From patchwork Tue Sep 15 19:16:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98342 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 536CAC982C5 for ; Tue, 15 Sep 2026 19:16:43 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.29]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4960.1789499791346222233 for ; Tue, 15 Sep 2026 12:16:32 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=ACn+39uZ; spf=pass (domain: est.tech, ip: 52.101.65.29, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=k3+dZ781CCIqeNCJNV+85OqJ83ofu4RQifAYHRxX06KV400zsE7smQq7BBAjRiLoTftekcMvKux8kVMbqQhV8UEk7F9OQGV+Ev1ZN7LE5UyjeOLXZGhWugrRu1bjrz9mzQfIFHpC/4LlmGQAW2Li2bhJTpzFnW7za/sovpaO8ShwaCCVQdTJPcHnwlXn4S/LHkU7OZOjeRBbt3TGiM/oRFpbSF9jKrqsJDqPiOEG2Ke4sNUG5NYiiG2U8vz5IHu8khwck7G6c6M/U/Lsy7AQg7U4XAbhFvKRuxziwn8MBvJHEpGG2H0nNUP8st+f2mj1WOgYJodpZPJVvKDdCqUHaQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=RCEkcbSorxUBzD/2zOIKQR5lci5KpOWCSjwpsp5bmiA=; b=gWeObOLga5QeisXC6u8EYx2kaXJ59HMY+5R0awN9DED2SKsWfZq/dZ/BG1SasumWLtjDxTnU+Wcz/DuYWdsaTDbR02uCmv7GWt3j3vHH34EY6Y6Aaxz5TTJkZPWTd0kcIyjCB4+nn2fHq6zt3lBtdlc0l+m9m9L5LLdI6oltkmXpjX+Jsr60dcQmJ50dDu9K6iUzGF6CgWoScsK255YL6T7RNEyhczx/C4WXf9bFtyb7m2DAdmUI8Srh1HifCLu0p8nQk2wV5Zx5FXrqGaWtKB7xFPTvSOVTKv5necjjMXOUoaCt4YzPqH5eJdXH9VY3YInytm34kXUuWkX7iRIBsQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RCEkcbSorxUBzD/2zOIKQR5lci5KpOWCSjwpsp5bmiA=; b=ACn+39uZ6uIrNX+PEZm+a9Z/vVlbFTKUg81KhQbXxuBtEVrFoCx7LQHeb8nKYRfbn/axARrSddU7NrrYIMtIUuNPGrM1Bjv7lNVvFu+qjr/vqZDS9uWO6ZG2t3+Rl+KkshFkrHL/1V3OSq9XIP/jER9tgb5l2NDN4lgktjbg62ONEQGDQYeK2N3uRnWlqAdCV7KK4LC9hepQLhYxIeY19HQlfySWk8Iea/5N9gRfHNc4Sifz2hqZDcot0L2qkLoRDUPu2diWvp5rH60Orp9KAKZVZa1GKqMRAEcgrHY1qKR3h6hz1lCvc9RzpN7a64A+hpy5JPs3aC5cg7GsllmaaA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:28 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:28 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 1/7] libpcap: Fix CVE-2026-0799 Date: Tue, 15 Sep 2026 21:16:17 +0200 Message-ID: <20260915191623.42107-2-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DB8PR04CA0029.eurprd04.prod.outlook.com (2603:10a6:10:110::39) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: 9401641a-3cf5-4e81-0a70-08df135dd7b3 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: q4jPIIJ2py/HUreupMpY4d/jPx7U2w1bfF+1sFnnM6nwZRY+HeuBBXJT8lG9kVyzy+9+bfwFlt60yUNZrIcohgiq4ndEGaqQlIhzWnKyIpPxccwlFIKvi295Gk0J2xsr0Qwac4N6HojNQEpsHIXbu9XSLbCXAIiqjfeNiw3M6Kl7xMv+XJIUG7fZ25V9G7jEeLDExAwCwpdY09FUoXqjteuHT6s57cqkLfGd+VIT9lHoZoQANGVdrpIEzSfUVLyYH3i5Kh5QbuC5/aOqQBbmxDlWgPfFtAStUor/MTTd4otLq4maR4umxsZR564V9SyXzxgW8P2VzqVm+vYC5jr99lAsecW46OLeLZSaah7wfKmUA/qbcDV/lFhIW/hFZwsGhSvKbqXaLy84wnv92x/iu4iSfU9da8ZMj9rcg5UJIQyUAoZDRSJYVVvXWSuvyeSRxynojZwNKIDzsY5m9iYjqSV7FNR0le97hWM4ZlVVE3xvHls9TCUPVtcxsHG+Cs+DV4E4jpevZHOg+LqzbPdGP4hh3R6OujGZrIJ4uhYZb5V34ZdYk4ug5GIKvcPcBPuxi/GlGhM4p5La4p8Ewo3Cn1Ut6Q1pq4s6D8NOUh7UVEI4rcm05DyqT9juY8crlJNY X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: FuVn1PpdOnHRhAaty7rjHvmGU35N9dpq65VtzxMThtjmoi7+TC3Na1zoCgGXnUxYQ3CG2eVl7qScBapsbVPTmOhBIZsPUuZAAHL9GCd6lSPOtj+qOnEFkBxkGU53Idfu0N3nlPS3NhPzCN7EA/Q1FIQnK/vd93bZ8GUFNx+5pMRGT0hO/emTn+EaY+R13VwNNnmZnd2DJ61bMz/4PD4uJT1R5O0GXBJqmKuVV2kBZ3mGlVmRUWHQoEi3tmlRDOt/IICasXrbhsnkPmLoGSPmmpkFxhJKJAIefpOFpsLCWT1mA0vzaq3miaos2dLc96OtQ+UY7fjMGFVSErm0XaVkGBc7hqjA6RQB6ioEm5KL13GdCFsF85dk5oZkuUUwiKyqcQEIa2SmJPHkX7V2g2iDUpYu05obFAkNRHJ9Nek6z8CGCis/3jizMfdC3oLdaTqM67kNcySeqfG3z0u7jL1ML933Lb2agwgyR3s3R1paHjjMwLn9Cl/znb1ssduwILC6t7EjQHhvHnTEA7K8rll6yjV77utXQiJSU6bK2fGKaOJsvbQd7JwGQM0IWtxgi5Iy20LBFED/fNpUPe+eIJt/T5ijtyoiqpDZqFXf+U3whzy37cIesWDgEKKeyUGAofh/2NVlF8YHvNtq3mG0KP45GtDehWGDtnbAn4hiYekaPooNNtkjQniymX0XAJxONrpd1OhYR57SxI7tajKP6UiasbsklI/Ni0d9aZ2BBwhi0NqZjR+l5ozAWmJfLeaMIJ2qbDsZwFm2kYgTcWCyxPIt8Y4gX6Zj4taKGbFwIXFpIZ0U4QNn6J9Cz6qvIag7xYrYY5Mr+ufsDC7yx3ta+DQBlrwJdHH/oiMjOm5x2+53luDBv6h/Unsn2aTWFFKwgOnEwL+rlKh2iyIlCKgmF4UtokFMu8XSycKLPbLJBmaRDpFRp1fqxn2VqhFydnjT/Uatoh5gEzZbil2rvEvNeCG98eWusrLENwx8GA/jl/nXKb3abIabofrkDbgJi8khOuTFNF7wwr+h/eANFX+1JCU6AkZwTg0YuXIKllGUkTefF/o05Ft6SwDdu98q9nXSj19V4Ae9iUrEmgRL6aqKQRMa3EWfqIj7yj3RPjzBzjn3ys55dU+U2lSkP9j24AytQ9cbNcvIorQ84NCwh7pCoYNpgzZbOnfznvnPLD5S8ozgw0oCSAvXwezxusMCWhTaLcmj7AisHCTZqbgNCd+ozC1yOviGTHETph5t5TT+ds3ynbo0Knj7DyTnpJeIZFcqyy38R10jpaadQtZm/61TRChleJFUq3LFV/Vz17+2r9DV+rOufSPH3hmOa2AWnhQiHln9eTndjAqYTpWRywHAyuwBSWDF2UI95qlFcW8VYO5/BHUIi++mA8PztS/fakoJ6TEe7pNGKQ1GcfhQRPQjAhlIMHLujtnk5YqMsM2Tar/87qHn+sRlAjMbOjiJc5MtPkrpXO/Q9kD8GNU/VrjDtMW4GgCNg5rYMsEhjRlaX297+yh561UkIYDcBduWrCKqS3/drvh2Gz2YWQhs4NIQlBZURc55Qx61E+Aa2L9inOPs29NYRX4C4S+PGiV+7PUwgWcZ3N3es6vXznYSeybApZE+dxU6R1AEzb4QOEsVR0IVlx5sV+HJdc5lG3gzChGukzym/HDgwNt79D0YwgC64BACJKAtWMxVWG5E/yIXGQ0TjAGF4ubMgs3fFkf6z2SVrhnXODKBPj6RzfNyDuh4bKH8oQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 9401641a-3cf5-4e81-0a70-08df135dd7b3 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:28.2703 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: AVNFIF0oWmA3SQYxYHUYQe3VUAa6xOSM/hqMHoSE5BD/PNeE9jl5XkvV9FpJW7VzpPQTAdriXBTm93EUeKTVMknJTMIU6WEuv5XyIzK9q2o= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245868 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/01-CVE-2026-0799.patch | 67 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 68 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch new file mode 100644 index 0000000000..7c40faa608 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch @@ -0,0 +1,67 @@ +From 3c55fdefa576c7a06feab86a9e4341be414de49b Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:41 +0100 +Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter. + +Include Security identified and reported this problem as a potential +vulnerability in 2018 (case reference "I7"). Their work was sponsored +by Mozilla under the Secure Open Source program. The vulnerability has +been independently confirmed only recently. + +The current revision of pcapint_filter_with_aux_data() can, but does not +check whether a scratch memory register index is valid in the "ld M[k]", +"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this +is always the case. This holds for programs that have been generated or +validated by libpcap. + +However, this does not necessarily hold for programs that come via +pcap_offline_filter() or [deprecated] bpf_filter() from an external +source and have not been explicitly validated. If the interpreter +executes such a program with an invalid index, it will read/write the +process memory at arbitrary locations starting at the current stack +frame. Depending on the address, the memory layout and the OS, this can +result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To +fix this, in the interpreter reject the packet if the index is invalid. + +(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a) + +(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7] +CVE: CVE-2026-0799 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 9b899bbb..510dbd9c 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -217,18 +217,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_LD|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + A = mem[pc->k]; + continue; + + case BPF_LDX|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + X = mem[pc->k]; + continue; + + case BPF_ST: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = A; + continue; + + case BPF_STX: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = X; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index d381a4eb2f..265c46e3bd 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -12,6 +12,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ + file://01-CVE-2026-0799.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98345 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8B059C982C9 for ; Tue, 15 Sep 2026 19:16:43 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.29]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4960.1789499791346222233 for ; Tue, 15 Sep 2026 12:16:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=s2FLsF8M; spf=pass (domain: est.tech, ip: 52.101.65.29, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=c+86am9IONGupCW0YMDXYcD2CV4sUYeTNJobeeaMuaSBPKAnzoqWyaboVN5ahK02+ikxZsHyRF8cePKdMfmbjmTx4KWai77lq8ZwM78Och0+xowdx8QlD+V6QgVvgFWttwkmuyySTQbAngg89CvdUUeJpHMX8cb1hEn5X1tumrecprE5GWBA5lELa2GKVszPRcpk7jAdXWBWFjilQB8D5M5kinEeudvx7UWjQ6R77crIyaValxFRxpHi4caM12HnNeRx60ZAoWTdtHnyZkV+q5CG46YlkN6tTZRxcpVOEGEbnbH4U5+KL+FwzH0MkuKvVEXNgkBnL7XxZRtvnAGkbw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=zfrGBmCBoUz8N6ra63tYN37ew1DOenu7EKyE7gvIaHc=; b=t9yeAlU1Q3B+euAc8RcCbaN1zXrN6ea/rMXJunLE2K+xxz+nbLfjmnhLuyg9yvtn9w5SYPK/r6oCCDmj3Ye13EV2TQUMsplzlGT7pbeWpXQxGwR9kxC0MXd8B0a5AmTwCKBBriPC1c1ZwuhkK7WEPr6YZX9YDgxJwEO92NLqXQSukm5ZpaR2ydrxVtkKyX42him2LE3E9Oz/CJ26TLZ9yJUXyBYd7DLsMUPOTyvBYjCwIfuxY01W+zzqSo4Ce6SXl8mA1ViVJ5+D7yJnAJdxdT89EQzGkxqGrqXhnYJnokb+u1IfKZJKEG4ASmo21yQbqAPGMuo4Smpj9ucoOrMPIA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zfrGBmCBoUz8N6ra63tYN37ew1DOenu7EKyE7gvIaHc=; b=s2FLsF8Ma869GW4ZKSY2uAAt6l7XwGyVi5l4E2niz/6j5Gc7F3Z5kRl1yUZl7YrpYT3XkDZcTk0Qd0+zCTIbMIaWhj0N+syUYeWOGwWAonzXvQ8w8DRaBvZHtoskltS8sTdjIejDrs7Xciri2ZA9qBWgFRz8Qt9biOdm7GzntGiJlMpq/gF5+Oz1BQTNIs51ZUW/WBMtuPK5Y7yVRrTt/wf9HzLNUeEIKeTOz13ujvYW+mz9krkDuUcB6YTpVhLHvkMBxhSnmlTot/Zo5P7rc3BEGknTZ5OxhhZ1nIJfsjpNXeQjuPuZkyXl+jP4fvJPNnwepAC5rk35nvyD8XVW6Q== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:29 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:29 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 2/7] libpcap: Fix CVE-2026-31912 