From patchwork Wed Sep 16 00:43:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98378 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB4BFC88E75 for ; Wed, 16 Sep 2026 00:44:05 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4579.1789519441611675131 for ; Tue, 15 Sep 2026 17:44:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=PxVZvMuJ; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8674704dab1so433628b3a.2 for ; Tue, 15 Sep 2026 17:44:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789519441; x=1790124241; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=yZjtJ/L8EAHhiRYYFq5QwpvH7azXz2lfbybh8BNEq4A=; b=PxVZvMuJ/t3g/GlLEfox0x29lUdfC77N6TVaOSYBFNHVHB2jtLYCBVzYkp/vcjaf6E g4jMxRzs0J1AGnvm+alghHfJ2hcRAVtx8s9m8BXOZFvTR6VQm/vR8lflIp6y91NJQe2n c1qp9ErylhojuUnLcY0Bpr0l8eI1rAXhkkOvoFas9O3ekDYqzTovjkrQ/EL2D315/GYk kycWe7E0aJXpnGfdmX/Oa+ATx31X9gl2zEsp2RbWdM0JM5+vFeT3giZblCACugDzyvJZ W4Tg+L7C7rorUrezT8rjHa2y14QnDuRXoYGPPgW8g83p4l+fehu+xrrzuiIMzcnKyavu Xuhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789519441; x=1790124241; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yZjtJ/L8EAHhiRYYFq5QwpvH7azXz2lfbybh8BNEq4A=; b=n6J07Nms4TJZgotliLxyWquiWMNNKw7hNcBMZzvhz++SwgesR8039yYbcBXlOyPED3 ApMQX7LhiM7N05RqHwsxw1DVSb+2Ils22SzzwKzutxnoXhWH8ufacNPC9w2ChMwpY3Jv w/SKzp1fxnmWtNv7OeWE3LvleZ4mTtTy2EONmuDhgEh9LQ0pcEpEi0BrfZFIVLQiyIbN p5xqkChELGiQj2KxbgWRF74koxJ5OWktC9IqLrAkDSlXILl6Iohn1NyhRVaKMOkm4og6 RjNn4c7wurQ2IrrtV7GjCK4U5CZy7FZatvBPddsmqHEnOx4TBKlsLV63VTOe1WxwLFpq Egmg== X-Gm-Message-State: AFuF++kjMVRnI528b06AfsJxtUDN9rpybCHVJI0j5W1aA9SGhM1GqVg3 0urWSKRrBZoTJrveKZsOeSMcJRMx9GeUZL4O1LHPD50NxUMqMjRPpzM0aBn6LA== X-Gm-Gg: AYBFou2Gu0zn5Q7TdHXRUwzeANlS0EiODKCirDz6AccfQOb+Wt0resV/ddf/6BSHyqc Ag7XgeXldZ8e1dVt+fxpMqgqhB/owDbYXhzPC8C4xQ3KgOxJFyIHflVfgJiEZkIXHLl3Jv9zmqs 6yBgb9y+nIMPvkU4kv0nOxD/SJFU5QaXHLpvU3DyYMZ5xc49/kJRnIfD4gTCAxOWXlhU0DXa2Ox jUJwpmAvUSaMiueqdmIS/E1CDx9EXwCcb/qilfrRvaEFm/daPKFCIz6E+hxfp9mBzNWRHqwv07o q5E8KYpFQQHfFveKAAQiZo0CIRvYYDGFFBWL/fV/am3Cyg5xKb2rAGrY3tCPmq9gRtUSqY+MdLb RdrmCVShxPxIs2kVTkFwlck6Y1JPoD3DurIg98o74Art1L4LsMFdMAggsjAWpJeuBsrJ3nuUnyo jz1U70sRwjbZay+pMfLw/tX7qyro4GoY3aVoiAlZ89Nher7OO22pL0pRZyblqE58hYQMvlT899p oS48jGMziX5AdXCgi3o00I= X-Received: by 2002:a05:6a00:10d0:b0:82f:50cd:e586 with SMTP id d2e1a72fcca58-8723cf31d94mr773413b3a.13.1789519440925; Tue, 15 Sep 2026 17:44:00 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87200c58265sm314134b3a.14.2026.09.15.17.43.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 15 Sep 2026 17:44:00 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-core@lists.openembedded.org Cc: Ankur Tyagi Subject: [OE-core][wrynose][PATCH 1/3] ffmpeg: mark CVE-2026-52295, CVE-2026-52296 and CVE-2026-52297 fixed Date: Wed, 16 Sep 2026 12:43:51 +1200 Message-ID: <20260916004353.478934-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 16 Sep 2026 00:44:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245910 From: Ankur Tyagi CVE-2026-52295: Debian[1] identified the fix[2] which exists[3] in the upstream version. CVE-2026-52296: Debian[4] identified the fix[5] which