From patchwork Tue Sep 29 04:18:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99545 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A918CA5FB3 for ; Tue, 29 Sep 2026 04:18:40 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.655.1790655517558975401 for ; Mon, 28 Sep 2026 21:18:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=cQ6uvzjB; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3514; q=dns/txt; s=iport01; t=1790655517; x=1791865117; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=ZSBU+hkMiyqkuYAAiGJ6YYWtNGBaUCtRgI5/YNAXevM=; b=cQ6uvzjBhereDkpDALm4MejsGaoNUfCDKOtQ6J03ETrVrXwgDUidSS1o eG5wtyXLMzEgFVLzA3vAWB4ujeE49zO4/zM5twwduzQYccWJZxK5aofJ4 twvaoblk26WrHSft05jqzXGSRArCajZSlJMYky3XsuP6OSYRwqyTaGxtE o4GQ3dWpnVwUvXQJyPuMFYJJ4qkRY8cnJty3+FWTnq8t9O6YAAxvbuWMW ODgzfsXXt2sEupyOfL0e//zmfhsDlM4rYnyc8/64yP+zGtb4ZyPyuwr0k HrgglEGhQGDd2e9M02t7RnRLQ7+PYmgSzn5MFHZweYa5k2ngEpyDVu0u4 w==; X-CSE-ConnectionGUID: dV/fGTf4Smi0IdNBuyFRbw== X-CSE-MsgGUID: QuCQxboaQX2W8BkZhaUP3Q== X-IPAS-Result: A0BGAgBDO7tq/5D/Ja1aHgEBCxIMggULgld1YUJJlkqLZ5I2gX4PAQEBD0QNBAEBhD9GjgoCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBIBAgEqCwEYAS0sAwECTwsjIYMCAYI6AzcCARHAAYF5M4EBgykBPwJDUNhLDYJaAQsUAQWBM4VAgn+FJF0YAYR8JxsbgXKBFYNpgQWBGkIBAQKIIwSCIoEMgVoekzhIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEgghkjGTZ6gQlegSspYAEQF4EHggcCglSCAQIBSUMOB0VTCSVFEkcmIggSCQETGjALgSE4QQkoPxgNSBEsNxUZBD5uB5A/HoIYTQF6CQoBKgEigSFBo32CIaAecQoog3aMIo8+hXwaM4QElBeSVAuYfY4KhAmRX2iEaYFoPIFHCwdwFYMiCUoZD445g2uBf4MUxyYkNQIJMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:aGZ8Dazn7gtjd3ZkkN56t+dhxyrEfRIJ4+MujC+fZmUNrF6WrkUFz mdOUW+Gbv6MZGWjf40iYIWw8kIAusTTzIRmSwtuqFhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCKa/lHyYuCJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 4yaT/H3Ygf/hWYlaDJMscpvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJE0IeoM3xugrOmRPr d0UDhoQfz65jf3jldpXSsE07igiBNPgMIVavjRryivUSK55B5vCWK7No9Rf2V/chOgXQq2YP JVfM2cyKk2cP3WjOX9PYH46tOe0hnD8eidwo1OOrq1x6G/WpOB0+OW3YIeOJYbRGK25mG6hu 0n/727+CygqbuPP4zm38nuRvrT2yHaTtIU6UefQGuRRqFqLy2oeDRcbWVe2rbyyjVSzc9ZeM FAPvC02oK4/8UamQtXwU1u/unHsg/IHc8BbH+t/7ESGzbDZpl7GQGMFVTVGLtchsafaWAAX6 7NApPuxbRQHjVFfYSv1Gmu8xd9qBRUoEA== IronPort-HdrOrdr: A9a23:S5oZGKiZbAf4AghiABaTZAuwuHBQXvYji2hC6mlwRA09TyVXra +TdZMgpHrJYVkqOU3I9ersBEDiewK/yXcK2+ks1N6ZNWGM0ldAR7sN0WKN+VHd8gTFh4pgPN 9bAstDIey1K0RmhsDn5wT9OdMhzN6btJ2Mv47lvhBQpcUAUdAY0++/YTzrdHFLeA== X-Talos-CUID: 9a23:Z8P6+GNRkqz1me5DVBcg+mEoFJwed3yF7Xv2CVKpJ1xjV+jA X-Talos-MUID: 9a23:l7RVVwp0Cu9rea2me2wezwh/H/546aOnMXBXrsUsuPuEPBFIYA7I2Q== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528537235" Received: from rcdn-l-core-07.cisco.com ([173.37.255.144]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-07.cisco.com (Postfix) with ESMTPS id A4F01180003C9; Tue, 29 Sep 2026 04:18:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 4AC62CC1292; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 1/8] libxml2: Fix CVE-2026-86137 Date: Mon, 28 Sep 2026 21:18:29 -0700 Message-Id: <20260929041836.2217090-1-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246813 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86137 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86137.patch | 59 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 60 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch new file mode 100644 index 0000000000..a756883d46 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch @@ -0,0 +1,59 @@ +From a9d489b86e46188d1c0fde7dbd0aa8281596e6d6 Mon Sep 17 00:00:00 2001 +From: Hieu Le Minh +Date: Sat, 18 Apr 2026 21:18:24 +0700 +Subject: [PATCH] xmlregexp: Prevent out-of-bounds read in NXT macro + +Fixes: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1099 + +CVE: CVE-2026-86137 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2] + +Backport Changes: +- Add the parser-context length field and allocation-failure guard required by the Scarthgap 2.12.10 source, which lacks both pieces of the upstream context. +- The allocation-failure guard is completed by the subsequent CVE-2026-86141.patch, which moves strlen() after the xmlStrdup() null check; keep that patch after this one in SRC_URI. + +(cherry picked from commit 76fe08d97de88bfaef2f7d5cd27f11954cc5bee2) +Signed-off-by: Hetvi Thakar +--- + xmlregexp.c | 13 +++++++++++-- + 1 file changed, 11 insertions(+), 2 deletions(-) + +diff --git a/xmlregexp.c b/xmlregexp.c +index f434a0cf..320a35ce 100644 +--- a/xmlregexp.c ++++ b/xmlregexp.c +@@ -56,7 +56,9 @@ + xmlRegexpErrCompile(ctxt, str); + #define NEXT ctxt->cur++ + #define CUR (*(ctxt->cur)) +-#define NXT(index) (ctxt->cur[index]) ++#define NXT(index) \ ++ (((size_t)(ctxt->cur + index - ctxt->string) < ctxt->len) \ ++ ? ctxt->cur[index] : 0) + + #define NEXTL(l) ctxt->cur += l; + #define XML_REG_STRING_SEPARATOR '|' +@@ -245,6 +247,7 @@ typedef xmlRegParserCtxt *xmlRegParserCtxtPtr; + struct _xmlAutomata { + xmlChar *string; + xmlChar *cur; ++ size_t len; + + int error; + int neg; +@@ -698,8 +701,14 @@ xmlRegNewParserCtxt(const xmlChar *string) { + if (ret == NULL) + return(NULL); + memset(ret, 0, sizeof(xmlRegParserCtxt)); +- if (string != NULL) ++ if (string != NULL) { + ret->string = xmlStrdup(string); ++ ret->len = strlen((const char *) ret->string); ++ if (ret->string == NULL) { ++ xmlFree(ret); ++ return(NULL); ++ } ++ } + ret->cur = ret->string; + ret->neg = 0; + ret->negs = 0; diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index d476ba14b6..e4db345af4 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -32,6 +32,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-0992-03.patch \ file://CVE-2026-1757.patch \ file://CVE-2026-11979.patch \ + file://CVE-2026-86137.