From patchwork Mon Sep 21 20:17:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98841 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 13799C982F0 for ; Mon, 21 Sep 2026 20:17:32 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5807.1790021841236341143 for ; Mon, 21 Sep 2026 13:17:22 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=TRy3/e4c; spf=pass (domain: est.tech, ip: 52.101.65.52, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=pFYQGKe5/gGgSA5TPvlXzoFRMefDqgHwLj2dFiZggbPyH8fJIlSJQggVb33gHqLuZVpUjeRmRiFXkUOaS1a7BlyUZf82bdiLtKEBYlNmaxN7FyRs1zDaIUTJuu9uhYufPkjubglQNYqGT2NUqsTREehxlnyi//djzTfqO03HuoQ1lVhi+ZIVv/UsFGR2QesfBR78FKH4bnpb20uYIBaM2CepmVRED3YSxYmoc7WwZQe4UUXTc43LQzrvLCIwYpA9/nMqALIrdLnqYsifHtyUiZrDyKVwVg3eUjyHCt5MNTZTHShQtrmcw2TQ/3ru/+hYuAIjfVgUWlqdj+5HaOwA0A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cH+zcMqk1ajB96GrQinmdPTW4q2mgzwuUslk5e8B++o=; b=gz+nAR7jdA587iGUxS3qv9V3unLQ9SeppSmJh1l+MMEA/RJNa5UZ+IiYfuunQTwPmi4eyfaU3hFrokZaY1XTAFuCLAlxF5QdrHDhe11fnliY7z69FNQRt2lTCLsuecXRmCspEMm4h/W/T8qq2FoCOLhtZVuP/AhALIGfmfXfXInTW4577A1cVQTikQzOHMevzm/rThx3Xk6eYDP8EtBmRvCjeOrTgxVsrRMBRFpd9mtjY9fErZCjEeLVphU1wzy0AK20v1OixYrb+WXYUrbWliiN6/vGRZhy3GwlnrDEBbgJ8apIU1fBzy5p7xNQSYv3Nh+ZvD0dq7UbO5K9i+WDWg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cH+zcMqk1ajB96GrQinmdPTW4q2mgzwuUslk5e8B++o=; b=TRy3/e4cSSuPun9uvIgMYd65PiTzay0vAZ7/BnQTx9ffLJsVGEtF0qBtP2dJTxulV0p96qfGf7YW4wdJeHxZlY/9nZ5rJEw4X5XFBySuIzeEXQxoGMQVndFwlEhjwRTcbhPnvV+XAeBBtkNSM+Ghyt+vhs/bb2kPws96BfGi04MAs0GvjktWX5LCrNn65tWwU8Oh5JTPyxJWt0THyb0rGPIm7XPNxc8AF14jR8z4kicp8/sCMHVIUlWe5yCN9GPAX3TiI6e5TRguyRDU4ulEp9K1BkgeFwMLkmfDprDj9n+B+F/kFoO4KgIMzDSdUjCVo5tFmOdVGMdd2avo4DhpIw== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:18 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:18 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 1/7] libpcap: Fix CVE-2026-0799 Date: Mon, 21 Sep 2026 22:17:09 +0200 Message-ID: <20260921201715.79085-2-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: AS4PR09CA0002.eurprd09.prod.outlook.com (2603:10a6:20b:5e0::9) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 5419c7ba-be3e-4561-1ad7-08df181d55c4 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|3023799007|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: q/+BeNm8plLKpasfn1Gt6d06WRTVJEV3tbPGaVH5Nu3eLyXM4+UpPgUtf99VyoXT1i/MNyqO6oC3ro+pI4BRnTDJWJBhEVpCEUbEkR4d0JCxLixT4JXPRgeEuHI1+u3p0bTtXZxkZONfXygEEs69ZEmgFJdgkOtsokN1eBgkHvP4bx0uTs2gDN+9HSP9d2SMgjR/un8dXq45h4nRICeOqSy3ukbxQZFRMZh/MTDChB388r85Pjo6VUzaLM+rKHbzvc+G1mgIpmr2GmiD0F3IXGeAlAC+CHxYq8LLylbT5Is/CBwzJCc0Y6lFlVDK7Cf0g5C03ZCoAdr0mj4GZbXwkBMcrN9OLPPtfUWG9R29aJdJZAAC12s7u0yiaI7YYcMtGznWjl1xIUPNTeoyb6YsF7ULuuCac/eAUxg/Y+chOg7ngZ0pnq+W6w8V8KG0fufmjEwNoRGCFOzL8x2Ifc8QCfJbZKst/NC6fEqE70aOO/1/TtMFltzYIY0ACnrkBIsWkqa0uj4iyAhgyH9Gu489RM8CN/NOMYaA9rbFbueDDIJAe1gXZQH3260So8FLUlQz6KddJQ2fe04tuipzQ2IPMjs6clsAulgmZo/ZklK3cm73osUjBLEk+7nk/VmrUm10 X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(3023799007)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 7s0LinomC2XvtZWt4ltc88rSoJ9BOA0m4Bs1KDZX4VMgUKcR/Mt4GBumDXOZbzmblsso/ACnc1FcQQNDljJjnxlNQmOfKG+XYtki6IXlJcQctZ+yeSBz74M4IYxy19kstagEG6f/m80syf6xH/RHMc4IeLuNIbr/zmPSKHkuxsMOSh9ATC6H1o3XZIvbBGS25jiWtVfQRCsDWlVx3q1yE/YcQK81b56h+ZheHzjnCOGu1anfMQDgZhpICLTzoSBjic11DV/gl4jflZfquilO621xB6V4bAzzW7mYlMqYC+xEHaxQSM2d76w8Zt2KmPpiMdAFHPiJkbGtGXgBwMpRgZ4PC0wRgEBxhzBa8ashUZjguWKED69shXJEZC6x5Fwrdx+25sxgXg8qp+LOye8HYkCOsB7RBOzGlRZBQAi+T17vDpU2aAaD8Uo0mfCZ1SNbDblsBzac4r6Dum3jB642zxb/i6JiHB+1oVLfcJKA/7THHM/jnEbbtcjlfEamseqzha7yoPIqq8mWMXFtvxvtSMqAY3gyfGVzIDWNYLTnDFM6qqCIDnGqjAF6t23Qk1MNe2WG/h6YjGony4HwMm23/j53EyP7XxyEYmWo6W1TuVbKlmonL+j/Bw+nyGck9FKRkwSqDbosQj7KuK8RQqXweoNEaTBCpIMaI01abr3cIw0NGfwzJuZ4eSQtA1d+s+E5LHVT5mmLYqza5kiV0W6i0jDDlVfOCKCTNVaS3fFh19Qn347VuQl8igJ4N9aIU7M5VFy9ZCE/y3nS+AOgUVBMj0P0D+Kf5Dzw6OtCLOTtMXWNOCswbF5xWEoZTEhP7vmTeWZ+bIfAej3KQyow/KyfNR+hfMT6TsHXVj9VlkmftjoM/yVfCPNaC6DqJngwy/Z51TahffloOxL4S4xCjZSU4aoST3sAE41nf8ajm5PzLu1l4+7305PxNbSb9V0PAQwCL682DoFEQHVWnMnb3OI4J+3BqDqHaJVVqsUEEDfLbHvwYZYCXZsF2kggW5GHjyHcWKregPpZnKE7tkbXJ9kzeJrJpWfT3LSojF4zjkbL7Bd1TsFbO46mz5HM8w1gDNQxwiAyNJhFMCDmt2AADSbxjcDxH78mmj9Z5O+wxKRujqjiGlbg6zpk7E4YUsx5FS8rAkz14r3vYE/1OBNkmo2ql5HPkwSzCjy5fU9EqSjg14D6/cfNXyCdzviJGMGcV0gwgNGmA1Vm9NR+JAwVwiVBjvBwQC6qUSzMCOsjDcw06x4lYQQmcbwd+woQ5XYUWuccdnB5pmQ1eZDCZ9VwZWH0NsN8W843hLg5fSSg1EUj6DLbEutx8Tn3xM5VS5mPluHMXexbHs7/e5Hk0biUXdmG3s7sIxG6U+SGNfEDXjb0+QMdG2o+dvO3LWJ7QvlU6P7f57b1iTxTtbaRA51w3Ol8njDjBMmyC2urTGiwMeJK+HjxlMqKZxOlW4G1ngIglHp+7TPb+Tx9TrYRQw0HhOmeggICxl/sO3ro0mi+/O36d4iOJEIj0a/puEdO/iriAU/XbgxA9pyGA63Ip91/F7AJItQ2+WizMLms4/WkOXKWKifVCRemWOJNBIV7uAx0cSADTFM7nPC+Cj+/8KOgryLOmzihVV0eA3ho26FhAi3YEJ5Q7y+KUNvoTAhIcWR4GKCsHIDXuxJEDG1u6FrKleuo7dOpoSv9Jv9gUJxvgRIyYsB9YIzuE/YOlLGigIH5gpuiTSCLxEYyUdTNyLmeLtfYrA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 5419c7ba-be3e-4561-1ad7-08df181d55c4 X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:18.3083 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: PxfSwgXThsA9Y9c1Le5AkfkKeIjV435SsqkwCJI/cHBbbzHJoJyCepLyMDTEd4+Ti16ckQXioTJ9IC9oLX0u4g8MEgP/qZliBEdKyvTpuM8= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246349 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/01-CVE-2026-0799.patch | 67 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 68 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch new file mode 100644 index 0000000000..a4dfea4236 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch @@ -0,0 +1,67 @@ +From 48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:41 +0100 +Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter. + +Include Security identified and reported this problem as a potential +vulnerability in 2018 (case reference "I7"). Their work was sponsored +by Mozilla under the Secure Open Source program. The vulnerability has +been independently confirmed only recently. + +The current revision of pcapint_filter_with_aux_data() can, but does not +check whether a scratch memory register index is valid in the "ld M[k]", +"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this +is always the case. This holds for programs that have been generated or +validated by libpcap. + +However, this does not necessarily hold for programs that come via +pcap_offline_filter() or [deprecated] bpf_filter() from an external +source and have not been explicitly validated. If the interpreter +executes such a program with an invalid index, it will read/write the +process memory at arbitrary locations starting at the current stack +frame. Depending on the address, the memory layout and the OS, this can +result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To +fix this, in the interpreter reject the packet if the index is invalid. + +(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a) + +(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7) + +Notes on backporting to 1.10.4: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7] +CVE: CVE-2026-0799 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 8691d0d1..fa82d1d0 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -219,18 +219,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_LD|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + A = mem[pc->k]; + continue; + + case BPF_LDX|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + X = mem[pc->k]; + continue; + + case BPF_ST: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = A; + continue; + + case BPF_STX: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = X; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index ee7d7540f6..692fdf606c 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11961-01.patch \ file://CVE-2025-11961-02.patch \ file://CVE-2025-11964.patch \ + file://01-CVE-2026-0799.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98845 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DFC92C982ED for ; Mon, 21 Sep 2026 20:17:32 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5807.1790021841236341143 for ; Mon, 21 Sep 2026 13:17:23 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=N09W0qUr; spf=pass (domain: est.tech, ip: 52.101.65.52, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=kF7Zi/ZH0BmHaq5m3BKwpAi2rFeqF5sKw1MfjmEaDWPMJr3bjcqsTUrDq3ef4H5c/ezhFHqusQBpOXbPI7Wt1gUu38eCWumUyb3ChegK/HYgnyaYbxj3GSeVeuluk2dQSA7PzXHkoCHfoVHJk3QbStVcG4Vz1+8dVeN7GNUw1f6CZlwVEjEp+JI7Aiy8oQJYbeg6KQwuTdfzpkxhjTYV7r5ZcR1JM/o1+opxGPQcVqrIrGeD9GsBANXUBvdrxf7HLQ1AnQdeYm0VM5Selc2/fPNG/cMKtQbHwe3WLw0ruseX7o6HAicsvfT+Of65uvl7v4s0UuSCazksPPS7Q9rshA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=yRgD/jOFtp1cgnJaStg9UYZ8b71J9sa0dffBu4FIJUY=; b=qHo7yGjlyurZQVtGdkDhpjZN54kLVJgTO6yMKhVgeFTm3TJAr345+FeRa5WCY7vCkOoQJ//mPrZwTH16pyr/CyPg2uGjZvGamOedoQBNg4/fg7XcfdUSuRncOcEyrZfdOs/VkkfXp/2tRp8yzNAMf8/OoqnAUdnEJC7/deB2NTci/THbDajTpYMHVjW4atTsETZGml5DTD8SNLcbJ0/LNpg/gfmjUxeMGyezfoiGoJhofKC9v8cgCw3NJJdRcqTbM7zycfNVUlGmUVwwuggCqEd5KdJNZ2r5f9NvCvjM9PFS5q9+lOWARECz+TGmB7qOZo/CKPkpqXXyjdRqKch2Ag== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yRgD/jOFtp1cgnJaStg9UYZ8b71J9sa0dffBu4FIJUY=; b=N09W0qUrg7cAiTkn1ziaUu/li7wJMFgUJvxw6ujajZoa4Ue+BwVKUfFdes6FdZgcwv7gJTfBeVJjmZ+hSWq6v077auZYTQzsMNbA4P8QQHUdSlf3cKcWIbdm4Fzi2n7mWNkLSCojTdDoIIDNIix2tTvlIQF9/0esYbu5kAx6ogcZWIvMmXEFpR7KuAG3MyLBccTPfyBOxEvxliy1S3uZgSQP3Z1IwauFEaxxbCMKe/Tuc1b9cVOMKklVF6Zp+2FklUa9d12c7zNAxGcu+OLj5+xwYR0kQj/XJCKQLTtaWb5Z4v0yYw3W2ytSBYbJtfLWQIz42eu6QHZ2rGXJVv9RMQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:20 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:20 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 