From patchwork Thu Sep 10 05:11:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97819 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CF93EC88E40 for ; Thu, 10 Sep 2026 05:12:08 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:01 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=GsZ618Qx; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=PBXcDCNybTAwP+ZLT74pEZwlHVddnLPwsJ0tuUrS3U8JeqVz+uZbiMclrsd45CrIL9fv3CKylQyHUv3L9Oegecfh1ziPvKwto9cMqAoAdcASTcnLDHTx4I12CyzwRc/4Vp5fiqm/2AMjTHvnWuCMAgbpYyh2l/2Nmc95nIIHcRqxCLCIjUneyg5Sbb+POpe1TW4bc2z74IVcgKmZ9YM1jQ+pxe67HuUJ4ohGDtDxaz63mbKeb7awcVud/jZDLhJ66XOyMkXckgyhrLDlzFncGgxk2hMLKCzTiap/gz0atci6VZMA7rMYKvCU8Vj2PeUOMWq2OSsksrRQhW17wwLTwA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=WIrgFiCcclDQo7S2CySR8Jajyvk9ixBx30BaNCWVxgI=; b=Bm0U42vNqGoztP7GEfrFni8xH1MGog7xYhUx462rlcu88q0dObHSa9x9Sx3Kh+7VgDj/qAsCrLOI3fT11tv/OxFIICb5SwKDEQLt32dhnPWnRyRF6gQwAA953ZKfEMRYnUEPuGjakCyt2LFzqtdaM6ICyoLvW3kvyf7SPv82AJGWNJ5Bh2dl0s04TnZ5rbxFxtl9l6iBlWWuFYt/lBR6++uzaw4nygAzWjEPnJl0RoBG/DyYBZUD5lq0uYObOQmPHUAp8lrxz2mKGrbkBcQOm43adu6IMb80k0V+iI5X2Xqztho8voXOc/6ypkiscKrNnvbtTm9l4st4IGtzW6N5JA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WIrgFiCcclDQo7S2CySR8Jajyvk9ixBx30BaNCWVxgI=; b=GsZ618QxZateRYVwfbMGgNuSWNcZs5J8c6Vd1E5m69tMa0fZoJglGd7hvwHXVLJddOXEW1RQY5eIS7DM7Fi8JWQmX2Wx0SrZA+oHe5Yr33JNlyQNJjiYohYsdEz4WqXa4L5gvtL2mT3mASnJTtgeWWr73qxB7kCuABx68WtrOkbtIUibPFb5m3peXgSbFyujTn4hFqmSZs9Gz7/sF3VEExpoe4pdhw5wXkVogmVBEkzzaO91wF9EBF+69WzfGjV8tJBpZZIjjsekKOtRwQy/iGRXvKeK/4QFhiBN2T2VuE6+dUgiVJ0DN8vxWvXqb+NN2G3PuvwR4EcpKzRPh5Sy1A== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:11:56 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:11:56 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 1/7] libpcap: Fix CVE-2026-0799 Date: Thu, 10 Sep 2026 07:11:48 +0200 Message-ID: <20260910051154.30595-2-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0151.eurprd01.prod.exchangelabs.com (2603:10a6:10:4bd::13) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: e1b0db70-6ee0-4bbd-da51-08df0efa08dc X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: PhCWJxhB3uTQInkbnpOAKgn9hp2QYECW5Wk9HpoeGcHUzugqN4/NlnO6qBP1S/bFTp5JQX2ynovVPMX/vFg1oowR7sAqDnkOdYJ5dWE1QoYsoiiHNyPBEVDR2Cd3cQoTVJRHc05tfsaJaoFS2IPNg+tDvezSJJsZnZT/E8GG286PwOTUuFpUQQ4B9nzDwbY+Vy53y55RzvjBfOURGB72GyPW+XA9DKMoOup0SoHv+CMmthi99zQgPs90zZlW+L0Tj1iX0Zz5uR3qUst3W/NUy7CJlpuA8Mgg7ugT22adiMASn06BPq/UbT0Zu1rhVEA63SshJ1xOmKwcKUl+3YKaUcA43HZK8ek6d45CPjZffgJN8HsVtZ8KXcloplTjpxukIBkmV1I3CNC7oTYz4a/l6NpCp3uB3ySpsVBDt2LpMhVouQM2cMRVIOQDnIlKTvuc+N1P1aprj3y2Vr60UYqVMQYKUwo/9e3kj0FB5gtuLe3QUpDCD2AyyxQa1YNwB4onf5M+kgNe4J+AixUyZe6VVchpTSZy50eFah028DhART4XpgaYbV+1rT4vgmvONThAk/dMkj8SGTyx3YyrMLUg/Y9QxcCH4FoZ5/PCSPvAnFhIstNHzGaTeWLVYUv4S85a X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: xNXGP2WGHP26sbNdP15Jd8T6SGUdDnyoUUft4ynRt92HEZKJi+54xGQPytox5X+Ox+z/SFvKPv/holzw8EuTE+SXcLabm/xosao+Aq5yQpBl3fCDfJ+vn0wUzhj1rRGgf6dIlmWUndto9PIcjF9FHcIDpgB9GcCxTVR1KDkuB6Cl8g+ux0Gnge3MgP0HoTMWD1mfcb2yK3Yo+tWEVoBdR9lTpjTDpVTqXWaY2inr7gJGJ/p8dgvhqS45f+AluqVpaY4f11wL5LVuhmDIV1QyYJAeEkoOcNYRN30Xc3aJaOsBD1KscodffWJIXOt1/YHfFFy6WQuPcczXkGI5FXbnDU7jvJKxOQcdqwkff4TFImANcaVwZZJ5ZK3ZuAWQpVp/qZnK3fuubO33rZ9Bbei6APNyaAt8mSRwk2RHp7X2O85+h1v2/gCOfzqNn+ZS4jqkg42+5sNeZWtI2YvYMbmJlkS12iPU4Zr3dhYa8c4dxtkyEeqrT6yNAfFLQN2H5LajaQ9gBtNT8uRuJew28OquxWkIaJw0L8WiRLOOsVVSIZtdfeV05Shy9fLYestrdE9bNfFczPCGIuRgZLb+QbZZSOWczZZcWJzTBK5L5GUYIruevrz/oke65x7rwt8/bf5wuGZkI+0am8EMN7qE6WtVYJzJOGisiUPLRfjj/NAbYBd5+fwTJ135hX9YScDsxfvvjG4bfkH0RGz9uarOjK3/THiF4jteeiB17KoyXsNjTRNK7vOX2o6v8NVJuI/L1nRoNqbIOVlCcXrzG13py8TCZZlCkQb1RCwdipQPpsS3T4vK1MeVwBZ644MrAceRAp46i70ILcvYylGAIntMgKGvGJ9DQrdmy2qElcDpeEyvF4CJ6w/lXHbWNwKLZrMPXabqwkF5h4ZZH+6dYcI4VK7WogLD94uQjFAOlp6RHWjXiFgJ5zTEKMvk+uUna19xxW2RNsnua7pKbdrlSDgpiKZ/4ag2SIotCalNFS2dxcs3frj17ud/QQAw+Z9KPvGy0rxZ2vIuIQOCF9IdBozqpraCifFPbp+Ixbjd4nMG2C6ZTCpWEQlSw5yoseYvSZ54XVWFm/LCYQ78ejvJRajeeec4VPpU8F6VMPArQ+2PFsbNYG1dwnp1GP4Sc9IzxPeZ4AFONPaVXdI3csFDkdvD10IikD4rS/Ty7iGbJIfILyZolscRP4rWwh8VR4EXunz/vMetkIB5fbIbtSwTCXUfVtin/qcchAsfzAlDGaKFvaFnR3nPy43gHeeNtTywHYGRX2a5KCGsMt229X05cACQTGIF9xO4JvlaqAXq4/HZXzIk/pIpmhnXUNeKeCvqYXPLvK+PjgewjKTM8QILPJZ5WZ0oJlFBFx3b2XH/h16/hYG/36gsVqeYHiU3EG/1u4mKY/tT4CgBZe4JoeiWCz/XYJYE6+UAexlv2G50ZVyQdVLIdOb5TXg4i9dFAnRhu3fSkUAJmooxUmpvxuHYUiDWexGE/in6wBEW+7+ooLfOTCaMPnWYTZ96S+suHZfZacNXEMdIjxpxYmOiqw/0HQQfTszasKNkkWuRmfmVUXkSetfYu64+7Xaq3aR0r/G5prCsRrGfzTdO8wjp+Kuwh3BCz1DCzLCXVgXk7AvKxZaQwwsD4yMMIiFjn3jRUjl32sW9Dl+s+UHtTMgHMHNOsVdEMs0m3ef8XxeKCukau9OmQv0uw5CJ1O0UXhdQyY14p8Q6bYGrUIs2roWsiIbhKmq/tK3BHxH0NiaC7oVjjiEz85J2dhhj6Wogj4pOs0fEDq3K1HB2ybH1Kpon X-MS-Exchange-AntiSpam-MessageData-1: V6srX7C6eoXfSVbW2SL200eSIhCBMRuQUsw= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: e1b0db70-6ee0-4bbd-da51-08df0efa08dc X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:11:56.4110 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: qVN5sZmtAxNFTggprPq4i+TFBjnasgYs5FYgaq+i3RLVGfBiP4glcWfcFrIV92mhJV/Q5Lctf+LaGzitI553bjENJMtLNf5aiT2tFJ+s3uo= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245524 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/01-CVE-2026-0799.patch | 87 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 88 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch new file mode 100644 index 0000000000..58289d7e3b --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch @@ -0,0 +1,87 @@ +From 3c55fdefa576c7a06feab86a9e4341be414de49b Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:41 +0100 +Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter. + +Include Security identified and reported this problem as a potential +vulnerability in 2018 (case reference "I7"). Their work was sponsored +by Mozilla under the Secure Open Source program. The vulnerability has +been independently confirmed only recently. + +The current revision of pcapint_filter_with_aux_data() can, but does not +check whether a scratch memory register index is valid in the "ld M[k]", +"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this +is always the case. This holds for programs that have been generated or +validated by libpcap. + +However, this does not necessarily hold for programs that come via +pcap_offline_filter() or [deprecated] bpf_filter() from an external +source and have not been explicitly validated. If the interpreter +executes such a program with an invalid index, it will read/write the +process memory at arbitrary locations starting at the current stack +frame. Depending on the address, the memory layout and the OS, this can +result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To +fix this, in the interpreter reject the packet if the index is invalid. + +(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a) + +(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7) + +Notes on backporting to 1.10.6: + - The CHANGES entry added by this and the following CVE patches is a + downstream addition to record the backported security fixes. It does not + come from upstream: rather than import the upstream 1.10.7 changelog block + (which also lists unrelated, non-backported changes) or claim a 1.10.7 + release in a 1.10.6 tree, a dedicated "1.10.6 + backported CVE fixes" + section is used, listing only the CVEs actually backported here. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7] +CVE: CVE-2026-0799 +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 4 ++++ + bpf_filter.c | 8 ++++++++ + 2 files changed, 12 insertions(+) +diff --git a/CHANGES b/CHANGES +index cb603f8..74f8ddf 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -1,3 +1,7 @@ ++1.10.6 + backported CVE fixes / The Tcpdump Group ++ Backported security fixes: ++ CVE-2026-0799: Access M[] safely in the BPF interpreter. ++ + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release + General: +diff --git a/bpf_filter.c b/bpf_filter.c +index 9b899bbb..510dbd9c 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -217,18 +217,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_LD|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + A = mem[pc->k]; + continue; + + case BPF_LDX|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + X = mem[pc->k]; + continue; + + case BPF_ST: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = A; + continue; + + case BPF_STX: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = X; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index d381a4eb2f..265c46e3bd 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -12,6 +12,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ + file://01-CVE-2026-0799.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97823 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 25E6BC88E41 for ; Thu, 10 Sep 2026 05:12:10 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:02 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=WdsU260t; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ZTqFs+yU5xkGL4lNMKjzNmsnkGPopbOIS+2qtvcNmDu8dBELK8Ig+8JI5NHSWYvFwCEIfTJUTyNZr9d/l+1CUf/PJNz0kh/u4eX6nMFQRECIdIncxh5A3aR7n8Jt8VJEoaHqDpBbihFQrC0NpWvuxpisZ5L+VDe4+gDQerCICFj48y41bvmkD7INKC6ZoSj1HRkjvR1Er7fs1xWXV5gkoOHZh56nbdmMAgdMGNXnRMZfid92yKsGZIsE+oRGxFq7b3unT3MlHHw9eOxJF70VOf7hxav18HrKzD8QdkJvXHt+ofeAujMuDoBLvk735gxo1IyZGDcUCOvjpgoBh7+30g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=lP6EBesQ3tKC9baf51olH0eVbcqD7+zTL70B4OJL51w=; b=GZ8uexYu9PMfG+GB6G8KcZcJ6VA0gtLVOk8+ru+oeA6Uob0os2iCUm83zXEVKPEFbxJCgT87NaPVv3+qemGyeMbq0BIvVWkTPRoau7OwxNgSySJxFkKx6N4BIqjAoLbfgHXEzGHK5wjT2QkChfMNZov4uROAHJhiPbCIpUF+kdd/Iv1VJYK6+NbqueqIn3QzWmPWj8yorW9jKrao4nOlwN8GNgV6mNdVvhIE1Dd4bDzzv2M9piJ6qrVTb/JzGCnvyqYi4kQJo0touCnjsAM448VbhMavPWOnCUKwbOOV1FRmojnVrsefeh7nOf9tj8MPF6qbYcFBgS2b8BQe8wfy4Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lP6EBesQ3tKC9baf51olH0eVbcqD7+zTL70B4OJL51w=; b=WdsU260t4P7or+6erWczCiOCKMFftAA/G6Jx/kkWilrtL92s0gklvtknqnpPhvFaGoBfopDD40I49iJgF5mh+kXDCppzfvdC9d8p36BWklMAfCOOcnQJBT89J+Z53XvbcYRfLN/J81vBG7m+VWtOyFd7fCWGqYe/HEA/p+WECIJrU526WeoNklVN+Dr+T3iAZqXhfSuBDMfZvHEzYWNcAIJ4euOq8cOHjbOt2Vlkk7b3LFY7FglI372I903hFpXT6D3vIheDN2EkITI3TP+s0AgISGf0ePr74UXWXdrgJ6AKOCv0GNqTMCUzz7d7n2yHRCQXBhSCDBA/4RKSZYApUw== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:11:57 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:11:57 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 2/7] libpcap: Fix CVE-2026-31912 Date: Thu, 10 Sep 2026 07:11:49 +0200 Message-ID: <20260910051154.30595-3-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZP191CA0007.