From patchwork Thu Sep 10 20:03:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97883 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0DB48C79FBF for ; Thu, 10 Sep 2026 20:05:59 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.24014.1789070750015842476 for ; Thu, 10 Sep 2026 13:05:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=bq/V6l34; spf=pass (domain: mvista.com, ip: 74.125.228.12, mailfrom: sdoshi@mvista.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc4bdf8abaaso236179a12.2 for ; Thu, 10 Sep 2026 13:05:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070749; x=1789675549; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=kK0aJWD41sZfcYiU515zYMlHpD6G+UY/n1zrL6w826s=; b=bq/V6l347LrZePo/g5znGBz0SdmxTEx/36nRk76esWpR2y2l3kNuqs3Tld5EnmMV1C r5vQ6W4bVgqw8nPBW/7Q7WCyYNMClvIjWWEgIKStBKHhRJ2esGDozptMZ4s7Ig8RlsW3 Q+qkp/3XCqE0wyCpCWYV3XltNdbKYGKkNZtUI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070749; x=1789675549; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=kK0aJWD41sZfcYiU515zYMlHpD6G+UY/n1zrL6w826s=; b=DmTo9nGfQGO1gIwy4ZISPmhCIwGUozNfxuOSoS/h+ZgePj5c7OvxMVbP9vkJ42B0mc qr+lfJcY9SV8mzZiso88fGGWH72sqa15HPK8/qfGF7UOxbXBT7bNMBA13gd+W+wpwrvB rtIorM4n0XLUVQFFcOVcixyBo+uoIFM3KjwgJGxo4hgaoS1H5Q+Cc/ifCQPmtn9GfHrz 1swrVDA9eQbGI0ugv1U+qnS7zySl1QOYemxXtaMRW32A0/jIXbsSAUDAbbEcRgUYTr5C ZaAkDq8BoplplDItRguWhfpmqIU94wfJ72GlArtTlJF+QYbK8Ozp9F3f4s+hc2Bofq8X t++A== X-Gm-Message-State: AFuF++lGhgu7oYlPpfe8qf7yBz4gtlq+fzNdGEGDfcmismuoLrmW1S7q wZUyPrFuxNiiQ9jwDBRfWFWQ6RIvea3uLpsM2UAFXRmzwa5KGJ5kvcqvGHHHtnvgDEqbbRMc8NJ +a0W/ X-Gm-Gg: AYBFou2ZUFZGQNkqGTXUEVIxPA2oyxN7S5FnN7Ua1zn59bSupkcIak+c86+5vwlhS/H aMF2Y6IyOPgaKNkHNzvTIHJsxxVMUb+XMRpmW92NdSlG57e7OeWJyeFjhEKpW+9JaOGqLbdnhmu enFzxF4PhpoYq36Aj6/0lKYyvH9JYi6tDlmgFBJpyWkHNLqT6aVqvW49hgAJRTRYmhu2KrK61iB eZFg4lmBw7W+wps/bFCki3L01Du/OpJ4SgJYQMbCuxwdOw/+cZCRgLwRad06Ve59KEKtju7fkDa WURvclpn/oNh6FNtRAvKXGJSiv3YoqN1C3jHgyeg53XV9nn+nnSh8dbhKnC1HmXIklqXIg5Zs3Y smy1yUqyRkP4N6l8NqC6b+8ONpOBK44rJw63U6Eiq/nytjCX1EcVF0n9p/l73CSfLOrHGOMpylm c5LzVaJmtk/DfjGbMdZf09jNWIokrrjJ3IBlXpr4MVf3vl/jwCWWVV/a75Bw/2k57/t+yj++DCE OXv6J+A9A== X-Received: by 2002:a05:6a20:1604:b0:3bf:5b7a:fc8b with SMTP id adf61e73a8af0-3daecac7fc7mr1077456637.0.1789070749097; Thu, 10 Sep 2026 13:05:49 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:05:48 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 1/6] libxml2: Security Fix for CVE-2026-86137 Date: Fri, 11 Sep 2026 01:33:24 +0530 Message-Id: <20260910200329.842463-1-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:05:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245593 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-86137 [2] https://security-tracker.debian.org/tracker/CVE-2026-86137 Signed-off-by: Siddharth Doshi --- .../libxml/libxml2/CVE-2026-86137.patch | 48 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 49 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch new file mode 100644 index 0000000000..e8ccd93142 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch @@ -0,0 +1,48 @@ +From 76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 Mon Sep 17 00:00:00 2001 +From: Hieu Le Minh +Date: Sat, 18 Apr 2026 21:18:24 +0700 +Subject: [PATCH] xmlregexp: Prevent out-of-bounds read in NXT macro + +Fixes: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1099 + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2] +CVE: CVE-2026-86137 +Signed-off-by: Siddharth Doshi +--- + xmlregexp.