From patchwork Tue Sep 15 19:45:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98370 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 91F3EC982C7 for ; Tue, 15 Sep 2026 19:45:36 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.7]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5557.1789501526272473796 for ; Tue, 15 Sep 2026 12:45:27 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=HS9wZTf2; spf=pass (domain: est.tech, ip: 52.101.66.7, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ZWoaufBQFBpkAK0pHaex/dnaqCbQdVShgRfqsM+tMHYRsbv693MDC3t+/XWLea3JOj1rYSJEEznOfhLnbDSApxgJka9WEe5JGnXIwdCg4U6xoY+jJ6uNqwKHJuDdr272Bg8OOmbabEwJlBTGUjIpek3F3tYOVwMxmlIGn/BgOYklWZvZnAeT/xpPRiUdvX9XorZV+E6DaTzZBqq7/MmcKYn4y5jEp/auZDXWE6xkoPBaqrXXKseoPwHbzykaPqImv0RhVcpB5GB+LAATCY75legjVXUb3F/4StFw9DfaFB2Tzjjor2TAGIszqiRwWYCWLV13ldRLoKfemNf9LERSJA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=1yTSSqyQmLERakG2YBE1ox4fQxaWgVs0cM1VBi5WXyI=; b=oAsO/GkQ5hw7u+NNrxuiSP+hZkDZ3vX6EmHH7e9Sz/yWAu9LMlSf/WVmzFjhHINulXrZ6hJHTqCsaCM3xiLuq+NAUzCoxkkWHiK0dW11Cjy7l3iEvGL6ZdQRWM3HhB1tXy6eT3fMVXLMufuyNvsOBFOmumJKsuI+i4jXd3thAXNqT1IXb9hg94b/L7Vu+ek+XoB1ZLL7szMkUW9yTViPIPY18bmIT4R8aUQGd6MtpF2V3uMPxrCjmBJM7DX+glpJMXOLQxH2RG3yAynxKNYZLzl3V/A2HVRDVu6MUNo1UxQB2b8BE17g/ceeSlO5wSxJiFspJ1rG6T9p679chz8qtw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1yTSSqyQmLERakG2YBE1ox4fQxaWgVs0cM1VBi5WXyI=; b=HS9wZTf2IpLftyQJt8s5lNQ8iiGTQFc8TpVvgY3Ie4sAN39xlGOGCSXTzEt0dA/F4FoBGiDtlxPPUYKRGF4Mq1TcKRt97Pl2Dt1s5RTzRFxebbtbQavBooQBYXsdoj4pImNr/wrVkHcavZG+PbP1iKCVVfjzkIRE2pg52C7RpSoNtbPFvlXwGT9lZ/Hna3+tY4WJnqIopLotIHaKiHR+hMRWZn6T9wywMEnP+rXF+VBNK9Oiwdl8eU4ThwQAO/13QBrS8OOzbFGPHRQTj/ZfhkJ/jXxUb9gvjnBone3aS10e4tw55rGBsU9fOip8+eg4R0PuMZKrYFqa9a7EFKXMog== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:23 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:23 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 1/7] libpcap: Fix CVE-2026-0799 Date: Tue, 15 Sep 2026 21:45:14 +0200 Message-ID: <20260915194520.45847-2-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0317.eurprd01.prod.exchangelabs.com (2603:10a6:10:4ba::27) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: bcf3d3a4-e13f-45d1-abef-08df1361e21c X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: E2wOl+j1kSYxls8y/Ggeq0mRchH/3a02B/rABmDCZJbwI+jygM2FSPdZj1BD14F0Et1QOy9thQwObynYh4eRZpXnji8FAtlXtcTxhcVAWAljdC7pQK7/pg9Vt5BqlLQzm4C0/mU9IjBL8fBJdI02unUNWxOCLVssI0l7DYTlNrY7eeXHwEH5QymGwl4GAgSiW8DQn/HgV/uKVdD8ohpqvoz+G0NDcg45y8b1MAymjMCs99jC5CWnNERyhufGfeSpGuC+eG+7pOVgtR0Dg4WQf/J2PMVL+vUiynUQcPyr/Zbt52jngQmEr56QHz1Z1UREQzV+dFtH7NuWwp91V5MiZC3sZQ6MTYWB9RWu9vfZKmcApSStoc9ZMHW9WHn/cX8OCiKunNrDJrwK0XLozTaEqBYJRaBtfbyTcTvxkCZMNrt+ywH37eXe046rbi/PY6+MGOC32c/7VNs/6uPZZvtUWarz6dexaE3GbheK9PzV1++IcAWr6rclCOOW+CmiVFar2WUPFznInnkdSF/ZWDrdMpuJspEroEx6F0qa8y5DQb1sh3yfv99RcPNnHSYoepio/OMP7WK2w5zkdqPFIFwHnjaA1P6InhV4HKxFTPi2WwdVIDpajP+h1qYpmTjA1X9D X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: qk2cEAK1Zw8DBmImqvgnb3MpMNBoGgAcDKXuioFmS7VhRmATaLtx87a+c+jUficRBipY7IdTuJS5G/HKhN/xFB7w72YatbIqZba+9KHttKrOHOaORXkmA2xPd4zsp3HnNvSsatGN5UAiHCP/6C+aQiZuBVXOPC9SSfkOLXdnq+RgBwO+9krMSxX/4WAqnnEm1GuEvE6PlAiNfvJfm/AnQFxrJqnm3L/1aKQ892GyNcVeGZQsFQuaT0NuKNkmDQ645bDlykP1pYzJEofgHZLksfhZnfr8jlXKpPaxEw/tGObYumvh2fdReyqVxGyyyfi4v8u0dFc6rIeAgxhc3XzO0oL8HpjwCd/lXhtYYobPIIJg6Oj3FSMFaFhNiD8dUtl4aftWi8r3dycYO+4I9BjRniyP0eN5emECO86rMbol5zntFKTEekdOtpT0jyTMp6BnrsWU2oqGG/Q1sHFNYet0/LEH5ZAQsQHs9FL7VrIaQq2exGDuiB02YnWeWS2Dg5nuC3/7a1/SFYeYL28ZPV3GVYHH58mEdKbT/zf/3APR7jDWHZkzx2ul9U0I3AfX/mXyWfVE5DOVUsr16pRsokjQQ9N4royICMjpfVE9vImMII1z9d3D+AnbQ19ITqBtbJYgcy7K6PTN0alJnCHg8M3qStMHzjIV1s2Ew5+Wo8tOvjf3rxfXf56Y9+TtS4IcnwqSNnRsax0VkO8vQ/YiglIXZe+iC0b+pqfoVCdq7q1N7VzdCHHQEMxKXdzXa/QwT8B9yxJbhs8Su+dJ2Y8s1PSaqGZXM/SZaBy9JrrErZhO/te1hKyXvQazBKTl8F9vOFV2g6/xEj6lI1nBy6TxN98z7UWtvSSM3lb/Oay979cZMv7ptdcvBqd0xFf8ZaxBRlLExuaU+JAtYiAM5HbiNFoF/clvlg7uhCKvNklZMP5Gq3zp0HMpA2O1Wmw1YpmdUw1RtZOlhy1VaX8b0YIr1vEsVpyjQytRIyZsCNE0f8SnxIC69DHjCi5aKV6kOnXJpt52OiGliFWb4C4UORCZudISZhcmS4yL4sfh5aZGQ49/+SZDgDLPSRp+5A9jevVrNwXLS3bpYcvmTs7aF7SW08YwG0UjKe0CZFTobB02QSDZO5xzxGSRXlizYAuIM+A0njX3sanLdA6vhonlvAdyihH0msO7t9sVb6ji5oVIdqWdBk8/F4pYGsCoBz5tY10O1pIVs57Ck9JYKWPoydLBRMsNzSusHume0RixmvqNdmtA4SKi4IaQm4edCErHfTPYnCXT4U/fNa+7TO/IGUpwhlOA6rp5fGHGDFiNd2Fl84VKAe7tLjNmmY+9x3ZWP3JcXJXhta2cYL6nc2W/ciuArGQDng/Z1GcRPgCGUOCvlwa225FlXkIUWBt27LpnDlwbOmRWajk7jrUPUhdamD/mefNyZHZ+/zlbI0onThbSEg6iUJzpryy92WFABxth4aKq3L6Q1SYOfF1Qo4VdQMvlf7HJlkSdw2vpRTvZHUtwnlejDxi003JOQDbRQC5n1kZyGP/jL2McARRImeae5Y6XFzRtITGiXwY6K2/y0XVxad2dCCk07X1WbX2d7zIAsQQP/GIhHBNY2ZxFKX6SM9/udSu0B93VpAIoGY3Wr4scYHsHYbKgr81xkEcUSOjQAknjjPX6p+1FsnP/fkBgzYYAWlf9p4BmLfNUNqAhK1qKli9moKRt0xeWddd0hhoHxbP7l09pmvQYvTcbVoQjgcosJ1qvFQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: bcf3d3a4-e13f-45d1-abef-08df1361e21c X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:23.7322 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: dmF40FAqC43iKzHOfFCsWWb01CbpJ7sjLQZFCzypQgY2ITjkOUOV39mUUCZPBehqNVYAgOt3ZEnMn7wpXunrgXEpe/wXScaSHfBipWnOOko= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245892 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/01-CVE-2026-0799.patch | 64 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 65 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch new file mode 100644 index 0000000000..8651079d0f --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch @@ -0,0 +1,64 @@ +From 48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:41 +0100 +Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter. + +Include Security identified and reported this problem as a potential +vulnerability in 2018 (case reference "I7"). Their work was sponsored +by Mozilla under the Secure Open Source program. The vulnerability has +been independently confirmed only recently. + +The current revision of pcapint_filter_with_aux_data() can, but does not +check whether a scratch memory register index is valid in the "ld M[k]", +"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this +is always the case. This holds for programs that have been generated or +validated by libpcap. + +However, this does not necessarily hold for programs that come via +pcap_offline_filter() or [deprecated] bpf_filter() from an external +source and have not been explicitly validated. If the interpreter +executes such a program with an invalid index, it will read/write the +process memory at arbitrary locations starting at the current stack +frame. Depending on the address, the memory layout and the OS, this can +result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To +fix this, in the interpreter reject the packet if the index is invalid. + +(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a) + +(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7] +CVE: CVE-2026-0799 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 8691d0d1..fa82d1d0 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -219,18 +219,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_LD|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + A = mem[pc->k]; + continue; + + case BPF_LDX|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + X = mem[pc->k]; + continue; + + case BPF_ST: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = A; + continue; + + case BPF_STX: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = X; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index ee7d7540f6..692fdf606c 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11961-01.patch \ file://CVE-2025-11961-02.patch \ file://CVE-2025-11964.patch \ + file://01-CVE-2026-0799.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98373 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D789FC982C4 for ; Tue, 15 Sep 2026 19:45:36 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.7]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5557.1789501526272473796 for ; Tue, 15 Sep 2026 12:45:27 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=bmhBBbqm; spf=pass (domain: est.tech, ip: 52.101.66.7, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=rD/r+/ZOvXOpvkqrL7plasq5PjuPIw9PN0tXzKlgC9bxTj8rZ/W7SbD1d7MXjXU7t+cCjRjXzfQt/5Mi25Xp9KJx2swFrpHHboZvT7dCZWzJaqhzXx7Cavg4ZozOUo8cdaIEU+Lqns3kFMlMPWqd5Z+nWkuQyhkrwdtK1T2vqVuaBHKhyX4uwrbvg1NNJuBlXoNfvZ5ukqHpRfrgB+OKCxKebdnfxFE8ho5cc6G6/XgcoSMeDS4+I645soyMtZ1BKiM2H39tt5SibM1NjFlnspkTzHfsqPbyEKhwA3+oHuYDc7zKnf+O3XeML5Y7cgjJuN9agv1/tOcziQD1KnWX+g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=epFr9pwU0M1g0CGRObxLEWeLqG75am9U8XIp+BTsKQ4=; b=yHjSqQb3Tqxo0OR0ve2AiPAgMmeHKM7z8xg5nSlsmZ6Zwhdn8LJl0jK11B1JYQfsg4aNVnNn7OUH3nSIIZTtnfka6yKXGZEKJ+51rBvuwyPzs3DgMQBr4rX5JWcUU5/hHFZka7YZVmt9k+TMFv5TYix0Wv2bKFyJ22/eZETk+J1oPQLFn+cyBnF+qryYN1o6QCT9PTnwVUWLwo8Bv4ZZFejW4d5ffL56MJKcTDC3E8uXKJRV66MDz0hOsRAvU7CDo85jPzn1Rwi5zO6mCDE0RLi5o6z0Mm/byMa3/bp41mogwaQdWzaCI8zvQBZy5EgQiOa85clp4FVQuys4KYehxw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=epFr9pwU0M1g0CGRObxLEWeLqG75am9U8XIp+BTsKQ4=; b=bmhBBbqmg8i/v8c9HVfIlbRiNVlJvEihX7VrvF0bsv4Am/wFadj0iMWrc77vGgz13awZ6SgA8yKaonYgn34KbrxExG32Ft6YuKLtBtyUqwn7a4DlPNHQlzwcWzMW8HpkmORyFnzcgu+8PvwOdzN74P5aQt7MSLmGP/y6Ne6u8o0y7zpKO0AscXi5/qcBAgoalielvA0yEVPVQa8XEA85S7KQ3uD6JWNqXjELpXv+1+k6myH0M+S/7ENSjjeOiansGUJz7s+uijcD6t92D86j+R3tFdE3ViyVRfGiuru+SAnAEU3KFPdRoJClqKF8+hGlrSbvpjQd3+Nl72oQg4UY3Q== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:25 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:25 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 2/7] libpcap: Fix CVE-2026-31912 Date: Tue, 15 Sep 2026 21:45:15 +0200 Message-ID: <20260915194520.45847-3-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU6P191CA0069.