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:4f9::11) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: da423111-ca51-4b42-ea82-08df0efa0989 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: +fNDns4QEUfUeeFMwu73dXnN11O6x2L5HgLnG9SqXor4lWa8QOJ2T+qrNQ6/RWS+YJbwPir0duDCoV5qQ3rdY6CnuQhYF1DQfthbJ2Ek4t0Y1o1O7XiwRv0x/YUOeY809oDEcNJd/kLvufM6thUHYlGyYI+YrErstalGLVXDLMNKSu4d6CsJ+ZPwtmyyRR59dwyJzQIbXs6xOrr/Y3zzwywEDOWGfeqMcWEUzKEVFNSeFjWc58URz69l8seaI9Dicpi+i+NgqjPBzj0DQ403rLAsuNHks0vlkJLX80KiEJchNFQZGXcIkjELLOVQgisJjdmTI4IUW2Mj7rCm85f9FV04ZTqhXOOPNiClUaP5MpG86pKwlWZS4fxeqmlW0mBLc/7CSLT6DsdWhN7GC9zKmniu9X7YJAaI1q0BkYmgFbtRoDeZHyIyWxWehg0bbSelTlf9JxeVYvJdrxvdJnzh8HEB2ZopTZr7zUyRZBjbXlgkAjBhZYooA/Ws3R7zlBnqsLrPelO1ycJtCaWn5BQnICzSAeHIdLxGExtVWKWrlY0DdhZsDhu0wls/mRFOuuTxKo2bkw3+vAXWziec2TmCUdmC+yMMWR9iO3/7AIIJ4mSnA4xNJWlXI2nIjlm4rVFi X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: FWZWRy29W1HZEwFCJq+143Xe8pXJ84QxuNqRnvPd/+A4kDJGowN53YBHbSPGimQtWhqNh7W6QdAEif3t5xEIVWxeunSqv2/oAUZC40RSw8gTpBtjPQ0I5p594tdYv4IpnHZtsdeH2CxE0mt/etL70WbtF/vV6GZdXYzkBmCySRWO8cx7Fls9K9mTr9leWUrcgD6VXBWEJu0xnO1oolipPQl+za+9iqwcEVYjxF40ED3PQpLwTbfxPNeXvqF/0CGhSfBJSLiy0TYXTu7XPblB2pmjrFKtPDK5DEkvuvBGZEnWgrzNl6vsqN1OI2OxwfI7kUD5uDbr5gxcs1Xd5QH1p3xM/y8kywki+yHOWbNzjHW7B6zU8bzASe3mIz9Uq40qOILGStGM4vzkhG2pz4UK1apfqxEypB8ajTQxdvmsjZTjL5Ho+RHKaQKpgaiJYvwMYqvm7qOF9sLOl2IJhX192nfpylSmpJFsLVJSjVOwcpBoYGYoF/LXOIn6xJ52IJ7XK9kg+rlb5u2Z8XB0+p7cpLUK+0js2tFt7SrQaDad8vFAL5HUtBf8L0Z4rzIdLpVlOWl/91IVkrtuHsm63xtemVpZOl3prBOhzgMPSkLjXDnS23XkX32cI4wTjvwL4cf5++3+7yVbxJDgBpJRs/sXE5ldm9qCZ6rqBwhvEOKsI7tflLtNu8HWbFAJOIjlEpqcc4Hh957ykzPzx369S83Jz0lTGQOGMV/O0I3gxZnBsRI3OC9lvv/8hJkq+PcCdqBRWaWYEbbPCed1pOMdQF3NJklTpew/vdK3c70g7RgX4Io3RsENUWF9Ht9EtxuTRKHFNDFigWqSWIz1Umv7C+gZ39kWAYEC0tfzQSRicPQ1oZcqhKpIp7XkPe99BOsNwOTp+DxiEaMNfwr/nZqH6dleaB6ACk5a6CCJMXGrrY14AkidnUWEZbM0kfv5PLZTUbbpbeDNHg17bXBT1NtzEa+My1vCMLjNU3kCv2GdQbHocBQlBshaRZVNLZqjHNC05bwgaqa2ky3AwXruvB1jXJ3sdhUjwK2USA22zegoxIjO3IuPw97ti+ETHCagXDird4j+cpGavqHVDe09HvF3bhygg+WyuahU++oh6eFPemmZSTzQS1X8jVY/gqOhqQ0hJLfAgNs91qBzoFTkvrOAx1mpFaDHRlfE5sSyrN80+Fra5/w4D9sUpwV2NjvGZ0X5PywI0d9lc5apaeHtCkF7y0DrHXe2f749VExTTRlrqa6xFwuErc9p9taeyuIPbdcDKzDaXLkEri2zJvTNav4/YtyCZEHbg9sdC859EbOYatY/8i290jDMbLap7QPH/BdC1Y4DD6+XQhrZWTt1TzgaSdOBXevwCS99QBULeOc3Cd4ANTDC7YKkXVCEnm80nmkO6MqxMCFyPojlo0LKZEmTA2xQQTO5Q5uVJH+YpPeVRTnqsKp6uiExnBnBvPAU3hE5ModVbPy+o8OZMhraj+usx9aowAia77Gq9ZuII4F1h79fPtMktm43ItbWCnZsqGtnec6hhdxAsHtig5xk/ie3GLH1W2pF1/qNT3syguVzjS8XUkdZPGQi4m26OP3ESNNzANrmq3t0Fi/eXZoHRPKvEEyFVruvqr0Gsj3yXZh+esihh9J1gE1i11kURiG8PBqretBqVh3Dsso8YCIsSRVVTCaVZS8lVmPkT2z+oKVV8K/z1IvMI5gkuPY58E4ZRt7PtN8ZOo/3gHe+5VIIl8kqecXZ4zxehKEDtW2GdKTprzdC0XB1my6KFsMMtOQDAZPwfJYywJV+B6VP X-MS-Exchange-AntiSpam-MessageData-1: 99dgEVZDlf6AMtGF32t01hIzco58zfhB6G8= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: da423111-ca51-4b42-ea82-08df0efa0989 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:11:57.5863 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: nhjGsnyXerI+0pcgaH1+mqb4x8Lm9ts5ENJUamcQjxrWYU30J7P0ZfpP/TvphYo73CIe6PWQ2rpJPYrnfcy3JRhwu+CUo2X+jEGR6BPFdQ0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245525 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/02-CVE-2026-31912.patch | 630 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 631 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch new file mode 100644 index 0000000000..f32c5ed39e --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch @@ -0,0 +1,630 @@ +From 09e04074ddfbca5fa33693c6e2d4f01a74857f65 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:55 +0100 +Subject: [PATCH] CVE-2026-31912: Mind the program bounds in + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() does not know the +number of instructions in the filter program, it assumes the program +counter always remains within the bounds of the provided filter program +and always reaches a return instruction. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program and advances the program counter beyond the last +instruction, it will be interpreting memory space after the filter +program as BPF instructions, which in the current implementation will +eventually cause either abort() (another commit addresses that) or +SIGSEGV. + +To fix the latter problem, in pcapint_filter_with_aux_data() add a +parameter for the number of instructions in the program and reject the +packet as soon as (or just before) the program counter goes out of +bounds. Update all incoming code paths to specify the length; also in +pcap_offline_filter(3PCAP) make it clear the function now requires the +'bf_len' member to be set correctly and uses it. + +(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551) + +(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9] +CVE: CVE-2026-31912 + +Notes on backporting to 1.10.6: + - Adjusted the pcapint_filter() call sites in pcap-dag.c, pcap-netmap.c and + pcap-snf.c to the 1.10.6 code base. In 1.10.7 these were already touched by + the unrelated "low snaplen" fixes (commits d5192db3, fb87fdeb, b0caefe8), + which are not part of this CVE and are not backported here; only the new + bf_len argument is added to each call. + - In bpf_filter.c the scratch-memory-store zero-initialisation and the removal + of the stray BPF_S_ANC_* enum (1.10.7-only cleanups) are not present in + 1.10.6, so only the new pc0 declaration and bounds checks from this commit + are added. + +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 1 + + bpf_filter.c | 137 +++++++++++++++++++++++++++++++------- + dlpisubs.c | 3 +- + pcap-bpf.c | 3 +- + pcap-bt-linux.c | 3 +- + pcap-bt-monitor-linux.c | 3 +- + pcap-dag.c | 4 +- + pcap-dbus.c | 3 +- + pcap-dpdk.c | 4 +- + pcap-haiku.c | 4 +- + pcap-int.h | 8 ++- + pcap-linux.c | 1 + + pcap-netfilter-linux.c | 4 +- + pcap-netmap.c | 3 +- + pcap-npf.c | 3 +- + pcap-rdmasniff.c | 3 +- + pcap-snf.c | 3 +- + pcap-usb-linux.c | 8 +-- + pcap.c | 2 +- + pcap_offline_filter.3pcap | 27 +++++++- + savefile.c | 3 +- + 21 files changed, 182 insertions(+), 48 deletions(-) +diff --git a/CHANGES b/CHANGES +index 74f8ddf..ab812dd 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -1,6 +1,7 @@ + 1.10.6 + backported CVE fixes / The Tcpdump Group + Backported security fixes: + CVE-2026-0799: Access M[] safely in the BPF interpreter. ++ CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/bpf_filter.c b/bpf_filter.c +index 510dbd9c..4f9adeea 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,24 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++/* ++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the ++ * userland interpreter in libpcap is meant to support much longer filter ++ * programs. In the latter case it is important that BPF_MAXINSNS does not ++ * interfere with the safety checks in the validator and the interpreter: ++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX ++ * It makes the most sense to be able to interpret as many instructions as ++ * pcap_compile() can produce, without optimization, for a valid filter ++ * expression before it consumes as much memory as the current definitions of ++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost ++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit ++ * machine. ++ */ ++#ifdef BPF_MAXINSNS ++#undef BPF_MAXINSNS ++#endif ++#define BPF_MAXINSNS 3060000U ++ + /* + * Execute the filter program starting at pc on the packet p + * wirelen is the length of the original packet +@@ -84,12 +102,14 @@ enum { + */ + #if defined(SKF_AD_VLAN_TAG_PRESENT) + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data) + #else + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data _U_) + #endif + { + register uint32_t A, X; +@@ -99,13 +119,36 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, + if (pc == 0) + /* + * No filter means accept all. ++ * In this case the value of 'proglen' is irrelevant. + */ + return (u_int)-1; ++ if (proglen < 1 || proglen > BPF_MAXINSNS) ++ return 0; ++ ++ /* ++ * Require the current instruction pointer not to overflow for both the ++ * filter program (where the pointer will be dereferenced) and an ++ * immediately following margin (where it will be not). So long as the ++ * margin is large enough to represent the destination of any single ++ * conditional [forward] jump from within the filter program, a single ++ * guard prevents all filter program over-read attempts that result ++ * from the program running out of instructions before a BPF_RET or a ++ * conditional jump directing the interpreter beyond the program end. ++ * Unconditional jumps mean a larger problem space, which the BPF_JA ++ * case below addresses separately. ++ */ ++ const struct bpf_insn *pcend = pc + proglen; ++ if (pcend + UINT8_MAX < pc) ++ return 0; ++ + A = 0; + X = 0; ++ const struct bpf_insn *pc0 = pc; + --pc; + for (;;) { + ++pc; ++ if (pc >= pcend) ++ return 0; + switch (pc->code) { + + default: +@@ -241,6 +284,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_JMP|BPF_JA: ++ /* ++ * The pointer (pc) decrements and increments in units ++ * of sizeof(struct bpf_insn) == 8 bytes. The number ++ * of units is in the [INT32_MIN, INT32_MAX] interval, ++ * hence the result can point before the beginning or ++ * beyond the end of the filter program and can under- ++ * or overflow; also on 32-bit architectures it can ++ * under- or overflow more than once and can test ++ * negative for underflow, overflow and out-of-range ++ * conditions after under- or overflowing at least ++ * once. ++ * ++ * However, it has been verified above that the program ++ * length is sufficiently small and the pointer does ++ * not wrap within the bounds of the filter program, so ++ * there