From patchwork Thu Sep 24 04:32:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99118 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2CE38C98312 for ; Thu, 24 Sep 2026 04:33:32 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.720.1790224402339212306 for ; Wed, 23 Sep 2026 21:33:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=gPSOKBz5; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-868a9c48f9eso1373030b3a.3 for ; Wed, 23 Sep 2026 21:33:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224402; x=1790829202; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=4b9Btfc2Uu1uAdENZmQU1WuhPlnrnHbp9C9e5Vie+Yc=; b=gPSOKBz5GfZMsGfI3U6eVDP7GoAU4ZViKno8rnGCad+snFsssgKIOK72zzEnR+o62H vCnlb/OOSDFTu1iy+Wb9lEzzo1Rray+tUkWHHHaX1hetoqx0gUE/ApViBweahQUqkPKw T8+Sb+gaAvyGr6llwC3+rl5Kvk3gqo/k9+EsqzIP+wME8G2sIRw4z/bxJzYtOWTmOO+n a2a7C73xtlYypI3devgUqn+NUzQ1y2w54vvtnkKFtK2HE41PGSVdLygdXREUBJhLZAPL Frs5q+JhgtthsahwN79NlzQQ7H8s0xvBOHD2b2L1ASqcDujUkXu5ZD6WtuNlpM46/2cq LvLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224402; x=1790829202; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4b9Btfc2Uu1uAdENZmQU1WuhPlnrnHbp9C9e5Vie+Yc=; b=qm8Tg7WAl8m9iYncqaZ56f/vymRir3L8FMceyKp0yq2YAhFI9JyttL9pMsYGc8N2RW wfy3wOsaWjVIcv89fKtwVND3IeoXUQPWgtcOgrrzesO4BYRfliJeg+y3//zYCr98CV1A 9Img7tTytTaRJ4cgW+sQsEEeAw1vAAgMSuSMgbtd8hFQNktqzuyz0MSAt1+9esub1XUA DX2BfxtYF+AJdXZlcuflc7r3/k4LqnI3iRu0jiW5zKuNMlgD5tVIFE35fSnHLH98DF67 C0iiSXHHZIrZTRMP8WasQ8JESm3jEW2//CiPObGVBDugyD2/8GgHM8y/g+tS/4KVlIII SbbA== X-Gm-Message-State: AFuF++msXz9NIqkgfB9seCOfI5/iQV6e1NEXYED1ymDS/gZT2XQXtzyH OyHLhqRbOkB4o4Kn3uHmaq4UJmEZB2f24Y0AHbfdUp11uvYFNblpm3TVDQ+Rsw== X-Gm-Gg: AYBFou2A5hpKt2OgqLVl7rT05rBVYcKxH2YgICRY9U3j1fLEOOUSXakHRSvYHAybKzz lN+QtkSYUo4DpNhNfRbamX1OGbwVw0NJ6NQQX7//4pI4dw87Jydr/NdbzCXMkRnV3v5j0gcljeE TvE6LMX+vCsQacBXIwLg3+z1MM/nz/D2Qymp7N4al3Db+F3TOZyGQv/RLnLGWbv72sZJCG0EjgN EjK8taHhZ6lUlSmwVEmUTkWanh5fv3RcWD7kpKUVwwH5fMKcEgjDy0DEe2mS1vzKb+PGxBG0COF HzHNkuTIjDY6dOMptMvQK5xfDrqdOXjrSz9He4pFbC6d042crSF1QQV8Vu6TD23suome7/6150d gxf+b+lrtst4UWoGCux/Jb6leE/+qXHmmKIhuo42nXAVmTQljaC0ToN+zKhNUT6w92b/2Nwu/lN pmRRksLUOCJoV9zgmMatOF49lGzKIecaSc7osJDxxpzwskmlgO5bV+JxzEqXXJ+aw9PrWJu0Tg/ qm4cyx68iRP6Q3m21g413M= X-Received: by 2002:a05:6a00:3e24:b0:869:d8e5:dc01 with SMTP id d2e1a72fcca58-87e9c543f1emr1016405b3a.4.1790224401559; Wed, 23 Sep 2026 21:33:21 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:20 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 1/24] rabbitmq-c: patch CVE-2026-44235 Date: Thu, 24 Sep 2026 16:32:51 +1200 Message-ID: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130249 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44235 Signed-off-by: Ankur Tyagi --- .../rabbitmq-c/CVE-2026-44235.patch | 95 +++++++++++++++++++ .../rabbitmq-c/rabbitmq-c_0.15.0.bb | 1 + 2 files changed, 96 insertions(+) create mode 100644 meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch new file mode 100644 index 0000000000..fcb0e1e1d1 --- /dev/null +++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch @@ -0,0 +1,95 @@ +From 52f00ef57e55c783c2c436590296d9ff986b65d0 Mon Sep 17 00:00:00 2001 +From: Claude +Date: Tue, 28 Apr 2026 00:30:47 +0000 +Subject: [PATCH] amqp_connection: reject undersized frames in + amqp_handle_input + +A malicious AMQP server (or active network attacker on an unencrypted +connection) can send an AMQP frame whose stated frame body is shorter +than the per-frame-type header it claims to carry. amqp_handle_input() +then computed encoded.len as + + state->target_size - HEADER_SIZE - - FOOTER_SIZE + +with no lower-bound check on target_size. Because encoded.len is a +size_t, the subtraction wrapped to a value near SIZE_MAX. The bogus +length was passed to amqp_decode_method() / amqp_decode_properties() +and through to the table decoder, whose internal bounds checks could +no longer constrain the parser. The result was an out-of-bounds read +and process crash on the client side, reachable during amqp_login. + +Validate target_size against the minimum required for each frame type +(METHOD: HEADER_SIZE+4+FOOTER_SIZE, HEADER: HEADER_SIZE+12+FOOTER_SIZE, +BODY: HEADER_SIZE+FOOTER_SIZE) and return AMQP_STATUS_BAD_AMQP_DATA +when the frame is too small, before computing encoded.len. + +Add the verified PoC bytes as a regression seed for the existing +fuzz_server harness. + +Refs: GHSA-9mmv-r8g3-qp46 +(cherry picked from commit 1d3afbb056fee5cc9ea05680bf32288715d0d802) + +CVE: CVE-2026-44235 +Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1d3afbb056fee5cc9ea05680bf32288715d0d802] +Signed-off-by: Ankur Tyagi +--- + .../input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw | Bin 0 -> 113 bytes + librabbitmq/amqp_connection.c | 19 ++++++++++++++++++ + 2 files changed, 19 insertions(+) + create mode 100644 fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw + +diff --git a/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw b/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw +new file mode 100644 +index 0000000000000000000000000000000000000000..558e9f5bff6b24ad3104b8a3038ab5b271257dcc +GIT binary patch +literal 113 +zcmZQ%0D&+DE+FItvaHO#6&U^l0azR#5qxj8*#?Ay5=J1KHNeNw(+|W*&5I8WKF0)> +L=Vq{ht2+k({(TL> + +literal 0 +HcmV?d00001 + +diff --git a/librabbitmq/amqp_connection.c b/librabbitmq/amqp_connection.c +index 56ab8a8..4326ef7 100644 +--- a/librabbitmq/amqp_connection.c ++++ b/librabbitmq/amqp_connection.c +@@ -320,6 +320,13 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data, + + switch (decoded_frame->frame_type) { + case AMQP_FRAME_METHOD: ++ /* A METHOD frame body must contain at least the 4-byte method id. ++ * Reject undersized frames before subtracting from target_size to ++ * avoid an unsigned underflow that would yield a huge encoded.len ++ * and cause out-of-bounds reads in amqp_decode_method(). */ ++ if (state->target_size < HEADER_SIZE + 4 + FOOTER_SIZE) { ++ return AMQP_STATUS_BAD_AMQP_DATA; ++ } + decoded_frame->payload.method.id = + amqp_d32(amqp_offset(raw_frame, HEADER_SIZE)); + encoded.bytes = amqp_offset(raw_frame, HEADER_SIZE + 4); +@@ -335,6 +342,15 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data, + break; + + case AMQP_FRAME_HEADER: ++ /* A HEADER frame body must contain at least 12 bytes (class_id, ++ * weight, body_size). Reject undersized frames before subtracting ++ * from target_size to avoid an unsigned underflow that would yield ++ * a huge encoded.len and cause out-of-bounds reads in ++ * amqp_decode_properties() / the table decoder ++ * (CVE: GHSA-9mmv-r8g3-qp46). */ ++ if (state->target_size < HEADER_SIZE + 12 + FOOTER_SIZE) { ++ return AMQP_STATUS_BAD_AMQP_DATA; ++ } + decoded_frame->payload.properties.class_id = + amqp_d16(amqp_offset(raw_frame, HEADER_SIZE)); + /* unused 2-byte weight field goes here */ +@@ -354,6 +370,9 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data, + break; + + case AMQP_FRAME_BODY: ++ if (state->target_size < HEADER_SIZE + FOOTER_SIZE) { ++ return AMQP_STATUS_BAD_AMQP_DATA; ++ } + decoded_frame->payload.body_fragment.len = + state->target_size - HEADER_SIZE - FOOTER_SIZE; + decoded_frame->payload.body_fragment.bytes = diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb index 4fd6302f2c..642e1e443b 100644 --- a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb +++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb @@ -4,6 +4,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=7e12f6e40e662e039e2f02b4893011ec" LICENSE = "MIT" SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \ + file://CVE-2026-44235.patch \ " SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8" From patchwork Thu Sep 24 04:32:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99119 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 21433C98310 for ; Thu, 24 Sep 2026 04:33:32 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.724.1790224404871480193 for ; Wed, 23 Sep 2026 21:33:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=r4yj9NJA; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85469a34908so1149848b3a.0 for ; Wed, 23 Sep 2026 21:33:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224404; x=1790829204; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HrhURTwkf/vjU3XSS+4oUzqkCQTwiM8RCxMDDQHaY7Q=; b=r4yj9NJA0WcPmpcAZdzusv1DkBqscaCH0YIbOVRPJub72kyy5rOD+0DUiaTaqvrEBc wwBUA3SSa6msavWiir5Y7ukHng72wYuvQzUenogUSjDFk06aU25x8Y+jgK27gvm49Fws Fue392dN6ZkTHBuH+gOrT6Z1e1txR0ZydUVaQaze4ZKtakDPi48Sx68HO/aBW9R8MpxF CUZqJ1ElmTtL1R0Q4p4Ezmd6dIJX8oM4YC5IwFJit0rma5FiDor6d1F8yM8h16hgvxaQ l2g+a0/35r6nte9XMaS6GDZjZB+6bTSpQfcWVz+TYtWZtFZsBjbALYK9R10CNahBdvn5 9gcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224404; x=1790829204; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HrhURTwkf/vjU3XSS+4oUzqkCQTwiM8RCxMDDQHaY7Q=; b=SkNqtpm2feUevXtECbwL0ElM2y1/uIrGFIikc91b/khYcGYZzWo587gXT/GVwsArzk dVGcIWX3IQx3TEbopUUFcBuQGBHT/NzwBneNEFpwfSOALY48GMbYfCqiFyk5Ax0q2KK2 2vwOKpYsXD1ODxHyNfK9FSBHYu7wgxvKENCyELZmt+jml6HjXVE/6KtjIL2jB3WyyI+M BU3cFlP5nJqZX4IMJUmqEtayh6qB+WdAXlrVsdaDnLlKZcZm8ckGVZG10rXgpysm7VBs i2VXAlEsVZI1Cpgqd2JlyVhZBqdpHojGDFCGXAG2+vTL+zkBamguYH1nU190b9W1Jcwd +KWA== X-Gm-Message-State: AFuF++n8pz1u3OV7B8IUIpaX/cEb2Uw0IQwF5VRa0l/ylMzm+IEfh3sL YuzH6ksRwXHsdt2JpGzNDc96XooMsXVcWwpRl/eG4JfvZKRudBjtMv8x0JHxqA== X-Gm-Gg: AYBFou3JJVSBP2MJBBrE/hpx22yEmsU/TXUFfuqNouU3zPMYWfYpnsRjGf6XbmPwmLs qWdH/Icj5mmR2EFcX8/woNUti0cLWL3uRZ8cmUcVoPlZuTNe7WW0v1u53guAp2hMYG+iazTZIqy Sl4UPbWtZQMRFMTxKyKTLWf4LVG3U86ddT1LbBhkyOe2nekokfRMiDNLdkxO79rBcxWZvlPCUgL x4Qu+Ikx0YoSq2mYKYVAo6kTZFPjFhDrWubixq64NQ5Qbmya3qLZ4WIPif8dOzVWrVyNc3aVDQy ht0qbwS96oEDZ9AEBf8wjQtbBhRNgSYgLRQn5o7aXVFPdVoK2UhIzL/Rfc0znq8ae72T1peEdS/ a5VuNURMA1LYurDsl+xj/H1sDn5TpR2zsT4S2Q+Angnl5F+ixwDW/pqgB8N8bAS62+XLgewj7gX B9BWkGWYLARfjc/21SLGT2EGkYozP9b0jai1QsO/NiBVaM2CE1VYJLbDxdM+NGHt8kLbBp8ChvE RowSKtnGeo21Xf0zcL05UA= X-Received: by 2002:a05:6a00:4c9c:b0:878:34d7:6982 with SMTP id d2e1a72fcca58-87ea0bc854cmr940107b3a.48.1790224403921; Wed, 23 Sep 2026 21:33:23 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:23 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 2/24] rabbitmq-c: patch CVE-2026-44236 Date: Thu, 24 Sep 2026 16:32:52 +1200 Message-ID: <20260924043315.1663186-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130250 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44236 Signed-off-by: Ankur Tyagi --- .../rabbitmq-c/CVE-2026-44236.patch | 145 ++++++++++++++++++ .../rabbitmq-c/rabbitmq-c_0.15.0.bb | 1 + 2 files changed, 146 insertions(+) create mode 100644 meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44236.patch diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44236.patch b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44236.patch new file mode 100644 index 0000000000..3c8a5a71a3 --- /dev/null +++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44236.patch @@ -0,0 +1,145 @@ +From 17f19124ba26f9c924f9ab53bca975cb8673f862 Mon Sep 17 00:00:00 2001 +From: Kevin Valerio +Date: Tue, 28 Apr 2026 13:45:22 +0200 +Subject: [PATCH] fix(connection): enforce minimum frame_max + +(cherry picked from commit 4777d0b5c58cb02966a04a85832436bd66ed5d1f) + +CVE: CVE-2026-44236 +Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/4777d0b5c58cb02966a04a85832436bd66ed5d1f] +Signed-off-by: Ankur Tyagi +--- + README.md | 6 ++++- + librabbitmq/amqp_connection.c | 4 +++ + librabbitmq/amqp_socket.c | 1 + + tests/CMakeLists.txt | 5 +++- + tests/test_tune_connection.c | 51 +++++++++++++++++++++++++++++++++++ + 5 files changed, 65 insertions(+), 2 deletions(-) + create mode 100644 tests/test_tune_connection.c + +diff --git a/README.md b/README.md +index 7c02d52..2682993 100644 +--- a/README.md ++++ b/README.md +@@ -133,6 +133,10 @@ terminal window: + Please see the `examples` directory for short examples of the use of + the `librabbitmq` library. + ++During login, `frame_max` negotiation follows the AMQP minimum frame size. ++Values below `AMQP_FRAME_MIN_SIZE` are raised before the client sizes its ++outbound frame buffer or sends `connection.tune-ok`. ++ + ### Threading + + You cannot share a socket, an `amqp_connection_state_t`, or a channel +@@ -177,4 +181,4 @@ NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS + BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN + ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN + CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +-SOFTWARE. +\ No newline at end of file ++SOFTWARE. +diff --git a/librabbitmq/amqp_connection.c b/librabbitmq/amqp_connection.c +index 4326ef7..f016fc1 100644 +--- a/librabbitmq/amqp_connection.c ++++ b/librabbitmq/amqp_connection.c +@@ -113,6 +113,10 @@ int amqp_tune_connection(amqp_connection_state_t state, int channel_max, + + ENFORCE_STATE(state, CONNECTION_STATE_IDLE); + ++ if (frame_max < AMQP_FRAME_MIN_SIZE) { ++ frame_max = AMQP_FRAME_MIN_SIZE; ++ } ++ + state->channel_max = channel_max; + state->frame_max = frame_max; + +diff --git a/librabbitmq/amqp_socket.c b/librabbitmq/amqp_socket.c +index 094ceb7..a7206c7 100644 +--- a/librabbitmq/amqp_socket.c ++++ b/librabbitmq/amqp_socket.c +@@ -1387,6 +1387,7 @@ static amqp_rpc_reply_t amqp_login_inner(amqp_connection_state_t state, + if (res < 0) { + goto error_res; + } ++ client_frame_max = (uint32_t)amqp_get_frame_max(state); + + { + amqp_connection_tune_ok_t s; +diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt +index 8c0aee0..624e7f5 100644 +--- a/tests/CMakeLists.txt ++++ b/tests/CMakeLists.txt +@@ -23,6 +23,10 @@ add_executable(test_status_enum + target_link_libraries(test_status_enum rabbitmq-static) + add_test(status_enum test_status_enum) + ++add_executable(test_tune_connection test_tune_connection.c) ++target_link_libraries(test_tune_connection rabbitmq-static) ++add_test(tune_connection test_tune_connection) ++ + add_executable(test_basic + test_basic.c) + target_link_libraries(test_basic rabbitmq-static) +@@ -40,4 +44,3 @@ add_test(sasl_mechanism test_sasl_mechanism) + add_executable(test_merge_capabilities test_merge_capabilities.c) + target_link_libraries(test_merge_capabilities rabbitmq-static) + add_test(merge_capabilities test_merge_capabilities) +- +diff --git a/tests/test_tune_connection.c b/tests/test_tune_connection.c +new file mode 100644 +index 0000000..276e18d +--- /dev/null ++++ b/tests/test_tune_connection.c +@@ -0,0 +1,51 @@ ++// Copyright 2007 - 2021, Alan Antonuk and the rabbitmq-c contributors. ++// SPDX-License-Identifier: mit ++ ++#include "amqp_private.h" ++#include ++#include ++ ++#include ++#include ++ ++static void expect_frame_max(int requested, int expected) { ++ int res; ++ amqp_connection_state_t state = amqp_new_connection(); ++ ++ if (state == NULL) { ++ fprintf(stderr, "amqp_new_connection failed\n"); ++ abort(); ++ } ++ ++ state->state = CONNECTION_STATE_IDLE; ++ ++ res = amqp_tune_connection(state, 0, requested, 0); ++ if (res != AMQP_STATUS_OK) { ++ fprintf(stderr, "amqp_tune_connection returned %d\n", res); ++ abort(); ++ } ++ ++ if (amqp_get_frame_max(state) != expected) { ++ fprintf(stderr, "expected frame_max %d, got %d\n", expected, ++ amqp_get_frame_max(state)); ++ abort(); ++ } ++ ++ if (state->outbound_buffer.len != (size_t)expected) { ++ fprintf(stderr, "expected outbound buffer length %d, got %zu\n", expected, ++ state->outbound_buffer.len); ++ abort(); ++ } ++ ++ amqp_destroy_connection(state); ++} ++ ++int main(void) { ++ expect_frame_max(0, AMQP_FRAME_MIN_SIZE); ++ expect_frame_max(1, AMQP_FRAME_MIN_SIZE); ++ expect_frame_max(AMQP_FRAME_MIN_SIZE - 1, AMQP_FRAME_MIN_SIZE); ++ expect_frame_max(AMQP_FRAME_MIN_SIZE, AMQP_FRAME_MIN_SIZE); ++ expect_frame_max(AMQP_DEFAULT_FRAME_SIZE, AMQP_DEFAULT_FRAME_SIZE); ++ ++ return 0; ++} diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb index 642e1e443b..f3c2a52fa2 100644 --- a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb +++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb @@ -5,6 +5,7 @@ LICENSE = "MIT" SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \ file://CVE-2026-44235.patch \ + file://CVE-2026-44236.patch \ " SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8" From patchwork Thu Sep 24 04:32:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99115 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 776C2C982FD for ; Thu, 24 Sep 2026 04:33:31 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.721.1790224406839364771 for ; Wed, 23 Sep 2026 21:33:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Cpbslsqu; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469e211a3so877766b3a.2 for ; Wed, 23 Sep 2026 21:33:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224406; x=1790829206; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=jNpz5bu3EtBX3wZBwhshpLFuwiVrEnqZ+vNL4WKg+mw=; b=CpbslsquUKpLGp2wzUPerHAhXuSBURDNVK9AAiwhB072ayyiyTUvEjJzu0ERAajAs8 hsBQstZCd8ri0v6sYttJOa7Iqt8dbBiGYrrxato84PhYZ4nH1X9ItOKU5h4s9x3ZhsLv 4W8cl95vWrSisXJxPeRfoVH5tmHvzAHKWBpjvtcimFn3X4yh7bp3EGf2pD2txarqQXeN F1aRMB2eNaegnTBif+tO0kWBnANyUtFQCzWJG8kB1NjSzISxiv2Pwbw3w9lL/0AkxqjY oya02WM1sXi8Qc+OZTAuKmQqwhZ5pNpl8sq+yyQSOMVCZwyPXQfefPv8L2jOmduPCgPm Sirw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224406; x=1790829206; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jNpz5bu3EtBX3wZBwhshpLFuwiVrEnqZ+vNL4WKg+mw=; b=0NurueZ+wqOBX8oHqzTm8pvz+VdT442uDr1bkyEKuMD/KF5wUtki5kK3/RbQVl9qzB eezihzvFUIdbKr96vl436Tt1FiIiiep0K616TFJkzVtMIi4XmuHxlb9yPzItUIGqRDzA Z5lL/dGb3VOaEpKloUNwyVgCnoGwh24wQn/xpNo/GaNreM4umEf3WucdWTkaRkLK7dBT CBepoc/IBqty8A3U4rSVnf36+cLBNvl8EGBOTGzKLDFL1YqjnkHC2px6s4cNzW4my2As wO1wNVUxrjPLbeU58hLt0LKf+XB7zNxgg6JBBG1/Bm0fna8qUPiSEvSqqzHpnGV0L2Hq VQ2w== X-Gm-Message-State: AFuF++nC1ZyVMtZIGhVIsmRKaMuhonJ5k7yxtKCr0H2RoXVmuS4O+FBv quY5TeQyy2UqPkKBARtcp8pAuf6RfrY4H8HHS7oA5phgrsgoDGT0SA1sMtP1AQ== X-Gm-Gg: AYBFou1R7qlkTkUtYWWEfJ73UM79kObST+3iBA+XRE2eTyTRVbPprP6OQy5ufzmZgTl lMUydMpkhpxwsMmFCH+GEVdX0iDPALNjOvQDEU8jFVJrhsVjcvbx5ozKY+glkdbQu4ZfCKFqOO3 x0FzgiVGo2MZtzWvIadg36fWAGWC7okOANld4CywlMGhL9vbiiz7AVYJCIQzT/BEK03KRH8ot29 LgD0IUxrFi58NZIxk9JFvC+MEJU3EWxFeLRXh+IdKw+AoJ7+CravFO0FJzwJ1PcHveuGGhxkX5K j8sMm9qzna9oDo3XcMYtVtDfoLpqE1sjJqMgYfLtUHW2h9yW0AIrIb3y6voDdXuoGNn779+0LGa NCktpUmX4zpLMqJHlJ3DsEz7VNqbVhlaBz3Ks/11WbdCf6xWANPvbnwsQ9ptJJ1oLxcwogoUzn0 lYGFqvv3TbUDRyecaskKnbjFvAzrU+H5HlHTOelkqANK/ew1Tljbqxufl6Xs3G/ixQhbsEjF8Nv oXWBQJkFtQESQv20SNjP8/kBP+lAnHCIQ== X-Received: by 2002:a05:6a00:6ca7:b0:87d:fa7:87c1 with SMTP id d2e1a72fcca58-87e9f053fa5mr1057389b3a.29.1790224406139; Wed, 23 Sep 2026 21:33:26 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:25 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 3/24] redis: patch CVE-2026-81934 Date: Thu, 24 Sep 2026 16:32:53 +1200 Message-ID: <20260924043315.1663186-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130251 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-81934 Signed-off-by: Ankur Tyagi --- .../redis/redis-8.0.6/CVE-2026-81934.patch | 53 +++++++++++++++++++ meta-oe/recipes-extended/redis/redis_8.0.6.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta-oe/recipes-extended/redis/redis-8.0.6/CVE-2026-81934.patch diff --git a/meta-oe/recipes-extended/redis/redis-8.0.6/CVE-2026-81934.patch b/meta-oe/recipes-extended/redis/redis-8.0.6/CVE-2026-81934.patch new file mode 100644 index 0000000000..80a9118d92 --- /dev/null +++ b/meta-oe/recipes-extended/redis/redis-8.0.6/CVE-2026-81934.patch @@ -0,0 +1,53 @@ +From 83b6dda66e69bdaf7927140d70666f838b33cbf0 Mon Sep 17 00:00:00 2001 +From: Sergei Georgiev +Date: Tue, 9 Jun 2026 14:22:50 +0300 +Subject: [PATCH] Fix use-after-free in tlsProcessPendingData() pending-list + iteration (#1391) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +`tlsProcessPendingData()` iterates `pending_list` using a `listIter`, which pre-caches the `next` node pointer on every `listNext()` call. This cached pointer can dangle and be dereferenced after the node it points to has been freed, causing a use-after-free and a server crash (SIGSEGV). + +The issue occurs because `tlsHandleEvent()` runs the connection's read handler, which can execute a command (e.g. `CLIENT KILL`) that closes a *different* pending TLS connection. That close path goes through `freeClient()` → `connClose()` → `connTLSClose()`, which calls `listDelNode()` and frees the victim connection's `pending_list` node. If the iterator's cached `next` pointer referenced that node, the following `listNext()` reads freed memory. The `listNext()` contract only permits removing the *current* node, not arbitrary other nodes. + +Replace the `listIter`-based iteration with a detach-from-head, bounded drain so that no list node pointer is ever held across a handler call: + +- Re-read `listFirst()` on each iteration instead of relying on a pre-cached `next` pointer +- Detach the head via `tlsPendingRemove()` *before* calling `tlsHandleEvent()`, so the loop always makes forward progress +- Semantics are preserved: in the common case each connection is handled exactly once per cycle, in order + +(cherry picked from commit 98ff29b2828bf3245167b416ee23e6797f551a37) +(cherry picked from commit 6d088c335d5c3ec49a6c28486140b498e70b7834) + +CVE: CVE-2026-81934 +Upstream-Status: Backport [https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834] +Signed-off-by: Ankur Tyagi +--- + src/tls.c | 9 ++++----- + 1 file changed, 4 insertions(+), 5 deletions(-) + +diff --git a/src/tls.c b/src/tls.c +index a0733a4b6..0fa468cfc 100644 +--- a/src/tls.c ++++ b/src/tls.c +@@ -1098,15 +1098,14 @@ static int tlsHasPendingData(struct aeEventLoop *el) { + } + + static int tlsProcessPendingData(struct aeEventLoop *el) { +- listIter li; +- listNode *ln; +- + list *pending_list = el->privdata[1]; + if (!pending_list) return 0; + int processed = listLength(pending_list); +- listRewind(pending_list,&li); +- while((ln = listNext(&li))) { ++ for (int i = 0; i < processed; i++) { ++ listNode *ln = listFirst(pending_list); ++ if (!ln) break; + tls_connection *conn = listNodeValue(ln); ++ tlsPendingRemove(conn); + tlsHandleEvent(conn, AE_READABLE); + } + return processed; diff --git a/meta-oe/recipes-extended/redis/redis_8.0.6.bb b/meta-oe/recipes-extended/redis/redis_8.0.6.bb index fe31033328..67126c9fcf 100644 --- a/meta-oe/recipes-extended/redis/redis_8.0.6.bb +++ b/meta-oe/recipes-extended/redis/redis_8.0.6.bb @@ -15,6 +15,7 @@ SRC_URI = "http://download.redis.io/releases/${BP}.tar.gz \ file://0003-hack-to-force-use-of-libc-malloc.patch \ file://0004-src-Do-not-reset-FINAL_LIBS.patch \ file://0005-Define-_GNU_SOURCE-to-get-PTHREAD_MUTEX_INITIALIZER.patch \ + file://CVE-2026-81934.patch \ " SRC_URI[sha256sum] = "6d0a9913887a4972536f9da226f1575859c34d86354129163260a5f9c6bd4229" From patchwork Thu Sep 24 04:32:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99116 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5E59DC98304 for ; Thu, 24 Sep 2026 04:33:31 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.722.1790224409279007414 for ; Wed, 23 Sep 2026 21:33:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=hIV6DQae; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-86868f7707dso731653b3a.2 for ; Wed, 23 Sep 2026 21:33:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224409; x=1790829209; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KRFuPBka9S7iS5QVkQkVRFwI2NJGW81vs8p42NGiXCQ=; b=hIV6DQaebn7ieEexjfObpaTqjZmIasmN6yJZf+f6f7VpURowWsEoFtQXLgn87fjq5d Tp8qmSw+j/LqoJVXn7p/0Ll+YYPvLElYAWRCqOABwGc5lO2Km+epL4XSAT2YJeZuSrsL ZzIGfM8zMXW8+ELwojKQiC/YDaF+MP5wtFS0wpaOsaQFOdRxG+VwCtpxSwLSIlk/Tl/s tjrUiV1tGjHPobsiBYez24eO06ZlBrNt1a1dmVGsSv80wu5iQVLI55WcstcZnqPkU55s J23bWWmDao7MFSWcr5A24wgeBSrfV1oIqWh97GsF9rP4JiQdekFr2kb/NtAinH4J6fO2 SWug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224409; x=1790829209; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KRFuPBka9S7iS5QVkQkVRFwI2NJGW81vs8p42NGiXCQ=; b=gq6kFmpV5A8psA19zPjd2/Vykx1cgYn8kBTXpCE5Dm/HYOi08C/vuRfD0rFtWL0dqt 5hM7Guau0rCLqjSGoWTWWHEPOycpzw/uGI2i8zInctzewJgXO6WbZfdODl3oRNH1y4vx PMN1rDrN8S4f7R1j8i1URVcBmL61YfRz2pO/lOTqYxdn2wEttn8IzloBEyURfspG/y3e uN0yHZOQhUYbgAYGx8s7N6xOcV9N6ijSoK+8Q80OkoLgT34ziElNch4nGFValWyj+hFx kZ9RuwNJe7oU1qoUUxwJV8dchcB8KE4z8Jiz/Vpfcfkdyrbx1ItNVzw+ZeqE6G0q9W7S 950g== X-Gm-Message-State: AFuF++lekqWDvav0VwddJZfU64zzJhOF7zXdAs3rjoebAp8UI6MFUwZd DLC4+GzqrZTnHB1Q4lkilihyLf6By9iUrCsxZOoGkzYG5tHOZKH+mLOuvQhDUQ== X-Gm-Gg: AYBFou1CVjtvc+fEtf8sRMjufc7vRHzRm3dVg9wkEDdqcmqHkr+2bcDoGH1HI5rTaVx YgvfSSMz6Li1hq0KFnybMAWJdKYwsmpsUM6yxsX0qgue6IP23i5pNLy8T78mkNgClR3sOInIQGQ B1CTM7OR+VeIAFasAucbZY5FS2nTrPUbvgbBAfe/1yOASPyGIp0jiK/JQIfT83mC2PvI0sZobWM /pwii80Mjum9E28ywbYackpS8FvRy/oKpiRp9QwNAlR/bzrVU2LHjVyeXRHdYowPpwDDoINysS9 BBG4fThc2pkMLCU1RtFUXISLBfPuHt6t1uYhB2d6vPpGT5+9hAIhWvJzk6iCUyDH834sW3toVAw yk/7o64VY3L5SAKWX714YeRvyCk+aAYX5cOxDfIVe/3qLJ+eEikObtSSC1gIttcXOuTWtgWJoOR h3l/rXPGuhqQu5BZqFgv+y5p4SlYpkIHEV1LTb4wkkiFvq/LdeJzMvdYGa2/jrjDUtElsz5mkNl Wc79AeelnVwI8OtKrLi2if+DJSksGVzew== X-Received: by 2002:a05:6a00:90a7:b0:87d:ddc7:4915 with SMTP id d2e1a72fcca58-87e9e29b99bmr876140b3a.1.1790224408543; Wed, 23 Sep 2026 21:33:28 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:27 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 4/24] sngrep: patch CVE-2026-90558 Date: Thu, 24 Sep 2026 16:32:54 +1200 Message-ID: <20260924043315.1663186-4-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130252 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-90558 Signed-off-by: Ankur Tyagi --- .../sngrep/sngrep/CVE-2026-90558.patch | 84 +++++++++++++++++++ .../recipes-support/sngrep/sngrep_1.8.2.bb | 4 +- 2 files changed, 87 insertions(+), 1 deletion(-) create mode 100644 meta-networking/recipes-support/sngrep/sngrep/CVE-2026-90558.patch diff --git a/meta-networking/recipes-support/sngrep/sngrep/CVE-2026-90558.patch b/meta-networking/recipes-support/sngrep/sngrep/CVE-2026-90558.patch new file mode 100644 index 0000000000..64fd8044a9 --- /dev/null +++ b/meta-networking/recipes-support/sngrep/sngrep/CVE-2026-90558.patch @@ -0,0 +1,84 @@ +From 399346a12ca3bcf7703734fa33b5b3427775b014 Mon Sep 17 00:00:00 2001 +From: Kaian +Date: Fri, 7 Aug 2026 08:45:42 +0200 +Subject: [PATCH] fix: prevent stack buffer overflow in SIP attribute + formatting + +call_get_attribute() formatted the Call-ID, X-Call-ID and Reason header +text with an unbounded sprintf("%s"). Call-ID/X-Call-ID can hold up to +MAX_CALLID_SIZE/MAX_XCALLID_SIZE (1023 bytes) and Reason text is copied +from the raw payload (up to MAX_SIP_PAYLOAD), while all callers pass a +255-byte SIP_ATTR_MAXLEN stack buffer (call list rendering, sort compare). +A SIP message with a long Call-ID, X-Call-ID or Reason header overflowed +the stack, triggerable via pcap, live capture or HEP/EEP remote capture. + +Bound these writes with "%.*s" and SIP_ATTR_MAXLEN - 1. Also fix a +matching off-by-one in msg_get_attribute(), where the existing "%.*s" +used SIP_ATTR_MAXLEN as the precision and could write 256 bytes +(255 chars + NUL) into the 255-byte buffer. + +Thanks to TristanInSec for reporting the issue. + +(cherry picked from commit 1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b) + +CVE: CVE-2026-90558 +Upstream-Status: Backport [https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b] + +SIP contract change was dropped during backport as it was introduced in +v1.8.4[1] + +[1]https://github.com/irontec/sngrep/commit/c61a26d90c166f996e31aceefc9c2f8f831ccd86 + +Signed-off-by: Ankur Tyagi +--- + src/sip_call.c | 6 +++--- + src/sip_msg.c | 6 +++--- + 2 files changed, 6 insertions(+), 6 deletions(-) + +diff --git a/src/sip_call.c b/src/sip_call.c +index bea879a..68ecb50 100644 +--- a/src/sip_call.c ++++ b/src/sip_call.c +@@ -257,10 +257,10 @@ call_get_attribute(sip_call_t *call, enum sip_attr_id id, char *value) + sprintf(value, "%d", call->index); + break; + case SIP_ATTR_CALLID: +- sprintf(value, "%s", call->callid); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, call->callid); + break; + case SIP_ATTR_XCALLID: +- sprintf(value, "%s", call->xcallid); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, call->xcallid); + break; + case SIP_ATTR_MSGCNT: + sprintf(value, "%d", vector_count(call->msgs)); +@@ -282,7 +282,7 @@ call_get_attribute(sip_call_t *call, enum sip_attr_id id, char *value) + break; + case SIP_ATTR_REASON_TXT: + if (call->reasontxt) +- sprintf(value, "%s", call->reasontxt); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, call->reasontxt); + break; + case SIP_ATTR_WARNING: + if (call->warning) +diff --git a/src/sip_msg.c b/src/sip_msg.c +index 379a40a..6762862 100644 +--- a/src/sip_msg.c ++++ b/src/sip_msg.c +@@ -136,13 +136,13 @@ msg_get_attribute(sip_msg_t *msg, int id, char *value) + } + break; + case SIP_ATTR_METHOD: +- sprintf(value, "%.