From patchwork Tue Sep 29 20:50:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Stasiak X-Patchwork-Id: 99606 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3CBACCA5FAC for ; Tue, 29 Sep 2026 20:51:21 +0000 (UTC) Received: from mail-dy2-f12.google.com (mail-dy2-f12.google.com [74.125.229.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6788.1790715071538312053 for ; Tue, 29 Sep 2026 13:51:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=sFT+pwpv; spf=pass (domain: gmail.com, ip: 74.125.229.12, mailfrom: jason.stasiak@gmail.com) Received: by mail-dy2-f12.google.com with SMTP id 5a478bee46e88-3396cec93b6so5287894eec.3 for ; Tue, 29 Sep 2026 13:51:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790715071; x=1791319871; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=D/YOUELBqwzIJWCEAxxeBLqes2cXsFp+lYo+9DBnHx4=; b=sFT+pwpvRKhkXdrjmzC0jU1n/o+4B0pY9GHYpRhUpusII+3n5Mk7oWA3CAI457Fpgk Z8/pCpIk0JO0irq9rfOzDY8IiMT3xGuJkAeJn5uIxwQp8oEBioSifCF1SmQefgPulLjk j4cVN8oyh6att5Mqre+Ms1BTAvxfL1uPv2cQb3bzrk55RWbDm59IRGcfItkTFIUqbjcj 4+hPo+AxICM2ucX84NfLyIENAmEbWrH4+eCU5ufh8fGx1FO0vd2A7zyQsGnn42v++h8i yzsbPvnyFUnzE4ZwVl5iET8y2casCdmZWWM35D1sFCm9L0nQ4IAheYMmqhny8Kwk1g8m DFkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790715071; x=1791319871; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=D/YOUELBqwzIJWCEAxxeBLqes2cXsFp+lYo+9DBnHx4=; b=KT6UunVM2T6UWdtFjbHo7FRTB5Lottu1ldeEXE7qEZDwt/99Fw+B6/V92R/M5JFQGD D/3tDHNM3N3EVzhCgE3nF3TCFyae9O3ympwGRSdolAiO3sphn+gHK6Cv/l/BRFPhOLls pf8Syoo+Mul7S+1JoLLUSN/gw1hzh03eSNQnI0yyz+8B6KAHMwr+9hFtQq9qmWOi+i0C C3V7LyMpir5AUAeezDvOUPJSwi1xrlH87Tiw+Nze3nl5fpTzuun7NL2QlK+4hS+idAOf kg9d/rQL2QvAoHlGHzub9d6NmUBQeQd59rfxZiGpzsCp31XSABC16QKNCbk5z638XRR3 btnw== X-Gm-Message-State: AFq9FYJL+nQd30Y6wjWsG3ZJVwmqrvP0Qda9mhuKNGAQFUD9JC+pbLSw u+MsI4qDsbvr52AaFXzmFOJ87g4cxJFhunKH5X/Tf2WLWBQBnneg0JQTBZpafA== X-Gm-Gg: AYBFou09jpivd9oPb9XtYiTUlSNl8ghdjEtvIl0FiDeq/lf32vYyIrHTtDrppQW60zC xBcIHwbiqouqKkmjGYnyDzzI7pj2zWk6wkFBx3TaDVeFnAE0Q4VEjUeVgWI2ENAr4Tp865AdOlG EiN4Kr3wIajrLGQKiucbcOT3HxWCzpZHdAdZmdls8gY1TI2jqMjCa3i+HZBcACtUj07rpgyZ2WN y51bO/dlSvMANJJ+uvdTRiqbqaj4qev9DJi7wB3MDmxk9l/eOaqexIYL2/owgkvSkp+hGFWDcfW DFh+cmwl3m4bB1BI/xjaG64VFSltZpA/Wdzx3mhY9yliMLibq8Sq6zv8KExnjrrvWrUc9T0RloE leLchiEXyNC+iwR8+JSTBbKIqef8oO3d8W/ajgjBGwRWag5DBIy71mdEGrRqV+nNdnQN7m3vEWS Fy8dLH1O8dpi+aZbsj07elJkA2qBDvBS4P1X8U5VTwXQKsOlzKiHKm8NdwXRy/xiQWmkAHbxgpf Beri0Vn9AF6udiPGgDtNez9w7sGnHs= X-Received: by 2002:a05:7300:8424:b0:341:67fc:98df with SMTP id 5a478bee46e88-34c63bfd133mr597292eec.12.1790715070757; Tue, 29 Sep 2026 13:51:10 -0700 (PDT) Received: from CHA-FQKPM83.ad.garmin.com ([65.175.40.146]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34c378c9b64sm2655843eec.6.2026.09.29.13.51.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Sep 2026 13:51:10 -0700 (PDT) From: Jason Stasiak X-Google-Original-From: Jason Stasiak To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 1/5] libsoup-2.4: fix CVE-2026-1539 Date: Tue, 29 Sep 2026 13:50:51 -0700 Message-ID: <20260929205055.2403390-2-jason.stasiak@garmin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260929205055.2403390-1-jason.stasiak@garmin.com> References: <20260929205055.2403390-1-jason.stasiak@garmin.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 20:51:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246894 Backport fix for CVE-2026-1539 from meta-oe to OE-core. Update CVE patch to restore the auth-redirect proxy validation unit test from the upstream libsoup3 patch. (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d) Signed-off-by: Jason Stasiak --- .../libsoup/libsoup-2.4/CVE-2026-1539.patch | 104 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 1 + 2 files changed, 105 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch new file mode 100644 index 0000000000..e8c9ee0583 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch @@ -0,0 +1,104 @@ +From 285faea567e1e2a95226201175dbf745a64a2439 Mon Sep 17 00:00:00 2001 +From: Changqing Li +Date: Fri, 20 Mar 2026 15:04:22 +0800 +Subject: [PATCH 4/4] Also remove Proxy-Authorization header on cross origin + redirect + +Closes #489 + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libsoup/-/commit/98c1285d9d78662c38bf14b4a128af01ccfdb446] +CVE: CVE-2026-1539 + +Signed-off-by: Changqing Li + +Backport the auth-redirect proxy validation unit tests from the upstream +libsoup3 patch + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-session.c | 1 + + tests/httpd.conf.in | 1 + + tests/proxy-test.c | 36 ++++++++++++++++++++++++++++++++++++ + 3 files changed, 38 insertions(+) + +diff --git a/libsoup/soup-session.c b/libsoup/soup-session.c +index fadd5cd2..4cad0946 100644 +--- a/libsoup/soup-session.c ++++ b/libsoup/soup-session.c +@@ -1192,6 +1192,7 @@ soup_session_redirect_message (SoupSession *session, SoupMessage *msg) + /* Strip all credentials on cross-origin redirect. */ + if (!soup_uri_host_equal (soup_message_get_uri (msg), new_uri)) { + soup_message_headers_remove (msg->request_headers, "Authorization"); ++ soup_message_headers_remove (msg->request_headers, "Proxy-Authorization"); + soup_message_set_auth (msg, NULL); + } + +diff --git a/tests/httpd.conf.in b/tests/httpd.conf.in +index 93fb7ff4..e190b6f7 100644 +--- a/tests/httpd.conf.in ++++ b/tests/httpd.conf.in +@@ -37,6 +37,7 @@ DirectoryIndex index.txt + TypesConfig /dev/null + AddType application/x-httpd-php .php + Redirect permanent /redirected /index.txt ++Redirect permanent /Basic/realm1/redirected https://127.0.0.1:47525/index.txt + + # Proxy #1: unauthenticated + Listen 127.0.0.1:47526 +diff --git a/tests/proxy-test.c b/tests/proxy-test.c +index 1d68aa05..105a02a6 100644 +--- a/tests/proxy-test.c ++++ b/tests/proxy-test.c +@@ -322,6 +322,41 @@ do_proxy_redirect_test (void) + soup_test_session_abort_unref (session); + } + ++static void proxy_auth_redirect_message_restarted (SoupMessage *msg) ++{ ++ if (msg->status_code != SOUP_STATUS_MOVED_PERMANENTLY) ++ return; ++ ++ g_assert_null (soup_message_headers_get_one (msg->request_headers, "Proxy-Authorization")); ++} ++ ++static void ++do_proxy_auth_redirect_test (void) ++{ ++ SoupSession *session; ++ SoupMessage *msg; ++ char *url; ++ ++ SOUP_TEST_SKIP_IF_NO_APACHE; ++ SOUP_TEST_SKIP_IF_NO_TLS; ++ ++ session = soup_test_session_new (SOUP_TYPE_SESSION_ASYNC, ++ SOUP_SESSION_PROXY_RESOLVER, proxy_resolvers[AUTH_PROXY], ++ NULL); ++ ++ url = g_strconcat (HTTP_SERVER, "/Basic/realm1/redirected", NULL); ++ msg = soup_message_new (SOUP_METHOD_GET, url); ++ g_signal_connect (session, "authenticate", G_CALLBACK (authenticate), NULL); ++ g_signal_connect (msg, "restarted", G_CALLBACK (proxy_auth_redirect_message_restarted), NULL); ++ ++ soup_session_send_message (session, msg); ++ soup_test_assert_message_status (msg, SOUP_STATUS_OK); ++ ++ g_free (url); ++ g_object_unref (msg); ++ soup_test_session_abort_unref (session); ++} ++ + static void + do_proxy_auth_request (const char *url, SoupSession *session, gboolean do_read) + { +@@ -433,6 +468,7 @@ main (int argc, char **argv) + + g_test_add_data_func ("/proxy/fragment", base_uri, do_proxy_fragment_test); + g_test_add_func ("/proxy/redirect", do_proxy_redirect_test); ++ g_test_add_func ("/proxy/auth-redirect", do_proxy_auth_redirect_test); + g_test_add_func ("/proxy/auth-cache", do_proxy_auth_cache_test); + + ret = g_test_run (); +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb index 7e00cd678a..4fe1e36f03 100644 --- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb +++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb @@ -41,6 +41,7 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \ file://CVE-2025-4476.patch \ file://CVE-2025-2784.patch \ file://CVE-2025-4945.patch \ + file://CVE-2026-1539.patch \ " SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13" From patchwork Tue Sep 29 20:50:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Stasiak X-Patchwork-Id: 99609 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7EC4ACA5FB4 for ; Tue, 29 Sep 2026 20:51:21 +0000 (UTC) Received: from mail-dy2-f43.google.com (mail-dy2-f43.google.com [74.125.229.