exists[6] in the upstream version. CVE-2026-52297: Debian[7] identified the fix[8] which exists[9] in the upstream version. [1]https://security-tracker.debian.org/tracker/CVE-2026-52295 [2]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/016a241102250372a9c2e96f6e8dca67ec01d3f7 [3]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ff43ef5219ad543e57ed56d065e9d4a3b0426468 [4]https://security-tracker.debian.org/tracker/CVE-2026-52296 [5]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/23227a444de4a8f7696f46660cdd044b460f7e47 [6]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d18354f8d4bd018eb486d18079ff0afb3b84c506 [7]https://security-tracker.debian.org/tracker/CVE-2026-52297 [8]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8439e0203744a30d280668fcd086f74ed5001da1 [9]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ebff1abbad8b036bfc0f52a4785433b06e865e3b Signed-off-by: Ankur Tyagi --- meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 8a6eb4eb86..e84a29ac87 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -185,3 +185,6 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0" CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0" CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3" CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2" +CVE_STATUS[CVE-2026-52295] = "fixed-version: fixed since v8.0.2" +CVE_STATUS[CVE-2026-52297] = "fixed-version: fixed since v8.0.2" +CVE_STATUS[CVE-2026-52297] = "fixed-version: fixed since v8.0.2" From patchwork Wed Sep 16 00:43:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98379 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E76EEC88E7F for ; Wed, 16 Sep 2026 00:44:05 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4580.1789519443900228406 for ; Tue, 15 Sep 2026 17:44:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=L7vW795T; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-86868f7707dso155269b3a.2 for ; Tue, 15 Sep 2026 17:44:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789519443; x=1790124243; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3++iwIoIr6QZIQfDn1e4imTFSOLbIHQlaKtZ8UR5r28=; b=L7vW795T+OPe1xGncMwGJs6pZImd5baUyMSm56Fidy1JeeHBTmveg2fuQYlpnXdj2D waMC8vAaPe/BwFPyy2TjRX3bBKU2HMgyO+Lh8iR3RyySxVRneoa+s+aJiuwRmatHoJak DgVIk05tz13XclLtjxjLs2GT6jpJUa24SJUbcJdgX8QISTdOWM2woBxsz0hrqypGrvwK fLMt8V86mcL28Dv13mdXVrMOxGvu/6HaFDnwcVjMi9wjdRtOOVbTA6Lr6woUGEi4KTxW tXe3nuFxgJLWKKAb+ZcqtrlmmveUBQwJ0GNhQPE01N0HZN8nYBlOarZtcpHQScqErqZ9 jXIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789519443; x=1790124243; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3++iwIoIr6QZIQfDn1e4imTFSOLbIHQlaKtZ8UR5r28=; b=ACZm5Arx1vop1CWWoc8A7L91ZyNMD5R25S9of8c6xfnhV3vzbfGeHF/YdRhfr27jEB ZfnrxCLXBO/VNrnUSMv2NwCRsfyoVXsIz6A9qxg/TKRl1x7XGL4SpSBUZP6y/CRvHD61 cbwHBMMPM7heXR1i4z9I8N4+yG+OOG7dbhspMwMlSNvGIfUgGlxpEWz258q2c5Po3SOn wupxBTxFYLpdG43eTY/BpacqSqp7xaNfBkZ2WiSc3MfEREnyAb4ibi8DQqeUEduxJuxv KRrsoctmzfOhcbra3I5VZzcxEFunKJOpQgPkNBQQ6nJ/qiESgkCOR79aD1gYzpP5tW+E q/fg== X-Gm-Message-State: AFuF++neV37tEPVSaZMtOEsav98BkXIvQzq14vP2K7I3w9+RJeQ/WIXr