!zlib._ZlibDecompressor` -+when memory allocation fails with :exc:`MemoryError`, which could let a -+subsequent :meth:`!decompress` call read or write through a stale pointer to -+the already-released caller buffer. -diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c -index 97bd44b..a732e89 100644 ---- a/Modules/_bz2module.c -+++ b/Modules/_bz2module.c -@@ -587,6 +587,7 @@ decompress(BZ2Decompressor *d, char *data, size_t len, Py_ssize_t max_length) - return result; - - error: -+ bzs->next_in = NULL; - Py_XDECREF(result); - return NULL; - } -diff --git a/Modules/_lzmamodule.c b/Modules/_lzmamodule.c -index 7bbd656..103a6ef 100644 ---- a/Modules/_lzmamodule.c -+++ b/Modules/_lzmamodule.c -@@ -1114,6 +1114,7 @@ decompress(Decompressor *d, uint8_t *data, size_t len, Py_ssize_t max_length) - return result; - - error: -+ lzs->next_in = NULL; - Py_XDECREF(result); - return NULL; - } -diff --git a/Modules/zlibmodule.c b/Modules/zlibmodule.c -index f94c57e..9759593 100644 ---- a/Modules/zlibmodule.c -+++ b/Modules/zlibmodule.c -@@ -1645,6 +1645,7 @@ decompress(ZlibDecompressor *self, uint8_t *data, - return result; - - error: -+ self->zst.next_in = NULL; - Py_XDECREF(result); - return NULL; - } --- -2.50.1 - diff --git a/meta/recipes-devtools/python/python3/CVE-2026-7210.patch b/meta/recipes-devtools/python/python3/CVE-2026-7210.patch deleted file mode 100644 index 029eb713e42..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-7210.patch +++ /dev/null @@ -1,148 +0,0 @@ -From 2ed6138dea0bc94c726f879501e4525712e885d1 Mon Sep 17 00:00:00 2001 -From: Stan Ulbrych -Date: Sun, 10 May 2026 18:36:26 +0100 -Subject: [PATCH] gh-149018: Use `XML_SetHashSalt16Bytes` in - `pyexpat`/`_elementtree` when possible (#149023) - - -CVE: CVE-2026-7210 -Upstream-Status: Backport [https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4] - -[yocto: Use weak symbol detection for XML_SetHashSalt16Bytes instead of -XML_COMBINED_VERSION >= 20800, since our backported expat 2.6.4 provides -the function but does not bump the version macros.] - -Signed-off-by: Amaury Couderc ---- - Include/pyexpat.h | 3 +++ - Include/pyhash.h | 8 +++++--- - .../2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst | 3 +++ - Modules/_elementtree.c | 8 ++++++-- - Modules/pyexpat.c | 22 ++++++++++++++++------ - 5 files changed, 33 insertions(+), 11 deletions(-) - create mode 100644 Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst - -diff --git a/Include/pyexpat.h b/Include/pyexpat.h -index 04548b7684a..d28d6828975 100644 ---- a/Include/pyexpat.h -+++ b/Include/pyexpat.h -@@ -57,6 +57,9 @@ struct PyExpat_CAPI - XML_Parser parser, unsigned long long activationThresholdBytes); - XML_Bool (*SetAllocTrackerMaximumAmplification)( - XML_Parser parser, float maxAmplificationFactor); -+ /* might be NULL for expat < 2.8.0 */ -+ XML_Bool (*SetHashSalt16Bytes)( -+ XML_Parser parser, const uint8_t entropy[16]); - /* always add new stuff to the end! */ - }; - -diff --git a/Include/pyhash.h b/Include/pyhash.h -index 182d223fab1..ec359bd2f35 100644 ---- a/Include/pyhash.h -+++ b/Include/pyhash.h -@@ -39,14 +39,14 @@ PyAPI_FUNC(Py_hash_t) _Py_HashBytes(const void*, Py_ssize_t); - * pppppppp ssssssss ........ fnv -- two Py_hash_t - * k0k0k0k0 k1k1k1k1 ........ siphash -- two uint64_t - * ........ ........ ssssssss djbx33a -- 16 bytes padding + one Py_hash_t -- * ........ ........ eeeeeeee pyexpat XML hash salt -+ * eeeeeeee eeeeeeee eeeeeeee pyexpat XML hash salt - * - * memory layout on 32 bit systems - * cccccccc cccccccc cccccccc uc - * ppppssss ........ ........ fnv -- two Py_hash_t - * k0k0k0k0 k1k1k1k1 ........ siphash -- two uint64_t (*) - * ........ ........ ssss.... djbx33a -- 16 bytes padding + one Py_hash_t -- * ........ ........ eeee.... pyexpat XML hash salt -+ * eeeeeeee eeeeeeee eeee.... pyexpat XML hash salt - * - * (*) The siphash member may not be available on 32 bit platforms without - * an unsigned int64 data type. -@@ -71,7 +71,9 @@ typedef union { - Py_hash_t suffix; - } djbx33a; - struct { -- unsigned char padding[16]; -+ /* 16 bytes for XML_SetHashSalt16Bytes */ -+ uint8_t hashsalt16[16]; -+ /* 4/8 bytes for legacy XML_SetHashSalt */ - Py_hash_t hashsalt; - } expat; - } _Py_HashSecret_t; -diff --git a/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst b/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst -new file mode 100644 -index 00000000000..d1b5b368684 ---- /dev/null -+++ b/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst -@@ -0,0 +1,3 @@ -+Improved protection against XML hash-flooding attacks in -+:mod:`xml.parsers.expat` and :mod:`xml.etree.ElementTree` when Python is -+compiled with libExpat 2.8.0 or later. -diff --git a/Modules/_elementtree.c b/Modules/_elementtree.c -index 56d1508af13..941376613b0 100644 ---- a/Modules/_elementtree.c -+++ b/Modules/_elementtree.c -@@ -3657,8 +3657,12 @@ _elementtree_XMLParser___init___impl(XMLParserObject *self, PyObject *target, - PyErr_NoMemory(); - return -1; - } -- /* expat < 2.1.0 has no XML_SetHashSalt() */ -- if (EXPAT(st, SetHashSalt) != NULL) { -+ // Prefer 16-byte entropy, only expat >= 2.8.0. See gh-149018 -+ if (EXPAT(st, SetHashSalt16Bytes) != NULL) { -+ EXPAT(st, SetHashSalt16Bytes)(self->parser, -+ _Py_HashSecret.expat.hashsalt16); -+ } -+ else if (EXPAT(st, SetHashSalt) != NULL) { - EXPAT(st, SetHashSalt)(self->parser, - (unsigned long)_Py_HashSecret.expat.hashsalt); - } -diff --git a/Modules/pyexpat.c b/Modules/pyexpat.c -index 79492ca5c4f..47e3a1b2c00 100644 ---- a/Modules/pyexpat.c -+++ b/Modules/pyexpat.c -@@ -14,6 +14,11 @@ - - #include "pyexpat.h" - -+/* Use weak symbol to detect XML_SetHashSalt16Bytes at link time. -+ This allows using the backported function from expat even when the -+ version macros have not been bumped (e.g. expat 2.6.4 + CVE-2026-41080). */ -+#pragma weak XML_SetHashSalt16Bytes -+ - /* Do not emit Clinic output to a file as that wreaks havoc with conditionally - included methods. */ - /*[clinic input] -@@ -1388,10 +1393,16 @@ newxmlparseobject(pyexpat_state *state, const char *encoding, - Py_DECREF(self); - return NULL; - } --#if XML_COMBINED_VERSION >= 20100 -- /* This feature was added upstream in libexpat 2.1.0. */ -- XML_SetHashSalt(self->itself, -- (unsigned long)_Py_HashSecret.expat.hashsalt); -+ /* Prefer 16-byte entropy (expat >= 2.8.0 or backported). */ -+ if (XML_SetHashSalt16Bytes != NULL) { -+ XML_SetHashSalt16Bytes(self->itself, _Py_HashSecret.expat.hashsalt16); -+ } -+#if XML_COMBINED_VERSION >= 20100 -+ else { -+ /* This feature was added upstream in libexpat 2.1.0. */ -+ XML_SetHashSalt(self->itself, -+ (unsigned long)_Py_HashSecret.expat.hashsalt); -+ } - #endif - XML_SetUserData(self->itself, (void *)self); - XML_SetUnknownEncodingHandler(self->itself, -@@ -2257,6 +2267,12 @@ pyexpat_exec(PyObject *mod) - #else - capi->SetHashSalt = NULL; - #endif -+ /* Detect at runtime via weak symbol */ -+ if (XML_SetHashSalt16Bytes != NULL) { -+ capi->SetHashSalt16Bytes = XML_SetHashSalt16Bytes; -+ } else { -+ capi->SetHashSalt16Bytes = NULL; -+ } - #if XML_COMBINED_VERSION >= 20600 - capi->SetReparseDeferralEnabled = XML_SetReparseDeferralEnabled; - #else diff --git a/meta/recipes-devtools/python/python3/CVE-2026-9669.patch b/meta/recipes-devtools/python/python3/CVE-2026-9669.patch deleted file mode 100644 index 266c8beef05..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-9669.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 5b412e1f7bdb3e0667b2bc8b216ad216d59d8373 Mon Sep 17 00:00:00 2001 -From: Stan Ulbrych -Date: Mon, 8 Jun 2026 11:55:32 +0200 -Subject: [PATCH] gh-150599: Prevent bz2 decompressor reuse after errors - (GH-150600) - -CVE: CVE-2026-9669 -Upstream-Status: Backport [https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e] - -Signed-off-by: Benjamin Robin ---- - Lib/test/test_bz2.py | 15 +++++++++++++++ - Modules/_bz2module.c | 18 +++++++++++++++--- - 2 files changed, 30 insertions(+), 3 deletions(-) - -diff --git a/Lib/test/test_bz2.py b/Lib/test/test_bz2.py -index cb730a1a46e2..dcbf6a298264 100644 ---- a/Lib/test/test_bz2.py -+++ b/Lib/test/test_bz2.py -@@ -958,6 +958,21 @@ def test_failure(self): - # Previously, a second call could crash due to internal inconsistency - self.assertRaises(Exception, bzd.decompress, self.BAD_DATA * 30) - -+ def test_decompress_after_data_error(self): -+ data = bytes.fromhex( -+ "425a6839314159265359000000000000007fffff000000000000000000000000" -+ "00000000000000000000000000000000000000e0370000000000000000000000" -+ "000000000000000000000000000000000000000000000000000083f3" -+ ) -+ bzd = BZ2Decompressor() -+ with self.assertRaisesRegex(OSError, "Invalid data stream"): -+ bzd.decompress(data) -+ # Previously, a second call could crash due to internal inconsistency -+ self.assertFalse(bzd.needs_input) -+ self.assertFalse(bzd.eof) -+ with self.assertRaisesRegex(ValueError, "previous error"): -+ bzd.decompress(b'\x00' * 18) -+ - @support.refcount_test - def test_refleaks_in___init__(self): - gettotalrefcount = support.get_attribute(sys, 'gettotalrefcount') -diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c -index 97bd44b4ac96..0b0916142f57 100644 ---- a/Modules/_bz2module.c -+++ b/Modules/_bz2module.c -@@ -114,6 +114,7 @@ typedef struct { - typedef struct { - PyObject_HEAD - bz_stream bzs; -+ int bzerror; - char eof; /* T_BOOL expects a char */ - PyObject *unused_data; - char needs_input; -@@ -453,8 +454,11 @@ decompress_buf(BZ2Decompressor *d, Py_ssize_t max_length) - - d->bzs_avail_in_real += bzs->avail_in; - -- if (catch_bz2_error(bzret)) -+ if (catch_bz2_error(bzret)) { -+ d->bzerror = bzret; -+ d->needs_input = 0; - goto error; -+ } - if (bzret == BZ_STREAM_END) { - d->eof = 1; - break; -@@ -621,10 +625,17 @@ _bz2_BZ2Decompressor_decompress_impl(BZ2Decompressor *self, Py_buffer *data, - PyObject *result = NULL; - - ACQUIRE_LOCK(self); -- if (self->eof) -+ if (self->eof) { - PyErr_SetString(PyExc_EOFError, "End of stream already reached"); -- else -+ } -+ else if (self->bzerror) { -+ // Re-entering BZ2_bzDecompress() after an error can write out of bounds. -+ PyErr_SetString(PyExc_ValueError, -+ "Decompressor is unusable after a previous error"); -+ } -+ else { - result = decompress(self, data->buf, data->len, max_length); -+ } - RELEASE_LOCK(self); - return result; - } -@@ -658,6 +669,7 @@ _bz2_BZ2Decompressor_impl(PyTypeObject *type) - return NULL; - } - -+ self->bzerror = 0; - self->needs_input = 1; - self->bzs_avail_in_real = 0; - self->input_buffer = NULL; --- -2.54.0 diff --git a/meta/recipes-devtools/python/python3/makerace.patch b/meta/recipes-devtools/python/python3/makerace.patch index fbe12a5fca2..4575a30bfcf 100644 --- a/meta/recipes-devtools/python/python3/makerace.patch +++ b/meta/recipes-devtools/python/python3/makerace.patch @@ -20,7 +20,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in index dce36a5..2d235d2 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2267,7 +2267,7 @@ COMPILEALL_OPTS=-j0 +@@ -2272,7 +2272,7 @@ COMPILEALL_OPTS=-j0 TEST_MODULES=@TEST_MODULES@ .PHONY: libinstall diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.14.bb similarity index 96% rename from meta/recipes-devtools/python/python3_3.12.13.bb rename to meta/recipes-devtools/python/python3_3.12.14.bb index b6ceb0c6343..7ee32601cd3 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.14.bb @@ -31,30 +31,18 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://0001-test_storlines-skip-due-to-load-variability.patch \ file://0001-test_shutdown-skip-problematic-test.patch \ file://0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch \ - file://0001-test_deadlock-skip-problematic-test.patch \ - file://0001-test_active_children-skip-problematic-test.patch \ + file://0001-test_deadlock-skip-problematic-test.patch \ + file://0001-test_active_children-skip-problematic-test.patch \ file://0001-test_readline-skip-limited-history-test.patch \ - file://CVE-2026-1502.patch \ - file://CVE-2026-6100.patch \ - file://CVE-2026-3644_CVE-2026-0672.patch \ - file://CVE-2026-4519_p1.patch \ - file://CVE-2026-4519_p2.patch \ - file://CVE-2026-4519_CVE-2026-4786.patch \ file://CVE-2026-6019_p1.patch \ file://CVE-2026-6019_p2.patch \ - file://CVE-2025-13462.patch \ - file://CVE-2026-4224.patch \ - file://CVE-2026-11940.patch \ - file://CVE-2026-11972.patch \ - file://CVE-2026-9669.patch \ - file://CVE-2026-7210.patch \ " SRC_URI:append:class-native = " \ file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \ " -SRC_URI[sha256sum] = "c08bc65a81971c1dd5783182826503369466c7e67374d1646519adf05207b684" +SRC_URI[sha256sum] = "5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a" # exclude pre-releases for both python 2.x and 3.x UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P\d+(\.\d+)+).tar" @@ -69,6 +57,12 @@ CVE_STATUS[CVE-2022-26488] = "not-applicable-platform: Issue only applies on Win CVE_STATUS[CVE-2015-20107] = "upstream-wontfix: The mailcap module is insecure by design, so this can't be fixed in a meaningful way" CVE_STATUS[CVE-2023-36632] = "disputed: Not an issue, in fact expected behaviour" CVE_STATUS[CVE-2026-3087] = "not-applicable-platform: Issue only applies on Windows" +CVE_STATUS[CVE-2025-12084] = "cpe-stable-backport: Fixed in v3.12.13" +CVE_STATUS[CVE-2025-13462] = "cpe-stable-backport: Fixed in v3.12.14" +CVE_STATUS[CVE-2025-13837] = "cpe-stable-backport: Fixed in v3.12.13" +CVE_STATUS[CVE-2026-3644] = "cpe-stable-backport: Fixed in v3.12.14" +CVE_STATUS[CVE-2026-4519] = "cpe-stable-backport: Fixed in v3.12.14" +CVE_STATUS[CVE-2026-7210] = "cpe-stable-backport: Fixed in v3.12.14" PYTHON_MAJMIN = "3.12" From patchwork Wed Sep 2 05:25:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96992 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 54A48C61DD6 for ; Wed, 2 Sep 2026 05:26:47 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5535.1788326803308695607 for ; Tue, 01 Sep 2026 22:26:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=vgjEGuUe; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49ccfbe062eso4672805e9.3 for ; Tue, 01 Sep 2026 22:26:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326801; x=1788931601; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xDbFATsXoVStQLnH+1BYbNXQqzOTI4aw00zn18kdJm8=; b=vgjEGuUeVvX1vW0pWWFTde4JeQLm8jqfjHmSnfL3kX7/LUdH9ShaRyoeZ+vpfjRUWu DDf4Ns+UjmkxvhHpt3HDkyhEKiTGh9ver5YLr/CyN0fy9HXpJTTBQrTT4qDHv1RSHrHT pd4EB7iTOHlrpfNQS26HJg6hzJCCHcrAA7uxY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326801; x=1788931601; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xDbFATsXoVStQLnH+1BYbNXQqzOTI4aw00zn18kdJm8=; b=FFGFzypRk0WuMKtXFF/0+8uG+AGSrOMH9K9WqDOGPdaJJoKm2ay4QTyjElc9+vsH6y COw8H9pYtsI2/JT2UnUh5mXe6NglIJstTld5k5ad1Vw/pTThpUkEmqbjZk+o3BL0ThSy /XNchEMl1OunMlGaWYqqE2B/p3GS+tPG8d49ADGfuNIRyg6ejg16DlAwQm7/uq6ntayo WeW4Um6fXAQfU5k0bCVe4W3RK8CyDROwzMtQIHWFtv2Y00UiizB8N4ByeKUPDG1qecTR 8v1hYSsr/eFs7rMLNHLIOgMD5KvdoJvp/7qBXYbpmRpyAdS5GK4FtagTreZW0EgVBccO EAog== X-Gm-Message-State: AFuF++lawz/a7blLNKyCwoWEWUmHgr3t8CfOiDiS37+zaGz+/KvhcADV 1qvv7xcCJQmC9M/gjdhwZ5phnLVPuCZ0G6wJgb/Khw85f3GmOtmz4u/ASU+0/8Ld2PZkTN5P1Ax YXj5Qd4I= X-Gm-Gg: AR+sD130P9Q/X/KR6U2N1vqhh/bjL5CZAdSuKI2VGc/vLync1w7NeRpr8UzGFc5Ln8X TsufpdXnykRllwXiW9u63XIQOJ7oR/a27Ww/PBTDT0P4oAsQquri5rv8WDFfogOY3aGcL7Iu2Yw /OCFoXuN+V5wZ/Dp7ER9NxggCSsKLeuC0DACpp/NO14enNJX3Tg8nVFZiCw/W3ksM+q62yaJLo0 HoO9R38FXo8jzIiv5/t/mR6j5mQy2ax3Jwjk6TwpnwFCLX7+9/cQWl9oeeWboOGBd++hqqRueCa zEfFqJhiAV09pWzNdqtXJvpmd6lhO0FbiwJ6Nk/2wOAnfFcMpmjbARfkiKAzNFQl8TXbveyHnA8 n/AjNP7ZNhFQxBlMsFDjxM+1WwvTUFlhsvUbqmWzb87a2tk2XeQX+mX+0hOD9klne/M+h+/DsXB XlLT94/gePHfp4L9uM0tOBobVr5yduAVzWNMVk6CHbmK5vb8JfdoBYlhxQ3RXK/UUcWFY6ISXE3 Fjd34bOYXYFf5765g== X-Received: by 2002:a05:600c:3b25:b0:49c:cfae:34d2 with SMTP id 5b1f17b1804b1-49ce55fb5f7mr34317385e9.4.1788326801577; Tue, 01 Sep 2026 22:26:41 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:41 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22 Date: Wed, 2 Sep 2026 07:25:24 +0200 Message-ID: <846292594d7513e0ffbec5e0481084844505b51c.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244858 From: Peter Marko Full changelog (36 commits): * https://github.com/systemd/systemd-stable/compare/v255.21...v255.22 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: fixed changelog URL] --- ...temd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} | 0 .../systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} | 0 meta/recipes-core/systemd/systemd.inc | 2 +- .../systemd/{systemd_255.21.bb => systemd_255.22.bb} | 0 4 files changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%) rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%) rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (100%) diff --git a/meta/recipes-core/systemd/systemd-boot-native_255.21.bb b/meta/recipes-core/systemd/systemd-boot-native_255.22.bb similarity index 100% rename from meta/recipes-core/systemd/systemd-boot-native_255.21.bb rename to meta/recipes-core/systemd/systemd-boot-native_255.22.bb diff --git a/meta/recipes-core/systemd/systemd-boot_255.21.bb b/meta/recipes-core/systemd/systemd-boot_255.22.bb similarity index 100% rename from meta/recipes-core/systemd/systemd-boot_255.21.bb rename to meta/recipes-core/systemd/systemd-boot_255.22.bb diff --git a/meta/recipes-core/systemd/systemd.inc b/meta/recipes-core/systemd/systemd.inc index 28392b6b09d..42e51913da4 100644 --- a/meta/recipes-core/systemd/systemd.inc +++ b/meta/recipes-core/systemd/systemd.inc @@ -15,7 +15,7 @@ LICENSE:libsystemd = "LGPL-2.1-or-later" LIC_FILES_CHKSUM = "file://LICENSE.GPL2;md5=751419260aa954499f7abaabaa882bbe \ file://LICENSE.LGPL2.1;md5=4fbd65380cdd255951079008b364516c" -SRCREV = "70500d37992a01d3275b1c414c3ed161d6f91f9e" +SRCREV = "356c54394add8c6a1d52773852c23656590dc33b" SRCBRANCH = "v255-stable" SRC_URI = "git://github.com/systemd/systemd-stable.git;protocol=https;branch=${SRCBRANCH}" diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.22.bb similarity index 100% rename from meta/recipes-core/systemd/systemd_255.21.bb rename to meta/recipes-core/systemd/systemd_255.22.bb From patchwork Wed Sep 2 05:25:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97002 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 03F33C624D3 for ; Wed, 2 Sep 2026 05:26:58 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5536.1788326807650884876 for ; Tue, 01 Sep 2026 22:26:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EnYRy/Og; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49557167508so5863355e9.1 for ; Tue, 01 Sep 2026 22:26:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326806; x=1788931606; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Q10Mg7VmUsN4dC3gNsnSAImkF7AyxOvWMr6dOCou1RA=; b=EnYRy/Og+39VImz3WTR0bTonYDtPkITibQTlylJ2Cs/KbCxBVP5BMoW//Y3MGC59fF YbtlaFVHbQOZ4+zzv6HXzTPvRM16/kaVtzfGKp9CssGTDhUOPd2otLIGf86y7cFlKpts 5NR5ih2qocejnYMWSDWgdWGZ1Ec/k9ckk1+AE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326806; x=1788931606; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Q10Mg7VmUsN4dC3gNsnSAImkF7AyxOvWMr6dOCou1RA=; b=SIjPZ1QIH4h1geks/GPfRsR3MrLqIkVpYSmtsV/nL339/5jcXM5GkJEAWHc48OMUr0 i72rHcoXZbEWpj6Vn99vJjcrRYMRgMcqVbBqUhsGV6O4/JQItYrgFW5qrmsEbXK82QF0 cZ7022zLSGcdqAbgqDRnFaBRRkIJ0+WGr6VaynJu+NRrkcxXKnjYS87Le1hIPrk+S8LJ R1dOiPIt8wRuX5FjVQTdr9YOiavQZZzf11iS+KlLQKziDQG+TS48iL95BPjdczDSp3p7 fnIcK5U9tOoVHycyBybmkkahiQbp/qTOumv3MUxnwnd7E047Oh+Svql4dYSrho5OSlTb PomQ== X-Gm-Message-State: AFuF++nOsTHxWMH0vB/ChQrbaUcKi2kEfe9+2uVt366mQ41d2I4Mzl3+ RdqxmIBVMx4LHavJpokQ1LcyOq2JUBL0XcSVUsI4wndmXxS8X4hUcSJf3a0R2fOrAEMrZeEsK/Y jtZtMFUc= X-Gm-Gg: AR+sD11ekYWUoQFOjuGdJ3iAJXBJX2F4kzBTtfv1gcmKFx23ayUOW1+DZ7RBWTYqomx qZ3bFI6msEE2hluykTPdHHHGNCPRAXeqdNYINt1su1TAWrxmBgCmBXEOddO2T5fs74A2f8LvDKe K8fdt3p/fkUxV9f3Fz6cNz7062YlkC9rfq6K6tnq42uJ6tltClGje0VSWnIfNPrn1lHAvoIYi9X t/O/eg/hC92hQXKFSLkY/KyjaZ7/SJnXMX5ZiZEVVMhgbOo0+SHCPqPGkduRkbDnWtBAnAiucp8 iA043Kp351J7d3XkZ+lz6T25aicy+Hma9EqG/HXltuGQSS/bPB7nSoQKVVc/idHKRjNVyAKW2v/ N6Ne+zEXYtAthXuXzHdNGTF2aezal4Hb2EeGZwlW4tTymO6PuTdIWdn8dkoJ6wkxLxMAQDSwQsG ewcsp6Jpy0oCWeDoScgBN5kI/N1kBlT+DPz818Vopbl2XMWGE+rnIuelXZoLG8hzblCMB8DJjux iBq5NFV05FGeytXk0Uf7XGfNlQq X-Received: by 2002:a05:600c:699b:b0:49b:9205:45b3 with SMTP id 5b1f17b1804b1-49ce584c6femr36888175e9.15.1788326805039; Tue, 01 Sep 2026 22:26:45 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121 Date: Wed, 2 Sep 2026 07:25:25 +0200 Message-ID: <608a151948db9652b0e7032863bba1ed022a00aa.