From patchwork Sun Oct 11 08:39:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100295 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1F51CCA9ECA for ; Sun, 11 Oct 2026 08:41:06 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23550.1791708061537838103 for ; Sun, 11 Oct 2026 01:41:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=NqsVy5oc; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-486e70f2457so390886f8f.2 for ; Sun, 11 Oct 2026 01:41:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708060; x=1792312860; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=3AlABoLRDBKEGcZx+vwFThlHxvk7zr3QplF7+erfsIs=; b=NqsVy5ocij6zQ0BvS0fH/TIFRnH9CUZrOCD+2CvlOuVdBtx8bu2s1ALHtcgp5sNfMW fPtStJihyQrfs5JImklpABLF1/xr025GZvmakZD3BgxqqPWljBeJjvp3pH4r4c8BkM83 mJ/JK/hFG3eA4gw2nbCcVVja6lENouEiSWGMw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708060; x=1792312860; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=3AlABoLRDBKEGcZx+vwFThlHxvk7zr3QplF7+erfsIs=; b=OjOoUo27nEo7/mhvPhcIJecRnUxMhW8nKCifuOtss42XQE/+JkfcUMTE2Z6cYkyYnZ mnPJB18ZzBrOULvIf4flHL2axOxA50O97YaaE4W/k6RycWcEyEn3DybaSufsc4LlhYbj i6n1ARwkCPcv0O24yG+B9xyxCGyPSmYGFQnR8tuuar08eXk4vu8F+IoPdxLnbrWjaVh0 x67MIMM+jI7tq/yeWM/WT0yGrNLzBmqvbJhJgGGSDFbRhG6q8fyg1CYfRLtnoe4BddQN plrHtYEzxxhGgI0uL8Uo6J8UIUPeq7DnHhjrYqBvp1w6eHTB+vkKJ677862uISoH0def GsrQ== X-Gm-Message-State: AFq9FYJuUemEWgO9O+OURvyX4xkpKjJk+lbqIAR2GA9grF8PLd9/l1rC BphOi5sORM+vkJWLUalDzC2rDRY9QoIQ7dxVFGDlzPqc4vuRRHqBpI3A65um/uxrItj0IrM3JpP WeJ+xUrs= X-Gm-Gg: AYBFou1EPMeEP3/wKUBDjn1xbvE4RU2o1yLaWIJv2dWuL/G5ienxpLXo8VTtzNh6pwe snNBItdJ0ugIumaJQYWfdOMWv/+z29ZLo4E9BVq3aUZZZVUCVyetZyMD0uRWEuPDEMTQKf/+DgN j2kKH7aJEfWr4ew5IEOdzi8Cgr2ASJCV8YoU09oQ7wuoKlfNh+nf0zAFPhFfMvScamrAdTWxGan z9NmkUo+SnR39UhxsGptedPYGqnweyaoocHId+QSQ7rAfsDknNLAqhUsq2CC1OIgCfYVENtsEbg bvO0h+cKjdMd/jDM98z2ip13pVy00ma255r4CCa6f/ZkD/FSD27jITCIX2CfO1KW7+cUttnHjDu arQ0G7DohvyBlCi6xRyRnZyv6WK+xJdqm7awhlXEIgyE1ZIWLh3fAkRT24fY2ZqrG7EJENPeh8J I0TwEON9/GQG3004XOD0Hi2ZWkHiWTxvYFAQ8VpOuNDEfviOAqzzdkLo1wmlsBacc7dXVss1mJP JD1POmnvQjvEDeieEk8XOpAbazFdABNo8uR0cZWB97osE3lNZVPO/FEMfjQSOCIQqUBm9yaqQ== X-Received: by 2002:a05:6000:2905:b0:48c:6d9d:9f90 with SMTP id ffacd0b85a97d-48dba9d0b47mr13252971f8f.26.1791708058713; Sun, 11 Oct 2026 01:40:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.40.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:40:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/60] glibc: set status for CVE-2011-0536 and CVE-2025-0577 Date: Sun, 11 Oct 2026 10:39:34 +0200 Message-ID: <5eeaf71f4201f523d241d98c3b83819a12cf4ced.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247510 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). * CVE-2011-0536: CVE desciption says it's related to RedHat patches * CVE-2025-0577: [1] linked CVE report says it's related to RedHat patches and no upstream release is impacted [1] https://bugzilla.redhat.com/show_bug.cgi?id=2338871 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 85babe3703588b00a03f7087c54440243a993ee5) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-core/glibc/glibc_2.43.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 9f3a3814d0a..5c21223b55f 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -16,6 +16,9 @@ CVE_STATUS[CVE-2019-1010025] = "disputed: \ Allows for ASLR bypass so can bypass some hardening, not an exploit in itself, may allow \ easier access for another. 'ASLR bypass itself is not a vulnerability.'" +CVE_STATUS[CVE-2011-0536] = "not-applicable-platform: specific to RHEL patches" +CVE_STATUS[CVE-2025-0577] = "not-applicable-platform: specific to RHEL patches" + CVE_STATUS_GROUPS += "CVE_STATUS_STABLE_BACKPORTS" CVE_STATUS_STABLE_BACKPORTS = "CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 CVE-2026-4437 CVE-2026-4438 \ CVE-2026-4046 \ From patchwork Sun Oct 11 08:39:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100298 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3C297CA9ED2 for ; Sun, 11 Oct 2026 08:41:07 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23424.1791708062204457840 for ; Sun, 11 Oct 2026 01:41:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=AfYgngzo; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4a020e65269so5685925e9.2 for ; Sun, 11 Oct 2026 01:41:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708060; x=1792312860; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=iaKThuqlZbIuVaurpFXZ3Wv5Kkr5PlG8vNXZzfWfKxs=; b=AfYgngzomiMpkdVAsgO1t/F2Zc8Fdsj51F4juC/O7pGcWawp2LJqg4aaY8BEIJpZh8 Xy7yMrRK195JmqhU3NkvcY1bZaKnk3ypvc3JiIwzrqlTvBjjkyBI1RBtZmwjjuiIyWiF 0LvjqZYkFTIaZ0l6XfKCTHtnsU+pPSEm/NaQI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708060; x=1792312860; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=iaKThuqlZbIuVaurpFXZ3Wv5Kkr5PlG8vNXZzfWfKxs=; b=MDYZ8xMgVJQbKVdAbxe9mN+nYd3+QLkCdjYxoUmzOrZHYAZY7aJ0ANOEZV8uGTypeA JtnTPU4o2uGiwCPW+XdJpvfcg8CAM5U0uIL8C15EbP9d/252HBDvlzI12mZb+NElcUDD SBiGOdNzWIPcseZAOr08WCxVUrHq6bm7Jvzh9TmCkQcNZ+fW98YNIz3qBmQ8W0klFLxL rGrSYHUPuInQnTOqee2cK8aInrJVlQkH3aN3n97cuGOqdb/aj49RX2l2b/6tspSLUbA8 MHZWL3IpyA5Qtrv7nmSltqE1aX05YcGjwcpQuz0krfezaQ6xKS8hxBFkQxl2fqIr65hI oyuQ== X-Gm-Message-State: AFq9FYJk4FAozSlMdxKcYjUszy33GxOIN2b1JbrC2EPYvp21KY3jiMg7 oqRNzX3m3Zj2oD33j/9juOjXNUNrll7zrkAkCGMxiIbEz5nJ+VaC6gqyYsfFGKJxH8+W2TC1pAg RDaPLMQc= X-Gm-Gg: AYBFou1tLuCeRh2uFHu1dje7jPOh4B2RyEqZ0WE7BeNxg8b1AHxLyRQWNscAOs/+Dqi NK6D4Zzcpxy80sXgXc7Q2Fgbh1oJJGOb+C6jtzvth/t+GXXWa0DHu/FVZgM/SkxO+Omug0w7wLS KQAiDhn750dqJOfagT6x/KtEuDqhF0RGEUdBbzYdn2klpjAdrSEyb+2dvHRIUBFRGfRSSW2bniz gNv8i4l8UnygrieSzNhTshaAfCcM9mZ3EF7w2wtm2XxXPI7esGVvCI4A97FnNaQtwZxPsViAC60 XiUQChl+65g7/qMjL2jPUDEdcYjmPsGrEBrufm5Gc1B/lRQ9WjtFeehQ1X5f6rpRY/R8Ylss0MC Ije8v/bDWUsuo0ZOJt1hh+UagjsWkU/0hUXN2mIHwTKIP1e+XFUnQVn7prWEQyZln1OQhNRZN2v /G5bJzzKI2XlyAK0Nt1VL9wb/LPOPHxrqjCJZLFYmFQnb0qOawjvM/N33DVb/Ae+LidAkMWMSLA 5Ds0QKWfuY5F3dOr2Vi7seSfPrPxU2JGAX41x4tV/gK2WD8Bd039irOmydgakJN354f6ou0Hw== X-Received: by 2002:a05:600c:3e16:b0:4a1:992f:d0e7 with SMTP id 5b1f17b1804b1-4a1992fd259mr28338575e9.16.1791708060278; Sun, 11 Oct 2026 01:41:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.40.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:40:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/60] gnutls: set status for CVE-2023-0361 Date: Sun, 11 Oct 2026 10:39:35 +0200 Message-ID: <16990a4d1c3c24112eeeecc7494adc3ead0a1998.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247511 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this CVE was fixed in v3.8.0. [1] https://security-tracker.debian.org/tracker/CVE-2023-0361 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 9d9b944d390efdf45196e53e4283e3ec2acfd0fd) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index 538fd9c9e0d..92854eeaf9c 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -123,6 +123,7 @@ pkg_postinst_ontarget:${PN}-fips () { fi } +CVE_STATUS[CVE-2023-0361] = "fixed-version: fixed in version 3.8.0" CVE_STATUS[CVE-2025-32989] = "fixed-version: fixed in version 3.8.10" CVE_STATUS[CVE-2025-32990] = "fixed-version: fixed in version 3.8.10" CVE_STATUS[CVE-2026-1584] = "fixed-version: fixed in version 3.8.12" From patchwork Sun Oct 11 08:39:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100296 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7F025CA9ECF for ; Sun, 11 Oct 2026 08:41:06 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23552.1791708062830826378 for ; Sun, 11 Oct 2026 01:41:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=d7h9EXJx; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4a180fbeef5so8743855e9.1 for ; Sun, 11 Oct 2026 01:41:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708061; x=1792312861; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pD7trybnOoUKfXdjQqb5bGjwMzL7cyTBsfJeC2xOMh8=; b=d7h9EXJx8oP5v50myucBV/I+t52Gcm69HIWjqcrZrKUoGbn5qO5oYxqfMl8FdvdBHK IDmluB8BFu9iV2VMI8p1oCMErtp7u0lyd2NzBrJw24sZpJhYv7yqngLgxs/MXwHPtA8O KxVNJi7PImSPEsLHPbIZuf3BCHgohKvDzVI1w= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708061; x=1792312861; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pD7trybnOoUKfXdjQqb5bGjwMzL7cyTBsfJeC2xOMh8=; b=xx8Pt9cIAGZbviePJULoMVlDK/V99gij2p1lX81bIqNns382GSm685M6Up65FIY93/ PulrbWHzZ44v7nImL0t2nUSc6hsO7o06eKa5p4k93NfD/3JtVIe6SyTCnGlgR/bBdKIQ rdFKZatOVzN5DEl1qC2XDVy4k8PNXNOW9h9IFjeK8031IWVaauKzhfSROFq/fagr/bQa sqhU9maV5kc3ptFffVv7+F9N7yHWX00Pl++vdH+s09otqduNeubAOi8FMx2dCqeRKMFy j81RlnkGRT723/LZP5ctOrWDfNlNaSaTFiMI4cuQ30FWHv2MvsCtJLq3Q9P1qupPwuoC bQ6Q== X-Gm-Message-State: AFq9FYID5wMvZGDN43GczbzMisa5VhtUt0JJBo6ND4a1+12OAAslnRQd FXRIdCUaajKSBj50g45jwYBsf5EAwtuajJx7mFnpmj/MUQmDkGYBxafyz/dYvs0vqBhIToMIw/q dt/JxQ8w= X-Gm-Gg: AYBFou3aCKILGDNS8GENzMflpwF91cxZoB5tJBm1GUCH//jvxmYhP0QOZ9ldtXtLdN6 njf5VhdGDNv6mzegJeLLXFNA6ACXonWMmF5Ut8VQfEEUZQCt6dJ9GDfkxUT5tX4g1M2h8xkjWlI +c6fbtOgkQ+35wqDLP6SXhxmoGhZIIVZxMru+KIxk/5A00/NSx0auYsY0+U5xkzvFR2eKSY0NMz Zd7gVdO7IuJUXYRF8nHb6LiyYJdqQpAy5nxaaVyFeUQU5owfgD5T5cRQziGC06G74qsZFNvLreV tEGJAjIwjHAOljenU1EazAVRrVO5Nbu507h88BaRBmBRHHrCGnHmFo5tmCsHIhsgj+6nOAvK57E f46vsPd3SOP+n/y8bySmC5tlM6wiZBUeqKGMQufvHt7kEs9R52szMK/e2wwJgmjEJAU+8WIHNuR 1tUHYsFDgdx7aoNv9fj6rxwRGa6bYZq89mucAg5fq+HKG3B+0nDrJgqicZRux4I4xRqIfiYji3j 0G6DNL9mMU6zv6WVG6ZR/FmGcgDfUkHm2qIMegU7JBVcI/fjzE6Ew0p3QvlHx+5gmn4GZuVYw== X-Received: by 2002:a05:600c:3f0c:b0:4a1:85d9:13be with SMTP id 5b1f17b1804b1-4a18e498471mr135427615e9.20.1791708061140; Sun, 11 Oct 2026 01:41:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/60] libarchive: set status for CVE-2026-4424 Date: Sun, 11 Oct 2026 10:39:36 +0200 Message-ID: <2cc935e7deeffe8483d634df2c2ff7a7f95eb15a.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247512 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). These are RedHat CVEs listing version-less or distro versions. Release 3.8.7 notes [1] contain reference to pull [2] from NVD report. [1] https://github.com/libarchive/libarchive/releases/tag/v3.8.7 [2] https://github.com/libarchive/libarchive/pull/2898 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 4359d85f9dcb0a6d188859f1ae0200352668b9cc) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-extended/libarchive/libarchive_3.8.7.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb index afc06f85d4c..c0a29211434 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb @@ -89,6 +89,7 @@ do_install_ptest() { RDEPENDS:${PN}-ptest += "bsdtar bsdcpio" +CVE_STATUS[CVE-2026-4424] = "fixed-version: fixed since 3.8.7" CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7" CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7" CVE_STATUS[CVE-2026-5745] = "fixed-version: fixed since 3.8.6" From patchwork Sun Oct 11 08:39:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100299 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6C08BCA9EC9 for ; Sun, 11 Oct 2026 08:41:06 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23553.1791708063745757095 for ; Sun, 11 Oct 2026 01:41:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DKizT6WE; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-48c4649b35bso863951f8f.3 for ; Sun, 11 Oct 2026 01:41:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708062; x=1792312862; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=XxrNC/IQ2cVlrvZjo3AB5P+cC2Fk24Mha2MmQ2ABUtU=; b=DKizT6WEvXIAc3N6wV/Dcfh44/y/SDqjD006gZOvKid5cjYuzRYk6z/E/5zHDFthgs LFW9rkBoITHuLxtUwhBvpot/JvCmStW/fl87e0FsZH/YoA8Py4o6nJQ7yANakWnqh7Uy vPHQIXIfGPOeIBf/8my6Bm1bvSbVoGYvZOWak= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708062; x=1792312862; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=XxrNC/IQ2cVlrvZjo3AB5P+cC2Fk24Mha2MmQ2ABUtU=; b=KOx7QnLOfeJj1OxP03X2K7E3vSU2XbBrvP/OTbG44AnBa0LxstKiVoPPMdHAReMnj9 EHSNTtiDf8UAS3DtCl1zX51F+jWeJJS55JvC6VPXGUsrZkENahFki68uuTaGbNRGtyVf I3GDXgOdRUQ794o1ESfaG03db6AK0ZGsNjygAwRMAKocZ8/uDJrZRSoJFQsTWnP2TMO/ /IAqzzmDptFbwtK/VKIZzCkPfCWa7oupXtNq4tvyLjZgbIKN18xp22ihB4Og28Nb4UNt wXegvv5G3AkkMWzEC6lwwGOVlr83H21yZFooe9dloytlE1Tn7nHwvzfei3oA1FYAYyOE ysEw== X-Gm-Message-State: AFq9FYI2u6/RWuJx2aEzUF65yxoUfK0oU0s2RnGVCTAGWYMMsPavlmNC VC7aCvUz10wFZ7bNBboRh2EIuo0oB6UdqJJ2YVfAv1+atdZo2+UihVaabUW5o0hhPE+JMYakIzq qXSn3PxQ= X-Gm-Gg: AYBFou2IvX1cyoJ6NWodDvK0Qb8cPjftoRxwiexXJRcTnfGW0+dX744ll5vo/m8yqWu MifqQm1j9f9z1eECEZZrRNGDTQq6pCdrLlXpuiJdJc88O4rS3o11nB2hrOKjr+PcH7c56iAmo/e 1d6E3mAhsjY+0iya+GljfYKMfBCa+CUnLkOaP4H2vLJdEDyOtlvXULYDsPSJtfkTiLG2w6NSuDr hAT3lJikU7EPj3lx5PtYuBwLY+S9aEF0KxpzCsCtwhrC6JVBjN/+9r+Swpv1TduJe7G2UV7lsZ1 CDHyIA6wJ7OcR5sjGnRGP7LL7Uh4Dsi+W5dI97lMRNlEpNz63P9WN7pNCtUa5vXAI+jsZfrXW3h RY9VCdVpcbrQqTV4y3iTydCAkFNtBE2HwAafQ+5IOzDFMmPj4FgZvzCKWOpMPooQ3SoIBVDH2Ah FTCP7QWSuB7sJG/1dq7lRRIOHrxZwiMoJCsCtze9x26fvRJCHmBYQxSSq4uUh4RtMMDxG5KAbZo W+NWHyCXQ/K/a0fFdkZ1sSpBtijcy24DnqgR32oo2o28aBRy/wmSIl+VAt8Z3ah9YesWF5q3w== X-Received: by 2002:a05:6000:2407:b0:487:1ddc:aaff with SMTP id ffacd0b85a97d-48dbace40cfmr10701350f8f.44.1791708061749; Sun, 11 Oct 2026 01:41:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/60] nfs-utils: set status for CVE-2025-12801 Date: Sun, 11 Oct 2026 10:39:37 +0200 Message-ID: <5a823c360be13dcc60a870eea6f1af1b60b95f0b.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247513 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). This is RedHat version-less CVE. Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 2bb062e403c7093734de6467c49503a7d8970d9e) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/nfs-utils/nfs-utils_2.8.7.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-connectivity/nfs-utils/nfs-utils_2.8.7.bb b/meta/recipes-connectivity/nfs-utils/nfs-utils_2.8.7.bb index 7693a88682f..a5ebf7043e7 100644 --- a/meta/recipes-connectivity/nfs-utils/nfs-utils_2.8.7.bb +++ b/meta/recipes-connectivity/nfs-utils/nfs-utils_2.8.7.bb @@ -147,3 +147,5 @@ do_install:append () { chown -R rpcuser:rpcuser ${D}${localstatedir}/lib/nfs/statd chmod 0644 ${D}${localstatedir}/lib/nfs/statd/state } + +CVE_STATUS[CVE-2025-12801] = "fixed-version: Fixed since v2.8.6" From patchwork Sun Oct 11 08:39:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100294 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0FBFACA9EC7 for ; Sun, 11 Oct 2026 08:41:06 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23425.1791708064294227446 for ; Sun, 11 Oct 2026 01:41:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=dAkpiz8W; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48af4d4e61fso514713f8f.2 for ; Sun, 11 Oct 2026 01:41:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708062; x=1792312862; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=4POro0R/iNnVbB8QmrbPQr11Gzmu81AHg4d6nzWFvlM=; b=dAkpiz8WoP2btMw+U8p75/xQUoiydGFVydy1bf/FSVwbZ5fBPKMKvPt4UxFNsJ2mlR CSetr2wE9yt30p62wgtxmwWXeYgQLFq+sT467YisORsGx4M3kyV66uKKZ/GWxYkQVB2d WoLm0nyN8VuFWeuTmXIJ0G4h9CbCqr622FfL4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708062; x=1792312862; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=4POro0R/iNnVbB8QmrbPQr11Gzmu81AHg4d6nzWFvlM=; b=DvEF67Bfb+VLuUoslKZ96jg5RI0TEoycJbuZM2marGy5m2Zo1t/FuC5HYt8T/KJ266 BvVV4oZHtrruTv9/RAYl18LKvTtLep4Fu/Kl5ANGbosEUzBiMXaN/2ouQVAVDAhaSu9y bNPaYuTrAlec6robydKOm6DMthV80Q6M1z2IROw6peT09d0Xy/B8ktXBXVnvQmgTZUQq iEMNdis8PTdVI7eP9NTUi9x9w0HUJyHO457FE8TuM7Gyvroy19dlxQmSnqC55NVeR/75 ANqDqjBKzV+tpMpjzoG8zjiCXdNx2L2s5McnLijEZ7vrUT59ALHHpP7dwlb+vV+IS40E be8A== X-Gm-Message-State: AFq9FYK/4cIeksHRn8iCyCnQkp46c07IqINWKAAJQPh0UwwPERQmioFy FPWSKQTwDVV3qZ71E9CJV4DZQ1AYc1/GGQzKXsS5lMOD/oPLaLQG983sRsXiY3bdSqxX/gulk4Y rdEIInCg= X-Gm-Gg: AYBFou1Umz5P5QE2VJOUxcPIiq5S894aIooX7byzxZOBSCb4HCsgSH9ONKlma+QCT9A lRXxXndWK2bD8WlvDHrwv+hl1zY4WyHe8fGN2szNSGFq4AD4cb1jaQp84j4R3Ytg0xPbeu7f/S3 HBt6077J7VQIib8XYR4b24VjzmdfM6HvWRa+21z32cxdMzoIdIsK0VOHRd5suKujVY3YTxKFfN7 kxJet/3Selsj9exJUQw1wEqElSczDzHpAmZfSMxSdlCpsAZgap3+j7f/+8QdznVQyyrDqhAhZJB 2awre41pz0vxkAjlkWI/azvNJ8oPv3QkdafCSSff7fcK6z3kpj6vlntN60Sx3J8EZ4XUybKnhGy zUu7B0au6EVAVnrZ/maz1+SYx5hnsTbEJnN8MwBOVqqHxEhkkeo6vpkdBCyHp/zwoJoMty/5pnR Yu52M/n/4tgtqPv3+TdyG7mfRoRT69q5mGCaFj7j16uISXWKY+w1o1TLNB89MLIWz9J7KQDPi6e MqUckd6Zil7/UQET2tWrKBQPJEEs4QmJN3bwmgGOpJOQ9uSDKOW3bVvKRfwI3BlRc7ILE1vHA== X-Received: by 2002:a05:6000:469c:b0:48d:b75d:30f6 with SMTP id ffacd0b85a97d-48dbad1226cmr7031406f8f.35.1791708062523; Sun, 11 Oct 2026 01:41:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/60] openssl: set status for CVE-2015-3216 Date: Sun, 11 Oct 2026 10:39:38 +0200 Message-ID: <64731c4dcd827574424b6ab297e1235c1231c409.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247514 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this fffects Red Hat specific patch. [1] https://security-tracker.debian.org/tracker/CVE-2015-3216 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 0353d7f67e6fedfc10e9ca56a6bf5f3ca9e215e8) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/openssl/openssl_3.5.8.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb index d8cae41291a..71446e62e31 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb @@ -301,3 +301,5 @@ INSANE_SKIP:${PN} = "already-stripped" BBCLASSEXTEND = "native nativesdk" CVE_PRODUCT = "openssl:openssl" + +CVE_STATUS[CVE-2015-3216] = "not-applicable-platform: specific to RHEL patches" From patchwork Sun Oct 11 08:39:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100297 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3969CA9ED0 for ; Sun, 11 Oct 2026 08:41:06 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23557.1791708064943136866 for ; Sun, 11 Oct 2026 01:41:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2FKG35qw; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-48b042c0728so142836f8f.1 for ; Sun, 11 Oct 2026 01:41:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708063; x=1792312863; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=kZqQnKu/8mZh0OsxmNrw2ySDLNirZ3Jwtzb/EghNPUI=; b=2FKG35qwsqPnk6dmvD8+yJDUPeDG0Gs9QSJ9U8uYaupeoFU7fjYyyBp9YLZTj6IPa+ zTU9A1pnIOy/7YiCdpyZGkpus2b8t7VJIUI3MyaovWfdYMElZ6npF9UBh3zaw42IJNqn ZHlPeN6XcnxWcDv3djAnG8k3zl22ly0w3lLJw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708063; x=1792312863; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=kZqQnKu/8mZh0OsxmNrw2ySDLNirZ3Jwtzb/EghNPUI=; b=nw3yeN15jJ6HsBD+iYMKp9ixx36QTx1Vp9ANuRQVBl3C4vM1v9/UOOw8xUkiXk75BZ dVbsEXtaBBH/tRrQ3QSR3WjAb2h0vTKA0Tkoyz56bfo2f+pjlPnq9zTud+Nd3ouE9yHC DmN1nz3RCmroqGibh5irMXta6LeKWN1O46I+AvT8eq64y13mRoihdkeXt5cgWdw2Hc0z xMF1KJ4Rxef8tZ6Unb6xAzbkhqxrbkHyXw/MIpDWD+JTopPBkI6rm3EmSCZoA7u5u949 gH0L9ROGdlIpnM1UPfy6xyljqmsbJUvsI2tjF+ZUOyKzNX+PVJFBZ+UTVDk5+EoblZNj jOoA== X-Gm-Message-State: AFq9FYIk6F8IPN04pDRA4a9JdfzOKsjnXb2pk5ou46ZZbJCxBDAGwNrk rQX/NC8S5xk6pK41UgxBGofvDrNghiza2W23d+dWvEdS7Zr1pxfh8uXJzHLUAVQpHcUhrOWWRXl mVQ9iQP0= X-Gm-Gg: AYBFou0XfdyEuD1+Sz59AZKT96AqnxCUuiZJcgmcK3cXahLTz9vvJjRZzmDfgR03h1d +yxiZsYx8ILmBPNiyXWKeJpvu8hO+5WEHwgjt2J6UzGP994HdlpjfiQOj5ak+3J+vQidA9KMqD0 rX6UcRKKESloF6/NZC7k5YjafE/cRqONWvtsA/1dBNEpxDQb2BgwaIPL4NtvuIUOi6YvIBMu1Uz akfudUqPExDossZVwhv4ajuFQ9OK8GMTF7y+60s5w1EtY8cS524hs/Pdzg8b2QCu8GPmNihxyUu HcfAwmSXXDUwWAg+m35J310Umtz0GXSxuLBAJ0EfYn07o52tqsCksKAgSOiI8l7k5WOmlyWhils M6hET72+QVry3gctVCTSOqZsXkuoTVA3NNszJbw2bAah3kx8jl3y4FvFWJOhNuifmj8DERYZEGO 6i4SYgofn+A3FWjN1K/g9CeSEymTdDaSDP84/SBpjyXWFKV5eSX0jchZqtRw7e7b5/+0cTD274d WQ2sxOxHYZxe7VH44wvx8n1TdzBS8/A53KZ5xP8kF+qBX1XngY/fegGj3jfHQQ7LYPIFEG62w== X-Received: by 2002:a05:6000:4b0d:b0:48b:d2d:2fcc with SMTP id ffacd0b85a97d-48dbaade73amr11046434f8f.9.1791708063067; Sun, 11 Oct 2026 01:41:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/60] ovmf: set status of CVE-2017-5731 and CVE-2019-14584 Date: Sun, 11 Oct 2026 10:39:39 +0200 Message-ID: <6131cb81820260cefb20bf03663b597546ef52b7.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247515 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). OVMF has a generic problem that version is encoded in different ways. Both CVE have their fixed version in NVD CVE reports encoded as YYYY-MM-DD... CVE-2017-5731 additionally predates tags in vurrent git repository. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 1ac5e07968d2dc23343ca3a7c1eab7c3788fff41) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-core/ovmf/ovmf_git.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-core/ovmf/ovmf_git.bb b/meta/recipes-core/ovmf/ovmf_git.bb index 01f840c2154..cd6a40a9d07 100644 --- a/meta/recipes-core/ovmf/ovmf_git.bb +++ b/meta/recipes-core/ovmf/ovmf_git.bb @@ -40,11 +40,13 @@ CVE_VERSION = "${@d.getVar('PV').split('stable')[1]}" CVE_STATUS[CVE-2014-8271] = "fixed-version: Fixed in svn_16280, which is an unusual versioning breaking version comparison." CVE_STATUS[CVE-2014-4859] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2014-4860] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." +CVE_STATUS[CVE-2017-5731] = "fixed-version: fixed since 2017-11-07" CVE_STATUS[CVE-2019-14553] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14559] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14562] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14563] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14575] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." +CVE_STATUS[CVE-2019-14584] = "fixed-version: fixed since edk2-stables202011" CVE_STATUS[CVE-2019-14586] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14587] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2024-1298] = "fixed-version: fixed since edk2-stable202405" From patchwork Sun Oct 11 08:39:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100302 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9CE8BCA9ED5 for ; Sun, 11 Oct 2026 08:41:07 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23558.1791708065570755917 for ; Sun, 11 Oct 2026 01:41:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SP5Lcexj; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48c411d6615so542313f8f.3 for ; Sun, 11 Oct 2026 01:41:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708064; x=1792312864; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=DZjjLcDCtbNRqsZUJw7VODyYTXvq9fliRaBgHcEn7wM=; b=SP5LcexjxlPN+mnKLf4J7imjYy30GkdNBv2TuW0naQSZ79V209syXCyo21CTsgpbHJ 2n1Gd9xzWwR+IKpwlZoTnYwEsQFfNKayhWBqKcrwnfmrd+f+tXFFPhQdvXTQLzrKAjZE dLgO/gJHNV9+urZwBknhTIbLg8Yrd1WVCs52g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708064; x=1792312864; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=DZjjLcDCtbNRqsZUJw7VODyYTXvq9fliRaBgHcEn7wM=; b=AsZ44Sj5ZadMzZuPEwoAYcxPxipzycCxswENSizuFvDYR0vP0vU1c4B8pj0xGGPEt6 psdNJXFkWgbqQKkVhpvD0H7k2hW9ESooHGkydfvE2eo3pXAr6zIaAca4J0YtRgL7ji9T W1Qe4M4UNcq7ViyjhRsE+hmKAN3Glx9oGA+3/FoJ+axro+xcQKs1XMrWvS4vMXHd1VSa KVLM7vG7k4h0fOkedJGAkeKYzRddiz2rbwC+Yh9PwdNIk0R2XM3TF+CnwvksDTFA1OTo R0zUBjZBjkmyqvFqIEWeGaKF8teSLjdHKbSKBhB+8wuli4iWTuxrqGDB0DSgpBJcyVsN Ey2w== X-Gm-Message-State: AFq9FYLctgFOBPMRpMiItWDH5finSzqqNrk3fu/3by5clm7FP+YkuVjC syUbCv1b8KF/VHDt3B1LeSNbAWrEfWDfv2xAz9PZbK3xp2ECVQYKk/0EplQ9VemTADsCtYDmb42 jwkN7ERg= X-Gm-Gg: AYBFou1vf1BENHloLNbufbCUNzo1VpfUC7TLiOxXE9CnZ8AE0TKw2uIRWrmzS/4FpfI J7l8GHjoLy79Xt0eMvyEsYFpop7vRhM6338JBhMZNLwYOeR1sNL3rpQzOZ1dkXiE28UYfG6Lh64 aeWieLi9ui1y8LLKM1jkA3h10PaEWw7KsaDSt7HISXyfDE8CjLXoDJl2qAp07qNNaG7eWR/QvEb FKryhAckvN2mj3FxrZ/gsa29YEgupI97i25+3TOWayKDKnJ0IcBo5ojY5Q1apGtRjYbRI39hY1s LrtQ59BfdObiUJDzKKYZgGahE2f3oMRayM2sOnL8wzF6MXsiZtxcLvBDyxJ21WY3XAHKwSTdRBE RVLLwTBwUVbQlRK0N2LSeXfEFYfX3MJ0+VGk+m+xgnCrlZrs9rtFE0N3GB1OLJzsl3NdtyLCGBx sgsNe7j+gPH1NUzYMurgbmKAQJBXGN3kC+A1WAo3d5b2lRuAi2wivGh3gzKh69MaoQN1wEqzGRF 2QoS7EROUis6+oa0rCBRav5WxcXcABnmgJeqKUSP9wu1ZBesl7TBIODOI/I9BW8v6HUXVV8HA== X-Received: by 2002:a05:600c:4ec9:b0:4a1:8961:78dd with SMTP id 5b1f17b1804b1-4a18e4c9e46mr124780195e9.27.1791708063740; Sun, 11 Oct 2026 01:41:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/60] ppp: set status for CVE-2020-15704 Date: Sun, 11 Oct 2026 10:39:40 +0200 Message-ID: <26bcc748aee748d6c05682c7bab04c2221a95c94.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247516 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this is Ubuntu-specific issue. [1] https://security-tracker.debian.org/tracker/CVE-2020-15704 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 1f875a76c3b5aca955f705163b07dd1fe20373be) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/ppp/ppp_2.5.2.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/ppp/ppp_2.5.2.bb b/meta/recipes-connectivity/ppp/ppp_2.5.2.bb index 37e223b4abe..698d6930ebe 100644 --- a/meta/recipes-connectivity/ppp/ppp_2.5.2.bb +++ b/meta/recipes-connectivity/ppp/ppp_2.5.2.bb @@ -79,3 +79,4 @@ SUMMARY:${PN}-password = "Plugin for PPP to get passwords via a pipe" SUMMARY:${PN}-l2tp = "Plugin for PPP for l2tp support" SUMMARY:${PN}-tools = "Additional tools for the PPP package" +CVE_STATUS[CVE-2020-15704] = "not-applicable-platform: specific to Ubuntu" From patchwork Sun Oct 11 08:39:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100301 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8FEA0CA9ED3 for ; Sun, 11 Oct 2026 08:41:07 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23428.1791708066091022406 for ; Sun, 11 Oct 2026 01:41:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eHDC6tHa; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48c02782159so553385f8f.0 for ; Sun, 11 Oct 2026 01:41:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708064; x=1792312864; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=B+f1JEQ/tlxS0qhtHIA25Ioj3m7kgjXXelU1ui0Msgw=; b=eHDC6tHa3FUyBHh0WNUXT4ejdBtj4vVB9813AkDixkjtK2NOZpftW9IUi3K3hIYU0d G64tfJHvy9X6efvpc+Bl4zIpLfF+G3NGwOZMwltM26SB/pINEwPwyDZhe3VgnZvjfWdi 5QDevmvgP/B9CuLOyRNk2drijj8jGLMvNYIrY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708064; x=1792312864; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=B+f1JEQ/tlxS0qhtHIA25Ioj3m7kgjXXelU1ui0Msgw=; b=aDpxxfpiLQnCD/qtprKcG0mHJT8jubwI9vqTtmVXiQWQZYKmfGxBpZcTY+wsMIlMhF jcnJU4BwLHvFLS9lia3Vdl7rs8yRp8q7AlHhEV6s5jwaZT+pe4ysQ/m9ytszJyhynyyL MXJyj0hqmDT4bWsrCjFgsFmP/aaUEqVDJSxPk6RwKzfMuO4znR2Ve0y+dsKKPKOjiNor WbZCo/yeO2bikCAbYhap2j+3p68M74MY5uNbP7VvErgOpUDEhe5Uo2t/CitvK/bpIHwI mnvOjVYWWDv9rbnjrrfyRrgifwGrzAHkvv8KHN3SaMnhNAL/NJMqsyYO6PwTgOXSW7vE mdgw== X-Gm-Message-State: AFq9FYK1Prup88faueMfVWXAMr8Vh2R6AODoetvTSQAXRcy4vSXHOB2a 3xfJPmQIGa1qLVX3L9/x0G9Ur3ZBiT3HOSrm0vifYFDdrRBbUnNSsT3JuJ85vXq7uYD+GR8WI7T tvqwGBpI= X-Gm-Gg: AYBFou2JDIudVyfm1+b2jRSK2ARbkzs7rDe85ZmtpJHkh5PJtl3r5/fanQDWHEeqsAf kEPlW7rjXwcsRxNsoSYqU3EyRjyInD2UKQEx1DHPCsnMAICIps+QZ4cxrurCaGdyGJOuhMtZ05M F3W5vq4FfByT1Ij0sJkEXisuodYPoKFwTS+0eclggwBJrILM2vCk4USOiW/gQLmTc9+dAt/Y1rv DR4f0b/GmxualKXBnaKuRPzaU0YdE2GKy4gJU1qbu5gSqEzC350vgsRH2b4ScRcYtN5Eom28pth VL/5SGw1zJIgY46yxeyIUcYXSg1DKDRj5LQi6Bp3/SVcOblRRND0A2P/gM7iMX3JKaftYh2GjLh aD68Jt9D9wnTaZ33mVTR9PjJbo86kWzFFNFsYwyeG4BoDCDZ229fEEOZVo8gq4OOq3a1zDMRKme FElGef0LLPEKx7w7r0M6YgDTXulfvSDlz2piiK6LhKn9Orn9PB497ZaoB43Irocavn+vMhlxhNJ iki/mdQfrjHnDZEpxOQoBFtnBsedFxc9mfOMEb9t7VcaCZio7VcV9GzC+kVDjEJjETiDG7Dbg== X-Received: by 2002:a05:6000:4288:b0:488:6ed9:b11d with SMTP id ffacd0b85a97d-48dbacf554cmr11210939f8f.52.1791708064281; Sun, 11 Oct 2026 01:41:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/60] pulseaudio: set status for CVE-2020-15710 and CVE-2020-16123 Date: Sun, 11 Oct 2026 10:39:41 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247517 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] and [2] these are Ubuntu specific CVEs. [1] https://security-tracker.debian.org/tracker/CVE-2020-15710 [2] https://security-tracker.debian.org/tracker/CVE-2020-16123 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: d202f8cb555f04eda34eb2793c5802aac43f58cc) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-multimedia/pulseaudio/pulseaudio.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-multimedia/pulseaudio/pulseaudio.inc b/meta/recipes-multimedia/pulseaudio/pulseaudio.inc index a8a5a1e074c..1df24bf04ba 100644 --- a/meta/recipes-multimedia/pulseaudio/pulseaudio.inc +++ b/meta/recipes-multimedia/pulseaudio/pulseaudio.inc @@ -297,4 +297,6 @@ RDEPENDS:pulseaudio-server += "${@bb.utils.contains('DISTRO_FEATURES', 'x11', \ bb.utils.contains('DISTRO_FEATURES', 'systemd', 'pulseaudio-module-systemd-login', 'pulseaudio-module-console-kit', d), \ '', d)}" +CVE_STATUS[CVE-2020-15710] = "not-applicable-platform: specific to Ubuntu" +CVE_STATUS[CVE-2020-16123] = "not-applicable-platform: specific to Ubuntu" CVE_STATUS[CVE-2024-11586] = "not-applicable-platform: specific to Ubuntu 16.04" From patchwork Sun Oct 11 08:39:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100303 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AAE0CCA9ED4 for ; Sun, 11 Oct 2026 08:41:07 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23560.1791708066535804730 for ; Sun, 11 Oct 2026 01:41:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ECNFaKuq; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49d0da752ffso9941515e9.3 for ; Sun, 11 Oct 2026 01:41:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708065; x=1792312865; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=45PCZNlExJGv8UmAX2kDETfUtaUmYHSPztKGbsZtDzk=; b=ECNFaKuqesftxZg8U5edsx3fxrdCkSsTSdHeUquf8vusf+E214Q2c6OuXcBage5W2W zjig9TmnhsNIV9BaFXzUkSQaNCE1v6lsai051MLprnMwSmLR1EinG18hk9idtbj/OYr4 nG0U+lzPenxSE50ofhYDrzLk+yOOQYwHMMr24= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708065; x=1792312865; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=45PCZNlExJGv8UmAX2kDETfUtaUmYHSPztKGbsZtDzk=; b=WQOOw1jysa2bW0pFViK7uNR/5JjIE+uxMMfWqVfn+/8PYe3i7m5h7nfpALFSlR8eiH goTnP/vl6ABlLb7cxp4aJWsIhKucYBDeEtYIkpuSeib7ZpM6kSbemG36ZPUPLuzn+JD1 56FsG3roBDsf28dloBIV7nfaouYApQnB2N0Wrc0VqUxBw07Kh4waHDAXQwH+LVQiB4/3 xgAi5tVp0AfiN+20dSzXUsjVBxgHMSg1LqzdheDw6WbTLR39xA4Q5zwgWAbcsi9XbuMX 2VRyO2Vx0TZIZV3XMdL251ugdJDE4BhaVr+/W/yOI4DJ8W17Hk39CdTvDA3H+UlCjKf2 QsbA== X-Gm-Message-State: AFq9FYLZb+/9ffqbRBbWdpKPslShwwDbYIwOVJphMw8dwR9Bh0t9joeZ rteEkcw0d6wcnh5GAs3YkDenfNcqwcHtNa3mHqBSOxIq6RQYCGj9i7yyTdyREDMyMNrhxbupJa0 P6LZnnyM= X-Gm-Gg: AYBFou30fiAQfnSvHi+mDZNrZ/+Odwaeji+/taKzQjQeS8pEBj84bNDKEWmfcNWRYgh 1NxJjVvN1vVLK6laSpQOBcCQ5VX6VycK3QaLDiznT0RmweCfM+SAz+tDED/gL+BC0vRxNRwpCgY IqBxbHE/dmjA3o/bgkiTNrE8GYfDZKxqXuM1QNT8UcjXB9yt1FxtpEiHGkGjgKvnLA/mrYEqjOP 26SoBDMMcJ5uHvlEKoDgrfzsHy4n9q3Y1p9NC2evNnYaNOYa+3Wp3ysaZ9R5Mi/BZSunFMKELLb 1zAVSxnT8HsAJk4s6Gane+bWjV5rh26zuebDFxc2RSVgLJhzKLUWyojh0mPBMdIWcd4qiCCWLWz veZx85U6u5yO/Qah+ycc5IWH8jf8hfMESApnzRIBQOpd+xkruQQrVdj4o9WjUDhHRUM4UZB7+1K LvOtLb5oAk/JozxcFFjwn9dpYs/YZEzK6ASGhEgJrOfEfselPFCfA7nGzUwGyoKgxfVozw7jYSt u7Myj1gfgveAlmTKS2eTe0DACSdfpM2REg10wag9b/QawR3i2Dwws1p4cSQEhLyMSqA9YWVHg== X-Received: by 2002:a05:600c:a00c:b0:49f:fe90:de63 with SMTP id 5b1f17b1804b1-4a18e4e0a3emr127533485e9.28.1791708064760; Sun, 11 Oct 2026 01:41:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/60] tzcode/tzdata: fix upstream version check Date: Sun, 11 Oct 2026 10:39:42 +0200 Message-ID: <836c83e2df95b50485f0911b2e35eda227e2fe10.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247518 From: Alexander Kanavin The webpage no longer lists tarballs directly, but the actual directory with them can again be listed. Signed-off-by: Alexander Kanavin Signed-off-by: Richard Purdie (cherry picked from commit 1486d28e70af2e297ac0a9650e782481beaa16bb) Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- meta/recipes-extended/timezone/timezone.inc | 2 -- 1 file changed, 2 deletions(-) diff --git a/meta/recipes-extended/timezone/timezone.inc b/meta/recipes-extended/timezone/timezone.inc index 47f9ac2855f..a09da2617f4 100644 --- a/meta/recipes-extended/timezone/timezone.inc +++ b/meta/recipes-extended/timezone/timezone.inc @@ -14,7 +14,5 @@ SRC_URI = "http://www.iana.org/time-zones/repository/releases/tzcode${PV}.tar.gz S = "${UNPACKDIR}/tz" -UPSTREAM_CHECK_URI = "http://www.iana.org/time-zones" - SRC_URI[tzcode.sha256sum] = "b1cffc3ace4c4c7cd0efba2f7add86ec3d0b79da48bcf03582671fd3c8feace8" SRC_URI[tzdata.sha256sum] = "e4a178a4477f3d0ea77cc31828ff72aa38feff8d61aa13e7e99e142e9d902be4" From patchwork Sun Oct 11 08:39:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100304 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BBB72CA9ED6 for ; Sun, 11 Oct 2026 08:41:07 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23562.1791708067055448713 for ; Sun, 11 Oct 2026 01:41:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fo+mf0Ky; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48bbb06e746so522740f8f.3 for ; Sun, 11 Oct 2026 01:41:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708065; x=1792312865; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZOdFOlnTyP7kP+SbGiJW9wmUUTFg9XLKphkdwo2mxNg=; b=fo+mf0KyFLHt+msIgvg8fufFi28yl7aPAJUEBsYeTGY8U+bhTJmfDuWRuMmA2Z5XAx rYJtzij4VGnF1XvdtEkdnuLkWH2WuxhLlo+MLZSwoV9oSycFHv+6LDQF84iqhrf446K+ VVIKcjE53UEgI54p/gCrbmLgkr53PCA8npa98= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708065; x=1792312865; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZOdFOlnTyP7kP+SbGiJW9wmUUTFg9XLKphkdwo2mxNg=; b=1alRUEgURZyCRY59Q6+kr012kKvRqYtQ4fyCCVyxHFHRsxYVh023AP+QIza3YbQSmR f+YqO/35kwtmB1NBeW0/CXrIBMqz5iuIA1jcec3ZfFAEkaO0WC6Kod3Gux29MHM0zrDt Ciwd8vH8Qwd053IEoG96UY9cggayqBoKJHMhXlbiJdi0tU/ChSynnEI2HQDKq9iOpD6i g2sBPPfDGWUywF/utkEdZ/Kh3WZUoUcVj2gyOlCobRtOYcl3JsEMBla28ABWykvgQ23A rWF36FxVjtb+3n1uV+2upwnOCqWXbDSd8qrkF+uTtR8o3Bk1A1EMJwiOrMXkmO7Kn8a1 Oz5g== X-Gm-Message-State: AFq9FYLYEDq1pLyPYKVz3W+99ffaXU8xBwRmPOMlPknf1lbF2LNQ1KtP WlgbZwC82EjNhev6hMfaVC2ZwuIp2BxRaUGtqcE4KZ080FjHKwyGw2rMHUL0+/FTWiY2Ya/hkwf PwBvL4Oc= X-Gm-Gg: AYBFou0DzbWJvKs7zUEWmbr9ztwn7hYquZT3MjOSyBmrW7hPDNipkxpuNfEEOxIYWLr g7Gi4NLjQrCc31AYWb1efhjJeTy/ejWfo2X6ErDWIM7X8DRo9+O6DWZzi8CFEo0TbqD9FTI+unV pLgAFVX7YGSPgAvADV7CeWCv4R0wVDI8SiUszXk0pQnimu3VrLcXyhOj0X8lr0TD5F/QLcI24WE +y2PnmHXCZt6ULiq/oSf7j4PfoqLK5Q5cue9vxB7UGZMWjxaQGaFUbDi7BeihXcurQzSsZ5oPDw u8fOodPCJ9bffle+iiKFe48dpwVt9KpWaaPaV4JPb7Vvsf2LSfMUhiVzcH+gb8QvvYTrbuQ3ueg p0D3EL1W30j+DVohV+pZ4V6VF2D/DoxwIUW4t5RdH6TdAAYpBmH4PJz5nOPG50b0WqdYC7u2yGB BhGUzzHu1yZfXDSbggxPcJYy33LL3KuriI3zGDidvbo/d4kDWjK4zrGrbNUB5Jxd1eZphA7qML7 pkjQnAUHwUAuqrnTa0K3BNJOEK3WQ+Yh1Lbv3q1zWNatINKGz2Y/ZC8LPFWUOSDiALgugbhaA== X-Received: by 2002:a05:6000:46da:b0:488:641b:2dfa with SMTP id ffacd0b85a97d-48dba77cd6fmr6390485f8f.2.1791708065264; Sun, 11 Oct 2026 01:41:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/60] tzdata/tzcode-native: upgrade 2026c -> 2026d Date: Sun, 11 Oct 2026 10:39:43 +0200 Message-ID: <2e7e0643ce8594d106f3d9d4efc30a890344b912.