TVwJZ+v69sZ76BB3JmSEJwC+OQeUwfOR8xv3/fr7I4btlQPrBBr4VvR+0VU8gw== X-Gm-Gg: AYBFou2GDDppGesuaVb4nHb48uUDPEaRJrVeAcFeJY6slUW8PQ80J0UiprXJUzHl3R7 tQbpZGWPk0zDzzaYBUORqETNCJdPpGK5hr2NI5pNo4cL+xp/l7tOlw37f/xzObM5mt7TAa0r7Bt ysHZhc3dMnTaCJQtsiuP1jk9x5xyk/RK6SEQcCxan5dNgHIMWvASjORTuUyml42LtDxrjT28spf inqIjRD9drRulhWd5ckHEA3IMSnU7TH+FAlVwwKO87XLKK6JN4FeULAct7W7gflpUzXCmrFQ8BB NA7JDHCCIsNfbml/a5tjyBO8Mr3Xydb1MfHNNvbC7qPwHp/od9+l6wCbBVSyDeDNfmZrB1gNXnx dS7ixwduiBjCHZbWsptSTqTUvPp9kt/xlqd4RI5QYITTexAnWxvBOyu09y36I5NfJkfZoRmkpqA fyqPQsCrwr/gUnz/0qn7RRsx4CiFKzdLG3mN5ov9qasMjtFJLeYfO6u133JcDTZk0ahMzZnsMir r6Asfh1Lu1DmxQt6NXK+RFFR1Z+op54Lg== X-Received: by 2002:a05:6a00:1304:b0:870:ef71:e8c8 with SMTP id d2e1a72fcca58-8723c64d085mr812264b3a.12.1789519443207; Tue, 15 Sep 2026 17:44:03 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87200c58265sm314134b3a.14.2026.09.15.17.44.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 15 Sep 2026 17:44:02 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-core@lists.openembedded.org Cc: Ankur Tyagi Subject: [OE-core][wrynose][PATCH 2/3] libxfont2: patch CVE-2026-59679 Date: Wed, 16 Sep 2026 12:43:52 +1200 Message-ID: <20260916004353.478934-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260916004353.478934-1-ankur.tyagi85@gmail.com> References: <20260916004353.478934-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 16 Sep 2026 00:44:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245911 From: Ankur Tyagi Debian[1] also identified the fix. [1]https://security-tracker.debian.org/tracker/CVE-2026-59679 Signed-off-by: Ankur Tyagi --- .../xorg-lib/libxfont2/CVE-2026-59679.patch | 93 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 94 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch new file mode 100644 index 0000000000..8e2ea4bd62 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch @@ -0,0 +1,93 @@ +From 016a21b1eea8e4aef4949e19cdf5f386f36fd978 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 13 Jul 2026 15:48:06 +1000 +Subject: [PATCH] fserve: validate num_chars against encoding array size in + fs_read_glyphs + +FS_QueryXExtents16 causes us to allocate the encoding[] array, later +during the FS_QueryXBitmaps16 reply handling we fill in that array. +There is no verification that the allocation is large enough, a +malicious font server could send us a small numExtents and a +large num_chars to force underallocation and OOB read/rwrite. + +A regression test is included that constructs a crafted +FS_QueryXBitmaps16 reply with num_chars > num_encoding and verifies +the library rejects it. + +CVE-2026-59679 + +Found-by: Zhixi "Jace" Sun, independent security researcher +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +CVE: CVE-2026-59679 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/668fea81f40bcb48ec67fb55d0b851049d265290] + +Dropped makefile and test changes during backport. + +Signed-off-by: Ankur Tyagi +--- + src/fc/fserve.c | 22 ++++++++++++++++++++++ + src/fc/fservestr.h | 1 + + 2 files changed, 23 insertions(+) + +diff --git a/src/fc/fserve.c b/src/fc/fserve.c +index