2/7] libpcap: Fix CVE-2026-31912 Date: Mon, 21 Sep 2026 22:17:10 +0200 Message-ID: <20260921201715.79085-3-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: VI1PR03CA0077.eurprd03.prod.outlook.com (2603:10a6:803:50::48) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 44d41be3-dcce-4c53-4bc9-08df181d56c9 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|3023799007|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: irvojTqUJeWrKyY9m1Skfa0dz/yBvWI8ts4ptte0SLa/adAFDr/tsOIot/WAA5WzV7MGSSAZtdGncjaFLZVNAVLSsqTXf/rsLJWNnJgM1l+LGmISxuF0M2z98uyP0eLc0pdf7ckEvMyNsRVcKx6z9kfIWWaxEBeppij8nb1PLnY3YYiniiWxYUMJJrvihOI38U2OXjA+hS5OzzBJ2CDBGKEFFQFATZLDiQoIUm2mrCy/v6OmWsi5RssMM3MPTXSoZbvKemxMTdLzZlSA0wc61tn1DxCMgJk9DJ3KzfAz8ktLirKWiCqPcUdmizKDP9m+KT7TPSzU5eoyAEo8SnnuQzgbADHJ9+xRiWaDeirusQB4wmJ0njxSsQ7Cjpeu+AD+nkGb06vMJmiUA41IckHBSd65VFJVulUUmDDeQ4bkjkuL1nf1UZWxVsIdCoO5Ydjk0cB1ATBVu2zkTND9uakuwrYpht/GaSg3DEhSgrgyt/pA7Rk0PB1OPiwxFttEYdgGZ9C8B4So/k+ZkOZQ4daknJAw43MPKzlhQnAcDVDfkKclzPKkcDtg6AVUN+4VLo5V1NHPBvauJj+TuAuqlY0zvPyj5fnsNrj5wmZqOntSHjU= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(3023799007)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: TCsI+p3q3/kgS/1I1X0fY2xzRiOCkUpF4s9yai0vFLiv74/1jKImhN4iML5o0Bw5aHWW+6gE+bi6YXPvMr3BTBhilqSICIeRlIQ3tOYTLMyIVpXGWfhfBNIVGhyvBVqmw1UAZyOxJpmKitnV2YHJNr+mRTkqnUq1pJoPcr6HvYT82UuJZmBgeXvct2GJYg9fhD9bKcVBmZq1m415PcaMTOaGcweUeMYuerpizaRY0wfBYBb/NwXMxz69r2Xdh/wys1cAs7N/D/WWxnLnFxnjMldKQgeSd/bnn8WYbbBkMNDdzS9k58lvad2hv2k5b29szPm23MUNRvmWiYqjqgIG8Fl2bVEFqdGEHvYB2mQQu2MOelg2jLf85lgje6eL/4thhWCJ7kTDZbxUl3HoIoJAyDlQWDYG8ydaezwOI5IXnWIX09nNWhrQMwJSBadi+v1XzFs9tKpyFqD1ZUYS7Mkay+AA3uhm2BwSfDXuGr6/oDGAWdPlSPWjI/hE2xh+F2FaWUM72wISVMB4O6/tUPOFpVqZ0bs3hjpkovBOyohcxNNBtU1MtBdU4wJdVz4QEKtwkG/Ao6zCQoZgNMpQ/Fh/Wj+0CgGsnuXlULqu96rQsQdarsizyAbwTTCICyUIeZZ6w0jawegGoA9DHBRmVMXAnvIRVr6C2w0VHZllU3eioEsLguddAo1WWoeH07ytZVUXiXIOrMyRO5Hiyn9P+otPiu7Ty+krcRD91t95BfxiIvBB4sdAeyB7bDevay4CP4YmpUT1BizuaATPpHEro6SlB0Cg5oxD0/7NVHG489vaUEeduPM3DcGDdSFrMgouvrzDAG1rVIyEHIA1k1Bdg1aSLzBWfr7WoQLVc05vjTidiL5TDvsmOiP6Vd/K7NUZTVhfGwQjGDDH1DlIHDxSIsGPs+oS1LSvRt337jLTzR8xImmP1lPQeafzpGs8SB09ciNZK8m8IJo0LLiLMTNwiILHtmlshHTP4aqzqhM2Cy8IR2vwLJ7YnijrcUddAtN2I9n3n/BRXjgExFEl3DdWaYn/E5LW/iIo43wPFzNagXiEgMhwXdzNyITno2XC0VkLgxlHeCDg7B8NHP8HPhBP1JGElAGufj88VT30xlV43pEyNb7EBJWkR6WgFU9BS8UtcuPTVD08adDeyusywHDHcpcxSa16h/tJIvKYtPOzBn/wRYDmvcdMk+6f9mhBHWecxKy7dZsTMcqtNgIwqdSIwPpKWCT00Tj9SrAuvWvQeFieN/FcdjpY4ARZqZKtUaWcz9BDSAdgw9JYa3k+SDoJn3oS2VgpvumkA8S5MWm0kUdSF7lp2ep0w0WpDXVNxKwZBlvox8ZQ2L4TG8mnMOJJX0qyokWWBh3CreO3g0ME1kawjyR3LfyJXVWmAOmW7Zw4TDrSB65Hx4lPmc5J/II/RwGYttCgAywJDmCFtx2LAn5kc3CVWA/iffh5tYahv+OuPakjyPSKdXYxhJEo113KUPlDW+DKFGao9N+iChFQ1GSp9IiokDBS+xLnbnt/lV1SsHfMBraZJ/6y7iXWXx82LaIsr5L8B9Voa3cmYjjyWxFJUVtjIeTNyzIMSwQjXC+FWVI66DbEZe1ZOKmh3h2K3Hs9bGz0EAonXPeyTlmjHfbi9w8ZujRBXr/m1SC6PurP8/x31rI0flLuyQOvPPFx+mvua6v5wDg6zT4rvTQq4QLLrCTv0hfeU4jPEEN3qUZoI1qZSZFbfRRQSVY5d4qIGhlsoQ== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 44d41be3-dcce-4c53-4bc9-08df181d56c9 X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:20.0664 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 8QnTc3j6LdoEQV12aPGkAvvN2PRVhdPQB09yrQIIF1Hw06a0AMckJ+fMXmRpl3de2I0ADZXN3N/GhqS2Xf8Z9AgbdRy2+DUAVTP5Rpd6lag= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246350 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/02-CVE-2026-31912.patch | 525 ++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 526 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch new file mode 100644 index 0000000000..d9fda1ec48 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch @@ -0,0 +1,525 @@ +From d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:55 +0100 +Subject: [PATCH] CVE-2026-31912: Mind the program bounds in pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() does not know the +number of instructions in the filter program, it assumes the program +counter always remains within the bounds of the provided filter program +and always reaches a return instruction. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program and advances the program counter beyond the last +instruction, it will be interpreting memory space after the filter +program as BPF instructions, which in the current implementation will +eventually cause either abort() (another commit addresses that) or +SIGSEGV. + +To fix the latter problem, in pcapint_filter_with_aux_data() add a +parameter for the number of instructions in the program and reject the +packet as soon as (or just before) the program counter goes out of +bounds. Update all incoming code paths to specify the length; also in +pcap_offline_filter(3PCAP) make it clear the function now requires the +'bf_len' member to be set correctly and uses it. + +(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551) + +(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9) + +Notes on backporting to 1.10.4: + - Adapted to the 1.10.4 pcap_filter*() names (renamed to pcapint_*() + after 1.10.4). + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9] +CVE: CVE-2026-31912 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index fa82d1d0..dec336ea 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -72,6 +72,24 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++/* ++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the ++ * userland interpreter in libpcap is meant to support much longer filter ++ * programs. In the latter case it is important that BPF_MAXINSNS does not ++ * interfere with the safety checks in the validator and the interpreter: ++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX ++ * It makes the most sense to be able to interpret as many instructions as ++ * pcap_compile() can produce, without optimization, for a valid filter ++ * expression before it consumes as much memory as the current definitions of ++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost ++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit ++ * machine. ++ */ ++#ifdef BPF_MAXINSNS ++#undef BPF_MAXINSNS ++#endif ++#define BPF_MAXINSNS 3060000U ++ + /* + * Execute the filter program starting at pc on the packet p + * wirelen is the length of the original packet +@@ -86,12 +104,14 @@ enum { + */ + #if defined(SKF_AD_VLAN_TAG_PRESENT) + u_int +-pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data) ++pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data) + #else + u_int +-pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_) ++pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data _U_) + #endif + { + register uint32_t A, X; +@@ -101,13 +121,36 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, + if (pc == 0) + /* + * No filter means accept all. ++ * In this case the value of 'proglen' is irrelevant. + */ + return (u_int)-1; ++ if (proglen < 1 || proglen > BPF_MAXINSNS) ++ return 0; ++ ++ /* ++ * Require the current instruction pointer not to overflow for both the ++ * filter program (where the pointer will be dereferenced) and an ++ * immediately following margin (where it will be not). So long as the ++ * margin is large enough to represent the destination of any single ++ * conditional [forward] jump from within the filter program, a single ++ * guard prevents all filter program over-read attempts that result ++ * from the program running out of instructions before a BPF_RET or a ++ * conditional jump directing the interpreter beyond the program end. ++ * Unconditional jumps mean a larger problem space, which the BPF_JA ++ * case below addresses separately. ++ */ ++ const struct bpf_insn *pcend = pc + proglen; ++ if (pcend + UINT8_MAX < pc) ++ return 0; ++ + A = 0; + X = 0; ++ const struct bpf_insn *pc0 = pc; + --pc; + for (;;) { + ++pc; ++ if (pc >= pcend) ++ return 0; + switch (pc->code) { + + default: +@@ -243,6 +286,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_JMP|BPF_JA: ++ /* ++ * The pointer (pc) decrements and increments in units ++ * of sizeof(struct bpf_insn) == 8 bytes. The number ++ * of units is in the [INT32_MIN, INT32_MAX] interval, ++ * hence the result can point before the beginning or ++ * beyond the end of the filter program and can under- ++ * or overflow; also on 32-bit architectures it can ++ * under- or overflow more than once and can test ++ * negative for underflow, overflow and out-of-range ++ * conditions after under- or overflowing at least ++ * once. ++ * ++ * However, it has been verified above that the program ++ * length is sufficiently small and the pointer does ++ * not wrap within the bounds of the filter program, so ++ * there is a one-to-one correspondence between BPF ++ * program counter values [0, proglen) and all valid ++ * values of the pointer. In other words, after this ++ * unconditional jump the pointer arithmetic result ++ * will be valid iff BPF program counter value will be ++ * valid. For the latter problem the solution is ++ * almost the same as in the validator. ++ * ++ * The main difference is that here the current value ++ * of BPF program counter is not a 32-bit unsigned ++ * variable, but a ptrdiff_t expression, which is ++ * 64-bit signed on 64-bit architectures and 32-bit ++ * signed on 32-bit architectures. However, the cast ++ * to 32-bit unsigned is safe in both cases because: ++ * pc0 <= pc < pc0 + proglen, therefore: ++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX ++ */ ++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -396,10 +473,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + } + + u_int +-pcap_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, +- u_int