From patchwork Sat Oct 3 21:42:09 2026
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Patchwork-Submitter: Yoann Congal
-+/* Added in Expat 2.7.2. */ -+XML_Bool -+XML_SetAllocTrackerMaximumAmplification(XML_Parser p, -+ float maximumAmplificationFactor); -+-+
-+ Sets the maximum tolerated amplification factor
-+ between direct input and bytes of dynamic memory allocated
-+ (default: 100.0)
-+ of parser p to maximumAmplificationFactor, and
-+ returns XML_TRUE upon success and XML_FALSE upon error.
-+
-+ Note: -+ There are three types of allocations that intentionally bypass tracking and limiting: -+
-+XML_MemMalloc
-+ and
-+ XML_MemRealloc
-+ —
-+ healthy use of these two functions continues to be a responsibility
-+ of the application using Expat
-+ —,
-+ XML_GetBuffer
-+ and
-+ XML_ParseBuffer
-+ (and thus also by plain
-+ XML_Parse), and
-+ XML_FreeContentModel).
-+ The amplification factor is calculated as ..
-+amplification := allocated / direct-+
-+ .. while parsing, whereas
-+ direct is the number of bytes read from the primary document in parsing and
-+ allocated is the number of bytes of dynamic memory allocated in the parser hierarchy.
-+
For a call to XML_SetAllocTrackerMaximumAmplification to succeed:
p must be a non-NULL root parser (without any parent parsers) andmaximumAmplificationFactor must be non-NaN and greater than or equal to 1.0.-+ Note: -+ If you ever need to increase this value for non-attack payload, -+ please file a bug report. -+
-+ -+-+ Note: -+ Amplifications factors greater than 100 can been observed near the start of parsing -+ even with benign files in practice. -+ -+ So if you do reduce the maximum allowed amplification, -+ please make sure that the activation threshold is still big enough -+ to not end up with undesired false positives (i.e. benign files being rejected). -+
-+-+/* Added in Expat 2.7.2. */ -+XML_Bool -+XML_SetAllocTrackerActivationThreshold(XML_Parser p, -+ unsigned long long activationThresholdBytes); -+-+
-+ Sets number of allocated bytes of dynamic memory
-+ needed to activate protection against disproportionate use of RAM
-+ (default: 64 MiB)
-+ of parser p to activationThresholdBytes, and
-+ returns XML_TRUE upon success and XML_FALSE upon error.
-+
-+ Note:
-+ For types of allocations that intentionally bypass tracking and limiting, please see
-+ XML_SetAllocTrackerMaximumAmplification
-+ above.
-+
For a call to XML_SetAllocTrackerActivationThreshold to succeed:
p must be a non-NULL root parser (without any parent parsers).-+ Note: -+ If you ever need to increase this value for non-attack payload, -+ please file a bug report. -+
-+- /* Added in Expat 2.6.0. */ diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-17.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-17.patch deleted file mode 100644 index ca0e3a34f73..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-17.patch +++ /dev/null @@ -1,28 +0,0 @@ -From a6a2a49367f03f5d8a73c9027b45b59953ca27d8 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping-Date: Wed, 10 Sep 2025 19:52:39 +0200 -Subject: [PATCH] docs: Promote the contract to call XML_FreeContentModel - -.. when registering a custom element declaration handler -(via a call to function XML_SetElementDeclHandler) - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/a6a2a49367f03f5d8a73c9027b45b59953ca27d8] -Signed-off-by: Peter Marko ---- - doc/reference.html | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/doc/reference.html b/doc/reference.html -index 81da4e6c..564fc1b2 100644 ---- a/doc/reference.html -+++ b/doc/reference.html -@@ -1902,7 +1902,7 @@ struct XML_cp { - Sets a handler for element declarations in a DTD. The handler gets - called with the name of the element in the declaration and a pointer - to a structure that contains the element model. It's the user code's --responsibility to free model when finished with it. See
diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-18.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-18.patch deleted file mode 100644 index c29b3018254..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-18.patch +++ /dev/null @@ -1,74 +0,0 @@ -From a21a3a8299e1ee0b0ae5ae2886a0746d088cf135 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping-+responsibility to free model when finished with via a call to- XML_FreeContentModel. - There is no need to free the model from the handler, it can be kept - around and freed at a later stage.-Date: Sun, 7 Sep 2025 16:00:35 +0200 -Subject: [PATCH] Changes: Document allocation tracking - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/a21a3a8299e1ee0b0ae5ae2886a0746d088cf135] -Signed-off-by: Peter Marko ---- - Changes | 37 +++++++++++++++++++++++++++++++++++++ - 1 file changed, 37 insertions(+) - -diff --git a/Changes b/Changes -index cb752151..ceb5c5dc 100644 ---- a/Changes -+++ b/Changes -@@ -30,6 +30,36 @@ - !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! - - Patches: -+ Security fixes: -+ #1018 #1034 CVE-2025-59375 -- Disallow use of disproportional amounts of -+ dynamic memory from within an Expat parser (e.g. previously -+ a ~250 KiB sized document was able to cause allocation of -+ ~800 MiB from the heap, i.e. an "amplification" of factor -+ ~3,300); once a threshold (that defaults to 64 MiB) is -+ reached, a maximum amplification factor (that defaults to -+ 100.0) is enforced, and violating documents are rejected -+ with an out-of-memory error. -+ There are two new API functions to fine-tune this new -+ behavior: -+ - XML_SetAllocTrackerActivationThreshold -+ - XML_SetAllocTrackerMaximumAmplification . -+ If you ever need to increase these defaults for non-attack -+ XML payload, please file a bug report with libexpat. -+ There is also a new environment variable -+ EXPAT_MALLOC_DEBUG=(0|1|2) to control the verbosity -+ of allocations debugging at runtime, disabled by default. -+ Known impact is (reliable and easy) denial of service: -+ CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C -+ (Base Score: 7.5, Temporal Score: 7.2) -+ Please note that a layer of compression around XML can -+ significantly reduce the minimum attack payload size. -+ Distributors intending to backport (or cherry-pick) the -+ fix need to copy 99% of the related pull request, not just -+ the "lib: Implement tracking of dynamic memory allocations" -+ commit, to not end up with a state that literally does both -+ too much and too little at the same time. Appending ".diff" -+ to the pull request URL could be of help. -+ - Bug fixes: - #980 #989 Restore event pointer behavior from Expat 2.6.4 - (that the fix to CVE-2024-8176 changed in 2.7.0); -@@ -39,6 +69,10 @@ Patches: - - XML_GetCurrentColumnNumber - - XML_GetCurrentLineNumber - - XML_GetInputContext -+ #1034 docs: Promote the contract to call function -+ XML_FreeContentModel when registering a custom -+ element declaration handler (via a call to function -+ XML_SetElementDeclHandler) - - Special thanks to: - Berkay Eren Ürün -@@ -71,6 +105,9 @@ Patches: - Linutronix - Red Hat - Siemens -+ and -+ OSS-Fuzz / ClusterFuzz -+ Perl XML::Parser - - Release 2.6.4 Wed November 6 2024 - Security fixes: diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-19.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-19.patch deleted file mode 100644 index afd4d91d03d..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-19.patch +++ /dev/null @@ -1,103 +0,0 @@ -From f4b5bb033dc4430bbd31dcae8a55f988360bcec5 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Wed, 17 Sep 2025 23:14:02 +0200 -Subject: [PATCH] lib: Document and regression-proof absence of integer - overflow from expat_realloc - -Matthew Fernandez (@Smattr) and I teamed up on whether function expat_realloc -could be vulnerable to integer overflow in line: - - mallocedPtr = parser->m_mem.realloc_fcn(mallocedPtr, sizeof(size_t) + size); - ^ -We ended up with a mathematical proof that, fortunately, the current code -already is safe from overflow. - -The proof uses technique "proof by contradiction". Let's assume, there *was* a -risk of integer overflow. For a risk of overflow, these four conditions would -all need to be met, together: - -(1) `SIZE_MAX < sizeof(size_t) + size` - or we would not hit an overflow on `size_t`. - -(2) `size > prevSize` - or `expat_malloc` would have already not allocated earlier - as `expat_realloc` relies on `expat_malloc` for the initial allocation. - -(3) `rootParser->m_alloc_tracker.bytesAllocated >= sizeof(size_t) + prevSize` - or the previous allocation would be gone already or have bypassed accounting. - The code is not thread-safe in general, race conditions are off the table. - -(4) `rootParser->m_alloc_tracker.bytesAllocated + (size - prevSize) <= SIZE_MAX` - or `expat_heap_increase_tolerable` would have returned `false` and - the overflow line would not be reached. - -We encoded this for the Z3 Theorem Prover (https://github.com/Z3Prover/z3) -and ended up with this document: - - $ cat proof_v2.smt2 - ; Copyright (c) 2025 Matthew Fernandez - ; Copyright (c) 2025 Sebastian Pipping - ; Licensed under the MIT license - - ; (1), (2), (3), (4) form a contradiction - - ; define `SIZE_MAX` - (declare-fun SIZE_MAX () (_ BitVec 64)) - (assert (= SIZE_MAX #xffffffffffffffff)) - - ; define `sizeof(size_t)` - (declare-fun sizeof_size_t () (_ BitVec 64)) - (assert (= sizeof_size_t #x0000000000000008)) - - ; claim we have inputs `size`, `prevSize`, and `bytesAllocated` - (declare-fun size () (_ BitVec 64)) - (declare-fun prevSize () (_ BitVec 64)) - (declare-fun bytesAllocated () (_ BitVec 64)) - - ; assume `SIZE_MAX - sizeof(size_t) < size` (1) - (assert (bvult (bvsub SIZE_MAX sizeof_size_t) size)) - - ; assume `bytesAllocated >= sizeof(size_t) + prevSize` (3) - (assert (bvuge bytesAllocated (bvadd sizeof_size_t prevSize))) - - ; assume `bytesAllocated - prevSize <= SIZE_MAX - size` (4) - (assert (bvule (bvsub bytesAllocated prevSize) (bvsub SIZE_MAX size))) - - ; assume `SIZE_MAX - sizeof(size_t) >= prevSize` (anti-overflow for 3) - (assert (bvuge (bvsub SIZE_MAX sizeof_size_t) prevSize)) - - ; prove we have a contradiction - (check-sat) - -Note that we operate on fixed-size bit vectors here, and hence had -to transform the assertions to not allow integer overflow by themselves. - -Z3 confirms the contradiction, and thus the absence of integer overflow: - - $ z3 -smt2 -model proof_v2.smt2 - unsat - -Co-authored-by: Matthew Fernandez - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/f4b5bb033dc4430bbd31dcae8a55f988360bcec5] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index de159493..24fd7b97 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -969,6 +969,10 @@ expat_realloc(XML_Parser parser, void *ptr, size_t size, int sourceLine) { - } - } - -+ // NOTE: Integer overflow detection has already been done for us -+ // by expat_heap_increase_tolerable(..) above -+ assert(SIZE_MAX - sizeof(size_t) >= size); -+ - // Actually allocate - mallocedPtr = parser->m_mem.realloc_fcn(mallocedPtr, sizeof(size_t) + size); - diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-20.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-20.patch deleted file mode 100644 index 80628f20fb9..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-20.patch +++ /dev/null @@ -1,285 +0,0 @@ -From faf36f806c9065bfd9f0567b01924d5e27c4911c Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Mon, 15 Sep 2025 18:05:23 +0200 -Subject: [PATCH] lib: Drop casts around malloc/realloc returns that C99 does - not need - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/faf36f806c9065bfd9f0567b01924d5e27c4911c] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 80 ++++++++++++++++++++++---------------------------- - 1 file changed, 35 insertions(+), 45 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 6e9c6fb2..fb8ad2e7 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -1370,12 +1370,12 @@ parserCreate(const XML_Char *encodingName, - XML_Memory_Handling_Suite *mtemp; - #if XML_GE == 1 - void *const sizeAndParser -- = (XML_Parser)malloc(sizeof(size_t) + sizeof(struct XML_ParserStruct)); -+ = malloc(sizeof(size_t) + sizeof(struct XML_ParserStruct)); - if (sizeAndParser != NULL) { - *(size_t *)sizeAndParser = sizeof(struct XML_ParserStruct); - parser = (XML_Parser)((char *)sizeAndParser + sizeof(size_t)); - #else -- parser = (XML_Parser)malloc(sizeof(struct XML_ParserStruct)); -+ parser = malloc(sizeof(struct XML_ParserStruct)); - if (parser != NULL) { - #endif - mtemp = (XML_Memory_Handling_Suite *)&(parser->m_mem); -@@ -1433,23 +1433,20 @@ parserCreate(const XML_Char *encodingName, - parser->m_bufferLim = NULL; - - parser->m_attsSize = INIT_ATTS_SIZE; -- parser->m_atts -- = (ATTRIBUTE *)MALLOC(parser, parser->m_attsSize * sizeof(ATTRIBUTE)); -+ parser->m_atts = MALLOC(parser, parser->m_attsSize * sizeof(ATTRIBUTE)); - if (parser->m_atts == NULL) { - FREE(parser, parser); - return NULL; - } - #ifdef XML_ATTR_INFO -- parser->m_attInfo = (XML_AttrInfo *)MALLOC( -- parser, parser->m_attsSize * sizeof(XML_AttrInfo)); -+ parser->m_attInfo = MALLOC(parser, parser->m_attsSize * sizeof(XML_AttrInfo)); - if (parser->m_attInfo == NULL) { - FREE(parser, parser->m_atts); - FREE(parser, parser); - return NULL; - } - #endif -- parser->m_dataBuf -- = (XML_Char *)MALLOC(parser, INIT_DATA_BUF_SIZE * sizeof(XML_Char)); -+ parser->m_dataBuf = MALLOC(parser, INIT_DATA_BUF_SIZE * sizeof(XML_Char)); - if (parser->m_dataBuf == NULL) { - FREE(parser, parser->m_atts); - #ifdef XML_ATTR_INFO -@@ -2588,7 +2585,7 @@ XML_GetBuffer(XML_Parser parser, int len) { - } - // NOTE: We are avoiding MALLOC(..) here to leave limiting - // the input size to the application using Expat. -- newBuf = (char *)parser->m_mem.malloc_fcn(bufferSize); -+ newBuf = parser->m_mem.malloc_fcn(bufferSize); - if (newBuf == 0) { - parser->m_errorCode = XML_ERROR_NO_MEMORY; - return NULL; -@@ -3133,7 +3130,7 @@ storeRawNames(XML_Parser parser) { - return XML_FALSE; - bufSize = nameLen + (int)rawNameLen; - if (bufSize > tag->bufEnd - tag->buf) { -- char *temp = (char *)REALLOC(parser, tag->buf, bufSize); -+ char *temp = REALLOC(parser, tag->buf, bufSize); - if (temp == NULL) - return XML_FALSE; - /* if tag->name.str points to tag->buf (only when namespace -@@ -3459,10 +3456,10 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - tag = parser->m_freeTagList; - parser->m_freeTagList = parser->m_freeTagList->parent; - } else { -- tag = (TAG *)MALLOC(parser, sizeof(TAG)); -+ tag = MALLOC(parser, sizeof(TAG)); - if (! tag) - return XML_ERROR_NO_MEMORY; -- tag->buf = (char *)MALLOC(parser, INIT_TAG_BUF_SIZE); -+ tag->buf = MALLOC(parser, INIT_TAG_BUF_SIZE); - if (! tag->buf) { - FREE(parser, tag); - return XML_ERROR_NO_MEMORY; -@@ -3495,7 +3492,7 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - } - bufSize = (int)(tag->bufEnd - tag->buf) << 1; - { -- char *temp = (char *)REALLOC(parser, tag->buf, bufSize); -+ char *temp = REALLOC(parser, tag->buf, bufSize); - if (temp == NULL) - return XML_ERROR_NO_MEMORY; - tag->buf = temp; -@@ -3874,8 +3871,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - #endif - -- temp = (ATTRIBUTE *)REALLOC(parser, (void *)parser->m_atts, -- parser->m_attsSize * sizeof(ATTRIBUTE)); -+ temp = REALLOC(parser, (void *)parser->m_atts, -+ parser->m_attsSize * sizeof(ATTRIBUTE)); - if (temp == NULL) { - parser->m_attsSize = oldAttsSize; - return XML_ERROR_NO_MEMORY; -@@ -3893,8 +3890,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - # endif - -- temp2 = (XML_AttrInfo *)REALLOC(parser, (void *)parser->m_attInfo, -- parser->m_attsSize * sizeof(XML_AttrInfo)); -+ temp2 = REALLOC(parser, (void *)parser->m_attInfo, -+ parser->m_attsSize * sizeof(XML_AttrInfo)); - if (temp2 == NULL) { - parser->m_attsSize = oldAttsSize; - return XML_ERROR_NO_MEMORY; -@@ -4070,8 +4067,7 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - #endif - -- temp = (NS_ATT *)REALLOC(parser, parser->m_nsAtts, -- nsAttsSize * sizeof(NS_ATT)); -+ temp = REALLOC(parser, parser->m_nsAtts, nsAttsSize * sizeof(NS_ATT)); - if (! temp) { - /* Restore actual size of memory in m_nsAtts */ - parser->m_nsAttsPower = oldNsAttsPower; -@@ -4252,7 +4248,7 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - #endif - -- uri = (XML_Char *)MALLOC(parser, (n + EXPAND_SPARE) * sizeof(XML_Char)); -+ uri = MALLOC(parser, (n + EXPAND_SPARE) * sizeof(XML_Char)); - if (! uri) - return XML_ERROR_NO_MEMORY; - binding->uriAlloc = n + EXPAND_SPARE; -@@ -4498,8 +4494,8 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - } - #endif - -- XML_Char *temp = (XML_Char *)REALLOC( -- parser, b->uri, sizeof(XML_Char) * (len + EXPAND_SPARE)); -+ XML_Char *temp -+ = REALLOC(parser, b->uri, sizeof(XML_Char) * (len + EXPAND_SPARE)); - if (temp == NULL) - return XML_ERROR_NO_MEMORY; - b->uri = temp; -@@ -4507,7 +4503,7 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - } - parser->m_freeBindingList = b->nextTagBinding; - } else { -- b = (BINDING *)MALLOC(parser, sizeof(BINDING)); -+ b = MALLOC(parser, sizeof(BINDING)); - if (! b) - return XML_ERROR_NO_MEMORY; - -@@ -4525,8 +4521,7 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - } - #endif - -- b->uri -- = (XML_Char *)MALLOC(parser, sizeof(XML_Char) * (len + EXPAND_SPARE)); -+ b->uri = MALLOC(parser, sizeof(XML_Char) * (len + EXPAND_SPARE)); - if (! b->uri) { - FREE(parser, b); - return XML_ERROR_NO_MEMORY; -@@ -5897,7 +5892,7 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - return XML_ERROR_NO_MEMORY; - } - -- char *const new_connector = (char *)REALLOC( -+ char *const new_connector = REALLOC( - parser, parser->m_groupConnector, parser->m_groupSize *= 2); - if (new_connector == NULL) { - parser->m_groupSize /= 2; -@@ -5917,15 +5912,14 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - } - #endif - -- int *const new_scaff_index = (int *)REALLOC( -+ int *const new_scaff_index = REALLOC( - parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); - if (new_scaff_index == NULL) - return XML_ERROR_NO_MEMORY; - dtd->scaffIndex = new_scaff_index; - } - } else { -- parser->m_groupConnector -- = (char *)MALLOC(parser, parser->m_groupSize = 32); -+ parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); - if (! parser->m_groupConnector) { - parser->m_groupSize = 0; - return XML_ERROR_NO_MEMORY; -@@ -6086,8 +6080,7 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - // applications that are not using XML_FreeContentModel but - // plain free(..) or .free_fcn() to free the content model's - // memory are safe. -- XML_Content *content -- = (XML_Content *)parser->m_mem.malloc_fcn(sizeof(XML_Content)); -+ XML_Content *content = parser->m_mem.malloc_fcn(sizeof(XML_Content)); - if (! content) - return XML_ERROR_NO_MEMORY; - content->quant = XML_CQUANT_NONE; -@@ -6364,8 +6357,7 @@ processEntity(XML_Parser parser, ENTITY *entity, XML_Bool betweenDecl, - openEntity = *freeEntityList; - *freeEntityList = openEntity->next; - } else { -- openEntity -- = (OPEN_INTERNAL_ENTITY *)MALLOC(parser, sizeof(OPEN_INTERNAL_ENTITY)); -+ openEntity = MALLOC(parser, sizeof(OPEN_INTERNAL_ENTITY)); - if (! openEntity) - return XML_ERROR_NO_MEMORY; - } -@@ -7164,8 +7156,8 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - if (type->nDefaultAtts == type->allocDefaultAtts) { - if (type->allocDefaultAtts == 0) { - type->allocDefaultAtts = 8; -- type->defaultAtts = (DEFAULT_ATTRIBUTE *)MALLOC( -- parser, type->allocDefaultAtts * sizeof(DEFAULT_ATTRIBUTE)); -+ type->defaultAtts -+ = MALLOC(parser, type->allocDefaultAtts * sizeof(DEFAULT_ATTRIBUTE)); - if (! type->defaultAtts) { - type->allocDefaultAtts = 0; - return 0; -@@ -7190,8 +7182,8 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - } - #endif - -- temp = (DEFAULT_ATTRIBUTE *)REALLOC(parser, type->defaultAtts, -- (count * sizeof(DEFAULT_ATTRIBUTE))); -+ temp = REALLOC(parser, type->defaultAtts, -+ (count * sizeof(DEFAULT_ATTRIBUTE))); - if (temp == NULL) - return 0; - type->allocDefaultAtts = count; -@@ -8145,8 +8137,7 @@ poolGrow(STRING_POOL *pool) { - if (bytesToAllocate == 0) - return XML_FALSE; - -- temp = (BLOCK *)REALLOC(pool->parser, pool->blocks, -- (unsigned)bytesToAllocate); -+ temp = REALLOC(pool->parser, pool->blocks, (unsigned)bytesToAllocate); - if (temp == NULL) - return XML_FALSE; - pool->blocks = temp; -@@ -8217,7 +8208,7 @@ nextScaffoldPart(XML_Parser parser) { - return -1; - } - #endif -- dtd->scaffIndex = (int *)MALLOC(parser, parser->m_groupSize * sizeof(int)); -+ dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int)); - if (! dtd->scaffIndex) - return -1; - dtd->scaffIndex[0] = 0; -@@ -8240,14 +8231,13 @@ nextScaffoldPart(XML_Parser parser) { - } - #endif - -- temp = (CONTENT_SCAFFOLD *)REALLOC( -- parser, dtd->scaffold, dtd->scaffSize * 2 * sizeof(CONTENT_SCAFFOLD)); -+ temp = REALLOC(parser, dtd->scaffold, -+ dtd->scaffSize * 2 * sizeof(CONTENT_SCAFFOLD)); - if (temp == NULL) - return -1; - dtd->scaffSize *= 2; - } else { -- temp = (CONTENT_SCAFFOLD *)MALLOC(parser, INIT_SCAFFOLD_ELEMENTS -- * sizeof(CONTENT_SCAFFOLD)); -+ temp = MALLOC(parser, INIT_SCAFFOLD_ELEMENTS * sizeof(CONTENT_SCAFFOLD)); - if (temp == NULL) - return -1; - dtd->scaffSize = INIT_SCAFFOLD_ELEMENTS; -@@ -8304,7 +8294,7 @@ build_model(XML_Parser parser) { - // NOTE: We are avoiding MALLOC(..) here to so that - // applications that are not using XML_FreeContentModel but plain - // free(..) or .free_fcn() to free the content model's memory are safe. -- ret = (XML_Content *)parser->m_mem.malloc_fcn(allocsize); -+ ret = parser->m_mem.malloc_fcn(allocsize); - if (! ret) - return NULL; - diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-21.