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99543 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CA204CA5FAC for ; Tue, 29 Sep 2026 04:18:38 +0000 (UTC) Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.656.1790655517560151638 for ; Mon, 28 Sep 2026 21:18:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=WXlLwNlr; spf=pass (domain: cisco.com, ip: 173.37.86.80, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3346; q=dns/txt; s=iport01; t=1790655517; x=1791865117; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=gXHW8rSiFUZKra4+wlt4bwickkJVQNpF7+sPEE6ibo0=; b=WXlLwNlrw5YM4s4UCHrY75Y2XEZIsL2qvx2jj+ZIQ+BQrOhUfBCy1DOY suefzq8OewOEncFkfx67Gv2y6jUe8KCve/loa3a/l59xYmSI7kYtG66OV sb+XgOlcpECD5cLJ3R+79qrk/tmJL5DYd3SogAePejC9buQthz1aXhyWE m392P6QDFBcG9UxbcykSv4fRQAh+wi/WvhDMrgk/W77Qo7yDQqwuPlP87 XG2KQsScAAK68IVcshQyxyQxU3yoFHrAnha41yHwqU+RbHaTiT5Owl2il LlGyWbuJI0r9YbMWlJ0vQNAzhAALoIp67xfP4RVSsvSUqbDVw7WHZCWrf w==; X-CSE-ConnectionGUID: rEvbAvW5Rpijl3LNxY2HWQ== X-CSE-MsgGUID: dmWBPNilQcuAI6JVPjPqUA== X-IPAS-Result: A0BIAgDTOrtq/5D/Ja1aHgEBCxIMggULgld1YUJJlkoDi2SSNoF+DwEBAQ9EDQQBAYQ/RgKOCAImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QEgECAQMyARgBLRAcAwECLyALIwgZgwIBgjoDNwIBEcAJgiyBAYMpAT8CQ1DYSw2CWgELFAEFgTOFQIJ/hSRdGAGEfCcbG4FygRWDaYEFgRpCAQECiCMEgiKBDIFaHpM4SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BIIIZIxk2eoEJXoErKWABEBeBB4IHAoJUggECAUlDDgdFUwklRRJHJiIIEgkBExowC4EhOEEJKD8YDUgRLDcVGQQ+bgeQPx6CGDoMB4EOASoBpgGCIaAecQoog3aMIo8+hXwaM6pvC5h9jgqECZJHhGmBaDyBRwsHcBWDIglKGQ+OOYNrgX+DFMcmJDUCCTIBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:Xtt9ZayJGoAA72GzpV56t+dhxyrEfRIJ4+MujC+fZmUNrF6WrkVTm 2cZXzyGP/iIZWegetF1ad++904F7MDTyNRgTQdkrFhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCKa/lHyYuCJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 4yaT/H3Ygf/hWYlaDJMscpvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJFsbI4cx5NkqO3lP9 /hDDBYdX0qjuNvjldpXSsE07igiBNPgMIVavjRryivUSK55B5vCWK7No9Rf2V/chOgXQq2YP JVfM2cyKk2cP3WjOX9PYH46tOe0hnD8eidwo1OOrq1x6G/WpOB0+OW3b4qJI43XFK25mG6Uo 13sx0L4BigRKfW+lxi7ynCUn9LmyHaTtIU6UefQGuRRqFqLy2oeDRcbWVe2rbyyjVSzc9ZeM FAPvC02oK4/8UamQtXwU1u/unHsg/IHc8BbH+t/7ESGzbDZpl7GQGMFVTVGLtchsafaWAAX6 7NApPuxbRQHjVFfYSj1Gmu8xd9qBRUoEA== IronPort-HdrOrdr: A9a23:ReeLvK9gXJu0desAZ59uk+AAI+orL9Y04lQ7vn2ZhyY7TiX+rb HIoB11737JYVoqNU3I3OrwWpVoIkmskaKdn7NwAV7KZmCP0wGVxcNZnO7fKlbbdREWmNQw6U 5ISdkZNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAY0++8YTzraXGfg2J9dOIEKK Y= X-Talos-CUID: 9a23:lITB5mjA+lajOFJAjj4J9oAlTTJuaFDDxl7OHBKCEWdrTOaxb0+hooNbqp87 X-Talos-MUID: 9a23:nL82ug6Divk1kNIt0aBtAUK4xoxk5puEMGYMlawNpuClaw5OAzWllQmeF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="527841959" Received: from rcdn-l-core-07.cisco.com ([173.37.255.144]) by rcdn-iport-9.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-07.cisco.com (Postfix) with ESMTPS id A66F3180003E5; Tue, 29 Sep 2026 04:18:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 4E4A6CC129C; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 2/8] libxml2: Fix CVE-2026-86138 Date: Mon, 28 Sep 2026 21:18:30 -0700 Message-Id: <20260929041836.2217090-2-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246810 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86138 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86138.patch | 52 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch new file mode 100644 index 0000000000..9b918f7570 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch @@ -0,0 +1,52 @@ +From d2e3efc8502313a1099ccc4aac19e8e03734e8c9 Mon Sep 17 00:00:00 2001 +From: mohammadmseet-hue +Date: Thu, 16 Apr 2026 02:54:24 +0200 +Subject: [PATCH] fix: add overflow checks to xmlDictAddQString in dict.c + +xmlDictAddString has overflow guards for pool size calculations, but its +sibling xmlDictAddQString lacks these entirely. The namelen + plen + 1 +addition can overflow unsigned int, and 4 * (overflowed_value) produces +a small allocation, leading to heap buffer overflow when memcpy writes +the prefix and name. + +Add the same SIZE_MAX-based overflow guards and safe size_t cast. + +CVE: CVE-2026-86138 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4] + +(cherry picked from commit a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4) +Signed-off-by: Hetvi Thakar +--- + dict.c | 19 +++++++++++++++---- + 1 file changed, 15 insertions(+), 4 deletions(-) + +diff --git a/dict.c b/dict.c +index d7156ed3..ae0210ea 100644 +--- a/dict.c ++++ b/dict.c +@@ -225,10 +225,21 @@ xmlDictAddQString(xmlDictPtr dict, const xmlChar *prefix, unsigned int plen, + return(NULL); + } + +- if (size == 0) size = 1000; +- else size *= 4; /* exponential growth */ +- if (size < 4 * (namelen + plen + 1)) +- size = 4 * (namelen + plen + 1); /* just in case ! */ ++ if (size == 0) { ++ size = 1000; ++ } else { ++ if (size < (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size *= 4; /* exponential growth */ ++ else ++ size = SIZE_MAX - sizeof(xmlDictStrings); ++ } ++ if (size / 4 < namelen + plen + 1) { ++ if ((size_t) namelen + plen + 1 < ++ (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size = 4 * ((size_t) namelen + plen + 1); /* just in case ! */ ++ else ++ return(NULL); ++ } + pool = (xmlDictStringsPtr) xmlMalloc(sizeof(xmlDictStrings) + size); + if (pool == NULL) + return(NULL); diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index e4db345af4..28ae601118 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -33,6 +33,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-1757.patch \ file://CVE-2026-11979.patch \ file://CVE-2026-86137.patch \ + file://CVE-2026-86138.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99540 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 07706CA5FA1 for ; Tue, 29 Sep 2026 04:18:38 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.655.1790655517558975401 for ; Mon, 28 Sep 2026 21:18:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=SJPqQ1Da; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1630; q=dns/txt; s=iport01; t=1790655517; x=1791865117; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=OioZAjyq2vww9Pr1seUpEFNMI3Zn/J7kl4ca5P23NOM=; b=SJPqQ1DaCQtT6QMyMfxEdRA08RbO3tIqokehnvznvDvPnLq1hiqCHQC1 YZbggNK3vjCNwGPfnkxG/SLn0E/xG3Re7W+g1DIhGQhN8IWkVeVBvpE5J l4aT6sOozKmuJIprcFBN49GoJr4QVU3aL33v+R6eKrlWunLhuFBA8rESE LZkfwv7B0cqjsve6PgC6KVIMLOSieXU/jN028ZCbZX5Md+xx3e2vRLL/3 UHDacmFE9uF3wXLZqza1PFWJaZBQZecNuutrhIrxKs112vbTSa4Sd5kPn tcLflvtMop0GqFuLBPVFiFEa8izEsvuOvRjly5DyoTyHG8E48bn/djlff w==; X-CSE-ConnectionGUID: n4+TQ0llRHiF8sbF9sdD2A== X-CSE-MsgGUID: rWxOk/5CS1CXyhPCRevJNg== X-IPAS-Result: A0BGAgBDO7tq/43/Ja1aglmCV3VhQkmWSgOBE50HgX4PAQEBD0QNBAEBhD9GAo4IAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDZATAgEDMgEYAS0QIDErKxmDAgGCdAIBEcABgiyBAYMpAT8CQ1DbMgELFAEFgTOFQIgjdoR8JxsbgXKBFYJzdoEFgVwBAYIthXgEgiKBDIF4kzhIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEgghkjGTZ6gQlegSspYAEQF4EHggcCglSCAQIBSUMOB0VTCSVFEkcmIggSCQETGjALgSE4QQkoPxgNSBEsNxUZBD5uB5A/HoFyc4EOLBcJAoFiAZNfgyKPHKEPCiiDdowilToaM6pvmQiOCpZQhGmBaDyBRwsHcBWDIglKGQ+OOYNrgX+DFMcmJDUCCTIBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:uy2D8qLZX5Nbqc9aFE+Rh5QlxSXFcZb7ZxGr2PjKsXjdYENS0jICn WVLC2+GOv6PZ2ugfY92aYni8U9UvpOAmtQwGQQd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZpCCea+Uf1WlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnS0 T/Oi5eHYgH9imQkajh8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1oUAIKBNUc/txXAE8e7 vY2eSsBQkqq0rfeLLKTEoGAh+w5J8XteYdasXZ6wHSBUbAtQIvIROPB4towMDUY358VW62BI ZBENHw2ME2ojx5nYj/7DLo+gOehhXDlWzZZs1mS46Ew5gA/ySQsiuiwa4WPIYLiqcN9hHmIg WGBok/CWzoqJdyn4gCI7FCKibqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++Mv0CSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXPIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:Mw2i8K3IU03hKItez22CywqjBGokLtp133Aq2lEZdPWaSKOlfq eV7ZMmPHDP6Qr5NEtMpTnEAtjjfZq+z+8Q3WBuB9eftWDd0QPCRr2Kr7GSpgEIcBeRygcy78 tdmoFFebvN5CBB/KXHyTj9Nco8y9+a963tr+Lfw3BxCTxOUchbnn5E4sLxKDwMeOGAbqBJbK ah2g== X-Talos-CUID: 9a23:KP9GwW9rt+BL3sxAk2iVv0hIWfwcKnnZ9lfRDR+jA0g4U7G5E3bFrQ== X-Talos-MUID: 9a23:EHD2pQWTtjSuEjbq/CXTlBZhc5pD2P2FOFENqb48ttemEyMlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528537236" Received: from rcdn-l-core-04.cisco.com ([173.37.255.141]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-04.cisco.com (Postfix) with ESMTPS id AA6D7180001A3; Tue, 29 Sep 2026 04:18:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 52244CC12B5; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 3/8] libxml2: mark CVE-2026-86139 fixed Date: Mon, 28 Sep 2026 21:18:31 -0700 Message-Id: <20260929041836.2217090-3-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246811 From: Hetvi Thakar The fix for CVE-2026-86139 adds a zero-length guard in xmlURIEscapeStr, as shown in the upstream commit [1]. The libxml2 2.12.10 source already contains the equivalent guard, so no additional patch is required. Mark the CVE as fixed in the recipe. [1] https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86139 Signed-off-by: Hetvi Thakar --- meta/recipes-core/libxml/libxml2_2.12.10.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 28ae601118..93b7a23754 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -46,6 +46,10 @@ CVE_STATUS[CVE-2023-45322] = "disputed: issue requires memory allocation to fail # https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 CVE_STATUS[CVE-2025-8732] = "disputed: the code maintainer explains, that the issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. The issue triggers a crash if an invalid file is provided. https://gitlab.gnome.org/GNOME/libxml2/-/issues/958" +# The Scarthgap 2.12.10 source already contains the equivalent zero-length +# guard required for the xmlURIEscapeStr integer-overflow issue. +CVE_STATUS[CVE-2026-86139] = "fixed-version: xmlURIEscapeStr returns NULL when xmlStrlen returns zero" + BINCONFIG = "${bindir}/xml2-config" PACKAGECONFIG ??= "python \ From patchwork Tue Sep 29 04:18:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99547 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E18CC9832A for ; Tue, 29 Sep 2026 04:18:50 +0000 (UTC) Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.660.1790655522216984856 for ; Mon, 28 Sep 2026 21:18:42 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=IKnfeA/j; spf=pass (domain: cisco.com, ip: 173.37.86.74, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=3193; q=dns/txt; s=iport01; t=1790655522; x=1791865122; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=c53GFlJDIxjeKyUO8bzux1Aex5TNBmjtdUZexmFqc4k=; b=IKnfeA/jNchUHlhO+FXqOKiivb86DEd6uUPJnfbNHSHzNhti8e+m5TJS dTYafaeoQjLmMloXecqO0y5ZoVRxKxdmSZ3qL5VZFUjFrwnVEoYFF+Fjy 9tfnPwIfenISWLlq8RfU92zBwTNJlaZoH0Wc4IQCfV9jwhC0Z/MEF/Vwy DGr+/oiu1Up5vGOTQf0kq/Lo5LMbdkhQz5rKaAK4DFdgxGjXDQYJ9J4MQ wzfo3xiuE0hcYjpANbVEzEv/S4NU1BZdef5IRk3QOmrQ7VCdoP+223ztI nBpHJvubz2Mybt6pAQXcnaZ7z7muVnOfxuSQ+AHyEMfq6gDfQ5vC3TUAh g==; X-CSE-ConnectionGUID: Lqz1uVEITBm64gWFSUphGw== X-CSE-MsgGUID: tycRhCQ0SLiDGDaXG80wFg== X-IPAS-Result: A0BIAgDEO7tq/4z/Ja1aHgEBCxIMggULgld1YUJJlk2LZJI2gX4PAQEBD0QNBAEBhD9GAo4IAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDZASAQIBAycLARgBLRAcAwECLyALIwgZgwIBgjoDNwIBEcAEgXkzgQGDKQE/AkNQ2EsNgloBCxQBBYEzhUCCf4UkXRgBhHwnGxuBcoEVg2mBBYEaQgEBAogjBIIigQyBWh6TOEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCGSMZNnqBCV6BKylgARAXgQeCBwKCVIIBAgFJQw4HRVMJJUUSRyYiCBIJARMaMAuBIThBCSg/GA1IESw3FRkEPm4HkD8eghhNgQ4BKgGCTqMzgiGgHnEKKIN2jCKPPoV8GjOqbwuYfY4KhAmSR4RpgWg8gUcLB3AVgyIJShkPjjmDa4F/gxTHJiQ1AgkyAQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:JVpxoqPIdvHMswbvrR3zlsFynXyQoLVcMsEvi/4bfWQNrUok1GMBy mRJCG7Xa62PMTCgft9wYYSy/EwOv8SBn4NqGXM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeap1yFjmD9k/F3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WVzlV e/a+ZWFZgf0gW4saAr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj69F3HhgrA6A5xsxyXz1By tIjFSgNQQ/W0opawJrjIgVtrt4oIM+uOMYUvWttiGmCS/0nWpvEBa7N4Le03h9p2ZsIRqmYP ZdEL2MzNHwsYDUXUrsTIJIinO6rj2PXeDxDo1XTrq0yi4TW5FErgeK0boCNKrRmQ+1Jj02ip kn/p1/dAz01GNWv5mrd7Vyj07qncSTTHdh6+KeD3vlyjVuew2YeBBEbWR6wpuO0okq/QM5Eb UsM9ywjqKI/+ECmQp/6RRLQnZKflgQXV9wVF6gx7xuAj/KPpQ2YHWMDCDVGbbTKqfMLeNDj7 XfR9/uBONClmOf9pa61nltMkQ6PBA== IronPort-HdrOrdr: A9a23:j9uloq1xNG/UQF9HhCwNWAqjBGokLtp133Aq2lEZdPWaSKOlfq eV7ZMmPHDP6Qr5NEtMpTnEAtjjfZq+z+8Q3WBuB9eftWDd0QPCRr2Kr7GSpgEIcBeRygcy78 tdmoFFebvN5CBB/KXHyTj9Nco8y9+a963tr+Lfw3BxCTxOUchbnn5E4sLxKDwMeOGAbqBJbK ah2g== X-Talos-CUID: 9a23:ObrlgGh4Fy3dRoI4krx5PxMyMzJuVmTPlWruDm6EI2M3FLKqZ2St4KNLjJ87 X-Talos-MUID: 9a23:HuhprQmgU00Qq2Ihe1K+dnp+JcxS44+XUHspkLkpl8C0GnwoJBmS2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="529216208" Received: from rcdn-l-core-03.cisco.com ([173.37.255.140]) by rcdn-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-03.cisco.com (Postfix) with ESMTPS id B032C18000587; Tue, 29 Sep 