buflen) ++pcap_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p, ++ u_int wirelen, u_int buflen) + { +- return pcap_filter_with_aux_data(pc, p, wirelen, buflen, NULL); ++ return pcap_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL); + } + + /* +@@ -419,7 +496,7 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + u_int i, from; + const struct bpf_insn *p; + +- if (len < 1) ++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f) + return 0; + + for (i = 0; i < (u_int)len; ++i) { +@@ -485,33 +562,45 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + case BPF_JMP: + /* + * Check that jumps are within the code block, +- * and that unconditional branches don't go +- * backwards as a result of an overflow. ++ * regardless of the direction. libpcap uses ++ * backward jumps to implement the "protochain" ++ * primitive. All offsets that mean a backward ++ * jump in libpcap (whether in-range or not) in ++ * kernel BPF implementations mean out-of-range ++ * or overflow forward jumps -- kernel ++ * implementations must reject that. ++ * + * Unconditional branches have a 32-bit offset, + * so they could overflow; we check to make + * sure they don't. Conditional branches have + * an 8-bit offset, and the from address is <= +- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS ++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS + * is sufficiently small that adding 255 to it + * won't overflow. + * + * We know that len is <= BPF_MAXINSNS, and we +- * assume that BPF_MAXINSNS is < the maximum size ++ * know that BPF_MAXINSNS is < the maximum value + * of a u_int, so that i + 1 doesn't overflow. +- * +- * For userland, we don't know that the from +- * or len are <= BPF_MAXINSNS, but we know that +- * from <= len, and, except on a 64-bit system, +- * it's unlikely that len, if it truly reflects +- * the size of the program we've been handed, +- * will be anywhere near the maximum size of +- * a u_int. We also don't check for backward +- * branches, as we currently support them in +- * userland for the protochain operation. + */ + from = i + 1; + switch (BPF_OP(p->code)) { + case BPF_JA: ++ /* ++ * So long as both 'from' and bpf_insn.k are ++ * 32-bit unsigned, this check rejects any jump ++ * offset that points outside of the valid BPF ++ * address space of the filter program no ++ * matter whether signed interpretation of the ++ * offset is positive or negative. ++ * ++ * Note that this condition is necessary, but ++ * not sufficient to get correct results from ++ * respective pointer arithmetic in the process ++ * address space. Other necessary conditions ++ * are that BPF_MAXINSNS is correctly defined ++ * and enforced, and that the pointer does not ++ * overflow. ++ */ + if (from + p->k >= (u_int)len) + return 0; + break; +@@ -539,12 +628,14 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + + /* + * Exported because older versions of libpcap exported them. ++ * This function is deprecated and unsafe, use pcap_offline_filter() instead. + */ + u_int + bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, + u_int buflen) + { +- return pcap_filter(pc, p, wirelen, buflen); ++ // The actual length of the filter program is not known. ++ return pcap_filter(pc, BPF_MAXINSNS, p, wirelen, buflen); + } + + int +diff --git a/dlpisubs.c b/dlpisubs.c +index 6815b0ec..790acf28 100644 +--- a/dlpisubs.c ++++ b/dlpisubs.c +@@ -195,7 +195,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user, + bufp += caplen; + #endif + ++pd->stat.ps_recv; +- if (pcap_filter(p->fcode.bf_insns, pk, origlen, caplen)) { ++ if (pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ pk, origlen, caplen)) { + #ifdef HAVE_SYS_BUFMOD_H + pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec; + pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec; +diff --git a/pcap-bpf.c b/pcap-bpf.c +index 2898e598..04b5620d 100644 +--- a/pcap-bpf.c ++++ b/pcap-bpf.c +@@ -1255,7 +1255,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + #endif + */ + if (pb->filtering_in_kernel || +- pcap_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + struct pcap_pkthdr pkthdr; + #ifdef BIOCSTSTAMP + struct bintime bt; +diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c +index c7bfef1d..dcf3b575 100644 +--- a/pcap-bt-linux.c ++++ b/pcap-bt-linux.c +@@ -394,7 +394,8 @@ bt_read_linux(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char + pkth.caplen+=sizeof(pcap_bluetooth_h4_header); + pkth.len = pkth.caplen; + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c +index 206e65b5..3f9d5b49 100644 +--- a/pcap-bt-monitor-linux.c ++++ b/pcap-bt-monitor-linux.c +@@ -151,7 +151,8 @@ bt_monitor_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_ch + bthdr->opcode = htons(hdr.opcode); + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-dag.c b/pcap-dag.c +index f261ead0..c3fe1dbd 100644 +--- a/pcap-dag.c ++++ b/pcap-dag.c +@@ -668,8 +668,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + /* Run the packet filter if there is one. */ +- if ((p->fcode.bf_insns == NULL) || pcap_filter(p->fcode.bf_insns, dp, packet_len, caplen)) { +- ++ if (p->fcode.bf_insns == NULL || ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ dp, packet_len, caplen)) { + /* convert between timestamp formats */ + register unsigned long long ts; + +diff --git a/pcap-dbus.c b/pcap-dbus.c +index 506f150f..760bb9ba 100644 +--- a/pcap-dbus.c ++++ b/pcap-dbus.c +@@ -91,7 +91,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char *)raw_msg, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char *)raw_msg); + count++; +diff --git a/pcap-dpdk.c b/pcap-dpdk.c +index 025a6748..cc31d2f2 100644 +--- a/pcap-dpdk.c ++++ b/pcap-dpdk.c +@@ -407,7 +407,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c + + } + if (bp){ +- if (p->fcode.bf_insns==NULL || pcap_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){ ++ if (p->fcode.bf_insns==NULL || ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ bp, pcap_header.len, pcap_header.caplen)){ + cb(cb_arg, &pcap_header, bp); + }else{ + pd->bpf_drop++; +diff --git a/pcap-int.h b/pcap-int.h +index 894e74af..11ca3c56 100644 +--- a/pcap-int.h ++++ b/pcap-int.h +@@ -619,13 +619,15 @@ struct pcap_bpf_aux_data { + * Filtering routine that takes the auxiliary data as an additional + * argument. + */ +-u_int pcap_filter_with_aux_data(const struct bpf_insn *, +- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *); ++u_int pcap_filter_with_aux_data(const struct bpf_insn *, const u_int, ++ const u_char *, const u_int, const u_int, ++ const struct pcap_bpf_aux_data *); + + /* + * Filtering routine that doesn't. + */ +-u_int pcap_filter(const struct bpf_insn *, const u_char *, u_int, u_int); ++u_int pcap_filter(const struct bpf_insn *, const u_int, const u_char *, ++ u_int, u_int); + + /* + * Routine to validate a BPF program. +diff --git a/pcap-linux.c b/pcap-linux.c +index 13bd8529..b2b2ca70 100644 +--- a/pcap-linux.c ++++ b/pcap-linux.c +@@ -3993,6 +3993,7 @@ static int pcap_handle_packet_mmap( + aux_data.vlan_tag = tp_vlan_tci & 0x0fff; + + if (pcap_filter_with_aux_data(handle->fcode.bf_insns, ++ handle->fcode.bf_len, + bp, + tp_len, + snaplen, +diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c +index 2eb0fc8c..5b5f5c18 100644 +--- a/pcap-netfilter-linux.c ++++ b/pcap-netfilter-linux.c +@@ -259,8 +259,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen)) +- { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ payload, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, payload); + count++; +diff --git a/pcap-netmap.c b/pcap-netmap.c +index 27d36e5b..bcfd6e93 100644 +--- a/pcap-netmap.c ++++ b/pcap-netmap.c +@@ -81,7 +81,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf) + const struct bpf_insn *pc = p->fcode.bf_insns; + + ++pn->rx_pkts; +- if (pc == NULL || pcap_filter(pc, buf, h->len, h->caplen)) ++ if (pc == NULL || ++ pcap_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen)) + pn->cb(pn->cb_arg, h, buf); + } + +diff --git a/pcap-npf.c b/pcap-npf.c +index 99b5981e..a4364353 100644 +--- a/pcap-npf.c ++++ b/pcap-npf.c +@@ -682,7 +682,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + */ + if (pw->filtering_in_kernel || + p->fcode.bf_insns == NULL || +- pcap_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + #ifdef ENABLE_REMOTE + switch (p->rmt_samp.method) { + +diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c +index d63ca898..c8763b33 100644 +--- a/pcap-rdmasniff.c ++++ b/pcap-rdmasniff.c +@@ -172,7 +172,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u + pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + ++priv->packets_recv; + ++count; +diff --git a/pcap-snf.c b/pcap-snf.c +index fe9cc9c8..16ce9c8e 100644 +--- a/pcap-snf.c ++++ b/pcap-snf.c +@@ -192,7 +192,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + if ((p->fcode.bf_insns == NULL) || +- pcap_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) { ++ pcap_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ req.pkt_addr, req.length, caplen)) { + hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision); + hdr.caplen = caplen; + hdr.len = req.length; +diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c +index 726e4a8a..44b2bf30 100644 +--- a/pcap-usb-linux.c ++++ b/pcap-usb-linux.c +@@ -735,8 +735,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u + pkth.ts.tv_usec = info.hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, handle->buffer, +- pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ handle->buffer, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, handle->buffer); + return 1; +@@ -904,8 +904,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch + pkth.ts.tv_usec = hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcap_filter(handle->fcode.bf_insns, (u_char*) hdr, +- pkth.len, pkth.caplen)) { ++ pcap_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char*) hdr, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char*) hdr); + packets++; +diff --git a/pcap.c b/pcap.c +index ef1bbb71..9ee83f98 100644 +--- a/pcap.c ++++ b/pcap.c +@@ -4179,7 +4179,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h, + const struct bpf_insn *fcode = fp->bf_insns; + + if (fcode != NULL) +- return (pcap_filter(fcode, pkt, h->len, h->caplen)); ++ return (pcap_filter(fcode, fp->bf_len, pkt, h->len, h->caplen)); + else + return (0); + } +diff --git a/savefile.c b/savefile.c +index db8a3aa0..e9708b23 100644 +--- a/savefile.c ++++ b/savefile.c +@@ -687,7 +687,8 @@ pcap_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + * and, if it passes, process it. + */ + if ((fcode = p->fcode.bf_insns) == NULL || +- pcap_filter(fcode, data, h.len, h.caplen)) { ++ pcap_filter(fcode, p->fcode.bf_len, ++ data, h.len, h.caplen)) { + (*callback)(user, &h, data); + n++; /* count the packet */ + if (n >= cnt) diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 692fdf606c..323cca3d98 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11961-02.patch \ file://CVE-2025-11964.patch \ file://01-CVE-2026-0799.patch \ + file://02-CVE-2026-31912.