is a one-to-one correspondence between BPF ++ * program counter values [0, proglen) and all valid ++ * values of the pointer. In other words, after this ++ * unconditional jump the pointer arithmetic result ++ * will be valid iff BPF program counter value will be ++ * valid. For the latter problem the solution is ++ * almost the same as in the validator. ++ * ++ * The main difference is that here the current value ++ * of BPF program counter is not a 32-bit unsigned ++ * variable, but a ptrdiff_t expression, which is ++ * 64-bit signed on 64-bit architectures and 32-bit ++ * signed on 32-bit architectures. However, the cast ++ * to 32-bit unsigned is safe in both cases because: ++ * pc0 <= pc < pc0 + proglen, therefore: ++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX ++ */ ++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -394,10 +471,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + } + + u_int +-pcapint_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, +- u_int buflen) ++pcapint_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p, ++ u_int wirelen, u_int buflen) + { +- return pcapint_filter_with_aux_data(pc, p, wirelen, buflen, NULL); ++ return pcapint_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL); + } + + /* +@@ -417,7 +494,7 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + u_int i, from; + const struct bpf_insn *p; + +- if (len < 1) ++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f) + return 0; + + for (i = 0; i < (u_int)len; ++i) { +@@ -483,33 +560,45 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + case BPF_JMP: + /* + * Check that jumps are within the code block, +- * and that unconditional branches don't go +- * backwards as a result of an overflow. ++ * regardless of the direction. libpcap uses ++ * backward jumps to implement the "protochain" ++ * primitive. All offsets that mean a backward ++ * jump in libpcap (whether in-range or not) in ++ * kernel BPF implementations mean out-of-range ++ * or overflow forward jumps -- kernel ++ * implementations must reject that. ++ * + * Unconditional branches have a 32-bit offset, + * so they could overflow; we check to make + * sure they don't. Conditional branches have + * an 8-bit offset, and the from address is <= +- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS ++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS + * is sufficiently small that adding 255 to it + * won't overflow. + * + * We know that len is <= BPF_MAXINSNS, and we +- * assume that BPF_MAXINSNS is < the maximum size ++ * know that BPF_MAXINSNS is < the maximum value + * of a u_int, so that i + 1 doesn't overflow. +- * +- * For userland, we don't know that the from +- * or len are <= BPF_MAXINSNS, but we know that +- * from <= len, and, except on a 64-bit system, +- * it's unlikely that len, if it truly reflects +- * the size of the program we've been handed, +- * will be anywhere near the maximum size of +- * a u_int. We also don't check for backward +- * branches, as we currently support them in +- * userland for the protochain operation. + */ + from = i + 1; + switch (BPF_OP(p->code)) { + case BPF_JA: ++ /* ++ * So long as both 'from' and bpf_insn.k are ++ * 32-bit unsigned, this check rejects any jump ++ * offset that points outside of the valid BPF ++ * address space of the filter program no ++ * matter whether signed interpretation of the ++ * offset is positive or negative. ++ * ++ * Note that this condition is necessary, but ++ * not sufficient to get correct results from ++ * respective pointer arithmetic in the process ++ * address space. Other necessary conditions ++ * are that BPF_MAXINSNS is correctly defined ++ * and enforced, and that the pointer does not ++ * overflow. ++ */ + if (from + p->k >= (u_int)len) + return 0; + break; +@@ -537,12 +626,14 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + + /* + * Exported because older versions of libpcap exported them. ++ * This function is deprecated and unsafe, use pcap_offline_filter() instead. + */ + u_int + bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, + u_int buflen) + { +- return pcapint_filter(pc, p, wirelen, buflen); ++ // The actual length of the filter program is not known. ++ return pcapint_filter(pc, BPF_MAXINSNS, p, wirelen, buflen); + } + + int +diff --git a/dlpisubs.c b/dlpisubs.c +index d4310de5..19934059 100644 +--- a/dlpisubs.c ++++ b/dlpisubs.c +@@ -203,7 +203,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user, + bufp += caplen; + #endif + ++pd->stat.ps_recv; +- if (pcapint_filter(p->fcode.bf_insns, pk, origlen, caplen)) { ++ if (pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ pk, origlen, caplen)) { + #ifdef HAVE_SYS_BUFMOD_H + pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec; + pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec; +diff --git a/pcap-bpf.c b/pcap-bpf.c +index 49bb273d..13f83930 100644 +--- a/pcap-bpf.c ++++ b/pcap-bpf.c +@@ -1372,7 +1372,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + #endif + */ + if (pb->filtering_in_kernel || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + struct pcap_pkthdr pkthdr; + #ifdef BIOCSTSTAMP + struct bintime bt; +diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c +index 2fc51665..9f464e70 100644 +--- a/pcap-bt-linux.c ++++ b/pcap-bt-linux.c +@@ -396,7 +396,8 @@ DIAG_ON_SIGN_COMPARE + pkth.caplen+=sizeof(pcap_bluetooth_h4_header); + pkth.len = pkth.caplen; + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c +index dfba8051..cfe52498 100644 +--- a/pcap-bt-monitor-linux.c ++++ b/pcap-bt-monitor-linux.c +@@ -153,7 +153,8 @@ DIAG_ON_SIGN_COMPARE + bthdr->opcode = htons(hdr.opcode); + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-dag.c b/pcap-dag.c +index 5ce15dd5..334a970c 100644 +--- a/pcap-dag.c ++++ b/pcap-dag.c +@@ -666,7 +666,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + /* Run the packet filter if there is one. */ +- if ((p->fcode.bf_insns == NULL) || pcapint_filter(p->fcode.bf_insns, dp, packet_len, caplen)) { ++ if ((p->fcode.bf_insns == NULL) || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ dp, packet_len, caplen)) { + + /* convert between timestamp formats */ + register unsigned long long ts; +diff --git a/pcap-dbus.c b/pcap-dbus.c +index d29fb81d..b0f30f6f 100644 +--- a/pcap-dbus.c ++++ b/pcap-dbus.c +@@ -90,7 +90,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char *)raw_msg, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char *)raw_msg); + count++; +diff --git a/pcap-dpdk.c b/pcap-dpdk.c +index c78724e5..4fb8ffea 100644 +--- a/pcap-dpdk.c ++++ b/pcap-dpdk.c +@@ -405,7 +405,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c + + } + if (bp){ +- if (p->fcode.bf_insns==NULL || pcapint_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){ ++ if (p->fcode.bf_insns==NULL || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ bp, pcap_header.len, pcap_header.caplen)){ + cb(cb_arg, &pcap_header, bp); + }else{ + pd->bpf_drop++; +diff --git a/pcap-haiku.c b/pcap-haiku.c +index 609f585a..7b994fee 100644 +--- a/pcap-haiku.c ++++ b/pcap-haiku.c +@@ -112,8 +112,8 @@ pcap_read_haiku(pcap_t* handle, int maxPackets _U_, pcap_handler callback, + if (handle->fcode.bf_insns) { + // NB: pcapint_filter() takes the wire length and the captured + // length, not the snapshot length of the pcap_t handle. +- if (pcapint_filter(handle->fcode.bf_insns, buffer, wireLength, +- captureLength) == 0) ++ if (pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ buffer, wireLength, captureLength) == 0) + goto drop; + } + +diff --git a/pcap-int.h b/pcap-int.h +index ce0ac698..3d466946 100644 +--- a/pcap-int.h ++++ b/pcap-int.h +@@ -579,13 +579,15 @@ struct pcap_bpf_aux_data { + * Filtering routine that takes the auxiliary data as an additional + * argument. + */ +-u_int pcapint_filter_with_aux_data(const struct bpf_insn *, +- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *); ++u_int pcapint_filter_with_aux_data(const struct bpf_insn *, const u_int, ++ const u_char *, const u_int, const u_int, ++ const struct pcap_bpf_aux_data *); + + /* + * Filtering routine that doesn't. + */ +-u_int pcapint_filter(const struct bpf_insn *, const u_char *, u_int, u_int); ++u_int pcapint_filter(const struct bpf_insn *, const u_int, const u_char *, ++ u_int, u_int); + + /* + * Routine to validate a BPF program. +diff --git a/pcap-linux.c b/pcap-linux.c +index 20802e43..7e04a041 100644 +--- a/pcap-linux.c ++++ b/pcap-linux.c +@@ -4279,6 +4279,7 @@ static int pcap_handle_packet_mmap( + aux_data.vlan_tag = tp_vlan_tci & 0x0fff; + + if (pcapint_filter_with_aux_data(handle->fcode.bf_insns, ++ handle->fcode.bf_len, + bp, + tp_len, + snaplen, +diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c +index 344bae47..ade53ea6 100644 +--- a/pcap-netfilter-linux.c ++++ b/pcap-netfilter-linux.c +@@ -257,8 +257,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen)) +- { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ payload, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, payload); + count++; +diff --git a/pcap-netmap.c b/pcap-netmap.c +index f17f36ca..925f677f 100644 +--- a/pcap-netmap.c ++++ b/pcap-netmap.c +@@ -79,7 +79,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf) + const struct bpf_insn *pc = p->fcode.bf_insns; + + ++pn->rx_pkts; +- if (pc == NULL || pcapint_filter(pc, buf, h->len, h->caplen)) ++ if (pc == NULL || ++ pcapint_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen)) + pn->cb(pn->cb_arg, h, buf); + } + +diff --git a/pcap-npf.c b/pcap-npf.c +index f638bd80..38e985bd 100644 +--- a/pcap-npf.c ++++ b/pcap-npf.c +@@ -720,7 +720,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + */ + if (pw->filtering_in_kernel || + p->fcode.bf_insns == NULL || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + #ifdef ENABLE_REMOTE + switch (p->rmt_samp.method) { + +diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c +index fd6d6fa6..5f15d4c5 100644 +--- a/pcap-rdmasniff.c ++++ b/pcap-rdmasniff.c +@@ -170,7 +170,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u + pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + ++priv->packets_recv; + ++count; +diff --git a/pcap-snf.c b/pcap-snf.c +index d08275ac..8a57eadd 100644 +--- a/pcap-snf.c ++++ b/pcap-snf.c +@@ -190,7 +190,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + if ((p->fcode.bf_insns == NULL) || +- pcapint_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ req.pkt_addr, req.length, caplen)) { + hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision); + hdr.caplen = caplen; + hdr.len = req.length; +diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c +index bc39b1db..d219721a 100644 +--- a/pcap-usb-linux.c ++++ b/pcap-usb-linux.c +@@ -733,8 +733,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u + pkth.ts.tv_usec = info.hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, handle->buffer, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ handle->buffer, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, handle->buffer); + return 1; +@@ -921,8 +921,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch + pkth.ts.tv_usec = hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char*) hdr, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char*) hdr, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char*) hdr); + packets++; +diff --git a/pcap.c b/pcap.c +index a076c5fb..6caa052b 100644 +--- a/pcap.c ++++ b/pcap.c +@@ -4349,7 +4349,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h, + const struct bpf_insn *fcode = fp->bf_insns; + + if (fcode != NULL) +- return (pcapint_filter(fcode, pkt, h->len, h->caplen)); ++ return (pcapint_filter(fcode, fp->bf_len, pkt, h->len, h->caplen)); + else + return (0); + } +diff --git a/pcap_offline_filter.3pcap b/pcap_offline_filter.3pcap +index 94b9a719..c6d62dee 100644 +--- a/pcap_offline_filter.3pcap ++++ b/pcap_offline_filter.3pcap +@@ -17,7 +17,7 @@ + .\" WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF + .\" MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. + .\" +-.TH PCAP_OFFLINE_FILTER 3PCAP "7 April 2014" ++.TH PCAP_OFFLINE_FILTER 3PCAP "12 March 2026" + .SH NAME + pcap_offline_filter \- check whether a filter matches a packet + .SH SYNOPSIS +@@ -45,10 +45,35 @@ points to the + structure for the packet, and + .I pkt + points to the data in the packet. ++.PP ++In the ++.B \%bpf_program ++structure the ++.B \%bf_insns ++member is either ++.B NULL ++(which means to reject all packets) or points to an array of one or more ++.B \%struct bpf_insn ++elements, in which case the ++.B \%bf_len ++member must be set to the number of elements (this is what ++.BR \%pcap_compile () ++produces). ++.PP ++The filter program must have been compiled for a link-layer header type ++that matches the packet data; also on Linux the filter must not use ++BPF extensions, see ++.BR \%pcap_compile () ++for more information. + .SH RETURN VALUE + .BR pcap_offline_filter () + returns the return value of the filter program. This will be zero if + the packet doesn't match the filter and non-zero if the packet matches + the filter. ++.SH BACKWARD COMPATIBILITY ++.PP ++In libpcap releases before 1.10.7 this function ignored the provided ++.B \%bf_len ++value. + .SH SEE ALSO + .BR pcap (3PCAP) +diff --git a/savefile.c b/savefile.c +index c711a81c..49ef52b6 100644 +--- a/savefile.c ++++ b/savefile.c +@@ -685,7 +685,8 @@ pcapint_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + * and, if it passes, process it. + */ + if ((fcode = p->fcode.bf_insns) == NULL || +- pcapint_filter(fcode, data, h.len, h.caplen)) { ++ pcapint_filter(fcode, p->fcode.bf_len, ++ data, h.len, h.caplen)) { + (*callback)(user, &h, data); + n++; /* count the packet */ + if (n >= cnt) diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 265c46e3bd..aa5265a54c 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -13,6 +13,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ + file://02-CVE-2026-31912.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97820 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3BC99C88E42 for ; Thu, 10 Sep 2026 05:12:10 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:03 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=MtxAtF1K; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=jgzCoRN9wjN83wQzpnqIHIHvElYHdXs17HpmBkd9uUzKztyHEWuLfgr/Py7dAMAK69MBYxk3tSuRohn5JLXQDjO0fFzYuxdUaTCs2hNBfmIzt1KcBrre3PcI+t73wLEGkJly3vibDeV5J0rpDLZRWrUcXNlRfJT0E5bT8Rya0CyvHMHKd4oJs8qsLmCiw8sZpww4TJvhNwLhwODG4vCLi2AZiGPG8Zp3SgelOawOn7jmZWWcIFA0UBHafYFQLA1jJ3payifwwCKSsczgTdXBpGOD8I0OAVcSsfYtQjbI9wCWAjQvtb2bRIffb/m6k08zxHyze09hyn1yoFyOFbpExg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gaeTFqqh62nh4sstXXyWS1rQfNZQze8tx09vj+MLMyM=; b=WKsgfzibqXq0XlkA6ycgCCsYJ5AyVg1r6U/keGR0qp2yRbPV2U6cEKQEKwm23SyEIsSGPqXtJRz8FHZIwvAFYyyDz9M4bMSqBQOgulm27YRs7NBVZ79gPt9evkjA6Hs8Xfp4Hp6fhXRcMaYzC2NTQxGMMGKX8CwRYvS5ionlqrvJXgX8Q4cPGRIu8e3ywf5BCLWixGzthGRnz2gR0w/pTg6alGGBfmU3L5aJyFKDO2yl7tLvT20EkXDYybPVonMfafSBhDh31WUNUc4kW6H5wsy7150ZBRXicyHUDs/gRIf13+KWjRIeKsCuZ2jt3Y1jH7080l/Dl6YYjbVPhJa9uA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gaeTFqqh62nh4sstXXyWS1rQfNZQze8tx09vj+MLMyM=; b=MtxAtF1KAdOK+tiRuR6Zuy59A0ptvjMHNvj6HC7EIHw+OLtgl48X6eV8vnz8lyqp+DGzzabMl3s5+TfI6Tr8AHlpOUvSdkdXEdUcYro0xvKQ7cjlX8Ehy5YzDX2d7Iax69vsb2vg3Ev6hyDPxnuFNUxODMMwCCh/SHv2uTSJDIkCqFmgBpRMUybM3EIen/GeyJyCAfGLsSjx1MEdtvJH6RxtH8X8uv8d5S+oVf5oJJLD3IZCXYgw8mFwifzEClGeeIoTpoC+8VWqkMf2skypxpPyawLoYqozKqEQJODHVBURgsQqcBQHMIcmM0Uw4/wAVWm2vBeGjHDlYE+Yv84QCQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:11:58 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:11:58 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 3/7] libpcap: Fix CVE-2026-31911 Date: Thu, 10 Sep 2026 07:11:50 +0200 Message-ID: <20260910051154.30595-4-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0067.eurprd01.prod.exchangelabs.com (2603:10a6:10:3c2::6) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: 3bcc02b1-751b-4817-61f9-08df0efa0a33 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: gbwIwh1dD9PnsFzbIUg+ZAruC0PsuH1Nf3hTRTv7ReZCtGTwahA0D4hIwm/LevctQ/XFfumv2Qe6lxySEgjcHNqJ95uJiaObBYfDcE66LyF4tAAV1dodWb89QmjzgGB0p6xRtdeZo4V3gFnAAjQncru0T5MCnnyvcl+RQYSmu9KCVq3MlIBuFOv0OOKbiQHNF58rYdrhHHS0DbzT4EDsVQxiCj+bzyZzELSqdaN4043ek5Vzr2nEgA6nrfE3MLtqjRcdK2t2/HBF2xhQ4L/q0903B0U89yGiulsScbTV3Ue4f451+bK39VY90ymHmnZbibKs7jFRhxvpL5tHNRXKzXEv3dgSEozTkjbgyjFAUkat6wGA+ap+/ne/iW/6f0bpTBoMA1MefZ6mgsuUldBselnf+uFv0EW8r1e9cgSJuhmBZ/lAXg9zKXr34ortabx8sKMmmiSZSlaFk4ycvUVlBADDPrx672sWlK9MgGxnEvwSP7GbzKLiXDNz2+Eow4rW94Fk684hlx7vNrkfWfTsqqGrGeOEeYw5+AYf9gXpRo5i6sJ5iRQEo9TPRvVtM4eYdqJfQUjhOMsu7XK+0gX8uAd/tFOcIxJvIkxqYQuOCoPe5wE8PsAzseYI+UfgM3Tt X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: v/Ctgc4Wlmeum9/HtqLDIXwnarHKel69P9P3gPqczhM95rWep9L8/5CC8UexdjfNGYNxNp+b5RCXm8AmMEEAzUTgAolUovqlyVXWYd5nEBMB62UfwQGTfUbgMyPoA2K04N/6Uwu4gZUjLbEL/W/0NtrQ3cO9OdJCwErKTFonSgEQ55PNL3wZNTWSz/Bk5ncf9LYI05zYn3gi1jvR1UysBsLYTOv7CNZoagJQdhO6Z8Qa11FA6+nm04i/kxEr5vo4K2BCyQQ+T+ZAyzvgAlPlhvZrLyPd0Hw5MrYkJP3c0p+UoxCLpLibx0A3u56iutK/c9lfIoWTrNIF0rH5zpKYoH6O7aqiA2EN0DZ4nRc+OJtx2/3yEc7dVX/nvkLmzX2xLBNZwh5NyrH6lBCYejmBNj3I5UCmgryVb3xULEovdpMaycAqeRjBXD5yKW03L3MhRSfelvGYmpVXE7FG3ypxBATFDeAV4RbGBR77ip6bvaZNykf5VorKmZmXsqZNgiqWJdV2sMPFAYtjyu2W6uD+arplMz2a0/+qWiWxV/p1pAplY2LdY2n6hhdOymdbug1dwAwbMZTvrSzEh2/IwiATo6ENzk+UNN5RQKFjuYOtdzBI9HyQzZuOUqDAO9cpsJI5sXI2MJ+38rYj6X4OgJr4xQS8exeTshwGrVyorWb3Uqf3OGuYc2WlV6IFM1AzPt6excqBLp9YlrP42PQ2pixHcJpO7EbOYSCWuwkibPNtD79QyIlvudrJcnEvbeUbHJNZRUQO6RZ5VJE3EIW2KmNa/VZ8I+/Fl/0Ln0x3t0RXpWiWvkT7ZYDwf44pylFGIAvo7VY5GxNiohPEMLCXacb+cWxD5GTbAtWSd7zsTQimtgiu5naqPW5mjh7SwLf40mnlx84vxmJ15h/QF415UJ2Qeo3n5SH0q5aRGl9Sj6YGDks30nNK4pNeKAPGCMgvi0wORfiOvNkXZ2o3iQOPd9JklTbo0Rv40ibCTqvVkDS0MYgu35be4ebdjvFkMgttKei0oaU8HADYY/S+k3yExfJORRq2g6YnwePoFhUj7p1Rp6xcJAeLS0iztDip8nTftkH5pFCPLaYmXMewnIAE/5h5sebxL0QQss+tfRmSCoITLDSy8WSXiUXTkK1R9rOE8xaU4ykLJreTghiL7CSjesIgcBCtoohNNdx3oB+zAjr0TJfQ0j+0UCPwXo5G3ZPJrFby10OBR1Xjk5tCT8yBR9AD+LTY1wmFhm43mLpwFBzQlHO40EvHNFZEWztmit8k1L26Jo0rcHg3Fg6vWe19QeerJye3pxb4lPT0VQF7AWnl9PeCbeaY1JOHS49ZgBnOCH+vihBjwh3Hq7kpGPdNdUHTzCiL/JjCFm04mAqoEumS2ZnJjLVwYVPqqZSmftYM37AAdrikE3JgeDVkoYPqKwwFj6IA515aKIIH1wansUXiFsxjwjLu3ADwL0PCjjJIyLpAd2rOjkwRUiVnmwVrWKz8oouc5IxLw5P1p3zGzvlt1egEfQBMG74Ps/XJUqKwcxPhU/0tWILSfDtdFis9/VXCaAWb6k65kkimWfesTT04yHGeWuXGGoUhixIVsDvN5qNt9Mb7L2I7sdzBwFuKqlMznISl2xHtCgARMpSicwhytsAS9y+ppeN2MVyt/Bx4FdcmWaLjY5r7L2AISabb0qGKxFIEP2HwpXjJueqrmIjWll1mmcKsYUNkZVjsPsRDMCc14Je2B8M21GJj7THviq5sV9OtOZ/haVv/uQ0CqvJgLZ0UINPnywWDX33K/jnMfZ3aUwbzIMDJ X-MS-Exchange-AntiSpam-MessageData-1: AgUfez+4B07N9C9kevxgnBhDLsgO/r9+3eI= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 3bcc02b1-751b-4817-61f9-08df0efa0a33 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:11:58.6668 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: HVpZuTcd7EU7wyD45knLYj0MsgUlI9sC3QFbve9LCE8BdaCQwoVX91s/yxGEzZVg0cGNO2eoGWBzx1jSguSadDJ2VYoigFcoCBDUpH9UKQ0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245526 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/03-CVE-2026-31911.patch | 57 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 58 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch new file mode 100644 index 0000000000..a0c53f9a09 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch @@ -0,0 +1,57 @@ +From 0067e8fd1f3caf866da3d95508831389f3b20e11 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:08 +0100 +Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + +This vulnerability has been discovered by FuzzAnything Organization. + +The current revision of pcapint_filter_with_aux_data() calls abort() if +the current instruction opcode is invalid, and assumes this never to be +the case. This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +Furthermore, this does not necessarily hold for programs that have been +validated by libpcap because the current revision of the validator has +gaps in the checks and accepts a number of invalid opcodes (another +commit addresses that). + +Thus in pcapint_filter_with_aux_data(), when the instruction opcode is +invalid, just reject the packet. + +(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7) + +(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9] +CVE: CVE-2026-31911 +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 1 + + bpf_filter.c | 2 +- + 2 files changed, 2 insertions(+), 1 deletion(-) +diff --git a/CHANGES b/CHANGES +index ab812dd..f0b5974 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -2,6 +2,7 @@ + Backported security fixes: + CVE-2026-0799: Access M[] safely in the BPF interpreter. + CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). ++ CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/bpf_filter.c b/bpf_filter.c +index 4f9adeea..f8b842d6 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -152,7 +152,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + switch (pc->code) { + + default: +- abort(); ++ return 0; + case BPF_RET|BPF_K: + return (u_int)pc->k; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index aa5265a54c..da218bd87b 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -14,6 +14,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ + file://03-CVE-2026-31911.