2026 04:18:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 56478CC1273; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 4/8] libxml2: Fix CVE-2026-86140 Date: Mon, 28 Sep 2026 21:18:32 -0700 Message-Id: <20260929041836.2217090-4-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246817 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86140 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86140.patch | 56 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 57 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch new file mode 100644 index 0000000000..bc7e069b09 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86140.patch @@ -0,0 +1,56 @@ +From 7d324fcfa71e8567678ad254c0e10e509ebae99b Mon Sep 17 00:00:00 2001 +From: mohammadmseet-hue +Date: Thu, 16 Apr 2026 02:54:37 +0200 +Subject: [PATCH] fix: add bounds checks to xmlSnprintfElements in valid.c + +CVE-2025-24928 fixed xmlSnprintfElementContent for unchecked strcat() +writes, but the sibling function xmlSnprintfElements has the identical +unfixed pattern. The strcat(buf, "(") before the while loop and +strcat(buf, ")") after the loop exit have no bounds checks. + +Add remaining-space checks before both strcat calls, with early return +and ellipsis when space is insufficient. + +CVE: CVE-2026-86140 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340] + +(cherry picked from commit d1686f91dbda141a752200419d35639fd6b38340) +Signed-off-by: Hetvi Thakar +--- + valid.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/valid.c b/valid.c +index ae4bb822..718e6d85 100644 +--- a/valid.c ++++ b/valid.c +@@ -5047,7 +5047,15 @@ xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) { + int len; + + if (node == NULL) return; +- if (glob) strcat(buf, "("); ++ len = strlen(buf); ++ if (glob) { ++ if (size - len < 50) { ++ if ((size - len > 4) && (buf[len - 1] != '.')) ++ strcat(buf, " ..."); ++ return; ++ } ++ strcat(buf, "("); ++ } + cur = node; + while (cur != NULL) { + len = strlen(buf); +@@ -5111,7 +5119,11 @@ xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) { + } + cur = cur->next; + } +- if (glob) strcat(buf, ")"); ++ if (glob) { ++ len = strlen(buf); ++ if (size - len > 1) ++ strcat(buf, ")"); ++ } + } + + /** diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 93b7a23754..9648228c43 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -34,6 +34,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-11979.patch \ file://CVE-2026-86137.patch \ file://CVE-2026-86138.patch \ + file://CVE-2026-86140.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99541 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7DF08C9832A for ; Tue, 29 Sep 2026 04:18:38 +0000 (UTC) Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.653.1790655517589887211 for ; Mon, 28 Sep 2026 21:18:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=P4LZhz7q; spf=pass (domain: cisco.com, ip: 173.37.86.76, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2630; q=dns/txt; s=iport01; t=1790655517; x=1791865117; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Irzb6BnMhyUaSd/FsqKyoJymq4yFwnaIxdyyK7fqSvY=; b=P4LZhz7qKhY3mqE4S+Q1ELz3zGXKZiB6+1LTgNDQLvb7HgnvuKnrDVaY Mah+VDJBt4vHC4d2uTVDKsMyhI/8VvtlBqBfSFD45sA3l1ipZDflKsoiJ tLU3sDtwGZNaTPEXcCZfZH8UToxr3Brk5jQC0Ve6zwMapER1u2qXm1+VD Bs+pQAIBSbX01/qdwJAtAmN1egnC8QJrCer9tPtH1Og1qocVMVt5CSFWV kQPv8bdhclIicVIbwScthNLhuo65rWPMz3U3Lb9+ez1nyyhgDTt+8NXL8 iCbdqXOxvjBw/arvo/UTz05+YYRpGYrrVteQyVXpB3kRGd6n1qC+jJnpc Q==; X-CSE-ConnectionGUID: SeGt2wOBTvOmBfwcQA3xwQ== X-CSE-MsgGUID: F+8K8gO6QzGIuObUBEUmJQ== X-IPAS-Result: A0BNAgDTOrtq/43/Ja1aglmCV3VhQkmWTZoWhASBfg8BAQEPRA0EAQGEP0YCjggCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NkBIBAgEDJwsBGAEtEBwDAQIvKyMIGYMCAYJ0AgERwAmBeTOBAYMpAT8CQ1DbMgELFAEFgTOFQIgjXRgBhHwnGxuBcoEVg2mBBYFcAQECgiuFeASCIoEMgVoekzhIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEgghkjGTZ6gQlegSspYAEQF4EHggcCglSCAQIBSUMOB0VTCSVFEkcmIggSCQETGjALgSE4QQkoPxgNSBEsNxUZBD5uB5A/HoIYTYEOASoBpgGCIaEPCiiDdowilToaM6pvC5h9igspg1aWUIRpgWg8gUcLB3AVgyIJShkPjjmDa4F/gxTHJiQ1AgkyAQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:sxXCzK8Dsx+u4dL6SopzDrUD1n+TJUtcMsCJ2f8bNWPcYEJGY0x3n zROUW2HOPqCZ2Xwf9t+boi+905VvMCGn9I1TFNsqC1EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmB4E/rbei5xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mtyyHjEAX9gWAsYzhEs/jrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kNMKIEoPlQK11Q0 vkyJi8GVznYl/2PlefTpulE3qzPLeHxN48Z/3UlxjbDALN+HdbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZP0Qn1lQ/UPrSmM+omnn2cDRCgFmUvqEwpWPUyWSd1ZCwaoqEKoPTFJ89ckCwi CGW3DT2JU8jJvO+1B2Pz1iBu+rtpHauMG4VPPjinhJwu3WU3mEVBRgcWFe3rPX8gUmkVvpbK lcI4WwptaU0+UmhQ9XxUhH+p2SL1iPwQPJKGOE8rQXIwa3O7kPBWi4PTyVKb5ots8peqSEW6 2JlVujBXVRH2IB5g1rEnltIhVte4RQoEFI= IronPort-HdrOrdr: A9a23:hYStgatCyw9pme57bh17SsT67skDrtV00zEX/kB9WHVpmwKj+P xG+85rsiMc5wxxZJhNo7290ey7MBHhHP1OkO0s1MmZPDUO0VHAROoJ0WKh+UyEJ8SUzIBgPM lbH5SWIeeAa2SS9fyKgzWQIpIH3MSN9ryuiKP1yndgShwvVoRbhj0Jczpy1iZNNXJ77V1TLu vl2vZ6 X-Talos-CUID: 9a23:wl6qyG9tlK/6QdSOD0eVv3UZNdx/bVr38Gn3JmW2Fm1QYeaFVmbFrQ== X-Talos-MUID: 9a23:uSGbmQxZ5QDNceWLwXp/kjkpn9maqIrtWGNdnrJYgturFDFXMQq3oQmyYLZyfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528987192" Received: from rcdn-l-core-04.cisco.com ([173.37.255.141]) by rcdn-iport-5.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-04.cisco.com (Postfix) with ESMTPS id B38831800018D; Tue, 29 Sep 2026 04:18:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 5A9E2CC1279; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 5/8] libxml2: Fix CVE-2026-86141 Date: Mon, 28 Sep 2026 21:18:33 -0700 Message-Id: <20260929041836.2217090-5-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246812 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86141 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86141.patch | 35 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch new file mode 100644 index 0000000000..416a50eda5 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86141.patch @@ -0,0 +1,35 @@ +From adb9287ae35770d9b281ed8f2160774198fbaf25 Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Mon, 4 May 2026 07:56:18 +0200 +Subject: [PATCH] xmlregexp: Calc string length after null checking + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107 + +CVE: CVE-2026-86141 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55] + +(cherry picked from commit e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55) +Signed-off-by: Hetvi Thakar +--- + xmlregexp.