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-21.patch deleted file mode 100644 index 38bc0d1dd8b..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-21.patch +++ /dev/null @@ -1,196 +0,0 @@ -From 4b43b8dacc96fd538254e17a69abc9745c3a2ed4 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 19 Sep 2025 23:32:46 +0200 -Subject: [PATCH] lib: Fix alignment of internal allocations for some non-amd64 - architectures - -sparc32 is known to be affected. - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/4b43b8dacc96fd538254e17a69abc9745c3a2ed4] -Signed-off-by: Peter Marko ---- - lib/internal.h | 6 ++++++ - lib/xmlparse.c | 38 ++++++++++++++++++++++---------------- - tests/alloc_tests.c | 13 ++++++++++--- - 3 files changed, 38 insertions(+), 19 deletions(-) - -diff --git a/lib/internal.h b/lib/internal.h -index 6e087858..8f5edf48 100644 ---- a/lib/internal.h -+++ b/lib/internal.h -@@ -108,6 +108,7 @@ - #endif - - #include // ULONG_MAX -+#include // size_t - - #if defined(_WIN32) \ - && (! defined(__USE_MINGW_ANSI_STDIO) \ -@@ -150,6 +151,11 @@ - #define EXPAT_ALLOC_TRACKER_ACTIVATION_THRESHOLD_DEFAULT \ - 67108864 // 64 MiB, 2^26 - -+// NOTE: If function expat_alloc was user facing, EXPAT_MALLOC_ALIGNMENT would -+// have to take sizeof(long double) into account -+#define EXPAT_MALLOC_ALIGNMENT sizeof(long long) // largest parser (sub)member -+#define EXPAT_MALLOC_PADDING ((EXPAT_MALLOC_ALIGNMENT) - sizeof(size_t)) -+ - /* NOTE END */ - - #include "expat.h" // so we can use type XML_Parser below -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 24fd7b97..ce29ab6f 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -850,14 +850,14 @@ static void * - # endif - expat_malloc(XML_Parser parser, size_t size, int sourceLine) { - // Detect integer overflow -- if (SIZE_MAX - size < sizeof(size_t)) { -+ if (SIZE_MAX - size < sizeof(size_t) + EXPAT_MALLOC_PADDING) { - return NULL; - } - - const XML_Parser rootParser = getRootParserOf(parser, NULL); - assert(rootParser->m_parentParser == NULL); - -- const size_t bytesToAllocate = sizeof(size_t) + size; -+ const size_t bytesToAllocate = sizeof(size_t) + EXPAT_MALLOC_PADDING + size; - - if ((XmlBigCount)-1 - rootParser->m_alloc_tracker.bytesAllocated - < bytesToAllocate) { -@@ -894,7 +894,7 @@ expat_malloc(XML_Parser parser, size_t size, int sourceLine) { - rootParser->m_alloc_tracker.peakBytesAllocated, sourceLine); - } - -- return (char *)mallocedPtr + sizeof(size_t); -+ return (char *)mallocedPtr + sizeof(size_t) + EXPAT_MALLOC_PADDING; - } - - # if defined(XML_TESTING) -@@ -914,8 +914,9 @@ expat_free(XML_Parser parser, void *ptr, int sourceLine) { - - // Extract size (to the eyes of malloc_fcn/realloc_fcn) and - // the original pointer returned by malloc/realloc -- void *const mallocedPtr = (char *)ptr - sizeof(size_t); -- const size_t bytesAllocated = sizeof(size_t) + *(size_t *)mallocedPtr; -+ void *const mallocedPtr = (char *)ptr - EXPAT_MALLOC_PADDING - sizeof(size_t); -+ const size_t bytesAllocated -+ = sizeof(size_t) + EXPAT_MALLOC_PADDING + *(size_t *)mallocedPtr; - - // Update accounting - assert(rootParser->m_alloc_tracker.bytesAllocated >= bytesAllocated); -@@ -954,7 +955,7 @@ expat_realloc(XML_Parser parser, void *ptr, size_t size, int sourceLine) { - - // Extract original size (to the eyes of the caller) and the original - // pointer returned by malloc/realloc -- void *mallocedPtr = (char *)ptr - sizeof(size_t); -+ void *mallocedPtr = (char *)ptr - EXPAT_MALLOC_PADDING - sizeof(size_t); - const size_t prevSize = *(size_t *)mallocedPtr; - - // Classify upcoming change -@@ -971,10 +972,11 @@ expat_realloc(XML_Parser parser, void *ptr, size_t size, int sourceLine) { - - // NOTE: Integer overflow detection has already been done for us - // by expat_heap_increase_tolerable(..) above -- assert(SIZE_MAX - sizeof(size_t) >= size); -+ assert(SIZE_MAX - sizeof(size_t) - EXPAT_MALLOC_PADDING >= size); - - // Actually allocate -- mallocedPtr = parser->m_mem.realloc_fcn(mallocedPtr, sizeof(size_t) + size); -+ mallocedPtr = parser->m_mem.realloc_fcn( -+ mallocedPtr, sizeof(size_t) + EXPAT_MALLOC_PADDING + size); - - if (mallocedPtr == NULL) { - return NULL; -@@ -1005,7 +1007,7 @@ expat_realloc(XML_Parser parser, void *ptr, size_t size, int sourceLine) { - // Update in-block recorded size - *(size_t *)mallocedPtr = size; - -- return (char *)mallocedPtr + sizeof(size_t); -+ return (char *)mallocedPtr + sizeof(size_t) + EXPAT_MALLOC_PADDING; - } - #endif // XML_GE == 1 - -@@ -1337,7 +1339,8 @@ parserCreate(const XML_Char *encodingName, - XML_Parser parser = NULL; - - #if XML_GE == 1 -- const size_t increase = sizeof(size_t) + sizeof(struct XML_ParserStruct); -+ const size_t increase -+ = sizeof(size_t) + EXPAT_MALLOC_PADDING + sizeof(struct XML_ParserStruct); - - if (parentParser != NULL) { - const XML_Parser rootParser = getRootParserOf(parentParser, NULL); -@@ -1352,11 +1355,13 @@ parserCreate(const XML_Char *encodingName, - if (memsuite) { - XML_Memory_Handling_Suite *mtemp; - #if XML_GE == 1 -- void *const sizeAndParser = memsuite->malloc_fcn( -- sizeof(size_t) + sizeof(struct XML_ParserStruct)); -+ void *const sizeAndParser -+ = memsuite->malloc_fcn(sizeof(size_t) + EXPAT_MALLOC_PADDING -+ + sizeof(struct XML_ParserStruct)); - if (sizeAndParser != NULL) { - *(size_t *)sizeAndParser = sizeof(struct XML_ParserStruct); -- parser = (XML_Parser)((char *)sizeAndParser + sizeof(size_t)); -+ parser = (XML_Parser)((char *)sizeAndParser + sizeof(size_t) -+ + EXPAT_MALLOC_PADDING); - #else - parser = memsuite->malloc_fcn(sizeof(struct XML_ParserStruct)); - if (parser != NULL) { -@@ -1369,11 +1374,12 @@ parserCreate(const XML_Char *encodingName, - } else { - XML_Memory_Handling_Suite *mtemp; - #if XML_GE == 1 -- void *const sizeAndParser -- = malloc(sizeof(size_t) + sizeof(struct XML_ParserStruct)); -+ void *const sizeAndParser = malloc(sizeof(size_t) + EXPAT_MALLOC_PADDING -+ + sizeof(struct XML_ParserStruct)); - if (sizeAndParser != NULL) { - *(size_t *)sizeAndParser = sizeof(struct XML_ParserStruct); -- parser = (XML_Parser)((char *)sizeAndParser + sizeof(size_t)); -+ parser = (XML_Parser)((char *)sizeAndParser + sizeof(size_t) -+ + EXPAT_MALLOC_PADDING); - #else - parser = malloc(sizeof(struct XML_ParserStruct)); - if (parser != NULL) { -diff --git a/tests/alloc_tests.c b/tests/alloc_tests.c -index 644a4952..dabdf0da 100644 ---- a/tests/alloc_tests.c -+++ b/tests/alloc_tests.c -@@ -2091,6 +2091,13 @@ START_TEST(test_alloc_reset_after_external_entity_parser_create_fail) { - } - END_TEST - -+#if XML_GE == 1 -+static size_t -+sizeRecordedFor(void *ptr) { -+ return *(size_t *)((char *)ptr - EXPAT_MALLOC_PADDING - sizeof(size_t)); -+} -+#endif // XML_GE == 1 -+ - START_TEST(test_alloc_tracker_size_recorded) { - XML_Memory_Handling_Suite memsuite = {malloc, realloc, free}; - -@@ -2106,16 +2113,16 @@ START_TEST(test_alloc_tracker_size_recorded) { - void *ptr = expat_malloc(parser, 10, -1); - - assert_true(ptr != NULL); -- assert_true(*((size_t *)ptr - 1) == 10); -+ assert_true(sizeRecordedFor(ptr) == 10); - - assert_true(expat_realloc(parser, ptr, SIZE_MAX / 2, -1) == NULL); - -- assert_true(*((size_t *)ptr - 1) == 10); // i.e. unchanged -+ assert_true(sizeRecordedFor(ptr) == 10); // i.e. unchanged - - ptr = expat_realloc(parser, ptr, 20, -1); - - assert_true(ptr != NULL); -- assert_true(*((size_t *)ptr - 1) == 20); -+ assert_true(sizeRecordedFor(ptr) == 20); - - expat_free(parser, ptr, -1); - #endif diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-22.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-22.patch deleted file mode 100644 index 9716be80841..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-22.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 5cc0010ad93868ec03248e4ac814272bc7d607bc Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 19 Sep 2025 22:50:54 +0200 -Subject: [PATCH] tests: Fix test guard for test related to allocation tracking - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/5cc0010ad93868ec03248e4ac814272bc7d607bc] -Signed-off-by: Peter Marko ---- - tests/alloc_tests.c | 14 ++++++-------- - 1 file changed, 6 insertions(+), 8 deletions(-) - -diff --git a/tests/alloc_tests.c b/tests/alloc_tests.c -index dabdf0da..045447b0 100644 ---- a/tests/alloc_tests.c -+++ b/tests/alloc_tests.c -@@ -2362,14 +2362,12 @@ make_alloc_test_case(Suite *s) { - tcase_add_test__ifdef_xml_dtd( - tc_alloc, test_alloc_reset_after_external_entity_parser_create_fail); - -- tcase_add_test__ifdef_xml_dtd(tc_alloc, test_alloc_tracker_size_recorded); -- tcase_add_test__ifdef_xml_dtd(tc_alloc, -- test_alloc_tracker_maximum_amplification); -- tcase_add_test__ifdef_xml_dtd(tc_alloc, test_alloc_tracker_threshold); -- tcase_add_test__ifdef_xml_dtd(tc_alloc, -- test_alloc_tracker_getbuffer_unlimited); -- tcase_add_test__ifdef_xml_dtd(tc_alloc, test_alloc_tracker_api); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_size_recorded); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_maximum_amplification); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_threshold); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_getbuffer_unlimited); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_api); - - tcase_add_test(tc_alloc, test_mem_api_cycle); -- tcase_add_test__ifdef_xml_dtd(tc_alloc, test_mem_api_unlimited); -+ tcase_add_test__if_xml_ge(tc_alloc, test_mem_api_unlimited); - } diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-23.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-23.patch deleted file mode 100644 index 60327df22b7..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-23.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 343594dc344e543acb7478d1283b50b299a1c110 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 19 Sep 2025 22:46:01 +0200 -Subject: [PATCH] tests: Add new test test_alloc_tracker_pointer_alignment - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/343594dc344e543acb7478d1283b50b299a1c110] -Signed-off-by: Peter Marko ---- - tests/alloc_tests.c | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/tests/alloc_tests.c b/tests/alloc_tests.c -index 045447b0..5ae6c6a7 100644 ---- a/tests/alloc_tests.c -+++ b/tests/alloc_tests.c -@@ -2132,6 +2132,22 @@ START_TEST(test_alloc_tracker_size_recorded) { - } - END_TEST - -+START_TEST(test_alloc_tracker_pointer_alignment) { -+ XML_Parser parser = XML_ParserCreate(NULL); -+#if XML_GE == 1 -+ assert_true(sizeof(long long) >= sizeof(size_t)); // self-test -+ long long *const ptr -+ = (long long *)expat_malloc(parser, 4 * sizeof(long long), -1); -+ ptr[0] = 0LL; -+ ptr[1] = 1LL; -+ ptr[2] = 2LL; -+ ptr[3] = 3LL; -+ expat_free(parser, ptr, -1); -+#endif -+ XML_ParserFree(parser); -+} -+END_TEST -+ - START_TEST(test_alloc_tracker_maximum_amplification) { - if (g_reparseDeferralEnabledDefault == XML_TRUE) { - return; -@@ -2363,6 +2379,7 @@ make_alloc_test_case(Suite *s) { - tc_alloc, test_alloc_reset_after_external_entity_parser_create_fail); - - tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_size_recorded); -+ tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_pointer_alignment); - tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_maximum_amplification); - tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_threshold); - tcase_add_test__if_xml_ge(tc_alloc, test_alloc_tracker_getbuffer_unlimited); diff --git a/meta/recipes-core/expat/expat/CVE-2025-59375-24.patch b/meta/recipes-core/expat/expat/CVE-2025-59375-24.patch deleted file mode 100644 index e51b2bb3277..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2025-59375-24.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 6fe5df59a1229ca647d365a0e3a7e17fee4d4548 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 19 Sep 2025 23:49:18 +0200 -Subject: [PATCH] Changes: Document pull request #1047 - -CVE: CVE-2025-59375 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/6fe5df59a1229ca647d365a0e3a7e17fee4d4548] -Signed-off-by: Peter Marko ---- - Changes | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/Changes b/Changes -index 706a4ae1..58c222d9 100644 ---- a/Changes -+++ b/Changes -@@ -61,6 +61,9 @@ Patches: - to the pull request URL could be of help. - - Bug fixes: -+ #1046 #1047 Fix alignment of internal allocations for some non-amd64 -+ architectures (e.g. sparc32); fixes up on the fix to -+ CVE-2025-59375 in release 2.7.2 from #1034 - #980 #989 Restore event pointer behavior from Expat 2.6.4 - (that the fix to CVE-2024-8176 changed in 2.7.0); - affected API functions are: -@@ -76,7 +79,9 @@ Patches: - - Special thanks to: - Berkay Eren Ürün -+ Rolf Eike Beer - and -+ Clang/GCC UndefinedBehaviorSanitizer - Perl XML::Parser - - Security fixes: diff --git a/meta/recipes-core/expat/expat/CVE-2026-24515-01.patch b/meta/recipes-core/expat/expat/CVE-2026-24515-01.patch deleted file mode 100644 index 0250374c76b..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-24515-01.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 86fc914a7acc49246d5fde0ab6ed97eb8a0f15f9 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 18 Jan 2026 17:53:37 +0100 -Subject: [PATCH] lib: Make XML_ExternalEntityParserCreate copy unknown - encoding handler user data - -Patch suggested by Artiphishell Inc. - -CVE: CVE-2026-24515 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/86fc914a7acc49246d5fde0ab6ed97eb8a0f15f9] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 593cd90d..18577ee3 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -1749,6 +1749,7 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - XML_ExternalEntityRefHandler oldExternalEntityRefHandler; - XML_SkippedEntityHandler oldSkippedEntityHandler; - XML_UnknownEncodingHandler oldUnknownEncodingHandler; -+ void *oldUnknownEncodingHandlerData; - XML_ElementDeclHandler oldElementDeclHandler; - XML_AttlistDeclHandler oldAttlistDeclHandler; - XML_EntityDeclHandler oldEntityDeclHandler; -@@ -1794,6 +1795,7 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - oldExternalEntityRefHandler = parser->m_externalEntityRefHandler; - oldSkippedEntityHandler = parser->m_skippedEntityHandler; - oldUnknownEncodingHandler = parser->m_unknownEncodingHandler; -+ oldUnknownEncodingHandlerData = parser->m_unknownEncodingHandlerData; - oldElementDeclHandler = parser->m_elementDeclHandler; - oldAttlistDeclHandler = parser->m_attlistDeclHandler; - oldEntityDeclHandler = parser->m_entityDeclHandler; -@@ -1854,6 +1856,7 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - parser->m_externalEntityRefHandler = oldExternalEntityRefHandler; - parser->m_skippedEntityHandler = oldSkippedEntityHandler; - parser->m_unknownEncodingHandler = oldUnknownEncodingHandler; -+ parser->m_unknownEncodingHandlerData = oldUnknownEncodingHandlerData; - parser->m_elementDeclHandler = oldElementDeclHandler; - parser->m_attlistDeclHandler = oldAttlistDeclHandler; - parser->m_entityDeclHandler = oldEntityDeclHandler; diff --git a/meta/recipes-core/expat/expat/CVE-2026-24515-02.patch b/meta/recipes-core/expat/expat/CVE-2026-24515-02.patch deleted file mode 100644 index 7d6758fe095..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-24515-02.patch +++ /dev/null @@ -1,117 +0,0 @@ -From 8efea3e255d55c7e0a5b70b226f4652ab00e1a27 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 18 Jan 2026 17:26:31 +0100 -Subject: [PATCH] tests: Cover effect of XML_SetUnknownEncodingHandler user - data - -CVE: CVE-2026-24515 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/8efea3e255d55c7e0a5b70b226f4652ab00e1a27] -Signed-off-by: Peter Marko ---- - tests/basic_tests.c | 42 +++++++++++++++++++++++++++++++++++++++ - tests/handlers.c | 10 ++++++++++ - tests/handlers.h | 3 +++ - 3 files changed, 55 insertions(+) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 0231e094..0ed98d86 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -4527,6 +4527,46 @@ START_TEST(test_unknown_encoding_invalid_attr_value) { - } - END_TEST - -+START_TEST(test_unknown_encoding_user_data_primary) { -+ // This test is based on ideas contributed by Artiphishell Inc. -+ const char *const text = "\n" -+ " \n"; -+ XML_Parser parser = XML_ParserCreate(NULL); -+ XML_SetUnknownEncodingHandler(parser, -+ user_data_checking_unknown_encoding_handler, -+ (void *)(intptr_t)0xC0FFEE); -+ -+ assert_true(_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ == XML_STATUS_OK); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_unknown_encoding_user_data_secondary) { -+ // This test is based on ideas contributed by Artiphishell Inc. -+ const char *const text_main = "\n" -+ "]>\n" -+ " &ext; \n"; -+ const char *const text_external = "\n" -+ "data "; -+ ExtTest2 test_data = {text_external, (int)strlen(text_external), NULL, NULL}; -+ XML_Parser parser = XML_ParserCreate(NULL); -+ XML_SetExternalEntityRefHandler(parser, external_entity_loader2); -+ XML_SetUnknownEncodingHandler(parser, -+ user_data_checking_unknown_encoding_handler, -+ (void *)(intptr_t)0xC0FFEE); -+ XML_SetUserData(parser, &test_data); -+ -+ assert_true(_XML_Parse_SINGLE_BYTES(parser, text_main, (int)strlen(text_main), -+ XML_TRUE) -+ == XML_STATUS_OK); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Test an external entity parser set to use latin-1 detects UTF-16 - * BOMs correctly. - */ -@@ -6372,6 +6412,8 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_unknown_encoding_invalid_surrogate); - tcase_add_test(tc_basic, test_unknown_encoding_invalid_high); - tcase_add_test(tc_basic, test_unknown_encoding_invalid_attr_value); -+ tcase_add_test(tc_basic, test_unknown_encoding_user_data_primary); -+ tcase_add_test(tc_basic, test_unknown_encoding_user_data_secondary); - tcase_add_test__if_xml_ge(tc_basic, test_ext_entity_latin1_utf16le_bom); - tcase_add_test__if_xml_ge(tc_basic, test_ext_entity_latin1_utf16be_bom); - tcase_add_test__if_xml_ge(tc_basic, test_ext_entity_latin1_utf16le_bom2); -diff --git a/tests/handlers.c b/tests/handlers.c -index 5bca2b1f..d077f688 100644 ---- a/tests/handlers.c -+++ b/tests/handlers.c -@@ -45,6 +45,7 @@ - # undef NDEBUG /* because test suite relies on assert(...) at the moment */ - #endif - -+#include- #include - #include - #include -@@ -407,6 +408,15 @@ long_encoding_handler(void *userData, const XML_Char *encoding, - return XML_STATUS_OK; - } - -+int XMLCALL -+user_data_checking_unknown_encoding_handler(void *userData, -+ const XML_Char *encoding, -+ XML_Encoding *info) { -+ const intptr_t number = (intptr_t)userData; -+ assert_true(number == 0xC0FFEE); -+ return long_encoding_handler(userData, encoding, info); -+} -+ - /* External Entity Handlers */ - - int XMLCALL -diff --git a/tests/handlers.h b/tests/handlers.h -index fa6267fb..915040e5 100644 ---- a/tests/handlers.h -+++ b/tests/handlers.h -@@ -159,6 +159,9 @@ extern int XMLCALL long_encoding_handler(void *userData, - const XML_Char *encoding, - XML_Encoding *info); - -+extern int XMLCALL user_data_checking_unknown_encoding_handler( -+ void *userData, const XML_Char *encoding, XML_Encoding *info); -+ - /* External Entity Handlers */ - - typedef struct ExtOption { diff --git a/meta/recipes-core/expat/expat/CVE-2026-25210-01.patch b/meta/recipes-core/expat/expat/CVE-2026-25210-01.patch deleted file mode 100644 index d56e8811915..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-25210-01.