From patchwork Thu Sep 3 09:49:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97205 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 377AAC624A4 for ; Thu, 3 Sep 2026 09:50:04 +0000 (UTC) Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4183.1788429002714832160 for ; Thu, 03 Sep 2026 02:50:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=JhJQVq28; spf=pass (domain: gmail.com, ip: 209.85.210.179, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-851cbd64814so928488b3a.1 for ; Thu, 03 Sep 2026 02:50:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429002; x=1789033802; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=cJWhQ89mlZxBs0tH9Nf4DA03qSw+ZPa6DOcbs9r+6vY=; b=JhJQVq28fqNa3MF9lUIU3yEFn6p7WDDVnMkxbM4Ovr4ouvC0llSw+ZyuWrZkqfvqVD 72j0wmdDNeDKGrZo9STGlcIAon3vw+qjdt3ixi5qtK58KdbyN15P54XsaoQF1mfkNWZE sv3GBqSfuOjxpI6dmDbPiuyrokRyp5H/YcGw4kudsaI3dVnhDv8Ru70ixtndDMPXw3C8 m4tKIlpJIXVcWC+In2EyHaSzB2ZuKAt1k1egPmzkUyG6Z6Tz7zbXeOJo2AVSCPK7i16/ P2Q2HMzwFTM4JboeEiJJzD01Q7w0kkcp3x262xntaJPNfzY6J7qiKxcfU3U1FN+NBntl TyCA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429002; x=1789033802; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cJWhQ89mlZxBs0tH9Nf4DA03qSw+ZPa6DOcbs9r+6vY=; b=PcsCFqoCdzsH23jJwm86ng3cHQFmqkcJWPtpmgCXs4pWletQV/zRryY8yVaeLh3diL zGxMzc5E22iva3ZmjGKEKKvsn/HGpfqFaSRwLEiQpaPcN41+mz2//AxXOMr9k/9pidT9 qqTetOC82BhAi5M9uQLC0IMNwQZqRxfw5Sbsm1fQaQKEByNODS2BfElzOiP3wCUZrwLn dk+GkaR7LEpcwEmHhlnx4PbppWWmRdb95XfB08ynrsPph8uV5hHVUxFgD4OoaQXwVpPM 15xBEf/cqdx3mEm3tsVi+XbelPMjl2UapdbvlIhyEzyg+zIjV75RvBUijlRCarVXW1bv EDvA== X-Gm-Message-State: AFuF++l8xHbgnecoQRXVBTiRhG6C+JBCvx+tcmzDt9pcJ+q+6WHwMNLg +MvKuwgxKKEgbwx2r4EcFR+SbOYYKsM8DOj7gIInlDxW4aHaD8my7bs/TrOrZkV2 X-Gm-Gg: AYBFou2OGtlgN2eQIEMEx4FSfmu9ZbZZE60P/g23PeTDQwaNf0QiR0taW0E3+Mpu7uw vt7tKbBebmxXr8etl3v4P9P+bqEALrsrOGzgm1Div7OnGtutZ9SoDOJpPOYNZ4r/mFrbiWcrgap uNX/8kZY75Psh80HMRLrEGjUDLvlcKC2YJpVKOYzuHozNm8N52GcTdOgpWiFVEyEwlvvnODPrMz cuInE2GJ4XCultbp1znaqBAjF/W9Z6T+a4nSZU4AgN+g1YQTFDBMGbUIsOCtNEydDROlYH8PFaq eg5KjkIk+qEp8UehmplLFlfwr8GllhuhCi34a4Y4ddriwOcoI7APOmD5codpiayb9v4I6HGS0TW uJnKJqxW/7tzSHZkPymZv2HGCvj+0ZihQJgjPdmxnRoaFk9i+l6hEaqmLncInOI5uEDv6OZy618 JI3E8h4YC+C3sk5NJxBhX1KJBCqjhcLsUGhAklRZI05RsjIc+SaVvZW+oXcY44Ceb2e0vkCnzo X-Received: by 2002:a05:6a00:3d88:b0:85f:3dd6:f421 with SMTP id d2e1a72fcca58-85f3de63c41mr13387523b3a.25.1788429001929; Thu, 03 Sep 2026 02:50:01 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.49.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:01 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 Date: Thu, 3 Sep 2026 21:49:32 +1200 Message-ID: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129717 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2025-49014 Fixes: WARNING: jq-1.8.1-r0 do_sbom_cve_check_recipe: jq-1.8.1: Found unpatched CVEs: CVE-2025-49014 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-devtools/jq/jq_1.8.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb index 5d2a1be398..9d4ae74c00 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb @@ -30,6 +30,8 @@ SRC_URI = "git://github.com/jqlang/jq.git;protocol=https;branch=master;tag=jq-${ file://CVE-2026-39956.patch \ " +CVE_STATUS[CVE-2025-49014] = "fixed-version: fixed in v1.8.1" + inherit autotools ptest UPSTREAM_CHECK_GITTAGREGEX = "${BPN}-(?P\d+(\.\d+)+)" From patchwork Thu Sep 3 09:49:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97209 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 81C39C624DD for ; Thu, 3 Sep 2026 09:50:14 +0000 (UTC) Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4047.1788429005359701763 for ; Thu, 03 Sep 2026 02:50:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=GiB898LZ; spf=pass (domain: gmail.com, ip: 209.85.210.176, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-8557c3f270eso1325046b3a.3 for ; Thu, 03 Sep 2026 02:50:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429005; x=1789033805; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Lm2QpSpFvF/DJsG27XJfFjdTfYNh8kpafJ8z1pv7rcU=; b=GiB898LZQrQ+OFHf6F7TiSiQndxfdvv+XviL/EFTKFiQdX+dnyJtp0/D9AclMeKGtr nv/704eMoFo6HPrDfOXJUjWwNE8TTTN2OucODXOw9UkvZHMr1xxeMo651TJnx0uQ9tJ8 4roCh7tZ6UNrXMRqGyoR/jSvBRjIUCFWZdNsUTl5yHUSqvh+LRyojoopgN7VO/lPsbKm vRj48h1l4RALIO2r6Je9XoNL72xEHnH/Q/fhCepq908tP9TA1Qs1X2Ta/8igCYp3Vg0/ 1mpgHe+fMveEkzVNU81M9RbBnQU9kxrj53SYftOgzZCNTBjdwoW1G4JBucWwf6CQwcEE Detw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429005; x=1789033805; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Lm2QpSpFvF/DJsG27XJfFjdTfYNh8kpafJ8z1pv7rcU=; b=b0ZMuw7LfhlOQJmIhppA5Mtrq9vEf63JKwl66ze6z70SEPQU5FxYDLlNAxCJdTx1sh Lpg1qWl+uzErIUaRe+xT5ApmdzJU9NBDdIsk5FdmzckTqddJYoXjXo9bfaqG3DQcjguF mwCWJn3i6dyoFZD5ExnQLBijv1ZesYtcjaXsW8GqfNMRnJbyE3tmDlgzuHQOzbIdxZRh dl8iH4KpMnxIuV/lyp4uMicBqSAviDbC0ZwSOWx8z9ZLAXKoGVGpa6MDBtXnzOGseY4K IOZS6OJSFZ8d9GRkU72K0H0j2Spr5Mor3RLm232xilb729cSNkRyj+n+EGvpF2y26v63 GJoA== X-Gm-Message-State: AFuF++nD5fm1dORnnxR07p8Ly6nkI/9qtrSVDRevkiHtw3wFSwdzoD6K O8yTR93bGOlZHMXIACGalb23+iXRZwL+gsx8OP8BzrUnRDNoraJAdR6DyMZf3nLF X-Gm-Gg: AYBFou1XWJdY2FKyBLqvTuRWMsBokIFOgX/tpfTHGt1mmqYPTiRM7PNXqQR3xsah08u Az1RSM9PrbQzPY5iZMWulz+bmIHy/h3r/lL1Rh1Sp/9NSbPojsYiUg6VjMbzQJB+ENJXFGutiyX dKhUmIc6tr1K3Qn9d/jBxGavnyyXJLxEfSinBrpGiP8M571OKJbQpHoCS2I5h0ZVDdyMvsFwHjk nkNP3P9CoN1a0MONbNNwgo0DiUoNRtydW1XZt9UIqBWZQCw7uQncW6QXEioANbLE5ji4SV9RyC+ VQm4/66/rA+X29fgOpINZlQadfpvOVvz1bR15++vyaX2OJNvXEPbq4ffG40NNpJnAlnt42MRv+J LS9DnWRQPxw1kMdFg+qMyg6bDz+p4iFb6273x+4tK91DZmo8KQN01Z6+pVZLVFR8egoxT59n+fD oiDQXyFYkECVwER6s4EHxphGlnDl5CPqHwz+1LqANJK6fBDTLKtxTjTE/pNfm/8noQ3SMY5nJCT sm+hlcpQb0= X-Received: by 2002:a05:6a00:3021:b0:856:30dd:91ba with SMTP id d2e1a72fcca58-85ed7158015mr16779738b3a.2.1788429004612; Thu, 03 Sep 2026 02:50:04 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:03 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 Date: Thu, 3 Sep 2026 21:49:33 +1200 Message-ID: <20260903094954.3240723-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129718 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42798 Signed-off-by: Ankur Tyagi --- .../lcms/lcms/CVE-2026-42798.patch | 38 +++++++++++++++++++ meta-oe/recipes-support/lcms/lcms_2.18.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch diff --git a/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch new file mode 100644 index 0000000000..fa3f497be6 --- /dev/null +++ b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch @@ -0,0 +1,38 @@ +From e05d3427b84028854177a417572e96543a40c3eb Mon Sep 17 00:00:00 2001 +From: Marti Maria +Date: Thu, 19 Feb 2026 08:48:50 +0100 +Subject: [PATCH] Fix for ParseCube integer overflow in LUT allocation + +thanks to @zerojackyi for reporting + +(cherry picked from commit 6a686019825a89b715d16671f18d049523354176) + +CVE: CVE-2026-42798 +Upstream-Status: Backport [https://github.com/mm2/Little-CMS/commit/6a686019825a89b715d16671f18d049523354176] +Signed-off-by: Ankur Tyagi +--- + src/cmscgats.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/src/cmscgats.c b/src/cmscgats.c +index 862eb91..7248d39 100644 +--- a/src/cmscgats.c ++++ b/src/cmscgats.c +@@ -3180,7 +3180,16 @@ cmsBool ParseCube(cmsIT8* cube, cmsStage** Shaper, cmsStage** CLUT, char title[] + + if (lut_size > 0) { + +- int nodes = lut_size * lut_size * lut_size; ++ int nodes; ++ ++ /** ++ * Professional LUT‑generation tools (e.g., Nobe LutBake) list 65×65×65 as their highest supported size. ++ */ ++ if (lut_size > 65) ++ return SynError(cube, "LUT size '%d' is over maximum of 65", lut_size); ++ ++ nodes = lut_size * lut_size * lut_size; ++ + + cmsFloat32Number* lut_table = (cmsFloat32Number*) _cmsMalloc(cube->ContextID, nodes * 3 * sizeof(cmsFloat32Number)); + if (lut_table == NULL) return FALSE; diff --git a/meta-oe/recipes-support/lcms/lcms_2.18.bb b/meta-oe/recipes-support/lcms/lcms_2.18.bb index 1ff3b3908f..501e1e2a79 100644 --- a/meta-oe/recipes-support/lcms/lcms_2.18.bb +++ b/meta-oe/recipes-support/lcms/lcms_2.18.bb @@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e9ce323c4b71c943a785db90142b228a" SRC_URI = "${SOURCEFORGE_MIRROR}/lcms/lcms2-${PV}.tar.gz \ file://CVE-2026-41254_1.patch \ file://CVE-2026-41254_2.patch \ + file://CVE-2026-42798.patch \ " SRC_URI[sha256sum] = "ee67be3566f459362c1ee094fde2c159d33fa0390aa4ed5f5af676f9e5004347" From patchwork Thu Sep 3 09:49:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97206 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 248A2C624DA for ; Thu, 3 Sep 2026 09:50:14 +0000 (UTC) Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4186.1788429007521959208 for ; Thu, 03 Sep 2026 02:50:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iTVgk/Cc; spf=pass (domain: gmail.com, ip: 209.85.210.182, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-85c9a79590aso2480422b3a.1 for ; Thu, 03 Sep 2026 02:50:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429007; x=1789033807; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=m84/SvVVrjPhJyEwAMRpnASSnXIVPesRlp0Y88XGk5s=; b=iTVgk/Cc6v76F1d2ak6KSaOr0/pxui74rz4z0Y5/3KsUkAroQG8AEHLOwKBTQ72tTk NY31Us21G1Rp91tLOj6r4lyalO+kbGPpWfkE/TwrIlIcxv94hXW6u6mBu9M/C39GjW0D B9DBi4+cX546dKSKOyB2JO+li8ne0rQMLoYp04nVlmNQIi4TIVHVJokI4RjxVq9HolTu tjDtmQ8GeDtnec7ZjDNMTWuxQ5a5FGXg41hLHR2HN0mNZ12q5x49M88ut+w3VrYTHX7K 8PYqHA5tVs1PvQqMuB7+O1+9KfiseSSZhtF2lueEdKjqOR/V0oAWnH7Vg/ZhhcHzeFXt mF1Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429007; x=1789033807; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=m84/SvVVrjPhJyEwAMRpnASSnXIVPesRlp0Y88XGk5s=; b=UbIgy6aPFUzmwabrXaZU67UBH6bHYJnaX/BXLHqNqCqxioMOyGD6CsV/MmYDUL2j7k JCzO+ZDr+2e7qOblLHHKW5cAKD67D80eOpBGehzLQZg+uSGk3v6o9vzSD26FhOV+KMKc WqBBRb+gOx+TZEXgBu/Fvoyy3IOoWaF2Ctn4ww3QkuYde5nB67vXLw85/f3Dm8rKLAWX TrrwqPR+VRTKnaOMsD+GozAhPQgrdnnCRG1xtqBrsbKHP1W2UQyFGxIRnaUYQ9IqKrMv p8l64xX5/Ci4u6Q0juWcw23EzNO8oLYjspb0iUFH6mQ05cfQQiYd+EV9hvTtBcFAggXB U6fA== X-Gm-Message-State: AFuF++mr7hiOai2rFy+GQDCxbXvfjcO+mzm9aHBp/Ju7kB9RJoZBuWsx RgYNPGIQT1bxzuCeus7SSVTCtrKatGALRa9EiO3UFgit5IGf9KV1/9a0+9wBkcpq X-Gm-Gg: AYBFou0GuIgerKDA/pIWTEX7qbiLznOPA1pXTT7kyJ8oCFNjlxVdXZfLUh1PgJeoKxC GNVTVLNp1EWbWOvc5zaPuPqFOJCYO5Qf+29xAD5ygLhkB/x4NHpXgkoPHNZZpDtNmEY/XxwtJ7L ci/GM7O/sM02JxOrDgvz7+u24EBN6JpVqkYkL7SUkjBUkKt4Kb7xycO8Rbj9ksC93PS8qqq98CQ 9nKD2rC6UTxJHBjd4rEF+PS5Cf777fEKx8slAW8d8/BG3L0nHIGsy4iqWmLTr0esU+NjX/wuvFD q7iKxYA9AGqCIbwXAMeYtAMIhjeUg0m2n4hoBxZDMx2f7qGAlaM49SEUZJmhLCZ8/u0dgGaj9Le AHPesZr85pVjpu/xYCMG/CFGQRLD/OVCTzf9S5dAZyaxtP9e153Vjsj/VzSej4NOy9kGRpFiq1i bDWeinskwA/vjRBVDaQqghfovhMufX+RxGhnADU3CvPX/TqQjiBQghfABtwG6Usrp9SLD7+y/0T A+hdq4/B2k= X-Received: by 2002:a05:6a00:3c8d:b0:853:5152:a3e9 with SMTP id d2e1a72fcca58-85ed8023e20mr15838577b3a.11.1788429006798; Thu, 03 Sep 2026 02:50:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:06 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched Date: Thu, 3 Sep 2026 21:49:34 +1200 Message-ID: <20260903094954.3240723-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129719 From: Ankur Tyagi Release Note[1] also mentions fixed CVE. Details: https://nvd.nist.gov/vuln/detail/cve-2026-45382 https://nvd.nist.gov/vuln/detail/cve-2026-45383 [1] https://github.com/strukturag/libde265/releases/tag/v1.0.19 Signed-off-by: Ankur Tyagi --- meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb index c5fbedb22a..54f158eef9 100644 --- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb +++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb @@ -22,3 +22,6 @@ PACKAGECONFIG[libsdl] = "-DENABLE_SDL=ON,-DENABLE_SDL=OFF,virtual/libsdl2" FILES:${PN} += "${libdir}/libde265.so" FILES:${PN}-dev = "${includedir} ${libdir}/cmake ${libdir}/pkgconfig" INSANE_SKIP:${PN} = "dev-so" + +CVE_STATUS[CVE-2026-45382] = "fixed-version: fixed in v1.0.19" +CVE_STATUS[CVE-2026-45383] = "fixed-version: fixed in v1.0.19" From patchwork Thu Sep 3 09:49:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97210 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 743CEC61DD3 for ; Thu, 3 Sep 2026 09:50:14 +0000 (UTC) Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4189.1788429009579961831 for ; Thu, 03 Sep 2026 02:50:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=UXXJJ29R; spf=pass (domain: gmail.com, ip: 209.85.210.176, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-84fa3b14ee1so1952865b3a.0 for ; Thu, 03 Sep 2026 02:50:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429009; x=1789033809; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8Z+9GDNntGk7eYYoGmaAYkw8FSWA84+e8MC8H8nE3Ow=; b=UXXJJ29RSbqFpGkK+VmoOxb+tc/GgXL6/gTyzh5EOsFOPQW7jFK9tDKo/igwcF9FDG vXMmH9/gOLLw8yQEE+RpVR9nvBKTUXRz/4KuS6X1WSAVQbmTPhzYrx4Q71qZn/zZOXVm jra4N76kGyWMxt87fBJjqPS+96oNLvDRJR59kXAX/pj3Yww9fjHEO4j5lDSiam5m/FcQ wb89EwWTtCNEBiMsQMuMIRvslIdIfYoTH8d1nOE9W9x5ND4zU0HdOCxBagZYRjUgZH7Y g+kMHiUfohTpOoN767LkbzSIawVZHR/a62AKNnAYhfpBNhKWPLwm5SkARq988BOz6x2X 9kMw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429009; x=1789033809; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8Z+9GDNntGk7eYYoGmaAYkw8FSWA84+e8MC8H8nE3Ow=; b=TEaXzB27yq4OQReg4ymZTsp3nsqlPJ0E76INRZrY67l3ExT+lh+68FGsdYASolpDuQ V3zPZwKgnYxaaRXi9SPalkGN3Nyyu+341R9TWixSrNhT5UJ1ekcrSNcQPddOtjgl2KHA 4MVN9QtTBNZn3OyGwc09KGPbBP9kgLlzz/pEcxLHmxMW/MT5nyYPkPcU3RsGfyLjORS+ mCwY/QDMlCsgdED6lUgsKZRwiSstuOE3BsW4Vn/t3FJpYocc2jaT1EfMIS/SI8boUDHj 133oVG0F5VNDZPWdqHN5UeE2efrPFfErToACoO3Y63T5sFTGEPSwjSjuu6apwcDExqPt 5joQ== X-Gm-Message-State: AFuF++lnbo8L8E1oRz9vsaQ936diiu+HTxSmpghSQ3MwBP3eovR+VYgY f+ojb8qiwg63TReIIZvnTOInavNWezHXhhKQsis5AdrK5euAFfY2BBjOQD4Y0VTY X-Gm-Gg: AYBFou0fGUv7FmC8N7fIGwbPSaj0wRmHiw29HZZs/jHMWhRLpblpsynIVzx0uWrRAAM LzVI4ZoZfwSdkg651Q+3SzswElUJ19JpE9IKHLe7dLLJUpm3xQllUaxDII/4vLU0b73YEZ3qnJt wOrFYYAtFOPRwrlAzAe3tN7uvDSgvz/nsq+RQMLIo/L+x9CTxi6o9xmXT+I7l330DsWNi+rxVcY HkUT6P26NtK2mZ12tEhA0gt1LP6sK+EhEG3RxkwSsv0evutZdd0YpajOnzwr2hf1lYxVFuI0r/m sUa42D2EUO6KvhUV2Y97DAoRiifvSvsJTs+yohQD1foaR7Dd619+SfrhL2tRcAb4BF1Vu8OXeo8 Hs11gf5wZ/aAnhgseKGQi3ZSmnWIta7Y5Xamy3zMX2pnfm9EKiggo6SXTdUcgwcSwCmB0YPyWob cVRRYPLrhR52lg7BKHaDPBZosvFYPWdjts1UGY1rXKRmAz+AHb3uK/1TlrGH5XNAl9p03pFtZz X-Received: by 2002:a05:6a00:a0b:b0:853:50f2:9c03 with SMTP id d2e1a72fcca58-85ed28d91f2mr14723200b3a.11.1788429008891; Thu, 03 Sep 2026 02:50:08 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:08 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 Date: Thu, 3 Sep 2026 21:49:35 +1200 Message-ID: <20260903094954.3240723-4-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129720 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-49295 Signed-off-by: Ankur Tyagi --- .../libde265/libde265/CVE-2026-49295.patch | 41 +++++++++++++++++++ .../libde265/libde265_1.0.19.bb | 4 +- 2 files changed, 44 insertions(+), 1 deletion(-) create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch new file mode 100644 index 0000000000..189d330b9a --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch @@ -0,0 +1,41 @@ +From 7d5e48dbf9324691ba3ce4cd8ffa089d735b0b70 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Mon, 25 May 2026 20:14:07 +0200 +Subject: [PATCH] bound aggregate short-term RPS size (GHSA-g2rg-wj66-w594) + +(cherry picked from commit 691f3a3c55b3d32478c4a49895dee061a282652b) + +CVE: CVE-2026-49295 +Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652] +Signed-off-by: Ankur Tyagi +--- + libde265/refpic.cc | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/libde265/refpic.cc b/libde265/refpic.cc +index ea4db4b0..dcd2b214 100644 +--- a/libde265/refpic.cc ++++ b/libde265/refpic.cc +@@ -322,6 +322,22 @@ bool read_short_term_ref_pic_set(error_queue* errqueue, + + out_set->compute_derived_values(); + ++ // The unused short-term references are all collected into a single PocStFoll array ++ // of MAX_NUM_REF_PICS entries (see decoder_context::process_reference_picture_set). ++ // While each individual list is bounded above, the predicted-RPS construction can ++ // append the current-picture delta to an already-full source set, pushing the ++ // combined count past MAX_NUM_REF_PICS. Reject such sets to avoid an out-of-bounds ++ // write when filling PocStFoll. ++ if (out_set->NumDeltaPocs > MAX_NUM_REF_PICS) { ++ out_set->NumNegativePics = 0; ++ out_set->NumPositivePics = 0; ++ out_set->NumDeltaPocs = 0; ++ out_set->NumPocTotalCurr_shortterm_only = 0; ++ ++ errqueue->add_warning(DE265_WARNING_MAX_NUM_REF_PICS_EXCEEDED, false); ++ return false; ++ } ++ + return true; + } + diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb index 54f158eef9..b4f80d18a7 100644 --- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb +++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb @@ -8,7 +8,9 @@ LICENSE = "LGPL-3.0-only & MIT" LICENSE_FLAGS = "commercial" LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f" -SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV}" +SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \ + file://CVE-2026-49295.patch \ +" SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06" From patchwork Thu Sep 3 09:49:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97208 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 80521C624DB for ; Thu, 3 Sep 2026 09:50:14 +0000 (UTC) Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4192.1788429011688239160 for ; Thu, 03 Sep 2026 02:50:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=O5KMBk/G; spf=pass (domain: gmail.com, ip: 209.85.210.170, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-84864086bfeso2091027b3a.1 for ; Thu, 03 Sep 2026 02:50:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429011; x=1789033811; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zJNaaA117FjO44ZoX/aNvEUa03P/eWFlU96iCZaTQ+0=; b=O5KMBk/GCwMhBcYdCfAVVQXWi1KgZ11W/e7y0B45xaF8Fz3ip2rO/F9PGI+ODusuJA s2r9/BDH6YOMK4eWwCzEEEHkqQKVn7mM+R+TcytsBnEYqP9Cxh5N4NhDquI3rcpjOYdV nL7lXlJXr6yItbSkB+jBEzsy+EfbzJhhF+CuFkmjnXux/ZlHJ3MRslXT8nsx29EgkVCf otFGiONNG0FlT1sfD2Kv7R/Ty+mMZxoFHRwsS+nPHiVckmeqnMqE6OAxEo4wWPewfReg z7k6bnwNSuEeqHOGFP2n3NpqnfDdj6fBCSvqh9X9H+7s+cuir9CGNgU/xOQdzDbPBoGw hxxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429011; x=1789033811; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zJNaaA117FjO44ZoX/aNvEUa03P/eWFlU96iCZaTQ+0=; b=JRN5uhWdb5pDu828NcJIXGQgQAGABK2lh/PynOaayZzh44AmOsBoRfbzaCGfRWU5/6 qLzyH+VVq4vxgy+cpwt3KFWHu+QfU1Muh0/zNc/Zpf9mzggTGNLJcP8PFwfUix8UzvAn mVvdsrRoUWYVlhx6zjTepno/NfEVKRrEW54Nln5/WotycmhtS1fd20Zl0qnwZ8b0fzyd 3SoA4n+FHrbFPVfDH79UOR+0AzMSL9mudNybtisbdE9jstB1uZCqDA4/JhLzhoR0nZK+ F5s2pjO4y3/hHqY3xE/RMDzvrlh5KBf/QB4BjyOmzYfwqIBDRAXgq1Vbfb/7XqDqJlYH DJyg== X-Gm-Message-State: AFuF++kfnaFJdN7P3KTDBrHkkZFmT2SB8+4c6yfx3/tFaAVW/YXacb32 KDLpl0N6syNl7/izuf8yst+W4RGUdkB9xGt7d6F0QDuwS5dInY6r5u7k3VuiqWPU X-Gm-Gg: AYBFou3g5dQBneVj/dqXpZnOR+V+4yLmLCQP3kPqCbJfrPcWX81SzXhutFjVtZjnP38 9ZSW6cG7DMTD6lo3kMNK37/OmhnKmIWqwxdyoQfMVwvNvNqO3d97CTNprGA20i0zGtM9uF9VJGJ kpf8quDBehIVvXsBbBopi/NBpoQJTgsnCwUziDk8MsjI8bNdDAASwzNZRic8WrIKYN4oiwDcuFT qIMpBv23fX7Bc0a2RswGK5Ew5/RvT22E814FwiiYeT2LdJToufHUXC04+gDAXCmRa6vTUMGRNyn HdVVC0P1bAUZEb1NBKs7pN6T3CokF+5kIjUD7aAOolSJPqMU49W9YAvDj+3WhMKDyjZKy1QYgk7 h40Y4gfG8SlUNcUwsHMjGR2OoAUBlJJXzW4WozCpLr/uUVlZbItAJrE+cfwnn8xPJn+BJcUh9Ox Q2jUnA8IteRBY4BS9Xx3bVayayZXf/k4GbFDmxwGbkR1QW7LFgYHtSf2kC0BykZu2V9o7mncQWo s0v9BtFs0E= X-Received: by 2002:a05:6a00:6d43:b0:85f:1492:61a8 with SMTP id d2e1a72fcca58-85f1492679fmr14115223b3a.7.1788429011050; Thu, 03 Sep 2026 02:50:11 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:10 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 Date: Thu, 3 Sep 2026 21:49:36 +1200 Message-ID: <20260903094954.3240723-5-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129721 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-49337 Signed-off-by: Ankur Tyagi --- .../libde265/libde265/CVE-2026-49337.patch | 53 +++++++++++++++++++ .../libde265/libde265_1.0.19.