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98842 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 14A64C982FA for ; Mon, 21 Sep 2026 20:17:33 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5807.1790021841236341143 for ; Mon, 21 Sep 2026 13:17:24 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=vi7ikXCi; spf=pass (domain: est.tech, ip: 52.101.65.52, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=t8K2DarSXxsSKRAmaC5gjQbEMmhKklNWLUfo6VO3A+Eg1KLmxMlp+axqTKzuprYbNuW5Lh5+Ho+og7UtS6934iXDBoish7o+gokv/mQarCMKBh/1GOyQlEq30Np041YuHNEw5Jt/s9MurCMGueYLnrQbyimLaE77fv+otd9ViZsDMp9A9zdutmA0Gzd9dyqMbPXx4izu0945UO9OxXxnKEhgF+9vEZ9mWUEbQ+bthc8M1ZD/IZEACrJPBnomU15oBlUynjodxC2ZRLK5rL5ErpUJp/NdoaK6TlaCKKw4XaoBREOBWOeoUGW4KlpMe5Bs/X+KtcGNsFQ10C8kocz65g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rqLn+agFwRZya8Nlmc/+WoCsZiYU5thhu1qJhJN8OH0=; b=eHvx/LT99HnuuYERa70ZTNivvhz/Bh42kfHD/HlvdFLxGJHDF3dCnIRelC9RfH3h4k1PXnVsQCT5wVaKFSwScgSbYXAJzUsZKR9r7U6qoAYOW/G5ZOL2NDMpGuX/XVE5+FsKG5a6YFP3BzHE6ky+0x5pCWeBcyOHSbjSLpPC1+AfQy4VXFn2Tq8U8JQAJMCI6yA/IeZRIcJJ5K38fu6bV8vs+MK17b8DL8s3bIZuSY7ZXl4zmpRUzDADk/vFBms/6wXkimR3HKpY9g10OoDJ/sk7tRw9fZlTLQYNifDpJMY/lSRXnOarQKpRv4CNXkfaKHMrVBcUFrkcb12CkKErSg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rqLn+agFwRZya8Nlmc/+WoCsZiYU5thhu1qJhJN8OH0=; b=vi7ikXCiJafW3r38hl3S+Fcf2WRuqV0d4L4f5CZIGknrCa7GSlHmgKiX6ww9nRbr0/1Q8V76/D3QD2q3H1YK/QFv9SLkiLlzCdfE19GA86aDrlxVomzkn3NZgb3/5UPtCR5OOXnhVedmWr/QAwezmNi0U1Vmi9GsPMXhSii/sGVq9us3S1VnNFMThtu0zPa9c0nc5ogSBe/PFxCUtmxV4GRisaBgYrAztXkd1fpf4oBNCnoBeOX8Clz0fLPk7p8Ot/bjaX2L2EFdyJ/0Kr+Uhz1s/YoGPuaL2vcjIPI0wGFQI+CADOvyWTyhugHpXsDxSXofsdL1f9Fexp9DaHkV2w== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:21 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:21 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 3/7] libpcap: Fix CVE-2026-31911 Date: Mon, 21 Sep 2026 22:17:11 +0200 Message-ID: <20260921201715.79085-4-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: CWLP123CA0050.GBRP123.PROD.OUTLOOK.COM (2603:10a6:401:59::14) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 6ac741d2-cc4b-49fd-302e-08df181d57c8 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|3023799007|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: tTAMWeKbC95EQEmgnfYy6OuI4Y+8og/PwRdMi4SE1MRBnpcIsZqmfG2laXhRy5oA4UNNHkpIcdjsImeMi0SBKmGQWKJyrvL/K1sg2mMVwTtAryKMaHtk1BoBAlitrStlaI0rh8zXkoDJCMqMNsyr05yETHh38aTbqumkrsVlR+4DJiFChFWseso1LcUTFvV3PWewz5PQyXdgZgvnmWRMypNjJd8EESeGd/clbdLI0HPM07juuuKQr0/qmLuOZnWJJdCBsPd2v8MlWCzIUXZEK30P/jtNSUfSa1bb0soogG6eDGJZ/nBbpixCLHwTuLS4CFJtouO/3mlxsr8izrirQGltuvPVv7lWXC00uV0hRJZDrKLQSltYiUuyxWauzXY/8xdluL3NMNmjef1lF8PT0T9BC1qhT4ozzwaIPUcOzf28PoHk8HCnexs535DgTJjs05PFlrnq+QS3cnoKjuL+6DEEJhqhSpueT8zC0w4Lc49eeV2gse34k+wA7JbyKOSDR4wW3+IaVgzZUzWjjNZDkCvENNMYeNjP689PAJMetQqTQE7o6YPHg3Yf7euTvjQGkcstQ2XY/kUo/xYjsbYSqNFXLMUelTi0BNytuCJAVLM= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(3023799007)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: D/JYJuXf5EXpXPyJsl0Yaq5vne79EyvVG8FRDuqtdkwTxCyYQq6Fd9JP/0OQ+IgycioCbFaLOftQC11P0zcuD2VPj2JdzBa3RJIzUbZ/nADI+9oFtC1J9foy/z5ppW2EfU3Gw/MFJ77xuE+XjC+Qm3ztuEXfpiOkL31H0YOvdO3lL99GpeTDVRxdfsXZsQpHXGUZpdpqKUaQLd3f7n/kNzLGz0xRV+eSn3eM4GdoCug8ASNWk3G2tfNdCoWn01+QXDxzeh1vbzj/Z1dchlDsRja8a6cRm4xZbrr3wrC3cT88JA8g7A6KfXR8bZ+R+em7xqN3f9FWXzLHJAy6ICx8qzYo7qf5jbZyqbynp+ozmDIOhEmjc9MDi4av2zhViWrJvrShbmWQuhre9+g6MJ8t757XhOAl1o7ddUqw4fU6eKvIG7D9PiHSwE+I9F5whxWTmlMUtrZbSSANhAFnyOAlbWDMGuqPHJWh1RjJymJjogLhPyoQzF0WWMOC6dnUKlUEKBKDkgvM8x2BPz0CdyMfaL7CwKO6wrsHBOth5F9zYEXhOvqLDpM4Y8EDpzPrVgYTBiRUmHcQ6Tr5114BnLoiWl8OG9AMj2Bo5XLMFB2wzDt6jPsavWPfpxUSmtLF5eiWN3Uq/AmCUUCnR4c4gVdkOp11HTKqzl1N4Jg6Dg6sUB0eSRGMtadNsYSDcbO7gQNGo/PRCsTlPxyt1zqE7MpSt98/E7gaPTC/GVPQ7weAdCyhjXSUEfbKvIH3ZuJgy+vaROPJNKU7gxP1sBsceVN1x9YUM78tjQ6sJh2F2YCoz1Jn6pWT3LDGCrg/Ob4X1czQ5EPmjGI8wy4uygw7hmoUeB9fBhjEtHcZsyRCHMLZwbhLe+ODPHUE4Zf6FQi9DLB2uHbdZ83Ok0J9p1leu8Ob973B09mIDwlRUma3W3mNoe5hjFtv8SZNfrgu31xMXbwSVJvs30Q0PkDjsDO6mNiggGZgsl07u/IjDtAu9qrMtluKd+VHJzYy9lJfGHoVznRKHpRhXJFEWxOne69D8XqQrBUcEwUkyK4Qh3UPD4/dNqB9JgZ2BUcGdCtJzmwJspollPuZckAIFxukpApMsHC7sh6OmM43VzDjVSeo7NeSk/qQ41UGDf4P6yPgPy3muIkONt+TcZdLWEjjobSZFqj4Cjqzh32JXKdShC0xNO/XUvVrTjjiWskxDSQjKDg+11AfX7iHLsbHwMGmxXwQ0IZMA/TgcfstEcE443giYak61RYkT5t8vShJWEmFWPv8PLvsxdeHQ8Nw5MxcjitjTo0PM3dj8LJcy4ThlcxQ9CBZ9WlgK0oMc4+WajBLKJGbHcSAKnEMtWVOp6mKHWsV5Zxw//XkzAmXmbF0tI9/xG5dDX8x4kTQVEiXBJF+51Pe2UcEyn2unwLBC8dXD3TdIlEtbN134KE+IPpR+7yzEkbv+ktVfLHKa0Tj2GEk8J+iOlrt0CVNcSFqs2C5c/vxWjGWHdmYiyufO9Myoyju80pL49UYNx8ipRQFtcsqptRIlAyQusRKw/uT7UH7po8fQe/oGnBGGY6aGvIE2ExPuKgpakxAMOSRM2CYzNuE3Od2ENsELvBdZI7JiT8Go9xnEV9f2UFNIhVakMtPz+yoFaBP+/s2nZVEHR/jRJu0aN6Ctn66UzBt4EX3tmiGlxxzjT6Q20qQl4XCLpgPWG+gm5qC/pKIRvF/l8fGiQov7Jb21YfSQgvHt5xIGqFwERT2Xt74nA== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 6ac741d2-cc4b-49fd-302e-08df181d57c8 X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:21.7022 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 6NzbyJljZf0DmuW/ysLqY3GSUwj+L142a6pzcw0J5fV6bEDSXO9LUh/IkElT8vlVhCUoa24mycAG1NvH2es6/20LhXnHKb2cD1Azxd/g6Vc= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246351 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/03-CVE-2026-31911.patch | 45 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch new file mode 100644 index 0000000000..a2d00d8c53 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch @@ -0,0 +1,45 @@ +From a715bcdde830299cba4171514385cb17ec19b6e9 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:08 +0100 +Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + +This vulnerability has been discovered by FuzzAnything Organization. + +The current revision of pcapint_filter_with_aux_data() calls abort() if +the current instruction opcode is invalid, and assumes this never to be +the case. This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +Furthermore, this does not necessarily hold for programs that have been +validated by libpcap because the current revision of the validator has +gaps in the checks and accepts a number of invalid opcodes (another +commit addresses that). + +Thus in pcapint_filter_with_aux_data(), when the instruction opcode is +invalid, just reject the packet. + +(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7) + +(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9) + +Notes on backporting to 1.10.4: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9] +CVE: CVE-2026-31911 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 2ea11d46..d6e4b019 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -146,7 +146,7 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + switch (pc->code) { + + default: +- abort(); ++ return 0; + case BPF_RET|BPF_K: + return (u_int)pc->k; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 323cca3d98..5b97c14e85 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -19,6 +19,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://CVE-2025-11964.patch \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ + file://03-CVE-2026-31911.