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:53e::22) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: 14d765fa-88f5-40bf-a0d3-08df1361e2e6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: a5o7xswQHvVLaVbj5nzErYFXTrETdCnV+djVgELgDrd01jBQIYhbxV0cSwmKfPfY2c+35NjrVd0zj5BLhvCBOG5lA6yiPc+WGiuf54rQ25qd+RYdrAIc3auhxeZpt3nDa6MuoaBNGbsgW8gLSi8uy6fUAeegVbFmzy7kIt2mcoyzASvIsJ/qf5gwdq6TCDzBj/Hm2d26gFlAN3dxjkER5NKbV3EdStYZofW+LeCZm7BhTJIiz8Gxmeu+7ukOMnEXbGc560wKGyCTQa0jFxHEVnI68eP6yOXINwDz3Xn0d8xKy+ToFpKVQvqW9TWsgwsZ3J8PZkXsaCQ0Y76bjTAhDXJ2kbKtGM7Gg6B3mJvznC/oR8rI4kNHT3bNH8FNSTmfXL3W9gSaGn4qyjMYDYJv8S8nlIk1ziW/IoA9OO7uJL6CO/mZDsrToyi2EVo1F/kOxk3UMPNwHdq++659JRk18NhK+TI70sK8IlD/kG/4FUH40PAQOJzc9Atat0gYxKQZST+mwROaOYTExIkyHITAY1kC3Xv/jK1lfhg60sItuD96N6ejC4QnpmVR75B7WR4YMP6zEjjRAWwImdULJ3owgHwDp0aFIZVUdbIyriepjio= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: gsoLFep+IIgHmRvXne9DaTsTLefhv9bEV5Fz6QQhqs0iBZRkgq4H+bB0Qu7q1qXD7D8a/0rjWuvrbJYKLOBwVNAxuOpnOUrDcIwWChAYu5WhGGuunZTwPuJ3JSncPBPw++/NjBwZ1IMlRFjJFvLKeAe8lOb96iItSBXRic9HlT95maVA+TlGzHaSs0II9/gXzepTeOX0gl3k9H533NSsoWw0YVDGlbmuUCxpn3xNF9lIVIlMiGdIgi2dlmLcDoco3iBDBP9dpZTx9FxWMivxLniwsZa+L7Z4+B5BhvvtaWXTV3GR8RhlaZmhHdKxE8PPkBpm/BsffvKVvPONttPDM7inELyTIZd2szDPWARZqTs7vg180tU/nFa/KxhYwaoRl9jdsRYF0ZGQDVCJOxmh9GhsNSw4lRWHNt7CTQ1d+WOuD1asTUd3lGSYiRvKVDfN9rnMPoo2EVz4sRstTy2cbl0QAFBVq/5/sXfhL/Ox345FtV4+X4D3KqfZx5csiFyN/D6ADHob+NlqG7EZJt79qwRnAC2KA7hD4crbg9k1D+6jlAIsyVDdZfR4pkCmbXsubxE6axROaK8w1a3oj0Coiia9IKB2EigqlaSCnFQvlZMb7T5XmOQr/vxzqegvnH/4waFZUeJrbMfv/nNqDbpQx+2oT9a+cakl8JK9sx7xcHSuXggKAOOTzNtTpOLg71B6urCB9lptjKKiOWBcwM7alvTcSJEIiGKHixlAxlESWwJFrFcMLW1m+Fg+Fv30X1isiHxkK0J35zHGxhWPaZkzSfp2+XMJSnGOX/CWzNZHgetpufNpU6j8eQwN8UIK48u4Aeqc98XecPkPOKqSBh2DM7LaGa9+Aou79W0fSPxAdy23Xp44P+q6pO4fkmZXJ/gdv2ZlTyt5nDktRRpMaeJ1y3NKofzqfsDkp/NgUnsnUMRuwLbY1tPYZVpdz+hTwhodgWuzQL1/D8OQVcPfGNRSOl9fEvFHXzZE1R7kWV1VXEurZLoqShAyGSA/iKt4ipKconBjTHgOgBfHuIffyLLsf7wrP0sKFGgYSZ8VmNfljGfVuxYg40wgRuvBzY/wZQH8g7CdrFrpY1Jymj1ubdtONDc7Tm/U1sLo3X02yisPjXs/JJjLExGCKQj7s6uGgEOHkanxJ9ejPf5KjYRJpPLxDvdIVe78D7FgDxFcVgxaxik/XoyxGysac9Xyqdh5daSQfb0UjreEARTLToIzfFLsCoBWxFugccipb3vgCUlmKLUnqKGez72ELU7Kj6cT4u8dTl+N16soZaIV6SYF+KGTM2ClwTFWDgPPGGZTxIV/2lUNB09JbhdFqutW+J4cPFU1yyM+QvO2rj5tLezy68917M/w6+HbOtAvmtEpcTuq3fSWtp0UeSz9p/juqKs7TMXpF08kBE74E3zI4N/qJV6LOooglKUVmIUz0MMUd4cT3t7wHz0FBBXQDR9m5zaKFhfVfgEy40sR7bwYxR2a/uN5h4SG6VF57/KUf1l7HUsA83gQVqYRMq8omS0JuvjY0WW41SErqTUfxCTfISuXI5OSLmaykxDHrXJ/Y1T6WVOQS1hYs0FNLdrkZ02RBCgLzYyspP2ZwV1AZkSIIU31Tq0pUBFMW0JvgM03ConL04TC3b6255LkcaA298L664TXcf6+uDUZlt8Pr0Us4ivq9TjuUZesv7nOT5DRQRwiOLi2wIQv0/KpVbR+iD1QUoybIMjQjMSTSQPAi+1LRBqEo3wloQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 14d765fa-88f5-40bf-a0d3-08df1361e2e6 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:25.0716 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 62ECNUInwwcxBUPh4HcK0moQStomoJkyNa8NyHIGXeVUb7AkShjRrhuu1i+/nqEeVFkvvmitnqp8q0Zr1AqNpoY0+KihZ7YjBNDj7+Zu1SA= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245893 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/02-CVE-2026-31912.patch | 520 ++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 521 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch new file mode 100644 index 0000000000..1173a4f9d7 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch @@ -0,0 +1,520 @@ +From d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:55 +0100 +Subject: [PATCH] CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() does not know the +number of instructions in the filter program, it assumes the program +counter always remains within the bounds of the provided filter program +and always reaches a return instruction. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program and advances the program counter beyond the last +instruction, it will be interpreting memory space after the filter +program as BPF instructions, which in the current implementation will +eventually cause either abort() (another commit addresses that) or +SIGSEGV. + +To fix the latter problem, in pcapint_filter_with_aux_data() add a +parameter for the number of instructions in the program and reject the +packet as soon as (or just before) the program counter goes out of +bounds. Update all incoming code paths to specify the length; also in +pcap_offline_filter(3PCAP) make it clear the function now requires the +'bf_len' member to be set correctly and uses it. + +(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551) + +(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9] +CVE: CVE-2026-31912 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index fa82d1d0..dec336ea 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -72,6 +72,24 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++/* ++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the ++ * userland interpreter in libpcap is meant to support much longer filter ++ * programs. In the latter case it is important that BPF_MAXINSNS does not ++ * interfere with the safety checks in the validator and the interpreter: ++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX ++ * It makes the most sense to be able to interpret as many instructions as ++ * pcap_compile() can produce, without optimization, for a valid filter ++ * expression before it consumes as much memory as the current definitions of ++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost ++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit ++ * machine. ++ */ ++#ifdef BPF_MAXINSNS ++#undef BPF_MAXINSNS ++#endif ++#define BPF_MAXINSNS 3060000U ++ + /* + * Execute the filter program starting at pc on the packet p + * wirelen is the length of the original packet +@@ -86,12 +104,14 @@ enum { + */ + #if defined(SKF_AD_VLAN_TAG_PRESENT) + u_int +-pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data) ++pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data) + #else + u_int +-pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_) ++pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data _U_) + #endif + { + register uint32_t A, X; +@@ -101,13 +121,36 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, + if (pc == 0) + /* + * No filter means accept all. ++ * In this case the value of 'proglen' is irrelevant. + */ + return (u_int)-1; ++ if (proglen < 1 || proglen > BPF_MAXINSNS) ++ return 0; ++ ++ /* ++ * Require the current instruction pointer not to overflow for both the ++ * filter program (where the pointer will be dereferenced) and an ++ * immediately following margin (where it will be not). So long as the ++ * margin is large enough to represent the destination of any single ++ * conditional [forward] jump from within the filter program, a single ++ * guard prevents all filter program over-read attempts that result ++ * from the program running out of instructions before a BPF_RET or a ++ * conditional jump directing the interpreter beyond the program end. ++ * Unconditional jumps mean a larger problem space, which the BPF_JA ++ * case below addresses separately. ++ */ ++ const struct bpf_insn *pcend = pc + proglen; ++ if (pcend + UINT8_MAX < pc) ++ return 0; ++ + A = 0; + X = 0; ++ const struct bpf_insn *pc0 = pc; + --pc; + for (;;) { + ++pc; ++ if (pc >= pcend) ++ return 0; + switch (pc->code) { + + default: +@@ -243,6 +286,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_JMP|BPF_JA: ++ /* ++ * The pointer (pc) decrements and increments in units ++ * of sizeof(struct bpf_insn) == 8 bytes. The number ++ * of units is in the [INT32_MIN, INT32_MAX] interval, ++ * hence the result can point before the beginning or ++ * beyond the end of the filter program and can under- ++ * or overflow; also on 32-bit architectures it can ++ * under- or overflow more than once and can test ++ * negative for underflow, overflow and out-of-range ++ * conditions after under- or overflowing at least ++ * once. ++ * ++ * However, it has been verified above that the program ++ * length is sufficiently small and the pointer does ++ * not wrap within the bounds of the filter program, so ++ * there is a one-to-one correspondence between BPF ++ * program counter values [0, proglen) and all valid ++ * values of the pointer. In other words, after this ++ * unconditional jump the pointer arithmetic result ++ * will be valid iff BPF program counter value will be ++ * valid. For the latter problem the solution is ++ * almost the same as in the validator. ++ * ++ * The main difference is that here the current value ++ * of BPF program counter is not a 32-bit unsigned ++ * variable, but a ptrdiff_t expression, which is ++ * 64-bit signed on 64-bit architectures and 32-bit ++ * signed on 32-bit architectures. However, the cast ++ * to 32-bit unsigned is safe in both cases because: ++ * pc0 <= pc < pc0 + proglen, therefore: ++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX ++ */ ++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -396,10 +473,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + } + + u_int +-pcap_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, +- u_int buflen) ++pcap_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p, ++ u_int wirelen, u_int buflen) + { +- return pcap_filter_with_aux_data(pc, p, wirelen, buflen, NULL); ++ return pcap_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL); + } + + /* +@@ -419,7 +496,7 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + u_int i, from; + const struct bpf_insn *p; + +- if (len < 1) ++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f) + return 0; + + for (i = 0; i < (u_int)len; ++i) { +@@ -485,33 +562,45 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + case BPF_JMP: + /* + * Check that jumps are within the code block, +- * and that unconditional branches don't go +- * backwards as a result of an overflow. ++ * regardless of the direction. libpcap uses ++ * backward jumps to implement the "protochain" ++ * primitive. All offsets that mean a backward ++ * jump in libpcap (whether in-range or not) in ++ * kernel BPF implementations mean out-of-range ++ * or overflow forward jumps -- kernel ++ * implementations must reject that. ++ * + * Unconditional branches have a 32-bit offset, + * so they could overflow; we check to make + * sure they don't. Conditional branches have + * an 8-bit offset, and the from address is <= +- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS ++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS + * is sufficiently small that adding 255 to it + * won't overflow. + * + * We know that len is <= BPF_MAXINSNS, and we +- * assume that BPF_MAXINSNS is < the maximum size ++ * know that BPF_MAXINSNS is < the maximum value + * of a u_int, so that i + 1 doesn't overflow. +- * +- * For userland, we don't know that the from +- * or len are <= BPF_MAXINSNS, but we know that +- * from <= len, and, except on a 64-bit system, +- * it's unlikely that len, if it truly reflects +- * the size of the program we've been handed, +- * will be anywhere near the maximum size of +- * a u_int. We also don't check for backward +- * branches, as we currently support them in +- * userland for the protochain operation. + */ + from = i + 1; + switch (BPF_OP(p->code)) { + case BPF_JA: ++ /* ++ * So long as both 'from' and bpf_insn.k are ++ * 32-bit unsigned, this check rejects any jump ++ * offset that points outside of the valid BPF ++ * address space of the filter program no ++ * matter whether signed interpretation of the ++ * offset is positive or negative. ++ * ++ * Note that this condition is necessary, but ++ * not sufficient to get correct results from ++ * respective pointer arithmetic in the process ++ * address space. Other necessary conditions ++ * are that BPF_MAXINSNS is correctly defined ++ * and enforced, and that the pointer does not ++ * overflow. ++ */ + if (from + p->k >= (u_int)len) + return 0; + break; +@@ -539,12 +628,14 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + + /* + * Exported because older versions of libpcap exported them. ++ * This function is deprecated and unsafe, use pcap_offline_filter() instead. + */ + u_int + bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, + u_int buflen) + { +- return pcap_filter(pc, p, wirelen, buflen); ++ // The actual length of the filter program is not known. ++ return pcap_filter(pc, BPF_MAXINSNS, p, wirelen, buflen); + } + + int +diff --git a/dlpisubs.c b/dlpisubs.c +index 6815b0ec..790acf28 100644 +--- a/dlpisubs.c ++++ b/dlpisubs.c +@@ -195,7 +195,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user, + bufp += caplen; + #endif + ++pd->stat.ps_recv; +- if (pcap_filter(p->fcode.bf_insns, pk, origlen, caplen)) { ++ if (pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ pk, origlen, caplen)) { + #ifdef HAVE_SYS_BUFMOD_H + pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec; + pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec; +diff --git a/pcap-bpf.c b/pcap-bpf.c +index 2898e598..04b5620d 100644 +--- a/pcap-bpf.c ++++ b/pcap-bpf.c +@@ -1255,7 +1255,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + #endif + */ + if (pb->filtering_in_kernel || +- pcap_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + struct pcap_pkthdr pkthdr; + #ifdef BIOCSTSTAMP + struct bintime bt; +diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c +index c7bfef1d..dcf3b575 100644 +--- a/pcap-bt-linux.c ++++ b/pcap-bt-linux.c +@@ -394,7 +394,8 @@ bt_read_linux(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char + pkth.caplen+=sizeof(pcap_bluetooth_h4_header); + pkth.len = pkth.caplen; + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c +index 206e65b5..3f9d5b49 100644 +--- a/pcap-bt-monitor-linux.c ++++ b/pcap-bt-monitor-linux.c +@@ -151,7 +151,8 @@ bt_monitor_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_ch + bthdr->opcode = htons(hdr.opcode); + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-dag.c b/pcap-dag.c +index f261ead0..c3fe1dbd 100644 +--- a/pcap-dag.c ++++ b/pcap-dag.c +@@ -668,8 +668,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + /* Run the packet filter if there is one. */ +- if ((p->fcode.bf_insns == NULL) || pcap_filter(p->fcode.bf_insns, dp, packet_len, caplen)) { +- ++ if (p->fcode.bf_insns == NULL || ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ dp, packet_len, caplen)) { + /* convert between timestamp formats */ + register unsigned long long ts; + +diff --git a/pcap-dbus.c b/pcap-dbus.c +index 506f150f..760bb9ba 100644 +--- a/pcap-dbus.c ++++ b/pcap-dbus.c +@@ -91,7 +91,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char *)raw_msg, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char *)raw_msg); + count++; +diff --git a/pcap-dpdk.c b/pcap-dpdk.c +index 025a6748..cc31d2f2 100644 +--- a/pcap-dpdk.c ++++ b/pcap-dpdk.c +@@ -407,7 +407,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c + + } + if (bp){ +- if (p->fcode.bf_insns==NULL || pcap_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){ ++ if (p->fcode.bf_insns==NULL || ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ bp, pcap_header.len, pcap_header.caplen)){ + cb(cb_arg, &pcap_header, bp); + }else{ + pd->bpf_drop++; +diff --git a/pcap-int.h b/pcap-int.h +index 894e74af..11ca3c56 100644 +--- a/pcap-int.h ++++ b/pcap-int.h +@@ -619,13 +619,15 @@ struct pcap_bpf_aux_data { + * Filtering routine that takes the auxiliary data as an additional + * argument. + */ +-u_int pcap_filter_with_aux_data(const struct bpf_insn *, +- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *); ++u_int pcap_filter_with_aux_data(const struct bpf_insn *, const u_int, ++ const u_char *, const u_int, const u_int, ++ const struct pcap_bpf_aux_data *); + + /* + * Filtering routine that doesn't. + */ +-u_int pcap_filter(const struct bpf_insn *, const u_char *, u_int, u_int); ++u_int pcap_filter(const struct bpf_insn *, const u_int, const u_char *, ++ u_int, u_int); + + /* + * Routine to validate a BPF program. +diff --git a/pcap-linux.c b/pcap-linux.c +index 13bd8529..b2b2ca70 100644 +--- a/pcap-linux.c ++++ b/pcap-linux.c +@@ -3993,6 +3993,7 @@ static int pcap_handle_packet_mmap( + aux_data.vlan_tag = tp_vlan_tci & 0x0fff; + + if (pcap_filter_with_aux_data(handle->fcode.bf_insns, ++ handle->fcode.bf_len, + bp, + tp_len, + snaplen, +diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c +index 2eb0fc8c..5b5f5c18 100644 +--- a/pcap-netfilter-linux.c ++++ b/pcap-netfilter-linux.c +@@ -259,8 +259,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen)) +- { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ payload, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, payload); + count++; +diff --git a/pcap-netmap.c b/pcap-netmap.c +index 27d36e5b..bcfd6e93 100644 +--- a/pcap-netmap.c ++++ b/pcap-netmap.c +@@ -81,7 +81,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf) + const struct bpf_insn *pc = p->fcode.bf_insns; + + ++pn->rx_pkts; +- if (pc == NULL || pcap_filter(pc, buf, h->len, h->caplen)) ++ if (pc == NULL || ++ pcap_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen)) + pn->cb(pn->cb_arg, h, buf); + } + +diff --git a/pcap-npf.c b/pcap-npf.c +index 99b5981e..a4364353 100644 +--- a/pcap-npf.c ++++ b/pcap-npf.c +@@ -682,7 +682,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + */ + if (pw->filtering_in_kernel || + p->fcode.bf_insns == NULL || +- pcap_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + #ifdef ENABLE_REMOTE + switch (p->rmt_samp.method) { + +diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c +index d63ca898..c8763b33 100644 +--- a/pcap-rdmasniff.c ++++ b/pcap-rdmasniff.c +@@ -172,7 +172,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u + pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + ++priv->packets_recv; + ++count; +diff --git a/pcap-snf.c b/pcap-snf.c +index fe9cc9c8..16ce9c8e 100644 +--- a/pcap-snf.c ++++ b/pcap-snf.c +@@ -192,7 +192,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + if ((p->fcode.bf_insns == NULL) || +- pcap_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ req.pkt_addr, req.length, caplen)) { + hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision); + hdr.caplen = caplen; + hdr.len = req.length; +diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c +index 726e4a8a..44b2bf30 100644 +--- a/pcap-usb-linux.c ++++ b/pcap-usb-linux.c +@@ -735,8 +735,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u + pkth.ts.tv_usec = info.hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, handle->buffer, +- pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ handle->buffer, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, handle->buffer); + return 1; +@@ -904,8 +904,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch + pkth.ts.tv_usec = hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, (u_char*) hdr, +- pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char*) hdr, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char*) hdr); + packets++; +diff --git a/pcap.c b/pcap.c +index ef1bbb71..9ee83f98 100644 +--- a/pcap.c ++++ b/pcap.c +@@ -4179,7 +4179,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h, + const struct bpf_insn *fcode = fp->bf_insns; + + if (fcode != NULL) +- return (pcap_filter(fcode, pkt, h->len, h->caplen)); ++ return (pcap_filter(fcode, fp->bf_len, pkt, h->len, h->caplen)); + else + return (0); + } +diff --git a/savefile.c b/savefile.c +index db8a3aa0..e9708b23 100644 +--- a/savefile.c ++++ b/savefile.c +@@ -687,7 +687,8 @@ pcap_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + * and, if it passes, process it. + */ + if ((fcode = p->fcode.bf_insns) == NULL || +- pcap_filter(fcode, data, h.len, h.caplen)) { ++ pcap_filter(fcode, p->fcode.bf_len, ++ data, h.len, h.caplen)) { + (*callback)(user, &h, data); + n++; /* count the packet */ + if (n >= cnt) diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 692fdf606c..323cca3d98 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11961-02.patch \ file://CVE-2025-11964.patch \ file://01-CVE-2026-0799.patch \ + file://02-CVE-2026-31912.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98371 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1CA7DC982CA for ; Tue, 15 Sep 2026 19:45:37 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.7]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5557.1789501526272473796 for ; Tue, 15 Sep 2026 12:45:28 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=Ubt8gSIp; spf=pass (domain: est.tech, ip: 52.101.66.7, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=K21c4wVLwxhulfjeg9C25DxuBeYP9YgRxwJLQtMUfWmn/WmBsAd9/SID+7J3snD4FXib1Y+thuSpIajEpoBd1zlmD1koEvK6XwtMczN51zgWlNzg9ym6QOs5DSsalmmGWHPFStWCUIlRXGalDFZOY/7AsP4j4cJlZ1veCKbPTmwwZVrW3Kyk7tSPIjihp6FNkLgnzC4a1b48KGOnXZR6W71otJvt2Qwq9gUAlRZveIphxydRWCEXy1o6KMEt19QMtFQepIzI9O1YWgwdT/qewjnfBouT+a0TziyCgxfLUakSbqZM7IE2iuxl2Uh2ffdjwuQi8alHn1W2If4fYxtqug== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gwbkjW/B/k6ixh+PPHOcvSydbNpV8x6SipxprSkPatQ=; b=p1lmBdB5ZP2W1o0a9YXRdYy5O7siab1ypwsARN5zRGQPwWXPXs+gkp0CFzylwcRHCbYm/msDxlIqMG9Iiuo6TmopCa3KHdleuA5cvwStYTQnV6uxSB3pPR+WdalYlgOJIo7l3LZ13j5j9Typ+hjwMopxbSnHvriW+xBir2o4EDR1rLREgx+Sr7DJ+yfd5Rls03LCgwU5NNP9IHBimU1aLLQ11j5H6Dq+f9R0s07Z6oDl0KkmWcM8GturirYLY5NcypvCavQGfJVyL5IN3YeXQ/RWNKQDJwZkJf2NpTL+oKWfTuCrQD4yGZ7z+3GzDsN+LA53057mtfppz/YX1jXqRQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gwbkjW/B/k6ixh+PPHOcvSydbNpV8x6SipxprSkPatQ=; b=Ubt8gSIp33YMjGOTNO8SL2QankQUFc7sI2bVsSJAfb2ib7KUHSXbpRIjaLVMdNZ5B+QF+Ifendi8ncQu6Exhd3t08/62YxpzhKNaOMtZtlvItSU6FLvg9d8QaOKMubAto56GDzLQ3dQZlJiQ3xFDGKsm98tFpSPZzLBr6gdd4GaQ4hdbqYT703uvLyXZrJlfMisOh90sU8JK9i0GzfJHtwdl2hPmkLrpo9MlwVM4JZ1n7gLgu7b4P2qGV6jgIO0VwQn5sEmIYpMN+Idjmw7/jOm9tejvwLpjWGxRBX9Zz7PVwj4v7vlAPkiu2ySWyLfVjPclObEMmwMvrap37nsBdA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:26 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:26 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 3/7] libpcap: Fix CVE-2026-31911 Date: Tue, 15 Sep 2026 21:45:16 +0200 Message-ID: <20260915194520.45847-4-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0059.eurprd04.prod.outlook.com (2603:10a6:10:234::34) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: 5ca8bbb5-8ecd-4070-f762-08df1361e3ba X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: 7GFWlkuYGvnPCurc4p+y379M42Qnrm2RZu7xO1Kll6gSwMHR3gh9erKOK40Mo1bZnEPFug5vamT1XP1LvD8OH5RJJU6B2ZPwkgZ0iPRTaqy5iNulhiGxdM1wYDBWYJhYEXWC2Trk/was0dilGmEOG6SlkE9rOJFa0Zv+CRb8gHys82Gtf5vZVFtlSZ6f/a4e2EAb6MkqWySf9ors7iPk3Qzf26f/chO+C7frgUB9p90hOePL8pIJ1M3KTJiyy2kuNWA7PRlRLQoUCLCPvEY8BB8j+MZ52BKXhfiCOnN3tOuHR2Nm8DD/MemJGZDg9lmfkG9ucqGHLMVjvYYX9bCeZLMRys/wXO/2ITSHGFKTKTATfUB9a0zBM4T9u5QGvDOP4dtfWGoBG50pKpqI2AEQhoH9oLrBD3ZyMnrpcNPXUCjIw3ehhVvg3eIvvLALpK2s57G2Ro/H4iV4FabUe2IuGXKSP3zpx4mirw6JPudDUqyuC3bwsruGgRTLoVy6SxkbT+XtVYFaYivkwTPeNp8drfEuHs/pwkQl4xTp5meqAlMKpdLEMPpjHJYDK3tk58Vq6zcONrcKe4/qq7hXIAZAa6XVzDJGpmyZpGQxIqwa2GQ= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: Y+p/Yd6PsS6zWvIE9sCIkakK5rbSg9RS4NMsGtyJVTKR4oH8+XDZ9OjJEYYIJUzsmRu4+fQdGUVqLP4Ac25J/lBTkWMwKFb/F0cFOMht7aIwxjrytOR2i74Z49naN7woaBW7MjN6Yz5is3nxRycifivnPm7pV6CUOECHwEdcFxDgG4WH5Nk1o4cL4ogsAaWrSQja2I4K3s9850zykA1Kv3GcbammJJGp0qkpvpoVxPc4Tvb5o0k9gIYGZO01Y+ea63XZGZTAjZh0hfhBtxx9U1OSCZH9g+VIO3Jr3QJr8WyeE6cZemA67vkv7MwAB7if1WFRtVCvdsB7O25o9oBVydabAmT/ySIFzMxreh9JLAdCFfcKIKWWUq97QIL/3wXIICmENaJTViqyLvey/ORE0y8JeUk0JfFKcWfvLoERvN1uGKhLikWp545l/oY9m3yvbUJYf1RA1dLEBfXp3yM88RUitVTMRafO7ve1Yz9xmicXOy04GyLLp7EERy5MAZe4aOgXAUKD0B2OCvgVPbfeEZyJDxUakecL3W+8E3jDTRXCtjCMrKWlO4ZX3kZBolB+Jq7SvC22qZAeMN7c4YjHM7ndsNK57zo38uwPmGIwy1bWDBoPjUQqap3Z69jEOT04as4ROL5uNL3+KRtz8m77McflnOT3IB0PzZMA/8cehEZ8IUqDMMiQ7on50gtGUb/6Zq/o8fIIk0XlIgNhXflX1lW48rpp1sRN1tml6nuq4qg3EpqoILvJzJDDS/FBmwssgDzSLtsnDyfvENi05bfsoz7bcorzdDWm2xMvcB5bWeq2v4a97IlpXfk7B48ESWsC1dLfNqZx/+O+pjdkcJs3Z7qvKB++89qUu1pxdTWOks2haYYisa6fTTo+GD5Zmq7aI0OHbTxXwnAGT//agYVN3NphdO2noXAB7jNs2l29OCSgauOQHDRC4/V5DAx+erNpMfz3fRfaCSpUa2hvp9ikp53ALefLyv1TUDVi90S505hPKDxvX8gq4m77s+YCFurChelO5qT6u9MPFOJ2txeM+9z+7m4pOUY+xcu6VybS1QNiB7rKyfZnJU1KC4gHV9uoXRIHXCaMNcf5bkTb2MmB0VAnTc0kY9F/r+zSovczdgVoe5djO4WN1ejtKDoFQEOaPxzhF5lvQwNdgjJQW70++/P0UP1pl7/u+RqnQ1CyxEvkyNQ77NaKHAeeIpXSaOtIG5EwGI5yLBLiW+RbIwugr695nIPJwhmVRbxLXKXFDU0aymq3Htr9UVPBCJykW/6VEXePPBuYgsyfVrBs0HYup9zHje2Z/FIu9GpmGFOjnNNncbtikgo2rw4xj09dtVipCJHdYXMswiGozFabFLiJ6qclGifAJhebiybF9yh06KynxZRMHKi665sOZsu5qpH0CsK5tzLO9USica2+zz9ZF0XY6dLVdjtuiziS/yf/0wRdMPMZKF0kJU6mutMFlQN4R/Uc2/SfE8gjoP9XD3VNwCV9lvcTjBlqFGEKXgGwjnL7DL9KuhgXOwjSR4pvOA0QF4/Qp2ASRc96BM243+ruXWHUnYUiNmuUYutz1iZXYsiiVWwQKdvnoevrmDGPgk2MqQbjAhx0qAuXencHrfu9Oq9yT7f/rs0GyMt+ldSftJgqcfEVdkYPUdW1I/nwak+PVGsE6QUejsGYN0SlPL8SDrdMh67NT8UW8Gsm1mJbqAUhBAcsKHT//NMcYHJs6TTlliyOUlyKKV4dfcLUJsyFzw== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 5ca8bbb5-8ecd-4070-f762-08df1361e3ba X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:26.4489 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 5wxRnAj9Vs8WAgA5MzhoNcvpwLJHgNkCYFzxYh4ux8oF4hybrdwbuRkCA2NXe3BlZgT3VbNLJeBCC8ztAP/UW/hHW3VVy4dvERPk6WhbUyY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245894 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/03-CVE-2026-31911.patch | 42 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 43 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch new file mode 100644 index 0000000000..ccd470ef7e --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch @@ -0,0 +1,42 @@ +From a715bcdde830299cba4171514385cb17ec19b6e9 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:08 +0100 +Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + +This vulnerability has been discovered by FuzzAnything Organization. + +The current revision of pcapint_filter_with_aux_data() calls abort() if +the current instruction opcode is invalid, and assumes this never to be +the case. This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +Furthermore, this does not necessarily hold for programs that have been +validated by libpcap because the current revision of the validator has +gaps in the checks and accepts a number of invalid opcodes (another +commit addresses that). + +Thus in pcapint_filter_with_aux_data(), when the instruction opcode is +invalid, just reject the packet. + +(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7) + +(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9] +CVE: CVE-2026-31911 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 2ea11d46..d6e4b019 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -146,7 +146,7 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + switch (pc->code) { + + default: +- abort(); ++ return 0; + case BPF_RET|BPF_K: + return (u_int)pc->k; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 323cca3d98..5b97c14e85 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -19,6 +19,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11964.patch \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ + file://03-CVE-2026-31911.