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 7ddea353ad3795f7222441274d4d9a155b523cba Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 2 Oct 2025 17:15:15 -0700 -Subject: [PATCH] lib: Make a doubling more readable - -Suggested-by: Sebastian Pipping - -CVE: CVE-2026-25210 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/7ddea353ad3795f7222441274d4d9a155b523cba] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 8cf29257..2f9adffc 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -3499,7 +3499,7 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - tag->name.strLen = convLen; - break; - } -- bufSize = (int)(tag->bufEnd - tag->buf) << 1; -+ bufSize = (int)(tag->bufEnd - tag->buf) * 2; - { - char *temp = REALLOC(parser, tag->buf, bufSize); - if (temp == NULL) diff --git a/meta/recipes-core/expat/expat/CVE-2026-25210-02.patch b/meta/recipes-core/expat/expat/CVE-2026-25210-02.patch deleted file mode 100644 index 21bd6e4fd0e..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-25210-02.patch +++ /dev/null @@ -1,38 +0,0 @@ -From 8855346359a475c022ec8c28484a76c852f144d9 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 2 Oct 2025 17:15:15 -0700 -Subject: [PATCH] lib: Realign a size with the `REALLOC` type signature it is - passed into - -Note that this implicitly assumes `tag->bufEnd >= tag->buf`, which should -already be guaranteed true. - -CVE: CVE-2026-25210 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/8855346359a475c022ec8c28484a76c852f144d9] -Signed-off-by: Peter Marko ---- ---- - lib/xmlparse.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 2f9adffc..ee18a87f 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -3488,7 +3488,6 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - const char *fromPtr = tag->rawName; - toPtr = (XML_Char *)tag->buf; - for (;;) { -- int bufSize; - int convLen; - const enum XML_Convert_Result convert_res - = XmlConvert(enc, &fromPtr, rawNameEnd, (ICHAR **)&toPtr, -@@ -3499,7 +3498,7 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - tag->name.strLen = convLen; - break; - } -- bufSize = (int)(tag->bufEnd - tag->buf) * 2; -+ const size_t bufSize = (size_t)(tag->bufEnd - tag->buf) * 2; - { - char *temp = REALLOC(parser, tag->buf, bufSize); - if (temp == NULL) diff --git a/meta/recipes-core/expat/expat/CVE-2026-25210-03.patch b/meta/recipes-core/expat/expat/CVE-2026-25210-03.patch deleted file mode 100644 index 46a1618e040..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-25210-03.patch +++ /dev/null @@ -1,28 +0,0 @@ -From 9c2d990389e6abe2e44527eeaa8b39f16fe859c7 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 2 Oct 2025 17:15:15 -0700 -Subject: [PATCH] lib: Introduce an integer overflow check for tag buffer - reallocation - -Suggested-by: Sebastian Pipping - -CVE: CVE-2026-25210 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/9c2d990389e6abe2e44527eeaa8b39f16fe859c7] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index ee18a87f..d8c54c38 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -3498,6 +3498,8 @@ doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc, - tag->name.strLen = convLen; - break; - } -+ if (SIZE_MAX / 2 < (size_t)(tag->bufEnd - tag->buf)) -+ return XML_ERROR_NO_MEMORY; - const size_t bufSize = (size_t)(tag->bufEnd - tag->buf) * 2; - { - char *temp = REALLOC(parser, tag->buf, bufSize); diff --git a/meta/recipes-core/expat/expat/CVE-2026-32776.patch b/meta/recipes-core/expat/expat/CVE-2026-32776.patch deleted file mode 100644 index 96a869a7c85..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-32776.patch +++ /dev/null @@ -1,91 +0,0 @@ -From 3340f971f2f92e499adf03156024105bb9bb7ed9 Mon Sep 17 00:00:00 2001 -From: Francesco Bertolaccini -Date: Tue, 3 Mar 2026 16:41:43 +0100 -Subject: [PATCH] Fix NULL function-pointer dereference for empty external - parameter entities - -When an external parameter entity with empty text is referenced inside -an entity declaration value, the sub-parser created to handle it receives -0 bytes of input. Processing enters entityValueInitProcessor which calls -storeEntityValue() with the parser's encoding; since no bytes were ever -processed, encoding detection has not yet occurred and the encoding is -still the initial probing encoding set up by XmlInitEncoding(). That -encoding only populates scanners[] (for prolog and content), not -literalScanners[]. XmlEntityValueTok() calls through -literalScanners[XML_ENTITY_VALUE_LITERAL] which is NULL, causing a -SEGV. - -Skip the tokenization loop entirely when entityTextPtr >= entityTextEnd, -and initialize the `next` pointer before the early exit so that callers -(callStoreEntityValue) receive a valid value through nextPtr. - -CVE: CVE-2026-32776 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/5be25657583ea91b09025c858b4785834c20f59c] - -(cherry picked from commit 5be25657583ea91b09025c858b4785834c20f59c) -Signed-off-by: Hugo SIMELIERE ---- - lib/xmlparse.c | 9 ++++++++- - tests/basic_tests.c | 19 +++++++++++++++++++ - 2 files changed, 27 insertions(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index aa5e91e4..56faf2eb 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -6777,7 +6777,14 @@ storeEntityValue(XML_Parser parser, const ENCODING *enc, - return XML_ERROR_NO_MEMORY; - } - -- const char *next; -+ const char *next = entityTextPtr; -+ -+ /* Nothing to tokenize. */ -+ if (entityTextPtr >= entityTextEnd) { -+ result = XML_ERROR_NONE; -+ goto endEntityValue; -+ } -+ - for (;;) { - next - = entityTextPtr; /* XmlEntityValueTok doesn't always set the last arg */ -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 2a5e43d6..023d9ce4 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -6210,6 +6210,24 @@ START_TEST(test_varying_buffer_fills) { - } - END_TEST - -+START_TEST(test_empty_ext_param_entity_in_value) { -+ const char *text = " "; -+ ExtOption options[] = { -+ {XCS("ext.dtd"), "" -+ ""}, -+ {XCS("empty"), ""}, -+ {NULL, NULL}, -+ }; -+ -+ XML_SetParamEntityParsing(g_parser, XML_PARAM_ENTITY_PARSING_ALWAYS); -+ XML_SetExternalEntityRefHandler(g_parser, external_entity_optioner); -+ XML_SetUserData(g_parser, options); -+ if (_XML_Parse_SINGLE_BYTES(g_parser, text, (int)strlen(text), XML_TRUE) -+ == XML_STATUS_ERROR) -+ xml_failure(g_parser); -+} -+END_TEST -+ - void - make_basic_test_case(Suite *s) { - TCase *tc_basic = tcase_create("basic tests"); -@@ -6456,6 +6474,7 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_empty_element_abort); - tcase_add_test__ifdef_xml_dtd(tc_basic, - test_pool_integrity_with_unfinished_attr); -+ tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_ext_param_entity_in_value); - tcase_add_test__if_xml_ge(tc_basic, test_entity_ref_no_elements); - tcase_add_test__if_xml_ge(tc_basic, test_deep_nested_entity); - tcase_add_test__if_xml_ge(tc_basic, test_deep_nested_attribute_entity); --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-32777-01.patch b/meta/recipes-core/expat/expat/CVE-2026-32777-01.patch deleted file mode 100644 index 50ba27dcd42..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-32777-01.patch +++ /dev/null @@ -1,49 +0,0 @@ -From a6e6cf7c30e54402b2fa3c49f9d98702e74f8c34 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 1 Mar 2026 20:16:13 +0100 -Subject: [PATCH 1/2] lib: Reject XML_TOK_INSTANCE_START infinite loop in - entityValueProcessor - -.. that OSS-Fuzz/ClusterFuzz uncovered - -CVE: CVE-2026-32777 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/55cda8c7125986e17d7e1825cba413bd94a35d02] - -(cherry picked from commit 55cda8c7125986e17d7e1825cba413bd94a35d02) -Signed-off-by: Hugo SIMELIERE ---- - lib/xmlparse.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 56faf2eb..bfb8ac58 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -5077,7 +5077,7 @@ entityValueInitProcessor(XML_Parser parser, const char *s, const char *end, - } - /* If we get this token, we have the start of what might be a - normal tag, but not a declaration (i.e. it doesn't begin with -- " -Date: Fri, 6 Mar 2026 18:31:34 +0100 -Subject: [PATCH 2/2] misc_tests.c: Cover XML_TOK_INSTANCE_START infinite loop - case - -.. that OSS-Fuzz/ClusterFuzz uncovered - -CVE: CVE-2026-32777 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/a7805c1a8a48d2ce83ef289cf55bdc8b45de76a8] - -(cherry picked from commit a7805c1a8a48d2ce83ef289cf55bdc8b45de76a8) -Signed-off-by: Hugo SIMELIERE ---- - tests/misc_tests.c | 30 ++++++++++++++++++++++++++++++ - 1 file changed, 30 insertions(+) - -diff --git a/tests/misc_tests.c b/tests/misc_tests.c -index 07902d52..cdcdd507 100644 ---- a/tests/misc_tests.c -+++ b/tests/misc_tests.c -@@ -713,6 +713,35 @@ START_TEST(test_misc_async_entity_rejected) { - } - END_TEST - -+START_TEST(test_misc_no_infinite_loop_issue_1161) { -+ XML_Parser parser = XML_ParserCreate(NULL); -+ -+ const char *text = ""; -+ -+ struct ExtOption options[] = { -+ {XCS("secondary.txt"), -+ ""}, -+ {XCS("tertiary.txt"), " -Date: Sun, 8 Mar 2026 17:28:06 -0700 -Subject: [PATCH 1/2] copy prefix name to pool before lookup - -.. so that we cannot end up with a zombie PREFIX in the pool -that has NULL for a name. - -CVE: CVE-2026-32778 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/576b61e42feeea704253cb7c7bedb2eeb3754387] - -Co-authored-by: Sebastian Pipping -(cherry picked from commit 576b61e42feeea704253cb7c7bedb2eeb3754387) -Signed-off-by: Hugo SIMELIERE ---- - lib/xmlparse.c | 43 +++++++++++++++++++++++++++++++++++-------- - 1 file changed, 35 insertions(+), 8 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index bfb8ac58..9bc67f38 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -590,6 +590,8 @@ static XML_Char *poolStoreString(STRING_POOL *pool, const ENCODING *enc, - static XML_Bool FASTCALL poolGrow(STRING_POOL *pool); - static const XML_Char *FASTCALL poolCopyString(STRING_POOL *pool, - const XML_Char *s); -+static const XML_Char *FASTCALL poolCopyStringNoFinish(STRING_POOL *pool, -+ const XML_Char *s); - static const XML_Char *poolCopyStringN(STRING_POOL *pool, const XML_Char *s, - int n); - static const XML_Char *FASTCALL poolAppendString(STRING_POOL *pool, -@@ -7443,16 +7445,24 @@ setContext(XML_Parser parser, const XML_Char *context) { - else { - if (! poolAppendChar(&parser->m_tempPool, XML_T('\0'))) - return XML_FALSE; -- prefix -- = (PREFIX *)lookup(parser, &dtd->prefixes, -- poolStart(&parser->m_tempPool), sizeof(PREFIX)); -- if (! prefix) -+ const XML_Char *const prefixName = poolCopyStringNoFinish( -+ &dtd->pool, poolStart(&parser->m_tempPool)); -+ if (! prefixName) { - return XML_FALSE; -- if (prefix->name == poolStart(&parser->m_tempPool)) { -- prefix->name = poolCopyString(&dtd->pool, prefix->name); -- if (! prefix->name) -- return XML_FALSE; - } -+ -+ prefix = (PREFIX *)lookup(parser, &dtd->prefixes, prefixName, -+ sizeof(PREFIX)); -+ -+ const bool prefixNameUsed = prefix && prefix->name == prefixName; -+ if (prefixNameUsed) -+ poolFinish(&dtd->pool); -+ else -+ poolDiscard(&dtd->pool); -+ -+ if (! prefix) -+ return XML_FALSE; -+ - poolDiscard(&parser->m_tempPool); - } - for (context = s + 1; *context != CONTEXT_SEP && *context != XML_T('\0'); -@@ -8041,6 +8051,23 @@ poolCopyString(STRING_POOL *pool, const XML_Char *s) { - return s; - } - -+// A version of `poolCopyString` that does not call `poolFinish` -+// and reverts any partial advancement upon failure. -+static const XML_Char *FASTCALL -+poolCopyStringNoFinish(STRING_POOL *pool, const XML_Char *s) { -+ const XML_Char *const original = s; -+ do { -+ if (! poolAppendChar(pool, *s)) { -+ // Revert any previously successful advancement -+ const ptrdiff_t advancedBy = s - original; -+ if (advancedBy > 0) -+ pool->ptr -= advancedBy; -+ return NULL; -+ } -+ } while (*s++); -+ return pool->start; -+} -+ - static const XML_Char * - poolCopyStringN(STRING_POOL *pool, const XML_Char *s, int n) { - if (! pool->ptr && ! poolGrow(pool)) { --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-32778-02.patch b/meta/recipes-core/expat/expat/CVE-2026-32778-02.patch deleted file mode 100644 index 2cfda33dc85..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-32778-02.patch +++ /dev/null @@ -1,61 +0,0 @@ -From c26728576de3850258c7762c036dd0eb7783ea15 Mon Sep 17 00:00:00 2001 -From: laserbear <10689391+Laserbear@users.noreply.github.com> -Date: Sun, 8 Mar 2026 17:28:06 -0700 -Subject: [PATCH 2/2] test that we do not end up with a zombie PREFIX in the - pool - -CVE: CVE-2026-32778 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/d5fa769b7a7290a7e2c4a0b2287106dec9b3c030] - -(cherry picked from commit d5fa769b7a7290a7e2c4a0b2287106dec9b3c030) -Signed-off-by: Hugo SIMELIERE ---- - tests/nsalloc_tests.c | 27 +++++++++++++++++++++++++++ - 1 file changed, 27 insertions(+) - -diff --git a/tests/nsalloc_tests.c b/tests/nsalloc_tests.c -index a8f5718d..d284a58a 100644 ---- a/tests/nsalloc_tests.c -+++ b/tests/nsalloc_tests.c -@@ -1505,6 +1505,32 @@ START_TEST(test_nsalloc_prefixed_element) { - } - END_TEST - -+/* Verify that retry after OOM in setContext() does not crash. -+ */ -+START_TEST(test_nsalloc_setContext_zombie) { -+ const char *text = " Hello "; -+ unsigned int i; -+ const unsigned int max_alloc_count = 30; -+ -+ for (i = 0; i < max_alloc_count; i++) { -+ g_allocation_count = (int)i; -+ if (XML_Parse(g_parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_ERROR) -+ break; -+ /* Retry on the same parser — must not crash */ -+ g_allocation_count = ALLOC_ALWAYS_SUCCEED; -+ XML_Parse(g_parser, text, (int)strlen(text), XML_TRUE); -+ -+ nsalloc_teardown(); -+ nsalloc_setup(); -+ } -+ if (i == 0) -+ fail("Parsing worked despite failing allocations"); -+ else if (i == max_alloc_count) -+ fail("Parsing failed even at maximum allocation count"); -+} -+END_TEST -+ - void - make_nsalloc_test_case(Suite *s) { - TCase *tc_nsalloc = tcase_create("namespace allocation tests"); -@@ -1539,4 +1565,5 @@ make_nsalloc_test_case(Suite *s) { - tcase_add_test__if_xml_ge(tc_nsalloc, test_nsalloc_long_default_in_ext); - tcase_add_test(tc_nsalloc, test_nsalloc_long_systemid_in_ext); - tcase_add_test(tc_nsalloc, test_nsalloc_prefixed_element); -+ tcase_add_test(tc_nsalloc, test_nsalloc_setContext_zombie); - } --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch deleted file mode 100644 index 0c6af75a5de..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch +++ /dev/null @@ -1,50 +0,0 @@ -From fe04a7f0ff8afe57ba33d919f368b1ba23bcda92 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping-Date: Sun, 30 Mar 2025 19:26:55 +0200 -Subject: [PATCH 1/3] lib/xmlparse.c: Address clang-tidy warning - misc-no-recursion - -CVE: CVE-2026-41080 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/fe04a7f0ff8afe57ba33d919f368b1ba23bcda92] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 17 ++++++++++------- - 1 file changed, 10 insertions(+), 7 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 9bc67f38..cb25c37b 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -1243,9 +1243,10 @@ generate_hash_secret_salt(XML_Parser parser) { - - static unsigned long - get_hash_secret_salt(XML_Parser parser) { -- if (parser->m_parentParser != NULL) -- return get_hash_secret_salt(parser->m_parentParser); -- return parser->m_hash_secret_salt; -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ -+ return rootParser->m_hash_secret_salt; - } - - static enum XML_Error -@@ -2321,12 +2322,14 @@ int XMLCALL - XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { - if (parser == NULL) - return 0; -- if (parser->m_parentParser) -- return XML_SetHashSalt(parser->m_parentParser, hash_salt); -+ -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ - /* block after XML_Parse()/XML_ParseBuffer() has been called */ -- if (parserBusy(parser)) -+ if (parserBusy(rootParser)) - return 0; -- parser->m_hash_secret_salt = hash_salt; -+ rootParser->m_hash_secret_salt = hash_salt; - return 1; - } - diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch deleted file mode 100644 index 953f93c68a9..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 7fb2c7a454edc9e2880073a27f899c31d9b078ce Mon Sep 17 00:00:00 2001 -From: Atrem Borovik -Date: Sat, 20 Dec 2025 13:22:16 +0300 -Subject: [PATCH 2/3] WASI: remove getpid - -CVE: CVE-2026-41080 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/7fb2c7a454edc9e2880073a27f899c31d9b078ce] -Signed-off-by: Peter Marko ---- - lib/xmlparse.c | 5 ++++- - 1 file changed, 4 insertions(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index cb25c37b..1bafb948 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -1228,8 +1228,11 @@ generate_hash_secret_salt(XML_Parser parser) { - # endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */ - /* .. and self-made low quality for backup: */ - -+ entropy = gather_time_entropy(); -+# if ! defined(__wasi__) - /* Process ID is 0 bits entropy if attacker has local access */ -- entropy = gather_time_entropy() ^ getpid(); -+ entropy ^= getpid(); -+# endif - - /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */ - if (sizeof(unsigned long) == 4) { diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch deleted file mode 100644 index 4d17f1a0b0e..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch +++ /dev/null @@ -1,467 +0,0 @@ -From b77ab600e1893fdcfc3868d0a46efcc87c87943d Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Wed, 8 Apr 2026 15:41:54 +0200 -Subject: [PATCH 3/3] [CVE-2026-41080] Improve protection against hash flooding - (fixes #47) - -Fixes #47 - -CVE: CVE-2026-41080 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1183] -Signed-off-by: Peter Marko ---- - Changes | 16 ++++++ - doc/reference.html | 51 ++++++++++++++-- - lib/expat.h | 12 ++++ - lib/internal.h | 2 + - lib/xmlparse.c | 118 ++++++++++++++++++++++++++------------ - tests/basic_tests.c | 25 ++++++++ - 6 files changed, 181 insertions(+), 43 deletions(-) - -diff --git a/Changes b/Changes -index 4265d608..1d87d6a0 100644 ---- a/Changes -+++ b/Changes -@@ -30,6 +30,22 @@ - !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! - - Patches: -+ Security fixes: -+ #47 #1183 CVE-2026-41080 -- The existing hash flooding protection -+ (based on SipHash) only used 4 to 8 bytes of entropy for -+ a salt, when 16 bytes of salt are supported by the -+ implementation of SipHash used by Expat. Now full 16 bytes -+ of entropy are used to improve protection against hash -+ flooding attacks. -+ Existing API function XML_SetHashSalt is now deprecated -+ because of its limitations, and its use should be -+ considered a vulnerability. Please either use the new API -+ function XML_SetHashSalt16Bytes (with known-high-quality -+ entropy input only!) instead, or leave the derivation of -+ a 16-bytes hash salt from high quality entropy to Expat's -+ internal machinery (by *not* calling either of the two -+ XML_SetHashSalt* functions). -+ - Security fixes: - #1018 #1034 CVE-2025-59375 -- Disallow use of disproportional amounts of - dynamic memory from within an Expat parser (e.g. previously -diff --git a/doc/reference.html b/doc/reference.html -index 8f14b011..7f374f84 100644 ---- a/doc/reference.html -+++ b/doc/reference.html -@@ -174,7 +174,8 @@ interface. - XML_GetAttributeInfo -XML_SetEncoding -XML_SetParamEntityParsing --XML_SetHashSalt -+XML_SetHashSalt (deprecated) -+XML_SetHashSalt16Bytes -XML_UseForeignDTD -XML_SetReturnNSTriplet -XML_DefaultCurrent -@@ -2553,10 +2554,10 @@ The choices forcodeare: - no effect and will always return 0. - - --XML_SetHashSalt
-+XML_SetHashSalt (deprecated)
-- int XMLCALL --XML_SetHashSalt(XML_Parser p, -+XML_SetHashSalt(XML_Parser parser, - unsigned long hash_salt); ---@@ -2564,15 +2565,55 @@ Sets the hash salt to use for internal hash calculations. - Helps in preventing DoS attacks based on predicting hash - function behavior. In order to have an effect this must be called - before parsing has started. Returns 1 if successful, 0 when called --after- -+XML_ParseorXML_ParseBuffer. -+afterXML_ParseorXML_ParseBufferor when -+parserisNULL. -+-+ Note: Function
. -XML_SetHashSaltis -+ deprecated. Please use functionXML_SetHashSalt16Bytesinstead for better -+ security.XML_SetHashSaltonly provides 4 to 8 bytes of entropy -+ (depending on the size of typeunsigned long) while the SipHash -+ implementation used by Expat can leverage up to 16 bytes of entropy — at least -+ twice as much. FunctionXML_SetHashSalt16Bytesof Expat >=2.7.6 -+ (and where backported) matches the amount of entropy supported by SipHash. -+Note: This call is optional, as the parser will auto-generate --a new random salt value if no value has been set at the start of parsing.