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6790.1790715073091004697 for ; Tue, 29 Sep 2026 13:51:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=eWrmyZ2k; spf=pass (domain: gmail.com, ip: 74.125.229.43, mailfrom: jason.stasiak@gmail.com) Received: by mail-dy2-f43.google.com with SMTP id 5a478bee46e88-33bfb26865fso4614259eec.2 for ; Tue, 29 Sep 2026 13:51:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790715072; x=1791319872; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rP+9WrEos1wY4bSyx8bqOx5rofbS3QcbncDIHg5SldI=; b=eWrmyZ2kNxzXFfD/MmfQPCARUVxQwtfGS2QHJox9iPenEeUy8njgKVRLWTELkzC2l/ iKS6eoPYDOFIO9EK4pPO6knW4JsG/XDkGB3DzR4rcKwVtHhF7LXlvd33cojBYQd5apM2 Se/F5PTznXf2YAiPbyS9t7Q6XoGVihT0K5QsxXrUrKaK1ne4MRqhy4//r1xVdSTyi2nx b32omhPT8SlBlLBXRGmZK3LWr6ou1/edNlYZq7yv8VUTgdHoGF4cv4EhSLYKOymnLWlO CaRwFhFFwu7B2nBvL8QY50tx9ajC9iqs9l6D64slclmqTbjOh6ryDV2sqtxbz64hRdRj QJXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790715072; x=1791319872; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rP+9WrEos1wY4bSyx8bqOx5rofbS3QcbncDIHg5SldI=; b=p7aYvdX/y0+jQodBfPgTlrzt4lsWLp+6B6KCEQrs6WugVqGFs6iCd16LNtCYbCysIS RdUcp/JO0UP3Jt+4lTlOpqvMHrd8bC4YlLa8K1RMucGazkee7f1rTPtx/wQcDzMIagMw nLOxQf4WCm5kqeOG7V37t8ga1TMacgjFs4NkmVdTbr7Bw+oPWdkZ0fN96N11pPwxHek5 wogscvrIQGs6qLP7XzSMfCmU0H5a7IQELETqk9IfA8zM4q9LKRX5rAtVkwAijxr6M4Ty zTOnnZ01Vf9XWoPWj30O41fKkxHnlQEajTCs54G50jt/VhcWqcRfPJQJtX3q3dzq9Kyb WpoQ== X-Gm-Message-State: AFq9FYJlx6uA/khqXT3J5Pa52FNkF/bFbZAN5kxnSALBokQJfEo/f7Fw TwKvPsbXw9vSf3YhOEfLZcJnBgZDHkfropRpOYU/vkzi2Zib6CFxe6994er9jA== X-Gm-Gg: AYBFou3L6PwSRy6I2JggC8kPz+Ml3uM79O6JO2pbBgkIPOAIHhrm01poFTAKSAzD4eo nhsBXubzga2aZaZ66qR8Xcp0CmZB5HjadnIAkoyFGbo5E/YSfdKXTQ5/M5KxXz6Ti3sp2M2P6yQ L78DUEb/GzyzeLMOGwnvvFU7ajGDZAjN0K2tY3gL+udIv5q0m/zIvfJSCJP1Wfik0320o/2galD TMB+jA1sozREg8wssAJp01E/1zaq1ZBhD0DWOA+8dkM//c5cK6ZKuz1blAMhjrBA5r/RCzFKPSs ZT9gv5z/PFGdfAuibbZs/bQEqE1ggvi2P1d+ALfGf1mKdPGOQ2HRCxMLKYMLuaUKwLWRRUArESV 61eUJ2V6GF0HR1bQqPbBQxrjrb+vvD8oERzhDSpKlYLEO/Z6YH2IyVX8Y5vxpjhNu55FEcZepM1 L2lFw36UlSql+ngCo55CENtromqZ3d+S1BxbPVtNC8FKlzY6pNw0mgJG7OwUEMpch2gd7b4anZz a96DrffBPAfQY3xYHf8 X-Received: by 2002:a05:7301:150c:b0:34b:fd9e:ad4f with SMTP id 5a478bee46e88-34c636156ffmr612413eec.22.1790715072007; Tue, 29 Sep 2026 13:51:12 -0700 (PDT) Received: from CHA-FQKPM83.ad.garmin.com ([65.175.40.146]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34c378c9b64sm2655843eec.6.2026.09.29.13.51.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Sep 2026 13:51:11 -0700 (PDT) From: Jason Stasiak X-Google-Original-From: Jason Stasiak To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 2/5] libsoup-2.4: fix CVE-2026-1801 Date: Tue, 29 Sep 2026 13:50:52 -0700 Message-ID: <20260929205055.2403390-3-jason.stasiak@garmin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260929205055.2403390-1-jason.stasiak@garmin.com> References: <20260929205055.2403390-1-jason.stasiak@garmin.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 20:51:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246895 Backport fix for CVE-2026-1801 from meta-oe to OE-core. Update CVE patch to restore the chunked server validation unit test from the upstream libsoup3 patch (b9a1c0663ff8ab6e79715db4b35b54f560416ddd). (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d) Signed-off-by: Jason Stasiak --- .../libsoup/libsoup-2.4/CVE-2026-1801.patch | 217 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 1 + 2 files changed, 218 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1801.patch diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1801.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1801.patch new file mode 100644 index 0000000000..13666b6d87 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1801.patch @@ -0,0 +1,217 @@ +From f9c933e258e9ef2f221cca6395f8092a1c4b93dd Mon Sep 17 00:00:00 2001 +From: Changqing Li +Date: Thu, 19 Mar 2026 17:10:36 +0800 +Subject: [PATCH 2/4] Fix CVE-2026-1801 + +This patch merges 3 upstream patches + +Chery-pick the first two patches to make the context is the same as the +third patch that fix CVE-2026-1801 + +Upstream-Status: Backport +[https://gitlab.gnome.org/GNOME/libsoup/-/commit/1e32b5e123aa1689505472bdbfcbd897eac41977, +https://gitlab.gnome.org/GNOME/libsoup/-/commit/8a2e15c88512ae4517d2c2c887d39299725b22da, +https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9a1c0663ff8ab6e79715db4b35b54f560416ddd] +CVE: CVE-2026-1801 + +Signed-off-by: Changqing Li + +Backport the chunked server validation unit test from the upstream +libsoup3 patch (b9a1c0663ff8ab6e79715db4b35b54f560416ddd). + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-body-input-stream.c | 66 +++++++++++++++++++------------ + tests/server-test.c | 67 ++++++++++++++++++++++++++++++++ + 2 files changed, 108 insertions(+), 25 deletions(-) + +diff --git a/libsoup/soup-body-input-stream.c b/libsoup/soup-body-input-stream.c +index 6b95884..25d9312 100644 +--- a/libsoup/soup-body-input-stream.c ++++ b/libsoup/soup-body-input-stream.c +@@ -159,15 +159,18 @@ soup_body_input_stream_read_chunked (SoupBodyInputStream *bistream, + again: + switch (bistream->priv->chunked_state) { + case SOUP_BODY_INPUT_STREAM_STATE_CHUNK_SIZE: +- nread = soup_filter_input_stream_read_line ( +- fstream, metabuf, sizeof (metabuf), blocking, +- &got_line, cancellable, error); +- if (nread <= 0) ++ nread = soup_filter_input_stream_read_until ( ++ fstream, metabuf, sizeof (metabuf), ++ "\r\n", 2, blocking, TRUE, ++ &got_line, cancellable, error); ++ if (nread < 0) + return nread; +- if (!got_line) { +- g_set_error_literal (error, G_IO_ERROR, +- G_IO_ERROR_PARTIAL_INPUT, +- _("Connection terminated unexpectedly")); ++ if (nread == 0 || !got_line) { ++ if (error && *error == NULL) { ++ g_set_error_literal (error, G_IO_ERROR, ++ G_IO_ERROR_PARTIAL_INPUT, ++ ("Connection terminated unexpectedly")); ++ } + return -1; + } + +@@ -180,9 +183,9 @@ again: + + case SOUP_BODY_INPUT_STREAM_STATE_CHUNK: + nread = soup_body_input_stream_read_raw ( +- bistream, buffer, +- MIN (count, bistream->priv->read_length), +- blocking, cancellable, error); ++ bistream, buffer, ++ MIN (count, bistream->priv->read_length), ++ blocking, cancellable, error); + if (nread > 0) { + bistream->priv->read_length -= nread; + if (bistream->priv->read_length == 0) +@@ -191,16 +194,19 @@ again: + return nread; + + case SOUP_BODY_INPUT_STREAM_STATE_CHUNK_END: +- nread = soup_filter_input_stream_read_line ( +- SOUP_FILTER_INPUT_STREAM (bistream->priv->base_stream), +- metabuf, sizeof (metabuf), blocking, +- &got_line, cancellable, error); +- if (nread <= 0) ++ nread = soup_filter_input_stream_read_until ( ++ SOUP_FILTER_INPUT_STREAM (bistream->priv->base_stream), ++ metabuf, sizeof (metabuf), ++ "\r\n", 2, blocking, TRUE, ++ &got_line, cancellable, error); ++ if (nread < 