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98372 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38B80C982C9 for ; Tue, 15 Sep 2026 19:45:37 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.7]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5557.1789501526272473796 for ; Tue, 15 Sep 2026 12:45:29 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=zzzdbk81; spf=pass (domain: est.tech, ip: 52.101.66.7, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=BnNYjnKcuUjKHR/dzfyIv7D/vCZQIiVAPInLOUJXur55wks8Szfh579goJK6EvKqREpvjUFAPaCWU6iN1eEuu1TOUOh82/3DxJmsp7b4hwS40KKDSBqCEEUzjktAvlI3gGg9anhdNXe15mAtVJIVBbXP0PQTqRCn+G0qj0UgeDPnWxcQHHB961F3ktfkB2yv0JQdbRc24gowCH5uG1Pip2qSvqbt7vKz58ey7kAkMxeH1oCUlF5/+wrrZfUzB1Ypt8cdyo0AG6H1ViJKgtsxPCVNbBD5TwmrosEVGEUcOn+V71/YofklObImiQ/ry1RxQUL5TvlhjI1L7f7nTBAk7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=pOmfwa1dMyiH0eZaSkczzfyle9EdcWJL1GDJkXmN368=; b=ATJ3rhwLyBe0WhBR72GGFPq5nnn1I0MVmldCTpGuEnqge05GZBNYZrDTSll2XWJTrgBnCEp6Wbgm82USm+m/n7A+mhWOORqDvojv6sDSpwZ0HAg2UnmjGN1l7nNAOHEXy4/Xi8Mnzq5j/HbKqfsY00JKHQyrWL8TxrOYm3r2UoiCeqEc268ZIXPaI6lE50etCwiONZ7CMtpxe5p5G1SetYSBDvkLqJoR+IUIvNPFjFPqDOWINrgzDQdUT5uMMr+GlSxXuqnx8CybB9qToVBY0OrEuIppGBqshdTsFzMvIw2ElCK1oU03cxWIbaGqF4vB7m4ymmAnbtJ5B69NM6PYkQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pOmfwa1dMyiH0eZaSkczzfyle9EdcWJL1GDJkXmN368=; b=zzzdbk81aJR/o9UiN648ZFlWR2hv/2o382LYtfm3Bzgh10hketGHoVohNdHi8RnxDwqa93ArOgfntF7mTvL73Ino19yplMoI9WOlNnJqaKKIgOc/5K612inCZCax30iC2UwZx12Zsu0i64pb25E6NX47f/t6tvf+9xnF6z0RJs2hMOIHVIEdGseOfzWgPiqtP00IjWkYE8Um+PFMaGtNWwLtvDHoMCmIIyL8WGYsgybCa2K0symdKu0rSz+GRmAmaBdF18el4mZlV6tStzIrWLgogxphAJGAAtQ9IJirvdpynYeVJyIUeoTsNtz8tKdrOOmaCEDPG0hUwfv6geC+hQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:27 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:27 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 4/7] libpcap: Fix CVE-2026-6244 Date: Tue, 15 Sep 2026 21:45:17 +0200 Message-ID: <20260915194520.45847-5-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DUZPR01CA0334.eurprd01.prod.exchangelabs.com (2603:10a6:10:4b8::25) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: 11885ddd-16c0-41d0-ccc0-08df1361e46b X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|13003099007; X-Microsoft-Antispam-Message-Info: lbjwehOtXj0t4wW7rAICvM3v3Chki2kUWg6TpzV3WwTHwDygrWNR8w0zMUIClKRX2MStZCNnTkEdtUAkQF46qKb2Jom0QXqi2kp+3oB4tONrkeF/hz78C7RdUqofjeFGxPj6dPJS/xzzR85PIiFzamjWtXmjddT75RmMD4f9b9IdwiUE3zBxQ0rZ+ozw0EiMqyi4F90QDiFJ/YKZKYTCKthwveAZJkHtaKgPHeg9Jw2XK8Y/AbzgW92K1zUkz109EWwmQpviM2Hv0s3H6c+YkRQ9+iK64+8lx0JuLA0kC/Fpi16+s4QKGHLP/Vf/fhvwNmLOGctlrhJ9QRXwey7Dh6iEvN1723UYhlR3333F+0DmANAAmf9aFHxodxYjgz6kvJ/JtrD6AHrjlcci11ofZpCk5Fi/QrFOzNesyYJRsxjhkRGqAa6MLO7W7KcqhT6qt4GQ1X7nhJziNhkejtQcVDdj5rJ/yUiPQ+mMCe+fB9r+0nWdFYnOxgeuSGNnmaVbOtkuLeEDaNbaJkq3kZqqQUf+FfNV5Kx52voMMLHVe2Y5YCaTQebgyvXdgCl4peOd1m/we1ttoGW3n/ucEdBP1oLTQIAU7ca1DGWt7jlm0V2GL5jl0NVD0s9cKWHDLFio X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: NeDiPoooAzaO1B9u7fIEut1BSHrSfFmEP6qpXH6pbV8/1BtWsbh90f4Ev2ogdE8VxH3vJ8gNNUykAxPyn41rGM/7vyTR1vt4d5vK+fIQ2LC+eHZ1OAqxuXy1UHzyqgK8vpnGVHk2KH7xilyr1r/BftNoP3CVQAiPUyeTDwRQcSRF9dzRoO8fYSfPxAeN64hNxOHJMqXTIVv8gU9Xx4SBewYvlWlpB8jn276Q/YKjmJe1VQjOjFlx3VPdrKhXe252QMLA7YRH6XLSlWZ57csqOv2V3XT4XnqmD95E57JglquLXDU4mc3Gu+9ey1zVhnLHZ631urd1nU5aLWWwBxURh+p2sl2FyfnJ8C/e2LrRjzhyF8nobtXCRrwySdnAdsmyBy7qslwPniMFEl2wZJLMKiZr3IA07wcrHQZ0cWB4EIQ1scceQUti54zuTZp7OAN5sxnCzTGqmUwY6AKSYVdgEoGtGV5JEUKw5LUwF5/NtMSyGWhs//sGY7SROOb9xUtgW3Ms0xF5hPR0R4cbMPq9jht/nvtTwdjr9D1u1omc9hwJSblVmBwSg+QhWC4dRr7vSBMSByY0X+4VCXFxGfs39JNFduY7hSIgurV9lGTW2H/3tyy7XmKxv0yoq6Mzt50D1ekPMKAfEkdhhLS7QUeJZFw8QulMqbYK23eVnFa9ZK2qU/nE0lbimhljPBjYzoECCSNXs7/SsFKWvYeoDPVz9c0uOK28bKP3G+edFbc6wUessaIpt+u1ychJAsR4rdFnKRrY703OsKcFw7sfjUwqGoY5RcxgrAc+ZfYY0sf7vkCGAfP15MaXoWEawzh3PyWELQmoi1p78vFUcwohrmd+9P/0ReHiHVHMaSaILYfR/4RQ/H8GU8R9zY6YPc6thXt/rG/1JjRmAekHXIvfeExCQiFVE30FLGdZFyCw0Pqn/3ojqyOXaVOabBWSGtulge6P2DaOmIdxn3b9SyhZDv/6CGEqpjocmKxLvE+zWHJjhWuXCkQp9MaPzArW+SDqMCfjk1AABJJ6vAlhGWaW5znWvRBuH4TU1UGX32o2AgtNV7g2LO+ybbPVqMqCKkWY5nOUfZIxdfaNMsPjM1ruU2fTQrNAInj6Js7Mdt2U36GflokCk/tTtAEwPSS89+uIQrJ/A89l9ydVlTJL1QY6TEuYTd7kfPtdImq1WzTKvnZe+0svu54U488kva/Sv+ecngypZuRA4qf9Bb88DvTBwtC8co3iZaUq23d/RGLbG2GtRw0v59U4sAaWwyGdSktxBIz8GMjRU8YmYfjcEk3Vm/CpublbLmXLGp8B9/Jwx7jmvW9ev33az0iahXvuflPSdhHYMT8UhANuV2m7bVgY4i+W073/Czx40QT8csP4ivKFYi8Z+AmWli0kxfnXgug6fj6AfdqbUog1N3l7gR6ZW7h6B2iG2SK2yj9bAgsLRm02LCGQFWYwLIEfUdQcBnhaQUq4Uwwxn6bCakbwYjtzDc0Eg07aCVmF4i/9LGwtfjK910+0NN341NGYpyD79LXFJacz1I4PCdzQRfo4AB8YlA6ku7mWII3q+0jV0zPVWF6M4Bo1dQOZxFo1zjSPFQR/RgNz+Jv53Un6oHLSUbhQpKdregSAZCieykeQ9i5btNJigJRm55mCkUomrLfmKBK9Kg+RoL/z7Vs6gusmJ01kS1TNHpRgSgV5WUriedRSJyFljZrHejBR/51Zb93FwO/H2OT5Fo1Zdz4a9bfiqJdzXyh/JQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 11885ddd-16c0-41d0-ccc0-08df1361e46b X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:27.6501 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 59cD1nvvBFMdHAvpkEg9kg8/kcrEUnpK3S1vKSU9ADNyPfXy3QXSBYiJpX0b1wSfarWR6Msu0ccACmFTE2gkGX3Qhsp9Ux6eQPH5AgBHgS0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245895 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/04-CVE-2026-6244.patch | 46 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 47 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch new file mode 100644 index 0000000000..bb9ab04255 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch @@ -0,0 +1,46 @@ +From 98bb921b141aa642faedbf2ac510541c76499a19 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:21 +0100 +Subject: [PATCH] CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() for "div x" and +"mod x" correctly rejects the packet if X is zero, but for "div #k" and +"mod #k" it assumes that k is never zero. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program, it can attempt a division by zero, which will typically +terminate the process via SIGFPE. + +To fix this problem, in pcapint_filter_with_aux_data() treat "div #k" +and "mod #k" the same way as "div x" and "mod x". + +(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4) + +(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19] +CVE: CVE-2026-6244 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 497b1586..df92c433 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -422,10 +422,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_ALU|BPF_DIV|BPF_K: ++ if (pc->k == 0) ++ return 0; + A /= pc->k; + continue; + + case BPF_ALU|BPF_MOD|BPF_K: ++ if (pc->k == 0) ++ return 0; + A %= pc->k; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 5b97c14e85..d23a018a95 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -20,6 +20,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ + file://04-CVE-2026-6244.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98368 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 010C5C982C5 for ; Tue, 15 Sep 2026 19:45:36 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.8]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5345.1789501531153569957 for ; Tue, 15 Sep 2026 12:45:31 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=AgWccbsi; spf=pass (domain: est.tech, ip: 52.101.66.8, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ie97FtQ51Po6pXTnW4eJoLToNK21X0KvHwra0UqL8/O629dOm1oNL+TcvkUtILr2upA8tJggaErK9G/7peI31K3AB/tSPBMJT29ra1bix6j6lPBJst3nRjElhWMIEjcpxJdFw+q12PFjgArDbxP930tFX/wM+HO6ysNysYO5KngpV+Kohr8ypVkG0/zwQz3xtcPkfHjLiplBqR6BByuU2GBQ05ZWGNnD0BgF//LSJ85T18LPgGRfl+anrwBJUTBCOmErOScDmIhEdmh7kkUEKn90q3ATmyMvcxokBBAuqjNJ1lQqnfLz4y7PUQ+82mhBzBl8pifAl0URPOpenMmsuw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=KHoU3uoddlQD0ajw6sjHDOyHgyX2NbZA2txpIuR5ZXc=; b=QISO58QLvL/A+xsrgoVcPXqK3dtkJ0KA/ea8zU2J7rTRVZHR7nc5gH0F3Zg+tvG3IcvDIgUF5XjHZfwqkpniokZESXyz4JpqhECZ2CJ/h3q6uoy+y/fVsihe8L47gXzTQy/fCR6oKSsUfC60xhO+ajBEJso6RO7cVPo+zW4tN/eIh0Kjn8zulEIYzxUWqiPEzjlTj7ts8E8fYObAp2Xpk97osjQdjboZZWrsw+Xdxk6u9a/Y8FmW3218REwO0s+F7cNsoTsIR+jVtB8zQq6ey8NP/ts0H86W4+yU2zfuQ2JzWhjgYVJFdPSNQMSxatizMrtNdIZZMo5wNKR/mqjULw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=KHoU3uoddlQD0ajw6sjHDOyHgyX2NbZA2txpIuR5ZXc=; b=AgWccbsi1w/ixaIYrgkiY0cwjisBPS+EBaQvD/3aGMYaeuiFN9g/TTe9kMKsfoHlNP00tkiFM7mw9v21UtUDL2z4TzO0pwbhLTYf4eubee9Q8yQP4tBY+ed/SXAMOPWD76Ykhv0S8Mdnmk+JIJo0leCsdfJXpTDGUawpTt0NQe/X2iDewxohceIUTRuM40mXvRRMpDbxTzdrY6KDHKNDZWAnAY3X7TjDs3080WRySpsesYKYwdaRjjeWZVzfkrUPY7rNO/4iWLoV9t0tJY5IWFA6F1e0ULY9Pwh5s+q5NAjb5odyncGiQ2CEoQ16FZAxPFLCQx6Oq1ZIxreeTcW/hA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:29 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:28 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 5/7] libpcap: Fix CVE-2026-6554 Date: Tue, 15 Sep 2026 21:45:18 +0200 Message-ID: <20260915194520.45847-6-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DB9PR06CA0030.eurprd06.prod.outlook.com (2603:10a6:10:1db::35) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: a18dd1b3-e563-4493-8063-08df1361e537 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: XZ3/DgPg1UNsWEwUrQNVQ/HRr6epnnKBlAj8QaQ68f+PdISBEfBBhtfBOn3PGSJ1fEGeEGNIU7DYVYWAf6wo5E5/NJmzYtXOwrkceh+BKO9jbRoP1Qkfode0c1SxdrOTtbRLnOW0rW8DD6ES42zIQi0DO79uXShWKOSJ/9R80GiF3CweEtcV7y23+AfWCM9KaV3Z2q7WIevMDdPZPVo7uNke8I2E7iZt1YykCt71W2Jom4jbpRugZrtEUC7kLCLJjakfoT738zdHtvHpdRD+Gdm+1vhej8lfnCXOVzCvbIe5Qpx/x/0Mr2W3Zjln68MFdr0e5b974vQpA7c2p0P/bFEbMEXCAEIuMfGp2/gu9e2bU+H/l+VNoD6uRfKdmN/BGyrcoKV2aqibaRLOgyPOr5kItKN1c8htO/LhQNbrYiVPYAYpNAhiHxuSuBKpv9DRinW/raZZyX2raKRtlDxBse3vJcFnfwdP8fTWu3Z1YGjrNBvlb3+CH/Krc88qeRsjPs/pfpwJsjq6xjNEHgl4HZuhPRQHVvN7IN0hx1RY5qgBI5xSPkgXXtJgWquaDQpWdxX4DR7VHKLOzHUwCHH6Z5aj4fi8ClXS+81EyuGW1Xa0e8gyhp8h0Kqy5Un0gjaL