-+a new random salt value internally if no value has been set by the start of parsing. -Note: One should not call
-XML_SetHashSaltwith a - hash salt value of 0, as this value is used as sentinel value to indicate - thatXML_SetHashSalthas not been called. Consequently - such a call will have no effect, even if it returns 1.-+ XML_SetHashSalt16Bytes -+
-+ -+-+/* Added in Expat 2.7.6. */ -+XML_Bool XMLCALL -+XML_SetHashSalt16Bytes(XML_Parser parser, -+ const uint8_t entropy[16]); -+-+-+ Sets the hash salt to use for internal hash calculations. Helps in preventing DoS -+ attacks based on predicting hash function behavior. In order to have an effect -+ this must be called before parsing has started. Returns-+ -XML_TRUEif -+ successful,XML_FALSEwhen called afterXML_Parseor -+XML_ParseBufferor whenparserisNULL. -+-+ Note: Setting a salt that is not from a source of high quality -+ entropy (like
-+ -+getentropy(3)) will make the parser vulnerable to -+ hash flooding attacks. -+-+ Note: This call is optional, as the parser will auto-generate a new -+ random salt value internally if no value has been set by the start of parsing. -+
-+XML_UseForeignDTD
-- enum XML_Error XMLCALL -diff --git a/lib/expat.h b/lib/expat.h -index df207e9e..b356e002 100644 ---- a/lib/expat.h -+++ b/lib/expat.h -@@ -44,6 +44,7 @@ - #ifndef Expat_INCLUDED - #define Expat_INCLUDED 1 - -+# include// for uint8_t - #include - #include "expat_external.h" - -@@ -916,10 +917,21 @@ XML_SetParamEntityParsing(XML_Parser parser, - function behavior. This must be called before parsing is started. - Returns 1 if successful, 0 when called after parsing has started. - Note: If parser == NULL, the function will do nothing and return 0. -+ DEPRECATED since Expat 2.7.6. - */ - XMLPARSEAPI(int) - XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt); - -+/* Sets the hash salt to use for internal hash calculations. -+ Helps in preventing DoS attacks based on predicting hash function behavior. -+ This must be called before parsing is started. -+ Returns XML_TRUE if successful, XML_FALSE when called after parsing has -+ started or when parser is NULL. -+ Added in Expat 2.7.6. -+*/ -+XMLPARSEAPI(XML_Bool) -+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]); -+ - /* If XML_Parse or XML_ParseBuffer have returned XML_STATUS_ERROR, then - XML_GetErrorCode returns information about the error. - */ -diff --git a/lib/internal.h b/lib/internal.h -index 32faaa05..617d6454 100644 ---- a/lib/internal.h -+++ b/lib/internal.h -@@ -113,6 +113,7 @@ - #if defined(_WIN32) \ - && (! defined(__USE_MINGW_ANSI_STDIO) \ - || (1 - __USE_MINGW_ANSI_STDIO - 1 == 0)) -+# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x" - # define EXPAT_FMT_ULL(midpart) "%" midpart "I64u" - # if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW - # define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d" -@@ -122,6 +123,7 @@ - # define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u" - # endif - #else -+# define EXPAT_FMT_LLX(midpart) "%" midpart "llx" - # define EXPAT_FMT_ULL(midpart) "%" midpart "llu" - # if ! defined(ULONG_MAX) - # error Compiler did not define ULONG_MAX for us -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 1bafb948..75a7e5d0 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -604,7 +604,7 @@ static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc, - - static XML_Char *copyString(const XML_Char *s, XML_Parser parser); - --static unsigned long generate_hash_secret_salt(XML_Parser parser); -+static struct sipkey generate_hash_secret_salt(void); - static XML_Bool startParsing(XML_Parser parser); - - static XML_Parser parserCreate(const XML_Char *encodingName, -@@ -777,7 +777,8 @@ struct XML_ParserStruct { - XML_Bool m_useForeignDTD; - enum XML_ParamEntityParsing m_paramEntityParsing; - #endif -- unsigned long m_hash_secret_salt; -+ struct sipkey m_hash_secret_salt_128; -+ XML_Bool m_hash_secret_salt_set; - #if XML_GE == 1 - ACCOUNTING m_accounting; - MALLOC_TRACKER m_alloc_tracker; -@@ -1189,69 +1190,65 @@ gather_time_entropy(void) { - - #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */ - --static unsigned long --ENTROPY_DEBUG(const char *label, unsigned long entropy) { -+static struct sipkey -+ENTROPY_DEBUG(const char *label, struct sipkey entropy_128) { - if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) { -- fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label, -- (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy)); -+ fprintf(stderr, -+ "expat: Entropy: %s --> [0x" EXPAT_FMT_LLX( -+ "016") ", 0x" EXPAT_FMT_LLX("016") "] (16 bytes)\n", -+ label, (unsigned long long)entropy_128.k[0], -+ (unsigned long long)entropy_128.k[1]); - } -- return entropy; -+ return entropy_128; - } - --static unsigned long --generate_hash_secret_salt(XML_Parser parser) { -- unsigned long entropy; -- (void)parser; -+static struct sipkey -+generate_hash_secret_salt(void) { -+ struct sipkey entropy; - - /* "Failproof" high quality providers: */ - #if defined(HAVE_ARC4RANDOM_BUF) - arc4random_buf(&entropy, sizeof(entropy)); - return ENTROPY_DEBUG("arc4random_buf", entropy); - #elif defined(HAVE_ARC4RANDOM) -- writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy)); -+ writeRandomBytes_arc4random(&entropy, sizeof(entropy)); - return ENTROPY_DEBUG("arc4random", entropy); - #else - /* Try high quality providers first .. */ - # ifdef _WIN32 -- if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_rand_s(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("rand_s", entropy); - } - # elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM) -- if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_getrandom_nonblock(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("getrandom", entropy); - } - # endif - # if ! defined(_WIN32) && defined(XML_DEV_URANDOM) -- if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_dev_urandom(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("/dev/urandom", entropy); - } - # endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */ - /* .. and self-made low quality for backup: */ - -- entropy = gather_time_entropy(); -+ entropy.k[0] = 0; -+ entropy.k[1] = gather_time_entropy(); - # if ! defined(__wasi__) - /* Process ID is 0 bits entropy if attacker has local access */ -- entropy ^= getpid(); -+ entropy.k[1] ^= getpid(); - # endif - - /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */ - if (sizeof(unsigned long) == 4) { -- return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647); -+ entropy.k[1] *= 2147483647; -+ return ENTROPY_DEBUG("fallback(4)", entropy); - } else { -- return ENTROPY_DEBUG("fallback(8)", -- entropy * (unsigned long)2305843009213693951ULL); -+ entropy.k[1] *= 2305843009213693951ULL; -+ return ENTROPY_DEBUG("fallback(8)", entropy); - } - #endif - } - --static unsigned long --get_hash_secret_salt(XML_Parser parser) { -- const XML_Parser rootParser = getRootParserOf(parser, NULL); -- assert(! rootParser->m_parentParser); -- -- return rootParser->m_hash_secret_salt; --} -- - static enum XML_Error - callProcessor(XML_Parser parser, const char *start, const char *end, - const char **endPtr) { -@@ -1320,8 +1316,10 @@ callProcessor(XML_Parser parser, const char *start, const char *end, - static XML_Bool /* only valid for root parser */ - startParsing(XML_Parser parser) { - /* hash functions must be initialized before setContext() is called */ -- if (parser->m_hash_secret_salt == 0) -- parser->m_hash_secret_salt = generate_hash_secret_salt(parser); -+ if (parser->m_hash_secret_salt_set != XML_TRUE) { -+ parser->m_hash_secret_salt_128 = generate_hash_secret_salt(); -+ parser->m_hash_secret_salt_set = XML_TRUE; -+ } - if (parser->m_ns) { - /* implicit context only set for root parser, since child - parsers (i.e. external entity parsers) will inherit it -@@ -1609,7 +1607,9 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) { - parser->m_useForeignDTD = XML_FALSE; - parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER; - #endif -- parser->m_hash_secret_salt = 0; -+ parser->m_hash_secret_salt_128.k[0] = 0; -+ parser->m_hash_secret_salt_128.k[1] = 0; -+ parser->m_hash_secret_salt_set = XML_FALSE; - - #if XML_GE == 1 - memset(&parser->m_accounting, 0, sizeof(ACCOUNTING)); -@@ -1776,7 +1776,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - from hash tables associated with either parser without us having - to worry which hash secrets each table has. - */ -- unsigned long oldhash_secret_salt; -+ struct sipkey oldhash_secret_salt_128; -+ XML_Bool oldhash_secret_salt_set; - XML_Bool oldReparseDeferralEnabled; - - /* Validate the oldParser parameter before we pull everything out of it */ -@@ -1822,7 +1823,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - from hash tables associated with either parser without us having - to worry which hash secrets each table has. - */ -- oldhash_secret_salt = parser->m_hash_secret_salt; -+ oldhash_secret_salt_128 = parser->m_hash_secret_salt_128; -+ oldhash_secret_salt_set = parser->m_hash_secret_salt_set; - oldReparseDeferralEnabled = parser->m_reparseDeferralEnabled; - - #ifdef XML_DTD -@@ -1877,7 +1879,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg; - parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities; - parser->m_ns_triplets = oldns_triplets; -- parser->m_hash_secret_salt = oldhash_secret_salt; -+ parser->m_hash_secret_salt_128 = oldhash_secret_salt_128; -+ parser->m_hash_secret_salt_set = oldhash_secret_salt_set; - parser->m_reparseDeferralEnabled = oldReparseDeferralEnabled; - parser->m_parentParser = oldParser; - #ifdef XML_DTD -@@ -2321,6 +2324,7 @@ XML_SetParamEntityParsing(XML_Parser parser, - #endif - } - -+// DEPRECATED since Expat 2.7.6. - int XMLCALL - XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { - if (parser == NULL) -@@ -2332,10 +2336,46 @@ XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { - /* block after XML_Parse()/XML_ParseBuffer() has been called */ - if (parserBusy(rootParser)) - return 0; -- rootParser->m_hash_secret_salt = hash_salt; -+ -+ rootParser->m_hash_secret_salt_128.k[0] = 0; -+ rootParser->m_hash_secret_salt_128.k[1] = hash_salt; -+ -+ if (hash_salt != 0) { // to remain backwards compatible -+ rootParser->m_hash_secret_salt_set = XML_TRUE; -+ -+ if (sizeof(unsigned long) == 4) -+ ENTROPY_DEBUG("explicit(4)", rootParser->m_hash_secret_salt_128); -+ else -+ ENTROPY_DEBUG("explicit(8)", rootParser->m_hash_secret_salt_128); -+ } -+ - return 1; - } - -+XML_Bool XMLCALL -+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]) { -+ if (parser == NULL) -+ return XML_FALSE; -+ -+ if (entropy == NULL) -+ return XML_FALSE; -+ -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ -+ /* block after XML_Parse()/XML_ParseBuffer() has been called */ -+ if (parserBusy(rootParser)) -+ return XML_FALSE; -+ -+ sip_tokey(&(rootParser->m_hash_secret_salt_128), entropy); -+ -+ rootParser->m_hash_secret_salt_set = XML_TRUE; -+ -+ ENTROPY_DEBUG("explicit(16)", rootParser->m_hash_secret_salt_128); -+ -+ return XML_TRUE; -+} -+ - enum XML_Status XMLCALL - XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { - if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) { -@@ -7837,8 +7877,10 @@ keylen(KEY s) { - - static void - copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) { -- key->k[0] = 0; -- key->k[1] = get_hash_secret_salt(parser); -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ -+ *key = rootParser->m_hash_secret_salt_128; - } - - static unsigned long FASTCALL -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 023d9ce4..380caf19 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -204,6 +204,30 @@ START_TEST(test_hash_collision) { - END_TEST - #undef COLLIDING_HASH_SALT - -+START_TEST(test_hash_salt_setter) { -+ const uint8_t entropy[16] = {'0', '1', '2', '3', '4', '5', '6', '7', -+ '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'}; -+ XML_Parser parser = XML_ParserCreate(NULL); -+ -+ // NULL parser should be rejected -+ assert_true(XML_SetHashSalt16Bytes(NULL, entropy) == XML_FALSE); -+ -+ // NULL entropy should be rejected -+ assert_true(XML_SetHashSalt16Bytes(parser, NULL) == XML_FALSE); -+ -+ // Setting should be allowed more than once -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE); -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE); -+ -+ // But not after parsing has started -+ assert_true(XML_Parse(parser, "", 0, XML_FALSE /* isFinal */) -+ == XML_STATUS_OK); -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_FALSE); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Regression test for SF bug #491986. */ - START_TEST(test_danish_latin1) { - const char *text = "\n" -@@ -6244,6 +6268,7 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_bom_utf16_le); - tcase_add_test(tc_basic, test_nobom_utf16_le); - tcase_add_test(tc_basic, test_hash_collision); -+ tcase_add_test(tc_basic, test_hash_salt_setter); - tcase_add_test(tc_basic, test_illegal_utf8); - tcase_add_test(tc_basic, test_utf8_auto_align); - tcase_add_test(tc_basic, test_utf16); diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch deleted file mode 100644 index 787006c0fdb..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch +++ /dev/null @@ -1,70 +0,0 @@ -From 3020144133b2d860c44f4eeacf72e5f2843235a3 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= -Date: Fri, 13 Mar 2026 13:26:45 +0100 -Subject: [PATCH 1/7] Make "counting_start_element_handler" count default attrs - -(cherry picked from commit 0802a5892030610144b736dec6e2f63e8600fe85) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/0802a5892030610144b736dec6e2f63e8600fe85] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 8 ++++---- - tests/handlers.c | 2 +- - tests/handlers.h | 1 + - 3 files changed, 6 insertions(+), 5 deletions(-) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 023d9ce..d6edb16 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2439,9 +2439,9 @@ START_TEST(test_attributes) { - {XCS("id"), XCS("one")}, - {NULL, NULL}}; - AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("doc"), 3, XCS("id"), NULL}, -- {XCS("tag"), 1, NULL, NULL}, -- {NULL, 0, NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL}, -+ {XCS("tag"), 1, 0, NULL, NULL}, -+ {NULL, 0, 0, NULL, NULL}}; - info[0].attributes = doc_info; - info[1].attributes = tag_info; - -@@ -5496,7 +5496,7 @@ START_TEST(test_deep_nested_attribute_entity) { - (long unsigned)(N_LINES - 1)); - - AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("foo"), 1, NULL, NULL}, {NULL, 0, NULL, NULL}}; -+ ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}}; - info[0].attributes = doc_info; - - XML_Parser parser = XML_ParserCreate(NULL); -diff --git a/tests/handlers.c b/tests/handlers.c -index e658223..9ff7b35 100644 ---- a/tests/handlers.c -+++ b/tests/handlers.c -@@ -137,7 +137,7 @@ counting_start_element_handler(void *userData, const XML_Char *name, - fail("ID does not have the correct name"); - return; - } -- for (i = 0; i < info->attr_count; i++) { -+ for (i = 0; i < info->attr_count + info->default_attr_count; i++) { - attr = info->attributes; - while (attr->name != NULL) { - if (! xcstrcmp(atts[0], attr->name)) -diff --git a/tests/handlers.h b/tests/handlers.h -index ac4ca94..11d45eb 100644 ---- a/tests/handlers.h -+++ b/tests/handlers.h -@@ -88,6 +88,7 @@ typedef struct attrInfo { - typedef struct elementInfo { - const XML_Char *name; - int attr_count; -+ int default_attr_count; - const XML_Char *id_name; - AttrInfo *attributes; - } ElementInfo; --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch deleted file mode 100644 index fef531a4392..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch +++ /dev/null @@ -1,318 +0,0 @@ -From ba12af3b3ffd98b9e31c3a01a20d392c89aa974e Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= -Date: Fri, 13 Mar 2026 13:27:31 +0100 -Subject: [PATCH 2/7] test(attlist): Cover duplicate attribute names - -Co-authored-by: Sebastian Pipping -(cherry picked from commit e569f47181c43dca5d262089e541ddf9a9c09927) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/e569f47181c43dca5d262089e541ddf9a9c09927] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 282 ++++++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 282 insertions(+) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index d6edb16..907a458 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2462,6 +2462,279 @@ START_TEST(test_attributes) { - } - END_TEST - -+START_TEST(test_duplicate_cdata_attribute) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_1) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{XCS("identifier"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_2) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{NULL, NULL}}; -+ -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_2) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, {NULL, NULL}}; -+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 0, 1, NULL, doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_3) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text -+ = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, -+ {XCS("second_attribute"), XCS("second_expected_doc")}, -+ {NULL, NULL}}; -+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 0, 2, NULL, doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ " \n"; -+ AttrInfo doc_info[] -+ = {{XCS("identifier"), XCS("doc_identity")}, {NULL, NULL}}; -+ AttrInfo tag_info[] -+ = {{XCS("identifier"), XCS("identifier_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 1, 0, XCS("identifier"), doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Test reset works correctly in the middle of processing an internal - * entity. Exercises some obscure code in XML_ParserReset(). - */ -@@ -6325,6 +6598,15 @@ make_basic_test_case(Suite *s) { - tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_foreign_dtd); - tcase_add_test(tc_basic, test_set_base); - tcase_add_test(tc_basic, test_attributes); -+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_1); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_2); -+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute_multiple_attlistdecl); -+ tcase_add_test(tc_basic, -+ test_duplicate_cdata_attribute_multiple_attlistdecl_2); -+ tcase_add_test(tc_basic, -+ test_duplicate_cdata_attribute_multiple_attlistdecl_3); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl); - tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity); - tcase_add_test(tc_basic, test_resume_invalid_parse); - tcase_add_test(tc_basic, test_resume_resuspended); --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch deleted file mode 100644 index 2afe6dbebc4..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch +++ /dev/null @@ -1,46 +0,0 @@ -From 852ab610685b45c62017556c38096d941c154963 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Mon, 20 Apr 2026 13:44:43 +0200 -Subject: [PATCH 3/7] tests: Define .attributes the first time around - -(cherry picked from commit 05307d352a5aa858cdda57ec53a53b597b3a4a82) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/05307d352a5aa858cdda57ec53a53b597b3a4a82] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 10 ++++------ - 1 file changed, 4 insertions(+), 6 deletions(-) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 907a458..b0178fc 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2439,11 +2439,9 @@ START_TEST(test_attributes) { - {XCS("id"), XCS("one")}, - {NULL, NULL}}; - AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL}, -- {XCS("tag"), 1, 0, NULL, NULL}, -+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), doc_info}, -+ {XCS("tag"), 1, 0, NULL, tag_info}, - {NULL, 0, 0, NULL, NULL}}; -- info[0].attributes = doc_info; -- info[1].attributes = tag_info; - - XML_Parser parser = XML_ParserCreate(NULL); - assert_true(parser != NULL); -@@ -5769,8 +5767,8 @@ START_TEST(test_deep_nested_attribute_entity) { - (long unsigned)(N_LINES - 1)); - - AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}}; -- info[0].attributes = doc_info; -+ ElementInfo info[] -+ = {{XCS("foo"), 1, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; - - XML_Parser parser = XML_ParserCreate(NULL); - ParserAndElementInfo parserPlusElemenInfo = {parser, info}; --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch deleted file mode 100644 index f4c7733c70d..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 89c6acdcd919b64014b180fadec46b0d25760832 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Mon, 13 Apr 2026 01:34:03 +0200 -Subject: [PATCH 4/7] tests: Make counting_start_element_handler enforce - complete attribute lists - -(cherry picked from commit 4176aff73840711060913e0ac6aa1168d8ba5c8d) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4176aff73840711060913e0ac6aa1168d8ba5c8d] -Signed-off-by: Theo Gaige ---- - tests/handlers.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/tests/handlers.c b/tests/handlers.c -index 9ff7b35..5e72e8b 100644 ---- a/tests/handlers.c -+++ b/tests/handlers.c -@@ -155,6 +155,9 @@ counting_start_element_handler(void *userData, const XML_Char *name, - /* Remember, two entries in atts per attribute (see above) */ - atts += 2; - } -+ -+ // Self-test that the test case's list of expected attributes is complete -+ assert_true(atts[0] == NULL); - } - - void XMLCALL --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch deleted file mode 100644 index 480f941cb6f..