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +diff --git a/xmlregexp.c b/xmlregexp.c +index f434a0c..5e15311 100644 +--- a/xmlregexp.c ++++ b/xmlregexp.c +@@ -56,7 +56,9 @@ + xmlRegexpErrCompile(ctxt, str); + #define NEXT ctxt->cur++ + #define CUR (*(ctxt->cur)) +-#define NXT(index) (ctxt->cur[index]) ++#define NXT(index) \ ++ (((size_t)(ctxt->cur + index - ctxt->string) < ctxt->len) \ ++ ? ctxt->cur[index] : 0) + + #define NEXTL(l) ctxt->cur += l; + #define XML_REG_STRING_SEPARATOR '|' +@@ -245,6 +247,7 @@ typedef xmlRegParserCtxt *xmlRegParserCtxtPtr; + struct _xmlAutomata { + xmlChar *string; + xmlChar *cur; ++ size_t len; + + int error; + int neg; +@@ -700,6 +703,7 @@ xmlRegNewParserCtxt(const xmlChar *string) { + memset(ret, 0, sizeof(xmlRegParserCtxt)); + if (string != NULL) + ret->string = xmlStrdup(string); ++ ret->len = strlen((const char *) ret->string); + ret->cur = ret->string; + ret->neg = 0; + ret->negs = 0; +-- +2.34.1 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index d476ba14b6..e4db345af4 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -32,6 +32,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-0992-03.patch \ file://CVE-2026-1757.patch \ file://CVE-2026-11979.patch \ + file://CVE-2026-86137.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Thu Sep 10 20:03:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97884 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1D0E4C79FBB for ; Thu, 10 Sep 2026 20:05:59 +0000 (UTC) Received: from mail-pj1-f51.google.com (mail-pj1-f51.google.com [209.85.216.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24036.1789070752655672286 for ; Thu, 10 Sep 2026 13:05:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=EOqOYzGk; spf=pass (domain: mvista.com, ip: 209.85.216.51, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f51.google.com with SMTP id 98e67ed59e1d1-381b831d535so259981a91.0 for ; Thu, 10 Sep 2026 13:05:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070752; x=1789675552; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=I2xbkRFJ+t4cH3nqfYPROH/fI0loMSAqyPMFqmJ/oxI=; b=EOqOYzGkftYjshuH/2VGYvGIGPFGKmNs1PQs/fCAIGnoz/50EbXkPV7E7r51H7yfgT b/JJ5pOoVZQ6uK1J7GuM1irf3IY+opsiYj2oCXexBh24ygs48+TA+IGOYOa7fnkPtlUm eBVwt7d9VDy6Mtg7W2KwRz3uakqz9oI4Hn3J8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070752; x=1789675552; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=I2xbkRFJ+t4cH3nqfYPROH/fI0loMSAqyPMFqmJ/oxI=; b=R88Rqc9MuVZPSCihkcldBdbkf1MTXUXAawUvyjuZe22bdnWU+eRXyp7Dw/0+JrSNwJ Dsp6hSRo6oUYaurEvv+FAMuIZ38vmzQUS+isbIaY30PRnhNXN2ScHz1/mOUz2gSHBGDB xc0gOcbiA6tdb0hXTPPU6TWZH9I+h4AaQCcb/EePc6d/XcY+PcVV+TgsobI7O9zIv1AX DQ6Q6YLJVufE+JkRJhQGmF04zFaPXXsyDI01GYLHJwfhDWjmn5gl5DU3feFvR95kTBBA DAqpm2zbn+T4+jmira0+ewB+tk4aa8t7PhOUPZEy2jccJWELvJtnprwDpew3E4Gcaooy 5tAg== X-Gm-Message-State: AFuF++krNhc/JlCYio9tCKSk0Uup72UI+5ftMXCymhwB0EYL7z47H0FL DfAW0dDGdX+CBK4nvXtiE5P7iC7WHKWgoUH+SJiocrPkJEg5EAjUETGa4RgWkZbmbXK7rVowvLM D0Xqp X-Gm-Gg: AYBFou2oBn1ncpBMWwrz9zMz55wJsRGezYVHffl3LK5J+Q2yW+MWitz4ONeoa67vv3C MDEqKPXAj7ONh71J5mL95KlTK12DY/aCFxoLpMJXDOv2xZjDRP2CUy6FHqFJ0HWQ1T1trVOIqPf zjZLXjUcetG3b0dNRBojgGs8wWDOl5e2QZdShvUDpF7nG4EwAxmoDhRY/BZxGgMbnm1KG6nlLlG L973Zc5obsFUywztHXxubBvCvhtr2lOk4vkjUFRMPebEPly3HOm/8rv73aI8eMT+H2iDfe6Vmu7 lQBRNviFeccF8kAmn5xe67G8waQNyX4CTR/6Tt/J2CiNVfWgc5UsUshoorN37JKQQAFQFx2VUA1 tiegfO5Mc52dOKHhuCnng+HRbAli6PCmQLfhZDXLchS9nwui/4l3roqkUJOkHoOfk2VhAuBZodE 386/9Vh9IW1qCKfrS9BwieAT6NLZYmbGzL/bJYHUQ95rzTzyKBVTTiRZLYbMfP7jckkau5FzJUN x5GF6t7DA== X-Received: by 2002:a17:90a:38c4:b0:399:ecd:d68d with SMTP id 98e67ed59e1d1-39d9c342654mr364991a91.22.1789070751973; Thu, 10 Sep 2026 13:05:51 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:05:51 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 