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/xmlregexp.c b/xmlregexp.c +index 320a35ce..72e8e459 100644 +--- a/xmlregexp.c ++++ b/xmlregexp.c +@@ -702,12 +702,12 @@ xmlRegNewParserCtxt(const xmlChar *string) { + return(NULL); + memset(ret, 0, sizeof(xmlRegParserCtxt)); + if (string != NULL) { +- ret->string = xmlStrdup(string); +- ret->len = strlen((const char *) ret->string); ++ ret->string = xmlStrdup(string); + if (ret->string == NULL) { + xmlFree(ret); + return(NULL); + } ++ ret->len = strlen((const char *) ret->string); + } + ret->cur = ret->string; + ret->neg = 0; diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 9648228c43..49a1a8dbaa 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -35,6 +35,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86137.patch \ file://CVE-2026-86138.patch \ file://CVE-2026-86140.patch \ + file://CVE-2026-86141.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99542 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C6D0CA5FB1 for ; Tue, 29 Sep 2026 04:18:40 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.655.1790655517558975401 for ; Mon, 28 Sep 2026 21:18:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=LzsnkJtW; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2820; q=dns/txt; s=iport01; t=1790655518; x=1791865118; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=BuFT/WmAAqR6Sy5V8hk9PgwtZfyUoFMojJP7gs24x5k=; b=LzsnkJtWFApNaI5Gy4Ve6uX/GxOXVMLyCmX/SjypTO2il9/DfTfO4C1+ EDSnGfEHlMX51NL8ntgJe2iHkRMVvPJUEM74VIg521MI9YAnz1W22WFUu 3vxwbA+/TSBZVwnrQJYirR92NmSZnJXd7B/LtxTlz/giAGgAOCaqaS7I+ UW1vzKryGKQCwn87xP0xW9eaomH1u6fU8VnMPXPglXAIOtPmrD3u6Ogt7 2q6LqvhYvyfy3+D405IJp3VlSiaYLJwKOrTrCzC0oN90hJD3LTAlRhkoj Q7txpU2DcTnuZvruIEev0QcNuOk7murgKp3ARj8dPmjcjlK+fI3Kcbm3p A==; X-CSE-ConnectionGUID: +N0TtB8oQ32EFvqIpakXWA== X-CSE-MsgGUID: FnqEvNVxTDuUmR0I0C7rfQ== X-IPAS-Result: A0BNAgBDO7tq/5D/Ja1aHgEBCxIMggULgld1YUJJlkoDmhaEBIF+DwEBAQ9EDQQBAYQ/RgKOCAImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QEgECAQMnCwEYAS0QHAMBAi8rIwgZgwIBgnQCARHAAYF5M4EBgykBPwJDUNsyAQsUAQWBM4VAiCNdGAGEfCcbG4FygRWDaYEFgVwBAQKCK4V4BIIigQyBWh6TOEiBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBBxsGBYEdgSCCGSMZNnqBCV6BKylgARAXgQeCBwKCVIIBAgFJQw4HRVMJJUUSRyYiCBIJARMaMAuBIThBCSg/GA1IESw3FRkEPm4HkD8eghhNAXoJCgEqAYFalAqQHYIhoQ8KKIN2jCKVOhozqm8LmH2KC4N/llCEaYFoPIFHCwdwFYMiCUoZD445g2uBf4MUxyYkNQIJMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:1Vn5IaKup3527wVFFE+Rh5QlxSXFcZb7ZxGr2PjKsXjdYENShGYEy GBNX2yBb/3fYGP2f4wjaoq0pB4FvpKGztRiHgMd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZpCCea+Uf1WlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnS0 T/Oi5eHYgH9imQkajh8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN0tKhkKIadI/d8sW0xg6 +U5MDkOXi+q0rfeLLKTEoGAh+w5J8XteYdasXZ6wHSBUrAtQIvIROPB4towMDUY358VW62BI ZBENHw2MEiojx5nYj/7DLo+gOehhXDlWzZZs1mS46Ew5gA/ySQsiuiwa4WPIYPiqcN9sECBi 3zgwXTFLgwnMebH6GKurWiiv7qa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYGUNZWVul/4waXx++MvECSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXPIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:rgX+I6FZka8wxkyUpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:NeXPAG7qjDfHK6lcONsst2hMJtwPInrkly39DVGhKH5gS42qYArF X-Talos-MUID: 9a23:uAewTg4FXfmPZ0/NgF/6sqzXxoxG5b2DFmYzgakqpvSBD3RRYxzCljqOF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528537237" Received: from rcdn-l-core-07.cisco.com ([173.37.255.144]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:37 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-07.cisco.com (Postfix) with ESMTPS id 11C93180003C9; Tue, 29 Sep 2026 04:18:37 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 5FB91CC127A; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 6/8] libxml2: Fix CVE-2026-86142 Date: Mon, 28 Sep 2026 21:18:34 -0700 Message-Id: <20260929041836.2217090-6-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246815 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86142 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86142.patch | 37 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch new file mode 100644 index 0000000000..d63d8cdceb --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch @@ -0,0 +1,37 @@ +From 51f0e78349cbbc9081f14e02f440733e5880fb3d Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Mon, 4 May 2026 09:32:43 +0200 +Subject: [PATCH] xpointer: Check overflow in xmlXPtrEvalXPtrPart + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113 + +CVE: CVE-2026-86142 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58] + +Backport Changes: +- Use xmlXPathErr(ctxt, XPATH_MEMORY_ERROR) because the Scarthgap xpointer implementation does not provide the newer xmlXPathPErrMemory() call shape. This preserves the XPath parser error state as well as reporting the allocation failure. + +(cherry picked from commit 6b3a736c0edc74ceec3d82f5252499d7911b3a58) +Signed-off-by: Hetvi Thakar +--- + xpointer.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/xpointer.c b/xpointer.c +index 6e1e5f46..f5457c9f 100644 +--- a/xpointer.c ++++ b/xpointer.c +@@ -956,6 +956,13 @@ xmlXPtrEvalXPtrPart(xmlXPathParserContextPtr ctxt, xmlChar *name) { + level = 1; + + len = xmlStrlen(ctxt->cur); ++ /* Overflow in xmlStrlen */ ++ if (len == 0 && ctxt->cur != NULL && *ctxt->cur != 0) { ++ xmlXPathErr(ctxt, XPATH_MEMORY_ERROR); ++ xmlFree(name); ++ return; ++ } ++ + len++; + buffer = (xmlChar *) xmlMallocAtomic(len); + if (buffer == NULL) { diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 49a1a8dbaa..881b60133d 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -36,6 +36,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86138.patch \ file://CVE-2026-86140.patch \ file://CVE-2026-86141.patch \ + file://CVE-2026-86142.