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch +++ /dev/null @@ -1,32 +0,0 @@ -From d352c83afaa3945c964aba74cb60a00822af96d3 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 22:14:41 +0100 -Subject: [PATCH 5/7] lib: Extract a constant for upcoming reuse - -(cherry picked from commit fb35f2d2040d114f355bae8a7450942533237530) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 9bc67f3..8d3e8db 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -7708,8 +7708,9 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes), - oldE->prefix->name, 0); - for (i = 0; i < newE->nDefaultAtts; i++) { -+ const XML_Char *const attributeName = oldE->defaultAtts[i].id->name; - newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup( -- oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0); -+ oldParser, &(newDtd->attributeIds), attributeName, 0); - newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata; - if (oldE->defaultAtts[i].value) { - newE->defaultAtts[i].value --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch deleted file mode 100644 index d39eb91f2f1..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch +++ /dev/null @@ -1,87 +0,0 @@ -From a2c8ddb3d6f4df7af64e05bed4b3a4edeae33fd0 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 23:05:49 +0100 -Subject: [PATCH 6/7] lib: Introduce ELEMENT_TYPE.defaultAttsNames - -(cherry picked from commit 7f0f1b9e70d937072d2e9e37ae9edf27784cc080) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 8d3e8db..4a29c18 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -388,6 +388,7 @@ typedef struct { - int nDefaultAtts; - int allocDefaultAtts; - DEFAULT_ATTRIBUTE *defaultAtts; -+ HASH_TABLE defaultAttsNames; - } ELEMENT_TYPE; - - typedef struct { -@@ -3844,6 +3845,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - sizeof(ELEMENT_TYPE)); - if (! elementType) - return XML_ERROR_NO_MEMORY; -+ if (! elementType->defaultAttsNames.parser) -+ hashTableInit(&(elementType->defaultAttsNames), parser); - if (parser->m_ns && ! setElementTypePrefix(parser, elementType)) - return XML_ERROR_NO_MEMORY; - } -@@ -7549,6 +7552,7 @@ dtdReset(DTD *p, XML_Parser parser) { - ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); - if (! e) - break; -+ hashTableDestroy(&(e->defaultAttsNames)); - if (e->allocDefaultAtts != 0) - FREE(parser, e->defaultAtts); - } -@@ -7590,6 +7594,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) { - ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); - if (! e) - break; -+ hashTableDestroy(&(e->defaultAttsNames)); - if (e->allocDefaultAtts != 0) - FREE(parser, e->defaultAtts); - } -@@ -7683,6 +7688,10 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - sizeof(ELEMENT_TYPE)); - if (! newE) - return 0; -+ -+ if (! newE->defaultAttsNames.parser) -+ hashTableInit(&(newE->defaultAttsNames), parser); -+ - if (oldE->nDefaultAtts) { - /* Detect and prevent integer overflow. - * The preprocessor guard addresses the "always false" warning -@@ -7719,6 +7728,12 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - return 0; - } else - newE->defaultAtts[i].value = NULL; -+ -+ NAMED *const nameAddedOrFound = (NAMED *)lookup( -+ parser, &(newE->defaultAttsNames), attributeName, sizeof(NAMED)); -+ if (! nameAddedOrFound) { -+ return 0; -+ } - } - } - -@@ -8458,6 +8473,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr, - sizeof(ELEMENT_TYPE)); - if (! ret) - return NULL; -+ if (! ret->defaultAttsNames.parser) -+ hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL)); - if (ret->name != name) - poolDiscard(&dtd->pool); - else { --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch deleted file mode 100644 index 26c829b5220..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 0e4829f4be500ce687b37ec82f9650b86c8419c7 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 23:06:29 +0100 -Subject: [PATCH 7/7] lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute - collision detection - -.. to resolve quadratic runtime behavior - -(cherry picked from commit 4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 14 ++++++++++---- - 1 file changed, 10 insertions(+), 4 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 4a29c18..b3f0b73 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -7177,10 +7177,10 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - if (value || isId) { - /* The handling of default attributes gets messed up if we have - a default which duplicates a non-default. */ -- int i; -- for (i = 0; i < type->nDefaultAtts; i++) -- if (attId == type->defaultAtts[i].id) -- return 1; -+ NAMED *const nameFound -+ = (NAMED *)lookup(parser, &(type->defaultAttsNames), attId->name, 0); -+ if (nameFound) -+ return 1; - if (isId && ! type->idAtt && ! attId->xmlns) - type->idAtt = attId; - } -@@ -7227,6 +7227,12 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - att->isCdata = isCdata; - if (! isCdata) - attId->maybeTokenized = XML_TRUE; -+ -+ NAMED *const nameAddedOrFound = (NAMED *)lookup( -+ parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED)); -+ if (! nameAddedOrFound) -+ return 0; -+ - type->nDefaultAtts += 1; - return 1; - } --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch deleted file mode 100644 index fc5b5778787..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch +++ /dev/null @@ -1,80 +0,0 @@ -From 9d1c131840a501e6664c5770046153235467f574 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH 13/17] lib: Remove reuse of `m_groupSize` to count - `m_scaffIndex` allocation - -The sizes of the two arrays `m_groupConnector` and `scaffIndex` need to -vary independently. This change is a step towards allowing this. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3] - -Backport Changes: -- Adapt scaffIndex sizing to Scarthgap 2.6.4, where m_groupSize is - not temporarily doubled before reallocation. - Keep the branch's equivalent size_t overflow check. - -(cherry picked from commit 3a4eaf47af8fd7abda38ea2c08308c91152061f3) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 8439dc0e..e9ad78df 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -423,6 +423,7 @@ typedef struct { - unsigned scaffCount; - int scaffLevel; - int *scaffIndex; -+ size_t scaffIndexSize; - } DTD; - - enum EntityType { -@@ -5975,6 +5976,7 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - if (new_scaff_index == NULL) - return XML_ERROR_NO_MEMORY; - dtd->scaffIndex = new_scaff_index; -+ dtd->scaffIndexSize = parser->m_groupSize; - } - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); -@@ -7575,6 +7577,7 @@ dtdCreate(XML_Parser parser) { - - p->in_eldecl = XML_FALSE; - p->scaffIndex = NULL; -+ p->scaffIndexSize = 0; - p->scaffold = NULL; - p->scaffLevel = 0; - p->scaffSize = 0; -@@ -7615,6 +7618,7 @@ dtdReset(DTD *p, XML_Parser parser) { - - FREE(parser, p->scaffIndex); - p->scaffIndex = NULL; -+ p->scaffIndexSize = 0; - FREE(parser, p->scaffold); - p->scaffold = NULL; - -@@ -7790,6 +7794,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - newDtd->scaffSize = oldDtd->scaffSize; - newDtd->scaffLevel = oldDtd->scaffLevel; - newDtd->scaffIndex = oldDtd->scaffIndex; -+ newDtd->scaffIndexSize = oldDtd->scaffIndexSize; - - return 1; - } /* End dtdCopy */ -@@ -8310,6 +8315,7 @@ nextScaffoldPart(XML_Parser parser) { - dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int)); - if (! dtd->scaffIndex) - return -1; -+ dtd->scaffIndexSize = parser->m_groupSize; - dtd->scaffIndex[0] = 0; - } - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch deleted file mode 100644 index c8a4971e839..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch +++ /dev/null @@ -1,60 +0,0 @@ -From a4c1b874dffcc80ee63ca3b4d6a1537c56da8dc1 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH 14/17] lib: doProlog: Fix out-of-bound scaffolding index store -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The scaffold backing array is reallocated using the caller parser’s -per-parser `m_groupSize`, but the DTD struct (which carries -`scaffIndex`) is shared between a parent parser and any external -parameter-entity sub-parser created via -`XML_ExternalEntityParserCreate(parent, NULL, …)`. A sub-parser whose -group nesting is shallower than the parent’s can `REALLOC` the shared -`scaffIndex` down to its own size; when the parent resumes and parses a -deeper element content model, its bounds check passes (its private -`m_groupSize` is still large enough), the doubling-grow path is skipped, -and the next write lands past the shrunken buffer. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario -Reported-by: Trail of Bits, in collaboration with Anthropic - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e] - -(cherry picked from commit 58400483d7c97be316d7a77739c0a6af5d55932e) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 15 +++++++++++++++ - 1 file changed, 15 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index e9ad78df..c46c17bc 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5992,6 +5992,21 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - if (myindex < 0) - return XML_ERROR_NO_MEMORY; - assert(dtd->scaffIndex != NULL); -+ if ((size_t)dtd->scaffLevel >= dtd->scaffIndexSize) { -+ /* Detect and prevent integer overflow */ -+ if (dtd->scaffIndexSize > SIZE_MAX / 2 / sizeof(int)) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ assert(dtd->scaffIndexSize > 0); -+ const size_t new_size = dtd->scaffIndexSize * 2; -+ int *const new_scaff_index -+ = REALLOC(parser, dtd->scaffIndex, new_size * sizeof(int)); -+ if (new_scaff_index == NULL) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ dtd->scaffIndex = new_scaff_index; -+ dtd->scaffIndexSize = new_size; -+ } - dtd->scaffIndex[dtd->scaffLevel] = myindex; - dtd->scaffLevel++; - dtd->scaffold[myindex].type = XML_CTYPE_SEQ; diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch deleted file mode 100644 index 1376e1d4c0c..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch +++ /dev/null @@ -1,74 +0,0 @@ -From 5d4d0dab46e077b327f70a7c02a307287e8d1fe5 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH 15/17] tests: Add a test case for scaffolding array limits in - shared DTDs - -This test case provokes the bug fixed in the previous commit. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario -Reported-by: Trail of Bits, in collaboration with Anthropic - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf] - -(cherry picked from commit 353919b3b9f2174073a557ac7d517a5f3cd0cbbf) -Signed-off-by: Deepak Rathore ---- - expat/tests/basic_tests.c | 33 +++++++++++++++++++++++++++++++++ - 1 file changed, 33 insertions(+) - -diff --git a/expat/tests/basic_tests.c b/expat/tests/basic_tests.c -index 023d9ce4..d52dcf1c 100644 ---- a/expat/tests/basic_tests.c -+++ b/expat/tests/basic_tests.c -@@ -4044,6 +4044,37 @@ START_TEST(test_skipped_external_entity) { - } - END_TEST - -+START_TEST(test_scaff_index_shared_across_external_entity_parser) { -+ const char text[] -+ = "\n" -+ "\n" -+ "%e;\n" -+ "\n" -+ "]>\n" -+ " "; -+ ExtOption options[] -+ = {{XCS("ext"), -+ ""}, -+ {NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS); -+ XML_SetUserData(parser, options); -+ XML_SetExternalEntityRefHandler(parser, external_entity_optioner); -+ XML_SetElementDeclHandler(parser, dummy_element_decl_handler); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ == XML_STATUS_ERROR) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Test a different form of unknown external entity */ - START_TEST(test_skipped_null_loaded_ext_entity) { - const char *text = "\n" -@@ -6399,6 +6430,8 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_trailing_cr_in_att_value); - tcase_add_test(tc_basic, test_standalone_internal_entity); - tcase_add_test(tc_basic, test_skipped_external_entity); -+ tcase_add_test__ifdef_xml_dtd( -+ tc_basic, test_scaff_index_shared_across_external_entity_parser); - tcase_add_test(tc_basic, test_skipped_null_loaded_ext_entity); - tcase_add_test(tc_basic, test_skipped_unloaded_ext_entity); - tcase_add_test__ifdef_xml_dtd(tc_basic, test_param_entity_with_trailing_cr); diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch deleted file mode 100644 index 74d0e33a9d9..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch +++ /dev/null @@ -1,60 +0,0 @@ -From a7d7ed5d6dbcc7231529357d64eb19ede3114868 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH 16/17] lib: Remove unnecessary `scaffIndex` expansion - -Following the previous changes, all locations that append entries to -`scaffIndex` handle expanding the array if it is not already large -enough. So this extra expansion code is no longer necessary. In some -cases such as processing siblings with alternating scaffolding counts, -this logic would actually _shrink_ the array only to then later -re-expand it. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4] - -Backport Changes: -- Remove the Scarthgap 2.6.4 scaffIndex resize block because later - append paths already expand the array when required. - -(cherry picked from commit bca93b4ba9e15fd84425568d772b69baebf790e4) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 19 ------------------- - 1 file changed, 19 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index c46c17bc..3afe2884 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5959,25 +5959,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - } - parser->m_groupConnector = new_connector; - } -- -- if (dtd->scaffIndex) { -- /* Detect and prevent integer overflow. -- * The preprocessor guard addresses the "always false" warning -- * from -Wtype-limits on platforms where -- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */ --#if UINT_MAX >= SIZE_MAX -- if (parser->m_groupSize > (size_t)(-1) / sizeof(int)) { -- return XML_ERROR_NO_MEMORY; -- } --#endif -- -- int *const new_scaff_index = REALLOC( -- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); -- if (new_scaff_index == NULL) -- return XML_ERROR_NO_MEMORY; -- dtd->scaffIndex = new_scaff_index; -- dtd->scaffIndexSize = parser->m_groupSize; -- } - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); - if (! parser->m_groupConnector) { diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch deleted file mode 100644 index 59229f331ca..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch +++ /dev/null @@ -1,56 +0,0 @@ -From 778ba31c47f9930fe339194f4d97081e43893362 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH 17/17] lib: Remove indented scoping of `new_connector` local - -Following the previous change, the lifetime of `new_connector` as -constrained by this introduced scope was identical to the parent scope. - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5] - -Backport Changes: -- Retain the Scarthgap 2.6.4 unsigned integer overflow guard while - removing only the redundant new_connector scope. - -(cherry picked from commit 08baa7ef9d168b99094249998fd78f8d190526e5) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 22 ++++++++++------------ - 1 file changed, 10 insertions(+), 12 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 3afe2884..df8331d5 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5945,20 +5945,18 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - case XML_ROLE_GROUP_OPEN: - if (parser->m_prologState.level >= parser->m_groupSize) { - if (parser->m_groupSize) { -- { -- /* Detect and prevent integer overflow */ -- if (parser->m_groupSize > (unsigned int)(-1) / 2u) { -- return XML_ERROR_NO_MEMORY; -- } -+ /* Detect and prevent integer overflow */ -+ if (parser->m_groupSize > (unsigned int)(-1) / 2u) { -+ return XML_ERROR_NO_MEMORY; -+ } - -- char *const new_connector = REALLOC( -- parser, parser->m_groupConnector, parser->m_groupSize *= 2); -- if (new_connector == NULL) { -- parser->m_groupSize /= 2; -- return XML_ERROR_NO_MEMORY; -- } -- parser->m_groupConnector = new_connector; -+ char *const new_connector = REALLOC(parser, parser->m_groupConnector, -+ parser->m_groupSize *= 2); -+ if (new_connector == NULL) { -+ parser->m_groupSize /= 2; -+ return XML_ERROR_NO_MEMORY; - } -+ parser->m_groupConnector = new_connector; - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); - if (! parser->m_groupConnector) { diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch deleted file mode 100644 index 8c9860c6e67..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch +++ /dev/null @@ -1,81 +0,0 @@ -From b689559597116ee75a633453e2f7177c8541b04e Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Wed, 20 May 2026 12:12:10 +0200 -Subject: [PATCH 01/17] lib: Protect function `storeAtts` from signed integer - overflow - -CVE: CVE-2026-56403 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648] - -Backport Changes: -- Adapt storeAtts to the Scarthgap 2.6.4 loop and URI allocation - logic while preserving the upstream overflow checks. - -(cherry picked from commit 12dc6d8d3d65f79471a94d8565f6bf1cf245f648) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 30 ++++++++++++++++++++---------- - 1 file changed, 20 insertions(+), 10 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 9bc67f38..df92a3ca 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -4226,26 +4226,32 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - return XML_ERROR_NONE; - prefixLen = 0; - if (parser->m_ns_triplets && binding->prefix->name) { -- for (; binding->prefix->name[prefixLen++];) -- ; /* prefixLen includes null terminator */ -+ size_t candidateLen = 0; -+ for (; binding->prefix->name[candidateLen++];) -+ ; /* candidateLen includes null terminator */ -+ /* Detect and prevent integer overflow */ -+ if (candidateLen > INT_MAX) -+ return XML_ERROR_NO_MEMORY; -+ prefixLen = (int)candidateLen; - } - tagNamePtr->localPart = localPart; - tagNamePtr->uriLen = binding->uriLen; - tagNamePtr->prefix = binding->prefix->name; - tagNamePtr->prefixLen = prefixLen; -- for (i = 0; localPart[i++];) -- ; /* i includes null terminator */ -+ -+ size_t localPartLen = 0; -+ for (; localPart[localPartLen++];) -+ ; /* localPartLen includes null terminator */ - - /* Detect and prevent integer overflow */ -- if (binding->uriLen > INT_MAX - prefixLen -- || i > INT_MAX - (binding->uriLen + prefixLen)) { -+ if (localPartLen > INT_MAX || binding->uriLen > INT_MAX - prefixLen -+ || localPartLen > (size_t)INT_MAX - (binding->uriLen + prefixLen)) { - return XML_ERROR_NO_MEMORY; - } - -- n = i + binding->uriLen + prefixLen; -+ n = (int)localPartLen + binding->uriLen + prefixLen; - if (n > binding->uriAlloc) { - TAG *p; -- - /* Detect and prevent integer overflow */ - if (n > INT_MAX - EXPAND_SPARE) { - return XML_ERROR_NO_MEMORY; -@@ -4273,10 +4279,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - /* if m_namespaceSeparator != '\0' then uri includes it already */ - uri = binding->uri + binding->uriLen; -- memcpy(uri, localPart, i * sizeof(XML_Char)); -+ /* Detect and prevent integer overflow */ -+ if (localPartLen > SIZE_MAX / sizeof(XML_Char)) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ memcpy(uri, localPart, localPartLen * sizeof(XML_Char)); - /* we always have a namespace separator between localPart and prefix */ - if (prefixLen) { -- uri += i - 1; -+ uri += localPartLen - 1; - *uri = parser->m_namespaceSeparator; /* replace null terminator */ - memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char)); - } diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch deleted file mode 100644 index 88cb66c5469..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 2855ce68a1ce9732267c06734427930364ab66c1 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 22 May 2026 00:43:52 +0200 -Subject: [PATCH 02/17] xmlwf: Protect function `xcsdup` from signed integer - overflow - -CVE: CVE-2026-56403 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15] - -Backport Changes: -- Add stdint.h and convert count and numBytes to size_t because - Scarthgap 2.6.4 lacks these upstream prerequisites. - -(cherry picked from commit 147c8f36d6277d5c6011c098370a8362aed47b15) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index fd4fc3f8..7bbdb303 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -45,6 +45,7 @@ - - #include - #include -+#include - #include - #include - #include -@@ -304,13 +305,18 @@ processingInstruction(void *userData, const XML_Char *target, - static XML_Char * - xcsdup(const XML_Char *s) { - XML_Char *result; -- int count = 0; -- int numBytes; -+ size_t count = 0; -+ size_t numBytes; - - /* Get the length of the string, including terminator */ - while (s[count++] != 0) { - /* Do nothing */ - } -+ -+ // Detect and prevent integer overflow -+ if (count > SIZE_MAX / sizeof(XML_Char)) -+ return NULL; -+ - numBytes = count * sizeof(XML_Char); - result = malloc(numBytes); - if (result == NULL) diff --git a/meta/recipes-core/expat/expat/CVE-2026-56404.patch b/meta/recipes-core/expat/expat/CVE-2026-56404.patch deleted file mode 100644 index bd5f99742b7..