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247519 From: Vijay Anusuri Briefly: Canada’s Northwest Territories moved to permanent -06 on 2026-08-21. Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. Fix security, performance and porting bugs in zic and localtime. Changes to future timestamps Canada’s Northwest Territories will not fall back on 2026-11-01 and will stay on -06 year-round, matching Alberta’s recent change. Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-08-21, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.) This affects only America/Inuvik as the rest of the territory is covered by America/Edmonton, for which the equivalent change was released in 2026c. Changes to past timestamps Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00. Iran’s 1979-05-26 spring forward was at 00:00, not 24:00. (Thanks to N.F. Hase.) The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and PST8PDT now conform better to POSIX. For example, EST5EDT now always uses the abbreviation "EST" for standard time (now always 5 hours behind UT) and "EDT" for daylight saving time, whereas it formerly had different UT offsets before standard time was introduced and sometimes used abbreviations like "LMT", "EWT" and "EPT", all contrary to POSIX. Also, though not required by POSIX these names now use US federal rules rather than rules of places like New York, reverting to 2024a behavior. This change affects only timestamps before 1966-10-30 at 01:00 standard time. Other data changes The temporary hacks used for North American timekeeping changes now work around a libstdc++ std::chrono bug in GCC 14.1-14.4, 15.1-15.2, and 16.1; see GCC bug 124851. This data change does not affect TZif files or timestamps. The change does not work around the related but less serious GCC bugs 116110 and 124513. These GCC bugs are all fixed in GCC 16.2. Changes to code zic now rejects Link targets that would have invalid names, and more efficiently processes Expires, Leap and Rule lines with years far in the past or future. (Thanks to Darren Carreras.) zic now ports to systems that report lack of link support via EINVAL, ENOSYS or EPERM errno values. (Thanks to Tom Lane.) When tzset and related functions encounter a TZif file that is too large for them, they now consistently fail instead of sometimes silently ignoring excess parts of the file. localtime-related functions no longer mishandle extreme timestamps when given TZif files holding some unlikely timezone histories. (Problem reported by David Sarkisyan.) localtime-related functions no longer check the values of TZif files’ standard/wall and UT/local indicators, which these functions have not used since 2026a’s removal of the old posixrules feature. tzcode has been ported to Haiku. localtime.c now works again by default on AIX and DragonFly BSD. zic now rejects ‘:’ and ‘\’ in Zone and Link names when running on Microsoft Windows. (Problem reported by David Diaz.) Changes to documentation URLs for release tarballs in tz-link.html have been updated to reflect their new canonical URLs on data.iana.org. Ref: https://www.iana.org/time-zones/releases/2026d Signed-off-by: Vijay Anusuri Signed-off-by: Antonin Godard Signed-off-by: Richard Purdie (cherry picked from commit 400938b8ca41654fbda6c34c6eb8c12aec1f43b0) Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- meta/recipes-extended/timezone/timezone.inc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/meta/recipes-extended/timezone/timezone.inc b/meta/recipes-extended/timezone/timezone.inc index a09da2617f4..6a65f2deb22 100644 --- a/meta/recipes-extended/timezone/timezone.inc +++ b/meta/recipes-extended/timezone/timezone.inc @@ -6,7 +6,7 @@ SECTION = "base" LICENSE = "PD & BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=c679c9d6b02bc2757b3eaf8f53c43fba" -PV = "2026c" +PV = "2026d" SRC_URI = "http://www.iana.org/time-zones/repository/releases/tzcode${PV}.tar.gz;name=tzcode;subdir=tz \ http://www.iana.org/time-zones/repository/releases/tzdata${PV}.tar.gz;name=tzdata;subdir=tz \ @@ -14,5 +14,5 @@ SRC_URI = "http://www.iana.org/time-zones/repository/releases/tzcode${PV}.tar.gz S = "${UNPACKDIR}/tz" -SRC_URI[tzcode.sha256sum] = "b1cffc3ace4c4c7cd0efba2f7add86ec3d0b79da48bcf03582671fd3c8feace8" -SRC_URI[tzdata.sha256sum] = "e4a178a4477f3d0ea77cc31828ff72aa38feff8d61aa13e7e99e142e9d902be4" +SRC_URI[tzcode.sha256sum] = "2f5c9f7fe29e6b8cb863583667884b8ce17b0a485355a054b591c6bdfcd81791" +SRC_URI[tzdata.sha256sum] = "0cb2aa8e333c3dc049badc42a0c61f21987b8cd44e107fa900bad764aacc7767" From patchwork Sun Oct 11 08:39:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100319 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8F544CA9ED7 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23429.1791708067949004448 for ; Sun, 11 Oct 2026 01:41:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wxjem2+y; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-48441a2ba1bso518360f8f.1 for ; Sun, 11 Oct 2026 01:41:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708066; x=1792312866; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=T4nkVpkBHgoVdUxB5q3FW04+XSFv/2p8/7PTO58TEpM=; b=wxjem2+yCyA0/3L/9tgtramPsoF3N2TK3/ELb1anMwtW8RuJL5hS/NQZhnLngTeHz3 2iT1FbkxAtPgHCUFi2AhwnfK17Lzx2YHU1OZFQusfpFi7FhlaTOheHK0k566UiTh04f6 zHd20CPdgj8ET9JGHP5T1qzO7jXnVTMSUr+bw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708066; x=1792312866; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=T4nkVpkBHgoVdUxB5q3FW04+XSFv/2p8/7PTO58TEpM=; b=pVwew0UqNjhvkmspRMlYwT1FgML6u72MjbRctFHnz2j6AtxJh965+Y0lfautRyYRT8 rf61qbzqonMtJa9hoAmjC43z+BNxEuEiuhl+xlk711sw5WrVA6CdHzqBUb9BEWtGVUg6 6fAvp4J2ANt12616xU6nB0BVB0ngsVTbuik8k6H8xCY6G4kBLqQHnCn2EkRAVZGESj1/ EKQjl8U/f9s2MUtmJ19OkqBMDf9ev41gDQE60huGwHiESZT/iBlWwM0wgj7Djjjo7IGc z3xir/i8jtkF87JaIMClMpHPIlE7tTZHhbVARCUhE2YeY0MM7XEK8f/KMjcUCvvtabmJ Ocdw== X-Gm-Message-State: AFq9FYJy6PgFKPGIOPw5gVmpO+9dI3jwRtrVd0nvzIXbyj5sZ3UE/qQX SdkQx+mhu2VZcBZ1r8dogQc+O3BYVEYu6BJ87OLbmnNQN+VExss0HBgO1tn76lCARlHH+guIx63 c+Hft3cQ= X-Gm-Gg: AYBFou0FpTQp1CG1ZOFTETBrWZodNubuaBCHC5LxxOkJAL+due9MG9tNFicYyQoMdwJ Mia/0oZkBUVBBa8SkMArNWQ+yofH2g+JxfFS9/rSGpofcYdvcI0ntbeWFLhM9l9qPCIbhi/rVLC Y8rGaT8OxYqQbh+Atjk9XeZE4vvtvOo3s1zmCKHspA81IXB6Hg3R9a3sOToSADBewdi3ialfsu0 GLvZjuzs+FWjMHxWZGegRmQhM/Vr5/ZsRGDLd4kPJW6/t3ovqSly/3JVz6zjGB4lFEjtGxPTs0p oLLT6MgqqCp0xgk/EcN7TEOQPWsDl47Pd/SNdFScsrvLErvm50uuLnpGj2f5dQ3Y86Yxd5uq4NH ZlvM6z/BTG+9alB0fI5TkrPvjHYglskXyGNWmgFCp2CISjnAGmAsvX22q04hQqbrCV43u2tT30V aiboJrEsky6QLMEMgfeutEdGR9T7BbjFcwEdHoQXI+/PoalIPROUz/XorK/Tj593HugedRVOqID jv0OXFOPIJD1mf5/LKE+P+M1jTNKR1QaLpJ/ty7NP49Xp7XaFQbEruYPzcYGLr1wY25173Lww== X-Received: by 2002:a5d:4a8d:0:b0:48b:a21:87f7 with SMTP id ffacd0b85a97d-48dbaae3792mr9021783f8f.44.1791708066067; Sun, 11 Oct 2026 01:41:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/60] bind: upgrade 9.20.26 -> 9.20.27 Date: Sun, 11 Oct 2026 10:39:44 +0200 Message-ID: <6d4261cbea4c9dc965f2907bbd30b493e9c834ce.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247520 From: Jaipaul Cheernam ChangeLog: https://bind9.readthedocs.io/en/stable/changelog.html#bind-9-20-27 Signed-off-by: Jaipaul Cheernam Signed-off-by: Richard Purdie (cherry picked from commit 6de1243270216428d7eefdbc0ea5657e0aeb3a48) Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../bind/bind/0001-avoid-start-failure-with-bind-user.patch | 2 +- .../0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch | 2 +- ...0001-named-lwresd-V-and-start-log-hide-build-options.patch | 4 ++-- ...bind-ensure-searching-for-json-headers-searches-sysr.patch | 4 ++-- meta/recipes-connectivity/bind/bind/conf.patch | 2 +- .../bind/bind/init.d-add-support-for-read-only-rootfs.patch | 2 +- .../bind/bind/make-etc-initd-bind-stop-work.patch | 2 +- .../bind/{bind_9.20.26.bb => bind_9.20.27.bb} | 2 +- 8 files changed, 10 insertions(+), 10 deletions(-) rename meta/recipes-connectivity/bind/{bind_9.20.26.bb => bind_9.20.27.bb} (97%) diff --git a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch index 7ed4c5fd2f9..30da1e9fd3e 100644 --- a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch +++ b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch @@ -1,4 +1,4 @@ -From a67ac281cd86d8d9ca27e64a5944deb5578e5087 Mon Sep 17 00:00:00 2001 +From 7682cbc2fa624fbeeb088736e154090d92c8b524 Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Mon, 15 Oct 2018 16:55:09 +0800 Subject: [PATCH] avoid start failure with bind user diff --git a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch index da4cdef696e..f1d8a8e5691 100644 --- a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch +++ b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch @@ -1,4 +1,4 @@ -From 16608520c9d946223404165732eacd79b59de471 Mon Sep 17 00:00:00 2001 +From a633e336c248ceab41d3182848b65c95e90ef88c Mon Sep 17 00:00:00 2001 From: Khem Raj Date: Fri, 10 Apr 2026 23:33:49 +0000 Subject: [PATCH] m4: Backport ax_prog_cc_for_build.m4 macros diff --git a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch index 07acce9cba0..da4057064e1 100644 --- a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch +++ b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch @@ -1,4 +1,4 @@ -From d925183807ae182cf332124ff5a617d257e184f9 Mon Sep 17 00:00:00 2001 +From 4b870f60338fe45e036b8a76d47f053338920048 Mon Sep 17 00:00:00 2001 From: Hongxu Jia Date: Mon, 27 Aug 2018 21:24:20 +0800 Subject: [PATCH] `named/lwresd -V' and start log hide build options @@ -20,7 +20,7 @@ Signed-off-by: Armin Kuster 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index af020f0..f461229 100644 +index 56bca5b..4fd62ed 100644 --- a/configure.ac +++ b/configure.ac @@ -35,7 +35,7 @@ AC_DEFINE([PACKAGE_VERSION_EXTRA], ["][bind_VERSION_EXTRA]["], [BIND 9 Extra par diff --git a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch index 4e90e972715..9adc101247e 100644 --- a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch +++ b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch @@ -1,4 +1,4 @@ -From af229781e60d6779c76d5a61d26a4597b2a42f6c Mon Sep 17 00:00:00 2001 +From f3736e5535236cf978fd368b6905098ff6e4fd84 Mon Sep 17 00:00:00 2001 From: Paul Gortmaker Date: Tue, 9 Jun 2015 11:22:00 -0400 Subject: [PATCH] bind: ensure searching for json headers searches sysroot @@ -32,7 +32,7 @@ Signed-off-by: Paul Gortmaker 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index f47ce7b..af020f0 100644 +index c06a0d7..56bca5b 100644 --- a/configure.ac +++ b/configure.ac @@ -872,7 +872,7 @@ AS_CASE([$with_lmdb], diff --git a/meta/recipes-connectivity/bind/bind/conf.patch b/meta/recipes-connectivity/bind/bind/conf.patch index 3425742d1ba..803456c0b33 100644 --- a/meta/recipes-connectivity/bind/bind/conf.patch +++ b/meta/recipes-connectivity/bind/bind/conf.patch @@ -1,4 +1,4 @@ -From bde3a4cb010f459a9ef92817c7e6e6e2d871794a Mon Sep 17 00:00:00 2001 +From 450187e8feac041de02afd4c0c9039cc41e04cb9 Mon Sep 17 00:00:00 2001 From: Qing He Date: Tue, 30 Nov 2010 13:35:42 +0800 Subject: [PATCH] bind: add new recipe diff --git a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch index 9b55afb5d3b..a2c1fbb8f70 100644 --- a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch +++ b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch @@ -1,4 +1,4 @@ -From 8876e722beda701a0de021360ff381347120c6ff Mon Sep 17 00:00:00 2001 +From 582334d31432969be7e10906de7540f1dc64b17e Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Thu, 27 Mar 2014 02:34:41 +0000 Subject: [PATCH] init.d: add support for read-only rootfs diff --git a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch index 33d5d34f158..dc1f8f5a9a6 100644 --- a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch +++ b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch @@ -1,4 +1,4 @@ -From 26c988eee9d2eae7c7dec8c529176352017b2ce1 Mon Sep 17 00:00:00 2001 +From 50601a7ee8fd19ddbe9a592c57ae6197782d4c2f Mon Sep 17 00:00:00 2001 From: Roy Li Date: Thu, 15 Nov 2012 02:27:54 +0000 Subject: [PATCH] bind: make "/etc/init.d/bind stop" work diff --git a/meta/recipes-connectivity/bind/bind_9.20.26.bb b/meta/recipes-connectivity/bind/bind_9.20.27.bb similarity index 97% rename from meta/recipes-connectivity/bind/bind_9.20.26.bb rename to meta/recipes-connectivity/bind/bind_9.20.27.bb index fe2ae3f002f..6d2b88e0123 100644 --- a/meta/recipes-connectivity/bind/bind_9.20.26.bb +++ b/meta/recipes-connectivity/bind/bind_9.20.27.bb @@ -21,7 +21,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \ file://0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch \ " -SRC_URI[sha256sum] = "55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350" +SRC_URI[sha256sum] = "145ab7a50b33a06d9d488b5e668c887e754f42acf8954e2b5dc7e238b080e4a0" UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/" # follow the ESV versions divisible by 2 From patchwork Sun Oct 11 08:39:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100311 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DAA74CA9ECA for ; Sun, 11 Oct 2026 08:41:17 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23430.1791708068664376024 for ; Sun, 11 Oct 2026 01:41:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=zs7NHLvD; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48bbb06e746so522746f8f.3 for ; Sun, 11 Oct 2026 01:41:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708067; x=1792312867; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NpyJ2DiLmDmuyE538UrY92LmM1UpOwjvEvp109tUFJI=; b=zs7NHLvDcSO1cWWcneSnSJYe8CEPjVOjPLSu0UVfx0oEvGnljzlyspo7mMuqAlwRZB +ty7JKZVmA75bBFdo6oDmLNT+Ajh8yu6XzIkWb8EfuyqcYNvS+PnazydSep9bx4D0nc6 b3lNOlKp6bQdEggLfKBDNMVyZVmrZljvQemAg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708067; x=1792312867; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NpyJ2DiLmDmuyE538UrY92LmM1UpOwjvEvp109tUFJI=; b=Ko2L+HsGl1rT6E7b8K7qbCH1KkYPkk5gpiP7fnb3INIbsnlqjxGFqEUDAPyvg8lYuY yXd/CslL6+ekkavp77b+XxpTYedzs/HyIx46yLRu85VK4yNhWILz8jWOXsP1uDPgudYz TYwOuJODGyYKNirbUlPdqDgvllxUxTxR1/24H+hHNSMPL8mvtodWRBomj6gtRgiqiepB FhMy6wq+IeVwYnnroSWzvk+ZGgU8VGePL2GICErbjm1vZQeNJbzFbjO+o/+JXoDkil2F 1YWpSApkZtwjIthhmqHYmFY9Ys4YZqMDSdB3d3qHOIEdzayQtPCOYOgC9WPX0hmvo9Ce PxPQ== X-Gm-Message-State: AFq9FYKVn4hm9iqP4dq9SZG6D21RTRLtEZH1Ryb58RZhyT+IaMwdKH+g 5j9Z2Th/h5N7mTsbIgbE6rUTuCciyeLMZxQlKA3rpw7coA8mCQv9SEPjbO5d4ZGjJtA5Zs1lD0I YFCYv6eY= X-Gm-Gg: AYBFou08dOEKCIPzjRe8oxAXELKx7TZT6JdQJn1fIckI84s/0IxPXxEGKXEQqRgDSMa Ug470/E4HXw6s6F6c0jmhdJtKXVbQLc952ch0unUevAHjoQBTBUjKSv4R5LCQrwCMxZWlVogMJ/ BiYt6g3w8ouLM9p6+AaI5HzdeFJ6pOotzcomp+gj15GFuJfVj0lzHJAlNA19msJ78FGJeMq3QXG g2iO4H0EmXH0gKHfjyUbmVxU+DDWiTW5n+fizJcTCpooLIqjsGQJ0mw6EFvoFRwrgMJecLCPUje /1HgneqZDJCezK6w2zTLeTjLssxRtLd/4ACRgQrT+bNnxveuZQ2YUYLlq6W6iK4u+grxBM0JUhx PPxDsiA0NOKVletyM3wT5YNtwermfN1vbKuXGkTp2k+v9LOriBe6XbSIRd9GaMLGRbjLokGonMf Neoj1NvYOycVN8obRqZp+30Maw5njcXaG8LcNEIBCReXCQuuFKHw4+cEA7udY3ubdizARQvW+D+ VL7ExuGu0CIkoitfNtTpisdqksydsbCTUunqHnOsKlDiggKyIcvvEPbIsiGKiuzAqvb7v3J+w== X-Received: by 2002:a05:6000:491c:b0:488:8751:e78e with SMTP id ffacd0b85a97d-48dba9bdd09mr12638956f8f.16.1791708066620; Sun, 11 Oct 2026 01:41:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/60] bind: upgrade 9.20.27 -> 9.20.29 Date: Sun, 11 Oct 2026 10:39:45 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247521 From: Richard Purdie BIND 9.20.28 ------------ The BIND 9.20.28 release was withdrawn after the discovery of a regression in it during pre-release testing. BIND 9.20.29 ------------ Security Fixes ~~~~~~~~~~~~~~ - [CVE-2026-19668] Prevent excessive CPU use validating crafted DNSSEC responses. ``a0a61dba9e`` - [CVE-2026-19033] Require a TSIG on every message of incoming zone transfers. ``9404cd2b8c`` - [CVE-2026-77119] Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3. ``3bed9c8e9e`` - [CVE-2026-19941] Prevent forged DNSSEC-validated NXDOMAIN responses. ``a36bf58daf`` - [CVE-2026-19666] DNS64 with break-dnssec could cause an assertion failure. ``4cec4965c4`` - [CVE-2026-19667] Reject negative cache records that do not fit in a dns_rdata_t. ``dbf08c8581`` - [CVE-2026-19662] Prevent resolver crash with cached DNSSEC proofs. ``c884cc1ba0`` - [CVE-2026-75029] Discard repeated SOA, CNAME, and DNAME records when parsing DNS messages. ``0d630758c2`` - [CVE-2026-77692] Fix an unauthenticated crash on HTTPS using SIG(0) ``5a24401c5c`` - [CVE-2026-81736] Cached HTTPS/SVCB aliases could exhaust resolver CPU. ``20bbb1639a`` - [CVE-2026-76163] Prevent TKEY queries from terminating named without global options. ``7645138538`` - [CVE-2026-78301] Out-of-zone records in a zone database could be served as authoritative. ``72a10c3a0b`` - [CVE-2026-80274] Crash on wildcard answers carrying both NSEC and NSEC3 proofs. ``0e44451b1a`` - [CVE-2026-81563] Following HTTPS/SVCB aliases could leak resolver cache memory. ``3162df369e`` New Features ~~~~~~~~~~~~ - Add an agent skill for the isc_job/isc_async/isc_work APIs. ``fe32990b06`` Removed Features ~~~~~~~~~~~~~~~~ - Remove unused closest encloser proof caching. ``abd8b5bfd8`` Feature Changes ~~~~~~~~~~~~~~~ - Reject oversized and malformed DNSKEY records up front. ``6c22109924`` Bug Fixes ~~~~~~~~~ - Prevent a crash when using both dns64 and filter-a. ``bce5d10d18`` - Fix update-policy grant external address passing. ``b1e955c326`` - Missing required NSEC3 for delegation not detected. ``e84ed2e9d7`` - Tighten EUI48 and EUI48 text parsing. ``ff50f2cdf1`` - GeoIP ACL state can be stale or wrong after reload. ``63baf425b3`` - Honor DNSSEC policy key tag ranges. ``b82e5834b7`` - Fix double free in mdig when EDNS options are specified. ``af5bd0b0ff`` - Fix a crash when an IXFR falls back to AXFR with updates still pending. ``e34062bc7e`` - Fix DS requests to parental agents over TLS. ``55830d30f6`` - Fix a crash when resolving names below a cached DNAME. ``b94e940f52`` - Rndc-confgen `-q` (quiet) option is documented but doesn't work. ``7e4a7ca1a7`` - Enforce query ACLs for redirect zones and searched DLZs. ``bc69876b2e`` - Check "asnum" validity in GeoIP ACLs. ``28c2bfdc7b`` - Prevent crashes while reporting DNSSEC signing statistics. ``c190514f0a`` - Fix various nits in the netmgr code. ``c28cdad51b`` The MR consists of couple of small fixes and uncaught errors in the Network Manager. :gl:`#6257` :gl:`!12576` - Fix a crash on remote-servers lists that reference themselves. ``aaae614f9d`` - A record from outside a response policy zone could stop named. ``d135513b37`` - "rndc flushtree ." failed to flush the cache. ``96e8b585ed`` - Invalid key-store configuration could abort the DNSSEC tools. ``1d796ab072`` - NSEC signature set could bypass the secure-delegation check. ``c966177f6c`` - Fix a possible nsupdate issue when using GSS-TSIG. ``4ddcab2d3c`` - Fix isccc_alist_define error paths. ``af1349552a`` - Check for empty 'endpoints' list. ``23f58af443`` - Named could crash with a single-element geoip sortlist. ``0e996a4d3b`` - Prevent out-of-bailiwick CNAMEs from evicting cached records. ``cdedd4acd5`` - Restore periodic cleanup of stale resolver address data. ``356f4013f8`` - Fix named-checkconf/named crash with malformed key name. ``9f218f6aaf`` - Fix -Wformat-truncation warning in totext_in_wks() ``f97c2bea40`` - Fix off-by-one errors caused by magic hardcoded values. ``726c6cb795`` - Hmac_verify() now accepts truncated HMACs only when requested. ``c81b111496`` - Prevent resolver crashes while processing DNS over TCP. ``81b3b6d89f`` Signed-off-by: Richard Purdie (cherry picked from commit c366449b3b6cb47dc418cf65340a35ea3a047621) Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../bind/bind/0001-avoid-start-failure-with-bind-user.patch | 2 +- .../0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch | 2 +- ...0001-named-lwresd-V-and-start-log-hide-build-options.patch | 4 ++-- ...bind-ensure-searching-for-json-headers-searches-sysr.patch | 4 ++-- meta/recipes-connectivity/bind/bind/conf.patch | 2 +- .../bind/bind/init.d-add-support-for-read-only-rootfs.patch | 2 +- .../bind/bind/make-etc-initd-bind-stop-work.patch | 2 +- .../bind/{bind_9.20.27.bb => bind_9.20.29.bb} | 2 +- 8 files changed, 10 insertions(+), 10 deletions(-) rename meta/recipes-connectivity/bind/{bind_9.20.27.bb => bind_9.20.29.bb} (97%) diff --git a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch index 30da1e9fd3e..15796a15fba 100644 --- a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch +++ b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch @@ -1,4 +1,4 @@ -From 7682cbc2fa624fbeeb088736e154090d92c8b524 Mon Sep 17 00:00:00 2001 +From 95141cf9494292fc5645165ef3d5e9e2ed2208c6 Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Mon, 15 Oct 2018 16:55:09 +0800 Subject: [PATCH] avoid start failure with bind user diff --git a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch index f1d8a8e5691..99e781799da 100644 --- a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch +++ b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch @@ -1,4 +1,4 @@ -From a633e336c248ceab41d3182848b65c95e90ef88c Mon Sep 17 00:00:00 2001 +From 06e9624eb7e474a08ed7e1a456bfe9759ba211da Mon Sep 17 00:00:00 2001 From: Khem Raj Date: Fri, 10 Apr 2026 23:33:49 +0000 Subject: [PATCH] m4: Backport ax_prog_cc_for_build.m4 macros diff --git a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch index da4057064e1..80a4f2abded 100644 --- a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch +++ b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch @@ -1,4 +1,4 @@ -From 4b870f60338fe45e036b8a76d47f053338920048 Mon Sep 17 00:00:00 2001 +From f28920a59b658fcda24efde1c45322f785a0b0fe Mon Sep 17 00:00:00 2001 From: Hongxu Jia Date: Mon, 27 Aug 2018 21:24:20 +0800 Subject: [PATCH] `named/lwresd -V' and start log hide build options @@ -20,7 +20,7 @@ Signed-off-by: Armin Kuster 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index 56bca5b..4fd62ed 100644 +index 0bc3965..e1c2b12 100644 --- a/configure.ac +++ b/configure.ac @@ -35,7 +35,7 @@ AC_DEFINE([PACKAGE_VERSION_EXTRA], ["][bind_VERSION_EXTRA]["], [BIND 9 Extra par diff --git a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch index 9adc101247e..323985a4025 100644 --- a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch +++ b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch @@ -1,4 +1,4 @@ -From f3736e5535236cf978fd368b6905098ff6e4fd84 Mon Sep 17 00:00:00 2001 +From f003f396067e6cc1e2ec609b296bb642b8ddf47b Mon Sep 17 00:00:00 2001 From: Paul Gortmaker Date: Tue, 9 Jun 2015 11:22:00 -0400 Subject: [PATCH] bind: ensure searching for json headers searches sysroot @@ -32,7 +32,7 @@ Signed-off-by: Paul Gortmaker 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index c06a0d7..56bca5b 100644 +index 26c442a..0bc3965 100644 --- a/configure.ac +++ b/configure.ac @@ -872,7 +872,7 @@ AS_CASE([$with_lmdb], diff --git a/meta/recipes-connectivity/bind/bind/conf.patch b/meta/recipes-connectivity/bind/bind/conf.patch index 803456c0b33..28ee4ae74d3 100644 --- a/meta/recipes-connectivity/bind/bind/conf.patch +++ b/meta/recipes-connectivity/bind/bind/conf.patch @@ -1,4 +1,4 @@ -From 450187e8feac041de02afd4c0c9039cc41e04cb9 Mon Sep 17 00:00:00 2001 +From 5fc3dfd3f994b5fd97e97837eee2ad808cd8af93 Mon Sep 17 00:00:00 2001 From: Qing He Date: Tue, 30 Nov 2010 13:35:42 +0800 Subject: [PATCH] bind: add new recipe diff --git a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch index a2c1fbb8f70..b373251c47e 100644 --- a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch +++ b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch @@ -1,4 +1,4 @@ -From 582334d31432969be7e10906de7540f1dc64b17e Mon Sep 17 00:00:00 2001 +From 42c109317070d19fda70635b7043cbc6f9ec36ef Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Thu, 27 Mar 2014 02:34:41 +0000 Subject: [PATCH] init.d: add support for read-only rootfs diff --git a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch index dc1f8f5a9a6..74cf947787a 100644 --- a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch +++ b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch @@ -1,4 +1,4 @@ -From 50601a7ee8fd19ddbe9a592c57ae6197782d4c2f Mon Sep 17 00:00:00 2001 +From 2e1314f2e71be15704ba18756250185b36a5c0da Mon Sep 17 00:00:00 2001 From: Roy Li Date: Thu, 15 Nov 2012 02:27:54 +0000 Subject: [PATCH] bind: make "/etc/init.d/bind stop" work diff --git a/meta/recipes-connectivity/bind/bind_9.20.27.bb b/meta/recipes-connectivity/bind/bind_9.20.29.bb similarity index 97% rename from meta/recipes-connectivity/bind/bind_9.20.27.bb rename to meta/recipes-connectivity/bind/bind_9.20.29.bb index 6d2b88e0123..5ce94d597b4 100644 --- a/meta/recipes-connectivity/bind/bind_9.20.27.bb +++ b/meta/recipes-connectivity/bind/bind_9.20.29.bb @@ -21,7 +21,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \ file://0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch \ " -SRC_URI[sha256sum] = "145ab7a50b33a06d9d488b5e668c887e754f42acf8954e2b5dc7e238b080e4a0" +SRC_URI[sha256sum] = "587029508b3b1b43229fae416c97e5543aba45809cefaca98a5004a02a5736c1" UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/" # follow the ESV versions divisible by 2 From patchwork Sun Oct 11 08:39:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100318 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9F034CA9ED9 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23564.1791708069285868406 for ; Sun, 11 Oct 2026 01:41:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tU6oOnvl; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48b042c0759so656214f8f.2 for ; Sun, 11 Oct 2026 01:41:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708067; x=1792312867; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TrsbDjNhTpr6m+6ftGT3SA1Jkb0yZRMl++FkGQRQuu4=; b=tU6oOnvlqJZmiZanQV6aVtRIHdh/JVJT9rSmj5z2ayGf0m4I9gqj7DBO6BPH+uLNSj gmC1yjZkXrGNPvLrN9NAZ6XhX0N2gh4JkvCu9+/hfhktGM/WG5auY7hCOjl24DFBWBlk tz+cOMmIc6YrZg1M+KEoK+6mRzMCeFhvpOz9g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708067; x=1792312867; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TrsbDjNhTpr6m+6ftGT3SA1Jkb0yZRMl++FkGQRQuu4=; b=l8YtuCrztBDNjhJXD9raMD4kWc9FwZbNBGX3nn6n5mx7vG+UJkQ0YL+G0iw0WGK5gd TXufUoCgl5nlQfD720ZInLmz5gNm9RqjovMD+k/l55s2AhthEWMZ4jdyfHlAc6+a9tpg FXXtcedRkHAVpVbB6JVUUjz2rXSzFdOqMmRamKOF7JGJHARxXg1ONJNOg4YHwtBtAKxy n8iIVjh4h1Tzgzh9oPGq0h+hs3SGW/WX7vgtlXFsYBuAUKrl0v0Z2nq+mQrBFXwubYlj GO/qvwtLmK3SRZ9hTBCYFVclIDR8c3OqQ/gaPXPMqMze1K+8GLRVRUIFqyFS+d8awZPX 7+1w== X-Gm-Message-State: AFq9FYISACt6/9x45bqhNBrdIwsnXJjX3NR7f362LnHOJXHe1ECEAZ+r LrUG+8/Uz7tMev/Qla8kTIf06wGTeOrG4G+5gWk444GBSJb5TGMRqni5jLIdd9kjdu4ZTMQBcc5 CGh6p/y8= X-Gm-Gg: AYBFou1xk/kv+b7MCHEE3yH81rervHjw8URstpzZcGhrhm07zMoObb0cBKkRI12yHW6 v0gUG0aJ+q/w34YShFEdyD5Do4+Lgvn6sbf7Zi18nYxNl4rC4xAdMerKBOlsWJm1WVgNHgGjiT5 /OfA6HGaZVVGpJ0094teIbCyWtZPCms+bR1PSqtaFPd/rk+U/H0WB2FmI9bWUwBjSoNqXLzNMgv Vbp5hspVUPejxA/QTKRkozUPit5sO9sBxcAo32p8aMCjNWi4oBgQb7uQdsq1PvnireH5jj3c+rw MTAwhJOeDvDAlgCHx4xHacpZnWG0uhCpRUOEKk+3cPP2OC560Hdaf/PgB2VsYvyWzmQ00TRq0Dj dzL/q3shpjELo/SuP/NOpgOW6HjNoRu4kO3cTJzaDO3B82Coqify5UaiysvoybVx4B8xaLZF9Qv D4tx1pPcYx1JDw7gSxF6+0+sbQY1Uk7n7QMvJYN5Nd0MqFXq6wF3HE1ln8E52n/ZHANjH5/59o/ gnFLvp0DOWepYsKTPoRQjmCLwY0byPu1T44V51knUAvr5AYHavxtLeombvVh/qstRPkatGkZkwZ YRVQrBmh X-Received: by 2002:a05:6000:400d:b0:48b:10c8:2183 with SMTP id ffacd0b85a97d-48dbacdd2afmr10015500f8f.32.1791708067449; Sun, 11 Oct 2026 01:41:07 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/60] graphene: set status for CVE-2026-81281 Date: Sun, 11 Oct 2026 10:39:46 +0200 Message-ID: <577e328f76acd93025b54329d8aec72ddfbe38f7.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247522 From: Peter Marko Per description in [1] and also per [2] this is CVE is for WordPress theme. [1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/81xxx/CVE-2026-81281.json [2] https://security-tracker.debian.org/tracker/CVE-2026-81281 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 41cfe5df728cfeef3adac69f0bbdace70c339e78) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-graphics/graphene/graphene_1.10.8.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-graphics/graphene/graphene_1.10.8.bb b/meta/recipes-graphics/graphene/graphene_1.10.8.bb index 7aa72b4a78f..0d526d3d76f 100644 --- a/meta/recipes-graphics/graphene/graphene_1.10.8.bb +++ b/meta/recipes-graphics/graphene/graphene_1.10.8.bb @@ -28,3 +28,4 @@ FILES:${PN} += "${libdir}/graphene-1.0" BBCLASSEXTEND = "native nativesdk" CVE_STATUS[CVE-2024-1984] = "cpe-incorrect: issue in a WordPress theme" +CVE_STATUS[CVE-2026-81281] = "cpe-incorrect: issue in a WordPress theme" From patchwork Sun Oct 11 08:39:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100314 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6F782CA9ED4 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23565.1791708070070341519 for ; Sun, 11 Oct 2026 01:41:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PNJf/dNx; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-48c14a06c95so777274f8f.1 for ; Sun, 11 Oct 2026 01:41:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708068; x=1792312868; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=SvnzbS+CuDQK2a71WTwmgoAGN3e8lxxcfO5vy+9mf7o=; b=PNJf/dNxS5rUIriGt5hPBj0fP6sXhpiH7ODHVPxSfRcOvw0FdJbR/jrth6YoKHFzGX H40L+3+Q8QLrfBCze1g5cZv4tBeLRADzZ/MeNSi6y47ZfEuXL1NEDU4cnH3DLMpkxDsE ecAK76PRBYJsx6OtSbROE6ElOlad5f1P9Xtl8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708068; x=1792312868; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=SvnzbS+CuDQK2a71WTwmgoAGN3e8lxxcfO5vy+9mf7o=; b=lzINCcEltOecBIyuiF+4T2Q9MIKbG0to1Is1s6W8fA5PLarouf8AWE3t7pSIRboSB0 2uMkoXsFqUBtnlm1fcUUXHZ543U6h+62IHf9F3HaiFSmNI9riwbltvJJoUOIb19cCqin 3NXW2pc/hG3Lma4i3iYQlHuZAHr2NVVcLELb2AOiZx3kc9b8iB391USggVOgehqc3awo aPT+5CUMv/Wu0IO52YF0/+yo/FJSkN8wYLIcdQhij3fNuqXdJuiD61O1JoJ+cYgbPEVa 7AJ6lRZyFyZqSfX/fM3wnbIFWNXAUk1xVrwYoPqiSHKgQJHyhQ/NoFXg1B8DsBiZb4kq rD7Q== X-Gm-Message-State: AFq9FYJWb8jJHP77E5jmEkzXR8wQqvGGUQGUCFL/Rr9xtvc2DJlUFtaN enFH9Iki4kVkT+rKLmp3kUJtCs2r0aqNgwzBM1hQksfnSnvSOQBTBoW7D/hEJX3d1tVfHdFAT+G 6D5MaC80= X-Gm-Gg: AYBFou2Xc631ACTjFGZGd8bDHLD1Uq7AJbf4MBB/fmO5rRPjj2V8J390+Y0QTgT2N05 P/Zc0oaMusWfm3s7mOJ6gTNd9KzNqKM7hoskQnUPwqQydNmWOkV+yLiAvsxUCKdMHw8vuoMiF1q jfFkQVQYXdL372yM3W3U9UpSYg+/hYQO5cRppRWW8iSk8N4Lu9yzHixSdDJR/N5s+A989umXJ+T RCT4LZuukFJdz+5BYH/LluiJT9P+UeQI3M+KDk6QgZiOkuZPa/ZbKYMriiUj65Sqw9D9Easz8p3 nJhMXCClZj1Djm87yYOjwdpF5yTIHk2gwFVqZxjkPx5/ogkxksoMJkQlKKy7lQ3szc/xlwOCqwB /CtP8qGE+w847pDIlQaX9Ott9Ut9MmpFO01vbupk6t3A6PSLGyNTdb2YSBX4tXNGsfPieRTLGxS vlM5RVdyGYHD5aswXnJSEWlKY1soh8GRIGasRzenATx1Pg1J3dP/Jing+xxPjca5xXbgACfWFbP D/LgLcPJjEel9TfYxz3wVkLI9LoXitssvkQo6AeodRjRu85GBuBMrgqiyMnqjCzWp5yT0wtwkoy AUpNRef9 X-Received: by 2002:a05:6000:4a03:b0:48c:6aed:6b32 with SMTP id ffacd0b85a97d-48dbacef5e5mr11168772f8f.54.1791708068090; Sun, 11 Oct 2026 01:41:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/60] openssh: set status for CVE-2026-55655 Date: Sun, 11 Oct 2026 10:39:47 +0200 Message-ID: <5465433e4f6cc9f50c504f4493a51eedc47d8095.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247523 From: Peter Marko Per [1] and [2] this this is only problem in RedHet patches. [1] https://security-tracker.debian.org/tracker/CVE-2026-55655 [2] https://ubuntu.com/security/CVE-2026-55655 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 9ea8649149e711668b85c7e35cb7c259437e8c0e) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/openssh/openssh_10.3p1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index e6bc9e9a5b6..9793e3fa6dc 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -46,6 +46,7 @@ CVE_STATUS[CVE-2023-51767] = "upstream-wontfix: It was demonstrated on modified CVE_STATUS[CVE-2026-3497] = "not-applicable-platform: Only affects GSSAPI Key Exchange patches used by some Linux distributions and does not exist in upstream openssh." CVE_STATUS[CVE-2026-55653] = "not-applicable-platform: Only applies to RHEL FIPS patches." CVE_STATUS[CVE-2026-59998] = "${@bb.utils.contains('PACKAGECONFIG', 'kerberos', 'unpatched', 'not-applicable-config: GSSAPI/Kerberos support is disabled in the default OpenSSH configuration', d)}" +CVE_STATUS[CVE-2026-55655] = "not-applicable-platform: Only applies to RHEL patches." PAM_SRC_URI = "file://sshd" From patchwork Sun Oct 11 08:39:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100313 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B7F8CA9ED3 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23432.1791708070738122985 for ; Sun, 11 Oct 2026 01:41:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hzSw2jLL; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48c6f764f82so219929f8f.0 for ; Sun, 11 Oct 2026 01:41:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708069; x=1792312869; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cvo+X8tQS8ztgTvEvsm+YjywPJRL6eRj+zIQYskufZE=; b=hzSw2jLLpHqPEpcDxdr5sNPEa5OueafLCKCOOnO99Sus17pjBjSaKZKiMLV1GmpO7c YaAzJ3Ug0yWWx9Ne1rpXcK1lHqPoe9YzMhIcqwiUP5xfncWyXqrkXPShH05vpqMes2Ni sbmSe1TeSl3ZdKe4n2l+1cGAKxb+FXM9LfDoQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708069; x=1792312869; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cvo+X8tQS8ztgTvEvsm+YjywPJRL6eRj+zIQYskufZE=; b=2kl/WIBNc4lmj9+cZ7i4G7YzfX2orbk3pAqSoC19D1HCduktLeT6kcAJ9tvYchVOkJ pxgp4YeNHscO9C5ZSv/0t8a/4zTVikQTvtSWLDkAsX//BLc/nhUKRWmKndBJEaPuu3yC +UhxMS3SfwLanClKasM0FtN/YwDHsVYcNDvolSHAWrK4qENJ+yNHoj41mohcL57uoTRJ OVK+j3w3hhFs7kl82fHtkAB+j6vWo9gszLsE/XnEdIkHfzaMw4GIqza8wqBALFb2M8C7 RvOVUu9wIxi46iVoJzoF3AUnV+15Fe5LgNrpatnNF/GpTSL7AVto6jEJKhnfbWyAvnZr eSoQ== X-Gm-Message-State: AFq9FYJgn7elY/sAwl+MmcqKOjRq2Z/Kl+xe7uGLfgmIr2vjYV7gTTAF hIrjFV9rbRcHTtzmwVVuWxxfzHQT0lIGK2DxYM4ivm/IlNT+vkyuaH+oX4lBcp/BNbkkDtOtjOy AyOJUr5I= X-Gm-Gg: AYBFou3y5gIdcz+aAsTR469xC9PfD1PHhcledzm2h3Ex/68mEEZGVOGXV7ADVGQXjk3 FwYXHbajoMpskez+zYJxSao3FGJCzkLwjoo/JMKU+hequUsbXJd9nHuS83ocGgRF4KOrQbRfewD gmnQ/+L2C0AHWkh9UcvHsuWvv3xsm8sFyhbngscvuRDdgxb7vXFrXoQ0ApdoyeotSgIszZVo0q2 /uT2q1BfsWngo1TnIX2SWWiWoRuNIRfZtR/RKWa9gbKbWcKXjmf59eqqy7jh21IDelIFf3nSfSv P2E1kTx8mPa/IibS9j2ET/VnD1Yhz+n0GIpZO9mTRBg2uWbosWakVuYLIgUx9jGX5tyoscq0GQl Dzvzum1xMYJHt9jBVsX26oKGBkx30C3z6EQJYk8Ixb3yoFwff0GI792Lz/x4zfaWGzTVd80I6pA 9zuj+9Ci6bJ2Xirkjsr7C4zYxAC/jr9HTYufPcyF4DnoyliF4mNt6yYbe2RDbtCV5YkV2M+MepR tD0CBGNRIMMVHojmXb2aNfjcNUEommAKk/pbK8jVdcr3ZLhILzGEhr+/ZhWtFBVZvBHtXS0qcij algUEy1G X-Received: by 2002:adf:e183:0:b0:487:490:8391 with SMTP id ffacd0b85a97d-48dbaadd94cmr11178073f8f.16.1791708068910; Sun, 11 Oct 2026 01:41:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/60] openssh: set status for CVE-2026-55654 Date: Sun, 11 Oct 2026 10:39:48 +0200 Message-ID: <7940891fd50e0fe5a509d81afd66ebc05e4420d3.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247524 From: Peter Marko Per desctiption in [1] (which is different than description in [2]), this is RedHat patches. Also [3] suggests this. [1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/55xxx/CVE-2026-55654.json [2] https://security-tracker.debian.org/tracker/CVE-2026-55654 [3] https://ubuntu.com/security/CVE-2026-55654 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 389919ea7927962a61a5aaa7b641c5b60af560e0) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/openssh/openssh_10.3p1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index 9793e3fa6dc..c53100cd99f 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -46,6 +46,7 @@ CVE_STATUS[CVE-2023-51767] = "upstream-wontfix: It was demonstrated on modified CVE_STATUS[CVE-2026-3497] = "not-applicable-platform: Only affects GSSAPI Key Exchange patches used by some Linux distributions and does not exist in upstream openssh." CVE_STATUS[CVE-2026-55653] = "not-applicable-platform: Only applies to RHEL FIPS patches." CVE_STATUS[CVE-2026-59998] = "${@bb.utils.contains('PACKAGECONFIG', 'kerberos', 'unpatched', 'not-applicable-config: GSSAPI/Kerberos support is disabled in the default OpenSSH configuration', d)}" +CVE_STATUS[CVE-2026-55654] = "not-applicable-platform: Only applies to RHEL patches." CVE_STATUS[CVE-2026-55655] = "not-applicable-platform: Only applies to RHEL patches." PAM_SRC_URI = "file://sshd" From patchwork Sun Oct 11 08:39:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100310 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4AA46CA9ED2 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23433.1791708071694317115 for ; Sun, 11 Oct 2026 01:41:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KR00gBQO; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-4a19cba5c14so1684785e9.3 for ; Sun, 11 Oct 2026 01:41:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708070; x=1792312870; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rNRyhAIgwedZCvvSf//nbSMfhHBPkUVX2ATPd+AX9Rw=; b=KR00gBQOGWlU0G35ym2t3+yRrgEfbRaP1dBCSLXiebbxjyhaGikryujZ72qpe0pY1s Q2fi1j/nwtVYaXfeKc/xRvJ/Jh1AKTPjj/uBcjV7KQLjDD5mBEJ0YZHV99rYai3VhE8s Si5PjV5WxJAKvtS6Rey/OTBv0D6yJAOAVr97Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708070; x=1792312870; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rNRyhAIgwedZCvvSf//nbSMfhHBPkUVX2ATPd+AX9Rw=; b=eUftCwj9ZAy5eGexKW4x6qpui90nR6o9tDtaJEY00XcSSfYSE8cYbF7gjwNfzz0jPI S3z7EhEy0OB7RKIOLqEwM+qvJvOl38osoTeqKU91zFrwU8GhtPKRAIlaR5CK6CzBm7yO hbGDN/Ha5bV4n89xDa8O1KZPGmmPIr3fsoSobFVM7/2rzoqfPdx3Zo0c42rPiJ2YLjwB pxpRso5Yo5Y1BMb9AAdbjgfw+LPc1GNISimkcabBqFUm6XePF1f0QZShDrojKiAcjOPS kCyIyYoL3+g/9vbnP6xqmKEZziR0hdgk+JwlX361m+hKtJK0/xJWxfFtnbbIhLppRzkO kXow== X-Gm-Message-State: AFq9FYKcTfiXUap+aLStez2ZnR+Mu1qmgClRHNOSu6T1+8C96lopRwgI 6VTH9//As2zjOq3UNabF1GUWZm4dD3gxOLVGyTYJL5rLklg7xodjKpK6s8t6SeP75ULhF93at80 ZK9CBLyY= X-Gm-Gg: AYBFou0bWeVVvmqpQn9FPLCpuPpKG+WpZfn8GXID5ZWdZhlzflCoSmehQ31dg/eEsRn nL33Ng1luRBJUMH071z/WAThpI/lPoDTQsgi+6Yn7QBdE3yU7eAK0RPuKG9RRClh8rZxhuBjiXc UPTacyHXXot4EKP2f0M8EdxR9G/2+4Da5fVF2mRFYnljz9xfRtMW8gQCmRe+Zb/BxHu0zKnnP9X Mm/YFuAsdspdli66ZBM7xY/vE20nA6vuBwg2kPP+vaC9h4ebnS8PuXGdhY56uA5dq+uDRdbHDMO NWpQ8f7/o83lzmXWwNnBOvNkMDqc/jXR1d30GXUNH2xDJ0oi3U806xLVZkg+dUX4GfmCUvBxZUB 5KxzgU6uyQJl2K7OiZAccPtsE/hxXQ+OPhTQYZEcKTEWq/3ZLmfxJJ6unpFRXs8KWrccRohdEop CmY3R1VR//jRivRbXmIi51rEoYDXGtUK7Vl6zK9ztnLVegvS4DjE4o+kU2oivbegWCEY1f987vP ltGD0mfOG26S+Euoq0aOHz3jQOTMYT1XKTVKIkR4ORk+Gj/UoiO0uqXuJ2ETSKwEWPxS1ECNxZ+ fkkn40ML X-Received: by 2002:a05:600c:3e8d:b0:4a1:7701:f863 with SMTP id 5b1f17b1804b1-4a18e4aeae4mr111242335e9.15.1791708069590; Sun, 11 Oct 2026 01:41:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/60] xserver-xorg: set status for CVE-2026-55999 and CVE-2026-56000 Date: Sun, 11 Oct 2026 10:39:49 +0200 Message-ID: <3ac73f299c2f78d9a37f20951917d7ee0f036930.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247525 From: Peter Marko Per [1], CVE-2026-55999 was fixed by [2] which was backported as [3]. Per [4], CVE-2026-56000 was fixed by [5] which was backported as [6]. [1] https://security-tracker.debian.org/tracker/CVE-2026-55999 [2] https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1 [3] https://gitlab.freedesktop.org/xorg/xserver/-/commit/0f1f4bcbfb1f23b800dfe386782d3a0f05b6756f [4] https://security-tracker.debian.org/tracker/CVE-2026-56000 [5] https://gitlab.freedesktop.org/xorg/xserver/-/commit/2779affbdb4354e894f490e56f962527d6125043 [6] https://gitlab.freedesktop.org/xorg/xserver/-/commit/d6d96084f305a142eb3db7f720d7edd21e4c98b4 cvelistV5 has correct version identification, so CNA (SUSE) has it correct, too. NVD however shows non-existing version 21.2.24 (probably from CVE description), so it's showing up in reports as unfixed. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: b6ab21c7e75acb65a3993565929be9c72f4a3d39) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-graphics/xorg-xserver/xserver-xorg.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-graphics/xorg-xserver/xserver-xorg.inc b/meta/recipes-graphics/xorg-xserver/xserver-xorg.inc index 782c1f76ca4..419e539a541 100644 --- a/meta/recipes-graphics/xorg-xserver/xserver-xorg.inc +++ b/meta/recipes-graphics/xorg-xserver/xserver-xorg.inc @@ -31,6 +31,8 @@ available for this flaw." CVE_STATUS[CVE-2022-3553] = "cpe-incorrect: This is specific to XQuartz, which is the macOS X server port" CVE_STATUS[CVE-2026-34000] = "fixed-version: fixed since v21.1.22" CVE_STATUS[CVE-2026-34002] = "fixed-version: fixed since v21.1.22" +CVE_STATUS[CVE-2026-55999] = "fixed-version: fixed since v21.1.24" +CVE_STATUS[CVE-2026-56000] = "fixed-version: fixed since v21.1.24" S = "${UNPACKDIR}/${XORG_PN}-${PV}" From patchwork Sun Oct 11 08:39:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100315 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7AD58CA9ED6 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23434.1791708072524345039 for ; Sun, 11 Oct 2026 01:41:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SBDUJ7/Z; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48441a2ba1bso518373f8f.1 for ; Sun, 11 Oct 2026 01:41:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708071; x=1792312871; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jkewcsiStxqki59oytX2BNCLMj8Re1sRm78Vsv2XkVs=; b=SBDUJ7/Zhd8YBk6GuzGycwnRqzMgnsrf8jZaQ58ddvVOl/3+1CRA72Pd5pLz+PyPeB +JNLNgEO2awbRIzy/xUYQ0aP3LrDGTIB/40io8Sb3qLhP2w2EV1UR+IQNafSRwUuDMeq t7W5O98BdQeylWgmAzAPYm9EDRJAeqegJQQEw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708071; x=1792312871; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jkewcsiStxqki59oytX2BNCLMj8Re1sRm78Vsv2XkVs=; b=O5qq5RM6FBSSMjMKXX9/qxC+ikRAbvfV6p136/KeYxf6cDvK/IZJcTMBhcKKZtGo9j yH0uYlBcdRL95/a6McboQiQa04TfVdsAV58ezsBL/QcdhasymyHsBxTIhswYb9KyWbxX /qA1qQhUgUZ2pbi4/P1ty3t95Xy21wB8jPzOJjbLxal+E1EakYDbp6+wGfZT6P2fZ2my o8N4Tdv6oR8SvquHUeRKiaaKy5yP4a1zLWexHBxiKhvI3NICz3SLnx5BIV1nn6edZwl5 hQ8KkNUJ+W7sy7hRbd5CRjvHTUNjHWdRgFEgvzfqkrU10mHNqiCzzM+b5Bf18iUg/sEX 5BPw== X-Gm-Message-State: AFq9FYIaZHWnpX24o6W9iUtuviGKqdDDw+xfxbCBfUwiaKpOu7PdAaXK WjiHmqnn3fzAZTugmocF04NId4aB0IhHs/xtyabyxHAWh14Xd/rUMcBpBOJFtjXT6TFe8t40av8 YbQ11Kd8= X-Gm-Gg: AYBFou2ajKd7tOmvf/i49+9HKq35WNvionvJNGNEjguVeVUCEChFw6APcckm/bNW235 rew1ysSkGq1CDFYiduqo+VABoLVCBqPqU/aXagtB1tBoih5RkZEuzavoLAb51kMLvqtc85sOfzU z4MC+OuJ5tbx6YJrwjzAmwF+ZDgSHp1EsKbYWcjZqnray+S0ofC/1chB7dJBiF3cj+s8+MuuWrU 2vu5QnyoPyqntsjsYwHT53e9QOvltikh0t+IjshuFlbtPwkNq2vvRCIk3eYHo5OFXOPZVtyUFWR kVzaiCEJNnZ6wq9dFhF9dxkL8cTuWEiG1o55YfoesKqAW9lC2NMQcGekxYMjzloUYjpKLyK0srL yJasvf3cO00i6dAsvU88bUXgVe1B3LtpTviyU/lM9YcbnNiX+mF2tcp5m29B2MMlCgRRv+fH29a CqT1oVhp7/+3P+FAfTQxwa1mQ6zfC5GvZWl++W7JXTk9XsrZpFFetr6Rx2qK47+UL8zzfbbgEeE q9FhzQ4YBNY7wwco9+x3SepCF5CVUl9ccY9xgzLBjkhBXTStzCAY8Q3P2hQ1tdGcTrhfy0Vxw== X-Received: by 2002:a05:6000:11c8:b0:487:da0:df5a with SMTP id ffacd0b85a97d-48dbaae370emr8769966f8f.42.1791708070624; Sun, 11 Oct 2026 01:41:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/60] openssh: fix CVE-2026-73283 Date: Sun, 11 Oct 2026 10:39:50 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247526 From: Hetvi Thakar This patch applies the upstream fix that makes the authorized_keys restrict keyword apply to tunnel forwarding. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/d322f2ccf7da095ce94d1d99cb563246f61487b [2] https://www.cve.org/CVERecord?id=CVE-2026-73283 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-73283.patch | 42 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 43 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73283.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73283.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73283.patch new file mode 100644 index 00000000000..d2660149e31 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73283.patch @@ -0,0 +1,42 @@ +From d322f2ccf7da095ce94d1d99cb563246f61487b Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Tue, 14 Jul 2026 01:05:05 +0000 +Subject: [PATCH] upstream: make authorized_keys "restrict" keyword apply + correctly + +to tunnel forwarding (which is administratively disabled by default). + +Reported by Erichen, Institute of Computing Technology, +Chinese Academy of Sciences + +OpenBSD-Commit-ID: 5b3cc987a64749c94b20e12755db32a83f8f01e6 + +CVE: CVE-2026-73283 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d322f2ccf7da095ce94d1d99cb563246f61487b] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose + OpenSSH 10.3p1 revision. + +(cherry picked from commit d322f2ccf7da095ce94d1d99cb563246f61487b) +Signed-off-by: Hetvi Thakar +--- + serverloop.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/serverloop.c b/serverloop.c +index 8e63480ec..9d8a3429 100644 +--- a/serverloop.c ++++ b/serverloop.c +@@ -523,7 +523,8 @@ server_request_tun(struct ssh *ssh) + ssh_packet_send_debug(ssh, "Unsupported tunnel device mode."); + return NULL; + } +- if ((options.permit_tun & mode) == 0 || options.disable_forwarding) { ++ if ((options.permit_tun & mode) == 0 || options.disable_forwarding || ++ auth_opts->restricted) { + ssh_packet_send_debug(ssh, "Server has rejected tunnel device " + "forwarding"); + return NULL; +-- +2.43.0 diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index c53100cd99f..e3c8c1944d0 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -31,6 +31,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-60001.patch \ file://CVE-2026-60002.patch \ file://CVE-2026-60000.patch \ + file://CVE-2026-73283.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Sun Oct 11 08:39:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100308 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1B483CA9ED1 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23567.1791708073045052628 for ; Sun, 11 Oct 2026 01:41:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=k7WMWylY; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-48c4649b35bso863999f8f.3 for ; Sun, 11 Oct 2026 01:41:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708071; x=1792312871; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5u5G+bRWHYMwkVDP3Ev0nRVPaAtqe1DXG83c3GC/DvE=; b=k7WMWylY8y/hazH33EEn3YjlkTWoamujpV9kvwEhmKqhv0SJka7kaGIE15TxSpIeCC TLa+DYS82TNNYbU5tmMv63ZxmTT1f+JHVuSQozOV/cVV5pvHBgSg8wcrVJfzPHl+9kiu UJ+K8S2t0K7uyz5RU8R0CxG4NDDcGTNKjtPT0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708071; x=1792312871; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5u5G+bRWHYMwkVDP3Ev0nRVPaAtqe1DXG83c3GC/DvE=; b=1SIAReWn6qirRDniEH3ASqGCq/yPDgolD8JPqvVjwS/Z8Ja+TzKQwaPQxXFnqgFp1+ ASyj3E7DItSmLdLqMl0w6GSbOs4/GNfDenGR4Z9nY95B7/Eoy7+F/TGdOxFmU6iSLdru ahhjpA51XW0GmLmiLUC53A7gzsUtAfrzeWE4/VeqBIPFHc/j5ummC+7D4watTrMzkQ/z +PNylGXcF9I0k0pY4BRHGZQYoXEUAOuqGF/u9sKcVKuajiRFqFRuHpULEZWMgw+xKAEP 6bYXgcHpv2fvvUWULDVlcSpZl/xMnfOV5ixJvIBFWWqJFHbONPrB2RkvDSuiw2tzTs6n lzTw== X-Gm-Message-State: AFq9FYK5Y7PGFI45Jfh4k+fWJspYEfknCP59mk/pH/VTtNrDyQvZhsrK mA/GYP7AI1JFEc0h3osgmN3ukctnRMVWRXj0jB+bcQJwUBTPv9RA/0YVzDx8c3I0cxmbVCeqfgs JSuT/Xqs= X-Gm-Gg: AYBFou2JWHTZribJ7y82kVWxOnCN0GtOkdhbMjuss8rlHRM076Bqn62RbOCm7+wbm8a c/jWhWOdTJ2xFUK2mVeUNE35k0gVFmMGMdNQbkVUuhYbEUhqKRyTSR1DNJ74qK8uo+GPk1NrAef nfKWgxUJrdDH/1+eXJO/CN5BMHH+3dL4uFwy5Dh0JFvvFutne1XV/wIEfChLUPn08hlsPA1e3Wg x14HHGQxg44UsO8nrd9xEHsFEiSM3CNQZiTFY/024ZVxC0d/eHRTqW3IfgxZVZLm+d+iONoaMu2 0hm7RkiwxDQRNotSdJLDdCF3oe1I7zst2lDp+bsjDgF6tiyUDHZ561feZHd4A0ZiTmlcviPJH4A JFRg0vdvTDKqo0ICm50ZB7gTHPXRcFF/8RSOP5v2grU2Y7afIzDFpUakZ2tUv0LfB6WgCTkSmnP K4xunm16baTTjfrcyZ4mlDm31OlIZXUg+lMnCjtXI3qsiNYNWq6ybIZlYrErGdytczsfJG8HjJD wifeLOO4+EN44DRaWkUE+9cKt+lTfNPEKpvZNn7cIUkKBp2CMon7kfCHeZXkjnbxKSxlXXzzg== X-Received: by 2002:a05:6000:240b:b0:487:169f:d339 with SMTP id ffacd0b85a97d-48dbacef394mr10218672f8f.54.1791708071159; Sun, 11 Oct 2026 01:41:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/60] openssh: fix CVE-2026-73282 Date: Sun, 11 Oct 2026 10:39:51 +0200 Message-ID: <3005ba08f0b81fe18ce60f3289de4ad892e8aa04.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247527 From: Hetvi Thakar This patch applies the upstream fix that tracks pending remote-forward requests by index instead of retaining a pointer that realloc may invalidate. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299 [2] https://www.cve.org/CVERecord?id=CVE-2026-73282 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-73282.patch | 80 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 81 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch new file mode 100644 index 00000000000..f5b4762e511 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch @@ -0,0 +1,80 @@ +From 9910d5ef53124ce1157d57bc11e222658aa41299 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Fri, 7 Aug 2026 05:03:56 +0000 +Subject: [PATCH] upstream: avoid potential realloc use-after-free in the + client if a + +remote forwarding is added via the local session multiplexing socket while a +remote forwarding open request is pending with the server. + +Report and fix from Brian Mingus of Cognatory + +OpenBSD-Commit-ID: c7888d566576386d0e96859f9ec7310a1e2d3609 + +CVE: CVE-2026-73282 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/9910d5ef53124ce1157d57bc11e222658aa41299] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose + OpenSSH 10.3p1 revision. + +(cherry picked from commit 9910d5ef53124ce1157d57bc11e222658aa41299) +Signed-off-by: Hetvi Thakar +--- + ssh.c | 19 +++++++++++++++++-- + 1 file changed, 16 insertions(+), 3 deletions(-) + +diff --git a/ssh.c b/ssh.c +index d030b548..e9f99c43 100644 +--- a/ssh.c ++++ b/ssh.c +@@ -1899,14 +1899,24 @@ + } + } + ++struct rfwd_confirm_ctx { ++ int fid; ++}; ++ + /* Callback for remote forward global requests */ + static void + ssh_confirm_remote_forward(struct ssh *ssh, int type, uint32_t seq, void *ctxt) + { +- struct Forward *rfwd = (struct Forward *)ctxt; ++ struct rfwd_confirm_ctx *rctx = (struct rfwd_confirm_ctx *)ctxt; ++ struct Forward *rfwd; + u_int port; + int r; + ++ if (rctx->fid < 0 || rctx->fid >= options.num_remote_forwards) ++ fatal_f("invalid forwarding ID %d", rctx->fid); ++ rfwd = &options.remote_forwards[rctx->fid]; ++ freezero(rctx, sizeof(*rctx)); ++ + /* XXX verbose() on failure? */ + debug("remote forward %s for: listen %s%s%d, connect %s:%d", + type == SSH2_MSG_REQUEST_SUCCESS ? "success" : "failure", +@@ -2084,6 +2094,8 @@ + + /* Initiate remote TCP/IP port forwardings. */ + for (i = 0; i < options.num_remote_forwards; i++) { ++ struct rfwd_confirm_ctx *rctx; ++ + debug("Remote connections from %.200s:%d forwarded to " + "local address %.200s:%d", + (options.remote_forwards[i].listen_path != NULL) ? +@@ -2098,9 +2110,10 @@ + if ((options.remote_forwards[i].handle = + channel_request_remote_forwarding(ssh, + &options.remote_forwards[i])) >= 0) { ++ rctx = xcalloc(1, sizeof(*rctx)); ++ rctx->fid = i; + client_register_global_confirm( +- ssh_confirm_remote_forward, +- &options.remote_forwards[i]); ++ ssh_confirm_remote_forward, rctx); + forward_confirms_pending++; + } else if (options.exit_on_forward_failure) + fatal("Could not request remote forwarding."); +-- +2.43.0 diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index e3c8c1944d0..c92b059a052 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -32,6 +32,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-60002.patch \ file://CVE-2026-60000.patch \ file://CVE-2026-73283.patch \ + file://CVE-2026-73282.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Sun Oct 11 08:39:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100307 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01736CA9ECF for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23435.1791708073637871388 for ; Sun, 11 Oct 2026 01:41:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xM5ZJore; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-487049569b6so598942f8f.1 for ; Sun, 11 Oct 2026 01:41:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708072; x=1792312872; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=U/Ajp5IoeOCrSNlJuhn5SUbm2lYhM1iq5jxLdjrr00E=; b=xM5ZJoreKuzZtGMUwyEIJturXkOkVORHgrCigTOP0MDX5SarDI2C+7ohMWAhOc8cyY JdUHXRW0fYIcStBjo3lYfdkiInXbWZzQhzo+N1kJpT/DeeFvIQyB6W8qkXjXnv+fFw23 l99VITuAMNvbdmvhQeLMCRBgxAFQviz591n0g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708072; x=1792312872; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=U/Ajp5IoeOCrSNlJuhn5SUbm2lYhM1iq5jxLdjrr00E=; b=gv6CefsyHWzCzFx9U5Grc8cvfdTmEKR3MUXyAJyDH5fl+XUI1eGgbqRTYmOcUWzHpU 11ogbG74e1lJKX8Ty5N/tcDY/vO8WirdJX9WDUlHktEIyfTYbKNP6p8Gg23fH92qKtK2 UkbNFLKKRMTX97lAt490ZkV+TpDViDjqzpbRaNx2XPmnIDBYNC+KglKBbhF5CNbeUZ8K OOaPCvTxVew5UGW84dwZ31SLyAzm4bEi03mC8THt7wwbbk5hYr9p36KdHlseo4tEmDpA BGtS8CGuGF9Odas03HOaNW/Ddm9qunGv1Lz7dRf9XOGwBroP4LSNBZECMYryZurlydu5 Lqqw== X-Gm-Message-State: AFq9FYL6WwW9hLgcQ3EFitlAJ9ezUJyoNr+1gyX+0SSdSIBQNTNxFrYg QF09KNBCRUSBkVJaoyfHw1rhIRP0u76q0wJ5TB1UfbNOrqreCKIK5tOrUtQTTj0XjPUetPU+Hfb sxNuM8ro= X-Gm-Gg: AYBFou2kU9+WAMS7I4PEBw/NlYTuPS0Qmnso/+76sDBiQxUUkktW7I7joqdtHtUEKfS +nWs17ba57Z2NPQjH2GWY2dK87fjmo+S7C6X1wdfhj3V/EkaC0bqHhR0hHqqvejfwB0W9CLZ+gu exf2m2zZWaPht74IZZJh2FpwOL0NR19PLNCF1EJhaksg3i0bk1qrUu/bxyQoUC7GNQNVTKjnBEB lkn1epGvKzDQrAZt15GbfwiaB0ns3avgN00T6TKjxKdySqCUJOwJT0mrH9+nD32b2Fwb5OR6xKy euFGZNLTid86yWaAUqoiJ3IHrc4vnJTSSh/Qlp7kv1sz+CYgc0rHSNx8Tcg9jt56g/BaT1sq3iN l8aLk4DKuqzRcn4Lvdkf3RKmlfb3owswf4MOVMCObUaPbB4/dGON6fSK3+IJs11u2y7OpTQTm1C /Rl1d3eFw+pOjjiJmE6sZjG3KHwlIsnLbzYBPa1MZc4+NRF4fgtWRxCro1zZTuxE3GKO674HTcv d0ZI04g+Al0g3RJXQJRTi1Ia+coJ7y4KYLm77PWKGiZDuA+g6tvV6I6RUCBbBeyoxlywGMsxw== X-Received: by 2002:a05:6000:310c:b0:487:8b9:526a with SMTP id ffacd0b85a97d-48dbacdaa60mr11068364f8f.36.1791708071707; Sun, 11 Oct 2026 01:41:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/60] openssh: fix CVE-2026-73281 Date: Sun, 11 Oct 2026 10:39:52 +0200 Message-ID: <925268cdaefa76dd6e2de8b727dfc3825e6a5c22.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247528 From: Hetvi Thakar This patch applies the upstream fix that permits session-bind requests while the agent is locked so forwarded sessions remain classified as remote. The upstream fix commit is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/openssh/openssh-portable/commit/6a57081dc35acf3ee298108d4bc3580489608d5 [2] https://www.cve.org/CVERecord?id=CVE-2026-73281 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../openssh/openssh/CVE-2026-73281.patch | 80 +++++++++++++++++++ .../openssh/openssh_10.3p1.bb | 1 + 2 files changed, 81 insertions(+) create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch new file mode 100644 index 00000000000..6dbe7b33ff3 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch @@ -0,0 +1,80 @@ +From 6a57081dc35acf3ee298108d4bc3580489608d5 Mon Sep 17 00:00:00 2001 +From: "djm@openbsd.org" +Date: Fri, 7 Aug 2026 05:18:05 +0000 +Subject: [PATCH] upstream: Allow session-bind@openssh.com requests when the + agent is + +locked, otherwise forwarding sessions established with an agent was locked +will be treated as local, rather than remote. + +Reported by sn0x-sharma + +OpenBSD-Commit-ID: 524f210c6f2b3a06e0a2f6d0af5188a9a75fa2c7 + +CVE: CVE-2026-73281 +Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/6a57081dc35acf3ee298108d4bc3580489608d5] + +Backport Changes: +- Omitted the upstream OpenBSD revision-only hunk and retained the Wrynose + OpenSSH 10.3p1 revision. +- OpenSSH 10.3p1 lacks the later `replied` result tracking in + process_extension(), so retained `success = process_ext_query(e)`. + +(cherry picked from commit 6a57081dc35acf3ee298108d4bc3580489608d5) +Signed-off-by: Hetvi Thakar +--- + ssh-agent.c | 23 +++++++++++++++++++---- + 1 file changed, 18 insertions(+), 5 deletions(-) + +diff --git a/ssh-agent.c b/ssh-agent.c +index 5fc73d69..1604f540 100644 +--- a/ssh-agent.c ++++ b/ssh-agent.c +@@ -1795,12 +1795,22 @@ + return; + } + +- if (strcmp(name, "query") == 0) +- success = process_ext_query(e); +- else if (strcmp(name, "session-bind@openssh.com") == 0) ++ /* ++ * This function can be called while the agent is locked to allow ++ * session binds to be processed for new channels. ++ * Other operations should be refused when locked. ++ */ ++ ++ if (strcmp(name, "session-bind@openssh.com") == 0) { + success = process_ext_session_bind(e); +- else { ++ } else if (locked) { ++ debug_f("attempt to use extension \"%s\" while locked", name); ++ goto generic_fail; ++ } else if (strcmp(name, "query") == 0) { ++ success = process_ext_query(e); ++ } else { + debug_f("unsupported extension \"%s\"", name); ++ generic_fail: + free(name); + send_status(e, 0); + return; +@@ -1857,14 +1867,17 @@ + /* check whether agent is locked */ + if (locked && type != SSH_AGENTC_UNLOCK) { +- sshbuf_reset(e->request); + switch (type) { + case SSH2_AGENTC_REQUEST_IDENTITIES: + /* send empty lists */ + no_identities(e); + break; ++ case SSH_AGENTC_EXTENSION: ++ process_extension(e); ++ break; + default: + /* send a fail message for all other request types */ + send_status(e, 0); + } ++ sshbuf_reset(e->request); + return 1; + } +-- +2.43.0 diff --git a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb index c92b059a052..a476645f40f 100644 --- a/meta/recipes-connectivity/openssh/openssh_10.3p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_10.3p1.bb @@ -33,6 +33,7 @@ SRC_URI = "https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.ta file://CVE-2026-60000.patch \ file://CVE-2026-73283.patch \ file://CVE-2026-73282.patch \ + file://CVE-2026-73281.patch \ " SRC_URI[sha256sum] = "56682a36bb92dcf4b4f016fd8ec8e74059b79a8de25c15d670d731e7d18e45f4" From patchwork Sun Oct 11 08:39:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100309 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3792CCA9ED0 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23568.1791708074596030812 for ; Sun, 11 Oct 2026 01:41:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oG/woIQy; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48c6955a7c3so127369f8f.1 for ; Sun, 11 Oct 2026 01:41:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708073; x=1792312873; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=g9/KcSkDg60NAPusg6YWATKdw6U0Jdti5Hk6MMxn7TE=; b=oG/woIQyjFHU5LbMTqnQDkiLle5DshB74N9HdpVJHAlX9nBYLViQHLz8hgfCF+VC30 Y5WTy2CLUURxNIYvFEAu+9ODYh3Lek1SkBpOH2yHnSE2KN5CKdBYR6tkYmzlXIPjf8KN m34Yz8Ri2Slu18Y4ITaZhoxd7DM0q3JLSxIuQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708073; x=1792312873; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=g9/KcSkDg60NAPusg6YWATKdw6U0Jdti5Hk6MMxn7TE=; b=qLOuXwpDPTMRP9B/rwu8moBfV2UUC9tRuW6wxxNTgALB/pdcgIH+1RrGI6CjXUATMZ oT1FrscKBtPTd8KVYMGYzJsLMLDs9IWa4fC+n+FxUBNCWAglQf8TomtLFrYLIrF6NC+z B3NQIgHkoTRPTp+Rfglm1zGqrnUTcz7lDOSLnGMhapK870sXcIH6J5lMRctdzoaCy8Al OqY6YQv7s0KKuLORhHpst3UAS1I4e0rKtdlYyF4jqCxs8YEaA0aYFeHCLAY/foxlnek1 vcYhf5J1dBl0BAlOFQNVpR8+B+k4QspQ0BSJexi3YinoWYGIC38aODNlSb+n9gN6jxT6 61iA== X-Gm-Message-State: AFq9FYI2X11tcBUnk7qlg8fx9+tXCmlBIvy8pRQfiJwmDtU7FOsM8o2R r9+Nl2BPMLJzqeo4nawCHumQp1eJZglNd6tQwSt9ZVDTuhWe6eZWF1cLtjEpJ3pJwj6Y/AaQCFx AbgcY6DU= X-Gm-Gg: AYBFou05paaEpbiaYrVIrYXloVsrK+YoNA3CGykBas7+9XET0Zi0dwogPBNhXl9k5nl J6hoH37p9YCEYolUfjqR/RevFkE6HCuudIPcWW0PbiL2lgxjw1b+TPWqQ+hlFId+nn3iBTUlzbE UHgh8ymggRJTnLYh+6w5bvX6mOKttZKEwZVumgKquVO5xuq4lqE13Ep3e4AYiWDv2EM+4TVsCar 2jFO/DyXpgaf2Rttz4UTTCWF/6IyEvL36o1q55O0hCi7SjI5rOB8xw4hdlIrlpnv9vXdWdbIWHk oMhIuOmNplz/arcLk4MoBaUi/BYVAEfn3ZE2HOt8blChLpX797HhWcPbfDHE9vEaNkiN63ucRx/ rJa4BjxehCkzVpXWQaCs5CxW5gWlW2nKIWLpKZoKDMRg0JRYm6A47a0dLHH52myISCvhMdYuwur A2bq2mAx9BGWnhVvhTuSZpza98mKoys4EylgZ1npkMPs1mAzwCKoB7OWVyv82Rl6geHTcjO2CmX /RkICPvBBTSxEO4RBk6E4UahBrRMPTN/cotkEOBN/XhB1I5nytCRVTX5EfUU2u9hDSBdPssW5c= X-Received: by 2002:adf:f184:0:b0:48a:f5de:2ad1 with SMTP id ffacd0b85a97d-48dbad2acb9mr8241988f8f.42.1791708072636; Sun, 11 Oct 2026 01:41:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/60] vim: set CVE_STATUS for CVE-2026-51400 Date: Sun, 11 Oct 2026 10:39:53 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247529 From: Hetvi Thakar Analysis: - The vulnerable code for CVE-2026-51400 is in src/os_vms.c. [1] - src/os_vms.c is VMS-specific and is not compiled for Linux builds. - Record the not-applicable-platform status; no source patch is required. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-51400 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-support/vim/vim.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index de639a65026..37c5cacaaaf 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -52,6 +52,8 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} PV .= ".0340" SRCREV = "6addd6c101117706bc9b3609d3a418e26e92618f" +CVE_STATUS[CVE-2026-51400] = "not-applicable-platform: Vulnerable code is in src/os_vms.c, which is not compiled for Linux builds." + # Do not consider .z in x.y.z, as that is updated with every commit UPSTREAM_CHECK_GITTAGREGEX = "(?P\d+\.\d+)\.0" # Ignore that the upstream version .z in x.y.z is always newer From patchwork Sun Oct 11 08:39:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100312 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 62434CA9ED5 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23438.1791708075339148001 for ; Sun, 11 Oct 2026 01:41:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ddEzhRzZ; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48c4d99c32bso887426f8f.1 for ; Sun, 11 Oct 2026 01:41:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708073; x=1792312873; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/azLy5sz+KPXZ4Tfoo04za8IeQ8sdstVgh3eT/Hb3PA=; b=ddEzhRzZOEGWQBuq6/AbEy/f+X0wR0g4FIf3UmWLZnD2S2lA5mkpOKHDC4KEaDRKX4 tfqNHMTgG1WtdGLQIq/RriBABQrOl/DlciWHYKbTQ53vbaGK5HVIF7XCTrwJ7+1slSr6 bdezGkcPQdX4r4e6xUUJNhrgwxkGcrf2q09jA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708073; x=1792312873; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/azLy5sz+KPXZ4Tfoo04za8IeQ8sdstVgh3eT/Hb3PA=; b=YAJluylGDaqHa0VPY6s7WbrK4WbuX+a5HzXcieNrNKCiVWUoFA8nGFSP2MJcVlONFZ gnvDWECx6bYNsK1SP/Oz+MiBJkKT2PKisdDyPahawDLGS5+ox+AqWViCHv2DNIe4hMjT 2y5U5qJib8/72uINrLb2IO7/lOlJ4ypfCW8ub4UUg/oY6oBxOC0AFooJNOEbJ4mYNa8f aJ1Xc4nktfWaw7HGsszRCgWSAs5MdEeTUgmX1oKbW3LPPa6dyj2ukPxGw3ZSaQbMuuT/ ZbFrtKwsSZzqG38BQdNP4OvVEsjI/eLVchgOohmqrnaIvIpfuKv0+zZwEUCj+AMrKhTg SwPg== X-Gm-Message-State: AFq9FYLZcizPK+0Dgu9QIZZpKKoJPY0TaYmEpvggYIzqF0XwUYwpxzlA LGMD3TCQWBJ7D1REQHRhlabQVFAwqY6MAQhIcBgujQOubujGnU3i9g4una+7ZjCKpBLiQUi1Ue7 PB+42AxY= X-Gm-Gg: AYBFou3S0cCIwwhxZEGLuSCc9Ps+dp0OruFUGZc8efl9ahcFhL2e0NM/lG6Tac5PAB+ nBXfnDU/F7U7EH/WPM8FUaA3KCHLcuelkfzcjNs8bZIkj2swQOK5IfnksMYmdbfUoE3pZxlUFCD 2CVSr4yN8r/Q4mU3NAn3CcccGTz695JRxEnCmF+D/qB8c7O3KiscT82GLEmLYUI3PdA1V6mR/0q mZ6BAzmzw8wV5s2PiUWJY2nJGU0IO9OPG45b0Emtgt3zN3aObrMDo+6QgWB8T/3XDq9UpJ947vz vRM4CQ/IIH33z2a0f7RW0FHtza+ILmYcvxT/V/W+45gf0XCtPUDJPDox1d1/Ufed5pF8biU/eGZ bELZw9K8LfFpTfBoWYPYcvtfkb0S0X5/eN24qLciDe2N/DTFXYWLqqhH5vbPnQauGEUnUySaq7K Rp4nIzFdbSGDb8qBL9uRfjJFkBdZ7iIIXfaKJT96umMEsdSIf5bw6kHosrAW0SmjdKaL32Ri1rU 5Pmx3n9gzwqheABPvTIf9pp5wSkmREAmjSOqLqFqVycpOG+IJXSzdH6vmdJHVP4Vj6OBvKecg== X-Received: by 2002:a05:6000:298e:10b0:48c:7f53:9603 with SMTP id ffacd0b85a97d-48dba77d033mr8983890f8f.7.1791708073402; Sun, 11 Oct 2026 01:41:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/60] vim: set CVE_STATUS for CVE-2026-51401 Date: Sun, 11 Oct 2026 10:39:54 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247530 From: Hetvi Thakar Analysis: - The vulnerable code for CVE-2026-51401 is in src/os_vms.c. [1] - src/os_vms.c is VMS-specific and is not compiled for Linux builds. - Record the not-applicable-platform status; no source patch is required. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-51401 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-support/vim/vim.inc | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 37c5cacaaaf..3fbfd887a5f 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -53,6 +53,7 @@ PV .= ".0340" SRCREV = "6addd6c101117706bc9b3609d3a418e26e92618f" CVE_STATUS[CVE-2026-51400] = "not-applicable-platform: Vulnerable code is in src/os_vms.c, which is not compiled for Linux builds." +CVE_STATUS[CVE-2026-51401] = "not-applicable-platform: Vulnerable code is in src/os_vms.c, which is not compiled for Linux builds." # Do not consider .z in x.y.z, as that is updated with every commit UPSTREAM_CHECK_GITTAGREGEX = "(?P\d+\.\d+)\.0" From patchwork Sun Oct 11 08:39:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100306 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C3E39CA9EC9 for ; Sun, 11 Oct 2026 08:41:17 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23439.1791708076542510648 for ; Sun, 11 Oct 2026 01:41:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=uYF4YYLf; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-48c411d6615so542345f8f.3 for ; Sun, 11 Oct 2026 01:41:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708075; x=1792312875; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=KvWLtCgLmZHJsK8WRlJvQkKvRp6HcXvE6CMTooHGl/U=; b=uYF4YYLfPRMuGQYCwoE/WmX6NJYQaByBr3LAAogZ0f3NAUnQFBig0VwtbtgZsyK81Y 0H28otr9+FjLwdkKc7dqmbVkkMDP6LoZxlLBk3FCaKXGLRN5k9MIENteGhwL5O3ylb9F CqjKzpxUd9mM9o7PmQY9XqKkeNAkKKpu8DnPI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708075; x=1792312875; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=KvWLtCgLmZHJsK8WRlJvQkKvRp6HcXvE6CMTooHGl/U=; b=vjpOF2oYJLup0XL/Bd2EVduaQCyGrMCVk8afj4ssIM3NimTMTja+iPDdYJPfJSoN+d 93ibSFqIrlpeDQkzHqwKHtgQ904sXYIEs9tncOg73K/NpDwwSF0un2ll3Evg16rmqv6a f3/BgcQWeY3TyPNUImyFPUsyRUk4k1LqRIuFWNoZkkkEh+8FOI/qIPh5ddwA0j4iclKM jwfOHla7HIZUugGSraLBC+jnXKanpnnPFpF1KOMZITY1Ufi9lHrEsc53ZZHY/v8SVK1x 8u7EoVNxhrpyHI/hwAVkRPx1/Ic+z2Iv5Xr8FiQWcS33Mj4P4Ng9Hozz4fPX1oA/W+SV 4RQw== X-Gm-Message-State: AFq9FYKCEne2FlR0TzYtkvisJn4Qk9LTQhQqCgSRRei3o0NyBM/rJjrD GaJ4EDTpqmppa9T7ETQjzS5n58xuLV5Wja8fNUYSFfqkPyG6qJee1FudWk04WRzh5FaZ6J/F61e DQ+wwsu0= X-Gm-Gg: AYBFou2tABHQQS0eB3tCJjoHXhQgsIa6QOtxzx8mNAabc1zKtvupm+WK7x8qQRiv5CJ 5iu8wBmHzqUG4UvEEsfvW+bwLdy1nkcnlstbWweamvbcd0xaymt6UnLs+jI0JOCengW2VtJ3GEf fA+TL0Zi+sL53FtRPIsWCsX+2IDZhBHYe7EDt8QQI2hkHagHEXUKH0C82dikNLTwbBGpZBjRHRZ 4hzlgrZcwokiXN1bkihMc++1zaJtKbX02ZAgdbskW2wDBkwdPGdiC5hZD+KRPU6R24oDJY4HjOD Lx17cg7k9oUSOlbslWng8SOov+yb71TKS04kDlCzUkdUzP3o1dZVBdu7s839mE8q8y400P3IixU 4BFxLM9xr72RY9kJ/loQgE5TTxK/Br4shprdR04nl4KNOweX6+SKETghrb4vcIFL5xaGe/of29L hLo59XNYzKdIxFULuBXZqvkt/2Tyx09PDTgjf7Q77X8u8auc8d9Olpmojc+EXDMlwvy6JM/Yohj RjUIczZwCdgvQKM5Lt9Ir12Jvf+GhvxQPKkG7OKlvnH5yGZwcujM5lV7U3pj2G+FOZRCt0PLEtI 9+xcY4mt X-Received: by 2002:a05:6000:29c3:b0:48d:c15c:94a5 with SMTP id ffacd0b85a97d-48dc15c964amr5888215f8f.14.1791708074562; Sun, 11 Oct 2026 01:41:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/60] gnutls: fix CVE-2026-42012 Date: Sun, 11 Oct 2026 10:39:55 +0200 Message-ID: <46a5bd5e5e1c08791cfaf36d3a7f1df5dfcf4028.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247531 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42012. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42012 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/8dcc6a1f48945997666ac9f10896819edd01a03b Tested with ptest Pre patches taken from upstream so CVE fix will land cleanly Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42012-pre1.patch | 69 ++++++++ .../gnutls/gnutls/CVE-2026-42012-pre2.patch | 161 ++++++++++++++++++ .../gnutls/gnutls/CVE-2026-42012.patch | 48 ++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 3 + 4 files changed, 281 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre2.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre1.patch new file mode 100644 index 00000000000..9b2a5d16cab --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre1.patch @@ -0,0 +1,69 @@ +From 6133fb459b74a9dcfa2d0ff010a4e03c56822d39 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Fri, 13 Mar 2026 17:00:03 +0100 +Subject: [PATCH] x509/hostname-verify: refactor and simplify CN fallback logic + +Signed-off-by: Alexander Sosedkin +CVE: CVE-2026-42012 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/6133fb459b74a9dcfa2d0ff010a4e03c56822d39] + +Signed-off-by: Jakub Szczudlo +--- + lib/x509/hostname-verify.c | 15 ++++++--------- + 1 file changed, 6 insertions(+), 9 deletions(-) + +diff --git a/lib/x509/hostname-verify.c b/lib/x509/hostname-verify.c +--- a/lib/x509/hostname-verify.c ++++ b/lib/x509/hostname-verify.c +@@ -108,7 +108,7 @@ unsigned gnutls_x509_crt_check_ip(gnutls + * that we do not fallback to CN-ID if we encounter a supported name + * type. + */ +-#define IS_SAN_SUPPORTED(san) \ ++#define PRECLUDES_CN_FALLBACK(san) \ + (san == GNUTLS_SAN_DNSNAME || san == GNUTLS_SAN_IPADDRESS) + + /** +@@ -151,13 +151,12 @@ unsigned gnutls_x509_crt_check_hostname2 + { + char dnsname[MAX_CN]; + size_t dnsnamesize; +- int found_dnsname = 0; + int ret = 0; + int i = 0; + struct in_addr ipv4; + char *p = NULL; + char *a_hostname; +- unsigned have_other_addresses = 0; ++ bool cn_fallback_allowed = true; + gnutls_datum_t out; + + /* check whether @hostname is an ip address */ +@@ -213,9 +212,10 @@ hostname_fallback: + ret = gnutls_x509_crt_get_subject_alt_name(cert, i, dnsname, + &dnsnamesize, NULL); + +- if (ret == GNUTLS_SAN_DNSNAME) { +- found_dnsname = 1; ++ if (PRECLUDES_CN_FALLBACK(ret)) ++ cn_fallback_allowed = false; + ++ if (ret == GNUTLS_SAN_DNSNAME) { + if (memchr(dnsname, '\0', dnsnamesize)) { + _gnutls_debug_log( + "certificate has %s with embedded null in name\n", +@@ -236,13 +236,10 @@ hostname_fallback: + ret = 1; + goto cleanup; + } +- } else { +- if (IS_SAN_SUPPORTED(ret)) +- have_other_addresses = 1; + } + } + +- if (!have_other_addresses && !found_dnsname && ++ if (cn_fallback_allowed && + _gnutls_check_key_purpose(cert, GNUTLS_KP_TLS_WWW_SERVER, 0) != 0) { + /* did not get the necessary extension, use CN instead, if the + * certificate would have been acceptable for a TLS WWW server purpose. diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre2.patch new file mode 100644 index 00000000000..30ed2252c24 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre2.patch @@ -0,0 +1,161 @@ +From 5cc003b9688378f6c7934b1df0aa147e80006be4 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Fri, 13 Mar 2026 17:41:33 +0100 +Subject: [PATCH] x509: add bare-bones awareness of SRV virtual SAN + +There's no support for constraints, no certtool support, no nothing. +Just added what's easy to add because I needed a virtual SAN for them. + +Signed-off-by: Alexander Sosedkin +CVE: CVE-2026-42012 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/5cc003b9688378f6c7934b1df0aa147e80006be4] + +Backport Changes: +- virt-san.c: use _gnutls_steal_datum instead of upstream _gnutls_take_datum + (3.8.12 already provides steal_datum; take_datum is added later). + +Signed-off-by: Jakub Szczudlo +--- + lib/includes/gnutls/gnutls.h.in | 4 +++- + lib/x509/common.h | 1 + + lib/x509/name_constraints.c | 3 ++- + lib/x509/output.c | 6 ++++++ + lib/x509/virt-san.c | 23 +++++++++++++++++++++++ + lib/x509/x509.c | 3 ++- + 6 files changed, 37 insertions(+), 3 deletions(-) + +diff --git a/lib/includes/gnutls/gnutls.h.in b/lib/includes/gnutls/gnutls.h.in +--- a/lib/includes/gnutls/gnutls.h.in ++++ b/lib/includes/gnutls/gnutls.h.in +@@ -2698,6 +2698,7 @@ void gnutls_psk_set_server_params_functi + * @GNUTLS_SAN_OTHERNAME_XMPP: Virtual SAN, used by certain functions for convenience. + * @GNUTLS_SAN_OTHERNAME_KRB5PRINCIPAL: Virtual SAN, used by certain functions for convenience. + * @GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL: Virtual SAN, used by certain functions for convenience. ++ * @GNUTLS_SAN_OTHERNAME_SRV: Virtual SAN, used by certain functions for convenience. + * + * Enumeration of different subject alternative names types. + */ +@@ -2715,7 +2716,8 @@ typedef enum gnutls_x509_subject_alt_nam + Used by gnutls_x509_crt_get_subject_alt_othername_oid. */ + GNUTLS_SAN_OTHERNAME_XMPP = 1000, + GNUTLS_SAN_OTHERNAME_KRB5PRINCIPAL, +- GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL ++ GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL, ++ GNUTLS_SAN_OTHERNAME_SRV + } gnutls_x509_subject_alt_name_t; + + struct gnutls_openpgp_crt_int; +diff --git a/lib/x509/common.h b/lib/x509/common.h +--- a/lib/x509/common.h ++++ b/lib/x509/common.h +@@ -107,6 +107,7 @@ + #define XMPP_OID "1.3.6.1.5.5.7.8.5" + #define KRB5_PRINCIPAL_OID "1.3.6.1.5.2.2" + #define MSUSER_PRINCIPAL_NAME_OID "1.3.6.1.4.1.311.20.2.3" ++#define SRV_OID "1.3.6.1.5.5.7.8.7" + #define PKIX1_RSA_PSS_MGF1_OID "1.2.840.113549.1.1.8" + #define PKIX1_RSA_OAEP_P_SPECIFIED_OID "1.9" + +diff --git a/lib/x509/name_constraints.c b/lib/x509/name_constraints.c +--- a/lib/x509/name_constraints.c ++++ b/lib/x509/name_constraints.c +@@ -516,7 +516,8 @@ static int validate_name_constraints_nod + if (type != GNUTLS_SAN_DNSNAME && type != GNUTLS_SAN_RFC822NAME && + type != GNUTLS_SAN_DN && type != GNUTLS_SAN_URI && + type != GNUTLS_SAN_IPADDRESS && +- type != GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL) { ++ type != GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL && ++ type != GNUTLS_SAN_OTHERNAME_SRV) { + return gnutls_assert_val(GNUTLS_E_X509_UNKNOWN_SAN); + } + +diff --git a/lib/x509/output.c b/lib/x509/output.c +--- a/lib/x509/output.c ++++ b/lib/x509/output.c +@@ -121,6 +121,7 @@ static void print_name(gnutls_buffer_st + if ((type == GNUTLS_SAN_DNSNAME || type == GNUTLS_SAN_OTHERNAME_XMPP || + type == GNUTLS_SAN_OTHERNAME_KRB5PRINCIPAL || + type == GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL || ++ type == GNUTLS_SAN_OTHERNAME_SRV || + type == GNUTLS_SAN_RFC822NAME || type == GNUTLS_SAN_URI) && + sname != NULL && strlen(sname) != name->size) { + adds(str, _("warning: SAN contains an embedded NUL, " +@@ -180,6 +181,11 @@ static void print_name(gnutls_buffer_st + name->size, NON_NULL(name->data)); + break; + ++ case GNUTLS_SAN_OTHERNAME_SRV: ++ addf(str, _("%sSRVName: %.*s\n"), prefix, name->size, ++ NON_NULL(name->data)); ++ break; ++ + default: + addf(str, _("%sUnknown name: "), prefix); + _gnutls_buffer_hexprint(str, name->data, name->size); +diff --git a/lib/x509/virt-san.c b/lib/x509/virt-san.c +--- a/lib/x509/virt-san.c ++++ b/lib/x509/virt-san.c +@@ -45,6 +45,9 @@ static int san_othername_to_virtual(cons + memcmp(oid, MSUSER_PRINCIPAL_NAME_OID, + sizeof(MSUSER_PRINCIPAL_NAME_OID) - 1) == 0) + return GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL; ++ else if ((unsigned)size == (sizeof(SRV_OID) - 1) && ++ memcmp(oid, SRV_OID, sizeof(SRV_OID) - 1) == 0) ++ return GNUTLS_SAN_OTHERNAME_SRV; + } + + return GNUTLS_SAN_OTHERNAME; +@@ -59,6 +62,8 @@ static const char *virtual_to_othername_ + return KRB5_PRINCIPAL_OID; + case GNUTLS_SAN_OTHERNAME_MSUSERPRINCIPAL: + return MSUSER_PRINCIPAL_NAME_OID; ++ case GNUTLS_SAN_OTHERNAME_SRV: ++ return SRV_OID; + default: + return NULL; + } +@@ -126,6 +131,15 @@ int _gnutls_alt_name_assign_virt_type(st + name->type = GNUTLS_SAN_OTHERNAME; + break; + ++ case GNUTLS_SAN_OTHERNAME_SRV: ++ ret = _gnutls_x509_encode_string(ASN1_ETYPE_IA5_STRING, ++ san->data, san->size, ++ &encoded); ++ if (ret < 0) ++ return gnutls_assert_val(ret); ++ name->san = _gnutls_steal_datum(&encoded); ++ break; ++ + default: + return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST); + } +@@ -187,6 +201,15 @@ int gnutls_x509_othername_to_virtual(con + othername->data, + othername->size, virt, 0); + if (ret < 0) { ++ gnutls_assert(); ++ return ret; ++ } ++ return 0; ++ case GNUTLS_SAN_OTHERNAME_SRV: ++ ret = _gnutls_x509_decode_string(ASN1_ETYPE_IA5_STRING, ++ othername->data, ++ othername->size, virt, 0); ++ if (ret < 0) { + gnutls_assert(); + return ret; + } +diff --git a/lib/x509/x509.c b/lib/x509/x509.c +--- a/lib/x509/x509.c ++++ b/lib/x509/x509.c +@@ -1562,7 +1562,8 @@ inline static int is_type_printable(int + { + if (type == GNUTLS_SAN_DNSNAME || type == GNUTLS_SAN_RFC822NAME || + type == GNUTLS_SAN_URI || type == GNUTLS_SAN_OTHERNAME_XMPP || +- type == GNUTLS_SAN_OTHERNAME || type == GNUTLS_SAN_REGISTERED_ID) ++ type == GNUTLS_SAN_OTHERNAME_SRV || type == GNUTLS_SAN_OTHERNAME || ++ type == GNUTLS_SAN_REGISTERED_ID) + return 1; + else + return 0; diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch new file mode 100644 index 00000000000..1f43efc1222 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch @@ -0,0 +1,48 @@ +From 8dcc6a1f48945997666ac9f10896819edd01a03b Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Fri, 13 Mar 2026 17:02:07 +0100 +Subject: [PATCH] x509/hostname-verify: make URI/SRV SAN preclude CN fallback + +URI/SRV SAN did not suppress CN fallback as required by RFC 6125 6.4.4: +> a client MUST NOT seek a match for a reference identifier of CN-ID +> if the presented identifiers include a DNS-ID, *SRV-ID*, *URI-ID*, +> or any application-specific identifier types supported by the client. + +With this change, certificates containing URI or SRV SAN +no longer pass DNS hostname checks via CN fallback +to avoid potential misuse of such certificates +beyond their original purpose. + +Reported-by: Oleh Konko +Fixes: #1802 +Fixes: CVE-2026-42012 +Fixes: GNUTLS-SA-2026-04-29-7 +CVSS: 6.5 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N +Signed-off-by: Alexander Sosedkin +CVE: CVE-2026-42012 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/8dcc6a1f48945997666ac9f10896819edd01a03b] + +Signed-off-by: Jakub Szczudlo +--- + lib/x509/hostname-verify.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/lib/x509/hostname-verify.c b/lib/x509/hostname-verify.c +index e7597ad3b0..d989bb1abc 100644 +--- a/lib/x509/hostname-verify.c ++++ b/lib/x509/hostname-verify.c +@@ -108,8 +108,9 @@ unsigned gnutls_x509_crt_check_ip(gnutls_x509_crt_t cert, + * that we do not fallback to CN-ID if we encounter a supported name + * type. + */ +-#define PRECLUDES_CN_FALLBACK(san) \ +- (san == GNUTLS_SAN_DNSNAME || san == GNUTLS_SAN_IPADDRESS) ++#define PRECLUDES_CN_FALLBACK(san) \ ++ (san == GNUTLS_SAN_DNSNAME || san == GNUTLS_SAN_IPADDRESS || \ ++ san == GNUTLS_SAN_URI || san == GNUTLS_SAN_OTHERNAME_SRV) + + /** + * gnutls_x509_crt_check_hostname2: +-- +GitLab + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index 92854eeaf9c..fd332ee8c55 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -42,6 +42,9 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42010.patch \ file://CVE-2026-33845.patch \ file://CVE-2026-5419.patch \ + file://CVE-2026-42012-pre1.patch \ + file://CVE-2026-42012-pre2.patch \ + file://CVE-2026-42012.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sun Oct 11 08:39:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100305 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B1A61CA9EC7 for ; Sun, 11 Oct 2026 08:41:17 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23440.1791708077042498508 for ; Sun, 11 Oct 2026 01:41:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Pl6iApY7; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-48af27fe287so818846f8f.0 for ; Sun, 11 Oct 2026 01:41:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708075; x=1792312875; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=V23RtXl4Lyyx7QLRvMbNj5+7rsZN7u++iwDpLKOTgic=; b=Pl6iApY7rEbVlzmYhgOZN7Kt+4UOu+TcJ6/NfI9apzL7KfuSrt9EBgtWegZLOl4hRO AFF+uEMHkQ+EZ+9hRbc4EjIizIClsr8TQaZ8n91VodT1Oljnv+PEYqBDCmLswCa/RD3g WvwtuxljZeahJfFkNEcZwisaeiCO9dmblArYs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708075; x=1792312875; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=V23RtXl4Lyyx7QLRvMbNj5+7rsZN7u++iwDpLKOTgic=; b=0ZOkak4LpCnpkRVy66p/FW4x2IoK7qsnLU4R7RrZUlcEM8R9OSZnX7SVSixB2RTuzW KfT2ujVK6DjGO/iV8ezgMIryKpkZrkEk92GGJu9Kf2dLbTJ5APtBjFyv6U1ucTm+tnJ8 GkLksJtKrz4FY5rBwTAFuu5+sCm+oZJ5RgqHx2wZ8LIB41kiZ2rK2GALxfN3Bh99WqoY t4g/2oC4S+RhpPq5Zlu+YSj05dzsvzNdpngAE6Fu4VXfaiteqzkGObGoEo4osKRZzupl a0c6c3J38MdhQxMfqBKeLcBjz9FyzHDR3D4+IcXvTcL3GaAtmRTql4TTbQC55PqaRoh5 I2Tg== X-Gm-Message-State: AFq9FYKhRMvq8UxOLHO9FI/pKHub6dk/i7xk+x89wclPp0ncBoAucSkj YakcjlpdumOAWOA5gYjWeTuP/nWhNqV0Od/81ldb2tGt7SBQSR5o/f9aLj8fVQTknuqtDcIdaCA IhWXiH54= X-Gm-Gg: AYBFou1//fjmP4RfhYavf8HtnzJpaZVkkyYFVZO8RVK3T71SV5Sd74z9IO0J5RrKyvO O8lGHA0OSkJxXhhoBLlVf6loIfOfhW86LbP18y0T9ig3wefGzC6NzmYRo1Cjgw7zfk5KOVazByj 1+GBEhbZdlvDDYnwuyapiJVIiJolA7BSi41cGpNJOsf9r4GOf2AolFkRYHgWsNUoGOXh1APq/X1 YRXWPOGZKjQavgtkaRRhxI9GPsE8Qr5j67EONDxJu5624SD/JPOUSr+jxr/jIlm9I+v2TozuJKr NXICG7n24GVS6xwpx66K2trH+wNrxOcY0enDasGKID43bLMr6+TAVQPA8jLYt0LMHJgOohSMdPq bZt7bl63gJ4O/1YFgWtOLhpOAlWA16DYPvYtwVqA1oeO2gZ0NxZwjdyj3Zx+j/Si5OI3LiRu/QB OCWM/ZN+Sh+6cS1zb7uP+K2hqXg7pcHlIKf/qSBu+Uw39g+NBBMctIWiMOYVw7MiTW2nAOJXXMY hWxBkpZVZXWr7yTAt8aGrHr3nBoXoqsNxIIaCNW8NAs/hxVnKr4X4PCvxGLhP09IrTDT+heSsJh 0+E5ZXGj X-Received: by 2002:a5d:59c3:0:b0:48c:7082:ebb with SMTP id ffacd0b85a97d-48dbaaef693mr11624304f8f.42.1791708075064; Sun, 11 Oct 2026 01:41:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/60] gnutls: fix CVE-2026-42013 Date: Sun, 11 Oct 2026 10:39:56 +0200 Message-ID: <7bb61fbec24285a15d6f43d4fe3fa21d2e93ae75.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247532 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42013. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42013 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/29801bef00ecc0f23c0bac4cd333b269cd2c1af4 Tested with ptest Pre patch taken from upstream so CVE fix will land cleanly Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42013-pre1.patch | 56 ++++++++++++++ .../gnutls/gnutls/CVE-2026-42013.patch | 74 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 + 3 files changed, 132 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013-pre1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42013-pre1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42013-pre1.patch new file mode 100644 index 00000000000..53687cb53b9 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42013-pre1.patch @@ -0,0 +1,56 @@ +From 3ee2cb707002f755e4bda3f75285caa0cb36c214 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Wed, 15 Apr 2026 15:35:59 +0200 +Subject: [PATCH] x509/email-verify: call fallback DN fallback + +A comment was inaccurately referring to DN email field fallback +as CN fallback. +Rename a few things as well to match x509/hostname-verify more closely. + +Signed-off-by: Alexander Sosedkin +CVE: CVE-2026-42013 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/3ee2cb707002f755e4bda3f75285caa0cb36c214] + +Signed-off-by: Jakub Szczudlo +--- + lib/x509/email-verify.c | 12 +++++------- + 1 file changed, 5 insertions(+), 7 deletions(-) + +diff --git a/lib/x509/email-verify.c b/lib/x509/email-verify.c +index dbef0bb86e..3c22ffed37 100644 +--- a/lib/x509/email-verify.c ++++ b/lib/x509/email-verify.c +@@ -42,7 +42,7 @@ unsigned gnutls_x509_crt_check_email(gnutls_x509_crt_t cert, const char *email, + { + char rfc822name[MAX_CN]; + size_t rfc822namesize; +- int found_rfc822name = 0; ++ bool dn_fallback_allowed = true; + int ret = 0; + int i = 0; + char *a_email; +@@ -76,7 +76,7 @@ unsigned gnutls_x509_crt_check_email(gnutls_x509_crt_t cert, const char *email, + cert, i, rfc822name, &rfc822namesize, NULL); + + if (ret == GNUTLS_SAN_RFC822NAME) { +- found_rfc822name = 1; ++ dn_fallback_allowed = false; + + if (memchr(rfc822name, '\0', rfc822namesize)) { + _gnutls_debug_log( +@@ -102,12 +102,10 @@ unsigned gnutls_x509_crt_check_email(gnutls_x509_crt_t cert, const char *email, + } + } + +- if (!found_rfc822name) { +- /* did not get the necessary extension, use CN instead +- */ ++ if (dn_fallback_allowed) { ++ /* did not get the necessary extension, use DN email instead */ + +- /* enforce the RFC6125 (§1.8) requirement that only +- * a single CN must be present */ ++ /* only a single one must be present */ + rfc822namesize = sizeof(rfc822name); + ret = gnutls_x509_crt_get_dn_by_oid(cert, + GNUTLS_OID_PKCS9_EMAIL, 1, diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch new file mode 100644 index 00000000000..c63e4d7039d --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch @@ -0,0 +1,74 @@ +From 29801bef00ecc0f23c0bac4cd333b269cd2c1af4 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Wed, 15 Apr 2026 16:02:19 +0200 +Subject: [PATCH] x509: prevent fallback on oversized SAN + +Passing oversized SAN did not preclude CN (or DN email) fallback +during verification, which is an RFC 6125 6.4.4 violation. + +Now oversized SAN are skipped over, +but prevent the fallback from happening. + +Reported-by: Haruto Kimura (Stella) +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1825 +Fixes: #1849 +Fixes: CVE-2026-42013 +Fixes: GNUTLS-SA-2026-04-27-8 +CVSS: 6.5 Moderate CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N +Signed-off-by: Alexander Sosedkin +CVE: CVE-2026-42013 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/29801bef00ecc0f23c0bac4cd333b269cd2c1af4] + +Signed-off-by: Jakub Szczudlo +--- + lib/x509/email-verify.c | 14 ++++++++++++++ + lib/x509/hostname-verify.c | 14 ++++++++++++++ + 2 files changed, 28 insertions(+) + +--- a/lib/x509/email-verify.c ++++ b/lib/x509/email-verify.c +@@ -75,6 +75,20 @@ unsigned gnutls_x509_crt_check_email(gnu + ret = gnutls_x509_crt_get_subject_alt_name( + cert, i, rfc822name, &rfc822namesize, NULL); + ++ if (ret < 0) { ++ if (ret == GNUTLS_E_SHORT_MEMORY_BUFFER) { ++ /* oversized SAN; proceed without DN fallback */ ++ _gnutls_debug_log("oversized SAN ignored, " ++ "disabling DN fallback\n"); ++ dn_fallback_allowed = false; ++ ret = 0; ++ continue; ++ } ++ if (ret != GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE) ++ gnutls_assert(); ++ break; ++ } ++ + if (ret == GNUTLS_SAN_RFC822NAME) { + dn_fallback_allowed = false; + +--- a/lib/x509/hostname-verify.c ++++ b/lib/x509/hostname-verify.c +@@ -213,6 +213,20 @@ hostname_fallback: + ret = gnutls_x509_crt_get_subject_alt_name(cert, i, dnsname, + &dnsnamesize, NULL); + ++ if (ret < 0) { ++ if (ret == GNUTLS_E_SHORT_MEMORY_BUFFER) { ++ /* oversized SAN; proceed without CN fallback */ ++ _gnutls_debug_log("oversized SAN ignored, " ++ "disabling CN fallback\n"); ++ cn_fallback_allowed = false; ++ ret = 0; ++ continue; ++ } ++ if (ret != GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE) ++ gnutls_assert(); ++ break; ++ } ++ + if (PRECLUDES_CN_FALLBACK(ret)) + cn_fallback_allowed = false; + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index fd332ee8c55..b5b3736a773 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -45,6 +45,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42012-pre1.patch \ file://CVE-2026-42012-pre2.patch \ file://CVE-2026-42012.patch \ + file://CVE-2026-42013-pre1.patch \ + file://CVE-2026-42013.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sun Oct 11 08:39:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100316 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AEAA2CA9ED8 for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23441.1791708077383997662 for ; Sun, 11 Oct 2026 01:41:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KlXaPDpn; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48afe75f055so928553f8f.2 for ; Sun, 11 Oct 2026 01:41:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708076; x=1792312876; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=veVcv8nywW2rVWrIQALXP0Hb45wdQ7fTuaDGZrLMAxw=; b=KlXaPDpnUlXAafwkbr5BhgXYl9ZmvZveEn3kbOMeqEAwKsM8bOXooG+2AmpGvzT3ik 71MjhMz2Z2L7pgCY7Ya1o+NgXkmLmpV35HZ/2B6BVP+GkvdLew9J/iOmTfL7TWkrXVz/ nhRN2p6Bj6U/ilRk1qoRF1RUQy1mhg4SOlaYU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708076; x=1792312876; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=veVcv8nywW2rVWrIQALXP0Hb45wdQ7fTuaDGZrLMAxw=; b=fSfI9pJksVcgDCnFYpJUuP9c03qa/a5IfWVbplf9xmxqDDQIH2dfbOcrm4vOMhQ6Hi XaP3TVLZrhHj3TtIOHD3DG8qDaaBvEG0pGnLoKz6VExEn1UX6j435dd39ygi3r14oEHc VpZuIdmFWsERnoLhuVmQ07B+RLcoegZXQEzbcib2pWRG3UwhmzPqnwCGTIZ9YYPL5kYf jNvzLV+Nb8Hqx3Fcnb1lYU+ggEUe+IvBVVk/zHFSspjHB42Nd5xRnJ4Bn14FyrXIlG48 l1ISV1+nxbgZBAPNcZ1uCg+jKBEnPejqjuHzekk6IpKN9ikEY801rbrSouaxz2Anu5B7 QX2g== X-Gm-Message-State: AFq9FYLfYMOeGcsmBPijZp9qQiOP0FzA4MVtPcECDFkKGnVYBQhTF3+W k8Rs0PhWEZZxpOcTqYSZ7oe4x3WyoneFmUe9cL5YbV7RDntlCLfowdtXRFNPcK9a4KaAzI4e83m mmLQqBww= X-Gm-Gg: AYBFou1ECK+sOIPPHZh6h0Xjhx3UBG+cWOPg0BEDT1xYTEdZlITWffi3ijQBSomoeTr oixIH/1IK0tLXpR0H46S+BTBJe5QO9YqCH0leSsrnq4h9+WpkkdyK82ds2cTIuG85+YiuTMpeMJ f90WjXKCzlvwU27QtMJzS9FO8kYSeunWZ1HRUIJUXYFdm3gfP2rwp5/TH7uaE2RbroySkhOwqDs mA/yCnKMgculDAZn7A9PVYwA4BCN7q5kbnJMj683yNPs1AnTkQqmw1GoG04+/4ZDVsY0QDgIf7M 2urcNYIlF83r1rdUBAzlQEBOl0swvBVRYIQ0a+JM3FYpk9eyfKAvnCysPNT+2HZjt1FSCOqyWH0 XK9Mi4Zjw3V1khBAA7bCkLNN6homn1Cj4S3g2i9pbDcVaIEUbzceghyGmqYBjmnYltkEexIYAs6 hfX26iGMrHB/MrMcjvFYXlowbu9zRjG5Bh2tcw8fIzKI179L8+ur5XD8cAMFQEMu/OMbje+48xt k5evFy5peDXD3sfRnBV++nFH3imnScP3VQi1xf+2D/yRx+FpNvlwYXhvMMnaIwkeTqYP4+ewg== X-Received: by 2002:a05:6000:420b:b0:48c:a08:5858 with SMTP id ffacd0b85a97d-48dbaae6fa0mr10554818f8f.23.1791708075534; Sun, 11 Oct 2026 01:41:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/60] gnutls: fix CVE-2026-42014 Date: Sun, 11 Oct 2026 10:39:57 +0200 Message-ID: <0442eedb5e359e2a6de0006274c96a772a18fd3f.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247533 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42014. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42014 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/3957f136e2ed23caf176a594b54b3827f5cef701 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42014.patch | 60 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch new file mode 100644 index 00000000000..776733829ad --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch @@ -0,0 +1,60 @@ +From 3957f136e2ed23caf176a594b54b3827f5cef701 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Wed, 18 Mar 2026 18:19:06 +0100 +Subject: [PATCH] pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin + +Changing Security Officer PIN with gnutls_pkcs11_token_set_pin() with +oldpin == NULL for a token that lacks a protected authentication path +led to a use-after-free. + +Reported-by: Luigino Camastra and Joshua Rogers of AISLE Research Team +Fixes: #1766 +Fixes: #1809 +Fixes: CVE-2026-42014 +Fixes: GNUTLS-SA-2026-04-29-9 +CVSS: 4.0 Medium CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-42014 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/3957f136e2ed23caf176a594b54b3827f5cef701] + +Signed-off-by: Jakub Szczudlo +--- +diff --git a/lib/pkcs11_write.c b/lib/pkcs11_write.c +index 64b85a2..1dff578 100644 +--- a/lib/pkcs11_write.c ++++ b/lib/pkcs11_write.c +@@ -1266,10 +1266,9 @@ int gnutls_pkcs11_token_set_pin(const char *token_url, const char *oldpin, + ses_flags = SESSION_WRITE | SESSION_LOGIN; + + ret = pkcs11_open_session(&sinfo, NULL, info, ses_flags); +- p11_kit_uri_free(info); +- + if (ret < 0) { + gnutls_assert(); ++ p11_kit_uri_free(info); + return ret; + } + +@@ -1290,9 +1289,11 @@ int gnutls_pkcs11_token_set_pin(const char *token_url, const char *oldpin, + oldpin_size = L(oldpin); + + if (!(sinfo.tinfo.flags & CKF_PROTECTED_AUTHENTICATION_PATH)) { +- if (newpin == NULL) +- return gnutls_assert_val( ++ if (newpin == NULL) { ++ ret = gnutls_assert_val( + GNUTLS_E_INVALID_REQUEST); ++ goto finish; ++ } + + if (oldpin == NULL) { + struct pin_info_st pin_info; +@@ -1324,6 +1325,7 @@ int gnutls_pkcs11_token_set_pin(const char *token_url, const char *oldpin, + ret = 0; + + finish: ++ p11_kit_uri_free(info); + pkcs11_close_session(&sinfo); + return ret; + } diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index b5b3736a773..f0fec16d039 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -47,6 +47,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42012.patch \ file://CVE-2026-42013-pre1.patch \ file://CVE-2026-42013.patch \ + file://CVE-2026-42014.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sun Oct 11 08:39:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100317 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BF0BACA9EDA for ; Sun, 11 Oct 2026 08:41:18 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23569.1791708078186269214 for ; Sun, 11 Oct 2026 01:41:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=IruvinmK; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-4a02753c04fso4743335e9.3 for ; Sun, 11 Oct 2026 01:41:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708076; x=1792312876; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=q1VAMJuuJf6f/0jwp70Dli2hx10p7UVI6pGYer5VNDo=; b=IruvinmKOIJSMUCBrDJblZubdmW6k/2ijy4UsAf2QrEthLYWqC2GaN8F28jLBYwuUv 3peaxGjElGBvt634hN7r711MzDOLzPgm3bpM7notG77OMZYrknapGQ8h7VFtmS0dagOh l8r9CvxZO4PnZxGbN88dJc0UFDa+xCfn9SXRM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708076; x=1792312876; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=q1VAMJuuJf6f/0jwp70Dli2hx10p7UVI6pGYer5VNDo=; b=m577oUE5defrT1oP3tmDGYvYkSxKlQOk7TOGO4DJ8gTnfyYP/dBCxZyxN/qF3JES/7 JOO+NryEoSBDfMW14kZ2I67CSynZ0P2dMo6qYkeP+n4daiUuM8SJZ9LIkzVrGsaWFwkY d/M2qOzmWyqGr0W+5hujJa7oyUNxyxyaHRu8e9j6pqb7RQWt6HW+x/2Yo9oz7uEy/Yt0 Do55g/onTS+ufwJLng1zB/czhnakjvNKQUwRPYCmqz4qma5u3t49XGfqZUz3KJUiH1A0 REVuSA3OVNqu4pd6bqvpZJYVeut2AZMkB62F/kasOq+9FfXX89Vh4LrhzuN7O3/ygMwy yYDw== X-Gm-Message-State: AFq9FYK8uuMw91cXp8c1P8WC+G+OgZ5r9rR23YKJrcv8DX213haC1MOA jHIdpqUZQ689/FYdJyCbWjQ+COdZwcjwkYrqJHBk1dI8m0WQh8zt8npxbeaIJAW3MSm2oTDjBvk rT6FpXM0= X-Gm-Gg: AYBFou2Tloc3PtIzZ00eTGrRLcseLGcZhW528M3qVtiYeH+FfLCLcjK0SdPX27lIp+t cG2X25FXHNG783qUR7rEjpSIFJruq/khGPZxvBtMNANTGlbh4kiOuZIBFlQ1+sbWorlRcknSu5A XxRHwjXUlpiBZE8B9NXzRbk8+raxIgBcFeDfoVd8yS2P4wJrn5bmRzRLOSzRnEDM3o3vjg7vPSj zSnUKjEgzp6iMCoDB1xFhk1HthxoOa7BXipaKc4z07fcY95VKI5Ys5S1rOS9fca+6rP2PbxmLrU b6iG59oycZgZwSjkN4BbeIoee29jrC41hd0xjEGmyyHRVPreY4d2f2w6mt9NFcx/Uf8SUJt76Kw kW5hUmoeOkmdxKCraGWmYWSf4Y5Mqjr7AlD9SFWebxxjsF4ezrxdm+el9FZPtqWgVzSKs7Yzd6M cckRoENk5r/JHnaWFECOG1YOAPIJ050s3BXE1PKYdggpM/WTrgCYIUoOGuL05jOg8yhfTMam8Ft GEnGluzIrzQG7CFzYUf7G+5Luyq+v1gKVDDs/4NiuRfmbaMhyXEcc047bxSvtjtELYHykMHoA== X-Received: by 2002:a05:600d:6409:10b0:4a1:96cd:2f6e with SMTP id 5b1f17b1804b1-4a196cd3213mr31223035e9.4.1791708076230; Sun, 11 Oct 2026 01:41:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/60] gnutls: fix CVE-2026-42015 Date: Sun, 11 Oct 2026 10:39:58 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247534 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42015. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42015 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/a3e7c50d3e1761e5ef1d4b225507cab8f2b2c3ca Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42015.patch | 43 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 2 files changed, 44 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch new file mode 100644 index 00000000000..1a2065371d4 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch @@ -0,0 +1,43 @@ +From a3e7c50d3e1761e5ef1d4b225507cab8f2b2c3ca Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Mon, 20 Apr 2026 22:42:20 +0200 +Subject: [PATCH] x509/pkcs12_bag: fix off-by-one in bag element bounds check + +Appending elements to a PKCS#12 bag had a bounds check that +prevented adding the 32nd element. +On the other hand, it is possible to import one that already has 32. +Subsequent appending then led to writing past the 32-element array, +smashing its length. + +Tighten the check to reject any bag with 32 or more elements. + +We'll treat this vulnerability as a Low due to how contrived +the requirements are: for the code to be vulnerable, +it needs to append to an imported untrusted unencrypted PKCS#12 structure. + +Reported-by: Zou Dikai +Fixes: #1840 +Fixes: CVE-2026-42015 +Fixes: GNUTLS-SA-2026-04-29-11 +CVSS: 6.1 Medium CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H +Severity: Low +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-42015 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/a3e7c50d3e1761e5ef1d4b225507cab8f2b2c3ca] + +Signed-off-by: Jakub Szczudlo +--- +diff --git a/lib/x509/pkcs12_bag.c b/lib/x509/pkcs12_bag.c +index 911aeff..3822861 100644 +--- a/lib/x509/pkcs12_bag.c ++++ b/lib/x509/pkcs12_bag.c +@@ -375,7 +375,7 @@ int gnutls_pkcs12_bag_set_data(gnutls_pkcs12_bag_t bag, + return GNUTLS_E_INVALID_REQUEST; + } + +- if (bag->bag_elements == MAX_BAG_ELEMENTS - 1) { ++ if (bag->bag_elements >= MAX_BAG_ELEMENTS - 1) { + gnutls_assert(); + /* bag is full */ + return GNUTLS_E_MEMORY_ERROR; diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index f0fec16d039..c9ec3b08f96 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -48,6 +48,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42013-pre1.patch \ file://CVE-2026-42013.patch \ file://CVE-2026-42014.patch \ + file://CVE-2026-42015.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sun Oct 11 08:39:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100332 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8AAC2CA9ED8 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23570.1791708079561204948 for ; Sun, 11 Oct 2026 01:41:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PqXbb8pS; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49d0da752ffso9942105e9.3 for ; Sun, 11 Oct 2026 01:41:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708078; x=1792312878; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=qL3nLJSnGHZru/zl4WhEf0m8H66p9ladY4CHXDt42Yo=; b=PqXbb8pSbz9W0gbrI4iSdPeBC4J9PEtZnnPpDZeRODTHy5odYNbzPrN/2L0gd26VVU BaxlSmEiVwVkP3j9Zj8rau6xQstr2TPlDpvuUs5Tf/E90NTpvL/sNSfh6Vt0u563t7ga vM9pvKvR3HzL7AVhQeZLjA439Wl4AgNl8vYGE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708078; x=1792312878; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=qL3nLJSnGHZru/zl4WhEf0m8H66p9ladY4CHXDt42Yo=; b=dqFaX9rPpkU+NczyFiapKgiyO2n9LtdrWmagRKuf497wt4EHwUnUCBW4T02/fsk7w+ D6uKA/yojRbJPHpioFr1mDfYIQHN2oe196heD4ZtwavivpL4w1A57K1Z0y/rdTpeNdzt SxM6M9W2ejL4uisG+6QEfIgZYSp3HuvsGhjf/8Z5X/Yw2vItZy1AeZhQubIxxghFNfH2 fB7sOsD5Iy8IerorLZfAjFo3Fv2CTzhtGUzTqx/oTcRhSBomwgu4Ig1P6jrfeHm2q1Yg h+dNfW51LgwFDFo1fZDA478Ha0OE/VDKG1l7vKYjXuP1UHD+lqGiWce3zOXxeSYqkmSd ERwg== X-Gm-Message-State: AFq9FYIIcVjRVbGipICMi2LpjRUXvjmOPVUxP3i5FgLcrgntk/JggyHh A418ah/8zqgxgFtGuHVMaxxg75VIpG63RKvTnr1Gl8T9KUjYuYmLo2cA0qmhZPIVyF0i91TOFPy bK9bUfls= X-Gm-Gg: AYBFou3Flg/JrM6jV/qgFkKSjEQoeYklTaIgHnp91MFj5c7cOU6rNtmV/GlzxcO9Mt2 Aru8pE9datUXWXO8ifrIU8Vi4pkXPcPIeX4eMBZdUgOJuLLr42WL9xRpFKqI55pHpicpDtgTVlE 2lgRn4HM0EWxMr23uFNyMELR8CNldJc+0VCk5gbWd4/VnP0ZsFJ344qNqgXBVw75/0huYl4ov7y xL+bt/k/gH0vVjnYWSPXbDz9P64KgAf/b5yE08PT2DvxvjFi+YlLcfQ4Zb83aoQHA2CMJlbfLae ty/QCcKJyUNAlFM6z1QUAHYUrgM/ZGxaLjIWoYkqWasL3JgqWNM6Q8WYzZrhPbHhk+O/c9uHvq8 JXkK76bZAf6ILpztVR71wh7jsXzYdSudqEiVAZoWwOe8LbhKe/9ghm6ZGYiEg7VW8FHZjX8UUSg dkcbFuIn8BDHEjvAH8U+jsRThKszpGlZ45a56WJK1huaP/5K1/Ulqfrg9zhXaoUck7lZyodTRjM oFl808UDFYkAc906q2kJ5d6dQh1c9zMUW9MDcoFG/Ki3xO8WGmowRcs2cnNYZbCcWBrg/O5dw== X-Received: by 2002:a05:600c:4709:b0:4a1:7baa:7303 with SMTP id 5b1f17b1804b1-4a18e4a5237mr123297365e9.7.1791708076844; Sun, 11 Oct 2026 01:41:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/60] gnutls: fix CVE-2026-5260 Date: Sun, 11 Oct 2026 10:39:59 +0200 Message-ID: <4ad1fb8b7d674369ab50bcc12678ecac9891748b.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247535 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-5260. References: https://nvd.nist.gov/vuln/detail/CVE-2026-5260 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/77228f2d1ac207d2f894e5a168fbb47e5378e42f https://gitlab.com/gnutls/gnutls/-/commit/cf6bdc5e4df49e5583d3fb4d2296779785f10683 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-5260_p1.patch | 69 +++++++++++++++++++ .../gnutls/gnutls/CVE-2026-5260_p2.patch | 33 +++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 + 3 files changed, 104 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch new file mode 100644 index 00000000000..c5ab814031e --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch @@ -0,0 +1,69 @@ +From 77228f2d1ac207d2f894e5a168fbb47e5378e42f Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Mon, 30 Mar 2026 17:31:07 +0200 +Subject: [PATCH] lib/auth/rsa: check that ciphertext matches the modulus size + +A client sending extremely short premaster secret as part of an +RSA key exchange could've theoretically triggered a short heap overread +to nowhere when the RSA key was backed with a PKCS#11 token. +With this fix, the internal decryption function will not be called +with an mismatching plaintext length specified, avoiding the overread. + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1814 +Fixes: CVE-2026-5260 +Fixes: GNUTLS-SA-2026-04-29-10 +CVSS: 5.9 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-5260 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/77228f2d1ac207d2f894e5a168fbb47e5378e42f] + +Signed-off-by: Jakub Szczudlo +--- +diff --git a/lib/auth/rsa.c b/lib/auth/rsa.c +index 4d18132..496c378 100644 +--- a/lib/auth/rsa.c ++++ b/lib/auth/rsa.c +@@ -158,6 +158,7 @@ static int proc_rsa_client_kx(gnutls_session_t session, uint8_t *data, + int ret, dsize; + ssize_t data_size = _data_size; + volatile uint8_t ver_maj, ver_min; ++ unsigned int key_bits; + + #ifdef ENABLE_SSL3 + if (get_num_version(session) == GNUTLS_SSL3) { +@@ -180,6 +181,10 @@ static int proc_rsa_client_kx(gnutls_session_t session, uint8_t *data, + } + ciphertext.size = dsize; + } ++ gnutls_privkey_get_pk_algorithm(session->internals.selected_key, ++ &key_bits); ++ if (ciphertext.size != (key_bits + 7) / 8) ++ return gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED); + + ver_maj = _gnutls_get_adv_version_major(session); + ver_min = _gnutls_get_adv_version_minor(session); +diff --git a/lib/auth/rsa_psk.c b/lib/auth/rsa_psk.c +index cc92b4a..dba4011 100644 +--- a/lib/auth/rsa_psk.c ++++ b/lib/auth/rsa_psk.c +@@ -257,6 +257,7 @@ static int _gnutls_proc_rsa_psk_client_kx(gnutls_session_t session, + ssize_t data_size = _data_size; + gnutls_psk_server_credentials_t cred; + volatile uint8_t ver_maj, ver_min; ++ unsigned int rsa_key_bits; + + cred = (gnutls_psk_server_credentials_t)_gnutls_get_cred( + session, GNUTLS_CRD_PSK); +@@ -313,6 +314,10 @@ static int _gnutls_proc_rsa_psk_client_kx(gnutls_session_t session, + return GNUTLS_E_UNEXPECTED_PACKET_LENGTH; + } + ciphertext.size = dsize; ++ gnutls_privkey_get_pk_algorithm(session->internals.selected_key, ++ &rsa_key_bits); ++ if (ciphertext.size != (rsa_key_bits + 7) / 8) ++ return gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED); + + ver_maj = _gnutls_get_adv_version_major(session); + ver_min = _gnutls_get_adv_version_minor(session); diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch new file mode 100644 index 00000000000..67154164c52 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch @@ -0,0 +1,33 @@ +From cf6bdc5e4df49e5583d3fb4d2296779785f10683 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Mon, 30 Mar 2026 17:46:40 +0200 +Subject: [PATCH] lib/pkcs11_privkey: guard against overreading on short + ciphertexts + +This is an alternative fix for the callee side. + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1814 +Fixes: CVE-2026-5260 +Fixes: GNUTLS-SA-2026-04-29-10 +CVSS: 5.9 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-5260 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/cf6bdc5e4df49e5583d3fb4d2296779785f10683] + +Signed-off-by: Jakub Szczudlo +--- +diff --git a/lib/pkcs11_privkey.c b/lib/pkcs11_privkey.c +index 568474e..e133c49 100644 +--- a/lib/pkcs11_privkey.c ++++ b/lib/pkcs11_privkey.c +@@ -838,7 +838,7 @@ int _gnutls_pkcs11_privkey_decrypt_data2(gnutls_pkcs11_privkey_t key, + if (ret != 0) + return gnutls_assert_val(GNUTLS_E_LOCKING_ERROR); + +- buffer = gnutls_malloc(siglen); ++ buffer = gnutls_malloc(MAX((size_t)siglen, plaintext_size)); + if (!buffer) { + gnutls_assert(); + return GNUTLS_E_MEMORY_ERROR; diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index c9ec3b08f96..069e3f447b6 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -49,6 +49,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42013.patch \ file://CVE-2026-42014.patch \ file://CVE-2026-42015.patch \ + file://CVE-2026-5260_p1.patch \ + file://CVE-2026-5260_p2.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sun Oct 11 08:40:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100320 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB156CA9ECA for ; Sun, 11 Oct 2026 08:41:28 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23571.1791708080073430873 for ; Sun, 11 Oct 2026 01:41:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=N7w6FfUh; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48afe75f055so928571f8f.2 for ; Sun, 11 Oct 2026 01:41:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708078; x=1792312878; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ntD1fLOdn0QX9QZ+f6AwbMX9P7fN0nNHfIj79hhZQBU=; b=N7w6FfUhIdmwTPBPWiF1tmTY4qXWaYNmXcfzYRQd6oWt6CTE9En38Vd0pLosxohV/l spElNLYp8qTIrWcgra4z45nO0alEOteIiMengSxFQTTr5t0FOwoLpvtXpZeRinUdGlw/ jIJnixVRMFqPcdkZjRRqqQvcwdFY5bAns2NGs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708078; x=1792312878; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ntD1fLOdn0QX9QZ+f6AwbMX9P7fN0nNHfIj79hhZQBU=; b=vld2ln5+lkTv1r7SxPn5A7GKKskYz2n1iRwUYyEILZGbsgc3EZ7DJVESU4l+YRKB7y ImaA/xuOHNcSbUz363mWWu5jn3pL0Mlfk68IJDcqeLRkSChWIOZfREuciklZsXkU+FQE blvqzycYp3r8/d+i/bjVb10E5YKK0hGwwczOPPb89RdDM0Xz07a62fQeJnXKlzOcqgUg cQo3EMSFEfb/7tJxdN7cUX421M/dh3xBvPKp3kdAEbTLF23x5IR51rG/YFSggKQFdFIq IQkTA6dmI0Ywh5ldek74mOpgkrY45exuauk7K4zf4+FMvCetCrp/VouUjFdwf++3oYym aX0A== X-Gm-Message-State: AFq9FYIiA2UutsTUDEyWOB+itqcFNDptXZUaHPy9XQ34MRbR5/LciPbI pxidiEMd9eua2IyVQlZugWFhxhUflv3F+HGZZXG4b1cmIpm6Np8QLQoD5vUhNK16FJRoPS9pMt0 7AplH79A= X-Gm-Gg: AYBFou1Vq+N3dQ4vAsK9CoGElVqGH+N2P3mDDrpbGeEdiRESVwiQXkfxo/yd/KNoHjZ eN5hfrakbPNcnXMeiFUm32e2uQSRgpdhEwM8yIqE2kiq922zzHgTslaFFedJlpflsvsowMuHNK1 O97Rj9KATMDiMJO5jutUuy0+n380s+RDKXAcH/VXbV32xqTLRQa7WunH05eZLPAsnivZG6oHuUQ Qg04UrhKkveH9/dpYJTz4kInk3U8FCR9JZwUFBMkGnvsoI5E3MeDKUN1CuYXFrYeZg+NFK5ZZrV OOpEnKWTRciMjUjRVOG41m4bqsFxumvR8BArCRfZl6pUYXNA+E5i9lvitTeQghZLjT7j3PP4UiT Fluqpc+sMQvjAmagq4feUTtO7maGM8U75VkTQXXgCntqiVynx6kSpL4/moR3eOegW0hPXRlHJc0 w70mvgfN/H+A+E0yTIdT1fxwo2K3Ar+2O9EVOzyxUwdOAYEXE5qkEvqERouTkXJL4drbPNfxsvh +FP38ZzZfpAjI4Q9Cl5Xm8y9dKex7QhS1CnF/TJHx69duxDLM0T/+Ztqydpxov+XZzeJAeeJYet S6weA1jc X-Received: by 2002:a5d:5590:0:b0:48c:6cdd:ba89 with SMTP id ffacd0b85a97d-48dbaaefa6emr8361571f8f.36.1791708078270; Sun, 11 Oct 2026 01:41:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/60] openssl: upgrade 3.5.8 -> 3.5.9 Date: Sun, 11 Oct 2026 10:40:00 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247536 From: Peter Marko Release information [1]: OpenSSL 3.5.9 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: * Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782) * Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189) * Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191) * Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772) * Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872) * Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873) * Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875) * Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897) * Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804) * Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805) * Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806) * Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696) * Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784) * Fixed a bug where EVP_DecryptFinal() incorrectly reported a stale success on AES-SIV authentication failure. [1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-358-and-openssl-359-29-sep-2026 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../openssl/{openssl_3.5.8.bb => openssl_3.5.9.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-connectivity/openssl/{openssl_3.5.8.bb => openssl_3.5.9.bb} (99%) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb b/meta/recipes-connectivity/openssl/openssl_3.5.9.bb similarity index 99% rename from meta/recipes-connectivity/openssl/openssl_3.5.8.bb rename to meta/recipes-connectivity/openssl/openssl_3.5.9.bb index 71446e62e31..06e25a61587 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.9.bb @@ -19,7 +19,7 @@ SRC_URI:append:class-nativesdk = " \ file://environment.d-openssl.sh \ " -SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2" +SRC_URI[sha256sum] = "603f5602e2eef00d77fbd429d34dcd5822bb301757a1bc9cdb24c670f1eb859a" inherit lib_package multilib_header multilib_script ptest perlnative manpages MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash" From patchwork Sun Oct 11 08:40:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100331 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 952E5CA9ED9 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23572.1791708080936399438 for ; Sun, 11 Oct 2026 01:41:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=m8/ubSCd; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48b0946c2c2so467102f8f.3 for ; Sun, 11 Oct 2026 01:41:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708079; x=1792312879; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fybJs4nCNdBhTsOkuZObdXHg9eC9TQiMY2Hta8Nq9Xg=; b=m8/ubSCdw16N2l4e0+0xnaidBrBWCxbmfvWZ0akPjWAwa+oYuIoWOLDw0QlSdxmfdY 2PWenqmv0HdoH4fRYirgjz1Xg/VtKfv80Ek8IIme2eUxQwxzNB08e4KEoTfGSHdi2A6t v1uEw7MySdXcyPtMF0DBi9qGz5Wx9jYecjF80= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708079; x=1792312879; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fybJs4nCNdBhTsOkuZObdXHg9eC9TQiMY2Hta8Nq9Xg=; b=MAl8LmhMFWmHpuwWOQRK4ALUSMIY561U89Ghk++gRsx1hgsz4EedSEhVgaYq1KhyzR lc1BVnqab/eR9d/R9r3bwyrmkQxkbjhsuuxL4FcPUIjTtWtS+J/4MsY9fqCoyyr45T2E xGAQeWOn+21syg7aCpxul+LiYCXFWGppueRpAGw6RnMowYl6wNdkji16ejuT6RB+bmIB Fg2MyLPQDLqgC+mbG3Kua01wbkTqTw7oSP8Na+93s/QrHuahwT9k2Sg2JWoiAclvNxjn yghCLPcniEPaq/XdsxJTa3TpKfhPEAPPB7xg0SGuUofHS4PSW2DESpaYAeI8uYEJARWI xFiA== X-Gm-Message-State: AFq9FYKHmtXQD6rhEHS0AbZTLE4TYUz57IBSxJHj7FXAcRTkMVy+BGh4 NMO3NaYyOMikAKb95h+ihrEFlVHtm+J6S7oq5EFWO4c5Zmr2JL0LL9HKWU9qZ9/dc1PWBK95NXe Me/uHj9Q= X-Gm-Gg: AYBFou3Iv4Hz1lod36plnhgZLe3VH5pP/0ViyF+UE55H0zkPqWVF37KlFp8w+SEW9Y5 r6ZtcEHitonPIwt63wUgn+xmJc7+3eeWQ/cClCh4diNyEQvNHgwgullZINknkyVOZqzoEAmSG+G r3ktzEaJ6Bh2q++5uW96eDHFb7GJcaj7lKGGv7nmKu7obWqCNbpaSeSVqTHSzxPlC4VGfs/QNSP piwMWctehPwPDWnrYFD/86HiZhP6VlWd0MdIFrWVgPe4MWJQ2wyzuVELmw0j6En3IurMxm/h4Yr 1jaF6CRHbl4CpoGW/dAQAZ18gA96TYHSB5VxC/YfF5ayxlnmGgt8G2YGaQxeqplRhLT2LLmOaj8 nAjBVZtkRxJgerTETsYyQMcCIbAOJ9BcA3hp86UGJ1J9ZVVEzZSn2iNiriHyqbfU22Qtw0Rc/jX GhvuItqOomq1PEGulZ1MGrCiB7xG7aRDwK3ZfdlU5eNfHtCR1uHiNRYjU6jtJlVvfPit0fqngnt pgDWY32FJRnAttuUjtzt5nDeszBdtueHFBdAX6X4ddNg73WLtPIqOPR+w1fFMU8J0Rt6VsWjA== X-Received: by 2002:a05:6000:481a:b0:48c:4d32:ccf8 with SMTP id ffacd0b85a97d-48dbaade745mr11173112f8f.16.1791708079070; Sun, 11 Oct 2026 01:41:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 28/60] glibc: stable 2.43 branch updates to 9cda6fc96ab Date: Sun, 11 Oct 2026 10:40:01 +0200 Message-ID: <1af34609676b625b7817bf06020e0897206d2f5f.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247537 From: Deepesh Varatharajan Update SRCREV to pull the latest fixes from the upstream release/2.43/master branch, including fixes for the following CVEs: CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 Commits between the old SRCREV (1c9988e5254) and the new SRCREV (9cda6fc96ab): 9cda6fc96a stdlib: Don't call clearenv from __libc_setenv_freemem d6c6dd71c6 resolv: Fix assertion failure on search list truncation [BZ 31026, CVE-2026-8674] 65f2295a98 zic: keep needed last transition to new type (bug 34618) f8f3d451ba nptl: Skip pretty-printer tests without python3 [BZ #34507] d9a8ff5c01 hesiod: use booleans in parser macro calls 1c1f5103a9 hesiod: fix swapped arguments in service parser 049168237f nss_files: use booleans in parser macro calls 0770e8b07c nss_files: fix swapped arguments in service parser 20b3e87176 libio: Add test for fopen with an empty ", ccs=" value [BZ #34574] 72351055c6 libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling 8dad0ee453 alpha: expect test-float32x-float64-div to fail f024355965 alpha: add the denormal trap enable bit to FE_NOMASK_ENV c4dac931ab alpha: Fix stack alignment in makecontext 76115597fe alpha: fix setrlimit compat symbol for negative rlim values besides -1 c29ca5d216 iconvdata: Test case for bug 34556, bug 34568 3ad1bbd8f9 iconvdata: EUC_JISX0213 decoding lacks pending character reset (CVE-2026-80489) 138c43f018 iconvdata: SHIFT_JISX0213 decoding lacks pending character reset (CVE-2026-77117) 713998bf00 stdlib: Fix right-justification in strfmon (bug 34510, CVE-2026-19499) 2a35bab35b posix: Remove unnecessary overflow check in wordexp (BZ 34090) 4964178b4d m68k: remove sysdeps/m68k/m680x0/fpu/w_fmod_compat.c (bug 34559) 0afa34adb0 misc: Fix out-of-bounds array write in tdelete (bug 34506) 7d26579873 malloc: Show hugetlb tunable default in --list-tunables 8017bcfc4d m68k: Fix fmod/fmodf infinite recursion (BZ 34508) a388c4002d posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) bc95068f5f ppc64le: Restore optimized memchr for power10 [BZ #34300] Testing Results: +--------------+--------+--------+------+ | Result | Before | After | Diff | +--------------+--------+--------+------+ | PASS | 6592 | 6598 | +6 | | XPASS | 4 | 4 | 0 | | FAIL | 127 | 125 | -2 | | XFAIL | 16 | 16 | 0 | | UNSUPPORTED | 559 | 559 | 0 | +--------------+--------+--------+------+ Changes in testcases: Before After malloc/tst-malloc-too-large-malloc-check FAIL PASS malloc/tst-malloc-too-large-mcheck FAIL PASS iconvdata/tst-jisx0213-progress(NEW) - PASS libio/tst-fopen-ccs-empty (NEW) - PASS posix/tst-wordexp-append (NEW) - PASS stdlib/tst-strfmon-bug34510 (NEW) - PASS Signed-off-by: Deepesh Varatharajan Signed-off-by: Yoann Congal --- meta/recipes-core/glibc/glibc-version.inc | 2 +- meta/recipes-core/glibc/glibc_2.43.bb | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/meta/recipes-core/glibc/glibc-version.inc b/meta/recipes-core/glibc/glibc-version.inc index cf5a4440956..5f6863df160 100644 --- a/meta/recipes-core/glibc/glibc-version.inc +++ b/meta/recipes-core/glibc/glibc-version.inc @@ -1,6 +1,6 @@ SRCBRANCH ?= "release/2.43/master" PV = "2.43+git" -SRCREV_glibc ?= "1c9988e52540c844928c6d93ff45305adc2c24a0" +SRCREV_glibc ?= "9cda6fc96abd035d9cbe68482138d4a78a51a7d5" SRCREV_localedef ?= "cba02c503d7c853a38ccfb83c57e343ca5ecd7e5" GLIBC_GIT_URI ?= "git://sourceware.org/git/glibc.git;protocol=https" diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 5c21223b55f..56942e86dcd 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -23,6 +23,7 @@ CVE_STATUS_GROUPS += "CVE_STATUS_STABLE_BACKPORTS" CVE_STATUS_STABLE_BACKPORTS = "CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 CVE-2026-4437 CVE-2026-4438 \ CVE-2026-4046 \ CVE-2026-5435 CVE-2026-5450 CVE-2026-5928 CVE-2026-6238 CVE-2026-6791 \ + CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 \ " CVE_STATUS_STABLE_BACKPORTS[status] = "cpe-stable-backport: fix available in used git hash" From patchwork Sun Oct 11 08:40:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100327 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5E80FCA9ED4 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23443.1791708081497145950 for ; Sun, 11 Oct 2026 01:41:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Vec/XnK1; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-4a020e65269so5686745e9.2 for ; Sun, 11 Oct 2026 01:41:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708080; x=1792312880; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FdgPesECK4bbr5VoRuG9us7SakLJBFLJUF63ZYc8plo=; b=Vec/XnK1Adu4v88YpUGV9quBdQ+5bDB7BNEua2S72hA4md40RFwmH894CCoIssFWyI ZndKEHEq82ZjEIctnYaRMI2i2BC/mUjp6IxYaKZy4BpIsQTwmcfBmiipGsp6IkUKPgRG UcFLkvOEMdE8rgLaB9fnoJmk+FLUEYnj3ei3c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708080; x=1792312880; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FdgPesECK4bbr5VoRuG9us7SakLJBFLJUF63ZYc8plo=; b=KiR+Fj+v2a/VghT34TchZoMKKzH/TBxsmGPgzIx3EzdiPLwbmPkVJxenhZ/lYpEFgS X7SOu7ew8eK2HKbxrtKkHSI+rlWcVPo0u9YkY054ps0Y9G0z3gyPXgYHlsst4Dqm3tg9 QCn6QjjeR5BRoFil4DffhCk1gXl1CbexXtB50OdFrEegmnLNV6U8nqgBFBqG4qTyDwdt ukiRyW202WbhEmcrEOhfVZD3ljtm7ZcbhCHk2vIWyl/nbcz2HH2sOJq//1ZXhP/teTH5 4WP37SiMMyp8b6y0ZAEw03xK9zwIfYs606dL3hHX4Q32j40A+btKUudCpWwwpMz3F1Z+ iTPA== X-Gm-Message-State: AFq9FYJq7Er8SxqDFXbFfv8uykeKhr3ar/jQ1CaI8JOGEwrxh5ztpO4x tkCX3m7GAy8N9A742h9hTQcANKw83StCQC5fUl2row/8SK0v345AmW2Fkh6T2wFWH9PiXGvlfRW MLBHtls4= X-Gm-Gg: AYBFou2ngI4zro1Fetw237Ibj2Jgj85Ysy3gT8rC7zQWVqUxgida+SMvGhuFbjdXDkj 97qom9IhYkGv9NYlSGmKD7+sCyUtrft/bIPjmaLpjb9gE7QxlIdQmci6A+LMlGIxQxyjbn1f6ne 9xpzZWoJbIvG/fKGyitmc8Uw5clh/VANehSQOGWGoJ66Njf98B65/NAtkkQI9XQt/t2BSTPUuNh 2y41n+GFoP9BcaRGF/HpD/iG+mHdss7OANVQ+n3i99gPWKykyKQHuRNQnDvSyuSXihhsnNX34Bl 0hORlDhJHS/4QTtLOCSbMuuq4JGcaoHfcCjEb1T4coHj8zh8Fb3KIZIOCBU+hojbPSZOYjthliU NITi0MgBfeyBoCSsFTbxKQSQTnOZbDc13xrdKmPkMHau4G33pDkyGOhSp/MwUtZNZ/jG3VwqHCY 8cmQLFY5IzV3k64TZKFD2M/ZumY0UChtKJqo2z/PP4DpaqfOVQIwMSEMv3aUaebv3MIUsVttTSV iNc2sYK4yw2uwQDZLM6bdhEbiVlWu7wUFe5FrAiuQgHwvlo9zKaceRZ4FrUjPKmaZ73V8iCTA== X-Received: by 2002:a05:600c:3541:b0:4a0:2488:71cc with SMTP id 5b1f17b1804b1-4a18e4e9ee8mr108838965e9.32.1791708079599; Sun, 11 Oct 2026 01:41:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 29/60] glibc: stable 2.43 branch updates to 562cd7badd Date: Sun, 11 Oct 2026 10:40:02 +0200 Message-ID: <98ff1c9d3e272a1773775211b0d7dc4c20b28f8b.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247538 From: Harish Sadineni Update SRCREV to pull the latest fixes from the upstream release/2.43/master branch, including fixes for the following CVEs: CVE-2026-89092 CVE-2026-97399 Commits between the old SRCREV (9cda6fc96ab) and the new SRCREV (562cd7badd): 562cd7badd powerpc: Fix one byte overread in strncasecmp (bug 34683, CVE-2026-97399) 533e1c955c elf: Open the normalized $ORIGIN rpath in AT_SECURE programs (BZ 34360) 8305f5b8fa realloc: Fix mmap non-mremap reallocation case [BZ #34697] e51efbc44f CVE-2026-89092: nscd: replace alloca with malloc in aicache, hstcache Testing Results: +--------------+--------+--------+------+ | Result | Before | After | Diff | +--------------+--------+--------+------+ | PASS | 6601 | 6601 | +0 | | XPASS | 4 | 4 | 0 | | FAIL | 142 | 143 | +1 | | XFAIL | 16 | 16 | 0 | | UNSUPPORTED | 559 | 560 | +1 | +--------------+--------+--------+------+ Changes in testcases: Before After elf/tst-dl-path-normalize --- PASS elf/tst-origin-secure --- UNSUPPORTED malloc/tst-malloc-too-large-malloc-check PASS FAIL Signed-off-by: Harish Sadineni Signed-off-by: Yoann Congal [YC: CVE-2026-19542 was fixed before this patch in the 2.43 branch ] --- meta/recipes-core/glibc/glibc-version.inc | 2 +- meta/recipes-core/glibc/glibc_2.43.bb | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/meta/recipes-core/glibc/glibc-version.inc b/meta/recipes-core/glibc/glibc-version.inc index 5f6863df160..e8e6bb665ae 100644 --- a/meta/recipes-core/glibc/glibc-version.inc +++ b/meta/recipes-core/glibc/glibc-version.inc @@ -1,6 +1,6 @@ SRCBRANCH ?= "release/2.43/master" PV = "2.43+git" -SRCREV_glibc ?= "9cda6fc96abd035d9cbe68482138d4a78a51a7d5" +SRCREV_glibc ?= "562cd7badd3f9edd74b68316439f910f6f7c4c1f" SRCREV_localedef ?= "cba02c503d7c853a38ccfb83c57e343ca5ecd7e5" GLIBC_GIT_URI ?= "git://sourceware.org/git/glibc.git;protocol=https" diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 56942e86dcd..3d642e6738d 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -24,6 +24,7 @@ CVE_STATUS_STABLE_BACKPORTS = "CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 CVE-20 CVE-2026-4046 \ CVE-2026-5435 CVE-2026-5450 CVE-2026-5928 CVE-2026-6238 CVE-2026-6791 \ CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 \ + CVE-2026-89092 CVE-2026-97399 CVE-2026-19542 \ " CVE_STATUS_STABLE_BACKPORTS[status] = "cpe-stable-backport: fix available in used git hash" From patchwork Sun Oct 11 08:40:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100329 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52486CA9ED3 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23444.1791708081869457368 for ; Sun, 11 Oct 2026 01:41:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=3G52hj+q; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-4a022fee0caso6665645e9.1 for ; Sun, 11 Oct 2026 01:41:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708080; x=1792312880; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jbFQqZPH3x6/TWPcEU592xyn33AG8u1hNjuuqEj85D0=; b=3G52hj+qpzDdZcbiG3NYPhyJj12eF3xsSwoc9p7McNGPCu7Gy8yv2F1XT/fRd4kJ20 GlQ16P+8VYAio6AqTs37VwgdaPB8hDd3hm+vAv1LcNlnOVJ3qhO4UfUjgVECV1xTuTZz 6T2mkevvD4lxr/paZLEKXE2rhUBm4OlIIHjSw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708080; x=1792312880; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jbFQqZPH3x6/TWPcEU592xyn33AG8u1hNjuuqEj85D0=; b=0uz0d/Y5Z7blt4aj0TRjmeqXrHwyhnnDHDXC5Xs7JINRHGX3NBxz9KYGhpzV+j/yHo INRPoRnhvYTW1iGa66Ru3BeXNPqXNjkG2lrOPBZTosAPkvaJ0FX2k5AKFioCoea2S9nH 3D0BiHKtQRehFYR5oOjqOjsW6TlhLta+0vUUWR39c4cQw+J4peejohK8rcYfEbfkbLzM BpEKIhPjMgfy53+KALz9JcGGh2QLR+liEGz1zRYhODDgQlxmIzbn0X/4mviz/TwpZovV G5v0iZdJ/r9mptJPqp6xne/Kpr2VT4f8dLv8Rv3QjbOBU0WlpujUlTam4/HVUO5ETY/2 aDtQ== X-Gm-Message-State: AFq9FYIzV+tl/gKXteEwuweluew+NxTmrrsOB2o3uThx1/PxbirAZExv r9HGxDPwzNwV0ObH4jVSt8KkyzMi+eZcFX8bZuzBssQxX0nm0gUzB+Ap8+vGQtSuZVktg066adn 2gWib/fg= X-Gm-Gg: AYBFou1wgLLx9GT+ByzK1qDwzCwW4wcTI/arqrmRQCOHTNewXc2UF0CwJJ0PcOTGtLH SDY1MStf0O1bNwpZpTbZw0vi9Gi+S+ePdvrsPf+5Ak1SN/SioSrEixcd+muTnpZwQQhrayk7QOG d2lzTXlf05OeUfv3xe5aTPPbjNJt1c8MxEDqYqBUQ4BUQtXGf+5g5jcXvNB3ZaWUDzbVLxVErtv JRiaovd0zX2349IE2+9DuGZjeS4fgp5QXn5H6VG3PH3RyoMWJG8iaHuufVl5kSPojQepVRjAtz3 Fz0/kvLJkF2kD251cF4lhZGcfOhP7WXM38WH0ellpttxQGgJu1g1KP3VR+GvHiPKFHOl8/Sye4Y iL2FUlmttcWLySq+tR5qHOSCoH3w6KGtT8H3Gw1XsGogSMWCazUH0a9f0t+Hv6of1xscNoKH1+c GwCFiRvZ96Pq50Kh71ud1d+97cVotqc+fMZ0PpLy5aI18jljKnTCS9FIf0rk0ijQvmr2C/77SZE kKEeYk6olFi8b420Cu3LfJX8vWjOfPYJ9PU2CpLQIddJkjcaRVXjX2btSkfI3Uiclke00IVIw== X-Received: by 2002:a5d:5f8f:0:b0:48b:42c:8b44 with SMTP id ffacd0b85a97d-48dbaaee9bcmr11079876f8f.32.1791708080029; Sun, 11 Oct 2026 01:41:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 30/60] glibc: set status for CVE-2026-86805 and CVE-2026-95818 Date: Sun, 11 Oct 2026 10:40:03 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247539 From: Peter Marko These CVEs are fixed in current hash with commit [1]. It is commit equivalent to [2] mentioned in [3] and [4]. [1] https://sourceware.org/git/?p=glibc.git;a=commit;h=533e1c955c7bb9b761749751ec743b46c6bd2238 [2] https://sourceware.org/git/?p=glibc.git;a=commit;h=ed0c137b97eb940b4b64981e84ed806d3276edd9 [3] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022 [4] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0023 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-core/glibc/glibc_2.43.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 3d642e6738d..c962171cf3a 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -24,7 +24,7 @@ CVE_STATUS_STABLE_BACKPORTS = "CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 CVE-20 CVE-2026-4046 \ CVE-2026-5435 CVE-2026-5450 CVE-2026-5928 CVE-2026-6238 CVE-2026-6791 \ CVE-2026-6368 CVE-2026-19499 CVE-2026-77117 CVE-2026-80489 CVE-2026-18374 CVE-2026-8674 \ - CVE-2026-89092 CVE-2026-97399 CVE-2026-19542 \ + CVE-2026-89092 CVE-2026-97399 CVE-2026-19542 CVE-2026-86805 CVE-2026-95818 \ " CVE_STATUS_STABLE_BACKPORTS[status] = "cpe-stable-backport: fix available in used git hash" From patchwork Sun Oct 11 08:40:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100330 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 427C4CA9ED2 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23445.1791708082665486611 for ; Sun, 11 Oct 2026 01:41:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eKXrqe4V; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4a022fee0caso6665725e9.1 for ; Sun, 11 Oct 2026 01:41:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708081; x=1792312881; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VAJScOss0VUVQMgPsM8KCuFQ668tr4/nE6Kh0T1bJjA=; b=eKXrqe4VVcYEuIA+8llNh/yWOTm4KI1zyP1jeKEOckZ0SM512JN5JZjMi/oLHnonUA LBbDj1dQkWd8WPNLyab7Hf3d3/GLNnU6oxr7jgfaXQDFfroHmuBTasBX+XFUANazhSjF m8p3BuxtA3rPY/zv582cHGlWjKfQgapHff1Yk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708081; x=1792312881; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VAJScOss0VUVQMgPsM8KCuFQ668tr4/nE6Kh0T1bJjA=; b=LaSrqEzAbEUPfyMqwX2OGKGotiRXEawUuKXhfJAkSDq/90aB66hSFQlyvQgaZ052LE Hi9SkfiM+kkUS+7HCZWTCxr4TxPMsF4/JvQ1WS9Xw+MCZ6qDKWCYNGaCSHBU4yoDUsQA t00bT+Lp9FBAE1SATdYIkF3ketQi6FzX8eBj7t6lhfo3/8EIaGZHQiz71bUWbLIVZOxt mhNAHjL62Ulr3UOqMB+0wG9cBMNEUM1EvCjDw/t0iwVSrtk6IVWgjPE1iZAbwZ4DdQXi pEnnzATOT2+MZFftAd4m8UFc88cdomgpSwX/OpCEBPXxKMh5e6GP7pIt766hA9R6BRLm VjAw== X-Gm-Message-State: AFq9FYJqwjY1v9XYSPZDspQDabVv/ATeRnoKI/ZK2J3BAguVmpfWhJ7o P0f5EDpv8KTEQi6+yVyao3Ul/BkHkol10kJ3Yydtti07HPSvyZqLGXwi7UIT7UMjjPntjoM5cZC QXW/noxI= X-Gm-Gg: AYBFou2ewGli1xmJC2cYZptAlNaGdiFi3uFTcHRtUsmMBu5oIgGXXxCahrhu3XCRL/E yh9TtkbPa1nYDrODo70LimqpJ4Ieze4nzffMXYkhld922+CGnjPnUg9S4OObqVAlVM4Z3fZ+4Dn y1O09OutqxVxvIEnPTQVFTJRuYOAXvq4r2BZhVRNfz8fyHJ2hJHbJKS3sZsAGK3mqHJ/ocpFQva 2tDhP/Si5NXH5C+95qMweD2Hdxms8Q+n6DfwgyA1nKmJaasCDPWzajvDgVPuNy/6B51utggS6rS waLzOAnSdscyuaGnZUuj0RKjWzrQsJEu4fNCoiAoxbQfyDlWIIgHeBD6XsaELgvDrbVPznKpV9r URypt7gtw+Z6S5/KfGxLuWKGHkz4q1jDp4nOBDBScx0ef+RUWooY9pgMrGdCWeWpRNcOpdarg03 UqP4s8xTrg/rAJHAmnwdtwIv3LfW01doENj7FvhIVdAmiTc3xqUTeNaSYltow/E+xGaQRDkEH6K +AUHVbDpthUFo4sZwB1Pk8cYr/rhkb/QetKWKSkxxftcufDi1oNlMlUQaC8VnMq2MT7oecd7A== X-Received: by 2002:a05:600c:8718:b0:4a1:7259:349e with SMTP id 5b1f17b1804b1-4a18e4e0a33mr120178435e9.27.1791708080538; Sun, 11 Oct 2026 01:41:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 31/60] devtool: standard: fix update-recipe/finish --initial-rev override Date: Sun, 11 Oct 2026 10:40:04 +0200 Message-ID: <81a3c5764376bc36e9f0c22a43869b5fdd41efc5.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247540 From: Babanpreet Singh Since 900129cbdf ("devtool: add support for git submodules") the --initial-rev option of update-recipe and finish has been broken: the parse loop in _get_patchset_revs() deliberately skips the recorded "# initial_rev ." entry from the workspace bbappend when an override is passed, but the override value itself is never inserted into the initial_revs dict. For a recipe without submodules the dict therefore ends up empty and update-recipe/finish fails in patch mode with: ERROR: Unable to find initial revision - please specify it with --initial-rev i.e. passing --initial-rev produces the very error message that instructs the user to pass --initial-rev. Before 900129cbdf the passed value simply took precedence over the one recorded in the bbappend. Seed initial_revs with the override before parsing so the option behaves as documented again; recorded values are still used for submodules and for the main repo when no override is given. AI-Generated: Uses Claude (claude-fable-5) Signed-off-by: Babanpreet Singh Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 62abb60b899e63ea6db5c745f4b1b6af0d4b40f1) Signed-off-by: Yoann Congal --- scripts/lib/devtool/standard.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/scripts/lib/devtool/standard.py b/scripts/lib/devtool/standard.py index 42fb13872d3..e2f5c28f8b6 100644 --- a/scripts/lib/devtool/standard.py +++ b/scripts/lib/devtool/standard.py @@ -1200,6 +1200,10 @@ def _get_patchset_revs(srctree, recipe_path, initial_rev=None, force_patch_refre commits = {} patches = [] initial_revs = {} + if initial_rev: + # A user-specified override applies to the main repo ("."); the + # parse loop below leaves it in place of the recorded value + initial_revs["."] = initial_rev with open(recipe_path, 'r') as f: for line in f: pattern = r'^#\s.*\s(.*):\s([0-9a-fA-F]+)$' From patchwork Sun Oct 11 08:40:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100325 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6DF22CA9ED6 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23447.1791708083315965392 for ; Sun, 11 Oct 2026 01:41:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=24p2Kv5I; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-48c4d870d54so487159f8f.2 for ; Sun, 11 Oct 2026 01:41:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708081; x=1792312881; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JcMASnky9rXchH/awBt0pVIQOymnxJBTmPQUsv3Tc64=; b=24p2Kv5IT5KPowX0+sFKBQ71j1LxsrZFF7/wKMxfCUXf5jqy+nwh5hu0/RWywirbl2 QetxA5+VcdmaQJp8WiGNOtFrqh9DiYIp7ZlDzb6jrbqY9Xo93PgBJRJd/5nkTxdZeY31 rSyPdZ6p2HlXT2spDOG8KOuGGdD5Skf1hsFNQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708081; x=1792312881; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JcMASnky9rXchH/awBt0pVIQOymnxJBTmPQUsv3Tc64=; b=f9DhdhvKMVNdNTBHgzayLMZeTEBSrHSh0Fq6elD6MG7/nB0FzHzfuOxKRDBEUAxJGh TZmymCpOJDMuhKvc1Ara0cDR5x7Fed+COPdSvaeHLc8FTEJCPJ2h9O8lSiEMP55BHg4B xIKq3nfXW0v897k/P+CxkP2Qc90Xrw1H8f71Ih57QXf7M/Bw5uGdnZlN8vDDd4UiLVUi 3Ejbm2EIVC4GjTdiPsFp19uTvV6CW5pp6gpMs37Q4009gOoxln5Lj2E67dXjRemQQHUV JOrdFrfru1yn0ncxh6ADdWwo4/t/wTCrWaoNrHqnyX6rC4IKMaO7j8pXIjWQUyX0r3Ox t2fw== X-Gm-Message-State: AFq9FYJOyorydNqBh/F8XwXKXvojbDCBqHtsdesLwadcc8qpZuZc2a3+ VZOy/ofEkd5aM0Bn2xLP9AdwQHqqKKwD2KcRda2V+X/1nNQqgYmOwebeZ5O1hJ9+seHKndSLO9x wYc0YVe8= X-Gm-Gg: AYBFou1a+lb7kgmIszLbt34tvPYT+Je+9Tim5Ko2s4CCljCcy7jBh0OyFqXG4n1Fo1V y0Cqb/st+yo/mpdq/IirXxDPo2ixykGurtUUPmWm7Dw0ycp4/6r3J3dN4nZerLjteRFxY2K3Rj2 KRzbQvQewDLnWQ7fB2ZPjXRR53mfydIZytNHp7hJGEe6fMuWq8XeTGx+AWaB6n4/up/EYeca4Gd VQi1+QIPUgahC5xdQt14aNk1YaC+RMuxCDjR1lKsPWjmMH0zb0dpgt1QbVZNMb44W6kJgIgzch+ gg7bIZBgNhrlKpUcMCpIigvngknqhfeqqp7oOsrVvENEHjXIqPNJQ3DI7JAyxt4um097RAkKjPT xDtJMfAS6wrHGq16E4w/G0QCG0KcasbonkELe3QTDBRgvRc1gh9tkKRtf687Nk2myAV6t3+HQCE unbX7sxHk7MvhDsrNywPs3Ug8fJsjJ3WH7oVvkRiHmlKaGkHwJGnH1ev9tCao63rE4EvgoFR9gp APBUgDb/F+OKDPgyndBXFqEz9RJXUWbtCIOtrQxeSEVEc0ToFBLfCfnLpFwo62VFqVyLfphpg== X-Received: by 2002:a05:6000:4541:b0:48c:7161:43e3 with SMTP id ffacd0b85a97d-48dbacfa612mr6901256f8f.54.1791708081028; Sun, 11 Oct 2026 01:41:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 32/60] oeqa/selftest/devtool: cover update-recipe --initial-rev Date: Sun, 11 Oct 2026 10:40:05 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247541 From: Babanpreet Singh The --initial-rev option had no selftest coverage, which let the regression fixed by the previous commit go unnoticed since 2023. Extend test_devtool_update_recipe to run update-recipe twice more with --initial-rev: once with the recorded initial revision, which must produce the same result as not passing the option, and once with a revision in the middle of the local commits, which must export only the commits after it. Without the fix in the previous commit, the first --initial-rev invocation fails with "Unable to find initial revision - please specify it with --initial-rev". AI-Generated: Uses Claude (claude-fable-5) Signed-off-by: Babanpreet Singh Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 171af3b2915dd076c8d1b205ff75eac1ebd5a586) Signed-off-by: Yoann Congal --- meta/lib/oeqa/selftest/cases/devtool.py | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/meta/lib/oeqa/selftest/cases/devtool.py b/meta/lib/oeqa/selftest/cases/devtool.py index 5ed69aee1b1..b485d752e7b 100644 --- a/meta/lib/oeqa/selftest/cases/devtool.py +++ b/meta/lib/oeqa/selftest/cases/devtool.py @@ -1219,6 +1219,28 @@ class DevtoolUpdateTests(DevtoolBase): self._check_repo_status(os.path.dirname(recipefile), expected_status) result = runCmd(cleanup_cmd) self._check_repo_status(os.path.dirname(recipefile), []) + # Now try the same passing --initial-rev: the recorded initial + # revision must give the same result as not passing the option, and a + # later revision must export only the commits after it + result = runCmd('git rev-parse devtool-base', cwd=tempdir) + initial_rev = result.output.strip() + result = runCmd('devtool update-recipe --initial-rev %s %s' % (initial_rev, testrecipe)) + result = runCmd('git add minicom', cwd=os.path.dirname(recipefile)) + expected_status = [(' M', '.*/%s$' % os.path.basename(recipefile)), + ('A ', '.*/0001-Change-the-README.patch$'), + ('A ', '.*/0002-Add-a-new-file.patch$')] + self._check_repo_status(os.path.dirname(recipefile), expected_status) + result = runCmd(cleanup_cmd) + self._check_repo_status(os.path.dirname(recipefile), []) + result = runCmd('git rev-parse HEAD~1', cwd=tempdir) + midpoint_rev = result.output.strip() + result = runCmd('devtool update-recipe --initial-rev %s %s' % (midpoint_rev, testrecipe)) + result = runCmd('git add minicom', cwd=os.path.dirname(recipefile)) + expected_status = [(' M', '.*/%s$' % os.path.basename(recipefile)), + ('A ', '.*/0001-Add-a-new-file.patch$')] + self._check_repo_status(os.path.dirname(recipefile), expected_status) + result = runCmd(cleanup_cmd) + self._check_repo_status(os.path.dirname(recipefile), []) def test_devtool_update_recipe_git(self): # Check preconditions From patchwork Sun Oct 11 08:40:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100323 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1CC4DCA9ECF for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23448.1791708084133088910 for ; Sun, 11 Oct 2026 01:41:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OvKpVNiZ; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-486e8faff03so389007f8f.1 for ; Sun, 11 Oct 2026 01:41:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708082; x=1792312882; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BDdRS7kCUIBhCw9RXTcCVznzGMBUlGT9bbkVieSzNsE=; b=OvKpVNiZaCfOptNKYq5QGVnMU6hIXUj9bCPxYpUEar6ZErY6Q/eReyqAgMl3pLFoM9 4iF5Pnw1wik7lwdoV/wj+8rH3VoyVywY//jpMK9eiF5tFpc0IvIwNyjMpHqI/guJ6BPc ZDf0tZ34b3k+dV9lrZTrXUaL25+gO0pGZrl3U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708082; x=1792312882; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=BDdRS7kCUIBhCw9RXTcCVznzGMBUlGT9bbkVieSzNsE=; b=Bq0Pbp+cdQoqYT/R7APpO9I6huDuhAH2UHRQhRVwm483oI10uuMLhabinsqSjy2OWW c6Y/ZaM+nrV4Xux4MokuaxHP9xI6VAKZuVwCNjLn1yT9j0YoPgSoGhzc9AFv31PgoTES 44hqpnrGuCuGx3DOB+//aLIgTcxKFYSdya51Ywuve8lYspM92OW7HJxAh1Em5xgVHJ0U Duu/n76SkImuM03VMbpqJ/jND2b6pT/pSfHFl5jo+MfdB/AOoZ/k1wegFCsGKCEpM19f Pu3UQRLM9gOdSufGB5i11J1Mus6OvGwqODg0nnAqX/3z0doP+plQVaDZ7N0MliRGBHwL jrjg== X-Gm-Message-State: AFq9FYLDeQo/1U/CbVD3rdvAqSLVlHHUfTLg5h2QPxNJeqWLNdNuDzN9 1/7HJmFwFc865BvGBa8+/F3HD16qbCtd3uvmSlcgJ0uL2pDEdJQEJSOM4xXUN8yRV5uIZ3UdiVR zdaoubwo= X-Gm-Gg: AYBFou1OwqaDzEKILZOwW56ZNNytBbJ+Q+RvGUfUBYSjY9e2Qg4OCb2h0A+0qYwBsk1 3IbXnA/wcqrDMXZQgHDBcT8hnhMOGIZJwCK5Gm837FEOF1QoTMNL8G6Vx+RHoYVvfnLrhtpzo+p rwZSZi7eFKjpMjaqvvXpaAbXgIqsrVquWfSlXw6J7piFkZnFHtLoNx76NI49ufn/NsgyPUnlLye FkgZBccbiJvX3EF1xs8gsxXyJhtv7PYlD9UVkdXLaqEA/ik9ek394YXD+hpPDMDu2Vq4Ad4ba5X RbpL+kWRRQDI1uZi5KOsRp0BsIUA+6Jl72jfJlGeBDiE5BNClY2kIVZy9DVwwDH1+LDIxx4DqT5 /ParTsA7t44dkwXSwgQsnoFA57gf+0MJeeaqxKJ6e+lWlb4AUCDl05VunkYWq0/fqt2AgVIdAwN dVfUnvSfBR155VBbMSRalLWHg96vt+SdqvpAMTWpllK6AEqIVSrCa9x+jDjP7kfCw+QRloUHW7q f4RlgwEd1j85+23l0iV1bpciZJp4y7Bu5lcsKn2pP5AKbS/4YJFzZvZOMYiYJEgAfK8kqeIrg== X-Received: by 2002:a05:6000:454f:b0:48c:69bd:e971 with SMTP id ffacd0b85a97d-48dbaadb133mr7611130f8f.16.1791708082387; Sun, 11 Oct 2026 01:41:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 33/60] barebox: upgrade 2026.04.0 -> 2026.04.2 Date: Sun, 11 Oct 2026 10:40:06 +0200 Message-ID: <2d1c214b939574f131f6ae728951b6d1fda5bf07.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247542 From: Lucas Stach Bump to the latest stable release, which includes a fix for a FIT image verification bypass, see: https://github.com/barebox/barebox/security/advisories/GHSA-jhvm-7xq8-rvgm Release: https://github.com/barebox/barebox/releases/tag/v2026.04.2 Signed-off-by: Lucas Stach Signed-off-by: Yoann Congal --- meta/recipes-bsp/barebox/barebox-common.inc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-bsp/barebox/barebox-common.inc b/meta/recipes-bsp/barebox/barebox-common.inc index f736ca68e02..db7fb25e264 100644 --- a/meta/recipes-bsp/barebox/barebox-common.inc +++ b/meta/recipes-bsp/barebox/barebox-common.inc @@ -3,6 +3,6 @@ SECTION = "bootloaders" LIC_FILES_CHKSUM = "file://COPYING;md5=f5125d13e000b9ca1f0d3364286c4192" -PV = "2026.04.0" +PV = "2026.04.2" SRC_URI = "https://barebox.org/download/barebox-${PV}.tar.bz2" -SRC_URI[sha256sum] = "07fd3e3440c23e27d0094432f67827887fcc0e37d5fe24dc257c39b97c4294a0" +SRC_URI[sha256sum] = "aa575d3ca4e7a8abe6b9796d0ff1d1ace43f86e34c627cc055ddb0a7ebd9dbe2" From patchwork Sun Oct 11 08:40:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100324 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0A893CA9ED0 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23573.1791708084677141629 for ; Sun, 11 Oct 2026 01:41:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mCEnE59J; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48c45111bebso504949f8f.0 for ; Sun, 11 Oct 2026 01:41:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708083; x=1792312883; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xaVOYYJnet0FXo0a8dHgLWS6KaTeqx+rT/yOXsv3fgE=; b=mCEnE59JWMn3GBS9orlunH0XxG/+VfCJbjRFSRtvThCYVujzsPNRK8ZnId/wFl0y8M /0k/qNJvskM/3pT1FnydXQJlyWfLCLOW7KllmBGYHCnmxeZ8J3+a1vt74+4OxgtDkgGM n+PL4C0NhZ/UE+Foo9SQKUfS4TES2ouNv1LNU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708083; x=1792312883; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xaVOYYJnet0FXo0a8dHgLWS6KaTeqx+rT/yOXsv3fgE=; b=WHQFCJiew13lKNrGwOsf7v93v8vsHNehZqwJdY9UP88ylZJGi0DOzpka1TKzgxGmCN mCu5jB+oxZ/XwEZbuYlwFP6ZnvH8q4RnY/M3/0dVyTpgaox+ykCWBlFLK3s/X2Uw+dVN 10/dHCB31Wac1WLYJOyINRZ0eNe7P5flUQtdTvx8DEZjKssoTgY5GnGR60Vg0gAU0X69 aReF8dHbd4zyfTSnSTl3EGpaHXSX3QXR1tjTIqAxOuAfLF48pFSR8KQZHiq5nK4CVhyU Z4pyNKAH6qPazVlFv8z8YIqDtiSBOvBSh9i22xturz1fg0KrhJzHWYXsLe2+MrEYkX7u 2ulw== X-Gm-Message-State: AFq9FYK+2/d0QOmYLsgbguhDNX3v6Cc/RZLL8KYTgNNGvI4IohGXFlIh wxF1/pqXyXvGPr+ohEPkIxvyWcrmerIh+ZFWO3vE0aFmjm+T73m6hie39cVVDt4LBEjM3mtU2xp pFs3SURY= X-Gm-Gg: AYBFou3sDqMRIFu+6+YatMhRFx9rfpf0PE0gvRp+yMOgLoF8059ZDw9P6VuiOkgf4bM NyhGVViB98uAvp7YH4AqULixbB2SR9ItnK7S4P5GrXCLHi2qxB8pryj1WTjRFyBU177tzr5p68T vHjasQNdXC30ERTbxOdVdWhAbKOljSG6bEBmLo4xC8xBKDP3GOLbzztnKIp53NeWAUoxgXEy441 1y5oe/MH1I4HZ6QikPjRSaB8lVlFSVeAlgK+qeQMWhyZTg1Mar+kdDGy7j3UctvYjSqTZNqBYLr uTRwffB9hzUrTbIJoPxe1kDtZXunTuYCWd1Hj+jpOYVIT5eFpngYI5IPZM/vOxakxhAQ90wEArN S2Wjga+m7hz4vFl39SHq8OgFAq6SwaLHHcaPMjxzvNjMiNVHpHutnoFGUwTHLh+I8v8XIERSeue sYrQf5qpzFkAnDtuTb8to6oaxV+8FygCK80HSrTQD5zwuZfioY290uP4xjdVzP++MwG3+yJLJXK rqloCLDWusQNBbc9pg+Z2KklD2pxHJTEnXDpjFNVDE5fzubsiXePzAhR1xRncnfM0sKBE7E8g== X-Received: by 2002:a05:600c:698d:b0:4a1:98ed:7a79 with SMTP id 5b1f17b1804b1-4a198ed7aecmr29123635e9.8.1791708082943; Sun, 11 Oct 2026 01:41:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 34/60] python3-click: depend on python3-shell for shlex Date: Sun, 11 Oct 2026 10:40:07 +0200 Message-ID: <39904a443d351da342109c6be23e77286e1949f0.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247543 From: Darsh Kelaiya Click 8.3.3 imports shlex when loading _termui_impl. OE packages shlex.py in python3-shell, so add it to the main package's runtime dependencies. Confirmed module ownership in python3-manifest.json. Signed-off-by: Darsh Kelaiya Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 8dded0894fdb2c17ab8f8cb2f13f9f95638d493e) Signed-off-by: Yoann Congal [YC: updated Click version to match wrynose's ] --- meta/recipes-devtools/python/python3-click_8.3.3.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-click_8.3.3.bb b/meta/recipes-devtools/python/python3-click_8.3.3.bb index 9e80f8aff0f..44612cb8f3e 100644 --- a/meta/recipes-devtools/python/python3-click_8.3.3.bb +++ b/meta/recipes-devtools/python/python3-click_8.3.3.bb @@ -30,6 +30,7 @@ CLEANBROKEN = "1" RDEPENDS:${PN} += "\ python3-io \ python3-threading \ + python3-shell \ " RDEPENDS:${PN}-ptest += "coreutils less" From patchwork Sun Oct 11 08:40:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100333 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 59879CA9ED5 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23575.1791708086230105189 for ; Sun, 11 Oct 2026 01:41:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=MYPVNIjJ; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48c411d6615so542384f8f.3 for ; Sun, 11 Oct 2026 01:41:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708084; x=1792312884; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NDYofPWX1be+c+Np2uLmsO1MBzsjZ5MH/4ybTucAgko=; b=MYPVNIjJ7YveqaXObPGTwlDHrfPfF1O2WfUY4w0HxZKGS2hQS+gdFoVNMv2BqPUXTm IoAfms7Xr+sBUQY52quLwduhROaTcAD1Qhh0NYl2yLp87kdPf3pgSPNFfxz68u45l2l8 kWjIButUuC6dnxNfamvrNG2XOOWtBsN5HVKy0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708084; x=1792312884; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NDYofPWX1be+c+Np2uLmsO1MBzsjZ5MH/4ybTucAgko=; b=mXI8lJk2irDAm1AiuEjiEJFxf8Subx7FDfudvsffNKd6X+zJVJg1vUFBygWpm/HbI2 vjGYr7KuIJDQ+r1Zcbb3jAJKV/dH0CRAzHgkT+Ldd5JAGy9XhX1CppxMeRcUrC53c5q4 qEdPPEXVxmMw08io53zxVwtRT9xRky5mmpwruGOyWmPec1Mo5aX/iBg8QDG5Br+o42RR qQ+izot0XjQo0y15xmD50hRSVTmbZkqyH+NKi3EuZwSNM6GYKRusOHIQ0ib7ccv4/cwT JezyI+d2r5I+ub9Yr30b5CDzgfSg8VNrBHvqGcA2XLxMTtIgFCnLCjag0VTVk5Va2a7O L59w== X-Gm-Message-State: AFq9FYI1NKcZv2H7V1fJk/614Gkrwx2/nvmO0utSIGAMQAwvwHPBA6KZ hB3i5hGiC456O3XDH47HAoSYtGbBEfvbswnNkXBNHVRJo/U2K7GL2qiuY/GMny0wyb8uCMxcfuy 8Eu6iFoU= X-Gm-Gg: AYBFou2sIp8TwXZZT4KChu8Dbc7bgGS1Bx3ddl4aY4V8l5fU6g3OX/HN//v0q35GrHH Y6qVXn/0F/anS0E4TV4AxDPdJAfOeo4CKBOUfvxYAqe9ZI9pWVqt2UNG48HHDVpV8u7628irZeX 0FwAbzXvNgp8EJG5s620Pa2wsDzkbZ2yoWd+H5X4BLCIyvcK4lBqEgzcvNylh7CWLw0HC5fvaGo 8IPNDa0H8QA70E+i7Z5sJIdGALSE72/ac2e0lOvt4wQDCeNARk+bWC455YHc2AZ4MkF3NpCf6KW u90OASLhY6xUDK1SsBKf0X6EelrneOZuqjLYBDpaWiZoUht8424UXfm96uCDw0uZeoC2boy8ZOX 7yt4W4YHHtzM8cb/4zE2+Dl0NCE3hbWzGmMW1uEdAPYEaWKFZ5x9wKdl6809/++t282cW2g+J4R N+LuB9a2SxOswKlpxCBVsGa8zWL3Gad07gGIFPIRTEZgEOEn2rqvWhuK75HedUDLLzDKTdoK/K6 p/qIMiJ735/8gw227x4lml941uP6k/E3UiI/OIC1lVoEghZ7ZXfWyKfeV2OTnP9yqRnlAxMLw== X-Received: by 2002:adf:e190:0:b0:48d:bfd5:79c with SMTP id ffacd0b85a97d-48dbfd507e6mr10824933f8f.42.1791708083640; Sun, 11 Oct 2026 01:41:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 35/60] libpng: upgrade 1.6.56 -> 1.6.58 Date: Sun, 11 Oct 2026 10:40:08 +0200 Message-ID: <0f0a480b7068ff8f567c8814d4f0a64888a63e56.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247545 From: Peter Marko Solves CVE-2026-34757 (in 1.6.57, as described in CVE description). Solves also regression of CVE-2026-33416 (in 1.56.58). Explicit CVE_STATUS is needed to remove it from open CVE list. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: 31725b7411be75c124385b7fdc778eda2cfe9f69) This also removes CVE patch which was added on Wrynose branch meanwhile and is included in this release. Also resolves conflict in CVE_STATUS added in opposite order. Release notes: * https://github.com/pnggroup/libpng/blob/v1.6.57/CHANGES#L6371 * https://github.com/pnggroup/libpng/blob/v1.6.58/CHANGES#L6382 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpng/files/CVE-2026-34757_p1.patch | 518 ------------------ .../libpng/files/CVE-2026-34757_p2.patch | 481 ---------------- .../{libpng_1.6.56.bb => libpng_1.6.58.bb} | 7 +- 3 files changed, 3 insertions(+), 1003 deletions(-) delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch rename meta/recipes-multimedia/libpng/{libpng_1.6.56.bb => libpng_1.6.58.bb} (94%) diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch deleted file mode 100644 index 7b5ebb18b7e..00000000000 --- a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch +++ /dev/null @@ -1,518 +0,0 @@ -From e621c40a46aa748608d5392f6a5c0278f77573d3 Mon Sep 17 00:00:00 2001 -From: Cosmin Truta -Date: Mon, 30 Mar 2026 17:35:30 +0300 -Subject: [PATCH] fix: Handle self-referencing pointers in getter-to-setter - aliasing - -Apply a robustness fix for a caller-side API usage pattern involving -the getters and the setters for PLTE, tRNS, and hIST. - -Passing a pointer returned by the PLTE, tRNS, or hIST getters back -into the corresponding setters used to cause the setters to read from -a stale pointer. The fix consists in snapshotting the caller's data -into a stack-local buffer before freeing the old internal storage. - -Fixes pnggroup/libpng#836 - -Reported-by: Iv4n -CVE: CVE-2026-34757 -Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a] - -(cherry picked from commit 398cbe3df03f4e11bb031e07f416dfdde3684e8a) -Signed-off-by: Deepak Rathore ---- - CMakeLists.txt | 12 ++ - Makefile.am | 9 +- - contrib/libtests/pnggetset.c | 328 +++++++++++++++++++++++++++++++++++ - pngset.c | 29 +++- - tests/pnggetset | 5 + - 5 files changed, 380 insertions(+), 3 deletions(-) - create mode 100644 contrib/libtests/pnggetset.c - create mode 100755 tests/pnggetset - -diff --git a/CMakeLists.txt b/CMakeLists.txt -index fde2a323c..6401b7bd3 100644 ---- a/CMakeLists.txt -+++ b/CMakeLists.txt -@@ -624,6 +624,9 @@ set(pngvalid_sources - set(pngstest_sources - contrib/libtests/pngstest.c - ) -+set(pnggetset_sources -+ contrib/libtests/pnggetset.c -+) - set(pngunknown_sources - contrib/libtests/pngunknown.c - ) -@@ -786,6 +789,15 @@ if(PNG_TESTS AND PNG_SHARED) - COMMAND pngtest - FILES "${TEST_PNG3_PNGS}") - -+ # pnggetset test: -+ # Getter-to-setter roundtrips for various chunk types. -+ add_executable(pnggetset ${pnggetset_sources}) -+ target_link_libraries(pnggetset -+ PRIVATE png_shared) -+ -+ png_add_test(NAME pnggetset -+ COMMAND pnggetset) -+ - # pngvalid tests: - # Internal validation of standard and progressive reading, - # transforms, and gamma handling. -diff --git a/Makefile.am b/Makefile.am -index 88f7ab628..fa5bbeb61 100644 ---- a/Makefile.am -+++ b/Makefile.am -@@ -13,7 +13,7 @@ ACLOCAL_AMFLAGS = -I scripts/autoconf - - # test programs - run on make check, make distcheck - if ENABLE_TESTS --check_PROGRAMS= pngtest pngunknown pngstest pngvalid pngimage pngcp -+check_PROGRAMS= pngtest pnggetset pngunknown pngstest pngvalid pngimage pngcp - if HAVE_CLOCK_GETTIME - check_PROGRAMS += timepng - endif -@@ -42,6 +42,9 @@ if ENABLE_TESTS - pngtest_SOURCES = pngtest.c - pngtest_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la - -+pnggetset_SOURCES = contrib/libtests/pnggetset.c -+pnggetset_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la -+ - pngvalid_SOURCES = contrib/libtests/pngvalid.c - pngvalid_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la - -@@ -73,6 +76,7 @@ endif - if ENABLE_TESTS - TESTS =\ - tests/pngtest-all\ -+ tests/pnggetset\ - tests/pngvalid-gamma-16-to-8\ - tests/pngvalid-gamma-alpha-mode\ - tests/pngvalid-gamma-background\ -@@ -303,9 +307,10 @@ $(srcdir)/scripts/pnglibconf.h.prebuilt: - pngtest.o: pnglibconf.h - - contrib/libtests/makepng.o: pnglibconf.h -+contrib/libtests/pnggetset.o: pnglibconf.h -+contrib/libtests/pngimage.o: pnglibconf.h - contrib/libtests/pngstest.o: pnglibconf.h - contrib/libtests/pngunknown.o: pnglibconf.h --contrib/libtests/pngimage.o: pnglibconf.h - contrib/libtests/pngvalid.o: pnglibconf.h - contrib/libtests/readpng.o: pnglibconf.h - contrib/libtests/tarith.o: pnglibconf.h -diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c -new file mode 100644 -index 000000000..b42508094 ---- /dev/null -+++ b/contrib/libtests/pnggetset.c -@@ -0,0 +1,328 @@ -+/* pnggetset.c -+ * -+ * Copyright (c) 2026 Cosmin Truta -+ * -+ * This code is released under the libpng license. -+ * For conditions of distribution and use, see the disclaimer -+ * and license in png.h -+ * -+ * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. -+ * -+ * Passing the internal pointer returned by a getter back into the -+ * corresponding setter is a natural API usage pattern. A previous -+ * version had a use-after-free on this path because the setter freed -+ * the internal buffer before copying from the caller-supplied pointer. -+ */ -+ -+#include -+#include -+#include -+ -+#if defined(HAVE_CONFIG_H) && !defined(PNG_NO_CONFIG_H) -+# include -+#endif -+ -+#ifdef PNG_FREESTANDING_TESTS -+# include -+#else -+# include "../../png.h" -+#endif -+ -+/* Test: get the PLTE, pass it straight back to set, verify roundtrip. */ -+static int -+test_plte_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_color palette[4]; -+ png_colorp got_palette = NULL; -+ int num_palette = 0; -+ int i; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, "pnggetset: libpng error in test_plte_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Set up a palette-color image header. */ -+ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, -+ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); -+ -+ /* Populate with recognizable values. */ -+ for (i = 0; i < 4; i++) -+ { -+ palette[i].red = (png_byte)(i * 10); -+ palette[i].green = (png_byte)(i * 20); -+ palette[i].blue = (png_byte)(i * 30); -+ } -+ png_set_PLTE(png_ptr, info_ptr, palette, 4); -+ -+ /* Get the internal pointer and feed it straight back. */ -+ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); -+ if (got_palette == NULL || num_palette != 4) -+ { -+ fprintf(stderr, "pnggetset: png_get_PLTE returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: the pointer aliases info_ptr->palette. */ -+ png_set_PLTE(png_ptr, info_ptr, got_palette, num_palette); -+ -+ /* Verify the data survived the roundtrip. */ -+ got_palette = NULL; -+ num_palette = 0; -+ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette); -+ if (got_palette == NULL || num_palette != 4) -+ { -+ fprintf(stderr, "pnggetset: PLTE lost after roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ for (i = 0; i < 4; i++) -+ { -+ if (got_palette[i].red != (png_byte)(i * 10) || -+ got_palette[i].green != (png_byte)(i * 20) || -+ got_palette[i].blue != (png_byte)(i * 30)) -+ { -+ fprintf(stderr, -+ "pnggetset: PLTE entry %d corrupted after roundtrip\n", i); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+ -+#ifdef PNG_hIST_SUPPORTED -+/* Test: get the hIST, pass it straight back to set, verify roundtrip. */ -+static int -+test_hist_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_color palette[4]; -+ png_uint_16 hist[4]; -+ png_uint_16p got_hist = NULL; -+ int i; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, "pnggetset: libpng error in test_hist_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Set up a palette-color image header. */ -+ memset(palette, 0, sizeof palette); -+ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, -+ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); -+ png_set_PLTE(png_ptr, info_ptr, palette, 4); -+ -+ /* Populate with recognizable values. */ -+ for (i = 0; i < 4; i++) -+ hist[i] = (png_uint_16)(i * 100 + 42); -+ -+ png_set_hIST(png_ptr, info_ptr, hist); -+ -+ /* Get the internal pointer and feed it straight back. */ -+ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_get_hIST returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: the pointer aliases info_ptr->hist. */ -+ png_set_hIST(png_ptr, info_ptr, got_hist); -+ -+ /* Verify the data survived the roundtrip. */ -+ got_hist = NULL; -+ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL) -+ { -+ fprintf(stderr, "pnggetset: hIST lost after roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ for (i = 0; i < 4; i++) -+ { -+ if (got_hist[i] != (png_uint_16)(i * 100 + 42)) -+ { -+ fprintf(stderr, -+ "pnggetset: hIST entry %d corrupted after roundtrip\n", i); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+#endif /* PNG_hIST_SUPPORTED */ -+ -+#ifdef PNG_tRNS_SUPPORTED -+/* Test: get the tRNS, pass it straight back to set, verify roundtrip. */ -+static int -+test_trns_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_color palette[4]; -+ png_byte trans_alpha[4]; -+ png_color_16 trans_color; -+ png_bytep got_alpha = NULL; -+ png_color_16p got_color = NULL; -+ int num_trans = 0; -+ int i; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, "pnggetset: libpng error in test_trns_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Set up a palette-color image. */ -+ memset(palette, 0, sizeof palette); -+ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE, -+ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); -+ png_set_PLTE(png_ptr, info_ptr, palette, 4); -+ -+ /* Populate tRNS with recognizable values. */ -+ for (i = 0; i < 4; i++) -+ trans_alpha[i] = (png_byte)(0xff - i * 0x11); -+ memset(&trans_color, 0, sizeof trans_color); -+ -+ png_set_tRNS(png_ptr, info_ptr, trans_alpha, 4, &trans_color); -+ -+ /* Get the internal pointer and feed it straight back. */ -+ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); -+ if (got_alpha == NULL || num_trans != 4) -+ { -+ fprintf(stderr, "pnggetset: png_get_tRNS returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: the pointer aliases info_ptr->trans_alpha. */ -+ png_set_tRNS(png_ptr, info_ptr, got_alpha, num_trans, got_color); -+ -+ /* Verify the data survived the roundtrip. */ -+ got_alpha = NULL; -+ num_trans = 0; -+ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color); -+ if (got_alpha == NULL || num_trans != 4) -+ { -+ fprintf(stderr, "pnggetset: tRNS lost after roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ for (i = 0; i < 4; i++) -+ { -+ if (got_alpha[i] != (png_byte)(0xff - i * 0x11)) -+ { -+ fprintf(stderr, -+ "pnggetset: tRNS entry %d corrupted after roundtrip\n", i); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+#endif /* PNG_tRNS_SUPPORTED */ -+ -+int -+main(void) -+{ -+ int result = 0; -+ -+ printf("Testing PLTE get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_plte_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+ -+#ifdef PNG_hIST_SUPPORTED -+ printf("Testing hIST get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_hist_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+#endif -+ -+#ifdef PNG_tRNS_SUPPORTED -+ printf("Testing tRNS get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_trns_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+#endif -+ -+ return result; -+} -diff --git a/pngset.c b/pngset.c -index b9ccb7fb1..a6f20123e 100644 ---- a/pngset.c -+++ b/pngset.c -@@ -385,6 +385,7 @@ void PNGAPI - png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, - png_const_uint_16p hist) - { -+ png_uint_16 safe_hist[PNG_MAX_PALETTE_LENGTH]; - int i; - - png_debug1(1, "in %s storage function", "hIST"); -@@ -401,6 +402,13 @@ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr, - return; - } - -+ /* Snapshot the caller's hist before freeing, in case it points to -+ * info_ptr->hist (getter-to-setter aliasing). -+ */ -+ memcpy(safe_hist, hist, (unsigned int)info_ptr->num_palette * -+ (sizeof (png_uint_16))); -+ hist = safe_hist; -+ - png_free_data(png_ptr, info_ptr, PNG_FREE_HIST, 0); - - /* Changed from info->num_palette to PNG_MAX_PALETTE_LENGTH in -@@ -742,7 +750,7 @@ void PNGAPI - png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, - png_const_colorp palette, int num_palette) - { -- -+ png_color safe_palette[PNG_MAX_PALETTE_LENGTH]; - png_uint_32 max_palette_length; - - png_debug1(1, "in %s storage function", "PLTE"); -@@ -776,6 +784,15 @@ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr, - png_error(png_ptr, "Invalid palette"); - } - -+ /* Snapshot the caller's palette before freeing, in case it points to -+ * info_ptr->palette (getter-to-setter aliasing). -+ */ -+ if (num_palette > 0) -+ memcpy(safe_palette, palette, (unsigned int)num_palette * -+ (sizeof (png_color))); -+ -+ palette = safe_palette; -+ - png_free_data(png_ptr, info_ptr, PNG_FREE_PLTE, 0); - - /* Changed in libpng-1.2.1 to allocate PNG_MAX_PALETTE_LENGTH instead -@@ -1165,6 +1182,16 @@ png_set_tRNS(png_structrp png_ptr, png_inforp info_ptr, - - if (trans_alpha != NULL) - { -+ /* Snapshot the caller's trans_alpha before freeing, in case it -+ * points to info_ptr->trans_alpha (getter-to-setter aliasing). -+ */ -+ png_byte safe_trans[PNG_MAX_PALETTE_LENGTH]; -+ -+ if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) -+ memcpy(safe_trans, trans_alpha, (size_t)num_trans); -+ -+ trans_alpha = safe_trans; -+ - png_free_data(png_ptr, info_ptr, PNG_FREE_TRNS, 0); - - if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH) -diff --git a/tests/pnggetset b/tests/pnggetset -new file mode 100755 -index 000000000..57ef731a5 ---- /dev/null -+++ b/tests/pnggetset -@@ -0,0 +1,5 @@ -+#!/bin/sh -+ -+# pnggetset test: -+# Getter-to-setter roundtrips for various chunk types. -+exec ./pnggetset diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch deleted file mode 100644 index 894f9d618be..00000000000 --- a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch +++ /dev/null @@ -1,481 +0,0 @@ -From 815fdfc8dba0603abc26523d0b7e37f7ad21988b Mon Sep 17 00:00:00 2001 -From: Cosmin Truta -Date: Mon, 30 Mar 2026 17:43:05 +0300 -Subject: [PATCH] fix: Handle getter-to-setter aliasing in append-style chunk - setters - -Apply the same class of robustness fix from the previous commit to -`png_set_text`, `png_set_sPLT` and `png_set_unknown_chunks`. These -append-style setters used `png_realloc_array` to grow the internal -array, then freed the old array before copying from the caller's -input. If the caller's pointer was obtained from the corresponding -getter, it aliased the freed array. - -The fix defers the freeing of the old array until after the copy loop. - -Also extend the pnggetset regression test to cover all three setters. - -CVE: CVE-2026-34757 -Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc] - -(cherry picked from commit 55d20aaa322c9274491cda82c5cd4f99b48c6bcc) -Signed-off-by: Deepak Rathore ---- - contrib/libtests/pnggetset.c | 330 ++++++++++++++++++++++++++++++++++- - pngset.c | 25 ++- - 2 files changed, 347 insertions(+), 8 deletions(-) - -diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c -index b42508094..6ae43dc66 100644 ---- a/contrib/libtests/pnggetset.c -+++ b/contrib/libtests/pnggetset.c -@@ -6,12 +6,12 @@ - * For conditions of distribution and use, see the disclaimer - * and license in png.h - * -- * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST. -+ * Test the get-then-set roundtrip for chunk types whose getters return -+ * a pointer to internal storage. - * -- * Passing the internal pointer returned by a getter back into the -- * corresponding setter is a natural API usage pattern. A previous -- * version had a use-after-free on this path because the setter freed -- * the internal buffer before copying from the caller-supplied pointer. -+ * Passing such a pointer back into the corresponding setter must not -+ * cause a use-after-free. A previous version freed the internal buffer -+ * before copying from the caller-supplied pointer. - */ - - #include -@@ -285,6 +285,290 @@ test_trns_roundtrip(void) - } - #endif /* PNG_tRNS_SUPPORTED */ - -+#ifdef PNG_TEXT_SUPPORTED -+/* Test: get the text array, pass it straight back to set, verify data. */ -+#define TEXT_COUNT 6 /* enough to trigger reallocation on the second set */ -+static int -+test_text_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_text text_entries[TEXT_COUNT]; -+ png_textp got_text = NULL; -+ int got_num_text = 0; -+ int i; -+ -+ /* Recognizable keys and values. */ -+ static const char *keys[TEXT_COUNT] = { -+ "Title", "Author", "Desc", "Copyright", "Source", "Comment" -+ }; -+ static const char *vals[TEXT_COUNT] = { -+ "t0", "t1", "t2", "t3", "t4", "t5" -+ }; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, "pnggetset: libpng error in test_text_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Populate the text entries. */ -+ memset(text_entries, 0, sizeof text_entries); -+ for (i = 0; i < TEXT_COUNT; i++) -+ { -+ text_entries[i].compression = PNG_TEXT_COMPRESSION_NONE; -+ text_entries[i].key = (png_charp)keys[i]; -+ text_entries[i].text = (png_charp)vals[i]; -+ } -+ png_set_text(png_ptr, info_ptr, text_entries, TEXT_COUNT); -+ -+ /* Get the internal pointer and feed it straight back (append). */ -+ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); -+ if (got_text == NULL || got_num_text != TEXT_COUNT) -+ { -+ fprintf(stderr, "pnggetset: png_get_text returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: got_text aliases info_ptr->text. */ -+ png_set_text(png_ptr, info_ptr, got_text, got_num_text); -+ -+ /* Verify the original entries survived. */ -+ got_text = NULL; -+ got_num_text = 0; -+ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text); -+ if (got_text == NULL || got_num_text != TEXT_COUNT * 2) -+ { -+ fprintf(stderr, "pnggetset: text count %d, expected %d after roundtrip\n", -+ got_num_text, TEXT_COUNT * 2); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ for (i = 0; i < TEXT_COUNT; i++) -+ { -+ if (got_text[i].key == NULL || -+ strcmp(got_text[i].key, keys[i]) != 0 || -+ got_text[i].text == NULL || -+ strcmp(got_text[i].text, vals[i]) != 0) -+ { -+ fprintf(stderr, -+ "pnggetset: text entry %d corrupted after roundtrip\n", i); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+#undef TEXT_COUNT -+#endif /* PNG_TEXT_SUPPORTED */ -+ -+#ifdef PNG_sPLT_SUPPORTED -+/* Test: get the sPLT array, pass it straight back to set, verify data. */ -+static int -+test_splt_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_sPLT_t splt; -+ png_sPLT_entry splt_entries[4]; -+ png_sPLT_tp got_spalettes = NULL; -+ int got_num, i; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, "pnggetset: libpng error in test_splt_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Populate with recognizable values. */ -+ memset(splt_entries, 0, sizeof splt_entries); -+ for (i = 0; i < 4; i++) -+ { -+ splt_entries[i].red = (png_uint_16)(i * 1000); -+ splt_entries[i].green = (png_uint_16)(i * 2000); -+ splt_entries[i].blue = (png_uint_16)(i * 3000); -+ splt_entries[i].alpha = 0xffffU; -+ splt_entries[i].frequency = (png_uint_16)(i + 1); -+ } -+ memset(&splt, 0, sizeof splt); -+ splt.name = (png_charp)"test_sPLT"; -+ splt.depth = 16; -+ splt.entries = splt_entries; -+ splt.nentries = 4; -+ -+ png_set_sPLT(png_ptr, info_ptr, &splt, 1); -+ -+ /* Get the internal pointer and feed it straight back (append). */ -+ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); -+ if (got_spalettes == NULL || got_num != 1) -+ { -+ fprintf(stderr, "pnggetset: png_get_sPLT returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: got_spalettes aliases internal storage. */ -+ png_set_sPLT(png_ptr, info_ptr, got_spalettes, got_num); -+ -+ /* Verify the original entry survived. */ -+ got_spalettes = NULL; -+ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes); -+ if (got_spalettes == NULL || got_num != 2) -+ { -+ fprintf(stderr, "pnggetset: sPLT count %d, expected 2 after roundtrip\n", -+ got_num); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ if (strcmp(got_spalettes[0].name, "test_sPLT") != 0 || -+ got_spalettes[0].nentries != 4 || -+ got_spalettes[0].depth != 16) -+ { -+ fprintf(stderr, -+ "pnggetset: sPLT entry 0 corrupted after roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ for (i = 0; i < 4; i++) -+ { -+ if (got_spalettes[0].entries[i].red != (png_uint_16)(i * 1000) || -+ got_spalettes[0].entries[i].green != (png_uint_16)(i * 2000) || -+ got_spalettes[0].entries[i].blue != (png_uint_16)(i * 3000)) -+ { -+ fprintf(stderr, -+ "pnggetset: sPLT[0] entry %d corrupted after roundtrip\n", i); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+#endif /* PNG_sPLT_SUPPORTED */ -+ -+#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED -+/* Test: get unknown chunks, pass them straight back to set, verify data. */ -+static int -+test_unknown_roundtrip(void) -+{ -+ png_structp png_ptr; -+ png_infop info_ptr; -+ png_unknown_chunk unk; -+ png_unknown_chunkp got_unknowns = NULL; -+ int got_num; -+ static const png_byte test_data[] = {0xde, 0xad, 0xbe, 0xef}; -+ -+ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, -+ NULL, NULL, NULL); -+ if (png_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_write_struct failed\n"); -+ return 1; -+ } -+ -+ info_ptr = png_create_info_struct(png_ptr); -+ if (info_ptr == NULL) -+ { -+ fprintf(stderr, "pnggetset: png_create_info_struct failed\n"); -+ png_destroy_write_struct(&png_ptr, NULL); -+ return 1; -+ } -+ -+ if (setjmp(png_jmpbuf(png_ptr))) -+ { -+ fprintf(stderr, -+ "pnggetset: libpng error in test_unknown_roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* Set up an unknown chunk with recognizable data. */ -+ memset(&unk, 0, sizeof unk); -+ memcpy(unk.name, "teSt", 5); -+ unk.data = (png_bytep)test_data; -+ unk.size = sizeof test_data; -+ unk.location = PNG_HAVE_IHDR; -+ -+ png_set_keep_unknown_chunks(png_ptr, PNG_HANDLE_CHUNK_ALWAYS, NULL, 0); -+ png_set_unknown_chunks(png_ptr, info_ptr, &unk, 1); -+ -+ /* Get the internal pointer and feed it straight back (append). */ -+ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); -+ if (got_unknowns == NULL || got_num != 1) -+ { -+ fprintf(stderr, -+ "pnggetset: png_get_unknown_chunks returned unexpected values\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ /* This is the critical call: got_unknowns aliases internal storage. */ -+ png_set_unknown_chunks(png_ptr, info_ptr, got_unknowns, got_num); -+ -+ /* Verify the original entry survived. */ -+ got_unknowns = NULL; -+ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns); -+ if (got_unknowns == NULL || got_num != 2) -+ { -+ fprintf(stderr, -+ "pnggetset: unknown_chunks count %d, expected 2 after roundtrip\n", -+ got_num); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ if (memcmp(got_unknowns[0].name, "teSt", 4) != 0 || -+ got_unknowns[0].size != sizeof test_data || -+ memcmp(got_unknowns[0].data, test_data, sizeof test_data) != 0) -+ { -+ fprintf(stderr, -+ "pnggetset: unknown chunk 0 corrupted after roundtrip\n"); -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 1; -+ } -+ -+ png_destroy_write_struct(&png_ptr, &info_ptr); -+ return 0; -+} -+#endif /* PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED */ -+ - int - main(void) - { -@@ -324,5 +608,41 @@ main(void) - printf("PASS\n"); - #endif - -+#ifdef PNG_TEXT_SUPPORTED -+ printf("Testing tEXt get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_text_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+#endif -+ -+#ifdef PNG_sPLT_SUPPORTED -+ printf("Testing sPLT get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_splt_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+#endif -+ -+#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED -+ printf("Testing unknown chunks get-then-set roundtrip... "); -+ fflush(stdout); -+ if (test_unknown_roundtrip() != 0) -+ { -+ printf("FAIL\n"); -+ result = 1; -+ } -+ else -+ printf("PASS\n"); -+#endif -+ - return result; - } -diff --git a/pngset.c b/pngset.c -index a6f20123e..513c51eb4 100644 ---- a/pngset.c -+++ b/pngset.c -@@ -954,6 +954,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, - png_const_textp text_ptr, int num_text) - { - int i; -+ png_textp old_text = NULL; - - png_debug1(1, "in text storage function, chunk typeid = 0x%lx", - png_ptr == NULL ? 0xabadca11UL : (unsigned long)png_ptr->chunk_name); -@@ -1001,7 +1002,10 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, - return 1; - } - -- png_free(png_ptr, info_ptr->text); -+ /* Defer freeing the old array until after the copy loop below, -+ * in case text_ptr aliases info_ptr->text (getter-to-setter). -+ */ -+ old_text = info_ptr->text; - - info_ptr->text = new_text; - info_ptr->free_me |= PNG_FREE_TEXT; -@@ -1086,6 +1090,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, - { - png_chunk_report(png_ptr, "text chunk: out of memory", - PNG_CHUNK_WRITE_ERROR); -+ png_free(png_ptr, old_text); - - return 1; - } -@@ -1139,6 +1144,8 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr, - png_debug1(3, "transferred text chunk %d", info_ptr->num_text); - } - -+ png_free(png_ptr, old_text); -+ - return 0; - } - #endif -@@ -1276,6 +1283,7 @@ png_set_sPLT(png_const_structrp png_ptr, - */ - { - png_sPLT_tp np; -+ png_sPLT_tp old_spalettes; - - png_debug1(1, "in %s storage function", "sPLT"); - -@@ -1296,7 +1304,10 @@ png_set_sPLT(png_const_structrp png_ptr, - return; - } - -- png_free(png_ptr, info_ptr->splt_palettes); -+ /* Defer freeing the old array until after the copy loop below, -+ * in case entries aliases info_ptr->splt_palettes (getter-to-setter). -+ */ -+ old_spalettes = info_ptr->splt_palettes; - - info_ptr->splt_palettes = np; - info_ptr->free_me |= PNG_FREE_SPLT; -@@ -1360,6 +1371,8 @@ png_set_sPLT(png_const_structrp png_ptr, - } - while (--nentries); - -+ png_free(png_ptr, old_spalettes); -+ - if (nentries > 0) - png_chunk_report(png_ptr, "sPLT out of memory", PNG_CHUNK_WRITE_ERROR); - } -@@ -1408,6 +1421,7 @@ png_set_unknown_chunks(png_const_structrp png_ptr, - png_inforp info_ptr, png_const_unknown_chunkp unknowns, int num_unknowns) - { - png_unknown_chunkp np; -+ png_unknown_chunkp old_unknowns; - - if (png_ptr == NULL || info_ptr == NULL || num_unknowns <= 0 || - unknowns == NULL) -@@ -1454,7 +1468,10 @@ png_set_unknown_chunks(png_const_structrp png_ptr, - return; - } - -- png_free(png_ptr, info_ptr->unknown_chunks); -+ /* Defer freeing the old array until after the copy loop below, -+ * in case unknowns aliases info_ptr->unknown_chunks (getter-to-setter). -+ */ -+ old_unknowns = info_ptr->unknown_chunks; - - info_ptr->unknown_chunks = np; /* safe because it is initialized */ - info_ptr->free_me |= PNG_FREE_UNKN; -@@ -1500,6 +1517,8 @@ png_set_unknown_chunks(png_const_structrp png_ptr, - ++np; - ++(info_ptr->unknown_chunks_num); - } -+ -+ png_free(png_ptr, old_unknowns); - } - - void PNGAPI diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.56.bb b/meta/recipes-multimedia/libpng/libpng_1.6.58.bb similarity index 94% rename from meta/recipes-multimedia/libpng/libpng_1.6.56.bb rename to meta/recipes-multimedia/libpng/libpng_1.6.58.bb index 9a85d44f52b..6e4e5e9f387 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.56.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.58.bb @@ -12,11 +12,9 @@ LIBV = "16" SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}${LIBV}/${BP}.tar.xz \ file://run-ptest \ - file://CVE-2026-34757_p1.patch \ - file://CVE-2026-34757_p2.patch \ - " +" -SRC_URI[sha256sum] = "f7d8bf1601b7804f583a254ab343a6549ca6cf27d255c302c47af2d9d36a6f18" +SRC_URI[sha256sum] = "28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775" MIRRORS += "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/ ${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/older-releases/" @@ -73,4 +71,5 @@ do_install_ptest() { BBCLASSEXTEND = "native nativesdk" +CVE_STATUS[CVE-2026-34757] = "fixed-version: fixed since 1.6.57" CVE_STATUS[CVE-2026-40930] = "cpe-incorrect: Yocto never included affected libpng-apng patch" From patchwork Sun Oct 11 08:40:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100326 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2CD37CA9ED1 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23449.1791708086039193086 for ; Sun, 11 Oct 2026 01:41:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Cfx5ip2Z; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-48af4d4e61fso514852f8f.2 for ; Sun, 11 Oct 2026 01:41:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708084; x=1792312884; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=35gcTE7SF3CSIusWkdcrVmGatku2cCZ3zyW64XHW84k=; b=Cfx5ip2ZDRLo5XcsRgHNVbv9hbjwDKOF5Cn4vTL+yxNa6UOfuulOoNJm1w9EmazLGh I9UXU2FGOJzZrkX3sbCYwMjj6MQdXWZjc6qQGXlSoD9c6FsXpGMVKipPWU1BCHw3CEgI hILDycyzXC1AqJx82CEcaJLtWZotXBGU87kbw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708084; x=1792312884; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=35gcTE7SF3CSIusWkdcrVmGatku2cCZ3zyW64XHW84k=; b=y1hF1tndR64pjTnEyqyxaTXnpEcTPUsJ8FghrC8yI+SLNtWdJ1lC8JlbspiwIolF+E CBWdCfGveHv5ok/f2VCG78RPFME7clreoTjfKWpzVw3am1oWc05xd3K2J3UF0JVPhvz6 oWBzTrj7XuK5tmd4glkZuhvwrZA/+IaEjsg7BpADQ2WIXH6UEt6QncB0XZrY/xW8EQku HBshR7KldwH5h57WZcDKE8RBR8iwBaCuPvAj/asgxaKqqPUXKLb12xhLe4FWK2dJIRLC U3CeILcZGvGCtrgRfEzJ0vg+jS+rDa4r6lua0yYeq/IS+GQlFUaa8oBagt1E6kbE0LzP SwfQ== X-Gm-Message-State: AFq9FYKnm083rL54DcSpMBAGt8vTJFVA3HeYqYcSgVcsHR7Fd0vZqgPB nrbeVCNLLe036qZNXfiMUR9ClEg/3Uby/pWYAQR7+sVxKJs6R++dLJeOACtyI5XieiuslROHLgs y0aXO4MI= X-Gm-Gg: AYBFou31x158l83DLT3m4pJxKnJQc8q8MCrgwJFNtr5KcGWDVw1ZgKnSN/aIFQdw14H h/R6bnuSnSd4nwkwCvhWsSL8UG3kewZz1TRlbff/2Bdz7yrUP7CSvuDpLrBICtis4Pkawj7nkTh FDjm4wjj+cy6Fjo938RWiNWwDR8Pw+Z0NY4XlgSL8aLfydVXpiBjHRbY2YtwRcRd2Q0G/I3LwGh fV4R5FyrBG8XWdbqduDmssS/PTWXem/10DZPieqYzB44Me6185cPmNbmPcB8rIOhjhu+u+q1eyu FQxGXrnRLNjySZRJcTRK8AGSWUNUl090hq5ukyfJEwWurepZLvTLI/w+JbaZGQzo/Hjnm89YZf4 TKmFOJH+cWOg34e4cU20k+GcdRUrgr9F4t9Y4ix5ILnf9jSMABW5Xclnf9fV1qho8rnQr63dJoM j9KoAJs58raS6dWCxs2Azp91BT9Vqhj0fjpvrqIVmZy6QOv/mpTrR9ZVtU8xsQENKG+ezxbthoo ijO1Aazb3vN5rVSdIYDoZjZNCdHBzHoumT9AMuIWSd/0oehlvOLkPNnmYrfavK0Ey7I8z5WKw== X-Received: by 2002:a05:6000:4312:b0:487:27f6:a4e4 with SMTP id ffacd0b85a97d-48dbad489d1mr10965625f8f.52.1791708084211; Sun, 11 Oct 2026 01:41:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 36/60] libpng: upgrade 1.6.58 -> 1.6.59 Date: Sun, 11 Oct 2026 10:40:09 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247544 From: Peter Marko Release notes [1]: Version 1.6.59 [September 28, 2026] Fixed CVE-2026-46675 (medium severity): Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression. (Reported independently by Ze Sheng and .) Fixed a regression introduced in version 1.6.47 that caused libpng to reject hIST chunks in their correct position, after PLTE. (Contributed by Yuki Sekiguchi.) Prevented a double free of `png_struct` members after an allocation failure. (Contributed by Anthony Hurtado.) Applied fixes and updates to the CMake build. Adopted the REUSE Specification for licensing the CI files. Note: cmake is not used in Yocto build of libpng. [1] https://github.com/pnggroup/libpng/blob/v1.6.59/CHANGES#L6388 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 907c6fa2d0c4f8a8f765cde004c55fb2dd2c402d) Signed-off-by: Yoann Congal --- .../libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-multimedia/libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb} (97%) diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb similarity index 97% rename from meta/recipes-multimedia/libpng/libpng_1.6.58.bb rename to meta/recipes-multimedia/libpng/libpng_1.6.59.bb index 6e4e5e9f387..21f3a8ff3b6 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb @@ -14,7 +14,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}${LIBV}/${BP}.tar.xz \ file://run-ptest \ " -SRC_URI[sha256sum] = "28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775" +SRC_URI[sha256sum] = "d80dd2a38a37f803cb9b6ac7b14bd6e74ddc3b654780a8380bdf93523fdb4389" MIRRORS += "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/ ${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/older-releases/" From patchwork Sun Oct 11 08:40:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100322 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C919DCA9EC9 for ; Sun, 11 Oct 2026 08:41:28 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23450.1791708087497854866 for ; Sun, 11 Oct 2026 01:41:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JihaMVHH; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4a018792ab3so8339355e9.0 for ; Sun, 11 Oct 2026 01:41:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708086; x=1792312886; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HJ7QdButf75PTlPgbCJg72d5wLccVxgweTmQJD6Xh5E=; b=JihaMVHH5GHhMVjTNlj/i3RYZklZF/YmVmK6ultQHUpgQlzmr3YW6P5hyTtcysZWFO P+TK5UvLqig4B+cGsFU4Gib9nxd4Un84ARGsgkvv4BkOxc6ta+NQOUAfGXux+9mnTAjY Ny/gVpQe3Ngy/rHkOYyLB1wZnoCLFcEKCXjV8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708086; x=1792312886; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HJ7QdButf75PTlPgbCJg72d5wLccVxgweTmQJD6Xh5E=; b=zlL5WCiMbn9NkfTd6jDa+TzLZUzc7tGJjFmJ+kApR9KyrPVc0Krhb+mfhgVcMlFmli R6aKj/bbSdlmgdj83T3i9QEZe4yNTrpko14VtkMBmINHplB0gk9d/mK+4R/UsjMx1/cg 17/G4z7VaTPRyF8IlAvc3cNfbBs0Te7TpXJwHjxMNzDW/RdLzXtT98MQIy8EQ39AaEPw T+qfFo7kLBjb4FoQh5TewVvWt1nYkKX9hH8flkkQl5MsvvVNtn/3hAZ/PTLbVHTAf97J 1MGEy4+Dnmn3MddgvVc9fVXch8XyBLC8Ddb04ghxIwp24j1TW4qX/SFHFV0Ubxdikpv2 pnLQ== X-Gm-Message-State: AFq9FYIYSFN/Jq1AJ48HyQqIYwAQuWVY6g1ViKS+gbCg0H/6qbCAGCVQ 1WSqPxRyTEL3h55mYNJZoJ9t9tFQb/kipybpjHENTBVR07WSkVooa4uCN14XlcZEgDUKekak+2N R6p+Cvqs= X-Gm-Gg: AYBFou3sokrQs5L4i9k6Msxt9jAEnyhK95pIRkqAueZBjSFjMVbKbXiZOgDz+830rrn YaPx7hng9yd+tnHG/T6d2AVhylmC7PSwjSmzfC2TAQZjm8udq+dSUUkVXCVVJvtdbFV7sjsqvml r5dxmH3yfWUwRTeDNU/1nrGyvN4anuiAHYsxLd3ONh6jvuhtNQIAYXouHCGC8u3qBjzJq9dQjKG 2TfP+yg0vIJaIN9Tx/CtbBihkUDnbirbv39DfaGw6YpkYQEkhB0l9pA4mqGAqDxF/6lCRxgJKdX aiuKCpizHOdXkfyhHJGRPQiC+UTn/nkPl6TLE7hbONi7XU5pT+tjfZX7sqUrF4GlV5aFYqKtviX JgUfZs7fTIlGC0vJKJ1X0E6QtOMVBodmlRHspLKxYIrLfXyCnEfb7CQI40tFYJyNoSrOCRVK9mN 87WMNkD6Sspje0glAMqawnviOy17if8/Fmvzrp7CZm0UPsJRX0t9hciyDRFGROU5Z1pzCX8+Scp kGT3DciVZ3LZcczXJ8bK45MWdTFd8xOjQk+lBFhXz0hudhcCWHnE+MYChDWhLX9XZDpesYzVw== X-Received: by 2002:a05:600c:6749:b0:4a0:1a7f:2abf with SMTP id 5b1f17b1804b1-4a18e49d633mr107741425e9.7.1791708085479; Sun, 11 Oct 2026 01:41:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 37/60] util-linux(-uuid): upgrade 2.41.5 -> 2.41.6 Date: Sun, 11 Oct 2026 10:40:10 +0200 Message-ID: <00d16929859fe07756403c97644c7ed08a3eadde.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247546 From: Peter Marko Backported a patche from v2.41 branch to fix build. Also backported patch to fix CVE fixes regressions. Release notes [1]: Security fixes: CVE-2026-76642 - mount(8) post-mount hooks execute after helper failure. When an external mount. helper exits nonzero, post-mount hooks (X-mount.idmap, X-mount.owner/group/mode) still execute as if the mount had succeeded, allowing privileged operations on the pre-existing target filesystem. CVE-2026-78410 - mount(8) TOCTOU race on source path. In restricted (SUID, non-root) mode, the source path is canonicalized with realpath() as euid=0, following symlinks through user-writable directories. Additionally, open_tree() follows symlinks in intermediate path components. A local attacker can redirect a privileged mount or post-mount ownership change to an arbitrary path. CVE-2026-78408 - nsenter(1), unshare(1) file descriptor leak. File descriptors in nsenter and unshare were not created with O_CLOEXEC, potentially leaking them across exec. Added O_CLOEXEC as defense in depth. wall(1), write(1) - hostname escape sequence injection. The CVE-2024-28085 fix sanitized only message bodies; the banner headers still interpolated the system hostname without sanitization. An unprivileged user can inject terminal escape sequences via a user namespace hostname. Additional fix for CVE-2024-28085. Reported-by: Skyler Ferrante Changes between v2.41.5 and v2.41.6: lib/fileutils: - add ul_openat_resolve() openat2 wrapper (by Karel Zak) libmount: - skip post-mount hooks after failed mount helper [CVE-2026-76642] (by Karel Zak) - pin source path with openat2() for restricted users [CVE-2026-78410] (by Karel Zak) - restrict source path canonicalization for non-root users [CVE-2026-78410] (by Karel Zak) - add mnt_open_tree() helper for safe tree opening (by Karel Zak) loopdev: - use openat2(RESOLVE_NO_SYMLINKS) for backing file (by Karel Zak) nsenter, unshare: - add O_CLOEXEC to all open() calls [CVE-2026-78408] (by Karel Zak) tests: - (lsfd) add a function checking the availability of UDPLite socket (by Masatake YAMATO) - (lsfd/option-inet) make UDPLite related test case skippable (by Masatake YAMATO) - (lsfd/mkfds-udp*) make UDPLite related test cases skippable (by Masatake YAMATO) wall, write: - sanitize hostname in banner header (by Karel Zak) [1] https://github.com/util-linux/util-linux/blob/v2.41.6/Documentation/releases/v2.41.6-ReleaseNotes Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...2.41.5.bb => util-linux-libuuid_2.41.6.bb} | 0 meta/recipes-core/util-linux/util-linux.inc | 5 +- ...sing-fileutils.h-include-to-hook_idm.patch | 38 ++++++ .../util-linux/CVE-2026-78408.patch | 75 ++++++++++++ .../util-linux/CVE-2026-78410.patch | 115 ++++++++++++++++++ ...l-linux_2.41.5.bb => util-linux_2.41.6.bb} | 0 6 files changed, 232 insertions(+), 1 deletion(-) rename meta/recipes-core/util-linux/{util-linux-libuuid_2.41.5.bb => util-linux-libuuid_2.41.6.bb} (100%) create mode 100644 meta/recipes-core/util-linux/util-linux/0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch rename meta/recipes-core/util-linux/{util-linux_2.41.5.bb => util-linux_2.41.6.bb} (100%) diff --git a/meta/recipes-core/util-linux/util-linux-libuuid_2.41.5.bb b/meta/recipes-core/util-linux/util-linux-libuuid_2.41.6.bb similarity index 100% rename from meta/recipes-core/util-linux/util-linux-libuuid_2.41.5.bb rename to meta/recipes-core/util-linux/util-linux-libuuid_2.41.6.bb diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index be49160eac9..5b9762e24d9 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -21,9 +21,12 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin file://0001-ts-kill-decode-use-RTMIN-from-kill-L-instead-of-hard.patch \ file://0001-tests-script-Disable-size-option-test.patch \ file://CVE-2026-3184.patch \ + file://0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch \ + file://CVE-2026-78408.patch \ + file://CVE-2026-78410.patch \ " -SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8aa6a728" +SRC_URI[sha256sum] = "e596083744e746be7d2823b62b43f4418dd7bf56303b4dc09e6fe8112fe3d7ed" CVE_PRODUCT = "util-linux" diff --git a/meta/recipes-core/util-linux/util-linux/0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch b/meta/recipes-core/util-linux/util-linux/0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch new file mode 100644 index 00000000000..2beb9963c86 --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch @@ -0,0 +1,38 @@ +From 79c2881c27a0b40889cd5433d9f125689826d1d2 Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Wed, 2 Sep 2026 13:32:27 +0200 +Subject: [PATCH] libmount: add missing fileutils.h include to hook_idmap.c + +The hook_idmap.c uses RESOLVE_NO_SYMLINKS (added by commit fb8e26535) +but does not include fileutils.h, which provides the fallback #define +for this constant. + +On Fedora (glibc 2.40+), this is masked because glibc's + transitively includes , which +defines RESOLVE_NO_SYMLINKS. On Ubuntu (and other distros with older +glibc), does not pull in openat2.h, so the build fails: + + hook_idmap.c:335:33: error: 'RESOLVE_NO_SYMLINKS' undeclared + +Fixes: fb8e26535 ("libmount: pin source path with openat2() for restricted users") +Signed-off-by: Karel Zak +(cherry picked from commit 7e2e010874b10b3aabdc3c4c844c9ffc46a4a374) + +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/79c2881c27a0b40889cd5433d9f125689826d1d2] +Signed-off-by: Peter Marko +--- + libmount/src/hook_idmap.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/libmount/src/hook_idmap.c b/libmount/src/hook_idmap.c +index 97d8e0d1e..d4d7fbacc 100644 +--- a/libmount/src/hook_idmap.c ++++ b/libmount/src/hook_idmap.c +@@ -23,6 +23,7 @@ + + #include "strutils.h" + #include "all-io.h" ++#include "fileutils.h" + #include "namespace.h" + + #include "mountP.h" diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch new file mode 100644 index 00000000000..676e4a6feaa --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch @@ -0,0 +1,75 @@ +From 485dbb67f1b6bb18e08b1b77f4aa2373ff3a705b Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Thu, 3 Sep 2026 12:17:14 +0200 +Subject: [PATCH] nsenter: close cgroup.procs fd after join to prevent + authority leak [CVE-2026-78408] + +The --join-cgroup option opens the target's cgroup.procs while running +as root and writes nsenter's own PID to migrate itself. The descriptor +was left open across subsequent namespace transitions, credential drops +(setgroups/setgid/setuid) and execve(). + +The kernel performs cgroup migration permission checks using the +credentials captured at open time (file->f_cred). An open cgroup.procs +descriptor therefore carries the opener's migration authority regardless +of later privilege changes. A program executed inside the target +namespace inherits root's cgroup migration capability even when running +as an unprivileged user with no capabilities. + +Fix this by: + + - closing the temporary /proc/PID/cgroup fd after reading the path + - adding O_CLOEXEC to the cgroup.procs open as defense in depth + - closing cgroup_procs_fd immediately after the self-migration write + - initializing the temporary cgroup fd to -1 instead of 0 to avoid + accidentally closing stdin via open_target_fd() + +The descriptor has no legitimate use after the single migration write. + +Introduced-by: b40650b71a74 ("nsenter: add option -c to join the cgroup of target process") +References: b0cf1cf0d255 ("nsenter: close cgroup.procs fd after join to prevent authority leak") +Signed-off-by: Karel Zak +(cherry picked from commit afe067c979b9ba2cbe856f7c6411210120ea62aa) + +CVE: CVE-2026-78408 +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/485dbb67f1b6bb18e08b1b77f4aa2373ff3a705b] +Signed-off-by: Peter Marko +--- + sys-utils/nsenter.c | 9 +++++++-- + 1 file changed, 7 insertions(+), 2 deletions(-) + +diff --git a/sys-utils/nsenter.c b/sys-utils/nsenter.c +index 9d9d90a48..99f1da3a0 100644 +--- a/sys-utils/nsenter.c ++++ b/sys-utils/nsenter.c +@@ -379,7 +379,7 @@ static int get_ns_ino(const char *path, ino_t *ino) + static void open_cgroup_procs(void) + { + char *buf = NULL, *path = NULL, *p; +- int cgroup_fd = 0; ++ int cgroup_fd = -1; + char fdpath[PATH_MAX]; + + open_target_fd(&cgroup_fd, "cgroup", optarg); +@@ -387,6 +387,8 @@ static void open_cgroup_procs(void) + if (read_all_alloc(cgroup_fd, &buf) < 1) + err(EXIT_FAILURE, _("failed to get cgroup path")); + ++ close(cgroup_fd); ++ + p = strtok(buf, "\n"); + if (p) + path = strrchr(p, ':'); +@@ -816,8 +818,11 @@ int main(int argc, char *argv[]) + } + + // Join into the target cgroup +- if (cgroup_procs_fd >= 0) ++ if (cgroup_procs_fd >= 0) { + join_into_cgroup(); ++ close(cgroup_procs_fd); ++ cgroup_procs_fd = -1; ++ } + + if (uid_gid_fd >= 0) { + struct stat st; diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch new file mode 100644 index 00000000000..1bacdf6dc94 --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch @@ -0,0 +1,115 @@ +From 233cf7321e9d0fd2cea901d0a97e565c725640ad Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Thu, 3 Sep 2026 10:01:29 +0200 +Subject: [PATCH] libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook + +The idmap hookset was originally guarded by HAVE_MOUNTFD_API (kernel +headers have the new mount syscalls) rather than +USE_LIBMOUNT_MOUNTFD_SUPPORT (libmount is built with mountfd support). + +This was intentional (commit 9040c0900, 2022) -- the idea was to keep +idmap working even with --disable-libmount-mountfd-support by calling +the raw open_tree() syscall directly, while using an inner #ifdef +USE_LIBMOUNT_MOUNTFD_SUPPORT to optionally reuse the sysapi fd_tree. + +This fine-grained approach broke when the CVE-2026-78410 fix replaced +the raw open_tree() call with mnt_open_tree(), which is only available +under USE_LIBMOUNT_MOUNTFD_SUPPORT. The build fails with +--disable-libmount-mountfd-support because mnt_open_tree() is +undeclared. + +Rather than maintaining two code paths for a feature that fundamentally +depends on the new mount API, gate the entire idmap hookset on +USE_LIBMOUNT_MOUNTFD_SUPPORT -- consistent with how hookset_mount is +guarded. Remove the now-redundant inner #ifdef. + +Also add a note to mount.8 that X-mount.idmap requires the new +fd-based mount API. + +Addresses: https://github.com/util-linux/util-linux/issues/4598 +Signed-off-by: Karel Zak +(cherry picked from commit e06799ac325a881a297d2ffd6fe568cacdcd00ab) + +CVE: CVE-2026-78410 +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/233cf7321e9d0fd2cea901d0a97e565c725640ad] +Signed-off-by: Peter Marko +--- + libmount/src/hook_idmap.c | 6 ++---- + libmount/src/hooks.c | 2 +- + libmount/src/version.c | 2 +- + sys-utils/mount.8.adoc | 1 + + 4 files changed, 5 insertions(+), 6 deletions(-) + +diff --git a/libmount/src/hook_idmap.c b/libmount/src/hook_idmap.c +index d4d7fbacc..94c025097 100644 +--- a/libmount/src/hook_idmap.c ++++ b/libmount/src/hook_idmap.c +@@ -32,7 +32,7 @@ + # include + #endif + +-#if defined(HAVE_MOUNTFD_API) && defined(HAVE_LINUX_MOUNT_H) ++#ifdef USE_LIBMOUNT_MOUNTFD_SUPPORT + + typedef enum idmap_type_t { + ID_TYPE_UID, /* uidmap entry */ +@@ -317,7 +317,6 @@ static int hook_mount_post( + * Once a mount has been attached to the filesystem it can't be + * idmapped anymore. So create a new detached mount. + */ +-#ifdef USE_LIBMOUNT_MOUNTFD_SUPPORT + { + struct libmnt_sysapi *api = mnt_context_get_sysapi(cxt); + +@@ -327,7 +326,6 @@ static int hook_mount_post( + DBG(HOOK, ul_debugobj(hs, " reuse tree FD")); + } + } +-#endif + if (fd_tree < 0) + fd_tree = mnt_open_tree(AT_FDCWD, target, + OPEN_TREE_CLONE | OPEN_TREE_CLOEXEC | +@@ -544,4 +542,4 @@ const struct libmnt_hookset hookset_idmap = + .deinit = hookset_deinit + }; + +-#endif /* HAVE_MOUNTFD_API && HAVE_LINUX_MOUNT_H */ ++#endif /* USE_LIBMOUNT_MOUNTFD_SUPPORT */ +diff --git a/libmount/src/hooks.c b/libmount/src/hooks.c +index 23eca4efd..5ae91edd7 100644 +--- a/libmount/src/hooks.c ++++ b/libmount/src/hooks.c +@@ -45,7 +45,7 @@ static const struct libmnt_hookset *const hooksets[] = + &hookset_mount, + #endif + &hookset_mount_legacy, +-#if defined(HAVE_MOUNTFD_API) && defined(HAVE_LINUX_MOUNT_H) ++#ifdef USE_LIBMOUNT_MOUNTFD_SUPPORT + &hookset_idmap, + #endif + &hookset_owner +diff --git a/libmount/src/version.c b/libmount/src/version.c +index 3b61618b5..5c70ebf8a 100644 +--- a/libmount/src/version.c ++++ b/libmount/src/version.c +@@ -37,7 +37,7 @@ static const char *lib_features[] = { + #ifdef USE_LIBMOUNT_SUPPORT_NAMESPACES + "namespaces", + #endif +-#if defined(HAVE_MOUNTFD_API) && defined(HAVE_LINUX_MOUNT_H) ++#ifdef USE_LIBMOUNT_MOUNTFD_SUPPORT + "idmapping", + #endif + #ifdef USE_LIBMOUNT_MOUNTFD_SUPPORT +diff --git a/sys-utils/mount.8.adoc b/sys-utils/mount.8.adoc +index add2914ae..4bc1bb0f9 100644 +--- a/sys-utils/mount.8.adoc ++++ b/sys-utils/mount.8.adoc +@@ -790,6 +790,7 @@ Set _mountpoint_'s mode after mounting. + + *X-mount.idmap*=__id-type__:__id-mount__:__id-host__:__id-range__ [__id-type__:__id-mount__:__id-host__:__id-range__], *X-mount.idmap*=__file__:: + Use this option to create an idmapped mount. ++This feature requires the new file-descriptor-based mount API (available since Linux 5.2). + An idmapped mount allows to change ownership of all files located under a mount according to the ID-mapping associated with a user namespace. + The ownership change is tied to the lifetime and localized to the relevant mount. + The relevant ID-mapping can be specified in two ways: diff --git a/meta/recipes-core/util-linux/util-linux_2.41.5.bb b/meta/recipes-core/util-linux/util-linux_2.41.6.bb similarity index 100% rename from meta/recipes-core/util-linux/util-linux_2.41.5.bb rename to meta/recipes-core/util-linux/util-linux_2.41.6.bb From patchwork Sun Oct 11 08:40:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100321 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B4CAFCA9EC7 for ; Sun, 11 Oct 2026 08:41:28 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23576.1791708087852152830 for ; Sun, 11 Oct 2026 01:41:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xeumlKDz; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4a0213948d3so5922865e9.2 for ; Sun, 11 Oct 2026 01:41:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708086; x=1792312886; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=MGV9SwW0n+TV2tCg77WAWatGSVfuRSXCp7XUN50HmTk=; b=xeumlKDzp9KIBrbmn0Eid48FHX+xHE8q9JCH14ec0cmRA8YfEtlmjg/D5ht6dt1WdK p2Ft2bmgHHZxvd/5GJfYuU5zVCPQGfwLOe0bTdqCHaa2+Vu4k1dXecTWaF9wD1dPcUXl 8EgccGU7feKFCru8GIKtbwDypTyZfj/LNdj88= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708086; x=1792312886; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=MGV9SwW0n+TV2tCg77WAWatGSVfuRSXCp7XUN50HmTk=; b=IZj9zi9x1Sh+hUbrbC1y4yp8qmHYcQrzDSsahcRhcCTqycoT4YHfkciN/DJ4Djl1IJ AxWmTxH/3XaKsbMN+rJmBZj9owXr4+VayW45u+j5OJnVBd5dzdPiNOGEPirJahZhm6Sr Admp9hKbSqXV4NtqKYaz8yAB3DIZPSyrht2EKPVPkTSv2lKgOzbZn+E1j5PjLi930fTS 03FTb4LJL9+8NrrPKUUzVVjhgOjg162jZFbEnzblBfIs+QDhmnGRlWwLMFjXai49CD4+ DxgxcpPqnIwtqTPuugrYbaRPFHPdRqO3PJvIW92a2bpZVKnAdJ2e5XGA5wiHsp2IIuYj aX8A== X-Gm-Message-State: AFq9FYIdLjCmfmwFrJqF0Rag60sjCiH2brMVLeOXqhkISfXNojvxVRRJ amY2ux8Sbs717l7P/uSuX1prO3ooOn2Y5fZJLDJMKlCIEe2NAMem/ZNv75M/hciSUai+DczdKE2 39JV4MT4= X-Gm-Gg: AYBFou2fBrYMd34DxLYvKrVO6T5l+wVi2Bue/gU197RavfcVU34S4SLxHda/hvz1M06 tfopahNpUfuOgSdkPUX/q/DBFlMafEytHzwtt5A0CPwCaP87NAyjHSwNl41fi/kh84OkbOk+p3u A/4lIl08cfQc3V+JW41ODE1xiBn85NvhF+I6stpKIKHj3p6XcjM5YCXToSqMAxS2aHfvB9CKvgo oG6kXw8SMX6Wg9IFZtNU0iJxPf2hBT+dQgPuydW/XhFT4IdUiiegfszshvfSfOwpukpNumVyCef 682eO/CDPygLOc2RmD51pV2gFk2j3NteA4s4n2c3+dnJhQEaqvwf2wd9WoZAs4ehk6OudrctBog HrzZcHoZzAweCxBIUmWlykA7eOW2aaAwgAJuBHOWxJNv+O82nT99WIGiyzYmqOah2qLWYBnmrVK 0YYUqlGt+M64HqamMfZSNFDClsUnNGYvCaos+tX2udCxJjiiLNXRjGIdnH7otUpvb3p0+scrNEf j74tELaPH4TSMKWiw7ZB/j4uHyfc5ThBfaS503JeJO48q8gO1gSzlxqaCGY1R3LyUoVmwsHRw== X-Received: by 2002:a05:600c:64c7:b0:49f:ff32:803c with SMTP id 5b1f17b1804b1-4a18e49c536mr117069305e9.16.1791708086068; Sun, 11 Oct 2026 01:41:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 38/60] qemuriscv.inc: default to fw_dynamic.elf as QEMU BIOS Date: Sun, 11 Oct 2026 10:40:11 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247547 From: Harish Sadineni QEMU RISC-V can hang at boot when using fw_jump.elf as the BIOS if the kernel Image is large enough to overlap the memory region where the FDT (device tree blob) is loaded. This was observed with KERNEL_DEBUG-enabled 6.18 kernel builds, which inflate the Image size (e.g. ~27M -> ~33M on qemuriscv64), but the underlying issue is not specific to KERNEL_DEBUG or to any one kernel version, it is a property of fw_jump.elf's fixed compile-time boot address layout which does not adapt to a larger next-stage image. This was confirmed by dumping guest memory from the QEMU monitor at the kernel load address and finding the FDT magic number (0xd00dfeed, see scripts/dtc/libfdt/fdt.h) sitting where kernel code should be, i.e. the DTB and Image had started to overlap [1]. fw_dynamic.elf instead receives next-stage boot information at runtime from the prior boot stage rather than assuming a fixed address, avoiding this overlap. [1] https://lists.openembedded.org/g/openembedded-core/message/246090 [YOCTO #16409] Suggested-by: Trevor Gamblin Signed-off-by: Harish Sadineni Signed-off-by: Antonin Godard Signed-off-by: Richard Purdie (cherry picked from commit 51b72fb2e8917a8627023f419b27a1d83132a361) Signed-off-by: Harish Sadineni Signed-off-by: Yoann Congal --- meta/conf/machine/include/riscv/qemuriscv.inc | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/meta/conf/machine/include/riscv/qemuriscv.inc b/meta/conf/machine/include/riscv/qemuriscv.inc index bac376ce5a8..d8522fd552e 100644 --- a/meta/conf/machine/include/riscv/qemuriscv.inc +++ b/meta/conf/machine/include/riscv/qemuriscv.inc @@ -29,7 +29,10 @@ QB_SMP ?= "-smp 4" QB_KERNEL_CMDLINE_APPEND = "earlycon=sbi" QB_CPU:riscv64 ?= "-cpu rva23s64,pmp=true" QB_MACHINE = "-machine virt" -QB_DEFAULT_BIOS = "fw_jump.elf" +# fw_jump.elf's memory layout can be overrun by a sufficiently large kernel Image, +# causing it to overlap the FDT load address and hang QEMU at boot (see [YOCTO #16409]), +# so use fw_dynamic.elf in that case instead, which avoids the overlap. +QB_DEFAULT_BIOS = "fw_dynamic.elf" QB_TAP_OPT = "-netdev tap,id=net0,ifname=@TAP@,script=no,downscript=no" QB_NETWORK_DEVICE = "-device virtio-net-device,netdev=net0,mac=@MAC@" QB_ROOTFS_OPT = "-drive id=disk0,file=@ROOTFS@,if=none,format=raw -device virtio-blk-device,drive=disk0" From patchwork Sun Oct 11 08:40:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100328 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BD5BBCA9ED7 for ; Sun, 11 Oct 2026 08:41:29 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23577.1791708088427987845 for ; Sun, 11 Oct 2026 01:41:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QyFw8W0v; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-48c4d870d54so487174f8f.2 for ; Sun, 11 Oct 2026 01:41:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708087; x=1792312887; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=K3WbsvUORKZ/20/6gUhi+3d/uow9CTxOfJbCz6ZdZRE=; b=QyFw8W0veYWmRDm7A7A2fDkFlIvicEmO93je2NSIfuxnsEyva6tAtOFzziS1783VWc oQZMbuHDuYsMfH21O98jhJApw+LClbINKWSMUhvmzqYaL5JoEGLhcMlv6d47X6q2tPOy d40ETG9Fr+Z288zY5w4S3cNCmjA58htrh1/Qo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708087; x=1792312887; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=K3WbsvUORKZ/20/6gUhi+3d/uow9CTxOfJbCz6ZdZRE=; b=ue4VDVFHEBg4ABmyCXl5K6wQ0X1fub/X2mD/3hPIZ1AhvMPbXabzGZXIok7Y/MdGaW IS8Eidqbs/jsLMpk4s3xTekBQHj5DVuNEXxsrW3i+0Z8E1Lu2YDyBR7vZ/tr2s/CTagR GasbzamgLCl9ZRvcr5ln5Xnn5JfKVaaWh6FaWRK5l4OWGv4V63246s6Yhl7M5rH5HQs8 Ih5RqDeeYarMj5897MlnRD3ud5K7vm+uuWXxEde5n8dECaX1/rb7tDayGmyhOtEwrJrH 9qV019W9/h2Ude1e4ikyD1Utqpk00qJkbEUE+L6D7ej/4sahhkiQQ+qAN83f4ekyKQVa 9sXQ== X-Gm-Message-State: AFq9FYL/kE8GqUs2h+Xkhiw+j6oj7up9gu9U0ADrnpze5bRv42kQYXP1 FwADDGWEM1J3xTwhJi3YKgAnQChFy8xn9OMRwcDD+Pbr4yiwWMTDUUZdwZZwTXGC+vD/1lgQq4U LLFXmiG0= X-Gm-Gg: AYBFou3wzC1UQnQ3neegdVGmrjvy/nhW3hhjx76EJzrqJSBU8rIAQfdPQYXOwYVJzoi 508NU/S/9/9HYNh7AITLuyBlmrknDh4eycoVAVzgsCGX+0MbV7CbK9CPR+GKdiQjd6Ehj9uVQXG oHQohmptJFE/uNZmvJY+8oc+KQ1H/RemUiudTEX8FFq8sj8iNbavQh3dIwLi4X2574WOm+HKsG/ N56uwmFN/AwBl3yseLTGJh77f3Fx+Ta5togD+gCJLnD1cpRxNcz9eDzFevnZ1OI/2XYCz/RsaJF lEc5MEGMJsrKbTI/ClqyuhBUElfPsTtH/S3Mf5MdJ9l38JJ05l4VoUXx7n3zU8hlb4VIh13XbdY STaqUCjoP82JJrVZh9u2I8rAeJzGCUTwe/118qB7LhWkurszFkH0derMqVGrpTMo0Vq2mIxSCKi eTRArvnO21rKrGRCdw7H6n27zpHUKKtVvb1Gvf9C/3yM3TyBxiNsL6f9tc/s6QKQBfTTB1ZZF1E 0mHg//G2il9cOsZ6vfAZyDFtKq3+rH5w7Vztb1qMJC6YCjd+8dUSfsgkOj4KYQg1zc6QtIsRQ== X-Received: by 2002:a05:6000:2991:20b0:48c:4e9e:dc7 with SMTP id ffacd0b85a97d-48dbaced3c8mr8355579f8f.42.1791708086543; Sun, 11 Oct 2026 01:41:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 39/60] libsolv: patch CVE-2026-48863 Date: Sun, 11 Oct 2026 10:40:12 +0200 Message-ID: <7dc8f3f4f1a4e62ed04bd1f68847f6eefc941973.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247548 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-48863 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libsolv/libsolv/CVE-2026-48863.patch | 25 +++++++++++++++++++ .../libsolv/libsolv_0.7.36.bb | 1 + 2 files changed, 26 insertions(+) create mode 100644 meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch diff --git a/meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch b/meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch new file mode 100644 index 00000000000..131d035b408 --- /dev/null +++ b/meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch @@ -0,0 +1,25 @@ +From 44f8c085045b1f771641091bbb2b810d12cff9e8 Mon Sep 17 00:00:00 2001 +From: Michael Schroeder +Date: Tue, 26 May 2026 10:30:31 +0200 +Subject: [PATCH] Fix wrong variable being used in solv_pgpvrfy + +CVE: CVE-2026-48863 +Upstream-Status: Backport [https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8] +Signed-off-by: Peter Marko +--- + ext/solv_pgpvrfy.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/ext/solv_pgpvrfy.c b/ext/solv_pgpvrfy.c +index 9f1bd72e..9358558b 100644 +--- a/ext/solv_pgpvrfy.c ++++ b/ext/solv_pgpvrfy.c +@@ -589,7 +589,7 @@ solv_pgpvrfy(const unsigned char *pub, int publ, const unsigned char *sig, int s + if (rlen) + memcpy(sigdata + 32 - rlen, r, rlen); + if (slen) +- memcpy(sigdata + 64 - slen, s, rlen); ++ memcpy(sigdata + 64 - slen, s, slen); + res = mped25519(pub + 1 + 10 + 2 + 1, sigdata, sig + 2, hashl); + break; + } diff --git a/meta/recipes-extended/libsolv/libsolv_0.7.36.bb b/meta/recipes-extended/libsolv/libsolv_0.7.36.bb index cca2511ea57..b6704a3d3bb 100644 --- a/meta/recipes-extended/libsolv/libsolv_0.7.36.bb +++ b/meta/recipes-extended/libsolv/libsolv_0.7.36.bb @@ -13,6 +13,7 @@ SRC_URI = "git://github.com/openSUSE/libsolv.git;branch=master;protocol=https;ta file://run-ptest \ file://CVE-2026-9150.patch \ file://CVE-2026-9149.patch \ + file://CVE-2026-48863.patch \ " SRCREV = "1e377699be108ec82bb798ec9c223d45d84a733c" From patchwork Sun Oct 11 08:40:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100349 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A8B76CA9EDC for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23578.1791708089180511505 for ; Sun, 11 Oct 2026 01:41:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XLFkzY3A; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-48afcd7ba9bso526360f8f.3 for ; Sun, 11 Oct 2026 01:41:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708087; x=1792312887; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5gG7Et9uPnCeX6lRaluTF0fSQ7mKVwIZFeuZCKBQaOM=; b=XLFkzY3A3xTOESK+8vQA/6b/dIuvV014mBfxGVjUxxhVpViayp1wQns02WLWQVzmCo K6PJR/wUbZPmPit3TIrDT8XOnUX8bacbp9W4uWwYwXXJxJ1/Cb+4IdCUYXcZpPNdk65l djqYhL6EmS2rfAkQHbftJ+/lPmK/OpQ47oZJ0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708087; x=1792312887; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5gG7Et9uPnCeX6lRaluTF0fSQ7mKVwIZFeuZCKBQaOM=; b=cLWwfBEBURYipx/tMvT6AstkFriFJ5Ib++9BCCQrHkW8RKxL9srSdI0oEzfjcCd/IW x6PkDRoinPjV1REGzLx5XqKWg1HkFlSDegZ43xkNpoUXcpaDHxnRG5mALQrPrYbYb65y 7sKdZx9Mr1eQag6HItxaOpN0hsFfdH98xjG4wvCXI5QjLbZJfe7K+Cqjfk6vs1k28aPb h5XdAmZ9WRTjkV8DUQxZlcOGT3aLjFUjYJYNawx9vfZLAw0z/oORs81hMIO18PxD+e87 1fVmF8BTLRWI8PeGfadc1BWj0fHMwj8A8kAT1328bInoBvuv6upVPVbCiuEw4hmewK+d bwNQ== X-Gm-Message-State: AFq9FYJEIq6brOGW1TrFrCrxp+OBJA9CO0zLdIsO4/0sEMksTsXUP1pD 2CnCOTtlPWA6SpH9KLcKAOis78sX5IlERErCseEnaKREFV2kDC8DxzkI20qH925B096KrThRFS1 +t6nA0Cw= X-Gm-Gg: AYBFou2LnJ+Bed2T/sBbwh7cJvSCW1qix6hPvJTrDOMA+P0l1viHK3vmR+jEAVreRFT h26q2Th0dRyEKfZz06Dl4FIZ++VAgXnaTrlMueZ3GrGV5GDG5N29CnFLk/ObrNkRjSISgAYfHlb YIZ3YXY/cNw/FlSeALXpPAHksHd926W8N/PFS0dBrVfL4GNVJhO3/KqPwp1bkfNq3GNXjMos22f 3oDh64y/ndaDmLYD7/NZSA2uF9wPzdjBQBNqlQBWTNFHY44ZI3PsbTA07RvNlydMaBWop/3y0dC +prYDNeMVR/BfIjbFF3Q8YFIk6N7FaADFG3W19flr/4RVlwudDr2k5a6tEBsNH2XrpM7JFHZo/4 9Wkq1K2wgaRyGKxxsZ+JhXor+Z8UzFD+/A7LyctQz0D6ykcVOA4fy7zSGz/VPCxsOJJCa1yX1ke tB2KnPFuCC5X6OqtuMqAL5tzPIOqM8EJLh36PFq6hlwSHE5Qi+4+KbADnj0JuyeYJxrKGPckgSp 6MDJW7l1r5k0MuFzzK8BYJNEZrGpv/gYjFhNYQkrgnODoa9PGiUE3k3O7XRrlasVaMFJtspjQ== X-Received: by 2002:adf:e012:0:10b0:48c:4d32:ccfd with SMTP id ffacd0b85a97d-48dba7845d7mr8320510f8f.6.1791708087070; Sun, 11 Oct 2026 01:41:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 40/60] expat: patch CVE-2026-66046 and CVE-2026-76641 Date: Sun, 11 Oct 2026 10:40:13 +0200 Message-ID: <132d54c85a8ad4611539c83d2b32b9d0b5de40a6.