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99544 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B7B6ACA5FAE for ; Tue, 29 Sep 2026 04:18:39 +0000 (UTC) Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.654.1790655517978245632 for ; Mon, 28 Sep 2026 21:18:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=X8KmYebq; spf=pass (domain: cisco.com, ip: 173.37.86.77, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=4680; q=dns/txt; s=iport01; t=1790655518; x=1791865118; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=XjT2RJ1hU5ecgJ0qcp8/aZeQammU2Hf+1ERjGek+iYs=; b=X8KmYebqBtcOypZZxVObqFfLKUoDfeq+b4uREPNHotnwVU+yRU9d/qe4 tMuO7mfDAScLtMd3L6QIJmuwReUMZykbpCDTsQASl4PJuipZRSoKACzZ6 Bx/+9l4Rk9Cw1SyiMskrbRWosCt1X9AYZtS9VURcirX5etHK9Chybr7wR ZY6aV3Pw+JpenZitoIpECbHPsWCqhHS1+V8sTNldK6zIOOX/jLoxyKFoU jXiK5kMiUMWmniIjwJXXDPbtkOJsxe0V3+XJataQVfwF9axAmOo/IGbv4 zrObEFk6SlNrkBMY0sjfUTSAJSKVjJ0yI7UXzMeuZzGN4ziIHXcx3/8lF g==; X-CSE-ConnectionGUID: si6LKPtIS2i0m6bQZUQddQ== X-CSE-MsgGUID: xgIA0M6fSAG3hbklDYXtcA== X-IPAS-Result: A0BNAgDTOrtq/43/Ja1aHgEBCxIMggULgld1YUJJlkoDmhaEBIF+DwEBAQ9EDQQBAYQ/RgKOCAImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2QEgECAQMnCwEYAS0QHAMBAi8rIwgZgwIBgnQCARHACYF5M4EBgykBPwJDUNsyAQsUAQWBM4VAiCNdGAGEfCcbG4FygRWDaYEFgVwBAQKIIwSCIoEMgVoekzhIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEgghkjGTZ6gQlegSspYAEQF4EHggcCglSCAQIBSUMOB0VTCSVFEkcmIggSCQETGjALgSE4QQkoPxgNSBEsNxUZBD5uB5A/HoIYTAEBPD4TASoBgQVQgSWjB4IhoQ8KKIN2jCKVOhozqm8LmH2KCymDVpZQhGmBaDyBRwsHcBWDIglKGQ+OOYNrgX+DFMcmJDUCCTIBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:lPX5eaDNpWFgqBVW/3/iw5YqxClBgxIJ4kV8jS/XYbTApD1302YFy 2ZMC2rSO/mOMWLxeo0nPNjl8htUupKDxt9jOVdlrnsFo1CmBibm6XV1Cm+qYkt+++WaFBoPA /02M4eGcYZsCCCM/n9BC5C5xVFkz6aEW7HgP+DNPyF1VGdMRTwo4f5Zs7ZRbrVA357jXGthh fuo+5eBYA7/i2YuWo4pw/vrRC1H7ayaVAww5jTSVdgT1HfCmn8cCo4oJK3ZBxPQXolOE+emc P3Ixbe/83mx109F5gSNy+uTnuUiG9Y+DCDW4pZkc/HKbitq+kTe5p0G2M80Mi+7vdkmc+dZk 72hvbToIesg0zaldO41C3G0GAkmVUFKFSOuzXWX6aSuI0P6n3TE2PQwKGIOIawjoOcvBD9Ez M4lETwBV0XW7w626OrTpuhEnM8vKozveYgYoHwllW2fBvc9SpeFSKLPjTNa9G5v3YYVQrCEO pdfMGY2BPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237kVYhj+GzbIWLEjCMbdVav2/Ag zzIxE3WWREQN9iz+AqZ+Vv504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFC8u/SRjk+lR8kZL FQZ/Ccrp6U++EGnCN7nUHWFTGWspBUQXZ9UVuY98gzIkvaS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH6dV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:P+1HXKho0iO8sWZiqdEZG/ohdnBQXgIji2hC6mlwRA09TyVXra +TdZMgpHjJYVkqOU3I9ersBEDEewK/yXcX2/h0AV7dZmnbUQKTRekIh7cKgQeQfhEWndQy6U 4PScRD4fTLfD5HZL7BkWqFOudl5sWb+6a1guqb5XJsQQZ2L5xE1W5Ce3+m+okcfng8OXL/f6 DsnvZ6mw== X-Talos-CUID: 9a23:cMw5Sm/Smt9li7hY3i2Vv1UVROQGSmH89y3Re0rmA19bdYSZRWbFrQ== X-Talos-MUID: 9a23:Bpf0pwuzdMg6tJblNc2nlD5DHZ9NvaqVIW9WkZ8Fv+W1BTB7EmLI X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528716476" Received: from rcdn-l-core-04.cisco.com ([173.37.255.141]) by rcdn-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:37 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-04.cisco.com (Postfix) with ESMTPS id 11C9D1800018D; Tue, 29 Sep 2026 04:18:37 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 6353ECC127B; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 7/8] libxml2: Fix CVE-2026-86143 Date: Mon, 28 Sep 2026 21:18:35 -0700 Message-Id: <20260929041836.2217090-7-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-04.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246814 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86143 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86143.patch | 91 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 92 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch new file mode 100644 index 0000000000..228b5136bb --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch @@ -0,0 +1,91 @@ +From 83259eee08067b547d2aaedd436504939b2c343b Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno +Date: Mon, 4 May 2026 09:54:34 +0200 +Subject: [PATCH] xmlIO: Check for int overflow before calling writecallback + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111 + +CVE: CVE-2026-86143 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35] + +Backport Changes: +- Change nbchars to size_t in both Scarthgap write functions before assigning the size_t result of xmlBufUse(). Add the INT_MAX guard to both xmlOutputBufferWrite() callback paths. The upstream commit assumes earlier refactoring that changed nbchars to size_t and routed xmlOutputBufferWriteEscape() through the protected write path; the existing flush guards are retained. + +(cherry picked from commit 90f293ba74d28b1d570920382e707586f68ebf35) +Signed-off-by: Hetvi Thakar +--- + xmlIO.c | 26 ++++++++++++++++++---- + 1 file changed, 22 insertions(+), 4 deletions(-) + +diff --git a/xmlIO.c b/xmlIO.c +index 95d27157..de227d8c 100644 +--- a/xmlIO.c ++++ b/xmlIO.c +@@ -3318,7 +3318,7 @@ + */ + int + xmlOutputBufferWrite(xmlOutputBufferPtr out, int len, const char *buf) { +- int nbchars = 0; /* number of chars to output to I/O */ ++ size_t nbchars = 0; /* number of chars to output to I/O */ + int ret; /* return from function call */ + int written = 0; /* number of char written to I/O so far */ + int chunk; /* number of byte current processed from buf */ +@@ -3378,6 +3378,10 @@ + if ((nbchars < MINLEN) && (len <= 0)) + goto done; + ++ if (nbchars >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + /* + * second write the stuff to the I/O channel + */ +@@ -3487,7 +3491,7 @@ + int + xmlOutputBufferWriteEscape(xmlOutputBufferPtr out, const xmlChar *str, + xmlCharEncodingOutputFunc escaping) { +- int nbchars = 0; /* number of chars to output to I/O */ ++ size_t nbchars = 0; /* number of chars to output to I/O */ + int ret; /* return from function call */ + int written = 0; /* number of char written to I/O so far */ + int oldwritten=0;/* loop guard */ +@@ -3572,6 +3576,10 @@ + if ((nbchars < MINLEN) && (len <= 0)) + goto done; + ++ if (nbchars >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + /* + * second write the stuff to the I/O channel + */ +@@ -3667,15 +3675,25 @@ + */ + if ((out->conv != NULL) && (out->encoder != NULL) && + (out->writecallback != NULL)) { ++ size_t bufsize = xmlBufUse(out->conv); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->conv), +- xmlBufUse(out->conv)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->conv, ret); + } else if (out->writecallback != NULL) { ++ size_t bufsize = xmlBufUse(out->buffer); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->buffer), +- xmlBufUse(out->buffer)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->buffer, ret); + } diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 881b60133d..1b0c3d50da 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -37,6 +37,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86140.patch \ file://CVE-2026-86141.patch \ file://CVE-2026-86142.patch \ + file://CVE-2026-86143.