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56404.patch +++ /dev/null @@ -1,45 +0,0 @@ -From d8e09a54fa9214e64d8e73057ca6918d08857022 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Thu, 28 May 2026 12:44:11 +0530 -Subject: [PATCH 04/17] lib: protect function addBinding from signed integer - overflow - -CVE: CVE-2026-56404 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164] - -(cherry picked from commit babfc48090977cbf7be24b2c48f6053dca75c164) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 12bbe23e..9d21e136 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -4456,6 +4456,10 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - } - - for (len = 0; uri[len]; len++) { -+ /* Detect and prevent signed integer overflow */ -+ if (len == INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len])) - isXML = XML_FALSE; - -@@ -4496,8 +4500,13 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - if (isXMLNS) - return XML_ERROR_RESERVED_NAMESPACE_URI; - -- if (parser->m_namespaceSeparator) -+ if (parser->m_namespaceSeparator) { -+ /* Detect and prevent signed integer overflow */ -+ if (len == INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - len++; -+ } - if (parser->m_freeBindingList) { - b = parser->m_freeBindingList; - if (len > b->uriAlloc) { diff --git a/meta/recipes-core/expat/expat/CVE-2026-56405.patch b/meta/recipes-core/expat/expat/CVE-2026-56405.patch deleted file mode 100644 index 67595173414..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56405.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 49ba5bdafa7aaee9b77a32ffaa798e625bd46e73 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Fri, 29 May 2026 11:45:17 +0530 -Subject: [PATCH 05/17] lib: Protect function getAttributeId from signed - integer overflow - -CVE: CVE-2026-56405 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0] - -(cherry picked from commit 2c6c42d33689f6b266a5267b639e03cde17e53c0) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 9d21e136..80ad0811 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -7312,6 +7312,10 @@ getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start, - } else { - int i; - for (i = 0; name[i]; i++) { -+ /* Detect and prevent signed integer overflow */ -+ if (i == INT_MAX) { -+ return NULL; -+ } - /* attributes without prefix are *not* in the default namespace */ - if (name[i] == XML_T(ASCII_COLON)) { - int j; diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch b/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch deleted file mode 100644 index d749ef06089..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch +++ /dev/null @@ -1,59 +0,0 @@ -From 9aafa47798332618f08af046c3471de1f3a9e031 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Wed, 27 May 2026 17:01:44 -0700 -Subject: [PATCH 08/17] lib: Make `XML_Index` overflow check more intuitive - -In fixing a bug, 7e5b71b748491b6e459e5c9a1d090820f94544d8 introduced a magic number `2` in this code that made it difficult to understand the rationale for this overflow check without reading the commit log. This change introduces some more readable constants to use in these situations. - -CVE: CVE-2026-56406 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd] - -Backport Changes: -- Adapt include context for Scarthgap 2.6.4 and expose SIZE_MAX in - the existing stdint.h comment. - -(cherry picked from commit 252ff1a307b1490ce0f430632791e7e52d7e43fd) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 12 +++++++++--- - 1 file changed, 9 insertions(+), 3 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 80ad0811..5bf706b0 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -97,10 +97,10 @@ - #include - #include /* memset(), memcpy() */ - #include --#include /* UINT_MAX */ -+#include /* INT_MAX, LLONG_MAX, LONG_MAX, UINT_MAX */ - #include /* fprintf */ - #include /* getenv, rand_s */ --#include /* uintptr_t */ -+#include /* SIZE_MAX, uintptr_t */ - #include /* isnan */ - - #ifdef _WIN32 -@@ -211,6 +211,12 @@ typedef char ICHAR; - - #endif - -+#ifdef XML_LARGE_SIZE -+# define XML_INDEX_MAX LLONG_MAX -+#else -+# define XML_INDEX_MAX LONG_MAX -+#endif -+ - /* Round up n to be a multiple of sz, where sz is a power of 2. */ - #define ROUND_UP(n, sz) (((n) + ((sz) - 1)) & ~((sz) - 1)) - -@@ -2360,7 +2366,7 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { - int nLeftOver; - enum XML_Status result; - /* Detect overflow (a+b > MAX <==> b > MAX-a) */ -- if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) { -+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { - parser->m_errorCode = XML_ERROR_NO_MEMORY; - parser->m_eventPtr = parser->m_eventEndPtr = NULL; - parser->m_processor = errorProcessor; diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406.patch b/meta/recipes-core/expat/expat/CVE-2026-56406.patch deleted file mode 100644 index 56de9e41249..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56406.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 5db699faa6af1c66e96abec5dbd1908efd64ef70 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 31 May 2026 15:18:58 +0200 -Subject: [PATCH 09/17] lib: Copy overflow check from `XML_Parse` to - `XML_ParseBuffer` - -CVE: CVE-2026-56406 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d] - -(cherry picked from commit 99d8454fdf900a6d00c2a52748e6c0eeb507574d) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 8 ++++++++ - 1 file changed, 8 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 5bf706b0..9f07b860 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -2483,6 +2483,14 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) { - parser->m_parsingStatus.parsing = XML_PARSING; - } - -+ // Detect and avoid integer overflow -+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { -+ parser->m_errorCode = XML_ERROR_NO_MEMORY; -+ parser->m_eventPtr = parser->m_eventEndPtr = NULL; -+ parser->m_processor = errorProcessor; -+ return XML_STATUS_ERROR; -+ } -+ - start = parser->m_bufferPtr; - parser->m_positionPtr = start; - parser->m_bufferEnd += len; diff --git a/meta/recipes-core/expat/expat/CVE-2026-56407.patch b/meta/recipes-core/expat/expat/CVE-2026-56407.patch deleted file mode 100644 index 498f93d5b93..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56407.patch +++ /dev/null @@ -1,41 +0,0 @@ -From d1cd2bd7da8ed830e9432660616e9b4831df959a Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Tue, 2 Jun 2026 11:59:01 +0530 -Subject: [PATCH 12/17] cap entity textLen against signed integer overflow - -CVE: CVE-2026-56407 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13] - -(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 9f07b860..8439dc0e 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5655,6 +5655,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar, - XML_ACCOUNT_NONE); - if (parser->m_declEntity) { -+ /* Detect and prevent signed integer overflow */ -+ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool); - parser->m_declEntity->textLen - = (int)(poolLength(&dtd->entityValuePool)); -@@ -7076,6 +7080,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) { - return XML_ERROR_NO_MEMORY; - } - -+ /* Detect and prevent signed integer overflow */ -+ if ((size_t)poolLength(pool) > (size_t)INT_MAX) { -+ poolDiscard(pool); -+ return XML_ERROR_NO_MEMORY; -+ } - entity->textPtr = poolStart(pool); - entity->textLen = (int)(poolLength(pool)); - poolFinish(pool); diff --git a/meta/recipes-core/expat/expat/CVE-2026-56408.patch b/meta/recipes-core/expat/expat/CVE-2026-56408.patch deleted file mode 100644 index 8e066565ba2..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56408.patch +++ /dev/null @@ -1,29 +0,0 @@ -From c1ad5610cf060c6374d8f8d3b39163edd7053321 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Thu, 23 Apr 2026 10:31:45 +0200 -Subject: [PATCH 03/17] lib: Waterproof `copyString` from integer overflow - -CVE: CVE-2026-56408 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817] - -(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index df92a3ca..12bbe23e 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -8489,6 +8489,10 @@ copyString(const XML_Char *s, XML_Parser parser) { - /* Include the terminator */ - charsRequired++; - -+ /* Detect and prevent integer overflow */ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) -+ return NULL; -+ - /* Now allocate space for the copy */ - result = MALLOC(parser, charsRequired * sizeof(XML_Char)); - if (result == NULL) diff --git a/meta/recipes-core/expat/expat/CVE-2026-56409.patch b/meta/recipes-core/expat/expat/CVE-2026-56409.patch deleted file mode 100644 index b0aac260739..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56409.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 174ce18f2a283be634d830a5259bd07142635fe8 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Mon, 1 Jun 2026 11:53:19 +0530 -Subject: [PATCH 10/17] xmlwf: protect output path join from integer overflow - -CVE: CVE-2026-56409 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e] - -Backport Changes: -- Adapt the allocation hunk to the explicit XML_Char cast used by - Scarthgap 2.6.4; overflow checks are unchanged. - -(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++-- - 1 file changed, 20 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index 7bbdb303..bd5f68a4 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -1240,8 +1240,26 @@ tmain(int argc, XML_Char **argv) { - } - #endif - } -- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2) -- * sizeof(XML_Char)); -+ const size_t outputDirLen = tcslen(outputDir); -+ const size_t fileLen = tcslen(file); -+ -+ /* Detect and prevent integer overflow in the addition (without -+ risking underflow) and the multiplication, mirroring the guards -+ in xcsdup() and resolveSystemId() */ -+ if (outputDirLen > SIZE_MAX - fileLen -+ || outputDirLen > SIZE_MAX - fileLen - 2) { -+ tperror(T("Could not allocate memory")); -+ exit(XMLWF_EXIT_INTERNAL_ERROR); -+ } -+ -+ const size_t charsRequired = outputDirLen + fileLen + 2; -+ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) { -+ tperror(T("Could not allocate memory")); -+ exit(XMLWF_EXIT_INTERNAL_ERROR); -+ } -+ -+ outName = malloc(charsRequired * sizeof(XML_Char)); - if (! outName) { - tperror(T("Could not allocate memory")); - exit(XMLWF_EXIT_INTERNAL_ERROR); diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch deleted file mode 100644 index 6f906e682d3..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch +++ /dev/null @@ -1,46 +0,0 @@ -From b454931c42290c9f0faf2a01f9634d82db636bac Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Fri, 29 May 2026 17:51:25 +0530 -Subject: [PATCH 06/17] xmlwf: protect resolveSystemId from integer overflow - -CVE: CVE-2026-56410 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347] - -Backport Changes: -- Adapt the allocation hunk to Scarthgap 2.6.4's explicit cast and - include stdint.h so SIZE_MAX is available. - -(cherry picked from commit deeb97f7c88d17a16b0ea2521a13733abc283347) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlfile.c | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c -index 9c4f7f8d..ad691b12 100644 ---- a/expat/xmlwf/xmlfile.c -+++ b/expat/xmlwf/xmlfile.c -@@ -41,6 +41,7 @@ - #include "expat_config.h" - - #include -+#include - #include - #include - #include -@@ -130,8 +131,13 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, - #endif - ) - return systemId; -- *toFree = (XML_Char *)malloc((tcslen(base) + tcslen(systemId) + 2) -- * sizeof(XML_Char)); -+ const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; -+ -+ /* Detect and prevent integer overflow */ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) -+ return systemId; -+ -+ *toFree = malloc(charsRequired * sizeof(XML_Char)); - if (! *toFree) - return systemId; - tcscpy(*toFree, base); diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch deleted file mode 100644 index 148592ba9bc..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 7e6230212ddc4ea74115218fdbe5717e8e1c0f2b Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Sat, 30 May 2026 11:28:51 +0530 -Subject: [PATCH 07/17] xmlwf: guard each operator in resolveSystemId length - sum - -CVE: CVE-2026-56410 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea] - -(cherry picked from commit cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlfile.c | 12 ++++++++++-- - 1 file changed, 10 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c -index ad691b12..4d2e3220 100644 ---- a/expat/xmlwf/xmlfile.c -+++ b/expat/xmlwf/xmlfile.c -@@ -131,9 +131,17 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, - #endif - ) - return systemId; -- const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; -+ const size_t baseLen = tcslen(base); -+ const size_t systemIdLen = tcslen(systemId); - -- /* Detect and prevent integer overflow */ -+ /* Detect and prevent integer overflow in the addition (without risking -+ underflow) */ -+ if (baseLen > SIZE_MAX - systemIdLen || baseLen > SIZE_MAX - systemIdLen - 2) -+ return systemId; -+ -+ const size_t charsRequired = baseLen + systemIdLen + 2; -+ -+ /* Detect and prevent integer overflow in the multiplication */ - if (charsRequired > SIZE_MAX / sizeof(XML_Char)) - return systemId; - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56411.patch b/meta/recipes-core/expat/expat/CVE-2026-56411.patch deleted file mode 100644 index c6dd601f202..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56411.patch +++ /dev/null @@ -1,50 +0,0 @@ -From 5e696e78f8c4a709c4f774973b142e57090c4364 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Tue, 2 Jun 2026 13:13:34 +0530 -Subject: [PATCH 11/17] xmlwf: protect notation list allocation from integer - overflow - -CVE: CVE-2026-56411 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5] - -Backport Changes: -- Use Scarthgap 2.6.4 freeNotations cleanup and return directly - because the newer shared cleanUp label is absent. - -(cherry picked from commit 528a4e5017e1bd3b48b689fd0c131df940ae3ea5) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 12 ++++++++++-- - 1 file changed, 10 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index bd5f68a4..6a3d31b7 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -387,9 +387,9 @@ static void XMLCALL - endDoctypeDecl(void *userData) { - XmlwfUserData *data = (XmlwfUserData *)userData; - NotationList **notations; -- int notationCount = 0; -+ size_t notationCount = 0; - NotationList *p; -- int i; -+ size_t i; - - /* How many notations do we have? */ - for (p = data->notationListHead; p != NULL; p = p->next) -@@ -401,6 +401,14 @@ endDoctypeDecl(void *userData) { - return; - } - -+ /* Detect and prevent integer overflow in the multiplication, mirroring -+ the guards in xcsdup() and resolveSystemId() */ -+ if (notationCount > SIZE_MAX / sizeof(NotationList *)) { -+ fprintf(stderr, "Unable to sort notations"); -+ freeNotations(data); -+ return; -+ } -+ - notations = malloc(notationCount * sizeof(NotationList *)); - if (notations == NULL) { - fprintf(stderr, "Unable to sort notations"); diff --git a/meta/recipes-core/expat/expat_2.6.4.bb b/meta/recipes-core/expat/expat_2.6.4.bb deleted file mode 100644 index 93f0622373e..00000000000 --- a/meta/recipes-core/expat/expat_2.6.4.bb +++ /dev/null @@ -1,104 +0,0 @@ -SUMMARY = "A stream-oriented XML parser library" -DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)" -HOMEPAGE = "https://github.com/libexpat/libexpat" -SECTION = "libs" -LICENSE = "MIT" - -LIC_FILES_CHKSUM = "file://COPYING;md5=7b3b078238d0901d3b339289117cb7fb" - -VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}" - -SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ - file://run-ptest \ - file://0001-tests-Cover-indirect-entity-recursion.patch;striplevel=2 \ - file://CVE-2024-8176-01.patch;striplevel=2 \ - file://CVE-2024-8176-02.patch;striplevel=2 \ - file://CVE-2024-8176-03.patch \ - file://CVE-2024-8176-04.patch \ - file://CVE-2024-8176-05.patch \ - file://CVE-2025-59375-00.patch \ - file://CVE-2025-59375-01.patch \ - file://CVE-2025-59375-02.patch \ - file://CVE-2025-59375-03.patch \ - file://CVE-2025-59375-04.patch \ - file://CVE-2025-59375-05.patch \ - file://CVE-2025-59375-06.patch \ - file://CVE-2025-59375-07.patch \ - file://CVE-2025-59375-08.patch \ - file://CVE-2025-59375-09.patch \ - file://CVE-2025-59375-10.patch \ - file://CVE-2025-59375-11.patch \ - file://CVE-2025-59375-12.patch \ - file://CVE-2025-59375-13.patch \ - file://CVE-2025-59375-14.patch \ - file://CVE-2025-59375-15.patch \ - file://CVE-2025-59375-16.patch \ - file://CVE-2025-59375-17.patch \ - file://CVE-2025-59375-18.patch \ - file://CVE-2025-59375-19.patch \ - file://CVE-2025-59375-20.patch \ - file://CVE-2025-59375-21.patch \ - file://CVE-2025-59375-22.patch \ - file://CVE-2025-59375-23.patch \ - file://CVE-2025-59375-24.patch \ - file://CVE-2026-24515-01.patch \ - file://CVE-2026-24515-02.patch \ - file://CVE-2026-25210-01.patch \ - file://CVE-2026-25210-02.patch \ - file://CVE-2026-25210-03.patch \ - file://CVE-2026-32776.patch \ - file://CVE-2026-32777-01.patch \ - file://CVE-2026-32777-02.patch \ - file://CVE-2026-32778-01.patch \ - file://CVE-2026-32778-02.patch \ - file://CVE-2026-41080-01.patch \ - file://CVE-2026-41080-02.patch \ - file://CVE-2026-41080-03.patch \ - file://CVE-2026-45186-01.patch \ - file://CVE-2026-45186-02.patch \ - file://CVE-2026-45186-03.patch \ - file://CVE-2026-45186-04.patch \ - file://CVE-2026-45186-05.patch \ - file://CVE-2026-45186-06.patch \ - file://CVE-2026-45186-07.patch \ - file://CVE-2026-56403_p1.patch;striplevel=2 \ - file://CVE-2026-56403_p2.patch;striplevel=2 \ - file://CVE-2026-56408.patch;striplevel=2 \ - file://CVE-2026-56404.patch;striplevel=2 \ - file://CVE-2026-56405.patch;striplevel=2 \ - file://CVE-2026-56410_p1.patch;striplevel=2 \ - file://CVE-2026-56410_p2.patch;striplevel=2 \ - file://CVE-2026-56406-dependent.patch;striplevel=2 \ - file://CVE-2026-56406.patch;striplevel=2 \ - file://CVE-2026-56409.patch;striplevel=2 \ - file://CVE-2026-56411.patch;striplevel=2 \ - file://CVE-2026-56407.patch;striplevel=2 \ - file://CVE-2026-56132_p1.patch;striplevel=2 \ - file://CVE-2026-56132_p2.patch;striplevel=2 \ - file://CVE-2026-56132_p3.patch;striplevel=2 \ - file://CVE-2026-56132_p4.patch;striplevel=2 \ - file://CVE-2026-56132_p5.patch;striplevel=2 \ - " - -GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" -UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P .+)" - -SRC_URI[sha256sum] = "8dc480b796163d4436e6f1352e71800a774f73dbae213f1860b60607d2a83ada" - -EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF" - -RDEPENDS:${PN}-ptest += "bash" - -inherit cmake lib_package ptest github-releases - -do_install_ptest:class-target() { - install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH} - install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH} -} - -BBCLASSEXTEND += "native nativesdk" - -CVE_PRODUCT = "expat libexpat" - -CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \ -EXPAT_CHAR_TYPE:STRING=char is for Yocto builds" diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb new file mode 100644 index 00000000000..79e8c15227a --- /dev/null +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -0,0 +1,33 @@ +SUMMARY = "A stream-oriented XML parser library" +DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)" +HOMEPAGE = "https://github.com/libexpat/libexpat" +SECTION = "libs" +LICENSE = "MIT" + +LIC_FILES_CHKSUM = "file://COPYING;md5=f4fedd6116da0e171f7cb4d2923d7ac2" + +VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}" + +SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ + file://run-ptest \ + " + +GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" +UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P .