*s", SIP_ATTR_MAXLEN, sip_get_msg_reqresp_str(msg)); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, sip_get_msg_reqresp_str(msg)); + break; + case SIP_ATTR_SIPFROM: +- sprintf(value, "%.*s", SIP_ATTR_MAXLEN, msg->sip_from); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, msg->sip_from); + break; + case SIP_ATTR_SIPTO: +- sprintf(value, "%.*s", SIP_ATTR_MAXLEN, msg->sip_to); ++ sprintf(value, "%.*s", SIP_ATTR_MAXLEN - 1, msg->sip_to); + break; + case SIP_ATTR_SIPFROMUSER: + if (msg->sip_from && (ar = strchr(msg->sip_from, '@'))) { diff --git a/meta-networking/recipes-support/sngrep/sngrep_1.8.2.bb b/meta-networking/recipes-support/sngrep/sngrep_1.8.2.bb index 12fe3ececa..1bcbebf554 100644 --- a/meta-networking/recipes-support/sngrep/sngrep_1.8.2.bb +++ b/meta-networking/recipes-support/sngrep/sngrep_1.8.2.bb @@ -15,7 +15,9 @@ DEPENDS = "\ ncurses \ " -SRC_URI = "git://github.com/irontec/sngrep.git;protocol=https;branch=master" +SRC_URI = "git://github.com/irontec/sngrep.git;protocol=https;branch=master \ + file://CVE-2026-90558.patch \ +" SRCREV = "dad1033640f249fa4994f976cf6ee96826c15702" From patchwork Thu Sep 24 04:32:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99117 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7A388C98314 for ; Thu, 24 Sep 2026 04:33:32 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.723.1790224411280968684 for ; Wed, 23 Sep 2026 21:33:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=cSMEAzoz; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469e211a0so947378b3a.1 for ; Wed, 23 Sep 2026 21:33:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224411; x=1790829211; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=afJiYSoCw8o0Pt+VkzZm3maco/ZyJK/IozJpYEsz8zA=; b=cSMEAzozvkw3bQXg3yWQHmGMRBJjubpjx/NtY46VGzMew5HguzqJyHAQvS4tPmFyWM GefQqCZkcJ3S1oQx79EigRa33b9rOPd0XE8GSyzylvdalQVP16K5Gv5w4xHCEmohlKR6 52xhQSAKMfLAMEBeFmAhihwrd6y0o5/ajjIGGNKCUZoBM451yLqvm60I6+COZcYW3XgT fphkYA8ynr8gXc2KLaXTJj0p9WJ+NA/xQv433MKra5w5R5tVig8TcbcS4+EReBmr6NWS VWHx6Zo0MA641kHfABv26rbrEYN8zNRqh+PBbgbUz8ciyg98ko32M1TehVjGzbV0mukf pKNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224411; x=1790829211; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=afJiYSoCw8o0Pt+VkzZm3maco/ZyJK/IozJpYEsz8zA=; b=Qb/4Sjv8X0AYwSBEODU3kljormf+3Lt2vWFdxfQlKMSYSw2ClK2/40SHc/S0d9Eaoc 1jGDMVp1YY5po3vNKKYQSa+84c/TnIWbfWVH1AebJ2g2qf7ADk2RDaro4f1ZkRW1vvn8 oxRdNbw/dld87bILd/v4+4qk9/ODm56ifX/HP9dvtnFH1o5KciPPu3FPyrsrSBObBRln qtRsih7K8tAPtWgd3VpbJAWuuLsFs5xy1fN3SDZeEHuuSvbzMHyPgFm18YRmCLk0CEyI V/MJcsy35ku6EzwHMjIRm0l+12x3gIvg2id1HMiH/Pu8vIAIDX/2T7ePWYj5OGA0TdxC 38fQ== X-Gm-Message-State: AFuF++lWB0vvBH2xuZogFmICMfZ/XM8/ui7i76x4ZTSElehbLbT51oj9 XOROsf5EFnRu0LdxD5xBXLxe+dV7KySQ81+0I8AF8RZySY3ZY0ZnLRRowBLMQw== X-Gm-Gg: AYBFou0B9jqfrrFMjs3XngqTSag6jrZXj374i8xlpRvlBytPgfjGVXhzIH6ghyighBo hrEfCNQvK05mh4YEY8Aiq/w3/Q6mKro54GwOEICMwZxCF6PUKaEIujRGVC2R7VBLp44o9HELm1O 1ozb6AriOHzpHXssXJHHFAVEjlFDRl3vt318eKOJwBrpEbnS12F2YTxF6Ij7rlroIKZr28rnZZQ Ak2Fr69kzNQNP/bTXdT2wWk0tiCWCtJ8YN+6i9N9xL+NemXoF4NUoZlZEbU2XTimSsik5AGL/lX xfMqaQMQ3aJoOO2Yns9ZP4KaArC8JplbcbgsxJT2Rs2o36cSploeN+m8Qb2wXgf95h8t7HWgaw5 vrPT5s74tKrtzgLR2QVGDYj2Rx44/aRj1eo7KNbXS6K5/qP0fee7MkpwUm5ehxSld+QS8zIUuRL vjcbofe6LXoCcntspOiQSjWchrgKMgUbrMi7Uzgl0WkZnBmhCYrXjGPioDE1GYmHg+8VxihoraG w7I2+/SPYSaDu1v4bHAv7x7rBaesGLjxQ== X-Received: by 2002:a05:6a20:6a22:b0:3dd:a196:9072 with SMTP id adf61e73a8af0-3de0e94439fmr1190327637.60.1790224410661; Wed, 23 Sep 2026 21:33:30 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:30 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 5/24] strongswan: patch CVE-2026-78123 Date: Thu, 24 Sep 2026 16:32:55 +1200 Message-ID: <20260924043315.1663186-5-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130253 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78123 [1]https://download.strongswan.org/security/CVE-2026-78123/strongswan-5.0.2-6.0.7_openssl_pkcs7_info_init.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78123.patch | 51 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78123.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78123.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78123.patch new file mode 100644 index 0000000000..5a810f0613 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78123.patch @@ -0,0 +1,51 @@ +From 23707d346f1f85dba0419c43658a86a80a24f568 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 1 Jun 2026 17:51:35 +0200 +Subject: [PATCH] openssl: Fix undefined memory access when verifying PKCS#7 + containers + +If the signerInfo or recipientInfo structure doesn't contain +issuerAndSerialNumber but instead a subjectKeyIdentifier, then the called +functions will leave the passed name and serial numbers unchanged. While +openssl_x509_name2id() prevents a NULL-pointer dereference, it tries to +DER-encode the object at the passed pointer via i2d_X509_NAME(). +Depending on the stack contents, this likely causes a segmentation fault. + +Fixes: 3c820cdc232a ("Implement PKCS#7 decryption using openssl") +Fixes: c61723c69fb5 ("Implement OpenSSL PKCS#7 signed-data parsing and verification") +Fixes: CVE-2026-78123 + +CVE: CVE-2026-78123 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/e59b4c96990635a482d6532f7905143f2541d8b5] + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/plugins/openssl/openssl_pkcs7.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c +index d9abcf8..b15c8d7 100644 +--- a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c ++++ b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c +@@ -222,8 +222,8 @@ static auth_cfg_t *verify_signature(CMS_SignerInfo *si, + auth_cfg_t *auth, *found = NULL; + identification_t *issuer, *serial; + chunk_t attrs = chunk_empty, sig, attr; +- X509_NAME *name; +- ASN1_INTEGER *snr; ++ X509_NAME *name = NULL; ++ ASN1_INTEGER *snr = NULL; + int i; + + if (CMS_SignerInfo_get0_signer_id(si, NULL, &name, &snr) != 1) +@@ -628,8 +628,8 @@ static bool decrypt(private_openssl_pkcs7_t *this, + identification_t *serial, *issuer; + private_key_t *private; + X509_ALGOR *alg; +- X509_NAME *name; +- ASN1_INTEGER *sn; ++ X509_NAME *name = NULL; ++ ASN1_INTEGER *sn = NULL; + u_char zero = 0; + int oid; + diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index d6176f000e..4d9fe14eb2 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -10,6 +10,7 @@ DEPENDS:append = "${@bb.utils.contains('DISTRO_FEATURES', 'tpm2', ' tpm2-tss', SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-47895.patch \ + file://CVE-2026-78123.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:32:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99123 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F0F36C98310 for ; Thu, 24 Sep 2026 04:33:42 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.726.1790224413547991577 for ; Wed, 23 Sep 2026 21:33:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=dgGxOf51; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc1cea4ae2cso1026951a12.0 for ; Wed, 23 Sep 2026 21:33:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224413; x=1790829213; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MUBEb+xvAXH2zkoe5y4mF+lOp8kxDJqVR167PVQu690=; b=dgGxOf51DgzQSlQofRSgXh6m0VYOt8U5IctbQi2y7dlsaqAtun0RCmBDDXexkioeql VYRo/sCKBG4m37JF6EJoecg3H9R/hThYrICTP7+7ANVnbinyF7AxN9X1Ok/smVk7F9sj TY0cniCd2s3IITJ3xVVXwW4nt7wCSE+voK3mbJRtxKbmriLrCK7oyz59DaXl51EbDEPX WdDn0XRDcbF8k0IaeTKvY0s4QFgLayFIykq6FAx5dYF6JTqTk6K/KM1Mr7VEdTL8Br/R 7yGYP1Lbvq1lmcjUm0OcY2Z6Qu8LWguhqCmSNk3vzLTMiji6o7qiMgC7filQsh5b3Ts7 rMbA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224413; x=1790829213; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MUBEb+xvAXH2zkoe5y4mF+lOp8kxDJqVR167PVQu690=; b=Ge2fW6zo4SzQJs+e4PJCyNZxVJHF83NtPZw4xo5gfd9T9FHhP32YnMe0Z0PjU2W1Ib 23qkY8pbq5sGhc/RWDGCeZHjvmjo9acWl+zs8DGp1o82ThHjbK3F7cf+xA23lUygqi6X hS464ZSATB7q4K9ZdJshngffHdFt7S0a77k/fF5YGYvW2G22S+cfzduRr7WADpN4yfgI UJYLosvjSBGdyOmV6GMLlLDtWvujb3zvrzSBm22XTB9OzvOoBLZcfpqsfw9KaOGNVphh sK1hMXRGXZ5wGVga3k+JVy6dTK+kGAehDK+RAYaco8etcw+1bWL1NR21goEP5qfIaRd/ 9XeQ== X-Gm-Message-State: AFuF++mPGIrMJfrI3L6uzD+RSg3WNpM95QxZ8Jf7yqOaf/jgO141Nia+ NJ/RWYMwRVGwpN5cczd3f0dTNteLPSQqQsifHDXITcXD27KdtGuN/IVvpQmkTA== X-Gm-Gg: AYBFou1Nd+a80ca1HArvinMWsK0altNRVkAB01/fEa3XhgASpOicnTvAJHHSAxzoujE mpE9/u8iVGuQtOK6O36PJaE9gmAFm58V/q5b0fQ5PnTRQwM9VUCixch5RhufbXBhxYA85EdcpzR wNz96FEyXzBpK/fA8yl8gHbDyLfPOoqGc92Him77yEDuwHQw28fCuzPszP92RC2efphYIl8HqcH 2uAz9ryTsbCFQpVxDd56tN4ZQu6LN45D4k9OTQKeyJgEi0rkCuLxRg6k3EVFubmrNvrZxF+9DId 5wdB2NHHBKZ/QNPpTjMVIBwUhDJaBjyvf829qwvbjABPO4ioCMgaZwM57n7bz39BFxSLxVdTFAa 4UMHXXBRec6krAr51Bcw1DgpZHEIAU1XD9yscf45f2St9qBWBFyhiJKxz0bGotC9YSoAssJOJfe 6jCLO4a1ARgz1L5zZVQoa1/boari7qZt8hl+9MkLEA19PubM1XbbTAazbMDp6v11Jvo+B+w4IGZ wxsJ1P2uzzeReYQFAjZMcI= X-Received: by 2002:a05:6a20:43a7:b0:3dd:a196:53a0 with SMTP id adf61e73a8af0-3de0e97679fmr1189747637.66.1790224412791; Wed, 23 Sep 2026 21:33:32 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:32 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 6/24] strongswan: patch CVE-2026-78124 Date: Thu, 24 Sep 2026 16:32:56 +1200 Message-ID: <20260924043315.1663186-6-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130254 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78124 [1]https://download.strongswan.org/security/CVE-2026-78124/strongswan-5.0.2-6.0.7_openssl_pkcs7_certs_leak.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78124.patch | 34 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 35 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch new file mode 100644 index 0000000000..b0b2a9eeef --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch @@ -0,0 +1,34 @@ +From 36ce778a76b4b912699a52cf1109394fce109c83 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 15 Jun 2026 16:02:01 +0200 +Subject: [PATCH] openssl: Fix memory leaks after enumerating certificates in + PKCS#7 container + +This can be triggered via IKEv1. + +Fixes: 04884be3b5f7 ("Implement openssl PKCS#7 certficiate enumeration") +Fixes: CVE-2026-78124 + +CVE: CVE-2026-78124 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/49bf0725fa61198d1e29d5b4c2651c9190b2c10c] + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/plugins/openssl/openssl_pkcs7.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c +index b15c8d7..cefe1ae 100644 +--- a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c ++++ b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c +@@ -132,6 +132,10 @@ typedef struct { + METHOD(enumerator_t, cert_destroy, void, + cert_enumerator_t *this) + { ++ if (this->certs) ++ { ++ sk_X509_pop_free(this->certs, X509_free); ++ } + DESTROY_IF(this->cert); + free(this); + } diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 4d9fe14eb2..e7a5370f03 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -11,6 +11,7 @@ DEPENDS:append = "${@bb.utils.contains('DISTRO_FEATURES', 'tpm2', ' tpm2-tss', SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-47895.patch \ file://CVE-2026-78123.patch \ + file://CVE-2026-78124.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:32:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99122 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F1922C98314 for ; Thu, 24 Sep 2026 04:33:42 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.727.1790224416374566366 for ; Wed, 23 Sep 2026 21:33:36 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Do5w+nZ7; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id 41be03b00d2f7-cc4c3304833so760372a12.3 for ; Wed, 23 Sep 2026 21:33:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224416; x=1790829216; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=h+X8IxMYmMycn6JsDTax5c7WqoUCis5/wvpTpU1NeCw=; b=Do5w+nZ7CzUzIPH9MVn9ZzrZnV7HRU8RxFUmqDzlgqIBtjrZtk6jVdZFcfaW6J0taz msR6IE+LEqGnmK+bBZh2E4kIm5ly1UPkBDPhPedASFP2z3NLteQj0OUNFVUyfKmlFlzC EFRtJ7Mr/FHff2MdO1HuJiRvF5i346aaQaH7PLWnuvVE64wwBC9aZUiUOJnyG9FbQzq6 nmKyVPKUG6zYXq5QeaUkDnxwp2wjhYp93/pxZEnUiheAYm1PxCAibKDuJ3Cptv7tbKCf ZSWJLwESXHheQoyCvYTwytGds310LYBvDtHisxyRP0yoFrdh9yiuaZA7dFTD4RvfuaxT v+zg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224416; x=1790829216; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=h+X8IxMYmMycn6JsDTax5c7WqoUCis5/wvpTpU1NeCw=; b=qQ9fGr9P0qdhldQsr9hMF6SzmCstpv6MIH8XcAGgcU0tbkJMKTeP/CMx8a9OSS2IQp DrGnEDINSj1N6xB9LN309hsgKFHLyebrEhgt22QuAsepSuAwxLBSbDYWM/8ImrhldJUg i6hdJQgYaQeb7OxgwC7ZMYK7K6uR9fUdQFD6RfaexFGUGU9bU6xeoicaGdkmNGbqIGzW 293WbVEfBkcYErD+Z2di6xiYiMtG/JAucd1onBUF3DQs874ppqXDIiBk5LdARFWSLcYa Sq8XYcDXCByAX8KFxahKBfBo70bLd+a3NeOqhkBvcl+IIHHgewSaAxi7JYgVj3M6w6x8 DIJg== X-Gm-Message-State: AFuF++lx6v6UAhoGIgUuhmVkkSfwQjAMSynQ9bsuXPRARFlxF8d1xyBG ymwkQV0g4gPKzvfJ/sOyu+b4GhZCtAbpRDXHPud8O7zKCOP7UzUVwGzdYhtvog== X-Gm-Gg: AYBFou1q42yP30/xxSrOqp7nMUMPXdNvLwp/tnGzBOXwkbrNhW8HprWF6vmTncRhHrX 4SB3g8iQkm6K/19A0xsGr5xeG/k7Qs/tTdXhw2H81LMixN2gJlwfMdpweNqK73f0g2SIV/qe4u3 ow+HtKQjHXZe+pNF1BWBd1K8/Z3JTevjIe/T2U+FdttqSq6sL39w/wtWol3KsTxlvDxctnmOM2e dbQI0el7YWW/mjmGTbs1KDHh0zRgGlhXKUs+0Re5XrNRH2UW5WVBauI3e6uosjtPoCg/ptq3eYK 8OlJ1oV3C73v/TJO8T3Z1RL7dkb2g87Fb/bSEJJ63vYXvnoNOac4pdatfmbwCiUSXxACg5HNBrj 0NH/0Lorf0SmjX5blUB6SOdlhdoGiaTmPUhkQZ5ej3PVMezSFhDv7C3EE0VRzv0SRI7SmoX4hOz isCDvtPpURDgQOnuLA5y0aWGxykYGJ+U1mSdCjhF2sXw8+vWc8gncEk2wmZ7yjNGOAMC3CW6Bmx F/NgH1szIRUJ+bNScJsnt8= X-Received: by 2002:a05:6a20:ce44:b0:3dd:a196:906d with SMTP id adf61e73a8af0-3de0e93798dmr1022463637.55.1790224415697; Wed, 23 Sep 2026 21:33:35 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:34 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 7/24] strongswan: patch CVE-2026-78126 Date: Thu, 24 Sep 2026 16:32:57 +1200 Message-ID: <20260924043315.1663186-7-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130255 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78126 [1]https://download.strongswan.org/security/CVE-2026-78126/strongswan-4.4.0-6.0.7_eap_aka_sync_fail.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78126.patch | 37 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78126.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78126.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78126.patch new file mode 100644 index 0000000000..9d4ce09d38 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78126.patch @@ -0,0 +1,37 @@ +From 13aa926cad7ec7f668249b6513c938b8c2e95af4 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Thu, 4 Jun 2026 10:00:02 +0200 +Subject: [PATCH] eap-aka: Only accept AKA-Synchronization-Failure if expected + +This fixes a NULL-pointer dereference if the client sends such an error +before the server issued a challenge and allocated this->rand. + +Fixes: 26e246769224 ("ported EAP-AKA branch into trunk") +Fixes: 4735965fc048 ("EAP servers check if the received EAP message was expected") +Fixes: CVE-2026-78126 + +CVE: CVE-2026-78126 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/7bedb451346261370256d390a8c155b86e4b455d] + +Signed-off-by: Ankur Tyagi +--- + src/libcharon/plugins/eap_aka/eap_aka_server.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/libcharon/plugins/eap_aka/eap_aka_server.c b/src/libcharon/plugins/eap_aka/eap_aka_server.c +index 0712ccc..95d4b03 100644 +--- a/src/libcharon/plugins/eap_aka/eap_aka_server.c ++++ b/src/libcharon/plugins/eap_aka/eap_aka_server.c +@@ -505,6 +505,12 @@ static status_t process_synchronize(private_eap_aka_server_t *this, + simaka_attribute_t type; + chunk_t data, auts = chunk_empty; + ++ if (this->pending != AKA_CHALLENGE) ++ { ++ DBG1(DBG_IKE, "received %N, but not expected", ++ simaka_subtype_names, AKA_SYNCHRONIZATION_FAILURE); ++ return FAILED; ++ } + if (this->synchronized) + { + DBG1(DBG_IKE, "received %N, but peer did already resynchronize", diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index e7a5370f03..82dbd3367c 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -12,6 +12,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-47895.patch \ file://CVE-2026-78123.patch \ file://CVE-2026-78124.patch \ + file://CVE-2026-78126.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:32:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99120 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4FF00C98304 for ; Thu, 24 Sep 2026 04:33:42 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.728.1790224418577209366 for ; Wed, 23 Sep 2026 21:33:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=FHJyYJl/; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc1cea4ae2dso749657a12.3 for ; Wed, 23 Sep 2026 21:33:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224418; x=1790829218; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KuAzQ3+RWfDXmSNzIjK5ByVvA5oNALsqD66ou7Sr9Yc=; b=FHJyYJl/hxf+rZTpEV3JMaNr9XXTQmDoyOGDTK7XGaaZYZr42lbqapEsrgSIadepCK /wk1LHKTk5YTCvrbHig0AdiB2TwOHKVgh/bCDnjO7SGxaz45H/FoYW7B5AZ/VhpDEnXO eQJowAF3ontHSw+leTJzs7kr0/6IfmNF/vrJp7yTxt5NrTak6zXGhh/uwUw4zx4GlcFd ETP/ucn51rX7/cite1DE8PhRDnjluaH4pMIvNWFSSegYpaMJzuzBRRSrYvFwjXqcirRP +y2XYWTVKM+klUMHtZ/4c4Qh0ydjgzPKyidhx3S6q0an7vb0Mj2YwneabiPUHB9Z+Doi kV0w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224418; x=1790829218; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KuAzQ3+RWfDXmSNzIjK5ByVvA5oNALsqD66ou7Sr9Yc=; b=hZ2gPVXpAaa2AbTgoMCXMk3yT44xuMqanT3DVcdbXC8FU/D3eKUzeJq68cH3fozztE CQUnJfbxtEYaki3PCk2M8RfBLdpPeQQ7zA39m5aFrc9VAlMvG8RsrF6cgbnEPgGzpQIr xDJOKG26x3pXTz/crOKsPe0WkGnCe/Tjbw+j3Rl4nAZKWgCIxEX+nX6Ez3bnTAe1sYZ2 joFcM7bUhrzlVR/Q1zKdafm/zlC/Z+CCwLBUQJxR7JN8r4Gxd6/7QpUuULrpm5tUa1bc oligH7VbD/zLAq4jDQF6PPdyoA+6DsBVXqKHH2564uZrz1BsESMlKgG2xASbbNgb2wpZ jlsg== X-Gm-Message-State: AFuF++ng4FcHYRREJ8nSmyeh427QruXk2kxbbRkWinRI31FzlJEBoPwD /PnQyCtqnQiEhxjvrJHQQP/0//ZLAiajZV5N0aq0vNfy8c3G3m2cYap4OF/mIA== X-Gm-Gg: AYBFou2VfQ8PiuXhcTAKNJ3n0e+CSzbvdgxA4+nY/88Zop6NNnFgw5HEO1IdaACMuJI twDS3XMz0zkFX3qdWhK1A4I+XA3kTtiFZtMgVKafPWHRhmmzr0VOvU3lSGhymyd/BYoDzH0xwln A1d++UJSU31XZp1iHxANCMXNnKDGjT9fUxAHvWS4SJjQXYy4NGb8eLPo/JoOHPPCgh+fwlgEd7k tajmGKWgEXFKjPKG0MwodHMb6eZfvtxKfUDSl37DJWn23xqHXm0R9bINBht9SH3k6LTSVMwN6Rb jIxgttdfIvhJOZOibjgBI0YhuYRLrJOCprqei0NCN6gi6MkGKddfkHgADwEjTxXGjNJM9Ks1UWc MWqfzmn2trL81ku8VrOdVgcWa/9eSBksiWEFFE6iDQDyeVwNLLdU79u8EZ8S9RAU5cZZjbN5AeT 1dd9P239sgaCaLWwISfxAC2qYYzqbwhJwAjrkJZq9LiSXXGMNv6lD+bNjSKopVA2SoSccPGKMmh w+cv4kmZ37x29feQ8aO+bXfVNiKfIANGA== X-Received: by 2002:a05:6a21:6e86:b0:3c3:b57b:627d with SMTP id adf61e73a8af0-3de0e708e51mr1206497637.12.1790224417768; Wed, 23 Sep 2026 21:33:37 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:37 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 8/24] strongswan: patch CVE-2026-78127 Date: Thu, 24 Sep 2026 16:32:58 +1200 Message-ID: <20260924043315.1663186-8-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130256 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78127 [1]https://download.strongswan.org/security/CVE-2026-78127/strongswan-5.3.1-6.0.7_message_log_leak.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78127.patch | 115 ++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 116 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78127.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78127.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78127.patch new file mode 100644 index 0000000000..4f1358e59b --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78127.patch @@ -0,0 +1,115 @@ +From b38d55b7df137e599c0364a8f0e6d3e1ab84ed50 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 8 Jun 2026 09:19:42 +0200 +Subject: [PATCH] message: Avoid memory leak if string buffer for message is + too small + +This leaked 40 or 80 bytes per parsed message for the enumerators that +were not destroyed. While triggering an OOM condition will require quite +a lot of messages and the DoS protection also helps avoiding that this +is triggered quickly, it all depends on the memory constraints of the +system and the time available to the attacker. Also, if IKEv1 is allowed, +it could get quicker as the lack of message IDs doesn't allow dismissing +unexpected messages before parsing them. + +Fixes: 092958c89d52 ("fixed payload debug message") +Fixes: 6a4a47511f75 ("Show contents of the CP payload in message_t stringification") +Fixes: CVE-2026-78127 + +CVE: CVE-2026-78127 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/4b7108ac0f84fbf40da2b510eb6333afa2a54240] + +Signed-off-by: Ankur Tyagi +--- + src/libcharon/encoding/message.c | 23 ++++++++++++----------- + 1 file changed, 12 insertions(+), 11 deletions(-) + +diff --git a/src/libcharon/encoding/message.c b/src/libcharon/encoding/message.c +index 8da9a1d..a4bf9cb 100644 +--- a/src/libcharon/encoding/message.c ++++ b/src/libcharon/encoding/message.c +@@ -1398,7 +1398,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + payload->get_type(payload)); + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1424,7 +1424,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + } + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1454,7 +1454,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + eap->get_code(eap), method); + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1495,7 +1495,8 @@ static char* get_string(private_message_t *this, char *buf, int len) + attribute->get_type(attribute)); + if (written >= len || written < 0) + { +- return buf; ++ attributes->destroy(attributes); ++ goto err; + } + pos += written; + len -= written; +@@ -1507,7 +1508,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + written = snprintf(pos, len, ")"); + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1529,7 +1530,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + } + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1544,7 +1545,7 @@ static char* get_string(private_message_t *this, char *buf, int len) + frag->get_total_fragments(frag)); + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; +@@ -1557,16 +1558,16 @@ static char* get_string(private_message_t *this, char *buf, int len) + written = snprintf(pos, len, "(%d)", unknown->get_type(unknown)); + if (written >= len || written < 0) + { +- return buf; ++ goto err; + } + pos += written; + len -= written; + } + } +- enumerator->destroy(enumerator); +- +- /* remove last space */ + snprintf(pos, len, " ]"); ++ ++err: ++ enumerator->destroy(enumerator); + return buf; + } + #endif diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 82dbd3367c..2637c19d1e 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -13,6 +13,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78123.patch \ file://CVE-2026-78124.patch \ file://CVE-2026-78126.patch \ + file://CVE-2026-78127.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:32:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99121 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3D11C982FD for ; Thu, 24 Sep 2026 04:33:42 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.728.1790224420630621001 for ; Wed, 23 Sep 2026 21:33:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=lIPJKk1B; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8692a8568e9so789716b3a.3 for ; Wed, 23 Sep 2026 21:33:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224420; x=1790829220; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+WPhtXwCjvOyBtO0TJ2wBlznFBwJbVfptGad2ehmvos=; b=lIPJKk1Bh4cL+e3E3WtmV7DKcTSR0pno4cy9ApbsknJzgNJ3o+qv9mQPsOkWPX4ThQ q9cWq8byxhj3XxpPJVnG1VjrR9vOyaXWguJyZg/96a+QDB//2Ev/fhCZ5QlhSaf6RNUU x4Idg4LvwShsKL7UZ+DJr5T5V3TZsEpK94TPKG5OooxUaxwI9tUwdDZpSLb5/apSwF/T vCBs0QdXt4LMqt6RgqPrQqqqyRWDooGQ1OfpK87QvhZVydmVOLOMSp65cHVi5I6w05Bh qpEYQnbiMFVNkwJYBlr49HNWrjL4+3UL0wvd5KxX3I1iU7FVsGBSNay1LZhXNbArHHI5 mePA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224420; x=1790829220; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+WPhtXwCjvOyBtO0TJ2wBlznFBwJbVfptGad2ehmvos=; b=0o3Rl1go3nbQFp0WZqX71/7MozQl7Qoh7uLIDOc7F4XuVPtkmCDcamaIQMGLqjfCJE 9Ta5zzssFWgKTzLPKDtRZOyCLEYnJAgiKb0fSpmX08wmVH5/9M18Ax1DnRLK/id3rG93 /QkcsAA+dSSYZx8X7guJIZgoaKvokwnbarW7hDiPDCoo+MhFbNmQURWgfgwI/h/4Umdg swwc0DoHGqpsN3Rfde+gY0uvpEl9x6h5EvxTQgUXYSemq4wV9uZ889cv2+OL9U93v9GS k4sYjjrr6LwUmw94Ynt47nC8bORa5xtbEXkW82uZe5W8UP2j+fF1UFz20iN9qvX2gZak XqJA== X-Gm-Message-State: AFuF++m0kK3pTd3qqdaSLq+d2eNy+FeJ9TGPLEvZizJCYE4emXjiSCCp Pf7eNqYRYgaGgQd8EI7olsSOOt+X4qd4rRfvxGMSMw3Kz7dfGtarrorsaw5sFA== X-Gm-Gg: AYBFou2jgcBPLydgbVc5iU9HMFtun7d68WHDfs+RY9YGUxmYDHgFZF3GcdLf5jWn0zm VUAKAfjBn+1cC9ZUHhuWEaRo3Q+J3v972z1ORgMj8WNvhgMtIldqhTUrXYtDpm5NXf2E0l3mmHf zk2VxVseFOiBpJTAL41JrlA5g3cy1fBqxTi42/+GcJnJOalfU1NImnxHu+M+SHVIzlglWTVIqWD m/YGokYo0y/iuiZgzEMI2cfUbkbXDdwaklMmXwDMZTA8s2FL3wYO9fES2Xd+BSX29ekYCxK9SIf liWdH40RUHszmCuuPRI9QNevlh3Uf+VJg2UTvAXLx+1IA5CBlG/072qMVvSpSBoApXPJ/AGSpix JtiTw+Kz6cu+RDh/BjhH8+BDC3c55k2mstu7NKxBwwrLUbR72uLGhtL7M0grXrkxl/TPaXPXrdZ 84tLQ0gl/at9qZOznrWQ/GEq5pp54WIALMKCy4CmvMk//ozjhcHgcKTZic0QSx01YmrF3MuCQQX C8JSPLPGt7nIzDyuMiZ4Ow= X-Received: by 2002:a05:6a00:6ca2:b0:87d:6df6:103 with SMTP id d2e1a72fcca58-87e9f054f68mr989386b3a.34.1790224419948; Wed, 23 Sep 2026 21:33:39 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:39 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 9/24] strongswan: patch CVE-2026-78129 Date: Thu, 24 Sep 2026 16:32:59 +1200 Message-ID: <20260924043315.1663186-9-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:42 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130257 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78129 [1]https://download.strongswan.org/security/CVE-2026-78129/strongswan-5.6.3-6.0.7_pkcs5_params_dos.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78129.patch | 155 ++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 156 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78129.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78129.