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:58 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244859 From: Peter Marko Cherry-pick patch for this CVE mentioned in [1]. Since the actual code change is already included in previous patch for CVE-2026-4426, add reference to CVE-2026-5121 to that patch and keep the remaining part (test) as CVE-2026-5121-02.patch. [1] https://security-tracker.debian.org/tracker/CVE-2026-5121 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...atch => CVE-2026-4426_CVE-2026-5121.patch} | 1 + .../libarchive/CVE-2026-5121-02.patch | 1270 +++++++++++++++++ .../libarchive/libarchive_3.7.9.bb | 3 +- 3 files changed, 1273 insertions(+), 1 deletion(-) rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%) create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch similarity index 99% rename from meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch rename to meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch index c303c2372a5..bc754e742a9 100644 --- a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch @@ -21,6 +21,7 @@ decompression path from executing. Found by fuzzing with ASAN/UBSAN. CVE: CVE-2026-4426 +CVE: CVE-2026-5121 Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/c3cb1c568ebf9e8f7f478cfc0356ae54e99712b0] Signed-off-by: Hitendra Prajapati --- diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch new file mode 100644 index 00000000000..90b9e6f6102 --- /dev/null +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch @@ -0,0 +1,1270 @@ +From a2a73a8f14b3208c7f6acbbc93265254a7c1efd0 Mon Sep 17 00:00:00 2001 +From: elhananhaenel +Date: Thu, 19 Mar 2026 16:43:29 +0200 +Subject: [PATCH] Add regression test for zisofs 32-bit heap overflow + +A crafted ISO with pz_log2_bs=2 and pz_uncompressed_size=0xFFFFFFF9 +causes an integer overflow in the block pointer allocation in +zisofs_read_data(). On 32-bit, (ceil+1)*4 wraps size_t to 0, malloc(0) +returns a tiny buffer, and the code writes ~4GB past it. + +The pz_log2_bs validation fix prevents this. Add a regression test with +a crafted 48KB ISO that triggers the overflow on unfixed 32-bit builds. + +CVE: CVE-2026-5121 +Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/a2a73a8f14b3208c7f6acbbc93265254a7c1efd0] +Modification: part of oupstream patch is moved to CVE-2026-4426_CVE-2026-5121.patch +Signed-off-by: Peter Marko +--- + Makefile.am | 2 + + libarchive/test/CMakeLists.txt | 1 + + .../test_read_format_iso_zisofs_overflow.c | 104 ++ + ...est_read_format_iso_zisofs_overflow.iso.uu | 1096 +++++++++++++++++ + 4 files changed, 1203 insertions(+) + create mode 100644 libarchive/test/test_read_format_iso_zisofs_overflow.c + create mode 100644 libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu + +diff --git a/Makefile.am b/Makefile.am +index 57102431..e55882af 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -505,6 +505,7 @@ libarchive_test_SOURCES= \ + libarchive/test/test_read_format_isorr_new_bz2.c \ + libarchive/test/test_read_format_isorr_rr_moved.c \ + libarchive/test/test_read_format_isozisofs_bz2.c \ ++ libarchive/test/test_read_format_iso_zisofs_overflow.c \ + libarchive/test/test_read_format_lha.c \ + libarchive/test/test_read_format_lha_bugfix_0.c \ + libarchive/test/test_read_format_lha_filename.c \ +@@ -861,6 +862,7 @@ libarchive_test_EXTRA_DIST=\ + libarchive/test/test_read_format_iso_rockridge_rr_moved.iso.Z.uu \ + libarchive/test/test_read_format_iso_xorriso.iso.Z.uu \ + libarchive/test/test_read_format_iso_zisofs.iso.Z.uu \ ++ libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu \ + libarchive/test/test_read_format_lha_bugfix_0.lzh.uu \ + libarchive/test/test_read_format_lha_filename_cp932.lzh.uu \ + libarchive/test/test_read_format_lha_filename_utf16.lzh.uu \ +diff --git a/libarchive/test/CMakeLists.txt b/libarchive/test/CMakeLists.txt +index 4838f336..95c1b33f 100644 +--- a/libarchive/test/CMakeLists.txt ++++ b/libarchive/test/CMakeLists.txt +@@ -149,6 +149,7 @@ IF(ENABLE_TEST) + test_read_format_isorr_new_bz2.c + test_read_format_isorr_rr_moved.c + test_read_format_isozisofs_bz2.c ++ test_read_format_iso_zisofs_overflow.c + test_read_format_lha.c + test_read_format_lha_bugfix_0.c + test_read_format_lha_filename.c +diff --git a/libarchive/test/test_read_format_iso_zisofs_overflow.c b/libarchive/test/test_read_format_iso_zisofs_overflow.c +new file mode 100644 +index 00000000..bad52b15 +--- /dev/null ++++ b/libarchive/test/test_read_format_iso_zisofs_overflow.c +@@ -0,0 +1,104 @@ ++/*- ++ * Copyright (c) 2025 ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR ++ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES ++ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. ++ * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT, ++ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT ++ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, ++ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY ++ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT ++ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF ++ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++#include "test.h" ++ ++/* ++ * Verify that a crafted ISO9660 image with an invalid zisofs block-size ++ * exponent (pz_log2_bs) is handled gracefully. ++ * ++ * The ZF extension in the Rock Ridge entry stores pz_log2_bs as a raw ++ * byte from the image. The zisofs spec only permits values 15-17. ++ * Values outside that range can cause: ++ * - Undefined behavior via oversized bit shifts (any platform) ++ * - Integer overflow in block pointer allocation on 32-bit platforms, ++ * leading to a heap buffer overflow write ++ * ++ * The test image has pz_log2_bs=2 (out of spec) combined with ++ * pz_uncompressed_size=0xFFFFFFF9. On 32-bit, (ceil+1)*4 overflows ++ * size_t to 0, malloc(0) returns a tiny buffer, and the code attempts ++ * to write ~4GB into it. On 64-bit the allocation is huge and safely ++ * fails. ++ * ++ * We verify the fix by checking archive_entry_size() after reading the ++ * header. When pz_log2_bs validation rejects the bad value (pz=0), ++ * the entry keeps its raw on-disk size (small). Without the fix, ++ * the reader sets the entry size to pz_uncompressed_size (0xFFFFFFF9). ++ * ++ * We intentionally do NOT call archive_read_data() here. Without the ++ * fix, the data-read path triggers a heap buffer overflow on 32-bit ++ * that silently corrupts the process heap, causing later tests to ++ * crash rather than this one. ++ */ ++DEFINE_TEST(test_read_format_iso_zisofs_overflow) ++{ ++ const char reffile[] = "test_read_format_iso_zisofs_overflow.iso"; ++ struct archive *a; ++ struct archive_entry *ae; ++ int r = ARCHIVE_OK; ++ int found_regular_file = 0; ++ ++ extract_reference_file(reffile); ++ assert((a = archive_read_new()) != NULL); ++ assertEqualIntA(a, ARCHIVE_OK, archive_read_support_filter_all(a)); ++ assertEqualIntA(a, ARCHIVE_OK, archive_read_support_format_all(a)); ++ assertEqualIntA(a, ARCHIVE_OK, ++ archive_read_open_filename(a, reffile, 10240)); ++ ++ while ((r = archive_read_next_header(a, &ae)) == ARCHIVE_OK || ++ r == ARCHIVE_WARN) { ++ /* ++ * With the fix, pz_log2_bs=2 is rejected and pz is set ++ * to 0, so the entry keeps its small raw size from the ++ * ISO directory record. Without the fix, zisofs sets ++ * the entry size to pz_uncompressed_size (0xFFFFFFF9). ++ * ++ * We intentionally do NOT call archive_read_data(). ++ * Without the fix, the data-read path triggers a heap ++ * buffer overflow on 32-bit that silently corrupts the ++ * process heap, causing later tests to crash rather ++ * than this one. ++ */ ++ if (archive_entry_filetype(ae) == AE_IFREG) { ++ la_int64_t sz = archive_entry_size(ae); ++ failure("entry \"%s\" has size %jd" ++ "; expected < 1 MiB" ++ " (if size is 4294966265 = 0xFFFFFFF9, the" ++ " pz_log2_bs validation is missing)", ++ archive_entry_pathname(ae), (intmax_t)sz); ++ assert(sz < 1024 * 1024); ++ found_regular_file = 1; ++ } ++ } ++ ++ /* Iteration must have completed normally. */ ++ assertEqualInt(ARCHIVE_EOF, r); ++ ++ /* The PoC image contains a regular file; if we never saw one, ++ * something is wrong with the test image. */ ++ assert(found_regular_file); ++ ++ assertEqualIntA(a, ARCHIVE_OK, archive_read_close(a)); ++ assertEqualInt(ARCHIVE_OK, archive_read_free(a)); ++} +diff --git a/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu b/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu +new file mode 100644 +index 00000000..5e7dcc37 +--- /dev/null ++++ b/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu +@@ -0,0 +1,1096 @@ ++begin 664 test_read_format_iso_zisofs_overflow.iso ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````!0T0P,#$!```````````````````````````````````````` ++M````4$]#7U=2251%`````````````````````````````````````````!@` ++M```````8```````````````````````````````````````````!```!`0`` ++M`0`("``*````````"A(`````````````$@`````B`!,````````3``@````` ++M"`!Z`1D,`````@```0```0$````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M``````````````````````````````````````````````$````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M`````````````````````````````````````````/]#1#`P,0$````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M`````````````0`3`````0`````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M``````````````````````````````````````````!5`!,````````3``@` ++M````"`!Z`1D,`````@```0```0$`4U`'`;[O`%!8+`'M00````!![0(````` ++M```"``````````````````````$````````!(@`3````````$P`(``````@` ++M>@$9#`````(```$```$!`7T`%````````!00"``````($'H!&0P````````! ++M```!#D]615)&3$]7+D))3CLQ`%I&$`%P>@0"^?O__P````!.31$!`$]615)& ++M3$]7+D))3E!8+`&D@0````"!I`$````````!``````````````````````(` ++M```````"```````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M`````````````#?D4Y;)V]8'^?O__P0"``!!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1! ++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%" ++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)# ++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$ ++M04)#1``````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++M```````````````````````````````````````````````````````````` ++,```````````````` ++` ++end diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index c167b164b4b..fb6ed5686df 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb @@ -46,9 +46,10 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \ file://CVE-2025-60753-02.patch \ file://CVE-2026-4111-1.patch \ file://CVE-2026-4111-2.patch \ - file://CVE-2026-4426.patch \ + file://CVE-2026-4426_CVE-2026-5121.patch \ file://CVE-2026-4424-1.patch \ file://CVE-2026-4424-2.patch \ + file://CVE-2026-5121-02.patch \ " UPSTREAM_CHECK_URI = "http://libarchive.org/" From patchwork Wed Sep 2 05:25:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96996 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9A467C61DFD for ; Wed, 2 Sep 2026 05:26:57 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5670.1788326810537290343 for ; Tue, 01 Sep 2026 22:26:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xbfkw6vg; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-484415c8cb1so468710f8f.2 for ; Tue, 01 Sep 2026 22:26:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326808; x=1788931608; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GHEt83feZ7mEGXkJ8EGO1kZiv0uAX2NTdm98FC+NT4c=; b=xbfkw6vgSrRgl/HHvY0HSBRj1y7VGCENq3AhDoRIUMU0sGfebr8fP05q5wbR64kD3w QOboPs3VI32gYMSHuZXNSfMu9m0pfmiSjCWm9qwINw1iT1e6oXz7maKSSoTG5J/mhUu3 W5kO3GZqYhTxZVmbfQvxoPXzDqfwSbJ7+f41M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326808; x=1788931608; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GHEt83feZ7mEGXkJ8EGO1kZiv0uAX2NTdm98FC+NT4c=; b=htFbaYWiVY5ntI32cjJtjdJhutctzgz90zERIpHru/WtBO85OuXv4CfbP84hI5xSi3 bC19bxg1+lGhSZr7qnAwnlDtpu13oN3YlUW9RNJlms2ndhaTp0jscmI7cSyGVBySGF+r CZV3SUUCEIgq8jP1+hQwlTpo67feCV4HKIfL4ubqMeyOkq8jPSc50WyKHKtHhSVAem9u 3hf7IJtaOgDBiCrn3xryURzU/+w/Mt+r65MEU7Lt5mvB30wUtQykJHvdvsF1IbnpQ4yt ijf9y74gl02EPEHW7A1OZVUPd6HjE/FUSTZbm0jmtRyPV8siiEpaW+5QEQ3P7tzKun4X Mktw== X-Gm-Message-State: AFuF++l5j6LDYkb1bKK6mGVx1Q7VDOhBdviT0f0FbMQIJFIxSOxdCXnv LJZ1Hj/WUzzeQ8puoMHQEtAz1bYF6qloYUWR+cASfW9Oam2ATGW5cmY7bxWsEMJHOKYqUwa6v9k UtKp+IlA= X-Gm-Gg: AR+sD11mB1vVuev36uU9krlEOsGK963F46hfaG0i/QFR84PZGN8YND0KMoM24c/391p 9pZCq3eDpNY7vHv5pXlZeqw878N8Etg43+maQOj5l6SRRsiB0rzHLcAjNi0HYPzqBxxxRDF5Thu SV5H0Cq0atu6miSFFWPVfcnET8R8llFb/RtUss2EglGLb7eQWyXYEkE6bXsUHpbCff4DG92O9QR y8Ri74LcEbMTUfr8e6inW1wZF0QTRcbTxp2hN8ys6Y+jFanorKrBt/slldgxXOzK/Lq6/rqExbz kFHKSMGYo4GztZqk8De2Kj4SkUCfXBX77mWDxJBhVY4vGLook7U7fsPXZsITcbw8WXulTwItRew Srv6ZQdrIxDwrA66+gQNUQ1XLnkMxW4RpbiitQXwOTnR8M7vnkK36R4sLvMnyaAUWVe7SHAgnC7 VpA3lw6poWaZ1zjvkTplQ1Rds6YCXL8GR1JA0emTyW7tfWqwE+4WVSJK0YmsZd74gygX+8RXa8p cNhumC5Yj659GOJOA== X-Received: by 2002:a05:600c:37c7:b0:49b:909e:922e with SMTP id 5b1f17b1804b1-49ce583d716mr38168675e9.10.1788326808524; Tue, 01 Sep 2026 22:26:48 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:48 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745 Date: Wed, 2 Sep 2026 07:25:26 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244860 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-5745 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libarchive/libarchive/CVE-2026-5745.patch | 39 +++++++++++++++++++ .../libarchive/libarchive_3.7.9.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch new file mode 100644 index 00000000000..a060b081ad8 --- /dev/null +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch @@ -0,0 +1,39 @@ +From 5f7025543205106d64081cbafd8c345bf859b86f Mon Sep 17 00:00:00 2001 +From: Tim Kientzle +Date: Sat, 18 Apr 2026 21:04:59 -0700 +Subject: [PATCH] Merge pull request #2905 from Patsakas/Patsakas-fix-acl-bug + +Fix NULL pointer increment in archive_acl_from_text_nl + +(Not a security issue, and arguably not really even a bug, but easy to fix regardless.) + +(cherry picked from commit 0b0b888f86b46e3b279f5f7c6eef0479f35978ee) + +CVE: CVE-2026-5745 +Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/5f7025543205106d64081cbafd8c345bf859b86f] +Signed-off-by: Peter Marko +--- + libarchive/archive_acl.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/libarchive/archive_acl.c b/libarchive/archive_acl.c +index ab601833..14a107a4 100644 +--- a/libarchive/archive_acl.c ++++ b/libarchive/archive_acl.c +@@ -1718,7 +1718,6 @@ archive_acl_from_text_nl(struct archive_acl *acl, const char *text, + + tag = 0; + s = field[n].start; +- st = field[n].start + 1; + len = field[n].end - field[n].start; + + if (len == 0) { +@@ -1726,6 +1725,8 @@ archive_acl_from_text_nl(struct archive_acl *acl, const char *text, + continue; + } + ++ st = s + 1; ++ + switch (*s) { + case 'u': + if (len == 1 || (len == 4 diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index fb6ed5686df..b36632cc1fe 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb @@ -50,6 +50,7 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \ file://CVE-2026-4424-1.patch \ file://CVE-2026-4424-2.patch \ file://CVE-2026-5121-02.patch \ + file://CVE-2026-5745.patch \ " UPSTREAM_CHECK_URI = "http://libarchive.org/" From patchwork Wed Sep 2 05:25:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96997 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CF560C61DD6 for ; Wed, 2 Sep 2026 05:26:57 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5537.1788326812505372943 for ; Tue, 01 Sep 2026 22:26:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jESiAlW7; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so6489905e9.2 for ; Tue, 01 Sep 2026 22:26:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326811; x=1788931611; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xoTWlAuWMvxa2V6tGFd7aDl/JLcVECse5mxcVtTAh2o=; b=jESiAlW7z+eXQxqnk+TSMj9hMAnbTasSaHK6aky3GJLGyWaSO/8yb0ZiCA2PjKm6Eq isd4Z/CQtHaIo34EJ8mH8a4f2TaZUVLhMbeECAIEcO/NH8kG8DXWrPGYbpaHdPPReLRw ngDDtpZMv1SmDx5/bQu0R8xhmHqykwgPYy2fA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326811; x=1788931611; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xoTWlAuWMvxa2V6tGFd7aDl/JLcVECse5mxcVtTAh2o=; b=S0Ct+/G2M2V/ACUUS05kAMdUEm+70iOfpkwBscwSkmVBB8756iYs4UYTyTv6BUMONL DPfFhHRf0vaEVv58uJikIAnjYsRrD7XUhRzVTu7ttijH5tmRvvEc5xZswQ3vHRfmR+mK PHuBVUNjPECWtm+i7iFEX1I/F7/eYVa2M4qOy93KW9Nomra2LAHMcWXBiYsmPyhTBTXh nvL47sBsyUcfZwH2NUFg4YhgAmGlgElWVyUlFV4xkptQ22jzaO+qjgZ7O6CbMMc4Gjoy CrLAZEw1Kdnj8A+xQ9sKGjawfIF31xIj/j+oksw0el4BTvKtol61b8pak08jr4EI2Q5H pacg== X-Gm-Message-State: AFuF++lJR/myO8uMwVkoDNeE8CzzDjG0vOg8rsOne+IFSxR/Ms3l+shT CfmZG8REKLmHnZcOtPZB6G4ec5v1h8G1w0pnIXflTaowa/0/uFjKbSDwxufcuFU4tcw0XmWk/Ly X9TC1ogQ= X-Gm-Gg: AR+sD10ERYYcE0ba19WrdLh0kCVtI8n1wW7jUacxl4rGU2L1LXyEUcBDJDqUUAu2xcn CJcHV9L7oKBtxZo0giRai5l6dKTreS9WE5F4PizcgTBbkwXBd88+KgOxPV0K0DNn8Oe1amvGmCJ bfM/br9zFBCqXvR1zPdTf8YfbYnWF3kgiktLr1TXXT2Rp21yx/58xiw8cH1WlaYjAFa4KoW0+FJ D9bc20bqf4akSTaPBuLT8y6JRw6MjzGK+XzmXnqXZzf1m/2zc1cFe23ostfUos82Xc25apIVK1r UL0UKFQjJ39sJWPJHKML625Xbz6Jg0NvKV14o4Y0iUsznOQSH7MkT9UhZVyZz5bP2y4ZONwjaWq 1J7xzC+eTiLtWh06vvCg/C1bhc57NegEbducrEh9SOxcsLt0IJ1vCP9XQEp2iR4DFNCN93DEBl2 f61YmP7+p44zBPdWewuwxXiDvxE5PvBS2Zzu7OohJXQmSJ2A8rX1JKkmBzgNpwH27nHo99Ar23Z +1dMJOnPZz7kkCf+w== X-Received: by 2002:a05:600c:37ca:b0:49c:cf18:494e with SMTP id 5b1f17b1804b1-49ce5819a2fmr40009955e9.12.1788326810734; Tue, 01 Sep 2026 22:26:50 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584 Date: Wed, 2 Sep 2026 07:25:27 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244861 From: Peter Marko Set status per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-1584 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 676c5c6f940..0eabc517ce5 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -129,3 +129,4 @@ pkg_postinst_ontarget:${PN}-fips () { } CVE_STATUS[CVE-2026-3832] = "fixed-version: vulnerable multi-record OCSP response handling was introduced in 3.8.8 and is not present in 3.8.4" +CVE_STATUS[CVE-2026-1584] = "fixed-version: vulnerable code not present, introduced with 3.8.11" From patchwork Wed Sep 2 05:25:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96998 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E9539C624D6 for ; Wed, 2 Sep 2026 05:26:57 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5538.1788326813857541590 for ; Tue, 01 Sep 2026 22:26:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=brTQZjKX; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49b0eab380eso5794805e9.0 