+)" + +SRC_URI[sha256sum] = "b4cc2483927d5e90bf8c40b44a6b95b368b42a8a96e25883fce188b48a92b670" + +EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF" + +RDEPENDS:${PN}-ptest += "bash" + +inherit cmake lib_package ptest github-releases + +do_install_ptest:class-target() { + install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH} + install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH} +} + +BBCLASSEXTEND += "native nativesdk" + +CVE_PRODUCT = "expat libexpat" From patchwork Sat Oct 3 21:42:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99946 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 650A3CA5FF0 for ; Sat, 3 Oct 2026 21:43:20 +0000 (UTC) Received: from mail-wr2-f34.google.com (mail-wr2-f34.google.com [74.125.225.98]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.13725.1791063795027870387 for ; Sat, 03 Oct 2026 14:43:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=p0Wd+y94; spf=pass (domain: smile.fr, ip: 74.125.225.98, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f34.google.com with SMTP id ffacd0b85a97d-48af4663da5so541626f8f.3 for ; Sat, 03 Oct 2026 14:43:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063793; x=1791668593; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FqcsiLC3G539KkSiK7f0LWqzz24Zu+4Qy7Q4HaoqEvE=; b=p0Wd+y94HOKqkjBRdLXa4frWrKqgB3NVZb9MvKpMbOm7ccKgjpqh9/szUlP4veQngu Ar01/W1c7cVxOnZoPAN1crKirbVEw1EJrPIp7spJpxRcXYuZPXBr366Fk9KYbazjsjmB fREiluQjdmcVQyty/ohoUMkOTJY5hU57PxR20= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063793; x=1791668593; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FqcsiLC3G539KkSiK7f0LWqzz24Zu+4Qy7Q4HaoqEvE=; b=zFRNg2klp9PzqO+PktUVKwHgUzK4/QyDNSH0swV7BHSj9KqgDvRD6siN7/E/AAWGvu cvqnTSNN9XVwnme3SIBJ+hPuEzQlE5dmCe2iewR/vXfqhVkLPHs2Ea01HnI9GIAuwcA8 Qkh7DXrsqaiWFKL1T4BvkSbHLRkfUQBulQ5cfGeYqqPdkftTE4TYUKQcT8gpcmP8hLXZ m0cHsxziVuKtlu6MYmbw62DDhgVg3RLcJUNE6IlJGHvs9QrdPHTaoj7FyeKxcOWZ2CzY 3lYpRcYlog9LogEoNoPx2Ru/L9vonl+iJEoPwCKwIvDXgchpdPwqgFzH3wVE3/+l2Cqq hQiA== X-Gm-Message-State: AFq9FYIiMXKo8+/G2VM0sagLtlEFZYavdEHTvsPK0cZ+twvAS1RUQ5rc BrNuBU0hOQS29ByMercKCzxw+KVaBG8S3bvwndJ5oWRD9/fwGXnNUohExBv6wfDtN26oPVdKqvM QXQpxWww= X-Gm-Gg: AYBFou34rq/2p0hnfhk+AqmHwkFOLtJEddlRQZIxdexjIjrEyokPL8LMcsr7vfNSMAS 734j8cYjo8Frwf6lt9hETeLPj8gUBRRopLp41wT9QxSvWF0JUW9xvTxdjEOT2MfSxJzZ9RWCDtY lSq7HToQp8pnt+7zHuulCWFSG2P1L1Lf7HHVb3Qbd0fiNwrdE2wd5bQ/SRJbThsDTsjr6V0i/Vc PKFS8fTPhzt3ZtM3C71OTcUpoA3ce2UfHpyySIlP/4FlEswqt1PNbOU2N/P6hRMIPX+niKY6kLk l5rGZycvrzgKx4YJJiVTzBmSQGB7nJtsi05ObAsho9faHioWk/9NNSM/T+SY/xTGIw7AsbMRvdv 4yaTOHMbzwKviEJkHdcnau5W9bB6veLeMLaYk0HPD24qp6KtZkrYoVUo/1BafAv93ES8osU8Fs0 xBoRhVE7HZEJd4fIadoYvFTEnGn4Vn2VFbJU3xEiCfjBYYr20eaVIfrUEOSioge54afsaOR5g5l AK9zR3IMzrNpQDIGy0CMhuSDVQyTLjbDkY9wkc1ROXhs8KTTjYKEw+zSqYukd3s61G79Uh681LH 9Jw= X-Received: by 2002:a05:6000:1862:b0:48b:5083:96ae with SMTP id ffacd0b85a97d-48b50839985mr11250983f8f.15.1791063792981; Sat, 03 Oct 2026 14:43:12 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 3/8] vim: Fix CVE-2026-28417 regressions Date: Sat, 3 Oct 2026 23:42:11 +0200 Message-ID: <1505d5181d610b221fd75d413d884172b46b7860.1791061402.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247180 From: Devansh Patel The older Vim patch 9.2.0073 fixed CVE-2026-28417 by tightening netrw hostname validation. That CVE fix requires two regression patches because it rejects valid hostnames that include an optional port or an underscore. Backport Vim patches 9.2.0089 and 9.2.0553 in that order. They restore optional-port and underscore handling while retaining the stricter validation introduced by the original CVE fix. Scarthgap's Vim 9.1.1683 source does not contain test_plugin_netrw.vim, so the upstream test hunks are omitted. The src/version.c hunks are also omitted because this backport does not change the recipe version or Vim's upstream patch-number table. [1] https://github.com/vim/vim/commit/79348dbbc09332130f4c86045e1541d68514fcc1 [2] https://github.com/vim/vim/commit/a6198523fb28a50d96945458792cdb4787d3cdda [3] https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11 [4] https://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../files/CVE-2026-28417-regression_p1.patch | 78 +++++++++++++++++++ .../files/CVE-2026-28417-regression_p2.patch | 53 +++++++++++++ meta/recipes-support/vim/vim.inc | 2 + 3 files changed, 133 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch create mode 100644 meta/recipes-support/vim/files/CVE-2026-28417-regression_p2.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch b/meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch new file mode 100644 index 00000000000..0289614bfe5 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch @@ -0,0 +1,78 @@ +From a6e9906380af2b51ea4b77234ef77b14cc712f2c Mon Sep 17 00:00:00 2001 +From: Miguel Barro +Date: Sun, 1 Mar 2026 19:32:29 +0000 +Subject: [PATCH] patch 9.2.0089: netrw: does not take port into account in + hostname validation + +Problem: netrw: does not take port into account in hostname validation + (after v9.2.0073) +Solution: Update hostname validation check and test for an optional port + number (Miguel Barro) + +closes: #19533 + +CVE: CVE-2026-28417 +Upstream-Status: Backport [https://github.com/vim/vim/commit/a6198523fb28a50d96945458792cdb4787d3cdda] + +Backport Changes: +- Omitted src/testdir/test_plugin_netrw.vim because this test file is not + present in the Vim 9.1.1683 source used by Scarthgap. +- Omitted src/version.c because this backport does not change the recipe's + Vim version or its upstream patch-number table. + +Signed-off-by: Miguel Barro +Signed-off-by: Christian Brabandt +(cherry picked from commit a6198523fb28a50d96945458792cdb4787d3cdda) +Signed-off-by: Devansh Patel +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 18 +++++++++++------- + 1 file changed, 11 insertions(+), 7 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 1b790d250..69eababf1 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -6,6 +6,7 @@ + " 2025 Aug 07 by Vim Project (netrw#BrowseX() distinguishes remote files #17794) + " 2025 Aug 22 by Vim Project netrw#Explore handle terminal correctly #18069 + " 2026 Feb 27 by Vim Project Make the hostname validation more strict ++" 2026 Mar 01 by Vim Project include portnumber in hostname checking #19533 + " Copyright: Copyright (C) 2016 Charles E. Campbell {{{1 + " Permission is hereby granted to use and distribute this code, + " with or without modifications, provided that this copyright +@@ -2575,7 +2576,8 @@ endfunction + + " s:NetrwValidateHostname: Validate that the hostname is valid {{{2 + " Input: +-" hostname, may include an optional username, e.g. user@hostname ++" hostname, may include an optional username and port number, e.g. ++" user@hostname:port + " allow a alphanumeric hostname or an IPv(4/6) address + " Output: + " true if g:netrw_machine is valid according to RFC1123 #Section 2 +@@ -2584,17 +2586,19 @@ function s:NetrwValidateHostname(hostname) + let user_pat = '\%([a-zA-Z0-9._-]\+@\)\?' + " Hostname: 1-64 chars, alphanumeric/dots/hyphens. + " No underscores. No leading/trailing dots/hyphens. +- let host_pat = '[a-zA-Z0-9]\%([-a-zA-Z0-9.]{,62}[a-zA-Z0-9]\)\?$' ++ let host_pat = '[a-zA-Z0-9]\%([-a-zA-Z0-9.]\{0,62}[a-zA-Z0-9]\)\?' ++ " Port: 16 bit unsigned integer ++ let port_pat = '\%(:\d\{1,5\}\)\?$' + + " IPv4: 1-3 digits separated by dots +- let ipv4_pat = '\%(\d\{1,3}\.\)\{3\}\d\{1,3\}$' ++ let ipv4_pat = '\%(\d\{1,3}\.\)\{3\}\d\{1,3\}' + + " IPv6: Hex, colons, and optional brackets +- let ipv6_pat = '\[\?\%([a-fA-F0-9:]\{2,}\)\+\]\?$' ++ let ipv6_pat = '\[\?\%([a-fA-F0-9:]\{2,}\)\+\]\?' + +- return a:hostname =~? '^'.user_pat.host_pat || +- \ a:hostname =~? '^'.user_pat.ipv4_pat || +- \ a:hostname =~? '^'.user_pat.ipv6_pat ++ return a:hostname =~? '^'.user_pat.host_pat.port_pat || ++ \ a:hostname =~? '^'.user_pat.ipv4_pat.port_pat || ++ \ a:hostname =~? '^'.user_pat.ipv6_pat.port_pat + endfunction + + " NetUserPass: set username and password for subsequent ftp transfer {{{2 diff --git a/meta/recipes-support/vim/files/CVE-2026-28417-regression_p2.patch b/meta/recipes-support/vim/files/CVE-2026-28417-regression_p2.patch new file mode 100644 index 00000000000..e33c64ac91e --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-28417-regression_p2.patch @@ -0,0 +1,53 @@ +From 047b5dfc3213a42d7db960569f53b37e332f3c76 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 28 May 2026 20:53:53 +0000 +Subject: [PATCH] patch 9.2.0553: runtime(netrw): netrw rejects hostnames + containing _ + +Problem: runtime(netrw): netrw rejects hostnames containing _ + (lilydjwg) +Solution: Relax the restriction and allow the underscore + +fixes: #20344 + +CVE: CVE-2026-28417 +Upstream-Status: Backport [https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11] + +Backport Changes: +- Preserved Scarthgap's multi-line netrw change history and appended the + upstream 2026 May 28 change instead of replacing it with a single date. +- Omitted src/testdir/test_plugin_netrw.vim because this test file is not + present in the Vim 9.1.1683 source used by Scarthgap. +- Omitted src/version.c because this backport does not change the recipe's + Vim version or its upstream patch-number table. + +Signed-off-by: Christian Brabandt +(cherry picked from commit 93d177cd2b69bac58fc51a5a514d7bc71e264b11) +Signed-off-by: Devansh Patel +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 69eababf1..58aecc81e 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -7,6 +7,7 @@ + " 2025 Aug 22 by Vim Project netrw#Explore handle terminal correctly #18069 + " 2026 Feb 27 by Vim Project Make the hostname validation more strict + " 2026 Mar 01 by Vim Project include portnumber in hostname checking #19533 ++" 2026 May 28 by Vim Project allow underscores in hostname checking #20344 + " Copyright: Copyright (C) 2016 Charles E. Campbell {{{1 + " Permission is hereby granted to use and distribute this code, + " with or without modifications, provided that this copyright +@@ -2585,8 +2586,8 @@ function s:NetrwValidateHostname(hostname) + " Username: + let user_pat = '\%([a-zA-Z0-9._-]\+@\)\?' + " Hostname: 1-64 chars, alphanumeric/dots/hyphens. +- " No underscores. No leading/trailing dots/hyphens. +- let host_pat = '[a-zA-Z0-9]\%([-a-zA-Z0-9.]\{0,62}[a-zA-Z0-9]\)\?' ++ " No leading/trailing dots/hyphens. ++ let host_pat = '[a-zA-Z0-9_]\%([-a-zA-Z0-9._]\{0,62}[a-zA-Z0-9_]\)\?' + " Port: 16 bit unsigned integer + let port_pat = '\%(:\d\{1,5\}\)\?$' + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 5a34c1fa35f..bd2ce2f6abb 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -30,6 +30,8 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-28421.patch \ file://CVE-2026-32249.patch \ file://CVE-2026-28417.patch \ + file://CVE-2026-28417-regression_p1.patch \ + file://CVE-2026-28417-regression_p2.patch \ file://CVE-2026-45130.patch \ file://CVE-2026-46483.patch \ file://CVE-2026-28420.patch \ From patchwork Sat Oct 3 21:42:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99947 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E8835CA5FF7 for ; Sat, 3 Oct 2026 21:43:20 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13635.1791063795112725309 for ; Sat, 03 Oct 2026 14:43:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=b1MXqglT; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-482f635552aso397326f8f.2 for ; Sat, 03 Oct 2026 14:43:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063793; x=1791668593; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bm5kTm/hHfED9+6LfUaz8gBiKKW9RArPGy4MyVeytEs=; b=b1MXqglTKXi7IPvEvFCOv7B0ib9LAm1zTrBaUfPgN8dfVeicWsedhn8S6bR9CcUFIf 4VJRgn7byExPIkVNh8lEo4113z7cl1dKXmINCFc7Mxaq4nMc165+Tf3SW3wCMLM7h4j8 Ce0v9ORXT0S3F9nbrCUWGZHMmNn+awNR1Q7e4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063793; x=1791668593; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bm5kTm/hHfED9+6LfUaz8gBiKKW9RArPGy4MyVeytEs=; b=ZKP3XAn0ksExy2V6No1my9vU//mRNCgRb3/D+VH1qF56S74AdOGEeX9h0R/LyDo9A3 6BhPR23YzuQD1dbN5dIb3E2rgrAcnaEVndnDjHAjGwfleGldC5gsr94zNU4lZSx8TnRl YE2Rx9CPgYR9bF3+yxNXEUB7LvyY/HaEsVoTxtcV86yDhSICQWT3OiumwyyqSKEldK+a u2skTY/zr6YdgrTB7tSCP6KXd1gdIs03h5QZzO/RVaZDv2vMGJXltwdJZf71QWhO1ORb U0PkNPrkfm9KCbCauG1Zb9Ys922JMc3XUGCHGDFzPhxRCnYbAJfDYmX8dFWqJ76lCqrO /KfA== X-Gm-Message-State: AFq9FYILIP3eTH9ZpDI1AYX0E+kXpQMBXwdmVwP1EmSq6PxEKo0FN94B Y8ZUsLSwe5hdvCs5fJ0LYW8H/qVd4C6D8L9oaCs/jlgjjjZB1sBbU6vK1QtpEBM/MgA7bYJdB8l 9v1K7Pw8= X-Gm-Gg: AYBFou3JYenubVM/T5NCR4rJ25521XPm0v/H7Fi2LOqXjIZlZ3BKOcV5+5fUTsg/9e3 8ISAgnhKajSj1TwwaEBQSGoQEpLQSfQZ+llbntk85zZaTm8eWHOAYdb6SgTm0hfKXLfe1oVGLHt j1lG8iYOryLiGlPFd56avqm5Mem7JPnYPAA/Z8CBgJPYA+cbq+r1i09CWjEc9+ubR6yvwTfrLWj pAp1LCQEiHFBzhphtO8yQ08S7Eg0EUXBvfM3+qofdU1bnRNjg9WUwlra3uVamjTEWfJOvd7vevX HppRu6TUFM4tyylNypNgIuy0wVZL2fi2nGTuvuMLumNoH4KtCSgosOvVXh0QMgiNyatEBHpjKSl DALSk+IZ2YwS7tpl6VW/U9LfFE4uVDxOYmWcW964KVSzf7PL8ZdXL9yQpFLXc8AXaxXeMNBOhKf yJ8+odCWIFz85v/BgGcVTywm08iC8qgxQ7nmjFPo13NWVSeT64IfYS8zctXjhIK3eowacDBkq3f Ld3aoaUWurCVCgtCDsi8y/KWMBmK+bzcPBXJKyAl3rLaXQrnTr6p0bn4dEnspVjVAA= X-Received: by 2002:a05:6000:401f:b0:48c:4485:3357 with SMTP id ffacd0b85a97d-48c448533f4mr8219401f8f.57.1791063793374; Sat, 03 Oct 2026 14:43:13 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 4/8] at-spi2-core: RDEPENDS on gsettings-desktop-schemas Date: Sat, 3 Oct 2026 23:42:12 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247179 From: Tim Orling at-spi-bus-launcher aborts when no compiled GSettings schema is present. This has been a fatal error since [1]: "26f75dc0 bus: Abort if we cannot get the default GSettingsSchemaSource" [1] https://gitlab.gnome.org/GNOME/at-spi2-core/-/commit/26f75dc00eb16ccec89561aefe15f4036d45b4ec Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit fb1b8a5338201a2163fcdb5d46550f46da716d8b) Signed-off-by: Yoann Congal --- meta/recipes-support/atk/at-spi2-core_2.50.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/atk/at-spi2-core_2.50.1.bb b/meta/recipes-support/atk/at-spi2-core_2.50.1.bb index 6996ebebcd6..e63eb13e724 100644 --- a/meta/recipes-support/atk/at-spi2-core_2.50.1.bb +++ b/meta/recipes-support/atk/at-spi2-core_2.50.1.bb @@ -25,6 +25,8 @@ DEPENDS = " \ PROVIDES += "atk at-spi2-atk" RPROVIDES:${PN} += "atk at-spi2-atk" +RDEPENDS:${PN}:append:class-target = " gsettings-desktop-schemas" + inherit meson gi-docgen gettext systemd pkgconfig upstream-version-is-even gobject-introspection EXTRA_OEMESON = " -Dsystemd_user_dir=${systemd_user_unitdir} \ From patchwork Sat Oct 3 21:42:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99944 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8F39ACA5FF4 for ; Sat, 3 Oct 2026 21:43:20 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13636.1791063795683132748 for ; Sat, 03 Oct 2026 14:43:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=HowcldC/; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48afe75f055so523476f8f.2 for ; Sat, 03 Oct 2026 14:43:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063794; x=1791668594; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=h37iQzfSjWKwnQrGz7g5jtJoX8Bm1TyhFG4iqN0tii0=; b=HowcldC/AWh9QVQyntGd2kaedv+C79GFSicfy9JiH9f1cjlHWJRIZ60foFk6834/+w Zh/fpcsRTGaoR77iReRotL8rTcaXuooiF2xwYUmwvsXoDLA7SS+8zNBT1jmJxkpM80Qf uuqsH2tM6WOK6je736mTIidamy77F5XWBqnDs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063794; x=1791668594; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=h37iQzfSjWKwnQrGz7g5jtJoX8Bm1TyhFG4iqN0tii0=; b=gfm12JWT/oKcSTr9uO3AMX096yhL+5SIRNbOr6VdwVT+E0TqVOTpSXzu/1aGMYzrXi ogZKnF+VCJlFCR/5GpCDC6iyY0caaC0HBqJp9YzCRTeCrnjT6Wt9G2hpsqZXwfzmO+yf nxp92ubyGdA6ZsxKZnRxeXmjSI6dkEhrJWPy2gto2jmt9haCi4VrwGhNG8MOlFqhgo23 TDXAqFVil6sDQTzmdW8d3UTLrA7+3Om8ixqEgjmoM3hztbYsmazjDErN+SN+aATX1nBb JVnewnAyT9vgyLK/+mv3q093yWoLHuGXn4r2kCY0EkJ1kvsYrIw8F8dY5RvezgUhFZ5E iHLw== X-Gm-Message-State: AFq9FYLNp1MxEYvrikI/pMbZ9BNwFA8K5E80bwNIyzyyhrvm182nTmjp pVcFdDT6w8Rvh4z1cJ1VbVQtbmAqJIhnIxnYjF9mRCfQmh9GkVKz0D2bjM4QOyJ2hvsXIfoprgr 5au4e89o= X-Gm-Gg: AYBFou3yH2SZXDhhY38gyP0LmUWb/5mOlJ4XBFREWk+qIf1ueSxI3G1QF/vEJB7rScg hAUdhR9VCv0hL8HC7y3EzebSyinrVrOemgKdObyxNBeWZinOwbUAlXU6X/d8la/9One+4FIpO4V dRdSM4qH3tQ7elvoj5Ij7SyxVW1+PFEBln/ZMb1CQcvm3x9EOVwJTtC0I6cSGENl3CDnpKrPqNw ZAx8EEVv8teZfSbCi9ZPb9sQlNfJ0sn3vDjy+2sQvci6XzL4kNU1vGKV4Fl68Q1Ao0k8K7K5uYT +tpz0OqGBvKXRafJOKB7LTY3GhcQKYYyfWWBw+JJ1jA629s+C14C1ru/pe1Qeht/MTseMUtOISq /1ST3R0KGiu1t2SPm4ZgOA044CByOApcdAikz2ZxF9yqvU9WVRZjzPaeBp3J7hG6jewF+e/AwQL 7oir1PWHZAWzB/bU3YOU3Fkps/fRY4+tWIMn6B3jNlRcMIVDiqZ+Jgt3o0yKOQooEhKcttjNX+6 cOkiOWTAeCpMcz5guoX2yHOYAbsqg26TdmHGIeWSykgIzpHBG015gqO0EHpeehzCxQ= X-Received: by 2002:a5d:64e9:0:b0:48a:fdb2:f2f4 with SMTP id ffacd0b85a97d-48c4801be23mr5904847f8f.57.1791063793974; Sat, 03 Oct 2026 14:43:13 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 5/8] sstate: Update mtime/atime for sig/siginfo files in sstate_checkhashes() Date: Sat, 3 Oct 2026 23:42:13 +0200 Message-ID: <2bd595a9d95fac64174a25759124a0aa3d0dd001.1791061402.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247181 From: Richard Purdie If we touch sstatefile, we should also touch any .sig/.siginfo file if we can. We try and keep them both updated with accesses so one isn't removed without the other and they stay consistent. [YOCTO #15289] Signed-off-by: Richard Purdie (cherry picked from commit cc07895f951140dbbffcf32d3eabf65788cc4d00) Signed-off-by: Yoann Congal --- meta/classes-global/sstate.bbclass | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/classes-global/sstate.bbclass b/meta/classes-global/sstate.bbclass index 567797305f2..f2fc4e99524 100644 --- a/meta/classes-global/sstate.bbclass +++ b/meta/classes-global/sstate.bbclass @@ -978,6 +978,9 @@ def sstate_checkhashes(sq_data, d, siginfo=False, currentcount=0, summary=True, if os.path.exists(sstatefile): oe.utils.touch(sstatefile) + for ext in ['.sig', '.siginfo']: + if os.path.exists(sstatefile + ext): + oe.utils.touch(sstatefile + ext) found.add(tid) bb.debug(2, "SState: Found valid sstate file %s" % sstatefile) else: From patchwork Sat Oct 3 21:42:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99943 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 11744CA5FEC for ; Sat, 3 Oct 2026 21:43:20 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13637.1791063796287690383 for ; Sat, 03 Oct 2026 14:43:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wKLKZOhn; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-48b03eb33b2so198690f8f.0 for ; Sat, 03 Oct 2026 14:43:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063794; x=1791668594; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NwOVOGPxUrzVvvK63WqePqdtkl63bk87TrAAj/yEeq0=; b=wKLKZOhncnVF4bBTWfDMnt+9upuqtjg91TQ/CkShjVYyw5gjBsKhaoSw2H3H+WKRea ovaezo+vYr9J194cz1RWQO7IBYy/BUy3v2fcolYDfmsGKhEIdt4a9vzGSfNb3mLh3A1A WNXuzjxQP8EUzqyfs1VNsFuKBXJo9jqtI+Qlg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063794; x=1791668594; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NwOVOGPxUrzVvvK63WqePqdtkl63bk87TrAAj/yEeq0=; b=JjFyKcIVjuxYdX7I45HokV73z9KOAxmM5aySiXTV1/abWa3748MtWmioNADTVcXV0d r/tjJq438FH8EnASPZKLb2CXqRgxmEuqYFKH1/U4Fi1XxFUy2OaSgTKLjOvsyvOatlco c5lmUt66t2bOK9m4wtNQuDxGBewcyF6oFsXFhjdw2gmGYBjHOKyvzOeVkpot9CVRPgnQ EinL/4krQ5EEOE2H5/ZU9YcQs/n56DuW//a9DJDKTOl4CB+uHYWabUeGtp3NRVtkzWXq omfsfH55BR0F79iOL5ft4BcxaXAxlr8hBzRdRJzgPv0Zrk3CXvCuq7bGEf+hEtE/Xvju CBQQ== X-Gm-Message-State: AFq9FYKHaHVNFECCbaD4rDnup3bkX15UEq3XWQkJp1HfMH14U+Koq3Df 97OuBFkWjpmjV2SBlcDr2l1YF0cXC8BmI7rmMJw4WYd59Mboc9SUIcradsp+plWzOyj1z0hTScz kGY5ecOI= X-Gm-Gg: AYBFou3Q8Ubm8ikYRbaJ1YatBPmpsCK3SvhbLh2YxsgNuD3Ek2I39sRAb/vvVxX2fEL H8kVta8ZdoAR8UTkk4hE/OW3KRnChpPbc9l8uZboxcTmVe3hOynlfHwSl1PogtMAeBl8pzksFtg rkZfqwrS0PLqITcIrNW/LjOxShM1CrOxKCYJw6SutI3AQMagb/teyQInQYtBpBPW/SxjV9t0YD5 /mtjXhGXP1BYvmj/RTqCgokVR4ZqWlMqICTiT/+8OD0zBfUM55we5tWKdCVoai4/hh+28u4C8XC slH0Fy4xIlGhlZLDisKNVX7Ku9B94GEMnnzCpp6ZBhE88/qH1JTuL0ZdaaN5rnC/5KAuev4VAFX Qu6zq8QFSABSHcNRmcpq98AHUfUitDFL9IFUIGqIF85ySBuT60jAxBhECOZVpNtwULkvWNYYzZs b7mO7xxw+KNYMPH1ZtwkNCDWTBR+ZhD9uwEvt8vEmruwhAmTPpQWURS20MGupKi/Fj2xI6W05LA 5ucsyGZ3RerLpZ9D2SWNFY3OQY1OVlS8CzWzNbYW8qdE+o653MGfB6Pns+DI71vMw8= X-Received: by 2002:a05:6000:22c9:b0:48b:469:b562 with SMTP id ffacd0b85a97d-48b126f0b7fmr11804260f8f.2.1791063794555; Sat, 03 Oct 2026 14:43:14 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 6/8] sstate: Update unpack touch code to be consistent Date: Sat, 3 Oct 2026 23:42:14 +0200 Message-ID: <147004ef60987039372c977e6c2f304a5414f39f.1791061402.