2/6] libxml2: Security Fix for CVE-2026-86138 Date: Fri, 11 Sep 2026 01:33:25 +0530 Message-Id: <20260910200329.842463-2-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260910200329.842463-1-sdoshi@mvista.com> References: <20260910200329.842463-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:05:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245594 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-86138 [2] https://security-tracker.debian.org/tracker/CVE-2026-86138 Signed-off-by: Siddharth Doshi --- .../libxml/libxml2/CVE-2026-86138.patch | 53 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch new file mode 100644 index 0000000000..14ddff8215 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch @@ -0,0 +1,53 @@ +From 6261b1ca983717c71a9c0409ff045ee9c81ff3b6 Mon Sep 17 00:00:00 2001 +From: mohammadmseet-hue +Date: Thu, 16 Apr 2026 02:54:24 +0200 +Subject: [PATCH 2/6] fix: add overflow checks to xmlDictAddQString in dict.c + +xmlDictAddString has overflow guards for pool size calculations, but its +sibling xmlDictAddQString lacks these entirely. The namelen + plen + 1 +addition can overflow unsigned int, and 4 * (overflowed_value) produces +a small allocation, leading to heap buffer overflow when memcpy writes +the prefix and name. + +Add the same SIZE_MAX-based overflow guards and safe size_t cast. + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4] +CVE: CVE-2026-86138 +Signed-off-by: Siddharth Doshi +--- + dict.c | 19 +++++++++++++++---- + 1 file changed, 15 insertions(+), 4 deletions(-) + +diff --git a/dict.c b/dict.c +index d7156ed..ae0210e 100644 +--- a/dict.c ++++ b/dict.c +@@ -225,10 +225,21 @@ xmlDictAddQString(xmlDictPtr dict, const xmlChar *prefix, unsigned int plen, + return(NULL); + } + +- if (size == 0) size = 1000; +- else size *= 4; /* exponential growth */ +- if (size < 4 * (namelen + plen + 1)) +- size = 4 * (namelen + plen + 1); /* just in case ! */ ++ if (size == 0) { ++ size = 1000; ++ } else { ++ if (size < (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size *= 4; /* exponential growth */ ++ else ++ size = SIZE_MAX - sizeof(xmlDictStrings); ++ } ++ if (size / 4 < namelen + plen + 1) { ++ if ((size_t) namelen + plen + 1 < ++ (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size = 4 * ((size_t) namelen + plen + 1); /* just in case ! */ ++ else ++ return(NULL); ++ } + pool = (xmlDictStringsPtr) xmlMalloc(sizeof(xmlDictStrings) + size); + if (pool == NULL) + return(NULL); +-- +2.34.1 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index e4db345af4..28ae601118 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -33,6 +33,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-1757.patch \ file://CVE-2026-11979.patch \ file://CVE-2026-86137.patch \ + file://CVE-2026-86138.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Thu Sep 10 20:03:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97886 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 735E7C88E42 for ; Thu, 10 Sep 2026 20:05:59 +0000 (UTC) Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24038.1789070755285719815 for ; Thu, 10 Sep 2026 13:05:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=HIyOTpPU; spf=pass (domain: mvista.com, ip: 209.85.216.44, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-383b4a3755fso126553a91.3 for ; Thu, 10 Sep 2026 13:05:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070754; x=1789675554; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZHWP6DM91DbS67E+q99Cke0GRF2GtNWUxEA/ZG6cI9M=; b=HIyOTpPUMUsY0fGs2A5k+S9f7yh6/2Vmsi04a4vhcdYuQu61UvZNGd2Y78u4aFZ1I/ yLs1PO+wOpgyYaKbD1yQlJqBQhkGv0WzEGyy9ZyZqShADBKGSvNAPUNhQ2xQnAnhPjBr 62kwGPczLg+09qBffxehNGpAL52pi+gvXDWaI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070754; x=1789675554; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ZHWP6DM91DbS67E+q99Cke0GRF2GtNWUxEA/ZG6cI9M=; b=lTmL0PrkZFL+xfXe/UctYJnbWrHTnr3hHm4sVfaWcY+FrrqltE8LFUHPWaCpp63P8B N/DcUhp/AlPjpJxULk6HPJmIXTg93FOgP2TwtE0JqmTTg41ohwrRWrueBHMGQwG1zMAo mQoLwCputfO7T3WkP3OUwwScj4QsZMjDX23bzElbeNrPX8z7j0NHCPy42jUx0+PaTxR+ NiwKsd5FG8PXruc40mHfrONLWffgqlLrhiqLC5Pq692yV0wdaS3nIHoYOFfQv8G9nL6Q Z8e4nIKZtNsAWegVFoaBt8cbMffjNxVTmnOOHRC5R5V7yRdx24C0uazwVUPF922WbShC 2uiQ== X-Gm-Message-State: AFuF++ktanse7f4qmMgdKj/krFvR2uLOloAZIj13j/G/Uy9VrhhSfQBd fknLK7YFZqjmDpIv1A79kfkbn7LYNo5YrNisIV8efGmPWzQwLX1adquhjD3904mLDbqX2QMceDi AAIAA X-Gm-Gg: AYBFou0AWWcX489B6IIcdUWU+ZJTlbCesykXb+Ag7miPC1HJzFT6mQi0T0uSnjvW8gh wZpYCFVl1iRBEU3T+k3gG2wBKWBzRSUkXYxSaZglVZqUfa4UllHOutkrWtMDAnraN6wT87yBE4N m50Pv/d+HO3//tM/tYWBb6y3/4kq/BaIjHFqog28N9ekI8WhVkixYhiU1fPI6tPUfCvKkXviiN9 T/BiFBniFnF7xVclVB7Hcekfewld5DX0BvmiM/K0lZI7zkD0BUeguLetUdKAmXXCQTi0SOKLz7P 5LJkSOWfkPX4vpw7fq0AVzpiDcs0I6o1WPk2N/dqFVRoz0vrLHTB2fT+HnzA2W1vFsSchcTqNNR Myg8mDDaCBoQrZ6bPOj2G7f0NACWyAv9BripUSWhJVGqrpjdDpTsTP3qyQkm0NH8yrilkqwR/dR upwbZgKWCjrgGmPJKX8Ry0850HfDYh3TFm24LPdCEF3DStVIzxACEItfAcsQfloeA2CputdHQ2f afZRsvt8Q== X-Received: by 2002:a17:90a:e7cb:b0:395:7fff:a08f with SMTP id 98e67ed59e1d1-39d9b960825mr696706a91.0.1789070754488; Thu, 10 Sep 2026 13:05:54 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:05:54 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 3/6] libxml2: set CVE_STATUS for CVE-2026-86139 Date: Fri, 11 Sep 2026 01:33:26 +0530 Message-Id: <20260910200329.842463-3-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260910200329.842463-1-sdoshi@mvista.com> References: <20260910200329.842463-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:05:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245595 From: Siddharth Doshi Analysis: - The patch adds return NULL guard when xmlStrlen returns 0. [1] - However, in libxml2-2.10.12, an older iteration of the guard clause is present, which was removed in future versions and then added back as patch via CVE-2026-86139. - Hence, adding the patch as fixed-version. Reference: [1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86139 Signed-off-by: Siddharth Doshi --- meta/recipes-core/libxml/libxml2_2.12.10.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 28ae601118..581f38197f 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -46,6 +46,9 @@ CVE_STATUS[CVE-2023-45322] = "disputed: issue requires memory allocation to fail # https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 CVE_STATUS[CVE-2025-8732] = "disputed: the code maintainer explains, that the issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. The issue triggers a crash if an invalid file is provided. https://gitlab.gnome.org/GNOME/libxml2/-/issues/958" +#The codebase contains an older iteration of the guard clause if (!(len > 0)) return(NULL); which inherently mitigates the len == 0 attack vector described in CVE-2026-86139. +CVE_STATUS[CVE-2026-86139] = "fixed-version: Length guard safety logic natively present in version 2.12.10 protects against zero-length integer overflows." + BINCONFIG = "${bindir}/xml2-config" PACKAGECONFIG ??