abf7d07..744a68c 100644 +--- a/src/fc/fserve.c ++++ b/src/fc/fserve.c +@@ -1081,6 +1081,7 @@ fs_read_extent_info(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + return AllocError; + } + fsfont->encoding = pCI; ++ fsfont->num_encoding = numExtents; + if (haveInk) + fsfont->inkMetrics = pCI + numExtents; + else +@@ -1980,6 +1981,17 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + { + minchar = 0; + maxchar = rep->num_chars; ++ ++ /* Reject replies where num_chars exceeds the encoding array ++ size allocated in fs_read_extent_info() to prevent ++ out-of-bounds access on encoding[]. */ ++ if (rep->num_chars > (CARD32)fsdata->num_encoding) ++ { ++ ErrorF("fserve: num_chars (%u) > num_encoding (%d)\n", ++ (unsigned) rep->num_chars, fsdata->num_encoding); ++ err = AllocError; ++ goto bail; ++ } + } + + off_adr = (char *)ppbits; +@@ -2001,6 +2013,16 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + for (i = 0; i < rep->num_chars; i++) + { + memcpy(&local_off, off_adr, SIZEOF(fsOffset32)); /* align it */ ++ /* Bounds-check minchar against the encoding array size to ++ prevent out-of-bounds access from a malicious font server ++ reply with more num_chars than num_extents. */ ++ if (minchar >= (unsigned long)fsdata->num_encoding) ++ { ++ ErrorF("fserve: glyph index %lu >= num_encoding (%d)\n", ++ minchar, fsdata->num_encoding); ++ err = AllocError; ++ goto bail; ++ } + if (blockrec->type == FS_OPEN_FONT || + fsdata->encoding[minchar].bits == &_fs_glyph_requested) + { +diff --git a/src/fc/fservestr.h b/src/fc/fservestr.h +index 29ae46e..da95e41 100644 +--- a/src/fc/fservestr.h ++++ b/src/fc/fservestr.h +@@ -43,6 +43,7 @@ typedef struct _fs_glyph { + typedef struct _fs_font { + CharInfoPtr pDefault; + CharInfoPtr encoding; ++ int num_encoding; + CharInfoPtr inkMetrics; + FSGlyphPtr glyphs; + } FSFontRec, *FSFontPtr; diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index de6418b11a..8775d1cc13 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -18,6 +18,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ file://CVE-2026-56003.patch \ + file://CVE-2026-59679.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" From patchwork Wed Sep 16 00:43:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 98380 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BB011C88E77 for ; Wed, 16 Sep 2026 00:44:15 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4572.1789519445983312602 for ; Tue, 15 Sep 2026 17:44:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=W3hlcEp2; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85469e25187so208372b3a.2 for ; Tue, 15 Sep 2026 17:44:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789519445; x=1790124245; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eXIV9GSzys60igQw6GTgZOYelRbQVf/NYyDKx1lmx+U=; b=W3hlcEp2GEisphYClPG128Bm7dKTu/92bdC6V9higVmuXdgPCtSmZPf+6RRJzGciD8 EGj5OCC0+1VrlIWFRyVRvzBy0hVM0DzwfI4u0us3u8RY1ETo54hXoJEI3DOsjb3J7NBc hjnWsEYJGBdwtIF8YHa8kPZtmrogsG0NWr2sYw6f992atctYM8i7SuBFFS6hC4lrhm76 kJzrHE1A4eeNbUcPcROkHxeX3q2/GPpnYg4Nald+UzeOf4FqWiw7VYhJK9JHPzqJH+Pz 