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch new file mode 100644 index 0000000000..88e0e32949 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch @@ -0,0 +1,53 @@ +From 2f0c53241cb9bf2f5acded53c25f1b74db536de7 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Mon, 25 May 2026 20:29:40 +0200 +Subject: [PATCH] free orphaned slice header when no active image unit + (GHSA-g5hj-rf9f-7vxm) + +(cherry picked from commit 683cb9fa603e35840642f98765ab95cdb71cadf9) + +CVE: CVE-2026-49337 +Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9] + +Signed-off-by: Ankur Tyagi +--- + libde265/decctx.cc | 12 ++++++++---- + 1 file changed, 8 insertions(+), 4 deletions(-) + +diff --git a/libde265/decctx.cc b/libde265/decctx.cc +index fbb3baa1..5deddc37 100644 +--- a/libde265/decctx.cc ++++ b/libde265/decctx.cc +@@ -478,10 +478,6 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na + shdr->entry_point_offset[i] -= skipped; + } + +- this->img->add_slice_segment_header(shdr); +- +- +- + // --- start a new image if this is the first slice --- + + if (shdr->first_slice_segment_in_pic_flag) { +@@ -495,6 +491,13 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na + + if ( ! image_units.empty() ) { + ++ // Hand the slice header to the picture (which takes ownership and frees it ++ // on release). Only do this when there is an active image unit to decode ++ // the slice; otherwise the header would be retained on img->slices forever, ++ // which a crafted stream of non-first slice NALs can exploit to grow memory ++ // without bound. ++ this->img->add_slice_segment_header(shdr); ++ + slice_unit* sliceunit = new slice_unit(this); + sliceunit->nal = nal; + sliceunit->shdr = shdr; +@@ -507,6 +510,7 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na + } + else { + nal_parser.free_NAL_unit(nal); ++ delete shdr; + } + + bool did_work; diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb index b4f80d18a7..bca5c9d776 100644 --- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb +++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb @@ -10,6 +10,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f" SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \ file://CVE-2026-49295.patch \ + file://CVE-2026-49337.patch \ " SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06" From patchwork Thu Sep 3 09:49:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97207 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1897FC624A4 for ; Thu, 3 Sep 2026 09:50:14 +0000 (UTC) Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4053.1788429013874036776 for ; Thu, 03 Sep 2026 02:50:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=G3glF83q; spf=pass (domain: gmail.com, ip: 209.85.210.179, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-853c07a76adso2544983b3a.0 for ; Thu, 03 Sep 2026 02:50:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429013; x=1789033813; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=59Fyx46p2ZUCg6GJLHi8Tq37NfYD3pXKLUToZQVcqNc=; b=G3glF83qOLpiH0SMyujsqtksHEMaIi+g0a85d32plMiSAnZnlidE2wu20VrZqwpxCI 1c/jLfGWUDlEF3i/Q9Pcqio7J8MwEpn1Q1X2othHdmfbUC12wvhEhaJ/iR4yeGhqDAzu hUYX+EleBw3okKcOQmU4BgURxRBHK6D4xOfxQBjZoJQKY+61HNXKA297ZwP7pl+c3Mwt 94Etb1CeSDm/PCpD05oXn/4p4dunTy/JvGruBCBg1OJuMob7Lw/SJDd8QsmDIezbK3tA Ryn8yRSJ5fG18t6NdzYJsAHnkUpDnpIFLVUxtSbJnzH0t2qZSAryXfZQHiZem16OmaLw nEnw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429013; x=1789033813; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=59Fyx46p2ZUCg6GJLHi8Tq37NfYD3pXKLUToZQVcqNc=; b=EyaZHlXRIeNuJkUcqBpQgVNQU6SW3dGG/Whozqz/lI63OmWpu79YWMHAJ8rlRcm7Nw DJAxE6wxtl252yXBsHKWlAzLPHUv/6IxZ5CzO3jcmP1v05fviixEax8etQ9uObN6NdZF gXGSopEulzuUK2v+hIAeg+hPg5kXsCd+kjO5/CYZNutzwfHVa+kJ6KdydMi6EPgWtlvW Rw+RRGfn0kx/la5bqi8cv3FJUXJuMqoQNxQ3I7q8nwpi1GlI2iwtJOQcIvXWr7MYxMB+ x0E/jAZFzH+OOXI199dR4/n+7ggYNzR7Tu705jJTD3aPNpVlOLrq0NH34uu+Si+3RR3S 6YHg== X-Gm-Message-State: AFuF++klSLj+Hsk7QEEY8jY7SD03yGMqWP06HCniwBUdXVug+GQ6Qjzl 3CJHJzUOUsDljrYquJ0pqO305z1jO07ZUl+TjdAFlU9ynArKOcJOI41tXyqJtdoc X-Gm-Gg: AYBFou0XDisjGIq4+Ynp7VoowaQ1Y7yYMbZ5qDlDBnn1VeyJ3vs3Fjxrxe8ub7DS0PE WhElzQdl9PoxjD25ioQEkFi9MRPeQYR6HLGF33YpU+NbuwOSDpna6V6VR4iT49t8ZvA8UaUmn/Z p2/7NqsH3ZpLvs+qGT8kk30gBPMR8TNgmpoqV9idSw68B2wWns3glvBZFNOrnXG36w0+Y7hRYzV G/WYRk8R1yuPBXj5w6Cpgv8/59xfaGci0B33AFewiqvruM7jMfIJ7gSucdQF1ln8R+7nnF0fSDq V6ZZfOlRUKViqo4Ytrf+fG7KR942ZPjDfl3vdltYlVXLPeEb67XiV7xTdEQW7QZriG9wp1v+Qq8 AmKZszYh7ZSTc4XMXwo6yTf/fLh4PMFvdvquEDvxf6jWNzaPM3ZUEsvR5Ln7zPNUW2CrAj1KutY x64QKJg5N08D3D8D3t1Y1s+pRtpBQNps84+Pp09cvjJnXCXGZeXvFQIfb908fxEMUCR/ETg4mY X-Received: by 2002:a05:6a00:27a4:b0:846:4d4c:23f8 with SMTP id d2e1a72fcca58-85ed5cccc9dmr16519271b3a.1.1788429013239; Thu, 03 Sep 2026 02:50:13 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:12 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 Date: Thu, 3 Sep 2026 21:49:37 +1200 Message-ID: <20260903094954.3240723-6-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129722 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-49346 Signed-off-by: Ankur Tyagi --- .../libde265/libde265/CVE-2026-49346.patch | 102 ++++++++++++++++++ .../libde265/libde265_1.0.19.bb | 1 + 2 files changed, 103 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch new file mode 100644 index 0000000000..288295b08a --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch @@ -0,0 +1,102 @@ +From 1667c33f2778a04f08ba4f7d6c1c16508350a779 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Tue, 26 May 2026 00:59:08 +0200 +Subject: [PATCH] fix integer overflow in image plane allocation size + (GHSA-vv8h-932h-7r86) + +(cherry picked from commit 8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8) + +CVE: CVE-2026-49346 +Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8] + +Signed-off-by: Ankur Tyagi +--- + libde265/image.cc | 46 +++++++++++++++++++++++++++------------------- + 1 file changed, 27 insertions(+), 19 deletions(-) + +diff --git a/libde265/image.cc b/libde265/image.cc +index 0b6071ba..94f3c974 100644 +--- a/libde265/image.cc ++++ b/libde265/image.cc +@@ -70,10 +70,11 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx, + void* inputdata, int inputstride, void *userdata) + { + int alignment = STANDARD_ALIGNMENT; +- int stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment; +- int height = img->get_height(cIdx); ++ uint32_t stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment; ++ uint32_t height = img->get_height(cIdx); + +- uint8_t* p = static_cast(ALLOC_ALIGNED_16(stride * height + MEMORY_PADDING)); ++ // size computed in size_t: stride*height can exceed UINT32_MAX for large planes ++ uint8_t* p = static_cast(ALLOC_ALIGNED_16(static_cast(stride) * height + MEMORY_PADDING)); + + if (p==nullptr) { return nullptr; } + +@@ -82,12 +83,14 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx, + // copy input data if provided + + if (inputdata != nullptr) { +- if (inputstride == stride) { +- memcpy(p, inputdata, stride*height); ++ if (inputstride == static_cast(stride)) { ++ memcpy(p, inputdata, static_cast(stride) * height); + } + else { +- for (int y=0;y(inputdata) + inputstride*y, inputstride); ++ for (uint32_t y=0;y(y) * stride, ++ static_cast(inputdata) + static_cast(inputstride) * y, ++ inputstride); + } + } + } +@@ -107,30 +110,35 @@ LIBDE265_API void de265_free_image_plane(struct de265_image* img, int cIdx) + static int de265_image_get_buffer(de265_decoder_context* ctx, + de265_image_spec* spec, de265_image* img, void* userdata) + { +- const int rawChromaWidth = spec->width / img->SubWidthC; +- const int rawChromaHeight = spec->height / img->SubHeightC; ++ const uint32_t rawChromaWidth = spec->width / img->SubWidthC; ++ const uint32_t rawChromaHeight = spec->height / img->SubHeightC; + +- int luma_stride = (spec->width + spec->alignment-1) / spec->alignment * spec->alignment; +- int chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment; ++ uint32_t luma_stride = (spec->width + spec->alignment-1) / spec->alignment * spec->alignment; ++ uint32_t chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment; + + assert(img->BitDepth_Y >= 8 && img->BitDepth_Y <= 16); + assert(img->BitDepth_C >= 8 && img->BitDepth_C <= 16); + +- int luma_bpl = luma_stride * ((img->BitDepth_Y+7)/8); +- int chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8); ++ uint32_t luma_bpl = luma_stride * ((img->BitDepth_Y+7)/8); ++ uint32_t chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8); + +- int luma_height = spec->height; +- int chroma_height = rawChromaHeight; ++ uint32_t luma_height = spec->height; ++ uint32_t chroma_height = rawChromaHeight; + + bool alloc_failed = false; + +- uint8_t* p[3] = { 0,0,0 }; +- p[0] = static_cast(ALLOC_ALIGNED_16(luma_height * luma_bpl + MEMORY_PADDING)); ++ // Compute the plane sizes in size_t. Each operand fits in uint32_t, but the ++ // height * bytes-per-line product can exceed UINT32_MAX for large frames, so ++ // the multiplication must be done in 64 bits. Computing it in 32 bits wraps ++ // the allocation size to a small value while fill_image() later writes the ++ // real (size_t) size -> heap buffer overflow (GHSA-vv8h-932h-7r86). ++ uint8_t* p[3] = { nullptr,nullptr,nullptr }; ++ p[0] = static_cast(ALLOC_ALIGNED_16(static_cast(luma_height) * luma_bpl + MEMORY_PADDING)); + if (p[0]==nullptr) { alloc_failed=true; } + + if (img->get_chroma_format() != de265_chroma_mono) { +- p[1] = static_cast(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING)); +- p[2] = static_cast(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING)); ++ p[1] = static_cast(ALLOC_ALIGNED_16(static_cast(chroma_height) * chroma_bpl + MEMORY_PADDING)); ++ p[2] = static_cast(ALLOC_ALIGNED_16(static_cast(chroma_height) * chroma_bpl + MEMORY_PADDING)); + + if (p[1]==nullptr || p[2]==nullptr) { alloc_failed=true; } + } diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb index bca5c9d776..07d108b915 100644 --- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb +++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb @@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f" SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \ file://CVE-2026-49295.patch \ file://CVE-2026-49337.patch \ + file://CVE-2026-49346.patch \ " SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06" From patchwork Thu Sep 3 09:49:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97213 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BF9F6C624DB for ; Thu, 3 Sep 2026 09:50:24 +0000 (UTC) Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4193.1788429015925575589 for ; Thu, 03 Sep 2026 02:50:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=RW8ZaDuM; spf=pass (domain: gmail.com, ip: 209.85.210.174, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-8557c3f270eso1325118b3a.3 for ; Thu, 03 Sep 2026 02:50:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429015; x=1789033815; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CA3EgUX6ufWUvu7n6WLdjqniUHZ/Nfd4qdZ6+mr35T4=; b=RW8ZaDuMWvwP89NgyL0jndN9XQJM++gQ8P20Re/yYNU5hlFe8Ut7Hf1/v9AcPBtEKF ElEuQeZSqhlW6ue0yeUfxB1Vckfq08v5U3m4xQbDz9QyMHQHL9jIx3aveb/IhVOUW9KR /5OVureun9FjDClldAkRqPAhkkVWfIezwxzdxlJjO7Wv2SG9NHI69KrkMhiz/EcnNyDd 4iLXxH8pFxB9n3rQvOXFbJ9PmFFuUkIbOKt1CvuILFLnlZaurDvoVchyL4DPMoiJJ1MG 6DoqCbHtV4v58vvXMK69+MoEF64AHh/1cVY9nej9Jha3MrHm2rYoQ8NStP8uP68sENK0 l+XA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429015; x=1789033815; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=CA3EgUX6ufWUvu7n6WLdjqniUHZ/Nfd4qdZ6+mr35T4=; b=YEaOJS4h1XgxZoU8eqPoIf6T6zqtXMfUapYyPrIRgUXS+eHEv2GE07ROCJ80X9FtKm i7H6ZifndCPXVkXNXghDaqqR4f/Z0cNcHzczrqVIKKSTUw90FUw67a3+96/JSmh66k06 t8BQg1td/z83bRZqZQc56jJ6ZeWNwPr9crJwgFYPKGnmkPP4ee5zfRhPP3cMcGIxpMEk DcBRbwcoh0FFpGmVLi/KleiiWLptYG++dwclaNcrn8YHK9o4HK7wM/1auyDFiRyPEzS7 4B3SihMrbBUpuFape5H4YOqicHlAH8Fdq8Xzf9FIj948sLr5YmAXLr2vKHR50pOMjgzY kdSw== X-Gm-Message-State: AFuF++msnOoQhYxyzJ5mH3Z55qqwp3ycOEa9+8ZtYc1xQ7vG51TRXfRg OyoO/r0L1STA9Q5x0W/0rUTu+DspIuKbfeCSyRj8ym70Y7RkJfqI3kJDyn8qWAUH X-Gm-Gg: AYBFou1JmzaBC8U98j1ASVBrOAL5jr7BDwKdbDJahE2qcR8ENKWHXZkqCZ4xoNbj8Uu iQOHacdBR3lbRDNh234BSmRFEWSM42dY4C2AyvdnWCVnSKx+TXEjiGcMJ2zuMCaaPoj+24S6E8K gzxLdlHz6RIVQ4cIPtZPGzo6s09zWZevAEhrrjSRbTxclL3gheexU084LaJARvoJ6yX3LCXnFGI QR1MsGFWcsino43++B8hJ0OHECiiEpHO4+vkOb+xKJg4/OutkeBvrGbBrH2nYMIOXVIV1yLqBqi R91sKnc/W6+13TioMgmacI6zbyQULN/6YuWHjZ+TzZtDyPv54AP+dM7BgHKiWrC0Sr6aYnq5OJE vq/U3dIVB0I9+rB/h0kphTHJqlcOmnpxOG5qNIVK4ZNz8PbM83C7/VSOycdoMJg5YyiEktRKaoF WUQHIgtUxH7XN/I5XCN4gWkUAD0WpM01sMoxonp9Hi7ScMxCkhzZmekRLNTZKPZXDT+oPe4mxTP jZDheYZUzI= X-Received: by 2002:a05:6a00:4f92:b0:857:73e2:9105 with SMTP id d2e1a72fcca58-85ed94bb426mr14673642b3a.21.1788429015287; Thu, 03 Sep 2026 02:50:15 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:15 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 Date: Thu, 3 Sep 2026 21:49:38 +1200 Message-ID: <20260903094954.3240723-7-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129723 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-40947 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb | 2 ++ meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb | 2 ++ 2 files changed, 4 insertions(+) diff --git a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb index 7d9838b003..053d1f6d45 100644 --- a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb +++ b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb @@ -38,3 +38,5 @@ do_install() { ${S}/src/libfido2.pc.in > ${D}${datadir}/pkgconfig/libfido2.pc } + +CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows" diff --git a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb index 09d34603d6..8595cbae81 100644 --- a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb +++ b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb @@ -21,3 +21,5 @@ EXTRA_OECMAKE = "-DUDEV_RULES_DIR=${nonarch_base_libdir}/udev/rules.d -DBUILD_EX PACKAGE_BEFORE_PN = "${PN}-tools" FILES:${PN}-tools = "${bindir}/fido2-*" + +CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows" From patchwork Thu Sep 3 09:49:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97212 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A8906C61DD3 for ; Thu, 3 Sep 2026 09:50:24 +0000 (UTC) Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4055.1788429018056280327 for ; Thu, 03 Sep 2026 02:50:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=EQ1hYTqO; spf=pass (domain: gmail.com, ip: 209.85.210.180, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-8534d507f59so2739655b3a.0 for ; Thu, 03 Sep 2026 02:50:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429017; x=1789033817; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=nowewthG0wVXsjTBf+hJSWnbh84++hTFx2FIAyU07ro=; b=EQ1hYTqOZ4pobIIuJQRiLQVo3ApM7eDMwkO4VWxJHh4O3lm+Bdn81DSZPddZpiV5PI cyI24w2XNlsThdb9AtPiLFGIfqaB5vGc0Lx0/b7wI0/pcT+WjPeZ6FMnn11UrJW7lbsT Qp1/F01lfa8MkxZVdcCl+P1bEHGMuuCbpf6o71F2yOAZY2+ROlULix8LD5LxH+hjy5Pq 2jmDSNDzU34lA1KXP/s01H5xorFXNMz9ReVh+OTWzupNisJPWcrbsIE8lOYU2CxxAtSC 0xjtvxTEkYPAvhz68fgdMPEmSOcmOok48hvhqmUQVbtH2QIYp4JWhRk7IrNCSfQaDJu6 z3XA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429017; x=1789033817; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=nowewthG0wVXsjTBf+hJSWnbh84++hTFx2FIAyU07ro=; b=X1bC5roTzQqzGf8quDPN+YBg4uE/xnTbJWvlNgwHJLNo1094vbkjmoI6hnyFH04sVt Cv3/GDbl1Y6iX56LdK12/sjc9M3+MdmUOsA+2//U+FONi6lcue1jnHta0HVr0dohJwvR OOTOgkjSikLPLMfzUp/ygP3yoEu7zteOqtsBV3+XriZzG457BCu8OuZtZMzNufvJqL+P VEcJKxkVb9kc6Tn+iU47F0y8EN3MQWCdZPN+4Hm9g++vHNo2mo93nNtGRCrsJ7F3XfgJ cEWYcM99in+vfFBZD9ycGEowOi8NazT7UgOGSXLSt9Stj7f7lPpwPvLTSOkDhj7mIEtF y1lg== X-Gm-Message-State: AFuF++mqiUoiM8kZjPE5BP4FnUUoWIzFqnmbVqPEjSac59wEEZ2tuNcn WlPYEqHQUmM5AFV8GXYF6KIzdKFGnjX612TFH7h0IWz2jkhjy+3KiuEsEr1Lt4VG X-Gm-Gg: AYBFou26u6y8RNcn1ydrzBE7yvKbs0wyeUy8jZV7pcrPIR1tksGmRxxxAHXmCxRBLki FOhMI//oYsGR+bE7K0IAJ6WyB4KyeA3Mm6Yi+jrcEqMv0lGa1oqAQpPokxA8RCrvjw93dtJ//dI 1n8duJkrsMdiK0aGPYlki1cqcbl1z/jmcQrlhcoWY997y8dzADqNR6oMk7tDetenhmt8MwDS4V8 ZCFtNp2/bGnMnckCyA+009kCe4zwGEEtDJxsPU0WHIEEXTymCSroZj4/54DBH+baDeQuvY0cbkr 6Va2aQca0ZVcO9AfS15p86Q1cUpCtflsIKRlLNbF5rg5WpXVmg8JFVdE17YPERSwastvGbY+zcu IKB8I11kqjRX4j2ZDfwKR4+8EkRpsuZhD5aHe58plSYbIZfTe2PGckRIAo8DcMH5wbydx2aPNAT I3n6FpkItjE+gXpREOEwMmLpPUWmjGPVAfIgncIUj4NHBZWrW91xtSNsfNZosLxjaqUzuvKf1n X-Received: by 2002:a05:6a00:3d88:b0:85f:3dd6:f426 with SMTP id d2e1a72fcca58-85f3de63c5emr12739022b3a.17.1788429017379; Thu, 03 Sep 2026 02:50:17 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:17 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 Date: Thu, 3 Sep 2026 21:49:39 +1200 Message-ID: <20260903094954.3240723-8-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129724 From: Ankur Tyagi Backport commit identified by Debian[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-32738 [1]https://security-tracker.debian.org/tracker/CVE-2026-32738 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-32738.patch | 32 +++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 33 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch new file mode 100644 index 0000000000..4308aa6195 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch @@ -0,0 +1,32 @@ +From 95a7008c89335ca97fc22ab8caab5d62b077a34f Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Sat, 14 Mar 2026 20:32:39 +0100 +Subject: [PATCH] check that 'stsc' box does not have zero samples per chunk + +(cherry picked from commit bdaa37728442800497ea224bd232ca25e2f9bdff) + +CVE: CVE-2026-32738 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/bdaa37728442800497ea224bd232ca25e2f9bdff] +Signed-off-by: Ankur Tyagi +--- + libheif/sequences/seq_boxes.cc | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc +index aec84fd5..91865848 100644 +--- a/libheif/sequences/seq_boxes.cc ++++ b/libheif/sequences/seq_boxes.cc +@@ -875,6 +875,13 @@ Error Box_stsc::parse(BitstreamRange& range, const heif_security_limits* limits) + entry.samples_per_chunk = range.read32(); + entry.sample_description_index = range.read32(); + ++ if (entry.samples_per_chunk == 0) { ++ return { ++ heif_error_Invalid_input, ++ heif_suberror_Unspecified, ++ "'stsc' box with zero samples per chunk entry."}; ++ } ++ + if (entry.sample_description_index == 0) { + return { + heif_error_Invalid_input, diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index ab29fa3b02..b238807fc5 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -8,6 +8,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null" SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \ file://CVE-2026-3949.patch \ + file://CVE-2026-32738.