for ; Tue, 01 Sep 2026 22:26:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326812; x=1788931612; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TAUiBCEx2A8dHZUFbjnRFSc9fQ154dlp3li6sDcWtE8=; b=brTQZjKXPs0d/CIwVoN+W0GWcvMJQlZGqt8wJhK51+V6hs+aWLT/4VVlKlBQ/zfrIX 0giBqxPcJ0dzqebCYWBS9z2J4uKBG4X+FPLU6T3NMyNB8CrMoZxPFyxxmDW1fpvgcV4X KubKfytcvv9KN2L7UYTxLuOHTKqHp0kJTE3yM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326812; x=1788931612; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TAUiBCEx2A8dHZUFbjnRFSc9fQ154dlp3li6sDcWtE8=; b=lIu1T2RzrYUSfcNt+J4On+F6ASQB1KC1URnQJSopsTDi99EBeTr83XvpSznnic8x0N qYibgiHT0dFVVSSP24qFwzqOoj3l5/M9uQjRqoDmrzUVxfgC0GmVBY7B60S5kd8TVrLo vxqApDJXrKTSyQMSUEbWHhDVPZ4aB/m9LCkWegPSw3WM2pWwaysuuK5CaSGlVGidV9+P aiI5Ap9Bd595I257R+M6FXxiTNrbaYWc8Yz8oaVbI+VJ+wXVFZk9J0Bik57d/WEG20GW v0XnmyRnmnqNJPRjWbydBLCVky3+K/DDNVwAMRPTNpl0F7Qh33rPiAfouv73XQfPUdEi FgoA== X-Gm-Message-State: AFuF++lvdjwdjFd0b9GmJ7dOJpIAyI5QfVNARHxt1knu3WM+Ct9XJUpY 7Q67QkL/9D5tzsxrv6pjRSWH5cBfK8/Cfz9sZpOeeTnt6Q47WjXmf7RYuUvYGNHb1ziQOwvATJM 3YJ3f2VM= X-Gm-Gg: AR+sD12sdqsroYyoHFy/nbJmjK5yB+N9SpB2K4GVb5YnL1oD/ObJHAILbsBf7oZluFO oTJ/pXG27qBqnu9onhUy5NHTN2mcjfad9YZhCGIb7cXPeJw7JCtEad8eCO6HKA/fjNTWcXIUXMV P6x6gSSVu8GmGcGd0sJlt3kUcu1pNQOX+LacLk0Jul+jlnglxaC3Yuofy2oL4Uz6Q3PE7BWKd4i kGR1sLL/c7m8oPLUepW/FyxYAQwSyXbZJjo+zcW5/E7i8IIv38H19HQAsLmu5igurqYaF/dq++T vunMfz6gqkmsYAK+o6oZaoCEWNajaq7NlpQvTrC8BIEaExyObPnirRix2jrFkKX/8iNzH83L84S B+n/Rf7xgLCF9tMl+xLPjGzTg9dVDZhY36y/JkM0CJGWmpRjJTg9wu+7o2eCcTjO8h9l+3MpK8X 1RNrr9TVnuBccJjZCPJR4YnUwQHQ/qMoMV0Qi39iW+pZu0+c4xhH1uxOUnGbRlm66Cglb0JnZZN k7adOhIqob6pneGpg== X-Received: by 2002:a05:600c:3f0b:b0:49c:ced9:ab7f with SMTP id 5b1f17b1804b1-49ce7c316aemr7309535e9.8.1788326812059; Tue, 01 Sep 2026 22:26:52 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221 Date: Wed, 2 Sep 2026 07:25:28 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244862 From: Jaipaul Cheernam This patch applies the upstream fix as referenced in [1], using the commit shown in [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221 [2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.38.4.bb | 1 + 2 files changed, 76 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch new file mode 100644 index 00000000000..03396f3e434 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch @@ -0,0 +1,75 @@ +From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001 +From: Karl Williamson +Date: Thu, 26 Mar 2026 10:13:49 -0600 +Subject: [PATCH] regcomp_study: Don't create a trie that would overflow + +This addresses GH #23388 + +The design of the trie compiling code is to batch extra long tries into +smaller chunks that fit into whatever limitations there are. However, +this ticket shows that that isn't always being done. + +In this case, a bunch of branches that have TAIL operands can be +combined together, and the final TAIL is used. And the code requires +that the delta between the first branch and this final TAIL fit into a +16-bit field. That is the root cause of this bug. + +I'm not familiar enough with the trie construction code to easily +understand why the final tail needs to be used here. So this patch +simply doesn't optimize a sequence of branches into a trie that would +overflow. + +This could be revisited by someone who knows more about this than I, or +earlier in the development cycle. + +CVE: CVE-2026-13221 +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7] +Signed-off-by: Jaipaul Cheernam +--- + regcomp_study.c | 10 ++++++++++ + t/re/pat_advanced.t | 9 +++++++++ + 2 files changed, 19 insertions(+) + +diff --git a/regcomp_study.c b/regcomp_study.c +index db7ab3a409..a1b2c3d4e5 100644 +--- a/regcomp_study.c ++++ b/regcomp_study.c +@@ -1933,6 +1933,16 @@ Perl_study_chunk(pTHX_ + tail = regnext( tail ); + } + ++ /* The code below currently saves the difference from ++ * start to finish in a 16-bit field, causing ++ * GH #23388. This defeats the design of batching ++ * tries into chunks that each fit. khw thinks it is ++ * too late in the 5.44 cycle to relook at the design, ++ * so for now anyway, don't make a trie that would ++ * overflow */ ++ if (tail - startbranch >= U16_MAX) { ++ continue; ++ } + + DEBUG_TRIE_COMPILE_r({ + regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state); +diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t +index 398680838d..c9e389ecb3 100644 +--- a/t/re/pat_advanced.t ++++ b/t/re/pat_advanced.t +@@ -4898,6 +4898,15 @@ EOF_DEBUG_OUT + $x =~ s/^[\x{0301}\x{030C}]+//; + } + ++ { # GH #23388 ++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow"); ++ my $x = join "|", "aaa".."mzz"; ++ my $y = join "|", "naa".."zzz"; ++ use re 'Debug'; ++ "fnord" =~ m/(?:$x)|(?:$y)/; ++ PROG ++ } ++ + + # !!! NOTE that tests that aren't at all likely to crash perl should go + # a ways above, above these last ones. There's a comment there that, like +-- +2.43.0 diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb index 9f4cc1c4044..8dccd34499b 100644 --- a/meta/recipes-devtools/perl/perl_5.38.4.bb +++ b/meta/recipes-devtools/perl/perl_5.38.4.bb @@ -20,6 +20,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://0001-Fix-intermittent-failure-of-test-t-op-sigsystem.t.patch \ file://CVE-2026-8376-01.patch \ file://CVE-2026-8376-02.patch \ + file://CVE-2026-13221.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Wed Sep 2 05:25:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 96999 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A89CC624D7 for ; Wed, 2 Sep 2026 05:26:58 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5671.1788326814766527048 for ; Tue, 01 Sep 2026 22:26:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XyOEKJfK; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49cd9add88aso3479805e9.3 for ; Tue, 01 Sep 2026 22:26:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326813; x=1788931613; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EvWUvS3iMv/kORPaFfHxbaQjpqZXi5WyyrO+XmDW9w4=; b=XyOEKJfKM5TR9DcvzZ6qOJ2qXulb9r8fozko57Xz493hT3Vt1QVsIEC120gQ1cAjZS l0W9W1oJM2JaP6oGXncw5kE/4yy8lvvWmhTeLs2KWCXQFVuS9MVQygaG9cMWYAdHjrhH WZWXC3ne/RGuG0VAMgK1bDunyitBQCXcQ4yRg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326813; x=1788931613; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EvWUvS3iMv/kORPaFfHxbaQjpqZXi5WyyrO+XmDW9w4=; b=Gxfx0Hn79pQjp/UMNg3FmVxhvSC62/IRDDkr/f9ElJpfWBxCzJIKjwhwehZnrS6Xmj C8wwMuNA1JK8OFYCaAlzgbm/fai6pMZoHU8bRflab3E13ErHWCYoWzXt3TVCgazcmGQk FWLBUqO8oZshKv7k8/z7ujhzanXXf3JLrVDLOYoWUUA8uGpQerQHQslGBpuFC4EH61MD g7YdXmBWUEDE3vP1YCF4sGVMGXinyep9WU5/u9qiNgWaGg3ZwOqKOc2EPszJJ/xM5m6C Pww+MAGHxTp/A6Os58cdWDnGl5OPuw9IP9Rx7BEqAo38Rtor4cBIHtViWb0dCd1OgE+O hiBg== X-Gm-Message-State: AFuF++ncj0CsrjjjEbr28prPfoLj0iO68N42dWwR/cEY9LZVVNjQg0a9 Ph1SVzYT72mGVJiHOdjGxxacqN+aNDC4DgJOVN7FnmcH06vx1TDipfZGq8Si3FzCahsRUzunNTl YPsqHqSw= X-Gm-Gg: AR+sD12H8T2vdxgsXYiXDUOpMA0jqxinUI5LFruz1XtJEfklyMazBKM/pKvULwiLlVQ yacG5tZAd5fXPZVnw0pIS9UjK6DF3KSaBuAvFnRYVMkDNbS+ATWGgYaMhf/0m/djReoJU+4lpoc NKx5bNuvPb2LIYsH4CA7/A6KbbKFWYrIo1qInYeXAOLePbLyBFHN0Vcv/gLnU1s2CVapv8JCw98 //+xEpf5sTnz9Tn689a5Xe5llwJRwHpjjspLABQkeGS1f1gKW8bQkJyZIvOV7HzFw5czi1KiKwP Cj4iIEGTIxnbiTMBDKZzUhL7x/ae0UbslPEJBsJ9ZrU3BJfX0eOsko+/5pjpSZEAscKuL8jqM0w l+iKAXBFU5N6wQ8Rds5BdDLy7aEapi7WrWwh7xYCLHr3lH6eS651Je3fqbex/odfYdviStqpVXH OejEHUc89Ra1yzs5BIm1RdsCLkloXIZ5xrmFnY23V8OlIv5ouuqbJhf9m/07nvd4dl+FWDHfzcq 68HFji8WMCu336wfA== X-Received: by 2002:a05:600c:a55:b0:49c:cedc:768a with SMTP id 5b1f17b1804b1-49ce5828e7amr37971715e9.16.1788326812892; Tue, 01 Sep 2026 22:26:52 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432 Date: Wed, 2 Sep 2026 07:25:29 +0200 Message-ID: <93fbbdc19eea157c4c9b040291481c4f778ab6db.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:58 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244863 From: Jaipaul Cheernam This patch applies the upstream fix as referenced in [1], using the commits shown in [2] and [3]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57432 [2] https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 [3] https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../perl/files/CVE-2026-57432-01.patch | 52 +++++++++++++++++++ .../perl/files/CVE-2026-57432-02.patch | 34 ++++++++++++ meta/recipes-devtools/perl/perl_5.38.4.bb | 2 + 3 files changed, 88 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch new file mode 100644 index 00000000000..ef92b0d7b21 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch @@ -0,0 +1,52 @@ +From 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Sat, 9 May 2026 17:18:43 +0100 +Subject: [PATCH] pp_pack.c: Avoid ssize_t overflow when calculating the size + of a structure + +If the user has requested a size that would overflow a SSize_t, then the +only sensible thing to do is throw an exception, because the structure +this implies couldn't possibly fit into memory anyway. + +CVE: CVE-2026-57432 +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55] +Signed-off-by: Jaipaul Cheernam +--- + pod/perldiag.pod | 6 ++++++ + pp_pack.c | 4 ++++ + 2 files changed, 10 insertions(+) + +diff --git a/pod/perldiag.pod b/pod/perldiag.pod +index 841e22d580..d9231077363d 100644 +--- a/pod/perldiag.pod ++++ b/pod/perldiag.pod +@@ -4880,6 +4880,12 @@ mixed-case attribute name, instead. See L. + (F) You can't specify a repeat count so large that it overflows your + signed integers. See L. + ++=item Pack template structure size is too large ++ ++(F) You called C or C to operate on a structure, whose ++computed size is too large to fit in memory. This usually happens as a ++result of embedding a large number as the repeat count for an item. ++ + =item page overflow + + (W io) A single call to write() produced more lines than can fit on a +diff --git a/pp_pack.c b/pp_pack.c +index b5c0b261ef..6075e83aac 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + } + } ++ if ((size > 0) && ++ ((len > SSize_t_MAX / size) || /* detect overflow of len * size */ ++ (len * size > SSize_t_MAX - total))) /* detect overflow of total + len * size */ ++ croak("Pack template structure size is too large"); + total += len * size; + } + return total; +-- +2.43.0 diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch new file mode 100644 index 00000000000..273a247a88f --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch @@ -0,0 +1,34 @@ +From 40754edc72dd3e513d758153c0e2f0215897740e Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Mon, 11 May 2026 12:25:33 +0100 +Subject: [PATCH] pp_pack.c: Avoid some other potential overflows when + calculating sizes + +CVE: CVE-2026-57432 +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e] +Signed-off-by: Jaipaul Cheernam +--- + pp_pack.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/pp_pack.c b/pp_pack.c +index 6075e83aac..b2019902203a 100644 +--- a/pp_pack.c ++++ b/pp_pack.c +@@ -515,12 +515,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr) + break; + case 'B': + case 'b': +- len = (len + 7)/8; ++ len = (len / 8) + !!(len % 8); + size = 1; + break; + case 'H': + case 'h': +- len = (len + 1)/2; ++ len = (len / 2) + !!(len % 2); + size = 1; + break; + +-- +2.43.0 diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb index 8dccd34499b..b4927646d75 100644 --- a/meta/recipes-devtools/perl/perl_5.38.4.bb +++ b/meta/recipes-devtools/perl/perl_5.38.4.bb @@ -21,6 +21,8 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-8376-01.patch \ file://CVE-2026-8376-02.patch \ file://CVE-2026-13221.patch \ + file://CVE-2026-57432-01.patch \ + file://CVE-2026-57432-02.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Wed Sep 2 05:25:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97001 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 58B41C624D8 for ; Wed, 2 Sep 2026 05:26:58 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5539.1788326815599460945 for ; Tue, 01 Sep 2026 22:26:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=iLwzmPf4; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4998b5a63e2so5714495e9.1 for ; Tue, 01 Sep 2026 22:26:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326814; x=1788931614; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=AeAIafQkWTFl5hRSPt5du3UvE7GpRscClJ0D45H4ohU=; b=iLwzmPf4Fsc5Dhsv4Vu/L3TMOOga30om9mMCoBCNVUze+jsklWjVhMMT4s7heUag5i GRiZMVr/gUlH1z1FZOBSO7P+pKis5dVCDDFwZnUvmKAbSs21Q74Sv8Zt0K7qEBX5lwep xV696V7rofzqpYorJxgX0BTIst7GfuZiPsqEY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326814; x=1788931614; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=AeAIafQkWTFl5hRSPt5du3UvE7GpRscClJ0D45H4ohU=; b=eZrZjv2qOg+4ZGtuX9L6X1JPcoe/B/jkkxzWgzFsd4QP6vDWgamk9gT5l5U69frcv4 9fnhYf8bprs+X+GYi0YoUbPdl/+G8pJwBB5a03HW/LNi9ZchVPQ13O3TLr69aoRb1rJe ecoZpUdAWOEoaKaWftm6rw71EOmeie06nFz7kL9oqOMQDhrmlYjuxZRirDRHL34rzlMK /YBNzZAGmWpW6WTDFOCEd7MxdEmncOwf30J1jyMCeIOmyJ5jH/FmCMT4doxql/bYsaju vnlWFjyDFt16iA/hpL1gunDE8kTMcHzcw5QFThi5ETfhg0EGKc2xRg2OI67T+IgQNy+g BaYQ== X-Gm-Message-State: AFuF++ly317U+8LrCqXl9KpdatAHSE9jo9C7NiynFpgFz1p6BXa7P+Tp a3hBe5SZ7GdUOxdGncD4SjPnHiY0pfnD4t0grUDmjBOtKfUBhha8aOf3lmo/7ngLFy8UoESC0el zlUjlo1k= X-Gm-Gg: AR+sD129vQIIDiazOhCp1kN27G3586XwQCQt+7Cepwshfh+ttTiKZqr57qUl8u8WBT9 dwxhsxsF1p02Whd6GMp+NqeVv/Mc6ei3dnozBbWbZd8ONEVJAxSZAB7Ub2Lu4QIr67tooHQOKDD GcLDw0wNkM2bfNctqW4o4yZqCIUG+idNMCIHBi+kK/2ap8/VP1sfB01cp1cjCPoDyFM0EgxqcfM 6dV0Kdxwk+nPIMP4S4w2bXYP4yIPPJyFtvQl1GsdPXVuRt7M7UdpPt9AjeOOfaxIADjC6K4mF0L V9Td539hxt8X0Uy8oWfIDnubhpSi8tKX3Di/vPa1QXAei6PZBswDuAL0M3bF/HSFPalfn0JrYZp oM4mtdBjR4WI78BxID/aEOUAiKLLPWNMmim0lsaXTJvWSEERt6qW+/hN+/lzZAg82ycwVWIZew9 xnNH1KPvhkthokaY+0rBWBXG242ozrKXDZnsbbloZZ7r8UYnGX7vaBg9KmNkT9DewKlsq4YD/29 0RNW57dHUsEaOmFCQ== X-Received: by 2002:a05:600c:3486:b0:499:8704:242c with SMTP id 5b1f17b1804b1-49ce5591a08mr42059225e9.0.1788326813693; Tue, 01 Sep 2026 22:26:53 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909 Date: Wed, 2 Sep 2026 07:25:30 +0200 Message-ID: <4a210e907972f476c87fbfefe502735abd230dce.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:58 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244864 From: Jaipaul Cheernam This patch applies the upstream fix as referenced in [1], using the commit shown in [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2025-40909 [2] https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal [YC: CVE-2025-40909.patch is not merged on a main branch but was provided by upstream to facilitate backport (Thanks!) https://github.com/Perl/perl5/issues/23010#issuecomment-2919448987 ] --- .../perl-cross/files/CVE-2025-40909-dep.patch | 25 ++ .../perl-cross/perlcross_1.6.2.bb | 1 + .../perl/files/CVE-2025-40909.patch | 412 ++++++++++++++++++ meta/recipes-devtools/perl/perl_5.38.4.bb | 1 + 4 files changed, 439 insertions(+) create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch diff --git a/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch b/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch new file mode 100644 index 00000000000..d5d4bf279d2 --- /dev/null +++ b/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch @@ -0,0 +1,25 @@ +From f702c387e6940fab3801d7562a668b974a2b3a8f Mon Sep 17 00:00:00 2001 +From: Audrey Dutcher +Date: Fri, 30 May 2025 12:29:54 -0700 +Subject: [PATCH] add d_fdopendir configuration + +Upstream-Status: Submitted [https://github.com/arsv/perl-cross/pull/159] +Signed-off-by: Jaipaul Cheernam +--- + cnf/configure_func.sh | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/cnf/configure_func.sh b/cnf/configure_func.sh +index 4c13e4c..b24fe03 100644 +--- a/cnf/configure_func.sh ++++ b/cnf/configure_func.sh +@@ -83,6 +83,7 @@ checkfunc d_fchmodat 'fchmodat' "0,NULL,0,0" 'unistd.h sys/stat.h' + checkfunc d_fchown 'fchown' "0,0,0" 'unistd.h' + checkfunc d_fcntl 'fcntl' "0,0" 'unistd.h fcntl.h' + checkfunc d_fdclose 'fdclose' "NULL,NULL" 'stdio.h' ++checkfunc d_fdopendir 'fdopendir' "0" 'dirent.h' + checkfunc d_ffs 'ffs' "0" 'strings.h' + checkfunc d_ffsl 'ffsl' "0" 'strings.h' + checkfunc d_fgetpos 'fgetpos' "NULL, 0" 'stdio.h' +-- +2.43.0 diff --git a/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb b/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb index e4bd90c5723..1c5fc27d97b 100644 --- a/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb +++ b/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb @@ -15,6 +15,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${PV}/perl-cross-${PV}.tar.gz;name=perl-c file://0001-perl-cross-add-LDFLAGS-when-linking-libperl.patch \ file://determinism.patch \ file://0001-Makefile-check-the-file-if-patched-or-not.patch \ + file://CVE-2025-40909-dep.patch \ " GITHUB_BASE_URI = "https://github.com/arsv/perl-cross/releases/" diff --git a/meta/recipes-devtools/perl/files/CVE-2025-40909.patch b/meta/recipes-devtools/perl/files/CVE-2025-40909.patch new file mode 100644 index 00000000000..c9418a3574d --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2025-40909.patch @@ -0,0 +1,412 @@ +From 918bfff86ca8d6d4e4ec5b30994451e0bd74aba9 Mon Sep 17 00:00:00 2001 +From: Leon Timmermans +Date: Fri, 23 May 2025 15:40:41 +0200 +Subject: [PATCH] CVE-2025-40909: Clone dirhandles without fchdir + +This uses fdopendir and dup to dirhandles. This means it won't change +working directory during thread cloning, which prevents race conditions +that can happen if a third thread is active at the same time. + +CVE: CVE-2025-40909 +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9] +Signed-off-by: Jaipaul Cheernam +--- + Configure | 6 ++ + Cross/config.sh-arm-linux | 1 + + Cross/config.sh-arm-linux-n770 | 1 + + Porting/Glossary | 5 ++ + Porting/config.sh | 1 + + config_h.SH | 6 ++ + configure.com | 1 + + plan9/config_sh.sample | 1 + + sv.c | 91 +---------------------------- + t/op/threads-dirh.t | 104 +-------------------------------- + win32/config.gc | 1 + + win32/config.vc | 1 + + 12 files changed, 28 insertions(+), 191 deletions(-) + +diff --git a/Configure b/Configure +index 44c12ced4014..7a13249caa96 100755 +--- a/Configure ++++ b/Configure +@@ -478,6 +478,7 @@ d_fd_set='' + d_fds_bits='' + d_fdclose='' + d_fdim='' ++d_fdopendir='' + d_fegetround='' + d_ffs='' + d_ffsl='' +@@ -13344,6 +13345,10 @@ esac + set i_fcntl + eval $setvar + ++: see if fdopendir exists ++set fdopendir d_fdopendir ++eval $inlibc ++ + : see if fork exists + set fork d_fork + eval $inlibc +@@ -25052,6 +25057,7 @@ d_flockproto='$d_flockproto' + d_fma='$d_fma' + d_fmax='$d_fmax' + d_fmin='$d_fmin' ++d_fdopendir='$d_fdopendir' + d_fork='$d_fork' + d_fp_class='$d_fp_class' + d_fp_classify='$d_fp_classify' +diff --git a/Cross/config.sh-arm-linux b/Cross/config.sh-arm-linux +index bfa0b00d5f0f..9e056539198b 100644 +--- a/Cross/config.sh-arm-linux ++++ b/Cross/config.sh-arm-linux +@@ -212,6 +212,7 @@ d_fd_macros='define' + d_fd_set='define' + d_fdclose='undef' + d_fdim='undef' ++d_fdopendir=undef + d_fds_bits='undef' + d_fegetround='define' + d_ffs='undef' +diff --git a/Cross/config.sh-arm-linux-n770 b/Cross/config.sh-arm-linux-n770 +index 47ad5c37e3fd..365e4c4f9671 100644 +--- a/Cross/config.sh-arm-linux-n770 ++++ b/Cross/config.sh-arm-linux-n770 +@@ -211,6 +211,7 @@ d_fd_macros='define' + d_fd_set='define' + d_fdclose='undef' + d_fdim='undef' ++d_fdopendir=undef + d_fds_bits='undef' + d_fegetround='define' + d_ffs='undef' +diff --git a/Porting/Glossary b/Porting/Glossary +index bb505c653b0b..8b2965ca99c6 100644 +--- a/Porting/Glossary ++++ b/Porting/Glossary +@@ -947,6 +947,11 @@ d_fmin (d_fmin.U): + This variable conditionally defines the HAS_FMIN symbol, which + indicates to the C program that the fmin() routine is available. + ++d_fdopendir (d_fdopendir.U): ++ This variable conditionally defines the HAS_FORK symbol, which ++ indicates that the fdopen routine is available to open a ++ directory descriptor. ++ + d_fork (d_fork.U): + This variable conditionally defines the HAS_FORK symbol, which + indicates to the C program that the fork() routine is available. +diff --git a/Porting/config.sh b/Porting/config.sh +index a921f7e1c79a..6231ea0f31ea 100644 +--- a/Porting/config.sh ++++ b/Porting/config.sh +@@ -223,6 +223,7 @@ d_fd_macros='define' + d_fd_set='define' + d_fdclose='undef' + d_fdim='define' ++d_fdopendir='define' + d_fds_bits='define' + d_fegetround='define' + d_ffs='define' +diff --git a/config_h.SH b/config_h.SH +index da0f2dbcd7b7..5a0f81cf2011 100755 +--- a/config_h.SH ++++ b/config_h.SH +@@ -142,6 +142,12 @@ sed <$CONFIG_H -e 's!