1iPZGDpykKe6ysTswx0foaq36wuSP5fPdRNTU80dXT15202k0PwTqsummwOuay2cOBrC 5mSg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789519445; x=1790124245; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=eXIV9GSzys60igQw6GTgZOYelRbQVf/NYyDKx1lmx+U=; b=ketdT/TDGYeWebnvsyW6e/ZApcgnfj7I412HoRKV+i5iN3WksavKv1qb1J2ah/9Azn PpHw7RrlzHJj8AXcOlHH2R/2WvR36f+b1Cemvd5YZ73JejZuDIRqsR06XiIoEOFnYrUA KFRte4ftqZDJ+WqoHju60h9HkI6jkryoAlpWNJkN3A0GXrKWjfI2ddnL3ex8EDUs1pbD wUQH6kiy1nn+4wdXsVxYs+qbRw1MAqtMaXxwsLDC5kGjYwUG2JKd7RFCet5yO1S6e2ca GLm9Cml4Myzu1qACEZTb460z3GQSVa0IHzm3rw0OtodyFG4XLlbOmwyDhJ2rfLVJRGTM seng== X-Gm-Message-State: AFuF++nJYT3xMFQn66422FlMpYkKpf5bSTtGIqgcLvUFX3BGxTS/rstD iH2Q9BA+QDNjsHQzILXKPZc2iT23jyh6F2/LyazqMZje/kLQnKEG9ftTHyMxdQ== X-Gm-Gg: AYBFou1c2hoANu/vXJqlSUGiMq/hf/b1gXIWP26HLs+yTScCm3eS7lm6qVuXGNVAqaQ WKFN7QFaKWkopNRUhH5DAJbGgXz4uUiYY+y9AwsiGuAl8TflYiPZRRpMIU2nGuVEjRSvpbYNkCF OACy3rQpSIWCOq3h3nn3QudQktuIEZl7mjpoi5Ox17ZZZWVrIghAXDulzvyotUAyDVSMhm8QOu6 eqznsiMeCSPALcycercyP78XqWwLmJU4WohBuLBBIundvUAjSjaXNtJXMofX3U+0MMfJtPOAZR2 unpTgwfgoZe61JgcqyVhJHZ0bYeEgCdmgFzoDDaKl3ts4ynD/kHwXAvhZ3IPfl1LNxd4+ELplOd Z4y7R8ZF2ZYcq6bt89ASCkwcgHKi7XbuG8Q2aQDLl7WnUrlCMUK44Hkqumgi4XXkt3U5i2V+f+r YYzmSU3s1O617dkwEev+bRkl/NZQVMHyiMb6CPMdyrHprJzGEMXcn1PCtQw4vQ4WEQUOVKd5xo7 asn1WUHBMkj2VpDjgBS2vk= X-Received: by 2002:a05:6a00:3317:b0:86a:c062:8af2 with SMTP id d2e1a72fcca58-872362fb364mr1180552b3a.3.1789519445318; Tue, 15 Sep 2026 17:44:05 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87200c58265sm314134b3a.14.2026.09.15.17.44.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 15 Sep 2026 17:44:04 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-core@lists.openembedded.org Cc: Ankur Tyagi Subject: [OE-core][wrynose][PATCH 3/3] libxfont2: patch CVE-2026-44950 Date: Wed, 16 Sep 2026 12:43:53 +1200 Message-ID: <20260916004353.478934-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260916004353.478934-1-ankur.tyagi85@gmail.com> References: <20260916004353.478934-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 16 Sep 2026 00:44:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245912 From: Ankur Tyagi Debian[1] also identified the fix. [1]https://security-tracker.debian.org/tracker/CVE-2026-44950 Signed-off-by: Ankur Tyagi --- .../xorg-lib/libxfont2/CVE-2026-44950.patch | 99 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 100 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch new file mode 100644 index 0000000000..96e3c1f0a8 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch @@ -0,0 +1,99 @@ +From b48aa50f2ba02f74167492c1c3aa312a7590991a Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 13 Jul 2026 15:50:09 +1000 +Subject: [PATCH] fserve: bounds-check cumulative glyph data writes in + fs_read_glyphs + +fs_read_glyphs() copies each glyph's bitmap into a single allbits +buffer allocated to rep->nbytes bytes. The per-glyph guard validates +only that the source slice (position, length) lies within the pbitmaps +source buffer. It does not check whether the running destination cursor +has exceeded the allocation. + +A malicious font server can send