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97211 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B53ACC624A4 for ; Thu, 3 Sep 2026 09:50:24 +0000 (UTC) Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4194.1788429020120854483 for ; Thu, 03 Sep 2026 02:50:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=mdJbB06f; spf=pass (domain: gmail.com, ip: 209.85.210.169, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-84e84a6c4bfso838952b3a.1 for ; Thu, 03 Sep 2026 02:50:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429019; x=1789033819; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Xt0DsEzYfg2N1l1lKc8p50V4MIDbRVm3Csf9fTiMOzU=; b=mdJbB06fd1UQxpDkGSbWStGoOYDdRevXydjgX8o6tMZ/eSFcdx0ZROH1MrGni4s2BF ZaonROcbbOZaHSCOYKE1sztJkTT8I7Ock7xzflb2olAnCfm6Fd1yc2Uq/+K4zoKAEEg3 IPBmf75K774WPnmxlKLQvwBNPuqjwtn8FE6AEFfKXr0tUqzstaXJi1Sgl2LGYu93AAWS f6jT46pedL4bhSRVyei2vbb6kxeEjQHutZnpxu9actox7X+HzJ7yucsUt6HAPgoYqnWL GT4WxVzIGqVA/pXmnggrvQatW7nOJyBvXpLfyJYSdzrcVDoYxvUkbrrPftWuFjwdFatY 8fYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429019; x=1789033819; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Xt0DsEzYfg2N1l1lKc8p50V4MIDbRVm3Csf9fTiMOzU=; b=MEEB8tuSno3ZezSS0hZnQV+o1PKB8NfP5OofOlpUVltVVmVcO5jk5LFmWi7reCckZ4 wEwakVqwDSdk8P1X2Ukl8fCNHAkHuH1d1DJps7Osney/czox/p9JusH3Y+SOwdMVgrFX B7OhlOItOlNxXFHOmdcOfq6YBrERMW6xCaFWb4m33y8cidhgy1cPk4q9N3cl1Oji0vF9 +Wh48UVIgEW5vH+An0+krTqvsFt6m05V0d8G7Jfkek87nOcv3AFD7QcfTXk1ftP70bDG 5ltsR0NcYboDTMdnuCiOscZeMkZOYu1Rcf8qysy4KqrqA02znhVym+CxQJBK6JJgpneo xL3A== X-Gm-Message-State: AFuF++mkGGOm7T53+a/Ckg1WE7M31dmODCMX6epr2IApsStBXZb3m9Ka ZnvY1S+ae8FRGBOX355yymPdZSlfWDLOp9+S6EmOBr3SgqhDNgFDoL0spFY0uvh7 X-Gm-Gg: AYBFou2xzH93vspFEEq20voWclv3GI8hEJgtbyFmqMx/2hUjH/QdDNhvz1uCpTGi3rV 6ldQn/7pNXgaJf5sg//d73V4VOl8Ut74460EBiOKDW2usgUJk55TiE6muR7nJ8v3ZWj0q0OKh2M 2qVaW1SCUTOBnoRCPl0s6u79Ky7B5Cwi20OPAWWRoz0zkz0XyPqVxyhZ+d/E7p/1NQOv9xtnyLW /xnX9CkGtq2t6o520o37HZx5p25sCbphrR71siuKmMy8Ye4murfSxxqC0XaIAtn89L8GfXrjKg3 1z3UZHuMF5sRL49blhDO9Uu35VuwqMXwp2865gMLJSqUuXl60oUfOTV4ZUl5Vw6jRrmYQ10bbO5 b6Pag9slKKfSJE1RvljI0R7I6p99We93vy/EmO37uKE/e0cSSnSOHqOMlxrdb4tUA766v6Y1pBG BiQw2nAtU4n4rvt9eXHa/QAe0FGVApMbTJ4MVJVejz/aABfXIx9Tky6INFIH7ZliPUZ5MIRJR4 X-Received: by 2002:a05:6a00:e8f:b0:851:c1f6:948 with SMTP id d2e1a72fcca58-85ffe109fcbmr4043850b3a.16.1788429019447; Thu, 03 Sep 2026 02:50:19 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:19 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 Date: Thu, 3 Sep 2026 21:49:40 +1200 Message-ID: <20260903094954.3240723-9-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129725 From: Ankur Tyagi Backport commit identified by Debian[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-32739 [1]https://security-tracker.debian.org/tracker/CVE-2026-32739 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-32739.patch | 54 +++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 55 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch new file mode 100644 index 0000000000..59cd793ef6 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch @@ -0,0 +1,54 @@ +From 1c6fde64e37efa6031a6be2318dac62dfb38f370 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Fri, 13 Mar 2026 23:39:33 +0100 +Subject: [PATCH] fix infinite loop for sequences with variable frame-rate + +CVE: CVE-2026-32739 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/723b58d6ca329b2743822951aeaf3299c7410448] +Signed-off-by: Ankur Tyagi +--- + libheif/sequences/seq_boxes.cc | 22 ++++++++-------------- + 1 file changed, 8 insertions(+), 14 deletions(-) + +diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc +index 91865848..39c2e8f4 100644 +--- a/libheif/sequences/seq_boxes.cc ++++ b/libheif/sequences/seq_boxes.cc +@@ -621,14 +621,11 @@ Error Box_stts::write(StreamWriter& writer) const + + uint32_t Box_stts::get_sample_duration(uint32_t sample_idx) + { +- size_t i = 0; +- while (i < m_entries.size()) { +- if (sample_idx < m_entries[i].sample_count) { +- return m_entries[i].sample_delta; +- } +- else { +- sample_idx -= m_entries[i].sample_count; ++ for (const auto& entry : m_entries) { ++ if (sample_idx < entry.sample_count) { ++ return entry.sample_delta; + } ++ sample_idx -= entry.sample_count; + } + + return 0; +@@ -813,14 +810,11 @@ Error Box_ctts::write(StreamWriter& writer) const + + int32_t Box_ctts::get_sample_offset(uint32_t sample_idx) + { +- size_t i = 0; +- while (i < m_entries.size()) { +- if (sample_idx < m_entries[i].sample_count) { +- return m_entries[i].sample_offset; +- } +- else { +- sample_idx -= m_entries[i].sample_count; ++ for (const auto& entry : m_entries) { ++ if (sample_idx < entry.sample_count) { ++ return entry.sample_offset; + } ++ sample_idx -= entry.sample_count; + } + + return 0; diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index b238807fc5..ba16ee7afe 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -9,6 +9,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null" SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \ file://CVE-2026-3949.patch \ file://CVE-2026-32738.patch \ + file://CVE-2026-32739.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97214 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB93DC624DA for ; Thu, 3 Sep 2026 09:50:24 +0000 (UTC) Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4056.1788429022298496984 for ; Thu, 03 Sep 2026 02:50:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iYGW68VO; spf=pass (domain: gmail.com, ip: 209.85.210.174, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-8525efa7274so1698239b3a.2 for ; Thu, 03 Sep 2026 02:50:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429022; x=1789033822; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rpnr2k4NsCxQGngaRC9fUfWF51MHq4eMCGGb0Nw5nRQ=; b=iYGW68VOa4Qr14fQgjIvaFDEXVO5GvcrMnDwAZYdBZPUSswprxsM+QBaa8VJbhy3l9 t1ihcvdlmCRoix7Ba4HUr4vKSj7+TrnRTTTzIWQvBEdSbV55Za8FWBvv6g2mKf6cMbJs B7/hRm1rTyqiFSke1FIt+OuAMZmXtH2mUGHsDHl//KYImH7K30/AuwfqxhZlyv67Gjlg /BS95L4lliFtwYIg1O+z/czdcFH6r8t+AKAs2cAA3YQL8OQxESaHVk5w8gFsmCit0EO3 v3WqirYFyDYME1DrrYQyhLe79hjcYsrWrf6NdkvpKXW8kor4FDf+cndSiL6Qkk/K3wrE GJ9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429022; x=1789033822; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rpnr2k4NsCxQGngaRC9fUfWF51MHq4eMCGGb0Nw5nRQ=; b=a9uiF4KsvEVpcY/MUHmjLG6uBjukVKKqYJMbv1UN0NSJmcA+mpY9n1ZnnKHK3fF7CA /0dWP+OTAVdPmWcEF5XnWd6fIdDGGV0Qo4IsfLVU99OGcgR1D0l7lprK3knsqe/N8l6I vfGBSwet3Y9guvIhzTXy8iNGV0nfh1GlAD2/G46hKtEjyrZlBbemdJTv9S531OkyTSmb OUbTnJauE5WVAI413TyYK8bx6an4z1OCVNuvYZXBZzQpDmgATCMMUfDLQRwumzhVCDRb Z/UTf17UzoaOzOM6iGrByi2ObwJyxGkj+Gc0JCc6Ul+2BhOBtnj12tnuQBEjqWEodofa X6Cw== X-Gm-Message-State: AFuF++lridVrQPFzIUyipHB0wanFesT/3/v7YcibsBgxLFBl1jfV3hNj 4KY4NZyuZpHy39AXNyWnyz1Oks2pgBzlBeLB5UhciydQwGPtWg9nI6wTQrFdvsU0 X-Gm-Gg: AYBFou1t+NE4bc2abyHm5HkMzmtZhAPs4DwvT7QrxUHE8muWFFpfBLfkyZzL8Sroo1b mH3BxVEUBfVMNcJsj6gzpC9R37Uk17blecp1niWM93kkjfepYP/lfsVYXlKQb36rmufTiD9LcO0 aYnNbb5sqAuCEyaaXhhKgGAciKWi/DkHL+PqG0Ku15OEOxzJWk+PW6HOC0q2XNj4pTiHdR7wFoL mMfNv4itQ+Vof87jqRSXpABO/vBZcD61Pt8dihIj0u0uwFVuZzSMsEc4t7uV+VnjE1wFbPLnmby tCbgNZKgj0tAAF1iNfdPIPMTIQXdw1xRP53V+NlQeNnVT1XXTA3dQ7DK2K3jbHM7QwLOrd2CvMX Wc5h5oHRwrRZYtb1EndN9RSZY5XW5/4Qi2bGmx9HmsA9YHfa9gs6XH2ITqbUqMfw2VHjmUNcNpY Z0CNT2i/cTdFVi8gM4r1A3vH5PcuZyzQYvoslr7yuod91GKjkjkKWORV2U5aD1dQJD4wt1gQwo X-Received: by 2002:a05:6a00:b88:b0:847:93f3:a4b6 with SMTP id d2e1a72fcca58-85ed3d7808fmr15235701b3a.17.1788429021600; Thu, 03 Sep 2026 02:50:21 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:21 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 Date: Thu, 3 Sep 2026 21:49:41 +1200 Message-ID: <20260903094954.3240723-10-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129726 From: Ankur Tyagi Backport commit identified by Debian[1] to the original file which was renamed by upstream commit[2]. Details: https://nvd.nist.gov/vuln/detail/cve-2026-32740 [1]https://security-tracker.debian.org/tracker/CVE-2026-32740 [2]https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-32740.patch | 40 +++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch new file mode 100644 index 0000000000..e6ce0e01f4 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch @@ -0,0 +1,40 @@ +From eec74f24bf52764d870988bade74cd35075a09df Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Mon, 18 May 2026 18:03:01 +0200 +Subject: [PATCH] fix integer overflow when computing chroma sizes + +CVE: CVE-2026-32740 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/6721f307ad684804b735e917dde7d372c5faae31] + +Upstream commit[1] renamed libheif/pixelimage.cc as libheif/image/pixelimage.cc +Backport changes to the original file. + +[1] https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281 + +Signed-off-by: Ankur Tyagi +--- + libheif/pixelimage.cc | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/libheif/pixelimage.cc b/libheif/pixelimage.cc +index a8ab7397..da62ea88 100644 +--- a/libheif/pixelimage.cc ++++ b/libheif/pixelimage.cc +@@ -54,7 +54,7 @@ uint32_t chroma_width(uint32_t w, heif_chroma chroma) + switch (chroma) { + case heif_chroma_420: + case heif_chroma_422: +- return (w+1)/2; ++ return w/2 + (w & 1); // note: prevents integer overflow + default: + return w; + } +@@ -64,7 +64,7 @@ uint32_t chroma_height(uint32_t h, heif_chroma chroma) + { + switch (chroma) { + case heif_chroma_420: +- return (h+1)/2; ++ return h/2 + (h & 1); // note: prevents integer overflow + default: + return h; + } diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index ba16ee7afe..df7f0c56e1 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -10,6 +10,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master; file://CVE-2026-3949.patch \ file://CVE-2026-32738.patch \ file://CVE-2026-32739.patch \ + file://CVE-2026-32740.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97216 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 089ABC624DD for ; Thu, 3 Sep 2026 09:50:35 +0000 (UTC) Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4195.1788429025015129357 for ; Thu, 03 Sep 2026 02:50:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=XGw8+Ffd; spf=pass (domain: gmail.com, ip: 209.85.210.179, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-85339ed040aso1791808b3a.1 for ; Thu, 03 Sep 2026 02:50:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429024; x=1789033824; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iT/99nukjRp0VaRHGIIqFmcgOaEPb19MCQXcmwnLYMU=; b=XGw8+FfdRg9jBTrzpM++xa8mp7+Gq10pxQwtiOr252HUqM0nEARl6bNIaONbRI/0AJ tR7cYWbRrh9rYpzNR+mTOVz/olMHl9ouERgdWyXv3lFDV6viYEYeitbdOyPS7nKfPzK5 xRQtDww4iSzIryCsr8pjT/8BuCuz59/9rZ/SIzfcHvjhkR/q4zQ0br7F/HOqPGrP5v8w 0cBs4pvXy92FpqAJgW9oRvU7lU+ssg1pi/aL5NaBXQL9VaCR+5hsIhmJB1kabyrMH/72 jeF0D4OY5qJXnujgEmtopoXjCM/PQE8M+BUaL2K+YiThCb0t9seXoXKUbqIA3SntYjxs C5Rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429024; x=1789033824; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=iT/99nukjRp0VaRHGIIqFmcgOaEPb19MCQXcmwnLYMU=; b=UVPeL1vMHzIu3XEq6ubvBqZYekJtiX40/SWRBkwWm2wdayWNGyT0B46PCESMpGHmF7 Q5gjUm+mlSBLT7olJ/d5z3aB2aGlHBFYs91o5dybP7TINg5pQ3PfLTDkmefEOYKLVkgU 8AxIxO/CD/Mje0bVWWUocUto//qZ9Ab6Es5eaNwoMqFkSiu1/+CjeGandiLwhw/T/we7 EFjhOJvYhgYbAlAUO+laXEjSaiANlYOKQyqIMl6iTiUD2B023eswX+F9BhjIAtY0XqlF 8Sc/27tG2Mi4b+ySN1Q52/DpLhYCnxg18dcrhDnfFO/LipnxbPBKU9fPpiAemWw//UDu KdIA== X-Gm-Message-State: AFuF++kexyVMY5Rc5ORJAej3itneDJw3rovu7X3lPb1TWT6XFNCDC2re mzJchofNVfMdf1GE+bCJU5Muir8Jkc4/HebtPDh6wetApD2/S+Vk1ZvtaoZ+n1t0 X-Gm-Gg: AYBFou0uyjBKgf7peIk3/tNC9zEuUMbGmQ1MY0S8h2SJQzWwE4kTJY0SU1f9FMDajza 4awTzGSx9OQiTiuJ2GjPPqgBiFiN1ix14QxPddoh952CY7F8MTFne9bSXGB+DrKcrFV0D9i3ZYF m5wuIzZiQShW1PArQ0DuzT/rCIfT1L5PdNwAc+BUFYaNiefGjT3rGgdUeeHOHOT+rgkQ8fbi4Um pg/BkftLHq6TIByI1H/vccqsES2zPv1qCeQCFSDEtgHVilDbPIeAqKpp9lGpK3sgvkDK+lZJW5B pthhlryWIFS5Qd8NBF5wkNIhykS694alfy3TVYnVY/oH6HpCHsNJAhMQU45gH338h9sfQIQF8zE ahYa618Jn++/oQKZqLtAI7o0qaXHFNYI8JuLJlnrVPIKL2Dcc2dq6/gFAILwrMML98X+IlKIAq+ aeRpET0a/g06CZ1pmvtRn6L2w6K9daYlx3G6HN6LxKsc7JVAoDWVk+sYYP7dpekpALSdePE/m5 X-Received: by 2002:a05:6a00:4286:b0:857:4dea:e20e with SMTP id d2e1a72fcca58-85ecef11451mr16638880b3a.0.1788429023747; Thu, 03 Sep 2026 02:50:23 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:23 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 Date: Thu, 3 Sep 2026 21:49:42 +1200 Message-ID: <20260903094954.3240723-11-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129727 From: Ankur Tyagi Backport commit identified by Debian[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-32741 [1]https://security-tracker.debian.org/tracker/CVE-2026-32741 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-32741.patch | 29 +++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 30 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch new file mode 100644 index 0000000000..cd550aafa5 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch @@ -0,0 +1,29 @@ +From 3c38488fa2ea31928fcad8f6a5010c1f6f0c1ace Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Thu, 5 Mar 2026 19:00:57 +0100 +Subject: [PATCH] fix possible buffer overflow when reading mask image + +(cherry picked from commit 123694271ac02f2de68a3ccdc5d483eb8a2ae593) + +CVE: CVE-2026-32741 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/123694271ac02f2de68a3ccdc5d483eb8a2ae593] +Signed-off-by: Ankur Tyagi +--- + libheif/image-items/mask_image.cc | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/libheif/image-items/mask_image.cc b/libheif/image-items/mask_image.cc +index 328d1797..1c4357ff 100644 +--- a/libheif/image-items/mask_image.cc ++++ b/libheif/image-items/mask_image.cc +@@ -113,8 +113,8 @@ Error MaskImageCodec::decode_mask_image(const HeifContext* context, + + size_t stride; + uint8_t* dst = img->get_plane(heif_channel_Y, &stride); +- if (((uint32_t)stride) == width) { +- memcpy(dst, data.data(), data.size()); ++ if (stride == static_cast(width)) { ++ memcpy(dst, data.data(), static_cast(width) * height); + } + else + { diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index df7f0c56e1..92891cb5ef 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -11,6 +11,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master; file://CVE-2026-32738.patch \ file://CVE-2026-32739.patch \ file://CVE-2026-32740.patch \ + file://CVE-2026-32741.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97217 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CE5F9C624DA for ; Thu, 3 Sep 2026 09:50:34 +0000 (UTC) Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4058.1788429027223686844 for ; Thu, 03 Sep 2026 02:50:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=TYlyyb1q; spf=pass (domain: gmail.com, ip: 209.85.210.182, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-84e84a6c4bfso839040b3a.1 for ; Thu, 03 Sep 2026 02:50:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429027; x=1789033827; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ohda+GjkE1pzhK8s1gNpW3ESsrfnedrHSixqBsykdmg=; b=TYlyyb1qKx3uPnswlSRkyc7Xim3rP3g/xpf+em+pFoQKPJy6fLUTmllOveL0fgFZol uHHJq9eaMqSxiAVy8J3NkXzEO8CqPi9UkaWJsn/ubQGjqi/zn8039PN3nvzkJGSSKoyZ 7wwozvVb4uuF1oCzOEPAVTkdpKlPeiVGQgaUJSvSXswb55sXpMjVyYIhIrIMdJA2rEQd wZa0eqNG9q8r++pLTshzEIqm270RuiiyyPzRw10LWufTS1C1JTDMrttBvnrBQaRE/oGq 1afCipJhh72dXY2ldJymnAjPJR320rpOREiGPnzcFQ7PZCxg6FCOMUldWxQ/5JLSgs06 MFhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429027; x=1789033827; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ohda+GjkE1pzhK8s1gNpW3ESsrfnedrHSixqBsykdmg=; b=S7Wu9VzXzdZO/bvRYdknyWtOuAi9QMT21sbexkFx1MZt1d0ExKgBWTOa+8ol2vKxH5 AfV228E60RpgEeV/isp28qgdBMdY5jyXb+7q7M+IhhVraYIOb2zDWqQhTBgLoKOojbF0 uoCJda7hZBO0JkJDLsx4/3PlPwrkdz+hC2DkshWZr4xVJrMSv3leH6LsEIixq1a5Bcg6 yW1xxkICnn1XHQUrXFrVIWpgdNrh6fsC7g0XHkLzBBeSJ0NCAXG013SaKU8xcoTCHgvV Es1rXylK2MySCNUJ59KblZA/AC6wvO3ngUO6Rr+HPC3gL7me69/12vj0X1F8/+f6szYm 7ocQ== X-Gm-Message-State: AFuF++mc+sySm/+8GFKv2qVXZnQjBII/N1QerA0/ohSbna7/ww5wI0MQ TD+3fvgsQMNIEhnSiY4dqGwCeFRHBR9QHV6Y66nHK4Ph1U60r8kt9Kxeb+ztWtx2 X-Gm-Gg: AYBFou2anP/+sePkLSrIAYJY6treU+jnbPwiQMDPLQHtiU3iut702NoOzrSiJv/uEN6 dF354fqbM8+R1YAGtBN0Ql33+61dRPPW2VoILjcUt+SLzwtyR58TuFIGrHCBamgCsVGebSRHxKI F+lOIa0OZDiGJ72v3SXol7zb+MGVYyCBUXJTLl/3DZvD6bP8yN3MEuGcPExKptmf11K/SqISMxb 4Z2bbWJAQzKF+MtGJ9FnkSIYHLHTcESOW+I2aTnU29Qb9fwhnKPe2F1z0LsokwQBW3uNlEfPoRj BtxwNu8LpBLEUQ0AkE+bxT13jzN9XyOtBh3QKG55bKW2i7558R/vAFUN4u+o86wvhV2bJw0DHRR HDG81b5L9nggzUZ6toagcRADVlSOUCJPSYU0ac3Rk49gAcVnPL2YA5aonUdzTwCt96cAElmASTn 1ANnyLzuJpL3W1NFl7lA+6Yt+rPy7SWphu22DTuqmesRVWU5GFnMh+vW7cpgsFjIaBb4yhAUt7S usDx4/OF6s= X-Received: by 2002:a05:6a00:22ca:b0:84b:e69f:1b3f with SMTP id d2e1a72fcca58-8606687fc79mr2341594b3a.8.1788429026517; Thu, 03 Sep 2026 02:50:26 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:26 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 Date: Thu, 3 Sep 2026 21:49:43 +1200 Message-ID: <20260903094954.3240723-12-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129728 From: Ankur Tyagi Backport commit identified by Debian[1] Also backport[2] which is needed to cherry-pick[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-41071 [1]https://security-tracker.debian.org/tracker/CVE-2026-41071 [2]https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-41071-1.patch | 34 ++++++++++++++ .../libheif/libheif/CVE-2026-41071-2.patch | 44 +++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 2 + 3 files changed, 80 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch new file mode 100644 index 0000000000..7971ea3cef --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch @@ -0,0 +1,34 @@ +From 415b59839dcf46bb05e08de7422a21e65ab28e03 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Mon, 13 Apr 2026 19:49:06 +0200 +Subject: [PATCH] fix: reject malformed sequence files with saiz samples but no + chunks + +(cherry picked from commit 71755d3d41a117685a3274bdd1214fc50a760f20) + +CVE: CVE-2026-41071 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20] +Signed-off-by: Ankur Tyagi +--- + libheif/sequences/track.cc | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc +index acb916fa..ac5d5687 100644 +--- a/libheif/sequences/track.cc ++++ b/libheif/sequences/track.cc +@@ -443,6 +443,14 @@ Error Track::load(const std::shared_ptr& trak_box) + }; + } + ++ if (saio->get_num_chunks() != 1 && m_chunks.empty() && saiz->get_num_samples() > 0) { ++ return Error{ ++ heif_error_Invalid_input, ++ heif_suberror_Unspecified, ++ "'saiz' box references samples but no chunks exist." ++ }; ++ } ++ + if (aux_info_type == fourcc("suid")) { + m_aux_reader_content_ids = std::make_unique(saiz, saio, m_chunks); + } diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch new file mode 100644 index 0000000000..952c366966 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch @@ -0,0 +1,44 @@ +From b79d7d2a4f1502e93739453025ac2dbfd59e514f Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Mon, 13 Apr 2026 20:09:26 +0200 +Subject: [PATCH] fix: reject malformed sequence files where saiz sample count + exceeds actual samples + +(cherry picked from commit f20c81745e917b4c496615140385c86d7a2fa58d) +CVE: CVE-2026-41071 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d] +Signed-off-by: Ankur Tyagi +--- + libheif/sequences/track.cc | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc +index ac5d5687..e4b08afa 100644 +--- a/libheif/sequences/track.cc ++++ b/libheif/sequences/track.cc +@@ -138,7 +138,9 @@ SampleAuxInfoReader::SampleAuxInfoReader(std::shared_ptr saiz, + for (uint32_t i = 0; i < nSamples; i++) { + if (!oneChunk && i > chunks[current_chunk]->last_sample_number()) { + current_chunk++; +- assert(current_chunk < chunks.size()); ++ if (current_chunk >= chunks.size()) { ++ break; ++ } + offset = saio->get_chunk_offset(current_chunk); + } + +@@ -451,6 +453,14 @@ Error Track::load(const std::shared_ptr& trak_box) + }; + } + ++ if (saiz->get_num_samples() > m_stsz->num_samples()) { ++ return Error{ ++ heif_error_Invalid_input, ++ heif_suberror_Unspecified, ++ "Number of samples in 'saiz' box exceeds actual number of samples." ++ }; ++ } ++ + if (aux_info_type == fourcc("suid")) { + m_aux_reader_content_ids = std::make_unique(saiz, saio, m_chunks); + } diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index 92891cb5ef..f3f03abdc7 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -12,6 +12,8 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master; file://CVE-2026-32739.patch \ file://CVE-2026-32740.patch \ file://CVE-2026-32741.patch \ + file://CVE-2026-41071-1.patch \ + file://CVE-2026-41071-2.