= "python \ From patchwork Thu Sep 10 20:03:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97885 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8BD3DC88E46 for ; Thu, 10 Sep 2026 20:05:59 +0000 (UTC) Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.24017.1789070757832536805 for ; Thu, 10 Sep 2026 13:05:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=hfHokb1p; spf=pass (domain: mvista.com, ip: 209.85.214.176, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2dd020a2e44so920665ad.1 for ; Thu, 10 Sep 2026 13:05:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070757; x=1789675557; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IIkH1K0tEFvgxyp5qco6ihUlviFhr74aWqT3GK7LF5E=; b=hfHokb1pUcSLRHFfz8wouBbHaqUUtGiDUiLbhH+sddqb72mebOXqjtPg2e6xEx/RlY 9ZFTbIY6cO5CJStN+rSRcXWjO7nhCsoO4iVmL/vEBZVcteZ98oylJ6iwcmn3kreck2ot q6/2reYznqGvl7qS9Pfi73VuVXH5R4NM31BH4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070757; x=1789675557; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=IIkH1K0tEFvgxyp5qco6ihUlviFhr74aWqT3GK7LF5E=; b=VhN9RmA2ahGSbsAtq5cpT+QdioRb5wUuGYN30MSL+jf+nz+NArTGZ3ix5H7T0TTl5Z s1bvaAOWMe2qt4g1IuH+64y5XyvXNPpyFXaeFO/X43k5VAHsroIW6jDsJABmtSdVg3mL fyn5UVmyvW0Kl+tX0j33ylpecCKG7ncvNyPxd8rr2mWQxZrvhDhIP7o6VzQeJfRa+Da4 JpK8K+fIR2kpSiRClK/1i32q3pliKjZO3kRDFay2U+AKfwe6PYHbrWF7AdHsb0OCum+y fiWFEgEPwxbp85qGlnDTdblE4zh5CXYR+ubGP9HMie1DPJ/DPkzlPwxuYO8B5d3YBCws Jalg== X-Gm-Message-State: AFuF++l5p5xziMMOQX2Z6Bfy0vrD4sqgc6arVVYgjWJNJTvvSIBVR5d/ bHQHDCmu66sP3E564cLEKZlN99H4uGtvxf0w/VxTlSuVjVyvW1mz+ij87ZwzB8hC6YSrBqwO9oV H+GR6 X-Gm-Gg: AYBFou3r1CMIwPygmSYUZlly8J9x28b+jgmAF8Oe2E1Ki0qr7oOCwtTkiA4K1QDZ/m5 nJHZb5yh8c5jaswH3SOoHngA2RckbFJMOS/8uh8PpOYLGAVL/dqlDHoy5U2dk6d5wtbkXecHnB3 p3qtbFdYN5A1k/P/Knm1Nl2xCp3boqoSM0YuHPJ9Z07zQSwnR0YpCPk9gB5Fefh5ZS/huKH8ILF 74mdf8yZY3K6O+xo5LH8zBenlUOYZtFw5bC1FvkdlKFWr5L8Q/Q1Gqd4RuXkSuYA9eLtbWHyryN MUTbEK8E69eiBe98euEEoVZXynx4Nd4QRfd635vaiFhqkGzNhG1WZt/J//ggotGXp+Z7K4Xl/oq CZnVhTk74seew1Yb6szjL3FFd+6fYwSx23D7G2pT0rbh5k8TfLf/UZUfET71MD5JRLkDt/FiEv+ aJZ//iPNcQZahOAoB6zKPnZi8XcmYaV5N6igIXR0CrDW8Yf/ar8D7i/w8oRoZ/C/Z7b5s6YzqE9 GPoCre8P4mO9TNP1Avx X-Received: by 2002:a17:90a:da8f:b0:398:d6e8:f84e with SMTP id 98e67ed59e1d1-39d9bd6976amr522095a91.9.1789070757113; Thu, 10 Sep 2026 13:05:57 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:05:56 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 4/6] libxml2: Security Fix for CVE-2026-86140 Date: Fri, 11 Sep 2026 01:33:27 +0530 Message-Id: <20260910200329.842463-4-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260910200329.842463-1-sdoshi@mvista.com> References: <20260910200329.842463-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:05:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245596 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-86140 [2] https://security-tracker.debian.org/tracker/CVE-2026-86140 Signed-off-by: Siddharth Doshi --- .../libxml/libxml2/CVE-2026-86140.patch | 57 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 58 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch new file mode 100644 index 0000000000..c7b6ace560 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch @@ -0,0 +1,57 @@ +From 9a21b9dbb096f9e612f37ba72df6a2fb6a60c60c Mon Sep 17 00:00:00 2001 +From: mohammadmseet-hue +Date: Thu, 16 Apr 2026 02:54:37 +0200 +Subject: [PATCH 3/6] fix: add bounds checks to xmlSnprintfElements in valid.c + +CVE-2025-24928 fixed xmlSnprintfElementContent for unchecked strcat() +writes, but the sibling function xmlSnprintfElements has the identical +unfixed pattern. The strcat(buf, "(") before the while loop and +strcat(buf, ")") after the loop exit have no bounds checks. + +Add remaining-space checks before both strcat calls, with early return +and ellipsis when space is insufficient. + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/d1686f91dbda141a752200419d35639fd6b38340] +CVE: CVE-2026-86140 +Signed-off-by: Siddharth Doshi +--- + valid.