^#undef\(.*/\)\*!/\*#define\1 \*!' -e 's!^#un + */ + #$d_fcntl HAS_FCNTL /**/ + ++/* HAS_FDOPENDIR: ++ * This symbol, if defined, indicates that the fdopen routine is ++ * available to open a directory descriptor. ++ */ ++#$d_fdopendir HAS_FDOPENDIR /**/ ++ + /* HAS_FGETPOS: + * This symbol, if defined, indicates that the fgetpos routine is + * available to get the file position indicator, similar to ftell(). +diff --git a/configure.com b/configure.com +index 99527c180bfc..7c38711bb85d 100644 +--- a/configure.com ++++ b/configure.com +@@ -6010,6 +6010,7 @@ $ WC "d_fd_set='" + d_fd_set + "'" + $ WC "d_fd_macros='define'" + $ WC "d_fdclose='undef'" + $ WC "d_fdim='" + d_fdim + "'" ++$ WC "d_fdopendir='undef'" + $ WC "d_fds_bits='define'" + $ WC "d_fegetround='undef'" + $ WC "d_ffs='undef'" +diff --git a/plan9/config_sh.sample b/plan9/config_sh.sample +index 636acbdf6db3..246bad954424 100644 +--- a/plan9/config_sh.sample ++++ b/plan9/config_sh.sample +@@ -212,6 +212,7 @@ d_fd_macros='undef' + d_fd_set='undef' + d_fdclose='undef' + d_fdim='undef' ++d_fdopendir=undef + d_fds_bits='undef' + d_fegetround='undef' + d_ffs='undef' +diff --git a/sv.c b/sv.c +index ae6d09dea28a..8a005b2d165b 100644 +--- a/sv.c ++++ b/sv.c +@@ -14096,15 +14096,6 @@ Perl_dirp_dup(pTHX_ DIR *const dp, CLONE_PARAMS *const param) + { + DIR *ret; + +-#if defined(HAS_FCHDIR) && defined(HAS_TELLDIR) && defined(HAS_SEEKDIR) +- DIR *pwd; +- const Direntry_t *dirent; +- char smallbuf[256]; /* XXX MAXPATHLEN, surely? */ +- char *name = NULL; +- STRLEN len = 0; +- long pos; +-#endif +- + PERL_UNUSED_CONTEXT; + PERL_ARGS_ASSERT_DIRP_DUP; + +@@ -14116,89 +14107,13 @@ Perl_dirp_dup(pTHX_ DIR *const dp, CLONE_PARAMS *const param) + if (ret) + return ret; + +-#if defined(HAS_FCHDIR) && defined(HAS_TELLDIR) && defined(HAS_SEEKDIR) ++#ifdef HAS_FDOPENDIR + + PERL_UNUSED_ARG(param); + +- /* create anew */ +- +- /* open the current directory (so we can switch back) */ +- if (!(pwd = PerlDir_open("."))) return (DIR *)NULL; +- +- /* chdir to our dir handle and open the present working directory */ +- if (fchdir(my_dirfd(dp)) < 0 || !(ret = PerlDir_open("."))) { +- PerlDir_close(pwd); +- return (DIR *)NULL; +- } +- /* Now we should have two dir handles pointing to the same dir. */ +- +- /* Be nice to the calling code and chdir back to where we were. */ +- /* XXX If this fails, then what? */ +- PERL_UNUSED_RESULT(fchdir(my_dirfd(pwd))); ++ ret = fdopendir(dup(my_dirfd(dp))); + +- /* We have no need of the pwd handle any more. */ +- PerlDir_close(pwd); +- +-#ifdef DIRNAMLEN +-# define d_namlen(d) (d)->d_namlen +-#else +-# define d_namlen(d) strlen((d)->d_name) +-#endif +- /* Iterate once through dp, to get the file name at the current posi- +- tion. Then step back. */ +- pos = PerlDir_tell(dp); +- if ((dirent = PerlDir_read(dp))) { +- len = d_namlen(dirent); +- if (len > sizeof(dirent->d_name) && sizeof(dirent->d_name) > PTRSIZE) { +- /* If the len is somehow magically longer than the +- * maximum length of the directory entry, even though +- * we could fit it in a buffer, we could not copy it +- * from the dirent. Bail out. */ +- PerlDir_close(ret); +- return (DIR*)NULL; +- } +- if (len <= sizeof smallbuf) name = smallbuf; +- else Newx(name, len, char); +- Move(dirent->d_name, name, len, char); +- } +- PerlDir_seek(dp, pos); +- +- /* Iterate through the new dir handle, till we find a file with the +- right name. */ +- if (!dirent) /* just before the end */ +- for(;;) { +- pos = PerlDir_tell(ret); +- if (PerlDir_read(ret)) continue; /* not there yet */ +- PerlDir_seek(ret, pos); /* step back */ +- break; +- } +- else { +- const long pos0 = PerlDir_tell(ret); +- for(;;) { +- pos = PerlDir_tell(ret); +- if ((dirent = PerlDir_read(ret))) { +- if (len == (STRLEN)d_namlen(dirent) +- && memEQ(name, dirent->d_name, len)) { +- /* found it */ +- PerlDir_seek(ret, pos); /* step back */ +- break; +- } +- /* else we are not there yet; keep iterating */ +- } +- else { /* This is not meant to happen. The best we can do is +- reset the iterator to the beginning. */ +- PerlDir_seek(ret, pos0); +- break; +- } +- } +- } +-#undef d_namlen +- +- if (name && name != smallbuf) +- Safefree(name); +-#endif +- +-#ifdef WIN32 ++#elif defined(WIN32) + ret = win32_dirp_dup(dp, param); + #endif + +diff --git a/t/op/threads-dirh.t b/t/op/threads-dirh.t +index bb4bcfc14184..14c399ca19cd 100644 +--- a/t/op/threads-dirh.t ++++ b/t/op/threads-dirh.t +@@ -13,16 +13,12 @@ BEGIN { + skip_all_if_miniperl("no dynamic loading on miniperl, no threads"); + skip_all("runs out of memory on some EBCDIC") if $ENV{PERL_SKIP_BIG_MEM_TESTS}; + +- plan(6); ++ plan(1); + } + + use strict; + use warnings; + use threads; +-use threads::shared; +-use File::Path; +-use File::Spec::Functions qw 'updir catdir'; +-use Cwd 'getcwd'; + + # Basic sanity check: make sure this does not crash + fresh_perl_is <<'# this is no comment', 'ok', {}, 'crash when duping dirh'; +@@ -31,101 +27,3 @@ fresh_perl_is <<'# this is no comment', 'ok', {}, 'crash when duping dirh'; + async{}->join for 1..2; + print "ok"; + # this is no comment +- +-my $dir; +-SKIP: { +- skip "telldir or seekdir not defined on this platform", 5 +- if !$Config::Config{d_telldir} || !$Config::Config{d_seekdir}; +- my $skip = sub { +- chdir($dir); +- chdir updir; +- skip $_[0], 5 +- }; +- +- if(!$Config::Config{d_fchdir} && $^O ne "MSWin32") { +- $::TODO = 'dir handle cloning currently requires fchdir on non-Windows platforms'; +- } +- +- my @w :shared; # warnings accumulator +- local $SIG{__WARN__} = sub { push @w, $_[0] }; +- +- $dir = catdir getcwd(), "thrext$$" . int rand() * 100000; +- +- rmtree($dir) if -d $dir; +- mkdir($dir); +- +- # Create a dir structure like this: +- # $dir +- # | +- # `- toberead +- # | +- # +---- thrit +- # | +- # +---- rile +- # | +- # `---- zor +- +- chdir($dir); +- mkdir 'toberead'; +- chdir 'toberead'; +- {open my $fh, ">thrit" or &$skip("Cannot create file thrit")} +- {open my $fh, ">rile" or &$skip("Cannot create file rile")} +- {open my $fh, ">zor" or &$skip("Cannot create file zor")} +- chdir updir; +- +- # Then test that dir iterators are cloned correctly. +- +- opendir my $toberead, 'toberead'; +- my $start_pos = telldir $toberead; +- my @first_2 = (scalar readdir $toberead, scalar readdir $toberead); +- my @from_thread = @{; async { [readdir $toberead ] } ->join }; +- my @from_main = readdir $toberead; +- is join('-', sort @from_thread), join('-', sort @from_main), +- 'dir iterator is copied from one thread to another'; +- like +- join('-', "", sort(@first_2, @from_thread), ""), +- qr/(?join, 'undef', +- 'cloned dir iterator that points to the end of the directory' +- ; +- } +- +- # Make sure the cloning code can handle file names longer than 255 chars +- SKIP: { +- chdir 'toberead'; +- open my $fh, +- ">floccipaucinihilopilification-" +- . "pneumonoultramicroscopicsilicovolcanoconiosis-" +- . "lopadotemachoselachogaleokranioleipsanodrimypotrimmatosilphiokarabo" +- . "melitokatakechymenokichlepikossyphophattoperisteralektryonoptokephal" +- . "liokinklopeleiolagoiosiraiobaphetraganopterygon" +- or +- chdir updir, +- skip("OS does not support long file names (and I mean *long*)", 1); +- chdir updir; +- opendir my $dirh, "toberead"; +- my $test_name +- = "dir iterators can be cloned when the next fn > 255 chars"; +- while() { +- my $pos = telldir $dirh; +- my $fn = readdir($dirh); +- if(!defined $fn) { fail($test_name); last SKIP; } +- if($fn =~ 'lagoio') { +- seekdir $dirh, $pos; +- last; +- } +- } +- is length async { scalar readdir $dirh } ->join, 258, $test_name; +- } +- +- is scalar @w, 0, 'no warnings during all that' or diag @w; +- chdir updir; +-} +-rmtree($dir); +diff --git a/win32/config.gc b/win32/config.gc +index f8776188c09c..34aa8de6ed75 100644 +--- a/win32/config.gc ++++ b/win32/config.gc +@@ -199,6 +199,7 @@ d_fd_macros='define' + d_fd_set='define' + d_fdclose='undef' + d_fdim='undef' ++d_fdopendir='undef' + d_fds_bits='define' + d_fegetround='undef' + d_ffs='undef' +diff --git a/win32/config.vc b/win32/config.vc +index 619979e22b53..536085fe94e0 100644 +--- a/win32/config.vc ++++ b/win32/config.vc +@@ -199,6 +199,7 @@ d_fd_macros='define' + d_fd_set='define' + d_fdclose='undef' + d_fdim='undef' ++d_fdopendir='undef' + d_fds_bits='define' + d_fegetround='undef' + d_ffs='undef' diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb index b4927646d75..b86c58f5402 100644 --- a/meta/recipes-devtools/perl/perl_5.38.4.bb +++ b/meta/recipes-devtools/perl/perl_5.38.4.bb @@ -23,6 +23,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-13221.patch \ file://CVE-2026-57432-01.patch \ file://CVE-2026-57432-02.patch \ + file://CVE-2025-40909.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Wed Sep 2 05:25:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97000 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 63C44C624DA for ; Wed, 2 Sep 2026 05:26:58 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5540.1788326817423894572 for ; Tue, 01 Sep 2026 22:26:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=NimucAO8; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49b8be0409fso3756525e9.2 for ; Tue, 01 Sep 2026 22:26:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326816; x=1788931616; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ijr2+4i5F5EGY2mO7ySCDGKIHa5+0V/lhIkMiOXCXOw=; b=NimucAO8WigdvHEEulHiSJ1icVSsHM5a0VMOEcjYE/AVbca1+JAd+edY7s4gfsCKtR hhj+cTfokf0st+dqgesxqpU3Yk7LQx1PDyp3DC/xcrX3XCZPTtXRzfWUrnooObHFGz1g idAS9z/rdbP9ZyGxKbUn3Rw565pnlc3L05EBA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326816; x=1788931616; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ijr2+4i5F5EGY2mO7ySCDGKIHa5+0V/lhIkMiOXCXOw=; b=GLyqk/0Kf6RPmeLyVaiWHHQTXFS6knYmAyP0jjidTlihkX1MIRwp19J5rkekx2zpgI 8S6Vy9glQjb+mnttBsNJi6rJeEhuijJ/pG7ykN/S1q54l+AtK1gCQUvbAij9RHJhIRgZ Lecrk0O0Y3CXXejJ1+g1LLj6y4+9rBilQvXqBNjGEXhSAf/58Xz+vUUP6n2tp5h7iyr/ tF6GLw+Rx1ugXTzN2HkWhqXvQ9fJFSzqPCg72sBMwsbUfd133aT7G+bfVa7UG42e/Tsj RZUIppND5+QHlO91Kv9ZP+UhGhjrlLLcHaDKzjIpw29ElVJjI2cBrtpoMGPyMo5q0tjg iJ0w== X-Gm-Message-State: AFuF++kns7CBJfiUuSjCtANdUmlKLP3EJCwb0Gn7tb/oAaMiW1v9rJTP s1KwWVtg+3KPLykQJsimRRONmsqOVJFb2sKPper0tkZHxCnFoCKXl2simuMkKbnAtgzVleDVPfL 3EmEYy+0= X-Gm-Gg: AR+sD103iVQG0/ummOgBDHK5CwpbW1yeCOEQlcffrScIUX9r8312HLBP0ISn84xCtEn a/63Y8bsaSw7E1oIa+k/h5wU87RLtz+lag8ViaaT7Xj/ijHHWerr1vuhMfLFtLOVUsZM7Sm4x/0 rqnH7uMBzhYQdiyVNS+r960EoIjG8c9fhUzp/QU8EYij/Nss0S1bOCdB9DErm7BOPyV/7MsWBks qvjATgt+DWHVwnEz6Qq8cPf6K82jAiXrN+dFlANMGy/wbKsePF6Pq6ad2jt92N34KRQPzpTxoRw gDtIeSo5rHzBIcv+H7/42pFSv5F2T8q/xQhm5pa2kuPWZHo0NfplS8zJXn/Ie2xvrdE/fUD4s+b sNlLrgosLP4Wc61f3Gk9CSYPbtGm1zcvbh4l0UWt2Rl+rvuAAQL6OgFpyOlHhz0UBad/0Pk9W/n 9TewHF4BprwxW+e/jCXxJKm/Cg6b5F+VcnzUCgvhkodI45qU5mIVfptHUuHQP2eVqsXXZC4EqzX YFQizixrKCScxAB7A== X-Received: by 2002:a05:600c:3485:b0:49b:96a0:5c00 with SMTP id 5b1f17b1804b1-49ce5842b7bmr45215135e9.13.1788326815661; Tue, 01 Sep 2026 22:26:55 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469 Date: Wed, 2 Sep 2026 07:25:31 +0200 Message-ID: <9b76cb0b22f9a0ec2877ac69ab4007f2cd2178e5.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:26:58 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244865 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. It also includes the upstream follow-up fixes referenced in [3] and [4]. These correct the trailing whitespace check introduced by the original fix and add the required include for isspace(). [1] https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58469 [3] https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf [4] https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../wget/CVE-2026-58469-regression_p1.patch | 39 ++++++++++++++ .../wget/CVE-2026-58469-regression_p2.patch | 26 +++++++++ .../wget/wget/CVE-2026-58469.patch | 53 +++++++++++++++++++ meta/recipes-extended/wget/wget_1.21.4.bb | 3 ++ 4 files changed, 121 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch new file mode 100644 index 00000000000..0f8e93c2d3c --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch @@ -0,0 +1,39 @@ +From be4edfe6d30a9db8e51215f0232d31eb92d502ec Mon Sep 17 00:00:00 2001 +From: ChenYanpan +Date: Wed, 8 Jul 2026 12:09:55 +0800 +Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix inverted + trailing-space check + +37a40fcb added an `end > beg' bound guard to prevent a buffer +underflow, but accidentally flipped the condition from `isspace' to +`!isspace'. The loop therefore walked back over non-space characters +instead of trailing whitespace, collapsing any string without a +trailing newline to "". Every Metalink/HTTP resource URL was wiped, +so wget could not follow any mirror and +testenv/Test-metalink-http.py failed ("Expected file test.meta not +found"). Restore the `isspace' condition. + +Copyright-paperwork-exempt: Yes + +CVE: CVE-2026-58469 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf] + +(cherry picked from commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf) +Signed-off-by: Hetvi Thakar +--- + src/metalink.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/metalink.c b/src/metalink.c +index 10d58cf7..9f969a60 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -1061,7 +1061,7 @@ clean_metalink_string (char **str) + /* If we are at the end of the string, search the first legit + character going backward. */ + if (*end == '\0') +- while (end > beg && !isspace(*(end - 1))) ++ while (end > beg && isspace(*(end - 1))) + end--; + + new = xmemdup0 (beg, end - beg); diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch new file mode 100644 index 00000000000..940d63e00c7 --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch @@ -0,0 +1,26 @@ +From aa412523158313619dd04d49b6f769d639e7dcc5 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Thu, 9 Jul 2026 14:50:40 +0200 +Subject: [PATCH] * src/metalink.c: Include ctype.h + +CVE: CVE-2026-58469 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1] + +(cherry picked from commit 82d945ff5dc9942b78b2bf736aac298c24fe00a1) +Signed-off-by: Hetvi Thakar +--- + src/metalink.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/metalink.c b/src/metalink.c +index 9f969a60..16933be4 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -46,6 +46,7 @@ as that of the covered work. */ + #include "c-strcase.h" + #include + #include /* For unlink. */ ++#include + #include + #ifdef HAVE_GPGME + #include diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469.patch new file mode 100644 index 00000000000..96bcb62df7c --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58469.patch @@ -0,0 +1,53 @@ +From 2442499cc090e6aa804b0295fe9f881b78df2940 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 29 Jun 2026 18:32:02 +0200 +Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix buffer + underflow + +Reported-by: TristanInSec@gmail.com + +CVE: CVE-2026-58469 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826] + +(cherry picked from commit 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826) +Signed-off-by: Hetvi Thakar +--- + src/metalink.c | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/src/metalink.c b/src/metalink.c +index eca839c2..10d58cf7 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -1041,7 +1041,6 @@ void + clean_metalink_string (char **str) + { + int c; +- size_t len; + char *new, *beg, *end; + + if (!str || !*str) +@@ -1049,7 +1048,7 @@ clean_metalink_string (char **str) + + beg = *str; + +- while ((c = *beg) && (c == '\n' || c == '\r' || c == '\t' || c == ' ')) ++ while (isspace(*beg)) + beg++; + + end = beg; +@@ -1062,12 +1061,10 @@ clean_metalink_string (char **str) + /* If we are at the end of the string, search the first legit + character going backward. */ + if (*end == '\0') +- while ((c = *(end - 1)) && (c == '\n' || c == '\r' || c == '\t' || c == ' ')) ++ while (end > beg && !isspace(*(end - 1))) + end--; + +- len = end - beg; +- +- new = xmemdup0 (beg, len); ++ new = xmemdup0 (beg, end - beg); + xfree (*str); + *str = new; + } diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb index b5f50f6c841..cb05ff34f89 100644 --- a/meta/recipes-extended/wget/wget_1.21.4.bb +++ b/meta/recipes-extended/wget/wget_1.21.4.bb @@ -2,6 +2,9 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://0002-improve-reproducibility.patch \ file://CVE-2024-38428.patch \ file://CVE-2024-10524.patch \ + file://CVE-2026-58469.patch \ + file://CVE-2026-58469-regression_p1.patch \ + file://CVE-2026-58469-regression_p2.patch \ " SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c" From patchwork Wed Sep 2 05:25:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97006 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 88370C624D3 for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5672.1788326819179254016 for ; Tue, 01 Sep 2026 22:26:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=O8T0587m; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so6490575e9.2 for ; Tue, 01 Sep 2026 22:26:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326817; x=1788931617; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=t9eZd2ld8w4iKXEGV3L0LyCFqRb8Nw0fzxb9pZfvfbA=; b=O8T0587mYPRPbET16y3IbE1SGUmLyzYppl3xzqWFPjg/MrQZ4FNBc5Sz5gW5lDmKVG BB6o5NDlyfk7tJ84pVH2Jq5ExH4ADXzXCUw1xRr+ZruySX68w608dXmHwcU74yjVJahY rlO2ZP+Fno5rY5r6FB7N1oViudol81y5U8bAc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326817; x=1788931617; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=t9eZd2ld8w4iKXEGV3L0LyCFqRb8Nw0fzxb9pZfvfbA=; b=D8wN6bxRnSR6NBlRoaRHoYF6wbyL3Yeech/dtbl69ggmX4Yf/wY5iomiUrsEcHUSJI wtntMr5taRd8KfN3g4m6AeJPy8es7I7S9Sz46ofDFIe6ggQI6PXaJpAwpLnQqP18bntX XYM/cDklWDGs8Lg2I2Doi0/KT3y11xlP7IEsFVY+Db7ENvpxsQdvZI81Qp/pMwvqhRaz EbG7TaEYcSEP+QRS4mj2/NcE3kU0Ol/Ian2X1WJO6o/vGxg396FpY+7JSebjqPzaisGz zianbHZ7cxxXHDr25aclGcUtSUSd1RXlcArVoFrQnsyQQRvikA7APolE5WWSFryL6u75 UIJA== X-Gm-Message-State: AFuF++m/6sDXZ+RF4IdpmSb4ytCrMqv6OvO8duBLPQIU7DEXO8Vu8auC HYt8YjHRvxAhADZmXf2Nh21c7hHQ2eCc63PW1+TWqnjVVVnlu6T+0K0TIVtqLoRyP89cuwJqxli xr8SmIwU= X-Gm-Gg: AR+sD10NIR57ZNS31/6EbhMQ8OTHKR3m52xu2totxRM+l9LCXHM2yxlTnXVsR7V96NE B65orPXYrqzd2iDLxRiBfWdVbZtlB9adVlWO4UH7exBxQbU9lHNjIJiwzIT+CZI5IkG9KOw74GU xBQCX31FmUq33x/57V/VmHWKc9Xc1ucxvRL8DXfRNAh0dAZpyhSdBucD+5RA0cwXhbDdAlzGvRp CGjOm7MVBfXUyUBuCh78lTXQdrbFFXh+WwkyGvvHUw/bW8QgHADwLhUFbT14aSxWUHniTgQiPtr tmsbrEAjg2eb0rOf+C6dAUtF+jcqqxDPtmw6UDb9aB/g9bifnXBQ9TH1FEE6xwU2JgKNBRZsyXm hI17L4TwOC3jV3GBr5o8XFrZkyf0MV34Oi5Nf4G7cql97uNmR2YTZqisF4OGd01OHEl5QgHxRnu eoDUCWfVkCHguS0QXLVrvULJuVBYqK0KtzXdV1b1bTFAKj7hBp8svLi9gGOuS8aQ2ssab9on0ew Oi0RBBR+C0JEDz28w== X-Received: by 2002:a05:600c:4687:b0:49c:cfad:90c1 with SMTP id 5b1f17b1804b1-49ce5819a3amr31379485e9.14.1788326817339; Tue, 01 Sep 2026 22:26:57 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471 Date: Wed, 2 Sep 2026 07:25:32 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244866 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58471 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../wget/wget/CVE-2026-58471.patch | 71 +++++++++++++++++++ meta/recipes-extended/wget/wget_1.21.4.bb | 1 + 2 files changed, 72 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58471.patch b/meta/recipes-extended/wget/wget/CVE-2026-58471.patch new file mode 100644 index 00000000000..4938e6761a5 --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58471.patch @@ -0,0 +1,71 @@ +From f419222cc7e02dea2da104b4fb5a997019bab9a9 Mon Sep 17 00:00:00 2001 +From: Arkadi Vainbrand +Date: Tue, 13 Jan 2026 12:22:04 +0200 +Subject: [PATCH] Fix buffer size handling in filename conversion + +* src/url.c (convert_fname): Fix buffer overflow. + +Copyright-paperwork-exempt: Yes + +CVE: CVE-2026-58471 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee] + +Signed-off-by: Arkadi Vainbrand +(cherry picked from commit c2640fe5171c59f87c58dc9fcb195b2d18b010ee) +Signed-off-by: Hetvi Thakar +--- + src/url.c | 20 +++++++++++++------- + 1 file changed, 13 insertions(+), 7 deletions(-) + +diff --git a/src/url.c b/src/url.c +index 68688256..6a9efe88 100644 +--- a/src/url.c ++++ b/src/url.c +@@ -1603,7 +1603,7 @@ convert_fname (char *fname) + const char *from_encoding = opt.encoding_remote; + const char *to_encoding = opt.locale; + iconv_t cd; +- size_t len, done, inlen, outlen; ++ size_t len, inlen, outlen; + char *s; + const char *orig_fname; + +@@ -1625,7 +1625,6 @@ convert_fname (char *fname) + inlen = strlen (fname); + len = outlen = inlen * 2; + converted_fname = s = xmalloc (outlen + 1); +- done = 0; + + for (;;) + { +@@ -1633,7 +1632,7 @@ convert_fname (char *fname) + if (iconv (cd, (ICONV_CONST char **) &fname, &inlen, &s, &outlen) == 0 + && iconv (cd, NULL, NULL, &s, &outlen) == 0) + { +- *(converted_fname + len - outlen - done) = '\0'; ++ *s = '\0'; + iconv_close (cd); + DEBUGP (("Converted file name '%s' (%s) -> '%s' (%s)\n", + orig_fname, from_encoding, converted_fname, to_encoding)); +@@ -1656,10 +1655,17 @@ convert_fname (char *fname) + } + else if (errno == E2BIG) /* Output buffer full */ + { +- done = len; +- len = outlen = done + inlen * 2; +- converted_fname = xrealloc (converted_fname, outlen + 1); +- s = converted_fname + done; ++ size_t used = s - converted_fname; ++ size_t newlen = used + inlen * 2 + 1; ++ ++ /* Ensure we actually grow the buffer */ ++ if (newlen <= len) ++ newlen = len * 2; ++ ++ converted_fname = xrealloc (converted_fname, newlen + 1); ++ len = newlen; ++ s = converted_fname + used; ++ outlen = len - used; + } + else /* Weird, we got an unspecified error */ + { diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb index cb05ff34f89..9c7d42bd3f0 100644 --- a/meta/recipes-extended/wget/wget_1.21.4.bb +++ b/meta/recipes-extended/wget/wget_1.21.4.bb @@ -5,6 +5,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-58469.patch \ file://CVE-2026-58469-regression_p1.patch \ file://CVE-2026-58469-regression_p2.patch \ + file://CVE-2026-58471.patch \ " SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c" From patchwork Wed Sep 2 05:25:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97004 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 57EF8C61DD6 for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5542.1788326820592137871 for ; Tue, 01 Sep 2026 22:27:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XNom0TPE; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49557167508so5864725e9.1 for ; Tue, 01 Sep 2026 22:27:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326819; x=1788931619; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gyjFMAn+Nq8k41Ha6ptbIXqVfj9LNHKTkv3o0WcXtXU=; b=XNom0TPEfxzTPoD6eAwDhVlrYVUX9+bvFhveSBR6d9re1MNsSjfzouJCvKz3aYF8sN 1wMymmIGXpMpVcvPP6A5fNEuY0ggZBlW26/WnD4dI6ZsQSFXTMSo6TBcUa2y5W+hcn+4 SXwLm0f2rMKsOWgVtuqUS9JFJPm3EkdDn4m8U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326819; x=1788931619; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gyjFMAn+Nq8k41Ha6ptbIXqVfj9LNHKTkv3o0WcXtXU=; b=LGBI/vMa1+xR/Od7G2D4nVI+V0n1yTpLx3I9YmLkQsUHEtnJl+NMUTCKMafuJQkGSf 990xLrY00Cns0Ffmvv5F5lN7D+zS+xiN5nGiKN4jNJZOx3lGEy6Z3j+o/IONYe7a5Qea KGiYT5EvF+bnNIY+m74Y//IP19FI/gR6h6EynPQsOGlivGry0k3xFT7e1Mjwz8xANOdQ OY9M4nR9FPhqfbVklU0OcpTGWGeL5OEwlTwjvH1IB8CX2fIAym+gIPLOAX2CvxMBuGgk ZDU93idrJgf+hdJY3E6X700G4LeVQ1X4GVob4BJ7EXt5sIBl/BrqaRS8EYAD27kkR0pR nWAg== X-Gm-Message-State: AFuF++mBb3t2Rs8Iz8JhWe+aI6ZrBbMIf/PufALSeQVbUhyjYnP2bGg4 wuboL97VxtKWgy9DkxcQ+xPzrcaNLXgHq4SeAO4PbffFySuB71Eu4aQWPJGU5OuU7NVbssHUd0v lUgCOI/4= X-Gm-Gg: AR+sD12vZbvsYt+nypG33cVPq3OYaIpcSx53Yfqk3McPyCxHGFl7ijZZGZVMPKV94aK d/dJTre7yfTryWlGYWJYZNMTjspJKUBgbmmy4NIJdBBx8N33N/RBEqhEFItUUTN4s7E7WXOdnUA gZQg8oBy7zs8MmTiFmezmDXklFJ5E+mbiYF72FkoVsBR1XDn1NbZFbUJotzVv6PcfPTCUWHoQRY 6fSP09oe4YaT8Edkjm0GHuWWY2ne/9m/BpA+NjUyyj7q3l5hp/r6NZ0TncbPfHKinqaBbObvzqp 2pVJGJh6+VjaYn6S8dj3D6wYrebYqge06wbeqKkF4WB7a+Vj6FAGVAuV+vKnOASHFctas5riEA5 lSywdVUl9EjgBOGsRsWwGZFvN20aXSVhIDb+/053+ygEwYvpf/J/ePDAY+ecc9Xq6TzITw+xmQ9 kWUo8rvGKJe9bU305a2QvoBHVYFs8y81O2DqpQly6LRzlJNCMNxQ+x2imaouajLnvf/oQeM9ZEy e1Yui0rHnDtBaHdiQ== X-Received: by 2002:a05:600c:6388:b0:495:52a5:8829 with SMTP id 5b1f17b1804b1-49ce583e8a8mr37404355e9.11.1788326818730; Tue, 01 Sep 2026 22:26:58 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:26:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472 Date: Wed, 2 Sep 2026 07:25:33 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244867 From: Hetvi Thakar Apply the upstream fix referenced in [2] using the commit listed in [1]. Also include the upstream follow-up commit [3], which fixes encoded entity length handling and adds regression tests. [1] https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58472 [3] https://gitlab.com/gnuwget/wget/-/commit/f76978a51ba9365e7ecaed96c1cfb73197a38ca2 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../wget/wget/CVE-2026-58472-regression.patch | 236 ++++++++++++++++++ .../wget/wget/CVE-2026-58472.patch | 77 ++++++ meta/recipes-extended/wget/wget_1.21.4.bb | 2 + 3 files changed, 315 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch new file mode 100644 index 00000000000..c82d2f2b060 --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch @@ -0,0 +1,236 @@ +From 6ab6b6d2fc2ed5e4cbb4908b9ad282110f30a688 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Thu, 2 Jul 2026 13:13:07 +0200 +Subject: [PATCH] Regression: Fix buffer overflow in html_quote_string() + +The regression has been introduced in commit dd692d9 and +is not part of any release. + +The tests allow the address sanitizer to find the issue. + +* src/convert.c: Fix string size calculation. +* tests/unit-tests.c: Added tests including tests for html_quote_string(). +* tests/unit-tests.h: Add definitions for the test functions. + +Reported-by: Trung Nguyen + +CVE: CVE-2026-58472 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/f76978a51ba9365e7ecaed96c1cfb73197a38ca2] + +(cherry picked from commit f76978a51ba9365e7ecaed96c1cfb73197a38ca2) +Signed-off-by: Hetvi Thakar +--- + src/convert.c | 148 +++++++++++++++++++++++++++++++++++++++++++-- + tests/unit-tests.c | 4 ++ + tests/unit-tests.h | 4 ++ + 3 files changed, 152 insertions(+), 4 deletions(-) + +diff --git a/src/convert.c b/src/convert.c +index 51636340..4dae497c 100644 +--- a/src/convert.c ++++ b/src/convert.c +@@ -48,6 +48,9 @@ as that of the covered work. */ + #include "css-url.h" + #include "iri.h" + #include "xstrndup.h" ++#ifdef TESTING ++#include "../tests/unit-tests.h" ++#endif + + static struct hash_table *dl_file_url_map; + struct hash_table *dl_url_file_map; +@@ -1177,13 +1180,13 @@ html_quote_string (const char *s) + for (i = 0; *s; s++) + { + if (*s == '&') +- ok = INT_ADD_OK (i, 4, &i); /* `amp;' */ ++ ok = INT_ADD_OK (i, 4 + 1, &i); /* `amp;' */ + else if (*s == '<' || *s == '>') +- ok = INT_ADD_OK (i, 3, &i); /* `lt;' and `gt;' */ ++ ok = INT_ADD_OK (i, 3 + 1, &i); /* `lt;' and `gt;' */ + else if (*s == '\"') +- ok = INT_ADD_OK (i, 5, &i); /* `quot;' */ ++ ok = INT_ADD_OK (i, 5 + 1, &i); /* `quot;' */ + else if (*s == ' ') +- ok = INT_ADD_OK (i, 4, &i); /* #32; */ ++ ok = INT_ADD_OK (i, 4 + 1, &i); /* #32; */ + else + ok = INT_ADD_OK (i, 1, &i); + +@@ -1242,6 +1245,143 @@ html_quote_string (const char *s) + return res; + } + ++#ifdef TESTING ++ ++const char * ++test_construct_relative (void) ++{ ++ static const struct { ++ const char *basefile; ++ const char *linkfile; ++ const char *expected; ++ } test_array[] = { ++ { "foo", "bar", "bar" }, ++ { "A/foo", "A/bar", "bar" }, ++ { "A/foo", "A/B/bar", "B/bar" }, ++ { "A/X/foo", "A/Y/bar", "../Y/bar" }, ++ { "X/", "Y/bar", "../Y/bar" }, ++ { "/foo", "/bar", "bar" }, ++ { "/a/b/c", "/a/b/d", "d" }, ++ { "/a/b/c", "/a/b/c/d", "c/d" }, ++ { "/a/b/c", "/a/b/c/d/e", "c/d/e" }, ++ { "/a/b/c", "/x/y/z", "../../x/y/z" }, ++ { "a/b", "c/d", "../c/d" }, ++ { "./foo", "./bar", "bar" }, ++ }; ++ ++ for (unsigned i = 0; i < countof (test_array); ++i) ++ { ++ char *result = construct_relative (test_array[i].basefile, ++ test_array[i].linkfile); ++ mu_assert ("test_construct_relative: wrong result", ++ strcmp (result, test_array[i].expected) == 0); ++ xfree (result); ++ } ++ ++ return NULL; ++} ++ ++const char * ++test_match_except_index (void) ++{ ++ static const struct { ++ const char *s1; ++ const char *s2; ++ bool expected; ++ } test_array[] = { ++ { "foo/index.html", "foo/", true }, ++ { "foo/", "foo/index.html", true }, ++ { "foo", "foo/index.html", true }, ++ { "foo", "foo/", true }, ++ { "foo", "foo", true }, ++ { "/foo/index.html", "/foo/", true }, ++ { "/foo/", "/foo/index.html", true }, ++ { "/foo", "/foo/index.html", true }, ++ { "/foo", "/foo/", true }, ++ { "foo/bar", "foo/qux", false }, ++ { "foo/bar", "bar/foo", false }, ++ }; ++ ++ for (unsigned i = 0; i < countof (test_array); ++i) ++ { ++ bool result = match_except_index (test_array[i].s1, test_array[i].s2); ++ mu_assert ("test_match_except_index: wrong result", ++ result == test_array[i].expected); ++ } ++ ++ return NULL; ++} ++ ++const char * ++test_find_fragment (void) ++{ ++ static const struct { ++ const char *input; ++ int size; ++ bool has_fragment; ++ const char *fragment; ++ } test_array[] = { ++ { "http://example.com#section", 26, true, "#section" }, ++ { "http://example.com", 18, false, NULL }, ++ { "http://example.com?a=1#frag", 24, true, "#frag" }, ++ { "http://example.com?a=1%26#frag", 28, true, "#frag" }, ++ { "http://example.com?a=1&b=2#frag", 30, true, "#frag" }, ++ { "a#b", 3, true, "#b" }, ++ { "a", 1, false, NULL }, ++ }; ++ const char *bp, *ep; ++ ++ for (unsigned i = 0; i < countof (test_array); ++i) ++ { ++ bool result = find_fragment (test_array[i].input, ++ test_array[i].size, &bp, &ep); ++ mu_assert ("test_find_fragment: wrong result", ++ result == test_array[i].has_fragment); ++ if (test_array[i].has_fragment) ++ { ++ mu_assert ("test_find_fragment: wrong fragment", bp != NULL); ++ mu_assert ("test_find_fragment: fragment mismatch", ++ strncmp (bp, test_array[i].fragment, ++ strlen (test_array[i].fragment)) == 0 && ++ ep == test_array[i].input + test_array[i].size); ++ } ++ } ++ ++ return NULL; ++} ++ ++const char * ++test_html_quote_string (void) ++{ ++ static const struct { ++ const char *input; ++ const char *expected; ++ } test_array[] = { ++ { "hello", "hello" }, ++ { "a&b", "a&b" }, ++ { "", "<tag>" }, ++ { "\"quote\"", ""quote"" }, ++ { "space here", "space here" }, ++ { "&<>\" ", "&<>" " }, ++ { "no special", "no special" }, ++ { "&&&&", "&&&&" }, ++ { "<<>>", "<<>>" }, ++ { "" , "" }, ++ }; ++ ++ for (unsigned i = 0; i < countof (test_array); ++i) ++ { ++ char *result = html_quote_string (test_array[i].input); ++ mu_assert ("test_html_quote_string: wrong result", ++ strcmp (result, test_array[i].expected) == 0); ++ xfree (result); ++ } ++ ++ return NULL; ++} ++ ++#endif /* TESTING */ ++ + /* + * vim: et ts=2 sw=2 + */ +diff --git a/tests/unit-tests.c b/tests/unit-tests.c +index 085a0321..f92d72b4 100644 +--- a/tests/unit-tests.c ++++ b/tests/unit-tests.c +@@ -66,6 +66,10 @@ all_tests(void) + mu_run_test (test_hsts_read_database); + #endif + mu_run_test (test_parse_netrc); ++ mu_run_test (test_construct_relative); ++ mu_run_test (test_match_except_index); ++ mu_run_test (test_find_fragment); ++ mu_run_test (test_html_quote_string); + + return NULL; + } +diff --git a/tests/unit-tests.h b/tests/unit-tests.h +index 16573b1c..7542660b 100644 +--- a/tests/unit-tests.h ++++ b/tests/unit-tests.h +@@ -62,6 +62,10 @@ const char *test_hsts_url_rewrite_superdomain(void); + const char *test_hsts_url_rewrite_congruent(void); + const char *test_hsts_read_database(void); + const char *test_parse_netrc(void); ++const char *test_construct_relative(void); ++const char *test_match_except_index(void); ++const char *test_find_fragment(void); ++const char *test_html_quote_string(void); + + #endif /* TEST_H */ + +-- +2.35.6 + diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58472.patch b/meta/recipes-extended/wget/wget/CVE-2026-58472.patch new file mode 100644 index 00000000000..29f6f23d07a --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58472.patch @@ -0,0 +1,77 @@ +From 7d0400b63382fbf336df9b63c787571d2df8a772 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 29 Jun 2026 19:13:15 +0200 +Subject: [PATCH] * src/convert.c (html_quote_string): Fix integer+buffer + overflow + +Reported-by: TristanInSec@gmail.com + +CVE: CVE-2026-58472 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812] + +(cherry picked from commit dd692d9cea5335b181d877ae917fe6e75587a812) +Signed-off-by: Hetvi Thakar +--- + src/convert.c | 31 ++++++++++++++++++++++++------- + 1 file changed, 24 insertions(+), 7 deletions(-) + +diff --git a/src/convert.c b/src/convert.c +index b934d49b..51636340 100644 +--- a/src/convert.c ++++ b/src/convert.c +@@ -36,6 +36,7 @@ as that of the covered work. */ + #include + #include + #include ++#include + #include "convert.h" + #include "url.h" + #include "recur.h" +@@ -1169,21 +1170,37 @@ html_quote_string (const char *s) + { + const char *b = s; + char *p, *res; +- int i; ++ size_t i; ++ int ok; + + /* Pass through the string, and count the new size. */ +- for (i = 0; *s; s++, i++) ++ for (i = 0; *s; s++) + { + if (*s == '&') +- i += 4; /* `amp;' */ ++ ok = INT_ADD_OK (i, 4, &i); /* `amp;' */ + else if (*s == '<' || *s == '>') +- i += 3; /* `lt;' and `gt;' */ ++ ok = INT_ADD_OK (i, 3, &i); /* `lt;' and `gt;' */ + else if (*s == '\"') +- i += 5; /* `quot;' */ ++ ok = INT_ADD_OK (i, 5, &i); /* `quot;' */ + else if (*s == ' ') +- i += 4; /* #32; */ ++ ok = INT_ADD_OK (i, 4, &i); /* #32; */ ++ else ++ ok = INT_ADD_OK (i, 1, &i); ++ ++ if (!ok) ++ { ++ DEBUGP (("Overflow detected in html_quote_string().\n")); ++ abort(); ++ } + } +- res = xmalloc (i + 1); ++ ++ if (!INT_ADD_OK (i, 1, &i)) ++ { ++ DEBUGP (("Overflow detected in html_quote_string().\n")); ++ abort(); ++ } ++ ++ res = xmalloc (i); + s = b; + for (p = res; *s; s++) + { +-- +2.35.6 + diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb index 9c7d42bd3f0..8ae0bcf1f05 100644 --- a/meta/recipes-extended/wget/wget_1.21.4.bb +++ b/meta/recipes-extended/wget/wget_1.21.4.bb @@ -6,6 +6,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-58469-regression_p1.patch \ file://CVE-2026-58469-regression_p2.patch \ file://CVE-2026-58471.patch \ + file://CVE-2026-58472.patch \ + file://CVE-2026-58472-regression.patch \ " SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c" From patchwork Wed Sep 2 05:25:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97003 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6D9C0C61DFD for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5673.1788326822649841758 for ; Tue, 01 Sep 2026 22:27:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Z2nNyqNs; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49b96837ca3so3741785e9.3 for ; Tue, 01 Sep 2026 22:27:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326821; x=1788931621; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=za9lQzWTsrGVpZQ9cILX/7yNl5yu3tkOJq565O1kenI=; b=Z2nNyqNs4dzepRp/ZPXTRsrkXAVg9mD5QEkRg8mA7K0D5bbsdgh4yGY54hp1CvojQD CXMIxGboVamvYuPkeGiWKoh0Tdf/BUWDUot2eRo27R/FXNV1Cos1yQFj+7iyJ6g3QLqL 8kfeG6lpYrCn8egFxlhoEm0fgTq5FFQluYxXg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326821; x=1788931621; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=za9lQzWTsrGVpZQ9cILX/7yNl5yu3tkOJq565O1kenI=; b=EGBdqNsnUD0xAYSf1RDKCm/od9W0sHBfzy9NRTybhypbeEZbXhGcky0S6Pq/1puEDX pKGW4G4jMJIXWX25/oeW748SE057RSZTUSCY7qiJPN1d0d6t4OspMS4X9/u5eK0RI9uN GIMKgp4QM3hQnqHsIxJK+jug+RWZNbRy+xc7Wjdggp1fIJR2DRoKr1aPl4ZrmXqNkDqs Lph3A6y4cWWctCte19xGhlC9GLW/FB69YLClVtq8uRdET40djG3P8MZDvORPVA6CsT9z kqu5a756DLOvZIHGf5ME0e34yYj+gvwQUXf5JkGSUDfHSdBLG3G1Nylz2i8xpFIhjBEd kV0w== X-Gm-Message-State: AFuF++mCHenMVj1GPxQ/uvNoyDhSRaAnVC6H9KOu+RJRLBMjMXBwIxOY RLB8OUyHtzSFMgrwUTS7bxeJn7W0xrrr0g7rTyWjAX+SmWiV9Lps9qbe7XDezuc2A/ZLde51top zu+CqEhU= X-Gm-Gg: AR+sD11Wzv3lunDm64/OjQT5WHYhdWV46gP6mOB6HsfN9+zY7tprv29uXB02EYhg8d2 /Hzn8oQySXSmWzzJuBB9YskFgRzPaNqMERVLwckUNuIh8epZRay/LIhyBgnnoA71q+51qgrKgKm ZAH1hWsv1lWB40MjOCXhTXLjMtDzqnIfC4kLBk/GXGsf2vL3aoydT/Z/6LEIYSsGUWfTWccxFDZ 9Cyz/sWcACbMnIm98fLEdQgz5vuzQYukMjVWYEiCgVCisFYVsC+jq6jgaBovxn9iPs1LeJ5K4rd KHznIjK0NNZluJHN7fjTkJut+63wY2oatoIAs4wJirhXQfuswXxA0Y9EmRlNI5FL3bFW1AEe1fX v1QtJcg5++83GwiJXPAiIBgZ0qH83ywgo0xtHVJDvXYN+ATr31ZipVdvJztNC/jhRwNkGpmanBE z1KrpgCQQBKRjFx7wjW7I4/hATFOIksdu38pZyjbxJDHUsB5YJSVs2m1ubjoVcH+yiLMgRmNjS0 d+js91PpVszhRb2/g== X-Received: by 2002:a05:600c:621b:b0:499:dbae:86be with SMTP id 5b1f17b1804b1-49ce58352ccmr38554005e9.14.1788326820834; Tue, 01 Sep 2026 22:27:00 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.26.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693 Date: Wed, 2 Sep 2026 07:25:34 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244868 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693 [2] https://security-tracker.debian.org/tracker/CVE-2026-55693 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-55693.patch | 88 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 89 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55693.patch b/meta/recipes-support/vim/files/CVE-2026-55693.patch new file mode 100644 index 00000000000..d35b6f5fe54 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55693.patch @@ -0,0 +1,88 @@ +From 315b35adb406138c962bcc653db95acc3c87c8ab Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Mon, 15 Jun 2026 19:39:08 +0000 +Subject: [PATCH 09/17] patch 9.2.0653: [security]: out-of-bounds write in + tree_count_words() + +Problem: [security]: a crafted spell file can drive tree_count_words() + past the end of its MAXWLEN-sized depth arrays; the descent + loop has no depth bound. +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do; apply the same guard to sug_filltree(). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq + +Supported by AI. + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7] +CVE: CVE-2026-55693 +Signed-off-by: Siddharth Doshi +--- + src/spellfile.c | 4 ++-- + src/testdir/test_spellfile.vim | 27 +++++++++++++++++++++++++++ + 2 files changed, 29 insertions(+), 2 deletions(-) + +diff --git a/src/spellfile.c b/src/spellfile.c +index 0b9536dc16..0010d9aa27 100644 +--- a/src/spellfile.c ++++ b/src/spellfile.c +@@ -645,7 +645,7 @@ tree_count_words(char_u *byts, idx_T *idxs) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper to count the words. + ++depth; +@@ -5648,7 +5648,7 @@ sug_filltree(spellinfo_T *spin, slang_T *slang) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + tword[depth++] = c; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index b72974ed07..e5f8c5778f 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1166,4 +1166,31 @@ func Test_mkspell_empty_dic() + endfunc + + ++func Test_spell_sug_tree_count_words_overflow() ++ " A crafted .spl/.sug pair with a BY_INDEX self-cycle in the fold word tree ++ " parses cleanly (shared refs aren't recursed, so read_tree_node()'s depth ++ " cap never trips), but drove tree_count_words() past its MAXWLEN-sized depth ++ " arrays -> stack out-of-bounds write. The walk only happens when ++ " spellsuggest() loads the matching .sug. Reaching the assert == no OOB. ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_SUGFILE(ts), SN_END, LWORDTREE{node:1,BY_INDEX->0,'A'}, ++ " empty KWORDTREE/PREFIXTREE ++ let spl = eval('0z56494D7370656C6C320B0000000008000000001234' ++ \ .. '5678FF000000020101000000410000000000000000') ++ " VIMsug + v1, matching ts, SUGWORDTREE word "a", empty SUGTABLE ++ let sug = 0z56494D737567010000000012345678000000040161010000000000 ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ call writefile(sug, 'Xrtp/spell/xx.utf-8.sug', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ " Unpatched: OOB write here (ASan abort, or crash). Patched: returns a list. ++ call assert_equal(v:t_list, type(spellsuggest('helloo'))) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index ec2cedc965d..248160a82c2 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ + file://CVE-2026-55693.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97007 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7D57CC624D6 for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5674.1788326824513873943 for ; Tue, 01 Sep 2026 22:27:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=C8OlTaaP; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49b0dd3c9a0so3919735e9.1 for ; Tue, 01 Sep 2026 22:27:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326823; x=1788931623; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=d3SVAbhrqenkv1Ww5+v4UVLAjfI5Z3wOzn72hFwCk6g=; b=C8OlTaaPhaHNPJE2iH40Vp6z4bInxbwEkgy77mO+JDHXgPAAgS3ues4IEnRtfy1P2b +y+inMpY5kdUi3nG8T4FMNl8m/g368Pb0JULj6FFlikghU+ck9y8tZ3qVpzzKcIDvx2e bmM0Y9w9laX8CBphyw7ASl814jfHlufEn14Pw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326823; x=1788931623; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=d3SVAbhrqenkv1Ww5+v4UVLAjfI5Z3wOzn72hFwCk6g=; b=Q2U1lUwQPxP2J/SKmutejKzEosuCwog0D7qBF/9fsKaO504WDt7WMYM7+++U/mtspW fhB6U/tLXfvmXhFp4uFoHEVobWYm2hTjzDmLkGf6esMhHGnxjwCzKOZzutV3uIjZLqtM lScA2lIO8ocZZ099l809heJcKHwjTqQlUAv4GvNXXnGxw8M4OrwkbgYXCmdUZIYnpE2D nRd3TPRWRZr/uzUSQUbrA8/X1VZM35lxQk0HA76kGSRaoKy4TEVxED2fRpZup68ogiLN HRuIw8vg8tQVhYsQyH5VDuJI+C5McSw41TVxxckMs2KvOoRdyUAZf7QZuCIZGNG0Aod3 3PtA== X-Gm-Message-State: AFuF++lsk/zkVYUHB2u0YeTJsWeXsJcevugkbsonFPRQzDEMelvVWjBE pFBodK6+HlLAR6hdc0zrZEypo5MdU55ied6Js9wuCmeZLW5WidiogvPivDd4I8YLDRwcAi7hIHw lTh73VLs= X-Gm-Gg: AR+sD125/FYDYaQ3Nw7+5fAmI3bjhBLZ6TNrsebq6NMMOu565b2+3iTc1GZQd/X6GQ5 /fEU3zGLqA07aPbxFNKmma/aZO8MiOiVaVkhI8lqRD4U8J9Bsaqc8g2MLfg3fSXfGAFF6ttcMhW CbCO8X2apaoUN9ylMFRzhjJnWKcm/evqHsw/0jtyqDqh7JEZWJqNdTHmMsn8QgbWswS+JHQpV+E U8bA8SWtj9NXSLUplsalU9/Qvz+LWgJXeZG6/3EiyQN1FS4yj4XS3EryZ5f5mr2P6hyRVoPiCl2 2W+cP1MxMxKtO6RBKtFaS8QpKWSpXvFrCIglRMVyn3WlGYSOxA3gEbPnSfh6b3vsTEzZJzrTeta V7ZwtrLPFjyPO8U8/908ptuYrl72q0uK0V22QW9iQJwkEKY6zedXo/JPaEYDLCldn9JybWD3Nfx gWHDWZdvTWwrQj5pcYfSuSFzZF2rmjw8DllBxj3TuTBZhLjrLW0ruDnAkfEkSsRqU2TaqEegynw HpW0yfsSJaxwCAbiO4= X-Received: by 2002:a05:600c:1913:b0:49c:e3c3:5efd with SMTP id 5b1f17b1804b1-49ce583d6ecmr28979605e9.9.1788326822642; Tue, 01 Sep 2026 22:27:02 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892 Date: Wed, 2 Sep 2026 07:25:35 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244869 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892 [2] https://security-tracker.debian.org/tracker/CVE-2026-55892 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-55892.patch | 81 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 82 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55892.patch b/meta/recipes-support/vim/files/CVE-2026-55892.patch new file mode 100644 index 00000000000..5f46c97cfa3 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55892.patch @@ -0,0 +1,81 @@ +From f0df4a48a426bd67c0c2f5ad536000a4368cd4c0 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 20:32:21 +0000 +Subject: [PATCH 10/17] patch 9.2.0662: [security] Stack out-of-bounds write in + dump_prefixes() + +Problem: [security]: a crafted spell file with a self-referential + BY_INDEX node in the prefix tree can drive dump_prefixes() + past the end of its MAXWLEN-sized depth arrays on :spelldump + (cipher-creator) +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do (Yasuhiro Matsumoto) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241fc8633d93dff996b] +CVE: CVE-2026-55892 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spell.vim | 27 +++++++++++++++++++++++++++ + 2 files changed, 28 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 2281986435..6ef3fa899b 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -4328,7 +4328,7 @@ dump_prefixes( + } + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + prefix[depth++] = c; +diff --git a/src/testdir/test_spell.vim b/src/testdir/test_spell.vim +index 170ea57926..2a3f0e3696 100644 +--- a/src/testdir/test_spell.vim ++++ b/src/testdir/test_spell.vim +@@ -1567,4 +1567,31 @@ let g:test_data_aff_sal = [ + \"SAL Z S", + \ ] + ++" A crafted .spl with a self-referential BY_INDEX node in the PREFIXTREE drove ++" dump_prefixes() past its MAXWLEN-sized depth arrays (stack out-of-bounds ++" write). The tree parses cleanly (shared refs aren't recursed); the walk ++" happens on :spelldump. Reaching the assert means no OOB. Same class as the ++" tree_count_words() fix (9.2.0653). ++func Test_spelldump_prefixtree_overflow() ++ CheckUnix ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_PREFCOND(prefixcnt=1), SN_END, ++ " LWORDTREE word "a" with affixID=1 (so dump_prefixes runs), ++ " empty KWORDTREE, PREFIXTREE child BY_INDEX -> nodeidx 0 (self-cycle), 'A' ++ let spl = eval('0z56494D7370656C6C32030000000003000100FF00000004' ++ \ .. '0161010220010000000000000002010100000041') ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ spelldump ++ call assert_true(line('$') > 1) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 248160a82c2..07f7b7dd16c 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ file://CVE-2026-55693.patch \ + file://CVE-2026-55892.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97009 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B5428C61DFD for ; Wed, 2 Sep 2026 05:27:18 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5678.1788326829148628669 for ; Tue, 01 Sep 2026 22:27:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=nDDY968l; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49b8687630fso4317405e9.3 for ; Tue, 01 Sep 2026 22:27:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326824; x=1788931624; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sGrz6NYiJrzUJjb5sq6H3Vqb72HZT/DyugxJyfQTcEk=; b=nDDY968lKMXX1hkzkdgENV8pH9owAxL6JTgTupKilkknfDAMOT85V164Hy82XHZWFV kj49VqbbdMoVNbfs/XsIJR7c2/RY2OxKfm8xMj5Ex0oVl6hdPHUio3wJIVsgWO997Van Ak2SsEvW5f0eJanlqKzkMzD2HCT8cWLypOBAY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326824; x=1788931624; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sGrz6NYiJrzUJjb5sq6H3Vqb72HZT/DyugxJyfQTcEk=; b=VpqL9oo5PSp3AVKbKc23MZ+g6SClWLcNpzIk2SEu+PD9JMIMfHrsQv63kcFqwu0Lv6 7BRIBcFv6jOSaLlRuUDy2XAUnOQtjrwP0oc7moW/39fANskTJWykv39ZexB6zE6oPtW/ agkdCft+hQCp2HHYpAZNC9Cl+11j1cU3qxxsgyX8HD9VZlHqUpx0eK3A1WYL/d7PQ9A4 941ggyq0+GspEAgCJvC8YpvBFR1t2rRxNaNCdhbW1z1A+xBfnvMnnI+4C4FGS9xJCn0q dJDZFacgvzbf+sT0g7q6wDc96Paqb2evybDGPEmvmrVoLrnehb94OxwciuKWNM69Cf+D hNag== X-Gm-Message-State: AFuF++ni1ORihegz9sM/Ei/XwphHzklM0Fxp5Iq9Kvl74KXwj3j3k6hM ckZWviDpgYFhkkNrpKquoAscXrg31VB7VgTEYAL/eqwax/7LeKewgJVEY5odiEnZnOxXNcKrxBE 02e/z5Gg= X-Gm-Gg: AR+sD12nKvnYKhmvRZLpYiPLrHI33AR8DIETP18TQZNLxmvZAJDmnB2AzaXgZCP+W3W DBDRpoRuH3dOIGcAUsKwX1Kn8ywZJQmYIiU1dMbjm1LpXjqKkvuWeM36h4lz4tGHI0EZmLf6G81 OFqCe0MH2TycFlfVRfUsb4xTDmSGDf8mUasSj9e8QUyBFfdLa9BvW2nKVu8XUfStsHUpEv0Kghz BJv8qVwnz2Kw+iZV19EYDe1ZKmUBRnjniwAC100DN06uJ/ioEks2WQrHlxkIEdPtk/6lYdZF1Xh aNg11hswh7J6StLO2VgpsVguCnGGvHuVBox6QREJbW3/MGIqA+vRhnYD8mfY7/cNqjT1cJLq2XM Lx8kj98CowtgQv0KwaVFvPKTmGHiNSPCMnHf8gfr8s1OSTLksj51kwB/K5AHk2OltNK8M1jm1Gy EXH29mtZ1M9RoDYiGGmhWcf8RxtTgfRgcLNKsqryF3D8IoSaKhPVimAz2aqxJtkIi5vbyYd448Q VHaGz/f9b80yEktsQ== X-Received: by 2002:a05:600c:3b07:b0:496:bffb:fb7b with SMTP id 5b1f17b1804b1-49ce5823706mr32063605e9.10.1788326823963; Tue, 01 Sep 2026 22:27:03 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895 Date: Wed, 2 Sep 2026 07:25:36 +0200 Message-ID: <87b2def5858ea51650b1e0381ed104d5670c50b1.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244873 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895 [2] https://security-tracker.debian.org/tracker/CVE-2026-55895 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-55895.patch | 53 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch new file mode 100644 index 00000000000..0084006b72d --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch @@ -0,0 +1,53 @@ +From 0d286458d71ff7b4d759621dd9a567aa9354819a Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 21:00:28 +0000 +Subject: [PATCH 11/17] patch 9.2.0663: [security]: runtime(netrw): code + injection in local file deletion + +Problem: [security]: s:NetrwLocalRmFile() escapes only the backslash in + the file name before passing it to :execute, so a name + containing "|" injects arbitrary Ex commands when the file is + deleted (cipher-creator) +Solution: Use fnameescape() to correctly escape the file name + (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2] +CVE: CVE-2026-55895 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 9014ca339b..af43f469d1 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -3025,7 +3025,7 @@ function s:NetrwBrowse(islocal,dirname) + elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"' + " s:NetrwBrowse : remote regular file handler {{{3 + if bufname(dirname) != "" +- exe "NetrwKeepj b ".bufname(dirname) ++ exe "NetrwKeepj b ".fnameescape(bufname(dirname)) + else + " attempt transfer of remote regular file + +@@ -8737,7 +8737,7 @@ function s:NetrwLocalRmFile(path, fname, all) + call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile)) + else + " Remove file only if there are no pending changes +- execute printf('silent! bwipeout %s', rmfile) ++ execute printf('silent! bwipeout %s', fnameescape(rmfile)) + endif + + elseif dir && (all || empty(ok)) +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 07f7b7dd16c..bd1d52eaf67 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-47167.patch \ file://CVE-2026-55693.patch \ file://CVE-2026-55892.patch \ + file://CVE-2026-55895.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97005 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 955F7C624D7 for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5544.1788326827308028214 for ; Tue, 01 Sep 2026 22:27:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2Z87LDQ3; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so6491575e9.2 for ; Tue, 01 Sep 2026 22:27:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326825; x=1788931625; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7WEpviTguFZ5mTWL692eDw+N9GHxJmERu+9JJ+O1AXY=; b=2Z87LDQ3Ssb/OEvLL+9+M5ij4dvX/ZZ0YnIQRPcelCouS2w8k8qtSom99mq/cCAuvJ b3ZGBEnLotszyS2Op+hyez6C9mA2dJKC52CCF5/8/XcsBY3Ry4VOU3fCuuyMVqx3DNL7 /fpkObS5TeDC84igWCPx5JLso9IRW0N5j7P5I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326825; x=1788931625; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7WEpviTguFZ5mTWL692eDw+N9GHxJmERu+9JJ+O1AXY=; b=M5pHMpiVl7/NyWr0oWzaOdX8efOfKMMx3Wo1O+hA9M7kgpAZ73pzRZqBJ6EJu0b640 rnhZzv8qj3B36UIHiBfgyl7fgTbkJmfmrpHLio/35TxisGALM71/kqX1E9fMxe45G60e Euu4lKfzJYwZht+OXkWXR+IDFDzcbiPOrx3Z9MyJotVE634v6PEFCN94GODX+QGR6n63 0Nc/8aIyhGU6p7RSDFKuLMhEULt1RM6co4QjC5NHSbXpKw8uIE6RYX3f0fServ0JzoQm BX/jaqRfhWnBLsEXIDdrcFmddIC6qTJnvxNW6uZ4SWU4Nglug2krLVccxUdasuPHWwD9 u5CA== X-Gm-Message-State: AFuF++mi91MIcbJTEvLSMW4pWI7LOufWo9NcM26AcLExcjqgNZ7PS2Ta UkvFb9us9eeECltJ5LCu4SWFQDQ2izZWOWXNcVuVjIgLTq3CxtQ7IfmqSfZ0uMqDaeduYGZEpgf XuZt3jYs= X-Gm-Gg: AR+sD10P4135BRMYLhZEHazuG9a1vDkxQbWvzZ+sC+wodtrEosOsbJ7IPD5ZwYVmtfM xxTL4elSAN0o7XFTPUhnhKVf+WIvOAY1vCLFshRO3IhH/h9tVcWv9qvGdV+k4RTGBhzvbDjox2o CBUZDymeatUUe3jVFsVi/6H9XWXQknwDx+Is2ewQfwc1cMaZ7FB9oqsETSwH12pLkCAK4qMHKj0 Xuo+uWNIVRdruVQT/AKjJMSnmhk8rdJOl4Osx052qDGo7f1g9IBDJ7KcbgwkpriGUNx5z+CdHAu GqvZ/B3ChS3yql0wFVC6rn17tWniZ3W7OcvHq11SJT6pBR2xwdTuCgr2VsKMYy94Io8AAK6abSP p0cSft3rPylYs4szoBWykcH81gXKDunGYCC6B2VyW0/oLKT6Sd6TjOV3ybuerko+bs4V+j/nV9x z/hDFjPYc/rP7ZGer/M8rfwmoiJLgXO9doBPET8oQn+oEV8ZtKdIIG0ZHudJgpnsnUStAvxsUsH krG11OsWUdld7Fk0w== X-Received: by 2002:a05:600c:3b1b:b0:499:db27:7b1 with SMTP id 5b1f17b1804b1-49ce5823d39mr33854635e9.15.1788326825585; Tue, 01 Sep 2026 22:27:05 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452 Date: Wed, 2 Sep 2026 07:25:37 +0200 Message-ID: <140b752df903df36a10ffeb1f2bca7b2e3bb8a06.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244870 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452 [2] https://security-tracker.debian.org/tracker/CVE-2026-57452 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-57452.patch | 76 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 77 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57452.patch b/meta/recipes-support/vim/files/CVE-2026-57452.patch new file mode 100644 index 00000000000..aaefbe80eb7 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57452.patch @@ -0,0 +1,76 @@ +From c8777cec25dcfae89c42e9aff51af61f71c5745f Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 18 Jun 2026 18:41:16 +0000 +Subject: [PATCH] patch 9.2.0671: [security]: possible out-of-bounds read with + sodium encrypted files + +Problem: [security]: possible out-of-bounds read with sodium encrypted + files (cipher-creator) +Solution: Verify that there is enough space before calling + crypto_secretstream_xchacha20poly1305_init_pull() + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f] +CVE: CVE-2026-57452 +Signed-off-by: Siddharth Doshi +--- + src/crypt.c | 3 ++- + src/testdir/test_crypt.vim | 24 ++++++++++++++++++++++++ + 2 files changed, 26 insertions(+), 1 deletion(-) + +diff --git a/src/crypt.c b/src/crypt.c +index 55edd6c6de..a11d204e5e 100644 +--- a/src/crypt.c ++++ b/src/crypt.c +@@ -1257,7 +1257,8 @@ crypt_sodium_buffer_decode( + + if (sod_st->count == 0) + { +- if (crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, ++ if (len < crypto_secretstream_xchacha20poly1305_HEADERBYTES || ++ crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, + from, sod_st->key) != 0) + { + emsg(_(e_libsodium_decryption_failed_header_incomplete)); +diff --git a/src/testdir/test_crypt.vim b/src/testdir/test_crypt.vim +index 4a96c30702..151a4dea17 100644 +--- a/src/testdir/test_crypt.vim ++++ b/src/testdir/test_crypt.vim +@@ -459,4 +459,28 @@ func Test_crypt_set_key_disallow_append_subtract() + bwipe! + endfunc + ++func Test_crypt_sodium_short_body() ++ CheckFeature sodium ++ " A VimCrypt~04! file with a complete 36-byte header (12 magic + 16 salt + ++ " 8 seed) but a body shorter than one secretstream header (24 bytes) used to ++ " underflow the body length and crash with a wild out-of-bounds read in ++ " crypto_secretstream_xchacha20poly1305_pull(). It must now fail cleanly. ++ " Bytes: "VimCrypt~04!" + 16 salt + 8 seed + 8-byte body = 44 bytes. ++ call writefile(0z56696D43727970747E303421 ++ \ + 0zA0A1A2A3A4A5A6A7A8A9AAABACADAEAF ++ \ + 0zB0B1B2B3B4B5B6B7 ++ \ + 0z0000000000000000, 'Xtest_sodium_short') ++ ++ let v:errmsg = '' ++ try ++ call feedkeys(":split Xtest_sodium_short\foobar\", "xt") ++ catch /^Vim\%((\S\+)\)\=:E1198:/ ++ " no-op ++ endtry ++ ++ bwipe! ++ call delete('Xtest_sodium_short') ++ set key= ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index bd1d52eaf67..567da7be0cf 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55693.patch \ file://CVE-2026-55892.patch \ file://CVE-2026-55895.patch \ + file://CVE-2026-57452.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97008 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BCA31C624D8 for ; Wed, 2 Sep 2026 05:27:08 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5677.1788326828131406511 for ; Tue, 01 Sep 2026 22:27:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DUjqzkMQ; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso5308665e9.0 for ; Tue, 01 Sep 2026 22:27:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326826; x=1788931626; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fsU+IIM1Lz+o3k3lueCbhCom523fjcbdfRpS5O32Z0U=; b=DUjqzkMQ3jmon/oIAeXd+wSCeHfZ4U5B/Pdaqjokv6VaSJkbJPK9kwHb6avwgDkkHD OpnM6ZjLBpB0XQ4ffJT/Gvtr+q5P0SS1aJ5MrVylOZySy9BnA98PwIbFKDNn8ra+fv/d FBqonhc6w2a39ET8iHBj1dg/1X5RYaWEqMlv0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326826; x=1788931626; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fsU+IIM1Lz+o3k3lueCbhCom523fjcbdfRpS5O32Z0U=; b=FLvaOMEAAP4T8jt/M9bR8RKQwjHriIJBu7uVcSBSpTnTGcGjuYlJqAIiGsCuWh/0Sq SpRIEZCCC1GVciYSeJ5ka+Eab8dwLjPdQiLp2tkIXly8EXM2PNLA7F8W9TLeNgKgn0ng 5f3DY51uFHJCWyLeLKeuxEh0+nqr11Rv8le7GySzoCHZXh59ZJWTlltR2CQFKTrJvO1t HlgPcHPgLA53DwnbsmRRvOtjpCFcBFe7BEhO6e0von0HsaUACuH86HVX/idVZLU8ObXp btHmj+yIYzHluCi11BwxuxjCn0Aq1mmBWg6kOZ01j/lZNxgNjmXNj1EaUpsB6jVvXcaf 3ECw== X-Gm-Message-State: AFuF++kNcocb8aziT7957hjkbmIUldjout9UHiEN/7dBZwfY/TC97KZq efUFbo43EsmAaQwTp3gebm60IfOy3J/s5Ml67/zE7eBVCfjApxmf26rfY6X2DOYyeX5NrS4Ur2j AXHbrQ8U= X-Gm-Gg: AR+sD11t37E+OY53+U29H4toQRXzom4QWYODXv7Zy0je5pldxLbkyU6dEQ2Pz2U4EvG iKBAobgn3vhk4lT3xq1Yu3iK07ccwF4v3Y++Funkkf4DtU8vbvGZhquRTmNpp4G+Ny5QjFksvMB WtAMoZ3vh5HKtl4ttPKjKrY2T9YawMXXfcvtLSKAw+KM551coE7mBti42m5xJRuHR376qLuQiTK 7zU6dpkt9bp+sVhTC1z+fOy/pVrYUf63/6O0HMCjIUfyfWK2o1HIG3OZteB+B7PvrknjL7dGNsR 0QUUFKeL2t0pI4x4L+b8wDk7VIayAo1itYBaQT8srWvr9z4b9uXYvnuPmtrxe9EUM3Va8keMCWw xegEoNMMEVVuJ4UViGuvpYCj/+eSqpNRk1iu4doihC9LEBwCcNNOD0NWpVyL7EUlMrcDikg0Txg LMc6OfiErS30E/rfxfZnPU3LbbCWKxw/ol9t8vtiaCSsOcSWcC0LhtbH+qHtE1eJKc24vW6MVBh cIbohb4PgGGyAuzbA== X-Received: by 2002:a05:600c:608c:b0:49c:cedc:3c36 with SMTP id 5b1f17b1804b1-49ce5826c6amr41386075e9.16.1788326826359; Tue, 01 Sep 2026 22:27:06 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455 Date: Wed, 2 Sep 2026 07:25:38 +0200 Message-ID: <91c8229fe73a22fdd07cec3db56fee2f281f1942.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244871 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455 [2] https://security-tracker.debian.org/tracker/CVE-2026-57455 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-57455.patch | 72 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch new file mode 100644 index 00000000000..722238c794a --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch @@ -0,0 +1,72 @@ +From 497d2fb19b2af9bccf139bb910e4f91b583e769d Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 21 Jun 2026 19:20:03 +0000 +Subject: [PATCH 13/17] patch 9.2.0698: [security]: Out-of-bounds write with + soundfold() + +Problem: [security]: Out-of-bounds write with soundfold() + (cipher-creator) +Solution: Add an abort condition to the for loop to validate the buffer + size. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b] +CVE: CVE-2026-57455 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++ + 2 files changed, 22 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 6ef3fa899b..a7909ef46e 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3273,7 +3273,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res) + else + { + // The sl_sal_first[] table contains the translation. +- for (s = inword; (c = *s) != NUL; ++s) ++ for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s) + { + if (VIM_ISWHITE(c)) + c = ' '; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index e5f8c5778f..d04d024911 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1193,4 +1193,25 @@ func Test_spell_sug_tree_count_words_overflow() + bwipe! + endfunc + ++" A word longer than MAXWLEN must not overflow the soundfold result buffer in ++" the single-byte SOFO branch of spell_soundfold_sofo(). ++func Test_soundfold_overflow() ++ let _enc=&enc ++ set enc=latin1 ++ call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D') ++ call writefile(['1', 'foo'], 'Xtest.dic', 'D') ++ mkspell! Xtest Xtest ++ defer delete('Xtest.latin1.spl') ++ defer delete('Xtest.latin1.sug') ++ setl spelllang=Xtest.latin1.spl spell ++ ++ " Before the fix the copy loop wrote one byte per input byte into a ++ " MAXWLEN (254) stack buffer with no upper bound, smashing the stack. ++ let sound = soundfold(repeat('ab', 300)) ++ call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN') ++ ++ set spell& spelllang& ++ let &enc = _enc ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 567da7be0cf..8794f831b05 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -45,6 +45,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55892.patch \ file://CVE-2026-55895.patch \ file://CVE-2026-57452.patch \ + file://CVE-2026-57455.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97012 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 16FE5C61DD6 for ; Wed, 2 Sep 2026 05:27:19 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5545.1788326829107051386 for ; Tue, 01 Sep 2026 22:27:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qrdp9Vor; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso5308705e9.0 for ; Tue, 01 Sep 2026 22:27:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326827; x=1788931627; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=28CJidXR0pt89WG2pQePGbrZFc3DjiVxSEQ/iuqXCaw=; b=qrdp9VorslYoXQMvWAoP4zsyX9KZltfB0yNoedt6u6IyQpFeOx564Zp6fAmFNMJFPB 0Uji4uwuKsMSpsAVpdVYEeDSugLOZSevi8f6X6l4INXCsomHhr/OOj7HJVuFUrJVrlAY 4fPWlrVmj647aqm2IKEEWo6HDL7/xRXxGyFaI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326827; x=1788931627; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=28CJidXR0pt89WG2pQePGbrZFc3DjiVxSEQ/iuqXCaw=; b=OhSU2xLzl5kyCAf6GtQEsT8QB2K8py2YWV4w5/aB6HjJBALeTsFsPefUq4RdQI2AbV 796Sv10qkAArpV2YjqUz9gfBmVsJE8I7gf99ZSdr8QE7/mx5Ufb0V2ymYU9IERQ4N6bW h+Ohv7p/BySeJW3Oux0x68wpl5VtA5KU2xkfUWxveKNJJNL3u2QY+vNcoU+vGnseTH0c yvDe+Pz4X756Ue/84GMVnfwNLVrnGTcjEHyH5Rc3xUeOQDN9c1GRGrWBZI7E44E85djl 3TQjRlUcZNrtXSjqIMFwopwql/6NEF5Vk5keret2tg7pcgHLvTGR6Pn9gCIZ51pre9Wg MxCA== X-Gm-Message-State: AFuF++ld/ttyIzc0WUGwwr/NifRfl71/LATi302wRDrLF27gVv5u8dEF mFyQI9CDO3NJdzhsFJ9ox4II7dxKvibFDUEfx1lUNdFg3iUfvtOIb1vuDXFeSllOguDxRiKbnpm XxqTKoAQ= X-Gm-Gg: AR+sD10EZPV/e4NOQiJxU9lSsTSMmL7zdpHYiS9KL9jFffM4Cc4NoloBWOCdKWic9dE KcSwdIJ8CuHB+Ac5+5l0+WRcn0FKlW6ARygZqfdOJ12mzCxYW9jfMHUL5cG2w39f71MkF792/T1 jtro6MBu/pcqNXddQIM1cOcMnSA/VGsg6HFZDFE4KwBHxu5CPL4do4XXSYW1PUjYlYoUdGTcHHL mjMTK8kuF77vWdaUKF11YsZ6vR58WOyXf3zvkaVek5dKQmWSn3qYO5uRjw9oiJmHwk6tmlJJogc i/kKZhsCUKIFDEjrBxhsAz0TWhCrHsKeOLk+ZnlhKK+ltWAWg9X6ITwkRNVysQ9gea602S5YTkq 3sdYu47ZjE6/mrT2MNfhyxWfJjWP5hUVn61glcsv86jpeNuNdJSBzrG7hpfItzU5NSG7wrPpxOl p16GdR7dj0ztPyKwbsBsXkp5iXPEI1aMP5uxiYlL/8ZoDF8eIUKWgtEkGQJZfXjf/rmyXVaSVyr TFRBmVNRG6gldfaOZBFYh0Hl91s X-Received: by 2002:a05:600c:4e44:b0:49c:dcf8:5216 with SMTP id 5b1f17b1804b1-49ce57e7f55mr39040825e9.6.1788326827249; Tue, 01 Sep 2026 22:27:07 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856 Date: Wed, 2 Sep 2026 07:25:39 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244872 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856 [2] https://security-tracker.debian.org/tracker/CVE-2026-59856 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-59856.patch | 103 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 104 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch new file mode 100644 index 00000000000..01267460d11 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch @@ -0,0 +1,103 @@ +From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 20:07:01 +0900 +Subject: [PATCH] patch 9.2.0736: potential command execution in PHP + omni-completion + +Problem: With PHP omni-completion, a crafted file can potentially + execute arbitrary commands when completing a class member. +Solution: Quote the class name before inserting it into the search() + pattern run via win_execute(). + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24] +CVE: CVE-2026-59856 +Signed-off-by: Siddharth Doshi +--- + runtime/autoload/phpcomplete.vim | 3 ++- + src/testdir/Make_all.mak | 2 ++ + src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++ + 3 files changed, 39 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_phpcomplete.vim + +diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim +index 5b4263ae45..93f7d8b450 100644 +--- a/runtime/autoload/phpcomplete.vim ++++ b/runtime/autoload/phpcomplete.vim +@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam + let result = [] + let popup_id = popup_create(a:file_lines, {'hidden': v:true}) + +- call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')') ++ call win_execute(popup_id, 'call search(' ++ \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')') + call win_execute(popup_id, "let cfline = line('.')") + call win_execute(popup_id, "call search('{')") + call win_execute(popup_id, "let endline = line('.')") +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index 0d4aeb0432..7d57b2e727 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -248,6 +248,7 @@ NEW_TESTS = \ + test_plugin_man \ + test_plugin_matchparen \ + test_plugin_python3complete \ ++ test_plugin_phpcomplete \ + test_plugin_tar \ + test_plugin_termdebug \ + test_plugin_tohtml \ +@@ -522,6 +523,7 @@ NEW_TESTS_RES = \ + test_plugin_man.res \ + test_plugin_matchparen.res \ + test_plugin_python3complete.res \ ++ test_plugin_phpcomplete.res \ + test_plugin_tar.res \ + test_plugin_termdebug.res \ + test_plugin_tohtml.res \ + +diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim +new file mode 100644 +index 0000000000..7f66be47b7 +--- /dev/null ++++ b/src/testdir/test_plugin_phpcomplete.vim +@@ -0,0 +1,35 @@ ++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim). ++ ++" A buffer class name is interpolated into a search() pattern run via ++" win_execute(). Without escaping, "'" closes the string and "|" starts a new ++" Ex command, so the name runs as an Ex command during completion. ++func Test_phpcomplete_no_exec_via_class_name() ++ unlet! g:phpcomplete_injected ++ let lines = [' 0, 'no class structure returned') ++ call assert_match('class Foo', result[0].content, ++ \ 'class body missing from returned content') ++ call assert_match('bar', result[0].content, ++ \ 'class member missing from returned content') ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 8794f831b05..37a965429a9 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -46,6 +46,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55895.patch \ file://CVE-2026-57452.patch \ file://CVE-2026-57455.patch \ + file://CVE-2026-59856.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97011 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F00DAC624D6 for ; Wed, 2 Sep 2026 05:27:18 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5679.1788326830488353188 for ; Tue, 01 Sep 2026 22:27:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=T5tts1or; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso6495425e9.1 for ; Tue, 01 Sep 2026 22:27:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326829; x=1788931629; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EmBgRNCDXo/OG0uZ++bC36kXlYedGPK4jGzp1KAZIFM=; b=T5tts1ors5GhNryJjXC2LSweeM11+3T9IlyVowpLV/sTqvGs/Fu4Tx99DqBwbwZmTE jgsxmaBLzAmgjTMzziPASsVaBJUm1jYB5WeBH5I2XNOwZ436qx0ppM5jrI5hoY8aBHPN aiiFnQGsjDSYb/26XhjOoi6ejdCzuOu0TIBcQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326829; x=1788931629; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EmBgRNCDXo/OG0uZ++bC36kXlYedGPK4jGzp1KAZIFM=; b=Hmddz4swVN3iHOcE+oHBm2CFljxMK7tRGoj5TI5tFGAuUUJxRlaPknL1agA2C8n6fs EymsgkBQe0byQH8sNrZJnRm4l9tZBfLrGpdZ84a8wSxVigLgBXsXpMxiK+L2frHtGiqL 4pwRmjDsVL4cEnEOWVm81uu/gtH+b30QY0AfCwJZW3dndJv04/dFj6x6toQomUk09p53 X4NvIxfVthHB2+Igafnch9+QyrxvEEehC0X3wnURlHe+Hsp40wkobrDtfEA2ZbyUiiAy OXDMMxPEliDBfpoxTZVvBYRIFN58pxiLjX9agMRNUBjnbLtzArI6dKWqQZRmYyduNi5u 3ekg== X-Gm-Message-State: AFuF++m7SEc4/ZLdNfZZs6y0B/9SRoNBQeACW1hg6r384wsfuiC6v+bM 2YIHgE0jCZlQzbTfoNZp7IndhUOMf5pyIpsK80lph+X3OXh5Cc9Eom1SWgwvxL7GFGK9AQMFyHI 2QdXwsx4= X-Gm-Gg: AR+sD11NxNFpFiU+K55gPFvxKE77SkoOSJFhZgPBP1y7KIgcy9w4z6Bu9uaS0dmNoNC Ieg06X2A8UTlISOa92jEa+XAZ12p94NfrFRXkjtzfl57+scduHcZDUkGjQqf/dEtkcSSXz3HJhF T+uQCvc0o7y3Apw5XlU7ju31ERBIomhBN2eUR3kO1rrZmHm4pbiiXkPGvygQs6qKDG1TaahGjkS 9pSv10CDZMuYy0gTlHKGTrddgxG4fJZoXdfq7HljLll3SXNnqATCaX5ezbFdTkx54CRLFe3do8N AAMUK7f0zbd4hxzbkEzFH5TPcVBWiiRKsgzc13yeKpXtgGTlNau0bYfHXhdZub1XQoPFu5S/Q5c ztf7seOpPtvJ5/nLfkf6uTL7DDUJbZXqBCAiqo4bGt5bSMkMapFn6pYgygLpz7gwNHECpYMejqP EKW/douWQ+dBFDgjnHq9gevWxd5FjLWUvoxnDfGlJUmtxYwVRufPa2UjHk3v9WBem97pC+x6a7j khJQ/SvdxcgV33cIg== X-Received: by 2002:a05:600c:4e86:b0:49a:77c1:d246 with SMTP id 5b1f17b1804b1-49ce5852589mr34713755e9.15.1788326828682; Tue, 01 Sep 2026 22:27:08 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857 Date: Wed, 2 Sep 2026 07:25:40 +0200 Message-ID: <65c4b003cddf3a2489118a04c3caec37c8256df7.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244874 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857 [2] https://security-tracker.debian.org/tracker/CVE-2026-59857 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-59857.patch | 110 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 111 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch new file mode 100644 index 00000000000..ed92190a954 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch @@ -0,0 +1,110 @@ +From 48287480f53acfb5e6f9172e571ed2f0508dfab2 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Mon, 22 Jun 2026 13:00:36 +0900 +Subject: [PATCH 16/17] patch 9.2.0725: [security]: Stack out-of-bounds write + in spell_soundfold_sal() + +Problem: [security]: A crafted spell file with non-collapsing SAL rules + can make soundfold() write one byte past the end of the + MAXWLEN result buffer. This is the same class of + out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698 + for the SOFO branch), found while auditing the surrounding + code. +Solution: Bound the single-byte SAL result writes and the terminating + NUL to MAXWLEN - 1, matching the SOFO branch. + +The single-byte branch of spell_soundfold_sal() guarded its writes with +"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254). The trailing +"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer +res[MAXWLEN], an off-by-one out-of-bounds write. Input is case-folded to +about 253 characters, so a 253-character argument together with a SAL map +that does not collapse (collapse_result false) reaches the boundary. + +Related to previous issue +[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4) +(9.2.0698) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2 + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30] +CVE: CVE-2026-59857 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 6 +++--- + src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++ + 2 files changed, 27 insertions(+), 3 deletions(-) + +diff --git a/src/spell.c b/src/spell.c +index a7909ef46e..05d6f0159d 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3516,7 +3516,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + // no '<' rule used + i += k - 1; + z = 0; +- while (*s != NUL && s[1] != NUL && reslen < MAXWLEN) ++ while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1) + { + if (reslen == 0 || res[reslen - 1] != *s) + res[reslen++] = *s; +@@ -3526,7 +3526,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + c = *s; + if (strstr((char *)pf, "^^") != NULL) + { +- if (c != NUL) ++ if (c != NUL && reslen < MAXWLEN - 1) + res[reslen++] = c; + STRMOVE(word, word + i + 1); + i = 0; +@@ -3545,7 +3545,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + + if (z0 == 0) + { +- if (k && !p0 && reslen < MAXWLEN && c != NUL ++ if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL + && (!slang->sl_collapse || reslen == 0 + || res[reslen - 1] != c)) + // condense only double letters +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index d04d024911..c8c7ac2642 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -383,6 +383,30 @@ func Test_spellfile_format_error() + let &rtp = save_rtp + endfunc + ++" An over-length soundfold() argument must not overflow the MAXWLEN result ++" buffer in the single-byte branch of spell_soundfold_sal(). ++func Test_spellfile_soundfold_sal_overflow() ++ let save_enc = &encoding ++ set encoding=latin1 ++ " A SAL map that appends without collapsing, so the result is not shorter ++ " than the input. ++ call writefile(['SET ISO8859-1', 'SAL collapse_result false', ++ \ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff') ++ call writefile(['2', 'hello', 'world'], 'Xsal.dic') ++ mkspell! Xsal Xsal ++ set spl=Xsal.latin1.spl spell ++ ++ " 253 input characters hit the buffer boundary; the result must not exceed ++ " MAXWLEN - 1. ++ call assert_true(strlen(soundfold(repeat('a', 253))) <= 253) ++ ++ set nospell spl& spelllang& ++ call delete('Xsal.aff') ++ call delete('Xsal.dic') ++ call delete('Xsal.latin1.spl') ++ let &encoding = save_enc ++endfunc ++ + " Test for format errors in suggest file + func Test_sugfile_format_error() + let save_rtp = &rtp +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 37a965429a9..a484a5c8405 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -47,6 +47,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-57452.patch \ file://CVE-2026-57455.patch \ file://CVE-2026-59856.patch \ + file://CVE-2026-59857.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97013 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 126DEC624D7 for ; Wed, 2 Sep 2026 05:27:19 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5680.1788326832481676606 for ; Tue, 01 Sep 2026 22:27:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=S7sCj/Mj; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49b8687630fso4318115e9.3 for ; Tue, 01 Sep 2026 22:27:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326831; x=1788931631; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wTw09VALjOWOA0j3Dd5A0kY93eSILGRHCUmWWoDq6ws=; b=S7sCj/MjX1iQXj7PAlpHDVWU0GEerFnJrSEhipl0VVu2eAmgWdA6GeA8Q6dnhNhBaa BTEswY0Yo4eiDJttvqvYHRw/0ZRrwS5MbxNQOcokJJH8ULc/CUEDThoIs6f2HBcCF1Bj L8y1iMfm/+B+N8uBB8oDDEzYfQlZ1T6lkH1go= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326831; x=1788931631; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=wTw09VALjOWOA0j3Dd5A0kY93eSILGRHCUmWWoDq6ws=; b=pUQJpdilrqyE0r5ZI9NbZGfMoU/bo70WSxFQr2VMK7RmHNE2d6CazWdX01r8j4oLD8 x8G/Rptnz+YvURBN1rY1P5Z69eiqY6l6eLwG7QPOwtdm/idmCFThY12SMHS3cWlQ9n/E 1/Z1sWahR+Xtf3q08zjb1Uo8/mGFALfrHiFta9LoLd9rhuRtTFUuv+et/Sl11gUnNu30 UPv/9O7jk86pJ6V018vasVn3cC5oje5lvRtOrpbD2N77P+MN0ECNIt6CRi35qb3f6WNr XgpTIAgEzP3hQoU7plC2fIamnH90asJig4P26VA97LS/pKbTCKgBqVqneshpUV6KZ2zo YNAg== X-Gm-Message-State: AFuF++kPUbxZ9+bLnADqSgAkVga9U2fk9Lys/STkzTTkWSfIWbJg1JE/ Aib94c5RhCFaUe8ZFk3FyrP2SEOWFQ8gvEmcyBPzwIWiZS5+kOpYRRuICWGonSDf6Lrts0QuVx0 Fe8G1dRw= X-Gm-Gg: AR+sD103Mt0NKsxOKu240bf6RmbojzZU3pn9N0jyhtLrnnOSFUBoPw5GJAWWNGCsx9K pLJyFa40Kq533yC+dhbeJLTtPe9IRHlfUtQ4cSWJ6uwHTwm1VvEeoi+EyHbjeXgMd/axBETbWPx NiG087unPprN3YVi8T8Gz0w9juLCAc2sapAMWf8szdZF48BQZVPUnoIcN/V+sQjakTKxi9MPP9A SfUJndphd5NoZCeYawV5k4Ubpoq5Dxl64N8IU8h/hEcAzS4R7TAtRNNlpdj2oy/HivkGctfTdST xMKdvOpDY0bG2Fr5/V+vstKNz1GnOZ55hmfDwGYkxvBeoEU1hpZvz5F/hYuCoUnKo9YRRbCwNaa PTCf3LZ6P6LyY/okrOdpYWc4CKiNlDmVOGcAMOmYw3JdOC1pO/9EYYcNnmEcEL7jWNuvMvUeryD rfCT/EUP1Lrim74+TbS87M0eqasdRS4YwUgn1K/I/pA/4SHH/egVSnK0dbt8DHsuawNQveKETGP Y6erAgIR/D5r4ykwQ== X-Received: by 2002:a05:600c:310e:b0:49c:e3ad:41d3 with SMTP id 5b1f17b1804b1-49ce55906cfmr27491975e9.0.1788326830660; Tue, 01 Sep 2026 22:27:10 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858 Date: Wed, 2 Sep 2026 07:25:41 +0200 Message-ID: <7a9e6b91121683b4694d11138f148bfdd3e6f97a.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244875 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858 [2] https://security-tracker.debian.org/tracker/CVE-2026-59858 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 135 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch new file mode 100644 index 00000000000..0b754ec2d34 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch @@ -0,0 +1,134 @@ +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 15:41:24 +0900 +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution + during C omni-completion + +Problem: [security]: With C omni-completion, a crafted tags file can execute + arbitrary Ex commands when completing a struct/union member + (cipher-creator) +Solution: Escape the type field before inserting it into the :vimgrep + pattern so it cannot close the pattern and start a new command + (Hirohito Higashi). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x + +Co-Authored-By: Claude Opus 4.8 (1M context) " +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e] +CVE: CVE-2026-59858 +Signed-off-by: Siddharth Doshi +--- + runtime/autoload/ccomplete.vim | 2 +- + src/testdir/Make_all.mak | 2 + + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++ + 3 files changed, 65 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_ccomplete.vim + +diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim +index cb4bb2c167..248d6f2e60 100644 +--- a/runtime/autoload/ccomplete.vim ++++ b/runtime/autoload/ccomplete.vim +@@ -593,7 +593,7 @@ def StructMembers( # {{{1 + return [] + endif + execute 'silent! keepjumps noautocmd ' +- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j ' ++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j ' + .. fnames + + qflist = getqflist() +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index 7d57b2e727..681e9b3b2a 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -242,6 +242,7 @@ NEW_TESTS = \ + test_partial \ + test_paste \ + test_perl \ ++ test_plugin_ccomplete \ + test_plugin_comment \ + test_plugin_glvs \ + test_plugin_helptoc \ +@@ -516,6 +517,7 @@ NEW_TESTS_RES = \ + test_partial.res \ + test_paste.res \ + test_perl.res \ ++ test_plugin_ccomplete.res \ + test_plugin_comment.res \ + test_plugin_glvs.res \ + test_plugin_helptoc.res \ +diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim +new file mode 100644 +index 0000000000..a635bd50bd +--- /dev/null ++++ b/src/testdir/test_plugin_ccomplete.vim +@@ -0,0 +1,62 @@ ++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim). ++ ++func s:WriteTags(lines) ++ " Mark unsorted so lookup is a linear scan regardless of entry order. ++ let tagsfile = tempname() ++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile) ++ return tagsfile ++endfunc ++ ++" A crafted typeref field is interpolated into the :vimgrep pattern in ++" StructMembers(). Without escaping, "/" closes the pattern and "|" starts a ++" new Ex command, so the field runs as an Ex command during completion. ++func Test_ccomplete_no_exec_via_typeref() ++ unlet! g:ccomplete_injected ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ call ccomplete#Complete(0, 'myvar.x') ++ ++ call assert_false(exists('g:ccomplete_injected'), ++ \ 'typeref field was executed as an Ex command during omni-completion') ++ ++ bwipe! ++ let &tags = save_tags ++ unlet! g:ccomplete_injected ++endfunc ++ ++" A legitimate typeref must still drive struct-member completion: escaping the ++" field value must not break the normal path. ++func Test_ccomplete_typeref_completion_still_works() ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct", ++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ let items = ccomplete#Complete(0, 'myvar.') ++ ++ call assert_equal(type([]), type(items), ++ \ 'ccomplete#Complete did not return a list') ++ let names = map(copy(items), 'v:val.word') ++ call assert_true(index(names, 'alpha') >= 0, ++ \ 'struct member "alpha" missing from completion: ' . string(names)) ++ call assert_true(index(names, 'beta') >= 0, ++ \ 'struct member "beta" missing from completion: ' . string(names)) ++ ++ bwipe! ++ let &tags = save_tags ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index a484a5c8405..6ef9745b574 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -48,6 +48,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-57455.patch \ file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ + file://CVE-2026-59858.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97014 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 23808C624D8 for ; Wed, 2 Sep 2026 05:27:19 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5546.1788326834200316952 for ; Tue, 01 Sep 2026 22:27:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QxltZJwA; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-499b2981a7bso5899725e9.3 for ; Tue, 01 Sep 2026 22:27:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326832; x=1788931632; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cf1f1emJTxHXT0oUSRdRqmnHXb6av4SJU441WMHAPp4=; b=QxltZJwA9yIDjVg0gKBGqIRmrwbzxNXqg4qlhT6M4gEZRrXNCZifStd7W9mHLBvD5Y AbZdx0lCZzp65MeldX3BHE3xyMDe+7aJ5o1NYcuAP/py2vdrRYPPy0lpdcRAmQOtAhYY LXVoQjPg54HUb77Lf1kN/zCfqdF2EH/kXU84o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326832; x=1788931632; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cf1f1emJTxHXT0oUSRdRqmnHXb6av4SJU441WMHAPp4=; b=GLQukcWCAV98DUWv5y4Ms3hUAsnrrBTvdphOAfDd4T5WbGowBgK0XBfdf44piL90AX 9gNtZERsvdTK4XJZBsl5CqlILuLOg4C9CMWah3M1AEk1hjIK8gL8/B9BslZJwqWfjih0 oWG0T+rWA3FnyU2vK5mR501zQa09aAIuF7uXn0tgjJT7hxlVYea10jlaMtA+BUuO7c/f PtuE1f3q23m4SDeKSFpdRMm9KE/QOlAoaLaKtvgnGdb/hz2emphA5ajdz0+NEaM3DHGd pFnRVDjIxavBubdsiomkCzgK9QyGF18v1g0UD9hsDKXNtVMwPHaD29tllVZ8732JkxkN abvw== X-Gm-Message-State: AFuF++mbagbc6BjwwV9GvLuCxkMws8ddhlDGklSvDAcmIeA2UeNS2ZkF yzU9OT3I4wr7o49qKZXJpr8vQ0SKnlG0O+bmaKHPh+Ni8goz1Th1OFz33/BlYoOKrwd5G+62nbE YVTjq0qU= X-Gm-Gg: AR+sD139CpYR48BcWOdIVHViI8BV5wQNqXpfZ1D2vJuXLi/xMZFzbWCZBeHyWC+kjQ/ T2FcivMFPnWwGbsMid9HoSDRQEl01/I8QBUkQwuKlnK1f3r2NqyNMuNUdIZQT+tRQJmZBbnRYxu f8JfcUlkxH+q7GyrOQIvorR9peEN1fHM6i20dgGkRgG+8GR+E3xAL8cUIdInPnsbNcwPA4AM53i ZOwRv9mDwagX10ufHcjUGgGtTTGPZODuNEJvh90KBQtUbjMN2tfEMwt32QgflPG4wFjtES/Exu/ un5LNapSuohNdCfRVKHvtdrbmIzmnsXuC8Te1gAxVY1jGM9pfEU/r2JdNr69RL0OTf77KZxFqaL yMwBTPImnbXWx416tWecaF33gVsosV3k38sNv5Eo6o/Y/Jp/mLndnWiFxa1AgH8dsrS3Y3b+LHq TV+/G4izjDLJPKN0zv0CArTICfDmxywui6ZUdVb7cdCCJ+ec5CbpZvluEEaqxk3ccSzyWUvdSjn b7tT2x8Yy1/4ahRWQ== X-Received: by 2002:a05:600c:699b:b0:49b:9205:45b3 with SMTP id 5b1f17b1804b1-49ce584c6femr36914935e9.15.1788326832336; Tue, 01 Sep 2026 22:27:12 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456 Date: Wed, 2 Sep 2026 07:25:42 +0200 Message-ID: <146c6244fdc0647f6c24b92cc8410da02645ee96.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244876 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456 [2] https://security-tracker.debian.org/tracker/CVE-2026-57456 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-57456.patch | 90 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch new file mode 100644 index 00000000000..b9f3fcc84d4 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch @@ -0,0 +1,90 @@ +From 911e10a2e8e677c3982d392e185b7d9b3e574401 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 21 Jun 2026 19:50:56 +0000 +Subject: [PATCH 14/17] patch 9.2.0699: [security]: possible code execution + with python complete + +Problem: [security]: possible code execution with python complete + (morningbread) +Solution: Use repr() to quote the doc strings correctly + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8] +CVE: CVE-2026-57456 +Signed-off-by: Siddharth Doshi +--- + runtime/autoload/python3complete.vim | 6 +++--- + runtime/autoload/pythoncomplete.vim | 6 +++--- + 2 files changed, 6 insertions(+), 6 deletions(-) + +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim +index 56ee636b8d..e7cd149cdd 100644 +--- a/runtime/autoload/python3complete.vim ++++ b/runtime/autoload/python3complete.vim +@@ -326,7 +326,7 @@ class Scope(object): + + def get_code(self): + str = "" +- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n' + str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n' + for sub in self.subscopes: + str += sub.get_code() +@@ -369,7 +369,7 @@ class Class(Scope): + if _DOTTED_NAME_RE.match(s.strip())] + if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers) + str += ':\n' +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + if len(self.subscopes) > 0: + for s in self.subscopes: str += s.get_code() + else: +@@ -392,7 +392,7 @@ class Function(Scope): + safe_params = [p for p in safe_params if p] + str = "%sdef %s(%s):\n" % \ + (self.currentindent(),self.name,','.join(safe_params)) +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + str += "%spass\n" % self.childindent() + return str + +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim +index 0f41405c0e..abef32faf2 100644 +--- a/runtime/autoload/pythoncomplete.vim ++++ b/runtime/autoload/pythoncomplete.vim +@@ -341,7 +341,7 @@ class Scope(object): + + def get_code(self): + str = "" +- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n' + str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n' + for sub in self.subscopes: + str += sub.get_code() +@@ -384,7 +384,7 @@ class Class(Scope): + if _DOTTED_NAME_RE.match(s.strip())] + if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers) + str += ':\n' +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + if len(self.subscopes) > 0: + for s in self.subscopes: str += s.get_code() + else: +@@ -407,7 +407,7 @@ class Function(Scope): + safe_params = [p for p in safe_params if p] + str = "%sdef %s(%s):\n" % \ + (self.currentindent(),self.name,','.join(safe_params)) +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + str += "%spass\n" % self.childindent() + return str + +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 6ef9745b574..a4f8162d31c 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -49,6 +49,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ + file://CVE-2026-57456.patch \ " PV .= ".1683" From patchwork Wed Sep 2 05:25:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97015 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3CB7BC624DA for ; Wed, 2 Sep 2026 05:27:19 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5681.1788326836180601639 for ; Tue, 01 Sep 2026 22:27:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OaZldGE9; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49b0d78a801so4189185e9.2 for ; Tue, 01 Sep 2026 22:27:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326834; x=1788931634; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IogGLwXAEIqVsXBFAXtvkAj8bKKxRhqVfVSUZCvZxA8=; b=OaZldGE9E5OzTQvDJfWik51AA6Y31emPbJDR+Sbnpx0mgX/NGvKm6/LTnNHTAgdalF B0dNL8MQwx6qxPagLhr/vHaQwZBT4TE/i39Q3Sxp9PKwJHEgPm+ndUsEiVA0lnakx4xs ftQ0gHQl80IaSJeM8hF9XeLz9Zeqq4iFzfISo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326834; x=1788931634; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IogGLwXAEIqVsXBFAXtvkAj8bKKxRhqVfVSUZCvZxA8=; b=tGZbFVOSwhXVrrQi6F57DV0Uog6gvxHeGpQynXDE3XK1KFOfm14oetBRGRrbeQLk7z TVzRdd3o+/7KJdSsUrG2yfRJ4Q1Y4Kfsn+hQT2BVgc/ludu4Iebb0Og9yJLSR2Z7yG/j jOBqvFInI0rOJOdWqAEFMPy3q63vXIvPyVBQiEwsh0OhxTXuhT0Yr5KmRqzn/UB0KV3W c5ncMC0nqGWQKzrSMFvREVDs8nDJVgGnhilUmUaPnnNwDCcMSnzdY9Hc4OrADmdqgf5G spsnzmglA2LY13WRTrSjyQcCttCU1d3PN2+rB1cz/PaN9NkE1HcoV+v4wEW89Ri2//b/ oiuA== X-Gm-Message-State: AFuF++kXZW3I0AGBNtmvpdd/dIi5zn07hz7Y75tsT6BtRtBNBmKKPECg fyVI1mVOtdVB5MnU4uvWgXWuZpONiBNAH0IBmw0X2FC2UfQ3CqspUGcaPyVDU7DGac3No9dgcn2 zekAmNIA= X-Gm-Gg: AR+sD105P2Ho7Wx/mbAyPdVNTwjmOB3jcV2JM1+9HHVATwAW454fsKGjHkkBp12Eciv E1V5OiFkjqmVvz4TXYYmnmZGflVa8IRLyRx5swo0ue6JHmhAqWgJsnRvhbU9GqYRlksZ1hEv1Hy OkLFOZRTBA2BTGlelY6U4AeAHpy1oIFYAa5pS5HDAfxliLWlHTemy+uM6ljI8440bMmnk6beI3E 2TBOBZ8sR63M69lv/RjDLMJsZX3efbpj+NspHZlQZZA2Ypkl2o5yMhi8j0u2B0kr4ZwIRCQ/0Il 1ipkrd7nPEnryZvN+ovoMdG0P9pNdmcA3cikn4IMKhqoYxtc/A3KWXYyozmF4bY04AYBnEun3z5 3r+YpnlDrO4umALwlkh6REHYjIKclyT2d+O8Zz/FzWG+ioyaigOrTqakaSoYLkvcIcn49v4AHO2 SERXZe1hPOJzyAQa1HaRJH9qfSGgV6aXTBG7lZf1yex4Zb0wu6iyrPIh/sDUp4+slytbpozDn0W rpWgkWA+waPMWe3JA== X-Received: by 2002:a05:600c:a0b:b0:49b:910c:7703 with SMTP id 5b1f17b1804b1-49ce5818612mr28058085e9.9.1788326834411; Tue, 01 Sep 2026 22:27:14 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289 Date: Wed, 2 Sep 2026 07:25:43 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244877 From: Hetvi Thakar This patch applies the upstream fix referenced by NVD in [2], using the commit shown in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56289 Signed-off-by: Hetvi Thakar Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 48c1aa91e829a87c398e8c012cde45cd8c1aab0a) Signed-off-by: Yoann Congal --- .../patch/patch/CVE-2026-56289.patch | 36 +++++++++++++++++++ meta/recipes-devtools/patch/patch_2.7.6.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch diff --git a/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch b/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch new file mode 100644 index 00000000000..cfcb2216c35 --- /dev/null +++ b/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch @@ -0,0 +1,36 @@ +From a40c835ab06314526d623e62ae27830d0ad88752 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Tue, 21 Apr 2026 13:16:10 -0700 +Subject: [PATCH] =?UTF-8?q?Don=E2=80=99t=20infloop=20on=20null=20ranges?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* src/patch.c (locate_hunk): Don’t attempt to optimize +matches of a null range. Instead, apply all the checks +we apply to non-null ranges. + +CVE: CVE-2026-56289 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9] + +(cherry picked from commit faba04ef4f2b410257f76c1b9dc85e350929c4b9) +Signed-off-by: Hetvi Thakar +--- + src/patch.c | 3 --- + 1 file changed, 3 deletions(-) + +diff --git a/src/patch.c b/src/patch.c +index b348b5c..0e8d5c9 100644 +--- a/src/patch.c ++++ b/src/patch.c +@@ -1146,9 +1146,6 @@ locate_hunk (lin fuzz) + lin max_offset = MAX(max_pos_offset, max_neg_offset); + lin min_offset; + +- if (!pat_lines) /* null range matches always */ +- return first_guess; +- + /* Do not try lines <= 0. */ + if (first_guess <= max_neg_offset) + max_neg_offset = first_guess - 1; diff --git a/meta/recipes-devtools/patch/patch_2.7.6.bb b/meta/recipes-devtools/patch/patch_2.7.6.bb index e0e44f9c977..74d9085c6b9 100644 --- a/meta/recipes-devtools/patch/patch_2.7.6.bb +++ b/meta/recipes-devtools/patch/patch_2.7.6.bb @@ -11,6 +11,7 @@ SRC_URI += "file://0001-Unset-need_charset_alias-when-building-for-musl.patch \ file://0001-Don-t-leak-temporary-file-on-failed-ed-style-patch.patch \ file://0001-Don-t-leak-temporary-file-on-failed-multi-file-ed.patch \ file://CVE-2019-20633.patch \ + file://CVE-2026-56289.patch \ " SRC_URI[md5sum] = "4c68cee989d83c87b00a3860bcd05600" From patchwork Wed Sep 2 05:25:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97010 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B6721C624D3 for ; Wed, 2 Sep 2026 05:27:18 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5548.1788326837793506149 for ; Tue, 01 Sep 2026 22:27:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=HledwrnC; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49b8f86c6deso3711645e9.0 for ; Tue, 01 Sep 2026 22:27:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788326836; x=1788931636; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QN7MDTL/f7+pm94+Q5/15el1JwGtzF10TbfDrMABNOQ=; b=HledwrnCm3AXkIihxYQFW+kT3hx30Vh1swd4wYYwQRYxkc24tVCknoHdawyFpjQpM3 5MZuKecg/dskEYVRSt0e9QC3SxrWImRtX+wKAjb0K+Gx1FR7myu3FLsfqAna06MZavJj 36WTcPROY0Sbz55oKv2jFjVFNbEypNe/5rluQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788326836; x=1788931636; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QN7MDTL/f7+pm94+Q5/15el1JwGtzF10TbfDrMABNOQ=; b=ZoeFhcv1Gt0iM5ObLji6YbfUYnK80NgCc8hLdUNNYBiVvD7BXOAuCi38p3RtzG24lZ +EY3KSdBogyuotDcQOI49/Ocyh2VtLZyiMAZlJtWsbR5XWft/sw/nDMWkxILvd+f858O 1hsdekSQa5nojB8R8p35cdWAoH0uMP3VXOugs//k7W6CGW29LlZg5eHUpkifh28EDrey YXQgsPurAzxacTrV7ne9+NrLjWLz7A7M/5zQNhzt4ylfiYBUwPOiJuVipb8IFKEvokKI TuxKGRAjRIqH9phFw8EPrOv9bahT/VSzeLBbzoHGHtlqOt1hVe+XGo66nTNmy4DqFBbg 8Kxw== X-Gm-Message-State: AFuF++kAZ2asfAtSIQN3uiDMxMLrbEe8fajjwkaUIgSKUiOCxTEh4CBT NWspaayy3o9suP7SIy7SyRcEboLhuTw6m1eBdV4CdqvF+6v/j68ewuoM8wkFVIYEF0w90/DopcT G4xME/Xo= X-Gm-Gg: AR+sD12NgwIwC+ug/80uXzR9e95Mh8ag5jYNoXXk+H90AQVoGzEgDVaV4Fztv2GwMHI mAm1+xeKgIP2PVr8zhdeLoKkGlXdC07lSSPg5fc4AVYz3lEvAdJlVjA9Fkt1HopV9x+/MTgt2pn RKLXf0q/YVAz7ca7BemF0LlLSdGc1ZZsjzPIXJZS0GbLFk+3LRvNdF/GZojJOob47CROPj8huSz EwMDVAh13RAcp/EYBprtfyaLiZkVQtiEX2zSfrzps1EzmCO3XfUyrnX27O65oWBOLx40fG2GltB JBdYcDuzxZI5+p3FOWqRB81OsEUtntFa+WLP7TLEfS0n1BJX2dQA/TyeQ0s8xXjqCv/TyMhOtfC z1TcH+yT/nY3LFf5EiA+sdrOkbv525l7kAWI582SjyY1TqSGzDbWLpX7EDbg+/eJFz7355+4XV3 HxBm6WnGJ7LjbrXGIu6cH1UrMWFUdjdkytsAOrxHKfrpBU6iHj0okoq1aQdfzqoysgejTgReGZz Oym57hJyV1eMi+oZQ== X-Received: by 2002:a05:600c:1da1:b0:499:9eb8:a1d7 with SMTP id 5b1f17b1804b1-49ce5842935mr41312845e9.9.1788326836061; Tue, 01 Sep 2026 22:27:16 -0700 (PDT) Received: from FRSMI25-LASER.wifi-gare.sncf.com ([148.169.40.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce4780f0dsm37084695e9.12.2026.09.01.22.27.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 22:27:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288 Date: Wed, 2 Sep 2026 07:25:44 +0200 Message-ID: <1b1e13055b4eed838e1411d91dea46de08e1d72f.1788326578.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 02 Sep 2026 05:27:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244878 From: Hetvi Thakar This patch applies the upstream fix referenced by NVD in [2], using the commit shown in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56288 Signed-off-by: Hetvi Thakar Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit a30cd69993f9f48d5cf55e57181e49171f0a1b7a) Signed-off-by: Yoann Congal --- .../patch/patch/CVE-2026-56288.patch | 75 +++++++++++++++++++ meta/recipes-devtools/patch/patch_2.7.6.bb | 1 + 2 files changed, 76 insertions(+) create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch diff --git a/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch b/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch new file mode 100644 index 00000000000..03e1211f2ed --- /dev/null +++ b/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch @@ -0,0 +1,75 @@ +From f98fd4b5f696d1fcc9d86f81555370cf4b21150f Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Tue, 21 Apr 2026 10:05:02 -0700 +Subject: [PATCH] Avoid null pointer derefence with bad hunks +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* src/pch.c (another_hunk): Keep chars_read positive +even with malformed hunks. + +CVE: CVE-2026-56288 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313] + +(cherry picked from commit e6d6a4e021660679d7fc9150f981d4920f722313) +Signed-off-by: Hetvi Thakar +--- + src/pch.c | 15 ++++++++++----- + 1 file changed, 10 insertions(+), 5 deletions(-) + +diff --git a/src/pch.c b/src/pch.c +index 6f9f36f..0a31f72 100644 +--- a/src/pch.c ++++ b/src/pch.c +@@ -1728,7 +1728,8 @@ another_hunk (enum diff difftype, bool rev) + p_end = filldst-1; + malformed (); + } +- chars_read -= fillsrc == p_ptrn_lines && incomplete_line (); ++ chars_read -= (1 < chars_read && fillsrc == p_ptrn_lines ++ && incomplete_line ()); + p_Char[fillsrc] = ch; + p_line[fillsrc] = s; + p_len[fillsrc++] = chars_read; +@@ -1745,7 +1746,8 @@ another_hunk (enum diff difftype, bool rev) + malformed (); + } + context++; +- chars_read -= fillsrc == p_ptrn_lines && incomplete_line (); ++ chars_read -= (1 < chars_read && fillsrc == p_ptrn_lines ++ && incomplete_line ()); + p_Char[fillsrc] = ch; + p_line[fillsrc] = s; + p_len[fillsrc++] = chars_read; +@@ -1765,7 +1767,8 @@ another_hunk (enum diff difftype, bool rev) + p_end = fillsrc-1; + malformed (); + } +- chars_read -= filldst == p_end && incomplete_line (); ++ chars_read -= (1 < chars_read && filldst == p_end ++ && incomplete_line ()); + p_Char[filldst] = ch; + p_line[filldst] = s; + p_len[filldst++] = chars_read; +@@ -1852,7 +1855,8 @@ another_hunk (enum diff difftype, bool rev) + if (buf[0] != '<' || (buf[1] != ' ' && buf[1] != '\t')) + fatal ("'<' followed by space or tab expected at line %s of patch", + format_linenum (numbuf0, p_input_line)); +- chars_read -= 2 + (i == p_ptrn_lines && incomplete_line ()); ++ chars_read -= 2 + (3 < chars_read && i == p_ptrn_lines ++ && incomplete_line ()); + p_len[i] = chars_read; + p_line[i] = savebuf (buf + 2, chars_read); + if (chars_read && ! p_line[i]) { +@@ -1897,7 +1901,8 @@ another_hunk (enum diff difftype, bool rev) + if (buf[0] != '>' || (buf[1] != ' ' && buf[1] != '\t')) + fatal ("'>' followed by space or tab expected at line %s of patch", + format_linenum (numbuf0, p_input_line)); +- chars_read -= 2 + (i == p_end && incomplete_line ()); ++ chars_read -= 2 + (3 < chars_read && i == p_end ++ && incomplete_line ()); + p_len[i] = chars_read; + p_line[i] = savebuf (buf + 2, chars_read); + if (chars_read && ! p_line[i]) { diff --git a/meta/recipes-devtools/patch/patch_2.7.6.bb b/meta/recipes-devtools/patch/patch_2.7.6.bb index 74d9085c6b9..53e96dea0f8 100644 --- a/meta/recipes-devtools/patch/patch_2.7.6.bb +++ b/meta/recipes-devtools/patch/patch_2.7.6.bb @@ -12,6 +12,7 @@ SRC_URI += "file://0001-Unset-need_charset_alias-when-building-for-musl.patch \ file://0001-Don-t-leak-temporary-file-on-failed-multi-file-ed.patch \ file://CVE-2019-20633.patch \ file://CVE-2026-56289.patch \ + file://CVE-2026-56288.patch \ " SRC_URI[md5sum] = "4c68cee989d83c87b00a3860bcd05600"