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97218 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E5248C624DB for ; Thu, 3 Sep 2026 09:50:34 +0000 (UTC) Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4197.1788429029700951171 for ; Thu, 03 Sep 2026 02:50:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=RMi7uau/; spf=pass (domain: gmail.com, ip: 209.85.210.169, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-84f3ab8750cso1757061b3a.0 for ; Thu, 03 Sep 2026 02:50:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429029; x=1789033829; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uH+WFZpYPMGcyNdGLX9S0238HKwi0ufjoPk5hsnRTks=; b=RMi7uau/L+o7XHsVGQMsC+V28KGdqxAd/KxueHS2yYLZn5fA2pGZ+vNycZIJHCNR9c 3WTmkK3u7W2EPLK/IAfKVkyTFG7/EvoJCLwWNpvSiMAzYcOpp0unvQx+KxLtzSEBCfm4 /zvmhPi1xMYKBBruPXPAYejrpECV66tXCdEaNEg0NKQDIW/FZbJZKn2JJcwTkjYRZucg tWwB0c9OY79gtnd0anXA6TKnv2YOtdgM0d17mj+yr7v3FkoIoU+y6Vrku1NRlGkytf/Q I8RQVgvKDZ4s5HOMP9rpMAyfbju+9xtlzta86RAo5cJ+fkRXfQTtG6w6BpjKO6mFTkmn mWOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429029; x=1789033829; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uH+WFZpYPMGcyNdGLX9S0238HKwi0ufjoPk5hsnRTks=; b=NyAVTsXZZczG8493+sUT5NmbivePaCbVX24GgHYkFfNNDaDvzm5XLVSg9DO6B5d6u9 bhgxGgTE/Tld3rSk76W2PX6r4RZChmwYeNy7RQkHFe8wh17A+HFaVdQ+5WtYntbKY0BL iMKhxodSHbswfynbCxw6h62g+0S1TSN/a7+qKXXzl+5RrIcUcVwJhY+w6LH9lk7U5b2F r0zkB33k+tuG1maRzI+B3sMtbY/la3Gd0zQqkfnuKLqHy7WgLQE5/aPRX3nGnmnY4Zvk PsY+XmEKNUWNs4FS12HHLt+Vq7LWux7IQyEQUl06iJBBFNvf+Rbqfcm7cRtV/Ga5R0xP TVvQ== X-Gm-Message-State: AFuF++kD5CJbeie7tAj2NuE5dbo4NUv1ovNG2NVCniHZ2OQp1nlLfHdp e9PvPSN0BXvBMv/pJyE/jhPDSujZvqw68s+oaztViDXjLAdTiCvwWodLRGtRPoNw X-Gm-Gg: AYBFou0rzpn2ekp6Pl6mK+2TT/mSu67wQwt5uG2mWX3aHMF8ZyAOeK6+pUhF+NTKNRH ABX4xBwZ5vU+AeJqhl7bO89uT7cXODKG4HS297ZQgpXNWMwrUMO2Af0wi87TBiEs0qpxlZqa4yM fZjpmYDDdjy+oiQdPpwQARvAp2h0znX6Chaf7Mbpg1P2P2uf415oYF/iresDgD2X5KpFhulTmCm 2dLisT/3kyZTRfODN5/Kox6CMUdtn1NWL00k0pyfmd7q2Vgm4Odl7OO+KJOg3ukKyCLKQqjmDU6 XDxXJEY9RlVU3UCfQutbVPabzLiKF3sEMHoFX3SeCwKF6OZopL3z7xPGVqnbJBhtBpQVUtwlxRC SETSLaOgDrRkU5A0D6SN8qdYi30hlqfaDueGIV8KuIKd67MxZ+J0cB49NMA9LmR/hvfdakNiMbj 72x2yJs+1+9tq5BkMjO9lpjVfSQ7eqL6plTdIEfDTUFuEc1sTr1aU/schqjrz4U6KDiStpXJDMd 4jBQJDBi7U= X-Received: by 2002:a05:6a00:2305:b0:857:7384:b5fd with SMTP id d2e1a72fcca58-85ed5015dfemr11243090b3a.25.1788429028861; Thu, 03 Sep 2026 02:50:28 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:28 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 Date: Thu, 3 Sep 2026 21:49:44 +1200 Message-ID: <20260903094954.3240723-13-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129729 From: Ankur Tyagi Backport commit identified by Debian[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-62289 [1]https://security-tracker.debian.org/tracker/CVE-2026-62289 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-62289.patch | 189 ++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 190 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch new file mode 100644 index 0000000000..5473a2ae18 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch @@ -0,0 +1,189 @@ +From 49e188ca7a6a81fd1c7d5e76254308c82cbcb5c3 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Thu, 25 Jun 2026 19:58:57 +0200 +Subject: [PATCH] Fix clap transform double-application in image tiling + (GHSA-jc8f-p23p-5hjg) + +The base ImageItem::get_heif_image_tiling() returned the already +transformed m_width/m_height, but process_image_transformations_on_tiling() +applies the transformative properties (irot, imir, clap) itself. This +applied every transform twice. For a clap that rounds the image down to +zero, the second application passed 0 into Box_clap::left_rounded(), where +`image_width - 1U` underflowed to UINT32_MAX and overflowed the Fraction +constructor (assert abort in debug builds, corrupt crop in release builds). +The grid, unc and tiled overrides already return coded dimensions, so the +base class was the lone outlier. + +Fixes, in three layers: + + - image_item.cc: base get_heif_image_tiling() now reports coded (ispe) + dimensions when available, matching the other overrides, so transforms + are applied exactly once. This also fixes a silent irot/imir + double-transform on the same path. + - context.cc: reject a clap that rounds a dimension to zero or less at + parse time, mirroring the existing ispe zero-size check. + - box.cc: guard left_rounded()/top_rounded() against a zero image + dimension as defense in depth. + +Add tests/clap_zero_size.cc covering the hardened clap helpers. + +(cherry picked from commit f01870c1d7323a3003796d58eba7fff502be994c) + +CVE: CVE-2026-62289 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c] +Signed-off-by: Ankur Tyagi +--- + libheif/box.cc | 11 ++++++++ + libheif/context.cc | 12 +++++++-- + libheif/image-items/image_item.cc | 23 ++++++++++++++--- + tests/CMakeLists.txt | 1 + + tests/clap_zero_size.cc | 42 +++++++++++++++++++++++++++++++ + 5 files changed, 83 insertions(+), 6 deletions(-) + create mode 100644 tests/clap_zero_size.cc + +diff --git a/libheif/box.cc b/libheif/box.cc +index 76ba0f0a..57912ab0 100644 +--- a/libheif/box.cc ++++ b/libheif/box.cc +@@ -3592,6 +3592,12 @@ int Box_clap::left_rounded(uint32_t image_width) const + + // left = horizOff + (width-1)/2 - (clapWidth-1)/2 + ++ // Guard against image_width==0: `image_width - 1U` would underflow to ++ // UINT32_MAX and overflow the Fraction (GHSA-jc8f-p23p-5hjg). ++ if (image_width == 0) { ++ return 0; ++ } ++ + Fraction pcX = m_horizontal_offset + Fraction(image_width - 1U, 2U); + Fraction left = pcX - (m_clean_aperture_width - 1) / 2; + +@@ -3607,6 +3613,11 @@ int Box_clap::right_rounded(uint32_t image_width) const + + int Box_clap::top_rounded(uint32_t image_height) const + { ++ // Guard against image_height==0 underflowing the Fraction (see left_rounded). ++ if (image_height == 0) { ++ return 0; ++ } ++ + Fraction pcY = m_vertical_offset + Fraction(image_height - 1U, 2U); + Fraction top = pcY - (m_clean_aperture_height - 1) / 2; + +diff --git a/libheif/context.cc b/libheif/context.cc +index a1bcc268..a3371207 100644 +--- a/libheif/context.cc ++++ b/libheif/context.cc +@@ -644,8 +644,16 @@ Error HeifContext::interpret_heif_file_images() + for (const auto& prop : properties) { + auto clap = std::dynamic_pointer_cast(prop); + if (clap) { +- image->set_resolution(clap->get_width_rounded(), +- clap->get_height_rounded()); ++ int clap_width = clap->get_width_rounded(); ++ int clap_height = clap->get_height_rounded(); ++ if (clap_width <= 0 || clap_height <= 0) { ++ return {heif_error_Invalid_input, ++ heif_suberror_Invalid_clean_aperture, ++ "Clean aperture (clap) reduces image to zero size"}; ++ } ++ ++ image->set_resolution(static_cast(clap_width), ++ static_cast(clap_height)); + + if (image->has_intrinsic_matrix()) { + image->get_intrinsic_matrix().apply_clap(clap.get(), image->get_width(), image->get_height()); +diff --git a/libheif/image-items/image_item.cc b/libheif/image-items/image_item.cc +index e803107f..d05536e1 100644 +--- a/libheif/image-items/image_item.cc ++++ b/libheif/image-items/image_item.cc +@@ -967,10 +967,25 @@ heif_image_tiling ImageItem::get_heif_image_tiling() const + tiling.num_columns = 1; + tiling.num_rows = 1; + +- tiling.tile_width = m_width; +- tiling.tile_height = m_height; +- tiling.image_width = m_width; +- tiling.image_height = m_height; ++ // Report the coded (pre-transformation) dimensions here. The caller applies ++ // the transformative properties (irot, imir, clap) via ++ // process_image_transformations_on_tiling(), so handing it the already ++ // transformed m_width/m_height would apply them a second time. For a clap ++ // that shrinks the image to zero this double application underflowed inside ++ // Box_clap::left_rounded() (GHSA-jc8f-p23p-5hjg); for irot/imir it silently ++ // produced wrong dimensions. The grid/unc/tiled overrides likewise report ++ // coded dimensions. ++ uint32_t coded_width = m_width; ++ uint32_t coded_height = m_height; ++ if (has_ispe_resolution()) { ++ coded_width = get_ispe_width(); ++ coded_height = get_ispe_height(); ++ } ++ ++ tiling.tile_width = coded_width; ++ tiling.tile_height = coded_height; ++ tiling.image_width = coded_width; ++ tiling.image_height = coded_height; + + tiling.top_offset = 0; + tiling.left_offset = 0; +diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt +index d8fdfd8b..b52bc202 100644 +--- a/tests/CMakeLists.txt ++++ b/tests/CMakeLists.txt +@@ -38,6 +38,7 @@ if (WITH_REDUCED_VISIBILITY) + else() + add_libheif_test(bitstream_tests) + add_libheif_test(box_equals) ++ add_libheif_test(clap_zero_size) + add_libheif_test(conversion) + add_libheif_test(idat) + add_libheif_test(jpeg2000) +diff --git a/tests/clap_zero_size.cc b/tests/clap_zero_size.cc +new file mode 100644 +index 00000000..eafc1258 +--- /dev/null ++++ b/tests/clap_zero_size.cc +@@ -0,0 +1,42 @@ ++/* ++ libheif clean aperture (clap) zero-size unit tests ++ ++ MIT License ++ ++ Copyright (c) 2026 Dirk Farin ++ ++ Permission is hereby granted, free of charge, to any person obtaining a copy ++ of this software and associated documentation files (the "Software"), to deal ++ in the Software without restriction, including without limitation the rights ++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ copies of the Software, and to permit persons to whom the Software is ++ furnished to do so, subject to the following conditions: ++ ++ The above copyright notice and this permission notice shall be included in all ++ copies or substantial portions of the Software. ++ ++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ SOFTWARE. ++*/ ++ ++#include "catch_amalgamated.hpp" ++#include "box.h" ++ ++// Regression test for GHSA-jc8f-p23p-5hjg: passing a zero image dimension to ++// the clap rounding helpers used to underflow `image_width - 1U` to UINT32_MAX, ++// which overflowed the Fraction constructor (assert abort in debug builds, ++// corrupt crop in release builds). They must now return 0 without aborting. ++TEST_CASE("clap rounding with zero image size") { ++ std::shared_ptr clap = std::make_shared(); ++ clap->set(100, 200, 150, 250); // clap 100x200 inside a 150x250 image ++ ++ REQUIRE(clap->left_rounded(0) == 0); ++ REQUIRE(clap->right_rounded(0) == 99); // clapWidth - 1 + left(0) ++ REQUIRE(clap->top_rounded(0) == 0); ++ REQUIRE(clap->bottom_rounded(0) == 199); // clapHeight - 1 + top(0) ++} diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index f3f03abdc7..1dfab46513 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -14,6 +14,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master; file://CVE-2026-32741.patch \ file://CVE-2026-41071-1.patch \ file://CVE-2026-41071-2.patch \ + file://CVE-2026-62289.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97219 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 09B61C79F80 for ; Thu, 3 Sep 2026 09:50:35 +0000 (UTC) Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4199.1788429031745766031 for ; Thu, 03 Sep 2026 02:50:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Vv6JkEhg; spf=pass (domain: gmail.com, ip: 209.85.210.177, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-84f3ab8750cso1757074b3a.0 for ; Thu, 03 Sep 2026 02:50:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429031; x=1789033831; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VN8RJmq80pkVDawU7RF01ZSghwDNDUd81KtnchzoY1o=; b=Vv6JkEhg4HE3NYyp51t7xJvk5Kg/xNpE21kIVG1oMdEnk8xOKMuui7SMFJ3uJbTHac IWnTbb7FrO0nQV04ePjveNdzAZ/huovkNKTDWP90eOMPdfAx+RBXQt0XdJRH+zgKkpX8 akgawnGdrZKccJ9wMTA8jnxvUkx6G5KS7jyYrx/pVhPk+KLslNBJ9SWgUXLCKmo1Et7O srg88XUEymLkzhFMmL+iEkHhC8F/ZgekJp184+oA4LJUfPI8SMlj8jvzVLYEEnxaY1pK wdH8WJt5DQq93DSuu6CG4IgmQJ9m0pTeIVgVVDDParJQcZAqAoOIGOCBl+TPRVS8O4Lo NrQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429031; x=1789033831; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VN8RJmq80pkVDawU7RF01ZSghwDNDUd81KtnchzoY1o=; b=XrTW2b1KN7hrC0pLv6+JLEFqO7yB2SQ8NbkvDytEydJTV6MkXIeWg5H7zrd4WZv+iI ckfU0nBVOc1RR2aaYvFcWoUHG959Jb9y+vqwNoKz2cH9I+M1fEui49EBYrhBtfFFo4hN hlZjH0ewLaXr5od/urxU4051IDleOIFmV168DUgsE5MColVDQ43K+zBfwvI0vhYS4K7g ZsIFYKW0bQnxbRV26Z65Tn71N07SOg5qUdZRGb61iOFoEeMP/0Zzf6a26pKr83U560eZ i3ZvqcNDiDX7yKH83nf6et4Sscw8OxHp3UPPFFCX0oSKqNzI/vZmR328D3eocVjwq5MM rCNg== X-Gm-Message-State: AFuF++lbE2mXin4lUK2/xVYGp7uz/lcLeHiiELqZf8nkNLH7OZ3D36dq dhYb7dgZZZ1pYzXoYfhmc7aF/O/hgXdRBq6yfVRnJWlWdMpJf8tMm/gUkXRAD+35 X-Gm-Gg: AYBFou3Qa2MJupG02INPCp9YrqXDPEVjiaPV2IPDVlF6MwDTSFAXCqr9ar72+uVuyt9 8rPaDH0kUXbl3YSWNTtv1U9hBT4IOBiNFmRUQ/PHdeA+IbqBmSbuQRcA+S+0kcL+VDq2kW3zdY6 fqF8fVTHcsOdPXQsOv5/RclVMlrfYRbN/qw35ndYSUEyGTBMXehkU5TyA49hzCfAobdKI6ntHaq NVQswlUjaY+GzAPjalp0a9ZfjWpA1YjIWX3ArAuL+b3Rcjrvy/YsD/AILp6lsxwJWZ6ZbsAi2v5 Hu8saqSA4Y1XL5aVumOKpBEGTlbnairnNIGplUibBW4T/Vo4xolIZO7NLX09CIqK640opPSWn9Q olbUTDCVGd9Phmkd0EwAXql+MuUpKux83wredzJ6hdF3e5ouM49G30h1RFI5GZfVQYiMi/6P7va 3or8AfIJK0nPU7+Npo1vujseeu6oIduODC/phDHx7bbqmhgvfou+JLhDFXmnKpzr+RvRM8CFM5 X-Received: by 2002:a05:6a00:1d8e:b0:84c:5b65:ef86 with SMTP id d2e1a72fcca58-85ed454a639mr16388279b3a.17.1788429030974; Thu, 03 Sep 2026 02:50:30 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:30 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 Date: Thu, 3 Sep 2026 21:49:45 +1200 Message-ID: <20260903094954.3240723-14-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129730 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/CVE-2026-62377 Signed-off-by: Ankur Tyagi --- .../libheif/libheif/CVE-2026-62377.patch | 175 ++++++++++++++++++ .../libheif/libheif_1.21.2.bb | 1 + 2 files changed, 176 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch new file mode 100644 index 0000000000..5481c198b6 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch @@ -0,0 +1,175 @@ +From cace54a7491cd8eb46617f17ca7078182d9903b0 Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Fri, 26 Jun 2026 10:03:31 +0200 +Subject: [PATCH] Return error instead of asserting in get_track() without + sequence (#1844) + +HeifContext::get_track() asserted has_sequence() up front. Calling the +public heif_context_get_track() on a context that has no sequence tracks +(e.g. a still image, or a crafted sequence file accepted with zero tracks) +therefore aborted the process via the assert, instead of letting the public +wrapper return the documented nullptr. In NDEBUG builds the assert was +compiled out and the track_id==0 path dereferenced begin() on an empty map. + +Replace the assert with a normal error return so the public wrapper hands +the caller nullptr as documented. + +(cherry picked from commit e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3) + +CVE: CVE-2026-62377 +Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3] + +Signed-off-by: Ankur Tyagi +--- + libheif/context.cc | 9 +++- + tests/CMakeLists.txt | 1 + + tests/sequence_no_track.cc | 108 +++++++++++++++++++++++++++++++++++++ + 3 files changed, 117 insertions(+), 1 deletion(-) + create mode 100644 tests/sequence_no_track.cc + +diff --git a/libheif/context.cc b/libheif/context.cc +index a3371207..170f8314 100644 +--- a/libheif/context.cc ++++ b/libheif/context.cc +@@ -1945,7 +1945,14 @@ std::vector HeifContext::get_track_IDs() const + + Result> HeifContext::get_track(uint32_t track_id) + { +- assert(has_sequence()); ++ // The caller is expected to have confirmed (via has_sequence()) that there are ++ // sequence tracks before requesting one. Guard against an empty track map anyway, ++ // since this is reachable through the public API (e.g. on a still image file). ++ if (!has_sequence()) { ++ return Error{heif_error_Usage_error, ++ heif_suberror_Unspecified, ++ "File contains no sequence tracks"}; ++ } + + if (track_id != 0) { + auto iter = m_tracks.find(track_id); +diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt +index b52bc202..d66ffb38 100644 +--- a/tests/CMakeLists.txt ++++ b/tests/CMakeLists.txt +@@ -59,6 +59,7 @@ endif() + add_libheif_test(encode) + add_libheif_test(extended_type) + add_libheif_test(region) ++add_libheif_test(sequence_no_track) + add_libheif_test(tai) + add_libheif_test(text) + add_libheif_test(cxx_wrapper) +diff --git a/tests/sequence_no_track.cc b/tests/sequence_no_track.cc +new file mode 100644 +index 00000000..cde11f77 +--- /dev/null ++++ b/tests/sequence_no_track.cc +@@ -0,0 +1,108 @@ ++/* ++ libheif regression test for requesting a track from a context without sequence tracks. ++ ++ MIT License ++ ++ Copyright (c) 2026 Dirk Farin ++ ++ Permission is hereby granted, free of charge, to any person obtaining a copy ++ of this software and associated documentation files (the "Software"), to deal ++ in the Software without restriction, including without limitation the rights ++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ copies of the Software, and to permit persons to whom the Software is ++ furnished to do so, subject to the following conditions: ++ ++ The above copyright notice and this permission notice shall be included in all ++ copies or substantial portions of the Software. ++ ++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ SOFTWARE. ++*/ ++ ++#include "catch_amalgamated.hpp" ++#include "libheif/heif.h" ++#include "libheif/heif_sequences.h" ++#include "test_utils.h" ++ ++#include ++#include ++ ++namespace { ++ ++// Sequence API queries that must work on a context that holds no sequence ++// tracks (a still image, or no image at all). heif_context_get_track() is ++// documented to return nullptr on failure; it must not abort/crash. This ++// formerly tripped assert(has_sequence()) in HeifContext::get_track(). ++// See https://github.com/strukturag/libheif/issues/1844. ++void check_no_sequence_apis(heif_context* ctx) ++{ ++ REQUIRE(heif_context_has_sequence(ctx) == 0); ++ REQUIRE(heif_context_number_of_sequence_tracks(ctx) == 0); ++ ++ // Listing track IDs must work (and write nothing) when there are no tracks. ++ heif_context_get_track_ids(ctx, nullptr); ++ ++ heif_track* track = heif_context_get_track(ctx, 0); ++ REQUIRE(track == nullptr); ++} ++ ++heif_error mem_writer(heif_context*, const void* data, size_t size, void* userdata) ++{ ++ auto* out = static_cast*>(userdata); ++ const auto* p = static_cast(data); ++ out->insert(out->end(), p, p + size); ++ return heif_error{heif_error_Ok, heif_suberror_Unspecified, nullptr}; ++} ++ ++} ++ ++TEST_CASE("get_track on context without sequence returns nullptr") ++{ ++ heif_context* ctx = heif_context_alloc(); ++ REQUIRE(ctx != nullptr); ++ ++ // Fresh context, nothing loaded: no sequence tracks present. ++ check_no_sequence_apis(ctx); ++ ++ heif_context_free(ctx); ++} ++ ++TEST_CASE("get_track on a still-image file returns nullptr") ++{ ++ // Encode a tiny still image to an in-memory HEIF file, then read it back. ++ // A still image is a perfectly valid file that contains no sequence tracks. ++ heif_image* img = nullptr; ++ REQUIRE(heif_image_create(16, 16, heif_colorspace_YCbCr, heif_chroma_420, &img).code == heif_error_Ok); ++ fill_new_plane(img, heif_channel_Y, 16, 16); ++ fill_new_plane(img, heif_channel_Cb, 8, 8); ++ fill_new_plane(img, heif_channel_Cr, 8, 8); ++ ++ heif_encoder* enc = get_encoder_or_skip_test(heif_compression_HEVC); ++ ++ heif_context* enc_ctx = heif_context_alloc(); ++ REQUIRE(heif_context_encode_image(enc_ctx, img, enc, nullptr, nullptr).code == heif_error_Ok); ++ ++ std::vector file; ++ heif_writer writer{}; ++ writer.writer_api_version = 1; ++ writer.write = mem_writer; ++ REQUIRE(heif_context_write(enc_ctx, &writer, &file).code == heif_error_Ok); ++ ++ heif_encoder_release(enc); ++ heif_context_free(enc_ctx); ++ heif_image_release(img); ++ ++ // Read the still image back and query the sequence API on it. ++ heif_context* ctx = heif_context_alloc(); ++ REQUIRE(ctx != nullptr); ++ REQUIRE(heif_context_read_from_memory(ctx, file.data(), file.size(), nullptr).code == heif_error_Ok); ++ ++ check_no_sequence_apis(ctx); ++ ++ heif_context_free(ctx); ++} diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index 1dfab46513..165ed0ad2a 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -15,6 +15,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master; file://CVE-2026-41071-1.patch \ file://CVE-2026-41071-2.patch \ file://CVE-2026-62289.patch \ + file://CVE-2026-62377.patch \ " SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5" From patchwork Thu Sep 3 09:49:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97215 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C1AECC624A4 for ; Thu, 3 Sep 2026 09:50:34 +0000 (UTC) Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4200.1788429033797542864 for ; Thu, 03 Sep 2026 02:50:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=RHc4mM0O; spf=pass (domain: gmail.com, ip: 209.85.210.181, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-84eb992a881so1908937b3a.2 for ; Thu, 03 Sep 2026 02:50:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429033; x=1789033833; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=OPKhVPpvw6zPqqUd4PTNa4h7g5W+4HHTSZ9W9OFdJjk=; b=RHc4mM0OsxF0zoUf8W6KZ+Cj37C1xz74v2uV0/WZFoGxtrLhJ6Aj4IlkmEpaXpvtF8 gN3+vHI2LH7XOispsLArJ1incw0uvMVgwY/pwpWGOzXkU8CtBHLWIW8fl7Mt9nhZ1cLq 4sQQiHaJqMnYEyzZSA5YV4AtclPqanaPUJEVfJZx08RVnKCkkc2shhjCSgmaR2B+Ji0c krSpwny1zh3kFVVtKFRKgmOfRByvYRxYKT8K3LtaaLxh60JQ+ORPvLFB9RMT93f4Q8QV HypOWZDuVXW9tWnAUeIghBsNupYzAiRmttZF2da3Jm0pPk5HRmKLMFWx7QVPP83EJqat R5Gg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429033; x=1789033833; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=OPKhVPpvw6zPqqUd4PTNa4h7g5W+4HHTSZ9W9OFdJjk=; b=NfuicSoFIkFtilTuhwfSjHZcji0N4VavwVi02i66j9lJPimScucJZg3On0i+f5uurz YRfbKLv8OY9FhS83WGGf62VDzpJuWw3bcFBjYnukxVfHCzgJH8rQK/o3YpTR6jTNcK1m iCO/62wrUAci/xCM2RKTtagcZRWUzWukWDmFZfaaKtI2WUYmZ3ewg9faBRFCd76oqcrZ E8v1vLRldjcvCPOTTiZKnt/b1KLbNigm0GHLXZupgPLUymyc5pjNfnELYCk22UZ+wTQL KXLNLiulNEwCCuRl1CBhwFqvFVG9w0NE+e64H1RuURmKhlj9bePdyfOysKemAU2Sxe7y /Ciw== X-Gm-Message-State: AFuF++lC9yfB2bGUxLxQZoEOaec5XpyRQJU3lYls3EO1XNUI8bf/lkb2 9+j3oG4s9sGBneW3h6xl2I0cuol/NKhV/SbRNQffaTmRqpJIoHmy3flH2YhUZDVF X-Gm-Gg: AYBFou3z+l1BUjBsnTNYlYzsrRw+53TZKMGAcmBL7WDy3kWyMb4seKxo7XHadpMj/gk z7cFpyI+2s3hgkV6keNZhw5Ba/I0FW4BZW/B/1DBWFOTNWsJkufWBjg7rDYftGqSSkm42+37qXj HhIZx5WGkePqMz2zhrc/myOMuM5dCJC37Fxw/b8mE6XaIzWVnBZPLFpy2AIVbGpphjCGllAFBvb MgoHs/WRRVc6k/LIwL830+hfyJWW2LpLApxJ+8v++h3gttc8CaBtRsax/TmCcA9zWQWNbTkMKsX IhmmrqFR8igYDK67aDfjVA5okaykk8rATg7zhkdr27YJ6+4chDxE8rhqh/MDO1cENmNdRo3ru9r 1VDfj1t4NLNHg8hU21mlPH5kPD/Cf+YmB+TMU1BdTd3Bk9cWaMnzgG9yTg0zzHEI0vSiLIzLys3 sK8AuySqGpDZGaamtTNtFBPXHfht/VWoY8CMeU0u9LuB2o4P97gpf0OnELjnwpERCdfhWfnC/T X-Received: by 2002:a05:6a00:bd8a:b0:857:7317:cff2 with SMTP id d2e1a72fcca58-85ed444a110mr17312952b3a.19.1788429033066; Thu, 03 Sep 2026 02:50:33 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:32 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched Date: Thu, 3 Sep 2026 21:49:46 +1200 Message-ID: <20260903094954.3240723-15-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129731 From: Ankur Tyagi NVD[1] mentions commit[2] for v1.5 but is also present in v1.6[3] [1] https://nvd.nist.gov/vuln/detail/cve-2024-45969 [2] https://github.com/mz-automation/libiec61850/commit/7afa40390b26ad1f4cf93deaa0052fe7e357ef33 [3] https://github.com/mz-automation/libiec61850/commit/d1ab50298fcba3f87b1e58dabff92f8615b14ee7 Signed-off-by: Ankur Tyagi --- .../recipes-connectivity/libiec61850/libiec61850_1.6.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb index c46ed88d83..5a76ba5330 100644 --- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb +++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb @@ -35,3 +35,5 @@ FILES:${PN} += " \ ${PYTHON_SITEPACKAGES_DIR}/pyiec61850.py \ ${PYTHON_SITEPACKAGES_DIR}/_pyiec61850.so \ " + +CVE_STATUS[CVE-2024-45969] = "fixed-version: fixed since v1.6.0" From patchwork Thu Sep 3 09:49:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97222 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4D948C624DA for ; Thu, 3 Sep 2026 09:50:45 +0000 (UTC) Received: from mail-pf1-f175.google.com (mail-pf1-f175.google.com [209.85.210.175]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4059.1788429035784033241 for ; Thu, 03 Sep 2026 02:50:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=rDLv4pOc; spf=pass (domain: gmail.com, ip: 209.85.210.175, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f175.google.com with SMTP id d2e1a72fcca58-8568e3ed034so1810256b3a.0 for ; Thu, 03 Sep 2026 02:50:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429035; x=1789033835; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hw4M/Nd9JH/lA2s5Ub9G1Ehe6QW2hftbwiOq1xq7c6c=; b=rDLv4pOcRd38V74Thgac87veU4iN0clagwQHkqmAcbGrJjw5l0CsBa4ecTliUX1aE0 RwSOlvC8xFga+jeTf4u/HGLKEEsMuQGbnyyba9j8ZDq62k/fcq172TqqcE8qyzB9UVJO 1qTAouFlnRG5beFDtzt+1irs/WiYqkpfd41S3yKQIM+9RmDCFqeDI4gWBpxdOEmnzR4t Dl8J0sgSDNng1T5Vk2T3XLnT9cLupP1wc0B0QXokMncoy1jws1ikPGCioxU2uJ9OfuTY eMtS4qk8eRZYnd0zkhoQrc7ga23WhNzzLNY8LsDe1okHV0wozeYcXDW/23L80DddFEIU bGoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429035; x=1789033835; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hw4M/Nd9JH/lA2s5Ub9G1Ehe6QW2hftbwiOq1xq7c6c=; b=Ox80Xs4kAi3jt6ryNOtTEt5460xsvRd0rjeba0DYACdD4Sum4pmK9zkSLulQYr/AjR J3f67xngA1dn6BFdW+9Z5Gl8l51r3wzUgd690alYJnS2OU67+p+M1fgVy6ZX+mZSmHnJ tgaaigfLzfpWYAb7SIyKN4P85WwUFgXdJCuRZ7czK7NQkl0RSpHHBzV2Phv2aPHM49/w OG6rDy9+njLtF9Xd8FHsua8C27FpJec3/+SuWBMQeZA825aCdEnHz17Ny6WYQBF0M6XA 9QENknDH2YyCbh3SLpJ817/sOiG1AZM8QGwtYSVORnvc+fnAwMkJlyF6YVccE1kOSGOt GDhg== X-Gm-Message-State: AFuF++kwfSj0oB/+ZecxfUHCkiXoRDBaKnNR+82/bxNfotSScPI1E1ju GBcWL5wzu2gAvxI9edWYrnvpT9ZJ59N7acN/tvCm+QF44eFe9koKl0h+kGYoUBPR X-Gm-Gg: AYBFou3H46ixGOLylvJYmFyzxGVxkZSUwzmJHwg7sEtjZd7CDk5C+Zdc9oMIeN/YyqP WSv11mVZRfwkdEbaWYKE8KI6Y0rYCsnC2PSsotChyK65Brd3G5ZluciZ0UHXjypGwuynyiF2IDV B411G/WQyGukcTgJDpvDMxppXeo8HB1K/pcQxuvI5aXsUOzxn54Kg/iUn9rushm9c8QyJZCp6NS cgOnDFPcXbTBwYb6LrGEYtB/t2eZdldMSAyKIbyWzrMPomIBNFS1tKBicNo54z3LkQOVqVpdCbw q+sDlNCm6pDNoNlWHy3HpNquYACfOITODbjzdN37DfJ3sYBfzVY+BXP8wyvhortET08U+6G/+zM OgKui4xW5yFf5c27JAH6cQxLQb9fVWjrMgVhL3INPxlkOQiaEcbT6BBFQZYLAnP7+ziZfRwQpe1 FeE06qLyh7XndZMyOwQ5qWJsG484WC2d+9LW7MQ5ZwGnqavv6ADoItYePqtxi6TrpB+Yw7PySl X-Received: by 2002:a05:6a00:4654:b0:85c:e16c:a1f6 with SMTP id d2e1a72fcca58-85ed4b20841mr14935802b3a.24.1788429035125; Thu, 03 Sep 2026 02:50:35 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:34 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 Date: Thu, 3 Sep 2026 21:49:47 +1200 Message-ID: <20260903094954.3240723-16-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129732 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-18582 Signed-off-by: Ankur Tyagi --- .../libiec61850/files/CVE-2026-18582.patch | 51 +++++++++++++++++++ .../libiec61850/libiec61850_1.6.1.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch new file mode 100644 index 0000000000..6fcd1662b9 --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch @@ -0,0 +1,51 @@ +From 43aa106301639f2afddf11302d25e84c5482e26c Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Tue, 16 Jun 2026 19:24:12 +0100 +Subject: [PATCH] - MMS server: fixed - oversized RptID written to RCB can + trigger invalid free when reports are sent later + (LIB61850-561)(GHSA-7qg8-hm25-rv5v) + +(cherry picked from commit 5b2a69f44256b8548927d8afdd7ac5f5381abe1e) + +CVE: CVE-2026-18582 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e] + +Signed-off-by: Ankur Tyagi +--- + src/iec61850/server/mms_mapping/reporting.c | 9 +++++++-- + 1 file changed, 7 insertions(+), 2 deletions(-) + +diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c +index 2a230c28..a44f0583 100644 +--- a/src/iec61850/server/mms_mapping/reporting.c ++++ b/src/iec61850/server/mms_mapping/reporting.c +@@ -557,7 +557,6 @@ updateSingleTrackingValue(MmsMapping* self, ReportControl* rc, const char* name, + attributeToUpdate = trkInst->resv; + else if (!strcmp(name, "DatSet")) + { +- + char datSet[130]; + const char* datSetStr = MmsValue_toString(newValue); + +@@ -2664,6 +2663,12 @@ Reporting_RCBWriteAccessHandler(MmsMapping* self, ReportControl* rc, const char* + goto exit_function; + } + ++ if (MmsValue_getStringSize(value) > 129) ++ { ++ retVal = DATA_ACCESS_ERROR_OBJECT_VALUE_INVALID; ++ goto exit_function; ++ } ++ + #if (CONFIG_MMS_THREADLESS_STACK != 1) + Semaphore_wait(rc->rcbValuesLock); + #endif +@@ -3677,7 +3682,7 @@ sendNextReportEntrySegment(ReportControl* self) + + const char* rptIdStr = MmsValue_toString(rptIdFromRcb); + +- if (rptIdStr[0] == 0) ++ if (rptIdStr[0] == 0 || MmsValue_getStringSize(rptIdFromRcb) > 129) + { + /* use default rptId when RptID is empty in RCB */ + updateWithDefaultRptId(self, &rptId); diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb index 5a76ba5330..b22d8a09c9 100644 --- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb +++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb @@ -17,6 +17,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8" SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \ file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \ + file://CVE-2026-18582.patch \ " From patchwork Thu Sep 3 09:49:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97220 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2EA8DC624A4 for ; Thu, 3 Sep 2026 09:50:45 +0000 (UTC) Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4060.1788429037895723363 for ; Thu, 03 Sep 2026 02:50:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=jSKC1JOB; spf=pass (domain: gmail.com, ip: 209.85.210.172, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-853c07a76adso2545317b3a.0 for ; Thu, 03 Sep 2026 02:50:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429037; x=1789033837; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1WrVKKfN5QIJiVct7dJpYjEv+abhijZq+Ytu/4uqyvI=; b=jSKC1JOB92Zhj5KOAvC7wUyT6UzYm9hvPaSXnXc7mNhbSxB2P7CIoDnQADsQBp5VfJ C7aHhmYxw54KELJkNF+6nqfCUPDbzrE3sZbRwqdx4xtBAkO/ZkzZ6/Ts8GdcXcLNNnj5 0YSJQVP1CctJcd5iMYxH/MoXetO2fDtwDIgir9rDYHfYvrjAnf9Vr5tZ26MJAFHOYbEv Vx12oHVn+m/aKLPlqOtGCTRuPxO7NMSSUiEzK8ng33a2QX2hIYLM7qnMo3Nw0yZsN3LI Rrd+nATdrnjPI2IRE/VbbNbI+G8vMK92IWFLCB73tgyxjk0Ca/OtxMmncT7QMK+j6i7O v4uw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429037; x=1789033837; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1WrVKKfN5QIJiVct7dJpYjEv+abhijZq+Ytu/4uqyvI=; b=inp16VWAaSXEfeKFbSlZBH+siLOf0u7rXpiOguE7gZLnySD3kuqmBWuvp0e0UwpKom B8MVkrHJ1xYKf+M3b3f22L8v9ZlDmWjARE2u1NqbP1RcEZaUW/Bz8+4reTX2yeFsO42P QscWdV+18UAP/fPBvPm3/nvK2r4MSaj2cYxwsOsxnwzEv59pmIBTGy8Gt9YNPI3yuysZ 8ZEXk8ZhJGgpDj3PVJBDoxjD9m94fAW5iPvHQSqtGCs6ZBIuPA59AxsqaQa/dcFUv8Tz YsqhD+LpbkU5JUc3VYPPR55BEj9lXyL/XWXZSuZD4b18g4XLEqRcaVkw+F/liOMNJvyM frcw== X-Gm-Message-State: AFuF++njNzRGaobPriPLEAPybXwDuGnVCy8BAW+HdHV92+CmZyRUnqex 2Z8NjBTCTVZGToxQ0jUaWDTpXYVbVTCFvYDm0HNtZf9WZe9rILtdRA170h/bqG6n X-Gm-Gg: AYBFou00POj60yRcyOCF1cbkGYYsS+ro6q3LBibF5G0HnynKEWbOoD50+ld5iUFDlQC aLaDiberwQQMui8r4q1hNpXBuLS2+6m6KOUNKJyhWSgeTZ280KaxoZ7SefR8D6/yO+Fkd1ERQOC 2HFwIM25HoK1B1bSW8fVNn3WHtTNqRJkv4tYGybGcfuXf4rhCQVOMZWAClQWpEuz1S4dogb1Gj+ /5sA4g79fd16BewT93JcDOTzPq25uOlxzLtGYMjxL8jjefxt0PPw8M2TsZL5gia66RSxgza2/sq bbkil7AYFzIgf9i+Utrs4uZHBpNj5mE1qRyiKOZpmKcTLhw/Bt4i3SaiJlMcmQI3YVNTv80lyev IJe1Szy2ce8dm29dxF59iTyLAkr5YQyDBmZ0a+sQq/qv5U4mkCC2V+Hs+EDrN8WJp6wXvzX9I4r IBSDSAU+FjLcMiE6N2mwOuekAvghOW00IY3nP4j9eTX6KlQwHpkLktmUMvm2C8NyycpF3hdeem X-Received: by 2002:a05:6a00:3c8d:b0:857:72f8:dc98 with SMTP id d2e1a72fcca58-85ed8beb35bmr15107996b3a.25.1788429037213; Thu, 03 Sep 2026 02:50:37 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:36 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 Date: Thu, 3 Sep 2026 21:49:48 +1200 Message-ID: <20260903094954.3240723-17-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129733 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-18583 Signed-off-by: Ankur Tyagi --- .../libiec61850/files/CVE-2026-18583.patch | 35 +++++++++++++++++++ .../libiec61850/libiec61850_1.6.1.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch new file mode 100644 index 0000000000..8acf7e1465 --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch @@ -0,0 +1,35 @@ +From c8baade187e1c31ac9e9ca71dced5a46765d97b2 Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Tue, 16 Jun 2026 18:23:52 +0100 +Subject: [PATCH] - MMS server: fixed - potential crash in access control check + handler for association and vmd specific data sets + (LIB61850-560)(GHSA-7v2x-39mw-2979) + +(cherry picked from commit 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d) + +CVE: CVE-2026-18583 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d] + +Signed-off-by: Ankur Tyagi +--- + src/iec61850/server/mms_mapping/mms_mapping.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c +index e5e6b034..5620f63f 100644 +--- a/src/iec61850/server/mms_mapping/mms_mapping.c ++++ b/src/iec61850/server/mms_mapping/mms_mapping.c +@@ -3807,11 +3807,11 @@ checkDataSetAccess(MmsMapping* self, MmsServerConnection connection, MmsVariable + if (listType == MMS_ASSOCIATION_SPECIFIC) + { + dataSetRef[0] = '@'; +- StringUtils_copyStringToBuffer(dataSetRef + 1, listName); ++ StringUtils_copyStringMax(dataSetRef + 1, 129, listName); + } + else if (listType == MMS_VMD_SPECIFIC) + { +- StringUtils_copyStringToBuffer(dataSetRef, listName); ++ StringUtils_copyStringMax(dataSetRef, 129, listName); + } + else if (listType == MMS_DOMAIN_SPECIFIC) + { diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb index b22d8a09c9..408b4d2d11 100644 --- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb +++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb @@ -18,6 +18,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8" SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \ file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \ file://CVE-2026-18582.patch \ + file://CVE-2026-18583.patch \ " From patchwork Thu Sep 3 09:49:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97221 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3FD1AC61DD3 for ; Thu, 3 Sep 2026 09:50:45 +0000 (UTC) Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4201.1788429040133311591 for ; Thu, 03 Sep 2026 02:50:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=fTstgBzl; spf=pass (domain: gmail.com, ip: 209.85.210.173, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-8557c3f270eso1325367b3a.3 for ; Thu, 03 Sep 2026 02:50:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429039; x=1789033839; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4BojN+3uh6U69TPkdF2Nehebt1u0ViF0aUWl0yL6dYg=; b=fTstgBzl80PROU3O7migXVAsIzDBdhWoZqlJI9j1WP/davvGc9KO6dpVTl1yMzawIO CcmdA42aotfHj93gvbnnQ7PUtV9V7O9UkbFGnzLnFHF0LGcHGUQEwVhbIa7Tl1+Jt/0c zV436/3s64AD0Ov7CTzFelt1ht6ERcHN41OEeT0klreyQdBfFkhn/Gj69PCMGYSBjBUM 9bLyukCFVpzl71w3PrtyXV+VPoST29uct0mnq1MHO+/eugwjsB3BQnoYRBqR6exsQQWE ZuYJg3cCUVQuPa4MF+dfA30SNAsAf8+uWUQxPrI25gVKVv+TTxMmVEFIdFZNu7AHYjmZ 9+BQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429039; x=1789033839; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4BojN+3uh6U69TPkdF2Nehebt1u0ViF0aUWl0yL6dYg=; b=L0KPygOiZkrzG4DHtmUNolbrR70rQWNVj/W15m+2HvEiqmI7inDou+ORcNB1GWBBgL PC8DsqRLfoiUo2Lr49i4Wu7Rz1CLMmIE3BBFBjbOlnh14iaURYnBFbtUbVjjfAs0cJWo SmgSz1Y4aeKdfQWXkbGQZ981qPW94qdHfmEG1yPAlqWUsldqlQBLrB02h4P/IyQrwJgz Dz15QF8oLQW9C5QNthGVcCoj2/g3tbhYdU4EWIBIgtitZCeu+ZHGUeHqBueWOGr2eQ7C ckavG9AJbzFV8wjFGMDco9bAAmDFALf8h57CpjnxscX2COsIY0K+tg5nVcK95d5MVPy9 anmg== X-Gm-Message-State: AFuF++luXSDzlxsA1WPsejfW3K6x16xyZ7tINCFmDstCmObtp+H/YQz9 sYP192boPDMGIhwvVQUM4Rl3vktv8k6yAIgrwLNmjEoKoVO7O4sciDxt4gBz8p6Z X-Gm-Gg: AYBFou2cOVn2jZy/RF6b6L5m0ogc+Lv9L3lcAp/AZMvSx5djnlGl3oI1o8caqRNsqiz beGKSjjXfOPRH8A0wj9D7BLoggjuVfugbCEluEJ8AMh0O9yXvkoaH7/nFT3kVliQ6Oe1s4VtRez M4NPArnxSMLgtjrf/rHWR/6Lduts4uVkq2YcW61dksai8F4mC8GjiomC+UEbeyNpio0uflTYxI6 6BSGwuUkCplOCPPAB0KIJUdab/pWhUCf2Jql1IbA8FLhUiw+irdcCV9vKEzvlq6pa38jGShnKMT YA2sxpi6Hk3hCpVOsWDnS5ZI299B8ZFK9SjVJOxgDhcyklP8Lab4gGJEc4W1iHuVzvlmYA2tdsy SSSRNoM0PvYGiyFiWoeWvSS2LDO81kjIXw0D5v6ewvp+6lo0mmmFU4VIHc25oR5loXrcBDDaHjg 1JZpOBptqfuvt2a6S05urdgVwJALt1mvnanTlxKKLwiXV01XtWsnIYlDGoumEokYiwM/VKBde4 X-Received: by 2002:a05:6a00:4408:b0:857:4dea:e2fe with SMTP id d2e1a72fcca58-85ed8ed8414mr17201121b3a.13.1788429039383; Thu, 03 Sep 2026 02:50:39 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:39 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 Date: Thu, 3 Sep 2026 21:49:49 +1200 Message-ID: <20260903094954.3240723-18-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129734 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-19108 Signed-off-by: Ankur Tyagi --- .../libiec61850/files/CVE-2026-19108.patch | 208 ++++++++++++++++++ .../libiec61850/libiec61850_1.6.1.bb | 1 + 2 files changed, 209 insertions(+) create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch new file mode 100644 index 0000000000..673ce29af0 --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch @@ -0,0 +1,208 @@ +From 846bd407527061665a3c109eaa6ee7e870ae6bc1 Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Tue, 21 Jul 2026 10:26:33 +0000 +Subject: [PATCH] - MMS server: fixed - Update URCB that used an association + specific dataset of another connection can cause heap-use-after-free + (LIB61850-577)(#596) - fixed bitbucket sonarcloud pipeline + +(cherry picked from commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168) + +CVE: CVE-2026-19108 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168] + +Signed-off-by: Ankur Tyagi +--- + bitbucket-pipelines.yml | 11 +++---- + src/iec61850/inc_private/reporting.h | 1 + + src/iec61850/server/mms_mapping/mms_mapping.c | 29 +++++++++++++++++-- + src/iec61850/server/mms_mapping/reporting.c | 17 +++++++---- + .../iso_mms/server/mms_server_connection.c | 19 ++++++++++++ + 5 files changed, 65 insertions(+), 12 deletions(-) + +diff --git a/bitbucket-pipelines.yml b/bitbucket-pipelines.yml +index a7493663..30dce281 100644 +--- a/bitbucket-pipelines.yml ++++ b/bitbucket-pipelines.yml +@@ -1,4 +1,4 @@ +-image: atlassian/default-image:4 ++image: atlassian/default-image:5 + + clone: + depth: full # SonarCloud scanner needs the full history to assign issues properly +@@ -12,12 +12,13 @@ definitions: + caches: + - sonar + script: +- - export SONAR_SCANNER_VERSION=5.0.1.3006 +- - export SONAR_SCANNER_OPTS="-Dsonar.javaHome=/usr/lib/jvm/java-17-openjdk-amd64" +- - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux ++ - export SONAR_SCANNER_VERSION=6.2.1.4610 ++ - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux-x64 + - export BW_OUTPUT=$HOME/.sonar/bw-output + - mkdir -p $BW_OUTPUT +- - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux.zip ++ - apt-get update -qq ++ - apt-get install openjdk-21-jre cmake -y ++ - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux-x64.zip + - unzip -o $HOME/.sonar/sonar-scanner.zip -d $HOME/.sonar/ + - export PATH=$SONAR_SCANNER_HOME/bin:$PATH + - curl --create-dirs -sSLo $HOME/.sonar/build-wrapper-linux-x86.zip https://sonarcloud.io/static/cpp/build-wrapper-linux-x86.zip +diff --git a/src/iec61850/inc_private/reporting.h b/src/iec61850/inc_private/reporting.h +index eddeb2d1..bc23f937 100644 +--- a/src/iec61850/inc_private/reporting.h ++++ b/src/iec61850/inc_private/reporting.h +@@ -67,6 +67,7 @@ typedef struct { + bool buffered; /* true if report is a buffered report */ + + MmsValue** bufferedDataSetValues; /* used to buffer values during bufTm time */ ++ int bufferedDataSetValuesSize; /* number of dataset entries */ + + MmsValue** valueReferences; /* array to store value references for fast access */ + +diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c +index 5620f63f..ef6f3580 100644 +--- a/src/iec61850/server/mms_mapping/mms_mapping.c ++++ b/src/iec61850/server/mms_mapping/mms_mapping.c +@@ -3912,6 +3912,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType + { + ReportControl* rc = (ReportControl*) rcElement->data; + ++#if (CONFIG_MMS_THREADLESS_STACK != 1) ++ Semaphore_wait(rc->rcbValuesLock); ++#endif ++ + if (rc->isDynamicDataSet) + { + if (rc->dataSet != NULL) +@@ -3924,6 +3928,11 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType + { + if (strcmp(rc->dataSet->logicalDeviceName, MmsDomain_getName(domain) + strlen(self->model->name)) == 0) + { ++#if (CONFIG_MMS_THREADLESS_STACK != 1) ++ Semaphore_post(rc->rcbValuesLock); ++#endif ++ ++ /* dataset is in use and cannot be deleted */ + allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT; + break; + } +@@ -3936,6 +3945,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType + { + if (strcmp(rc->dataSet->name, listName) == 0) + { ++#if (CONFIG_MMS_THREADLESS_STACK != 1) ++ Semaphore_post(rc->rcbValuesLock); ++#endif ++ /* dataset is in use and cannot be deleted */ + allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT; + break; + } +@@ -3947,13 +3960,22 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType + { + if (strcmp(rc->dataSet->name, listName) == 0) + { +- allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT; +- break; ++ /* this is usually called when the connection is closed -> RCB has already been disabled by connection handler */ ++ ++ MmsMapping_freeDynamicallyCreatedDataSet(rc->dataSet); ++ ++ /* cleanup dataset information in RCB instance */ ++ rc->dataSet = NULL; ++ rc->isDynamicDataSet = false; + } + } + } + } + } ++ ++#if (CONFIG_MMS_THREADLESS_STACK != 1) ++ Semaphore_post(rc->rcbValuesLock); ++#endif + } + + #if (CONFIG_IEC61850_LOG_SERVICE == 1) +@@ -4729,6 +4751,9 @@ MmsMapping_getDomainSpecificDataSet(MmsMapping* self, const char* dataSetName) + void + MmsMapping_freeDynamicallyCreatedDataSet(DataSet* dataSet) + { ++ if (dataSet == NULL) ++ return; ++ + DataSetEntry* dataSetEntry = dataSet->fcdas; + + while (dataSetEntry) +diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c +index a44f0583..03add555 100644 +--- a/src/iec61850/server/mms_mapping/reporting.c ++++ b/src/iec61850/server/mms_mapping/reporting.c +@@ -193,13 +193,9 @@ deleteDataSetValuesShadowBuffer(ReportControl* self) + { + if (self->bufferedDataSetValues != NULL) + { +- assert(self->dataSet != NULL); +- +- int dataSetSize = DataSet_getSize(self->dataSet); +- + int i; + +- for (i = 0; i < dataSetSize; i++) ++ for (i = 0; i < self->bufferedDataSetValuesSize; i++) + { + if (self->bufferedDataSetValues[i] != NULL) + MmsValue_delete(self->bufferedDataSetValues[i]); +@@ -698,13 +694,24 @@ static void + createDataSetValuesShadowBuffer(ReportControl* rc) + { + int dataSetSize = DataSet_getSize(rc->dataSet); ++ rc->bufferedDataSetValuesSize = dataSetSize; + + MmsValue** dataSetValues = (MmsValue**)GLOBAL_CALLOC(dataSetSize, sizeof(MmsValue*)); + ++ if (dataSetValues == NULL) ++ return; ++ + rc->bufferedDataSetValues = dataSetValues; + + rc->valueReferences = (MmsValue**)GLOBAL_MALLOC(dataSetSize * sizeof(MmsValue*)); + ++ if (rc->valueReferences == NULL) ++ { ++ GLOBAL_FREEMEM(dataSetValues); ++ rc->bufferedDataSetValues = NULL; ++ return; ++ } ++ + DataSetEntry* dataSetEntry = rc->dataSet->fcdas; + + int i; +diff --git a/src/mms/iso_mms/server/mms_server_connection.c b/src/mms/iso_mms/server/mms_server_connection.c +index 644fcdb1..401ad40b 100644 +--- a/src/mms/iso_mms/server/mms_server_connection.c ++++ b/src/mms/iso_mms/server/mms_server_connection.c +@@ -829,6 +829,25 @@ MmsServerConnection_destroy(MmsServerConnection self) + #endif + + #if (MMS_DYNAMIC_DATA_SETS == 1) ++ /* notify IEC 61850 layer BEFORE destroying named variable lists */ ++ if (self->namedVariableLists) ++ { ++ LinkedList element = LinkedList_getNext(self->namedVariableLists); ++ ++ while (element) ++ { ++ MmsNamedVariableList variableList = (MmsNamedVariableList)element->data; ++ ++ if (variableList && variableList->name) ++ { ++ mmsServer_callVariableListChangedHandler(MMS_VARLIST_DELETE, MMS_ASSOCIATION_SPECIFIC, ++ NULL, /* domain (NULL for aa-specific) */ ++ variableList->name, self); ++ } ++ element = LinkedList_getNext(element); ++ } ++ } ++ + LinkedList_destroyDeep(self->namedVariableLists, (LinkedListValueDeleteFunction) MmsNamedVariableList_destroy); + #endif + diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb index 408b4d2d11..c0e6efedd6 100644 --- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb +++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb @@ -19,6 +19,7 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https; file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \ file://CVE-2026-18582.patch \ file://CVE-2026-18583.patch \ + file://CVE-2026-19108.patch \ " From patchwork Thu Sep 3 09:49:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97223 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4DB08C624DD for ; Thu, 3 Sep 2026 09:50:45 +0000 (UTC) Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4061.1788429042335738083 for ; Thu, 03 Sep 2026 02:50:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=crLlKCAI; spf=pass (domain: gmail.com, ip: 209.85.210.172, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-853c947bfefso764646b3a.0 for ; Thu, 03 Sep 2026 02:50:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429042; x=1789033842; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YJc8GFdgocD5qlrAVZjY5VVNh1aL+ZloB8bpH0lk3Ck=; b=crLlKCAIRWGJngJSq+NqnU68oYZMZwHTKozODzmrSSpqz+XBuKILp82ijAJ5RU18RV GdfoTfh5JmVWSFRoDFETtXwMMNXcFFx30UYv38B6o0K1k+80oqzk6VO06XBFP2seajKk sTNhCzX6XshRahVvc6g3BOrREUfgfZnzuSbZppfw3d8zvsxjbjz1NWxyN+pf9J2eaIJB SS+AypTmIBnMFfexbGRnOJy+/LF6fhmBejnfGL80rXXaAn1hOjIgajltXp9tG8yZsDwO upZEpqxN/fvvNrsf2Z0mQri8neoOiDO2FcTxv976EjmwAS7dpVBA9gB709AixQ3pJEPS OcCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429042; x=1789033842; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YJc8GFdgocD5qlrAVZjY5VVNh1aL+ZloB8bpH0lk3Ck=; b=izpbWk0y6s6IuLt9M6o4Z70Ai14hxn8lfUrExzqasVgGwHrWKZWEEJdUJApouJ0O+8 nrYd3NLXsE8g2wsxNPL87X9K0brUsWGoiG4zpORuSyr3URmCj5uvHrhe69nGG3bQJU1J ahndVIA9w2+8GJ+QWvtdQb3ekJxNHqxsu06i9xu9UlTRlUNIddsuROf+mGj1eWEMKQkO KHo/3mfFEdFi+uJnqHAEXAIrye3PTIbGRMIaYeQxerMJ7G2UITPWoJlknBVPxiVzRl9W oNFW7bkNOJfil/RNREla2Z7/o83PAkGE7Ch/KbFBR3uWCU1cKgDaY9KKhQM6Ia0/yRxC go2A== X-Gm-Message-State: AFuF++luUsHQVWGgozoxhJYRvvm1WxieWqzvx5tOBBm9SCYFIP8MPq75 mLJtQTwmcOjQrm000R4a2wXXV1K1VCc2KZnR049H4G6NBY8N0l/KE/3xSPmidc+o X-Gm-Gg: AYBFou3ft+WFhUkpJ4nivKHPWMkAN81SKJlYf+cfKj61qdQJsQvJUGOWiGvPdiLueKl 514ksGqsu94BO0/KNp0NwfCCLn4AMf9aC/lChX9otkuKnzqQtvhzuqOZWCHxrDg8koypSxwhdSX R89lbPVKwEdpwDlbTPRKheFLm+vXyq7zd4aLRfIxs1MZj9RRmZ2Y9JnkH+dlercIbfkeYa5Ydea SpJXoo37wYdij4ISLYk38e1R7UahZfzFEZESU5n5CGsHrKZxX8sAlG8z6EPphRrBxLEuWI8K7Ld 3Uwu/iU/nY7yiPTSyZrGOSsw79k0lrJJUKA9kljYJOKUzQZRUrK11oDzayVr67z3kxKXuvdUJOt lDaR9BEPGQ9uoUXj9zQdEe71+YPvjgSC8sYaXvMIo32fvpKvRovLVBdSfmG1/UB63NmYdlJZspd dfWdQjL+T8j3cqixc+t9dSmDXVYSj4BwlYPHBH/aOeEZUX4s/2arWWakuXF7g7G8qBiynPYFs1 X-Received: by 2002:aa7:8894:0:b0:857:73c3:446a with SMTP id d2e1a72fcca58-85fff0c85d0mr3902356b3a.25.1788429041560; Thu, 03 Sep 2026 02:50:41 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:41 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 Date: Thu, 3 Sep 2026 21:49:50 +1200 Message-ID: <20260903094954.3240723-19-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129735 From: Ankur Tyagi Backport commits[1][2] in order to cherry pick fix mentioned in NVD. Details: https://nvd.nist.gov/vuln/detail/cve-2026-19206 [1]https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c [2]https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1 Signed-off-by: Ankur Tyagi --- .../libiec61850/files/CVE-2026-19206-1.patch | 129 +++++++++++++++++ .../libiec61850/files/CVE-2026-19206-2.patch | 134 ++++++++++++++++++ .../libiec61850/files/CVE-2026-19206-3.patch | 115 +++++++++++++++ .../libiec61850/libiec61850_1.6.1.bb | 3 + 4 files changed, 381 insertions(+) create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch new file mode 100644 index 0000000000..b7b86b3f64 --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch @@ -0,0 +1,129 @@ +From 04f95bf3e54614122621b520eac29dea160de1c7 Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Tue, 17 Mar 2026 12:41:32 +0000 +Subject: [PATCH] - fixed memory-safety issues and potential NULL pointer + dereferenciations in SV parser (#585) + +(cherry picked from commit c85175ddf7018beb753d85a740d4c2c77f61c96c) + +CVE: CVE-2026-19206 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c] +Signed-off-by: Ankur Tyagi +--- + src/sampled_values/sv_subscriber.c | 35 +++++++++++++++++++++++------- + 1 file changed, 27 insertions(+), 8 deletions(-) + +diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c +index 221eb1a8..bb82818e 100644 +--- a/src/sampled_values/sv_subscriber.c ++++ b/src/sampled_values/sv_subscriber.c +@@ -423,16 +423,24 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + return; + } + ++ if (bufPos + elementLength > length) ++ { ++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: Malformed message: element length exceeds buffer length!\n"); ++ return; ++ } ++ + switch (tag) + { + case 0x80: + asdu.svId = (char*) (buffer + bufPos); + svIdLength = elementLength; ++ asdu.svId[svIdLength] = 0; + break; + + case 0x81: + asdu.datSet = (char*) (buffer + bufPos); + datSetLength = elementLength; ++ asdu.datSet[datSetLength] = 0; + break; + + case 0x82: +@@ -471,22 +479,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + + bufPos += elementLength; + } +- +- if (asdu.svId != NULL) +- asdu.svId[svIdLength] = 0; +- if (asdu.datSet != NULL) +- asdu.datSet[datSetLength] = 0; + + if (DEBUG_SV_SUBSCRIBER) + { + printf("SV_SUBSCRIBER: SV ASDU: ----------------\n"); + printf("SV_SUBSCRIBER: DataLength: %d\n", asdu.dataBufferLength); +- printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId); ++ printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId ? asdu.svId : "(empty)"); + printf("SV_SUBSCRIBER: SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu)); + printf("SV_SUBSCRIBER: ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu)); + + if (SVSubscriber_ASDU_hasDatSet(&asdu)) +- printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet); ++ printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)"); + + if (SVSubscriber_ASDU_hasRefrTm(&asdu)) + #ifndef _MSC_VER +@@ -598,7 +601,8 @@ exit_error: + static void + handleSVApdu(SVReceiver self, uint16_t appId, uint8_t* apdu, int apduLength, uint8_t* dstAddr) + { +- if (DEBUG_SV_SUBSCRIBER) { ++ if (DEBUG_SV_SUBSCRIBER) ++ { + printf("SV_SUBSCRIBER: SV message: ----------------\n"); + printf("SV_SUBSCRIBER: APPID: %u\n", appId); + printf("SV_SUBSCRIBER: APDU length: %i\n", apduLength); +@@ -791,6 +795,9 @@ SVSubscriber_setListener(SVSubscriber self, SVUpdateListener listener, void* pa + uint8_t + SVSubscriber_ASDU_getSmpSynch(SVSubscriber_ASDU self) + { ++ if (self->smpSynch == NULL) ++ return 0; ++ + return self->smpSynch[0]; + } + +@@ -800,6 +807,9 @@ SVSubscriber_ASDU_getSmpCnt(SVSubscriber_ASDU self) + uint16_t retVal; + uint8_t* valBytes = (uint8_t*) &retVal; + ++ if (self->smpCnt == NULL) ++ return 0; ++ + #if (ORDER_LITTLE_ENDIAN == 1) + valBytes[0] = self->smpCnt[1]; + valBytes[1] = self->smpCnt[0]; +@@ -912,6 +922,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self) + { + uint32_t retVal; + ++ if (self->confRev == NULL) ++ return 0; ++ + #if (ORDER_LITTLE_ENDIAN == 1) + memcpy_reverse(&retVal, self->confRev, sizeof(uint32_t)); + #else +@@ -924,6 +937,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self) + uint8_t + SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self) + { ++ if (self->smpMod == NULL) ++ return 0; ++ + uint8_t retVal = *((uint8_t*) (self->smpMod)); + + return retVal; +@@ -932,6 +948,9 @@ SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self) + uint16_t + SVSubscriber_ASDU_getSmpRate(SVSubscriber_ASDU self) + { ++ if (self->smpRate == NULL) ++ return 0; ++ + uint16_t retVal; + + #if (ORDER_LITTLE_ENDIAN == 1) diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch new file mode 100644 index 0000000000..e39cc3e17a --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch @@ -0,0 +1,134 @@ +From 62741cc994ae02ef95e664b9470a22089788cff4 Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Wed, 17 Jun 2026 12:22:34 +0100 +Subject: [PATCH] - SV subscriber: fixed - null terminator for svId and datSet + overwrites tag and can cause OOB write (LIB61850-563) + +(cherry picked from commit 6178540e8cdd26b7884a482905140cc9084966a1) + +CVE: CVE-2026-19206 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1] +Signed-off-by: Ankur Tyagi +--- + .../sv_subscriber/sv_subscriber_example.c | 4 ++ + src/sampled_values/sv_subscriber.c | 56 ++++++++++++++----- + 2 files changed, 46 insertions(+), 14 deletions(-) + +diff --git a/examples/sv_subscriber/sv_subscriber_example.c b/examples/sv_subscriber/sv_subscriber_example.c +index 0e3ff720..6487052b 100644 +--- a/examples/sv_subscriber/sv_subscriber_example.c ++++ b/examples/sv_subscriber/sv_subscriber_example.c +@@ -30,6 +30,10 @@ svUpdateListener (SVSubscriber subscriber, void* parameter, SVSubscriber_ASDU as + if (svID != NULL) + printf(" svID=(%s)\n", svID); + ++ const char* dataSet = SVSubscriber_ASDU_getDatSet(asdu); ++ if (dataSet != NULL) ++ printf(" dataSet=(%s)\n", dataSet); ++ + printf(" smpCnt: %i\n", SVSubscriber_ASDU_getSmpCnt(asdu)); + printf(" confRev: %u\n", SVSubscriber_ASDU_getConfRev(asdu)); + +diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c +index bb82818e..97f881f6 100644 +--- a/src/sampled_values/sv_subscriber.c ++++ b/src/sampled_values/sv_subscriber.c +@@ -81,8 +81,12 @@ struct sSVSubscriber + + struct sSVSubscriber_ASDU + { +- char* svId; +- char* datSet; ++ char svIdBuf[130]; /* copy of svId - only copied when the user requests the svId */ ++ char datSetBuf[130]; /* copy of datSet - only copied when the user requests the datSet */ ++ char* svId; /* pointer to the start of the svId in the ASDU buffer */ ++ char* datSet; /* pointer to the start of the datSet in the ASDU buffer */ ++ uint8_t svIdSize; /* size of the svId in the ASDU buffer */ ++ uint8_t datSetSize; /* size of the datSet in the ASDU buffer */ + + uint8_t* smpCnt; + uint8_t* confRev; +@@ -432,15 +436,27 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + switch (tag) + { + case 0x80: +- asdu.svId = (char*) (buffer + bufPos); +- svIdLength = elementLength; +- asdu.svId[svIdLength] = 0; ++ if (elementLength > 129) ++ { ++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n"); ++ } ++ else ++ { ++ asdu.svId = (char*) (buffer + bufPos); ++ asdu.svIdSize = elementLength; ++ } + break; + + case 0x81: +- asdu.datSet = (char*) (buffer + bufPos); +- datSetLength = elementLength; +- asdu.datSet[datSetLength] = 0; ++ if (elementLength > 129) ++ { ++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n"); ++ } ++ else ++ { ++ asdu.datSet = (char*) (buffer + bufPos); ++ asdu.datSetSize = elementLength; ++ } + break; + + case 0x82: +@@ -479,17 +495,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + + bufPos += elementLength; + } +- ++ + if (DEBUG_SV_SUBSCRIBER) + { + printf("SV_SUBSCRIBER: SV ASDU: ----------------\n"); + printf("SV_SUBSCRIBER: DataLength: %d\n", asdu.dataBufferLength); +- printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId ? asdu.svId : "(empty)"); ++ printf("SV_SUBSCRIBER: SvId: %s\n", SVSubscriber_ASDU_getSvId(&asdu)); + printf("SV_SUBSCRIBER: SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu)); + printf("SV_SUBSCRIBER: ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu)); +- ++ + if (SVSubscriber_ASDU_hasDatSet(&asdu)) +- printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)"); ++ printf("SV_SUBSCRIBER: DatSet: %s\n", SVSubscriber_ASDU_getDatSet(&asdu)); + + if (SVSubscriber_ASDU_hasRefrTm(&asdu)) + #ifndef _MSC_VER +@@ -899,13 +915,25 @@ SVSubscriber_ASDU_hasSmpMod(SVSubscriber_ASDU self) + const char* + SVSubscriber_ASDU_getSvId(SVSubscriber_ASDU self) + { +- return self->svId; ++ if (self->svId == NULL) ++ return NULL; ++ ++ memcpy(self->svIdBuf, self->svId, self->svIdSize); ++ self->svIdBuf[self->svIdSize] = 0; /* ensure null termination */ ++ ++ return self->svIdBuf; + } + + const char* + SVSubscriber_ASDU_getDatSet(SVSubscriber_ASDU self) + { +- return self->datSet; ++ if (self->datSet == NULL) ++ return NULL; ++ ++ memcpy(self->datSetBuf, self->datSet, self->datSetSize); ++ self->datSetBuf[self->datSetSize] = 0; /* ensure null termination */ ++ ++ return self->datSetBuf; + } + + static inline void diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch new file mode 100644 index 0000000000..75e476c6c5 --- /dev/null +++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch @@ -0,0 +1,115 @@ +From 03841913e3b8220f1ceb2ab5493bc31b769113bd Mon Sep 17 00:00:00 2001 +From: Michael Zillgith +Date: Wed, 1 Jul 2026 11:32:34 +0100 +Subject: [PATCH] - SV subscriber: fixed missing length validation of some ASDU + elements that can cause OOB reads when these fields are later used by the + application (LIB61850-574) + +(cherry picked from commit a96bd674e0238276dd1387d31d52e55229d0771e) + +CVE: CVE-2026-19206 +Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/a96bd674e0238276dd1387d31d52e55229d0771e] +Signed-off-by: Ankur Tyagi +--- + src/sampled_values/sv_subscriber.c | 48 +++++++++++++++++++++++++----- + 1 file changed, 40 insertions(+), 8 deletions(-) + +diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c +index 97f881f6..55422d87 100644 +--- a/src/sampled_values/sv_subscriber.c ++++ b/src/sampled_values/sv_subscriber.c +@@ -402,6 +402,20 @@ SVReceiver_stopThreadless(SVReceiver self) + self->running = false; + } + ++static void ++invalidFieldSize(const char* fieldName, int expectedSize, int actualSize) ++{ ++ if (DEBUG_SV_SUBSCRIBER) ++ printf("SV_SUBSCRIBER: Invalid %s size: expected %d, got %d\n", fieldName, expectedSize, actualSize); ++} ++ ++static void ++fieldTooLong(const char* fieldName, int maxSize, int actualSize) ++{ ++ if (DEBUG_SV_SUBSCRIBER) ++ printf("SV_SUBSCRIBER: %s too long: max %d, got %d\n", fieldName, maxSize, actualSize); ++} ++ + static void + parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + { +@@ -438,7 +452,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + case 0x80: + if (elementLength > 129) + { +- if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n"); ++ return fieldTooLong("svId", 129, elementLength); + } + else + { +@@ -450,7 +464,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + case 0x81: + if (elementLength > 129) + { +- if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n"); ++ return fieldTooLong("datSet", 129, elementLength); + } + else + { +@@ -460,23 +474,38 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + break; + + case 0x82: +- asdu.smpCnt = buffer + bufPos; ++ if (elementLength != 2) ++ return invalidFieldSize("SmpCnt", 2, elementLength); ++ else ++ asdu.smpCnt = buffer + bufPos; + break; + + case 0x83: +- asdu.confRev = buffer + bufPos; ++ if (elementLength != 4) ++ return invalidFieldSize("ConfRev", 4, elementLength); ++ else ++ asdu.confRev = buffer + bufPos; + break; + + case 0x84: +- asdu.refrTm = buffer + bufPos; ++ if (elementLength != 8) ++ return invalidFieldSize("RefrTm", 8, elementLength); ++ else ++ asdu.refrTm = buffer + bufPos; + break; + + case 0x85: +- asdu.smpSynch = buffer + bufPos; ++ if (elementLength != 1) ++ return invalidFieldSize("SmpSynch", 1, elementLength); ++ else ++ asdu.smpSynch = buffer + bufPos; + break; + + case 0x86: +- asdu.smpRate = buffer + bufPos; ++ if (elementLength != 2) ++ return invalidFieldSize("SmpRate", 2, elementLength); ++ else ++ asdu.smpRate = buffer + bufPos; + break; + + case 0x87: +@@ -485,7 +514,10 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length) + break; + + case 0x88: +- asdu.smpMod = buffer + bufPos; ++ if (elementLength != 1) ++ return invalidFieldSize("SmpMod", 1, elementLength); ++ else ++ asdu.smpMod = buffer + bufPos; + break; + + default: /* ignore unknown tag */ diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb index c0e6efedd6..c0a3d1d29b 100644 --- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb +++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb @@ -20,6 +20,9 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https; file://CVE-2026-18582.patch \ file://CVE-2026-18583.patch \ file://CVE-2026-19108.patch \ + file://CVE-2026-19206-1.patch \ + file://CVE-2026-19206-2.patch \ + file://CVE-2026-19206-3.patch \ " From patchwork Thu Sep 3 09:49:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97224 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 64297C624DB for ; Thu, 3 Sep 2026 09:50:45 +0000 (UTC) Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4202.1788429045025929557 for ; Thu, 03 Sep 2026 02:50:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=QO8sdYOZ; spf=pass (domain: gmail.com, ip: 209.85.210.178, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-853c947bfefso764678b3a.0 for ; Thu, 03 Sep 2026 02:50:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429044; x=1789033844; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hd7E1sEUC/HcjkD9UYyEWS3F/fe11mHX2jxjGBGlC3E=; b=QO8sdYOZAIsSUpm3Tht5CfABoiQs7CWdeHfyhnl5hAA6cSnrVAF5P8/5WlcPSIRsV6 yvA5zLJATkTB6Zqu4EBUgAZsObvFFWMO/H3I9BHyS/FgU4KCbpLmRiTI1ERfoDzTF/a+ hgwdJN0ltX8uSexF7JJE/U6ct3g5SyxHb2BJimKN9n/aEMM2atbb8o35reM4ylyvoZx8 RYzlnHn+K1kiqg6/QIwYbahLYqtaYqjlSZoJjeGmtBxllo33T6Cy3f/TNZ26WLkBvHoV RTzbXkHw39UpRXFEivZgm4K3zF9PC9Rp0zxxDnhWJNoHLltsfqYXQ7cgCS3XWXUjyDUI u25g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429044; x=1789033844; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hd7E1sEUC/HcjkD9UYyEWS3F/fe11mHX2jxjGBGlC3E=; b=OGnTtSleTH1/RgFKnxSsztY/GfRiVogbifEMIOdM+0JDPKAdamWf+GUYmB2oTy3n4K 47lmVtQfR0yuoF7WqgIXHjYf49IeJ70qNOQzAwyrk1cpPHLlwMjwAxJmPcLxKNq5drRq s7c9eXBW+oLsSdijmvQOk3qPEqI/LHOc/J3useYsnDkHR7i2WKKE2PwYcTzAFad5+gh3 BkIjwvCYB8UficeVSNp/e+roXJvHnk5kALvtkARlEUInEjb6dMnquyNjbYqJBWQvRFms EFs4pzVbXqg59AdUUt4Ho8QHmPeuggN/1hVbsw1UgJ7JJuRVzRRQIr4tORr1U7Gr6TCL zQAQ== X-Gm-Message-State: AFuF++nyeJ0cJ3R2HepT3aehA3Go9B0EWFm5bBAa4snYRk2nVC4pQlZw 5ImCoEbzNOPTBM6pTHquTPPmIQFjcvdES8+0PgRs9r0MBwgImEWHHea+v9RoToA7 X-Gm-Gg: AYBFou1zBKdyIj4j0TKLaGCT1zfJ3A9+nxtLLUtYvWaSLZYQTy4dEFPXOmvy6SRyS1G bar8XH0HU8kbvO9vB9hJG+i12LwmzoVRLwkDneJz8eG6lSkZCDpWUprTWEqlq38Sp01WE4TVArp TQH5Fc023/0Rq02l2KUuL3F7SMcZxL1zkRqMohkl38NUMadZ8lGI/YiIoCbSbyP4Ylowc+0oPmc 3QkVFyJV//exKgVQtmNMsx+cE/Tk/p0tPOFR6ycM7jcrpd2Fc8LECn4o5BQvfAwPXKXU2xFXZB4 o9UhnAE09pZQMR/7o/SyVOE5OibDFOAtsVIPsQwsk6DKjOaxs9xOiT3646UWvhtulEBrmUa1JQ+ XdWutMbM5ZqLKPah/t4DilRjnDT53oFdJklNls0Cxca2Bcx0CgMWQyqYyGRPiVmFkrH7q46q8xb Th7oFqgRcfst8vmOpFUOFR5wkzPH3ZIIrTs+eN8c1DCLHFvPHlKGR+/lvCytSuYfNf2DwDgtWd X-Received: by 2002:a05:6a00:3020:b0:858:ea6a:4415 with SMTP id d2e1a72fcca58-85ffc18a8femr3996145b3a.2.1788429044017; Thu, 03 Sep 2026 02:50:44 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:43 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 Date: Thu, 3 Sep 2026 21:49:51 +1200 Message-ID: <20260903094954.3240723-20-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129736 From: Ankur Tyagi Backport commits[1][2] needed to cherry pick fix for the CVE as per the release notes[3] Details: https://nvd.nist.gov/vuln/detail/cve-2026-71226 [1]https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd [2]https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311 [3]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1 Signed-off-by: Ankur Tyagi --- .../libkcapi/libkcapi/CVE-2026-71226-1.patch | 604 ++++++++++++++++++ .../libkcapi/libkcapi/CVE-2026-71226-2.patch | 55 ++ .../libkcapi/libkcapi/CVE-2026-71226-3.patch | 93 +++ .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 3 + 4 files changed, 755 insertions(+) create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch new file mode 100644 index 0000000000..d53d29423c --- /dev/null +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch @@ -0,0 +1,604 @@ +From 73a34808912e3cfea8d88f0a2c08fc0ed107a9d8 Mon Sep 17 00:00:00 2001 +From: Markus Theil +Date: Fri, 3 Apr 2026 15:06:53 +0200 +Subject: [PATCH] fixes found by analysis with LLM + +Signed-off-by: Markus Theil +Signed-off-by: Stephan Mueller +(cherry picked from commit e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd) + +CVE: CVE-2026-71226 +Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd] +Signed-off-by: Ankur Tyagi +--- + apps/app-internal.c | 15 +++++++++--- + apps/kcapi-dgst.c | 11 ++++++--- + apps/kcapi-enc.c | 9 ++++--- + apps/kcapi-hasher.c | 12 ++++++--- + apps/kcapi-rng.c | 24 ++++++++++++------ + configure.ac | 3 ++- + lib/kcapi-aead.c | 12 +++++++-- + lib/kcapi-kdf.c | 6 +++-- + lib/kcapi-kernel-if.c | 57 +++++++++++++++++++++++++++++-------------- + lib/kcapi-kpp.c | 4 +-- + lib/kcapi-md.c | 2 +- + lib/kcapi-sym.c | 6 +++++ + lib/kcapi-utils.c | 7 ++++-- + 13 files changed, 118 insertions(+), 50 deletions(-) + +diff --git a/apps/app-internal.c b/apps/app-internal.c +index 7e01dd7..724b0b1 100644 +--- a/apps/app-internal.c ++++ b/apps/app-internal.c +@@ -173,18 +173,24 @@ static uint8_t bin_char(char hex) + void hex2bin(const char *hex, uint32_t hexlen, uint8_t *bin, uint32_t binlen) + { + uint32_t i; +- uint32_t chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen; ++ uint32_t chars; + + /* + * handle odd-length of strings where the first digit is the least + * significant nibble + */ + if (hexlen & 1) { ++ if (!binlen) ++ return; + bin[0] = bin_char(hex[0]); + bin++; + hex++; ++ hexlen--; ++ binlen--; + } + ++ chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen; ++ + for (i = 0; i < chars; i++) { + bin[i] = (uint8_t)(bin_char(hex[(i*2)]) << 4); + bin[i] |= bin_char(hex[((i*2)+1)]); +@@ -238,13 +244,14 @@ ssize_t read_complete(int fd, uint8_t *buf, size_t buflen) + if (0 < ret) { + buflen -= (size_t)ret; + buf += ret; ++ rc += ret; + } +- rc += ret; +- if (ret) +- break; + } while ((0 < ret || EINTR == errno || ERESTART == errno) + && buflen > 0); + ++ if (ret < 0) ++ return -errno; ++ + return rc; + } + +diff --git a/apps/kcapi-dgst.c b/apps/kcapi-dgst.c +index 591a7fb..42d099c 100644 +--- a/apps/kcapi-dgst.c ++++ b/apps/kcapi-dgst.c +@@ -128,6 +128,11 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts) + } + + outlen = kcapi_md_digestsize(handle); ++ if (!outlen) { ++ dolog(KCAPI_LOG_ERR, "Cipher has zero digest size"); ++ ret = -EINVAL; ++ goto out; ++ } + + if (opts->hexout) + outlen *= 2; +@@ -285,8 +290,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts) + } + + while (j < saltbuflen) { +- ret = kcapi_rng_generate(rng, saltbuf, +- (size_t)saltbuflen); ++ ret = kcapi_rng_generate(rng, saltbuf + j, ++ (size_t)(saltbuflen - j)); + if (ret < 0) { + kcapi_rng_destroy(rng); + free(saltbuf); +@@ -320,7 +325,7 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts) + if (opts->key_fd != -1) { + ret = read_complete(opts->key_fd, keybuf, sizeof(keybuf)); + if (ret < 0) +- return (int)ret; ++ goto out; + + have_key = 1; + keybuflen = (uint32_t)ret; +diff --git a/apps/kcapi-enc.c b/apps/kcapi-enc.c +index 68cf2f7..e7aa9db 100644 +--- a/apps/kcapi-enc.c ++++ b/apps/kcapi-enc.c +@@ -218,7 +218,7 @@ static ssize_t return_data_fd(struct kcapi_handle *handle, + } + + out: +- munmap(outmem, outsize); ++ munmap(outmem, outsize + offset); + return (ret < 0) ? ret : generated_bytes; + } + +@@ -609,7 +609,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts) + } + + /* Get data from file. */ +- } else { ++ } else if (insb.st_size) { + uint32_t sent_data = 0; + + inmem = mmap(NULL, (size_t)insb.st_size, PROT_READ, MAP_SHARED, +@@ -636,6 +636,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts) + * we will not apply padding. + */ + if (!opts->decrypt && ++ insb.st_size >= 2 && + !(insb.st_size % opts->func_blocksize(handle)) && + (uint32_t)padbyte < opts->func_blocksize(handle)) { + uint32_t i; +@@ -803,8 +804,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts) + } + + while (j < saltbuflen) { +- ret = kcapi_rng_generate(rng, saltbuf, +- saltbuflen); ++ ret = kcapi_rng_generate(rng, saltbuf + j, ++ saltbuflen - j); + if (ret < 0) { + kcapi_rng_destroy(rng); + free(saltbuf); +diff --git a/apps/kcapi-hasher.c b/apps/kcapi-hasher.c +index 217f59d..90dc34d 100644 +--- a/apps/kcapi-hasher.c ++++ b/apps/kcapi-hasher.c +@@ -271,7 +271,7 @@ static int load_file(const char *filename, uint8_t **memory, off_t *size) + fprintf(stderr, "Key longer than UINT32_MAX\n"); + ret = -ERANGE; + goto out; +- } else if (buffer_size * 2 < buffer_size) ++ } else if (buffer_size > UINT32_MAX / 2) + buffer_size = UINT32_MAX; + else + buffer_size *= 2; +@@ -340,7 +340,7 @@ static int hasher(struct kcapi_handle *handle, const struct hash_params *params, + } while (left); + munmap(memblock, mapped); + offset = offset + (off_t)mapped; +- } while (offset ^ size); ++ } while (offset != size); + } else { + uint8_t tmpbuf[TMPBUFLEN] __aligned(KCAPI_APP_ALIGN); + uint32_t bufsize; +@@ -647,11 +647,17 @@ static int process_checkfile(const struct hash_params *params, + hexhash = buf; + + if (bsd_style) { ++ if (bsd_style > linelen) { ++ fprintf(stderr, "Invalid checkfile format\n"); ++ ret = 1; ++ goto out; ++ } ++ + /* Hash starts after separator */ + hexhashlen = linelen - bsd_style + 1; + + /* remove closing parenthesis behind filename */ +- if (buf[(bsd_style - 4)] == ')') ++ if (bsd_style >= 4 && buf[(bsd_style - 4)] == ')') + buf[(bsd_style - 4)] = '\0'; + } + +diff --git a/apps/kcapi-rng.c b/apps/kcapi-rng.c +index 9e025cd..46dab02 100644 +--- a/apps/kcapi-rng.c ++++ b/apps/kcapi-rng.c +@@ -282,16 +282,18 @@ int main(int argc, char *argv[]) + seedsize); + + if (!isatty(0) && (errno == EINVAL || errno == ENOTTY)) { +- while (fgets((char *)seedbuf, (int)seedsize, stdin)) { +- ret = kcapi_rng_seed(rng, seedbuf, seedsize); ++ ssize_t rret; ++ ++ while ((rret = read(STDIN_FILENO, seedbuf, seedsize)) > 0) { ++ ret = kcapi_rng_seed(rng, seedbuf, (uint32_t)rret); + if (ret) + dolog(KCAPI_LOG_WARN, +- "User-provided seed of %lu bytes not accepted by DRNG (error: %ld)", +- (unsigned long)sizeof(buf), ret); ++ "User-provided seed of %zd bytes not accepted by DRNG (error: %ld)", ++ rret, ret); + else + dolog(KCAPI_LOG_DEBUG, +- "User-provided seed of %u bytes", +- seedsize); ++ "User-provided seed of %zd bytes", ++ rret); + } + } + +@@ -312,9 +314,15 @@ int main(int argc, char *argv[]) + char hexbuf[2 * KCAPI_RNG_BUFSIZE]; + + bin2hex(buf, (size_t)ret, hexbuf, sizeof(hexbuf), 0); +- fwrite(hexbuf, 2 * (size_t)ret, 1, stdout); ++ if (fwrite(hexbuf, 2 * (size_t)ret, 1, stdout) != 1) { ++ ret = -EIO; ++ goto out; ++ } + } else { +- fwrite(buf, (size_t)ret, 1, stdout); ++ if (fwrite(buf, (size_t)ret, 1, stdout) != 1) { ++ ret = -EIO; ++ goto out; ++ } + } + + outlen -= (size_t)ret; +diff --git a/configure.ac b/configure.ac +index fbae4f9..446b8a8 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -14,16 +14,17 @@ m4_define([__KCAPI_MINVERSION], [5]) + m4_define([__KCAPI_PATCHLEVEL], [0]) + m4_define([KCAPI_VERSION], [__KCAPI_MAJVERSION.__KCAPI_MINVERSION.__KCAPI_PATCHLEVEL]) + ++AC_PREREQ([2.69]) + AC_INIT([libkcapi], [KCAPI_VERSION]) + AC_DEFINE([KCAPI_MAJVERSION], [__KCAPI_MAJVERSION]) + AC_DEFINE([KCAPI_MINVERSION], [__KCAPI_MINVERSION]) + AC_DEFINE([KCAPI_PATCHLEVEL], [__KCAPI_PATCHLEVEL]) ++AC_CONFIG_MACRO_DIRS([m4]) + AM_INIT_AUTOMAKE([foreign]) + LT_INIT([pic-only]) + AC_SUBST([LIBTOOL_DEPS]) + AC_PROG_CC + AC_CONFIG_FILES([Makefile]) +-AC_CONFIG_MACRO_DIR([m4]) + AX_PROG_CC_FOR_BUILD + AX_CHECK_PIE + +diff --git a/lib/kcapi-aead.c b/lib/kcapi-aead.c +index b52dda0..3a7d711 100644 +--- a/lib/kcapi-aead.c ++++ b/lib/kcapi-aead.c +@@ -566,7 +566,11 @@ size_t impl_aead_outbuflen_enc(struct kcapi_handle *handle, + { + struct kcapi_handle_tfm *tfm = handle->tfm; + uint32_t bs = tfm->info.blocksize; +- size_t outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen; ++ size_t outlen; ++ ++ if (!bs) ++ return 0; ++ outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen; + + /* the kernel does not like zero length output buffers */ + if (!outlen) +@@ -591,7 +595,11 @@ size_t impl_aead_outbuflen_dec(struct kcapi_handle *handle, + { + struct kcapi_handle_tfm *tfm = handle->tfm; + uint32_t bs = tfm->info.blocksize; +- size_t outlen = (inlen + bs - 1) / bs * bs + assoclen; ++ size_t outlen; ++ ++ if (!bs) ++ return 0; ++ outlen = (inlen + bs - 1) / bs * bs + assoclen; + + if (!handle->flags.ge_v4_9 == true) + outlen += taglen; +diff --git a/lib/kcapi-kdf.c b/lib/kcapi-kdf.c +index 54dc1ec..5f389b6 100644 +--- a/lib/kcapi-kdf.c ++++ b/lib/kcapi-kdf.c +@@ -54,6 +54,8 @@ + #include "kcapi.h" + #include "internal.h" + ++#define MAX_DIGESTSIZE 64 ++ + #ifndef __has_builtin + # define __has_builtin(x) 0 + #endif +@@ -101,7 +103,7 @@ ssize_t impl_kdf_dpi(struct kcapi_handle *handle, + ssize_t err = 0; + uint8_t *dst_orig = dst; + size_t dlen_orig = dlen; +- uint8_t Ai[h]; ++ uint8_t Ai[MAX_DIGESTSIZE]; + uint32_t i = 1; + + if (dlen > INT_MAX) +@@ -448,7 +450,7 @@ static inline uint64_t kcapi_get_time(void) + { + struct timespec time; + +- if (clock_gettime(CLOCK_REALTIME, &time) == 0) ++ if (clock_gettime(CLOCK_MONOTONIC, &time) == 0) + return (uint64_t)time.tv_nsec; + + return 0; +diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c +index 835e45a..b37f0dc 100644 +--- a/lib/kcapi-kernel-if.c ++++ b/lib/kcapi-kernel-if.c +@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle, + } + header->cmsg_level = SOL_ALG; + header->cmsg_type = ALG_SET_IV; +- header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size); ++ header->cmsg_len = CMSG_LEN(iv_msg_size); + alg_iv = (void*)CMSG_DATA(header); + alg_iv->ivlen = tfm->info.ivsize; + memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize); +@@ -409,8 +409,10 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle, + "AF_ALG: splice syscall returned %zd", ret); + } + ++ if (ret == 0) ++ return -EPIPE; + processed += ret; +- inlen -= (uint32_t)ret; ++ inlen -= (size_t)ret; + } + + return processed; +@@ -434,14 +436,17 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + + for (i = 0; i < rc; i++) { + struct iocb *cb; ++ unsigned int idx = (unsigned int)events[i].data; ++ ++ if (idx >= KCAPI_AIO_CONCURRENT) ++ return -EOVERFLOW; + + /* + * If one cipher operation fails, so will the entire + * AIO operation + */ + if (events[i].res < 0) { +- handle->aio.iocb_ret[events[i].data] = +- events[i].res; ++ handle->aio.iocb_ret[idx] = events[i].res; + return (int)events[i].res; + } + +@@ -452,16 +457,15 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + * return code. + */ + if (events[i].res > 0) { +- handle->aio.iocb_ret[events[i].data] = +- events[i].res; ++ handle->aio.iocb_ret[idx] = events[i].res; + } else { +- handle->aio.iocb_ret[events[i].data] = ++ handle->aio.iocb_ret[idx] = + (__s64)cb->aio_nbytes; + } + + cb->aio_fildes = 0; + } +- toread -= (uint32_t)rc; ++ toread -= (size_t)rc; + } + + return 0; +@@ -613,7 +617,7 @@ ssize_t _kcapi_common_read_data(struct kcapi_handle *handle, + ret = read(*_kcapi_get_opfd(handle), out, outlen); + if (ret > 0) { + out += ret; +- outlen -= (uint32_t)ret; ++ outlen -= (size_t)ret; + totallen += ret; + } + kcapi_dolog(KCAPI_LOG_DEBUG, +@@ -722,13 +726,13 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + goto out; + } + if (addr_len != sizeof(nl)) { +- ret = -errno; ++ ret = -EPROTO; + kcapi_dolog(KCAPI_LOG_ERR, + "Netlink error: wrong address length %d", addr_len); + goto out; + } + if (nl.nl_family != AF_NETLINK) { +- ret = -errno; ++ ret = -EPROTO; + kcapi_dolog(KCAPI_LOG_ERR, + "Netlink error: wrong address family %d", + nl.nl_family); +@@ -764,12 +768,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + goto out; + } + if (rc == 0) { +- ret = -errno; ++ ret = -ENODATA; + kcapi_dolog(KCAPI_LOG_ERR, "Netlink error: no data"); + goto out; + } + if (rc > (ssize_t)sizeof(buf)) { +- ret = -errno; ++ ret = -EOVERFLOW; + kcapi_dolog(KCAPI_LOG_ERR, + "Netlink error: received too much data"); + goto out; +@@ -779,6 +783,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + + ret = -EFAULT; + res_len = res_n->nlmsg_len; ++ if (res_len > sizeof(buf)) { ++ kcapi_dolog(KCAPI_LOG_ERR, ++ "Netlink error: nlmsg_len %lu exceeds buffer", ++ res_len); ++ goto out; ++ } + if (res_n->nlmsg_type == NLMSG_ERROR) { + /* + * return -EAGAIN -- this error will occur if we received a +@@ -819,6 +829,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + + if (tb[CRYPTOCFGA_REPORT_HASH]) { + struct rtattr *rta = tb[CRYPTOCFGA_REPORT_HASH]; ++ ++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_hash)) ++ goto out; + struct crypto_report_hash *rsh = + (struct crypto_report_hash *) RTA_DATA(rta); + tfm->info.hash_digestsize = rsh->digestsize; +@@ -831,6 +844,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + } + if (tb[CRYPTOCFGA_REPORT_BLKCIPHER]) { + struct rtattr *rta = tb[CRYPTOCFGA_REPORT_BLKCIPHER]; ++ ++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_blkcipher)) ++ goto out; + struct crypto_report_blkcipher *rblk = + (struct crypto_report_blkcipher *) RTA_DATA(rta); + tfm->info.blocksize = rblk->blocksize; +@@ -845,6 +861,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + } + if (tb[CRYPTOCFGA_REPORT_AEAD]) { + struct rtattr *rta = tb[CRYPTOCFGA_REPORT_AEAD]; ++ ++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_aead)) ++ goto out; + struct crypto_report_aead *raead = + (struct crypto_report_aead *) RTA_DATA(rta); + tfm->info.blocksize = raead->blocksize; +@@ -858,6 +877,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle, + } + if (tb[CRYPTOCFGA_REPORT_RNG]) { + struct rtattr *rta = tb[CRYPTOCFGA_REPORT_RNG]; ++ ++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_rng)) ++ goto out; + struct crypto_report_rng *rrng = + (struct crypto_report_rng *) RTA_DATA(rta); + tfm->info.rng_seedsize = rrng->seedsize; +@@ -981,19 +1003,19 @@ static int _kcapi_get_kernver(struct kcapi_handle *handle) + /* 3.15.0 */ + res = strtok_r(kernel.release, ".", &saveptr); + if (!res) { +- printf("Could not parse kernel version"); ++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version"); + return -EFAULT; + } + tfm->sysinfo.kernel_maj = strtoul(res, NULL, 10); + res = strtok_r(NULL, ".", &saveptr); + if (!res) { +- printf("Could not parse kernel version"); ++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version"); + return -EFAULT; + } + tfm->sysinfo.kernel_minor = strtoul(res, NULL, 10); + res = strtok_r(NULL, ".", &saveptr); + if (!res) { +- printf("Could not parse kernel version"); ++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version"); + return -EFAULT; + } + tfm->sysinfo.kernel_patchlevel = strtoul(res, NULL, 10); +@@ -1217,7 +1239,6 @@ static int _kcapi_handle_init_tfm(struct kcapi_handle *handle, const char *type, + + ret = _kcapi_common_getinfo(handle, ciphername); + if (ret) { +- ret = -errno; + kcapi_dolog(KCAPI_LOG_ERR, "NETLINK_CRYPTO: cannot obtain cipher information for %s (is required crypto_user.c patch missing? see documentation)", + ciphername); + return ret; +@@ -1368,7 +1389,7 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle, + in += inprocess; + inlen -= inprocess; + out += ret; +- outlen -= (uint32_t)ret; ++ outlen -= (size_t)ret; + } + + return totallen; +diff --git a/lib/kcapi-kpp.c b/lib/kcapi-kpp.c +index 814485a..d0383d6 100644 +--- a/lib/kcapi-kpp.c ++++ b/lib/kcapi-kpp.c +@@ -52,12 +52,12 @@ int kcapi_kpp_ecdh_setcurve(struct kcapi_handle *handle, + unsigned long curve_id) + { + struct kcapi_handle_tfm *tfm = handle->tfm; +- char curve_id_str[sizeof(unsigned long)]; ++ char curve_id_str[24]; + int ret = 0; + + snprintf(curve_id_str, sizeof(curve_id_str), "%lu", curve_id); + ret = setsockopt(tfm->tfmfd, SOL_ALG, ALG_SET_ECDH_CURVE, +- curve_id_str, sizeof(curve_id_str)); ++ curve_id_str, (socklen_t)strlen(curve_id_str)); + return (ret >= 0) ? ret : -errno; + } + +diff --git a/lib/kcapi-md.c b/lib/kcapi-md.c +index bddd76b..5f493eb 100644 +--- a/lib/kcapi-md.c ++++ b/lib/kcapi-md.c +@@ -196,7 +196,7 @@ ssize_t impl_md_sha256(const uint8_t *in, size_t inlen, + } + + ORIG_SYMVER(md_sha256, "1.0.0") +-ssize_t orig_md_sha256(const uint8_t *in, uint32_t inlen, ++int32_t orig_md_sha256(const uint8_t *in, uint32_t inlen, + uint8_t *out, uint32_t outlen) + { + return (int32_t)kcapi_md_conv_common("sha256", in, inlen, out, outlen); +diff --git a/lib/kcapi-sym.c b/lib/kcapi-sym.c +index 911ec1e..d500061 100644 +--- a/lib/kcapi-sym.c ++++ b/lib/kcapi-sym.c +@@ -47,6 +47,9 @@ ssize_t impl_cipher_encrypt(struct kcapi_handle *handle, + struct kcapi_handle_tfm *tfm = handle->tfm; + uint32_t bs = tfm->info.blocksize; + ++ if (!bs) ++ return -EINVAL; ++ + /* require properly sized output data size */ + if (outlen < ((inlen + bs - 1) / bs * bs)) + kcapi_dolog(KCAPI_LOG_WARN, +@@ -120,6 +123,9 @@ ssize_t impl_cipher_decrypt(struct kcapi_handle *handle, + { + struct kcapi_handle_tfm *tfm = handle->tfm; + ++ if (!tfm->info.blocksize) ++ return -EINVAL; ++ + /* require properly sized output data size */ + if (inlen % tfm->info.blocksize) + kcapi_dolog(KCAPI_LOG_WARN, +diff --git a/lib/kcapi-utils.c b/lib/kcapi-utils.c +index 46fd330..e801d29 100644 +--- a/lib/kcapi-utils.c ++++ b/lib/kcapi-utils.c +@@ -96,7 +96,7 @@ err: + } else { + kcapi_dolog(KCAPI_LOG_WARN, + "AF_ALG: setting maximum splice pipe size to %u failed: %s", +- size, strerror(ret)); ++ size, strerror(-ret)); + } + return ret; + } +@@ -109,7 +109,10 @@ int kcapi_get_maxsplicesize(struct kcapi_handle *handle) + return -EINVAL; + + /* Both pipe endpoints should have the same pipe size */ +- handle->pipesize = (unsigned int)fcntl(handle->pipes[0], F_GETPIPE_SZ); ++ int ret = fcntl(handle->pipes[0], F_GETPIPE_SZ); ++ if (ret < 0) ++ return -errno; ++ handle->pipesize = (unsigned int)ret; + + /* + * For vmsplice to allow the maximum number of 16 pages, we need to diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch new file mode 100644 index 0000000000..856d7a9879 --- /dev/null +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch @@ -0,0 +1,55 @@ +From 79198067bdf027f5d4d5e2804b086a0a37b277ec Mon Sep 17 00:00:00 2001 +From: Stephan Mueller +Date: Fri, 3 Apr 2026 17:43:05 +0200 +Subject: [PATCH] fix kernel invocation + +Signed-off-by: Stephan Mueller +(cherry picked from commit d9f16d5fbcf8270110a8f6f35523525f345ca311) + +CVE: CVE-2026-71226 +Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311] +Signed-off-by: Ankur Tyagi +--- + lib/kcapi-kernel-if.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c +index b37f0dc..5d3b352 100644 +--- a/lib/kcapi-kernel-if.c ++++ b/lib/kcapi-kernel-if.c +@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle, + } + header->cmsg_level = SOL_ALG; + header->cmsg_type = ALG_SET_IV; +- header->cmsg_len = CMSG_LEN(iv_msg_size); ++ header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size); + alg_iv = (void*)CMSG_DATA(header); + alg_iv->ivlen = tfm->info.ivsize; + memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize); +@@ -411,6 +411,7 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle, + + if (ret == 0) + return -EPIPE; ++ + processed += ret; + inlen -= (size_t)ret; + } +@@ -436,7 +437,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + + for (i = 0; i < rc; i++) { + struct iocb *cb; +- unsigned int idx = (unsigned int)events[i].data; ++ uint64_t idx = events[i].data; + + if (idx >= KCAPI_AIO_CONCURRENT) + return -EOVERFLOW; +@@ -459,8 +460,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + if (events[i].res > 0) { + handle->aio.iocb_ret[idx] = events[i].res; + } else { +- handle->aio.iocb_ret[idx] = +- (__s64)cb->aio_nbytes; ++ handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes; + } + + cb->aio_fildes = 0; diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch new file mode 100644 index 0000000000..591c32412b --- /dev/null +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch @@ -0,0 +1,93 @@ +From 8ab3c8939276848ec8f43156a7658f7c5dae4026 Mon Sep 17 00:00:00 2001 +From: Stephan Mueller +Date: Thu, 30 Jul 2026 08:36:32 +0200 +Subject: [PATCH] fix memory corruption + +Signed-off-by: Zoltan Fridrich +Signed-off-by: Stephan Mueller + +CVE: CVE-2026-71226 +Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4] + +Dropped changes to the CHANGES.md file. + +Signed-off-by: Ankur Tyagi +--- + lib/kcapi-kernel-if.c | 33 ++++++++++++++------------------- + 1 file changed, 14 insertions(+), 19 deletions(-) + +diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c +index 5d3b352..8a12c09 100644 +--- a/lib/kcapi-kernel-if.c ++++ b/lib/kcapi-kernel-if.c +@@ -423,6 +423,8 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle, + int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + struct timespec *timeout) + { ++ int err = 0; ++ + if (toread > KCAPI_AIO_CONCURRENT) + return -EINVAL; + +@@ -433,34 +435,26 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + events, timeout); + + if (rc < 0) +- return rc; ++ return err == 0 ? rc : err; + + for (i = 0; i < rc; i++) { + struct iocb *cb; + uint64_t idx = events[i].data; + +- if (idx >= KCAPI_AIO_CONCURRENT) +- return -EOVERFLOW; +- +- /* +- * If one cipher operation fails, so will the entire +- * AIO operation +- */ +- if (events[i].res < 0) { +- handle->aio.iocb_ret[idx] = events[i].res; +- return (int)events[i].res; ++ if (idx >= KCAPI_AIO_CONCURRENT) { ++ if (err == 0) ++ err = -EOVERFLOW; ++ continue; + } + + cb = (struct iocb *)(uintptr_t)events[i].obj; + +- /* +- * Older symmetric AIO implementations used a wrong +- * return code. +- */ +- if (events[i].res > 0) { +- handle->aio.iocb_ret[idx] = events[i].res; +- } else { ++ if (events[i].res == 0) { + handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes; ++ } else { ++ handle->aio.iocb_ret[idx] = events[i].res; ++ if (events[i].res < 0 && err == 0) ++ err = (int)events[i].res; + } + + cb->aio_fildes = 0; +@@ -468,7 +462,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + toread -= (size_t)rc; + } + +- return 0; ++ return err; + } + + int _kcapi_aio_send_iov(struct kcapi_handle *handle, struct iovec *iov, +@@ -544,6 +538,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle, + } else { + kcapi_dolog(KCAPI_LOG_ERR, + "Could not sumbit AIO read\n"); ++ _kcapi_aio_read_all(handle, (size_t)ret, NULL); + return -EIO; + } + } diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb index 532c9e29df..f2ddc25336 100644 --- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb @@ -5,6 +5,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=3d8a091d797491204567185a6efce70f" SRCREV = "fc937358e71253a6efaa3ba74885364976b040ea" SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https \ + file://CVE-2026-71226-1.patch \ + file://CVE-2026-71226-2.patch \ + file://CVE-2026-71226-3.patch \ " inherit autotools From patchwork Thu Sep 3 09:49:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97225 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7C691C624DA for ; Thu, 3 Sep 2026 09:50:55 +0000 (UTC) Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4062.1788429047051646716 for ; Thu, 03 Sep 2026 02:50:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=q8j32drn; spf=pass (domain: gmail.com, ip: 209.85.210.177, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-8557c3f270eso1325444b3a.3 for ; Thu, 03 Sep 2026 02:50:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429046; x=1789033846; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=h7OINWDWkPFWoalCyjxjfpFoGHkJ625GNxys0namKfs=; b=q8j32drng1FCfuhlqEdJzzWvi8FiYiFEnsIN1iLcWLtTAskv7k2441Jkj+lBIJeCbq WnAJiQRWK4YNWG8abLkoZwDirB3OiLPw+W3x1R0BHuoZ0rsr8Vj+1k7vhnb8E9x+cAgh UZD9PCWRtZ6ksZOmKGwgSXfgNsHfswoK/X7BGi1jQzQuT4gJ8bqcPtHNqje2pKF/4O+O lrePzLdVta7tV0zz4By1eOKW0kp09lzs2wTldtKcKWbalZkAccGcEWfI8g8yWA+c2j9j gic3KUrPaWfW66dociHkWr8z6lCnqHOlR23TR6GrpAG4W5xVAROCoIQeWlH0EhRSewqB kydQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429046; x=1789033846; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=h7OINWDWkPFWoalCyjxjfpFoGHkJ625GNxys0namKfs=; b=aInyC3SrORyLzB8a257QVFrQqGmSo2YiuTlR9cyJ6po/IiiluyyqoqcUdwD2zdROPQ B0bNI2wmF+ClJ6t7korIcEcB7zUSOltrQvpI5MpTnHSgD3eXCrpyE5jbVUulR4XiFMwS HDc6eXrOt3jjZjoBwPz+8NdIGawIerXwRcxyaSb9Edxqvwf2VkBNGm6l8QPD8ijmsS0X YyoLPxxVuSZD24JwD4IxEbUwSqzFJQdBubMmBAvPkpA4F9g0Cf4I52bJcFeRxe+/Wg7Z j7m+YPvuoxeRUtaipcKbPE7Zr+7uk+XoF38V6SwbIC4nl5G5cXyMfkw0sV8JK+T2OMNV I4Mg== X-Gm-Message-State: AFuF++l2xbzsRwzqKGoUGhoWbtvA3gbAratiLuXwwKUtiU94nU4pFAH7 HgD+7Hu5UcISTQvSstVjjFziNF1sMCYWywKBJb/Co+lmSQu4VT3IV4zfUhaGuCk+ X-Gm-Gg: AYBFou1ab9DkUh05FJEwVB+doSIk41fivqxC72mmyTXMzrLXRSVwtUt+PVVWF1MoWQu MDJWar9GC8RuypDwohoHNGwiSSyOLEhx+GcTKlpMI7cLB2+aqJjEVIFB3OR8yTvrc8dE2yX4zY1 bdmYyboF8Hn77iWO9h3L9/E77LtLmj3KO+cNM6lfBHhojLNzIF8u0ws14RJvGHOEVnrGHY1S2RQ GYyOr+6hgLRgI3IAdc6G1iYk13FpPExcEJXPTt7MVS/gjJKBfKw2iw7obPk+Zyfmchg+VVZCIvf W79Bx28k3bu7ZQcD5Znnw3DJFKGq297cmhxktl0h1EvWedOzJSr+4HQT/AHvrW+6E50U/2hJjPD Vnqu0KjMO9rjFuUDE58ktk84PLswwWEMxvyx2twgCVAZawy/AbIRIV9+AJDOoHpdit4xW3Md0ht QNZp/SQurVRkqVhI9KZzw3P/V6e80gFGznv/7ZBQuuBgEzyF0G6n3hbOutx6wGwwwgLtrp3R0dH IevKLH4DMw= X-Received: by 2002:a05:6a00:bd8c:b0:847:770f:da4c with SMTP id d2e1a72fcca58-85ed8ed841fmr17615752b3a.16.1788429046328; Thu, 03 Sep 2026 02:50:46 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:45 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 Date: Thu, 3 Sep 2026 21:49:52 +1200 Message-ID: <20260903094954.3240723-21-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129737 From: Ankur Tyagi Backport commit fixing the CVE as per the release notes[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-71227 [1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1 Signed-off-by: Ankur Tyagi --- .../libkcapi/libkcapi/CVE-2026-71227.patch | 40 +++++++++++++++++++ .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch new file mode 100644 index 0000000000..6074c0da27 --- /dev/null +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch @@ -0,0 +1,40 @@ +From d85279e3bec7578f8c238aec92539985c2032616 Mon Sep 17 00:00:00 2001 +From: Stephan Mueller +Date: Thu, 30 Jul 2026 08:38:10 +0200 +Subject: [PATCH] Fix potential infinite loop + +Signed-off-by: Zoltan Fridrich +Signed-off-by: Stephan Mueller + +CVE: CVE-2026-71227 +Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60] + +Dropped changes to the CHANGES.md file. + +Signed-off-by: Ankur Tyagi +--- + lib/kcapi-kernel-if.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c +index 8a12c09..a54cdaa 100644 +--- a/lib/kcapi-kernel-if.c ++++ b/lib/kcapi-kernel-if.c +@@ -436,6 +436,8 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread, + + if (rc < 0) + return err == 0 ? rc : err; ++ if (rc == 0) ++ return err == 0 ? -ETIMEDOUT : err; + + for (i = 0; i < rc; i++) { + struct iocb *cb; +@@ -509,7 +511,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle, + timeout.tv_sec = 0; + timeout.tv_nsec = 10000; + ret = _kcapi_aio_read_all(handle, iovlen, &timeout); +- if (ret < 0) ++ if (ret < 0 && ret != -ETIMEDOUT) + return ret; + } + diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb index f2ddc25336..f1fe6a0940 100644 --- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb @@ -8,6 +8,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https file://CVE-2026-71226-1.patch \ file://CVE-2026-71226-2.patch \ file://CVE-2026-71226-3.patch \ + file://CVE-2026-71227.patch \ " inherit autotools From patchwork Thu Sep 3 09:49:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97226 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6E0A9C624A4 for ; Thu, 3 Sep 2026 09:50:55 +0000 (UTC) Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4203.1788429049566614891 for ; Thu, 03 Sep 2026 02:50:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=pGfg6in+; spf=pass (domain: gmail.com, ip: 209.85.210.177, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-84e27035206so1965891b3a.3 for ; Thu, 03 Sep 2026 02:50:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788429049; x=1789033849; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=kEI6p+CRA9EMBL6/HGN7/awslcYQEBdet1Ze67a8jUA=; b=pGfg6in+TYORfEno3tsM+iZ+Vwlh3zJW8gBVNoRySYP8wHtYklE64zGHzKm8a+aKDn 7S7Otq3nJCYdCGXrpgNSLCw1gsO4WLbO+Iel2RW/Lz9ARDvZySShxIcbyPnfxY8U9n3o QiklwfsXqIQelhJwwvPEuezgWaZT50/0Lec1DxZlloj7CO/JxqADTAyH0LJGggQlXZwz V7qPVJp74cPOGOvrniuk8VqlVVaHZVo4peWakmkfhzApq63sVHytVu2Vwt9wqQM5R8xK wHpdhaVVSoD4a8U0UWTSeVJlIPlstHbz/8grGo5C8AjgeSSCzHX9GdH/+ovN2mU0MRFd fEeg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788429049; x=1789033849; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=kEI6p+CRA9EMBL6/HGN7/awslcYQEBdet1Ze67a8jUA=; b=iDXOv46dyN7YvxGnvTSw0rFvBudJzDkmh/IQFirIZ9+y30g+DdY/voilUgiJ3gvJvB 30vWH9/ywMZLima2sK9v+Q+2rd77vkyza7gObvIVdXKy05gHxB2fSbY5SUaxw7WoNfAZ qgwGe/1+c59gBCzHXCEIXolh9zm3+agTadWRgzq7ws7FeFETkBTG7AnNPMkK4dYbRnAY rgIs9FKY5xzqhumpTPDm0F7K3O/WGstH+1bVT1F5w2CVkdFFogoSjmEOQlZ7jFupbykN 7DljY2eCXnH9h4h+JQhrKDqfupJ8iqa8Ss5XJl8LfXfY1fvy//9i7ZEf+XjET7RB9HrA i3sg== X-Gm-Message-State: AFuF++kg5+VDTgJ0s1YCVDcqyuBGGUsdyIFkLgvHcclQWGVUp0w+fi3K a8tOEi8K4A9wMKXTd+y2ty9RxFDF+gnpgraySanjnn1GkTC3CI8WZmCx6/UUqcFE X-Gm-Gg: AYBFou0XRMTCyUTsLp6CoS8tFOjdx6DVNOwMh6Y88kp7soNXZrDE3KNnU/GS3TghHpM ujrP/exq7r5xC7IuuEs+NFi8HMWSNgTqkJx25bdeYVMgtMwD0pj08QRhWeDa97TphFO3FuBhq9Q eo0O8miaqTzxZWNWYztWgn0jqt7XunP6nTG5hcA6l9OXoY02+xDzYBoL216aQBiKjozvf2lLO5H Kvd+jESy9eEtt9JfJIQH5FgpyCpYpvejbsdYY6u58/PIT7fHJQBFf1yza7JwDzHHdqHbid79x/2 6jFDjiYwC8ywq9S2Yr11uHrxq4vo/QqXKWJLKsHJKzH3aeDQIWg46YuTLtiJ8pKhq7OvXs5ff7c hJuIiI5g3PhGiisKhK+a4iZ85jpiM3VOiPXsKBQrlapciQN8UE4JWYasJJNfTcl6EaI/v6QxoD7 O2UuMvJsHmKtAC2nnf9Uj4Ry9a7DIDVFoRdFb2VtRMGxQlcJ8vA0EQ++oQ+z4T0JJuqCuBxc1Po nAj1hMZXvzhYg== X-Received: by 2002:a05:6a00:230a:b0:857:726d:2e97 with SMTP id d2e1a72fcca58-85ed3f6e665mr14853712b3a.20.1788429048791; Thu, 03 Sep 2026 02:50:48 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc003aebdsm2581265b3a.39.2026.09.03.02.50.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 02:50:48 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 Date: Thu, 3 Sep 2026 21:49:53 +1200 Message-ID: <20260903094954.3240723-22-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> References: <20260903094954.3240723-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 09:50:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129738 From: Ankur Tyagi Backport commit fixing the CVE as per the release notes[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-71225 [1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1 Signed-off-by: Ankur Tyagi --- .../libkcapi/libkcapi/CVE-2026-71225.patch | 38 +++++++++++++++++++ .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch new file mode 100644 index 0000000000..8a2e4220e7 --- /dev/null +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch @@ -0,0 +1,38 @@ +From ca418d6cc684057bcead18b3dd68d64cb3e156af Mon Sep 17 00:00:00 2001 +From: Stephan Mueller +Date: Thu, 30 Jul 2026 08:39:37 +0200 +Subject: [PATCH] Add safety measure to prevent IV reuse + +Signed-off-by: Zoltan Fridrich +Signed-off-by: Stephan Mueller + +CVE: CVE-2026-71225 +Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6] + +Dropped changes to the CHANGES.md file. + +Signed-off-by: Ankur Tyagi +--- + lib/kcapi-kernel-if.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c +index a54cdaa..859ecdf 100644 +--- a/lib/kcapi-kernel-if.c ++++ b/lib/kcapi-kernel-if.c +@@ -1387,6 +1387,15 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle, + inlen -= inprocess; + out += ret; + outlen -= (size_t)ret; ++ ++ /* ++ * Clear the IV so subsequent chunks do not override the ++ * kernel's chained IV via ALG_SET_IV. The kernel updates ++ * its internal IV after each operation; by not sending ++ * ALG_SET_IV for later chunks, the next chunk continues ++ * where the previous one left off. ++ */ ++ handle->cipher.iv = NULL; + } + + return totallen; diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb index f1fe6a0940..edc8c0e47a 100644 --- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb +++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb @@ -9,6 +9,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https file://CVE-2026-71226-2.patch \ file://CVE-2026-71226-3.patch \ file://CVE-2026-71227.patch \ + file://CVE-2026-71225.patch \ " inherit autotools