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/valid.c b/valid.c +index ae4bb82..718e6d8 100644 +--- a/valid.c ++++ b/valid.c +@@ -5047,7 +5047,15 @@ xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) { + int len; + + if (node == NULL) return; +- if (glob) strcat(buf, "("); ++ len = strlen(buf); ++ if (glob) { ++ if (size - len < 50) { ++ if ((size - len > 4) && (buf[len - 1] != '.')) ++ strcat(buf, " ..."); ++ return; ++ } ++ strcat(buf, "("); ++ } + cur = node; + while (cur != NULL) { + len = strlen(buf); +@@ -5111,7 +5119,11 @@ xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) { + } + cur = cur->next; + } +- if (glob) strcat(buf, ")"); ++ if (glob) { ++ len = strlen(buf); ++ if (size - len > 1) ++ strcat(buf, ")"); ++ } + } + + /** +-- +2.34.1 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 581f38197f..b3f6a482d2 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -34,6 +34,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-11979.patch \ file://CVE-2026-86137.patch \ file://CVE-2026-86138.patch \ + file://CVE-2026-86140.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Thu Sep 10 20:03:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97888 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 77137C79FBB for ; Thu, 10 Sep 2026 20:06:09 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24039.1789070759992795819 for ; Thu, 10 Sep 2026 13:06:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=jsjPTOIu; spf=pass (domain: mvista.com, ip: 74.125.227.140, mailfrom: sdoshi@mvista.com) Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d747ed9865so643205ad.1 for ; Thu, 10 Sep 2026 13:05:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070759; x=1789675559; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=199OBdBhpDSKUFmwDSCWs+nUqnKGcdvRv98s2rnItXc=; b=jsjPTOIuhgzlWEuln0w5+xeTtgXZR3Plm7kJVrrJy1OOvQKVnntlh4UHYi4Mq4lKFU 90vQJEErOfdn06SW4qZRaZtR0YZYEdAs9popWrtOz9ZjhhHnbXTREQL7PX5k0EDUmARp ncmo4S4khsqxKZAsz9MMuy8xmj53MklQpXeD8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070759; x=1789675559; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=199OBdBhpDSKUFmwDSCWs+nUqnKGcdvRv98s2rnItXc=; b=TODaXVNlsf3YeWAewpfEY7Mj/Hp8rnB3DvaEfWz48z61AYk4vIOiosLz4v5LMhJ/P+ QYLiwYrbL0pKRdjl6yxKl+Vyn4ExDU++uQQvMs3kFr7sBBDMhy5ogeZ1BJkz/IxOuxiC Y6baBL5CiifDPvVx0/d3uoqLBOw8ewaO8XnCOH4DZ+ExmeZAffdaguXGzBQaK+7nsTFI 38dk1zv/PHAKFDDalHVtlFJpOUetNDmzjzlmVZMhegnYVeKUeX/qkK+yLmghApfXKEcY n15+GcWAycIRGB/ynO4i2BV6RR400RrbAz2NL6AIN9WI9Pbqu+YwauWeRKJl+OijXWVo sa5Q== X-Gm-Message-State: AFuF++mKRyy8SOmM6oszDUh9pSe2ealuot41bNwGAyflhAYzrS22RXZ+ 621ux68mrE9VT4XbFUh+QeYltUgT1ZfCF3uaW/uxXadCYKpCZUoqi9KClopTPOSx/pMb7nymuqz VDbBs X-Gm-Gg: AYBFou13hfa/cT9BvCdtf4DEMc8WYQGHfPJD0aG/YhXQrhKMiwpzF/sbWnurs0V8JGa 4oqgU+GzduNqUj5YdL+mPLiqh+krvErlXSuzkizhxQEL+5vya2uIzrAZYGD9PcAn1atVYsV1aYD phcN9xMp6eodIbU5nFU7mBX7wSE39Kv+JKLI/HLwFpaWSdgUIbhu1mJK0veNOnpl5E8uX1FATTB BJRVFAfwOFdMkrMFhdgiupuqb8au6HnlOJz5JIQtG4ydFnabmfsEUftatbW0vmmA30R6uIXrrKp vouc/GsxPJDiBhx1QjjmpwX/t0+PKmoA3H15cOh19qaHlDZgD+2m5fVS+abYsw3SCoGvfE2Ks2p 2ie/REw/uW82GgyocD/6UzRqne8aMeBaX9rxxU0QtNzSvu3NQdQlNgij3DCQEFqaC3Tx3wKok7w HF2fRotADFVaulkLkgwsRytC/K08lVJyDNjNmpW5up2Y7YwcBKOyQOB2V4c4AMw8AkxL2+Dm2++ 1xp5eGkQ2o= X-Received: by 2002:a17:90b:134f:b0:399:1b08:28de with SMTP id 98e67ed59e1d1-39d9beb0be4mr630705a91.7.1789070759452; Thu, 10 Sep 2026 13:05:59 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:05:59 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 5/6] libxml2: Security Fix for CVE-2026-86141 Date: Fri, 11 Sep 2026 01:33:28 +0530 Message-Id: <20260910200329.842463-5-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260910200329.842463-1-sdoshi@mvista.com> References: <20260910200329.842463-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:06:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245597 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-86141 [2] https://security-tracker.debian.org/tracker/CVE-2026-86141 Signed-off-by: Siddharth Doshi --- .../libxml/libxml2/CVE-2026-86141.patch | 36 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch new file mode 100644 index 0000000000..cea31d8d14 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch @@ -0,0 +1,36 @@ +From e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55 Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Mon, 4 May 2026 07:56:18 +0200 +Subject: [PATCH] xmlregexp: Calc string length after null checking + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107 + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55] +CVE: CVE-2026-86141 +Signed-off-by: Siddharth Doshi +--- + xmlregexp.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/xmlregexp.c b/xmlregexp.c +index 5e15311..1c1b25e 100644 +--- a/xmlregexp.c ++++ b/xmlregexp.c +@@ -702,8 +702,12 @@ xmlRegNewParserCtxt(const xmlChar *string) { + return(NULL); + memset(ret, 0, sizeof(xmlRegParserCtxt)); + if (string != NULL) +- ret->string = xmlStrdup(string); +- ret->len = strlen((const char *) ret->string); ++ ret->string = xmlStrdup(string); ++ if (ret->string == NULL) { ++ xmlFree(ret); ++ return(NULL); ++ } ++ ret->len = strlen((const char *) ret->string); + ret->cur = ret->string; + ret->neg = 0; + ret->negs = 0; +-- +2.34.1 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index b3f6a482d2..2869aa46ac 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -35,6 +35,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86137.patch \ file://CVE-2026-86138.patch \ file://CVE-2026-86140.patch \ + file://CVE-2026-86141.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Thu Sep 10 20:03:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 97887 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 86BECC79FBF for ; Thu, 10 Sep 2026 20:06:09 +0000 (UTC) Received: from mail-pg1-f177.google.com (mail-pg1-f177.google.com [209.85.215.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.24043.1789070762694860039 for ; Thu, 10 Sep 2026 13:06:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=bi+7zTor; spf=pass (domain: mvista.com, ip: 209.85.215.177, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f177.google.com with SMTP id 41be03b00d2f7-ca12086c06eso241550a12.0 for ; Thu, 10 Sep 2026 13:06:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1789070762; x=1789675562; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4y4LIWfBpkvMPnbNgj4fOm4ZuHW5jJUCnqEHtQoBcuw=; b=bi+7zTorUSAWNZHOu6dLbZyxoV3pNyxbAJ9EhEvNGSfbDD7MoxQN2V8hrLatCN9AI1 UzHS1WRXTJZbtAqpiT91USA5CevERIyLV59dA3s+zrMkIvs0nUhPCmnncxcLT1bi7djy KEPP8wXK2RTYE/hz+BqvY359YsPkdUyQEuUjA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789070762; x=1789675562; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4y4LIWfBpkvMPnbNgj4fOm4ZuHW5jJUCnqEHtQoBcuw=; b=KAxDzoO6k53TM8sY6Iirw/06NXstFUxRZ1Z44rydaJZKy202qUnzr48kdd0VptVAuK Z0uerioNrea+8NobB4gFJ/HyEr0YGW9rFoahAJ+SYS78HAfwywXAjfl/b17cU8dVfN1a 0c40AUUCOcOJdenzgT47mtdA/wJ4WOvE1kIww1RkKrjEcjtNhQIzjExH+/7/eJ+yVCIH pLPDY9nilnXk9hvFYqwODq42kczC7TN6atvxGA1/uFhSLqEh/1wzxqVt4zg0EXpX67lX HHxDt/8MBUI883vH6SX43HJuIi0M+hCFJbJCXTQhE5mhlyKX+ffFZla4jeoFmHLna1c2 vElA== X-Gm-Message-State: AFuF++k5FqlzU6oypwoZ/BqKYat2aKmGv36L2CDf4U4obfv695Pv6r2p /QDZCDOKZJjV5dNBWeoPO0+EjNcqn1noW7qWC499lKIG9xgIeOpUX/WGtxwL6VpqxPJF8GAa5nd m7p4t X-Gm-Gg: AYBFou07136L5pMH1bPkxClQYYiFb78bq4yJuy+hWRaDACAza8keDOtto1lhEu/lOem l4gdzS0Q+yEAbEBQ9NJmy2s/9SLlULH4WkSF2wtFRUlJ5Mo4HinURiRbfs+c1x6PWY4GDNjpghg RJj5M9+/kgsJI1SaB1zTxP2xfNqjo2Nvagc0/OerXxLenvLHLM2wF2IICK0E9Zr+sqeRe4K1TB0 7LGtKidJy9XHN2G+biKEv19XkicqcojKA48p1D70A3CynEYDG3bYzhuBNaGJ6IpybHuZVd+4CKU PZS+UJYk6j8UH8VXRvO0fQSlaKKL9oolJVgm5/hD6/wF1tpvZZraxaNzJprYTedUqo+t9hZ77DS nYi9zBlUVJZCeDU52OK0R2xrjzto9lTtKguoezl4VcqhmTGpyey9/8du+ZNLg+yKIRjMAx57rcy FrVc724SWICixnDSsKJd79a/H+cuqMOkoTPVw4f4csn0hEeuz9Fx2A1e32+qAr1XRQ5oBRmm68p rNVBGj2ow== X-Received: by 2002:a17:90b:57e6:b0:38e:2517:5d1f with SMTP id 98e67ed59e1d1-39d9bec3f25mr618228a91.9.1789070762041; Thu, 10 Sep 2026 13:06:02 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.196]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4cf72dbsm527974eec.3.2026.09.10.13.05.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 13:06:01 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 6/6] libxml2: Security Fix for CVE-2026-86143 Date: Fri, 11 Sep 2026 01:33:29 +0530 Message-Id: <20260910200329.842463-6-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260910200329.842463-1-sdoshi@mvista.com> References: <20260910200329.842463-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 20:06:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245598 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-86143 [2] https://security-tracker.debian.org/tracker/CVE-2026-86143 Signed-off-by: Siddharth Doshi --- .../libxml/libxml2/CVE-2026-86143.patch | 61 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch new file mode 100644 index 0000000000..e3f1197e2d --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch @@ -0,0 +1,61 @@ +From 90f293ba74d28b1d570920382e707586f68ebf35 Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Mon, 4 May 2026 09:54:34 +0200 +Subject: [PATCH] xmlIO: Check for int overflow before calling writecallback + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111 + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/90f293ba74d28b1d570920382e707586f68ebf35] +CVE: CVE-2026-86143 +Signed-off-by: Siddharth Doshi +--- + xmlIO.c | 19 +++++++++++++++++-- + 1 file changed, 17 insertions(+), 2 deletions(-) + +diff --git a/xmlIO.c b/xmlIO.c +index 95d2715..a117228 100644 +--- a/xmlIO.c ++++ b/xmlIO.c +@@ -3378,6 +3378,11 @@ xmlOutputBufferWrite(xmlOutputBufferPtr out, int len, const char *buf) { + if ((nbchars < MINLEN) && (len <= 0)) + goto done; + ++ if (nbchars >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } ++ + /* + * second write the stuff to the I/O channel + */ +@@ -3667,15 +3672,25 @@ xmlOutputBufferFlush(xmlOutputBufferPtr out) { + */ + if ((out->conv != NULL) && (out->encoder != NULL) && + (out->writecallback != NULL)) { ++ size_t bufsize = xmlBufUse(out->conv); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->conv), +- xmlBufUse(out->conv)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->conv, ret); + } else if (out->writecallback != NULL) { ++ size_t bufsize = xmlBufUse(out->buffer); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->buffer), +- xmlBufUse(out->buffer)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->buffer, ret); + } +-- +2.34.1 + diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 2869aa46ac..a15de5d353 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -36,6 +36,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86138.patch \ file://CVE-2026-86140.patch \ file://CVE-2026-86141.patch \ + file://CVE-2026-86143.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"