X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: NSizXCqrqmHz/19XrfHfo6i4qw0OSX3+J9j6TEr6Ri5Y6JmdLXbA3hwO13LGIRJprxWtxTU194+BGowqJODpyMWyx9u4o1Amfva0kodCRJzYHt22NhFS5UrrBZgylcIiaoQysJxvjl099FjfLTtLrC5nyywvFuKdRDAQPh6JuMEeI82A4YBcM0IvQxwDsxeGUjJcFacVfI57cWTg0e6sYKmVHhjyqHwNIP9FTcHKjsighqLLZOGpULEyHX7HTwNA+VhS5hS5T1nyhTmCUPGxy/5uLpExxKLyIOfppE22ycDT6X2QQZPd/hA7oxgCBiU4ch+CNJzq5WchuQ9TWPzaBCTqaBb1ObeEPFhG0EVVMxBbd8RSeS8DmiABuw6wjXk3/Ni3gjZug13+DVDbgkDslm1Mo+z+FjDrYDe028HJWpGPXNBSjSwYxeKSTM3OUnEmnnwByyhTqUAhL/0dydsi42+HIQY2gWg1booBDMxTl92iFpKUm9tsfKYBtwMMGTYCPhDQ6lXoo5VIICNGvjbfa6T9awLCgxJxAy2mxhK+rarB3oKnwsq7Hr0mh/b2T2ZNOQyCRbO0/f47sxnYdzmWUhkubxZPex9+0JpsaKGjmbTBNeIyc5FJwUTIOBlDwbcsjTwXjvL8BAWefmcsXD8trAeny0WhRKP2760BPxyZtGucpGcpOnJKpitGTHperOgI/b+nPmsue0PPCuU9Kljc9UKk7v8ZxAwwHXHrM/xKS/iVfYvbI+EgI0EowsAteeEoyk0awiF4zqm2JsJUFObGGuPDI12s/4PnyOZVZtiuqee7w+NAIIZZ9Y5oGTniDBnoYL1CWt+6SGF5i0qMj8ymoRn32bvKQ4yZpYpWxraRgPrKcFT75J5K5JuCTT4wqapVlNAaiRi2pR4SAuxflDbfCu5MPQpsQ4dnVri2aNo3RDz0fLGbLgk2SAyGOr19kKvEA5NbVyN4wU0mE3tegcapctdOLHsNzpyqu6v+A2ZofU8C33SCOZew5npPJ3bCqmOqRhSxDwAzPnWt74wRUF9cJf+QVovEyjfwdgyh5dwz7c4KSGTtMJv5OzpLwi4NOZM5TknVWb2Qdy3D1kC4zQokTsxJa9h0bHDhgX5oqvxd6AQ6gAXJ5QlkehnH0lYElw7q/afEpKe8hOE/ZAz/bjrJ7S92FPZ6VmnyWy5jbnYREqZvBGELqhSLAiFSD59WmYuBIcKz5A+r77/nJ2RQDw+sTmTFy7a55iwYtWCWBQtvM7j1KjwwNImhY19umdPkQIrM4BVlJgXk7+FPzuiSQ2hSxFQFgc6dxFxVf36jSCmsZD/8R9Q271zFO4v9Or9JV8Z1S1zEuZ6Uy1Co7mFkyBqdIVZPOTS9NujA8cGeNswpzjq05hoppPmARrSW/0B/ib0jbdEQLB5WEcI4u0CSNxwnwv/3FBbG3i5PE808weDct8BvoooIaIpi5BaEpw52d7/n3Hde8TiToieqA8Ho8bHeLUkpmWkKxgfOOqdExM0w3YNr19ZWYIsd6IfEpWHrwDpeHKnNU6+5biJ/eQyXxrtJ9OsPY4qaluW7h5nQqQnh8EWDeGo6z5JCR2kZNJBPKu9dm6BqjFjndf7jwKWOfmXOYQzflb/BwTfrDEZxm/5gQ1QKEXyVGRaDthMBkjOonff1MZca0VrwLhQHAqPLpnwQYlckOWX1CLHh7R7/vLw7LzQaYef+7rOkgBqNUTusBniKWmprSE/jZaHyoVoVVIZgbA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: a18dd1b3-e563-4493-8063-08df1361e537 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:28.9310 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 6/M9ZRor9pvCD9zEyy44VL5+TpVFMTN8mKYJaBwE9i+pf70OBoUAufuKOCsEvVQX8HKP/yXPzS37z/LosTanE8D2t1tkXusXI/j5fWPbwyQ= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245896 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/05-CVE-2026-6554.patch | 87 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 88 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch new file mode 100644 index 0000000000..539aa7c446 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch @@ -0,0 +1,87 @@ +From ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:33 +0100 +Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + +This vulnerability has been discovered by Kaixuan LI. + +The current revision of pcapint_filter_with_aux_data() assumes that any +"ja L" instruction in a filter program does not jump to itself or to a +prior instruction that is guaranteed to reach the same "ja L" again. +This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +If the interpreter executes such a program, upon reaching such an +instruction it will begin looping infinitely. + +To mitigate this problem, in pcapint_filter_with_aux_data() enforce a +hard-coded limit on the number of backward jumps per packet. Ibid., and +in pcapint_validate_filter() as well, reject the only immediately +detectable case of an infinite loop. + +(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0) + +(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce] +CVE: CVE-2026-6554 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index df92c433..ae8a3a36 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -72,6 +72,8 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++#define MAX_BACKWARD_JUMPS 64U ++ + /* + * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the + * userland interpreter in libpcap is meant to support much longer filter +@@ -146,6 +148,7 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + A = 0; + X = 0; + const struct bpf_insn *pc0 = pc; ++ unsigned backward_jumps = 0; + --pc; + for (;;) { + ++pc; +@@ -320,6 +323,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + */ + if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) + return 0; ++ /* ++ * Terminate the program if this is a non-forward jump ++ * and is: ++ * - a guaranteed infinite loop because it jumps to ++ * itself (exactly the same as in the validator), or ++ * - a backward jump after many enough backward jumps ++ * already made for this packet. ++ */ ++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 || ++ backward_jumps++ >= MAX_BACKWARD_JUMPS)) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -607,6 +621,17 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + */ + if (from + p->k >= (u_int)len) + return 0; ++ /* ++ * The only type of infinite loop that can be ++ * detected in this function is a "ja L" that ++ * jumps to itself. For this only k == -1 ++ * needs to be tested because the check above ++ * has already rejected all other values that ++ * would wrap the pointer equivalently on ++ * 32-bit architectures. ++ */ ++ if ((bpf_int32)p->k == -1) ++ return 0; + break; + case BPF_JEQ: + case BPF_JGT: diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index d23a018a95..f7ba1bf3ea 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -21,6 +21,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ + file://05-CVE-2026-6554.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98369 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01082C88E77 for ; Tue, 15 Sep 2026 19:45:36 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.8]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5345.1789501531153569957 for ; Tue, 15 Sep 2026 12:45:32 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=IeVA40qh; spf=pass (domain: est.tech, ip: 52.101.66.8, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=csrMes+KIKlqO1P3CvCFhWyyNZ5UX1j1Ol3ktYAYengaUoI0plUylJJWmvK0S/jHWRF8mO2KSVNDTEMYadWxC1FQ6NDHIuTZSMoN58HR0Lya8mR2TG84M8f8sN3llc06ZMAdHvayKcIXt9+bxSzlRujFHsVQ5/FRQm+5rJpeTYcf6/PHmKBsi718D829uoBJjn1FyLdiv5mCBBUdOd+bZ/7zMqrNS2xA/ADELo4/23K5o1FawqnrKL21VUKGeriGT7zFAEEalqPGGZ1mn5TeAtthJXrM5i3v2LQDnVmBCOAK6SfblNgwhqyKz8L1XnvbTAHztz9NKW9yFmm/ZyARww== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=/legvpdzM9Hqd9BWw08kt4eEdcnwliFOCvbt+wxk0AY=; b=JvoQ5+S8FYvE8t7cQF+Lx+Zv2CTt7Q9NJOAhhbreNQlsFnxeRvYG0d5gzUZ3ElgcRlcSJgg5nGeiNnV57zIQbJyLga6cqzJUxRrKKczrQ365PovmrHYrKDqrVfey0/SRlYFMQS6/dfJmOO3BPq7NK65CozEUYyraKdeHwCv80sZ3CFLWmHPQjfKp/h2NVcrPRQzfolYFODWP+jCvMpjatwMYQCc4hQrxOGgBAei428vsX2KMXbqZCvRaPXKtqfMWzL840hdVLWOVD8Etx31kz07u+S3Av/rK4YanIU0CDwe5ieHDRi6kJJsL+sMDrAYURXH88dqaRgwxdSKW9Sshfg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=/legvpdzM9Hqd9BWw08kt4eEdcnwliFOCvbt+wxk0AY=; b=IeVA40qhMKrR2tZE1lq4VaK7X8yAiFsFpo34tzV4M3SfImYsRtWxz9hRkrVgZyhcF7AiH5oOc/I0qkDtzoVQyfHkVijX/Kqoz3Wh3E5ZJqakLcshaLgl3FA2jU5cIF7Tjeoy091WU4soZBbZp7U46zNBXGgw6R8ito5MMjb8IUW+4QmOt4PXcyg2GMaPjB3qo0Ferjx4Vs3T/+psDj900RTbq9A9Baxl9MZCr3HYQDh8Txw5PrTjYYhLoB55XKfSQuTjzEzizack/JyDTcxXuizLmFpL7zDQR9vKuR2LI0GEsJLgkgv76UyAwvvofzl0vJeCIdBVNfslIZoaLBPeBA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:30 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:30 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 6/7] libpcap: Fix CVE-2026-18313 Date: Tue, 15 Sep 2026 21:45:19 +0200 Message-ID: <20260915194520.45847-7-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU7P195CA0020.EURP195.PROD.OUTLOOK.COM (2603:10a6:10:54d::11) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: 736bd527-dc87-4002-8830-08df1361e60d X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: BoR+2kqVPU7OhikyGOt0LSqD51Oc6uLQ8a23ULINLqvdywT7hL83vuza2UB1zSE/gFHQlLsBrgqKXfIidtGeAfSF7H0c7mdQXwbP9zF2dsFbtoV3M1rxUjqPooLRlY6k6YHq2ONh2YsZMTd+VW6vlEW3dcZS5DK5Qo3t3M7+UJ7spJlwm+n5pq/g4zdbh31cEZBDusHCtnzLH0Je/PzMhv4Qy493rTFeLhuxOBu7PTtohA41jkZSIbdGv5A72ASnRSfL+jO2hRFtEa8zKzL6lKjnI/Cqaz8LTHjSNk3JElVXjYNaHFn4IoqCidty7UP6nqZMMEkwHxelXrh4KE/ae5/0S0diHMZ/eX8QVDnKMXAAVuMX+5IOWzZgjKi9S22ITTp8d33lo+MnXPbNo6nvgYZyvQFYkjE7K5svGlJJ21acQH+qGRQ7nHICHl7e36J8Uuu1KNUFLoglhC2jAvdVgu484Nw0hDNjGLU7q4YexFQ0FXKvxmsQf3Is8VDcsqLNXfaHX1C8D++4edsjODEH1/2nFsDo+YGObJ2tgcn8BM5PgUkznjGXoz+y3Rg65kXPR7+RrJEUFIClnEKHbu+KK8CxthM0HgipSDTgW/ZG2GF16j3v6oxXaaZeyWls08Eq X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: aOwqDnq0USndgujCvHD/+L7tBKpK3iVj0yIDtODwWz06nJgQlsuLJIbKXYbFChtjmS1MWh82SSULXVp3fyXd6hvzuw2ZlxKOTGiEMWqIe3L/7JrvZKaZ3vVB4TnYqhFFADDsuB0q6gljoc55qUH80ke3tsCL2F7XX57k/QPQZ9DFN9BKoOr6bzFWOZwZsIFKbKBvq/cLkUfBCObnxXpIP9nsO5uMySm0Dn0SHPzQwf3yJgYoHm4Bdc904+LAO8pqKvHISDvV/KXN2Tq12DWCybO9nXZM1umjKA0ivPDTwg1Bu2kw6/+wDqhjRFtOvL8vSjiilZMvRDcZsl7dNDUtYPS8XIis0ZWJ5TrtwXSHQBcIJ8zO9heajGQR5GCV5b3uiocwBsipPRx6/n0E9raUFT6Gane+2bl3qY2nSK1fT1kv8Pvc20a71HC2eNkAPD/Qv9AnYzCf0bOnEqqp4AYKF8sXYpESV97JHcgsC8iCHOVLZAtrOeNcpQvWn0xZa4C8n6QEIaD6tMXiFv3bC9DnqqhB5pSghUNBUbz++O7rQ8U0ZqlPaOY1nCuuDKXznaHpTQzF3N2cp/4uzNQM8xMKbF/uHuTnd9crPdzzLwnJTQfNkjgn1GWnvqsOQDjP9MLpuZdkyXVwYt4FxfGDla4fCJeulykgD6mUFaedhHeYFnZAMwiy+mul4+49coEcIGBOHcjDJj975cKuQClanDvJOW+RmFRMkLe+ywrX9PsscT0ssXIZG7Ck6qqEnHU30aZyP5EiGyofLntw7pK0W6s7q6jHL488EyPP6GBK+Ft5H8C2JsejX14Hdqp9+vbt9P3WSbBNDdpXQ5B64rsAEdfIIQcI3oizvSLH58EWA8XlapfZCKM/+jLdylmfnmLC3SewUy/3porw0vuHCYEM4ByuHfqyqHnaSQgSDH9Nk1U+kNVlTXf2P9by/O5NWgOOJ1HHdFAdk4aEK79Li71O774z46ouPy1SJwhvIJeueGRsI2ItuYIu/q8tn/TzhWGyS4AQhUEZGH5tpvUQypL6hGsM3DmGzGKCn8cGMY8xKBQ+a9iFtBAzspuNvutSl5NYQLGC7sAHQiMNrNYZTIPuRPIH1Yjm+eY4R418lecb9Ynpdgt8Iyt1HIdpLRuCskpaSzj9R+4Oudokgo2vOjo+1L9RNrz2gfYi1w8dNt/+BzRRVFgOjWC7uaoMnQ5S8TtfrUCPqint+yYB1NZYKv5MzWuSZltqpN+QwKD3P2O3bsbq5qkYl0E/OTHDkEFLGFXPF4PvQNQ6ub4+z2rAy/OCHDZcEHb7VWQzgVoe+pt3IrV7hcTnojsfOqw5oIRnBZWJ9KEgfBVevIfxTT/33lXtc23sAezE56rH0KMTUA/f9ME+5EB3zVNZzEaaX0uc8ydYSsbmsbtIJ6pjh9wsByWbkCf9kbZHf/FYgZXmrpGbHNKETRezU+p8LAx0xI8O3VrkTG6qJCNLrK1Mk9bepuoAaiFnsHsL042LNn4N7hHSPE43azA2cB+5E8fWtP+seKxJ+wc7kMsOjPWKIR9XKlwJUaAIew5NPZyxBxSlCVeVximFYStGgaJHCP5I86Htd3A0kNoSxXQ4tSUnmXTwWyxWy+9beQc8MoOmdEEsirJBIhJVBsSy1SyFC2Zt5IFZ0f8fTazI249XaacmfsMMtBrHLkckZspecdoubcvsbZ+bAZGCgE2FHZt0t2IRnucLJLGvJjGdcR7nXQyw2dar6I7nO+Y9mA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 736bd527-dc87-4002-8830-08df1361e60d X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:30.3104 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: dWYZP8TIeecz2iLCvWKBAEWgRR7V8AdhqgO0338BN2ilbnHXSyexLhu4ceC54DVPyn2977CCQYbWrEumaTt6waS6tQBE2RgPnVc8+dmG9Bk= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245897 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/06-CVE-2026-18313.patch | 81 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 82 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch new file mode 100644 index 0000000000..a2f2a5fd4e --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch @@ -0,0 +1,81 @@ +From f9775af1a0ec76db60c7213241e6b48f1be10ac7 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 1 Aug 2026 18:24:48 +0100 +Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd. + +This vulnerability was originally reported publicly, hence no credit is +given. + +daemon_unpackapplyfilter() can allocate a temporary buffer for up to +RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each +received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message. +It never frees the memory, so repeated messages from a client will +eventually leak enough memory on the server to cause problems. This +holds for all connections that pass the validation and some connections +that do not. + +48 bytes in 1 blocks are definitely lost in loss record 2 of 2 + at 0x4844818: malloc (vg_replace_malloc.c:446) + by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372) + by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139) + by 0x114808: daemon_serviceloop (daemon.c:901) + by 0x115BC7: accept_connection (rpcapd.c:1321) + by 0x115BC7: accept_connections (rpcapd.c:1118) + by 0x115BC7: main_startup (rpcapd.c:709) + by 0x1112BD: main (rpcapd.c:567) + +To fix this, after a successful malloc() return exactly once, after the +free() call. + +(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b) + +(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7] +CVE: CVE-2026-18313 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c +index 9b0f8285..b0268688 100644 +--- a/rpcapd/daemon.c ++++ b/rpcapd/daemon.c +@@ -2378,14 +2378,8 @@ daemon_unpackapplyfilter(SOCKET sockctrl, SSL *ctrl_ssl, struct session *session + { + status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn, + sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf); +- if (status == -1) +- { +- return -1; +- } +- if (status == -2) +- { +- return -2; +- } ++ if (status == -1 || status == -2) ++ goto free_and_return_status; + + bf_insn->code = ntohs(insn.code); + bf_insn->jf = insn.jf; +@@ -2401,16 +2395,19 @@ daemon_unpackapplyfilter(SOCKET sockctrl, SSL *ctrl_ssl, struct session *session + if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions"); +- return -2; ++ status = -2; ++ goto free_and_return_status; + } + + if (pcap_setfilter(session->fp, &bf_prog)) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp)); +- return -2; ++ status = -2; + } + +- return 0; ++free_and_return_status: ++ free(bf_prog.bf_insns); ++ return status; + } + + static int diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index f7ba1bf3ea..5f1506f8fc 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -22,6 +22,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ + file://06-CVE-2026-18313.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Tue Sep 15 19:45:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98367 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB298C982C1 for ; Tue, 15 Sep 2026 19:45:35 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.24]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5565.1789501533986104486 for ; Tue, 15 Sep 2026 12:45:34 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=ZcteM91b; spf=pass (domain: est.tech, ip: 52.101.66.24, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=oxZgCKv/KVHpB7H3+l64bnneFGNdzncZzb198BO+PrDRsPlsbvx29RhshyqOn8eW01RmZUt+0vj6MtHO40kePYMNUcUzTfarbTkrCOll6A9zXXSj2vcALjxt8bGjNo8deUrnlmwHcML4gmWTESQusVS7mm7q+VWsq8ZeaEvLHOuUimfT5hhJAL9V+V1SHPKZMnQD1ohQLnzMxOOXWYVNUZ/eh/VUiXt8W8hv9o8SoHloEhS3cCtHI5nk1kzmvi9d9fc+2q3HERznl8DC9PnjAK3lLeYMit9oBvwjieN11JG7/sAi512Exsjyfgk3Uj+I4RxgGGKdwTwc1Pr8LUcX1w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=raQXxk+wyh/CUTST6nnIk9Bs5sF6NvV62Mao9hV93DE=; b=o8RCC9YJIu9xZVofTFMBfEJf1JJ+YjqP1Zrw/3l90lOusfF3uV9KzEj5+eQzadR/O4/OVbud0SwiXXPN46ezlCiEdB3arly4hDYh0Ex6AZfesgE1A8BqsotXWiO2PqFJaLm9h75EX0Atb4sG51jwNv1xak7etVm6dm8ojd4DO0uKISkE9WlOc/BaYyOeo7wbDoAiJEunbdnus10aB076eGxGp+VsCVvnWeCpMp6T+SNI3nc68GSvx9eQlteTN1Eu1Ywv6hx95hJInNeuCLAdBRvsYTTieUk92ily0qPzbi0ylBItSilyqm7fri0xM07zDy7fxPSVtZZp3r6+jx/AMw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=raQXxk+wyh/CUTST6nnIk9Bs5sF6NvV62Mao9hV93DE=; b=ZcteM91bI4TNMKy1l1qhYpAvsMWRr2EuvP0WE1xsILD06JdLB9KppEIxL2kHaCY7YZzqZrupr6lC8M2JMf3gUsqPVNTxbFq0R71gsE70Wa22Y+O2CnJnjZOHtp/H3exT702fR+C3gux0J//km3gFszmMZ13P9lqr0x/Jap6aIIWUbD73UMA622cQi8jBwPRAn++5uX9uJO1xSzrI0vJwHX/V+I/t4rh8PVrkHyBcAF7whoZCcAs2xkkVHVGmE3BKeqLjbqIb8N9hO2Pkb7qyJOUhlBgYU1/DmULh2ZruM4dy/6dMq8Tf/jVpH0A3uTq4Dy5tPwdWBZY+EVx0ybzO5A== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) by PA1P189MB3172.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4e7::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.9; Tue, 15 Sep 2026 19:45:31 +0000 Received: from DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666]) by DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM ([fe80::bf0:7714:72e:1666%7]) with mapi id 15.21.0406.007; Tue, 15 Sep 2026 19:45:31 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 7/7] libpcap: Fix CVE-2026-18238 Date: Tue, 15 Sep 2026 21:45:20 +0200 Message-ID: <20260915194520.45847-8-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260915194520.45847-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: DU2PR04CA0273.eurprd04.prod.outlook.com (2603:10a6:10:28c::8) To DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM (2603:10a6:18:3::ad4) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU7PPF66507B2D7:EE_|PA1P189MB3172:EE_ X-MS-Office365-Filtering-Correlation-Id: bc0facff-9ca1-4fac-61b5-08df1361e6d5 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|23010399003|1800799024|376014|56012099006|11063799006|5023799004|10067099003|22082099003|18002099003|6133799003|12006099003|3023799007|13003099007; X-Microsoft-Antispam-Message-Info: 44OEpmDi6nSF7aToo36DXHAZeKXQ7odQol15mEU4P5B3AaJLjbHgIoyr56RkeqRZ//bJk8509NAboFppELSKa8yflCV+JCBcG9iMSXWMUE5GJVgX7DeykNCPLoXyQ1GRjATo5C/RU9HaAhpX+yi/FGG8Tooi+r6ymeaPIjY+xgei/r1ziaA3nOiblnjwbogygWBIyTPqcdP6XHx9RQNGifNe09c/JpreSzum5IkC3G3r3FI9XtBo+GiLh/06/sDLXkTCKd3zTAuMsPW5HuRE+NzZYKOxXaQ5M5J1Wl/k1SNmBSxfIeV9B+TTfai/f+FVCLg4mJfmiKmIQyZkfxBahx+qYgJ3r2FmRQZDQsL0Kubt0Q5TgB2ZDv0uzsbWMmEpp9Ikg4dx4JQ8n7u+d6eRrkv52ltUiQ4MQ4x31nRnivVBXfsmm87vY00dsQnpx1rhpRR7wBNXkS3EJDeG+iPCo8cvxLOxjY6XECTRHuAyyEMiiJGYhR/EYrtsZrdXUN5Lv5pg+4NDHgtgnZd+vpsgLESSLUch2P/oZYKjwHuStJlv9ToVfQB5xqof9iUcvhyCAPXEOiYFoiRafxfFznm2WwoTuF1ni+0iMAyTY4sCXS11+/5UNJPbLaIMPOd0qSkL X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(23010399003)(1800799024)(376014)(56012099006)(11063799006)(5023799004)(10067099003)(22082099003)(18002099003)(6133799003)(12006099003)(3023799007)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: /TIDKS+y64Xri/K9JkUmOFG2JOrYpxedFuCFS7Gej7wf2vbWWzleWuHhbi/ZnnFr/hOsiBrSHPFxWsAYQzhyFeBnFzhML1olwB9S7PZDCZN+0orcwjAujT+bB0sHh0zTTmHLVgA5XG9h7hTqw5rxfbTQOb4iuYBPdr4a/ws8/RfUj8nJ6OJpawFJ4DGhDXPdgpU6Xosj9LZbMsG7O+pcCHKmDDed3CTBLpIE/2Ik75s903xoRoXhOm+3wHk9qEWIgi1cVW85ouK2ATXCFYR6up+gHIrvrWm2wTyl6Y6JXNHM4cYyP5bDCRnqjrAKaT3tWyFe8SSiKhp7Y9IoxLrb9LHcZcLnX4wL/S1NWGY+X5paSELPJlVNKzsaweVlO6ZJ2dJ4rA3VEh44xg8ltQHu8/zxsw+VOe0CLIqeDoxRr5VXd60Y8N+bZwbdNqO9Eg7xkCcz0MNVwxJXH3fsu8ox0TG/7sII5h2xTiYh+7u8L12H4qcVzHY90V9EfJ/gyATqhpNW5Nc7ucTTquh2hTMaMUqTd5QQYiBzKUOIBK0n5j47rxm0RZHgvGKle9pAhaqq0di481L3F1PqtC9KWJGJx6Zxz83PbQMuU/4dGW1ixcr2LEfoz5Nco1cjG5fCduoqRioLnebDNB+9ASxo8S81s78wpNFdQ6i0o4KJz30SgkolqMdgI4vtCBqXiJRxNPDpiCHVt8yJu/61ETSoyM41H1ej2VxTkCjGSTItttM5f43oJhMpo8vwDpGj/732XfU3hAInO0rz/IB6Sz0PeWXtRGKioyqP7i1/t395DCHLHt8S+p8JhH1dZJxYQJztxAycQ5fpCaAmhW+I1x/CL8amOYl2D4hYSJpPwgmDuSPK74ZHFKpyfbYW9kv46Iv/P4I9KVYO3wxW87Ustfjuj9nB6AqjoySvlvL5/oxW3x0Tsgz12O49Aqc88nb6RZMkGd4DFelIFoVmVUao7m5HzGFO+oAsWgZXR9lRAtJO9ZuUvBjoS7mgXJNjdZpQhBk3eBSUZ8Xj1b0BSUmWA7APWMvE3JCEg+UHKqWt5vMIk535juXaUSytfT3tbzhlfMYPqhE/y8wKKLgz36pMLthtgxfpAQnzbwpH6sG0JzIxVqR3T3AVd5W1kdJo03zbxpmbTHdsbd2NThN2k7Pg0PPVLuHcJ1F7hf/04b07d6+OI/ISKBw1eg/os8Q6H312qo2X6XFgIXX9kxDzG0EiSu/9QWhCsix1m2VPwY2g7oY3eW2qSFjRzQWUznLz8O5Jlcz6NHtZMkNl9iXVw7+4i+AVA5b/gYOlK8rj4EmiTx94JeO7qk1IpQbA1fo1PM7exqQgY2EmhtCO6DGx1owWsp4fif8PYFH2H/fbWWRorarOtOLRoSA5MABvd5Iu/XUXBNgMjGjPtsUCqjudjx8zZnBtwGtuOb7Rwf4cXW/1myy7IgddAeaqjQ8R4vBR1WIHFWPHunCUD0iIxwflVBMySGiKdyDTcur44J2aN4GizNsuy9mbUHxweunUJtfPDESta52rSFi6WIVIav9T2nqJf4BtnJc4cf+z50F3a+OMTlnBmk8MN+n93SQAjNWxJOhc7BuowXige4Rj/WdC5jjt7Vwf6pkCajjHe2c+hMYTSVHJ4uHHQreNurLISHhy7AMHPvUG1q866juVPRiguS9mKnanH2nk4qKvahRE8l7sW6Alc/15vUTC9l908TFXwoVC9T6ziOcnhaCn2JRnXAhq39c4vC86/A== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: bc0facff-9ca1-4fac-61b5-08df1361e6d5 X-MS-Exchange-CrossTenant-AuthSource: DU7PPF66507B2D7.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Sep 2026 19:45:31.6753 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: gRoTd54anHEhWvBqYx4OzsokmragvZgPSyWHXE0E7d/B6yQWSLs8eiHSshQr7A7DHSN50DO0U70+o7IqUPsYwqb1raA4Xtikve7enM5jpso= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA1P189MB3172 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 15 Sep 2026 19:45:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245898 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/07-CVE-2026-18238.patch | 219 ++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 220 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch new file mode 100644 index 0000000000..c981fa8ff1 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch @@ -0,0 +1,219 @@ +From b9590d482986d64673712460aae1d48d11fa0473 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 8 Aug 2026 00:31:10 +0100 +Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + +This vulnerability was originally reported publicly, hence no credit is +given. + +When pcap_read_nocb_remote() validates a received message, it does not +verify that there is a complete RPCAP_MSG_PACKET header in the rpcap +general payload, also it uses an incorrect value to validate the length +declared in the RPCAP_MSG_PACKET header. The latter can lead the +protocol client to over-read the message buffer by 20 bytes, which in at +least one scenario can cause a SIGSEGV. + +Fix this problem, as well as a potential integer overflow in the UDP +code path on 32-bit architectures. To make message encoding and +validation easier to follow, re-jig a few variables and update comments. + +(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9) + +(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473] +CVE: CVE-2026-18238 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/pcap-rpcap.c b/pcap-rpcap.c +index 22fc7363..30fbd6d6 100644 +--- a/pcap-rpcap.c ++++ b/pcap-rpcap.c +@@ -388,10 +388,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr_storage **soc + static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data) + { + struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */ +- struct rpcap_header *header; /* general header according to the RPCAP format */ +- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */ ++ struct rpcap_header *gen_header; /* rpcap general header */ ++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */ + u_char *net_pkt_data; /* packet data from the message */ +- uint32 plen; + int retval = 0; /* generic return value */ + int msglen; + +@@ -448,13 +447,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + + /* +- * We have to define 'header' as a pointer to a larger buffer, +- * because in case of UDP we have to read all the message within a single call ++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large ++ * enough to contain all of the following data at once: ++ * ++ * - a fixed-size rpcap general header ++ * - a fixed-size RPCAP_MSG_PACKET header ++ * - p->snapshot worth of bytes of a captured packet ++ * ++ * This is sufficient for all code paths below. + */ +- header = (struct rpcap_header *) p->buffer; ++ gen_header = (struct rpcap_header *)p->buffer; + net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header)); + net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr); + ++ /* ++ * Step 1: to receive a message that does not immediately look ++ * malformed, consider it as a fixed-size rpcap general header followed ++ * by a variable-size rpcap general payload and require: ++ * ++ * - a complete rpcap general header to land in the buffer, and ++ * - the header to declare an rpcap general payload length that fits ++ * in the buffer after the header, and ++ * - the complete declared payload to land in the buffer after the ++ * header. ++ * ++ * Since this step loosely corresponds to rpcap_process_msg_header(), ++ * which among other things converts rpcap_header.plen to host byte ++ * order, mimic that as well to produce a valid argument for ++ * rpcap_check_msg_ver() later on. ++ */ + if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) + { + /* Read the entire message from the network */ +@@ -470,6 +491,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + /* Interrupted receive. */ + return 0; + } ++ ++ // Require a complete rpcap general header to be present. + if ((size_t)msglen < sizeof(struct rpcap_header)) + { + /* +@@ -479,8 +502,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + "UDP packet message is shorter than an rpcap header"); + return -1; + } +- plen = ntohl(header->plen); +- if ((size_t)msglen < sizeof(struct rpcap_header) + plen) ++ gen_header->plen = ntohl(gen_header->plen); ++ ++ /* ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX ++ */ ++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header)) + { + /* + * Message is shorter than the header claims it +@@ -495,6 +528,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + { + int status; + ++ // Receive a complete rpcap general header from the network. + if ((size_t)p->cc < sizeof(struct rpcap_header)) + { + /* +@@ -514,27 +548,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + } + } ++ gen_header->plen = ntohl(gen_header->plen); + + /* +- * We have the header, so we know how long the +- * message payload is. The size we should get +- * is the size of the packet header plus the +- * size of the payload. ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) < p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX + */ +- plen = ntohl(header->plen); +- if (plen > p->bufsize - sizeof(struct rpcap_header)) ++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header)) + { + /* + * This is bigger than the largest +- * record we'd expect. (We do it by +- * subtracting in order to avoid an +- * overflow.) ++ * record we'd expect. + */ + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Server sent us a message larger than the largest expected packet message"); + return -1; + } +- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen); ++ ++ /* ++ * Receive the declared rpcap general payload from the network. ++ * ++ * p->cc == sizeof(struct rpcap_header) ++ * p->bp == p->buffer + sizeof(struct rpcap_header) ++ */ ++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen); + if (status == -1) + { + /* Network error. */ +@@ -557,27 +599,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + + /* + * We have the entire message. +- */ +- header->plen = plen; +- +- /* +- * Did the server specify the version we negotiated? ++ * Step 2: to validate the received message further, require: ++ * ++ * - the rpcap general header to have the correct version and type, and ++ * - the rpcap general payload to be large enough to contain at least a ++ * complete RPCAP_MSG_PACKET header, and ++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload ++ * (i.e. the captured packet) length that fits in the rpcap general ++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header. + */ + if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version, +- header, p->errbuf) == -1) +- { ++ gen_header, p->errbuf) == -1) ++ return 0; /* Return 'no packets received' */ ++ if (gen_header->type != RPCAP_MSG_PACKET) + return 0; /* Return 'no packets received' */ ++ if (gen_header->plen < sizeof(struct rpcap_pkthdr)) ++ { ++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE, ++ "Received an incomplete RPCAP_MSG_PACKET header."); ++ return -1; + } +- + /* +- * Is this a RPCAP_MSG_PACKET message? ++ * Validate the RPCAP_MSG_PACKET payload length declared in the ++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX ++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen ++ * gen_header->plen is significantly less than UINT32_MAX + */ +- if (header->type != RPCAP_MSG_PACKET) +- { +- return 0; /* Return 'no packets received' */ +- } +- +- if (ntohl(net_pkt_header->caplen) > plen) ++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr)) + { + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Packet's captured data goes past the end of the received packet message."); diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 5f1506f8fc..3892454a40 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -23,6 +23,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ file://06-CVE-2026-18313.patch \ + file://07-CVE-2026-18238.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f"