0) + return nread; +- if (!got_line) { +- g_set_error_literal (error, G_IO_ERROR, +- G_IO_ERROR_PARTIAL_INPUT, +- _("Connection terminated unexpectedly")); ++ if (nread == 0 || !got_line) { ++ if (error && *error == NULL) { ++ g_set_error_literal (error, G_IO_ERROR, ++ G_IO_ERROR_PARTIAL_INPUT, ++ _("Connection terminated unexpectedly")); ++ } + return -1; + } + +@@ -208,13 +214,23 @@ again: + break; + + case SOUP_BODY_INPUT_STREAM_STATE_TRAILERS: +- nread = soup_filter_input_stream_read_line ( +- fstream, buffer, count, blocking, +- &got_line, cancellable, error); +- if (nread <= 0) ++ nread = soup_filter_input_stream_read_until ( ++ fstream, metabuf, sizeof (metabuf), ++ "\r\n", 2, blocking, TRUE, ++ &got_line, cancellable, error); ++ if (nread < 0) + return nread; + +- if (strncmp (buffer, "\r\n", nread) || strncmp (buffer, "\n", nread)) { ++ if (nread == 0) { ++ if (error && *error == NULL) { ++ g_set_error_literal (error, G_IO_ERROR, ++ G_IO_ERROR_PARTIAL_INPUT, ++ _("Connection terminated unexpectedly")); ++ } ++ return -1; ++ } ++ ++ if (nread == 2 && strncmp (metabuf, "\r\n", nread) == 0) { + bistream->priv->chunked_state = SOUP_BODY_INPUT_STREAM_STATE_DONE; + bistream->priv->eof = TRUE; + } +diff --git a/tests/server-test.c b/tests/server-test.c +index 8976103e..fbe8bdcc 100644 +--- a/tests/server-test.c ++++ b/tests/server-test.c +@@ -1373,6 +1373,71 @@ do_steal_connect_test (ServerData *sd, gconstpointer test_data) + soup_uri_free (proxy_uri); + } + ++static void ++server_chunked_hundler (SoupServer *server, ++ SoupMessage *msg, ++ const char *path, ++ GHashTable *query, ++ gpointer data) ++{ ++ g_assert_true (msg->method == SOUP_METHOD_POST); ++ g_assert_cmpstr (path, ==, "/valid"); ++ ++ soup_message_set_status (msg, SOUP_STATUS_OK); ++ soup_message_set_response (msg, "text/plain", SOUP_MEMORY_STATIC, "index", 5); ++} ++ ++#define CHUNKED_FORMAT_REQUEST "POST /valid HTTP/1.1\r\nHost: 127.0.0.1\r\n%sGET /invalid HTTP/1.1\r\nHost: 127.0.0.1\r\n\r\n" ++ ++static void ++do_chunked_test (ServerData *sd, gconstpointer test_data) ++{ ++ gint i; ++ struct { ++ const char *description; ++ const char *test; ++ } tests[] = { ++ { "Lone LF", "Transfer-Encoding: chunked\r\n\r\n5;ext\n data\r\n0\r\n\r\n" }, ++ }; ++ ++ sd->server = soup_test_server_new (SOUP_TEST_SERVER_IN_THREAD); ++ sd->base_uri = soup_test_server_get_uri (sd->server, "http", NULL); ++ server_add_handler (sd, NULL, server_chunked_hundler, NULL, NULL); ++ ++ for (i = 0; i < G_N_ELEMENTS (tests); i++) { ++ GSocketClient *client; ++ GSocketConnection *conn; ++ GInputStream *input; ++ GOutputStream *output; ++ char *request; ++ char buffer[4096]; ++ gssize nread; ++ GError *error = NULL; ++ ++ debug_printf (1, " %s\n", tests[i].description); ++ ++ client = g_socket_client_new (); ++ conn = g_socket_client_connect_to_host (client, sd->base_uri->host, sd->base_uri->port, NULL, &error); ++ g_assert_no_error (error); ++ ++ request = g_strdup_printf (CHUNKED_FORMAT_REQUEST, tests[i].test); ++ ++ output = g_io_stream_get_output_stream (G_IO_STREAM (conn)); ++ g_output_stream_write_all (output, request, strlen (request), NULL, NULL, NULL); ++ g_output_stream_close (output, NULL, NULL); ++ g_socket_shutdown (g_socket_connection_get_socket (G_SOCKET_CONNECTION (conn)), FALSE, TRUE, &error); ++ ++ input = g_io_stream_get_input_stream (G_IO_STREAM (conn)); ++ do { ++ nread = g_input_stream_read (input, buffer, sizeof(buffer), NULL, NULL); ++ } while (nread > 0); ++ ++ g_free (request); ++ g_object_unref (conn); ++ g_object_unref (client); ++ } ++} ++ + int + main (int argc, char **argv) + { +@@ -1411,6 +1476,8 @@ main (int argc, char **argv) + server_setup_nohandler, do_early_multi_test, server_teardown); + g_test_add ("/server/steal/CONNECT", ServerData, NULL, + server_setup, do_steal_connect_test, server_teardown); ++ g_test_add ("/server/chunked", ServerData, NULL, ++ NULL, do_chunked_test, server_teardown); + + ret = g_test_run (); + +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb index 4fe1e36f03..9da2dde714 100644 --- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb +++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb @@ -42,6 +42,7 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \ file://CVE-2025-2784.patch \ file://CVE-2025-4945.patch \ file://CVE-2026-1539.patch \ + file://CVE-2026-1801.patch \ " SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13" From patchwork Tue Sep 29 20:50:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Jason Stasiak X-Patchwork-Id: 99610 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7DA9DCA5FAD for ; Tue, 29 Sep 2026 20:51:21 +0000 (UTC) Received: from mail-dy1-f170.google.com (mail-dy1-f170.google.com [74.125.82.170]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6708.1790715074220860378 for ; Tue, 29 Sep 2026 13:51:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=M0VCz2Wm; spf=pass (domain: gmail.com, ip: 74.125.82.170, mailfrom: jason.stasiak@gmail.com) Received: by mail-dy1-f170.google.com with SMTP id 5a478bee46e88-3115c4451c8so1041746eec.1 for ; Tue, 29 Sep 2026 13:51:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790715074; x=1791319874; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=btzZMfBCuoA87eUiBLyqdJY9mxEMNAZJDdE/DiJrZZo=; b=M0VCz2WmX4cgU+kadvVYjw8aDv9XIVpDafJg/PJPuCUDe+q4dwwI86grkG+XuFdAQE vxakmUKiqcqi39Fcocv1vnS2eFSSpqp5MapRQcbUNRk5POqXFtEXQ/JQOCmidLSnV69K jjn5iiTh0Aprx15fhwFo1DfKvfjDX8s6Mvl1muL09kgHHcUiPohwANjSEmYR7rx1tBle 0Muh8LBlOZWSpxjEN950gyR4yoMvu3uogYvHi7oWOtywiS5QJTpCE1TSkrQ+9UDNEoBh N51wHBTXzHOM28gl4yfPRDbSXrG8D2S16ZRlUW8nfl0KFz6Vm5D/bzdgP3VKyIXbhiCW A0lA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790715074; x=1791319874; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=btzZMfBCuoA87eUiBLyqdJY9mxEMNAZJDdE/DiJrZZo=; b=UNfFmH0gVeypXdfBH3cNk8KoJKg2Fej+cnyByLUiOnAqqD8VoVFosMjY3ERLloHLdB quIH4rtFp1ZbtN+oapqiLLN5xzs2ebh0DAwOBAThHoXqf7alNDpR87cSMCN8FSaT7K65 cSdhg2P97bThda22B3VfrvCfuPz2UuZ7lr1nbv5qTwRCd95VF82M+hr2crSmvAQTucnJ lyMIYPDnaJytyOwhBIhVS9ELotPFxcnDfCM5n/Iljjf7RIAc3ONz4GN27mV/vAHa0WNx NRwrcIZTnv1dmFkRdtEHl+dsEDKWExdI3rX7NsBGo2RfKTS++kWLjCmLfgyZEIw7X8d1 6/zg== X-Gm-Message-State: AFq9FYLelH39Azd51fm8rBx4JXtcZp9+BPqEy9kJETBU8CS3uVvJ5OsJ hhaCp1xFYVXBcfFKNta0bCxJNqWQHbzOhD6y83yJbUVB8EBDnzaB0NU9JtSCog== X-Gm-Gg: AYBFou34LsQyPeksw47FF9fSi/XkYyDWrgYUewxrdivQtpZ5GtmwWP964GxW2bCVljk kbUwNPd/Gcga5svY6Kl6mXmQMtOGq5ab5JZHZnVt5xzIDmqamPNQ2I22Kpc5g6pCEPfNgDAv9g8 UmTRz/kdOWm07TevG8ljdw/qGwYHjRwDuLjhXwJdO2v+pUk9lBqiwgkkiBmsTfezmCkcOf19XoU TV1TasaKW4lXgV0ONTIbZthr8YUG9LNr4JjhJzsgmuS1jF5AV1y9Fj9EadCnsHy/IhAF8COg1iM jdTxOqOORODC82ryWfSF5h9QuFvSU+WYdbi6GB61mR6uv7LutFEVyDYl47encsh/1ZhoDZVO5wH rP9ZaSjNUjmhZFKkJskHcCaLT4xFu/tPSfGLrWrq8wYkHHHhPAaOtX7UTYf4ydESp/FvfvW104V OC3shc2tAjYMGtuebwpIT9vnnLjWNgRinGp5RE7Nvwp4xohEUMfoCuUy84F9AFMYbJK3hJeww+p b23RNy/YqyQ2lhGDg73 X-Received: by 2002:a05:7300:271c:b0:33e:52d2:9219 with SMTP id 5a478bee46e88-34af7c5528fmr4062123eec.9.1790715073192; Tue, 29 Sep 2026 13:51:13 -0700 (PDT) Received: from CHA-FQKPM83.ad.garmin.com ([65.175.40.146]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34c378c9b64sm2655843eec.6.2026.09.29.13.51.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Sep 2026 13:51:12 -0700 (PDT) From: Jason Stasiak X-Google-Original-From: Jason Stasiak To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 3/5] libsoup-2.4: fix CVE-2026-2443 Date: Tue, 29 Sep 2026 13:50:53 -0700 Message-ID: <20260929205055.2403390-4-jason.stasiak@garmin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260929205055.2403390-1-jason.stasiak@garmin.com> References: <20260929205055.2403390-1-jason.stasiak@garmin.