Date: Tue, 15 Sep 2026 21:16:18 +0200 Message-ID: <20260915191623.42107-3-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0158.eurprd04.prod.outlook.com (2603:10a6:10:2b0::13) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: 4e170de0-76c0-4c06-8f07-08df135dd885 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: oj3GWQoBPZQTwvz0xEaQyWUSzI1YL9SwVt5yca0nmM+WeratfX8kIk6MPpe8yNSmPaCbw80h8uLnew97+9/1Wa53ScJDGuetYwl/JGuUgxZ2JfeX/jbvxzi/XMC/z7+5gqLvcmfKAt4PhhwTb9AMdjAsfE4vPlu3SRHEkqDBhxeTNf8+B1ihKTg6yX5uR6Is1mxRHyOnUTZ7fqbjdgIfaQT/HD0JVYAZb7iCZQHkrlBu83L/Y/UMuMK+CIueznZEfUMvt0jWjiOpjwbjdm65hKuseDeAjrhoSQbmdvO3LhflP+ey7fbtVOSkr34cPTXVZJrHps3SQ1N0iDs5XaGX+lYk7G3zZeS4lCFvHqm0FeS1FoDHVeh/Nzs00moyto1bhlqibqHM0dce9YHYKTrzClxSqpBgN8vZ1q5D49OCEF8otbc4/2to41Z4lA2GWnn3xwTb5plJWHwf3LwtYcWVYZoYbfMkttbeG2/zyc8dbqBnAwuq2Y/TOb3med0GIrI5puYEfaBLGeSMW/FNi14D6H7QF52zmyN8iW591wdzg9IBNpIheaDo0MulFur2fighXdm6Yu7Za9Yhn3ctgDk+lGRaq+XfZeKP35JuQ1LIlSP1rQEoyrzAxdPeL9U48wUt X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: jdEad6Gi8vvy0sa6YQscTTQjrKhuapv/4v16kunVf8lJaE0vvWTu6AF0lJeE/yQuAyBwfv2dHLgogUxMr6C42CoMCPiD8tmW4m9kovicyZYf62331I/m7zldZRTKI9SL1BQeBsBMTKIGOLbk4gAjcyePl07BlwbhKhpFOzdXRFKmPj0ZnU2zFWMym0v4GpWmh3KMGnC67kMS9B+7sRG7nWeL8U/l22OWTMfikZSOMb6gStXlsjm9f7d+vecVFg4Wv/KfZwpd9x/ydsAB+leAF1XX57XErP0sDBg6iEEFtizESRD2hTcd2Lyf8bewcSelABWMrFegofTagsdz5YBExJGMeSI2dAnQSy90DxNAas0Y4jsSp0xNPcu8eH/odM//jFyW802mOvuP1JNbM1yS2Ile4TWE7KIep5LsU+CIJOp5+05ycuSbM54p8dqKchFwTI73CFigYuOqszBdH8I6JVvbaXiKgYul6HtZrWfbvFsW+R4gLPt3++igB71RSxZ8fGxB3aOOj0JsyQ0NuPylmA/mRzO6FlUwHFmRACX78p3Ud7awWwEn7kShXQbPzJCKxQ6o6xVaQXp8dA/erUzAjn+LTQSBbDQw/B/uIagRbj3iiOsdEMxyU+5t+534SAdCEPvAU3ieeaZ/R3WDFrXqg/LbkfUHJbccbUiTaMETBuUeORoZNDIm8BlLIIMya8z92bmiqri3oJ49fLPKteRFlg5Vi5SQjD+slCmUkoiSodSK0NFeMALXoBK0OdKER6EAJEMU1unCNI1Rh3j09kt+ogj/C4rXpuwaQ6kcCJJqRSKYouYFbTKTalgCpSHsupTVUQL59HaOu1G1pVFDNDlQiB83AQECFYM0Yyiifj84WaP19EXTdH27uzRZXvhJjGGDCJ8BOopC7eHNWujI6BiU/lGYWKM8oXlllPY+zEBn0o0cJCCBfxwsMFYCR1lzMzvBeFJ3/eRWcndXwq8nVJ3B5OLxIC203L0lbshYAHBxW9uCr1gFgAKmgcRZ0s/daiFaY4bhRPkBtr21AdBRXfebONqozsgrNdwPZ/VTK6NpPu00Cd5lYthoaeynWt0vC124NAr/KLW25QWWuoHUMVqJLX0y2ToyXWnwof61o3+6bm4X6taGfj242vKM8bs1hEaf9czxcz5NjR6ewFwgst9fcpxBGZMOOhC5Ao3Tf7SoviCGwVcuG+Dq0uIb8mhbetbLuwzhtouJeLuuvCDUoYXkfviBrwUelTu7HUvx4bUklQl9V2h63kSs25o/O3LCzUzvK3UNNDckulRnXCcbBY5vYuS9FZUOYEqN5NW6iTDwDXsr57daTKp/MzazuT4+7DhNrKeC/H5m0vZFxkp0fJKKQ3oWnG9gE0ZgJ0vFQuUQZ1ur8CyqZNsZLeHmr2G31A2E5RXzU4nF4cxuSjWUVwXwfssV4sI00h67XVpEn3rej1tsjENsySal209Ym0bG+wf/uo7NurBPOcSg+3kJReV3uY7zo/yRICokIAFmaZnnHs7mk3z00K/1OQeG8tQkXMWdTBhWg31Va6kLsGEIzBCEqU06ojuk5rgJrXondeqI6pVRWdm1AxFXgar8nDwyZeGh1zhOIBwWVLJorLkv8rco6NNI91BkSg2qGsUK2fLzs/EytQYupeuuVVM7N+Pm4JKNsgrGLORTjt3Iy6DsHOsxhJVAAFlof8BqAzS1xhyvyJBkbYLJUaAJogz0MgfJ/XPF4Wk7n8/yvz0yuMHNGH3rOQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 4e170de0-76c0-4c06-8f07-08df135dd885 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:29.6989 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 78H2tSVugtmDlk/aBXj2O04koXPzdnp1AVUpv1ZvP0fh5Lmu5FnGASTn4zPyz31o3B8/fgXo5iJ4N1+8Nil4Nez2PD7JUakC6nhM1MAxbII= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245869 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/02-CVE-2026-31912.patch | 597 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 598 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch new file mode 100644 index 0000000000..ceae734ff7 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch @@ -0,0 +1,597 @@ +From 09e04074ddfbca5fa33693c6e2d4f01a74857f65 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:55 +0100 +Subject: [PATCH] CVE-2026-31912: Mind the program bounds in + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() does not know the +number of instructions in the filter program, it assumes the program +counter always remains within the bounds of the provided filter program +and always reaches a return instruction. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program and advances the program counter beyond the last +instruction, it will be interpreting memory space after the filter +program as BPF instructions, which in the current implementation will +eventually cause either abort() (another commit addresses that) or +SIGSEGV. + +To fix the latter problem, in pcapint_filter_with_aux_data() add a +parameter for the number of instructions in the program and reject the +packet as soon as (or just before) the program counter goes out of +bounds. Update all incoming code paths to specify the length; also in +pcap_offline_filter(3PCAP) make it clear the function now requires the +'bf_len' member to be set correctly and uses it. + +(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551) + +(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9] +CVE: CVE-2026-31912 + +Notes on backporting to 1.10.6: + - Adjusted the pcapint_filter() call sites in pcap-dag.c, pcap-netmap.c and + pcap-snf.c to the 1.10.6 code base. In 1.10.7 these were already touched by + the unrelated "low snaplen" fixes (commits d5192db3, fb87fdeb, b0caefe8), + which are not part of this CVE and are not backported here; only the new + bf_len argument is added to each call. + - In bpf_filter.c the scratch-memory-store zero-initialisation and the removal + of the stray BPF_S_ANC_* enum (1.10.7-only cleanups) are not present in + 1.10.6, so only the new pc0 declaration and bounds checks from this commit + are added. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 510dbd9c..4f9adeea 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,24 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++/* ++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the ++ * userland interpreter in libpcap is meant to support much longer filter ++ * programs. In the latter case it is important that BPF_MAXINSNS does not ++ * interfere with the safety checks in the validator and the interpreter: ++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX ++ * It makes the most sense to be able to interpret as many instructions as ++ * pcap_compile() can produce, without optimization, for a valid filter ++ * expression before it consumes as much memory as the current definitions of ++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost ++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit ++ * machine. ++ */ ++#ifdef BPF_MAXINSNS ++#undef BPF_MAXINSNS ++#endif ++#define BPF_MAXINSNS 3060000U ++ + /* + * Execute the filter program starting at pc on the packet p + * wirelen is the length of the original packet +@@ -84,12 +102,14 @@ enum { + */ + #if defined(SKF_AD_VLAN_TAG_PRESENT) + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data) + #else + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data _U_) + #endif + { + register uint32_t A, X; +@@ -99,13 +119,36 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, + if (pc == 0) + /* + * No filter means accept all. ++ * In this case the value of 'proglen' is irrelevant. + */ + return (u_int)-1; ++ if (proglen < 1 || proglen > BPF_MAXINSNS) ++ return 0; ++ ++ /* ++ * Require the current instruction pointer not to overflow for both the ++ * filter program (where the pointer will be dereferenced) and an ++ * immediately following margin (where it will be not). So long as the ++ * margin is large enough to represent the destination of any single ++ * conditional [forward] jump from within the filter program, a single ++ * guard prevents all filter program over-read attempts that result ++ * from the program running out of instructions before a BPF_RET or a ++ * conditional jump directing the interpreter beyond the program end. ++ * Unconditional jumps mean a larger problem space, which the BPF_JA ++ * case below addresses separately. ++ */ ++ const struct bpf_insn *pcend = pc + proglen; ++ if (pcend + UINT8_MAX < pc) ++ return 0; ++ + A = 0; + X = 0; ++ const struct bpf_insn *pc0 = pc; + --pc; + for (;;) { + ++pc; ++ if (pc >= pcend) ++ return 0; + switch (pc->code) { + + default: +@@ -241,6 +284,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_JMP|BPF_JA: ++ /* ++ * The pointer (pc) decrements and increments in units ++ * of sizeof(struct bpf_insn) == 8 bytes. The number ++ * of units is in the [INT32_MIN, INT32_MAX] interval, ++ * hence the result can point before the beginning or ++ * beyond the end of the filter program and can under- ++ * or overflow; also on 32-bit architectures it can ++ * under- or overflow more than once and can test ++ * negative for underflow, overflow and out-of-range ++ * conditions after under- or overflowing at least ++ * once. ++ * ++ * However, it has been verified above that the program ++ * length is sufficiently small and the pointer does ++ * not wrap within the bounds of the filter program, so ++ * there is a one-to-one correspondence between BPF ++ * program counter values [0, proglen) and all valid ++ * values of the pointer. In other words, after this ++ * unconditional jump the pointer arithmetic result ++ * will be valid iff BPF program counter value will be ++ * valid. For the latter problem the solution is ++ * almost the same as in the validator. ++ * ++ * The main difference is that here the current value ++ * of BPF program counter is not a 32-bit unsigned ++ * variable, but a ptrdiff_t expression, which is ++ * 64-bit signed on 64-bit architectures and 32-bit ++ * signed on 32-bit architectures. However, the cast ++ * to 32-bit unsigned is safe in both cases because: ++ * pc0 <= pc < pc0 + proglen, therefore: ++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX ++ */ ++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -394,10 +471,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + } + + u_int +-pcapint_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, +- u_int buflen) ++pcapint_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p, ++ u_int wirelen, u_int buflen) + { +- return pcapint_filter_with_aux_data(pc, p, wirelen, buflen, NULL); ++ return pcapint_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL); + } + + /* +@@ -417,7 +494,7 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + u_int i, from; + const struct bpf_insn *p; + +- if (len < 1) ++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f) + return 0; + + for (i = 0; i < (u_int)len; ++i) { +@@ -483,33 +560,45 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + case BPF_JMP: + /* + * Check that jumps are within the code block, +- * and that unconditional branches don't go +- * backwards as a result of an overflow. ++ * regardless of the direction. libpcap uses ++ * backward jumps to implement the "protochain" ++ * primitive. All offsets that mean a backward ++ * jump in libpcap (whether in-range or not) in ++ * kernel BPF implementations mean out-of-range ++ * or overflow forward jumps -- kernel ++ * implementations must reject that. ++ * + * Unconditional branches have a 32-bit offset, + * so they could overflow; we check to make + * sure they don't. Conditional branches have + * an 8-bit offset, and the from address is <= +- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS ++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS + * is sufficiently small that adding 255 to it + * won't overflow. + * + * We know that len is <= BPF_MAXINSNS, and we +- * assume that BPF_MAXINSNS is < the maximum size ++ * know that BPF_MAXINSNS is < the maximum value + * of a u_int, so that i + 1 doesn't overflow. +- * +- * For userland, we don't know that the from +- * or len are <= BPF_MAXINSNS, but we know that +- * from <= len, and, except on a 64-bit system, +- * it's unlikely that len, if it truly reflects +- * the size of the program we've been handed, +- * will be anywhere near the maximum size of +- * a u_int. We also don't check for backward +- * branches, as we currently support them in +- * userland for the protochain operation. + */ + from = i + 1; + switch (BPF_OP(p->code)) { + case BPF_JA: ++ /* ++ * So long as both 'from' and bpf_insn.k are ++ * 32-bit unsigned, this check rejects any jump ++ * offset that points outside of the valid BPF ++ * address space of the filter program no ++ * matter whether signed interpretation of the ++ * offset is positive or negative. ++ * ++ * Note that this condition is necessary, but ++ * not sufficient to get correct results from ++ * respective pointer arithmetic in the process ++ * address space. Other necessary conditions ++ * are that BPF_MAXINSNS is correctly defined ++ * and enforced, and that the pointer does not ++ * overflow. ++ */ + if (from + p->k >= (u_int)len) + return 0; + break; +@@ -537,12 +626,14 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + + /* + * Exported because older versions of libpcap exported them. ++ * This function is deprecated and unsafe, use pcap_offline_filter() instead. + */ + u_int + bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, + u_int buflen) + { +- return pcapint_filter(pc, p, wirelen, buflen); ++ // The actual length of the filter program is not known. ++ return pcapint_filter(pc, BPF_MAXINSNS, p, wirelen, buflen); + } + + int +diff --git a/dlpisubs.c b/dlpisubs.c +index d4310de5..19934059 100644 +--- a/dlpisubs.c ++++ b/dlpisubs.c +@@ -203,7 +203,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user, + bufp += caplen; + #endif + ++pd->stat.ps_recv; +- if (pcapint_filter(p->fcode.bf_insns, pk, origlen, caplen)) { ++ if (pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ pk, origlen, caplen)) { + #ifdef HAVE_SYS_BUFMOD_H + pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec; + pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec; +diff --git a/pcap-bpf.c b/pcap-bpf.c +index 49bb273d..13f83930 100644 +--- a/pcap-bpf.c ++++ b/pcap-bpf.c +@@ -1372,7 +1372,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + #endif + */ + if (pb->filtering_in_kernel || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + struct pcap_pkthdr pkthdr; + #ifdef BIOCSTSTAMP + struct bintime bt; +diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c +index 2fc51665..9f464e70 100644 +--- a/pcap-bt-linux.c ++++ b/pcap-bt-linux.c +@@ -396,7 +396,8 @@ DIAG_ON_SIGN_COMPARE + pkth.caplen+=sizeof(pcap_bluetooth_h4_header); + pkth.len = pkth.caplen; + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c +index dfba8051..cfe52498 100644 +--- a/pcap-bt-monitor-linux.c ++++ b/pcap-bt-monitor-linux.c +@@ -153,7 +153,8 @@ DIAG_ON_SIGN_COMPARE + bthdr->opcode = htons(hdr.opcode); + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-dag.c b/pcap-dag.c +index 5ce15dd5..334a970c 100644 +--- a/pcap-dag.c ++++ b/pcap-dag.c +@@ -666,7 +666,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + /* Run the packet filter if there is one. */ +- if ((p->fcode.bf_insns == NULL) || pcapint_filter(p->fcode.bf_insns, dp, packet_len, caplen)) { ++ if ((p->fcode.bf_insns == NULL) || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ dp, packet_len, caplen)) { + + /* convert between timestamp formats */ + register unsigned long long ts; +diff --git a/pcap-dbus.c b/pcap-dbus.c +index d29fb81d..b0f30f6f 100644 +--- a/pcap-dbus.c ++++ b/pcap-dbus.c +@@ -90,7 +90,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char *)raw_msg, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char *)raw_msg); + count++; +diff --git a/pcap-dpdk.c b/pcap-dpdk.c +index c78724e5..4fb8ffea 100644 +--- a/pcap-dpdk.c ++++ b/pcap-dpdk.c +@@ -405,7 +405,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c + + } + if (bp){ +- if (p->fcode.bf_insns==NULL || pcapint_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){ ++ if (p->fcode.bf_insns==NULL || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ bp, pcap_header.len, pcap_header.caplen)){ + cb(cb_arg, &pcap_header, bp); + }else{ + pd->bpf_drop++; +diff --git a/pcap-haiku.c b/pcap-haiku.c +index 609f585a..7b994fee 100644 +--- a/pcap-haiku.c ++++ b/pcap-haiku.c +@@ -112,8 +112,8 @@ pcap_read_haiku(pcap_t* handle, int maxPackets _U_, pcap_handler callback, + if (handle->fcode.bf_insns) { + // NB: pcapint_filter() takes the wire length and the captured + // length, not the snapshot length of the pcap_t handle. +- if (pcapint_filter(handle->fcode.bf_insns, buffer, wireLength, +- captureLength) == 0) ++ if (pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ buffer, wireLength, captureLength) == 0) + goto drop; + } + +diff --git a/pcap-int.h b/pcap-int.h +index ce0ac698..3d466946 100644 +--- a/pcap-int.h ++++ b/pcap-int.h +@@ -579,13 +579,15 @@ struct pcap_bpf_aux_data { + * Filtering routine that takes the auxiliary data as an additional + * argument. + */ +-u_int pcapint_filter_with_aux_data(const struct bpf_insn *, +- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *); ++u_int pcapint_filter_with_aux_data(const struct bpf_insn *, const u_int, ++ const u_char *, const u_int, const u_int, ++ const struct pcap_bpf_aux_data *); + + /* + * Filtering routine that doesn't. + */ +-u_int pcapint_filter(const struct bpf_insn *, const u_char *, u_int, u_int); ++u_int pcapint_filter(const struct bpf_insn *, const u_int, const u_char *, ++ u_int, u_int); + + /* + * Routine to validate a BPF program. +diff --git a/pcap-linux.c b/pcap-linux.c +index 20802e43..7e04a041 100644 +--- a/pcap-linux.c ++++ b/pcap-linux.c +@@ -4279,6 +4279,7 @@ static int pcap_handle_packet_mmap( + aux_data.vlan_tag = tp_vlan_tci & 0x0fff; + + if (pcapint_filter_with_aux_data(handle->fcode.bf_insns, ++ handle->fcode.bf_len, + bp, + tp_len, + snaplen, +diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c +index 344bae47..ade53ea6 100644 +--- a/pcap-netfilter-linux.c ++++ b/pcap-netfilter-linux.c +@@ -257,8 +257,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen)) +- { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ payload, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, payload); + count++; +diff --git a/pcap-netmap.c b/pcap-netmap.c +index f17f36ca..925f677f 100644 +--- a/pcap-netmap.c ++++ b/pcap-netmap.c +@@ -79,7 +79,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf) + const struct bpf_insn *pc = p->fcode.bf_insns; + + ++pn->rx_pkts; +- if (pc == NULL || pcapint_filter(pc, buf, h->len, h->caplen)) ++ if (pc == NULL || ++ pcapint_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen)) + pn->cb(pn->cb_arg, h, buf); + } + +diff --git a/pcap-npf.c b/pcap-npf.c +index f638bd80..38e985bd 100644 +--- a/pcap-npf.c ++++ b/pcap-npf.c +@@ -720,7 +720,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + */ + if (pw->filtering_in_kernel || + p->fcode.bf_insns == NULL || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + #ifdef ENABLE_REMOTE + switch (p->rmt_samp.method) { + +diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c +index fd6d6fa6..5f15d4c5 100644 +--- a/pcap-rdmasniff.c ++++ b/pcap-rdmasniff.c +@@ -170,7 +170,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u + pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + ++priv->packets_recv; + ++count; +diff --git a/pcap-snf.c b/pcap-snf.c +index d08275ac..8a57eadd 100644 +--- a/pcap-snf.c ++++ b/pcap-snf.c +@@ -190,7 +190,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + if ((p->fcode.bf_insns == NULL) || +- pcapint_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ req.pkt_addr, req.length, caplen)) { + hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision); + hdr.caplen = caplen; + hdr.len = req.length; +diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c +index bc39b1db..d219721a 100644 +--- a/pcap-usb-linux.c ++++ b/pcap-usb-linux.c +@@ -733,8 +733,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u + pkth.ts.tv_usec = info.hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, handle->buffer, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ handle->buffer, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, handle->buffer); + return 1; +@@ -921,8 +921,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch + pkth.ts.tv_usec = hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char*) hdr, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char*) hdr, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char*) hdr); + packets++; +diff --git a/pcap.c b/pcap.c +index a076c5fb..6caa052b 100644 +--- a/pcap.c ++++ b/pcap.c +@@ -4349,7 +4349,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h, + const struct bpf_insn *fcode = fp->bf_insns; + + if (fcode != NULL) +- return (pcapint_filter(fcode, pkt, h->len, h->caplen)); ++ return (pcapint_filter(fcode, fp->bf_len, pkt, h->len, h->caplen)); + else + return (0); + } +diff --git a/pcap_offline_filter.3pcap b/pcap_offline_filter.3pcap +index 94b9a719..c6d62dee 100644 +--- a/pcap_offline_filter.3pcap ++++ b/pcap_offline_filter.3pcap +@@ -17,7 +17,7 @@ + .\" WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF + .\" MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. + .\" +-.TH PCAP_OFFLINE_FILTER 3PCAP "7 April 2014" ++.TH PCAP_OFFLINE_FILTER 3PCAP "12 March 2026" + .SH NAME + pcap_offline_filter \- check whether a filter matches a packet + .SH SYNOPSIS +@@ -45,10 +45,35 @@ points to the + structure for the packet, and + .I pkt + points to the data in the packet. ++.PP ++In the ++.B \%bpf_program ++structure the ++.B \%bf_insns ++member is either ++.B NULL ++(which means to reject all packets) or points to an array of one or more ++.B \%struct bpf_insn ++elements, in which case the ++.B \%bf_len ++member must be set to the number of elements (this is what ++.BR \%pcap_compile () ++produces). ++.PP ++The filter program must have been compiled for a link-layer header type ++that matches the packet data; also on Linux the filter must not use ++BPF extensions, see ++.BR \%pcap_compile () ++for more information. + .SH RETURN VALUE + .BR pcap_offline_filter () + returns the return value of the filter program. This will be zero if + the packet doesn't match the filter and non-zero if the packet matches + the filter. ++.SH BACKWARD COMPATIBILITY ++.PP ++In libpcap releases before 1.10.7 this function ignored the provided ++.B \%bf_len ++value. + .SH SEE ALSO + .BR pcap (3PCAP) +diff --git a/savefile.c b/savefile.c +index c711a81c..49ef52b6 100644 +--- a/savefile.c ++++ b/savefile.c +@@ -685,7 +685,8 @@ pcapint_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + * and, if it passes, process it. + */ + if ((fcode = p->fcode.bf_insns) == NULL || +- pcapint_filter(fcode, data, h.len, h.caplen)) { ++ pcapint_filter(fcode, p->fcode.bf_len, ++ data, h.len, h.caplen)) { + (*callback)(user, &h, data); + n++; /* count the packet */ + if (n >= cnt) diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 265c46e3bd..aa5265a54c 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -13,6 +13,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ + file://02-CVE-2026-31912.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98343 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B92B2C982C1 for ; Tue, 15 Sep 2026 19:16:43 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.29]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4960.1789499791346222233 for ; Tue, 15 Sep 2026 12:16:34 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=lujZaWb9; spf=pass (domain: est.tech, ip: 52.101.65.29, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=eW9ZgfiGjGYQFGOLAFciUH2yJZB8daCwVlLaqeb2kDRH1RCzgMljXDWu9qxbpY6okyJ8o39/KQCgDff0lYFDX4tAWfoxEEYgQiWF5Uh+cpopAH1bxDz3p9Rxbr/Us0L9v9+kblItcBL9PP9JCVP/+9EeQFcVJKOZZkSy53hxUhHhxyD2/xP03HNvC3wpeRB3zHIfrNlhVPvtp87hVJy+ex9Rwug9cqUjJkR76STOMWvAERcBc/8hood72bnKy1eXtpCZaJgVAD7DNuHQJCBmZoGmShIq0V2kk++0vCT8lPe9lJ+BaeXlL+1iW7T3CnsmKDkDZnD6HyRQgQad3xgDpg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=RHH8z3XwbvW1s/jLnGEmOxm9glmJFm1p7AcBj9rM9YI=; b=DjNfgWdzD973oNJUAkoEDwYPcaGv2UPBYGIqEUfcOXa1kMtbRm2Cnr6T98QfOJDqMs+VztBjdYNUPeh5IqXJZXZ6VyF2VmM9IdQK3VL3Gn0MODZfpms9oRqR9osLzTaqagc2n3WLdx/w28xwRxnrJPlWWWXPhx46upp34Vth2sWCuCSYPwdoso1l5EVJHUeLL3/SfBRI5hw9QQJNCyzNHslbEqYrMPqGLrv8tozjiP95j4WyhTyXAK1varWoiX8o9rh+fm+ClDN5d4X5XTSKD2deTrX/jBhaW8rvVQeF1jznYJPSCCMSmPOwawpYPR/dEX+blTw4UuF1KwEoWeKouw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RHH8z3XwbvW1s/jLnGEmOxm9glmJFm1p7AcBj9rM9YI=; b=lujZaWb91Dlmbb5idw7PNuJQFrSb7piOR0UqbEXNLZ+lmi7Q9K+WjbUfGWglu70JrWzSAdP4p4LeeO3qS0DyxXLTbH1UUeEcTM5nuf+9KKWtc8ZcsB+93YkzjKVlj/FjI1/HA9e5oESouiDYFgIlgqW1OpUSSL+FUt/AX9pYOjb93YndyynMW1/2yd4IkDImzyMm1YkZzXvY3kMhqexrc914alVwpOsbUIrbUmtskSDrSqS9SswfnUlzNvG/czb7rCRLXL/vLtoZUhof3YeovlJ1agxAha7wKUjoI3loygvBHGLJyGZcz45A+mdTUVXGmIwDAzPW2HPU1iJdk7KrwA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:30 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:30 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 3/7] libpcap: Fix CVE-2026-31911 Date: Tue, 15 Sep 2026 21:16:19 +0200 Message-ID: <20260915191623.42107-4-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0085.eurprd04.prod.outlook.com (2603:10a6:10:232::30) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: ed505c9e-673d-4a6c-7835-08df135dd938 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: 1sP975fHve19YjlVRljgnwKaijo8YyD0N6i85to8tHhtKji7cqUhgST3FjRC0Z4kYKmikKCzAvPjndHzQFZMlHr8CcTAWF39gluaShfUl1+xzgjMu1Qj2Wko1VMPfUebsSpltSA9B7LC7dKxZ3+jpA1XjAxGHId8Ph+uVjDBDRNBkzXBH5F8+GvXbk7A38TF/C7il9NaUoJfISCiKyiyjNzG84DvB8b9bQMZ12OkupZjfx877aBNGt5k1LW5obtJIdyg/xlmDca10Ly5mGoHs4ujCGVW1kSjTJ6AaEHZ6287MoNLOTIQGl6GndX67XnQO8IelcR7rILyl0Qf9ewWDuBExZZEO9U7DK4jaNOxjqxEEQ/Km7n65CgNJ13Y7TnRQpFZqAzqlwCf13aQfxgbDFuxofcSfLrfhfcSQZ8VAJ3s0aK2vEKtnsgs5hIVBf8VatssqBl29hZIDcUnpf22MNSt1PDeOejm20bC1DcDyTf93ZDIIMW8V9EE8TFqFsVUpPgvLrQYl+m+A9oz2yXdcSeiFAcXVyImwF4grEyfAYHB7f+TWaJOhciXR7fDlGPOg6KBnCIkdjPHM+PU2sxUyoWSoSHcidlTVFeHKtaL9Tc= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: Yr7Iinb3VL41MEHIedni2yxwTHsJ/GQbXC94S3nfXD70t8hhk0yKWNX6mBti1YpkUvMZOXRgfHqgpMIKbg7lb5Dlnf5/QSuQZTMKs+IpOaGm6xx8fczrSxeD/0qOW9bwpak/kGkLbx2aG/V/sOFg/epXgINOUzJa9Kqp4eH9FKUPW5V4l08GW9lCt/rF9jDv2EEf1/Pcu6L03OjeTydrGDPEU9o6ieAYgriOG11QE/oPSwKov4rVR1+ddqbWpWmYUSP7iILDJfKOelwUG7C6dc6V2BsdVvmEZ2TE3rZH4nUSVrs7JgFt9R4Vj+RTF4BU6zJXLqK8bTZnlwXtb22A/6lF5DccKZIrf0E2BT/moGvQqIKZ38PZiUOcEn1ob3UMS/CmBDdbnDSVRb78Gi/lWDalitMtGJzg1kle8SfyK2yAIZBgekQIm6w/aRVe7ag7RbaVKHYTxlv5JFSkzdRl5VA0wh3KqluiRQLmeNqS6lNdcAjrbNmWbEHuQUEuoFba6IwnOp3f5MDpvkgevUG5RHT9q8dFsF5FOGCu0LRa1SsGtte6uo5BXbAR5jMMKPqR4LUdaSGBtjY6Og5jzoqRuBi/NmShyhE7pjd9kO3Qyr0WW6cGlvHHuW2cmrCXj69IK2NQx0iHO0BWGuqtfeu9S0JRrpbZ3uaW4gANBSMOq4/jyk7eFy1GNkqMRymcFm7+DykARC2W3+nrcWlzL9zK90Av2JXQ+wTYmXKJlaS5pn95pq1mYBlcHZ4Jxk9nWAOgg0pj9QuKshxsA4bMBBz+xysFVxSVIG+1cCdQaK0yBHT0dqb4XJfYRrFnkOKYLpKFcDgdcGCMYcFt75OguAumevDi2oS40hBC8DX5kc4eTKwqHPEngNfVC8uBZKHufb5NGJ+Wiu7GDH+NnZdTdAMIgFCq2YI/LPJ9IGjj7YhWBFBcXB1cMAVdaA9jd36ccwOEs3CZ4+EgVBYHN6+MlLGgfqwJt8c5IKtyrzSLNfkit8OfW35841ujMJQYFxG/GOdxVFlqnSxipqV8ZeMIlJYTkdWHEOtteEUj/dSUisdppOMa/EsohFMAT71OJ5gL3Z/IvV3EMzJMgQv5irDzUjsPbQXAs2Gl6E2fl2p6Sfc/4HMEqFq7YTa5Ko0bU4Rwo2lFV3hG+3LbrJEjfzPWJreReI3XCOiKOEgB8VpVPtl3TtB/EmycOo8toQn13EnM+ng3Z3tEQ4yJX70n2bVRL1FXtFAEOhoBr+mroAPD/G12Llfq1myvyxXCIiyj5JLNmodk2ihdOIpJeOmLM45CBlGqfN165UAcDlskzgpKtVfRtLKcYcqMeFRLiQOSqNF747BEN/z93tH09JDL8JtVjTvAu+yADPV++l8Y4RoPx3WfiNdENC0A+HdQoaWQn2kf41Xbe/h3aENOqLbd15gLZt0RPmj+tI9U0RiLa6vmh48orgmozaKMSoFfd2CEfb0rvu1iKB+0QiSOolkxS4TNJijZFhEZMIJSNHH4DyXBjBegBz7k9YmRZqyVXi4zohQE9vJdeR8umIR/crq02/KuS0/Nk/4ddDMx4YGVgyTrQAtfq38GASyQsuoSuaiQtuyOVvT3uIcJfE86Kj+eE9oC93McaGGlgcKoY5zw4FQ9su//PPykffa48Oo406JLqyK4Bb5X7U7wbGRAGBPuiWpIGA6a9a5VM0qu8jukjY7nafzcy3OMdbbimvc+FYxvorw41evwdmO1ykADFHvx8m7SxswaEA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: ed505c9e-673d-4a6c-7835-08df135dd938 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:30.8524 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: J3J2b2g/vgmKzSpvVq0Swn23lu92VJCtTfXDqhrtlGmLYcZ2/2hs3CfCVxPmaQKlLw+ccu0rdAHtC9ulsUbwwdJ+AbCrJexHj+Y93PEmcFk= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245870 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/03-CVE-2026-31911.patch | 45 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch new file mode 100644 index 0000000000..1060b3c372 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch @@ -0,0 +1,45 @@ +From 0067e8fd1f3caf866da3d95508831389f3b20e11 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:08 +0100 +Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + +This vulnerability has been discovered by FuzzAnything Organization. + +The current revision of pcapint_filter_with_aux_data() calls abort() if +the current instruction opcode is invalid, and assumes this never to be +the case. This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +Furthermore, this does not necessarily hold for programs that have been +validated by libpcap because the current revision of the validator has +gaps in the checks and accepts a number of invalid opcodes (another +commit addresses that). + +Thus in pcapint_filter_with_aux_data(), when the instruction opcode is +invalid, just reject the packet. + +(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7) + +(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9] +CVE: CVE-2026-31911 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 4f9adeea..f8b842d6 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -152,7 +152,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + switch (pc->code) { + + default: +- abort(); ++ return 0; + case BPF_RET|BPF_K: + return (u_int)pc->k; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index aa5265a54c..da218bd87b 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -14,6 +14,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ + file://03-CVE-2026-31911.