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78129.patch new file mode 100644 index 0000000000..2a6167dd62 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78129.patch @@ -0,0 +1,155 @@ +From ec14a504137915cc45080323238c64d348d020eb Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Tue, 23 Jun 2026 11:55:31 +0200 +Subject: [PATCH] pkcs5: Validate parsed parameters to avoid DoS attacks + +With the unbounded iterations, an attacker can craft a PKCS#7 file and +send it during IKEv1 to block the processing thread practically for an +unlimited amount of time. + +As the key length is used for an allocation on the stack, not limiting +it could cause a crash. We validate it after parsing the params, but +since `encryption_algorithm_from_oid()` only returns trusted key lengths +that are lower than the limit, that's fine. + +The unlimited salt length had no direct impact (the maximum is bound by +the accepted message size), but we now limit it as well before cloning. + +Fixes: 4076e3ee9121 ("Extract PKCS#5 handling from pkcs8 plugin to separate helper class") +Fixes: fd1ff46f6143 ("Added support for PKCS#5 v2 schemes when decrypting PKCS#8 files.") +Fixes: cab127cba66c ("Added support for encrypted PKCS#8 files (for some PKCS#5 v1.5 schemes).") +Fixes: CVE-2026-78129 + +CVE: CVE-2026-78129 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/f60a55e36f95e210ab067de295c9f6bacefcdd1a] + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/crypto/pkcs5.c | 65 +++++++++++++++++++++++++++++++- + 1 file changed, 64 insertions(+), 1 deletion(-) + +diff --git a/src/libstrongswan/crypto/pkcs5.c b/src/libstrongswan/crypto/pkcs5.c +index 822656f..e01010b 100644 +--- a/src/libstrongswan/crypto/pkcs5.c ++++ b/src/libstrongswan/crypto/pkcs5.c +@@ -14,6 +14,8 @@ + * for more details. + */ + ++#include ++ + #include "pkcs5.h" + + #include +@@ -22,6 +24,15 @@ + #include + #include + ++/** maximum accepted length for salts in parsed parameters */ ++#define PKCS5_SALT_LEN_MAX 128 ++ ++/** maximum accepted iteration count in parsed parameters */ ++#define PKCS5_ITERATIONS_MAX 1000000 ++ ++/** maximum key length accepted in parsed parameters */ ++#define PKCS5_KEY_LEN_MAX 64 ++ + typedef struct private_pkcs5_t private_pkcs5_t; + + /** +@@ -379,6 +390,41 @@ METHOD(pkcs5_t, decrypt, bool, + keymat, key, iv); + } + ++/** ++ * Make sure the salt has an appropriate length ++ */ ++static bool validate_salt_length(chunk_t salt) ++{ ++ if (salt.len > PKCS5_SALT_LEN_MAX) ++ { ++ DBG1(DBG_ASN, " salt length %zu exceeds maximum of %zu bytes", ++ salt.len, (size_t)PKCS5_SALT_LEN_MAX); ++ return FALSE; ++ } ++ return TRUE; ++} ++ ++/** ++ * Validate that parsed parameters are in an allowed range ++ */ ++static bool validate_params(private_pkcs5_t *this) ++{ ++ if (!this->iterations || this->iterations > PKCS5_ITERATIONS_MAX) ++ { ++ DBG1(DBG_ASN, " iteration count %" PRIu64 " is out of range " ++ "(1-%" PRIu64 ")", this->iterations, ++ (uint64_t)PKCS5_ITERATIONS_MAX); ++ return FALSE; ++ } ++ if (this->keylen > PKCS5_KEY_LEN_MAX) ++ { ++ DBG1(DBG_ASN, " key length %zu exceeds maximum of %zu bytes", ++ this->keylen, (size_t)PKCS5_KEY_LEN_MAX); ++ return FALSE; ++ } ++ return TRUE; ++} ++ + /** + * ASN.1 definition of a PBEParameter structure + */ +@@ -399,7 +445,7 @@ static bool parse_pbes1_params(private_pkcs5_t *this, chunk_t blob, int level0) + asn1_parser_t *parser; + chunk_t object; + int objectID; +- bool success; ++ bool success = FALSE; + + parser = asn1_parser_create(pbeParameterObjects, blob); + parser->set_top_level(parser, level0); +@@ -410,6 +456,10 @@ static bool parse_pbes1_params(private_pkcs5_t *this, chunk_t blob, int level0) + { + case PBEPARAM_SALT: + { ++ if (!validate_salt_length(object)) ++ { ++ goto end; ++ } + this->salt = chunk_clone(object); + break; + } +@@ -421,6 +471,11 @@ static bool parse_pbes1_params(private_pkcs5_t *this, chunk_t blob, int level0) + } + } + success = parser->success(parser); ++ if (success) ++ { ++ success = validate_params(this); ++ } ++end: + parser->destroy(parser); + return success; + } +@@ -471,6 +526,10 @@ static bool parse_pbkdf2_params(private_pkcs5_t *this, chunk_t blob, int level0) + { + case PBKDF2_SALT: + { ++ if (!validate_salt_length(object)) ++ { ++ goto end; ++ } + this->salt = chunk_clone(object); + break; + } +@@ -500,6 +559,10 @@ static bool parse_pbkdf2_params(private_pkcs5_t *this, chunk_t blob, int level0) + } + } + success = parser->success(parser); ++ if (success) ++ { ++ success = validate_params(this); ++ } + end: + parser->destroy(parser); + return success; diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 2637c19d1e..c8f956f4d8 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -14,6 +14,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78124.patch \ file://CVE-2026-78126.patch \ file://CVE-2026-78127.patch \ + file://CVE-2026-78129.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99128 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2DB9EC98315 for ; Thu, 24 Sep 2026 04:33:54 +0000 (UTC) Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.729.1790224423112949073 for ; Wed, 23 Sep 2026 21:33:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=JAjh6LbL; spf=pass (domain: gmail.com, ip: 74.125.228.40, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f40.google.com with SMTP id d2e1a72fcca58-87c90648f99so1232715b3a.0 for ; Wed, 23 Sep 2026 21:33:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224422; x=1790829222; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zHj0SzjhMC98zZ2sROPCKCwIoaZl3IH+evmbZ5KGJCo=; b=JAjh6LbL/YXEHadf57KhqTCN+Sjg2Hq+/F5yMITseAVtpDrHtsTJX5v3AQjDyrDhsT 7AEPttVZGBfHpq1YIN2ZcnCDmnx9mHo+EmvUimaQ3zccP0V7rmcsc/tZI9tGizwVD8Ne uF8fTLdDDq/Nb72XPxXbyDfym4uuqfD7kS1RqM98wqndHT3MerGgiXSYbu9m9EsiU4xo unHoffziUdnOgY9H+Y1lD7Zjb+6/9EuLH5QVf/y4/hfkJLhobZDd4es+mIyqPmpwZhBZ 8Y7PdRzbJa5vpQO5Bjty4xG6gd28eK8fePFuBvk+BpDRpMexhF1uXT4Ew0yLPVq7fsJs 285Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224422; x=1790829222; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zHj0SzjhMC98zZ2sROPCKCwIoaZl3IH+evmbZ5KGJCo=; b=XMwzGNFLp42Vt5Z/vetOwtH9qhRiKC/qpEDu9t4oHUxMJ+ANBLFpAx/CqxooJVhTPF tzNfnMnRilgPd+rZ5zCA8u66ZV0JhmTf7k2dZFj0td8lUqeGg6c08kjwocBqFkZEdzbX 3ksemRxT7hNTT7rX3TLjMrmTTdl1RopK1S7ouZ90h6KRg66hgQSl+OiJDcwCm/OqwDF2 /YXsWPRqQBeDjwJolpZ9EkMiJMMZsOr0WRIKq2aIl9CSREExdwp9Fyflx4XZhCgv3lvc +Sw3rMW6Sq+0PsFNYJJOJgsCbOu+ZYe2Fx6Ymn1wc+BshHSaDba2wUKgAIbR6Q194dhy Rcww== X-Gm-Message-State: AFuF++maAF8VCMYCg4bvQ3QvSwPdTTOYDuA2E40TuC6AmEjfxB3u13Ud WaddgKMMtG9Ty3thESSYNtmxCwhR/c2g9EohMM9p9Q1tMM1v1pF2SMYppOKMAw== X-Gm-Gg: AYBFou3REhaPS+Ln+ypajaIoQM/4u92XWXOCDsqOtkSQyJwYVRP1tzcOEGn9lLAec5M gXJPyjs2QgwxM/7mWU11K5IMm69o1Ru9OHjubCfZUkb7wOOremVCuIhJXcLNvp1UH9V6NE6fbtE HXKPPw0KiKthjX6S8Voy33nokpMynLu3um59VmAmUd8novsKs33o2itcoxanUXKVFAmTMQDpngU bu4zN+iyaX5AoLmdJwX7mjmBrsn/DrbOOzsW+SXTE309rVklPLxnc4/mOF6u1o0LHnT29RMuki+ RXpvPEQtGBiOHrYb5/gBl3sQuCl9Ty2LEqVOEdfjWrcxBTEiLYEaDbsd2GbHU+gT8c9/pvceIGX pk3Y9yQLe368NG8FthpSCPXPXeXMGFvmepbs6bLROtBwovqZRdi5Ky5R1HcjeSWJc6zHeZKggMz 3hH1oN4FdTLlBq2dj1Uj8xigbgkZQdZX3NQxMYWU8UndiuFvUIAyssnaSrXytjWyISZ3XmcHSVH C4+IpIFb8Dzf/AheoDCcF0= X-Received: by 2002:a05:6a00:a253:b0:878:34d7:6a39 with SMTP id d2e1a72fcca58-87e9ef5414amr929270b3a.45.1790224422238; Wed, 23 Sep 2026 21:33:42 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:41 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 10/24] strongswan: patch CVE-2026-78133 Date: Thu, 24 Sep 2026 16:33:00 +1200 Message-ID: <20260924043315.1663186-10-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130258 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78133 [1]https://download.strongswan.org/security/CVE-2026-78133/strongswan-6.0.0-6.0.7_ikev2_rekey_collision.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78133.patch | 620 ++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 621 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78133.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78133.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78133.patch new file mode 100644 index 0000000000..126f818023 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78133.patch @@ -0,0 +1,620 @@ +From 3f5768c48bc9dff62511c91157e0a9bd12b2159b Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Fri, 5 Jun 2026 08:15:46 +0200 +Subject: [PATCH] ikev2: Prevent use-after-free during collision after passive + multi-KE rekeying failed + +During a multi-KE rekey collision, where the initial response to the +active rekeying is delayed (or withheld), the active task already keeps +track of the passive task to eventually resolve the collision (it can +only do so once all nonces are known). + +If the passive task then fails, e.g. due to a missing or invalid KE +payload, and completes with SUCCESS, `collide()` previously recognized +that the passive task is not yet complete returned FALSE, which caused +the task manager to destroy the task. However, the reference in the +active task would remain. So once the active rekeying progresses and +the collision is resolved, that dangling pointer would get dereferenced +for an indirect method call. This happens via the `get_lower_nonce` +function pointer of the `child_create_t` instance in the private task +struct. So besides having to be authenticated, an attacker has to get +two indirections right to exploit this flaw for a potential RCE. +Otherwise, the effects are a crash or basically undefined behavior +triggered by the method call. + +By passing whether the passive task is done (and would get destroyed), +the active tasks can properly clear the held reference. + +Note that this patch includes another fix for a state change during +Child SA rekeying that's included in 6.1.0 (4611f41b1e14 ("child-rekey: +Only reset state of SAs not actively rekeyed if passive rekeying +fails")). + +Fixes: d2b2e1b3fae8 ("ikev2: Make CHILD_SAs properly trackable during rekey collisions") +Fixes: ca3e6d2d144e ("ike-rekey: Support IKE_SA rekeying with multiple key exchanges") +Fixes: CVE-2026-78133 + +CVE: CVE-2026-78133 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/eb615b452539461d57503f50041f01773c1ccf86] + +Signed-off-by: Ankur Tyagi +--- + src/libcharon/sa/ikev2/task_manager_v2.c | 13 +- + src/libcharon/sa/ikev2/tasks/child_rekey.c | 47 ++++-- + src/libcharon/sa/ikev2/tasks/child_rekey.h | 3 +- + src/libcharon/sa/ikev2/tasks/ike_rekey.c | 40 +++-- + src/libcharon/sa/ikev2/tasks/ike_rekey.h | 3 +- + src/libcharon/tests/suites/test_child_rekey.c | 136 ++++++++++++++++ + src/libcharon/tests/suites/test_ike_rekey.c | 147 ++++++++++++++++++ + 7 files changed, 361 insertions(+), 28 deletions(-) + +diff --git a/src/libcharon/sa/ikev2/task_manager_v2.c b/src/libcharon/sa/ikev2/task_manager_v2.c +index 0f3b937..5a19ce8 100644 +--- a/src/libcharon/sa/ikev2/task_manager_v2.c ++++ b/src/libcharon/sa/ikev2/task_manager_v2.c +@@ -927,7 +927,8 @@ static status_t process_response(private_task_manager_t *this, + * Handle exchange collisions, returns TRUE if the given passive task was + * adopted by the active task and the task manager lost control over it. + */ +-static bool handle_collisions(private_task_manager_t *this, task_t *task) ++static bool handle_collisions(private_task_manager_t *this, task_t *task, ++ bool done) + { + enumerator_t *enumerator; + task_t *active; +@@ -951,7 +952,7 @@ static bool handle_collisions(private_task_manager_t *this, task_t *task) + if (type == TASK_IKE_REKEY || type == TASK_IKE_DELETE) + { + ike_rekey_t *rekey = (ike_rekey_t*)active; +- adopted = rekey->collide(rekey, task); ++ adopted = rekey->collide(rekey, task, done); + break; + } + continue; +@@ -959,7 +960,7 @@ static bool handle_collisions(private_task_manager_t *this, task_t *task) + if (type == TASK_CHILD_REKEY) + { + child_rekey_t *rekey = (child_rekey_t*)active; +- adopted = rekey->collide(rekey, task); ++ adopted = rekey->collide(rekey, task, done); + break; + } + continue; +@@ -1011,14 +1012,14 @@ static status_t build_response(private_task_manager_t *this, message_t *request) + case SUCCESS: + /* task completed, remove it */ + array_remove_at(this->passive_tasks, enumerator); +- if (!handle_collisions(this, task)) ++ if (!handle_collisions(this, task, TRUE)) + { + task->destroy(task); + } + break; + case NEED_MORE: + /* processed, but task needs another exchange */ +- if (handle_collisions(this, task)) ++ if (handle_collisions(this, task, FALSE)) + { + array_remove_at(this->passive_tasks, enumerator); + } +@@ -1029,7 +1030,7 @@ static status_t build_response(private_task_manager_t *this, message_t *request) + /* FALL */ + case DESTROY_ME: + /* destroy IKE_SA, but SEND response first */ +- if (handle_collisions(this, task)) ++ if (handle_collisions(this, task, FALSE)) + { + array_remove_at(this->passive_tasks, enumerator); + } +diff --git a/src/libcharon/sa/ikev2/tasks/child_rekey.c b/src/libcharon/sa/ikev2/tasks/child_rekey.c +index fb3ba2a..e984668 100644 +--- a/src/libcharon/sa/ikev2/tasks/child_rekey.c ++++ b/src/libcharon/sa/ikev2/tasks/child_rekey.c +@@ -403,7 +403,7 @@ METHOD(task_t, build_r, status_t, + child_sa_t *child_sa, *old_replacement; + child_sa_state_t state = CHILD_INSTALLED; + uint32_t reqid; +- bool followup_sent = FALSE; ++ bool active, followup_sent = FALSE; + + if (!this->child_sa) + { +@@ -423,7 +423,8 @@ METHOD(task_t, build_r, status_t, + message->add_notify(message, TRUE, TEMPORARY_FAILURE, chunk_empty); + return SUCCESS; + } +- if (actively_rekeying(this, &followup_sent) && followup_sent) ++ active = actively_rekeying(this, &followup_sent); ++ if (active && followup_sent) + { + DBG1(DBG_IKE, "peer initiated rekeying, but we did too and already " + "sent IKE_FOLLOWUP_KE"); +@@ -483,8 +484,9 @@ METHOD(task_t, build_r, status_t, + /* like installing the outbound SA, we only trigger the child-rekey + * event once the old SA is deleted */ + } +- else if (this->child_sa->get_state(this->child_sa) == CHILD_REKEYING) +- { /* rekeying failed, reuse old child */ ++ else if (!active && ++ this->child_sa->get_state(this->child_sa) == CHILD_REKEYING) ++ { /* rekeying failed, reuse old child, unless we are actively rekeying */ + this->child_sa->set_state(this->child_sa, state); + } + return SUCCESS; +@@ -1127,8 +1129,22 @@ METHOD(child_rekey_t, handle_delete, child_rekey_collision_t, + return CHILD_REKEY_COLLISION_NONE; + } + ++/** ++ * Clear the colliding passive task if it did not complete successfully. ++ */ ++static void clear_collision(private_child_rekey_t *this, task_t *other) ++{ ++ if (this->collision == other) ++ { ++ DBG1(DBG_IKE, "colliding passive rekeying for CHILD_SA %s{%u} " ++ "failed", this->child_sa->get_name(this->child_sa), ++ this->child_sa->get_unique_id(this->child_sa)); ++ this->collision = NULL; ++ } ++} ++ + METHOD(child_rekey_t, collide, bool, +- private_child_rekey_t *this, task_t *other) ++ private_child_rekey_t *this, task_t *other, bool done) + { + private_child_rekey_t *rekey = (private_child_rekey_t*)other; + child_sa_t *other_child; +@@ -1142,16 +1158,25 @@ METHOD(child_rekey_t, collide, bool, + other_child = rekey->child_create->get_child(rekey->child_create); + if (!other_child) + { +- /* ignore passive tasks that did not successfully create a CHILD_SA */ ++ /* ignore passive tasks that did not successfully create a CHILD_SA, ++ * if we are already tracking it in the multi-KE case, clear it */ ++ clear_collision(this, other); + return FALSE; + } + if (other_child->get_state(other_child) != CHILD_INSTALLED) + { +- DBG1(DBG_IKE, "colliding passive rekeying for CHILD_SA %s{%u} is not " +- "yet complete", this->child_sa->get_name(this->child_sa), +- this->child_sa->get_unique_id(this->child_sa)); +- /* we do reference the task to check its state later */ +- this->collision = other; ++ if (done) ++ { /* passive task failed, clear it if necessary */ ++ clear_collision(this, other); ++ } ++ else ++ { ++ DBG1(DBG_IKE, "colliding passive rekeying for CHILD_SA %s{%u} is " ++ "not yet complete", this->child_sa->get_name(this->child_sa), ++ this->child_sa->get_unique_id(this->child_sa)); ++ /* we do reference the task to check its state later */ ++ this->collision = other; ++ } + return FALSE; + } + if (this->collision && this->collision != other) +diff --git a/src/libcharon/sa/ikev2/tasks/child_rekey.h b/src/libcharon/sa/ikev2/tasks/child_rekey.h +index a8daed7..fef0bba 100644 +--- a/src/libcharon/sa/ikev2/tasks/child_rekey.h ++++ b/src/libcharon/sa/ikev2/tasks/child_rekey.h +@@ -79,10 +79,11 @@ struct child_rekey_t { + * are going on and notifies the active task by passing the passive. + * + * @param other passive task ++ * @param done passive task is done and gets destroyed if not adopted + * @return whether the task was adopted and should be removed from + * the task manager's control + */ +- bool (*collide)(child_rekey_t* this, task_t *other); ++ bool (*collide)(child_rekey_t* this, task_t *other, bool done); + }; + + /** +diff --git a/src/libcharon/sa/ikev2/tasks/ike_rekey.c b/src/libcharon/sa/ikev2/tasks/ike_rekey.c +index c7e8ffb..f275d2d 100644 +--- a/src/libcharon/sa/ikev2/tasks/ike_rekey.c ++++ b/src/libcharon/sa/ikev2/tasks/ike_rekey.c +@@ -743,8 +743,23 @@ METHOD(ike_rekey_t, did_collide, bool, + return this->collision != NULL; + } + ++/** ++ * Clear the colliding passive task if it did not complete successfully. ++ */ ++static bool clear_collision(private_ike_rekey_t *this, ++ private_ike_rekey_t *other) ++{ ++ if (this->collision == other) ++ { ++ DBG1(DBG_IKE, "colliding passive rekeying failed, ignore"); ++ this->collision = NULL; ++ return TRUE; ++ } ++ return FALSE; ++} ++ + METHOD(ike_rekey_t, collide, bool, +- private_ike_rekey_t* this, task_t *other) ++ private_ike_rekey_t* this, task_t *other, bool done) + { + DBG1(DBG_IKE, "detected %N collision with %N", task_type_names, + TASK_IKE_REKEY, task_type_names, other->get_type(other)); +@@ -760,23 +775,30 @@ METHOD(ike_rekey_t, collide, bool, + + if (!rekey->ike_init) + { +- DBG1(DBG_IKE, "colliding exchange did not result in an IKE_SA, " +- "ignore"); +- if (this->collision == rekey) ++ if (!clear_collision(this, rekey)) + { +- this->collision = NULL; ++ DBG1(DBG_IKE, "colliding exchange did not result in an " ++ "IKE_SA, ignore"); + } + break; + } +- /* we keep track of the passive exchange in any case, if not +- * complete yet, this method might be called again later */ +- this->collision = rekey; ++ /* we keep track of the passive exchange, if not complete yet, this ++ * method might be called again later */ + if (rekey->flags & IKE_REKEY_DONE) + { ++ this->collision = rekey; + this->flags |= IKE_REKEY_ADOPTED_PASSIVE; + return TRUE; + } +- DBG1(DBG_IKE, "colliding passive exchange is not yet complete"); ++ else if (done) ++ { /* passive task failed, clear it if necessary */ ++ clear_collision(this, rekey); ++ } ++ else ++ { ++ DBG1(DBG_IKE, "colliding passive exchange is not yet complete"); ++ this->collision = rekey; ++ } + break; + } + default: +diff --git a/src/libcharon/sa/ikev2/tasks/ike_rekey.h b/src/libcharon/sa/ikev2/tasks/ike_rekey.h +index 5fab349..e68fa62 100644 +--- a/src/libcharon/sa/ikev2/tasks/ike_rekey.h ++++ b/src/libcharon/sa/ikev2/tasks/ike_rekey.h +@@ -54,10 +54,11 @@ struct ike_rekey_t { + * are going on and notifies the active task by passing the passive. + * + * @param other passive task ++ * @param done passive task is done and gets destroyed if not adopted + * @return whether the task was adopted and should be removed from + * the task manager's control + */ +- bool (*collide)(ike_rekey_t* this, task_t *other); ++ bool (*collide)(ike_rekey_t* this, task_t *other, bool done); + }; + + /** +diff --git a/src/libcharon/tests/suites/test_child_rekey.c b/src/libcharon/tests/suites/test_child_rekey.c +index 1c81e75..4ef081a 100644 +--- a/src/libcharon/tests/suites/test_child_rekey.c ++++ b/src/libcharon/tests/suites/test_child_rekey.c +@@ -2546,6 +2546,141 @@ START_TEST(test_collision_delayed_response_multi_ke) + } + END_TEST + ++/** ++ * Remove the KE payload from the IKE_FOLLOWUP_KE request ++ */ ++static bool remove_ke(listener_t *listener, ike_sa_t *ike_sa, ++ message_t *message, bool incoming, bool plain) ++{ ++ if (plain && incoming && ++ message->get_exchange_type(message) == IKE_FOLLOWUP_KE && ++ message->get_request(message)) ++ { ++ enumerator_t *enumerator = message->create_payload_enumerator(message); ++ payload_t *pld; ++ ++ while (enumerator->enumerate(enumerator, &pld)) ++ { ++ if (pld->get_type(pld) == PLV2_KEY_EXCHANGE) ++ { ++ message->remove_payload_at(message, enumerator); ++ pld->destroy(pld); ++ break; ++ } ++ } ++ enumerator->destroy(enumerator); ++ free(listener); ++ return FALSE; ++ } ++ return TRUE; ++} ++ ++#define remove_ke_from_ike_followup_ke() ({ \ ++ listener_t *_ke_listener; \ ++ INIT(_ke_listener, \ ++ .message = remove_ke, \ ++ ); \ ++ exchange_test_helper->add_listener(exchange_test_helper, _ke_listener); \ ++}) ++ ++/** ++ * This simulates an incorrect behavior by the peer. It triggers a collision by ++ * not responding to the initial CREATE_CHILD_SA and then sends an invalid ++ * IKE_FOLLOWUP_KE (in this case the KE payload is missing). The initiator ++ * has to correctly track and then untrack the passive rekey task. ++ * ++ * Peer A Peer B ++ * rekey ----\ /---- rekey ++ * \-----/----> detect collision and withhold response ++ * detect collision <---------/ ++ * ----------------> ++ * handle failure <---------------- send invalid additional KE ++ * handle rekey <---------------- send withheld response ++ */ ++START_TEST(test_collision_delayed_response_multi_ke_failure) ++{ ++ ike_sa_t *a, *b; ++ message_t *msg; ++ ++ assert_track_sas_start(); ++ ++ exchange_test_helper->establish_sa(exchange_test_helper, ++ &a, &b, &multi_ke_conf); ++ ++ /* make sure the responder wins the collision so it continues */ ++ exchange_test_helper->nonce_first_byte = 0x00; ++ initiate_rekey(a, 1); ++ assert_ipsec_sas_installed(a, 1, 2); ++ exchange_test_helper->nonce_first_byte = 0xff; ++ initiate_rekey(b, 2); ++ assert_ipsec_sas_installed(b, 1, 2); ++ ++ /* these should not get called as no SA goes down or gets rekeyed */ ++ assert_hook_not_called(child_updown); ++ assert_hook_not_called(child_rekey); ++ ++ /* CREATE_CHILD_SA { N(REKEY_SA), SA, Ni, [KEi,] TSi, TSr } --> */ ++ exchange_test_helper->nonce_first_byte = 0xff; ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ assert_child_sa_state(b, 2, CHILD_REKEYING, CHILD_OUTBOUND_INSTALLED); ++ assert_ipsec_sas_installed(b, 1, 2); ++ ++ /* <-- CREATE_CHILD_SA { N(REKEY_SA), SA, Ni, [KEi,] TSi, TSr } */ ++ exchange_test_helper->nonce_first_byte = 0xff; ++ exchange_test_helper->process_message(exchange_test_helper, a, NULL); ++ assert_child_sa_state(a, 1, CHILD_REKEYING, CHILD_OUTBOUND_INSTALLED); ++ assert_ipsec_sas_installed(a, 1, 2); ++ ++ /* the responder is not responding */ ++ msg = exchange_test_helper->sender->dequeue(exchange_test_helper->sender); ++ ++ /* CREATE_CHILD_SA { SA, Nr, [KEr,] TSi, TSr } --> */ ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ assert_num_tasks(b, 0, TASK_QUEUE_PASSIVE); ++ assert_num_tasks(b, 1, TASK_QUEUE_ACTIVE); ++ assert_child_sa_state(b, 2, CHILD_REKEYING, CHILD_OUTBOUND_INSTALLED); ++ assert_ipsec_sas_installed(b, 1, 2); ++ ++ /* remove the KE payload in the IKE_FOLLOWUP_KE request */ ++ remove_ke_from_ike_followup_ke(); ++ ++ /* <-- IKE_FOLLOWUP_KE { N(ADD_KE) } */ ++ assert_no_payload(IN, PLV2_KEY_EXCHANGE); ++ assert_single_notify(OUT, INVALID_SYNTAX); ++ exchange_test_helper->process_message(exchange_test_helper, a, NULL); ++ assert_child_sa_state(a, 1, CHILD_REKEYING, CHILD_OUTBOUND_INSTALLED); ++ assert_ipsec_sas_installed(a, 1, 2); ++ assert_num_tasks(a, 0, TASK_QUEUE_PASSIVE); ++ ++ /* <-- CREATE_CHILD_SA { SA, Nr, [KEr,] TSi, TSr } (delayed) */ ++ exchange_test_helper->process_message(exchange_test_helper, a, msg); ++ assert_num_tasks(a, 0, TASK_QUEUE_PASSIVE); ++ assert_num_tasks(a, 1, TASK_QUEUE_ACTIVE); ++ assert_child_sa_state(a, 1, CHILD_REKEYING, CHILD_OUTBOUND_INSTALLED); ++ assert_ipsec_sas_installed(a, 1, 2); ++ ++ /* drop the STATE_NOT_FOUND error message from the initiator */ ++ msg = exchange_test_helper->sender->dequeue(exchange_test_helper->sender); ++ msg->destroy(msg); ++ ++ /* since we explicitly forced the responder to win, it already removed ++ * the passive task it won't accept the request */ ++ ++ /* IKE_FOLLOWUP_KE { KEi, N(ADD_KE) } --> */ ++ assert_payload(IN, PLV2_KEY_EXCHANGE); ++ assert_notify(IN, ADDITIONAL_KEY_EXCHANGE); ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ ++ /* child_rekey/child_updown */ ++ assert_hook(); ++ assert_hook(); ++ assert_track_sas(2, 2); ++ ++ call_ikesa(a, destroy); ++ call_ikesa(b, destroy); ++} ++END_TEST ++ + /** + * In this scenario one of the peers does not notice that there is a + * rekey collision: +@@ -4436,6 +4571,7 @@ Suite *child_rekey_suite_create() + tcase_add_loop_test(tc, test_collision_delayed_response, 0, 4); + tcase_add_loop_test(tc, test_collision_delayed_response_delete, 0, 4); + tcase_add_loop_test(tc, test_collision_delayed_response_multi_ke, 0, 4); ++ tcase_add_test(tc, test_collision_delayed_response_multi_ke_failure); + tcase_add_loop_test(tc, test_collision_delayed_request, 0, 6); + tcase_add_loop_test(tc, test_collision_delayed_request_more, 0, 3); + tcase_add_loop_test(tc, test_collision_delayed_request_more_delete, 0, 3); +diff --git a/src/libcharon/tests/suites/test_ike_rekey.c b/src/libcharon/tests/suites/test_ike_rekey.c +index c6691ac..2c41022 100644 +--- a/src/libcharon/tests/suites/test_ike_rekey.c ++++ b/src/libcharon/tests/suites/test_ike_rekey.c +@@ -1784,6 +1784,152 @@ START_TEST(test_collision_delayed_response_multi_ke) + } + END_TEST + ++/** ++ * Remove the ADDITIONAL_KEY_EXCHANGE notify payload from the IKE_FOLLOWUP_KE ++ * request ++ */ ++static bool remove_notify(listener_t *listener, ike_sa_t *ike_sa, ++ message_t *message, bool incoming, bool plain) ++{ ++ if (plain && incoming && ++ message->get_exchange_type(message) == IKE_FOLLOWUP_KE && ++ message->get_request(message)) ++ { ++ enumerator_t *enumerator = message->create_payload_enumerator(message); ++ payload_t *pld; ++ ++ while (enumerator->enumerate(enumerator, &pld)) ++ { /* we only expect one notify, so just remove the first */ ++ if (pld->get_type(pld) == PLV2_NOTIFY) ++ { ++ message->remove_payload_at(message, enumerator); ++ pld->destroy(pld); ++ break; ++ } ++ } ++ enumerator->destroy(enumerator); ++ free(listener); ++ return FALSE; ++ } ++ return TRUE; ++} ++ ++#define remove_notify_from_ike_followup_ke() ({ \ ++ listener_t *_ke_listener; \ ++ INIT(_ke_listener, \ ++ .message = remove_notify, \ ++ ); \ ++ exchange_test_helper->add_listener(exchange_test_helper, _ke_listener); \ ++}) ++ ++/** ++ * This simulates an incorrect behavior by the peer. It triggers a collision by ++ * not responding to the initial CREATE_CHILD_SA and then sends an invalid ++ * IKE_FOLLOWUP_KE (in this case by removing the ADDITIONAL_KEY_EXCHANGE ++ * notify). The initiator has to correctly track and then untrack the passive ++ * rekey task. ++ * ++ * Peer A Peer B ++ * rekey ----\ /---- rekey ++ * \-----/----> detect collision and withhold response ++ * detect collision <---------/ ++ * ----------------> ++ * handle failure <---------------- send invalid additional KE ++ * handle rekey <---------------- send withheld response ++ */ ++START_TEST(test_collision_delayed_response_multi_ke_failure) ++{ ++ ike_sa_t *a, *b; ++ message_t *msg; ++ ++ assert_track_sas_start(); ++ ++ exchange_test_helper->establish_sa(exchange_test_helper, ++ &a, &b, &multi_ke_conf); ++ ++ /* these should not get called as no SA goes down or gets rekeyed */ ++ assert_hook_not_called(ike_updown); ++ assert_hook_not_called(ike_rekey); ++ assert_hook_not_called(child_updown); ++ ++ /* make sure the responder wins the collision so it continues */ ++ exchange_test_helper->nonce_first_byte = 0x00; ++ initiate_rekey(a); ++ exchange_test_helper->nonce_first_byte = 0xff; ++ initiate_rekey(b); ++ ++ /* CREATE_CHILD_SA { SA, Ni, KEi } --> */ ++ exchange_test_helper->nonce_first_byte = 0xff; ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ assert_ike_sa_state(b, IKE_REKEYING); ++ assert_child_sa_count(b, 1); ++ assert_ike_sa_count(0); ++ ++ /* <-- CREATE_CHILD_SA { SA, Ni, KEi } */ ++ exchange_test_helper->nonce_first_byte = 0xff; ++ exchange_test_helper->process_message(exchange_test_helper, a, NULL); ++ assert_ike_sa_state(a, IKE_REKEYING); ++ assert_child_sa_count(a, 1); ++ assert_ike_sa_count(0); ++ ++ /* the responder is not responding */ ++ msg = exchange_test_helper->sender->dequeue(exchange_test_helper->sender); ++ ++ /* simplify next steps by checking in original IKE_SAs */ ++ charon->ike_sa_manager->checkin(charon->ike_sa_manager, a); ++ charon->ike_sa_manager->checkin(charon->ike_sa_manager, b); ++ assert_ike_sa_count(2); ++ ++ /* CREATE_CHILD_SA { SA, Nr, KEr, N(ADD_KE) } --> */ ++ assert_notify(IN, ADDITIONAL_KEY_EXCHANGE); ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ assert_num_tasks(b, 0, TASK_QUEUE_PASSIVE); ++ assert_num_tasks(b, 1, TASK_QUEUE_ACTIVE); ++ assert_ike_sa_state(b, IKE_REKEYING); ++ assert_ike_sa_count(2); ++ ++ /* remove the ADD_KE notify from the IKE_FOLLOWUP_KE request */ ++ remove_notify_from_ike_followup_ke(); ++ ++ /* <-- IKE_FOLLOWUP_KE { KEi } */ ++ assert_payload(IN, PLV2_KEY_EXCHANGE); ++ assert_no_notify(IN, ADDITIONAL_KEY_EXCHANGE); ++ assert_single_notify(OUT, STATE_NOT_FOUND); ++ exchange_test_helper->process_message(exchange_test_helper, a, NULL); ++ assert_ike_sa_state(a, IKE_REKEYING); ++ assert_child_sa_count(a, 1); ++ assert_ike_sa_count(2); ++ ++ /* <-- CREATE_CHILD_SA { SA, Nr, KEr } (delayed) */ ++ exchange_test_helper->process_message(exchange_test_helper, a, msg); ++ assert_num_tasks(a, 0, TASK_QUEUE_PASSIVE); ++ assert_num_tasks(a, 1, TASK_QUEUE_ACTIVE); ++ assert_ike_sa_state(a, IKE_REKEYING); ++ assert_child_sa_count(a, 1); ++ assert_ike_sa_count(2); ++ ++ /* drop the STATE_NOT_FOUND error message from the initiator */ ++ msg = exchange_test_helper->sender->dequeue(exchange_test_helper->sender); ++ msg->destroy(msg); ++ ++ /* since we explicitly forced the responder to win, it already removed ++ * the passive task it won't accept the request */ ++ ++ /* IKE_FOLLOWUP_KE { KEi, N(ADD_KE) } --> */ ++ assert_payload(IN, PLV2_KEY_EXCHANGE); ++ assert_notify(IN, ADDITIONAL_KEY_EXCHANGE); ++ exchange_test_helper->process_message(exchange_test_helper, b, NULL); ++ ++ /* ike_updown/rekey/child_updown */ ++ assert_hook(); ++ assert_hook(); ++ assert_hook(); ++ assert_track_sas(2, 2); ++ ++ charon->ike_sa_manager->flush(charon->ike_sa_manager); ++} ++END_TEST ++ + /** + * In this scenario one of the peers does not notice that there is a rekey + * collision because the other request is dropped: +@@ -2590,6 +2736,7 @@ Suite *ike_rekey_suite_create() + tcase_add_loop_test(tc, test_collision_ke_invalid_delayed_retry, 0, 3); + tcase_add_loop_test(tc, test_collision_delayed_response, 0, 4); + tcase_add_loop_test(tc, test_collision_delayed_response_multi_ke, 0, 4); ++ tcase_add_test(tc, test_collision_delayed_response_multi_ke_failure); + tcase_add_loop_test(tc, test_collision_dropped_request, 0, 3); + tcase_add_loop_test(tc, test_collision_delayed_request, 0, 3); + tcase_add_loop_test(tc, test_collision_delayed_request_and_delete, 0, 3); diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index c8f956f4d8..4d13507151 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -15,6 +15,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78126.patch \ file://CVE-2026-78127.patch \ file://CVE-2026-78129.patch \ + file://CVE-2026-78133.