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98843 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8C625C982FC for ; Mon, 21 Sep 2026 20:17:33 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5807.1790021841236341143 for ; Mon, 21 Sep 2026 13:17:24 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=OJHb9mvY; spf=pass (domain: est.tech, ip: 52.101.65.52, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=eSYZaih6MN4+BE0dzQxb1gklAWTi0MeyFEsR/PBCJGH0wid13uGaXNXl8PYE+KHpH6n7rXr0Dfkm3YllD7Qq35osy1OSZstN4khp7If3FE5wmWlsCZFwnRcSvb5hpcCl3D4bSv/8pEZwoV4YzbNBCeyaGNkrSiQwd+acfipEWtE66b388CgLVtOU6BAIk53LoqnH1ZJkedupQB2Jx5QZE8kGVmW3CD2e2v1xJZmfFjSUaFFfUWY9gL04ImZOWPfEQwbAjvpIwldaoAqR93ckeVvTz3lFh4zfVLh5Sb0OtcKzo0SQ6rCYyKsIqJuXzuEjIzemsrNeuqf9xWuL6M5K4w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=5a6wgmYxO1aBeckioTV1DZCwK+Re+GgRIdMCKWTouEI=; b=Cju17387pKszc6axpFlGjVh8YJnM0VgoBi0Wf7cxIvWItGANibrgk6braS3f2wYSnfEv/F/yGmXJhagn0+y+bmHwyS6jWlmgKOz4+n98R9X2uOQ4QQv9Yu5epgxu0ujern55fJP78OLpESB4OSLzNPGnyhtWNWaZwdpsEAebSQDg0a5veiIvWhFPdSBqrurvm8RnrK1Q4vdbvfFwfz/c88dBXLMsIxXKBmjQ4xs5kR5CKR/V+6Co0bwh10ti82Q7irz3PLQhBCtBiEjZiCMnmtJXpx31Aqeb4c4Esk6ZNjCjy1YzxqFQqYBZIZ3WZhyYkjeZKCYRvzFmxva734ujNg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=5a6wgmYxO1aBeckioTV1DZCwK+Re+GgRIdMCKWTouEI=; b=OJHb9mvYtZZXIM5uAiM2uBIyIJoZ7KDis8RzFArCmmqz86s5EthfUp54geetvUTXTvudYnIiRCKECjMpxfNuKwil1zrwloRVY0QWBL79FxMztgYBGIMg0kX29V9Xbu8YVmAPJCeFVOpnuv2AOoLCXiu1iFrrEhWtwHBmkNg5+rD6oTXms/QyAy1SszAs7fPFzqIqD1MG1K/A6H8w2Ixv69qmbYy99MttB7o2xzIuxbejKmXkwVdByWG/eb9PzJE8U2BRHYkAoa1M0xkGlSKhIuiZM7cvihTcbc7CCM/lR+azzUBMb5ylQX2W3nlspiQUae2orH79Ih/1IV0L5Gdq3w== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:23 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:23 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 4/7] libpcap: Fix CVE-2026-6244 Date: Mon, 21 Sep 2026 22:17:12 +0200 Message-ID: <20260921201715.79085-5-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: OS6P279CA0064.NORP279.PROD.OUTLOOK.COM (2603:10a6:e10:3f::14) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 3dbe5ccc-9f80-4930-e6bb-08df181d58ae X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: 5Wpr6/MwQzJupObuSlhk1FTReeK+XdO9LrYkp+OFPqwBh9TXluLjNt74HWAlHL+BLj5CT95Nr9MPjrL0l3TmwXnwhRhbU0RW9VY5q+wnUIJQUE4O8n9z27HWMbYkcR6T/ui9l2aUUMZP8CsFgwX+2be0p1J5FLFA5CmXxUUNwNqVvdAxpv8s96PhK+JSwIpWyPWLvW/p4LjDUnzNqX8sgGKVe5lsUR1pDifh25as/7KB4p6tM/nuuvjlDbnD1mmtYugF/GHZoyY5loYrh48YJPOUA4qxwqcxx5/My3zDzyqpsb/7dgQ8NPB675Lme+bam+w7St5BIz4YqC4kEE6GmrOJGytzABcHeEEoIn8IfsLsz6/PXFqz1a5M9robNbntc7hWR3i1AFnnethVIh7sMsgSBLp13LlxcvGjzc4+fV9whRbUZpInAHP0aRgwbbpopoWo1swDSuaMeSnaNa/a+jBmJQ8R7Dq5riL7uuqKtJ/3QaSl37N1Aif+QkNzDetNLdLoDP6ZevvJXpC8MXTmIz31mw4iy4DkahajszCxK4+3MFhiV+llR5cSdAknE5R73qpU0cYwIhkoJqS3H7qeI7ACNQr4rd4gQoiy3D+BwWLfZEs9tPKB6RVJTCQ6loKp X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: I/e2OVTT5wgWJFB2ZPnRGwwX1fXyvlsi67qgITtqemqWmuMCWaC0KbQArOkeMPNEY8lCRPRAr8ckOQSQCk94MVyK61r1abjX+ydAfgkDVLnyf9f80mzE+TGchybTXLssP5MBc8cAQAkxQYfWD/WC6bfIsNpeIiF3Vdj8OIArKpPgbJB8A+JJ2OEF3g52P7PJ1rLlbPAxa/T9b8/9T6RM5KfYkM3JDLArQeY1EW5y+yaYqfdzbsrXRhtjiV/Irw0GUgaVIgh8YpWH0DskOgcy3V6SJWm8xushfnvwOE7HBdk0VIRfXiCFCsAokKfxU2Fd9wv/3YAOa9VL+TmgVja1fPgOleevdPXD37L0GTbk49sGO6057kGQ1qsYpXmlSn530qxgq6TGJZ0h3s0S3iqE6WUvv7pvNrj2s9HFhTa8imGQ2Ncs8dn5QZGZ3GNv0amb6bt68wJpWNw/R2Q8qA6f8SyfC78SzmVehLBPyUm4OsDvkO7lrnVpHHmUS7cX9CqyK4aEUtg5ILvVwfilNEOq1csqi6zzHUvTaLhCvrDOKroK17Ubpk9caWHfSXIRnCR9g10ifAj5Y31TltNV4Qvb5rmGbDEBKEQTnZw/nBh/2fY20jecDXlUUwC60eBNj7C7m8g/tVad2pOR6H8rpxbAH1Pzv23tDzl6xPJ/cJhXrje6Ahp61rG+GYCqTRg9eKSQthJyKOhIfBumcPJ24FeCzjgQaPL8Z6T/+GZUdeeVlLvAPIMs0LxHO91JwTuq4hAo2Fa8UziUq2Bd4gcLeNYXyAFrLG5tWP/ZaY0aMoQNEF4h7a11/Reo3WipGzzyTbqS/RF8lf+GQy+ADbhxVKYS03IOl7VKHe5peaGrh/cDTdnNrPcG4nWqIMlie2jaw8qUPIddlWClRSoGY79Z497D32N2oYyGsBox1aM90YgsQXthct2WeCDaM+ff2CSAWPqGzYwvCbrEI8eu7MWCqz540HwYkqKHCjKoRydg4BjILzeFuPagKd8I5E6O4xtcRfeTlCdcu0fStTVAx3IJMzhSHOV+tDu2jGiATPnczI64t9nd/AfdQ8LiTqR6V5LO4nVbN9B/GCartqHijRMhKJfMx9ks93MsiLV06+psJD18Cf3EEIC5USxUAGKOAMD2Qrb9rxT52X4r5gW79RgymS+/YDuJr3UdiLsIDkeuKWZRvLmjWqy1OibrPDLdVXqMtUvb+kCQAqNwKdHAScWvqlYka/H8/XR29RrG/ehvQ6U3nEZRLcKw5jT9dDKWooIN0ARenE3KMtv1g+F+PjhOox9HMvcx2KDG4Fbgl0oEHsNKWgPJWxS819gq0PZFvDcgkxqvFvOkhpzwj6SV5/pC6izyHrWpklm5cnauSOjNxTEmdlarRm84miqXupxcNyeYX0M/xrBChYMMFxRw080Xv2wL5dMNPg7zLoJ/9eenJ2iRzDI/0R/Gz9xiEGCmuBxGzeg8WIFWfL+pqmP2LJi/z1r/1GZw1YRK+zQ6l0wjCdWWBRaW77sRpHGsPu/UT0ZCrP2ma65N2KVtl1kXTzyi3CUCtsFEfBD+Phi75dQHkJmhQPk8jIc2uOYT4GjWF94rieWANWlv5z9rNu5FCmtOdHNU5V9lbZbEiA0j2DUwm6qojzDpZ5J/ZoaYJcXm86NBJwxePmNbjuSnJByPA8ratTZKXkKEz906IJfk4zgIkcSs6KgET7qgmj33ISxAuaaxIKuT46HXGVEPYeA/mQGhr3AY/g== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 3dbe5ccc-9f80-4930-e6bb-08df181d58ae X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:23.2125 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: IR1MzXmk0nqQp3C18L/S3H8Y3b/PJdNCG1gUJ8VhIbN/i8+WZTxAnLidxuvmCoWjCW5sgOQ56fFfY+9MCRJ0h1aSDDy1CWIOH+jPoO9S+Kc= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246352 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/04-CVE-2026-6244.patch | 49 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 50 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch new file mode 100644 index 0000000000..5215b12ffb --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch @@ -0,0 +1,49 @@ +From 98bb921b141aa642faedbf2ac510541c76499a19 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:21 +0100 +Subject: [PATCH] CVE-2026-6244: Avoid division by zero via pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() for "div x" and +"mod x" correctly rejects the packet if X is zero, but for "div #k" and +"mod #k" it assumes that k is never zero. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program, it can attempt a division by zero, which will typically +terminate the process via SIGFPE. + +To fix this problem, in pcapint_filter_with_aux_data() treat "div #k" +and "mod #k" the same way as "div x" and "mod x". + +(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4) + +(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19) + +Notes on backporting to 1.10.4: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19] +CVE: CVE-2026-6244 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 497b1586..df92c433 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -422,10 +422,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_ALU|BPF_DIV|BPF_K: ++ if (pc->k == 0) ++ return 0; + A /= pc->k; + continue; + + case BPF_ALU|BPF_MOD|BPF_K: ++ if (pc->k == 0) ++ return 0; + A %= pc->k; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 5b97c14e85..d23a018a95 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -20,6 +20,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ + file://04-CVE-2026-6244.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98844 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CCF93C982FD for ; Mon, 21 Sep 2026 20:17:33 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.65]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5809.1790021847111180949 for ; Mon, 21 Sep 2026 13:17:27 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=g3vJ6FtZ; spf=pass (domain: est.tech, ip: 52.101.65.65, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=IS50u/rUz51W4UJXhVamFoiUO/MnutYwjF+nBMOMoA8br0WRxw/2PB5mBSNJ/AGcbiRc+V8eILrZOeGUyKneNWUMKtdh/SrapBq32SV3N9svFHpNf/2DCroRc3fxPVlwUN//AjwsI1sYX1CH0Ku9gP4GBgBDSnXbcGmt3FfL0xuuySMcMI3KDyRSf+O5YTltmfZ3GlBs6YAVJiJ3G2DRUVcnsWh6vP5W+EIZ7oSgCx1w4u+Z7QjOzAZlKa/j16vC4cmpT95yE40saH27sxUGwDs94IRfoE5Zywv0WqY2t5aXReHX3+chKBCX5/qEjipIJoWeiZ2gJz9wuDGxXjgnjg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oHNbe5LjwcsnxZGYzHa431uJiWb33kDZFR80EXu8kbs=; b=fMCoBz/WwDHgf3dqrE5+z/hHy2lVEbF8Ht4+HFE7sHn2B+99crec2MJHoJl3p0zyqC+aRD7ED+LU9yvjBd41hij89tKsjdGy6t5+Lyug0/rnvzFs9tkX9jiQ+xa73FxabWI+wX2f67vrDTHPP7UElaXuhRbdh1wjGSse6eu5lskADt67VE2Ru/0UhGFZELpLXCKMwOyC2Plu7Hs6yAscWH/89iwsIjRs4QBkVJw9HaV6k0lED+S3klk65eDHWg8cwa4jcEHw6DCrD9jwenHh6qinnkXfXx0sFk7lU8Pts+MjP2Ngfq6PDfp14XP0cp2E0LG3IlbHwjaR6M0uGrUqig== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=oHNbe5LjwcsnxZGYzHa431uJiWb33kDZFR80EXu8kbs=; b=g3vJ6FtZpEadjQNm6onEpkcbhI4gKNVejiXu6IDU2YOKDj383y7u93rWB0ed7WG6eYJqvtW73/nD19xjXl2spxMju272kQL5IqzvIxAUwbJMRZc5xXT8EHbBKBzE4CUiZS74szZJUCkEES3gk++gy5yITslTAz8icJb2moBze9o0yBHpq+B2n97wIV4FBI1jVyDX/3+L6faNhzqyzz7OI3urAr1E0Sqva8fYl6GdU7aDxLp2sWRh0d2hSZjEAWlZAMOZ0FppWysJ+Tvdy3r+SI59ncC5lUF/sLWj16DugtSJC1+619quu898wYZ3+YrkzzYaHQVEON3QayjJgWryVA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:24 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:24 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 5/7] libpcap: Fix CVE-2026-6554 Date: Mon, 21 Sep 2026 22:17:13 +0200 Message-ID: <20260921201715.79085-6-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: VIVP296CA0070.AUTP296.PROD.OUTLOOK.COM (2603:10a6:800:35a::16) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 593e9226-83f6-4f05-6100-08df181d59a6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|3023799007|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: yaoPwX/YMRqmOpo9gWMHhgphDQNxHYRikWMVjv9PyezA8ue34Ep+xS7SoD1r5Ye4Qctm0cVJvw8zDXPUHDFp0U1i5giiox/9fACjUzCAlA4FiwVymK9xofK48zeDWOWkVL/az/jUlJEHvJ0aq/j5lbi9d1OAH7eGXbUZuPzqBSMQHW6CN0oaOdRRpV00IwD+owTJukj6OUR+XQY+pA5pR69Z8VNBye9hMSpzfiZXlbY7K/UBW+VqxXW+g43EOhQQ7YPqX0E5lZOXzUTxK90A1Vujk/pTE3fvg6k2Lq/dns381qklBTNDf7VcQxrrigriqctYyH2ub1j78XQjtSi+wMxKbfTlBqFahw7myJawP6gve7oyy2qAEReWSRitIXEd/IM53PFusUhvIV9nAbNA5HnNgBu22qV9PzKA5JZSDDd7wQ1CDCfJ1KEYimV6w+LLp4I8rWiV4VZPlXobKdNqQygajVAR5JRAyZVD4SexAQOF0gGMMEUwL0ZtONHY8MOND8mTtIhPpKUhImFXQPojqCzY5ZZb3EiICV1fkj7HxgSHb2VGH42LA4bNxjMPSQW7FllpKpEl0sJLjCOs/gEabV6pF0xfpx9P5Kf+aD+4X7pqfn7wxI0KM6JZ1s/qRUOr X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(3023799007)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: WWbsXaDhBjWlCOF65k5gv8Ibui+U2pLLi1wYxTTpT3kWE9GB39DBsNukUlK3687vb/yn4uOK7ep6dC1zjQm4URIixhplKZBfLjFO/xXJYlA3AqhUi3qRWNT9PIfttKv8b3rxYwzQVkjEpMheANBY8mN+uIuQTt0fHLOW3MiSm+fRJwfvUOe/He7rsBY3l9zqRTzTcy3UaX4E2zeauAV60YHwc0K8ahKyaiBF4Y0OEnKdz6VG+K7PzQsXb0Q+d4VYB9NudwNjdIJxWgc5fmPQeMiwi/B2TXCWu07y8tLlUxaI7nNazKWIji7BAGTV4tgPATi1WIBhtTZ5aUgypQKT0AxYqFmcehWXuC8MEp5fr9uT29uLjS5qqADcZrBCFd1odjSYMmjQsXrux1OR0v+lL8uqQ2NSSlqgIFM8ORM/J/M9dVw24hiXTjgPIHorbMnri/Jp3tFzWfSF7+J+Qqk+sJRi6x3B87NGZjDGKCP0zGXQJVmaIRc8uqlLxTF5Pv1iH9PZn2xZN7XfOyNjsu2XSBUrkCLK73WmXmQT0I+pjeyb0ASBNnEUH/eDxzHLgAf4DV7R832BjklUv/ZkqHGYrU6Gdp0f0AZZDnrdeaj9LO2adzoo7WtpXWjK5JPZELGfAyacOWGKN1EGcnJQBJhZiqkLJSgEIaUm56MOOxHHXnlfvsGv7taKn4v4bR3GYZ5V3eJ0Nwh7TstMm4H68JVXDm71c5owXXmfMi0Kl6IMxrpdRu+nLhoHnAlNxBI4yjosfYZ5ThTavbw36CsyY1k8NVsh5LH8/YNgugEMXSk4RUYDG+bp7uigUV8F+z9Y7O1OseI47aSUQ6jZ45x4BocDsyZLOHclEJAyObSRUE6GOL9F7b/tzBc4rRM3eqxh5l2mRS6cJpP+cKNQFUojC0Jb4mZSdvYBp0EohpZQlkswQnfvcymBFUuKXo+9jBFH/hQ6iOaXhnDeIhuhr6cGKa05PjWPONNza6t0hLa2iSHJRmj88fHXx/rwr2yWiR/qAademqSZe8HqYqyAIz2FKyrzyP0OxbqjeykLLVkvSRfdD6nCiyqW2CBQHTs9krOnLCfOYtGPB3dAEFXWtopoI38iara1aoCkYOkcp64vM5wr/oSN9UZhjA/hSKEO4bd22xQEgOn6XbGbO4/JaW+i/jCWQaT1boDVEywW3MXRhFu2qGQ69T0PWW/FOoIp1mfNryzL6Rgta1FtKHs7okegNREOyq2Uj/mQKyTRgtJMZlhGQFwskmXL/ok19LjZlthKjbOVSpPk/2vBBCXc7rQfcf/BqN8ohDiLYMpCVcyy7WbeWGVw6HFGnhnacFGGQsO3sv7m9UkSWylp4xR08wdO1hYmJ6fYhty7gUJHA0MWCZ6ncX9f4yTWd1t6efe/CcStG7TIY2HCMSuYHApgmvNXcyD5FdKx3prMrq3JGtvX9E88VAIc5vd0gVGAw+BZYwzaOSLum0id9HIbtcAWy50QYDm7y5V7u5pKXmK0TbJElwGG7J5hlL5H4RggGb5mCJA34cb134Gp6m2cQXIn+odIVyU47G5va46U2laXopDYln4b7Aaz8xP6MkYNGCYet4qy7SaaOYWHryK8tHZEayweB9mYWpZatJdzqqqX6P1VHG0LywbV/EF//eYPI3vlXdAfSghelL7qUb7jCaZoz3DL0n88Bqr0Y2Oj7jZkD8+AHOXC1gc8ZaHs6WlCcns73GI4D9yTbY0voJ2Sp//v209VZYxdBg== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 593e9226-83f6-4f05-6100-08df181d59a6 X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:24.8304 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: kRZgnBCPI8HgVXjBsX21YeOmk/HTDZAG2oaWeWTjiyEr0iL9rNnS6Su5404wtU+B+jkW02WmBN72iNRZpFLP+uiBMsqy2QLmdhX3QBMsGp0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246353 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/05-CVE-2026-6554.patch | 92 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 93 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch new file mode 100644 index 0000000000..9c44294d1f --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch @@ -0,0 +1,92 @@ +From ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:33 +0100 +Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + +This vulnerability has been discovered by Kaixuan LI. + +The current revision of pcapint_filter_with_aux_data() assumes that any +"ja L" instruction in a filter program does not jump to itself or to a +prior instruction that is guaranteed to reach the same "ja L" again. +This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +If the interpreter executes such a program, upon reaching such an +instruction it will begin looping infinitely. + +To mitigate this problem, in pcapint_filter_with_aux_data() enforce a +hard-coded limit on the number of backward jumps per packet. Ibid., and +in pcapint_validate_filter() as well, reject the only immediately +detectable case of an infinite loop. + +(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0) + +(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce) + +Notes on backporting to 1.10.4: + - Adapted to the 1.10.4 pcap_filter*() names (renamed to pcapint_*() + after 1.10.4). + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce] +CVE: CVE-2026-6554 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index df92c433..ae8a3a36 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -72,6 +72,8 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++#define MAX_BACKWARD_JUMPS 64U ++ + /* + * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the + * userland interpreter in libpcap is meant to support much longer filter +@@ -146,6 +148,7 @@ pcap_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + A = 0; + X = 0; + const struct bpf_insn *pc0 = pc; ++ unsigned backward_jumps = 0; + --pc; + for (;;) { + ++pc; +@@ -320,6 +323,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + */ + if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) + return 0; ++ /* ++ * Terminate the program if this is a non-forward jump ++ * and is: ++ * - a guaranteed infinite loop because it jumps to ++ * itself (exactly the same as in the validator), or ++ * - a backward jump after many enough backward jumps ++ * already made for this packet. ++ */ ++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 || ++ backward_jumps++ >= MAX_BACKWARD_JUMPS)) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -607,6 +621,17 @@ pcap_validate_filter(const struct bpf_insn *f, int len) + */ + if (from + p->k >= (u_int)len) + return 0; ++ /* ++ * The only type of infinite loop that can be ++ * detected in this function is a "ja L" that ++ * jumps to itself. For this only k == -1 ++ * needs to be tested because the check above ++ * has already rejected all other values that ++ * would wrap the pointer equivalently on ++ * 32-bit architectures. ++ */ ++ if ((bpf_int32)p->k == -1) ++ return 0; + break; + case BPF_JEQ: + case BPF_JGT: diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index d23a018a95..f7ba1bf3ea 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -21,6 +21,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ + file://05-CVE-2026-6554.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98840 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0FEB2C982EE for ; Mon, 21 Sep 2026 20:17:32 +0000 (UTC) Received: from DU2PR03CU002.outbound.protection.outlook.com (DU2PR03CU002.outbound.protection.outlook.com [52.101.65.65]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5809.1790021847111180949 for ; Mon, 21 Sep 2026 13:17:28 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=T6s0MsUQ; spf=pass (domain: est.tech, ip: 52.101.65.65, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=y4GZlB89PuKD7EwYiXtWze8KKgnYsY6ENBQCAxhkapNHwlUu5B7jHGFQPV6CLsnK1HqvY0UB3Zo6IXQ/VrNPPZXgfYP/u0qNDxNfYz5UuePVSb6JQcJxCp0s3JuKYkDA7fihjtcG9ctQVrtGHxZ+3f/Rt6yfGnEZZ3K7qbUOD8h8MD0oHonTV0mQHg1CgumZJKqxUQNuEu3pIV4fkuZt34e1UIhAcocyvYMloeMpO+HgB4SM71MRc+iz0BXXO06wX5OpxM40iKjPzdsLQ/0KLMp0gGYY72ZY6n+ILPMEYsU/t3Q77JF8tExjPasUODSR7eUFSQZLvI3wCzjIoZDTtA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=NHqgsC8NqXAMTHSzhSS+nUQV6h7LsGmhJwwBtM/fs+c=; b=P4LLThzCTGObOsfAZLpjJFnicUPPNjUnMQM4MFta9YbHa3E5bt1KFZuNSgJxDy8VeKxKuqbPYVj25FVR6sLEWOyXKru0/Uy4NYHwn/M6gfHhA5fkRQNAryqWxH1bFPcevMYCWA9Lt+kwsXNljFZ0YX1KjktnjGwW03x4zZ1S2REFS04YFyNLEXrwWb1dKDDA0vgbMgBCkhQV0Uq9DKaATJE93H0OgMdphg3Bzv9r2gBAcIyW4x2ujZP4EHspr1Aj+H0iPOWWSK9jnJv5OirCbtkKK97SH6QuQEfn5MYUmxDSCuR2LltBSyjnAuLtQPyzVFQwIwC3hgnc2uxvW37FTw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NHqgsC8NqXAMTHSzhSS+nUQV6h7LsGmhJwwBtM/fs+c=; b=T6s0MsUQQSefqxl9p81N/oe6P1f/aAPfJKzN3sx1lJSjxExuRk1fkM8E3zu8MidpC386YNrqTYX+5PNpBgQBCmM3q1AVXTpSm1Np8e7sJneAIK/cM64B5TTRe06KAif3F1qciSOpkK8Gz0RTJdvycBRrhh9MvQZ4Fp/FwOJC9H0n9HvKRH12E7bb/KRgcek8okG6hxA607JStInudlTEa5KUlIKzUVJ55A7cdlzxplNjIqk2EJc74p/jiJ+wlP49KSxaJgCUpuAVwttD6htK+XiteZKDpua+FnSvJsRqauvJtMPU9a1KGZY0DK1pKM0U4E86cTqF5rXqOTC5NlUQFA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by PA3P189MB3314.EURP189.PROD.OUTLOOK.COM (2603:10a6:102:4d4::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:26 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:26 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 6/7] libpcap: Fix CVE-2026-18313 Date: Mon, 21 Sep 2026 22:17:14 +0200 Message-ID: <20260921201715.79085-7-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: MI2PEPF00000B7F.ITAP293.PROD.OUTLOOK.COM (2603:10a6:298:1::413) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|PA3P189MB3314:EE_ X-MS-Office365-Filtering-Correlation-Id: 92a59361-2faa-48f0-71a2-08df181d5a9e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|1800799024|376014|23010399003|11063799006|56012099006|4143699003|12006099003|10067099003|3023799007|13003099007|6133799003|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: VhgCtPF+gCEsyKvoYFUlO+5g8tGC0ZTffbiT1fTnP+yvCSOcIeOMVYUcCuZWv6v+4wGcwfvJyCBJH+1JRUSbAb77F/gqGuoJ4xR+vIA6Fls2sbcSjhfihC4D8EMomMfyEiW40tZJG33L5VXKe1GuMVNbONpFf/ZH7nvLFLdkV8myvp54gEAXblu2s/GooAhu/oK9fNyNjyP2VdlKbHgTuWvXXLq86lVH1biBO7AyhcMNGRkCRe+Wrgl05aQtwQNgckM2supyjLPJAtnkguAGCbhgJUBxoXUtBOmg63vtGCDFVGOJA/0uj0luAKso4cCCXG+fN9oRH6DMqbuN2lrG3XgcLtNOU4hZTKCuvWYW4zMnqQLg4rtpm0ewbNLcmu1O4ASa8Kq+MK4rZXiON33ApPxzWLWXiR3tdwmxqOxIMGU77LxuhrRuqJucAEUf38mRmRLqOCGWR3/1eT6swkdWWTP8jSvz2wMf6tKCCRXHnXh6aPtucMAhiT/+a3rRRm5ZnH05FKHAz+hiZe3OymVigfR3CYIWKDI4sUj/IzAP3BXqSGHO3V4bnbMVrzX2H4bX7tcL8Tuzbta+N2PkbDsUzeMp4No14mDJvENghA3KV51pFWnPBGWQzx4ml9eSrZQ6 X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(23010399003)(11063799006)(56012099006)(4143699003)(12006099003)(10067099003)(3023799007)(13003099007)(6133799003)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: Tc4oGFDngqgIdUho96UdBTL042xOI6WK3pEqJqu44NzFva1GAjW0es+h0loSx1QrhnLEdxFe3Z1sjQfqbFdQxeqBwOAACsfpImNzNcCytUR+q7sISyEqL6NzG8u5uF4WWwySoEuC+hIUdI+QmyigDX0K48y75aNvIfYSm2rEEtylMs1CjvxbqWXTBYnS8ZqFmfoMLd1yOmG6OuFzMfGYj2SCb71icdmMxP7mNqfYzULcNgedbKaf5Tes7+ORo6VJeEJXfTcTanclyL0Ebk+tT98EmxlCT7qp+hI7QbCuvQq0Q/TY5WbuI5qp6s17xsiCeQZlB0t2PbxnCHDtb9kqspiT783LQ90g+iHqN8LlAJi1ufk3R3PlG50GChdZl/vQGaQ6uFoLj3yms46IYROUTPepVL3Zz7yBbrSN2TEvv+pBjPBcZpzXlNR08j0JRRHoWmCxGcYoZkPXE+7mHji/50nxpqVgvc5zrJ8Md9XkeZ49nvR5kMQ2SWUe/OsT3jD90vg0qbcQLZPTOWQTxYtsj3KGV5UalF/ZfVf/lCN8CoILbL2HEAmkuGW2ItpqvkUuLWz/uLVSpvppGmLtkBChdlc2pLWCo5OLMCD9hG19BkDkNsHGVYh5UPrhIoq45CqKNznIEqpwgBeubVolQ1B9UypeSw0aQRHdrYr8PnNBZyQV8Rdsl9qKmwlJd4z0WY4hVnKHU0KjSqA9Wk4ZgLsEuqqPeLLcURJcpYQLHT8V5j/sxhdwDOTYX1RH2ht13BEUE72P5FN0WBDWjS78XJ3YeVvoY4zD4eDBZnKrFkZ9x67Y4mCkZyCdLHTJNKrBJUbxKH1D5/VlfuKGqAtx9mhrglo+xJliUKqFvmw9i2KmqpCtpTIgLLBoUP4XF0uPgEWW/JJEdDu14xeKs6ZVWSOq7ZvqcniaYic/kkwJr+KFW/Da+3nUEiPSCFXPeyJEwVLV1Feo3hiZGc7ERebBx33q+V4mXhE9QgKiiVPr/oxdM6CSgXfOp8dqH1Ef47nBch3W3CwScoJPUrRmqhB3uAVmL5acvF2r4aguHYXxbLX/C3MO09+U3nUn6e0wiWg9m5xd0g/jmn2+hUBZE9tWPu9n88bwMukDAVRQOa1vc5Cdl7dyxCjrY59/kn6xFQQTzKHYIrLuuSrsWlcl3vqSTnOCvuKZQDiBO0XCP947xj3G2G4jDrU8rvpStOXyAKBcg5gY3TmUZSNKmptjGCrbjE/9ouPfAfsI39OHl3UdIcNhAVdPToZxPjUIFgeKcf4CVKGBwaZS6juNP+7ZaJIkZSU3d/9ycpBbT/oxzZLeRwwyFHNaD5AV3gKhGuIXDPK14UyoixTpyrQi7pQimVrj2EBnwAMtggozOw2jjQ8RvB8Rzq+Oj21/enhC9ACuyWjVIoOuCGypd9lEuyRt4OJ8W1z2zgU1ohTjJNccdDOqqXLagTVT4+SJROhE7nY8sAF/qQF5VGjiMkWx2exlVzkP6xsxRgIcWerd/9Oy7Jx3E+AiZp2kHKajgsr7qcyuSUHnSWmerabVYyi3C5AgUvAHPXvY5nCRnjonQweMZ/KQbEYG27bve9D4VDqS+gnlfdAuH6qP6ZON+2mi0b/qHFlnkv3xDKkpMvrm6aN7jj8syUu9Q1gIjMgvYuXdStWVhegQkkJ+AcGutO6NmrkgSRDTcH4/O8xWgWgzlWlNxXyabjEfaaQJvxYPrqpGfhxddOa47lAKtpOsoubclFDywhJhyM7HSw== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 92a59361-2faa-48f0-71a2-08df181d5a9e X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:26.4833 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: mh+9UGUB6oOj1n6XHwj6cbJERB4+fS4DZr7v3rKpTBHLgbATnCSugipxPXYZDSI9ARE5D3PxEL0Evb8ZnDrBnFCCrQtn/WHOUw+baPHsEig= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA3P189MB3314 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246354 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/06-CVE-2026-18313.patch | 84 +++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 85 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch new file mode 100644 index 0000000000..2a9df12e2a --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch @@ -0,0 +1,84 @@ +From f9775af1a0ec76db60c7213241e6b48f1be10ac7 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 1 Aug 2026 18:24:48 +0100 +Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd. + +This vulnerability was originally reported publicly, hence no credit is +given. + +daemon_unpackapplyfilter() can allocate a temporary buffer for up to +RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each +received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message. +It never frees the memory, so repeated messages from a client will +eventually leak enough memory on the server to cause problems. This +holds for all connections that pass the validation and some connections +that do not. + +48 bytes in 1 blocks are definitely lost in loss record 2 of 2 + at 0x4844818: malloc (vg_replace_malloc.c:446) + by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372) + by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139) + by 0x114808: daemon_serviceloop (daemon.c:901) + by 0x115BC7: accept_connection (rpcapd.c:1321) + by 0x115BC7: accept_connections (rpcapd.c:1118) + by 0x115BC7: main_startup (rpcapd.c:709) + by 0x1112BD: main (rpcapd.c:567) + +To fix this, after a successful malloc() return exactly once, after the +free() call. + +(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b) + +(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7) + +Notes on backporting to 1.10.4: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7] +CVE: CVE-2026-18313 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c +index 9b0f8285..b0268688 100644 +--- a/rpcapd/daemon.c ++++ b/rpcapd/daemon.c +@@ -2378,14 +2378,8 @@ daemon_unpackapplyfilter(SOCKET sockctrl, SSL *ctrl_ssl, struct session *session + { + status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn, + sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf); +- if (status == -1) +- { +- return -1; +- } +- if (status == -2) +- { +- return -2; +- } ++ if (status == -1 || status == -2) ++ goto free_and_return_status; + + bf_insn->code = ntohs(insn.code); + bf_insn->jf = insn.jf; +@@ -2401,16 +2395,19 @@ daemon_unpackapplyfilter(SOCKET sockctrl, SSL *ctrl_ssl, struct session *session + if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions"); +- return -2; ++ status = -2; ++ goto free_and_return_status; + } + + if (pcap_setfilter(session->fp, &bf_prog)) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp)); +- return -2; ++ status = -2; + } + +- return 0; ++free_and_return_status: ++ free(bf_prog.bf_insns); ++ return status; + } + + static int diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index f7ba1bf3ea..5f1506f8fc 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -22,6 +22,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ + file://06-CVE-2026-18313.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f" From patchwork Mon Sep 21 20:17:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jaipaul Cheernam X-Patchwork-Id: 98846 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB257C982FF for ; Mon, 21 Sep 2026 20:17:33 +0000 (UTC) Received: from DB3PR0202CU003.outbound.protection.outlook.com (DB3PR0202CU003.outbound.protection.outlook.com [52.101.84.16]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5812.1790021852865173722 for ; Mon, 21 Sep 2026 13:17:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@est.tech header.s=selector1 header.b=Bhcz84XK; spf=pass (domain: est.tech, ip: 52.101.84.16, mailfrom: jaipaul.cheernam@est.tech) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=lR3L04rCTdM3dtv7R5IU25KK/S12QTwrifg2nmxXkrhovmcW/gJMoCnRxBYnJjSEJddDrJNe6DMQ4ZgdjPg8TOTOXMVm1pf258g0dKzUXzy0FgM835ENFLodWIVajeSR0mcHtvJkJqOKzGxRE8YY8wfD/ctG8fwo501jm6h+KZ4uJKsYWby+sOBnY086Xqr/l+Uf5lPynmZ6HWVw+ve1999GtL3VMOTX3DOn3HQod/Soz/NRcrtaBSPJvPtIG4zIqTWbC1eos7+t4EUUCBIITMTIkCIOyBjuYyqdgr1n9+wYwGmvtMYJ8+NouLeDA0LAzzU7T+ldX+Kgg0xbQ1DjoQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=91gYnffLarq0ccFgu/lurfVxECPeIC58YO1UpBPYTPc=; b=brx2a5sciu/NFD3+6KmaoZlESS1EHR3rUn66h3X51Keujx8t9AUvn4XR6A/69dqdsB0kWy+Rtw6DI3aQGeUdpCbM9uH9RZ6hJN/sDMjQJp0G8bzhov0TPWf51oxyMozQFlzcRgMLExerNCZ56zAVTJiuE8mPACbnXigOH8SWcbcW2OZ0itC9PdKER0Hierxiz/AU77pskz/VxajLChyDFYFY+N7PBV0WJvG6F8zf4JXsECAYmt+v2TJJXHMMHjrcH9I11S7Tf87enuOXy29GRB3JD3yfB5c0hwmjo1LbQxkHIsdq4V4cCzHN9At78UZk9dGAemagkRXCx/ihXCevQA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=est.tech; dmarc=pass action=none header.from=est.tech; dkim=pass header.d=est.tech; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=est.tech; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=91gYnffLarq0ccFgu/lurfVxECPeIC58YO1UpBPYTPc=; b=Bhcz84XKjn6A6hCHr0mi0CHSm5/oWK7CgATsV/EicbFFwT5o66XqJTbucBThR88GlU7mVJX/kk73UPDrgXr1P1Ra1bkg9gysUJMSAEankEz95BsnewhCW0l/tT5Jq96QlnDXn6cOSn4lBZKetKhHSVhDLPOknz/XeIz2D20sMjTSd1892GtsANQcCuQSJ8IRH/wP4GSFSwnWd6L6gBdLFsKLn9HYNR3dvzF28vKNzbFwtw3RdLifuA7C33d5UONRAh3WnD0TFBpMV3jfMjh1wTuffdfL1VV1r5cxbCxty885yElQzykZClguy/Ay3yLBp1uwQKpApYN6KMYTiE9ZjA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=est.tech; Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) by AM8P189MB1234.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:247::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.16; Mon, 21 Sep 2026 20:17:28 +0000 Received: from AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb]) by AM6P189MB3107.EURP189.PROD.OUTLOOK.COM ([fe80::bc97:3847:8f02:acb%6]) with mapi id 15.21.0428.014; Mon, 21 Sep 2026 20:17:28 +0000 From: Jaipaul Cheernam To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH v2 7/7] libpcap: Fix CVE-2026-18238 Date: Mon, 21 Sep 2026 22:17:15 +0200 Message-ID: <20260921201715.79085-8-jaipaul.cheernam@est.tech> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260921201715.79085-1-jaipaul.cheernam@est.tech> References: <20260915194520.45847-1-jaipaul.cheernam@est.tech> <20260921201715.79085-1-jaipaul.cheernam@est.tech> X-ClientProxiedBy: MA3P292CA0016.ESPP292.PROD.OUTLOOK.COM (2603:10a6:250:47::10) To AM6P189MB3107.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:6c0::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM6P189MB3107:EE_|AM8P189MB1234:EE_ X-MS-Office365-Filtering-Correlation-Id: 66bd6e7d-55dd-4b4b-dbe6-08df181d5bc6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|23010399003|366016|1800799024|13003099007|6133799003|22082099003|18002099003|56012099006|5023799004|11063799006|4143699003|10067099003|3023799007|12006099003; X-Microsoft-Antispam-Message-Info: eRh+l2Pe7xN5Mwyi4PpkXviDlR4t+KSvRTu+egUE132iuqX2YlGHTiHB6ostpBHBQ0TmNmRy1iLa9aXpInpCsAXq1RYW7rqVbi81MGCyXDsYPaQaROdh+brJ/9IPcFrUuX2b1W/ZiFTny9F/DGWCfHDSnn1/JgqWA6D48nnnH8xr1jvS4E9zZNRJoKZPDKX7aOrliXt95f6LyzWkQ49BFwH5KLHJXT0GYlz0DxmbILL0ka9IqEw3tLftpbFxrifIGL7qnDKq8oFBwaPQrnujplcr/KafVgeX8j+wnCgSkv68SKqjHKyrzSLLO0WLAu/bfr+MOxUfgFla3vgVur/Et5O2EzQTO6VpI+8p2v3PEjCK7U4grUKsQIVj09LDjwpK2VK70lpx+VR4v4HMbE+xn8VDr9IcwtBzLw6FeuYgeiIbdT0x3vuquD2nHyOSWJboyTGqPJsJIWBG4jdJo2QBWvA2sx8nUn+RW1vViaik7in4ecE1d30LENJw6guG3J8bKLo/UGuA31rkbnMkHgGpc3vDj9XEm/xyE4ymRzl6ZcDGKSFZkUDJaxZNLpayEOvtb+be6xRrHsO/5EPv8sGasBGRnCp6ZJb8F9hwxsfWOJsXB5hkh+GqtkGl6M0oV8fr X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM6P189MB3107.EURP189.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(23010399003)(366016)(1800799024)(13003099007)(6133799003)(22082099003)(18002099003)(56012099006)(5023799004)(11063799006)(4143699003)(10067099003)(3023799007)(12006099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: iZGVTbMOQSUb+EAbBjv722sd5sWiMohHYyByS/AP/7vY/QFtbfI67tBaIuQomsmvasudzG3rIiLd/74BKehFJg+YEmEqNVieVyntnspFgLxKQ5pyZSZlU3vJLWkTdBExHBnmfkKleH1DRa8bA3+TLvYi6zAy55F+fnHb/nPZS8XrmJt8/QK1VeE1rIcm1YfJRiXXGToJDBsIP3X5WP7bg5IuyqLAJY4E0z7XEnX4BhinL480MNgQl3NXiudEmY17hfAS1L6nexBc0HoylMZPsq2f2Jubnn6fsSWLj1relsBnDltj1CWvzXFqICiEH1ZhakwRFZZU1MVWSS19vl3F29hcDHVZEMg6K6tXbfILRelGMY+PNEqA9zbb08RoFYh1Qxi76m1U/elObEUT3iNlja3jFxp5YSMyuv3uZNuiH+yh8G+z4LsHfYArjDzyj+or8Kcs6NPwVkhXA9hwYtBMVqWQ1ocsQO7PkhbKZ/CwuYaWrxZ0dKVnsGL6vywG9T2qk4QzQ90/IAUoiStR4zOSCBQ9E0O+RbnVZfQOIKkd47P2VUir0pgKJmWdrtau2V3Zca06gMMUIGIH/OWYFJ7WZbRVnlUrBwztuzDPwaXFKXKKMjbsQSgeJCLFCnxhFCrAFcHvhI/axafhRzju9WzekXiSzxZ+OvtTTpL69ciKRKZEAp6cZ/yPDeGyRfphB3jt6jngc1k3s5dhEh3GZlEYVbAE+qFZ+L0rYa4f/wwpDhPOJulR1XhUmOnxuFksDwFYQJtniGQ6VeGFg5XSy+KCe2U4+6duCXSoi6G4gueZxg1enXXAhaXJwZMnN6LHuNCe24AqsJHxSWwPQAufH0GQxBgWEK8d29qJquuowtYO3/agJJLb+WxjezJOS27ISjoIK2eJJUpNAaSlN5MeCYoFHXwI3naIKS8z1cFYMZVixhxu+I9lY1OjhF+sadvoexJ/dxgV6ZBBGuRY71IVw/slYYUHAI/5VV04v6+sM+buvwFKA7WfDnwHbPodcbeULo7DKIsjDY/aNooNwyBDKV3R+cJTDFg+fIzNq3DAHZVieOk8JBVNG/tuiu2kxlntV5Hkh9y8Al3LPXX2QY22eeFZ+siMoV7I7l6nPWFlSMIZQCdOgx1Vk+DL8S8l3V16GS2wHf84b08DgCczMowjLAQPM69eGXU7Lh8HjKpldRALqZDlM4678BeyrgkebLhw26v7KtJNcGqP9fRXKcxAYLY8yWeQWafQIG76nvB/1Ug85kvaHPZ5UoWO9w4bxYrRplxuUefLqLHH3LHxjlgwkNvG1b1V98Yi02EsIADTOZ7Mz6yJyaOg7pi7zGJm/dh69ZTDCSUwRym+S2PMM1xfQHC8B2kc3fUkJ1lNSz93Qzk9OIW0Wx1ty9hlhYUb70Qe2c65BpiggHRFG5XEaNEkGR9Bi+IKKNMDNtL9IesjTsNNlq1l9MzX0IDvRrxWlUMOsQsSi9x6VIQa14fPu/StuN2zDOGHcnMDmJSnaIGMdpGQHqFxQQaMyQoZSXGo4L73KP1UuHkm1GcNdxD2iM13qdocKe7GOXyuU+i6N4ThKdlRG4kBdicFwZs7yQ7HS+198BYAldKHTmJIa8a+CcKunb4RN6qMDZ5PBsIFTU162I39C0URllSle9dMb9CBf4YeF2a0vsY0hOxzG1P8VGqrXAlmKo37M+lys2v+CArw0lxgcwphizbc/5iclMoQXDGNOTc84i//vXQ9RJUOWchiI1Yjbg== X-OriginatorOrg: est.tech X-MS-Exchange-CrossTenant-Network-Message-Id: 66bd6e7d-55dd-4b4b-dbe6-08df181d5bc6 X-MS-Exchange-CrossTenant-AuthSource: AM6P189MB3107.EURP189.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2026 20:17:28.4465 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d2585e63-66b9-44b6-a76e-4f4b217d97fd X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: WM9jDgGyayV/XJX17sXpjT+HuIsBAm+0obQupJsuzeRZn+7dOu7dBcDgXzGjUnhZozKEZ/OjvGYVnaLgPbDV2zedVRaxdS681qz4OwDcr1E= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM8P189MB1234 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 21 Sep 2026 20:17:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246355 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 Signed-off-by: Jaipaul Cheernam --- .../libpcap/libpcap/07-CVE-2026-18238.patch | 222 ++++++++++++++++++ .../libpcap/libpcap_1.10.4.bb | 1 + 2 files changed, 223 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch new file mode 100644 index 0000000000..36f80c483f --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch @@ -0,0 +1,222 @@ +From b9590d482986d64673712460aae1d48d11fa0473 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 8 Aug 2026 00:31:10 +0100 +Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + +This vulnerability was originally reported publicly, hence no credit is +given. + +When pcap_read_nocb_remote() validates a received message, it does not +verify that there is a complete RPCAP_MSG_PACKET header in the rpcap +general payload, also it uses an incorrect value to validate the length +declared in the RPCAP_MSG_PACKET header. The latter can lead the +protocol client to over-read the message buffer by 20 bytes, which in at +least one scenario can cause a SIGSEGV. + +Fix this problem, as well as a potential integer overflow in the UDP +code path on 32-bit architectures. To make message encoding and +validation easier to follow, re-jig a few variables and update comments. + +(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9) + +(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473) + +Notes on backporting to 1.10.4: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473] +CVE: CVE-2026-18238 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/pcap-rpcap.c b/pcap-rpcap.c +index 22fc7363..30fbd6d6 100644 +--- a/pcap-rpcap.c ++++ b/pcap-rpcap.c +@@ -388,10 +388,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr_storage **soc + static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data) + { + struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */ +- struct rpcap_header *header; /* general header according to the RPCAP format */ +- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */ ++ struct rpcap_header *gen_header; /* rpcap general header */ ++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */ + u_char *net_pkt_data; /* packet data from the message */ +- uint32 plen; + int retval = 0; /* generic return value */ + int msglen; + +@@ -448,13 +447,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + + /* +- * We have to define 'header' as a pointer to a larger buffer, +- * because in case of UDP we have to read all the message within a single call ++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large ++ * enough to contain all of the following data at once: ++ * ++ * - a fixed-size rpcap general header ++ * - a fixed-size RPCAP_MSG_PACKET header ++ * - p->snapshot worth of bytes of a captured packet ++ * ++ * This is sufficient for all code paths below. + */ +- header = (struct rpcap_header *) p->buffer; ++ gen_header = (struct rpcap_header *)p->buffer; + net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header)); + net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr); + ++ /* ++ * Step 1: to receive a message that does not immediately look ++ * malformed, consider it as a fixed-size rpcap general header followed ++ * by a variable-size rpcap general payload and require: ++ * ++ * - a complete rpcap general header to land in the buffer, and ++ * - the header to declare an rpcap general payload length that fits ++ * in the buffer after the header, and ++ * - the complete declared payload to land in the buffer after the ++ * header. ++ * ++ * Since this step loosely corresponds to rpcap_process_msg_header(), ++ * which among other things converts rpcap_header.plen to host byte ++ * order, mimic that as well to produce a valid argument for ++ * rpcap_check_msg_ver() later on. ++ */ + if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) + { + /* Read the entire message from the network */ +@@ -470,6 +491,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + /* Interrupted receive. */ + return 0; + } ++ ++ // Require a complete rpcap general header to be present. + if ((size_t)msglen < sizeof(struct rpcap_header)) + { + /* +@@ -479,8 +502,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + "UDP packet message is shorter than an rpcap header"); + return -1; + } +- plen = ntohl(header->plen); +- if ((size_t)msglen < sizeof(struct rpcap_header) + plen) ++ gen_header->plen = ntohl(gen_header->plen); ++ ++ /* ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX ++ */ ++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header)) + { + /* + * Message is shorter than the header claims it +@@ -495,6 +528,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + { + int status; + ++ // Receive a complete rpcap general header from the network. + if ((size_t)p->cc < sizeof(struct rpcap_header)) + { + /* +@@ -514,27 +548,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + } + } ++ gen_header->plen = ntohl(gen_header->plen); + + /* +- * We have the header, so we know how long the +- * message payload is. The size we should get +- * is the size of the packet header plus the +- * size of the payload. ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) < p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX + */ +- plen = ntohl(header->plen); +- if (plen > p->bufsize - sizeof(struct rpcap_header)) ++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header)) + { + /* + * This is bigger than the largest +- * record we'd expect. (We do it by +- * subtracting in order to avoid an +- * overflow.) ++ * record we'd expect. + */ + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Server sent us a message larger than the largest expected packet message"); + return -1; + } +- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen); ++ ++ /* ++ * Receive the declared rpcap general payload from the network. ++ * ++ * p->cc == sizeof(struct rpcap_header) ++ * p->bp == p->buffer + sizeof(struct rpcap_header) ++ */ ++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen); + if (status == -1) + { + /* Network error. */ +@@ -557,27 +599,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + + /* + * We have the entire message. +- */ +- header->plen = plen; +- +- /* +- * Did the server specify the version we negotiated? ++ * Step 2: to validate the received message further, require: ++ * ++ * - the rpcap general header to have the correct version and type, and ++ * - the rpcap general payload to be large enough to contain at least a ++ * complete RPCAP_MSG_PACKET header, and ++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload ++ * (i.e. the captured packet) length that fits in the rpcap general ++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header. + */ + if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version, +- header, p->errbuf) == -1) +- { ++ gen_header, p->errbuf) == -1) ++ return 0; /* Return 'no packets received' */ ++ if (gen_header->type != RPCAP_MSG_PACKET) + return 0; /* Return 'no packets received' */ ++ if (gen_header->plen < sizeof(struct rpcap_pkthdr)) ++ { ++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE, ++ "Received an incomplete RPCAP_MSG_PACKET header."); ++ return -1; + } +- + /* +- * Is this a RPCAP_MSG_PACKET message? ++ * Validate the RPCAP_MSG_PACKET payload length declared in the ++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX ++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen ++ * gen_header->plen is significantly less than UINT32_MAX + */ +- if (header->type != RPCAP_MSG_PACKET) +- { +- return 0; /* Return 'no packets received' */ +- } +- +- if (ntohl(net_pkt_header->caplen) > plen) ++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr)) + { + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Packet's captured data goes past the end of the received packet message."); diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb index 5f1506f8fc..3892454a40 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.4.bb @@ -23,6 +23,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.gz \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ file://06-CVE-2026-18313.patch \ + file://07-CVE-2026-18238.patch \ " SRC_URI[sha256sum] = "ed19a0383fad72e3ad435fd239d7cd80d64916b87269550159d20e47160ebe5f"