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 20:51:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246896 Backport fix for CVE-2026-2443 from meta-oe to OE-core. Update CVE patch to restore the range-test validation unit test from the upstream libsoup3 patch (b9a1c0663ff8ab6e79715db4b35b54f560416ddd). (From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d) Signed-off-by: Jason Stasiak --- .../libsoup/libsoup-2.4/CVE-2026-2443.patch | 390 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 1 + 2 files changed, 391 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-2443.patch diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-2443.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-2443.patch new file mode 100644 index 0000000000..e4d5f184fa --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-2443.patch @@ -0,0 +1,390 @@ +From 7bb3115a296154e3f465900ea5c984a493385a7f Mon Sep 17 00:00:00 2001 +From: Philip Withnall +Date: Fri, 19 Dec 2025 23:49:05 +0000 +Subject: [PATCH] Fix CVE-2026-2443 + +Upstream-Status: Backport [ +c1796442 soup-message-headers: Rework Range response statuses to match Apache +191ef313 soup-message-headers: Fix rejection of Range headers with trailing garbage +be677bea soup-message-headers: Fix parsing of invalid Range suffix lengths +2bbfdfe8 soup-message-headers: Reject ranges where end is before start +739bf7cb soup-message-headers: Reject invalid Range ends longer than the content +] +CVE: CVE-2026-2443 + +Signed-off-by: Changqing Li + +Backport the range-test validation unit tests from the upstream libsoup3 patches. + +Upstream-Status: Backport [ +5890c42d tests: Add more tests for invalid Range headers +c1796442 soup-message-headers: Rework Range response statuses to match Apache +6574a84f tests: Allow range tests to check more response statuses +191ef313 soup-message-headers: Fix rejection of Range headers with trailing garbage +be677bea soup-message-headers: Fix parsing of invalid Range suffix lengths +2bbfdfe8 soup-message-headers: Reject ranges where end is before start +739bf7cb soup-message-headers: Reject invalid Range ends longer than the content +] + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-message-headers.c | 62 ++++++++++---- + tests/range-test.c | 149 ++++++++++++++++++++++++++++----- + 2 files changed, 172 insertions(+), 39 deletions(-) + +diff --git a/libsoup/soup-message-headers.c b/libsoup/soup-message-headers.c +index ff10e103..f30dd461 100644 +--- a/libsoup/soup-message-headers.c ++++ b/libsoup/soup-message-headers.c +@@ -940,10 +940,16 @@ sort_ranges (gconstpointer a, gconstpointer b) + } + + /* like soup_message_headers_get_ranges(), except it returns: +- * SOUP_STATUS_OK if there is no Range or it should be ignored. +- * SOUP_STATUS_PARTIAL_CONTENT if there is at least one satisfiable range. +- * SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE if @check_satisfiable +- * is %TRUE and the request is not satisfiable given @total_length. ++ * - SOUP_STATUS_OK if there is no Range or it should be ignored due to being ++ * entirely invalid. ++ * - SOUP_STATUS_PARTIAL_CONTENT if there is at least one satisfiable range. ++ * - SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE if @check_satisfiable ++ * is %TRUE, the Range is valid, but no part of the request is satisfiable ++ * given @total_length. ++ * ++ * @ranges and @length are only set if SOUP_STATUS_PARTIAL_CONTENT is returned. ++ * ++ * See https://httpwg.org/specs/rfc9110.html#field.range + */ + guint + soup_message_headers_get_ranges_internal (SoupMessageHeaders *hdrs, +@@ -957,22 +963,28 @@ soup_message_headers_get_ranges_internal (SoupMessageHeaders *hdrs, + GArray *array; + char *spec, *end; + guint status = SOUP_STATUS_OK; ++ gboolean is_all_valid = TRUE; + + if (!range || strncmp (range, "bytes", 5) != 0) +- return status; ++ return SOUP_STATUS_OK; /* invalid header or unknown range unit */ + + range += 5; + while (g_ascii_isspace (*range)) + range++; + if (*range++ != '=') +- return status; ++ return SOUP_STATUS_OK; /* invalid header */ + while (g_ascii_isspace (*range)) + range++; + + range_list = soup_header_parse_list (range); + if (!range_list) +- return status; ++ return SOUP_STATUS_OK; /* invalid list */ + ++ /* Loop through the ranges and modify the status accordingly. Default to ++ * status 200 (OK, ignoring the ranges). Switch to status 206 (Partial ++ * Content) if there is at least one partially valid range. Switch to ++ * status 416 (Range Not Satisfiable) if there are no partially valid ++ * ranges at all. */ + array = g_array_new (FALSE, FALSE, sizeof (SoupRange)); + for (r = range_list; r; r = r->next) { + SoupRange cur; +@@ -985,30 +997,44 @@ soup_message_headers_get_ranges_internal (SoupMessageHeaders *hdrs, + cur.start = g_ascii_strtoull (spec, &end, 10); + if (*end == '-') + end++; +- if (*end) { ++ if (*end) + cur.end = g_ascii_strtoull (end, &end, 10); +- if (cur.end < cur.start) { +- status = SOUP_STATUS_OK; +- break; +- } +- } else ++ else + cur.end = total_length - 1; + } ++ + if (*end) { +- status = SOUP_STATUS_OK; +- break; +- } else if (check_satisfiable && cur.start >= total_length) { +- if (status == SOUP_STATUS_OK) +- status = SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE; ++ /* Junk after the range */ ++ is_all_valid = FALSE; ++ continue; ++ } ++ ++ if (cur.end < cur.start) { ++ is_all_valid = FALSE; ++ continue; ++ } ++ ++ g_assert (cur.start >= 0); ++ if (cur.end >= total_length) ++ cur.end = total_length - 1; ++ ++ if (cur.start >= total_length) { ++ /* Range is valid, but unsatisfiable */ + continue; + } + ++ /* We have at least one (at least partially) satisfiable range */ + g_array_append_val (array, cur); + status = SOUP_STATUS_PARTIAL_CONTENT; + } + soup_header_free_list (range_list); + + if (status != SOUP_STATUS_PARTIAL_CONTENT) { ++ g_assert (status == SOUP_STATUS_OK); ++ ++ if (is_all_valid && check_satisfiable) ++ status = SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE; ++ + g_array_free (array, TRUE); + return status; + } +diff --git a/tests/range-test.c b/tests/range-test.c +index d3c49963..8bd0fa1c 100644 +--- a/tests/range-test.c ++++ b/tests/range-test.c +@@ -57,7 +57,8 @@ check_part (SoupMessageHeaders *headers, const char *body, gsize body_len, + + static void + do_single_range (SoupSession *session, SoupMessage *msg, +- int start, int end, gboolean succeed) ++ int start, int end, SoupStatus expected_status, ++ int expected_start, int expected_end) + { + const char *content_type; + +@@ -66,7 +67,7 @@ do_single_range (SoupSession *session, SoupMessage *msg, + + soup_session_send_message (session, msg); + +- if (!succeed) { ++ if (expected_status == SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE) { + soup_test_assert_message_status (msg, SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE); + if (msg->status_code != SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE) { + const char *content_range; +@@ -76,31 +77,78 @@ do_single_range (SoupSession *session, SoupMessage *msg, + if (content_range) + debug_printf (1, " Content-Range: %s\n", content_range); + } +- + g_object_unref (msg); + return; ++ } else if (expected_status == SOUP_STATUS_OK) { ++ soup_test_assert_message_status (msg, SOUP_STATUS_OK); ++ ++ content_type = soup_message_headers_get_content_type(msg->response_headers, NULL); ++ g_assert_cmpstr (content_type, !