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99126 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 220CDC98312 for ; Thu, 24 Sep 2026 04:33:54 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.729.1790224425087365579 for ; Wed, 23 Sep 2026 21:33:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ELjLPzXV; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc1cea4c7a0so924497a12.1 for ; Wed, 23 Sep 2026 21:33:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224424; x=1790829224; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8KosvtCUSJ21fJx86qYZ14SRwmW6A54Sj34r5H5qP8E=; b=ELjLPzXVqbGSiEnYdBEitlhbGwuVhfOYzQu4+3CZ9GHPfGZX3n7oMkA3SLd9Z1okr2 KHtcWIIOhvNtcw2l36I65ud2i/1s4+/hcYh50KEmRt0AEZ887N1ib44wKdAf0dwPVh5Y x/y2PRZ/iJOh73rCkq7WiPrzVmoIByHaoZJ2xrXDWgRMGF+aqJsFI8KYavBRVeUb3m/+ wIVa5SUZ8INx+4g9CtIwZJJxZGL5fCx7m5S7nFvoQ9P9QVAX+Wj0Ucn2r0vdNbTMqVO5 UGqhFquOkzPwBiCodyAlvFN/5Xh/T6Fg19b2WcEsb3xVVH1NZ3fHktzWH5zbf3ZLWXig H9aw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224424; x=1790829224; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8KosvtCUSJ21fJx86qYZ14SRwmW6A54Sj34r5H5qP8E=; b=Uw6w4zKjbbDG+K1rRzlfllJooDXuGzGhXpqrhYUHF8zzNN1uAobXjmYz7215BsV/XV wLqs5ZVuhOXjVzAUmffsAqkIHmy0e4jgvbOERIVsLpUMjU6kjOHFlEzFiq+La7Eak62X xkSZ0ZII5DlMzTSWUyjtG8PIHlJ0dqJcY6BmWxLgu4QvX6j0llIvdxot+JAxRqQmDBBg jTQjKCoX36JQSGnQjVV+k/5mHbVugH9MznFOnksAjLWZeMBF3blWHvHd2JslFQexttcH TOqsQw3eSL8dTQq4Pi0piSlYuaAr9Zaz4IbT6/YJXSZTUcMyCqHuOyjrqFNMafOg7qRJ 9Wxg== X-Gm-Message-State: AFuF++n4sVHEBd6MsD60tDK2hOQzBKWbTt3hEOTojjp/KsjSxJKf8+GQ rpUKprbvhI+fAVVlznY5taCYi66kYPfCq75mi03sENgWdNgTa4YvboGO1mQyIw== X-Gm-Gg: AYBFou0m0/rRAqkPu0rgjCvOm3Ue7yqL8PaRKM1CTfZ5yhGDofunCtV5eJanwpyNPIo uB3q0C+zBWnANaldj7JVjnrlIToXb+mEVdi61sS8NR7ssDIG/LTi6V/qHroC9duoybrHeqg7NW3 LDYtdWXTspjOuCGfKsp5bynlUGaWAip05fiT983MlJwHfzjXKCLLwoH77g7vdUX2qxEcZg4cyPg M0DOYbGptQ3cAqyVMKYnAt65pDB8iuZRIZKYe8fDU0H1bz6JXfZFKR41e7IzrysllqtICjZd1C8 l+P8LnNQW55Jz93LJKuWhZrKVNA/22OLuP1Jhc1GoGDJGLWOCjHtmi1kFMYNrVtenByEripInOm 2ETF6JK1bQjTuU1LlI5PQ2hh2lhZCH2PpA/+8nsGcDK4qqGiWZ8bP44Y2E5+/BLouwqdwX3lAPn sWWi6plMIj+jWmnEOoo5MUhF4zdBh7pDhc4somBwJbTVl6bKaFWXP6/8Nanrhjy6TEBcdoJH6cD rlEXF+CmuQNihruUUbcwQIilxS+wKYLlg== X-Received: by 2002:a05:6a20:3d09:b0:3dd:a00a:c5ba with SMTP id adf61e73a8af0-3de0e7f49aamr1164357637.45.1790224424446; Wed, 23 Sep 2026 21:33:44 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:44 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 11/24] strongswan: patch CVE-2026-78131 Date: Thu, 24 Sep 2026 16:33:01 +1200 Message-ID: <20260924043315.1663186-11-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130259 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78131 [1]https://download.strongswan.org/security/CVE-2026-78131/strongswan-5.5.3-6.0.7_x509_ac_leaks.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78131.patch | 86 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 87 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78131.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78131.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78131.patch new file mode 100644 index 0000000000..da53f8e5a0 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78131.patch @@ -0,0 +1,86 @@ +From d1d29ac675b42a8c4a6454db84803bfecf5a0d99 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Fri, 12 Jun 2026 15:55:43 +0200 +Subject: [PATCH] x509: Fix memory leaks when parsing attribute certificates + +This can be triggered by an attribute certificate with lots of GeneralName +entries or AuthorityKeyIdentifier extensions. There is no verification +before the certificate is parsed. + +Fixes: 3134379ac7f1 ("x509: Fix some whitespaces and do some minor style cleanups in acert") +Fixes: 26930a8c3e42 ("certificate factory can load certs from file") +Fixes: CVE-2026-78131 + +CVE: CVE-2026-78131 +Upstream-Status: Backport [1][2] + +[1]https://github.com/strongswan/strongswan/commit/23c9b9a2708e4958292d828424523fa63c0be829 +[2]https://github.com/strongswan/strongswan/commit/9762cc3b091b423543510113a5d05215daf16951 + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/plugins/x509/x509_ac.c | 33 +++++++----------------- + 1 file changed, 9 insertions(+), 24 deletions(-) + +diff --git a/src/libstrongswan/plugins/x509/x509_ac.c b/src/libstrongswan/plugins/x509/x509_ac.c +index 3fc5de2..68b7cf9 100644 +--- a/src/libstrongswan/plugins/x509/x509_ac.c ++++ b/src/libstrongswan/plugins/x509/x509_ac.c +@@ -186,41 +186,25 @@ extern bool x509_parse_generalNames(chunk_t blob, int level0, bool implicit, + static bool parse_directoryName(chunk_t blob, int level, bool implicit, + identification_t **name) + { +- identification_t *directoryName; +- enumerator_t *enumerator; +- bool first = TRUE; + linked_list_t *list; + + list = linked_list_create(); + if (!x509_parse_generalNames(blob, level, implicit, list)) + { +- list->destroy(list); ++ list->destroy_offset(list, offsetof(identification_t, destroy)); + return FALSE; + } +- +- enumerator = list->create_enumerator(list); +- while (enumerator->enumerate(enumerator, &directoryName)) +- { +- if (first) +- { +- *name = directoryName; +- first = FALSE; +- } +- else +- { +- DBG1(DBG_ASN, "more than one directory name - first selected"); +- directoryName->destroy(directoryName); +- break; +- } +- } +- enumerator->destroy(enumerator); +- list->destroy(list); +- +- if (first) ++ if (list->remove_first(list, (void**)name) != SUCCESS) + { + DBG1(DBG_ASN, "no directoryName found"); ++ list->destroy(list); + return FALSE; + } ++ if (list->get_count(list)) ++ { ++ DBG1(DBG_ASN, "more than one directory name - first selected"); ++ } ++ list->destroy_offset(list, offsetof(identification_t, destroy)); + return TRUE; + } + +@@ -539,6 +523,7 @@ static bool parse_certificate(private_x509_ac_t *this) + DBG2(DBG_ASN, " need to parse crlDistributionPoints"); + break; + case OID_AUTHORITY_KEY_ID: ++ chunk_free(&this->authKeyIdentifier); + this->authKeyIdentifier = + x509_parse_authorityKeyIdentifier(object, + level, &this->authKeySerialNumber); diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 4d13507151..19f1cc2f69 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -16,6 +16,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78127.patch \ file://CVE-2026-78129.patch \ file://CVE-2026-78133.patch \ + file://CVE-2026-78131.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99124 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 94044C98304 for ; Thu, 24 Sep 2026 04:33:53 +0000 (UTC) Received: from mail-pz2-f42.google.com (mail-pz2-f42.google.com [74.125.228.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.730.1790224427280783113 for ; Wed, 23 Sep 2026 21:33:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=dTEpjR/o; spf=pass (domain: gmail.com, ip: 74.125.228.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f42.google.com with SMTP id 41be03b00d2f7-cc4c08393dfso1124522a12.3 for ; Wed, 23 Sep 2026 21:33:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224427; x=1790829227; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rFZuLjhTMyCwa2hO2xMU37RqRhtN0t6F2/9DdfnYw94=; b=dTEpjR/oYljGfuISm6fJowHgihPsezkU01InxWmdQrOWQNgQ0BxMjDwWst8NMh4v8B iSsuQUOluMGhuWeguXsNnNDKQSpHcLIBpo9xKbA2/2zoSCf59qqy6tlLi16b85UiDkkl IgHRvG2gmIbg0dgJlV51Ee5ZyR8xw1viZ0tK39X+c6MR0Qi+6CSVSSxBvHUxXjav+h7q ukO6rsIeIUXO33KhLZXUw712J1MWRZWETnGWOgCM3lxx1QNQsm1nNsjnBcMA6lapuuOH 6xdgGGeEvQFZ3WIij9vNJI8uMgmG9G3hrmJYKgx4cvyy+QQacw/5l6cgMMV0GnfV/8Ci nRcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224427; x=1790829227; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rFZuLjhTMyCwa2hO2xMU37RqRhtN0t6F2/9DdfnYw94=; b=JJolEwDpe0lR/HkNyDcaoTg/FCJzRZxuS3ZIeuAypZ5ct3zD6lvN9xDMW3SAxa8bSM xFjuaQ0tgS0D8HBLGTonAwoS1M+62AisvZ3IBAnol3Z95cnR/zFQwZWKOzlIPcHU3pnb Mh379howQk7xVbMcZIyt/2zeAKCDSYbspD8OdiYr7Nri3oatmk/7MvhPk28yfxbs6Je1 9wBGR7mPzic3n3ini9F3cCqLTixF02F1l0GRTnpUEl/btlfRocOh7yDcUfj93myNm1oZ tc1tlCGEmH9zACF38HpYy/bi1LZ5RR8R6+YFeFrw2fhtoGbgmemeBHZPZQjceEdnxKon DX4Q== X-Gm-Message-State: AFuF++lAuEkLiDGICLK46+HErFK1Pf/ivkGNpYT6+sZf5c/boyUPFynx tBviZ1VcsahzFZOx6x/MDEg1qm6GwvZ75IEJE2HaBn1kxoOPpt7Ci1KMtgfUBg== X-Gm-Gg: AYBFou3BryBlGjbRCnzfuCjQlQR4EUJuom3nkl958H7OkBr3UC1l8pDMxpilrtx2CdZ MGGTunwbU5c+se2ei5tEVazOOeHw0MENZGafNpBcBTtK7t/wvpXa0tR/XLumd5ks1hZe2P/BBLW gZ9zNlzt8qCXFlB4W0pJ1hV4LTuJUlbx6RlNZ8V+95ZoPbl6LO85A1uUceNYWKWtI1PekxW972f RRy9g9uzorVvCu4sByTQgU5WLndmjN9J4dAp7xBw2Hx4dPE5gkTSPs1F71ViAb/aKpm+Pw6SPxl gjgRMLI88sRrQiX/emGvDPGLll9kjx1UIPg2EQVZNrjU54oCblYpjB4oShl74fPOh3q6gq9b6hR E8GfH4xOjCx42+SAfyOWffDqVqhUnvZ6uFLTRpZIA9c/1Vxl1Y9G/3qhELQlcVhB/+QxY0tb9Tw IdN+sZR8HPqR8fam/t5nxwxUZ4b2K3eutLnNpNdDLGqWghTZ2JLz8OFAeux/MVao7cFJ6ijFUKD KKz4HHNJsTokhpAP6tzf3I= X-Received: by 2002:a05:6300:197:b0:3cc:f008:8125 with SMTP id adf61e73a8af0-3de0e7f4b15mr1324327637.1.1790224426599; Wed, 23 Sep 2026 21:33:46 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:46 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 12/24] strongswan: patch CVE-2026-78130 Date: Thu, 24 Sep 2026 16:33:02 +1200 Message-ID: <20260924043315.1663186-12-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130260 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78130 [1]https://download.strongswan.org/security/CVE-2026-78130/strongswan-5.1.3-6.0.7_x509_ac_issuer_null.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78130.patch | 49 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 50 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78130.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78130.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78130.patch new file mode 100644 index 0000000000..36025c8093 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78130.patch @@ -0,0 +1,49 @@ +From 254d971bbe7479fe5fffc34cd1dd1e349a48e7aa Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Fri, 19 Jun 2026 11:57:48 +0200 +Subject: [PATCH] x509: Avoid NULL-pointer dereference if issuerName is missing + in attribute certificate + +If neither authoritiyKeyIdentifier nor issuerName are encoded in an +attribute certificate, the validation in `acert_validator.c:verify()` +will cause a NULL-pointer dereference via `issued_by()` (the lookup +with NULL identity will enumerate all trusted certificates). + +Fixes: 26930a8c3e42 ("certificate factory can load certs from file") +Fixes: CVE-2026-78130 + +CVE: CVE-2026-78130 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/bee6ce27761e1f38958be36ebe6688ef963c3d22] + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/plugins/x509/x509_ac.c | 9 +++++++-- + 1 file changed, 7 insertions(+), 2 deletions(-) + +diff --git a/src/libstrongswan/plugins/x509/x509_ac.c b/src/libstrongswan/plugins/x509/x509_ac.c +index 68b7cf9..11a847e 100644 +--- a/src/libstrongswan/plugins/x509/x509_ac.c ++++ b/src/libstrongswan/plugins/x509/x509_ac.c +@@ -898,7 +898,11 @@ METHOD(certificate_t, has_issuer, id_match_t, + { + return ID_MATCH_PERFECT; + } +- return this->issuerName->matches(this->issuerName, issuer); ++ if (this->issuerName) ++ { ++ return this->issuerName->matches(this->issuerName, issuer); ++ } ++ return ID_MATCH_NONE; + } + + METHOD(certificate_t, issued_by, bool, +@@ -935,7 +939,8 @@ METHOD(certificate_t, issued_by, bool, + } + else + { +- if (!this->issuerName->equals(this->issuerName, ++ if (!this->issuerName || ++ !this->issuerName->equals(this->issuerName, + issuer->get_subject(issuer))) + { + return FALSE; diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 19f1cc2f69..ffc9d1433e 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -17,6 +17,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78129.patch \ file://CVE-2026-78133.patch \ file://CVE-2026-78131.patch \ + file://CVE-2026-78130.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99125 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DCB31C982FD for ; Thu, 24 Sep 2026 04:33:53 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.732.1790224429431408342 for ; Wed, 23 Sep 2026 21:33:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=eiR8t6rI; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8631d0023daso914930b3a.2 for ; Wed, 23 Sep 2026 21:33:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224429; x=1790829229; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QozY+IpOyaLK2wJymvSE8umBSfDcKUb7Tnq4E703TZU=; b=eiR8t6rI8iYz4/NmsTh7eHTTArtGtIWS0QQ46OtNPxb5DShnoF9+4qxgJ12czS0jJn Us5Ojuqt7jJ4xs+KUgQQTvJPpgtR5XRWV9DWrEbVpTZN5jv0a+9g7QcqVkJ+SuJOJpXz Su6Kyd8LWnMOguxBHwzMUffylhGB9gdW+0nFwAmjIvcveqBmNMqER+VjdKXKVZ0nGUyZ LJJoIHLC1cgbnwleSmUhqwMe9jlfNzYI803twpbeC/Gj8bxeTYCmCGcPpCVWfjLEOaJy FZD/cF0oI7VhXBAEWPu66WsnNYnRSQ0OxBQmNFamBOigHTtntMAxadddSOToSrnXFkMn IuXQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224429; x=1790829229; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QozY+IpOyaLK2wJymvSE8umBSfDcKUb7Tnq4E703TZU=; b=fMAHYEZUZKIVtee8+oYKQ9bqzBOv7EdVIxWr/wyLPozOAecji1iexzFW1XeSzBi070 GbR/Enlz0l8S9w2MSiPXD3Scv0FOg00NT7WYl1eYILXMjr//E5FRoSyxn8fPdxgxU1ma aiyMdqOzmXogb1NLrlkuHe6sk923Ai06dpNJ6vH1NhacHJrMe10TUyYYelTvrHZld7ve 6NHfz6IKuV6vH+hvqZ+0AwEYyrp5QrWybCIv/BZ1gfoH5yI0a+EcT46i8VkQLe9kPuQf yqd7xcS668a1UbO8sUFE2WNdiWAjELozUTC+HpxCKG5KUuSh/88Q6ihwgtlIbHda/QGA CO9Q== X-Gm-Message-State: AFuF++nqNdWEy1VtgK8cBmr6agdoy4n/yn4piVo7BPu0G2ABXIlJl40E /6WPkdYqcyCapPvT4QwHVv+l8PTfp7+GwuujuaNLpdBpT9IpIooxP6pljV2VXw== X-Gm-Gg: AYBFou0efUKiOIgyjhR3Tft7NW4YFXLQJdT36J8bzYQKViWZ56UhTXeKTGwJ9l1LJza UgulBRm4T32aymxDVlQ0kNxDZvc7Au69HX6FyQ7rpGkzqXWTF7JNAXLWlddhJ24Vi8Pv9tQWF6x Yd4xTKvlCNgY1P9K0PekrSQTkkQWB+JJ2oAt3Qmc706md6Ugo0KuHW9xLRruazx8Zq/g9pMxkIn 4KYqSK0gapMHum3O751ExjMPjM6/BnpHYidwOtGTNjM/JkKnqvv5nmN/ktkIe/2Vm/t8+Som0fk CtAKeyz1s8RclZ2qzYZB17I4xDr+sIBvjsXSA6rufjzyIqZw9OrZbBKLHpPLNcIJEVtfypPgqMZ LwG2m1Oa538oDl/GEfgpanDjGx9ho7HBlXnUsv1T2l4sGuuYTDz7aXilM9y8Gym20uyDMjGNg9s zS7TfTtsCPqTWf0s26bQRXCLy0I0c+b9bgVm06bA2chGyxs4t7tSdr/P9mruDuy+eYVALxvG1ca Yq+WTBZ+V4Cne0Z6K2pKu0= X-Received: by 2002:aa7:88c2:0:b0:86b:43f6:67c4 with SMTP id d2e1a72fcca58-87e9869458amr1040994b3a.1.1790224428771; Wed, 23 Sep 2026 21:33:48 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:48 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 13/24] strongswan: patch CVE-2026-78132 Date: Thu, 24 Sep 2026 16:33:03 +1200 Message-ID: <20260924043315.1663186-13-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130261 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78132 [1]https://download.strongswan.org/security/CVE-2026-78132/strongswan-5.1.3-6.0.7_x509_ac_ietfattr_loop.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78132.patch | 75 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 76 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78132.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78132.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78132.patch new file mode 100644 index 0000000000..eb53d99ba5 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78132.patch @@ -0,0 +1,75 @@ +From d8144c609148eda1ca55eac2ecddcd81bbd799b5 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Wed, 1 Jul 2026 16:24:23 +0200 +Subject: [PATCH] x509: Prevent infinite loop when parsing ietfAttrSyntax in + attribute certificates + +This is the same issue that was fixed with 407fcca200fd ("asn1-parser: +Fix CHOICE parsing") for other CHOICE elements. This one was missed and +can be triggered pre-auth by sending an attribute certificate to a peer. +Since it's parsed before verifying it, the certificate doesn't have to +be valid. + +For versions older than 5.5.3, this patch requires prior application of +the fix for CVE-2017-9023, which introduced proper CHOICE handling in +the ASN.1 parser. + +Fixes: a17598bc6992 ("x509: Integrate IETF attribute handling, and obsolete ietf_attributes_t") +Fixes: CVE-2026-78132 + +CVE: CVE-2026-78132 +Upstream-Status: Backport [https://github.com/strongiswan/strongswan/commit/86bf2cbf5d9941b7ef16a1b25f0baf5589e0b64e] + +Signed-off-by: Ankur Tyagi +--- + src/libstrongswan/plugins/x509/x509_ac.c | 36 +++++++++++------------- + 1 file changed, 17 insertions(+), 19 deletions(-) + +diff --git a/src/libstrongswan/plugins/x509/x509_ac.c b/src/libstrongswan/plugins/x509/x509_ac.c +index 11a847e..46c1f58 100644 +--- a/src/libstrongswan/plugins/x509/x509_ac.c ++++ b/src/libstrongswan/plugins/x509/x509_ac.c +@@ -249,26 +249,24 @@ static void parse_roleSyntax(chunk_t blob, int level0) + */ + static const asn1Object_t ietfAttrSyntaxObjects[] = + { +- { 0, "ietfAttrSyntax", ASN1_SEQUENCE, ASN1_NONE }, /* 0 */ +- { 1, "policyAuthority", ASN1_CONTEXT_C_0, ASN1_OPT | +- ASN1_BODY }, /* 1 */ +- { 1, "end opt", ASN1_EOC, ASN1_END }, /* 2 */ +- { 1, "values", ASN1_SEQUENCE, ASN1_LOOP }, /* 3 */ +- { 2, "octets", ASN1_OCTET_STRING, ASN1_OPT | +- ASN1_BODY }, /* 4 */ +- { 2, "end choice", ASN1_EOC, ASN1_END }, /* 5 */ +- { 2, "oid", ASN1_OID, ASN1_OPT | +- ASN1_BODY }, /* 6 */ +- { 2, "end choice", ASN1_EOC, ASN1_END }, /* 7 */ +- { 2, "string", ASN1_UTF8STRING, ASN1_OPT | +- ASN1_BODY }, /* 8 */ +- { 2, "end choice", ASN1_EOC, ASN1_END }, /* 9 */ +- { 1, "end loop", ASN1_EOC, ASN1_END }, /* 10 */ +- { 0, "exit", ASN1_EOC, ASN1_EXIT } ++ { 0, "ietfAttrSyntax", ASN1_SEQUENCE, ASN1_NONE }, /* 0 */ ++ { 1, "policyAuthority", ASN1_CONTEXT_C_0, ASN1_OPT|ASN1_BODY }, /* 1 */ ++ { 1, "end opt", ASN1_EOC, ASN1_END }, /* 2 */ ++ { 1, "values", ASN1_SEQUENCE, ASN1_LOOP }, /* 3 */ ++ { 2, "value choice", ASN1_EOC, ASN1_CHOICE }, /* 4 */ ++ { 3, "octets", ASN1_OCTET_STRING, ASN1_OPT|ASN1_BODY }, /* 5 */ ++ { 3, "end choice", ASN1_EOC, ASN1_END|ASN1_CH }, /* 6 */ ++ { 3, "oid", ASN1_OID, ASN1_OPT|ASN1_BODY }, /* 7 */ ++ { 3, "end choice", ASN1_EOC, ASN1_END|ASN1_CH }, /* 8 */ ++ { 3, "string", ASN1_UTF8STRING, ASN1_OPT|ASN1_BODY }, /* 9 */ ++ { 3, "end choice", ASN1_EOC, ASN1_END|ASN1_CH }, /* 10 */ ++ { 2, "end choices", ASN1_EOC, ASN1_END|ASN1_CHOICE }, /* 11 */ ++ { 1, "end loop", ASN1_EOC, ASN1_END }, /* 12 */ ++ { 0, "exit", ASN1_EOC, ASN1_EXIT } + }; +-#define IETF_ATTR_OCTETS 4 +-#define IETF_ATTR_OID 6 +-#define IETF_ATTR_STRING 8 ++#define IETF_ATTR_OCTETS 5 ++#define IETF_ATTR_OID 7 ++#define IETF_ATTR_STRING 9 + + /** + * Parse group memberships, IETF attributes diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index ffc9d1433e..1597455d15 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -18,6 +18,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78133.patch \ file://CVE-2026-78131.patch \ file://CVE-2026-78130.patch \ + file://CVE-2026-78132.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99127 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0719FC98310 for ; Thu, 24 Sep 2026 04:33:54 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.733.1790224431856368436 for ; Wed, 23 Sep 2026 21:33:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=YLJGIR1I; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc1cea34f01so987627a12.1 for ; Wed, 23 Sep 2026 21:33:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224431; x=1790829231; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MxX8GAtDzzlGDWf5Ae57+OeqOHPyvNjE6aXiIfc9OWw=; b=YLJGIR1IbfpfrE74RJAYpGcfOiy+RCZgqA5Cp9VZDFjSjIRtnS6CjZTpWVrwuAuW62 RELWSVK9D6cNuYyP4q7YfLL9yCHZ9Q5Ng8aUETLrq39ERJJLJJ/Qk4hZIPgiIm9wtetS TG4QpuS4I6vHPjRtlVYzSdgJK11kvowEr8At+9u11H+HV58xg1br9f+eTMUzSioG87h5 49gn68h5odobI0dTnd/hHhkmc5AiyNbS2mpV3hLfWuuywfEqIX1CjTTyTVFNipntTzhj GUojakaTVwhfSOkHNbByubCBsUjNLbdYcn7AvhzhUSZoD+5BUi3FxLgH9CxvINjHEaIc TIeg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224431; x=1790829231; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MxX8GAtDzzlGDWf5Ae57+OeqOHPyvNjE6aXiIfc9OWw=; b=IkCAWD1F/idYz5C0eClOVD55ZKqtYN5avJE1RKnZlQYagr6jghuhHIMH50b1iaEash +uf4FqoZpMJ0hKmspp0UyW1HL10GhjRA77so42OXVwv9mdIbjll1yUxyZzqehsFFDaYq gxsV1QJmA/3OrR4H81UUN9JlkGJtjLWyirFuBaf8bd9pSI2p4sVZVwfUKTjUeX7p608A 69Xc/rm3BzivuoWbrFotDs40QfA4mHSLLAwswqiEgQUS0kMpZQc4Kffn7X4KScPtCvzn +At5VcToJu5+3eXIJmmZ6q1VdcesCYODS2ZJj0kj5YLbrqmuqpfhncNYQIqVVDFZ8vhB y9EA== X-Gm-Message-State: AFuF++kOl2Z2fl+VsP/OdDt2ecNFGotYTN+HgATe9qgT2lgEMy+zgQ2T dJnnNYYNkjfRL3sYcVtLzPIzsM6qyyCfdFFD1mhHYU246yuxPCZRkBkdfIoCTQ== X-Gm-Gg: AYBFou0BFD59VCa9HwgDIyr5KvBQe2Gx6dbqfrQc+bDeXMqtkNO4W0zyBhPTdbNf+th t4kF41x+X+7FOmruCyoO8hDFjKInQuPHqSfdboKxdgZU2I8RKtegH1/bWGrSN0MQ0HVGtFJqOW7 915leyfdGZVV4rFVXa4wFRsZEc6YQ4KUdT15gnEfK1RHkWIaaPvhjcoW3B7tvjIP0kY96Lq29FA 3uiqMtLNU8oAweUHC4acdCYZOSQilgTYdrBnWJMkWCFtbpdpT/6UJJErUJXashHmYLM+ypDShq8 yQm7gwFAJ7GmNJ4J+c0FWpGSnPbInyZ82e89Rq5v2YpX0Zk+rNe7X2aNksDSWzWaZsO+jIJwh5H gtfc4HWGR7Dqf+jvpIOMsmAVN+sLXbIT9R+4jXmNFC9MSj7EAlvd0zo8fibF+VIqumklIeN9XGi VmRyYVgHVCjtRJ5xWjNafR5XyGrmUo02aflPgDMPEHt2vkrEnFa64V1MMYtZMH7g4K4A3nrkKoA J2iRv8A8JR4v0PwNdfzuK2ua7Z9dDLvcg== X-Received: by 2002:a05:6a20:9195:b0:3dd:85aa:452b with SMTP id adf61e73a8af0-3de0e76baa3mr1287736637.29.1790224431054; Wed, 23 Sep 2026 21:33:51 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:50 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 14/24] strongswan: patch CVE-2026-78135 Date: Thu, 24 Sep 2026 16:33:04 +1200 Message-ID: <20260924043315.1663186-14-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:33:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130262 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78135 [1]https://download.strongswan.org/security/CVE-2026-78135/strongswan-5.9.7-6.0.7_early_create_child_sa.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78135.patch | 72 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78135.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78135.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78135.patch new file mode 100644 index 0000000000..1b6c472b30 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78135.patch @@ -0,0 +1,72 @@ +From 2c3d63bd7a05f88d25354dfe7805a5a6e474a699 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 27 Jul 2026 08:53:50 +0200 +Subject: [PATCH] ikev2: Properly reject CREATE_CHILD_SA requests on + unestablished IKE_SAs + +The previous check was not actually enforced as long as there were still +tasks in the passive queue (it was originally added to fix an issue on +initiators, so the passive queue was expected to be empty). This allowed +an unauthenticated attacker to potentially establish a usable Child SA +if certain preconditions were met. + +First, it required that the initiator is authenticated with EAP so the +authentication and the creation of the first Child SA is deferred. +Second, the responder must either not configure an IP address pool or +an explicit remote TS, otherwise, traffic selector negotiation fails. + +Note that the half-open IKE SA and the installed IPsec SA will be removed +after the default timeout of 30 seconds. + +Fixes: 8503077175cd ("ikev2: Reject CREATE_CHILD_SA exchange on unestablished IKE_SAs") +Fixes: c60c7694d2d8 ("merged tasking branch into trunk") +Fixes: CVE-2026-78135 + +CVE: CVE-2026-78135 +Upstream-Status: Backport [https://github.com/strongswan/strongswan/commit/4dcb132266a954202509a3b4b3be99378f3e3b4d] + +Signed-off-by: Ankur Tyagi +--- + src/libcharon/sa/ikev2/task_manager_v2.c | 21 +++++++++++---------- + 1 file changed, 11 insertions(+), 10 deletions(-) + +diff --git a/src/libcharon/sa/ikev2/task_manager_v2.c b/src/libcharon/sa/ikev2/task_manager_v2.c +index 5a19ce8..f9e9ab9 100644 +--- a/src/libcharon/sa/ikev2/task_manager_v2.c ++++ b/src/libcharon/sa/ikev2/task_manager_v2.c +@@ -1134,9 +1134,18 @@ static status_t process_request(private_task_manager_t *this, + delete_payload_t *delete; + ike_sa_state_t state; + ++ state = this->ike_sa->get_state(this->ike_sa); ++ if (message->get_exchange_type(message) == CREATE_CHILD_SA && ++ (state == IKE_CREATED || state == IKE_CONNECTING)) ++ { ++ DBG1(DBG_IKE, "received CREATE_CHILD_SA request for " ++ "unestablished IKE_SA, rejected"); ++ return FAILED; ++ } ++ ++ /* create tasks depending on request type, if not already some queued */ + if (array_count(this->passive_tasks) == 0) +- { /* create tasks depending on request type, if not already some queued */ +- state = this->ike_sa->get_state(this->ike_sa); ++ { + switch (message->get_exchange_type(message)) + { + case IKE_SA_INIT: +@@ -1177,14 +1186,6 @@ static status_t process_request(private_task_manager_t *this, + { /* FIXME: we should prevent this on mediation connections */ + bool notify_found = FALSE, ts_found = FALSE; + +- if (state == IKE_CREATED || +- state == IKE_CONNECTING) +- { +- DBG1(DBG_IKE, "received CREATE_CHILD_SA request for " +- "unestablished IKE_SA, rejected"); +- return FAILED; +- } +- + enumerator = message->create_payload_enumerator(message); + while (enumerator->enumerate(enumerator, &payload)) + { diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 1597455d15..5ddc3c32b9 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -19,6 +19,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78131.patch \ file://CVE-2026-78130.patch \ file://CVE-2026-78132.patch \ + file://CVE-2026-78135.