overlapping source offsets (e.g. 1000 +glyphs each referencing {position:0, length:64} with nbytes=64). Each +individual source range passes validation, but the cumulative writes +total 64000 bytes into a 64-byte destination buffer. + +Interestingly there was an unconditional debug printf in place that +sort-of warned about this but didn't prevent this. Let's remove that and +instead use the actual check to bail out before we run OOB. + +A regression test is included that sends 100 glyphs each referencing +the same 64-byte source slice into a 64-byte destination buffer, and +verifies the library rejects the overflow. + +CVE-2026-44950 + +Found-by: Zhixi "Jace" Sun, independent security researcher +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: +(cherry picked from commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a) + +CVE: CVE-2026-44950 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/c2d222bb22c623d8a40f3275077fc7e6617f2c8a] + +Dropped test changes during the backport. + +Signed-off-by: Ankur Tyagi +--- + src/fc/fserve.c | 23 ++++++++++++++--------- + 1 file changed, 14 insertions(+), 9 deletions(-) + +diff --git a/src/fc/fserve.c b/src/fc/fserve.c +index abf7d07..0fdc090 100644 +--- a/src/fc/fserve.c ++++ b/src/fc/fserve.c +@@ -1899,10 +1899,7 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + fsOffset32 local_off; + char *off_adr; + pointer pbitmaps; +- char *bits, *allbits; +-#ifdef DEBUG +- char *origallbits; +-#endif ++ char *bits, *allbits, *origallbits; + int i, + err; + int nranges = 0; +@@ -1992,8 +1989,8 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + goto bail; + } + +-#ifdef DEBUG + origallbits = allbits; ++#ifdef DEBUG + fprintf (stderr, "Reading %d glyphs in %d bytes for %s\n", + (int) rep->num_chars, (int) rep->nbytes, fsd->name); + #endif +@@ -2014,6 +2011,18 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + (local_off.position < rep->nbytes) && + (local_off.length <= (rep->nbytes - local_off.position))) + { ++ /* Check that the destination buffer has enough room ++ for this glyph to prevent a heap overflow from ++ overlapping source offsets. */ ++ if (local_off.length > ++ rep->nbytes - (allbits - origallbits)) ++ { ++ ErrorF("fserve: glyph data overflow: " ++ "cumulative write exceeds nbytes (%u)\n", ++ (unsigned) rep->nbytes); ++ err = AllocError; ++ goto bail; ++ } + bits = allbits; + allbits += local_off.length; + memcpy(bits, (char *)pbitmaps + local_off.position, +@@ -2041,10 +2050,6 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + } + off_adr += SIZEOF(fsOffset32); + } +-#ifdef DEBUG +- fprintf (stderr, "Used %d bytes instead of %d\n", +- (int) (allbits - origallbits), (int) rep->nbytes); +-#endif + + if (blockrec->type == FS_OPEN_FONT) + { diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index 8775d1cc13..17cfc133d6 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -19,6 +19,7 @@ SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ file://CVE-2026-56003.patch \ file://CVE-2026-59679.patch \ + file://CVE-2026-44950.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb"