From patchwork Fri Oct 9 18:45:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100260 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5DA23CA601F for ; Fri, 9 Oct 2026 18:46:39 +0000 (UTC) Received: from mta-65-226.siemens.flowmailer.net (mta-65-226.siemens.flowmailer.net [185.136.65.226]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2854.1791571593026564658 for ; Fri, 09 Oct 2026 11:46:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=Bv25Ommj; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.226, mailfrom: fm-256628-202610091846294429a7178900020752-bl0wq9@rts-flowmailer.siemens.com) Received: by mta-65-226.siemens.flowmailer.net with ESMTPSA id 202610091846294429a7178900020752 for ; Fri, 09 Oct 2026 20:46:30 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc; bh=BkDSl7rQNBhX5HCeEMas50Fvhbb8+0lmvtRcxGaO+ZU=; b=Bv25OmmjQPf3m8as3Lq8eEQBtE7Uqegd5QwRebBXTcd9S1H1wM16/yiZygQPSLc8umkFbB +J5iy4Zt519VE6OEQd1Gi5/FdpVM800dflENL8pCqz046fqD2K0lo1EhFolXgrpfmomo6GiU QLezskFNEV1qq3GaDogO/hWeOTCn3WChrq2e6ZPHN8SE22gVVDA3renIuexDpVs7/aOER9iA YfXyAcYd6NDDj0usFALuBj8FB63RAgl439t29u4zIt6eTVBkCg5Hqv5f2J6GPf6bvthTzg/m qqHAkP9e2Dtl7zehQHlxjVA7h9rlM6iA5ynNJYMJP7QYcnmxvoeVFMLQ==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 1/8] libpcre2: patch CVE-2026-89162 Date: Fri, 9 Oct 2026 20:45:41 +0200 Message-ID: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:46:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247476 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89162 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6 Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89162.patch | 88 +++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 89 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch new file mode 100644 index 0000000000..efc6c856b9 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch @@ -0,0 +1,88 @@ +From edc111a6831591f68b5355a08cc9df8be8f35304 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Sat, 25 Oct 2025 10:50:27 +0100 +Subject: [PATCH] Write padding values to ensure pcre2_serialize_encode() + outputs defined values (#826) + +Fixes low-severity valgrind error reported in GHSA-q7rw-r7qq-2hx6. + +CVE: CVE-2026-89162 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/edc111a6831591f68b5355a08cc9df8be8f35304] +Signed-off-by: Peter Marko +--- + src/pcre2_compile_class.c | 17 +++++++---------- + src/pcre2test_inc.h | 25 +++++++++++++++++++++++++ + 2 files changed, 32 insertions(+), 10 deletions(-) + +diff --git a/src/pcre2_compile_class.c b/src/pcre2_compile_class.c +index 9a1fc022..55b641c1 100644 +--- a/src/pcre2_compile_class.c ++++ b/src/pcre2_compile_class.c +@@ -1802,17 +1802,14 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + PUT(code, 0, (uint32_t)(char_lists_size >> 1)); + code += LINK_SIZE; + +-#if defined PCRE2_DEBUG || defined SUPPORT_VALGRIND ++ /* If we added padding to align the list, initialize the bytes to ++ defined values, so the library is valgrind-clean. It could also ++ be a security concern for clients calling into PCRE2 via bindings ++ from a memory-safe language, if pcre2_serialize_encode() exposes ++ uninitialized memory that may contain sensitive information. */ ++ + if ((char_lists_size & 0x2) != 0) +- { +- /* In debug the unused 16 bit value is set +- to a fixed value and marked unused. */ +- ((uint16_t*)data)[-1] = 0x5555; +-#ifdef SUPPORT_VALGRIND +- VALGRIND_MAKE_MEM_NOACCESS(data - 2, 2); +-#endif +- } +-#endif ++ ((uint16_t*)data)[-1] = 0xdead; + + cb->char_lists_size = + CLIST_ALIGN_TO(char_lists_size, sizeof(uint32_t)); +diff --git a/src/pcre2test_inc.h b/src/pcre2test_inc.h +index 8124e9ca..c4707417 100644 +--- a/src/pcre2test_inc.h ++++ b/src/pcre2test_inc.h +@@ -2019,6 +2019,9 @@ uint32_t use_forbid_utf = forbid_utf; + PCRE2_SIZE patlen, full_patlen; + PCRE2_SIZE valgrind_access_length; + PCRE2_SIZE erroroffset; ++int32_t serialize_rc; ++uint8_t *serialized_bytes; ++PCRE2_SIZE serialized_size; + + /* The perltest.sh script supports only / as a delimiter. */ + +@@ -2966,6 +2969,28 @@ if ((pat_patctl.control2 & CTL2_NL_SET) != 0) + rc = show_pattern_info(); + if (rc != PR_OK) return rc; + ++/* Verify that the compiled structure can be serialized without generating ++memory errors. */ ++ ++serialize_rc = pcre2_serialize_encode((const pcre2_code **)&compiled_code, 1, ++ &serialized_bytes, &serialized_size, general_context); ++if (serialize_rc != 1) ++ { ++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned %d instead of 1\n", ++ serialize_rc); ++ return PR_ABEND; ++ } ++ ++#if defined SUPPORT_VALGRIND ++if (VALGRIND_CHECK_MEM_IS_DEFINED(serialized_bytes, serialized_size) != 0) ++ { ++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned undefined data\n"); ++ return PR_ABEND; ++ } ++#endif ++ ++pcre2_serialize_free(serialized_bytes); ++ + /* The "push" control requests that the compiled pattern be remembered on a + stack. This is mainly for testing the serialization functionality. */ + diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 70079e0b65..b81480c8ff 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -14,6 +14,7 @@ LIC_FILES_CHKSUM = "file://LICENCE.md;md5=6720bf3bcff57543b915c2b22e526df0 \ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ + file://CVE-2026-89162.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100261 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E147CA9EBD for ; Fri, 9 Oct 2026 18:46:59 +0000 (UTC) Received: from mta-65-225.siemens.flowmailer.net (mta-65-225.siemens.flowmailer.net [185.136.65.225]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2788.1791571609913471659 for ; Fri, 09 Oct 2026 11:46:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=VBSTIvIL; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.225, mailfrom: fm-256628-20261009184647bd0f3ab4d0000207f7-uapzmk@rts-flowmailer.siemens.com) Received: by mta-65-225.siemens.flowmailer.net with ESMTPSA id 20261009184647bd0f3ab4d0000207f7 for ; Fri, 09 Oct 2026 20:46:47 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=XatiTZiI8ml7BWzjsxziycsdZpxQ5XleG8EaNG48osQ=; b=VBSTIvILRR2cYNCP258xBC2DeHlDDqCTblmxPYwYj8kg/gEv5CrR8mysH+2DIQGC20azBP wwLxUGbIP4qkTDroGbTgYXAVk88CDbMvL9w96+KjoyGI0FR7t0c/ArWmBYCmdgGadEDum/DX FED3EFNjFjkJsvaY4T1PMokrCMHB77Vcpl+49GbHhn6YIXeeqL7G7XqVX4zUBnV60g4uZ5RM Tds+AydUULq2x9YdVlBeuBrtPs8qfjzfPEaqRaUE+WeoXdG28ss8kBOXZDvk5jgqHfMcyC2T sYfQAfy0n/62foPoBxN8JFoVYWF+L5TKEjYp9f19z8KcUvLmFcfBjdOg==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 2/8] libpcre2: patch CVE-2026-89161 Date: Fri, 9 Oct 2026 20:45:42 +0200 Message-ID: <20261009184548.2962197-2-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:46:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247477 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89161 Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89161.patch | 221 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 222 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch new file mode 100644 index 0000000000..42e69acbcc --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch @@ -0,0 +1,221 @@ +From 1dcd0cf42a6a7cb62cc9a7c024196733abcfda95 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Sat, 8 Aug 2026 19:17:36 +0100 +Subject: [PATCH] Fix leak & stale PCRE2_MD_COPIED_SUBJECT if pcre2_jit_match + used with existing match context (#937) + +The problem is not that pcre2_jit_match() needs to add support for PCRE2_COPY_MATCHED_SUBJECT. Instead, if the passed-in context somehow contains a previously-copied subject (by non-JIT matcher using a global or cached subject) then it will be leaked, and worse, incorrectly free'd later. + +CVE: CVE-2026-89161 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95] +Signed-off-by: Peter Marko +--- + doc/html/pcre2jit.html | 9 +++--- + doc/pcre2.txt | 10 +++---- + doc/pcre2jit.3 | 9 +++--- + src/pcre2_jit_match_inc.h | 10 +++++++ + src/pcre2test_inc.h | 60 ++++++++++++++++++++++++++++++++------- + testdata/testinput17 | 1 + + testdata/testoutput17 | 2 ++ + 7 files changed, 77 insertions(+), 24 deletions(-) + +diff --git a/doc/html/pcre2jit.html b/doc/html/pcre2jit.html +index cc26cc06..4e6d31e5 100644 +--- a/doc/html/pcre2jit.html ++++ b/doc/html/pcre2jit.html +@@ -460,10 +460,11 @@ processed by pcre2_jit_compile()). + The fast path function is called pcre2_jit_match(), and it takes exactly + the same arguments as pcre2_match(). However, the subject string must be + specified with a length; PCRE2_ZERO_TERMINATED is not supported. Unsupported +-option bits (for example, PCRE2_ANCHORED and PCRE2_ENDANCHORED) are ignored, as +-is the PCRE2_NO_JIT option. The return values are also the same as for +-pcre2_match(), plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial +-or complete) is requested that was not compiled. ++option bits (for example, PCRE2_ANCHORED, PCRE2_ENDANCHORED, and ++PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the PCRE2_NO_JIT option. The ++return values are also the same as for pcre2_match(), plus ++PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial or complete) is requested ++that was not compiled. +

+

+ When you call pcre2_match(), as well as testing for invalid options, a +diff --git a/doc/pcre2.txt b/doc/pcre2.txt +index 693908ee..cc316178 100644 +--- a/doc/pcre2.txt ++++ b/doc/pcre2.txt +@@ -6176,11 +6176,11 @@ JIT FAST PATH API + The fast path function is called pcre2_jit_match(), and it takes ex- + actly the same arguments as pcre2_match(). However, the subject string + must be specified with a length; PCRE2_ZERO_TERMINATED is not sup- +- ported. Unsupported option bits (for example, PCRE2_ANCHORED and +- PCRE2_ENDANCHORED) are ignored, as is the PCRE2_NO_JIT option. The re- +- turn values are also the same as for pcre2_match(), plus PCRE2_ER- +- ROR_JIT_BADOPTION if a matching mode (partial or complete) is requested +- that was not compiled. ++ ported. Unsupported option bits (for example, PCRE2_ANCHORED, PCRE2_EN- ++ DANCHORED, and PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the ++ PCRE2_NO_JIT option. The return values are also the same as for ++ pcre2_match(), plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (par- ++ tial or complete) is requested that was not compiled. + + When you call pcre2_match(), as well as testing for invalid options, a + number of other sanity checks are performed on the arguments. For exam- +diff --git a/doc/pcre2jit.3 b/doc/pcre2jit.3 +index 95451b56..729d898f 100644 +--- a/doc/pcre2jit.3 ++++ b/doc/pcre2jit.3 +@@ -444,10 +444,11 @@ processed by \fBpcre2_jit_compile()\fP). + The fast path function is called \fBpcre2_jit_match()\fP, and it takes exactly + the same arguments as \fBpcre2_match()\fP. However, the subject string must be + specified with a length; PCRE2_ZERO_TERMINATED is not supported. Unsupported +-option bits (for example, PCRE2_ANCHORED and PCRE2_ENDANCHORED) are ignored, as +-is the PCRE2_NO_JIT option. The return values are also the same as for +-\fBpcre2_match()\fP, plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial +-or complete) is requested that was not compiled. ++option bits (for example, PCRE2_ANCHORED, PCRE2_ENDANCHORED, and ++PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the PCRE2_NO_JIT option. The ++return values are also the same as for \fBpcre2_match()\fP, plus ++PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial or complete) is requested ++that was not compiled. + .P + When you call \fBpcre2_match()\fP, as well as testing for invalid options, a + number of other sanity checks are performed on the arguments. For example, if +diff --git a/src/pcre2_jit_match_inc.h b/src/pcre2_jit_match_inc.h +index 32d4c8a5..4163cf61 100644 +--- a/src/pcre2_jit_match_inc.h ++++ b/src/pcre2_jit_match_inc.h +@@ -125,6 +125,16 @@ else if ((options & PCRE2_PARTIAL_SOFT) != 0) + if (functions == NULL || functions->executable_funcs[index] == NULL) + return match_data->rc = PCRE2_ERROR_JIT_BADOPTION; + ++/* If the match data block was previously used with PCRE2_COPY_MATCHED_SUBJECT, ++free the memory that was obtained. */ ++ ++if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) != 0) ++ { ++ match_data->memctl.free((void *)match_data->subject, ++ match_data->memctl.memory_data); ++ match_data->flags &= ~PCRE2_MD_COPIED_SUBJECT; ++ } ++ + /* Sanity checks should be handled by pcre2_match. */ + arguments.str = subject + start_offset; + arguments.begin = subject; +diff --git a/src/pcre2test_inc.h b/src/pcre2test_inc.h +index 5d282435..a74e3368 100644 +--- a/src/pcre2test_inc.h ++++ b/src/pcre2test_inc.h +@@ -5171,20 +5171,28 @@ for (gmatched = 0;; gmatched++) + /* If PCRE2_COPY_MATCHED_SUBJECT was set, check that things are as they + should be, but not for fast JIT, where it isn't supported. */ + +- if ((dat_datctl.options & PCRE2_COPY_MATCHED_SUBJECT) != 0 && +- (pat_patctl.control & CTL_JITFAST) == 0) ++ if ((dat_datctl.options & PCRE2_COPY_MATCHED_SUBJECT) != 0) + { +- if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) == 0) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: flag not set after copy_matched_subject\n"); ++ if ((pat_patctl.control & CTL_JITFAST) != 0) ++ { ++ if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) != 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: flag set after unsupported copy_matched_subject\n"); ++ } ++ else ++ { ++ if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) == 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: flag not set after copy_matched_subject\n"); + +- if (match_data->subject == pp) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: copy_matched_subject has not copied\n"); ++ if (match_data->subject == pp) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: copy_matched_subject has not copied\n"); + +- if (memcmp(match_data->subject, pp, ulen) != 0) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: copy_matched_subject mismatch\n"); ++ if (memcmp(match_data->subject, pp, ulen) != 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: copy_matched_subject mismatch\n"); ++ } + } + + /* If this is not the first time round a global loop, check that the +@@ -5661,6 +5669,9 @@ pcre2_match_context *test_dat_context = NULL, *test_dat_context_copy = NULL; + pcre2_convert_context *test_con_context = NULL, *test_con_context_copy = NULL; + pcre2_match_data *test_match_data = NULL; + pcre2_code *test_compiled_code = NULL; ++#ifdef SUPPORT_JIT ++BOOL test_compiled_with_jit = FALSE; ++#endif + PCRE2_UCHAR pattern[] = { CHAR_A, CHAR_B, CHAR_C, 0 }; + PCRE2_UCHAR callout_int_pattern[] = { + CHAR_LEFT_PARENTHESIS, CHAR_QUESTION_MARK, CHAR_C, CHAR_RIGHT_PARENTHESIS, 0 }; +@@ -5965,11 +5976,38 @@ ASSERT(rc == 0 && sizeval == 0, "pcre2_pattern_info(JIT)"); + + if (pcre2_jit_compile(test_compiled_code, PCRE2_JIT_COMPLETE) == 0) + { ++ test_compiled_with_jit = TRUE; ++ + rc = pcre2_pattern_info(test_compiled_code, PCRE2_INFO_JITSIZE, &sizeval); + ASSERT(rc == 0 && sizeval > 0, "pcre2_pattern_info(JIT after compile)"); + } + #endif + ++/* ----------------------- Matching functions ------------------------------ */ ++ ++#ifdef SUPPORT_JIT ++ ++/* Check that fast JIT releases a copied subject when reusing match data. */ ++if (test_compiled_with_jit) ++ { ++ test_match_data = pcre2_match_data_create_from_pattern(test_compiled_code, ++ test_gen_context); ++ ASSERT(test_match_data != NULL, "pcre2_match_data_create_from_pattern(JIT)"); ++ ++ rc = pcre2_match(test_compiled_code, pattern, 3, 0, ++ PCRE2_COPY_MATCHED_SUBJECT, test_match_data, NULL); ++ ASSERT(rc == 1, "pcre2_match(COPY_MATCHED_SUBJECT)"); ++ ++ rc = pcre2_jit_match(test_compiled_code, subject_abcz, 4, 0, 0, ++ test_match_data, NULL); ++ ASSERT(rc == 1, "pcre2_jit_match(reused match data)"); ++ ++ pcre2_match_data_free(test_match_data); ++ test_match_data = NULL; ++ } ++ ++#endif ++ + /* ----------------------- POSIX functions --------------------------------- */ + + #if PCRE2_CODE_UNIT_WIDTH == 8 +diff --git a/testdata/testinput17 b/testdata/testinput17 +index 08fd72e0..9d728965 100644 +--- a/testdata/testinput17 ++++ b/testdata/testinput17 +@@ -298,6 +298,7 @@ + + /abc/jitfast + abc ++ abc\=copy_matched_subject + abc\=no_jit + + # ---- +diff --git a/testdata/testoutput17 b/testdata/testoutput17 +index 6d550084..773ec18a 100644 +--- a/testdata/testoutput17 ++++ b/testdata/testoutput17 +@@ -542,6 +542,8 @@ Failed: error -47: match limit exceeded + + /abc/jitfast + abc ++ 0: abc (JIT) ++ abc\=copy_matched_subject + 0: abc (JIT) + abc\=no_jit + 0: abc (JIT) diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index b81480c8ff..fa59747fdc 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -15,6 +15,7 @@ LIC_FILES_CHKSUM = "file://LICENCE.md;md5=6720bf3bcff57543b915c2b22e526df0 \ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ file://CVE-2026-89162.patch \ + file://CVE-2026-89161.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100262 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 396BECA9EBD for ; Fri, 9 Oct 2026 18:47:09 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2863.1791571619354572589 for ; Fri, 09 Oct 2026 11:46:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=IDhIpmq9; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-20261009184657d6386262c100020756-lg1jrh@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 20261009184657d6386262c100020756 for ; Fri, 09 Oct 2026 20:46:57 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=ep5IZZ85TRJU7LFG18vU8PpRn6CijYgulW/vGAZoS1g=; b=IDhIpmq9MTPJTFDnsuNUvOYJwfAPVcCvNCzCW1OkMhIQzoCydOPY5S5i711kd0f55agoqF g3z2ayYfgLdXh8pqtD0x3dFin9U4g9i6ztdPXPKhdLOFgOn/DmKqU/FoIgP34Oi6cqNFYmZt 29Pyc7GAL4Z9aispmsOPygB88KW6rL0prJi2bv0XMpfzVTI3JScNZYGOd6qL8/nOdNMMtOwA bRheqNFoIoEWHQSBWW5LeucjRhc/nNak/B7wYgSjeioHXotg6e02MLDB0OM1VVqd8O2sydXL O+KU8/U5pNF3FZI/3GMO9u9N3UZusCGr5I9lUNIeXpCP/jCyJMWa6f8A==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 3/8] libpcre2: patch CVE-2026-89156 Date: Fri, 9 Oct 2026 20:45:43 +0200 Message-ID: <20261009184548.2962197-3-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:09 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247478 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89156 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89156.patch | 275 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 276 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch new file mode 100644 index 0000000000..7937a6a4c5 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch @@ -0,0 +1,275 @@ +From f67db227af31bba7cdf2a7a00b97af91b588c2f5 Mon Sep 17 00:00:00 2001 +From: Zoltan Herczeg +Date: Sun, 9 Aug 2026 11:05:54 +0200 +Subject: [PATCH] Fix pcre2_match to check for JIT support before JIT + validation & execution (#926) + +This fixes the issue that the JIT branch's UTF validation is not pinned to be identical to the interpreter's validation. + +This was not robust, and lead to a bug, in the case where the JIT UTF validation is done, but because the relevant JIT mode was not compiled, it falls through to the interpreter and skips the interpreter's own UTF validation and setup. + +CVE: CVE-2026-89156 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5] +Signed-off-by: Peter Marko +--- + src/pcre2_internal.h | 2 + + src/pcre2_jit_match_inc.h | 1 + + src/pcre2_jit_misc_inc.h | 38 +++++++++++++--- + src/pcre2_match.c | 95 +++++++++++++++------------------------ + 4 files changed, 71 insertions(+), 65 deletions(-) + +diff --git a/src/pcre2_internal.h b/src/pcre2_internal.h +index 2e8c7e47..930c745b 100644 +--- a/src/pcre2_internal.h ++++ b/src/pcre2_internal.h +@@ -2296,6 +2296,7 @@ is available. */ + #define _pcre2_is_newline PCRE2_SUFFIX(_pcre2_is_newline_) + #define _pcre2_jit_free_rodata PCRE2_SUFFIX(_pcre2_jit_free_rodata_) + #define _pcre2_jit_free PCRE2_SUFFIX(_pcre2_jit_free_) ++#define _pcre2_jit_check_exec PCRE2_SUFFIX(_pcre2_jit_check_exec_) + #define _pcre2_jit_get_size PCRE2_SUFFIX(_pcre2_jit_get_size_) + #define _pcre2_jit_get_target PCRE2_SUFFIX(_pcre2_jit_get_target_) + #define _pcre2_memctl_malloc PCRE2_SUFFIX(_pcre2_memctl_malloc_) +@@ -2325,6 +2326,7 @@ extern BOOL _pcre2_is_newline(PCRE2_SPTR, uint32_t, PCRE2_SPTR, + uint32_t *, BOOL); + extern void _pcre2_jit_free_rodata(void *, void *); + extern void _pcre2_jit_free(void *, pcre2_memctl *); ++extern BOOL _pcre2_jit_check_exec(void *, uint32_t); + extern size_t _pcre2_jit_get_size(void *); + const char * _pcre2_jit_get_target(void); + extern void * _pcre2_memctl_malloc(size_t, pcre2_memctl *); +diff --git a/src/pcre2_jit_match_inc.h b/src/pcre2_jit_match_inc.h +index 4163cf61..ba210007 100644 +--- a/src/pcre2_jit_match_inc.h ++++ b/src/pcre2_jit_match_inc.h +@@ -117,6 +117,7 @@ jit_arguments arguments; + int rc; + int index = 0; + ++/* The same check is performed by jit_check_exec(). */ + if ((options & PCRE2_PARTIAL_HARD) != 0) + index = 2; + else if ((options & PCRE2_PARTIAL_SOFT) != 0) +diff --git a/src/pcre2_jit_misc_inc.h b/src/pcre2_jit_misc_inc.h +index 0225fc6b..16c230e9 100644 +--- a/src/pcre2_jit_misc_inc.h ++++ b/src/pcre2_jit_misc_inc.h +@@ -200,17 +200,28 @@ if (jit_stack != NULL) + + + /************************************************* +-* Get target CPU type * ++* Checks function compilation * + *************************************************/ + +-const char* +-PRIV(jit_get_target)(void) ++BOOL ++PRIV(jit_check_exec)(void *executable_jit, uint32_t options) + { + #ifndef SUPPORT_JIT +-return "JIT is not supported"; ++(void)executable_jit; ++(void)options; ++return FALSE; + #else /* SUPPORT_JIT */ +-return sljit_get_platform_name(); +-#endif /* SUPPORT_JIT */ ++/* The same check is performed at the beginning of pcre2_jit_match(). */ ++executable_functions *functions = (executable_functions *)executable_jit; ++int index = 0; ++ ++if ((options & PCRE2_PARTIAL_HARD) != 0) ++ index = 2; ++else if ((options & PCRE2_PARTIAL_SOFT) != 0) ++ index = 1; ++ ++return functions->executable_funcs[index] != NULL; ++#endif + } + + +@@ -231,4 +242,19 @@ return executable_sizes[0] + executable_sizes[1] + executable_sizes[2]; + #endif + } + ++/************************************************* ++* Get target CPU type * ++*************************************************/ ++ ++const char* ++PRIV(jit_get_target)(void) ++{ ++#ifndef SUPPORT_JIT ++return "JIT is not supported"; ++#else /* SUPPORT_JIT */ ++return sljit_get_platform_name(); ++#endif /* SUPPORT_JIT */ ++} ++ ++ + /* End of pcre2_jit_misc_inc.h */ +diff --git a/src/pcre2_match.c b/src/pcre2_match.c +index 9ee8a476..a5a8421f 100644 +--- a/src/pcre2_match.c ++++ b/src/pcre2_match.c +@@ -6995,10 +6995,6 @@ PCRE2_SPTR req_cu_ptr; + PCRE2_SPTR start_partial; + PCRE2_SPTR match_partial; + +-#ifdef SUPPORT_JIT +-BOOL use_jit; +-#endif +- + /* This flag is needed even when Unicode is not supported for convenience + (it is used by the IS_NEWLINE macro). */ + +@@ -7008,9 +7004,6 @@ BOOL utf = FALSE; + BOOL ucp = FALSE; + BOOL allow_invalid; + uint32_t fragment_options = 0; +-#ifdef SUPPORT_JIT +-BOOL jit_checked_utf = FALSE; +-#endif + #endif /* SUPPORT_UNICODE */ + + PCRE2_SIZE frame_size; +@@ -7073,15 +7066,6 @@ options |= (re->flags & FF) / ((FF & (~FF+1)) / (OO & (~OO+1))); + #undef FF + #undef OO + +-/* If the pattern was successfully studied with JIT support, we will run the +-JIT executable instead of the rest of this function. Most options must be set +-at compile time for the JIT code to be usable. */ +- +-#ifdef SUPPORT_JIT +-use_jit = (re->executable_jit != NULL && +- (options & ~PUBLIC_JIT_MATCH_OPTIONS) == 0); +-#endif +- + /* Initialize UTF/UCP parameters. */ + + #ifdef SUPPORT_UNICODE +@@ -7128,20 +7112,25 @@ match_data->startchar = 0; + + /* ============================= JIT matching ============================== */ + +-/* Prepare for JIT matching. Check a UTF string for validity unless no check is +-requested or invalid UTF can be handled. We check only the portion of the +-subject that might be be inspected during matching - from the offset minus the +-maximum lookbehind to the given length. This saves time when a small part of a +-large subject is being matched by the use of a starting offset. Note that the +-maximum lookbehind is a number of characters, not code units. */ ++/* If the pattern was successfully studied with JIT support, we will run the ++JIT executable instead of the rest of this function. Most options must be set ++at compile time for the JIT code to be usable. */ + + #ifdef SUPPORT_JIT +-if (use_jit) ++if (re->executable_jit != NULL && ++ (options & ~PUBLIC_JIT_MATCH_OPTIONS) == 0 && ++ PRIV(jit_check_exec)(re->executable_jit, options)) + { ++ /* Prepare for JIT matching. Check a UTF string for validity unless no check ++ is requested or invalid UTF can be handled. We check only the portion of the ++ subject that might be be inspected during matching - from the offset minus ++ the maximum lookbehind to the given length. This saves time when a small part ++ of a large subject is being matched by the use of a starting offset. Note that ++ the maximum lookbehind is a number of characters, not code units. */ ++ + #ifdef SUPPORT_UNICODE + if (utf && (options & PCRE2_NO_UTF_CHECK) == 0 && !allow_invalid) + { +- + /* For 8-bit and 16-bit UTF, check that the first code unit is a valid + character start. */ + +@@ -7194,40 +7183,36 @@ if (use_jit) + match_data->startchar += start_match - subject; + return match_data->rc = rc; + } +- jit_checked_utf = TRUE; + } + #endif /* SUPPORT_UNICODE */ + +- /* If JIT returns BADOPTION, which means that the selected complete or +- partial matching mode was not compiled, fall through to the interpreter. */ +- + rc = pcre2_jit_match(code, subject, length, start_offset, options, + match_data, mcontext); +- if (rc != PCRE2_ERROR_JIT_BADOPTION) ++ /* JIT must be able to perform the match. */ ++ PCRE2_ASSERT(rc != PCRE2_ERROR_JIT_BADOPTION); ++ ++ match_data->options = original_options; ++ if (rc >= 0 && (options & PCRE2_COPY_MATCHED_SUBJECT) != 0) + { +- match_data->options = original_options; +- if (rc >= 0 && (options & PCRE2_COPY_MATCHED_SUBJECT) != 0) ++ if (length != 0) + { +- if (length != 0) +- { +- match_data->subject = match_data->memctl.malloc(CU2BYTES(length), +- match_data->memctl.memory_data); +- if (match_data->subject == NULL) +- return match_data->rc = PCRE2_ERROR_NOMEMORY; +- memcpy((void *)match_data->subject, subject, CU2BYTES(length)); +- } +- else +- match_data->subject = NULL; +- match_data->flags |= PCRE2_MD_COPIED_SUBJECT; ++ match_data->subject = match_data->memctl.malloc(CU2BYTES(length), ++ match_data->memctl.memory_data); ++ if (match_data->subject == NULL) ++ return match_data->rc = PCRE2_ERROR_NOMEMORY; ++ memcpy((void *)match_data->subject, subject, CU2BYTES(length)); + } + else +- { +- /* When pcre2_jit_match sets the subject, it doesn't know what the +- original passed-in pointer was. */ +- if (match_data->subject != NULL) match_data->subject = original_subject; +- } +- return rc; ++ match_data->subject = NULL; ++ match_data->flags |= PCRE2_MD_COPIED_SUBJECT; + } ++ else ++ { ++ /* When pcre2_jit_match sets the subject, it doesn't know what the ++ original passed-in pointer was. */ ++ if (match_data->subject != NULL) match_data->subject = original_subject; ++ } ++ return rc; + } + #endif /* SUPPORT_JIT */ + +@@ -7240,12 +7225,8 @@ this. */ + + mb->check_subject = subject; + +-/* If a UTF subject string was not checked for validity in the JIT code above, +-check it here, and handle support for invalid UTF strings. The check above +-happens only when invalid UTF is not supported and PCRE2_NO_CHECK_UTF is unset. +-If we get here in those circumstances, it means the subject string is valid, +-but for some reason JIT matching was not successful. There is no need to check +-the subject again. ++/* Check the validity of UTF subject strings. The check happens only when ++PCRE2_NO_CHECK_UTF is unset. + + We check only the portion of the subject that might be be inspected during + matching - from the offset minus the maximum lookbehind to the given length. +@@ -7257,11 +7238,7 @@ Note also that support for invalid UTF forces a check, overriding the setting + of PCRE2_NO_CHECK_UTF. */ + + #ifdef SUPPORT_UNICODE +-if (utf && +-#ifdef SUPPORT_JIT +- !jit_checked_utf && +-#endif +- ((options & PCRE2_NO_UTF_CHECK) == 0 || allow_invalid)) ++if (utf && ((options & PCRE2_NO_UTF_CHECK) == 0 || allow_invalid)) + { + #if PCRE2_CODE_UNIT_WIDTH != 32 + BOOL skipped_bad_start = FALSE; diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index fa59747fdc..7d027e90ee 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -16,6 +16,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ file://CVE-2026-89162.patch \ file://CVE-2026-89161.patch \ + file://CVE-2026-89156.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100263 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3ABD5CA601E for ; Fri, 9 Oct 2026 18:47:19 +0000 (UTC) Received: from mta-64-226.siemens.flowmailer.net (mta-64-226.siemens.flowmailer.net [185.136.64.226]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2868.1791571629450785577 for ; Fri, 09 Oct 2026 11:47:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=nc9oP/7a; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.226, mailfrom: fm-256628-202610091847072e85052fd6000207e0-2twbt2@rts-flowmailer.siemens.com) Received: by mta-64-226.siemens.flowmailer.net with ESMTPSA id 202610091847072e85052fd6000207e0 for ; Fri, 09 Oct 2026 20:47:07 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=re2RK9DExSZfj7/0D6f5sPBSjtSErDC0uFZciew5esI=; b=nc9oP/7a3u7cnCXBRL2TRTdXjnxuWNMWwkqEzzb4hAA09B1XDgmRPdHEttWFRRKsddcTw1 pgBWDZORiYvEaiRCUqE2gA6TqErJaz04jjU2Ub7xdLVupuUe1Q57/SD/bnwNZ+OEbwvH4XgT 1jPpCg0X2VAg7NpBO4t9rkMcpGmNg8UQAzaxh0C0FY38vDvWTfyqXpoWNwfRNchYGDamJ/SC 2BZln/vaaU+VLGU2X5OzjyKgpqD7Co2Vp7RDRHx5YQv9QvsHIX0Dp1fy2v0/85dpGtx4aKGU eRuLNAhZIlwYI9CItFgYIt/Dycm9R0zFtCQzaBAWQjQkgJt3mD438pZQ==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 4/8] libpcre2: patch CVE-2026-89157 Date: Fri, 9 Oct 2026 20:45:44 +0200 Message-ID: <20261009184548.2962197-4-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:19 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247479 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89157 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9 Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89157.patch | 61 +++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch new file mode 100644 index 0000000000..fa525c79d8 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch @@ -0,0 +1,61 @@ +From 8156b3989a82f2ddf9504d8248496e9b124be7f3 Mon Sep 17 00:00:00 2001 +From: Ilia Alshanetsky +Date: Sun, 9 Aug 2026 07:15:03 -0400 +Subject: [PATCH] Use CU2BYTES for byte sizing in two allocation sites (#909) + +Two allocation sites multiplied by PCRE2_CODE_UNIT_WIDTH (the bit width: +8, 16, or 32) where the CU2BYTES(x) byte-count helper is intended. The +result over-allocates by the code-unit byte width: 8x in 8-bit mode, 16x +in 16-bit, 32x in 32-bit. Subsequent memcpy calls already use CU2BYTES +correctly, so no out-of-bounds write occurs; the over-allocation is +leaked until the buffer is freed. + +Also guard each site against integer overflow in +sizeof(pcre2_memctl) + CU2BYTES(N + 1) by rejecting N greater than +(PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1) - 1. + +CVE: CVE-2026-89157 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3] +Signed-off-by: Peter Marko +--- + src/pcre2_convert.c | 8 +++++--- + src/pcre2_substring.c | 7 ++++--- + 2 files changed, 9 insertions(+), 6 deletions(-) + +diff --git a/src/pcre2_convert.c b/src/pcre2_convert.c +index ad7312ab..8a2b293d 100644 +--- a/src/pcre2_convert.c ++++ b/src/pcre2_convert.c +@@ -1215,9 +1215,11 @@ for (int i = 0; i < 2; i++) + /* Allocate memory for the buffer, with hidden space for an allocator at + the start. The next time round the loop runs the conversion for real. */ + +- allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + +- (*bufflenptr + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)ccontext); +- if (allocated == NULL) ++ if (*bufflenptr > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / ++ CU2BYTES(1)) - 1 || ++ (allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + ++ CU2BYTES(*bufflenptr + 1), ++ (pcre2_memctl *)ccontext)) == NULL) + { + *bufflenptr = 0; /* Error offset */ + return PCRE2_ERROR_NOMEMORY; +diff --git a/src/pcre2_substring.c b/src/pcre2_substring.c +index f68b464e..a6f5277a 100644 +--- a/src/pcre2_substring.c ++++ b/src/pcre2_substring.c +@@ -210,9 +210,10 @@ PCRE2_SIZE size; + PCRE2_UCHAR *yield; + rc = pcre2_substring_length_bynumber(match_data, stringnumber, &size); + if (rc < 0) return rc; +-yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + +- (size + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)match_data); +-if (yield == NULL) return PCRE2_ERROR_NOMEMORY; ++if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1 || ++ (yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + ++ CU2BYTES(size + 1), (pcre2_memctl *)match_data)) == NULL) ++ return PCRE2_ERROR_NOMEMORY; + yield = (PCRE2_UCHAR *)(((char *)yield) + sizeof(pcre2_memctl)); + if (size != 0) memcpy(yield, match_data->subject + match_data->ovector[stringnumber*2], + CU2BYTES(size)); diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 7d027e90ee..bbe3757321 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -17,6 +17,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89162.patch \ file://CVE-2026-89161.patch \ file://CVE-2026-89156.patch \ + file://CVE-2026-89157.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100264 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3DE36CA601F for ; Fri, 9 Oct 2026 18:47:29 +0000 (UTC) Received: from mta-64-228.siemens.flowmailer.net (mta-64-228.siemens.flowmailer.net [185.136.64.228]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2873.1791571639753291869 for ; Fri, 09 Oct 2026 11:47:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=eM/9KeKd; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.228, mailfrom: fm-256628-20261009184717a379591b16000207ee-p_2drx@rts-flowmailer.siemens.com) Received: by mta-64-228.siemens.flowmailer.net with ESMTPSA id 20261009184717a379591b16000207ee for ; Fri, 09 Oct 2026 20:47:18 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=S5UfHiw/PGjKL1/hhUnS7Qq29j1TOSZ4swmk5a/hUUo=; b=eM/9KeKdM0RM5n6Zmp514dAYbZiWmdgEzgxJYXNgD0HbHPMvbOb4F+QsMmHwbkSqi8advt xIfG+AcmRKtIEl+6M0kIyoWMBGloOe0iLsVOIvB+im/BaAeiWoE38+94IQWk2kBGBF41nqx8 TURNB9A0uMfiJO3SADt2gIE7RIUe0oIHGN3S8MqYHFNPUfJbuIWDH3MKvyJrN67K0s53HcDD VAGNCz9Xy89PiS4egC7airDRIpvEhV6McvWbEgmEm0MbDWA9ZKH5BQTEFc4rqqbvnus8gdfN gZEXzne4DhSXuTbV+mWyt67b+yTdl3V1yO+0ghpB7qm3PsVwVdyFDd/g==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 5/8] libpcre2: patch CVE-2026-89160 Date: Fri, 9 Oct 2026 20:45:45 +0200 Message-ID: <20261009184548.2962197-5-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247480 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89160 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89160.patch | 225 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 226 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch new file mode 100644 index 0000000000..bff6bc83ef --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch @@ -0,0 +1,225 @@ +From 4889caf31a4c5a6b3c051f0031bf2dbd78f2c287 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix invalid UTF backwards-scan reads; see GHSA-9qww-pwc4-77qq + for details + +CVE: CVE-2026-89160 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287] +Signed-off-by: Peter Marko +--- + src/pcre2_extuni.c | 10 +++++----- + src/pcre2_match.c | 10 +++++----- + testdata/testinput10 | 10 ++++++++++ + testdata/testinput12 | 10 ++++++++++ + testdata/testoutput10 | 12 ++++++++++++ + testdata/testoutput12-16 | 12 ++++++++++++ + testdata/testoutput12-32 | 12 ++++++++++++ + 7 files changed, 66 insertions(+), 10 deletions(-) + +diff --git a/src/pcre2_extuni.c b/src/pcre2_extuni.c +index 1b7f04b4..fea098a7 100644 +--- a/src/pcre2_extuni.c ++++ b/src/pcre2_extuni.c +@@ -54,12 +54,12 @@ support, because some compilers do not like functionless source files. */ + + #ifndef SUPPORT_UNICODE + PCRE2_SPTR +-PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR start_subject, ++PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR check_subject, + PCRE2_SPTR end_subject, BOOL utf, int *xcount) + { + (void)c; + (void)eptr; +-(void)start_subject; ++(void)check_subject; + (void)end_subject; + (void)utf; + (void)xcount; +@@ -80,7 +80,7 @@ same behaviour. + Arguments: + c the first character + eptr pointer to next character +- start_subject pointer to start of subject ++ check_subject pointer to start of validated subject + end_subject pointer to end of subject + utf TRUE if in UTF mode + xcount pointer to count of additional characters, +@@ -90,7 +90,7 @@ Returns: pointer after the end of the sequence + */ + + PCRE2_SPTR +-PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR start_subject, ++PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR check_subject, + PCRE2_SPTR end_subject, BOOL utf, int *xcount) + { + BOOL was_ep_ZWJ = FALSE; +@@ -121,7 +121,7 @@ while (eptr < end_subject) + + /* bptr is pointing to the left-hand character */ + +- while (bptr > start_subject) ++ while (bptr > check_subject) + { + bptr--; + if (utf) +diff --git a/src/pcre2_match.c b/src/pcre2_match.c +index a5a8421f..966576e1 100644 +--- a/src/pcre2_match.c ++++ b/src/pcre2_match.c +@@ -2893,7 +2893,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, utf, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, utf, + NULL); + } + CHECK_PARTIAL(); +@@ -3244,7 +3244,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, + mb->end_subject, utf, NULL); + } + CHECK_PARTIAL(); +@@ -4069,7 +4069,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, + utf, NULL); + } + CHECK_PARTIAL(); +@@ -4658,7 +4658,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, + utf, NULL); + } + CHECK_PARTIAL(); +@@ -6233,7 +6233,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + { + for (i = 0; i < Lmax; i++) + { +- if (Feptr == mb->start_subject) ++ if (Feptr <= mb->check_subject) + { + if (i < Lmin) RRETURN(MATCH_NOMATCH); + Lmax = i; +diff --git a/testdata/testinput10 b/testdata/testinput10 +index d9e6ba8c..bfa9dad8 100644 +--- a/testdata/testinput10 ++++ b/testdata/testinput10 +@@ -585,6 +585,16 @@ + AAA\x80BXYZ + AAA\x80BBXYZ + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x80X ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x80\x{1f1e6}\x{1f1e7} ++ + # ------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testinput12 b/testdata/testinput12 +index 01cc76a4..c4a89a26 100644 +--- a/testdata/testinput12 ++++ b/testdata/testinput12 +@@ -498,6 +498,16 @@ + /(..)(*scs:(1)ab$)/match_invalid_utf + ab\x{df00}cde + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput10 b/testdata/testoutput10 +index 393ac207..9e124e2b 100644 +--- a/testdata/testoutput10 ++++ b/testdata/testoutput10 +@@ -1779,6 +1779,18 @@ No match + AAA\x80BBXYZ + No match + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x80X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x80\x{1f1e6}\x{1f1e7} ++No match ++ + # ------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput12-16 b/testdata/testoutput12-16 +index d235c11f..b0676a19 100644 +--- a/testdata/testoutput12-16 ++++ b/testdata/testoutput12-16 +@@ -1659,6 +1659,18 @@ No match + 0: ab + 1: ab + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++No match ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput12-32 b/testdata/testoutput12-32 +index 725cb274..a97051a6 100644 +--- a/testdata/testoutput12-32 ++++ b/testdata/testoutput12-32 +@@ -1658,6 +1658,18 @@ No match + 0: ab + 1: ab + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++No match ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index bbe3757321..ef8274c9b1 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -18,6 +18,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89161.patch \ file://CVE-2026-89156.patch \ file://CVE-2026-89157.patch \ + file://CVE-2026-89160.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100265 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E1A2CA601E for ; Fri, 9 Oct 2026 18:47:39 +0000 (UTC) Received: from mta-65-226.siemens.flowmailer.net (mta-65-226.siemens.flowmailer.net [185.136.65.226]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2876.1791571648945491152 for ; Fri, 09 Oct 2026 11:47:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=A1bVi2zH; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.226, mailfrom: fm-256628-20261009184727c0e2e691ed00020752-kdo0zs@rts-flowmailer.siemens.com) Received: by mta-65-226.siemens.flowmailer.net with ESMTPSA id 20261009184727c0e2e691ed00020752 for ; Fri, 09 Oct 2026 20:47:27 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=45fUbLFwz7D9EKVIIvyHWA4oUDFKZpxEcaZWpi+0OcU=; b=A1bVi2zHNuvYqdsPko33M4FgoJ2VG9hqZI52WM9hFBQ0cX3qw+JkiqNTvzlGn9xnIKOIbP VDZ3o4mglkE3F5nm4JYcBfB4D+/io+KEmDjRkQGmWTySCquh5rYarHO1PHtO7sJqpn1YpGZF zsieyRlwbiSdqrnJfrLUSgdhE29fJ1wxlBF4GJMWQHgKxyALtcl0FuqdcjmrG8elKC68s/nW cICTB8iN9SzxJ8tErlVUsKBd/u+54CHnEG67GCLy2WmUE/w6znYFuxCol7ZuaetqVJB2p9Q0 bYZTpcB2wn8Y07UbArTLxC+cO+jNKjGodaJ7nPnb2e1x5SH5iY7KYazg==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 6/8] libpcre2: patch CVE-2026-89158 Date: Fri, 9 Oct 2026 20:45:46 +0200 Message-ID: <20261009184548.2962197-6-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247481 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89158 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859 Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-89158.patch | 208 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 209 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch new file mode 100644 index 0000000000..8099667433 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch @@ -0,0 +1,208 @@ +From ec9c286d5c10cf1c388b58a442ccefded42254fd Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix compiler integer overflows; see GHSA-fmgr-6ggq-9859 for + details + +CVE: CVE-2026-89158 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd] +Signed-off-by: Peter Marko +--- + src/pcre2_compile.c | 55 ++++++++++++++++++++++++++++++++++++--- + src/pcre2_compile_class.c | 35 ++++++++++++++++--------- + 2 files changed, 74 insertions(+), 16 deletions(-) + +diff --git a/src/pcre2_compile.c b/src/pcre2_compile.c +index 1081cf64..32cb32f6 100644 +--- a/src/pcre2_compile.c ++++ b/src/pcre2_compile.c +@@ -6195,7 +6195,8 @@ for (;; pptr++) + + if (meta < META_ASTERISK || meta > META_MINMAX_QUERY) + { +- if (OFLOW_MAX - *lengthptr < (PCRE2_SIZE)(code - orig_code)) ++ if (*lengthptr > OFLOW_MAX || ++ OFLOW_MAX - *lengthptr < (PCRE2_SIZE)(code - orig_code)) + { + *errorcodeptr = ERR20; /* Integer overflow */ + cb->erroroffset = 0; +@@ -8795,7 +8796,8 @@ for (;;) + *reqcuflagsptr = reqcuflags; + if (lengthptr != NULL) + { +- if (OFLOW_MAX - *lengthptr < length) ++ if (*lengthptr > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - *lengthptr < length) + { + *errorcodeptr = ERR20; + return 0; +@@ -8818,6 +8820,19 @@ for (;;) + { + code = *codeptr + 1 + LINK_SIZE + skipunits; + length += 1 + LINK_SIZE; ++ ++ /* Move the accumulated length into *lengthptr, providing the next call to ++ compile_branch with as much space in &length and &code as the first did. */ ++ ++ if (*lengthptr > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - *lengthptr < length) ++ { ++ *errorcodeptr = ERR20; ++ cb->erroroffset = 0; ++ return 0; ++ } ++ *lengthptr += length; ++ length = 0; + } + else + { +@@ -10831,7 +10846,8 @@ if (errorcode != 0) goto HAD_CB_ERROR; /* Offset is in cb.erroroffset */ + #if defined SUPPORT_WIDE_CHARS + PCRE2_ASSERT((cb.char_lists_size & 0x3) == 0); + if (length > MAX_PATTERN_SIZE || +- MAX_PATTERN_SIZE - length < (cb.char_lists_size / sizeof(PCRE2_UCHAR))) ++ BYTES2CU(cb.char_lists_size) > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - length < BYTES2CU(cb.char_lists_size)) + #else + if (length > MAX_PATTERN_SIZE) + #endif +@@ -10856,11 +10872,36 @@ if (cb.char_lists_size != 0) + /* Align to 32 bit first. This ensures the + allocated area will also be 32 bit aligned. */ + re_blocksize = (PCRE2_SIZE)CLIST_ALIGN_TO(re_blocksize, sizeof(uint32_t)); ++#else ++ /* Already 32 bit aligned. */ + #endif ++ ++ /* We have bounded the length and BYTES2CU(char_lists_size) to ++ MAX_PATTERN_SIZE units, however (with 32-bit code units) char_lists_size ++ in bytes could still be extremely close to (or greater than) SIZE_MAX, so ++ we require another overflow check. */ ++ ++ if (cb.char_lists_size > PCRE2_SIZE_MAX - re_blocksize) ++ { ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += cb.char_lists_size; + } + #endif + ++if (length > BYTES2CU(PCRE2_SIZE_MAX - re_blocksize)) ++ { ++ /* Given the current value of 2^30 for MAX_PATTERN_SIZE, this block is only ++ reachable when both PCRE2_CODE_UNIT_WIDTH >= 16 and sizeof(size_t) is ++ 32 bits. */ ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += CU2BYTES(length); + + if (re_blocksize > ccontext->max_pattern_compiled_length) +@@ -10870,7 +10911,15 @@ if (re_blocksize > ccontext->max_pattern_compiled_length) + goto HAD_CB_ERROR; + } + ++if (sizeof(pcre2_real_code) > PCRE2_SIZE_MAX - re_blocksize) ++ { ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += sizeof(pcre2_real_code); ++ + re = (pcre2_real_code *) + ccontext->memctl.malloc(re_blocksize, ccontext->memctl.memory_data); + if (re == NULL) +diff --git a/src/pcre2_compile_class.c b/src/pcre2_compile_class.c +index c6f30d6f..c0606643 100644 +--- a/src/pcre2_compile_class.c ++++ b/src/pcre2_compile_class.c +@@ -498,7 +498,7 @@ static const uint32_t char_list_starts[] = { + + static class_ranges * + compile_optimize_class(uint32_t *start_ptr, uint32_t options, +- uint32_t xoptions, compile_block *cb) ++ uint32_t xoptions, int *errorcodeptr, compile_block *cb) + { + class_ranges* cranges; + uint32_t *ptr; +@@ -538,12 +538,23 @@ PCRE2_ASSERT((range_list_size & 0x1) == 0); + + total_size = range_list_size + + ((range_list_size >= 2) ? CHAR_LIST_EXTRA_SIZE : 0); ++if (total_size > (PCRE2_SIZE_MAX - sizeof(class_ranges)) / sizeof(uint32_t)) ++ { ++ *errorcodeptr = ERR20; ++ cb->erroroffset = 0; ++ return NULL; ++ } + + cranges = cb->cx->memctl.malloc( + sizeof(class_ranges) + total_size * sizeof(uint32_t), + cb->cx->memctl.memory_data); + +-if (cranges == NULL) return NULL; ++if (cranges == NULL) ++ { ++ *errorcodeptr = ERR21; ++ cb->erroroffset = 0; ++ return NULL; ++ } + + cranges->header.next = NULL; + #ifdef PCRE2_DEBUG +@@ -1116,13 +1127,10 @@ if (utf) + { + if (lengthptr != NULL) + { +- cranges = compile_optimize_class(pptr, options, xoptions, cb); ++ cranges = compile_optimize_class(pptr, options, xoptions, errorcodeptr, cb); + + if (cranges == NULL) +- { +- *errorcodeptr = ERR21; + return NULL; +- } + + /* Caching the pre-processed character ranges. */ + if (cb->last_data != NULL) +@@ -1755,18 +1763,17 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + *lengthptr += 1 + LINK_SIZE; + #endif + +- cb->char_lists_size += char_lists_size; ++ PCRE2_ASSERT(BYTES2CU(cb->char_lists_size) <= MAX_PATTERN_SIZE); + +- char_lists_size /= sizeof(PCRE2_UCHAR); +- +- /* Storage space for character lists is included +- in the maximum pattern size. */ +- if (*lengthptr > MAX_PATTERN_SIZE || +- MAX_PATTERN_SIZE - *lengthptr < char_lists_size) ++ if (char_lists_size > PCRE2_SIZE_MAX - cb->char_lists_size || ++ BYTES2CU(char_lists_size) > MAX_PATTERN_SIZE || ++ BYTES2CU(cb->char_lists_size) > MAX_PATTERN_SIZE - BYTES2CU(char_lists_size)) + { + *errorcodeptr = ERR20; /* Pattern is too large */ + return NULL; + } ++ ++ cb->char_lists_size += char_lists_size; + } + else + { +@@ -1789,6 +1796,8 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + Each list is aligned to 32 bit with an optional unused + 16 bit value at the beginning of the character list. */ + ++ PCRE2_ASSERT(char_lists_size <= PCRE2_SIZE_MAX - cb->char_lists_size); ++ + cb->char_lists_size += char_lists_size; + data = (uint8_t*)cb->start_code - cb->char_lists_size; + diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index ef8274c9b1..2f40ef463e 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -19,6 +19,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89156.patch \ file://CVE-2026-89157.patch \ file://CVE-2026-89160.patch \ + file://CVE-2026-89158.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100266 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4B6C7CA9EBD for ; Fri, 9 Oct 2026 18:47:39 +0000 (UTC) Received: from mta-65-225.siemens.flowmailer.net (mta-65-225.siemens.flowmailer.net [185.136.65.225]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2879.1791571658708697867 for ; Fri, 09 Oct 2026 11:47:39 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=n7Vc+U97; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.225, mailfrom: fm-256628-202610091847378dc3effb8d000207f0-w4ctns@rts-flowmailer.siemens.com) Received: by mta-65-225.siemens.flowmailer.net with ESMTPSA id 202610091847378dc3effb8d000207f0 for ; Fri, 09 Oct 2026 20:47:37 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=0INocukSu1uZsFSbHN8lcjxRnqcXGG8r6Xjao9aEflo=; b=n7Vc+U978dBHDVBEMQMSasgaCb0CzNdcSG2/qs+W2jmof6V1UkYluPy+p4/pDuNNJfuqRR 50/2cv8uq9WIbgZm9eqVZshNVIfSiOPTzQkYvfOD6sKXW6PK6bm39JP7xMN+5JOuW0TPJYDC GlKnB0DTl/jnMEAN3dN+fmCBnDXE2Cm7srzvPO+hvjT18XYZenxHDu/oJpRf9/tO07xJfS1z /YyINQCtmhhSkNlRZx9SulMRiv0p5nw73pa80t2CUlyhFGfwZfr/lkX1pRAPjQsvJN2vfR9B yPM5gpAU7zxJWgKeinGv4CtNCMohfCNxqc5z9fpXvHYUIo3ut2VNnmIw==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 7/8] libpcre2: patch CVE-2026-86145 Date: Fri, 9 Oct 2026 20:45:47 +0200 Message-ID: <20261009184548.2962197-7-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247482 From: Peter Marko Pick patch per [1] since [2] does not provide valid commit hash. [1] https://security-tracker.debian.org/tracker/CVE-2026-86145 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-86145.patch | 158 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 159 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch new file mode 100644 index 0000000000..a044a006e5 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch @@ -0,0 +1,158 @@ +From c932e70451eafef922ebef364ac25042f0031135 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix DFA workspace overflows; see GHSA-3r4p-g7gg-ppmf for + details + +CVE: CVE-2026-86145 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135] +Signed-off-by: Peter Marko +--- + src/pcre2_dfa_match.c | 44 ++++++++++++++++++++++++++++++++++++------- + testdata/testinput6 | 7 +++++++ + testdata/testoutput6 | 8 ++++++++ + 3 files changed, 52 insertions(+), 7 deletions(-) + +diff --git a/src/pcre2_dfa_match.c b/src/pcre2_dfa_match.c +index 314e9775..8e9512c4 100644 +--- a/src/pcre2_dfa_match.c ++++ b/src/pcre2_dfa_match.c +@@ -405,8 +405,8 @@ return (mb->callout)(cb, mb->callout_data); + + /* This function is called when internal_dfa_match() is about to be called + recursively and there is insufficient working space left in the current +-workspace block. If there's an existing next block, use it; otherwise get a new +-block unless the heap limit is reached. ++workspace block. If there's a sufficiently large next block, use it; get a new ++block unless the heap limit is (or has been) reached. + + Arguments: + rwsptr pointer to block pointer (updated) +@@ -422,9 +422,18 @@ more_workspace(RWS_anchor **rwsptr, unsigned int ovecsize, dfa_match_block *mb) + { + RWS_anchor *rws = *rwsptr; + RWS_anchor *new; ++uint32_t requested; ++ ++PCRE2_ASSERT(ovecsize <= UINT32_MAX - RWS_RSIZE - RWS_ANCHOR_SIZE); ++requested = RWS_RSIZE + ovecsize + RWS_ANCHOR_SIZE; + + if (rws->next != NULL) + { ++ /* Although the initial block is large, and subsequent ones try to double, the ++ heap limit may cause the last one to be smaller; in this case, we have already ++ hit the heap limit and allocating a larger block will not be possible. */ ++ if (rws->next->size < requested) ++ return PCRE2_ERROR_HEAPLIMIT; + new = rws->next; + } + +@@ -434,14 +443,30 @@ overflow. */ + + else + { +- uint32_t newsize = (rws->size >= UINT32_MAX/(sizeof(int)*2))? UINT32_MAX/sizeof(int) : rws->size * 2; ++ uint32_t newsize = (rws->size >= (UINT32_MAX/sizeof(int))/2)? ++ UINT32_MAX/sizeof(int) : rws->size * 2; + uint32_t newsizeK = newsize/(1024/sizeof(int)); + +- if (newsizeK + mb->heap_used > mb->heap_limit) +- newsizeK = (uint32_t)(mb->heap_limit - mb->heap_used); +- newsize = newsizeK*(1024/sizeof(int)); ++ /* Clamp the allocation to the remaining heap allowance with care for overflows */ + +- if (newsize < RWS_RSIZE + ovecsize + RWS_ANCHOR_SIZE) ++ if (mb->heap_used >= mb->heap_limit) ++ { ++ newsize = 0; ++ newsizeK = 0; ++ } ++ else ++ { ++ PCRE2_SIZE availableK = mb->heap_limit - mb->heap_used; ++ /* newsize always capped at UINT32_MAX/sizeof(int), so newsizeK also capped; ++ and - if availableK is smaller - then multiplication to form newsize is safe */ ++ if (newsizeK > availableK) ++ { ++ newsize = (uint32_t)(availableK*(1024/sizeof(int))); ++ newsizeK = availableK; ++ } ++ } ++ ++ if (newsize < requested) + return PCRE2_ERROR_HEAPLIMIT; + new = mb->memctl.malloc(newsize*sizeof(int), mb->memctl.memory_data); + if (new == NULL) return PCRE2_ERROR_NOMEMORY; +@@ -2801,6 +2826,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + while (*endasscode == OP_ALT) endasscode += GET(endasscode, 1); +@@ -2900,6 +2926,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + while (*endasscode == OP_ALT) endasscode += GET(endasscode, 1); +@@ -2951,6 +2978,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_RSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_RSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_RSIZE; + + /* Check for repeating a recursion without advancing the subject +@@ -3050,6 +3078,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + if (codevalue == OP_BRAPOSZERO) +@@ -3149,6 +3178,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + rc = internal_dfa_match( +diff --git a/testdata/testinput6 b/testdata/testinput6 +index f6f5cbf4..197f6f76 100644 +--- a/testdata/testinput6 ++++ b/testdata/testinput6 +@@ -5263,4 +5263,11 @@ + abc\=replace=xyz + abc\=replace=xyz,substitute_matched + ++# -------------- ++ ++# Test workspace resizing and workspace re-use ++ ++/(*LIMIT_HEAP=4)(?=(?=(?=(?=(?=(?=(?=(?=a))(?R)))))))./ ++ a\=dfa ++ + # End of testinput6 +diff --git a/testdata/testoutput6 b/testdata/testoutput6 +index 8ecf0040..4316c8a6 100644 +--- a/testdata/testoutput6 ++++ b/testdata/testoutput6 +@@ -8237,4 +8237,12 @@ Failed: error -42: pattern contains an item that is not supported for DFA matchi + abc\=replace=xyz,substitute_matched + Failed: error -41: function is not supported for DFA matching + ++# -------------- ++ ++# Test workspace resizing and workspace re-use ++ ++/(*LIMIT_HEAP=4)(?=(?=(?=(?=(?=(?=(?=(?=a))(?R)))))))./ ++ a\=dfa ++Failed: error -63: heap limit exceeded ++ + # End of testinput6 diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 2f40ef463e..60ba56014b 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -20,6 +20,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89157.patch \ file://CVE-2026-89160.patch \ file://CVE-2026-89158.patch \ + file://CVE-2026-86145.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Fri Oct 9 18:45:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100267 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3B551CA601E for ; Fri, 9 Oct 2026 18:47:59 +0000 (UTC) Received: from mta-64-226.siemens.flowmailer.net (mta-64-226.siemens.flowmailer.net [185.136.64.226]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2883.1791571669089184662 for ; Fri, 09 Oct 2026 11:47:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=p3Z1J5Pq; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.226, mailfrom: fm-256628-20261009184747893b9c4fb80002073b-b9qaam@rts-flowmailer.siemens.com) Received: by mta-64-226.siemens.flowmailer.net with ESMTPSA id 20261009184747893b9c4fb80002073b for ; Fri, 09 Oct 2026 20:47:47 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=3GbqYym/xyaNN1ywu3KBnWCcjtgfL1xuC9d9KRwXaOA=; b=p3Z1J5PqQFhHCzybprXvLbZZcfGKBXPYa2X5yFnPqs/J+YxiodbxlaxU97qAlfJnYMb+k1 IOzov5M0nTQQpOuPJP/KiTELhzoJe27Yt8xn/4BOlUA4rvAgLxnH+UmIlQBSpBLEZY2VDSdI QlcSVqGXHrBspM4NlWS/TDI3DBRBmUTlHrgc2HeVQDYyHZq+98otSFuSzMMwuBZlFmTAtvLI wFpQPnvmplPINOuISQ02xisKExFPzT2/lFwtpKeXPmOt1cD+0FuSjzLdG2qfmBiMf9qTxVmW 9D8y6O5T4j+36GM5NJyzgfL5MRC70TAZqhv+RpNzUNNxEqvyEsjt3o+Q==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [wrynose][PATCH 8/8] libpcre2: patch CVE-2026-103111 Date: Fri, 9 Oct 2026 20:45:48 +0200 Message-ID: <20261009184548.2962197-8-peter.marko@siemens.com> In-Reply-To: <20261009184548.2962197-1-peter.marko@siemens.com> References: <20261009184548.2962197-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 18:47:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247483 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-103111 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m Signed-off-by: Peter Marko --- .../libpcre/libpcre2/CVE-2026-103111.patch | 111 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 112 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch new file mode 100644 index 0000000000..6006566d84 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch @@ -0,0 +1,111 @@ +From 2b4038298072684b0fae29b15bedfb1a75bda46d Mon Sep 17 00:00:00 2001 +From: Zoltan Herczeg +Date: Mon, 21 Sep 2026 07:46:13 +0000 +Subject: [PATCH] Fix large JIT stack allocation + +(GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out of bounds write with +arbitrary data. Applications are only affected if using the +pcre2_jit_stack_assign() API to create a growable JIT stack, and then matching +against a pattern with an extremely JIT stack usage, such as a large number of +capturing groups. + +The implications of an out of bounds write could include arbitrary code +execution. + +The issue is not a regression and affects releases 10.48 and earlier. + +CVE: CVE-2026-103111 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/2b4038298072684b0fae29b15bedfb1a75bda46d] +Signed-off-by: Peter Marko +--- + src/pcre2_jit_compile.c | 21 +++++++++++++++++++-- + testdata/testinput17 | 5 +++++ + testdata/testoutput17 | 6 ++++++ + 3 files changed, 30 insertions(+), 2 deletions(-) + +diff --git a/src/pcre2_jit_compile.c b/src/pcre2_jit_compile.c +index 105a1dd3..c5da883c 100644 +--- a/src/pcre2_jit_compile.c ++++ b/src/pcre2_jit_compile.c +@@ -99,7 +99,7 @@ Fast, but limited size. */ + + /* Growth rate for stack allocated by the OS. Should be the multiply + of page size. */ +-#define STACK_GROWTH_RATE 8192 ++#define STACK_GROWTH_RATE (sljit_sw)8192 + + /* Enable to check that the allocation could destroy temporaries. */ + #if defined SLJIT_DEBUG && SLJIT_DEBUG +@@ -472,6 +472,8 @@ typedef struct compiler_common { + BOOL local_quit_available; + /* Currently in a positive assertion. */ + BOOL in_positive_assertion; ++ /* More than STACK_GROWTH_RATE / 2 stack memory is allocated. */ ++ BOOL large_stack_allocation; + /* Newline control. */ + int nltype; + sljit_u32 nlmax; +@@ -3523,6 +3525,8 @@ static SLJIT_INLINE void allocate_stack(compiler_common *common, sljit_s32 size) + DEFINE_COMPILER; + + SLJIT_ASSERT(size > 0); ++if (size > (STACK_GROWTH_RATE / (SSIZE_OF(sw) * 2))) ++ common->large_stack_allocation = TRUE; + OP2(SLJIT_SUB, STACK_TOP, 0, STACK_TOP, 0, SLJIT_IMM, size * SSIZE_OF(sw)); + #ifdef DESTROY_REGISTERS + OP1(SLJIT_MOV, TMP1, 0, SLJIT_IMM, 12345); +@@ -13974,7 +13978,20 @@ SLJIT_ASSERT(TMP1 == SLJIT_R0 && STR_PTR == SLJIT_R1); + + OP1(SLJIT_MOV, SLJIT_MEM1(SLJIT_SP), LOCAL1, STR_PTR, 0); + OP1(SLJIT_MOV, SLJIT_R0, 0, ARGUMENTS, 0); +-OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE); ++if (common->large_stack_allocation) ++ { ++ SLJIT_COMPILE_ASSERT((STACK_GROWTH_RATE & (STACK_GROWTH_RATE - 1)) == 0, stack_growth_must_be_power_of_2); ++ // Negative difference. The positive difference would also use the same amount ++ // of operations, but the last subtraction emits several instructions on x86. ++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_TOP, 0, STACK_LIMIT, 0); ++ // Minimum extra space after allocation. ++ OP2(SLJIT_SUB, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, (STACK_GROWTH_RATE / 2)); ++ // Rounds down negative numbers. ++ OP2(SLJIT_AND, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, ~(STACK_GROWTH_RATE - 1)); ++ OP2(SLJIT_ADD, SLJIT_R1, 0, SLJIT_R1, 0, STACK_LIMIT, 0); ++ } ++else ++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE); + OP1(SLJIT_MOV, SLJIT_R0, 0, SLJIT_MEM1(SLJIT_R0), SLJIT_OFFSETOF(jit_arguments, stack)); + OP1(SLJIT_MOV, STACK_LIMIT, 0, TMP2, 0); + +diff --git a/testdata/testinput17 b/testdata/testinput17 +index a02e6be2..486998b4 100644 +--- a/testdata/testinput17 ++++ b/testdata/testinput17 +@@ -188,6 +188,11 @@ + /(?(R)a*(?1)|((?R))b)/ + \= Expect JIT stack limit reached + aaaabcde ++ ++# A single large stack allocation must grow beyond the current stack top. ++ ++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit ++ AAAAAA\=jitstack=192 + + # Invalid options disable JIT when called via pcre2_match(), causing the + # match to happen via the interpreter, but for fast JIT invalid options are +diff --git a/testdata/testoutput17 b/testdata/testoutput17 +index c678587f..b6e7e1a6 100644 +--- a/testdata/testoutput17 ++++ b/testdata/testoutput17 +@@ -350,6 +350,12 @@ Failed: error -46: JIT stack limit reached + \= Expect JIT stack limit reached + aaaabcde + Failed: error -46: JIT stack limit reached ++ ++# A single large stack allocation must grow beyond the current stack top. ++ ++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit ++ AAAAAA\=jitstack=192 ++Failed: error -46: JIT stack limit reached + + # Invalid options disable JIT when called via pcre2_match(), causing the + # match to happen via the interpreter, but for fast JIT invalid options are diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 60ba56014b..4884ffb092 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -21,6 +21,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89160.patch \ file://CVE-2026-89158.patch \ file://CVE-2026-86145.patch \ + file://CVE-2026-103111.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"