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99133 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C78F7C98312 for ; Thu, 24 Sep 2026 04:34:05 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.734.1790224434114041680 for ; Wed, 23 Sep 2026 21:33:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=IS1Y3RqX; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-868b2e5be4eso616766b3a.3 for ; Wed, 23 Sep 2026 21:33:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224433; x=1790829233; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ArCG9NXBLrnh4ZSsBiw78bmnHdZwxGNQzwjZ67Kw3fI=; b=IS1Y3RqXZ65EEbCg7l/tTH34va5kaMMylRDbS036euk6Y6EgOk1NqeL7dePq05C7TO 5HKMZ2f30ImK/I77TAQZSRvifgEvuaNsuU+r7QF3qu7eV6vy/AS4SUYHRMEm3RfzvDFZ rVYCOP2vytatHk2UDfvQxPHNqaYdl+0HTBxh7KfQ16rL6B0XvQni/9byFL3rYHfkXJyH FxLS+Bw316ebee1l8tPI2x5p4VtuccHdbsTCxj+Ekmn8rGLE7BRwpShGvvj1iCNv5vgK LpLcK+VRl1dakypQxtum/zs6LuB4CfKfgJp70UbJJoxAsOkGKlXmw5JR5gDPKtgegE3u 8Hag== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224433; x=1790829233; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ArCG9NXBLrnh4ZSsBiw78bmnHdZwxGNQzwjZ67Kw3fI=; b=DBPMVBJqb0h4m64Kav6F9tDu4rklE2nsfunBa5Oqqb/RRtDL6K8orFf/Q00J4w5UIY s27LFEKQ7yTezY+bycf4GzPtLInzRm07EQp1bG/GjmXFCkS+4ltIZvWKc5tYto5Q8EcR 7JMhAD06fjtMYDHRC+uBOQXN0Q9JbkML78RRMdkts+uIyiWcKG9PT3PBIDidBBD0LKbD 92X+OKljbS8bGjSM9bV+xfn40rQ7OOAx6OP9fpgdrPGIIDTD+2IkMtJ5BciZSyUj1f9J SiDG0tmIe/Y732NkMHSzqjqdfAHf4nwMvloA6oloJ5vX7xf7jExFnELL0yK54yPpU8TB UJHA== X-Gm-Message-State: AFuF++kGjZ5KOz9Z/2WcA8SxahU5PufHTDb2QjgYW06WwNnMq2CTCyYF l5/KUw/n57mNGg0TrLCkon+mCQgbMs74mQ7eRg+s5yO63o3B7ftxuS6cuwe3uQ== X-Gm-Gg: AYBFou2Q6xCsYpKhpPG52/SoNIYx5b/iZ5xBHl5/smSSUmnBlAiskUCF+adCgvsd0zf 0seM/8Y4y5yfFzRFyR98Ccc7SsxUroALycAi08USMZpdBFT0NYDS5zTsy5ahdooqagcxnzxKNfR Uj81cjoMHuPkr/L/Tol6h/Jos8+TwWXgaH9IdOvgZUjobtHu7iauOOGC8Qtg0vJHHY/risZgBxE gblawI2hE8WyeOb2a4YBWai0NB1KyXgIFHXcWyTJkEqVdMTki/W4Cr/PYtsjje5SIYnlTu+f0Hk Q9RkdvNySJG7KQanMbAa2abcfPoucCLsz/BXyYkqDzLb9sfM7uqGu2BcM8L/Sbn8sPkeYiCX84o bu2pFwxz0kfBE3M5HEkH33Q4uZ3PB5TqZK4pukYLN7o4466Ib4/6Lo378LDXhwanStPNouBonLb VIM0EgF7SNIHMYlvedhcYVK+AIO/GP3uNIMWtwjR3v6cFP62i9XaRHVZ2f4DGPFr4gUC/Fs2HjJ ng+A84mCmvLVgkx/nzH/vc= X-Received: by 2002:a05:6a00:3e1e:b0:87a:2e3c:7892 with SMTP id d2e1a72fcca58-87e9a70b7b6mr1015333b3a.10.1790224433335; Wed, 23 Sep 2026 21:33:53 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:52 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 15/24] strongswan: patch CVE-2026-78134 Date: Thu, 24 Sep 2026 16:33:05 +1200 Message-ID: <20260924043315.1663186-15-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130263 From: Ankur Tyagi Use patch[1] provided by strongSwan[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-78134 [1]https://download.strongswan.org/security/CVE-2026-78134/strongswan-5.9.10-6.0.7_eap_inner_auth_cfg.patch [2]https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html Signed-off-by: Ankur Tyagi --- .../strongswan/CVE-2026-78134.patch | 712 ++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 713 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78134.patch diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78134.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78134.patch new file mode 100644 index 0000000000..86646e5e96 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78134.patch @@ -0,0 +1,712 @@ +From d95e9d363b0e23d0ba3080bb518695e05a453748 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 27 Jul 2026 15:05:45 +0200 +Subject: [PATCH] eap-ttls/peap: Return auth-cfg with details on TLS and inner + EAP method + +This fixes several issues with binding identities to the IKE SA. + +If the client is authenticated with a certificate, the previous code still +used the client's proclaimed inner EAP-Identity when starting the EAP-TNC +method. So that method would potentially operate on an unverified +identity. + +Second, if the inner EAP method overrides the client identity (the only +one is currently EAP-MSCHAPV2), the missing merge meant that the outer +IKE/EAP identity could potentially be unconfirmed. + +For inner methods that don't override the identity (e.g. EAP-MD5), not +propagating the inner EAP-Identity could potentially have the same +effect. + +While the EAP-TTLS implementation returned the auth-cfg of the TLS +exchange since the first referenced commit, this was mainly intended to +enforce public key constraints. So it didn't cover the phase 2 EAP +methods. For some reason EAP-PEAP did not get that method at all in that +changeset, so we'll add that now. + +Additionally, the EAP-PEAP implementation now forwards the phase 2 EAP +method type to EAP-TNC like the EAP-TTLS implementation already did, +which allows a more informed decision on the client's identity. + +Fixes: 0864a31d13ff ("eap-ttls: Support EAP auth information getter in EAP-TTLS") +Fixes: 79f2102cb442 ("implemented server side support for EAP-TTLS") +Fixes: 2a421163bf4f ("make TNC client authentication type available to IMVs") +Fixes: 1be296dfb2af ("implemented the PEAP tunneling protocol as an EAP plugin") +Fixes: CVE-2026-78134 + +CVE: CVE-2026-78134 +Upstream-Status: Backport [1][2] + +[1]https://github.com/strongswan/strongswan/commit/e059077d3f3e307e78be7f91e5648aa5f94916a8 +[2]https://github.com/strongswan/strongswan/commit/6a7210731f6dd2889d22bf20310ab0ed7274d0d8 + +Signed-off-by: Ankur Tyagi +--- + src/libcharon/plugins/eap_peap/eap_peap.c | 49 ++++++++++- + .../plugins/eap_peap/eap_peap_peer.c | 20 +++++ + .../plugins/eap_peap/eap_peap_peer.h | 7 ++ + .../plugins/eap_peap/eap_peap_server.c | 81 ++++++++++++++++--- + .../plugins/eap_peap/eap_peap_server.h | 7 ++ + src/libcharon/plugins/eap_ttls/eap_ttls.c | 43 +++++++++- + .../plugins/eap_ttls/eap_ttls_peer.c | 19 +++++ + .../plugins/eap_ttls/eap_ttls_peer.h | 7 ++ + .../plugins/eap_ttls/eap_ttls_server.c | 56 +++++++++++-- + .../plugins/eap_ttls/eap_ttls_server.h | 7 ++ + 10 files changed, 278 insertions(+), 18 deletions(-) + +diff --git a/src/libcharon/plugins/eap_peap/eap_peap.c b/src/libcharon/plugins/eap_peap/eap_peap.c +index 3573cba..cd942f1 100644 +--- a/src/libcharon/plugins/eap_peap/eap_peap.c ++++ b/src/libcharon/plugins/eap_peap/eap_peap.c +@@ -40,6 +40,25 @@ struct private_eap_peap_t { + * TLS stack, wrapped by EAP helper + */ + tls_eap_t *tls_eap; ++ ++ /** ++ * Role ++ */ ++ bool is_server; ++ ++ /** ++ * Actual server/client implementation ++ */ ++ union { ++ tls_application_t *application; ++ eap_peap_server_t *server; ++ eap_peap_peer_t *client; ++ } impl; ++ ++ /** ++ * Cached auth data for TLS and inner EAP methods ++ */ ++ auth_cfg_t *auth; + }; + + /** Maximum number of EAP-PEAP messages/fragments allowed */ +@@ -113,10 +132,34 @@ METHOD(eap_method_t, is_mutual, bool, + return TRUE; + } + ++METHOD(eap_method_t, get_auth, auth_cfg_t*, ++ private_eap_peap_t *this) ++{ ++ if (!this->auth) ++ { ++ auth_cfg_t *inner; ++ ++ this->auth = auth_cfg_create(); ++ this->auth->merge(this->auth, ++ this->tls_eap->get_auth(this->tls_eap), FALSE); ++ if (this->is_server) ++ { ++ inner = this->impl.server->get_auth(this->impl.server); ++ } ++ else ++ { ++ inner = this->impl.client->get_auth(this->impl.client); ++ } ++ this->auth->merge(this->auth, inner, FALSE); ++ } ++ return this->auth; ++} ++ + METHOD(eap_method_t, destroy, void, + private_eap_peap_t *this) + { + this->tls_eap->destroy(this->tls_eap); ++ DESTROY_IF(this->auth); + free(this); + } + +@@ -135,6 +178,7 @@ static private_eap_peap_t *eap_peap_create_empty(void) + .get_type = _get_type, + .is_mutual = _is_mutual, + .get_msk = _get_msk, ++ .get_auth = _get_auth, + .get_identifier = _get_identifier, + .set_identifier = _set_identifier, + .destroy = _destroy, +@@ -147,7 +191,7 @@ static private_eap_peap_t *eap_peap_create_empty(void) + /** + * Generic private constructor + */ +-static eap_peap_t *eap_peap_create(private_eap_peap_t * this, ++static eap_peap_t *eap_peap_create(private_eap_peap_t *this, + identification_t *server, + identification_t *peer, bool is_server, + tls_application_t *application) +@@ -157,6 +201,9 @@ static eap_peap_t *eap_peap_create(private_eap_peap_t * this, + bool include_length; + tls_t *tls; + ++ this->is_server = is_server; ++ this->impl.application = application; ++ + if (is_server && !lib->settings->get_bool(lib->settings, + "%s.plugins.eap-peap.request_peer_auth", FALSE, + lib->ns)) +diff --git a/src/libcharon/plugins/eap_peap/eap_peap_peer.c b/src/libcharon/plugins/eap_peap/eap_peap_peer.c +index 95213a3..f6c087a 100644 +--- a/src/libcharon/plugins/eap_peap/eap_peap_peer.c ++++ b/src/libcharon/plugins/eap_peap/eap_peap_peer.c +@@ -52,6 +52,11 @@ struct private_eap_peap_peer_t { + */ + eap_method_t *ph2_method; + ++ /** ++ * Auth data for phase 2 methods ++ */ ++ auth_cfg_t *auth; ++ + /** + * Pending outbound EAP message + */ +@@ -166,6 +171,12 @@ METHOD(tls_application_t, process, status_t, + switch (status) + { + case SUCCESS: ++ if (this->ph2_method->get_auth) ++ { ++ this->auth->merge(this->auth, ++ this->ph2_method->get_auth(this->ph2_method), ++ FALSE); ++ } + this->ph2_method->destroy(this->ph2_method); + this->ph2_method = NULL; + /* fall through to NEED_MORE */ +@@ -220,11 +231,18 @@ METHOD(tls_application_t, build, status_t, + return INVALID_STATE; + } + ++METHOD(eap_peap_peer_t, get_auth, auth_cfg_t*, ++ private_eap_peap_peer_t *this) ++{ ++ return this->auth; ++} ++ + METHOD(tls_application_t, destroy, void, + private_eap_peap_peer_t *this) + { + this->server->destroy(this->server); + this->peer->destroy(this->peer); ++ this->auth->destroy(this->auth); + DESTROY_IF(this->ph2_method); + DESTROY_IF(this->out); + this->avp->destroy(this->avp); +@@ -247,10 +265,12 @@ eap_peap_peer_t *eap_peap_peer_create(identification_t *server, + .build = _build, + .destroy = _destroy, + }, ++ .get_auth = _get_auth, + }, + .server = server->clone(server), + .peer = peer->clone(peer), + .ph1_method = eap_method, ++ .auth = auth_cfg_create(), + .avp = eap_peap_avp_create(FALSE), + ); + +diff --git a/src/libcharon/plugins/eap_peap/eap_peap_peer.h b/src/libcharon/plugins/eap_peap/eap_peap_peer.h +index 53c25cd..7d16957 100644 +--- a/src/libcharon/plugins/eap_peap/eap_peap_peer.h ++++ b/src/libcharon/plugins/eap_peap/eap_peap_peer.h +@@ -38,6 +38,13 @@ struct eap_peap_peer_t { + * Implements the TLS application data handler. + */ + tls_application_t application; ++ ++ /** ++ * Get authentication details of this EAP method and its inner method(s). ++ * ++ * @return auth method, internal data ++ */ ++ auth_cfg_t *(*get_auth)(eap_peap_peer_t *this); + }; + + /** +diff --git a/src/libcharon/plugins/eap_peap/eap_peap_server.c b/src/libcharon/plugins/eap_peap/eap_peap_server.c +index 29ab9b4..388c3c6 100644 +--- a/src/libcharon/plugins/eap_peap/eap_peap_server.c ++++ b/src/libcharon/plugins/eap_peap/eap_peap_server.c +@@ -20,6 +20,8 @@ + #include + #include + ++#include ++ + typedef struct private_eap_peap_server_t private_eap_peap_server_t; + + /** +@@ -77,6 +79,16 @@ struct private_eap_peap_server_t { + */ + eap_method_t *ph2_method; + ++ /** ++ * Type of the completed phase 2 EAP method ++ */ ++ eap_type_t phase2_type; ++ ++ /** ++ * Auth data for phase 2 method ++ */ ++ auth_cfg_t *auth; ++ + /** + * Pending outbound EAP message + */ +@@ -132,8 +144,11 @@ static status_t start_phase2_auth(private_eap_peap_server_t *this) + /** + * If configured, start EAP-TNC protocol + */ +-static status_t start_phase2_tnc(private_eap_peap_server_t *this) ++static status_t start_phase2_tnc(private_eap_peap_server_t *this, ++ eap_type_t auth_type) + { ++ eap_inner_method_t *inner_method; ++ + if (this->start_phase2_tnc && lib->settings->get_bool(lib->settings, + "%s.plugins.eap-peap.phase2_tnc", FALSE, lib->ns)) + { +@@ -145,6 +160,8 @@ static status_t start_phase2_tnc(private_eap_peap_server_t *this) + DBG1(DBG_IKE, "%N method not available", eap_type_names, EAP_TNC); + return FAILED; + } ++ inner_method = (eap_inner_method_t *)this->ph2_method; ++ inner_method->set_auth_type(inner_method, auth_type); + this->start_phase2_tnc = FALSE; + + /* synchronize EAP message identifiers of inner protocol with outer */ +@@ -218,9 +235,13 @@ METHOD(tls_application_t, process, status_t, + DBG1(DBG_IKE, "received tunneled EAP-PEAP AVP [EAP/%N]", + eap_code_short_names, code); + in->destroy(in); +- /* if EAP_SUCCESS check if to continue phase2 with EAP-TNC */ +- return (this->phase2_result == EAP_SUCCESS && code == EAP_SUCCESS) ? +- start_phase2_tnc(this) : FAILED; ++ if (this->phase2_result == EAP_SUCCESS && code == EAP_SUCCESS) ++ { ++ /* only accept SUCCESS once after a successful inner method */ ++ this->phase2_result = EAP_FAILURE; ++ return start_phase2_tnc(this, this->phase2_type); ++ } ++ return FAILED; + } + + if (this->ph2_method) +@@ -245,6 +266,10 @@ METHOD(tls_application_t, process, status_t, + if (!received_vendor && received_type == EAP_IDENTITY) + { + chunk_t eap_id; ++ bool peer_auth; ++ ++ peer_auth = lib->settings->get_bool(lib->settings, ++ "%s.plugins.eap-peap.request_peer_auth", FALSE, lib->ns); + + if (this->ph2_method == NULL) + { +@@ -271,9 +296,22 @@ METHOD(tls_application_t, process, status_t, + + if (this->ph2_method->get_msk(this->ph2_method, &eap_id) == SUCCESS) + { +- this->peer->destroy(this->peer); +- this->peer = identification_create_from_data(eap_id); +- DBG1(DBG_IKE, "received EAP identity '%Y'", this->peer); ++ identification_t *id; ++ ++ id = identification_create_from_data(eap_id); ++ if (peer_auth && !id->equals(id, this->peer)) ++ { ++ DBG1(DBG_IKE, "received tunneled EAP identity '%Y', keeping " ++ "certificate-authenticated identity '%Y'", id, this->peer); ++ id->destroy(id); ++ } ++ else ++ { ++ DBG1(DBG_IKE, "received EAP identity '%Y'", id); ++ this->auth->add(this->auth, AUTH_RULE_EAP_IDENTITY, id); ++ this->peer->destroy(this->peer); ++ this->peer = id->clone(id); ++ } + } + + in->destroy(in); +@@ -281,10 +319,9 @@ METHOD(tls_application_t, process, status_t, + this->ph2_method = NULL; + + /* Start Phase 2 of EAP-PEAP authentication */ +- if (lib->settings->get_bool(lib->settings, +- "%s.plugins.eap-peap.request_peer_auth", FALSE, lib->ns)) ++ if (peer_auth) + { +- return start_phase2_tnc(this); ++ return start_phase2_tnc(this, EAP_TLS); + } + else + { +@@ -305,11 +342,26 @@ METHOD(tls_application_t, process, status_t, + switch (status) + { + case SUCCESS: ++ if (this->ph2_method->get_auth) ++ { ++ identification_t *id; ++ auth_cfg_t *auth; ++ ++ auth = this->ph2_method->get_auth(this->ph2_method); ++ id = auth->get(auth, AUTH_RULE_EAP_IDENTITY); ++ if (id) ++ { ++ this->peer->destroy(this->peer); ++ this->peer = id->clone(id); ++ } ++ this->auth->merge(this->auth, auth, FALSE); ++ } + DBG1(DBG_IKE, "%N phase2 authentication of '%Y' with %N successful", + eap_type_names, EAP_PEAP, this->peer, + eap_type_names, type); + this->ph2_method->destroy(this->ph2_method); + this->ph2_method = NULL; ++ this->phase2_type = type; + + /* EAP-PEAP requires the sending of an inner EAP_SUCCESS message */ + this->phase2_result = EAP_SUCCESS; +@@ -407,11 +459,18 @@ METHOD(eap_peap_server_t, set_tls, void, + this->tls = tls; + } + ++METHOD(eap_peap_server_t, get_auth, auth_cfg_t*, ++ private_eap_peap_server_t *this) ++{ ++ return this->auth; ++} ++ + METHOD(tls_application_t, destroy, void, + private_eap_peap_server_t *this) + { + this->server->destroy(this->server); + this->peer->destroy(this->peer); ++ this->auth->destroy(this->auth); + DESTROY_IF(this->ph2_method); + DESTROY_IF(this->out); + this->avp->destroy(this->avp); +@@ -435,10 +494,12 @@ eap_peap_server_t *eap_peap_server_create(identification_t *server, + .destroy = _destroy, + }, + .set_tls = _set_tls, ++ .get_auth = _get_auth, + }, + .server = server->clone(server), + .peer = peer->clone(peer), + .ph1_method = eap_method, ++ .auth = auth_cfg_create(), + .start_phase2 = TRUE, + .start_phase2_tnc = TRUE, + .start_phase2_id = lib->settings->get_bool(lib->settings, +diff --git a/src/libcharon/plugins/eap_peap/eap_peap_server.h b/src/libcharon/plugins/eap_peap/eap_peap_server.h +index 3abe88b..8080e9f 100644 +--- a/src/libcharon/plugins/eap_peap/eap_peap_server.h ++++ b/src/libcharon/plugins/eap_peap/eap_peap_server.h +@@ -47,6 +47,13 @@ struct eap_peap_server_t { + * @param tls TLS connection + */ + void (*set_tls)(eap_peap_server_t *this, tls_t *tls); ++ ++ /** ++ * Get authentication details of this EAP method and its inner method(s). ++ * ++ * @return auth method, internal data ++ */ ++ auth_cfg_t *(*get_auth)(eap_peap_server_t *this); + }; + + /** +diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls.c b/src/libcharon/plugins/eap_ttls/eap_ttls.c +index d8ad781..3df78bb 100644 +--- a/src/libcharon/plugins/eap_ttls/eap_ttls.c ++++ b/src/libcharon/plugins/eap_ttls/eap_ttls.c +@@ -40,6 +40,25 @@ struct private_eap_ttls_t { + * TLS stack, wrapped by EAP helper + */ + tls_eap_t *tls_eap; ++ ++ /** ++ * Role ++ */ ++ bool is_server; ++ ++ /** ++ * Actual server/client implementation ++ */ ++ union { ++ tls_application_t *application; ++ eap_ttls_server_t *server; ++ eap_ttls_peer_t *client; ++ } impl; ++ ++ /** ++ * Cached auth data for TLS and inner EAP methods ++ */ ++ auth_cfg_t *auth; + }; + + /** Maximum number of EAP-TTLS messages/fragments allowed */ +@@ -116,13 +135,31 @@ METHOD(eap_method_t, is_mutual, bool, + METHOD(eap_method_t, get_auth, auth_cfg_t*, + private_eap_ttls_t *this) + { +- return this->tls_eap->get_auth(this->tls_eap); ++ if (!this->auth) ++ { ++ auth_cfg_t *inner; ++ ++ this->auth = auth_cfg_create(); ++ this->auth->merge(this->auth, ++ this->tls_eap->get_auth(this->tls_eap), FALSE); ++ if (this->is_server) ++ { ++ inner = this->impl.server->get_auth(this->impl.server); ++ } ++ else ++ { ++ inner = this->impl.client->get_auth(this->impl.client); ++ } ++ this->auth->merge(this->auth, inner, FALSE); ++ } ++ return this->auth; + } + + METHOD(eap_method_t, destroy, void, + private_eap_ttls_t *this) + { + this->tls_eap->destroy(this->tls_eap); ++ DESTROY_IF(this->auth); + free(this); + } + +@@ -153,6 +190,10 @@ static eap_ttls_t *eap_ttls_create(identification_t *server, + .destroy = _destroy, + }, + }, ++ .is_server = is_server, ++ .impl = { ++ .application = application, ++ }, + ); + if (is_server && !lib->settings->get_bool(lib->settings, + "%s.plugins.eap-ttls.request_peer_auth", FALSE, +diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_peer.c b/src/libcharon/plugins/eap_ttls/eap_ttls_peer.c +index 63126a5..f8229f5 100644 +--- a/src/libcharon/plugins/eap_ttls/eap_ttls_peer.c ++++ b/src/libcharon/plugins/eap_ttls/eap_ttls_peer.c +@@ -54,6 +54,11 @@ struct private_eap_ttls_peer_t { + */ + eap_method_t *method; + ++ /** ++ * Auth data for phase 2 method ++ */ ++ auth_cfg_t *auth; ++ + /** + * Pending outbound EAP message + */ +@@ -215,6 +220,11 @@ METHOD(tls_application_t, process, status_t, + switch (status) + { + case SUCCESS: ++ if (this->method->get_auth) ++ { ++ this->auth->merge(this->auth, ++ this->method->get_auth(this->method), FALSE); ++ } + this->method->destroy(this->method); + this->method = NULL; + /* fall through to NEED_MORE */ +@@ -275,11 +285,18 @@ METHOD(tls_application_t, build, status_t, + return INVALID_STATE; + } + ++METHOD(eap_ttls_peer_t, get_auth, auth_cfg_t*, ++ private_eap_ttls_peer_t *this) ++{ ++ return this->auth; ++} ++ + METHOD(tls_application_t, destroy, void, + private_eap_ttls_peer_t *this) + { + this->server->destroy(this->server); + this->peer->destroy(this->peer); ++ this->auth->destroy(this->auth); + DESTROY_IF(this->method); + DESTROY_IF(this->out); + this->avp->destroy(this->avp); +@@ -301,10 +318,12 @@ eap_ttls_peer_t *eap_ttls_peer_create(identification_t *server, + .build = _build, + .destroy = _destroy, + }, ++ .get_auth = _get_auth, + }, + .server = server->clone(server), + .peer = peer->clone(peer), + .start_phase2 = TRUE, ++ .auth = auth_cfg_create(), + .avp = eap_ttls_avp_create(), + ); + +diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_peer.h b/src/libcharon/plugins/eap_ttls/eap_ttls_peer.h +index 0c3d90a..69a8435 100644 +--- a/src/libcharon/plugins/eap_ttls/eap_ttls_peer.h ++++ b/src/libcharon/plugins/eap_ttls/eap_ttls_peer.h +@@ -37,6 +37,13 @@ struct eap_ttls_peer_t { + * Implements the TLS application data handler. + */ + tls_application_t application; ++ ++ /** ++ * Get authentication details of this EAP method and its inner method(s). ++ * ++ * @return auth method, internal data ++ */ ++ auth_cfg_t *(*get_auth)(eap_ttls_peer_t *this); + }; + + /** +diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_server.c b/src/libcharon/plugins/eap_ttls/eap_ttls_server.c +index fc97f81..e1de1bf 100644 +--- a/src/libcharon/plugins/eap_ttls/eap_ttls_server.c ++++ b/src/libcharon/plugins/eap_ttls/eap_ttls_server.c +@@ -60,6 +60,11 @@ struct private_eap_ttls_server_t { + */ + eap_method_t *method; + ++ /** ++ * Auth data for phase 2 method ++ */ ++ auth_cfg_t *auth; ++ + /** + * Pending outbound EAP message + */ +@@ -220,6 +225,10 @@ METHOD(tls_application_t, process, status_t, + if (!received_vendor && received_type == EAP_IDENTITY) + { + chunk_t eap_id; ++ bool peer_auth; ++ ++ peer_auth = lib->settings->get_bool(lib->settings, ++ "%s.plugins.eap-ttls.request_peer_auth", FALSE, lib->ns); + + if (this->method == NULL) + { +@@ -244,9 +253,22 @@ METHOD(tls_application_t, process, status_t, + + if (this->method->get_msk(this->method, &eap_id) == SUCCESS) + { +- this->peer->destroy(this->peer); +- this->peer = identification_create_from_data(eap_id); +- DBG1(DBG_IKE, "received EAP identity '%Y'", this->peer); ++ identification_t *id; ++ ++ id = identification_create_from_data(eap_id); ++ if (peer_auth && !id->equals(id, this->peer)) ++ { ++ DBG1(DBG_IKE, "received tunneled EAP identity '%Y', keeping " ++ "certificate-authenticated identity '%Y'", id, this->peer); ++ id->destroy(id); ++ } ++ else ++ { ++ DBG1(DBG_IKE, "received EAP identity '%Y'", id); ++ this->auth->add(this->auth, AUTH_RULE_EAP_IDENTITY, id); ++ this->peer->destroy(this->peer); ++ this->peer = id->clone(id); ++ } + } + + in->destroy(in); +@@ -254,8 +276,7 @@ METHOD(tls_application_t, process, status_t, + this->method = NULL; + + /* Start Phase 2 of EAP-TTLS authentication */ +- if (lib->settings->get_bool(lib->settings, +- "%s.plugins.eap-ttls.request_peer_auth", FALSE, lib->ns)) ++ if (peer_auth) + { + return start_phase2_tnc(this, EAP_TLS); + } +@@ -278,6 +299,20 @@ METHOD(tls_application_t, process, status_t, + switch (status) + { + case SUCCESS: ++ if (this->method->get_auth) ++ { ++ identification_t *id; ++ auth_cfg_t *auth; ++ ++ auth = this->method->get_auth(this->method); ++ id = auth->get(auth, AUTH_RULE_EAP_IDENTITY); ++ if (id) ++ { ++ this->peer->destroy(this->peer); ++ this->peer = id->clone(id); ++ } ++ this->auth->merge(this->auth, auth, FALSE); ++ } + DBG1(DBG_IKE, "%N phase2 authentication of '%Y' with %N successful", + eap_type_names, EAP_TTLS, this->peer, + eap_type_names, type); +@@ -348,11 +383,18 @@ METHOD(tls_application_t, build, status_t, + return INVALID_STATE; + } + ++METHOD(eap_ttls_server_t, get_auth, auth_cfg_t*, ++ private_eap_ttls_server_t *this) ++{ ++ return this->auth; ++} ++ + METHOD(tls_application_t, destroy, void, + private_eap_ttls_server_t *this) + { + this->server->destroy(this->server); + this->peer->destroy(this->peer); ++ this->auth->destroy(this->auth); + DESTROY_IF(this->method); + DESTROY_IF(this->out); + this->avp->destroy(this->avp); +@@ -374,11 +416,13 @@ eap_ttls_server_t *eap_ttls_server_create(identification_t *server, + .build = _build, + .destroy = _destroy, + }, ++ .get_auth = _get_auth, + }, + .server = server->clone(server), +- .peer = peer->clone(peer), ++ .auth = auth_cfg_create(), + .start_phase2 = TRUE, + .start_phase2_tnc = TRUE, ++ .peer = peer->clone(peer), + .avp = eap_ttls_avp_create(), + ); + +diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_server.h b/src/libcharon/plugins/eap_ttls/eap_ttls_server.h +index 1e13f55..3348706 100644 +--- a/src/libcharon/plugins/eap_ttls/eap_ttls_server.h ++++ b/src/libcharon/plugins/eap_ttls/eap_ttls_server.h +@@ -37,6 +37,13 @@ struct eap_ttls_server_t { + * Implements the TLS application data handler. + */ + tls_application_t application; ++ ++ /** ++ * Get authentication details of this EAP method and its inner method(s). ++ * ++ * @return auth method, internal data ++ */ ++ auth_cfg_t *(*get_auth)(eap_ttls_server_t *this); + }; + + /** diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb index 5ddc3c32b9..5421ecf8f9 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb @@ -20,6 +20,7 @@ SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ file://CVE-2026-78130.patch \ file://CVE-2026-78132.patch \ file://CVE-2026-78135.patch \ + file://CVE-2026-78134.patch \ " SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c" From patchwork Thu Sep 24 04:33:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99131 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DBBB7C98314 for ; Thu, 24 Sep 2026 04:34:05 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.733.1790224436167171509 for ; Wed, 23 Sep 2026 21:33:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=B7hXuWAU; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-86e6d007703so877720b3a.0 for ; Wed, 23 Sep 2026 21:33:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224435; x=1790829235; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VOPsiIuLflelx5nYfMfvki3WyuWrMiONoEzn8gPE17w=; b=B7hXuWAUCIsT1yQtL41oaoTC/+wL+vgnLQzpRD7A+MJTrxJyFdDrGkbXGynOsXXyjK o6+mnjXU432sE/PNc0RlSp2efUEg0UC+WrOVRooAH3WYt4fATnfNCEfjlwbS6C44ci45 JnUuyc2WCHCkqsGKkNuMCiH0Ie2L7d53ihjdkSR5+Ureq2zcILr7aR+DIDiJhvmLLUfk yP/CyJM+8lxkzWHEGbTp4/TrOL87T4uCtjhCsyt3p1bU7GNapA8aWoPZa1Y+qN0naupj 6J2xmLtN5nxschpxDbxxzQ7As7W26Fbyz/ePo381OCJCaDsRFM2lcTWEBp97VJeBete/ NPdg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224435; x=1790829235; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VOPsiIuLflelx5nYfMfvki3WyuWrMiONoEzn8gPE17w=; b=O/L9VxjJMWdpASCdLr6PI8pUk2r2AFaFzbzRURK04xX6lLoNAZdf12dORp4cNMVR3C DC9rfSlqDDScqRPEIRKqEQ13OGCrYPYQmJRByhQGc68YT1Z+dNHwH9cziaybxOHqj/NQ utd7ViXZU5aG9SssFMF+cTTzklIf5bf+mxqYaEzHono7a7k6/eNK6o47zgAR7nTZhHLJ nXNUxqEa1nuTjtubvI2J1TDEQkfKce5Dfq20w8d9W2y+FHuE9BohIINOJmyeWLAPq72w FYqG8z5MQ9K7268NN9c+yugi7DCTF+ZxriIrBRTdTFza0z6nxKz9evIUoDxpuhKh5kvA 0Ueg== X-Gm-Message-State: AFuF++kaWZLjHv9P+NPMaBbh8zVUCNUmFJRN8ZSjKYHwcQl+R7ptwb/o +lTQNc5x+j2nY5MNUdPnfANynRgeOg/wWTEHC9JirafyidjAO+tJwKxJNLb0jA== X-Gm-Gg: AYBFou19S08tF7mUOKvmXMXyNnyoz8wDYPOGvbbAQ5OEpAfNiVEtjPMqyvnK06NBafq LnGWns1C68d6IQVzkpMdUcYX0YEQ5LHJr4GH2cbE+8bK2FUWEB9B8lr7VKvgZwKaw0KBIq9dxtr MgVnv2rx42/WoX/jJt6TIq6A3C8eOuCB6Ms5fMfZlxzkzVL3k5ta2YoQvKXvLdX54SAw0IOO5jX LnopgzurRyp2Eibj9s9yP6u4WK9Ye7s/fHYygLHEZQ0DtdxPpD9e3fASHikdzW4ZXa1ncA9Y9DL MJPx6cY9lxSccXfTr2BIR/09duPYbPw77X33t+fv1DdvzHmDYfleu0VlCj6I+66ypU8LHdfolKX HgrEhmvUi9S/Xc0FgNgamcxiyxAromx5rEnsDYrx6u0y97LZY5TukZZpKQAc3JEHrLyky8APBr/ nJPnX18/5cMJ2ToUt/r1RBD5L/47w7DlIbg69l72kHDf+ztEvMDG3Qn6cxw6jj9RxzNfvD44bqK XsM8QXFnj0w2Foy4myrW5tKGCGf04CFow== X-Received: by 2002:a05:6a00:ad02:b0:878:3538:8f82 with SMTP id d2e1a72fcca58-87e9f824483mr1058897b3a.48.1790224435483; Wed, 23 Sep 2026 21:33:55 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:55 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 16/24] tesseract: patch CVE-2026-88052 Date: Thu, 24 Sep 2026 16:33:06 +1200 Message-ID: <20260924043315.1663186-16-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130264 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88052 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88052.patch | 165 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 166 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88052.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88052.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88052.patch new file mode 100644 index 0000000000..fb21f6eb02 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88052.patch @@ -0,0 +1,165 @@ +From 26355d536f148a45a43cfe8b5b5f4a748d99fe8e Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 18:34:33 +0200 +Subject: [PATCH] Reject unicharset files whose inserts desync id from unichars + +UNICHARSET::load_via_fgets reads the unichar count via sscanf and +trusts it as the loop bound, indexing the unichars vector with the +loop index id via the unchecked set_* accessors. unichar_insert is a +no-op for duplicate (or empty) representations, so once any insert +no-ops, unichars.size() falls behind id and the subsequent +set_*(id, ...) and unichars[id].properties writes land past the end +of the vector - a deterministic heap out-of-bounds write (including a +std::string assignment via set_normed) for every remaining line, on +both the LSTM and legacy init paths. A malformed unicharset with a +duplicate line (e.g. two identical entries) triggers it; a +non-positive header count likewise loads an empty unicharset +"successfully". + +Key changes: +- unicharset.cpp: reject unicharset_size <= 0, and after each insert + verify the vector actually grew to id + 1; on mismatch report the + offending line and reject the file instead of writing out of bounds. +- unittest: add unicharset_load_test with a duplicate-representation + unicharset (on unpatched code the test dies on the + container-overflow in load_via_fgets), a zero and a negative count, + and a positive control that a valid unicharset still loads. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit 2d04d640db2e8c7e3bab2369d599343b5a8b8443) + +CVE: CVE-2026-88052 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/2d04d640db2e8c7e3bab2369d599343b5a8b8443] +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 +++ + src/ccutil/unicharset.cpp | 12 ++++++ + unittest/unicharset_load_test.cc | 64 ++++++++++++++++++++++++++++++++ + 3 files changed, 81 insertions(+) + create mode 100644 unittest/unicharset_load_test.cc + +diff --git a/Makefile.am b/Makefile.am +index 9f2a367d..1a0a6771 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1249,6 +1249,7 @@ check_PROGRAMS += tfile_test + if ENABLE_TRAINING + check_PROGRAMS += unichar_test + check_PROGRAMS += unicharcompress_test ++check_PROGRAMS += unicharset_load_test + check_PROGRAMS += unicharset_test + check_PROGRAMS += validate_grapheme_test + check_PROGRAMS += validate_indic_test +@@ -1522,6 +1523,10 @@ unicharcompress_test_SOURCES = unittest/unicharcompress_test.cc + unicharcompress_test_CPPFLAGS = $(unittest_CPPFLAGS) + unicharcompress_test_LDADD = $(TRAINING_LIBS) $(ICU_UC_LIBS) + ++unicharset_load_test_SOURCES = unittest/unicharset_load_test.cc ++unicharset_load_test_CPPFLAGS = $(unittest_CPPFLAGS) ++unicharset_load_test_LDADD = $(TESS_LIBS) ++ + unicharset_test_SOURCES = unittest/unicharset_test.cc + unicharset_test_CPPFLAGS = $(unittest_CPPFLAGS) + unicharset_test_LDADD = $(TRAINING_LIBS) $(ICU_UC_LIBS) +diff --git a/src/ccutil/unicharset.cpp b/src/ccutil/unicharset.cpp +index b29ec3b7..0e72ae48 100644 +--- a/src/ccutil/unicharset.cpp ++++ b/src/ccutil/unicharset.cpp +@@ -791,6 +791,9 @@ bool UNICHARSET::load_via_fgets( + sscanf(buffer, "%d", &unicharset_size) != 1) { + return false; + } ++ if (unicharset_size <= 0) { ++ return false; ++ } + for (UNICHAR_ID id = 0; id < unicharset_size; ++id) { + char unichar[256]; + unsigned int properties; +@@ -884,6 +887,15 @@ bool UNICHARSET::load_via_fgets( + } else { + this->unichar_insert_backwards_compatible(unichar); + } ++ // A duplicate or empty representation makes the insert a no-op, ++ // desynchronizing id from the unichars vector; the set_* calls and ++ // unichars[id] below would then write out of bounds. The file is ++ // malformed, so reject it. ++ if (size() != static_cast(id) + 1) { ++ fprintf(stderr, "%s:%d unichar %d has a duplicate or empty representation\n", ++ __FILE__, __LINE__, id); ++ return false; ++ } + + this->set_isalpha(id, properties & ISALPHA_MASK); + this->set_islower(id, properties & ISLOWER_MASK); +diff --git a/unittest/unicharset_load_test.cc b/unittest/unicharset_load_test.cc +new file mode 100644 +index 00000000..d775e233 +--- /dev/null ++++ b/unittest/unicharset_load_test.cc +@@ -0,0 +1,64 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: unicharset_load_test.cc ++// Description: Tests that UNICHARSET::load_via_fgets rejects unicharset ++// files whose insertions desynchronize the id loop index ++// from the unichars vector (duplicate or empty ++// representations), which would make the subsequent set_* ++// calls write out of bounds, and non-positive size counts. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "serialis.h" // for TFile ++#include "unicharset.h" ++ ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Loads the given unicharset text via the TFile-based loader. ++bool LoadUnicharset(const char *text, UNICHARSET *unicharset) { ++ TFile fp; ++ if (!fp.Open(text, std::strlen(text))) { ++ return false; ++ } ++ return unicharset->load_from_file(&fp, false); ++} ++ ++// A duplicate representation makes the second insert a no-op, so on ++// unpatched code the set_* calls for the remaining lines write past ++// the end of the unichars vector (ASan container-overflow). ++TEST(UnicharsetLoadTest, RejectsDuplicateRepresentation) { ++ const char *text = "3\nA 0 Latin\nA 0 Latin\nB 0 Latin\n"; ++ UNICHARSET unicharset; ++ EXPECT_FALSE(LoadUnicharset(text, &unicharset)); ++} ++ ++// A non-positive size count must be rejected; on unpatched code a ++// zero or negative count loads an empty unicharset successfully. ++TEST(UnicharsetLoadTest, RejectsNonPositiveCount) { ++ const char *texts[] = {"0\n", "-1\n"}; ++ for (const char *text : texts) { ++ UNICHARSET unicharset; ++ EXPECT_FALSE(LoadUnicharset(text, &unicharset)); ++ } ++} ++ ++// A valid unicharset must still be accepted. ++TEST(UnicharsetLoadTest, AcceptsValidUnicharset) { ++ const char *text = "3\nA 0 Latin\nB 0 Latin\nC 0 Latin\n"; ++ UNICHARSET unicharset; ++ ASSERT_TRUE(LoadUnicharset(text, &unicharset)); ++ EXPECT_EQ(unicharset.size(), 3u); ++ EXPECT_STREQ(unicharset.id_to_unichar(1), "B"); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index f26d2f36a1..a80407b749 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -10,6 +10,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-73066.patch \ file://CVE-2026-73067-1.patch \ file://CVE-2026-73067-2.patch \ + file://CVE-2026-88052.patch \ " From patchwork Thu Sep 24 04:33:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99129 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DA065C98310 for ; Thu, 24 Sep 2026 04:34:04 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.735.1790224438342697561 for ; Wed, 23 Sep 2026 21:33:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=DTrXdF37; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469a34907so1363792b3a.1 for ; Wed, 23 Sep 2026 21:33:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224438; x=1790829238; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HKOjw8j9leOqH4d9txEHvtH56wQu9n/u4sC/XxHsZHM=; b=DTrXdF37t4iua3qxkEsuhO0P0xlN/WnsRlUVe0efoHqPgTJsrRLeMLG8lBm9pAesnM JswrycRpDoWhHGMnhdpxWiHHr7szL4/0T08vsEaoEE6G4zI0bNO1oF6KRcaPxIbz5yPT 5Di14ZzC9Fx6jMMbVri0Wl/kIPhZKKD4o/jKYQTRfvwpO3NyQuFrIyQtDc3uNRDnhDYA wg9ROM1oIPBGMiy07Mt6XF6/b1prP+2B1O187RYtu/Ms7g7wXIQzT2xYq8oxNkuVE24m jLXKkzwqniQGCI0c8iMTC+74jBptTomp+HZRjVREtScn6YZlpfPt/RwmF4EqkQVhchqt HaQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224438; x=1790829238; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HKOjw8j9leOqH4d9txEHvtH56wQu9n/u4sC/XxHsZHM=; b=ejRPX8H3Lm542H78asROvPkK6IbwvVsfeaCYhMKIw/ZWppyk5otyZu6AOc5FyYnh9O OYl8Fn6ygHy14CacQYU5tLd7vJ8M1tklj6jpe+vwVcrKZupaGQi4g6n91yOMELqX7vvx 5XRQOrjLijKXdO32FEsVWBjcRi/uq3C/svRwI8UOgs6P3pfv3/MMEd3Cx3WWoWjO8POz TW3+CRMRxwz/UrP/zp0egi3k7rBVotAOknCuMWEUQp/WAvTySMNodZkGxrdI/gv7ICev uVjpJ0sI2jJBqOu7+m12P3lFm61taCDqFnO/iaWrXuVU6lNQM2O/GlMHMDr9M0X1y94g IjMg== X-Gm-Message-State: AFuF++kAsZ3aY+NnHw03kh73EbRBN9GrEC5Kw6Pjgxk0hrpgFDZQsFWd zVv3mJzOPQx18ca7o4z8R+cpcWmxYLP5Vrir3ewPM568+2z6mGoTIHlKseQhkg== X-Gm-Gg: AYBFou04xtO2w3GGPUMKcWRRCxqfeZ/DMgSJeyXcpfPEYXijhBy0cg9UFDe5myAkPtm CQoFMxUjk3CgK8EOsPLr0Idb/G6VExvWe28uA6jVHub6neN/B+8bS4x/XoiM/ouvLcSiGTXfmld mTi43lCjrZvXMpZtxY0FQOfqDQERPXIwA6mYN1tcz9lIPmw0GoeAwUMrz3nU0DXQB1qW460RurA dGrW3gO59SF04s54R8jhhWIKp29KflPe14FfxoWFdHCTdiM5bAETNzhsg4GJqIuI5yX9I3QQGCU F/djvRDRTpAGTD04Ia3YZ4HsKXm/GKLJYslmnhPWBGdtRj3WHOjydsHI7exaRjZXw/8YBW3hF22 QcqcnaThwBVwNidOJKj8oGIILP3Z0OX/9Byxv30CLnswDQpUepmOJqYaf0EEqENarbVCjk0dr+j yDkJRJz0rVrpidZlOVp/OubO6uo5YSaWzERJlaCucAhUzz9nCreFQxYMMtpi1x/Hu6Eb092zEwe SGQegH905uSWdFUkyd4J/FPYKUPVOuUMw== X-Received: by 2002:a05:6a20:4e92:b0:3da:755f:a031 with SMTP id adf61e73a8af0-3de0e7f76e6mr1327395637.12.1790224437602; Wed, 23 Sep 2026 21:33:57 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:57 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 17/24] tesseract: patch CVE-2026-88048 Date: Thu, 24 Sep 2026 16:33:07 +1200 Message-ID: <20260924043315.1663186-17-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130265 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88048 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88048.patch | 228 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 229 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88048.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88048.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88048.patch new file mode 100644 index 0000000000..bc1beb5753 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88048.patch @@ -0,0 +1,228 @@ +From 4dd118c5b87df1a4422ebb3ab3efaa3588b88cfa Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 15:23:59 +0200 +Subject: [PATCH] Validate FullyConnected weight matrix dimensions at load + +FullyConnected::DeSerialize read the WeightMatrix without checking +that its dimensions match the layer's declared ni/no. MatrixDotVector +drives the dot product from the matrix dimensions (writes w.dim1() +results, reads w.dim2()-1 inputs) while the scratch buffers are sized +from no_ and ni_, so a crafted .traineddata with a mismatched matrix +performed a heap out-of-bounds write (up to 65535 rows) and out-of- +bounds read on the first recognition step (crash, or heap corruption +with attacker-influenced size and content). + +Key changes: +- weightmatrix.h: add Dim1()/Dim2() accessors for the active weight + matrix (int or float), alongside the existing NumOutputs(). +- fullyconnected.cpp: reject the layer in DeSerialize unless + Dim1() == no_ and Dim2() == ni_ + 1 (the second dimension + includes the bias column), the layout that InitWeightsFloat + always produces. +- unittest: new fullyconnected_test that builds a Softmax network + with mismatched matrix dimensions and expects CreateFromFile to + return nullptr; on unpatched code the test reaches Forward and + ASan catches the out-of-bounds write in MatrixDotVector. A + second test verifies that matching dimensions are still accepted. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit 103dc134eb36411ddc6833ec20aa2c76795bd0ff) + +CVE: CVE-2026-88048 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/103dc134eb36411ddc6833ec20aa2c76795bd0ff] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 ++ + src/lstm/fullyconnected.cpp | 11 ++- + src/lstm/weightmatrix.h | 7 ++ + unittest/fullyconnected_test.cc | 115 ++++++++++++++++++++++++++++++++ + 4 files changed, 137 insertions(+), 1 deletion(-) + create mode 100644 unittest/fullyconnected_test.cc + +diff --git a/Makefile.am b/Makefile.am +index 1a0a6771..ea722409 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1187,6 +1187,7 @@ if !DISABLED_LEGACY_ENGINE + check_PROGRAMS += equationdetect_test + endif # !DISABLED_LEGACY_ENGINE + check_PROGRAMS += fileio_test ++check_PROGRAMS += fullyconnected_test + check_PROGRAMS += heap_test + check_PROGRAMS += imagedata_test + if !DISABLED_LEGACY_ENGINE +@@ -1319,6 +1320,10 @@ fileio_test_SOURCES = unittest/fileio_test.cc + fileio_test_CPPFLAGS = $(unittest_CPPFLAGS) + fileio_test_LDADD = $(TRAINING_LIBS) + ++fullyconnected_test_SOURCES = unittest/fullyconnected_test.cc ++fullyconnected_test_CPPFLAGS = $(unittest_CPPFLAGS) ++fullyconnected_test_LDADD = $(TESS_LIBS) ++ + heap_test_SOURCES = unittest/heap_test.cc + heap_test_CPPFLAGS = $(unittest_CPPFLAGS) + heap_test_LDADD = $(TESS_LIBS) +diff --git a/src/lstm/fullyconnected.cpp b/src/lstm/fullyconnected.cpp +index 85989f40..380707a1 100644 +--- a/src/lstm/fullyconnected.cpp ++++ b/src/lstm/fullyconnected.cpp +@@ -121,7 +121,16 @@ bool FullyConnected::Serialize(TFile *fp) const { + + // Reads from the given file. Returns false in case of error. + bool FullyConnected::DeSerialize(TFile *fp) { +- return weights_.DeSerialize(IsTraining(), fp); ++ if (!weights_.DeSerialize(IsTraining(), fp)) { ++ return false; ++ } ++ // The weight matrix must match the declared sizes (the second dimension ++ // includes the bias column); otherwise Forward would read or write ++ // outside the scratch buffers sized from ni_ and no_. ++ if (weights_.Dim1() != no_ || weights_.Dim2() != ni_ + 1) { ++ return false; ++ } ++ return true; + } + + // Runs forward propagation of activations on the input line. +diff --git a/src/lstm/weightmatrix.h b/src/lstm/weightmatrix.h +index a2cdaa52..66b69dfa 100644 +--- a/src/lstm/weightmatrix.h ++++ b/src/lstm/weightmatrix.h +@@ -107,6 +107,13 @@ public: + int NumOutputs() const { + return int_mode_ ? wi_.dim1() : wf_.dim1(); + } ++ // The dimensions of the active weight matrix (wi_ in int mode, else wf_). ++ int Dim1() const { ++ return int_mode_ ? wi_.dim1() : wf_.dim1(); ++ } ++ int Dim2() const { ++ return int_mode_ ? wi_.dim2() : wf_.dim2(); ++ } + // Provides one set of weights. Only used by peep weight maxpool. + const TFloat *GetWeights(int index) const { + return wf_[index]; +diff --git a/unittest/fullyconnected_test.cc b/unittest/fullyconnected_test.cc +new file mode 100644 +index 00000000..f9697de4 +--- /dev/null ++++ b/unittest/fullyconnected_test.cc +@@ -0,0 +1,115 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: fullyconnected_test.cc ++// Description: Tests that a FullyConnected (softmax) network layer with ++// weight-matrix dimensions that do not match the declared ++// ni/no is rejected at load. Without the check, ++// MatrixDotVector writes w.dim1() results into a scratch ++// buffer sized from no_ and reads w.dim2()-1 inputs from ++// a buffer sized from ni_ (heap out-of-bounds write/read) ++// on the first recognition step. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "network.h" // for Network, NetworkType ++#include "networkio.h" ++#include "networkscratch.h" ++#include "serialis.h" // for TFile ++ ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Appends raw little-endian values to a byte buffer. ++class ByteWriter { ++public: ++ void PutU8(uint32_t v) { data_.push_back(static_cast(v & 0xFF)); } ++ void PutU32(uint32_t v) { ++ for (int i = 0; i < 4; ++i) { ++ data_.push_back(static_cast((v >> (8 * i)) & 0xFF)); ++ } ++ } ++ void PutS32(int32_t v) { PutU32(static_cast(v)); } ++ const std::vector &data() const { return data_; } ++ ++private: ++ std::vector data_; ++}; ++ ++void PutDoubleLE(ByteWriter *w, double d) { ++ union { ++ double d; ++ uint64_t u; ++ } conv; ++ conv.d = d; ++ w->PutU32(static_cast(conv.u & 0xFFFFFFFF)); ++ w->PutU32(static_cast(conv.u >> 32)); ++} ++ ++// Builds a serialized NT_SOFTMAX network: header with the given ni/no, ++// then a float-mode WeightMatrix with the given (corrupt) dimensions. ++// The matrix is stored as doubles on disk (see WeightMatrix::DeSerialize). ++std::vector MakeSoftmaxNetwork(int ni, int no, int32_t dim1, int32_t dim2) { ++ ByteWriter w; ++ w.PutU8(static_cast(NT_SOFTMAX)); ++ w.PutU8(0); // training: TS_DISABLED ++ w.PutU8(0); // needs_to_backprop ++ w.PutU32(0); // network_flags ++ w.PutU32(static_cast(ni)); ++ w.PutU32(static_cast(no)); ++ w.PutU32(0); // num_weights (not cross-checked, kept consistent anyway) ++ w.PutU32(0); // name (empty string) ++ // WeightMatrix::DeSerialize: ++ w.PutU8(128); // mode: kDoubleFlag, float mode ++ w.PutS32(dim1); ++ w.PutS32(dim2); ++ PutDoubleLE(&w, 0.0); // empty_ cell ++ for (int32_t i = 0; i < dim1 * dim2; ++i) { ++ PutDoubleLE(&w, 0.0); // weight data ++ } ++ return w.data(); ++} ++ ++// A FullyConnected layer whose weight matrix does not match the declared ++// sizes must be rejected by CreateFromFile; on unpatched code the test ++// reaches Forward, where MatrixDotVector performs the out-of-bounds ++// write this regression test guards against. ++TEST(FullyconnectedTest, RejectsWeightMatrixDimensionMismatch) { ++ // ni_=no_=1 but dim1=3 (OOB write of 3 results into a 1-result buffer) ++ // and dim2=5 (OOB read of 4 inputs from a 1-input buffer). ++ std::vector bytes = MakeSoftmaxNetwork(1, 1, 3, 5); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ if (net == nullptr) { ++ return; // Fixed: the mismatched layer is rejected at load. ++ } ++ NetworkIO input; ++ input.Resize2d(false, /*width=*/1, /*num_features=*/1); ++ NetworkScratch scratch; ++ NetworkIO output; ++ net->Forward(false, input, nullptr, &scratch, &output); ++ delete net; ++ FAIL() << "crafted FullyConnected layer with mismatched weight matrix was accepted"; ++} ++ ++// Consistent dimensions must still be accepted. ++TEST(FullyconnectedTest, AcceptsMatchingDimensions) { ++ std::vector bytes = MakeSoftmaxNetwork(1, 2, 2, 2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ ASSERT_NE(net, nullptr); ++ delete net; ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index a80407b749..a8b3e55c7d 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -11,6 +11,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-73067-1.patch \ file://CVE-2026-73067-2.patch \ file://CVE-2026-88052.patch \ + file://CVE-2026-88048.patch \ " From patchwork Thu Sep 24 04:33:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99132 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0640DC98304 for ; Thu, 24 Sep 2026 04:34:05 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.738.1790224440520370271 for ; Wed, 23 Sep 2026 21:34:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=WC4M29cn; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so793616b3a.0 for ; Wed, 23 Sep 2026 21:34:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224440; x=1790829240; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TzSXAoHqmEJVaPCu8o7JnI1isEp3RttYWKL4Quo+/iQ=; b=WC4M29cn5gW78zDhocq6iXHUeDldm+nmixxojfewtRCZ/EWcACJlQNraRyd6pogcDU GEgzHP3BQHttTFyKtQOEBSa3p4McVQnkyWCcDDd6nnTmSeOD171D7QeI5cziR1x/R1vF wBTxFRQYt8e+hInsjfvNtXrbsn6Zd7qsPSOxoUaV1tqM618QhjyRylTQorUlWTGY3w+7 AgwwKKZ05fNfvBQh6/T+nx591AADwx5g7GJNGI4lC1BSO3Mb59y5LdsJt/qQ31s/0LJy rzoIyt9FK15b/G8LruYZY0vZSXcmljJrvnUWVk/SbcI0i18Rrk+9MhkIUVNi0i0CUFgS +XTQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224440; x=1790829240; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TzSXAoHqmEJVaPCu8o7JnI1isEp3RttYWKL4Quo+/iQ=; b=FnrQ8LtONt3SN2Wu7Yxl6LewFERiuYG25/91Nu31+WitQIakyqSIeJ3Mtaa8JOLgqu Va04jKC7riQlBYpkmXVH7LE6/3ysE0P5fl3IH1xsFGMPqZWVGKcxXod5DywngEj+5EyU OFmYAWix6hkKnDY+m4b6wlX4fljRFi9mBG+aZK/ojCvxg+486hIO3Vs3rDnghl71Tu49 peLirq8Hw1ctGtcrxwvVTtwhEgsrg5xfA2BkZW93NwaencOM+sdUNWsNCDV0VmEv/koR qULKxVD9EooOxob7xhVgUj/1OibWUy//+CQvquIjJ9KoqJ6MQwEgESfK9lbhDQrWTG91 b7Aw== X-Gm-Message-State: AFuF++kD6aEa+HB4Kaa330fpcFl2cnclbltEQA1CtNZZ0aXNIWGi5uJX ccQ+q274MJ5HNBf8E8v3Jrg0tDI8G6fliJuEFSNUCqnt7W6MmKlwKcSa4T4HUA== X-Gm-Gg: AYBFou3odnNo6r6x80KNJXkidHEUzA4l1HW2YqcnrhNVT1xEcF2qwzb3R0LUcqdGBdW 1EoORPwlZ1BPUzog+D+2T1GsGYbRyf7OaVD92fTdT2Z9KyyDOTXRxSQDZuONWJm9bHEhbypr1eg v0PnRtBppD3j7zXyto5LjHRziKghDe3I2I+BtAOdR4dBP0qdpzz6Z2f0djPZCKm4NtT3A1qmQIe Ex+zA7HE/nbS2URO6ZifnzeWfzhMu+zsrj1ls592B6DhzSVwGX/AiaUSBcl5EdlCqOIEp/mrRr0 5G9FukQjrgqzr3dXDJB3+WSOXlRT4iXAi59OEInZbFWhWGzOOMwXNo+nrQSozdLr+60r12HXjEB R27cGbR1WBjJroQDhZPT3B76Db64vlUFuhmfLCs+RqyYubFasHIkmF4maxD1eHW7pLjkvYkqS0/ HmVImThDoQOaoqo1Zs5hfScjrHnvnetBGNVcui+YbZKwzYUgCpocjxQX9mw2LTcvPcziFnTKsd3 tDbkvvkcwGQg4yaeefo5lQ= X-Received: by 2002:a05:6a00:a244:b0:878:d57a:6d03 with SMTP id d2e1a72fcca58-87e9b79bcaamr964660b3a.45.1790224439766; Wed, 23 Sep 2026 21:33:59 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.33.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:33:59 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 18/24] tesseract: patch CVE-2026-88049 Date: Thu, 24 Sep 2026 16:33:08 +1200 Message-ID: <20260924043315.1663186-18-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130266 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88049 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88049.patch | 316 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 317 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88049.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88049.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88049.patch new file mode 100644 index 0000000000..d7528e1825 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88049.patch @@ -0,0 +1,316 @@ +From 2a118419439d1bfeb2bf8a78732a0fb2ad33475d Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 16:41:51 +0200 +Subject: [PATCH] Validate LSTM gate matrix dimensions against na_/no_ at load + +LSTM::DeSerialize read na_ from the untrusted TESSDATA_LSTM component +and derived ns_ from the CI gate matrix's dim1, but never checked that +the deserialized dimensions were mutually consistent. The forward pass +sizes its buffers from na_, no_ and ns_ while the gate matrices drive +their own dimensions, so a crafted .traineddata performed heap +out-of-bounds writes and reads during the first recognition step, e.g. +WriteTimeStepPart writing ns_ floats at offset ni_+nf_ into a source_ +buffer sized from na_ (up to ~256 KB with an attacker-chosen gate +matrix dim1). + +The bounds assertions added by 2f4d2f4 (CVE-2026-73066) covered only +NetworkIO::CopyTimeStepGeneral and Randomize, leaving +WriteTimeStepPart and AddTimeStepPart unguarded. + +Key changes: +- weightmatrix.h: add Dim1()/Dim2() accessors for the active weight + matrix (int or float), alongside the existing NumOutputs(). +- lstm.cpp: reject the layer in DeSerialize unless na_ == + ni_ + nf_ + (is_2d_ ? 2 : 1) * ns_, every deserialized gate has + Dim1() == ns_ and Dim2() == na_ + 1 (the layout InitWeightsFloat + always produces), ns_ == no_ for plain NT_LSTM/NT_LSTM_SUMMARY, and + the softmax layer's sizes match ns_/no_ for the softmax variants. +- networkio.cpp: add the same defense-in-depth bounds assertions to + WriteTimeStepPart and AddTimeStepPart as 2f4d2f4 added to + CopyTimeStepGeneral and Randomize. +- unittest: add lstm_layer_test with crafted NT_LSTM layers for the + na_ mismatch, gate dim1 mismatch, and gate dim2 mismatch cases + (each rejected at load; on unpatched code the tests reach Forward + and ASan catches the out-of-bounds write in WriteTimeStepPart), + plus a positive control that a consistent layer loads and runs. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit b494ac18925f9d9aff9ef5815475de9943ab19bf) + +CVE: CVE-2026-88049 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/b494ac18925f9d9aff9ef5815475de9943ab19bf] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 + + src/lstm/lstm.cpp | 20 ++++ + src/lstm/networkio.cpp | 2 + + unittest/lstm_layer_test.cc | 177 ++++++++++++++++++++++++++++++++++++ + 4 files changed, 204 insertions(+) + create mode 100644 unittest/lstm_layer_test.cc + +diff --git a/Makefile.am b/Makefile.am +index ea722409..86ac9d0d 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1200,6 +1200,7 @@ check_PROGRAMS += layout_test + check_PROGRAMS += ligature_table_test + check_PROGRAMS += linlsq_test + check_PROGRAMS += list_test ++check_PROGRAMS += lstm_layer_test + if ENABLE_TRAINING + check_PROGRAMS += lstm_recode_test + check_PROGRAMS += lstm_squashed_test +@@ -1381,6 +1382,10 @@ loadlang_test_SOURCES = unittest/loadlang_test.cc + loadlang_test_CPPFLAGS = $(unittest_CPPFLAGS) + loadlang_test_LDADD = $(TESS_LIBS) $(LEPTONICA_LIBS) + ++lstm_layer_test_SOURCES = unittest/lstm_layer_test.cc ++lstm_layer_test_CPPFLAGS = $(unittest_CPPFLAGS) ++lstm_layer_test_LDADD = $(TESS_LIBS) ++ + lstm_recode_test_SOURCES = unittest/lstm_recode_test.cc + lstm_recode_test_CPPFLAGS = $(unittest_CPPFLAGS) + lstm_recode_test_LDADD = $(TRAINING_LIBS) +diff --git a/src/lstm/lstm.cpp b/src/lstm/lstm.cpp +index 11722d79..4ce361eb 100644 +--- a/src/lstm/lstm.cpp ++++ b/src/lstm/lstm.cpp +@@ -274,12 +274,32 @@ bool LSTM::DeSerialize(TFile *fp) { + is_2d_ = na_ - nf_ == ni_ + 2 * ns_; + } + } ++ // The deserialized dimensions must be mutually consistent: the forward ++ // pass sizes its buffers from na_, no_ and ns_ while the gate matrices ++ // drive their own dimensions. ++ if (na_ != ni_ + nf_ + (is_2d_ ? 2 : 1) * ns_) { ++ return false; ++ } ++ for (int w = 0; w < WT_COUNT; ++w) { ++ if (w == GFS && !Is2D()) { ++ continue; ++ } ++ if (gate_weights_[w].Dim1() != ns_ || gate_weights_[w].Dim2() != na_ + 1) { ++ return false; ++ } ++ } ++ if ((type_ == NT_LSTM || type_ == NT_LSTM_SUMMARY) && ns_ != no_) { ++ return false; ++ } + delete softmax_; + if (type_ == NT_LSTM_SOFTMAX || type_ == NT_LSTM_SOFTMAX_ENCODED) { + softmax_ = static_cast(Network::CreateFromFile(fp)); + if (softmax_ == nullptr) { + return false; + } ++ if (softmax_->NumInputs() != ns_ || softmax_->NumOutputs() != no_) { ++ return false; ++ } + } else { + softmax_ = nullptr; + } +diff --git a/src/lstm/networkio.cpp b/src/lstm/networkio.cpp +index 8636075b..929f5ac4 100644 +--- a/src/lstm/networkio.cpp ++++ b/src/lstm/networkio.cpp +@@ -641,6 +641,7 @@ void NetworkIO::AddTimeStep(int t, TFloat *inout) const { + + // Adds part of a single timestep to floats. + void NetworkIO::AddTimeStepPart(int t, int offset, int num_features, float *inout) const { ++ ASSERT_HOST(offset + num_features <= NumFeatures()); + if (int_mode_) { + const int8_t *line = i_[t] + offset; + for (int i = 0; i < num_features; ++i) { +@@ -662,6 +663,7 @@ void NetworkIO::WriteTimeStep(int t, const TFloat *input) { + // Writes a single timestep from floats in the range [-1, 1] writing only + // num_features elements of input to (*this)[t], starting at offset. + void NetworkIO::WriteTimeStepPart(int t, int offset, int num_features, const TFloat *input) { ++ ASSERT_HOST(offset + num_features <= NumFeatures()); + if (int_mode_) { + int8_t *line = i_[t] + offset; + for (int i = 0; i < num_features; ++i) { +diff --git a/unittest/lstm_layer_test.cc b/unittest/lstm_layer_test.cc +new file mode 100644 +index 00000000..2c874995 +--- /dev/null ++++ b/unittest/lstm_layer_test.cc +@@ -0,0 +1,177 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: lstm_layer_test.cc ++// Description: Tests that an NT_LSTM network layer with mutually ++// inconsistent deserialized dimensions is rejected at ++// load. The forward pass sizes its buffers from na_, no_ ++// and ns_ while the gate weight matrices drive their own ++// dimensions, so a crafted .traineddata performs heap ++// out-of-bounds writes/reads during the first ++// recognition step (e.g. WriteTimeStepPart writing ns_ ++// floats into a source_ buffer sized from na_). ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "network.h" // for Network, NetworkType ++#include "networkio.h" ++#include "networkscratch.h" ++#include "serialis.h" // for TFile ++#include "stridemap.h" ++ ++#include ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Appends raw little-endian values to a byte buffer. ++class ByteWriter { ++public: ++ void PutU8(uint32_t v) { data_.push_back(static_cast(v & 0xFF)); } ++ void PutU32(uint32_t v) { ++ for (int i = 0; i < 4; ++i) { ++ data_.push_back(static_cast((v >> (8 * i)) & 0xFF)); ++ } ++ } ++ void PutS32(int32_t v) { PutU32(static_cast(v)); } ++ const std::vector &data() const { return data_; } ++ ++private: ++ std::vector data_; ++}; ++ ++void PutDoubleLE(ByteWriter *w, double d) { ++ union { ++ double d; ++ uint64_t u; ++ } conv; ++ conv.d = d; ++ w->PutU32(static_cast(conv.u & 0xFFFFFFFF)); ++ w->PutU32(static_cast(conv.u >> 32)); ++} ++ ++// A serialized float-mode WeightMatrix with the given dimensions, ++// all weight data zeroed. ++void PutGateMatrix(ByteWriter *w, int32_t dim1, int32_t dim2) { ++ w->PutU8(128); // mode: kDoubleFlag, float mode ++ w->PutS32(dim1); ++ w->PutS32(dim2); ++ PutDoubleLE(w, 0.0); // empty_ cell ++ for (int32_t i = 0; i < dim1 * dim2; ++i) { ++ PutDoubleLE(w, 0.0); ++ } ++} ++ ++// A serialized 1-D NT_LSTM network: header with the given ni/no, na_, ++// then the four gates CI, GI, GF1, GO (GFS is not serialized for 1-D). ++std::vector MakeLstmNetwork(int ni, int no, int32_t na, ++ const int32_t gate_dim1[4], const int32_t gate_dim2[4]) { ++ ByteWriter w; ++ w.PutU8(static_cast(NT_LSTM)); ++ w.PutU8(0); // training: TS_DISABLED ++ w.PutU8(0); // needs_to_backprop ++ w.PutU32(0); // network_flags ++ w.PutU32(static_cast(ni)); ++ w.PutU32(static_cast(no)); ++ w.PutU32(0); // num_weights ++ w.PutU32(0); // name (empty string) ++ w.PutS32(na); ++ for (int g = 0; g < 4; ++g) { ++ PutGateMatrix(&w, gate_dim1[g], gate_dim2[g]); ++ } ++ return w.data(); ++} ++ ++// Builds the input a standalone LSTM layer would receive: one row of ++// the given width with ni features. ++NetworkIO MakeInput(int ni, int width) { ++ StrideMap stride_map; ++ stride_map.SetStride({{1, width}}); ++ NetworkIO input; ++ input.ResizeToMap(false, stride_map, ni); ++ return input; ++} ++ ++// Runs Forward on the loaded network; on unpatched code the out-of- ++// bounds access this regression test guards against fires here. ++void RunForward(Network *net, int ni, int width) { ++ NetworkIO input = MakeInput(ni, width); ++ NetworkScratch scratch; ++ NetworkIO output; ++ net->Forward(false, input, nullptr, &scratch, &output); ++ delete net; ++} ++ ++// na_ must equal ni_ + nf_ + ns_ for a 1-D LSTM; here na_=2 but the ++// CI matrix makes ns_=64, so the layer must be rejected. On unpatched ++// code Forward writes 64 floats at offset ni_=1 into a source_ buffer ++// sized for na_=2 (heap out-of-bounds write). ++TEST(LstmLayerTest, RejectsInconsistentNa) { ++ const int32_t dim1[4] = {64, 64, 64, 64}; ++ const int32_t dim2[4] = {3, 3, 3, 3}; ++ std::vector bytes = MakeLstmNetwork(1, 1, 2, dim1, dim2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ if (net == nullptr) { ++ return; // Fixed: the inconsistent layer is rejected at load. ++ } ++ RunForward(net, 1, 2); ++ FAIL() << "crafted LSTM layer with inconsistent na_ was accepted"; ++} ++ ++// All gate matrices must have dim1 == ns_; here the GI matrix has ++// dim1=9 while ns_=5. On unpatched code the GI gate dot product writes ++// 9 results into a temp line sized for 5 (heap out-of-bounds write). ++TEST(LstmLayerTest, RejectsGateDim1Mismatch) { ++ const int32_t dim1[4] = {5, 9, 5, 5}; ++ const int32_t dim2[4] = {7, 7, 7, 7}; ++ std::vector bytes = MakeLstmNetwork(1, 5, 6, dim1, dim2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ if (net == nullptr) { ++ return; // Fixed: the inconsistent layer is rejected at load. ++ } ++ RunForward(net, 1, 2); ++ FAIL() << "crafted LSTM layer with inconsistent gate dim1 was accepted"; ++} ++ ++// All gate matrices must have dim2 == na_ + 1; here the GI matrix has ++// dim2=9 while na_=6. On unpatched code the GI gate dot product reads ++// 8 inputs from a buffer sized for 6 (heap out-of-bounds read). ++TEST(LstmLayerTest, RejectsGateDim2Mismatch) { ++ const int32_t dim1[4] = {5, 5, 5, 5}; ++ const int32_t dim2[4] = {7, 9, 7, 7}; ++ std::vector bytes = MakeLstmNetwork(1, 5, 6, dim1, dim2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ if (net == nullptr) { ++ return; // Fixed: the inconsistent layer is rejected at load. ++ } ++ RunForward(net, 1, 2); ++ FAIL() << "crafted LSTM layer with inconsistent gate dim2 was accepted"; ++} ++ ++// A fully consistent 1-D LSTM layer must still be accepted and usable. ++TEST(LstmLayerTest, AcceptsConsistentLayer) { ++ const int32_t dim1[4] = {5, 5, 5, 5}; ++ const int32_t dim2[4] = {7, 7, 7, 7}; ++ std::vector bytes = MakeLstmNetwork(1, 5, 6, dim1, dim2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ Network *net = Network::CreateFromFile(&fp); ++ ASSERT_NE(net, nullptr); ++ RunForward(net, 1, 2); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index a8b3e55c7d..df6ff11d78 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -12,6 +12,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-73067-2.patch \ file://CVE-2026-88052.patch \ file://CVE-2026-88048.patch \ + file://CVE-2026-88049.patch \ " From patchwork Thu Sep 24 04:33:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99130 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CC4EAC982FD for ; Thu, 24 Sep 2026 04:34:04 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.734.1790224442740954091 for ; Wed, 23 Sep 2026 21:34:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=qKjhfl5/; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-8674704dab1so1511632b3a.2 for ; Wed, 23 Sep 2026 21:34:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224442; x=1790829242; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MJg+Vk80SDAORumMkzT1iLDsX11w6az1KkfwesQKlu8=; b=qKjhfl5/zJGdyKB0JP6gE49Vp6G8KhF10eby4pB1Do1ryDHhxY/c2qGh/e0eMl5MOD JzcQuu/QpGvC3kkgvjtPPvNYYZsszcJui9OVYxhW+y4sM3iyAJoJ7W31XJ9eGThQf08/ Rd7SFchyvmry3R5+53dimDFpdf2jdFpg/5P41zY71WkZps5/C9KGskU3k7r7yEb0kltY ls5k1O1S9aCIeiV5xhxaEcD0HVvcCE/Bq8VjuK4p60eQIOV1d9E1hHhLxqmVuQzFG1Ws zLZPWayqDG4ASWHk5WuLVEA8rh98MqXfnnrRdqK1demucUpg4D1Lxhn6BE/Ju0ct+kbE aiOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224442; x=1790829242; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MJg+Vk80SDAORumMkzT1iLDsX11w6az1KkfwesQKlu8=; b=E68jd6skSn+8zqqKsDXLadgWF1QqpbmuHnpui3P4DujOVpghY+D3ygjzaCltTJtBpl cjoI5Q3w6iYe+glc09hxOWsVl/qvTk68R9HkUs+AcfL5IzFoPa004935y/DyV9wHv/cF 010S+JS8kxUu/Z6RQwOfxB95hAGoJ/7ANm4ydI5TLMg7WdCJ2wcYkz1jHTAEb3K7USZ6 8wY+hUDlCspBm1uJg1YRhyf4oY81GFo2L1VuSE0L2w1nMl/WsJfQpDIh3sBGLI+wSfDJ dbanNJZ9pBkMeddtHke/E0v54ziLOrQKybkJwnvUZhg4KpS5c4lrqDbv/NqkNST3zhq+ jW0Q== X-Gm-Message-State: AFuF++mY7hhlEChr0xnvc3AJnQx0wBAGhwOLFGrkovblmfBz7/NSxuxI pjb2hr3WPH5fow4VdsbuAq54gRhVi02kA9CfQ2WF+GUlUHYjxKPT4AJ/JdB5qw== X-Gm-Gg: AYBFou2dMbLaCKsnajYN8boF2lQVXg2KzPGWKN89jj8hOWb69iVr0JTa5WVyQpGu3LO Fmf3k0gCpVRYxG+1w5vC7/yu3FjCnpVk4FU212MzSFy0uoGh+wVTU0ZBDjbrjQAhXf1YswD3WMb U+zFdfhXbayyvlki0D29yommwinqijzW/3+uJH6bXk1b2ZiUuIQp6D8QfQqB/GiIC59Rs/XsH3p PfznMMV8v1b67l3yFS8Jfh7qG7WCGdLRnJu90T08oLwPYkxohd+C+UZwL1xhqsAgPKd8WU51HAb THf8tUBWDV97scMxXjzUaajd6+g4la3SCqLqCnIFF4WcisC9NCwqeB7FkQg2y2JQHfBklOgh1Ow UNeTx8qwMkGW5oY6cmjz8V7Csrp5XPH2MsZSo8nyDoI/N74NhKc2VSDkM9Ai69+4jtYevclzRaN YHfhcwBmzEdP/d0pZ9KJM/L1OSrh1wy52Jc53ddl1nMVkEHSObNU0amP2YQvqpeKiHvTpQdiwna Paihw+i/NEnW3XP7zClArFtByZt7c8i/w== X-Received: by 2002:a05:6a00:4b15:b0:878:37b2:dfa9 with SMTP id d2e1a72fcca58-87e9f62dca2mr1030029b3a.57.1790224441910; Wed, 23 Sep 2026 21:34:01 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:01 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 19/24] tesseract: patch CVE-2026-88050 Date: Thu, 24 Sep 2026 16:33:09 +1200 Message-ID: <20260924043315.1663186-19-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130267 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88050 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88050.patch | 210 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 211 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88050.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88050.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88050.patch new file mode 100644 index 0000000000..b07ef69989 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88050.patch @@ -0,0 +1,210 @@ +From bb1e72a7f8488d653d2a37e482babac6d9dc7ab2 Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 16:56:51 +0200 +Subject: [PATCH] Reject recoder code values outside the sane range at load + +RecodedCharID::DeSerialize (hardened by 82727cc to check length_ +only) still read the individual code values as raw signed int32. +UnicharCompress::ComputeCodeRange computes code_range_ as 1 plus the +maximum code using a signed > comparison, so a code value of -1 +never raises the maximum and yields code_range_ = 0. SetupDecoder +then resizes is_valid_start_ to 0 and writes is_valid_start_[code(0)] +on the size-0 vector, an out-of-bounds write at a wild wrapped +index (deterministic crash) on LSTMRecognizer load. A code value of +INT32_MAX instead wraps code_range_ negative and makes resize() +throw. + +Key changes: +- unicharcompress.h: validate each deserialized code value to be + within [0, UINT16_MAX), the same arbitrary cap used elsewhere for + .traineddata counts; reject the recoder otherwise. +- unicharcompress.h/.cpp: add defense-in-depth bounds assertions to + IsValidFirstCode and SetupDecoder, matching the style of the + NetworkIO assertions from 2f4d2f4. +- unittest: add recoder_test, which feeds a crafted UnicharCompress + with a -1 code and an INT32_MAX code and expects DeSerialize to + fail (on unpatched code the -1 case dies on the SEGV in + SetupDecoder, the huge case on the uncaught length_error), plus a + positive control that valid codes load and answer + code_range()/IsValidFirstCode() correctly. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit c94a5532ee04db5a4919542832fd94caee5ea58f) + +CVE: CVE-2026-88050 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/c94a5532ee04db5a4919542832fd94caee5ea58f] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 ++ + src/ccutil/unicharcompress.cpp | 1 + + src/ccutil/unicharcompress.h | 13 ++++- + unittest/recoder_test.cc | 91 ++++++++++++++++++++++++++++++++++ + 4 files changed, 109 insertions(+), 1 deletion(-) + create mode 100644 unittest/recoder_test.cc + +diff --git a/Makefile.am b/Makefile.am +index 86ac9d0d..c1491263 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1231,6 +1231,7 @@ endif # !DISABLED_LEGACY_ENGINE + check_PROGRAMS += progress_test + check_PROGRAMS += qrsequence_test + check_PROGRAMS += recodebeam_test ++check_PROGRAMS += recoder_test + check_PROGRAMS += rect_test + check_PROGRAMS += resultiterator_test + check_PROGRAMS += scanutils_test +@@ -1464,6 +1465,10 @@ recodebeam_test_SOURCES = unittest/recodebeam_test.cc + recodebeam_test_CPPFLAGS = $(unittest_CPPFLAGS) + recodebeam_test_LDADD = $(TRAINING_LIBS) $(ICU_I18N_LIBS) $(ICU_UC_LIBS) + ++recoder_test_SOURCES = unittest/recoder_test.cc ++recoder_test_CPPFLAGS = $(unittest_CPPFLAGS) ++recoder_test_LDADD = $(TESS_LIBS) ++ + rect_test_SOURCES = unittest/rect_test.cc + rect_test_CPPFLAGS = $(unittest_CPPFLAGS) + rect_test_LDADD = $(TESS_LIBS) +diff --git a/src/ccutil/unicharcompress.cpp b/src/ccutil/unicharcompress.cpp +index d5efccab..7f3d48fe 100644 +--- a/src/ccutil/unicharcompress.cpp ++++ b/src/ccutil/unicharcompress.cpp +@@ -400,6 +400,7 @@ void UnicharCompress::SetupDecoder() { + for (unsigned c = 0; c < encoder_.size(); ++c) { + const RecodedCharID &code = encoder_[c]; + decoder_[code] = c; ++ ASSERT_HOST(code(0) >= 0 && code(0) < code_range_); + is_valid_start_[code(0)] = true; + RecodedCharID prefix = code; + int len = code.length() - 1; +diff --git a/src/ccutil/unicharcompress.h b/src/ccutil/unicharcompress.h +index 67a441e8..05778ce6 100644 +--- a/src/ccutil/unicharcompress.h ++++ b/src/ccutil/unicharcompress.h +@@ -79,7 +79,17 @@ public: + if (length_ > kMaxCodeLen) { + return false; + } +- return fp->DeSerialize(&code_[0], length_); ++ if (!fp->DeSerialize(&code_[0], length_)) { ++ return false; ++ } ++ // Code values index arrays sized from the maximum code; reject values ++ // that are out of the sane range for a recoded alphabet. ++ for (uint32_t i = 0; i < length_; ++i) { ++ if (code_[i] < 0 || code_[i] >= static_cast(UINT16_MAX)) { ++ return false; ++ } ++ } ++ return true; + } + bool operator==(const RecodedCharID &other) const { + if (length_ != other.length_) { +@@ -185,6 +195,7 @@ public: + int DecodeUnichar(const RecodedCharID &code) const; + // Returns true if the given code is a valid start or single code. + bool IsValidFirstCode(int code) const { ++ ASSERT_HOST(code >= 0 && code < code_range_); + return is_valid_start_[code]; + } + // Returns a list of valid non-final next codes for a given prefix code, +diff --git a/unittest/recoder_test.cc b/unittest/recoder_test.cc +new file mode 100644 +index 00000000..48dfa7ea +--- /dev/null ++++ b/unittest/recoder_test.cc +@@ -0,0 +1,91 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: recoder_test.cc ++// Description: Tests that a UnicharCompress (LSTM recoder) with code ++// values outside the sane range is rejected at load. ++// Negative code values leave code_range_ at zero, so ++// SetupDecoder writes is_valid_start_[code(0)] out of ++// bounds on a size-0 vector; huge code values wrap ++// code_range_ and make resize() throw. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "serialis.h" // for TFile ++#include "unicharcompress.h" ++ ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Appends raw little-endian values to a byte buffer. ++class ByteWriter { ++public: ++ void PutU8(uint32_t v) { data_.push_back(static_cast(v & 0xFF)); } ++ void PutU32(uint32_t v) { ++ for (int i = 0; i < 4; ++i) { ++ data_.push_back(static_cast((v >> (8 * i)) & 0xFF)); ++ } ++ } ++ void PutS32(int32_t v) { PutU32(static_cast(v)); } ++ const std::vector &data() const { return data_; } ++ ++private: ++ std::vector data_; ++}; ++ ++// A serialized UnicharCompress with one length-1 RecodedCharID per ++// given code value (self-normalizing). ++std::vector MakeRecoder(const std::vector &codes) { ++ ByteWriter w; ++ w.PutU32(codes.size()); ++ for (int32_t code : codes) { ++ w.PutU8(1); // self_normalized_ ++ w.PutU32(1); // length_ ++ w.PutS32(code); // code_[0] ++ } ++ return w.data(); ++} ++ ++// A recoder code of -1 keeps code_range_ at 0, so on unpatched code ++// SetupDecoder performs an out-of-bounds write into the size-0 ++// is_valid_start_ vector. ++TEST(RecoderTest, RejectsNegativeCode) { ++ std::vector bytes = MakeRecoder({-1}); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ UnicharCompress recoder; ++ EXPECT_FALSE(recoder.DeSerialize(&fp)); ++} ++ ++// A recoder code of INT32_MAX wraps code_range_ to a negative value, ++// so on unpatched code SetupDecoder's resize() throws. ++TEST(RecoderTest, RejectsHugeCode) { ++ std::vector bytes = MakeRecoder({INT32_MAX}); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ UnicharCompress recoder; ++ EXPECT_FALSE(recoder.DeSerialize(&fp)); ++} ++ ++// A valid recoder must still be accepted and usable. ++TEST(RecoderTest, AcceptsValidCodes) { ++ std::vector bytes = MakeRecoder({0, 1}); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ UnicharCompress recoder; ++ ASSERT_TRUE(recoder.DeSerialize(&fp)); ++ EXPECT_EQ(recoder.code_range(), 2); ++ EXPECT_TRUE(recoder.IsValidFirstCode(0)); ++ EXPECT_TRUE(recoder.IsValidFirstCode(1)); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index df6ff11d78..756e780659 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -13,6 +13,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-88052.patch \ file://CVE-2026-88048.patch \ file://CVE-2026-88049.patch \ + file://CVE-2026-88050.patch \ " From patchwork Thu Sep 24 04:33:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99134 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 76914C98315 for ; Thu, 24 Sep 2026 04:34:06 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.740.1790224444761690922 for ; Wed, 23 Sep 2026 21:34:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=DdLK49G8; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8674704dab1so1511641b3a.2 for ; Wed, 23 Sep 2026 21:34:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224444; x=1790829244; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=J54v1i5fRqcFDpi/tJNfyZInWjVAgj/j+3xZUk2GIS4=; b=DdLK49G8/wAXZ09hR7cPMhdpSx1mBzfOqg3TVTBNrkWxoK+LbEErnS0Hxq5OwlsavX hhPLZMORTMOxDz0MSGnRFmH4HFDhG4WeXVEBGmMyiPEDDWiI6QkBvRipkidag2D6MBZE DLdKs2iwik7SFE8kIXUKujqDbDddBTegV/gaFydg0oWOa+6QW+5h93TQvnmeZbQ2Xwk4 u9lJLCZFYrorEDggukld+dSkT+iNMYLIu1DBpMHEK+Nr+jlp/u1oZrqAA9Ji1KohBgag FpRq9FJypDlBpZYYynoiCGhKlgsBUw+upEANDpUwpSeHNtQd5gknWbPEhBvhdW7tZM6r cPmw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224444; x=1790829244; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=J54v1i5fRqcFDpi/tJNfyZInWjVAgj/j+3xZUk2GIS4=; b=YbPJOODPH3lDtJA77h5DxSyW74uV93upbE0izaRePzrvxsIcqpMBDv3Lm7bxHtBcVp hspvHUdQT2NHea3VaQEfTXcPmpSYIbIpBMVG7zKqFtXTsl+I91d9yS+6AXc3pFVS1OXA 5n/0I1IqR9uv9WLgbD54wwo3kv6ZyzCVdE12Bx01OrfaG2i7rDGprreENe/ZIo/ZRwE3 OemSH0RflUlHaR+Y8jtgforv+r5UHR9mN1/qoMEEuZQQ5EmPm5N0cqjvHrqWQ+14R14N q1Dtg+Hs7q3GEhhVdO2wOcxkd96icHGs0DuIERKuPN45H2cvi6qQUnvuaNkjIV5TGrnP X4wA== X-Gm-Message-State: AFuF++ndZ1X/Hgyyij/8lKiMhMYbH3oJKyo1IRfQt+Yw4u7cyhWBYWbz 1QWAa7UemgzGt5/cchjNLuf0eRgqNQv4980HgbeBQQ20qQdwV8vq6JwQAB1ecQ== X-Gm-Gg: AYBFou0k3JHxnUTvMaVLkQGRevgVYOkOxIB1d5WE5Ktf6dI3bEymMpC7d43XtA/Ccu9 Th65x0+sG1NshZLGiYZgftWb40soXxdd6PZ7DIsch/8A95JfX1FcWeIH7joTUWwtdWQLMmZrDM/ 5bXxHGhJ9wGG7p9Tzzb5QBXRhEZPJMYMVxpdAoSn+BBm4Ld5jAKMPcwoWiXT5LE6JfW2CgF4XT6 HomRdqComVKD6NCoOuRVhz3v63Lrh6pv+8Tz+BkH81ZufooKzyRr7rYmB/7ozO6W/+f0XEReEaj N95kUzIcS8ijZfhXcDFUW/QFkNpgEGG00No9Uvbi2GEFlnZfmx4wcDWl31TupnAtVEwrDrO/Sce RW0WajRNPgYCQSEGoOoxoKLR3I3FDVURcEZe29hn1c4ijmFbNlvdXHhYzykVqYUp4yLuPIifklH s3rDzPJUMJ6CQdjmMdKKzUgqVLxjhDnHwsVrIcU7vV2DpsEsdZ4sldvPNvrXV4bVCNWYCQQUUFg D8j+N21Xo0bH+h9FvMk6d4= X-Received: by 2002:a05:6a00:4087:b0:878:34d7:6a32 with SMTP id d2e1a72fcca58-87e9ea62357mr1039851b3a.38.1790224444046; Wed, 23 Sep 2026 21:34:04 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:03 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 20/24] tesseract: patch CVE-2026-88047 Date: Thu, 24 Sep 2026 16:33:10 +1200 Message-ID: <20260924043315.1663186-20-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130268 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88047 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88047.patch | 226 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 227 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88047.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88047.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88047.patch new file mode 100644 index 0000000000..04e9953d2a --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88047.patch @@ -0,0 +1,226 @@ +From a6e329ff576ad4a90952f08359dbffab7e480157 Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Mon, 24 Aug 2026 13:39:22 +0200 +Subject: [PATCH] Limit unichar extraction in ReadNormProtos to the buffer size + +Classify::ReadNormProtos parsed each normproto line with +`stream >> unichar >> NumProtos` into a char unichar[2 * UNICHAR_LEN + 1] +stack buffer, but char* extraction from an istream has no length limit +(the stream width was never set). A crafted TESSDATA_NORMPROTO component +in a .traineddata file whose first proto-line token exceeds 60 +characters (the 100-byte line buffer allows up to 99) overflows the +stack buffer during legacy engine initialization (CWE-121). + +Toolchain note: Apple's libc++ provides a C++20 array overload of +operator>>(basic_istream&, char(&)[N]) that implicitly bounds the +extraction to the array size, so builds against that standard library +are incidentally protected. Standard libraries without that overload +(e.g. libstdc++) still take the unbounded char* overload, so the +explicit width limit below makes the behavior defined on all +toolchains. + +Key changes: +- normmatch.cpp: read the unichar token with + std::setw(2 * UNICHAR_LEN + 1); char* extraction takes at most + width - 1 characters, which fits the buffer exactly. Overlong + tokens are truncated and the line is rejected like any other + unparseable line. +- unittest: add normproto_test covering a 99-character token (the + maximum a 100-byte line can hold), a token of exactly 2 * + UNICHAR_LEN characters, and a well-formed component. A minimal + reproduction of the unbounded extraction crashes an ASan build + with a stack-buffer-overflow. + +Reported-by: Tristan Madani +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit 1bda5079b1c8a7e25f523486837426903d29ce84) + +CVE: CVE-2026-88047 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/1bda5079b1c8a7e25f523486837426903d29ce84] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 ++ + src/classify/normmatch.cpp | 6 +- + unittest/CMakeLists.txt | 1 + + unittest/normproto_test.cc | 111 +++++++++++++++++++++++++++++++++++++ + 4 files changed, 122 insertions(+), 1 deletion(-) + create mode 100644 unittest/normproto_test.cc + +diff --git a/Makefile.am b/Makefile.am +index c1491263..48e7dcbc 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1213,6 +1213,7 @@ check_PROGRAMS += mastertrainer_test + endif # !DISABLED_LEGACY_ENGINE + check_PROGRAMS += matrix_test + check_PROGRAMS += networkio_test ++check_PROGRAMS += normproto_test + if ENABLE_TRAINING + check_PROGRAMS += normstrngs_test + endif # ENABLE_TRAINING +@@ -1417,6 +1418,10 @@ networkio_test_SOURCES = unittest/networkio_test.cc + networkio_test_CPPFLAGS = $(unittest_CPPFLAGS) + networkio_test_LDADD = $(TESS_LIBS) + ++normproto_test_SOURCES = unittest/normproto_test.cc ++normproto_test_CPPFLAGS = $(unittest_CPPFLAGS) ++normproto_test_LDADD = $(TESS_LIBS) ++ + normstrngs_test_SOURCES = unittest/normstrngs_test.cc + normstrngs_test_CPPFLAGS = $(unittest_CPPFLAGS) + normstrngs_test_LDADD = $(TRAINING_LIBS) $(ICU_I18N_LIBS) $(ICU_UC_LIBS) +diff --git a/src/classify/normmatch.cpp b/src/classify/normmatch.cpp +index d5bd7e6a..1ce7c928 100644 +--- a/src/classify/normmatch.cpp ++++ b/src/classify/normmatch.cpp +@@ -28,6 +28,7 @@ + + #include + #include ++#include // for std::setw + #include // for std::istringstream + + namespace tesseract { +@@ -190,7 +191,10 @@ NORM_PROTOS *Classify::ReadNormProtos(TFile *fp) { + while (fp->FGets(line, kMaxLineSize) != nullptr) { + std::istringstream stream(line); + stream.imbue(std::locale::classic()); +- stream >> unichar >> NumProtos; ++ // unichar holds at most 2 * UNICHAR_LEN characters; the width limit ++ // (width - 1 characters for char* extraction) keeps the extraction ++ // from overflowing the buffer on overlong lines. ++ stream >> std::setw(2 * UNICHAR_LEN + 1) >> unichar >> NumProtos; + if (stream.fail()) { + continue; + } +diff --git a/unittest/CMakeLists.txt b/unittest/CMakeLists.txt +index 6a91c62f..b65cf922 100644 +--- a/unittest/CMakeLists.txt ++++ b/unittest/CMakeLists.txt +@@ -61,6 +61,7 @@ set(LEGACY_TESTS + indexmapbidi_test.cc + intfeaturemap_test.cc + mastertrainer_test.cc ++ normproto_test.cc + osd_test.cc + params_model_test.cc + shapetable_test.cc) +diff --git a/unittest/normproto_test.cc b/unittest/normproto_test.cc +new file mode 100644 +index 00000000..574b2f3d +--- /dev/null ++++ b/unittest/normproto_test.cc +@@ -0,0 +1,111 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: normproto_test.cc ++// Description: Tests that Classify::ReadNormProtos handles a normproto ++// line whose first (unichar) token exceeds the ++// unichar[2 * UNICHAR_LEN + 1] stack buffer. The ++// istream extraction has no intrinsic length limit, so a ++// crafted NORMPROTO component in a .traineddata file ++// could overflow the stack buffer during legacy engine ++// initialization. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "classify.h" ++#include "serialis.h" // for TFile ++ ++#include ++#include ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Minimal unicharset (space and 'a'). ++const char kMinUnicharset[] = ++ "2\n" ++ "NULL 1 0,255,0,255,0,0,0,0,0,0 Latin 2 0 2\n" ++ "a 1 0,255,0,255,0,0,0,0,0,0 Latin 2 0 2\n"; ++ ++// Builds a normproto component: a sample-size line (5), five parameter ++// description lines, then the given raw proto lines. ++std::vector MakeNormproto(const std::string &lines) { ++ std::string data = "5\n"; ++ for (int i = 0; i < 5; ++i) { ++ data += "e e 0 1\n"; ++ } ++ data += lines; ++ return std::vector(data.begin(), data.end()); ++} ++ ++class NormprotoTest : public testing::Test { ++protected: ++ void SetUp() override { ++ tmpl_ = "/tmp/tess_normproto_test_XXXXXX"; ++ char *dir = mkdtemp(tmpl_.data()); ++ ASSERT_NE(dir, nullptr); ++ dir_ = dir; ++ std::string uc_path = dir_ + "/eng.unicharset"; ++ FILE *f = fopen(uc_path.c_str(), "w"); ++ ASSERT_NE(f, nullptr); ++ ASSERT_EQ(fwrite(kMinUnicharset, 1, sizeof(kMinUnicharset) - 1, f), ++ sizeof(kMinUnicharset) - 1); ++ fclose(f); ++ // Load the minimal unicharset into the classifier's inherited ++ // unicharset member. ++ ASSERT_TRUE(classifier_.unicharset.load_from_file(uc_path.c_str())); ++ } ++ void TearDown() override { ++ std::remove((dir_ + "/eng.unicharset").c_str()); ++ rmdir(dir_.c_str()); ++ } ++ std::string dir_; ++ std::string tmpl_; ++ Classify classifier_; ++}; ++ ++// A 99-character first token (the maximum FGets can return) overflows ++// unichar[2 * UNICHAR_LEN + 1] on unpatched code; the width-limited ++// extraction must reject the line instead. ++TEST_F(NormprotoTest, ToleratesOverlongUnicharToken) { ++ std::vector bytes = MakeNormproto(std::string(99, 'A') + "\n"); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ classifier_.NormProtos = classifier_.ReadNormProtos(&fp); ++ ASSERT_NE(classifier_.NormProtos, nullptr); ++ classifier_.FreeNormProtos(); ++ EXPECT_EQ(classifier_.NormProtos, nullptr); ++} ++ ++// A token of exactly 2 * UNICHAR_LEN characters is the maximum legitimate ++// size; it must not be truncated or rejected by the width limit. ++TEST_F(NormprotoTest, ToleratesMaxLenUnicharToken) { ++ std::vector bytes = MakeNormproto(std::string(2 * UNICHAR_LEN, 'A') + " 0\n"); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ classifier_.NormProtos = classifier_.ReadNormProtos(&fp); ++ ASSERT_NE(classifier_.NormProtos, nullptr); ++ classifier_.FreeNormProtos(); ++ EXPECT_EQ(classifier_.NormProtos, nullptr); ++} ++ ++// A well-formed normproto component must still parse. ++TEST_F(NormprotoTest, ReadsValidNormprotos) { ++ std::vector bytes = MakeNormproto("a 0\n"); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ classifier_.NormProtos = classifier_.ReadNormProtos(&fp); ++ ASSERT_NE(classifier_.NormProtos, nullptr); ++ classifier_.FreeNormProtos(); ++ EXPECT_EQ(classifier_.NormProtos, nullptr); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index 756e780659..61cb1f7cad 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -14,6 +14,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-88048.patch \ file://CVE-2026-88049.patch \ file://CVE-2026-88050.patch \ + file://CVE-2026-88047.patch \ " From patchwork Thu Sep 24 04:33:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99138 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9CD88C98310 for ; Thu, 24 Sep 2026 04:34:16 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.737.1790224446801071169 for ; Wed, 23 Sep 2026 21:34:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=dgy2rFwO; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469f20513so927171b3a.0 for ; Wed, 23 Sep 2026 21:34:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224446; x=1790829246; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R3rus/LyQ9yzYbQ0n5NNi0aVn97Qc0iH97ys1YBgzTA=; b=dgy2rFwOzHKot+z2EDOR5ji+6Kec4anEuBdFre3ugJMOzypUk4PVOUQxXSVqP/Hh60 CgE+lAvM1LR14tHL8dEy7FOQEvJHMe7+Fv5sxcUaMUEaflPNYLYeCz81cXUrkq1YgCr+ 36jSdHpTdzyhNKEtG8Jj+SFC7EVYAdGxykf4Kcvuah5CCHo/IArwhGUYmdyZ/DxkX6xT CAjGgDiLNVMHgH42DoMHgQ6x+UH+CyZqArlz44CUC+iuA3+htW9oiyjsaxuIJUk9DWjj EEAqbYpvT+Nm7HbiwIohfW113viHtN/TweRgQKCxohsSQoEEjTGa5Wn5oOc+HNYAHERL 7vzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224446; x=1790829246; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=R3rus/LyQ9yzYbQ0n5NNi0aVn97Qc0iH97ys1YBgzTA=; b=q6TJSD3j/yThgPVkZOi2w+rAKr8H6qbeQht88c5eQEzdk0TMAEq8H2XVLaobHVMSZo kOFoPzXeQiWtimkN6b1G88mxxhNjhu/2qOgeheaRxFlYapEZCU0j8zsWYDOjAmRC9TWf wIfBs1+j4XiKiRUYna7DwHwY7PsHRNS14LHZsj8GtpByks3RjE9jeTVTikpiGwZrLNq1 AFb44P4ydEhPeHY8cJV6F8XdLmmEXVGu/Ml6KZEln0dJH2li0lZtIvxom7zvKF6xI9SU 3DT0arIMj9r8t6vELhrp7I/xL0lqPXEZcVOnHOWPINEixUoMEaXe+odZCeSsRB4v8ynD wALw== X-Gm-Message-State: AFuF++mvq5mSsS58Ye9p5SLqjMbI/bhY4cGs2fiPj8bQRxDzbThdMrHw A+QJ29QaDTvjajgAaN5eQzR1vPfa45dsn6l8D/bHoPoDATwfCUskRnjwNox8rw== X-Gm-Gg: AYBFou2eggT7funsZ5cmQn/IEGVejAZ1YyEABWfrrzy1TlCshu1fjHDEFtiDpVYhU+I CO5ctlsVRQOJBZyagsyk5urW0a5JAx3gPiGn420knpPxcKjH+GVDgbqMwjysLqX7/elu2u7w2I2 fV+M1LX3qP4TNFMVuyeiT1l9pnGAgtrbPD1/gAXBdCpRbDQBqzYsT6KVlHxwFLNVsAYRTtzUoa6 3gWPVNqNp/iAV4gd4BXPcNSW0lyrMB5o8qz9dMq1qhS1SQk8kNUegxvFaiMVcYPXFzVlO3cJQEi SFQSmvVIhXYpz7i5PIezXAFl1Cg3hnzdYjvmgwngyjlWwTVpPmDjqCiszBbe6S3/UulZZE+l2fl tzq8D9IORge9iWvi3keSFRcnUIrcLvv8PZpOVSmZpVd+k/2V+1EOtxd3YbeDs+XNDAVfpDtLaSg pt2S0asNz9MK7fGEH1+qdy/q9tNcUZ4vxjObRxKzktlxSTEpXDTjzb9t/0cO1m5eFSpl0g40C3p U1zyeBUjAuEZly0jN9leJc= X-Received: by 2002:a05:6a00:a0d:b0:87c:d00a:f335 with SMTP id d2e1a72fcca58-87e9be7f2eemr987836b3a.44.1790224446078; Wed, 23 Sep 2026 21:34:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:05 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 21/24] tesseract: patch CVE-2026-88051 Date: Thu, 24 Sep 2026 16:33:11 +1200 Message-ID: <20260924043315.1663186-21-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130269 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88051 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88051.patch | 185 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 186 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88051.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88051.