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98344 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D262CC982CA for ; Tue, 15 Sep 2026 19:16:43 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.29]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4960.1789499791346222233 for ; Tue, 15 Sep 2026 12:16:34 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=ZMj1OO0m; spf=pass (domain: est.tech, ip: 52.101.65.29, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=jJBmFNGFUubCZVUozz0MlX2N5N5i8PS1ZLwzgb3bKd/pk5Cl14x4D5nBdeIWxb5FuK8pQY22ioECmoVP/1xViLNgHRYeC7bxJyku8c8o+s/w4z7LpwNM6MKGPlO45BNQKLVB2Hy8XGnWyE2eJc5Ej0ZGX6btrR9mk91seactXzv2uimw4k7ti08xPzinfPHAD2vcVuN6wmLrpeqccI12O0r3AtWjRUMPwOlnHYVSpbrf6ko6p3J390IeD/Kymi4PvFEsE26nJqzembaJiqhHHC3fAqlmKnbTerMGZHZU9HQwjEb8rxVjZNfIf3yFjXf2HRPamNQ+crwc4ifQ0gpqCA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=w8X+TaI1dwNFvM6UOU0gNUhwnitloxOMZ6wkYKKqvl8=; b=CnZsF+rEymE5/4P+YK6R1Chp5QB0/gBPnY41wyR/ARRH/+4HDZCe6mIxQV8FS1kvCMn+46WLNQ33Kenttf1oaOgyZTepfMBw7LKF6BKXwzqtcdYGOvPmwSGoJ7gq2qsazIL+TcxS58+N3WH++BC5FluoAW4nHTATmP8ObndzVwmG9e+kDA3/sIR2asjb+jNwlTzII+CPEqr8DzzByk82zAtp6Z3tnB2Af4DSF/ICJK9KfeajGMGkaRIX1nNRzuUuvffj+T+nkPmlSwdAFpxHjAyYUHhA3k0fhlYffEmAV1kDxQ6BEx4cuL9zXdpgR9CsVRuDWru37RtzEy0UWCcqcA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=w8X+TaI1dwNFvM6UOU0gNUhwnitloxOMZ6wkYKKqvl8=; b=ZMj1OO0mjm3htOAx0BYKlZT5qs1drQaDBBLbICWw8UNxL0Sk+X4/6aUMFJ/lah5HUBOnDMd00oV+o/iqqRHIaWSj7mIoIAqVGHuhmdvWtVqfY5a3wP5rilqrw1jCZ9+eVVDQZZS9MyIn/siWeCTEWXLsf168I/4OaMpaWHKq8rMdW7dAQ+1frUHuMOGL2Z3CZAh6dFNuPVv6R/6SzgPzs/wRIqPj9eZACtDS1SVt9SQBYY3lwGUMn+LrGhAevY/gF4Lz4Q7fCIkDtvhTWUzeZWpPhN99i5EUmKNh7snTZJRcmMbFEBAWVEef5uCwQhgNUn2Whc+UVhskO0UGzGUuZA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:32 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:32 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 4/7] libpcap: Fix CVE-2026-6244 Date: Tue, 15 Sep 2026 21:16:20 +0200 Message-ID: <20260915191623.42107-5-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0264.eurprd04.prod.outlook.com (2603:10a6:10:28e::29) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: aaa412b6-ae99-4e06-8733-08df135dda07 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: 0pM1ZwTUC1TQBCS2hfOyre1fVKXpjhXOzdT+0+gnaNfYtlkcJRpUgCZoDXbsL06qx9S2ZiGi0UKhoNOpceJamGIqHAkl22ei4B/5YQqofq8NE1vcTVLVRdFFd8SkrPQlmUN7fS6DCFw1AP8mM83wUjEDUpMgRp7+EQSwTcGUQl/fbye7py8S7/eBYywqZ0/mcnAofxxyih75Cl8pIkR54Yrnxvdh3JrIQMpVLpBAO3qLVmEuh1xnBsqz9mfwNqz1RzqPmekwYvgmO0NNQm5li2Ypfvnzv2nuHRMtlCwuEj+io12Ztm3wN3KsnjEmkam9rzaiT4ZAPMILAh5I3npcogIPkJ7eRZqIImA7SFJ8i/QkWTevsl5xex8kodRgYVhEJb7h6vHZPdWsKvMDP7o6bSjoBzTwXBoBCfszsypky/B6p6fReXoW7AF3oyb/+XvyvNibtIxPDLA9nmkc/OJkYYqvJmLtvWosodYCtX6AJ6qhdF1HzpETi3UbWo/+FS6yy0Qp5EXGQqWdqpcCdnPw8u8h/Z3VSa1dLHUlLebULscsKt3akip3D6JCQw8EU5nC7ciwlQPTRXXk8ueJ627iyp1frOccsJL7vijA1mPxaDDa/x0MOEwy7T/xr3ZQPt4X X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: cCSJxmt4aN6HnagNNe0ISCQauQvPVe2+54uA6NS0hH+AeVoUMP5U+wr2V2zbr/33dVN9GtgeT0ipzAqAGBXfXg1Zm5mtEE2Flm2cKANwdPmL1ghPMbCujjwKKYgmeVZNxopnhrJCLUAkTL1J5Pr6Rnhj3YuImD8jaZztHg6SvgvypQaGlLzHKAOK04bshViqEPRfz5Hv9+7byqB0ihXZzbBavFabSwi1QUA6ICI8AcIW8EwOIcZOBxlQHKPyXQin2M0jLoeszoMCJeh6qbsPMWWCxtUcdnsXp8jx0T3j0j153GhW3r1d0JPYgeS9E9WuVaWUe8VW2kLPl7/Knr1FYqC2ZkKKCDzTVUxxDO3cQ0uy4fZREp8jgExcZ6L8pIAsohC70ea6R/fgb0zYX+6ej4zuu4DRv9FxlglmmjS09lM2yuucZ9kEMpUOYix4xIAiI6MGwTZXBEMI9DE2KaWN3D+eqM+Uk9hLD5m4yFpZok/ByqR3j4NXQt63t6ZJXLsHW2S7xq6cMwWXJTPTfFY3eOLdHad0ZAgRfEj7HthzrLjzMyr76Tt5Ua2AxGgfaeP9197m9eDsyNDOonQrtYmwTHHHva6afpq9MU2J95bJ10lqatnP+29/0FqMbtZe2RpyVhE/5CbGzbriOzDLCJr85h7vVJlQLsRqyLdjJY/QLPOfnQ7MHkEKa20mJSi41rXdntLp4CRJ3ousgTeOne53f9RoQ8ubzedpDBr5OlLsA5RBJRue1EKmQmoNh/pS6TU70xUeiy6igudZaBYTQwdQQUmS1vhKkaNFFD5LAgmZzjZpHtcZiFFbqNOGJ1wQzIb1zX/RKOMmF52HaCShCz5Ia2wneD5hg4TUfLufJDXQd06LXNhJ8dnPPnAf4yl738/Ah+N4cJa2Pg5BZ4BpuY2JvDX+LG0SZgymffG4DLbqwDrf3zzBGT9dc3WgkS0skJloyNTvC4jA6z5gQ+nANDEYq/suulq/apni8rijcB+Yz2fCkJk+JS7I7ADk4vGb/obRt/AxSevDCl4Dj7kTN+xlMXdro5rXYkE4Nh9Jj0e1ZSDZ9Ldbzx6YYKcb6Ldnbw7f4rg8YIyvMdeaEL7cXypaq5vTYBq4bPt9BcfG0GitTpPcwG7zuEypOiRL6gCAHjVU0dPCW2kgHQVO+HpxweADkJpNb0DIxbqC/bYMVyi80sKT7JZYAt/YP1f0GsfN/9IAOXxOmWo+hgjeMun7a2oLq8kaHusC+E76cc/HIu/jy62USudEAxksf5/0HW25fND7hZfZufH9veC+S0YwxN3pjBHVqf6eMZa8F9vOPj8anJfDMBIiTXU9L5UYZD1rEfAtR0fnknhyoVZyDaxnKVOpjH2Y2Bxq0SJ4Dd16iAI+nShFq9hIHyte0HXXBKuPbsnZjxwCUAvnDa9LzTRpvPD8EmWMeCj3TakRxt+WDciLdm06w8NfHntonoWskTxWfkkAIC7CGEW7mkqy4hNG6Oe0Kx+a6OxhYb84YZEIb7CroR3WEzuiZrv6+z/rtqnN138BH5B0PEcLfOd69I/PPsujBDscca1vzNoncDqgwpjHdEoPOQyoKqosa0r9SKJUnuQKiXwTOivvX+HzMo1awfx7qu6jfRP893OR1Kiz9g4/EnVNTic48d80DFG++rlWmbtbz5zuPyHJmaXkcC2bcGQZXE0+wW6U3pRh3b1cfb6HSynuLEb8ynCzy39AXQ2VjXj8xeSd4WvOuLCiIQE2Xi2I7w== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: aaa412b6-ae99-4e06-8733-08df135dda07 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:32.1818 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: Aw1FA3PxjCorZ52ECXcI/Cz3uYkt1lsTYP3/U1+obZQTKXchGPHh25k2laHFSfMlAHeNbYZ1RJOvhsTb2qfpmMip36J2kh4laPVYltAfZHM= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245871 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/04-CVE-2026-6244.patch | 50 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 51 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch new file mode 100644 index 0000000000..b7fec6b554 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch @@ -0,0 +1,50 @@ +From e2f4d78f71237c44f730fee11fa0497b756e9d81 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:21 +0100 +Subject: [PATCH] CVE-2026-6244: Avoid division by zero via + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() for "div x" and +"mod x" correctly rejects the packet if X is zero, but for "div #k" and +"mod #k" it assumes that k is never zero. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program, it can attempt a division by zero, which will typically +terminate the process via SIGFPE. + +To fix this problem, in pcapint_filter_with_aux_data() treat "div #k" +and "mod #k" the same way as "div x" and "mod x". + +(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4) + +(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19] +CVE: CVE-2026-6244 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index f8b842d6..0178aae5 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -420,10 +420,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_ALU|BPF_DIV|BPF_K: ++ if (pc->k == 0) ++ return 0; + A /= pc->k; + continue; + + case BPF_ALU|BPF_MOD|BPF_K: ++ if (pc->k == 0) ++ return 0; + A %= pc->k; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index da218bd87b..258a15f5ba 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -15,6 +15,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ + file://04-CVE-2026-6244.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98341 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6702AC88E7D for ; Tue, 15 Sep 2026 19:16:42 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.67]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4962.1789499796613908729 for ; Tue, 15 Sep 2026 12:16:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=G0zADepB; spf=pass (domain: est.tech, ip: 52.101.65.67, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=fF9z/4JnA/fR8g8W7udZybB/xQD3YU9/4LMfna7DYjC6AQ2fk6DrEr+RYKzdlQdBd2wXGXoc160pT0vCPn74ycRJKWZieZmkSZcqLQM8Fu2P1FsdA2faInR1deaw3Qou41gbnjoIDjB0X8/zZiOiBFa06ajBEjfdrt16dmV8hpQHzeJEwcnOXWrnqa2OKAgMug0RRbI8nsJVe0Jmmu8n7L5dAXvnot2oD9DaQt0YBYB2xzzSJd5JgVtSwdkllJaEs2fWBRw7oK6iEM95znNGRFMH+f1f0J6oJCT+3zv7bbSXdd4RLOlIF58v/61yUaiAsBX8Dquq5qgy14O1m1gwGA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gg2CuQAi9qHPuP2grHuVKAMwCpPAGWyDbiE/4QqaHHo=; b=x4T4HUZYcTPyqy6xh5NEnXt28QiDHqe62UYDqpOLFJgfN1AM/kY068+U3Imbz3Y4Y4vmaDsxdIIjr5SLo1tzowj/M+ZKh2c5S+FgmJcY38jtqXws4jdK+bUtbeJIVwxofDpSTKGTwPhkWjG+b+yTGZ9S0XxudQFAhdo7Xyfl6RR+NEteHeUDzsaC0KcDrT4kbpKAte5Xq8FEBvewzBBnlN1ZQkDZ/EplBwANSxJXIXTLn3AL0Q7HgEPk6DM9/LtmzYUkjc7IsLs2bPFuREq6THAGP+8XZteUkXfrqW7ogEc27LGzQ08Q+UMIj2wkaX4c4Y8O6kSzOK3G45Y9bzQ3gA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gg2CuQAi9qHPuP2grHuVKAMwCpPAGWyDbiE/4QqaHHo=; b=G0zADepBp4ysNLM+khsomY9L8zXSKnueyPsO6daWJQUg6+eK44Ewo0Amfr8b5mf+i7JUWPkYRAXL4hpAtW/OeU6ASMGgZOAZ6C3S0ChJPD+LsOUUdFMuwgU1nYYufqqTfdRmJHgXMxXKKCDoGKY6ygiublPSzEauvO5su+kfG4kW1KFIuvFlYEvh4zV7QPd22OxrJBIHzRl2cDyngLCS51SigDQ6a4TboRV/SgdZjPwkSLt3G/hWOvmwqgZqCydEDXr86nBxwjjp1hIZ8MgdzaIG/G3V0i+SClbXYMJH90AvASe3x29m2nxwOvbxpw9sUxYXnHzvEw+kjkoUGUBMfg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:34 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:34 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 5/7] libpcap: Fix