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97822 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 51D74C88E45 for ; Thu, 10 Sep 2026 05:12:10 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:04 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=KKQSNLTa; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Y1lAGYU54GMWVNZhe5SVC0aB1oKLq5+z5k1l5Jp6bz3N0IHE2NL4MhhIUn9iYDjjPj4al8jJHV5v2+AR5oOy4xnuGtdB3SbIyt4gejIt3HFbe4Pzq4DW2Kug7mY8FHcDrFjP8KqdcEWFfcDUO/bH8xmf+U8FaVj9l2hiKUwf7vA4K92NxMeFALMLoEAfqzjwwsd3kIMMzO5nhQPWkjFmaGfpQd1eAlE1/bxR8efn7DgbUS0mUEO/qtGNph4XrBPwoKFPtZ6kH0wNVlGzU8O6AUUALfkDdQJu8ec2fzUodN4RfKtEEH85YvWhiSjll386XVa3f0b+/baO1dmYMzLkyg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=q1G5IYoJYtWmj/7u8jXjX9QBzitgPk2LvahOvauixL0=; b=GKa52BSfKF7a0Xt6FZLbyREfJfyQZzs5M0na7LYwfJvMBQrLVsul6h1hMiW06iyki2aPYJTJ8JLztBnIdkQSFNX3Z56CQ3dra2vv4B74ztK9he5IL7uYIGv+G7QYnhCyBQpC9wYEnR4ZTc+tWU1Omz2VA8a4tIvTnAhV1OUyq1TxSV2Jl1NGqCP+USCuLSRU4u470BlgQSSAOE0+HIUOo6yTNjpScUoNJnsJYOsjI9bJJmmmjtmNTVUof3bO4+wuBW6PAroyg+6wD60vYSt7m2pq+HKj9lAFtNQKvo3/h80XUZojay6VJNyfM7nP7VAqZCwdu2O9Ed2CjrbdKxdXTA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=q1G5IYoJYtWmj/7u8jXjX9QBzitgPk2LvahOvauixL0=; b=KKQSNLTaLXZkt5EI1MKoUApDtINvzatKE9gokIu2xiMI44DxSc8KGNbcosbXOS5uKsOv50NineZAibwUFec0zVI+PLCLz5f5BUxi77h/48HSU6WmgIAkMD5Q1kuW1T9cydVIizJyUubygjigbTrgwiJc7TCWKbGAoJhSU1t5IaUWvZ26EbQ+qDDYdwrtYJ9dJRQLzXifjtFMyMQoE6UEJg/K3Ny3n2CpwjBLYXQQI5/S165I/oR9vvYwyDOP4dlYU/GEf+BDXyw8NcvaQuE9nUzFLFTqidGea5KhIA/jUTvyW7HwVjzdee81a413bFVceySd1+hAAA1sRmVExjJKOg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:11:59 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:11:59 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 4/7] libpcap: Fix CVE-2026-6244 Date: Thu, 10 Sep 2026 07:11:51 +0200 Message-ID: <20260910051154.30595-5-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0085.eurprd01.prod.exchangelabs.com (2603:10a6:10:46a::17) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: 7f6151bc-5524-4a2f-7051-08df0efa0ad5 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: KuPJULer9EVblmTEs/RENNeL9cLvTR+VtoqIi59C0EIYLoobwkT0vDodZThZgJcc7BZu3UVEBby1Z1mGfn28YpemZPdvjcU40ujaKu8r7h19EmuSN4SBOMWLTV9UmqvgC73ScsyXnUXboG1/8YJJKtcuTkctyoe/5tBOKIKne6tiUxje7DiOjKJgv4Z5QfnyCw99uIQ594jznFy0jAI5a5kM5V8F56cD/0bDawwrn339B/qLxk6LGn76BysZXB2hLhnBPRVXBoH7adRk8YdGbh1NzsYRE6lzw/4t/QoSgpjZgBxaxeExUPr90mTrcB3/9bkeY60u7LuHL7R/UsCxr8PeSaF2C3PTCRq2C5os97+iGIM7Xwekz4FOtJhBYKqENMDNDS2lKdXYpMqwQzOWd9KkJ/PymQZKO+Q3qADSrNYaFDXiJuNw++gYuW7YUc8DY3EsmRPMjDPG0/aNPB/b+LWjq4bcTtqp5oVqDdO7gfFMrQ/xv4dRShZ9gX1+X1u7oQ0S60bUFHp1oJN0i+WqLJJkBqaDIZkRqoDSXdwRu9RDjRF7ioAnmWvcwzgnFuAJAQIAp+emiexIsiOxxG5ECGcodhq7nVptqzaH01YfFc2+9IBZ44T/ItdrQHIaBh6T X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: XVzD0vQZViRPKeko+aZb8aJ+Zl0t3LiQ1Cf+ha5zrLvN4qLxi8FUwaUGbLcIJAD5Tlq6HX3aW9YooNrLSJlZqKA2wSyg5uzIgbuUsuzJmXa0vlU2E+V8M63/WrQkxy1J9aU7AjSrVF5heY6HZqnh2/T3WLyf0xTWLu0asUtR3aMZIshbnz2rOjBuBYtKunpeoohGZ/aZlM0WI4zM4ICsviAWw7ljH2fhMs0yua7L/5VIFD0gfRdEhnd7C+ACdndrAqGQA3ltEaWQuF/R8BeWDXumT145s7xvxBAozyDTQoDabeEF2UEImLVBvieDqBVDeePlLy1naHuKbV2eshzO6cJXvSDKU443Bk8/sqgn+ZoimGTwzBWOnbErZl1ouAoEmNocgXHsNDj0DPGbbQiJp9wLbV/MlJKwr3EEe6vTcnBNI3C8akIBK514wCXLr6AFFLwqwVurVs17U4wbOEoukTzWtXFKqQKBIhXmI2grUKvISIbQOj60bNlNr5OOAoegVMCS5g2fIZts1ClV2I5f2zfU/4kiHBH1z0x7+XldGRl0nVm4C4O8RPYJVZ+dHwMCplvebocUeExWsUtEYjM85pQxo+ATuJRZtEkEaub3Bie2GpIl4UK3JxdANa7rb92QteR+c0a0quMCnBNUbLwoc32MDiWsfYXObG/bsUIIksdIyExbuTqpsxZxs2VYCckEOMeZ5qZUXnz7gOYIOZXdxRyNt7zftWiM+tezgHbGhYqV+olQpgYfqvGq63H8chanpY28XCwCT3K7SZ7JhqiP2prTgZId2LOMny9qjBRUgpPtJHxoorTakVAodU3U4hsPPuU4BE5nGXmW6zSxTLOsuJni4TMI6jYTGUuFhhrLsKb80WdzO02QVQPRJtzgZoCD65DC336cvEWsnTkACstxQ+4nhD6EUuD4apbhWupcu8PaCcNvBeW0mJ1M+LCrNi6RWb44qy6h6cNjgC2oOm4wkO+Ix0RjQNItB+wwmZZAzEmTuLmwStka/a+RWFZM+uUk6VxtAaS0rrJsvkQm9Z5+sQk0sUb4+zqoUz1hwDqLbm35tk1AA8ITHPbLB05cqlQ8AQ91A2h7Jv6sq3qrq9THV8lt2VEzv7TfJJmwMoTwn29Wz4wDhoLV9xX4IYcCm6vzYMsJqHaX+oAJB6ysZQMbR3L9e35ItO/xEurR+a7HQk7hdi+ETiHwbIlmr6AEE8Wxj/VD3TDRKPvh/Xd+8Ufmr1XCFr9XlBJY0sKkdBj3+MQy8zqLz1pWaECRPnZK6ecHpzVncWoxQPeWHSjGMXfmQJQv4arNdvXsIQj5p1PYtBRqTom98mB65GxyHkXcSJkmeQme8TRl5Cx+nsgWqOhu1RlNYqFlBVsT+g/sKRNTtRWCLQNeDFbZ90FPs6xt/CB9eQ+UMULQeYIYn+R7hoToYuXlv3H1N6kfRrdFJLsUfwBhEf8Zs+gpibMLhED0vd04BheZZXEC1702vp9IEYz2nZIY64uOf/pgV+G3GigOVDJ0y7ij25n05RmNQxdcYDS3s8Xon37d/qmaes2cwS36wlSRf0g0TjefksFrObhkmDsyznRhkWuj4qQM4GlcbbrCsvrivD/GdTO6ffT9ODkDlHqjsfmc+rJTY6bvThBv6qxiYkZM0XT+rq+7tKjk14pQFpterUc/rN8Y939cQJpmqU5Sdk7I12kgIi6BRLPdAHYouYtkzQV1nSBTht8WQQ1OvOojtKnjDmDCbngOMdUXbnRavT9Ck0DlZecBeA4OhqLZSLebGPQNGttSmCheRIPn3j6dj4vt X-MS-Exchange-AntiSpam-MessageData-1: mrZz2WPVgMzLoGePEds3gE/0f5MbZvdvDSM= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 7f6151bc-5524-4a2f-7051-08df0efa0ad5 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:11:59.7123 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: rb7kIWpY+u4N2LXvsb3puaNbs5gcljxHC8gobXGBsd7gb4nWV4w9GcIoWZ+HiJ0F13ncV7WGUnBaMuT6i/gKpFgNYV9tsUibbvzBToPwqWc= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245527 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/04-CVE-2026-6244.patch | 62 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 63 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch new file mode 100644 index 0000000000..0ef98e4580 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch @@ -0,0 +1,62 @@ +From e2f4d78f71237c44f730fee11fa0497b756e9d81 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:21 +0100 +Subject: [PATCH] CVE-2026-6244: Avoid division by zero via + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() for "div x" and +"mod x" correctly rejects the packet if X is zero, but for "div #k" and +"mod #k" it assumes that k is never zero. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program, it can attempt a division by zero, which will typically +terminate the process via SIGFPE. + +To fix this problem, in pcapint_filter_with_aux_data() treat "div #k" +and "mod #k" the same way as "div x" and "mod x". + +(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4) + +(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19] +CVE: CVE-2026-6244 +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 1 + + bpf_filter.c | 4 ++++ + 2 files changed, 5 insertions(+) +diff --git a/CHANGES b/CHANGES +index f0b5974..35121e7 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -3,6 +3,7 @@ + CVE-2026-0799: Access M[] safely in the BPF interpreter. + CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). + CVE-2026-31911: Fail opcodes safely in the BPF interpreter. ++ CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/bpf_filter.c b/bpf_filter.c +index f8b842d6..0178aae5 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -420,10 +420,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_ALU|BPF_DIV|BPF_K: ++ if (pc->k == 0) ++ return 0; + A /= pc->k; + continue; + + case BPF_ALU|BPF_MOD|BPF_K: ++ if (pc->k == 0) ++ return 0; + A %= pc->k; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index da218bd87b..258a15f5ba 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -15,6 +15,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ + file://04-CVE-2026-6244.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97821 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 727BFC88E47 for ; Thu, 10 Sep 2026 05:12:10 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=mRwzVMB/; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=J1CyOJSFEagqAtNT6ZLwox8A6WYeNdSTcQJysOTSWpX7T6A+03Zz4auOmEyjiNu0VNoRPWRBfF0JP6ugbNny2Vh79aoukBoLIXjDLIUrngbuZ3YXvNYEy2ugai0g0jn62/axjnjoSSf7bImvYw6wYqtfz4IkjNKRec89aXnumEOhkb1qj42pffk5l8SKzLxtzDkaQ5/Rod6DDzEWhLVoRUQ1VChVbGHhE2rvkWohUnTSyJyWCu/9yP2OH5uKJDLz1snah1a6UblDYeIaBVNISHJcdZOSPo2ZiCT8uX1OfNXgPfDTd5uNj4R0Bhz64WtMe4YH56TRRqsh8u8UCDuisg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=agIvHSP/PtSLKQ+/oqIpDgeBZyyWJwasy3Lj7gQHIYc=; b=dVP17hWRRHufxunGF+9iCSi5tZJhMXV3s0/tGA3m+rhuKd2dQ8hGuF3NJ5uOR9DNEJjnar8E9GuVkcg9b8LKbQS7rgL+fZYGUSgiLqS/Lc5YFl+P1vbqcRG7H4v3zJWbUywbihT7TEotVZZ2JGGskRzUabnHrez+RRi1WxRNEIkk6tUMnNUmHqjxBPowqayKhvwEru4OZTqOSMCUTwkYbeGVvhLxJA6/jxvyx2KIGFDUcrCsBTy4UAONmU8Eq4OKbSMUj/RIyfDYaMS1iW981RvJW0GfXjlSobhuadtMK02DgMWlGxz5lyb+EHRSM1yilpqXNiZRzJbLyU00Yk1sxg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=agIvHSP/PtSLKQ+/oqIpDgeBZyyWJwasy3Lj7gQHIYc=; b=mRwzVMB/ssJn3dLeVP4gKEatN9C5twXDn7nd5mPYv7W17HW3hNVluLW3creFIwp6wIgLKfJTpbTOl89UJ/R/vxQaXQMU69s4T3XLlJQFuXAyUY19q0ktS6y2xviGcVTvIed6bWS0BgZjQcDQK+r70EFyBGr7v/ig98Eb5dYhIDO71pZJmrO+vTzaPKytSkdOOONuycA4lVWqT579KcP62HemYkaZWlHoh1DI76S3/km8O4nRe09KNtKld2IZ4czs752bhQLyTUf4D0A6KVPHkUmLvh0gLPcmiUyROoO0ohsWsWiS56pC3kT7/RE9lnkwlYGjKgr9ntVXRnFyYUavwA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:12:00 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:12:00 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 5/7] libpcap: Fix CVE-2026-6554 Date: Thu, 10 Sep 2026 07:11:52 +0200 Message-ID: <20260910051154.30595-6-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0024.eurprd01.prod.exchangelabs.com (2603:10a6:10:46b::11) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: 80412ebe-968e-4b38-03bd-08df0efa0b5d X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: NUV9eo0hOKb6hQKvmNBeYQuXZDf+dnMVCh7WrvhHjO5XTOqn/KI81yFHZzzc/7soTOLr50qGL7L08nOff+SpNCzJfs0DtMSTqZ63hB398nZkUYk7NrSQM7nvPVpijV3yc6keC7SF/bXzujSrZuf3Qv/Wpl6PVfnvjez9AVMkuAmy6Gw2STJ3eUYJCSKcTHWOHKp9AIZGMpZ0dSiQviZMkDcfDYiPa7jTBJC83OPcTMrOOyfww6AcLi8AK8/tLiSSZv3EfSelCTa8B9tJ9LoTNk/TgCeSbF+0ErUjDn9N1BmBc2QgACI9ni17rHNGeljb/9OSBzHOunAfWfF61vdlE4GNB/H73AoYuyuEeFvPptVNlk/fTSeDU6Y/WLIIwy0TKqGM+4p9Cl0FkgfB2rW2ICu4eHont+O/BmmDZlnTaagDpFeCOAqmaw4xtWC+zbE5tsiu+tFWSneHJXWH5c8ypUGfnIuojgGJUGggj+vdmK1u3tx5CEJMldqKDoNrX1wuIfyBvvnRRVhC/Oe9o2YfKyu5/+Pzj/wRVbL6mcI6Qz1a9+oi9bI2XZsACR7qEN/md1eaGk58m//aJBdyhvbkf2aznde58L1J7BHSMfnnS4Kzb3G3P+JWLvojNJIL1slJ X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: j/H+TtkynzUll9fX3ahdmwGQ04KoGxrSn0tNFpF7VkJQ1oYSfflHezgcCX6Mg33sdnKI2TZHc4/N1HJgKHLsbaqFTBIYN3rWGftsUKR4Fyu95gBLA8pPy7XgdSDS0xsrRBvMfJjMeDhCMjt2+upCrKApSetPtAz3davOPbhPiswLSkrbxYnRQhejEMmlV3tWaiZiILSr75Ehoo/YjTaT8akgneFINTLWqCE364aAVaSv/kZXyt7VnuwR8dT617RV576d6yC7iU3zBnaLDfvsag8S04LCRu7j8sFswM+t0+iIR5RDkfZuE5BIr1AVIswKXcWA2UgQFwSAC8hfCTk9foFvIjUVKS8a0PCc3OQjlhdeR2N6TrnbWuPj29ynuvyKauW6tRtUdvvEw+qFfl3oG1TFHG6ssTwqLjakUrw20Hpv4zB2shA77sv26rcdEXvGqQVOH+D/hTOMJpGye8e7v5G+N6Tx+eOjaUDWtOfnOKiJaOZxL8xdLOwhge2Nde03GZGbI74lNJAtXR4PdiiV1VpDq4tVb5ST3d+2Q6BiGIep732t5rEpJ5ezjagcn7hVlAVxAtjsrUAn2+LGN46+gidbzcn7px4EnxyI3a0axgOT2UBMR5FbkkWhjTou79EnmYckA9s8OyAD1xoX1fcsnxim9hHA5acB+jUUqi6yOH3tcZ1Xo2qp73N2fW+qggU+rRc4Vl13dV2+bJzNwnCat4/rbTWwRnvEfn58q3iyyJ/lblb03MSPx3aW56hKFRjFWlrAccid3jK0WRxcki9Af21SM16AcDOsibLY1med1kjmYR4xN9yDA7XE/PlC443WNo0r0YfxDGkAh6mcVwqFc5PP8U783be49f/GZRWABvbe++DrziGvPIQD/6wqx+UGUQTNoAZSq9H7vXH9ODuts34Pf1ldQExzxrlid7dhX9mOkIJWykN7kvtD8P0ylwKxJs/CP9IE4PkJZxGE35TOQrWJkeGHWZvgMJ8wfMPFWQ8qagqdSKT52V/k6TKA4h7y9pFh0TB6iaG0hTICASANSCtD7ur/OFQ5r+YFTGSUjQ2+7DD8ITfghpU9PsEVCce44uuYlhP/gUgmXVmmyoLXNSmfcjDiN+qo4/JTXm4+2H2QNOPDIamcHrnhJiQ1XvbTaD5JZVqO1gMsmY5boPalbpIWonXxoeFnhdhtzzg1d9LI3VVTbaby4kyqhhPOL8i2zncNeoxrTSSLb29SvUGfsq7wla3t/yQXP+t4NsA/x00i6zBQMn+W4Pp3jAxgcypfYTSStI3TWrcMsubEPlNTq87al7alkvCMJ019/sFKi/8CqGCd8vFIPc05vnmQdk2NgxqPQDd+XPp03c1mivHF3sKDyvunn5YgrpJFz45VuViMDDSlc8tuSeXdGLJG+mQccQAn75AycaNExrir1PNNzsV3YIqZC6iF4LuQby/3ZnrpORiuecLy+SbXvD+0Unuj98fD2scetY1beescRkFAOtgs/3VC0aTn9IKpB4IU0fdnpVq3AKMUEEnnpoC0QcIAVdn+fn3dwEk/dk5evXLdjtJt9XoWbdwP0UM2ZqWj4H9FVWfoUuGeLGQ4tn/UGh63rYdmvTF86b7Whk0VpfSZnigeCafXaOVUpIl9s699cOkZzyNeNqSu9bcX+hlml249C3S+6iYEhcugjcKEzqjtwlePNHvY8Q2Nc+5su8t6UdHehl/YMUgNiwh4J4cvfsGZRXfQtkL8Ntv7xKuCj2NY6CTM5ZH9hdjGGVtHKZmkSR6xSDyPUHx8Bgik0IpF34mmzyafT9IA X-MS-Exchange-AntiSpam-MessageData-1: GGEYrvhmTR6qvUUI+k+XV+d3tJfvAKaoyOU= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 80412ebe-968e-4b38-03bd-08df0efa0b5d X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:12:00.6103 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: xMiCts+OGq2ts37hQCaNHUtSEZ3ku2AYW9j7EcDoopUFoPoRFkBu2ib32kPH1U4znuQ+hH3d7qiPC9knuDMN2SGUiW0/LB/JMPywnVZXTC4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245528 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/05-CVE-2026-6554.patch | 108 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 109 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch new file mode 100644 index 0000000000..720bce3f89 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch @@ -0,0 +1,108 @@ +From ee37e79521d28a04b09f5c37b835ae7955c15e75 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:33 +0100 +Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + +This vulnerability has been discovered by Kaixuan LI. + +The current revision of pcapint_filter_with_aux_data() assumes that any +"ja L" instruction in a filter program does not jump to itself or to a +prior instruction that is guaranteed to reach the same "ja L" again. +This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +If the interpreter executes such a program, upon reaching such an +instruction it will begin looping infinitely. + +To mitigate this problem, in pcapint_filter_with_aux_data() enforce a +hard-coded limit on the number of backward jumps per packet. Ibid., and +in pcapint_validate_filter() as well, reject the only immediately +detectable case of an infinite loop. + +(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0) + +(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce] +CVE: CVE-2026-6554 + +Notes on backporting to 1.10.6: + - The stray BPF_S_ANC_* enum removed upstream in 1.10.7 (commit ff47ba55) is + still present in 1.10.6, so the new MAX_BACKWARD_JUMPS define is added + alongside it instead of replacing it. + +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 1 + + bpf_filter.c | 25 +++++++++++++++++++++++++ + 2 files changed, 26 insertions(+) +diff --git a/CHANGES b/CHANGES +index 35121e7..ff9bac3 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -4,6 +4,7 @@ + CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). + CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). ++ CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/bpf_filter.c b/bpf_filter.c +index 0178aae5..bc6d149f 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,8 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++#define MAX_BACKWARD_JUMPS 64U ++ + /* + * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the + * userland interpreter in libpcap is meant to support much longer filter +@@ -144,6 +146,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + A = 0; + X = 0; + const struct bpf_insn *pc0 = pc; ++ unsigned backward_jumps = 0; + --pc; + for (;;) { + ++pc; +@@ -318,6 +321,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + */ + if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) + return 0; ++ /* ++ * Terminate the program if this is a non-forward jump ++ * and is: ++ * - a guaranteed infinite loop because it jumps to ++ * itself (exactly the same as in the validator), or ++ * - a backward jump after many enough backward jumps ++ * already made for this packet. ++ */ ++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 || ++ backward_jumps++ >= MAX_BACKWARD_JUMPS)) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -605,6 +619,17 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + */ + if (from + p->k >= (u_int)len) + return 0; ++ /* ++ * The only type of infinite loop that can be ++ * detected in this function is a "ja L" that ++ * jumps to itself. For this only k == -1 ++ * needs to be tested because the check above ++ * has already rejected all other values that ++ * would wrap the pointer equivalently on ++ * 32-bit architectures. ++ */ ++ if ((bpf_int32)p->k == -1) ++ return 0; + break; + case BPF_JEQ: + case BPF_JGT: diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 258a15f5ba..6ca75117e1 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -16,6 +16,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ + file://05-CVE-2026-6554.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97818 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C3162C79FB9 for ; Thu, 10 Sep 2026 05:12:08 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:06 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=vpMpv+7D; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=E7O4a6TRwT1SSHBL0wADQHF7HtRkjVtEqMnHBy55coqcYakmW1vVazM9wpzVQxNXlD+mndYFs2VmLdZ377xYG+0wVcm3fsd+Kmw/QnHJijJ+1WTiCCTw8Aw8iVgXeMtJQYRnptYBp7oDpEEEFZKD1M/SxWLDlN1hr/uHm88unBpd+ITHYagoyKYDfGT1ZgPxxQd9izpF/WBAmDLRrSAJXsGkyd40NaHB4PoPUFVjR2RUcA0h2HjQILML53JyxXIMqT8fh431OhjKJve2UmsU7rkrbkAr78M1lyl/cqAE0mn9jhzChuEOiMK9Qjr7HSApLHi5cCD1ZY79L54erF+a+A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=MP1e4XgY9jEJpu0v67fq7maVEuUuQ7iyc6ULTbE4WyI=; b=ZPIth6I0AqsZ/P9QSxgxtZhAQHTtCp4jBGwGN1ULEa4ldj73Bog1guYJRWVRdt3xmtKsQVFAwg3UZuIIybxtf9Pnb25psCZcUlqqGy8L1VvfTidR6cKhq3ZLxH5VJryKOc2uunzm1ZMPSDyPbkrXh9XGo5v3OYs3lvN0XzbZC5cUCEPW2+mZ3wP8WY2JqxXwmyGo6qex4D90MujzTSoPj4sfg0r0ZdDP5JqgyIA+f9TO+pwlT0oRVXnhoBiwJdgHomTSHroHuGjod+pEXMljzvPeTfsT4vYAC72XeJJ4PHkZzNxrkiMUWA/XB77R/LD265cO6x0Fz1x6iembwK8iBg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MP1e4XgY9jEJpu0v67fq7maVEuUuQ7iyc6ULTbE4WyI=; b=vpMpv+7DIs2sPzxA4E3ph93/K/qb5eWO+UFybuQ9QG6mHYiGRE0dmmS+49gavfG/BE/4ASegg5SgNEPzAtlo67VE/isg5/tzF9WVRMejhTwkJisT8ChJ2qELGPnQqfPUIP8+zXKYMpLNH+3Go2ejkkTGsoBe48Q7GNaiQ7PCNXZ6nd3v44bOw6/avoCrpy5s2DKnWuUipCzfBvKryvc3QQlluuc4IZwRmeLnihJGRI1EabMDZM0M5akAmwLe0antQdCLpbPxaZ1CoSd5YhDTYCklJeIir6vCRveuZt5eOXKtvgddJS8nmUkXQ3D3Q/evMVvNiwvdIEoowqRvOMFz5A== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:12:01 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:12:01 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 6/7] libpcap: Fix CVE-2026-18313 Date: Thu, 10 Sep 2026 07:11:53 +0200 Message-ID: <20260910051154.30595-7-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU6P191CA0031.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:53f::10) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: 798c40bf-c7fe-43ec-efcc-08df0efa0bee X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: P9KAWn1H3OD4I1FuGQNt7JYAuKYfJnhshdcgUtl9XR1msjV6Oj5jocrrfkv7Z+Hnl2QUEy6H4Lm00acOARiscv6jF8q1IhTaUga4xH1UEVL6gwxIRoo8/jFODZZluJ08u/enyn8SitwgohpHPhu18gfpPNMdF9581WqvGyylqiqQTbEht8rx9/RHyRskmfApwfvUjEcU1yyExpHw9dCGZOpdg172vYFllmU6jDi7RjcKMqMzoXFZhlcl4VZw54BcTN3U2qtCaFob+bz6eZ+ZuXkjrOBQKYdC/E2cg2BZ7fFPHCe37QCUWfI48fCjbTVHi1cigepd1rolY+yaZT4LL6BfdEupE+z06gEZqogeNmllsMHKXbrfReEatwDvDlDHM6W8X2AXgZt1KULgjlDFJFu1m4SgYq7JuSdgT4/jP1IIJaGg3+aJhMgMvatUAplIxvqDb1jagDqrNYPpNLf+vBsBzhxQlrCYjLxeoVydlh77oV8fYg3AZ5exa/CtQJAEBXN33SjIU7qdMs8Ln2fxTqvcXQ56StWZEQH21vLPW2WwvG6B9Z/Kx5JlwyYGEAYxhDeF9gMHC0pus5Z3f61/+clgj6Blh2/K5bAAnLC/AxhzcIP8YC6W5On7yTOIFlxe X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: gVdoUhKC7k0RvdjswsD4AkHKSGMct/Fhj9EmGxmBedmldQYlckew/NG5QJeusdh10bTSersq0kBmZ19YGjgujjaUYm/Lzn+k1LemBTqalOsRAV68jJlESJ6iY5CmX7Izzkj5NGLtiLqiKpI5uQ4JYWrdxmlx33/mER+81J28d2TAoxC+Sg6t5epCICMO5F9EwBX0ggI4chWtT2kiDPTPh3T5MQM8eJ2gsEzqpB/fqpsO9fPx/QVMvI+YK0VWzbaCOoSNsD8PM6L/ka74ECww7AdU7tDBPZPAGoY1QR3cUbUDSjBa/JKtRpx5VBp4o4uOXr9jvgjCdAX80bhz/azkZPpCJDXcixnCwcrspqsv5JWab/2H4WQVraewLhq0b36zKjvMo8V9W6XXmPqQ8SrpX0DiQhCzHZAt8e2QOaOIa9YZrVh+lhjwFq4Vx0a3q2/rwwFsO8k2ng8si8ooYotAxoN4ePqG+bvJrusjt/0WbBQ/5UBFr+rpZvws+GNhgmVVCUTGEooK5xaOsnkbH0A/OJdqK+QTUY+/RdaWZd+jcNKI16VdYp+u95WY/eW5aAaMbaGYFPd6u62wcfJ2Tj30cPtMcwu/lA93xy4mO1RCSDaplaht5Y0mrDhAFuKMWUYlLpHDPkX6RJzf17a5C9d3KSIrjpmtotBM5jSKJzj+6HWxF+hkSYeb5Md0iLTvSdqx7LwKAG6cGuPi+ka6pxP7ABIzYGKwFqvHKfMRVRX5aI6YiLOOoe8A7LsFZHF1BaUyne9qXz4Oka5JQAE8EhjO4/C01IwoSaIH9rKVCVfzHWHcg3OLzNxVZpXoYcHKDLwlQO2eYD7maLBk6L6i0RsLR8YplitUkpKIzzPsJyJ/G5AkNdKF4JL6J/X+cSCYE5YyF0XoLoqr7SkPeuo+j5TtuNYzAzvnfwbWhP0aHoprwgmjDQHrjyRJopZmy3q9FOEW6013X+pu0zDMfoN/SjV/T6O/F9lMrtB4A8t/QAj7FQuSTdqhE1YddW9iYKZ0H9+ge80JQzWNh4URVwzsGxw3/cZOr9ob50102aXjBmyDrYa8b5rB5iCt5vk36mgGvjY7VUG8E3Zgwn4jnSTMw0btuot3jS6RXmHv7jvIVrUIfL00J6fIvzDhhoh05Acx62gIXAoRjIQX7GIkidQVleHl0VhcinCgHRROeMSZZtsOrp/qUJcRYZKesF6hIlpvBdXkgpWrPD09rx1pYZtbwIX5DnOpSjxlQrLDXA+LZUWpycJUlSToBKb5JvEzq77xBwx/wjjxjeNWxcolsQwzDr7XLImewfGusVk6xkEX7Yg1AjZ6/45/OckiUIhQArCwFoO4CjdaanJP/KTOJUiwHC7Dmq1Ir3g+kLlUeM1iw9zj0lT8R8xzBu0D2xeFXDp4OGRuT1AquMqlKMDEYlKV+7T8zwxnGVjK0Z0ggABMyFw7rkJVRC2CNdg7GgtB3JKlHRUW2GdJj4Hb9u5it1Ux9p50B9VL1fFRMVAqk6Z6/XK3KxE/JER9a6555S0cXRXWW2WS9M9o0cYuvL2VafeVu31jz2AXPbJczpupNZY0X+DgWZQxDvRS+e4gr08HmE3iF/JrnYelinvJzX9eMGyTsb3IvCp+JeNagEROkuln7RAzS/a6VrUdFsUNPhfKHvtULu0RkRSs2jfbARxij7Hd0pnphi8IZ38Q2Otub/chS+YUXa5WVm7l2T2t9BUQeyslJJ7jGJXYJ31hildNvtsSp88OQqk9kaOJ71Ddbw7ytgHwGkfuPdgddu64WtFFQLV/Ou8gGbxPUQ2F X-MS-Exchange-AntiSpam-MessageData-1: 9/BtyXdnN4283+uVIDGhYyPXCwtMXsCyhKA= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 798c40bf-c7fe-43ec-efcc-08df0efa0bee X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:12:01.5571 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: rvWIcRBFFupQIBZf8oODdblwmFz68e55JpkIiU48xPuL5yAvWP4r/p3AiqHQ5Xn3+ow5tRCS3NzqNeU/y4bbUb3586RuFNYUFIBaEES2rVI= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245529 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/06-CVE-2026-18313.patch | 104 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 105 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch new file mode 100644 index 0000000000..7e6868898a --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch @@ -0,0 +1,104 @@ +From b039b8b66616852673c21ec5c7e0bad3190eae59 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 1 Aug 2026 18:24:48 +0100 +Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd. + +This vulnerability was originally reported publicly, hence no credit is +given. + +daemon_unpackapplyfilter() can allocate a temporary buffer for up to +RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each +received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message. +It never frees the memory, so repeated messages from a client will +eventually leak enough memory on the server to cause problems. This +holds for all connections that pass the validation and some connections +that do not. + +48 bytes in 1 blocks are definitely lost in loss record 2 of 2 + at 0x4844818: malloc (vg_replace_malloc.c:446) + by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372) + by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139) + by 0x114808: daemon_serviceloop (daemon.c:901) + by 0x115BC7: accept_connection (rpcapd.c:1321) + by 0x115BC7: accept_connections (rpcapd.c:1118) + by 0x115BC7: main_startup (rpcapd.c:709) + by 0x1112BD: main (rpcapd.c:567) + +To fix this, after a successful malloc() return exactly once, after the +free() call. + +(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b) + +(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7] +CVE: CVE-2026-18313 + +Notes on backporting to 1.10.6: + - The upstream commit was made after the "bogus instructions" -> "invalid + instructions" message change (commit 836d0fd0), which is not backported. + The 1.10.6 wording ("The filter contains bogus instructions") is therefore + kept; only the memory-leak fix (goto free_and_return_status / free()) is + applied. + +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 2 ++ + rpcapd/daemon.c | 19 ++++++++----------- + 2 files changed, 10 insertions(+), 11 deletions(-) +diff --git a/CHANGES b/CHANGES +index ff9bac3..4f24f94 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -5,6 +5,7 @@ + CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). + CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). ++ CVE-2026-18313: Fix a memory leak in rpcapd. + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c +index 87274665..b720cc45 100644 +--- a/rpcapd/daemon.c ++++ b/rpcapd/daemon.c +@@ -2380,14 +2380,8 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + { + status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn, + sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf); +- if (status == -1) +- { +- return -1; +- } +- if (status == -2) +- { +- return -2; +- } ++ if (status == -1 || status == -2) ++ goto free_and_return_status; + + bf_insn->code = ntohs(insn.code); + bf_insn->jf = insn.jf; +@@ -2403,16 +2397,19 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions"); +- return -2; ++ status = -2; ++ goto free_and_return_status; + } + + if (pcap_setfilter(session->fp, &bf_prog)) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp)); +- return -2; ++ status = -2; + } + +- return 0; ++free_and_return_status: ++ free(bf_prog.bf_insns); ++ return status; + } + + static int diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 6ca75117e1..859897acc5 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ + file://06-CVE-2026-18313.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 10 05:11:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 97824 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A61DAC79FB7 for ; Thu, 10 Sep 2026 05:12:10 +0000 (UTC) Received: from OSPPR02CU001.outbound.protection.outlook.com (OSPPR02CU001.outbound.protection.outlook.com [40.107.159.68]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6892.1789017120475080008 for ; Wed, 09 Sep 2026 22:12:07 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=C1ntu8QO; spf=pass (domain: est.tech, ip: 40.107.159.68, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Xz76o53yLBmHIF4sXOT0YYsX3Doxjnux8LOA9Ki8uFKLsGcs1tzPEYi5qdGQ+1FPfGVBsbMbUxcoOLtAevP183FvIyCKprYd6XhjuL4Q4VF2Zc5DwcAWcJjN2el5gS6tMlTqFyKzacVAjiZujbrlcJ/ooxcy7eGIw1ntSdo1S9TWifCVvPEok4htc6Iiibeu1L2r9pAFZWzu6vGN4FNSmSZ6gmK4DoYZjkTf5heqXxcWUQmVzpqYsfpkpuwjtJy7++eeHXQNtmK3Y0bWYR1ZKoTnxooLny6sKfY9X2rFupOUR+WMIJNmOQc5R3WLu5Z3rbgrKeVou43ozPWU1Gl6MA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=b8MJFvtEs4JbU5xgG3WfCaTyzRSUf5UxPxicW7X+kpc=; b=GWKz+cvVVa4rInPnXTlPln7EQDMNwwc75lLotBGax78h0T6BZG7O4qE9sY3pO5gy+w2Av1Kskm/QIMHdEv9CCxN/HVJJZHxYeUOy5/Eghja0DGJr0YqirY/BqzPYDfs4X5mAm+W6L0DIU1zrV7m26XaK+OhhKKiNI8zkCZIJVPFFFV1Fu42caZXBWKyv9HNOp5cOYY3C0lX815WYhFeNKlqZ6Qq1mhs0mu6qc972zKIQJHHzzoGkb5DynrvlsSHbX4TLqT3SlR4eZ4sYllb2cRsiCt71V0QY7Hy6azf/DVyym0EJkFGZzBlEU/wtboh4DdHOGau5o/B2vjnSoFo1qg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b8MJFvtEs4JbU5xgG3WfCaTyzRSUf5UxPxicW7X+kpc=; b=C1ntu8QOKjSuRG0C+a9oiTaST2hltVziiGX4RdDDW3mi6rSIBZmnqnvmMQ+eb5yl8YVrEgqOq0UEcTa55+4WFzXjKFLUq6OFPpmjwLveMnZ8PHzf6jkZL5FuOeEYbnyaDpvcIQ3aWjrWy201sv6U1V7fXd97PG/ZuUmbP1V6qYWHN2j6NWq+t6PYrvPI/Jb7BUyT9Umeqa+SNbbBeETsv2tz2xRWqsyoDbIjrgnVfKpFEX9Zi4ZEYvaHI7QMfU3sqvPlwMf4rUiY7BufWBZHgVGiwXvjEywbaDdpOIw4fitPs8FjS6tr+swATYPvXkHC0YHgNKAsjfxIN50R9DAdsQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AS4P189MB2085.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:514::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.9; Thu, 10 Sep 2026 05:12:02 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.005; Thu, 10 Sep 2026 05:12:02 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH 7/7] libpcap: Fix CVE-2026-18238 Date: Thu, 10 Sep 2026 07:11:54 +0200 Message-ID: <20260910051154.30595-8-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0304.eurprd04.prod.outlook.com (2603:10a6:10:2b5::9) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AS4P189MB2085:EE_ X-MS-Office365-Filtering-Correlation-Id: 430ae3ad-d56d-49c4-275a-08df0efa0c7f X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|10070799003|1800799024|23010399003|376014|10067099003|6133799003|3023799007|22082099003|18002099003|12006099003|56012099006|5023799004|11063799006|13003099007; X-Microsoft-Antispam-Message-Info: l9v9cgLTASORfMOLCSZxqrjFHbOQD/559BL8ZwEKLvMtt9dCuijkndPlqjn/AH8Wo4ojdu+/mBV73eemrBbM07LTNqMneNKAVm66oEmmcZ6IZQcJB6G88tqHCTb1fCNeKCzvGMfLkZN2HcCRf4apZCw1NM9HEA0NcdXuqq+pxDKRQHXEgqx7i+OS9fEL5WT+ADL9FR4gpEKQ34vRUVHOkc2bQXb1ItpImktOsEjM92CX163PRDd4w56Fsdwhg13XKrmXUgalXRle//KJqFH8nOzwjz7j5UGrd/dUGOxsyBBkT5ea9JtwcEhYvjyepzbhJQE9BTfBDV8VXSfVJfZB65s5088BIWRjslCnaLlULccFzV7I6zObxM9ekwCSbziqUw/5Bn3p1FL53kvyqOKF3g2stGqURV2jvhO9Mo5qCtV3KwM+kDsuA556INRR4bRJ83II4bpFaybBteudMTyiHLz+elBkj93pNS3bXIAAL4eiSe7C7h+XdfLrErcbCSZ/0EZZt36CMMiARFnD07AA3oFOzuOoh2S5jCueMRs5hD8WWxgIExKtJ3mgNFasL2gsNswwaxdrKioOtB9OaTCMC/8AREtTUd0otdBrSwNtgWk= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(10070799003)(1800799024)(23010399003)(376014)(10067099003)(6133799003)(3023799007)(22082099003)(18002099003)(12006099003)(56012099006)(5023799004)(11063799006)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2 X-MS-Exchange-AntiSpam-MessageData-0: Xx/5YEOf9xF/VXT5PQl3aheP5VEsPcgAPcFFzh9M9x00x+tFnVBDz6eJdy8nW6im3nRfFy6zJuluUjnO5Zlt+wAI/Vu7n+tz5/reIAgfT2Pov4dFJHJ3nja3I5Q4MECqxP3mZ/OfzUSjYLRzq4X9r94Nxp7pTJXRpGSDMqGV1hbi6B03VEg6wevwYGJcZLhA4GVLNs4Y/8MoQM1L0HX9DQtmLuksUpvjFqPWLKPhgFyjugww8rAgW3JRNuE7Y0OjjTxOzbTfHfDoh5F5awKTrwelh4MSgkO3G+JhOfZo2sMs+1HqsohOoGzeiSybOW1Rc53Mdo+O9VfDvSsXoLEmRb+VU7ON9GwG+gbvR20VXL0Ya4WKv8Pp7W2sMC3ejYAW73z4+Nk1eXpU9c9TE5takm6yRwUzIE8k70WEN9SwsgGwTwtMNgynlX8kppEb4CIbYKXNG4tlzT7F9xUUuTLxCr0NCt7iyi7jdvVGgH6vf3YqqYhmJs5VwQWlb23FbUNkz7d6CpYoGTckL3ZmJAvw5gut7cMLYWazXoC/CSEIpZyRHkiomxuPwSLLVUjW6U4GPgrPusKifXxkMXcDxKjbPUI8JFc0iNRphx2u8QdDOfWc2nHWN3uhMKD0vm8KaXgRgfzJ7Icb6apH4ecAJmH/NvB4nnT7GsVH0Mpvn3GsWcs8zCOfHPXbte7WPz6GpyFLDMehuohE1Q06oraehpxWok89HlVSIkNV3+kIJ+WNLHhzpuv42E7BqELAs9KzitojE/LsxhQA1/3GZHUyURSLKI5J09AdtU+Pt2PJvM1zhOMKjXWMmr9ZCPEvKAVzUmQOUW9sKyb1wKec6KU+fIwqPHFIq7WJ9DCc+PXrIBXgjUuGarq2KK5AAt+1etplG9yA71t1u4HojjgZr0iasqWZ9uKH1odEeoz3SKtGz/Q8slkfAnUO/fqdWIxu0qRvBApE5g/+B0jYolYCINZxx0UefC6iGAruXkabSXnbFb38iVnLeInbQFz9+dmyhZpwcbUJFQuUHiP0UiVM4xwGn92abGV8vNDWVuRfTz0CyxioxqD8PZW2YVH8eSamC4ukGR8h8w5uUgPvgkbL/0o6xDWmOnrd/Z3WqRzQyaQTdR/mmOzP6uOM3GvwlXx1fOqNfbIcDhNof7XpqedUcYwLd+VRtia/IqwMSL8LEXtSMFcT/jX6JqmkXQspyFm89mDdG+J8hnptgHdNLBYs9LKHY4JC8uQh6LEq3QYAbk3BP6gFFEt+mlMfSznfNXP73iYJcLMDAI66YTPznA72MFaTT/OyPxi4kuHn8pwqnv7pqRP3HkzugSYHxk9uX1drCc3KbYy82+bTx4IVjz5sgesz8s5WivYqEXjYcpwhDJq9ucz6+KoTAFVTpVfdN6AqYrjnvoaepMOzySjmqEa1JYEgXZCep9Of39hXjfz33Tw5RdWuImEmwwq4N0O1JhB9BIiZkg3lz2wgWR/ocdDSoYeCacmn7pci3dp8VTr1oM4z2wNzSik4yOReL8wTu9/yp6b4EwmflwWNErhiV9OhPPNYxEFn0AXNwXwZDiWNmcdQ1YQA9vyvgi2P0OK5rAOd0HhN3LleeUZ5W2UhVEp7TVcnsYTjm5tkzFZJgCA3rul3tfFKfwtsNhC5UP2smxftatYhw3IKzuFSsPHUbyw8G4IK7TN99Muraml2KyZgZBJFQ5bjdKCE5gZmgTcfa5RmbZdwS7lr1oRnpVSzKnkiN4+bZ4cFfV1sEelLtCUM3yPx8sl4PnRcu60vHCbRwuac+DaeLsmESoV9i+hH X-MS-Exchange-AntiSpam-MessageData-1: nD1tQuVBUle+9qWOUhMj6rtHt2HCn5q90/c= X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 430ae3ad-d56d-49c4-275a-08df0efa0c7f X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Sep 2026 05:12:02.5259 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: yYAUTwlGtccDFd223q9FNtcjG2j2KSDplD9kFZ8sJGflp9fhincswQ950eA01qjH9KRlKTKBaPV6KUBetn1bNoLpn39KWYSpz61sWkNxwA4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4P189MB2085 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 05:12:10 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245530 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/07-CVE-2026-18238.patch | 234 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 235 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch new file mode 100644 index 0000000000..373e64b1ff --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch @@ -0,0 +1,234 @@ +From 5aa9cfee8eb44967dec96199fde879022e4426d4 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 8 Aug 2026 00:31:10 +0100 +Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + +This vulnerability was originally reported publicly, hence no credit is +given. + +When pcap_read_nocb_remote() validates a received message, it does not +verify that there is a complete RPCAP_MSG_PACKET header in the rpcap +general payload, also it uses an incorrect value to validate the length +declared in the RPCAP_MSG_PACKET header. The latter can lead the +protocol client to over-read the message buffer by 20 bytes, which in at +least one scenario can cause a SIGSEGV. + +Fix this problem, as well as a potential integer overflow in the UDP +code path on 32-bit architectures. To make message encoding and +validation easier to follow, re-jig a few variables and update comments. + +(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9) + +(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473] +CVE: CVE-2026-18238 +Signed-off-by: Jaipaul Cheernam +--- + CHANGES | 1 + + pcap-rpcap.c | 117 ++++++++++++++++++++++++++++++++++++--------------- + 2 files changed, 85 insertions(+), 33 deletions(-) +diff --git a/CHANGES b/CHANGES +index 4f24f94..8e29fd7 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -6,6 +6,7 @@ + CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). + CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + CVE-2026-18313: Fix a memory leak in rpcapd. ++ CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + + Tuesday, December 30, 2025 / The Tcpdump Group + Summary for 1.10.6 libpcap release +diff --git a/pcap-rpcap.c b/pcap-rpcap.c +index 8f8960b9..b7f54641 100644 +--- a/pcap-rpcap.c ++++ b/pcap-rpcap.c +@@ -389,10 +389,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr **sockaddrout + static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data) + { + struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */ +- struct rpcap_header *header; /* general header according to the RPCAP format */ +- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */ ++ struct rpcap_header *gen_header; /* rpcap general header */ ++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */ + u_char *net_pkt_data; /* packet data from the message */ +- uint32 plen; + int retval = 0; /* generic return value */ + int msglen; + +@@ -449,13 +448,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + + /* +- * We have to define 'header' as a pointer to a larger buffer, +- * because in case of UDP we have to read all the message within a single call ++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large ++ * enough to contain all of the following data at once: ++ * ++ * - a fixed-size rpcap general header ++ * - a fixed-size RPCAP_MSG_PACKET header ++ * - p->snapshot worth of bytes of a captured packet ++ * ++ * This is sufficient for all code paths below. + */ +- header = (struct rpcap_header *) p->buffer; ++ gen_header = (struct rpcap_header *)p->buffer; + net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header)); + net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr); + ++ /* ++ * Step 1: to receive a message that does not immediately look ++ * malformed, consider it as a fixed-size rpcap general header followed ++ * by a variable-size rpcap general payload and require: ++ * ++ * - a complete rpcap general header to land in the buffer, and ++ * - the header to declare an rpcap general payload length that fits ++ * in the buffer after the header, and ++ * - the complete declared payload to land in the buffer after the ++ * header. ++ * ++ * Since this step loosely corresponds to rpcap_process_msg_header(), ++ * which among other things converts rpcap_header.plen to host byte ++ * order, mimic that as well to produce a valid argument for ++ * rpcap_check_msg_ver() later on. ++ */ + if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) + { + /* Read the entire message from the network */ +@@ -471,6 +492,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + /* Interrupted receive. */ + return 0; + } ++ ++ // Require a complete rpcap general header to be present. + if ((size_t)msglen < sizeof(struct rpcap_header)) + { + /* +@@ -480,8 +503,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + "UDP packet message is shorter than an rpcap header"); + return -1; + } +- plen = ntohl(header->plen); +- if ((size_t)msglen < sizeof(struct rpcap_header) + plen) ++ gen_header->plen = ntohl(gen_header->plen); ++ ++ /* ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX ++ */ ++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header)) + { + /* + * Message is shorter than the header claims it +@@ -496,6 +529,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + { + int status; + ++ // Receive a complete rpcap general header from the network. + if ((size_t)p->cc < sizeof(struct rpcap_header)) + { + /* +@@ -515,27 +549,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + } + } ++ gen_header->plen = ntohl(gen_header->plen); + + /* +- * We have the header, so we know how long the +- * message payload is. The size we should get +- * is the size of the packet header plus the +- * size of the payload. ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) < p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX + */ +- plen = ntohl(header->plen); +- if (plen > p->bufsize - sizeof(struct rpcap_header)) ++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header)) + { + /* + * This is bigger than the largest +- * record we'd expect. (We do it by +- * subtracting in order to avoid an +- * overflow.) ++ * record we'd expect. + */ + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Server sent us a message larger than the largest expected packet message"); + return -1; + } +- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen); ++ ++ /* ++ * Receive the declared rpcap general payload from the network. ++ * ++ * p->cc == sizeof(struct rpcap_header) ++ * p->bp == p->buffer + sizeof(struct rpcap_header) ++ */ ++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen); + if (status == -1) + { + /* Network error. */ +@@ -558,27 +600,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + + /* + * We have the entire message. +- */ +- header->plen = plen; +- +- /* +- * Did the server specify the version we negotiated? ++ * Step 2: to validate the received message further, require: ++ * ++ * - the rpcap general header to have the correct version and type, and ++ * - the rpcap general payload to be large enough to contain at least a ++ * complete RPCAP_MSG_PACKET header, and ++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload ++ * (i.e. the captured packet) length that fits in the rpcap general ++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header. + */ + if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version, +- header, p->errbuf) == -1) +- { ++ gen_header, p->errbuf) == -1) ++ return 0; /* Return 'no packets received' */ ++ if (gen_header->type != RPCAP_MSG_PACKET) + return 0; /* Return 'no packets received' */ ++ if (gen_header->plen < sizeof(struct rpcap_pkthdr)) ++ { ++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE, ++ "Received an incomplete RPCAP_MSG_PACKET header."); ++ return -1; + } +- + /* +- * Is this a RPCAP_MSG_PACKET message? ++ * Validate the RPCAP_MSG_PACKET payload length declared in the ++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX ++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen ++ * gen_header->plen is significantly less than UINT32_MAX + */ +- if (header->type != RPCAP_MSG_PACKET) +- { +- return 0; /* Return 'no packets received' */ +- } +- +- if (ntohl(net_pkt_header->caplen) > plen) ++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr)) + { + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Packet's captured data goes past the end of the received packet message."); diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 859897acc5..2844f4b2a9 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ file://06-CVE-2026-18313.patch \ + file://07-CVE-2026-18238.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"