=, "multipart/byteranges"); ++ ++ g_assert_false (soup_message_headers_get_content_range (msg->response_headers, NULL, ++ NULL, NULL)); ++ g_assert_cmpint (soup_message_headers_get_content_length (msg->response_headers), ++ ==, full_response->length); ++ } else { ++ soup_test_assert_message_status (msg, SOUP_STATUS_PARTIAL_CONTENT); ++ content_type = soup_message_headers_get_content_type (msg->response_headers, NULL); ++ g_assert_cmpstr (content_type, !=, "multipart/byteranges"); ++ ++ check_part (msg->response_headers, msg->response_body->data, ++ msg->response_body->length, TRUE, expected_start, expected_end); + } + +- soup_test_assert_message_status (msg, SOUP_STATUS_PARTIAL_CONTENT); +- +- content_type = soup_message_headers_get_content_type ( +- msg->response_headers, NULL); +- g_assert_cmpstr (content_type, !=, "multipart/byteranges"); +- +- check_part (msg->response_headers, msg->response_body->data, +- msg->response_body->length, TRUE, start, end); + g_object_unref (msg); + } + + static void + request_single_range (SoupSession *session, const char *uri, +- int start, int end, gboolean succeed) ++ int start, int end, SoupStatus expected_status, ++ int expected_start, int expected_end) + { + SoupMessage *msg; + + msg = soup_message_new ("GET", uri); + soup_message_headers_set_range (msg->request_headers, start, end); +- do_single_range (session, msg, start, end, succeed); ++ do_single_range (session, msg, start, end, expected_status, expected_start, expected_end); ++} ++ ++/* This always asserts failure (either 406 or 200 with no Content-Range); it’s ++ * intended to be used for passing invalid ++ * Range header formats which can’t be built by calling ++ * soup_message_headers_set_range(). */ ++static void ++request_single_range_by_string (SoupSession *session, const char *uri, ++ const char *range, SoupStatus expected_status) ++{ ++ SoupMessage *msg; ++ ++ msg = soup_message_new ("GET", uri); ++ soup_message_headers_replace (msg->request_headers, "Range", range); ++ ++ debug_printf (1, " Range: %s\n", ++ soup_message_headers_get_one (msg->request_headers, "Range")); ++ ++ soup_session_send_message (session, msg); ++ ++ if (expected_status == SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE) { ++ soup_test_assert_message_status (msg, SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE); ++ } else { ++ const char *content_type; ++ ++ soup_test_assert_message_status (msg, SOUP_STATUS_OK); ++ ++ content_type = soup_message_headers_get_content_type (msg->response_headers, NULL); ++ g_assert_cmpstr (content_type, !=, "multipart/byteranges"); ++ ++ g_assert_false (soup_message_headers_get_content_range (msg->response_headers, ++ NULL, NULL, NULL)); ++ ++ g_assert_cmpint (soup_message_headers_get_content_length (msg->response_headers), ++ ==, full_response->length); ++ } ++ ++ g_object_unref (msg); + } + + static void +@@ -165,7 +213,9 @@ request_double_range (SoupSession *session, const char *uri, + do_single_range (session, msg, + MIN (first_start, second_start), + MAX (first_end, second_end), +- TRUE); ++ SOUP_STATUS_PARTIAL_CONTENT, ++ MIN (first_start, second_start), ++ MAX (first_end, second_end)); + } else + do_multi_range (session, msg, expected_return_ranges); + } +@@ -193,7 +243,9 @@ request_triple_range (SoupSession *session, const char *uri, + do_single_range (session, msg, + MIN (first_start, MIN (second_start, third_start)), + MAX (first_end, MAX (second_end, third_end)), +- TRUE); ++ SOUP_STATUS_PARTIAL_CONTENT, ++ MIN (first_start, MIN (second_start, third_start)), ++ MAX (first_end, MAX (second_end, third_end))); + } else + do_multi_range (session, msg, expected_return_ranges); + } +@@ -248,7 +300,8 @@ do_range_test (SoupSession *session, const char *uri, + debug_printf (1, "Requesting %d-%d\n", 0 * twelfths, 1 * twelfths); + request_single_range (session, uri, + 0 * twelfths, 1 * twelfths, +- TRUE); ++ SOUP_STATUS_PARTIAL_CONTENT, ++ 0 * twelfths, 1 * twelfths); + + /* B: 11, end-relative request. These two are mostly redundant + * in terms of data coverage, but they may still catch +@@ -257,11 +310,13 @@ do_range_test (SoupSession *session, const char *uri, + debug_printf (1, "Requesting %d-\n", 11 * twelfths); + request_single_range (session, uri, + 11 * twelfths, -1, +- TRUE); ++ SOUP_STATUS_PARTIAL_CONTENT, ++ 11 * twelfths, -1); + debug_printf (1, "Requesting -%d\n", 1 * twelfths); + request_single_range (session, uri, + -1 * twelfths, -1, +- TRUE); ++ SOUP_STATUS_PARTIAL_CONTENT, ++ -1 * twelfths, -1); + + /* C: 2 and 5 */ + debug_printf (1, "Requesting %d-%d,%d-%d\n", +@@ -314,7 +369,8 @@ do_range_test (SoupSession *session, const char *uri, + (int) full_response->length + 100); + request_single_range (session, uri, + full_response->length + 1, full_response->length + 100, +- FALSE); ++ SOUP_STATUS_REQUESTED_RANGE_NOT_SATISFIABLE, ++ 0, 0); + + debug_printf (1, "Requesting (semi-invalid) 1-10,%d-%d,20-30\n", + (int) full_response->length + 1, +@@ -322,7 +378,58 @@ do_range_test (SoupSession *session, const char *uri, + request_semi_invalid_range (session, uri, + 1, 10, + full_response->length + 1, full_response->length + 100, +- 20, 30); ++ 20, 30); ++ ++ debug_printf (1, "Requesting (invalid end) %d-%d\n", ++ 1, ++ (int) full_response->length + 1000); ++ request_single_range (session, uri, ++ 1, full_response->length + 1000, ++ SOUP_STATUS_PARTIAL_CONTENT, ++ 1, full_response->length - 1); ++ ++ debug_printf (1, "Requesting (end before start) %d-%d\n", ++ 10, ++ 1); ++ request_single_range (session, uri, ++ 10, 1, ++ SOUP_STATUS_OK, ++ 1, full_response->length); ++ ++ debug_printf (1, "Requesting (malformed suffix length) -0\n"); ++ request_single_range_by_string (session, uri, ++ "bytes=-0", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (extra content after valid header value) 0-10\n"); ++ request_single_range_by_string (session, uri, ++ "bytes=0-10 but with weird trailing content", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (invalid range dash) 0a10\n"); ++ request_single_range_by_string (session, uri, ++ "bytes=0a10", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (invalid range unit) 0-10\n"); ++ request_single_range_by_string (session, uri, ++ "horses=0-10", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (missing equals) 0-10\n"); ++ request_single_range_by_string (session, uri, ++ "bytes 0-10", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (end before start but with whitespace) 10-1\n"); ++ request_single_range_by_string (session, uri, ++ "bytes \t = \t 10-1", ++ SOUP_STATUS_OK); ++ ++ debug_printf (1, "Requesting (delimiters but no ranges)\n"); ++ request_single_range_by_string (session, uri, ++ "bytes=, ,,\t, ", ++ SOUP_STATUS_OK); + } + + static void +@@ -341,7 +448,7 @@ do_apache_range_test (void) + + static void + server_handler (SoupServer *server, +- SoupMessage *msg, ++ SoupMessage *msg, + const char *path, + GHashTable *query, + SoupClientContext *client, +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb index 9da2dde714..18f82f8ef7 100644 --- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb +++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb @@ -43,6 +43,7 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \ file://CVE-2025-4945.patch \ file://CVE-2026-1539.patch \ file://CVE-2026-1801.patch \ + file://CVE-2026-2443.patch \ " SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13" From patchwork Tue Sep 29 20:50:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Stasiak X-Patchwork-Id: 99608 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E984CA5FB5 for ; Tue, 29 Sep 2026 20:51:21 +0000 (UTC) Received: from mail-dy2-f43.google.com (mail-dy2-f43.google.com [74.125.229.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6709.1790715074730681489 for ; Tue, 29 Sep 2026 13:51:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=OTCLjJZR; spf=pass (domain: gmail.com, ip: 74.125.229.43, mailfrom: jason.stasiak@gmail.com) Received: by mail-dy2-f43.google.com with SMTP id 5a478bee46e88-33e46a156f4so2647045eec.0 for ; Tue, 29 Sep 2026 13:51:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790715074; x=1791319874; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6jNBkOItkJfDUEFBQ0eP14mVgZfUZuO0gJ0R1xz2aZE=; b=OTCLjJZRijLedDULBCJMIjXEs1ww7k46uuLGgwUJXODPOGzgybaTEBtr0pOdtDmWu4 p6oWV3TXSAPCIGQZ81pS+rKN+C/6anPVZb9qZIo25pACZdjI8Yc/EWBn3IYzndvfJhbR fUZRyWBiYvkMA2kcn0qT7vkeFlTgd5WrdtEeuqa7XUsKBi+kGSmvCMPxWNmvGqG3m7GM dSwO8CcHt5/WuDkvzoTbOkLAN3TcbxUwrJbHxUlHufFweIpFkBjuhsKHy+qL6WjPTUWw +56o/+txU3G4nIZPUBZMv70p+GId5gt9f+yCaQL26BCGEAfvu8z0FNrwPNwGXhRMOPaW fkBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790715074; x=1791319874; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6jNBkOItkJfDUEFBQ0eP14mVgZfUZuO0gJ0R1xz2aZE=; b=rBB6ESfWSA0RHuicjTQXF6+q0Yd+PdUELHRuXWGOCPhNIJipPSrDkCnH0C02I50kqw nTMQSIXeT2ux6Nq5as/RU65Y4mdCmwYWmcXROAvXBjIRzNgOAwKmneeoK4xhPpY+fE7k ZZKvaS+f8cY2TW3ZZ+sW+uZSBJLP6pWDQak6RxhptBfBtA4hQnH72FahLqbBaScNg9fG JkenC1JGdO0N+3Yzrk0Ed/N8/Ha62eCPs86VTrUxWfo1/3KSSuCLt0pAYVXkKNs5ivGQ 8cilijoW30pLPeSXKV+UegmaDJwrD+SKrkCg2+6IrK86vQO3m1ZxXw2dKBR7u5aYPigq FBnA== X-Gm-Message-State: AFuF++lNvWujoM4rrE+7Os3KhtS+BZF87zy5g+CBOoWwK5k4IzhgtrEu /XHnOO45PmYih0wmh+jt7dmw9Z951rBe7IO5z+B5VUoOeK8qsd6iKYROqPepcw== X-Gm-Gg: AYBFou3zFnrfMccAjVoFvLTwPhkvcFBT1+UpFtMjL3F4pP2/j/rDY4KJU/brYa77PTf aQJrRXwGWy7V9xayXt15KFw3KVkYVqiGYLpfPC8xi5LaNL78HAivX9RBJWZwfisNooZoEk16vle 2lOi5g0jHd1S+aXLKynd+lRSOwtQoa1zFk0X8kfQmnn0NKr39XqElWOD4hjBZFbTHIwvUYgWbA3 wUPDrZ80bMahW4gPkggV29ZQDzGBB5Z37pwfA8dogPmiSwu+irJYSUD7O1iPYDptu16hGAsFjlD bx+Le9wXlpGfQLTrs58fVbdoJ787pUHvZ0bxH7IIQvw+SmCd3xzG5uiMauXeOYoMKA82PFzlaxu Q2JsEjjTBoiYYKaAYEgxbkzlmybDHrDs4tDpqAvpVoKOHQtT+t4Ri3j55GDjStBPdWRzsJVZrnn whkJEJT+lSzbjma/i7jSMCcVhg5zxCxy+6xNKNxS18bud/2PnkxEviKhGr76owIS3yiSR12kQSo 8KdIa41c/4QjhjCLhhs X-Received: by 2002:a05:7301:fd08:b0:34a:ab59:81ea with SMTP id 5a478bee46e88-34c64fad9bfmr582983eec.36.1790715073977; Tue, 29 Sep 2026 13:51:13 -0700 (PDT) Received: from CHA-FQKPM83.ad.garmin.com ([65.175.40.146]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34c378c9b64sm2655843eec.6.2026.09.29.13.51.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Sep 2026 13:51:13 -0700 (PDT) From: Jason Stasiak X-Google-Original-From: Jason Stasiak To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 4/5] libsoup-2.4: fix CVE-2026-5119 Date: Tue, 29 Sep 2026 13:50:54 -0700 Message-ID: <20260929205055.2403390-5-jason.stasiak@garmin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260929205055.2403390-1-jason.stasiak@garmin.com> References: <20260929205055.2403390-1-jason.stasiak@garmin.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 20:51:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246897 Backport fix for CVE-2026-5119 from upstream libsoup 3 patch [1]. [1] https://gitlab.gnome.org/GNOME/libsoup/-/commit/b0626fff8538e3dd4a52f148d91c8348d51d64d1 Signed-off-by: Jason Stasiak --- .../libsoup/libsoup-2.4/CVE-2026-5119.patch | 129 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 1 + 2 files changed, 130 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch new file mode 100644 index 0000000000..4df1a98ab8 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch @@ -0,0 +1,129 @@ +From b0626fff8538e3dd4a52f148d91c8348d51d64d1 Mon Sep 17 00:00:00 2001 +From: Carlos Garcia Campos +Date: Fri, 27 Feb 2026 12:03:25 +0100 +Subject: [PATCH] Fix CVE-2026-25119 + +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libsoup/-/commit/b0626fff8538e3dd4a52f148d91c8348d51d64d1] +CVE: CVE-2026-5119 + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-cookie-jar.c | 25 +++++++++++++++------ + tests/proxy-test.c | 46 +++++++++++++++++++++++++++++++++++++++ + 2 files changed, 64 insertions(+), 7 deletions(-) + +diff --git a/libsoup/soup-cookie-jar.c b/libsoup/soup-cookie-jar.c +index c8231f0e..b9abdc82 100644 +--- a/libsoup/soup-cookie-jar.c ++++ b/libsoup/soup-cookie-jar.c +@@ -12,6 +12,7 @@ + #include + + #include "soup-cookie-jar.h" ++#include "soup-connection.h" + #include "soup-message-private.h" + #include "soup-misc-private.h" + #include "soup.h" +@@ -818,18 +819,28 @@ process_set_cookie_header (SoupMessage *msg, gpointer user_data) + g_slist_free (new_cookies); + } + ++static gboolean ++allow_cookies_for_request (SoupMessage *msg) ++{ ++ /* Do not send cookies to a HTTP proxy for a HTTPS request */ ++ return msg->method != SOUP_METHOD_CONNECT || !soup_connection_is_tunnelled (soup_message_get_connection (msg)); ++} ++ + static void + msg_starting_cb (SoupMessage *msg, gpointer feature) + { + SoupCookieJar *jar = SOUP_COOKIE_JAR (feature); +- GSList *cookies; ++ GSList *cookies = NULL; ++ ++ if (allow_cookies_for_request (msg)) { ++ cookies = soup_cookie_jar_get_cookie_list_with_same_site_info (jar, soup_message_get_uri (msg), ++ soup_message_get_first_party (msg), ++ soup_message_get_site_for_cookies (msg), ++ TRUE, ++ SOUP_METHOD_IS_SAFE (msg->method), ++ soup_message_get_is_top_level_navigation (msg)); ++ } + +- cookies = soup_cookie_jar_get_cookie_list_with_same_site_info (jar, soup_message_get_uri (msg), +- soup_message_get_first_party (msg), +- soup_message_get_site_for_cookies (msg), +- TRUE, +- SOUP_METHOD_IS_SAFE (msg->method), +- soup_message_get_is_top_level_navigation (msg)); + if (cookies != NULL) { + char *cookie_header = soup_cookies_to_cookie_header (cookies); + soup_message_headers_replace (msg->request_headers, "Cookie", cookie_header); +diff --git a/tests/proxy-test.c b/tests/proxy-test.c +index 105a02a6..d8c7e8a1 100644 +--- a/tests/proxy-test.c ++++ b/tests/proxy-test.c +@@ -435,6 +435,51 @@ do_proxy_auth_cache_test (void) + g_object_unref (cache); + } + ++static void ++connect_message_wrote_headers_cb (SoupMessage *msg, guint *counter) ++{ ++ SoupMessageHeaders *hdrs; ++ ++ *counter += 1; ++ ++ if (msg->method == SOUP_METHOD_CONNECT) ++ g_assert_null (soup_message_headers_get_one (msg->request_headers, "Cookie")); ++ else ++ g_assert_nonnull (soup_message_headers_get_one (msg->request_headers, "Cookie")); ++} ++ ++static void ++request_queued_cb (SoupSession *session, SoupMessage *msg, guint *counter) ++{ ++ g_signal_connect (msg, "wrote-headers", G_CALLBACK (connect_message_wrote_headers_cb), counter); ++} ++ ++static void ++do_proxy_secure_cookies_test (void) ++{ ++ SoupSession *session; ++ SoupMessage *msg; ++ SoupCookieJar *jar; ++ guint counter = 0; ++ ++ SOUP_TEST_SKIP_IF_NO_APACHE; ++ SOUP_TEST_SKIP_IF_NO_TLS; ++ ++ session = soup_test_session_new (SOUP_TYPE_SESSION_SYNC, SOUP_SESSION_PROXY_RESOLVER, proxy_resolvers[SIMPLE_PROXY], NULL); ++ g_signal_connect (session, "request-queued", G_CALLBACK (request_queued_cb), &counter); ++ ++ soup_session_add_feature_by_type (session, SOUP_TYPE_COOKIE_JAR); ++ jar = SOUP_COOKIE_JAR (soup_session_get_feature (session, SOUP_TYPE_COOKIE_JAR)); ++ ++ msg = soup_message_new (SOUP_METHOD_GET, HTTPS_SERVER); ++ soup_cookie_jar_set_cookie (jar, soup_message_get_uri (msg), "user=password; secure"); ++ soup_session_send_message (session, msg); ++ soup_test_assert_message_status (msg, SOUP_STATUS_OK); ++ g_assert_cmpuint (counter, ==, 2); ++ ++ soup_test_session_abort_unref (session); ++} ++ + int + main (int argc, char **argv) + { +@@ -470,6 +515,7 @@ main (int argc, char **argv) + g_test_add_func ("/proxy/redirect", do_proxy_redirect_test); + g_test_add_func ("/proxy/auth-redirect", do_proxy_auth_redirect_test); + g_test_add_func ("/proxy/auth-cache", do_proxy_auth_cache_test); ++ g_test_add_func ("/proxy/secure-cookies", do_proxy_secure_cookies_test); + + ret = g_test_run (); + +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb index 18f82f8ef7..c79bced69d 100644 --- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb +++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb @@ -44,6 +44,7 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \ file://CVE-2026-1539.patch \ file://CVE-2026-1801.patch \ file://CVE-2026-2443.patch \ + file://CVE-2026-5119.patch \ " SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13" From patchwork Tue Sep 29 20:50:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Stasiak X-Patchwork-Id: 99607 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 40FEFCA5FA7 for ; Tue, 29 Sep 2026 20:51:21 +0000 (UTC) Received: from mail-dy2-f41.google.com (mail-dy2-f41.google.com [74.125.229.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6710.1790715075780709849 for ; Tue, 29 Sep 2026 13:51:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iOjVj8b8; spf=pass (domain: gmail.com, ip: 74.125.229.41, mailfrom: jason.stasiak@gmail.com) Received: by mail-dy2-f41.google.com with SMTP id 5a478bee46e88-34c4a0870d2so313098eec.2 for ; Tue, 29 Sep 2026 13:51:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790715075; x=1791319875; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mV8Dsm79UjSmL3f8YDP76bnQScpCWf/U8RehHSr8qFA=; b=iOjVj8b8mytD1OIXtWdjohQPS5wU1qk3Y6XcHIo2AQFCF7FaYek3tXKh+tG+K0cCER BKVq2aXiuvZp4xclMScbZTGQ0m6Iw7dIb6GByRdxj9Jyn+A57YToI85Q62+5YFrggOYJ EgE6yqrmJ7R+gYgTRcRKHjGq2fwJyNMfRNd22aJJkU11xi5UE4cc8VX3w/dN5n4AdD8g TosrnHv2LXOXdK5tx1kfkjJw6ZP97xM6Fk8FjfrDmw9JKQ8fJsYqkxZkbjiluBdIQS1b chbgpk/hGAXHlPS+mpEPVOhaDU0DqET5i/xWe72UJnzWOq8qLp32863Z+Dg2S+q8PqRb Qw9Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790715075; x=1791319875; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=mV8Dsm79UjSmL3f8YDP76bnQScpCWf/U8RehHSr8qFA=; b=ZdDusSRCdECUuD2rOVUkRZ47VQAY1hqtApEuUL+6pDY8Ing4YP1zOu52UuVCZwyNBQ Fbxf8yeumZ2UqCJLddKgrCQgY6Agjy4lMxKU3Hqj6Bq67PsXpv7biDXnRbYWQpJpM8PJ mjvLiYX8zR+p+giFcWZpC4lCH+8Y2wFkRRBT6f/E0Xt58RLaMPYRI3JDt+mezzpb01zz jvGlasEKhKbEk9iLxff8sx9/bNxqJ9T5elU13PDDzuddsppRDs2Wa0k+GS9odBLs/qEi 9ct2jsebeBhwaFnIs0Gp+8++ic4VGqm0uLzy0LYVWXdWxGh0+Xl/Ft1V+oSXM4j/kSep CY9Q== X-Gm-Message-State: AFq9FYJkxvGFMmDinyYF2jNjQJj9Rv0SJN0Llzl7QeI9gW0rumZ+zgwj rLO/krNPTboyZ3vWccbeUXNStW7LwO9BxTKpmz9iueshpj67u5cxbWRHDrOVWQ== X-Gm-Gg: AYBFou2wE8SaWLt80eQdO3yNbi5BQbX93darRDQbY34RxCzTNLt+dFm6jNCWnSmisJv nPUkgtWNzB12GxQsb3YZ5t5GUEf61nMrTdQl7ZyCkdlioCbvfYsfYEQdXw6rGAWeLbqoOv5EfTU ndlVUSUL7tVa/0EEDQ2ytL6K7RoFeVce8OE3oZtqGhl6LA/wJRbETZLrmo9G80PCOb5ILe/t9as unWBQwUezQO7hFLhnvbR/Ux+otC7QP4bvOs6VlLR2xYXoLcQy47U/cM6/QGTtJ1fw1qpEckbkDL UId/gwJNk+WERfAqwxs6MmcF2+CYklAFY7gTaWutmpJhDttzyzHN69TQVZa+FAwsKO9PPmnOY7b kmmxatnWSQ0kO2jYjZvR5OZdCh5qxwKhmvf8EZ7u3xMwk3xfTKYUhJ5oE5rGkR77JPlQlsnbWFD KvV6Xhaly6ccX9GW5S7xOLmKWYa5YIAAhJA5u4wKZ7gsMYUaU/FoC1+fWbhoU2gBxzNreIVoLEG VdU7jnF/ZBKxvCCvdfF X-Received: by 2002:a05:7300:5620:b0:349:11ea:1c with SMTP id 5a478bee46e88-34c66054123mr526689eec.6.1790715074855; Tue, 29 Sep 2026 13:51:14 -0700 (PDT) Received: from CHA-FQKPM83.ad.garmin.com ([65.175.40.146]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34c378c9b64sm2655843eec.6.2026.09.29.13.51.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Sep 2026 13:51:14 -0700 (PDT) From: Jason Stasiak X-Google-Original-From: Jason Stasiak To: openembedded-core@lists.openembedded.org Subject: [scarthgap][PATCH 5/5] libsoup-2.4: fix CVE-2026-3633 Date: Tue, 29 Sep 2026 13:50:55 -0700 Message-ID: <20260929205055.2403390-6-jason.stasiak@garmin.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260929205055.2403390-1-jason.stasiak@garmin.com> References: <20260929205055.2403390-1-jason.stasiak@garmin.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 20:51:21 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246898 Backport fix for CVE-2026-3633 [1] and additional supporting patches [2][3][4] from the upstream libsoup 3 repo. [1] https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926 [2] https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf [3] https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa [4] https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8 Signed-off-by: Jason Stasiak --- .../libsoup/libsoup-2.4/CVE-2026-3633-1.patch | 51 ++++++++ .../libsoup/libsoup-2.4/CVE-2026-3633-2.patch | 53 ++++++++ .../libsoup/libsoup-2.4/CVE-2026-3633-3.patch | 49 ++++++++ .../libsoup/libsoup-2.4/CVE-2026-3633-4.patch | 113 ++++++++++++++++++ .../libsoup/libsoup-2.4_2.74.3.bb | 4 + 5 files changed, 270 insertions(+) create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch new file mode 100644 index 0000000000..37eeb24409 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch @@ -0,0 +1,51 @@ +From 5d61da4e261fab02d07dc74bb3049bbd13535247 Mon Sep 17 00:00:00 2001 +From: Jason Stasiak +Date: Fri, 25 Sep 2026 10:17:05 -0700 +Subject: [PATCH 1/4] CVE-2026-3633: Make SoupMessage a private and final type + +CVE: CVE-2026-3633 +Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf ] + +Backport the introduction of soup_message_set_method() from upstream +libsoup 3 patch to begin alignment of libsoup 2.4 code with that needed +to address CVE-2026-3633. + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-message-private.h | 2 ++ + libsoup/soup-message.c | 10 ++++++++++ + 2 files changed, 12 insertions(+) + +diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h +index c30361c0..ee73112f 100644 +--- a/libsoup/soup-message-private.h ++++ b/libsoup/soup-message-private.h +@@ -179,4 +179,6 @@ gboolean soup_message_has_chunk_allocator (SoupMessage *msg); + SoupBuffer *soup_message_allocate_chunk (SoupMessage *msg, + goffset read_length); + ++void soup_message_set_method (SoupMessage *msg, ++ const char *method); + #endif /* __SOUP_MESSAGE_PRIVATE_H__ */ +diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c +index cc4f22b6..eae11eea 100644 +--- a/libsoup/soup-message.c ++++ b/libsoup/soup-message.c +@@ -2394,3 +2394,13 @@ soup_message_allocate_chunk (SoupMessage *msg, + + return priv->chunk_allocator (msg, read_length, priv->chunk_allocator_data); + } ++ ++ ++void ++soup_message_set_method (SoupMessage *msg, ++ const char *method) ++{ ++ g_return_if_fail (method != NULL); ++ ++ msg->method = g_intern_string (method); ++} +\ No newline at end of file +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch new file mode 100644 index 0000000000..c98a26ee6a --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch @@ -0,0 +1,53 @@ +From ef7fb85f6bda553c37f50606205396b1a3b363a7 Mon Sep 17 00:00:00 2001 +From: Jason Stasiak +Date: Fri, 25 Sep 2026 10:23:14 -0700 +Subject: [PATCH 2/4] CVE-2026-3633: message: ensure GObject::notify signal is + always emitted when properties change + +CVE: CVE-2026-3633 +Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa ] + +Backport the following portions of the libsoup 3 patch to align +libsoup 2.4 code with that needed to address CVE-2026-3633: +- Calling of soup_message_set_property() within soup_message_set_method() + for a method property change +- Update of soup_message_set_property() which triggers the GObject::notify + signal when the method property changes + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-message.c | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c +index eae11eea..ff8aaab5 100644 +--- a/libsoup/soup-message.c ++++ b/libsoup/soup-message.c +@@ -205,7 +205,7 @@ soup_message_set_property (GObject *object, guint prop_id, + + switch (prop_id) { + case PROP_METHOD: +- msg->method = g_intern_string (g_value_get_string (value)); ++ soup_message_set_method (msg, g_value_get_string (value)); + break; + case PROP_URI: + soup_message_set_uri (msg, g_value_get_boxed (value)); +@@ -2400,7 +2400,12 @@ void + soup_message_set_method (SoupMessage *msg, + const char *method) + { +- g_return_if_fail (method != NULL); ++ const char *new_method = g_intern_string (method); + +- msg->method = g_intern_string (method); ++ if (msg->method == new_method) ++ return; ++ ++ msg->method = new_method; ++ ++ g_object_notify (G_OBJECT (msg), "method"); + } +\ No newline at end of file +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch new file mode 100644 index 0000000000..825d7f0436 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch @@ -0,0 +1,49 @@ +From ac0de649ae76b073c8c405f141e6509eb624ee89 Mon Sep 17 00:00:00 2001 +From: Jason Stasiak +Date: Fri, 25 Sep 2026 10:32:36 -0700 +Subject: [PATCH 3/4] CVE-2026-3633: message: make soup_message_set_method + public + +CVE: CVE-2026-3633 +Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8 ] + +Backport the portion of the libsoup 3 patch that transitions +soup_message_set_method() from being a private getter to a public +getter to align the libsoup 2.4 code with that needed to address +CVE-2026-3633. + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-message-private.h | 2 -- + libsoup/soup-message.h | 4 ++++ + 2 files changed, 4 insertions(+), 2 deletions(-) + +diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h +index ee73112f..c30361c0 100644 +--- a/libsoup/soup-message-private.h ++++ b/libsoup/soup-message-private.h +@@ -179,6 +179,4 @@ gboolean soup_message_has_chunk_allocator (SoupMessage *msg); + SoupBuffer *soup_message_allocate_chunk (SoupMessage *msg, + goffset read_length); + +-void soup_message_set_method (SoupMessage *msg, +- const char *method); + #endif /* __SOUP_MESSAGE_PRIVATE_H__ */ +diff --git a/libsoup/soup-message.h b/libsoup/soup-message.h +index 42379a4b..18066d35 100644 +--- a/libsoup/soup-message.h ++++ b/libsoup/soup-message.h +@@ -115,6 +115,10 @@ SoupHTTPVersion soup_message_get_http_version (SoupMessage *msg); + SOUP_AVAILABLE_IN_2_4 + gboolean soup_message_is_keepalive (SoupMessage *msg); + ++SOUP_AVAILABLE_IN_2_4 ++void soup_message_set_method (SoupMessage *msg, ++ const char *method); ++ + SOUP_AVAILABLE_IN_2_4 + SoupURI *soup_message_get_uri (SoupMessage *msg); + SOUP_AVAILABLE_IN_2_4 +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch new file mode 100644 index 0000000000..471df33ec9 --- /dev/null +++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch @@ -0,0 +1,113 @@ +From bd9d3c8c6af2783fed2745834f6623a2df70f75d Mon Sep 17 00:00:00 2001 +From: Jason Stasiak +Date: Fri, 25 Sep 2026 10:39:16 -0700 +Subject: [PATCH 4/4] Fix CVE-2026-3633 + +CVE: CVE-2026-3633 +Upstream-Status: Backport [ https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926 ] + +Backport the upstream libsoup 3 fix for CVE-2026-3633 to +libsoup 2.4. + +Signed-off-by: Jason Stasiak +--- + libsoup/soup-message.c | 32 ++++++++++++++++++++++++++++++-- + tests/misc-test.c | 22 ++++++++++++++++++++++ + 2 files changed, 52 insertions(+), 2 deletions(-) + +diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c +index ff8aaab5..08f22c19 100644 +--- a/libsoup/soup-message.c ++++ b/libsoup/soup-message.c +@@ -2395,17 +2395,45 @@ soup_message_allocate_chunk (SoupMessage *msg, + return priv->chunk_allocator (msg, read_length, priv->chunk_allocator_data); + } + ++/* Validates that a method string conforms to the RFC 9110 'token' specification. */ ++static gboolean ++method_is_valid (const char *method) ++{ ++ const char *p; ++ ++ if (method == NULL || *method == '\0') ++ return FALSE; ++ ++ for (p = method; *p != '\0'; p++) { ++ char c = *p; ++ ++ if (g_ascii_isalnum (c)) ++ continue; ++ ++ if (strchr ("!#$%&\'*+-.^_`|~", c) == NULL) ++ return FALSE; ++ } ++ ++ return TRUE; ++} + + void + soup_message_set_method (SoupMessage *msg, + const char *method) + { +- const char *new_method = g_intern_string (method); ++ const char *new_method; ++ ++ g_return_if_fail (method != NULL); + ++ if (!method_is_valid (method)) { ++ g_warning ("soup_message_set_method: Rejecting invalid method '%s'", method); ++ return; ++ } ++ ++ new_method = g_intern_string (method); + if (msg->method == new_method) + return; + + msg->method = new_method; +- + g_object_notify (G_OBJECT (msg), "method"); + } +\ No newline at end of file +diff --git a/tests/misc-test.c b/tests/misc-test.c +index 0f9b0d33..afb7bb30 100644 +--- a/tests/misc-test.c ++++ b/tests/misc-test.c +@@ -89,6 +89,27 @@ server_callback (SoupServer *server, SoupMessage *msg, + } + } + ++static void ++do_method_injection_test (void) ++{ ++ SoupMessage *msg; ++ ++ g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING, ++ "soup_message_set_method: Rejecting invalid method*"); ++ msg = soup_message_new_from_uri ("GET / HTTP/1.1\r\nX-Injected: evil", base_uri); ++ g_assert_null (msg->method); ++ g_test_assert_expected_messages (); ++ g_object_unref (msg); ++ ++ g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING, ++ "soup_message_set_method: Rejecting invalid method*"); ++ msg = soup_message_new_from_uri (SOUP_METHOD_GET, base_uri); ++ soup_message_set_method (msg, "POST /evil HTTP/1.1\r\nHost: attacker\r\n\r\nGET"); ++ g_assert_cmpstr (msg->method, ==, SOUP_METHOD_GET); ++ g_test_assert_expected_messages (); ++ g_object_unref (msg); ++} ++ + /* Host header handling: client must be able to override the default + * value, server must be able to recognize different Host values. + */ +@@ -1276,6 +1297,7 @@ main (int argc, char **argv) + + g_test_add_func ("/misc/bigheader", do_host_big_header); + g_test_add_func ("/misc/host", do_host_test); ++ g_test_add_func ("/misc/method-injection", do_method_injection_test); + g_test_add_func ("/misc/callback-unref/msg", do_callback_unref_test); + g_test_add_func ("/misc/callback-unref/req", do_callback_unref_req_test); + g_test_add_func ("/misc/msg-reuse", do_msg_reuse_test); +-- +2.55.0 + diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb index c79bced69d..19a2d96b91 100644 --- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb +++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb @@ -45,6 +45,10 @@ SRC_URI = "${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \ file://CVE-2026-1801.patch \ file://CVE-2026-2443.patch \ file://CVE-2026-5119.patch \ + file://CVE-2026-3633-1.patch \ + file://CVE-2026-3633-2.patch \ + file://CVE-2026-3633-3.patch \ + file://CVE-2026-3633-4.patch \ " SRC_URI[sha256sum] = "e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"