CVE-2026-6554 Date: Tue, 15 Sep 2026 21:16:21 +0200 Message-ID: <20260915191623.42107-6-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0003.eurprd04.prod.outlook.com (2603:10a6:10:3b::8) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: dc5b92dd-cb48-4454-c45b-08df135ddb0d X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: FJW3uMBi4bbzR2PFAFIYDOVUvtE2l+xTFtpnXCOn5LrrHt59XoD8PBsvPfV4CFdenzZGOvEYIKCNPOO3wrGDfaZpiEICLPm6+XcjzbZ1OXsEWrNmILNTX+JsR/uxmd9bHZ6Zl2NDWJRP5RjdsvksTjXhMXoQC0PwJwDqwQkNqzGFVgXp6eV5DrEWgK6cKDToBOx+voVR9JmLacUxBQ+nYk/gZM8SIA8QL+x4V05R9Uu3NOySlmgp/bjRuUZ4OZBeAC5qbjDlzLqW39hsnsIfLFTHpH7qmKt9JPpoGzOPsZXgc0EzxRJtGazWcNRbFFyLmu6iiVH70dtOp50XGWbCXvpQIlzHJlr5c8/e26z9+zRRl6P+padDWMHFb1KGxF3lx8Y7HwhMdvFdIunAQwSHmXnWw1tYdY5OMYVcX7qwouOgXgR03INWZ0f9NVXcjJpmb1kSXP7e1dTzoW00IIMbDpgD3935dFzobOqIwGo+niXJxqsBEXOkNxk28TKVFGG81X3QS8X0xn+R/cw1tV5nM8z/PSX/74ecFie2HGFBfGUCbJku1JyUr4VWh9iz+SHhD3YdxoiEGTT2sz2EPUwMZMcW2hvN5MGCjLBBamTR6i0pVDzVlQ2RQVfB+1Ta8Coj X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: mL3McEBPcMqiJWo+V4uUj8BK1Ck/n/f5ox6iHEd8FwbRuF2DG3lRY1KK69+toPwTr2ciyRXQaeP5HU+stxNtiMsNUYxGNEJfbdMqFklCZkcfWqjhsvAFCWD8exQvYmpyqNJipeLLEFvOLTWC8AbZEqIiG3k/vIZNVRWmTUB3z0EhkQDxipBwLCXMQi/2cKhfjqgsUsKlne4B3LGfNLMsJWKDT1wbJFP4MZc6FTwwZQ516OUjygsdyA3DJGKtiB1KkGo71h4YObgTWtrVVh1gtc3GZSaYOAaKlkdi/UUwNf5+A2nKBC6xsktRCdBOdZ2EXpEu2xbOeX7AlIFg4kOk7V/ncLOOV0wY0lYXp6LuuvF22CH/0brTiBBvRhnBTgrMFZDgnxLAdoTJwLTDV/l6XZPEbEo9Y8HLCO7O0bRtPEFZZ3L7HBSM1DQIYV0tcpMPlCFlT/yodiLeLZGFIih/s2GLlOo8eveZRfyeJ60q3L/FaiUVxWQQ/1DZHeNA9A349KKNvtNwcIYGGFfkmzMK9jRg8D8iQ1NQ7QSi3gGM3OL0YsT7Ln25ThQIMhnUHGaAdn0BtWzfycx4ScBvlBrro4EVKNm1R7av3Zi9oiDitses/EvTu4AClscIE3uxZYNTRGeRWqy1p7PlNtoFIarl2650rdKqPG+Snk/4thYMkgQyKQkN6yFg0p0gBM+JeclJdNetIYB5zOauzPi4wfQstmrpRVQh0C25UyfuyY+wWK4pHgbe19Xr3cj1H+au7ltNjyOjrTqtf03EAJ1gLdLyWyE/MOmdgocOUjPGcGlkv6zKPRW7vmNziCvLlIdlErIEvqyPvu3r8v7Rmet9r/6EPhwjCD9NODRffDNo5uMp/eu+yYRdacFyggGZiybvhUo2XllPaLgEKs/1enXO+rLaH8vo0R3cbe8yGWSDk7qS/ukLLxhIasmv/TbqDKlaE1uAWp85/MeJHUz8VY7vZZAngIFJsuMVEW0zmx05E3EgusjhjcCxPgzdrDgx54w9ppt6jc7x1BaV/F17smuDHqwiW8n15/7neTiqdKPkHNSrSIF5VWMgA6QnL9mqkZ+6D36F9eAkzeC/TyB1KJHD468QGiJr4mZv8j1fbyCNZocaGwaJB+hnpKtp2GshXvVFPDzryIVxDmkuwsl6IVqtBDBM5cQvYzI19w3/+eG4PR4E6BFDK27DU4bC6Gcm1i4auh82cL3X53djFZCWDQRFdvMIl8I+RCGpyiD+j4ArhNKVLSp0c6gl5E/dbJo1/tyN2QUt2d2whEGSYCntBVJLm5iMpiIVsZs1s292cdR0lojCqV8UHSEn+SE28IUcF+H9Amb4WWZIiV9nkgYOT2To42lW7iTButYnvdiLDM/lFZKfDayjl4EYaFbCC/qt4Ww2fcsGfS/rdnGGs/P59j70v/swbXf0x7wWttExAKwipZ51UsC2FaQBRsh8jtVM/HZ5s6xoBGoWMW3sHHHafsr35LmcYa9MVZX0q37GLk84EGB4m4PvOaHJLlaucMDEFgs32CykeUbIiYeyrmSBarGReQJ6/GZhEZwPM8TiD2cZRklnFtxu3HUed2s3p1byMP42uVbGDepZ0OfDFzhbezf7R7Ic22HRUCO0JYIWNXLWeRunyq08EEFjRo00E95IDw0Gc4M9LXPf6Cd2SMVahHaGqI2hdYcTpSi4FVttZKi4BMoMo4nTzVrR+1IQitl/pCbcqoCE9KQ2Gi4jkLuVFAhcJ4CgsQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: dc5b92dd-cb48-4454-c45b-08df135ddb0d X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:33.9631 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 9cYNffqK85k9WpSP/qEv0+25nGoO0gbAuMDrvaaZZnI+MJsZEqUVHuf90HAgvbctHfsv5cl74W2pdIBcJ+lTpafkhEMp79NhZMYfo1AN4fc= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245872 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/05-CVE-2026-6554.patch | 94 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch new file mode 100644 index 0000000000..208225105d --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch @@ -0,0 +1,94 @@ +From ee37e79521d28a04b09f5c37b835ae7955c15e75 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:33 +0100 +Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + +This vulnerability has been discovered by Kaixuan LI. + +The current revision of pcapint_filter_with_aux_data() assumes that any +"ja L" instruction in a filter program does not jump to itself or to a +prior instruction that is guaranteed to reach the same "ja L" again. +This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +If the interpreter executes such a program, upon reaching such an +instruction it will begin looping infinitely. + +To mitigate this problem, in pcapint_filter_with_aux_data() enforce a +hard-coded limit on the number of backward jumps per packet. Ibid., and +in pcapint_validate_filter() as well, reject the only immediately +detectable case of an infinite loop. + +(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0) + +(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce] +CVE: CVE-2026-6554 + +Notes on backporting to 1.10.6: + - The stray BPF_S_ANC_* enum removed upstream in 1.10.7 (commit ff47ba55) is + still present in 1.10.6, so the new MAX_BACKWARD_JUMPS define is added + alongside it instead of replacing it. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 0178aae5..bc6d149f 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,8 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++#define MAX_BACKWARD_JUMPS 64U ++ + /* + * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the + * userland interpreter in libpcap is meant to support much longer filter +@@ -144,6 +146,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + A = 0; + X = 0; + const struct bpf_insn *pc0 = pc; ++ unsigned backward_jumps = 0; + --pc; + for (;;) { + ++pc; +@@ -318,6 +321,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + */ + if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) + return 0; ++ /* ++ * Terminate the program if this is a non-forward jump ++ * and is: ++ * - a guaranteed infinite loop because it jumps to ++ * itself (exactly the same as in the validator), or ++ * - a backward jump after many enough backward jumps ++ * already made for this packet. ++ */ ++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 || ++ backward_jumps++ >= MAX_BACKWARD_JUMPS)) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -605,6 +619,17 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + */ + if (from + p->k >= (u_int)len) + return 0; ++ /* ++ * The only type of infinite loop that can be ++ * detected in this function is a "ja L" that ++ * jumps to itself. For this only k == -1 ++ * needs to be tested because the check above ++ * has already rejected all other values that ++ * would wrap the pointer equivalently on ++ * 32-bit architectures. ++ */ ++ if ((bpf_int32)p->k == -1) ++ return 0; + break; + case BPF_JEQ: + case BPF_JGT: diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 258a15f5ba..6ca75117e1 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -16,6 +16,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ + file://05-CVE-2026-6554.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98340 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 69A72C982C4 for ; Tue, 15 Sep 2026 19:16:42 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.67]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4962.1789499796613908729 for ; Tue, 15 Sep 2026 12:16:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=YrfbO7sa; spf=pass (domain: est.tech, ip: 52.101.65.67, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=iijknouU9ceCY6LhIZpVOwYhU03VrdI5/HuTFDmrpVaO4rOKycbMJzDBP6urh0G/4ouu7WfXYnrY7uwSEbkq51YTXxIQ8Q2SChB5IpkCs1VJzRRnKgsYP43nHKm4EmEWRgPWcoyCM2JgzBIgFQY8bNd5/YZ5kRAxEXtOIPb9ZXNEAwbO+coMAq6mYrjonuuFDI4/iG0CQtLEYpxy6QTM7+T/DcWC6uiNK+Q1iA/5gnWO6QG1/v0nhcSbvw/3jluQL5ndYv3M66uINPSylsn4+Mkl5K1syL68qu/S/LFG+pQsetK8ld+DoUxNb3SVvi3wXUBTuj9BVQlbQPjsi4oYDw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=bwy/U4B/f8L/UWjBD17MsuyTS1KS43v23ZWDEwJ1LdE=; b=hWvADtnZBgLBqcNJ6RcsYRfUVZp96+KhYCoKvAAL9iN7P9l2UqODVb1kqSp/oqRBMkdq05iE+5DP5EGOfR+BNl/bupU6L7n18QpODPiAzlRQSSiUnxB+P0ggm6CrlUWLyj6dshB/jbqHo2th4eKnAO+xhBpBGKgC36y321fJ8THyzFpXsAekBeQgwZiQzMYnQTWq+G89nkmM2v6CBCLg0BzRfzI0e53wUU4u5W81QX2r477KQTgFLClXwrAgaMZoPai/WzeAm0m9XzSsLjBccQnoFtNVY95dPmTzTmt2S5qUMfImQZ3o1oe1XUpigbnvvaOgKxUjKAONGbGbauEk+A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=bwy/U4B/f8L/UWjBD17MsuyTS1KS43v23ZWDEwJ1LdE=; b=YrfbO7saq/QethqRAJjK8WtXAFng5kKSmNVlXG8nTS4r5MpoSWSf2Q3E0a202ojzhEfG7T5SmKnKDNsUQuGSNSj7TsIHQ2Zjbb1dHEn2kXCxUeWZ32SD4OE6UVGSkrNTP/CAkjwp21MriTcXuJ3bWeVNsh7pd/jk/bP4sVpUcQ/2wK57nXMIIjeIBLhUG7WRBGaJRiKKg0Gk+0nCNR3tNDK114M6+V7BQ5uwXMVZdbelrDR+uqvhh8mwN2HxgO+jaVT4yDjzj9G/yTw5EKsCTwSM9o4ahY+vXtlS3Nvhp6PxjmLjMXdbmJHm6me1m358M5QuuuvrJpYT/ty1d8zMWg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:35 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:35 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 6/7] libpcap: Fix CVE-2026-18313 Date: Tue, 15 Sep 2026 21:16:22 +0200 Message-ID: <20260915191623.42107-7-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2P250CA0030.EURP250.PROD.OUTLOOK.COM (2603:10a6:10:231::35) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: 60ae6bc3-fcbb-46b4-ee0d-08df135ddbc6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|4143699003; X-Microsoft-Antispam-Message-Info: 15x4vf/bcYQeTKpZlYRbMm7OBcAaZRfEMsArFQjPEuWRd+GeqCwczKb53j2wL3oSEPEhjCKVybr5/C7wkAll1xs42pINondnxiE0SVl6QzAo/2X6sT6kRFLG8KBHJFbhtCJE9M9mSl+TAW17oXrIqsnUHjs/u8y0RSG9AKno/ADtM9h3LTuos2lNSXSSKT9MVkPFcBtfNEIBOVGvrQwMDZFCrHXyJItDiunn0tsuXAp1oglWiToeib3/xw0AcWO3bwtHGR6es1sV7SpL8lVbDILUIrwlQNYp4WghUQ7VzGwWj9uul/lFPAIojh/oUPsI4J5+ySE7CI/szxO6SWwQBPzbWSPqJV6LsUwd9IdzYii/lNDJDaHWD23ZLn1es7pWQeKdU2IhoN8/JSsh+7nfqvIVGTJnPnL/AakLg67bzhMPTSasiNfcO6mo+I7Ungtit+t05pCznuOrnijnIxvseFlctUF2g+TBY0SKeLfqHwI2Cp/PE5QpKsaf0N0gYMQd7R3RFmPoraQFkq9bJhzw03TKvnwxkmiA+UPrD4VGWMSeRwUjWvIQrwxrnQUs3XFW6S/bSKSagCFBtCjDR7NgSyowYNiT1W0kdPPDaQLKIQMvn3xQPbfwXzS5ssgUPYJV X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: AKfp9Q9w6KqPRaqhqFncRyYHpY2kIqQGOL6VEkBfPLOrORqS0Fw/ZJXxtel4OR2sQhB5gr5ta1pawvbra/ulTx//AyV+frn8Y8EVWhGDziYJJOtFYtOYvMLTTOuoHX3QGoT2mJJZsyl8ELDoN3gOaOKlFa452oEgvuDFvoijnh27LnKH42soJ8Y8Bh6NwXLfgh7iY2JzsAuLcc3WjiO+YBkFzrd9gmtWJDx/s4fmixNNxBadqXyThI3VjN9cVr2mIHrExtNhH+AIhH0s5cPDXv0mVp+AS6sl2m8TSOzqhy9owK7jT5WcJoOLNY8ewAteeoe8X9QdTba69SVLz8XCsLwqvEy1Lh/cN+aeBqGqsxitv1zeKRTgX2iawniNfCRzMmdk5nUTYXzY6mpiTxNTs0bQ3vcE3l5kRQyOmw209VgKxoM2N1cG2wQR7yx1yrQ24mn1TIqf7UJo57cXYc3HBA1WgVozoXpIW5gAcveZPDA75qoFnFnp69BV5eyBzlOgXw43BQJzObepNjAaBixCD9hb9GWuHj2nobdAqaTbuOjC11WzMB+Fc+DAgtaF/cOaMaD02CJeAbSBTpybY6axH+th8wPVZwL39/8hjNu/MhQB2P+2WoFhWCGTWah6IGBOhenK5/rePhoWaKQL4ymqkpvaPaOeVGUBGInDqqNYip+ZBR8c91QyA6NJwrY6bfIvzgVyznmE268YtcfJ9yMVTi/9LXKWjYQD5n7WopY6Zry7U/eSIFMOC8Jkk8BqQYx7Dbei36FDvYHpHEcFKgFXtg/UkfWe/0K1sxTlhRMYaUBsCEWoSN6AtcocrVmWwaxT5vMJxnwXXjmfex0JX+Tk77lZqjs+3ifKE3V+gpjuYE5GlvZrDY6svoVfBrxtfzBDIHyNOdBTCO2p4QtQnTulZV/It0Cqk9dvtY11rpPzXUQSriMxGV9paMwFTS+nBreglwCFkJrXXwdQRk+OUC5bGw9DjzR5U6WX9t3JJv1nBX7QakhCn+vOOTL6qDNDagh555J6pocs2zrVI04y5kO1eVYQUi6Musn/fv2k0ZKJiqc8bxhNujyu6dPoEjCslAa1xaMnMX08CPOd5IA1ci/hS2UZ5zMt6RHrwBne7Ci5krlaoNTT46QMuzOCWXHwREIPRVXBAFE16cNtoC3n8ekO1SNA5wwGG68Ol3adRbJ/u4cDDsOuvZ7YWMZplb9DidJdwZxA30zf7w45IMBHU7jNnBrojoDa7yNKWv3trWZKCpAXDVfoObGY4kAByrKsljpUJ5PxvRL0ZySKFv2DXWPNeiWdPB00oG34l1NKM8oFG9PRGz5Mw1LOOKQFczQlgnnNXBcS3+tzDYeQCTrKFJCYAkmupUZysIo+aFpFFMtTcC5z/kXL59szODc/nP0iJ9NLP7VyK5cjptU6vaVHlqZKWT0RCgg9eMPkkf03QeEHlkxwtQKCO/k4Qo391LhgSEp5qDfk6VapjPXPgGZy+VuRZghBEUmtmL7aoYTMjMGS76VYXGId4guMzbYJyc+lYnRuejuoHColILLGL5Gqyqdh/CI7HVOoijylEzDQ2vm2XMLsxDwZZiTrvmWAd3CoCDvuwrWR4n3Jw5laLebU9pXewsx/uO7vOJ1HaDeiR3UTEaS2v9Q7anRtbcLv+6416kHtDmorkS48cXKJipFfZEd+ohTLTt7PS1ArBwXyB4Jk7PKK47QKGr4YJ5udfrf+zxEu4JKYe29xQDgBjs0qHDKjVA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 60ae6bc3-fcbb-46b4-ee0d-08df135ddbc6 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:35.1318 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: gbsnxzed/EuFL+4rZL6hetnYE7pb5n+PSZjboNz4yFBwEydrN2aFE+Wi7LVbqCR4RAgDLNOxPTPhKudYvrPb7oYoFrJUWbwBEQD3BWeROF4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245873 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/06-CVE-2026-18313.patch | 90 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch new file mode 100644 index 0000000000..eae9aaa989 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch @@ -0,0 +1,90 @@ +From b039b8b66616852673c21ec5c7e0bad3190eae59 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 1 Aug 2026 18:24:48 +0100 +Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd. + +This vulnerability was originally reported publicly, hence no credit is +given. + +daemon_unpackapplyfilter() can allocate a temporary buffer for up to +RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each +received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message. +It never frees the memory, so repeated messages from a client will +eventually leak enough memory on the server to cause problems. This +holds for all connections that pass the validation and some connections +that do not. + +48 bytes in 1 blocks are definitely lost in loss record 2 of 2 + at 0x4844818: malloc (vg_replace_malloc.c:446) + by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372) + by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139) + by 0x114808: daemon_serviceloop (daemon.c:901) + by 0x115BC7: accept_connection (rpcapd.c:1321) + by 0x115BC7: accept_connections (rpcapd.c:1118) + by 0x115BC7: main_startup (rpcapd.c:709) + by 0x1112BD: main (rpcapd.c:567) + +To fix this, after a successful malloc() return exactly once, after the +free() call. + +(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b) + +(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7] +CVE: CVE-2026-18313 + +Notes on backporting to 1.10.6: + - The upstream commit was made after the "bogus instructions" -> "invalid + instructions" message change (commit 836d0fd0), which is not backported. + The 1.10.6 wording ("The filter contains bogus instructions") is therefore + kept; only the memory-leak fix (goto free_and_return_status / free()) is + applied. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c +index 87274665..b720cc45 100644 +--- a/rpcapd/daemon.c ++++ b/rpcapd/daemon.c +@@ -2380,14 +2380,8 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + { + status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn, + sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf); +- if (status == -1) +- { +- return -1; +- } +- if (status == -2) +- { +- return -2; +- } ++ if (status == -1 || status == -2) ++ goto free_and_return_status; + + bf_insn->code = ntohs(insn.code); + bf_insn->jf = insn.jf; +@@ -2403,16 +2397,19 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions"); +- return -2; ++ status = -2; ++ goto free_and_return_status; + } + + if (pcap_setfilter(session->fp, &bf_prog)) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp)); +- return -2; ++ status = -2; + } + +- return 0; ++free_and_return_status: ++ free(bf_prog.bf_insns); ++ return status; + } + + static int diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 6ca75117e1..859897acc5 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ + file://06-CVE-2026-18313.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Tue Sep 15 19:16:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98339 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 494AFC88E75 for ; Tue, 15 Sep 2026 19:16:42 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.67]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4962.1789499796613908729 for ; Tue, 15 Sep 2026 12:16:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=jl8xXtv3; spf=pass (domain: est.tech, ip: 52.101.65.67, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=emYv+2/9BQpNcjD1JpEkZ9DgCnFW7jUWawQrpPv5qjyuWpCwMO7AfsCQ9PG7k5dXSghMUKyAHaumnmGoli/HFQcNOUY1vg37FQKLvGMDSjCee1RReRG6X+zWt7zFJojqTnRLmJSDsJ0rDwBVAOqmsVTdV8XFAbvQSS+cR8Jd+U43xk+HuJx2grll88VPBRHBGEgBuHugyMOeBVchXW6pxbNj1kS+wztLilPiOhNSXfvqTSWBqqMfzCPKhDgHmpZmk5tXx4iP4mTiAZ1Zmpcd/mF2NUJhQ1+0lM0fzJrvFeMJCJfz0JSJVj3H3OBxXC435vJ/gLspBfYA2/gi7mkFLA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Dxj/upShgYShp30gp45iPXh/6oT+L4XV50+OnNeT30Q=; b=ElpvRBUqRp35J9JOV6CLCgv7vt+T0MBCSzqCQGgMjYV+g8e0ES8uezI9BkgENLkTh2kg1f4/MCHngNa++x18DC3raOfIkPTGXKJ12JHUW8+1badVvFaXSgQq/ova4Hi0397EwM9W/6SBxg8LABewwYw0DJB4gM/I4D715ZDtTY/qm5YCHohms+yQIche8ZRd5GDy0kuUcVMHKCMYj1w3qArMdx41MDIw7IXSv0mrrfUmZYkEV9M1w6n05zMfDq+MVqc5IfVCFP+L8BQjQqS2uH4dO/QOrOeQhQKXLxAXduaBILlDaZL7a6IanzVTLON1ex8Zq+4MhwrH6yt50HJ4dw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Dxj/upShgYShp30gp45iPXh/6oT+L4XV50+OnNeT30Q=; b=jl8xXtv3LNByj/JqHn9lYGVAaQzZGA5y/28AHOBc0dDz4hgPQbOc4oupLy9YBwqkujhng+3BpYJaOIlV8v878MEhpnyeUfolhzdViv6PFB1U72e8BBPe2uvQ2cVlUd6DhVJ5jOXJVrN9nxmgoooJkYE8x7Mpr1Tp5SlCZd/Cz292417fIVRcNeh2Wq+IFsV82C2+sO5y3uXC4B5APfA2bHYaAj53ezoSFfU2FP981nIWmNoJq+KUxVvRcZ9SCcUT9Ls54oD+HNTvUj1/JwMYfiKwBLXMw14+9rL2+T+BJVoJhs9Xh3C0ucSXJ+DogdyvMtq5HXkQeEyYAsidMf+MHg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by AM7PPFCA14042DD.EURP189.PROD.OUTLOOK.COM (2603:10a6:20f:fff1::6a8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:16:36 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:16:36 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [wrynose][PATCH v2 7/7] libpcap: Fix CVE-2026-18238 Date: Tue, 15 Sep 2026 21:16:23 +0200 Message-ID: <20260915191623.42107-8-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech> References: <20260910051154.30595-2-jaipaul.cheernam@est.tech> <20260915191623.42107-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU7P189CA0007.EURP189.PROD.OUTLOOK.COM (2603:10a6:10:552::35) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|AM7PPFCA14042DD:EE_ X-MS-Office365-Filtering-Correlation-Id: 075baef4-a4bb-4cca-b0c8-08df135ddc9b X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|6133799003|12006099003|18002099003|22082099003|13003099007|3023799007|10067099003|11063799006|56012099006|5023799004|4143699003; X-Microsoft-Antispam-Message-Info: qThsGpkyXbbxptgh55TmmzMxO8IsDUqyjzNKp4rA4RG7NguENf/w9kS/XlkY4NiWwCI/RBb6mdW7qZ5J82qfwLhd130+6jyQjzHAwtxjd8aAdbFbLWV07OBOD7u72dEsO/JTKD4rnHcHxraH83AMp17eK4ayEXkgI1qrz8MuExPBSHD1N/OVeM8eFqCJkSv6Hz1Yh5Y6cte1X/TWrDUVHvPx/Z+YNSADEPkE67naSPANhZ0afjqdVuTkEC5ToAGz+NwDqiqxCV8bRuDzBJcIzLiyEwI7Y0hoOXGHQdtximPT2ERZa9SHXFb1sPekuYqHDTorw6R1h66amARcE3PAaul1k4/5lB0tAIMC30YBCE3W+YsnDZ32CTsGPywY0KQ3iYgJmFSv9kGoU/fyVCUOP/rvfqpG1lTsqyZSnbccWuAvfR2r6CGi82yjFxIURlx0YwQdeYDNvG+QTu26ODV0/rMse185PvjMGxtKm+0TDXC38c/WUTLk6hVfYWDuQSiMTO8mnZlhCXV2BQHaEZzOtjymLE4RhjoIG+obeDg0EDoMkAFSOkL34SImB0vEd7HEane1WwjBtHm9OHbGdJEwAiJxLtNZpufLM2PoQnGcNws= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(6133799003)(12006099003)(18002099003)(22082099003)(13003099007)(3023799007)(10067099003)(11063799006)(56012099006)(5023799004)(4143699003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: ion5iZ6S//X/QA42w3/0w9AZO6lrkiZiJredLARfRet5NSWyjKxkQj3+jWQkb1gVrIe8SrHolvCak3baXoP/Seo2gcLN3D+gmEd87I1n7s/Kia/5Pm5iFeDlMJPYMZZ6QZLmU2GCQ7JXqGfTBezYaHPINn4ytjjeFpBEj4ffMGCqdLP5yk3Qun3KSXOoS9uV1VpaW5gUDH8B6FE0cnJorjMtXDL1Lbi54JaSm4y1gFf8dleWRoYSfnUsicHtPWkwPlVZMK2BqUZ5ZOH3mrRBQ+Ot7cXYcK8ahe7zuk6ZnHjPHTNZrf5zUy8tTHQX+ukkWyiQnQZYQn1EGdp0V+1l2gyntAky9Ko/tuQUl60XRaeOyN1TXF6oikvIIKUB+felLwp9kR1Uf/iJCUbi+9xfpbKGpHigelM6Xm15S3wUevYb2lJWGgnvJGtoKRmVrtXSWNr9JbOBLaRoWizI750+zSp4dTN/YzPaCBdN/QUAYEfi0ZhIera4DOsjQWhcCqQudwjkTIwImB9AeFgT0eFcJMwGSNCLgFOde7sTm9670Mn9XzhgKclHGLcl3DMo3M1teSTj2j/fK/0qVbY18DXd41ZD6PMtrlQeJSRzRT7OV8y+qdM784+sExX+YHjXbLIz8tNFn3fHNfKSg8VqwHnPmjjbuCUN+cccOJRnVjdBWnk8Q3Hui1mKLTtiSl5LRLR/K0OkIcskk5vdp0uYJvOI2kzvoY/es8tCYLo90xeHD4kjVrprPT1DL7TgucJUWxBOZ4qUDeIOn2JRLAQBqnsApFp75Q9wnFKMRvf5t3zqCK05bHCk5HkdNywcd+LRCWSPv/cECxi+T8TWCCnEUSDkR+x0dCxIVjCnB0IV0ryP2s9Zt9z3CKUeR8HoquwWz5XD6VTLKOwNphjoTM9TdpLnjo6Zr+k8cDgvtKqRonhfPYAr2GRHoyhWfcoMD2liJEAo/B44E5qLgDYvl6MTJoclDVHs/1WcWICVU1NRtBE3Y4SVbjzIXktzYHXIK55vc4IAA3n3ppxAEFDgI8jgnKWdve28a0cW88PXlvmZEX5fbMQo19wCjA24sdAj00im0s5RQlDGze2ayBfL+hGiSsadhBnUgwZiLHzMYNZW+1N/62KKW4USMyD93CaR9wUPV7w1mXzn/5Cz+IDMO6qZVbiQTI41HYoBsh0EQmvu5B8LRqHof7NG/jFVvyJ8A0QcwIRyiKn3WTfx57QDRTNtsmyyQYcMD/9nzwLrU/cEan0by+IH4kEmuAPJdjv2UF2ww+5vAC9o/+Te9S9pndZkEKlmd5QgcLJHuRV2WQPbCRxBKQ9Y7NYCgfXcrsqnl+70Cwl6QLZCJAdGcaacjgJmvNAxGJnegGL6YEwXdpsd9K9scrSup1ic+aZ13QXjubPrqAl7P4itOFBEK5QtJzQNh+sPU1Cy7Pre3ij0G5ExlWxHI+4HwqLYDxN4haU4ru90exLpkAOgWK2Bra1XhGqQm6iWzNnnq6h9J5RtBYRvLX1gALh+oRe5VMijYAkIXX8YoxGFEg2qwSnk1sr6OSAU97XcZnqNTr9QwqmCdQZC2huzksosIQ63KbO1IBiH2tRl7C/mHFHComfy8uxrELhaJjyDIEWVT8xbSMM1bJoLHvo8qLbP0MXNonsJ0tfOgopXzrUkf16e1lnQEcK3wYCabNn/bYZILE96kYGwVupNkgRDrEpnCdnhydtnsY3xNNT1ILf2/3lDgLn4Y1XIAaVwDFliCg== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 075baef4-a4bb-4cca-b0c8-08df135ddc9b X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:16:36.5249 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: vxrt7zfdfItgHvY+UIEPldl0viG2KvK0lqh+DfKPV4xJVHN1MnERpuJ/vZq06Hbpo9Dw+UmVqS0iMm4sgDrDDBWmLaZAC9jP8pUTQ79Luz8= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PPFCA14042DD List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:16:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245874 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/07-CVE-2026-18238.patch | 222 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 223 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch new file mode 100644 index 0000000000..d664f5b358 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch @@ -0,0 +1,222 @@ +From 5aa9cfee8eb44967dec96199fde879022e4426d4 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 8 Aug 2026 00:31:10 +0100 +Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + +This vulnerability was originally reported publicly, hence no credit is +given. + +When pcap_read_nocb_remote() validates a received message, it does not +verify that there is a complete RPCAP_MSG_PACKET header in the rpcap +general payload, also it uses an incorrect value to validate the length +declared in the RPCAP_MSG_PACKET header. The latter can lead the +protocol client to over-read the message buffer by 20 bytes, which in at +least one scenario can cause a SIGSEGV. + +Fix this problem, as well as a potential integer overflow in the UDP +code path on 32-bit architectures. To make message encoding and +validation easier to follow, re-jig a few variables and update comments. + +(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9) + +(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473] +CVE: CVE-2026-18238 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/pcap-rpcap.c b/pcap-rpcap.c +index 8f8960b9..b7f54641 100644 +--- a/pcap-rpcap.c ++++ b/pcap-rpcap.c +@@ -389,10 +389,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr **sockaddrout + static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data) + { + struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */ +- struct rpcap_header *header; /* general header according to the RPCAP format */ +- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */ ++ struct rpcap_header *gen_header; /* rpcap general header */ ++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */ + u_char *net_pkt_data; /* packet data from the message */ +- uint32 plen; + int retval = 0; /* generic return value */ + int msglen; + +@@ -449,13 +448,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + + /* +- * We have to define 'header' as a pointer to a larger buffer, +- * because in case of UDP we have to read all the message within a single call ++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large ++ * enough to contain all of the following data at once: ++ * ++ * - a fixed-size rpcap general header ++ * - a fixed-size RPCAP_MSG_PACKET header ++ * - p->snapshot worth of bytes of a captured packet ++ * ++ * This is sufficient for all code paths below. + */ +- header = (struct rpcap_header *) p->buffer; ++ gen_header = (struct rpcap_header *)p->buffer; + net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header)); + net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr); + ++ /* ++ * Step 1: to receive a message that does not immediately look ++ * malformed, consider it as a fixed-size rpcap general header followed ++ * by a variable-size rpcap general payload and require: ++ * ++ * - a complete rpcap general header to land in the buffer, and ++ * - the header to declare an rpcap general payload length that fits ++ * in the buffer after the header, and ++ * - the complete declared payload to land in the buffer after the ++ * header. ++ * ++ * Since this step loosely corresponds to rpcap_process_msg_header(), ++ * which among other things converts rpcap_header.plen to host byte ++ * order, mimic that as well to produce a valid argument for ++ * rpcap_check_msg_ver() later on. ++ */ + if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) + { + /* Read the entire message from the network */ +@@ -471,6 +492,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + /* Interrupted receive. */ + return 0; + } ++ ++ // Require a complete rpcap general header to be present. + if ((size_t)msglen < sizeof(struct rpcap_header)) + { + /* +@@ -480,8 +503,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + "UDP packet message is shorter than an rpcap header"); + return -1; + } +- plen = ntohl(header->plen); +- if ((size_t)msglen < sizeof(struct rpcap_header) + plen) ++ gen_header->plen = ntohl(gen_header->plen); ++ ++ /* ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX ++ */ ++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header)) + { + /* + * Message is shorter than the header claims it +@@ -496,6 +529,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + { + int status; + ++ // Receive a complete rpcap general header from the network. + if ((size_t)p->cc < sizeof(struct rpcap_header)) + { + /* +@@ -515,27 +549,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + } + } ++ gen_header->plen = ntohl(gen_header->plen); + + /* +- * We have the header, so we know how long the +- * message payload is. The size we should get +- * is the size of the packet header plus the +- * size of the payload. ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) < p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX + */ +- plen = ntohl(header->plen); +- if (plen > p->bufsize - sizeof(struct rpcap_header)) ++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header)) + { + /* + * This is bigger than the largest +- * record we'd expect. (We do it by +- * subtracting in order to avoid an +- * overflow.) ++ * record we'd expect. + */ + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Server sent us a message larger than the largest expected packet message"); + return -1; + } +- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen); ++ ++ /* ++ * Receive the declared rpcap general payload from the network. ++ * ++ * p->cc == sizeof(struct rpcap_header) ++ * p->bp == p->buffer + sizeof(struct rpcap_header) ++ */ ++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen); + if (status == -1) + { + /* Network error. */ +@@ -558,27 +600,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + + /* + * We have the entire message. +- */ +- header->plen = plen; +- +- /* +- * Did the server specify the version we negotiated? ++ * Step 2: to validate the received message further, require: ++ * ++ * - the rpcap general header to have the correct version and type, and ++ * - the rpcap general payload to be large enough to contain at least a ++ * complete RPCAP_MSG_PACKET header, and ++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload ++ * (i.e. the captured packet) length that fits in the rpcap general ++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header. + */ + if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version, +- header, p->errbuf) == -1) +- { ++ gen_header, p->errbuf) == -1) ++ return 0; /* Return 'no packets received' */ ++ if (gen_header->type != RPCAP_MSG_PACKET) + return 0; /* Return 'no packets received' */ ++ if (gen_header->plen < sizeof(struct rpcap_pkthdr)) ++ { ++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE, ++ "Received an incomplete RPCAP_MSG_PACKET header."); ++ return -1; + } +- + /* +- * Is this a RPCAP_MSG_PACKET message? ++ * Validate the RPCAP_MSG_PACKET payload length declared in the ++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX ++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen ++ * gen_header->plen is significantly less than UINT32_MAX + */ +- if (header->type != RPCAP_MSG_PACKET) +- { +- return 0; /* Return 'no packets received' */ +- } +- +- if (ntohl(net_pkt_header->caplen) > plen) ++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr)) + { + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Packet's captured data goes past the end of the received packet message."); diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 859897acc5..2844f4b2a9 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ file://06-CVE-2026-18313.patch \ + file://07-CVE-2026-18238.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"