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88051.patch new file mode 100644 index 0000000000..efc204dc04 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88051.patch @@ -0,0 +1,185 @@ +From 0ad773414bcb9a4f41e7d86759353d9558ba8cbe Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 20:29:37 +0200 +Subject: [PATCH] Validate vector counts in GenericVector::read + +The callback form of GenericVector::read read two independent int32 +fields from the file: reserved sized the allocation via reserve(), +while size_used_ drove the element loop. Neither was capped and no +size_used_ <= reserved invariant was checked, so a crafted +.traineddata (e.g. the fontinfo table of a version >= 4 inttemp +component) performed a heap out-of-bounds write during legacy +engine initialization. + +Key changes: +- genericvector.h: reject negative or over-limit reserved + (matching the 50000000 cap of the DeSerialize overloads) and + reject size_used_ < 0 or size_used_ > reserved before entering + the read loop. Legit files always satisfy size_used_ <= reserved, + as write() persists size_reserved_ first. +- unittest: add genericvector_test covering size_used_ beyond + reserved (on unpatched code the ASan build dies on a + heap-buffer-overflow in the read loop), negative counts, and a + consistent vector that must still load. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit 56e09ca12e751623fe796ce1554ce704bffd2ef0) + +CVE: CVE-2026-88051 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/56e09ca12e751623fe796ce1554ce704bffd2ef0] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 ++ + src/ccutil/genericvector.h | 10 ++++ + unittest/genericvector_test.cc | 91 ++++++++++++++++++++++++++++++++++ + 3 files changed, 106 insertions(+) + create mode 100644 unittest/genericvector_test.cc + +diff --git a/Makefile.am b/Makefile.am +index 48e7dcbc..d2b503d4 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1188,6 +1188,7 @@ check_PROGRAMS += equationdetect_test + endif # !DISABLED_LEGACY_ENGINE + check_PROGRAMS += fileio_test + check_PROGRAMS += fullyconnected_test ++check_PROGRAMS += genericvector_test + check_PROGRAMS += heap_test + check_PROGRAMS += imagedata_test + if !DISABLED_LEGACY_ENGINE +@@ -1327,6 +1328,10 @@ fullyconnected_test_SOURCES = unittest/fullyconnected_test.cc + fullyconnected_test_CPPFLAGS = $(unittest_CPPFLAGS) + fullyconnected_test_LDADD = $(TESS_LIBS) + ++genericvector_test_SOURCES = unittest/genericvector_test.cc ++genericvector_test_CPPFLAGS = $(unittest_CPPFLAGS) ++genericvector_test_LDADD = $(TESS_LIBS) ++ + heap_test_SOURCES = unittest/heap_test.cc + heap_test_CPPFLAGS = $(unittest_CPPFLAGS) + heap_test_LDADD = $(TESS_LIBS) +diff --git a/src/ccutil/genericvector.h b/src/ccutil/genericvector.h +index 4a5bbe12..cbe1e203 100644 +--- a/src/ccutil/genericvector.h ++++ b/src/ccutil/genericvector.h +@@ -654,10 +654,20 @@ bool GenericVector::read(TFile *f, const std::function &c + if (f->FReadEndian(&reserved, sizeof(reserved), 1) != 1) { + return false; + } ++ // Arbitrarily limit the number of elements to protect against bad data. ++ const uint32_t limit = 50000000; ++ if (reserved < 0 || static_cast(reserved) > limit) { ++ return false; ++ } + reserve(reserved); + if (f->FReadEndian(&size_used_, sizeof(size_used_), 1) != 1) { + return false; + } ++ // size_used_ is an independent file field; without this check the reads ++ // below land past the end of the buffer sized from reserved. ++ if (size_used_ < 0 || size_used_ > reserved) { ++ return false; ++ } + if (cb != nullptr) { + for (int i = 0; i < size_used_; ++i) { + if (!cb(f, data_ + i)) { +diff --git a/unittest/genericvector_test.cc b/unittest/genericvector_test.cc +new file mode 100644 +index 00000000..269b00f0 +--- /dev/null ++++ b/unittest/genericvector_test.cc +@@ -0,0 +1,91 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: genericvector_test.cc ++// Description: Tests that the callback form of GenericVector::read ++// rejects vectors whose size_used_ exceeds reserved (or ++// whose counts are negative). reserved sizes the buffer ++// while size_used_ is an independent file field driving ++// the element loop, so a crafted .traineddata (e.g. the ++// fontinfo table of a version >= 4 inttemp component) ++// performs a heap out-of-bounds write during legacy ++// engine initialization. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include "genericvector.h" ++#include "serialis.h" // for TFile ++ ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Appends raw little-endian values to a byte buffer. ++class ByteWriter { ++public: ++ void PutS32(int32_t v) { ++ uint32_t u = static_cast(v); ++ for (int i = 0; i < 4; ++i) { ++ data_.push_back(static_cast((u >> (8 * i)) & 0xFF)); ++ } ++ } ++ const std::vector &data() const { return data_; } ++ ++private: ++ std::vector data_; ++}; ++ ++// A serialized vector header (reserved, size_used_) followed by the ++// given number of int32 elements. ++std::vector MakeVector(int32_t reserved, int32_t size_used, int32_t num_elements) { ++ ByteWriter w; ++ w.PutS32(reserved); ++ w.PutS32(size_used); ++ for (int32_t i = 0; i < num_elements; ++i) { ++ w.PutS32(i); ++ } ++ return w.data(); ++} ++ ++// reserved=4 but size_used_=0x10000: on unpatched code the callback ++// loop writes 65536 ints past the 4-int buffer (heap out-of-bounds ++// write). ++TEST(GenericVectorTest, RejectsSizeUsedBeyondReserved) { ++ std::vector bytes = MakeVector(4, 0x10000, 0x10000); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ GenericVector v; ++ EXPECT_FALSE(v.read(&fp, [](TFile *f, int *p) { return f->DeSerialize(p); })); ++} ++ ++// Negative counts must be rejected; on unpatched code the read ++// "succeeds" and leaves size_used_ negative. ++TEST(GenericVectorTest, RejectsNegativeCounts) { ++ std::vector bytes = MakeVector(-1, -1, 0); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ GenericVector v; ++ EXPECT_FALSE(v.read(&fp, [](TFile *f, int *p) { return f->DeSerialize(p); })); ++} ++ ++// A consistent vector must still be accepted. ++TEST(GenericVectorTest, AcceptsConsistentVector) { ++ std::vector bytes = MakeVector(4, 2, 2); ++ TFile fp; ++ ASSERT_TRUE(fp.Open(bytes.data(), bytes.size())); ++ GenericVector v; ++ ASSERT_TRUE(v.read(&fp, [](TFile *f, int *p) { return f->DeSerialize(p); })); ++ EXPECT_EQ(v.size(), 2); ++ EXPECT_EQ(v[0], 0); ++ EXPECT_EQ(v[1], 1); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index 61cb1f7cad..60b50f16a5 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -15,6 +15,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-88049.patch \ file://CVE-2026-88050.patch \ file://CVE-2026-88047.patch \ + file://CVE-2026-88051.patch \ " From patchwork Thu Sep 24 04:33:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99137 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 95697C98312 for ; Thu, 24 Sep 2026 04:34:16 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.738.1790224448953964695 for ; Wed, 23 Sep 2026 21:34:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=IuXiPSnx; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8674704dab1so1511662b3a.2 for ; Wed, 23 Sep 2026 21:34:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224448; x=1790829248; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TnYz9qctaaiIUurcmrX0BgkZG2UkcVgty4SKhwas4W0=; b=IuXiPSnxemDaHlB8IM9xLd4kOwT1NzlsuXdfcYJnWSpL83uaI8ReTt2p2f7SMstvNF 4RLOG0xXWYphvwXPejcW1jMnaXjNgRZV2p0BsnkqcPaHGUPm0j2ZeVRrke8zhDuy/loJ RPqKwtiWdBPMFIJaHrxXWubaG6pX7qFKpOP38erYOx14HAphXpn1vAV9j8gvpXJTHxzg b6uYo6JWI2zTzWHWmA2O9JUv155y4dVrJ8Degk8+CkSFEKwJCQyAHbMra5Sy9CrXHXKi QwAyppf+jl4ximKwXvcyucx494ePNyKWXkA4ucvvQV9VkMOEqUhwAYTd+2qaxpxhTrRW e+hg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224448; x=1790829248; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TnYz9qctaaiIUurcmrX0BgkZG2UkcVgty4SKhwas4W0=; b=2MIYYIHXqSWYP676uTBMYtxUOc5bI5mebmQ20jy//5/B3S0k3EaacyeZev9FXE7Tx2 UqjT2G9BW4XYp2DW7PZzvt95KliaLiuE8t+Dw+Z/Ruye/T1CMeoyU52R6CahFS6dV3H9 EfOvUBLQTNtkvDTzlyfb3UZ40Sl/FMlhdWdyiAadw7sxKq3Ter7qYzRGvaLiRaeb06DY TNJoQSlxm4oBYjg5sRXHIZgO5Jq25SQwqR+X5g/twQ99utA8i6bxBbrbJatiigLuoLdS BO6CB9c0zfd7CBAQqOJhrN5QGYTO1W5/34W1ArgyK5U5nryLo2bsp24joAjqul/C//7R zShw== X-Gm-Message-State: AFuF++kL5G0rx79ctV1fslu8eMllWIxBqSxtoseWJmX1Lp24iqrUK+Xi vBDYZ2HPhJjqMjZgQr5Nbxz/0hSvulWB2fA0Yk40tMPkNW2wWJuau5Vq+AF56g== X-Gm-Gg: AYBFou17DDV2DpUGyR/zVAP1Ul7MKmxYu5m52x/rP+wU06M5udSn3SHOdkwwAFcIs7h n3jrnTAXOrJzugIozjloRKk+cn89bjI+jmU6ImtAZu2EJumg5+mgvwvuj6Rf05DyaTgWMVHZXep mijpF84zKBpC9Xb7PywQG6IaTmwOglQQUvea44liOhUhx+PcQGHwNmQZZfE6ndhdjbfT6sVs8Yq pVTR5x9uZuFZfE+omHH2GhcCw8YsEF6qMlcfvX02b5nToweoCA89Ep9cvO9jbbUiIOMYrdKNbuJ 3qOscpvru0ZkAwx+Lx8TWZZElXbZO0nEYLLpnD8FBBsQbA1MmP+56p6b8SIEhKByQ4FjT0LOLMP umx/a5F5jMTeZgBLO5sgxQvs330zbJ7NAGRyrNh9Jm7dyY4xh1rior1BR5ExsVEwhIfxmawUrx7 nVBFsR8nB7yFbGCslwoeMqUYcww49FVtcXK+O+t9qR6T7bV8NdgM6LO3dQzvWxTVUj+et77AIDM I5/eFnECWySEE2gKq4C/30= X-Received: by 2002:a05:6a00:1bca:b0:879:27a6:cc5b with SMTP id d2e1a72fcca58-87e9c543038mr1029245b3a.6.1790224448185; Wed, 23 Sep 2026 21:34:08 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:07 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 22/24] tesseract: patch CVE-2026-88054 Date: Thu, 24 Sep 2026 16:33:12 +1200 Message-ID: <20260924043315.1663186-22-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130270 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-88054 Signed-off-by: Ankur Tyagi --- .../tesseract/tesseract/CVE-2026-88054.patch | 275 ++++++++++++++++++ .../tesseract/tesseract_5.5.2.bb | 1 + 2 files changed, 276 insertions(+) create mode 100644 meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88054.patch diff --git a/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88054.patch b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88054.patch new file mode 100644 index 0000000000..e89df4c477 --- /dev/null +++ b/meta-oe/recipes-graphics/tesseract/tesseract/CVE-2026-88054.patch @@ -0,0 +1,275 @@ +From 3e9dc6d17fbbba936ca0c18a785cc481e6539555 Mon Sep 17 00:00:00 2001 +From: Stefan Weil +Date: Fri, 21 Aug 2026 14:38:55 +0200 +Subject: [PATCH] Reject empty network stacks in LSTM .traineddata + deserialization + +Plumbing::DeSerialize read the network stack size from the untrusted +TESSDATA_LSTM component and only rejected size > 10000. A crafted +.traineddata with a top-level Series/Parallel/Reversed layer with an +empty stack survived load; LSTMRecognizer initialization then called +network_->CacheXScaleFactor(network_->XScaleFactor()), which +dereferences stack_[0] on the empty vector: +- Series: Series::CacheXScaleFactor (series.cpp) +- Parallel/Reversed: inherited Plumbing::XScaleFactor +The virtual call through the wild pointer crashed the process at +initialization (deterministic denial of service). + +Key changes: +- plumbing.cpp: reject size == 0 for all plumbing types, and + size < 2 for NT_SERIES (Series::Forward requires two or more + networks and always aborts on one). +- tessedit.cpp: fail the language load gracefully when the LSTM model + cannot be loaded, instead of aborting via ASSERT_HOST, so + TessBaseAPI::Init returns -1 on corrupt traineddata. +- unittest: add plumbing_test, which builds a minimal traineddata + with empty/undersized LSTM plumbing stacks and expects a graceful + init failure. On unpatched code the tests die on the original + SEGV in Series::CacheXScaleFactor / Plumbing::XScaleFactor. + +Reported-by: Zhixi "Jace" Sun +Assisted-by: OpenCode / qwen3.8-27b-thinking (Alibaba Cloud) +Signed-off-by: Stefan Weil +(cherry picked from commit 552771236b0d80cbdb0c7dd856120fa21a4672e5) + +CVE: CVE-2026-88054 +Upstream-Status: Backport [https://github.com/tesseract-ocr/tesseract/commit/552771236b0d80cbdb0c7dd856120fa21a4672e5] + +Signed-off-by: Ankur Tyagi +--- + Makefile.am | 5 ++ + src/ccmain/tessedit.cpp | 7 +- + src/lstm/plumbing.cpp | 6 ++ + unittest/plumbing_test.cc | 165 ++++++++++++++++++++++++++++++++++++++ + 4 files changed, 182 insertions(+), 1 deletion(-) + create mode 100644 unittest/plumbing_test.cc + +diff --git a/Makefile.am b/Makefile.am +index d2b503d4..76978570 100644 +--- a/Makefile.am ++++ b/Makefile.am +@@ -1227,6 +1227,7 @@ if ENABLE_TRAINING + check_PROGRAMS += pango_font_info_test + endif # ENABLE_TRAINING + check_PROGRAMS += paragraphs_test ++check_PROGRAMS += plumbing_test + if !DISABLED_LEGACY_ENGINE + check_PROGRAMS += params_model_test + endif # !DISABLED_LEGACY_ENGINE +@@ -1456,6 +1457,10 @@ paragraphs_test_SOURCES = unittest/paragraphs_test.cc + paragraphs_test_CPPFLAGS = $(unittest_CPPFLAGS) + paragraphs_test_LDADD = $(TESS_LIBS) + ++plumbing_test_SOURCES = unittest/plumbing_test.cc ++plumbing_test_CPPFLAGS = $(unittest_CPPFLAGS) ++plumbing_test_LDADD = $(TESS_LIBS) ++ + if !DISABLED_LEGACY_ENGINE + params_model_test_SOURCES = unittest/params_model_test.cc + params_model_test_CPPFLAGS = $(unittest_CPPFLAGS) +diff --git a/src/ccmain/tessedit.cpp b/src/ccmain/tessedit.cpp +index c7518883..fcbf5d9b 100644 +--- a/src/ccmain/tessedit.cpp ++++ b/src/ccmain/tessedit.cpp +@@ -170,7 +170,12 @@ bool Tesseract::init_tesseract_lang_data(const std::string &arg0, + #endif // ndef DISABLED_LEGACY_ENGINE + if (mgr->IsComponentAvailable(TESSDATA_LSTM)) { + lstm_recognizer_ = new LSTMRecognizer(language_data_path_prefix.c_str()); +- ASSERT_HOST(lstm_recognizer_->Load(this->params(), lstm_use_matrix ? language : "", mgr)); ++ if (!lstm_recognizer_->Load(this->params(), lstm_use_matrix ? language : "", mgr)) { ++ delete lstm_recognizer_; ++ lstm_recognizer_ = nullptr; ++ tprintf("Error: Failed to load the LSTM model from %s\n", tessdata_path.c_str()); ++ return false; ++ } + } else { + tprintf("Error: LSTM requested, but not present!! Loading tesseract.\n"); + tessedit_ocr_engine_mode.set_value(OEM_TESSERACT_ONLY); +diff --git a/src/lstm/plumbing.cpp b/src/lstm/plumbing.cpp +index f0133148..15cf3d62 100644 +--- a/src/lstm/plumbing.cpp ++++ b/src/lstm/plumbing.cpp +@@ -226,6 +226,12 @@ bool Plumbing::DeSerialize(TFile *fp) { + if (size > 10000) { + return false; + } ++ // Reject empty stacks: XScaleFactor, CacheXScaleFactor and other methods ++ // unconditionally dereference stack_[0] during network initialization. ++ // A Series needs at least two networks (see Series::Forward). ++ if (size == 0 || (type() == NT_SERIES && size == 1)) { ++ return false; ++ } + for (uint32_t i = 0; i < size; ++i) { + Network *network = CreateFromFile(fp); + if (network == nullptr) { +diff --git a/unittest/plumbing_test.cc b/unittest/plumbing_test.cc +new file mode 100644 +index 00000000..27486f86 +--- /dev/null ++++ b/unittest/plumbing_test.cc +@@ -0,0 +1,165 @@ ++/////////////////////////////////////////////////////////////////////// ++// File: plumbing_test.cc ++// Description: Tests that a corrupt TESSDATA_LSTM component in a ++// .traineddata file is rejected without crashing. A ++// plumbing layer (Series/Parallel/Reversed) with an ++// empty or undersized network stack would make ++// XScaleFactor/CacheXScaleFactor dereference stack_[0] ++// during engine initialization. ++// ++// Licensed under the Apache License, Version 2.0 (the "License"); ++// you may not use this file except in compliance with the License. ++// You may obtain a copy of the License at ++// http://www.apache.org/licenses/LICENSE-2.0 ++// ++/////////////////////////////////////////////////////////////////////// ++ ++#include "include_gunit.h" ++ ++#include ++ ++#include "network.h" // for NetworkType ++#include "tessdatamanager.h" // for TessdataManager, TESSDATA_LSTM ++ ++#include ++#include ++#include ++#include ++#include ++#include ++ ++namespace tesseract { ++namespace { ++ ++// Minimal unicharset with the special codes (space, Joined, Broken) that ++// UNICHARSET::load_from_file expects, as embedded in the TESSDATA_LSTM ++// component by LSTMRecognizer::Serialize. ++const char kMinUnicharset[] = ++ "3\n" ++ "NULL 0 NULL 0\n" ++ "Joined 7 0,69,188,255,486,1218,0,30,486,1188 Latin 26 0 98 Joined\n" ++ "|Broken|0|1 f 0,69,186,255,892,2138,0,80,892,2058 Common 84 10 84 |Broken|0|1\n"; ++ ++// Appends raw little-endian values to a byte buffer. ++class ByteWriter { ++public: ++ void PutU8(uint32_t v) { data_.push_back(static_cast(v & 0xFF)); } ++ void PutU32(uint32_t v) { ++ for (int i = 0; i < 4; ++i) { ++ data_.push_back(static_cast((v >> (8 * i)) & 0xFF)); ++ } ++ } ++ void PutS32(int32_t v) { PutU32(static_cast(v)); } ++ void PutString(const char *s) { ++ PutU32(static_cast(std::strlen(s))); ++ data_.insert(data_.end(), s, s + std::strlen(s)); ++ } ++ void PutRaw(const char *s) { data_.insert(data_.end(), s, s + std::strlen(s)); } ++ const std::vector &data() const { return data_; } ++ ++private: ++ std::vector data_; ++}; ++ ++// Serialized network header as written by Network::Serialize: ++// int8 type, int8 training, int8 needs_to_backprop, int32 network_flags, ++// int32 ni, int32 no, int32 num_weights, string name. ++void AppendNetworkHeader(ByteWriter *w, NetworkType type) { ++ w->PutU8(static_cast(type)); ++ w->PutU8(0); // training: TS_DISABLED ++ w->PutU8(0); // needs_to_backprop ++ w->PutU32(0); // network_flags ++ w->PutU32(0); // ni ++ w->PutU32(0); // no ++ w->PutU32(0); // num_weights ++ w->PutString(""); // name ++} ++ ++// A minimal valid child network (NT_INPUT with a 1x1x1x1 shape). ++void AppendInputChild(ByteWriter *w) { ++ AppendNetworkHeader(w, NT_INPUT); ++ w->PutS32(1); // batch ++ w->PutS32(1); // height ++ w->PutS32(1); // width ++ w->PutS32(1); // depth ++ w->PutS32(0); // loss type ++} ++ ++// Builds a TESSDATA_LSTM component whose top-level network is a plumbing ++// layer of the given type with the given (corrupt) stack size, followed by ++// the remaining fields of LSTMRecognizer::DeSerialize. ++std::vector MakeLstmComponent(NetworkType type, uint32_t stack_size) { ++ ByteWriter w; ++ AppendNetworkHeader(&w, type); ++ w.PutU32(stack_size); // Plumbing::DeSerialize reads this as uint32 ++ for (uint32_t i = 0; i < stack_size; ++i) { ++ AppendInputChild(&w); ++ } ++ w.PutRaw(kMinUnicharset); // unicharset (raw text, no recoder/unicharset components) ++ w.PutString(""); // network_str_ ++ w.PutS32(0); // training_flags_ ++ w.PutS32(0); // training_iteration_ ++ w.PutS32(0); // sample_iteration_ ++ w.PutS32(0); // null_char_ ++ w.PutU32(0); // adam_beta_ (float 0.0) ++ w.PutU32(0); // learning_rate_ (float 0.0) ++ w.PutU32(0); // momentum_ (float 0.0) ++ return w.data(); ++} ++ ++// Writes a traineddata file with the given (corrupt) LSTM component to ++// dir/eng.traineddata. ++bool WriteCorruptTraineddata(const std::string &dir, const std::vector &lstm) { ++ TessdataManager mgr; ++ mgr.OverwriteEntry(TESSDATA_LSTM, lstm.data(), static_cast(lstm.size())); ++ return mgr.SaveFile((dir + "/eng.traineddata").c_str(), nullptr); ++} ++ ++class PlumbingTest : public testing::Test { ++protected: ++ void SetUp() override { ++ tmpl_ = "/tmp/tess_plumbing_test_XXXXXX"; ++ char *dir = mkdtemp(tmpl_.data()); ++ ASSERT_NE(dir, nullptr); ++ dir_ = dir; ++ } ++ void TearDown() override { ++ std::remove((dir_ + "/eng.traineddata").c_str()); ++ rmdir(dir_.c_str()); ++ } ++ // Expects the LSTM engine to reject the corrupted traineddata ++ // gracefully (init failure) instead of crashing. ++ void ExpectInitFails(const std::vector &lstm) { ++ ASSERT_TRUE(WriteCorruptTraineddata(dir_, lstm)); ++ tesseract::TessBaseAPI api; ++ EXPECT_EQ(api.Init(dir_.c_str(), "eng", tesseract::OEM_LSTM_ONLY), -1); ++ } ++ std::string dir_; ++ std::string tmpl_; ++}; ++ ++// Empty NT_SERIES stack: Series::CacheXScaleFactor would dereference ++// stack_[0] on the empty vector during initialization. ++TEST_F(PlumbingTest, RejectsEmptySeriesStack) { ++ ExpectInitFails(MakeLstmComponent(NT_SERIES, 0)); ++} ++ ++// Empty NT_PARALLEL stack: Plumbing::XScaleFactor would dereference ++// stack_[0] on the empty vector during initialization. ++TEST_F(PlumbingTest, RejectsEmptyParallelStack) { ++ ExpectInitFails(MakeLstmComponent(NT_PARALLEL, 0)); ++} ++ ++// Empty NT_XREVERSED stack: same crash as the parallel case. ++TEST_F(PlumbingTest, RejectsEmptyReversedStack) { ++ ExpectInitFails(MakeLstmComponent(NT_XREVERSED, 0)); ++} ++ ++// A Series with a single network: Series::Forward requires at least two ++// networks, so such a model can never work. ++TEST_F(PlumbingTest, RejectsSingleNetworkSeries) { ++ ExpectInitFails(MakeLstmComponent(NT_SERIES, 1)); ++} ++ ++} // namespace ++} // namespace tesseract diff --git a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb index 60b50f16a5..b537fe56bd 100644 --- a/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb +++ b/meta-oe/recipes-graphics/tesseract/tesseract_5.5.2.bb @@ -16,6 +16,7 @@ SRC_URI = "git://github.com/${BPN}-ocr/${BPN}.git;branch=main;protocol=https;tag file://CVE-2026-88050.patch \ file://CVE-2026-88047.patch \ file://CVE-2026-88051.patch \ + file://CVE-2026-88054.patch \ " From patchwork Thu Sep 24 04:33:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99135 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA4CEC982FD for ; Thu, 24 Sep 2026 04:34:15 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.743.1790224450974303533 for ; Wed, 23 Sep 2026 21:34:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Nb8/WKM3; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85469f204f6so829406b3a.2 for ; Wed, 23 Sep 2026 21:34:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224450; x=1790829250; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sziH8+UsrCrq7HRSzs0iSTQTQXRGh5t9uyqdZUe91VI=; b=Nb8/WKM3y32usA06VdHcWWwKhwrWgNhk94z/L5xNxBdC55vskRxsiCig8PfHnb+AE5 d7IAtS16da8z+QZXIulNl/l4StFqDMvWAMEIFNbSxIx0nsPHHy/Ldejatosat//Jib70 iG2JdaeyTytaVWxbVXBbC674aTwTVZZo4yW8L9lBC3id2of94nFDOLI2qBvplvmz7IV1 uGxSMBbxCC39xdgiZSP5I9nXAmHUn5b4LvKbwYa5S+nGCRiDaTAMYUbVmB+NJKUm4ssh Dw+G3wvSyN1CU/DPPhvdlDvVvfxz30+hTVXejLIWQIHBlmaTJSX7AOWanwmjq/q+RhcK yrlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224450; x=1790829250; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=sziH8+UsrCrq7HRSzs0iSTQTQXRGh5t9uyqdZUe91VI=; b=Du5JDnqoXquBR2Z9z/AOdVbLVTndhDACN59daYhrDwxRwfW9/aRrG+oS7vmQoBYLHH QtALesVFBu6z4gh2i5+bC0Ef14zEQrrSo+pYRlWBUb0ABzONfI1MUEk4POwuafbKb02i 0YhCFYBN9UlIwHEB00xe+rjG9OUoiyeRBuepAlYXr74PjaS4J1kcf2n5Wcjewcymcit5 jzCdMXIBD4959zbHzuz6y5aPifEajy+JJOb44ANX4WyuqE/dG+yXgTgFoLJ5M5Gva+5L oZSRL6QFzpSfef0DJmSnNhu67aj+Xw3kHVW6A3K23Mprk17UN0OCSgxVhDlatUnuCBD8 q61w== X-Gm-Message-State: AFuF++lua0t9gy+uI71YGKMcNERJgFU1P9oJtoGckIEsr4swn0e+El1p zRCDsFPPjYmFGSf2nDvzOwT3YtplP5IXHKIAW4ivPLLJ+V+i/iQ/Um19jVZW3Q== X-Gm-Gg: AYBFou3tG1ZYB+++t58x3OcTlEXG0s97qBw4RiaNhFhn/1EGCh5RXv/654EMIOdcjWz VPYv74d2b3WN/GF5OTNwbzakIyo5S1xz8QWSQiyZWwRCIt2r4c9qJx9pOLgYrmVvHBI7gZSBM5B upDJNxMw6TrQUO5pm05/yOYhAxGKJgd1uwns7oDmAr0PwtQKNGbxpu91+hhp6cdgyf3oKMlmlrW 84GU/93T8m5GsLdzk6XCtxQ/sbpSaJsD8/oU8R8RdtcPJvx2RaEJ1EbQy9wUY8u9wmk/tjZEnDW VpSuI9uiqMgpy2G4RLetrzOgb6NsYRtT/8TVUbs7woH0wgM3nZAdeKY3PH6DYX/w8UNmMpTtIIj LVl40XP0vfoIZQR5OLQI55Hvv2hi9LMXXc7W4ng+TlaLvYZdIy+PxEXK7PJqZ7GRVik0BcEuvPT Fx+x6goTyvZQTmejeNiU2FsahlGZVbCLwSnktyB7E5bwiEpS2MBUPUW90iz4QLwLWprclSFeple phaDLaw2w+yubV94eKUr9SGwa9q+JA04w== X-Received: by 2002:a05:6a00:2d99:b0:874:708d:b61f with SMTP id d2e1a72fcca58-87e9b69f768mr985148b3a.29.1790224450278; Wed, 23 Sep 2026 21:34:10 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:09 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 23/24] valkey: upgrade 9.0.5 -> 9.0.6 Date: Thu, 24 Sep 2026 16:33:13 +1200 Message-ID: <20260924043315.1663186-23-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130271 From: Ankur Tyagi Changelog: https://github.com/valkey-io/valkey/releases/tag/9.0.6 Signed-off-by: Ankur Tyagi --- .../valkey/{valkey_9.0.5.bb => valkey_9.0.6.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-oe/recipes-extended/valkey/{valkey_9.0.5.bb => valkey_9.0.6.bb} (98%) diff --git a/meta-oe/recipes-extended/valkey/valkey_9.0.5.bb b/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb similarity index 98% rename from meta-oe/recipes-extended/valkey/valkey_9.0.5.bb rename to meta-oe/recipes-extended/valkey/valkey_9.0.6.bb index d7ce19ce72..7b20612130 100644 --- a/meta-oe/recipes-extended/valkey/valkey_9.0.5.bb +++ b/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb @@ -15,7 +15,7 @@ SRC_URI = "git://github.com/valkey-io/valkey.git;branch=9.0;protocol=https;tag=$ file://0001-src-Do-not-reset-FINAL_LIBS.patch \ file://GNU_SOURCE-7.patch \ " -SRCREV = "a253513ac7ff5790ca119053f3c7fbca4fdaad44" +SRCREV = "a100149d56208209c03f8af9840afe2efa7fb8d1" RPROVIDES:${PN} = "virtual-redis" From patchwork Thu Sep 24 04:33:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99136 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7BDE1C98304 for ; Thu, 24 Sep 2026 04:34:16 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.744.1790224452998049638 for ; Wed, 23 Sep 2026 21:34:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=YLb6C/Jc; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469b35611so793651b3a.0 for ; Wed, 23 Sep 2026 21:34:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790224452; x=1790829252; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/cSSzVvvR7/fgCYqNTFy/f4WWti3goPRIp+aP5xwuxY=; b=YLb6C/JcHae/3rKxd/6+N7yvzqhqUNbF3NVLaYetxbN5GPktSdh3Br7eLjVRLjV2+1 3F0O2PIPhhrV4dhoSHEhSwKvmJq+373i83ErYkEoHHPNkQwqwCLkPQWeTbg3HNI7RUjc rbHUJf6F84wouLrjDFOxBccPsb4cHlMtwPfccUUOuEw7SCuhbeVgTVsbyHmzXA3bXGeT li2X2SetO5sDU5vlwQVFi+aHdBstKLyD4kiqh1xPubCUrvvHZD66hdHvI/MCgfAuuxzs a3nzxwRRM7DIF+hw/CojMKQv6cJMhDa9oOYnJcLoRPif14eDCl12uGOtN5rakUylyysw zs8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790224452; x=1790829252; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/cSSzVvvR7/fgCYqNTFy/f4WWti3goPRIp+aP5xwuxY=; b=Yv47x5aFDOr/GzOj2BNSAFN8Wlwpu6QINS9BW8FROFbZtqOJsSmkhDhoq1kUaJgh6L BvOAlSZMWr33EEYeXoYnpvfBuelu68cprg0SledDxC9HNRAbL3bfBN1ahDqzzBnNeJzU MvpHIwVNN2FfPaV0z+/sBDZUqW/+unyLDBUb2se0ujd3jX3WVr6XrW+P7XUoYLNThVok 4T7bXg+wpm0vovqBMGs6hw6JeJ1SWhZ8cxXlU7QR7QzVn4rCoA/rj7nf3c1EXxDnA/pp 5jy8Ifohm49omTxftjr+bHYs5nPOuiCT978UPPlHjVrDDYxXm9tMrPDUJZZSEK1uUBus JEyA== X-Gm-Message-State: AFuF++nLgT5xo2HzgwgUVzCleEsWXgkiHl3GiQopTH0xI0Pehg4fPzg0 2bO4ktI1eNwvQGZD+iMxNacOVFaKFQ2sy6SpYoyg0Ek0Xh759kj4rXGdC3JFNw== X-Gm-Gg: AYBFou2MQeTj8M65i/BI1el6f9XtugRUD/JLY597TNIljIfC84sS0BhZqYkt5Vmas2K YDT58VjlE5FpHJ7ndp6tylUgGssAQMHT2V42ERS2lD/SOhVnwdZtTcbt1XEF1hLBxw9eHaLwwXj muDrXk2S7I1hGiDv9lIfjFM4CLILTqUCUFUXhSfhxu30/Of25dkQ7CT0HPJaysHbQ8lDMBznRqs 5o3RPELnqIb9rX+iw3c8BSMw1/90xJCQ0NQh7JuDASGrJFHWMgVvz/Klr/jdIEAvzqnmAS/qJkb JQwCBOazm+0etFEG8Ctw4AttlaX/bU2IeSelHgBa3UzWnsqXt/Zt58ycrbeQ+pLOJVPRUcPtefF BTPzhJRC9/BoZ9js1BDJOKXWLvaB0GqYSXLAux49gMD5tsnGL+2fjhxLtP4wTDsBjlcIVtAD3nm ydJX8nqOEYg/N4oA8gRAvjHt3bAGAfkXbGG6AJ05LMeXGKJ6SFHUznXzf1T2gEkk2mz6QZFl9VB IHm4+KvtTwegiIanj/MYDA= X-Received: by 2002:a05:6a00:10d2:b0:87c:9094:b72f with SMTP id d2e1a72fcca58-87e98789dbdmr1078355b3a.12.1790224452275; Wed, 23 Sep 2026 21:34:12 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1e601b5dsm2189686b3a.61.2026.09.23.21.34.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 21:34:11 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 24/24] valkey: mark CVE-2026-86227 fixed Date: Thu, 24 Sep 2026 16:33:14 +1200 Message-ID: <20260924043315.1663186-24-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> References: <20260924043315.1663186-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 24 Sep 2026 04:34:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130272 From: Ankur Tyagi Fix[1] for the CVE is part of current upstream version. Details: https://nvd.nist.gov/vuln/detail/cve-2026-86227 [1]https://github.com/valkey-io/valkey/commit/b7c39406bbfac01068c1469df28b22ccf1ecc102 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-extended/valkey/valkey_9.0.6.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb b/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb index 7b20612130..d31a5dbfe5 100644 --- a/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb +++ b/meta-oe/recipes-extended/valkey/valkey_9.0.6.bb @@ -76,3 +76,4 @@ SYSTEMD_SERVICE:${PN} = "valkey.service" CVE_STATUS[CVE-2022-3734] = "not-applicable-platform: CVE only applies for Windows." CVE_STATUS[CVE-2026-56684] = "fixed-version: fixed in v9.0.5" CVE_STATUS[CVE-2026-63639] = "fixed-version: fixed in v9.0.5" +CVE_STATUS[CVE-2026-86227] = "fixed-version: fixed in v9.0.6"