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" From patchwork Tue Sep 29 04:18:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 99546 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E6ABCA5FB2 for ; Tue, 29 Sep 2026 04:18:40 +0000 (UTC) Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.655.1790655517558975401 for ; Mon, 28 Sep 2026 21:18:38 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Aq+wsWJV; spf=pass (domain: cisco.com, ip: 173.37.86.72, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=9426; q=dns/txt; s=iport01; t=1790655518; x=1791865118; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=uczez0uQcmVA8O8XqK7kkYlnfpz36KXQxVm/8/22wzQ=; b=Aq+wsWJV5q04y02hoQvR5IvyfCOPUZ9nQBZLIfFxa0SijCqxwCI0FO+g 8FICrYvJCG69IqlJFD/CSO66eOcjqTPrKiunqjGWGW7BDM19iGspVAlqL fVrQIuwM3tS2HFJGWZb77DV/DGSFtqRLd43nTKBbgLtZipQZZzohQ1nVV KpE/sDdr5NB2Lnez/WYCCySR2sDo4PcPVL2ZaoG0gDFf8oH9NTkuo/C4I TQmq41hwpb0GWCh+ERYbr2epEFkkONNIMZfeZeMYw+8RbBBapQpd37Lyb a+H6zSfh3MKu+ZqeecmTBbicQy9+yYItV7GDEqRmb2GJW5Ark5Z4BrsHO A==; X-CSE-ConnectionGUID: UfpeZ09JSouyg4nvrMn3nQ== X-CSE-MsgGUID: uQH5yvOXQIuvA7wGOarQtA== X-IPAS-Result: A0AnAABDO7tq/5D/Ja1aHQEBAQEJARIBBQUBgXwIAQsBglZ1YUJJjHKJWAOBE50HgX4PAQEBD0QNBAEBhD9GAo4IAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQEKAQEFAQEBAgEHBYEOE4ZPDZASAQIBAycLARgBLRAcAwECLysjCBmDAgGCdAIBEcABgXkzgQGDKQE/AkNQ2zIBCxQBBYEzAYU/iCNdGAFEhDgnGxuBcoEVgTuBOHaBBYFcAQECiCMEgiKBDIFaHpM4SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BIIIZIxk2eoEJXoErKWABEBeBB4IHAoJUggECAUlDDgdFUwklRRJHJiIIEgkBExowC4EhOEEJKD8YDUgRLDcVGQQ+bgeQPx6CGC0ZBwF6EwEoAgEXgR2BMpJ0kCeCIYE1n1oKKIN2jCKVOhozqm8LmH2OCpU0gRyEaYFoPIFHCwdwFYMiCUoZD445g2uBf4MUxyYkNQIJMgEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:3olM/a5QfEz+Taaa1N5Y8gxRtG7GchMFZxGqfqrLsTDasY5as4F+v mJNCzuCOveMZ2ahL4wgPdjj80MD6pXWmodiG1BlryA1Zn8b8sCt6fZ1gavT04J+CuWZESqLO u1HMoGowPgcFyGa+1H1dOex9RGQ7InQLpLkEunIJyttcgFtTSYlmHpLlvUw6mJSqYDR7zil5 5Wo/KUzBHf/g2QqajNOu/rZwP9SlK2aVA0w7wRWic9j5Dcyp1FNZLoDKKe4KWfPQ4U8NoaSW +bZwbilyXjS9hErB8nNuu6TnpoiG+O60aCm0xK6aoD66vRwjnVaPpUTaJLwXXxqZwChxLid/ jniWauYEm/FNoWU8AgUvoIx/ytWZcWq85efSZSzXFD6I0DuKxPRL/tS4E4eAIMA99QvUEN18 uEJJ2wLcAqmgbmw+efuIgVsrpxLwMjDJogTvDRkiDreF/tjGc+FSKTR7tge1zA17ixMNa+BP IxCNnw1MUmGOkETUrsUIMpWcOOAhmX/ej5RsnqepLE85C7YywkZPL3FbYCFJ4fVH54F9qqej n//3znoHDYqDf2C1xPa7V2Lj/X2gQquDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4CeY27kSJj6HT+QvcXjdCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1rN94cRva1fApEFI/ IronPort-HdrOrdr: A9a23:jJDy4axDVRIomCst+LL9KrPw9L1zdoMgy1knxilNoNJuHfBw8P re+8jzuiWUtN98YhwdcJW7Scu9qBDnhPpICPcqXYtKNTOO0ADDEGgh1/qG/9SKIUPDH4BmuZ uIWpIObuEYdWIK7vrS0U2fD8sqxsWB/eSDgOfTyGoocCRRApsQljuQzm2gYzZLrM4sP+tAKK ah X-Talos-CUID: 9a23:pAKAHGA7auKeXbD6ExRp7EMmQpEHSXrA3XiMJVGiLGAyToTAHA== X-Talos-MUID: 9a23:7NH+DQ194mFhgWoKNmH0FpV8hzUj/p2OVVETtqU/mtSaHHNvFBCUlg2ra9py X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.27,129,1787011200"; d="scan'208";a="528537238" Received: from rcdn-l-core-07.cisco.com ([173.37.255.144]) by rcdn-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 29 Sep 2026 04:18:37 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by rcdn-l-core-07.cisco.com (Postfix) with ESMTPS id 16923180003E5; Tue, 29 Sep 2026 04:18:37 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 67E25CC127C; Mon, 28 Sep 2026 21:18:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com Subject: [OE-core][scarthgap][PATCH 8/8] libxml2: Fix CVE-2026-86144 Date: Mon, 28 Sep 2026 21:18:36 -0700 Message-Id: <20260929041836.2217090-8-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260929041836.2217090-1-hthakar@cisco.com> References: <20260929041836.2217090-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: rcdn-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 04:18:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246816 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86144 Signed-off-by: Hetvi Thakar --- .../libxml/libxml2/CVE-2026-86144.patch | 219 ++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 220 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch new file mode 100644 index 0000000000..41fee42732 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch @@ -0,0 +1,219 @@ +From 8d0c6eb94f8a32a49e3c9122a6da82c519198063 Mon Sep 17 00:00:00 2001 +From: Ruben Thijssen +Date: Fri, 15 May 2026 15:42:18 +1000 +Subject: [PATCH] fix(xinclude): propagate parseFlags in xmlXIncludeProcess and + xmlXIncludeProcessTree + +CVE: CVE-2026-86144 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61] + +Backport Changes: +- Use xmlLoadExternalEntity() with xmlCtxtUseOptions() because Scarthgap 2.12.10 predates xmlLoadResource() and resource-loader callbacks. +- Adapt the regression tests for 2.12.10 by using the global structured-error handler, matching 2.12.10 loader network-entity diagnostics, and restoring the test handler after xmlXIncludeProcess(). +- Omit the upstream XML_IO_NETWORK_ATTEMPT filter because the 2.12.10 xmlLoadExternalEntity() path has no corresponding post-load error-filtering block. +- Add a parser-context allocation guard because the target version can return NULL from xmlNewParserCtxt(). + +(cherry picked from commit b63cd517afecb76582dd9488c55e54ceaf50de61) +Signed-off-by: Hetvi Thakar +--- + result/XInclude/issue1120-1.xml | 4 ++ + result/XInclude/issue1120-1.xml.err | 1 + + result/XInclude/issue1120-2.xml | 4 ++ + result/XInclude/issue1120-2.xml.err | 1 + + runtest.c | 75 +++++++++++++++++++++++++ + test/XInclude/issue1120/issue1120-1.xml | 6 ++ + test/XInclude/issue1120/issue1120-2.xml | 6 ++ + xinclude.c | 9 ++- + 8 files changed, 104 insertions(+), 2 deletions(-) + create mode 100644 result/XInclude/issue1120-1.xml + create mode 100644 result/XInclude/issue1120-1.xml.err + create mode 100644 result/XInclude/issue1120-2.xml + create mode 100644 result/XInclude/issue1120-2.xml.err + create mode 100644 test/XInclude/issue1120/issue1120-1.xml + create mode 100644 test/XInclude/issue1120/issue1120-2.xml + +diff --git a/result/XInclude/issue1120-1.xml b/result/XInclude/issue1120-1.xml +new file mode 100644 +index 00000000..5d83cc96 +--- /dev/null ++++ b/result/XInclude/issue1120-1.xml +@@ -0,0 +1,4 @@ ++ ++ ++ Network access is not allowed ++ +diff --git a/result/XInclude/issue1120-1.xml.err b/result/XInclude/issue1120-1.xml.err +new file mode 100644 +index 00000000..c134bed1 +--- /dev/null ++++ b/result/XInclude/issue1120-1.xml.err +@@ -0,0 +1 @@ ++I/O error : Attempt to load network entity http://example.invalid/file.txt +diff --git a/result/XInclude/issue1120-2.xml b/result/XInclude/issue1120-2.xml +new file mode 100644 +index 00000000..af5bde91 +--- /dev/null ++++ b/result/XInclude/issue1120-2.xml +@@ -0,0 +1,4 @@ ++ ++ ++

Network access is not allowed

++
+diff --git a/result/XInclude/issue1120-2.xml.err b/result/XInclude/issue1120-2.xml.err +new file mode 100644 +index 00000000..051f5928 +--- /dev/null ++++ b/result/XInclude/issue1120-2.xml.err +@@ -0,0 +1 @@ ++I/O error : Attempt to load network entity http://example.invalid/file.xml +diff --git a/runtest.c b/runtest.c +index e91e2dfd..297cb5e2 100644 +--- a/runtest.c ++++ b/runtest.c +@@ -2444,6 +2444,75 @@ noentParseTest(const char *filename, const char *result, + return(res); + } + ++#ifdef LIBXML_XINCLUDE_ENABLED ++/** ++ * Parse a file and run xmlXIncludeProcess() to verify that doc->parseFlags ++ * is propagated properly. ++ * ++ * @param filename the file to parse ++ * @param result the file with expected result ++ * @param err the file with error messages ++ * @returns 0 in case of success, an error code otherwise ++ */ ++static int ++xincludeProcessTest(const char *filename, const char *result, const char *err, ++ int options) { ++ xmlParserCtxtPtr ctxt; ++ xmlDocPtr doc; ++ xmlChar *base = NULL; ++ int size, res; ++ int ret = 0; ++ ++ nb_tests++; ++ ++ /* Create a new parser context */ ++ ctxt = xmlNewParserCtxt(); ++ if (ctxt == NULL) ++ return(-1); ++ ++ /* Load the data from `filename` into a parser context */ ++ xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler); ++ doc = xmlCtxtReadFile(ctxt, filename, NULL, options); ++ xmlFreeParserCtxt(ctxt); ++ ++ /* Check if `doc` was created successfully */ ++ if (doc == NULL) { ++ testErrorHandler(NULL, "%s : failed to parse\n", filename); ++ return(-1); ++ } ++ ++ /* ++ * Run xmlXIncludeProcess() with a structured error handler to check that ++ * the parse flags are propagated. ++ */ ++ xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler); ++ xmlXIncludeProcess(doc); ++ xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler); ++ ++ /* Check the result and for any errors */ ++ if (result) { ++ xmlDocDumpMemory(doc, &base, &size); ++ res = compareFileMem(result, (char *) base, size); ++ xmlFree(base); ++ if (res != 0) { ++ fprintf(stderr, "Result for %s failed in %s\n", filename, result); ++ ret = -1; ++ } ++ } ++ ++ if ((ret == 0) && (err != NULL)) { ++ res = compareFileMem(err, testErrors, testErrorsSize); ++ if (res != 0) { ++ fprintf(stderr, "Error for %s failed\n", filename); ++ ret = -1; ++ } ++ } ++ ++ xmlFreeDoc(doc); ++ return(ret); ++} ++#endif ++ + /** + * errParseTest: + * @filename: the file to parse +@@ -5134,6 +5203,12 @@ testDesc testDescriptions[] = { + { "XInclude regression tests without reader", + errParseTest, "./test/XInclude/without-reader/*", "result/XInclude/", "", + ".err", XML_PARSE_XINCLUDE }, ++ { "XInclude issue1120 regression tests", ++ errParseTest, "./test/XInclude/issue1120/*", "result/XInclude/", "", ++ ".err", XML_PARSE_XINCLUDE | XML_PARSE_NONET }, ++ { "XInclude xmlXIncludeProcess() issue1120 regression tests", ++ xincludeProcessTest, "./test/XInclude/issue1120/*", "result/XInclude/", ++ "", ".err", XML_PARSE_NONET }, + #endif + #ifdef LIBXML_XPATH_ENABLED + #ifdef LIBXML_DEBUG_ENABLED +diff --git a/test/XInclude/issue1120/issue1120-1.xml b/test/XInclude/issue1120/issue1120-1.xml +new file mode 100644 +index 00000000..b0b8feef +--- /dev/null ++++ b/test/XInclude/issue1120/issue1120-1.xml +@@ -0,0 +1,6 @@ ++ ++ ++ ++ Network access is not allowed ++ ++ +diff --git a/test/XInclude/issue1120/issue1120-2.xml b/test/XInclude/issue1120/issue1120-2.xml +new file mode 100644 +index 00000000..b4c9fe5e +--- /dev/null ++++ b/test/XInclude/issue1120/issue1120-2.xml +@@ -0,0 +1,6 @@ ++ ++ ++ ++

Network access is not allowed

++
++
+diff --git a/xinclude.c b/xinclude.c +index b6581558..0d57f5a1 100644 +--- a/xinclude.c ++++ b/xinclude.c +@@ -1688,6 +1688,11 @@ xmlXIncludeLoadTxt(xmlXIncludeCtxtPtr ctxt, const xmlChar *url, + * Load it. + */ + pctxt = xmlNewParserCtxt(); ++ if (pctxt == NULL) { ++ xmlXIncludeErrMemory(ctxt, ref->elem, NULL); ++ goto error; ++ } ++ xmlCtxtUseOptions(pctxt, ctxt->parseFlags); + inputStream = xmlLoadExternalEntity((const char*)URL, NULL, pctxt); + if(inputStream == NULL) + goto error; +@@ -2416,7 +2421,7 @@ xmlXIncludeProcessFlags(xmlDocPtr doc, int flags) { + */ + int + xmlXIncludeProcess(xmlDocPtr doc) { +- return(xmlXIncludeProcessFlags(doc, 0)); ++ return(xmlXIncludeProcessFlags(doc, doc ? doc->parseFlags : 0)); + } + + /** +@@ -2461,7 +2466,7 @@ xmlXIncludeProcessTreeFlags(xmlNodePtr tree, int flags) { + */ + int + xmlXIncludeProcessTree(xmlNodePtr tree) { +- return(xmlXIncludeProcessTreeFlags(tree, 0)); ++ return(xmlXIncludeProcessTreeFlags(tree, (tree && tree->doc) ? tree->doc->parseFlags : 0)); + } + + /** diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 1b0c3d50da..c100ef2a8c 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -38,6 +38,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86141.patch \ file://CVE-2026-86142.patch \ file://CVE-2026-86143.patch \ + file://CVE-2026-86144.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"