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247182 From: Richard Purdie When we unpack sstate files, we want to update the mtime+atime of the sstate object and any sig/siginfo files, both for the files themselves and symlinks. The logic was getting a bit hard to follow and wasn't entirely consistent with only a time in some cases. Clean it up and be consistent for all the files. Signed-off-by: Richard Purdie (cherry picked from commit 5213ca88cbec4e86b50d8da1fe4c300ca8f5de17) Signed-off-by: Yoann Congal [YC: for [YOCTO #15289] ] --- meta/classes-global/sstate.bbclass | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/meta/classes-global/sstate.bbclass b/meta/classes-global/sstate.bbclass index f2fc4e99524..9d2125c398e 100644 --- a/meta/classes-global/sstate.bbclass +++ b/meta/classes-global/sstate.bbclass @@ -932,12 +932,13 @@ sstate_unpack_package () { fi tar -I "$ZSTD" -xvpf ${SSTATE_PKG} - # update .siginfo atime on local/NFS mirror if it is a symbolic link - [ ! -h ${SSTATE_PKG}.siginfo ] || [ ! -e ${SSTATE_PKG}.siginfo ] || touch -a ${SSTATE_PKG}.siginfo 2>/dev/null || true - # update each symbolic link instead of any referenced file - touch --no-dereference ${SSTATE_PKG} 2>/dev/null || true - [ ! -e ${SSTATE_PKG}.sig ] || touch --no-dereference ${SSTATE_PKG}.sig 2>/dev/null || true - [ ! -e ${SSTATE_PKG}.siginfo ] || touch --no-dereference ${SSTATE_PKG}.siginfo 2>/dev/null || true + + # Update both any file and any symlink pointing to the file for sigs as well as the file + for file in ${SSTATE_PKG} ${SSTATE_PKG}.sig ${SSTATE_PKG}.siginfo + do + [ ! -e $file ] || touch $file 2>/dev/null || true + [ ! -e $file ] || touch --no-dereference $file 2>/dev/null || true + done } BB_HASHCHECK_FUNCTION = "sstate_checkhashes" From patchwork Sat Oct 3 21:42:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99945 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8347CA5FF2 for ; Sat, 3 Oct 2026 21:43:20 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13638.1791063796714823771 for ; Sat, 03 Oct 2026 14:43:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SV503HaH; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48b02a2359aso234463f8f.0 for ; Sat, 03 Oct 2026 14:43:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063795; x=1791668595; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eefE7+d+3qkAlciloRcPj/XCNULTBH0KHfXblshVcMk=; b=SV503HaHOSFaNflAzTvCwKngdhlExBUUj+mZPQiUVNp4feyqOa6okqloKKqBMqPUwn fq9j9in5kbkLI+hN/DnyxQa2HdJ1Gj8wFmZnYNMybO6TUxmprEvilaK9szomhpAz6XKH 6EXNYb4hcn4ZyTZsUfL/2bcuDmZNIiEPDFQpk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063795; x=1791668595; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=eefE7+d+3qkAlciloRcPj/XCNULTBH0KHfXblshVcMk=; b=LyQWD4uAFH+QfrBt9qRmJrQnixVGeUeXQB9jJugtQqAXACzbtldtKolUdAJRSiRvDg 0CJ3iua1z4Joz20/ijN+nCBq8OJmbcxQv4uHSajg6sZ1JrPZA3F1DaxNShTDvNBYcnkT 3aZjeZ8N5qCaGFIpwvcawLuQ03p51KU215nApKSd7kz63ryrr544ilCEDhbIsf0we17m psZ27VHoQ8s1TIvpHlx2XAQuiKLlPpTbJfSIuWlDSsDWeMS+4gd2fmPJw5wjIhMbbqDB +bh9kMTFzUfRvvGM3p/fic2ajOtxakLoPjpJ1HQKJnRD5PYfnXMLhAViwPYc9rfPF46k Bgew== X-Gm-Message-State: AFq9FYLZ+nxOEFGg58NyJd9K8YsuO10fO5XLQlruVp5M/9+SowdIGmoF aoGY0VUbHaFu8u/BTYEmZf9/Ogs+8IQjX+N1pdj5lOeDQjvA9CBpJCUcNAM1B6C9AQ9Ny9+sfYR JC1R7lZY= X-Gm-Gg: AYBFou0yuSVQelM07LV+Cx82s9GT6/eV12Y4AE2ktCgIq3OgoxHHqzM7exNbyPjHHku uQyYQUcQ1h1Xm0/je70U8/NeJqnv9cfSg4zXgI+aJK3NJvCXng1RFhwJXa0afhBu0zKM8q7Nscu 3fIAtHHM8gA0WXhKKyoc+GZcXz2Y7GVXRgOUfujlzt7eFZfDX9cpG83wk4k7V66Z/6lcWGkOagw VEHWzR8xVI7lnpxB6KLde5KLbMbXFUE6F/kgmAvLlHHvlC6Jf8el/WryVHoeatcH2vOhzgsXiig mD4Xcu/CQYEnHnk9xDVrSclltbb84qFo1ALH6vTMhTBXTgZRxODPrKEsqnwBFl4v8H38W9qWiej a2uC27cJSn4HjQvhaVnBBxEa43SS5Kjfyj4iAwfTRRl795GY13V5X7MWIJwUKu5AyJIeziWnGVE WT66dYt8ZlMn7JTcYuEC3JSy9xDkvX8441ga6kRcRgFImzTlwoRZV2CTS3dr41I3DAYh3CmRFuG gQk7WKZbzFlukp6NPZeHJRu54gFswWuyjWvEe91xWGuQvg6wGLJfuDksZo8poz80gg= X-Received: by 2002:a05:6000:2086:b0:48c:54ec:ea3 with SMTP id ffacd0b85a97d-48c54ec1528mr478717f8f.13.1791063794982; Sat, 03 Oct 2026 14:43:14 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 7/8] python3-pyasn1: fix CVE-2026-30922 Date: Sat, 3 Oct 2026 23:42:15 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247183 From: Yogita Urade This patch applies upstream fix for CVE-2026-30922 as referenced in [2], using the upstream commit identified in [1]. [1] https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-30922 Signed-off-by: Yogita Urade Signed-off-by: Yoann Congal --- .../recipes-devtools/python/python-pyasn1.inc | 1 + .../python3-pyasn1/CVE-2026-30922.patch | 262 ++++++++++++++++++ 2 files changed, 263 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc index ae96f09fb1d..0fe5e70adfc 100644 --- a/meta/recipes-devtools/python/python-pyasn1.inc +++ b/meta/recipes-devtools/python/python-pyasn1.inc @@ -21,6 +21,7 @@ SRC_URI += " \ file://CVE-2026-23490.patch \ file://CVE-2026-59886.patch \ file://CVE-2026-59884.patch \ + file://CVE-2026-30922.patch \ " RDEPENDS:${PN}-ptest += " \ diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch new file mode 100644 index 00000000000..c7b6fe4bff5 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch @@ -0,0 +1,262 @@ +From bcab1fc8f72230ad7ee6d9612a5216cc556e2d0a Mon Sep 17 00:00:00 2001 +From: Simon Pichugin +Date: Mon, 16 Mar 2026 17:23:11 -0700 +Subject: [PATCH] Merge commit from fork + +CVE: CVE-2026-30922 +Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0] + +(cherry picked from commit 25ad481c19fdb006e20485ef3fc2e5b3eff30ef0) +Signed-off-by: Yogita Urade +--- + pyasn1/codec/ber/decoder.py | 10 +++ + tests/codec/ber/test_decoder.py | 116 ++++++++++++++++++++++++++++++++ + tests/codec/cer/test_decoder.py | 24 +++++++ + tests/codec/der/test_decoder.py | 42 ++++++++++++ + 4 files changed, 192 insertions(+) + +diff --git a/pyasn1/codec/ber/decoder.py b/pyasn1/codec/ber/decoder.py +index 18865c2..4d34080 100644 +--- a/pyasn1/codec/ber/decoder.py ++++ b/pyasn1/codec/ber/decoder.py +@@ -38,6 +38,7 @@ SubstrateUnderrunError = error.SubstrateUnderrunError + # Maximum number of continuation octets (high-bit set) allowed per OID arc. + # 20 octets allows up to 140-bit integers, supporting UUID-based OIDs + MAX_OID_ARC_CONTINUATION_OCTETS = 20 ++MAX_NESTING_DEPTH = 100 + + # Maximum number of octets in a long-form tag ID (20 octets = up to + # 140-bit tag IDs, matching the OID arc limit) +@@ -1519,6 +1520,15 @@ class SingleItemDecoder(object): + decodeFun=None, substrateFun=None, + **options): + ++ _nestingLevel = options.get('_nestingLevel', 0) ++ ++ if _nestingLevel > MAX_NESTING_DEPTH: ++ raise error.PyAsn1Error( ++ 'ASN.1 structure nesting depth exceeds limit (%d)' % MAX_NESTING_DEPTH ++ ) ++ ++ options['_nestingLevel'] = _nestingLevel + 1 ++ + allowEoo = options.pop('allowEoo', False) + + if LOG: +diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py +index 0152027..672c9af 100644 +--- a/tests/codec/ber/test_decoder.py ++++ b/tests/codec/ber/test_decoder.py +@@ -2048,6 +2048,122 @@ class CompressedFilesTestCase(BaseTestCase): + os.remove(path) + + ++class NestingDepthLimitTestCase(BaseTestCase): ++ """Test protection against deeply nested ASN.1 structures (CVE prevention).""" ++ ++ def testIndefLenSequenceNesting(self): ++ """Deeply nested indefinite-length SEQUENCEs must raise PyAsn1Error.""" ++ # Each \x30\x80 opens a new indefinite-length SEQUENCE ++ payload = b'\x30\x80' * 200 ++ try: ++ decoder.decode(payload) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested indef-length SEQUENCEs not rejected' ++ ++ def testIndefLenSetNesting(self): ++ """Deeply nested indefinite-length SETs must raise PyAsn1Error.""" ++ # Each \x31\x80 opens a new indefinite-length SET ++ payload = b'\x31\x80' * 200 ++ try: ++ decoder.decode(payload) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested indef-length SETs not rejected' ++ ++ def testDefiniteLenNesting(self): ++ """Deeply nested definite-length SEQUENCEs must raise PyAsn1Error.""" ++ inner = b'\x05\x00' # NULL ++ for _ in range(200): ++ length = len(inner) ++ if length < 128: ++ inner = b'\x30' + bytes([length]) + inner ++ else: ++ length_bytes = length.to_bytes( ++ (length.bit_length() + 7) // 8, 'big') ++ inner = b'\x30' + bytes([0x80 | len(length_bytes)]) + \ ++ length_bytes + inner ++ try: ++ decoder.decode(inner) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested definite-length SEQUENCEs not rejected' ++ ++ def testNestingUnderLimitWorks(self): ++ """Nesting within the limit must decode successfully.""" ++ inner = b'\x05\x00' # NULL ++ for _ in range(50): ++ length = len(inner) ++ if length < 128: ++ inner = b'\x30' + bytes([length]) + inner ++ else: ++ length_bytes = length.to_bytes( ++ (length.bit_length() + 7) // 8, 'big') ++ inner = b'\x30' + bytes([0x80 | len(length_bytes)]) + \ ++ length_bytes + inner ++ asn1Object, _ = decoder.decode(inner) ++ assert asn1Object is not None, 'Valid nested structure rejected' ++ ++ def testSiblingsDontIncreaseDepth(self): ++ """Sibling elements at the same level must not inflate depth count.""" ++ # SEQUENCE containing 200 INTEGER siblings - should decode fine ++ components = b'\x02\x01\x01' * 200 # 200 x INTEGER(1) ++ length = len(components) ++ length_bytes = length.to_bytes( ++ (length.bit_length() + 7) // 8, 'big') ++ payload = b'\x30' + bytes([0x80 | len(length_bytes)]) + \ ++ length_bytes + components ++ asn1Object, _ = decoder.decode(payload) ++ assert asn1Object is not None, 'Siblings incorrectly rejected' ++ ++ def testErrorMessageContainsLimit(self): ++ """Error message must indicate the nesting depth limit.""" ++ payload = b'\x30\x80' * 200 ++ try: ++ decoder.decode(payload) ++ except error.PyAsn1Error as exc: ++ assert 'nesting depth' in str(exc).lower(), \ ++ 'Error message missing depth info: %s' % exc ++ else: ++ assert False, 'Expected PyAsn1Error' ++ ++ def testNoRecursionError(self): ++ """Must raise PyAsn1Error, not RecursionError.""" ++ payload = b'\x30\x80' * 50000 ++ try: ++ decoder.decode(payload) ++ except error.PyAsn1Error: ++ pass ++ except RecursionError: ++ assert False, 'Got RecursionError instead of PyAsn1Error' ++ ++ def testMixedNesting(self): ++ """Mixed SEQUENCE and SET nesting must be caught.""" ++ # Alternate SEQUENCE (0x30) and SET (0x31) with indef length ++ payload = b'' ++ for i in range(200): ++ payload += b'\x30\x80' if i % 2 == 0 else b'\x31\x80' ++ try: ++ decoder.decode(payload) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert False, 'Mixed nesting not rejected' ++ ++ def testWithSchema(self): ++ """Deeply nested structures must be caught even with schema.""" ++ payload = b'\x30\x80' * 200 ++ try: ++ decoder.decode(payload, asn1Spec=univ.Sequence()) ++ except error.PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested with schema not rejected' ++ ++ + class NonStreamingCompatibilityTestCase(BaseTestCase): + def setUp(self): + from pyasn1 import debug +diff --git a/tests/codec/cer/test_decoder.py b/tests/codec/cer/test_decoder.py +index d759f76..2994846 100644 +--- a/tests/codec/cer/test_decoder.py ++++ b/tests/codec/cer/test_decoder.py +@@ -389,6 +389,30 @@ class SequenceDecoderWithExplicitlyTaggedSetOfOpenTypesTestCase(BaseTestCase): + assert s[1][0] == univ.OctetString(hexValue='02010C') + + ++class NestingDepthLimitTestCase(BaseTestCase): ++ """Test CER decoder protection against deeply nested structures.""" ++ ++ def testIndefLenNesting(self): ++ """Deeply nested indefinite-length SEQUENCEs must raise PyAsn1Error.""" ++ payload = b'\x30\x80' * 200 ++ try: ++ decoder.decode(payload) ++ except PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested indef-length SEQUENCEs not rejected' ++ ++ def testNoRecursionError(self): ++ """Must raise PyAsn1Error, not RecursionError.""" ++ payload = b'\x30\x80' * 50000 ++ try: ++ decoder.decode(payload) ++ except PyAsn1Error: ++ pass ++ except RecursionError: ++ assert False, 'Got RecursionError instead of PyAsn1Error' ++ ++ + suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__]) + + if __name__ == '__main__': +diff --git a/tests/codec/der/test_decoder.py b/tests/codec/der/test_decoder.py +index 726c999..3a81a6e 100644 +--- a/tests/codec/der/test_decoder.py ++++ b/tests/codec/der/test_decoder.py +@@ -396,6 +396,48 @@ class SequenceDecoderWithExplicitlyTaggedSetOfOpenTypesTestCase(BaseTestCase): + assert s[1][0] == univ.OctetString(hexValue='02010C') + + ++class NestingDepthLimitTestCase(BaseTestCase): ++ """Test DER decoder protection against deeply nested structures.""" ++ ++ def testDefiniteLenNesting(self): ++ """Deeply nested definite-length SEQUENCEs must raise PyAsn1Error.""" ++ inner = b'\x05\x00' # NULL ++ for _ in range(200): ++ length = len(inner) ++ if length < 128: ++ inner = b'\x30' + bytes([length]) + inner ++ else: ++ length_bytes = length.to_bytes( ++ (length.bit_length() + 7) // 8, 'big') ++ inner = b'\x30' + bytes([0x80 | len(length_bytes)]) + \ ++ length_bytes + inner ++ try: ++ decoder.decode(inner) ++ except PyAsn1Error: ++ pass ++ else: ++ assert False, 'Deeply nested definite-length SEQUENCEs not rejected' ++ ++ def testNoRecursionError(self): ++ """Must raise PyAsn1Error, not RecursionError.""" ++ inner = b'\x05\x00' ++ for _ in range(200): ++ length = len(inner) ++ if length < 128: ++ inner = b'\x30' + bytes([length]) + inner ++ else: ++ length_bytes = length.to_bytes( ++ (length.bit_length() + 7) // 8, 'big') ++ inner = b'\x30' + bytes([0x80 | len(length_bytes)]) + \ ++ length_bytes + inner ++ try: ++ decoder.decode(inner) ++ except PyAsn1Error: ++ pass ++ except RecursionError: ++ assert False, 'Got RecursionError instead of PyAsn1Error' ++ ++ + suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__]) + + if __name__ == '__main__': +-- +2.44.4 From patchwork Sat Oct 3 21:42:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99942 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3021CA5FDD for ; Sat, 3 Oct 2026 21:43:18 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.13641.1791063797218132585 for ; Sat, 03 Oct 2026 14:43:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VyCdYwyA; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48b0ef9c76eso494740f8f.0 for ; Sat, 03 Oct 2026 14:43:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791063795; x=1791668595; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=impcnMZXQN+7KeLEU2PZJ1OmKgBOirEtWLZen/jDAIA=; b=VyCdYwyAq+4fLtDL80ivcaF2u1atPUPJNEJzgiwAh5Wr//cIK7nNR4gAqVA5a2wDzI NubUVfkFzj5lkCPCk1mpGDobx+aPhF7tmz/AvdTq87UzPocU+4w4p6YYDr8MEq2QKkuv TAppC6rwwZ1Jlu5RScvl8Xik71T2qI89J7LQg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791063795; x=1791668595; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=impcnMZXQN+7KeLEU2PZJ1OmKgBOirEtWLZen/jDAIA=; b=T8FgTrXTPHvUECT474U7sz5XOeFxof7RQKDmQR+3nlZeP2wa9dGickOtKxi1VBFBgw BZh8Y6JTTapb2wQ+p0LVRJOMw+1ytK0MqV1HRg3Ft+45Z+0ZREURTaRWGlF3rMoiHQce lX8pguc2vS132fV6Vdr6fwmD5neMRvkaZjazpOc58b27mR75TxyQpDE6AWImKb4yHB8K PQEUM46vCjNpSATy3ERxf/v4cecJ8vrbVEdXhUJJ6f/VJdcbBBzJATcNnCiJXJ3y6Uw+ +hC8lwXNgSqsts1VhIXn4/M7V+O+fcb2eJdTdl20RSJ5J2aFTk6B9IZKcNGYQkMctMMD tP9A== X-Gm-Message-State: AFq9FYLJoJMJOgtYRFubRM3vlB3vt7MHoZpxChGVA/IocqdX+7a69CVD TW2crpjjCfvCSOoF4i1uHAO2ZhXCIcn1qOEVLlQT45pvUNcHJkk8vAlosP+W44X5KPaVlBoJtR6 x58+nkNI= X-Gm-Gg: AYBFou08TLyr7gNsmSLUyvMe+gbLx+8J5VRmh9Kse3oxdXugoBql10zWP8aYUrNp5vr lMH0tZizZ0a7TrBXPJM9ZCBLTxeUNQWjTaMWrGNZ0ZBtUgwyaU3NObPfTO1Yhs2q9JHQlFYv3Rj r3O9oSszI6/oubep2MsjysKpCu9BqheOJgxP9ZQqYj2Dii623YNWVL67NFrXTk9KockXouZD1mN Mev40Ww1kcbbFlceM5Y6KxfzUsktdlseULuQVxL9DgPTDryQsyi4uh1zgZpayWnUoxV4lmqqUFo hWI+qFkYXxA4+kF+x4IDavoLEl4wgEhdfzaywR2OPzjUGOf9LvFfnlUYl0ZDpruGQ3vYSNXUliX 1/SRLQGNRoLkKTxEY6mXNdsu4NCRY/VB+DNBRllK0fbCaGRkQhvxiyOHUrYajLJlgzP221TDGQg gEaaaJbMCMuqj1qzs9/BtDdo0CtamyEo3Tz3Ork2vfNykoc3o2xRoJgTapRi3fpw0rTgZkg1F0Y 9vbGvX4ulNQJM3N3YAkm0t7APNMonVZixjyyDI9S6ntua+HR5CBn7d6SKUfE9H5o0g= X-Received: by 2002:a05:6000:40cb:b0:48a:f29b:27d with SMTP id ffacd0b85a97d-48c47c6707dmr5277444f8f.7.1791063795397; Sat, 03 Oct 2026 14:43:15 -0700 (PDT) Received: from FRSMI25-LASER (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48b380f04e2sm12832952f8f.15.2026.10.03.14.43.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Oct 2026 14:43:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 8/8] python3-pyasn1: fix CVE-2026-59885 Date: Sat, 3 Oct 2026 23:42:16 +0200 Message-ID: <827730f97b522c4ab31dd2b7b5a33a4933c94750.1791061402.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 21:43:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247184 From: Yogita Urade This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59885 Signed-off-by: Yogita Urade Signed-off-by: Yoann Congal --- .../recipes-devtools/python/python-pyasn1.inc | 1 + .../python3-pyasn1/CVE-2026-59885.patch | 183 ++++++++++++++++++ 2 files changed, 184 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59885.patch diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc index 0fe5e70adfc..9ab2ca9a84d 100644 --- a/meta/recipes-devtools/python/python-pyasn1.inc +++ b/meta/recipes-devtools/python/python-pyasn1.inc @@ -22,6 +22,7 @@ SRC_URI += " \ file://CVE-2026-59886.patch \ file://CVE-2026-59884.patch \ file://CVE-2026-30922.patch \ + file://CVE-2026-59885.patch \ " RDEPENDS:${PN}-ptest += " \ diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59885.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59885.patch new file mode 100644 index 00000000000..af2e7abc8be --- /dev/null +++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59885.patch @@ -0,0 +1,183 @@ +From 844a3c11d47d346469f5b9ffd49f91e9b76a2572 Mon Sep 17 00:00:00 2001 +From: Simon Pichugin +Date: Wed, 8 Jul 2026 17:37:40 -0700 +Subject: [PATCH] Merge commit from fork + +CVE: CVE-2026-59885 +Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9] + +Backport Changes: +- Omitted RelativeOID decoder and encoder changes, together with their + decoder and encoder regression tests, because RelativeOID support was + introduced in pyasn1 0.6.0 and is absent from pyasn1 0.5.1 + +(cherry picked from commit 45bdb19eb7df4b3780fe9c912c63e99bffc39dd9) +Signed-off-by: Yogita Urade +--- + pyasn1/codec/ber/decoder.py | 18 ++++++++++-------- + pyasn1/codec/ber/encoder.py | 12 ++++++------ + tests/codec/ber/test_decoder.py | 22 ++++++++++++++++++++++ + tests/codec/ber/test_encoder.py | 10 ++++++++++ + 4 files changed, 48 insertions(+), 14 deletions(-) + +diff --git a/pyasn1/codec/ber/decoder.py b/pyasn1/codec/ber/decoder.py +index 4d34080..3c95a59 100644 +--- a/pyasn1/codec/ber/decoder.py ++++ b/pyasn1/codec/ber/decoder.py +@@ -428,14 +428,14 @@ class ObjectIdentifierPayloadDecoder(AbstractSimplePayloadDecoder): + + chunk = octs2ints(chunk) + +- oid = () ++ oid = [] + index = 0 + substrateLen = len(chunk) + while index < substrateLen: + subId = chunk[index] + index += 1 + if subId < 128: +- oid += (subId,) ++ oid.append(subId) + elif subId > 128: + # Construct subid from a number of octets + nextSubId = subId +@@ -451,11 +451,11 @@ class ObjectIdentifierPayloadDecoder(AbstractSimplePayloadDecoder): + subId = (subId << 7) + (nextSubId & 0x7F) + if index >= substrateLen: + raise error.SubstrateUnderrunError( +- 'Short substrate for sub-OID past %s' % (oid,) ++ 'Short substrate for sub-OID past %s' % (tuple(oid),) + ) + nextSubId = chunk[index] + index += 1 +- oid += ((subId << 7) + nextSubId,) ++ oid.append((subId << 7) + nextSubId) + elif subId == 128: + # ASN.1 spec forbids leading zeros (0x80) in OID + # encoding, tolerating it opens a vulnerability. See +@@ -465,15 +465,17 @@ class ObjectIdentifierPayloadDecoder(AbstractSimplePayloadDecoder): + + # Decode two leading arcs + if 0 <= oid[0] <= 39: +- oid = (0,) + oid ++ oid.insert(0, 0) + elif 40 <= oid[0] <= 79: +- oid = (1, oid[0] - 40) + oid[1:] ++ oid[0] -= 40 ++ oid.insert(0, 1) + elif oid[0] >= 80: +- oid = (2, oid[0] - 80) + oid[1:] ++ oid[0] -= 80 ++ oid.insert(0, 2) + else: + raise error.PyAsn1Error('Malformed first OID octet: %s' % chunk[0]) + +- yield self._createComponent(asn1Spec, tagSet, oid, **options) ++ yield self._createComponent(asn1Spec, tagSet, tuple(oid), **options) + + + class RealPayloadDecoder(AbstractSimplePayloadDecoder): +diff --git a/pyasn1/codec/ber/encoder.py b/pyasn1/codec/ber/encoder.py +index c59b43e..7c3c5cf 100644 +--- a/pyasn1/codec/ber/encoder.py ++++ b/pyasn1/codec/ber/encoder.py +@@ -327,30 +327,30 @@ class ObjectIdentifierEncoder(AbstractItemEncoder): + else: + raise error.PyAsn1Error('Impossible first/second arcs at %s' % (value,)) + +- octets = () ++ octets = [] + + # Cycle through subIds + for subOid in oid: + if 0 <= subOid <= 127: + # Optimize for the common case +- octets += (subOid,) ++ octets.append(subOid) + + elif subOid > 127: + # Pack large Sub-Object IDs +- res = (subOid & 0x7f,) ++ res = [subOid & 0x7f] + subOid >>= 7 + + while subOid: +- res = (0x80 | (subOid & 0x7f),) + res ++ res.append(0x80 | (subOid & 0x7f)) + subOid >>= 7 + + # Add packed Sub-Object ID to resulted Object ID +- octets += res ++ octets.extend(reversed(res)) + + else: + raise error.PyAsn1Error('Negative OID arc %s at %s' % (subOid, value)) + +- return octets, False, False ++ return tuple(octets), False, False + + + class RealEncoder(AbstractItemEncoder): +diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py +index 672c9af..43b9617 100644 +--- a/tests/codec/ber/test_decoder.py ++++ b/tests/codec/ber/test_decoder.py +@@ -27,6 +27,14 @@ from pyasn1.compat.octets import ints2octs, str2octs, null + from pyasn1 import error + + ++def encode_length(length): ++ if length < 128: ++ return bytes([length]) ++ ++ lengthBytes = length.to_bytes((length.bit_length() + 7) // 8, 'big') ++ return bytes([0x80 | len(lengthBytes)]) + lengthBytes ++ ++ + class LargeTagDecoderTestCase(BaseTestCase): + def testLargeTag(self): + assert decoder.decode(ints2octs((127, 141, 245, 182, 253, 47, 3, 2, 1, 1))) == (1, null) +@@ -476,6 +484,20 @@ class ObjectIdentifierDecoderTestCase(BaseTestCase): + ints2octs((0x06, 0x13, 0x88, 0x37, 0x83, 0xC6, 0xDF, 0xD4, 0xCC, 0xB3, 0xFF, 0xFF, 0xFE, 0xF0, 0xB8, 0xD6, 0xB8, 0xCB, 0xE2, 0xB6, 0x47)) + ) == ((2, 999, 18446744073709551535184467440737095), null) + ++ def testManySingleByteArcs(self): ++ encodedArcCount = 4096 ++ substrate = ( ++ bytes([0x06]) + ++ encode_length(encodedArcCount) + ++ bytes([0x01] * encodedArcCount) ++ ) ++ ++ value, rest = decoder.decode(substrate) ++ assert rest == b'' ++ assert len(value) == encodedArcCount + 1 ++ assert tuple(value[:3]) == (0, 1, 1) ++ assert tuple(value[-3:]) == (1, 1, 1) ++ + def testExcessiveContinuationOctets(self): + """Test that OID arcs with excessive continuation octets are rejected.""" + # Create a payload with 25 continuation octets (exceeds 20 limit) +diff --git a/tests/codec/ber/test_encoder.py b/tests/codec/ber/test_encoder.py +index 3d7567a..ef38eef 100644 +--- a/tests/codec/ber/test_encoder.py ++++ b/tests/codec/ber/test_encoder.py +@@ -349,6 +349,16 @@ class ObjectIdentifierEncoderTestCase(BaseTestCase): + ) == ints2octs((0x06, 0x13, 0x88, 0x37, 0x83, 0xC6, 0xDF, 0xD4, 0xCC, 0xB3, 0xFF, 0xFF, 0xFE, 0xF0, 0xB8, 0xD6, + 0xB8, 0xCB, 0xE2, 0xB6, 0x47)) + ++ def testManySingleByteArcs(self): ++ arcCount = 4096 ++ substrate = encoder.encode( ++ univ.ObjectIdentifier((1, 3) + (1,) * arcCount) ++ ) ++ ++ assert substrate == ( ++ bytes([0x06, 0x82, 0x10, 0x01, 0x2B]) + bytes([0x01] * arcCount) ++ ) ++ + + class ObjectIdentifierWithSchemaEncoderTestCase(BaseTestCase): + def testOne(self): +-- +2.44.4