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247549 From: Peter Marko Pick patches per [1] and [2]. (fix for CVE-2026-66046 introduces CVE-2026-76641) [1] https://security-tracker.debian.org/tracker/CVE-2026-66046 [2] https://security-tracker.debian.org/tracker/CVE-2026-76641 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: fixed CVE: tags in CVE-2026-66046-{01,02}.patch ] --- .../expat/expat/CVE-2026-66046-01.patch | 107 ++++++++++++ .../expat/expat/CVE-2026-66046-02.patch | 90 ++++++++++ .../expat/expat/CVE-2026-76641.patch | 160 ++++++++++++++++++ meta/recipes-core/expat/expat_2.8.3.bb | 3 + 4 files changed, 360 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-01.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-02.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76641.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-66046-01.patch b/meta/recipes-core/expat/expat/CVE-2026-66046-01.patch new file mode 100644 index 00000000000..e7b3d467899 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-66046-01.patch @@ -0,0 +1,107 @@ +From 98f5acc146af76859cd7c345c0906e9e9e8ea656 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Thu, 13 Aug 2026 15:47:24 +0200 +Subject: [PATCH] lib: Rename hash table `defaultAttsNames` to + `defaultAttForName` + +It was previously used as a "set". This prepares for the upcoming +change to a true "dictionary". + +CVE: CVE-2026-66046 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 24 ++++++++++++------------ + 1 file changed, 12 insertions(+), 12 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index e5242480..239dc6de 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -394,7 +394,7 @@ typedef struct { + size_t nDefaultAtts; + size_t allocDefaultAtts; + DEFAULT_ATTRIBUTE *defaultAtts; +- HASH_TABLE defaultAttsNames; ++ HASH_TABLE defaultAttForName; + } ELEMENT_TYPE; + + typedef struct { +@@ -3837,8 +3837,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, + sizeof(ELEMENT_TYPE)); + if (! elementType) + return XML_ERROR_NO_MEMORY; +- if (! elementType->defaultAttsNames.parser) +- hashTableInit(&(elementType->defaultAttsNames), parser); ++ if (! elementType->defaultAttForName.parser) ++ hashTableInit(&(elementType->defaultAttForName), parser); + if (parser->m_ns && ! setElementTypePrefix(parser, elementType)) + return XML_ERROR_NO_MEMORY; + } +@@ -7239,7 +7239,7 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, + /* The handling of default attributes gets messed up if we have + a default which duplicates a non-default. */ + NAMED *const nameFound +- = lookup(parser, &(type->defaultAttsNames), attId->name, 0); ++ = lookup(parser, &(type->defaultAttForName), attId->name, 0); + if (nameFound) + return 1; + if (isId && ! type->idAtt && ! attId->xmlns) +@@ -7276,7 +7276,7 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, + attId->maybeTokenized = XML_TRUE; + + NAMED *const nameAddedOrFound +- = lookup(parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED)); ++ = lookup(parser, &(type->defaultAttForName), attId->name, sizeof(NAMED)); + if (! nameAddedOrFound) + return 0; + +@@ -7597,7 +7597,7 @@ dtdReset(DTD *p, XML_Parser parser) { + ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); + if (! e) + break; +- hashTableDestroy(&(e->defaultAttsNames)); ++ hashTableDestroy(&(e->defaultAttForName)); + FREE(parser, e->defaultAtts); + } + hashTableClear(&(p->generalEntities)); +@@ -7639,7 +7639,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) { + ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); + if (! e) + break; +- hashTableDestroy(&(e->defaultAttsNames)); ++ hashTableDestroy(&(e->defaultAttForName)); + FREE(parser, e->defaultAtts); + } + hashTableDestroy(&(p->generalEntities)); +@@ -7732,8 +7732,8 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, + if (! newE) + return 0; + +- if (! newE->defaultAttsNames.parser) +- hashTableInit(&(newE->defaultAttsNames), parser); ++ if (! newE->defaultAttForName.parser) ++ hashTableInit(&(newE->defaultAttForName), parser); + + if (oldE->nDefaultAtts) { + /* Detect and prevent integer overflow. */ +@@ -7766,7 +7766,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, + } else + newE->defaultAtts[i].value = NULL; + +- NAMED *const nameAddedOrFound = lookup(parser, &(newE->defaultAttsNames), ++ NAMED *const nameAddedOrFound = lookup(parser, &(newE->defaultAttForName), + attributeName, sizeof(NAMED)); + if (! nameAddedOrFound) { + return 0; +@@ -8535,8 +8535,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr, + sizeof(ELEMENT_TYPE)); + if (! ret) + return NULL; +- if (! ret->defaultAttsNames.parser) +- hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL)); ++ if (! ret->defaultAttForName.parser) ++ hashTableInit(&(ret->defaultAttForName), getRootParserOf(parser, NULL)); + if (ret->name != name) + poolDiscard(&dtd->pool); + else { diff --git a/meta/recipes-core/expat/expat/CVE-2026-66046-02.patch b/meta/recipes-core/expat/expat/CVE-2026-66046-02.patch new file mode 100644 index 00000000000..90e10514b50 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-66046-02.patch @@ -0,0 +1,90 @@ +From f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Thu, 13 Aug 2026 16:39:35 +0200 +Subject: [PATCH] lib: Migrate .isCdata lookup from a linear loop to a hash + table lookup + +.. to resolve quadratic runtime + +CVE: CVE-2026-66046 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 48 ++++++++++++++++++++++++++++++++++++++++-------- + 1 file changed, 40 insertions(+), 8 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 239dc6de..1cd20125 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -381,6 +381,22 @@ typedef struct { + const XML_Char *value; + } DEFAULT_ATTRIBUTE; + ++// This structure allows mapping attribute names to instances of ++// `DEFAULT_ATTRIBUTE`. ++typedef struct { ++ // Member `name` goes first to make this structure compatible with structure ++ // `NAMED` (further up), which is needed to support use of structure ++ // `NAME_AND_DEFAULT_ATTRIBUTE` in a hash table as implemented by function ++ // `lookup` (further down). ++ const XML_Char *name; ++ // We would store a `DEFAULT_ATTRIBUTE *` here but the backing array ++ // can be reallocated which would invalidate the pointer. Using an index ++ // into the array instead, avoids that problem. ++ size_t attIndex; ++ // This is set to `false` by function `lookup`. ++ bool initialized; ++} NAME_AND_DEFAULT_ATTRIBUTE; ++ + typedef struct { + unsigned long version; + unsigned long hash; +@@ -3951,11 +3967,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, + + /* figure out whether declared as other than CDATA */ + if (attId->maybeTokenized) { +- for (size_t j = 0; j < nDefaultAtts; j++) { +- if (attId == elementType->defaultAtts[j].id) { +- isCdata = elementType->defaultAtts[j].isCdata; +- break; +- } ++ NAME_AND_DEFAULT_ATTRIBUTE *const nameAndDefaultAttribute ++ = (NAME_AND_DEFAULT_ATTRIBUTE *)lookup( ++ parser, &(elementType->defaultAttForName), attId->name, 0); ++ if (nameAndDefaultAttribute != NULL) { ++ assert(nameAndDefaultAttribute->attIndex < elementType->nDefaultAtts); ++ const DEFAULT_ATTRIBUTE *const att ++ = elementType->defaultAtts + nameAndDefaultAttribute->attIndex; ++ isCdata = att->isCdata; + } + } + +@@ -7275,11 +7294,24 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, + if (! isCdata) + attId->maybeTokenized = XML_TRUE; + +- NAMED *const nameAddedOrFound +- = lookup(parser, &(type->defaultAttForName), attId->name, sizeof(NAMED)); +- if (! nameAddedOrFound) ++ NAME_AND_DEFAULT_ATTRIBUTE *const nameAndDefaultAttribute ++ = (NAME_AND_DEFAULT_ATTRIBUTE *)lookup( ++ parser, &(type->defaultAttForName), attId->name, ++ sizeof(NAME_AND_DEFAULT_ATTRIBUTE)); ++ if (! nameAndDefaultAttribute) + return 0; + ++ assert(nameAndDefaultAttribute->name == attId->name); ++ ++ // NOTE: The XML 1.0r4 spec says: ++ // "When more than one definition is provided for the same attribute of a ++ // given element type, the first declaration is binding and later ++ // declarations are ignored." ++ if (! nameAndDefaultAttribute->initialized) { ++ nameAndDefaultAttribute->attIndex = type->nDefaultAtts; ++ nameAndDefaultAttribute->initialized = true; ++ } ++ + type->nDefaultAtts += 1; + return 1; + } diff --git a/meta/recipes-core/expat/expat/CVE-2026-76641.patch b/meta/recipes-core/expat/expat/CVE-2026-76641.patch new file mode 100644 index 00000000000..26fa5704a6e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-76641.patch @@ -0,0 +1,160 @@ +From 98599f6dcc2b460410881fe420f5f55d6bec63bf Mon Sep 17 00:00:00 2001 +From: Zeyou Liu +Date: Thu, 20 Aug 2026 20:29:56 +0800 +Subject: [PATCH] lib: Fix out-of-bounds read from hash table entries created + by dtdCopy + +Commit f8f7c4ff grew the entries of ELEMENT_TYPE member +.defaultAttForName from structure NAMED to the larger structure +NAME_AND_DEFAULT_ATTRIBUTE and adjusted function defineAttribute +accordingly, but function dtdCopy kept creating entries of size +sizeof(NAMED). Because function lookup allocates exactly createSize +bytes, function storeAtts reads member .attIndex past the end of those +entries whenever attributes are parsed by a parser that was created by +XML_ExternalEntityParserCreate. + +That out-of-bounds value is then used as an index into member +.defaultAtts, so the effects range from silently not normalizing +whitespace in attributes that are not of type CDATA, to dereferencing a +wild pointer: a release build of master segfaults in function storeAtts +on the document used by the new test. A zero-filled heap happens to +yield index 0, which is why the existing tests did not catch this. + +Member .attIndex is now stored the way function defineAttribute stores +it, i.e. keeping the index of the first declaration, so that a copied +DTD resolves attributes exactly like the DTD that it was copied from. + +This was found while backporting the fix for CVE-2026-66046 onto Expat +2.6.4 for the OpenCloudOS Stream distribution. Only master is affected, +no released version of Expat contains commit f8f7c4ff. + +CVE: CVE-2026-76641 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 17 +++++++-- + tests/basic_tests.c | 74 +++++++++++++++++++++++++++++++++++++++ + 2 files changed, 88 insertions(+), 3 deletions(-) + +diff --git a/lib/xmlparse.c b/expat/lib/xmlparse.c +index 10592ac3..e72c4570 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -7800,11 +7800,22 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, + } else + newE->defaultAtts[i].value = NULL; + +- NAMED *const nameAddedOrFound = lookup(parser, &(newE->defaultAttForName), +- attributeName, sizeof(NAMED)); +- if (! nameAddedOrFound) { ++ NAME_AND_DEFAULT_ATTRIBUTE *const nameAndDefaultAttribute ++ = (NAME_AND_DEFAULT_ATTRIBUTE *)lookup( ++ parser, &(newE->defaultAttForName), attributeName, ++ sizeof(NAME_AND_DEFAULT_ATTRIBUTE)); ++ if (! nameAndDefaultAttribute) { + return 0; + } ++ ++ // NOTE: The XML 1.0r4 spec says: ++ // "When more than one definition is provided for the same attribute of a ++ // given element type, the first declaration is binding and later ++ // declarations are ignored." ++ if (! nameAndDefaultAttribute->initialized) { ++ nameAndDefaultAttribute->attIndex = i; ++ nameAndDefaultAttribute->initialized = true; ++ } + } + } + +diff --git a/tests/basic_tests.c b/expat/tests/basic_tests.c +index 308adf6c..6c2d3280 100644 +--- a/tests/basic_tests.c ++++ b/tests/basic_tests.c +@@ -2809,6 +2809,79 @@ START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) { + } + END_TEST + ++static void XMLCALL ++check_second_attr_normalization(void *userData, const XML_Char *name, ++ const XML_Char **atts) { ++ int *const seen_second = userData; ++ UNUSED_P(name); ++ ++ for (size_t i = 0; atts[i] != NULL; i += 2) { ++ const XML_Char *const key = atts[i]; ++ const XML_Char *const value = atts[i + 1]; ++ if (xcstrcmp(key, XCS("second")) != 0) ++ continue; ++ *seen_second = 1; ++ /* Attribute "second" is not of type CDATA, so leading, trailing and ++ * repeated whitespace is to be normalized away. */ ++ if (xcstrcmp(value, XCS("a b")) != 0) ++ fail("Attribute of non-CDATA type was not whitespace-normalized"); ++ } ++} ++ ++static int XMLCALL ++external_entity_attr_checker(XML_Parser parser, const XML_Char *context, ++ const XML_Char *base, const XML_Char *systemId, ++ const XML_Char *publicId) { ++ const char *const text = ""; ++ UNUSED_P(base); ++ UNUSED_P(systemId); ++ UNUSED_P(publicId); ++ ++ XML_Parser ext_parser = XML_ExternalEntityParserCreate(parser, context, NULL); ++ if (ext_parser == NULL) ++ fail("Could not create external entity parser"); ++ ++ if (_XML_Parse_SINGLE_BYTES(ext_parser, text, (int)strlen(text), XML_TRUE) ++ != XML_STATUS_OK) ++ xml_failure(ext_parser); ++ ++ XML_ParserFree(ext_parser); ++ return XML_STATUS_OK; ++} ++ ++START_TEST(test_default_attr_index_after_dtd_copy) { ++ /* Function storeAtts resolves member .attIndex of structure ++ * NAME_AND_DEFAULT_ATTRIBUTE to tell whether an attribute value needs ++ * whitespace normalization, so function dtdCopy needs to carry that index ++ * over to the copy. Attribute "first" is declared before attribute ++ * "second" so that a mixed-up index resolves to the wrong declaration. ++ */ ++ const char *text = "\n" ++ " \n" ++ " \n" ++ " \n" ++ " \n" ++ "]>\n" ++ "&e;\n"; ++ int seen_second = 0; ++ ++ XML_Parser parser = XML_ParserCreate(NULL); ++ assert_true(parser != NULL); ++ XML_SetUserData(parser, &seen_second); ++ XML_SetExternalEntityRefHandler(parser, external_entity_attr_checker); ++ XML_SetStartElementHandler(parser, check_second_attr_normalization); ++ ++ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) ++ != XML_STATUS_OK) ++ xml_failure(parser); ++ if (! seen_second) ++ fail("Attribute \"second\" has not been reported"); ++ ++ XML_ParserFree(parser); ++} ++END_TEST ++ + /* Test reset works correctly in the middle of processing an internal + * entity. Exercises some obscure code in XML_ParserReset(). + */ +@@ -6737,6 +6810,7 @@ make_basic_test_case(Suite *s) { + tcase_add_test(tc_basic, + test_duplicate_cdata_attribute_multiple_attlistdecl_3); + tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl); ++ tcase_add_test__if_xml_ge(tc_basic, test_default_attr_index_after_dtd_copy); + tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity); + tcase_add_test(tc_basic, test_resume_invalid_parse); + tcase_add_test(tc_basic, test_resume_resuspended); diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb index 79e8c15227a..5d30a844fa0 100644 --- a/meta/recipes-core/expat/expat_2.8.3.bb +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -10,6 +10,9 @@ VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}" SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://run-ptest \ + file://CVE-2026-66046-01.patch \ + file://CVE-2026-66046-02.patch \ + file://CVE-2026-76641.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Sun Oct 11 08:40:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100336 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3ECCCA9ECF for ; Sun, 11 Oct 2026 08:41:39 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23451.1791708089591590942 for ; Sun, 11 Oct 2026 01:41:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qEpIU3T0; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-4a02718da81so7072815e9.1 for ; Sun, 11 Oct 2026 01:41:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708088; x=1792312888; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Nh7UOtNWe5PyzALQ/UflpgcpJ7Ps7/WRN8jlHbzohwI=; b=qEpIU3T0vnIqsJ0iDT5cOuiD1gEMWzLMske0TAwQRk9Pk5ZEGT2mgwBq6M89g9qWGm NvNny/LxE2EUwm1hu3oeo5WVVQmmSJuF6OYU+V0kvLc3iGHEEy2qYepjKPllZ2n030/6 ghvYJCiWaNpIAZWSlaUurRgmm5+lmc99h1vvU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708088; x=1792312888; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Nh7UOtNWe5PyzALQ/UflpgcpJ7Ps7/WRN8jlHbzohwI=; b=A6cyuaAPYij1PNIUDSULm2G2kf6ngr0Rc34viBJ41GV75/XhfS4WzF76Be3YE6xcU0 j/PB/09pg2gys+Ebo09BrqddUUeaCBQNhNRa1RG9dNsT5QBfoJgmhFktEuEcjWVqqnRF 3MOv6CTtNZmWKyXq0qFnUPlDBrs2YC+8H2OJAP1M/cT1W423xMSGrUaxa6q3IG1a9PGH 7MWEM9k09/d8lCNxVvurCySMkuyLlL7Z4wmkxQv6lsV8Y43fg6WDNCMjNgRY+caGXnkJ XIUu5W6o9VLnVTCLIH9E9L22q052YJT3sjDBvZmQDJdMW9+RwF4iLQM+RQEWMykXFwQt 5Slg== X-Gm-Message-State: AFq9FYIDiiBDEPk51T1N0a7pxwfkzxSbajyn2B5nlyNRtwdFXuUURD9J H33nwLCkf7CNL/wWyVmFi92J94fYZjlDUW7YnbQXqvMSUvMdpX6IXzNatmhQ2PNG4yD/+f9iOHn 62kmgphI= X-Gm-Gg: AYBFou3jrMVwvqVDidJ9Gjbu+1DrRAz6Y9D3XHAwmth2Kzd/Ao3jwoVcaWqwQ5z+fj+ fZuQIhn+4hxoIwyfXERjQ/q6CnhiilSVfw8Q2mjTRqmWFxIYI9RERErAlGzcM/ilROvClrt3OAS KXTf32w7rCV3iSOQK7IqH1Lwv/8hFPjenYwPgbDvOSWVmYC4/dzryuZ++50tId1vB1MSKAQM5xl hG+tJMLqQVqqZtmU0vrSrVwQ6g2+KVSyYx2FD3YASpj9TWARvQT1+VMxls1GnoJuYkHFtFmZCTV Lw4qG9pIlOs2KEMeLlIDbqITw75G/NSJVDS33qI075BUWPl7flAABkqQFivp7pq/yDQ1A1p6hQu +CgQr5xshIqREQEHaf+7h/CekOjNaNtHqRBT6GtmNhHwnQwpBbGhuKmFghW8xkYiVxdm9NGKTCT RAm8zcuomVNxZBPL7VKY+KB4Vahbtj/Nv/jRYem+hg8C7+jXtPZVR6mkas0Dqk4CqYHl90H/UTI 8AWXT7WqDZhbn7YL4mBDNbrvOWixf7+cq8eQQ1tpbv+Bn4IVm997HOwnHBXZ1VW3VpW24tmJw== X-Received: by 2002:a05:600c:3554:b0:49e:6778:c2bd with SMTP id 5b1f17b1804b1-4a18e4a01a1mr121078365e9.6.1791708087725; Sun, 11 Oct 2026 01:41:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 41/60] expat: patch CVE-2026-76956 Date: Sun, 11 Oct 2026 10:40:14 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247550 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-76956 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-76956.patch | 26 +++++++++++++++++++ meta/recipes-core/expat/expat_2.8.3.bb | 1 + 2 files changed, 27 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76956.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-76956.patch b/meta/recipes-core/expat/expat/CVE-2026-76956.patch new file mode 100644 index 00000000000..96d9b68ee7c --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-76956.patch @@ -0,0 +1,26 @@ +From 40daa9996d616e66a75dea41ed2b18f2c3901b9f Mon Sep 17 00:00:00 2001 +From: Sorrachat <32319737+Sorrashut-K@users.noreply.github.com> +Date: Fri, 14 Aug 2026 17:29:50 -0400 +Subject: [PATCH] lib: Fix inverted getentropy() return in + writeRandomBytes_getentropy + +CVE: CVE-2026-76956 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/40daa9996d616e66a75dea41ed2b18f2c3901b9f] +Signed-off-by: Peter Marko +--- + lib/random_getentropy.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/random_getentropy.c b/expat/lib/random_getentropy.c +index d258df6a..ad8b1984 100644 +--- a/lib/random_getentropy.c ++++ b/lib/random_getentropy.c +@@ -54,7 +54,7 @@ + bool + writeRandomBytes_getentropy(void *target, size_t count) { + errno = 0; +- const bool success = getentropy(target, count); ++ const bool success = (getentropy(target, count) == 0); + // MSan does not understand `getentropy`, so explain its effects + if (success) + MSAN_UNPOISON(target, count); diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb index 5d30a844fa0..c3c9f738453 100644 --- a/meta/recipes-core/expat/expat_2.8.3.bb +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -13,6 +13,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-66046-01.patch \ file://CVE-2026-66046-02.patch \ file://CVE-2026-76641.patch \ + file://CVE-2026-76956.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Sun Oct 11 08:40:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100348 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B453ECA9EDB for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23452.1791708090548997397 for ; Sun, 11 Oct 2026 01:41:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tUGm29Q0; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-48b03f23305so846379f8f.1 for ; Sun, 11 Oct 2026 01:41:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708089; x=1792312889; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=9Bkyt2khnodyEBG7zKiI+Jz44B9lsc08qb0A16lEuSo=; b=tUGm29Q0oOTexriuPJz+txxMcPndh6tJXbArtpVWgbKEz9svxTwEMQYCuKapXoC6UN MdLpSK203DAs4OVqvxfM0vN/yYx6+WtuZikI2DfUMLNurZCnpajo82TAl+A5smO242s+ iRwCMJoaj3W9KMJ5tgRZAzrl4dA4TyeGxGooE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708089; x=1792312889; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=9Bkyt2khnodyEBG7zKiI+Jz44B9lsc08qb0A16lEuSo=; b=z9jnMbh4z3mDW8mMfWTtjq5f9P3Y+W50/pOiWVQSsGkSQ/08rifJpFyWmFzVOO0mYF u6GuaqVCaWhtnXnlJeaO926dbEbQJ+u4b4096EienRqIxHv9HUvFQGEddaHU1GH7alfu G0iA9hqOzqeEVbOBzO/ChkgBdTepuAdnZbvfCCX1YkA7NEXE8lFxuy1lZ9uZr+uL+L77 Ce+6wsuMETOZQPUo8UexKCxfqFx+x13XgHSZ+mIbH94m368nrNN0/moXaJr7uoirGNJ4 glQsRE3FlwvNE8Kufu/dor7aTQYS/ySGUmLOB+srWZv2utl7gPfeQnmfvpkjrYACbxM5 BBTQ== X-Gm-Message-State: AFq9FYLB9p59E4aLvgWaMmAu/0DgbOFzREWuUlEDqHGcAGz3d9H+OHTp cWc9d2rKBuogXPBnXqbEuO+I1BWi9jEWhuwVqv39s9/+z/8JUEx7VycsmbWiInmGcDvxhI6MbEZ ISiDuw5g= X-Gm-Gg: AYBFou2ApENL7IWfsQptZcYCjTb0KjD5GkIH18Qu+kf0FF6sCvwrTbQXdv4xJjGQo2a /s2zN4joUC3maC1W8GslAbuIPTDwFkL9wpU18fAP9SHsxYC2HMs9Ki3AAg9Y0QhZIJblDBOZEGG w7NY8M7mtModq0SRLLaZggd6JaUtABm4ZHxEnvneFeWRePpaK9/MO9n9q/BWjD2qKuIkNZzYvAI ByvG69A51iJGUPRpdb/Ij/C7Bfg8ELGH1iJC5A+2Psyzf/BFg7nIjPCHjnrUufAbbYRbXTcPwh/ gGQCEl5b7DgjeDBe3ZT+Gc7n+C2P+2RMVeesHMnTxz01EvuYzd201sf22oHlOx+5o7YPnHDjLQJ kJqaPoE1YxejxgnIS0q8Ktp6ul4d8k+R+EqMw7HYCW2NXQU6UvBEZtXIVfL9tXtr1JJJ0DU+fM4 /QGjPCjsPoiM9iXgQTtwmzYaY+93Kvmbf8jLZENQdPyhMuly3IGp3gHg7d41LqKvhHNGDGq+lrg tm0GRiI9amF88Vn+JMimqMTng8ww7l67ZGqgoTSQfHi3rmeXr1Jtz0vuc2T16ooRcCKGIdmIQEY 8jBueUiG X-Received: by 2002:a05:6000:e8e:b0:48b:11d7:f3d4 with SMTP id ffacd0b85a97d-48dbaaeb05amr8111044f8f.28.1791708088458; Sun, 11 Oct 2026 01:41:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 42/60] expat: patch CVE-2026-76957 Date: Sun, 11 Oct 2026 10:40:15 +0200 Message-ID: <4ee814e91e8693265fc4e3c72768f5353284aba3.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247551 From: Peter Marko Pick patches per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-76957 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-76957-01.patch | 121 ++++++++++++++++++ .../expat/expat/CVE-2026-76957-02.patch | 85 ++++++++++++ meta/recipes-core/expat/expat_2.8.3.bb | 2 + 3 files changed, 208 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-01.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-02.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-76957-01.patch b/meta/recipes-core/expat/expat/CVE-2026-76957-01.patch new file mode 100644 index 00000000000..fb7a8e0b022 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-76957-01.patch @@ -0,0 +1,121 @@ +From 127b7d4beb8fe7e5ce5cb021c2e56379c95863d0 Mon Sep 17 00:00:00 2001 +From: Darren Carreras +Date: Mon, 17 Aug 2026 21:16:00 -0400 +Subject: [PATCH] Protect custom encoding callbacks from parser reentry + +Co-authored-by: Sebastian Pipping + +CVE: CVE-2026-76957 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/127b7d4beb8fe7e5ce5cb021c2e56379c95863d0] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 49 ++++++++++++++++++++++++++++++++++++++++--------- + 1 file changed, 40 insertions(+), 9 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index e5242480..4f9dcbb6 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -771,6 +771,8 @@ struct XML_ParserStruct { + void *m_unknownEncodingMem; + void *m_unknownEncodingData; + void *m_unknownEncodingHandlerData; ++ // Application callback invoked by callUnknownEncodingConvert. ++ int(XMLCALL *m_unknownEncodingConvert)(void *, const char *); + void(XMLCALL *m_unknownEncodingRelease)(void *); + PROLOG_STATE m_prologState; + Processor *m_processor; +@@ -1193,6 +1195,25 @@ isCalledFromInsideHandler(XML_Parser parser) { + return parser->m_handlerCallDepth > 0; + } + ++static void ++callUnknownEncodingRelease(XML_Parser parser) { ++ beforeHandler(parser); ++ parser->m_unknownEncodingRelease(parser->m_unknownEncodingData); ++ afterHandler(parser); ++ parser->m_unknownEncodingRelease = NULL; ++ parser->m_unknownEncodingData = NULL; ++} ++ ++static int XMLCALL ++callUnknownEncodingConvert(void *data, const char *p) { ++ XML_Parser parser = data; ++ beforeHandler(parser); ++ const int result ++ = parser->m_unknownEncodingConvert(parser->m_unknownEncodingData, p); ++ afterHandler(parser); ++ return result; ++} ++ + static enum XML_Error + callProcessor(XML_Parser parser, const char *start, const char *end, + const char **endPtr) { +@@ -1540,6 +1561,7 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) { + parser->m_inheritedBindings = NULL; + parser->m_nSpecifiedAtts = 0; + parser->m_unknownEncodingMem = NULL; ++ parser->m_unknownEncodingConvert = NULL; + parser->m_unknownEncodingRelease = NULL; + parser->m_unknownEncodingData = NULL; + parser->m_parsingStatus.parsing = XML_INITIALIZED; +@@ -1620,7 +1642,7 @@ XML_ParserReset(XML_Parser parser, const XML_Char *encodingName) { + moveToFreeBindingList(parser, parser->m_inheritedBindings); + FREE(parser, parser->m_unknownEncodingMem); + if (parser->m_unknownEncodingRelease) +- parser->m_unknownEncodingRelease(parser->m_unknownEncodingData); ++ callUnknownEncodingRelease(parser); + poolClear(&parser->m_tempPool); + poolClear(&parser->m_temp2Pool); + FREE(parser, (void *)parser->m_protocolEncodingName); +@@ -1931,7 +1953,7 @@ XML_ParserFree(XML_Parser parser) { + FREE(parser, parser->m_nsAtts); + FREE(parser, parser->m_unknownEncodingMem); + if (parser->m_unknownEncodingRelease) +- parser->m_unknownEncodingRelease(parser->m_unknownEncodingData); ++ callUnknownEncodingRelease(parser); + FREE(parser, parser); + } + +@@ -4965,25 +4987,34 @@ handleUnknownEncoding(XML_Parser parser, const XML_Char *encodingName) { + const int status = parser->m_unknownEncodingHandler( + parser->m_unknownEncodingHandlerData, encodingName, &info); + afterHandler(parser); ++ ++ parser->m_unknownEncodingRelease = info.release; ++ parser->m_unknownEncodingData = info.data; ++ + if (status) { + ENCODING *enc; + parser->m_unknownEncodingMem = MALLOC(parser, XmlSizeOfUnknownEncoding()); + if (! parser->m_unknownEncodingMem) { +- if (info.release) +- info.release(info.data); ++ if (parser->m_unknownEncodingRelease) ++ callUnknownEncodingRelease(parser); ++ else ++ parser->m_unknownEncodingData = NULL; + return XML_ERROR_NO_MEMORY; + } ++ parser->m_unknownEncodingConvert = info.convert; + enc = (parser->m_ns ? XmlInitUnknownEncodingNS : XmlInitUnknownEncoding)( +- parser->m_unknownEncodingMem, info.map, info.convert, info.data); ++ parser->m_unknownEncodingMem, info.map, ++ info.convert ? callUnknownEncodingConvert : NULL, parser); + if (enc) { +- parser->m_unknownEncodingData = info.data; +- parser->m_unknownEncodingRelease = info.release; + parser->m_encoding = enc; + return XML_ERROR_NONE; + } ++ parser->m_unknownEncodingConvert = NULL; + } +- if (info.release != NULL) +- info.release(info.data); ++ if (parser->m_unknownEncodingRelease != NULL) ++ callUnknownEncodingRelease(parser); ++ else ++ parser->m_unknownEncodingData = NULL; + } + return XML_ERROR_UNKNOWN_ENCODING; + } diff --git a/meta/recipes-core/expat/expat/CVE-2026-76957-02.patch b/meta/recipes-core/expat/expat/CVE-2026-76957-02.patch new file mode 100644 index 00000000000..827499958ac --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-76957-02.patch @@ -0,0 +1,85 @@ +From acbd2e1179c04fe9a8c3f3837701904d05de71fc Mon Sep 17 00:00:00 2001 +From: Darren Carreras +Date: Mon, 17 Aug 2026 21:19:12 -0400 +Subject: [PATCH] Test custom encoding callback reentry protection + +CVE: CVE-2026-76957 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/acbd2e1179c04fe9a8c3f3837701904d05de71fc] +Signed-off-by: Peter Marko +--- + tests/misc_tests.c | 55 ++++++++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 55 insertions(+) + +diff --git a/tests/misc_tests.c b/tests/misc_tests.c +index 82b4b54b..04538c25 100644 +--- a/tests/misc_tests.c ++++ b/tests/misc_tests.c +@@ -839,6 +839,60 @@ START_TEST(test_misc_resume_parser_forbidden_from_handler) { + } + END_TEST + ++typedef struct { ++ XML_Parser parser; ++ int converterCallCount; ++ int releaseCallCount; ++} EncodingCallbackData; ++ ++static int XMLCALL ++reentrant_encoding_converter(void *userData, const char *s) { ++ EncodingCallbackData *const data = userData; ++ UNUSED_P(s); ++ data->converterCallCount++; ++ forbidden_calls_character_handler(data->parser, NULL, 0); ++ return 'A'; ++} ++ ++static void XMLCALL ++reentrant_encoding_release(void *userData) { ++ EncodingCallbackData *const data = userData; ++ data->releaseCallCount++; ++ forbidden_calls_character_handler(data->parser, NULL, 0); ++} ++ ++static int XMLCALL ++reentrant_encoding_handler(void *userData, const XML_Char *name, ++ XML_Encoding *info) { ++ EncodingCallbackData *const data = userData; ++ UNUSED_P(name); ++ ++ for (int i = 0; i < 256; i++) ++ info->map[i] = i; ++ info->map[0x80] = -2; // Route byte 0x80 through the custom converter. ++ info->data = data; ++ info->convert = reentrant_encoding_converter; ++ info->release = reentrant_encoding_release; ++ return XML_STATUS_OK; ++} ++ ++START_TEST(test_misc_unknown_encoding_callbacks_protected) { ++ const char *const doc ++ = "\x80\x80"; ++ XML_Parser parser = XML_ParserCreate(NULL); ++ EncodingCallbackData data = {parser, 0, 0}; ++ XML_SetUnknownEncodingHandler(parser, reentrant_encoding_handler, &data); ++ ++ assert_true(XML_Parse(parser, doc, (int)strlen(doc), /*isFinal=*/XML_TRUE) ++ == XML_STATUS_OK); ++ assert_true(data.converterCallCount > 0); ++ assert_true(data.releaseCallCount == 0); // Released by XML_ParserFree below. ++ ++ XML_ParserFree(parser); ++ assert_true(data.releaseCallCount == 1); ++} ++END_TEST ++ + // General attack payload idea by Jason Kratzer of Mozilla + START_TEST(test_misc_low_surrogate_mozilla_bug_2053153) { + const char doc_before[] = "<\0!\0D\0O\0C\0T\0Y\0P\0E\0 \0d\0 \0[\0\n\0" +@@ -936,6 +990,7 @@ make_miscellaneous_test_case(Suite *s) { + tcase_add_test(tc_misc, test_misc_no_infinite_loop_issue_1161); + tcase_add_test(tc_misc, test_misc_calls_forbidden_from_handlers); + tcase_add_test(tc_misc, test_misc_resume_parser_forbidden_from_handler); ++ tcase_add_test(tc_misc, test_misc_unknown_encoding_callbacks_protected); + tcase_add_test(tc_misc, test_misc_input_2gb); + tcase_add_test(tc_misc, test_misc_low_surrogate_mozilla_bug_2053153); + } diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb index c3c9f738453..c9a1c9b18e3 100644 --- a/meta/recipes-core/expat/expat_2.8.3.bb +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -14,6 +14,8 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-66046-02.patch \ file://CVE-2026-76641.patch \ file://CVE-2026-76956.patch \ + file://CVE-2026-76957-01.patch \ + file://CVE-2026-76957-02.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Sun Oct 11 08:40:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100351 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 841ABCA9ED8 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23453.1791708091328304466 for ; Sun, 11 Oct 2026 01:41:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0XRJhWpc; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48b0ef9c76eso780226f8f.0 for ; Sun, 11 Oct 2026 01:41:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708089; x=1792312889; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IMtUr6QdYy46NyOdO6cO4WIrGcVkzBf4z6Wqq90h8VQ=; b=0XRJhWpcb1H/jdvD5QKi1nZOEVtcJh6p4Edd6ATDF5g3bWbNtcI7KJSd4f8FJhfYrB Q9Gkr9MxkPb9UVeFwxcZ1Ht09FRPWsdxE30XavYuJm10PWMIaBHyrABCi9FxQaASN2Ko ubi/eiOaN0/Zaa3uymLnC1TT+FIG2cm2L6TL0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708089; x=1792312889; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IMtUr6QdYy46NyOdO6cO4WIrGcVkzBf4z6Wqq90h8VQ=; b=lan5GXPxO/9G5FXkT36rLHrmLwGt+k5r3UlCz8CS/BhH/xWxIip31N9TDBETJ+NkwY 1FPGbpxcIw+Vol5Wt8D7j/yH5vWnviaLUcry0P1UtvvfF2AwM4lxGYfqUZEcrQ5tdZjT wrfI/SM2gt0Mh9o+b/RBoOwArIW2npEVyBCPxx3/6Jfuk+IY14FdMOmTumYLVDVt1L2c bFu9SO68unGWPGusP3EUYgFIaNmJouXhgSS7PaPWERL8BUg8JYFmbLXsSJeZT9uHbdul T80h0wrA7baf1kNSc0NTnYDgS01GoRns/7ty4xv7aT3XYEVnPTT+AVp9hEbXsPUzSYqb BWww== X-Gm-Message-State: AFq9FYKpLVyvznHNVLhX/csN8qFG5XJT3WOvDLWdvtWPMRqGCCN5xvC1 UgiEhLUyCDm7JuxK0dSkeF10H9BGgH5BHc4urxjRPITxSqZhyRvqy5dqbcyAAUGT6+i7rh3u+kp ZIWvAc5o= X-Gm-Gg: AYBFou29nJpIufzO/J8kzgFqpOSvdPzARPVWrET6YiKl9DiDqgwUpuZLEz0mJb0JJq2 WX0i6WFs4bcxf1TpJRIiISmMW81Y+RCN+XmAPqEQ2h74EnuVJ3/1wE7OEW4GkeMTgEO0dQQKnuQ Bhxo11idzIAs9U7GF+h6eKwIPgQwXZH+1cgll7vQD9vCQqvkCFJwTMYBdauDmMMnJC6o9TvvOs3 4GQ1G0bvf+Oyf8QLHTWU+TpwHKIRIuWXvQmotN7Rz9h/zeb6eFwUtfUyoYPPACmzMVEnLiiJi6L uwbppxHHaryZDwTSVnX8AAJ0Pu5Fq67zdteeEATVNy/DC68n/wDEe49xdRd/t8qHE+bxvEUCOEC LVolEtQcIBubxo4cjdZG4kfdYiaqNO0U7OpuK/0JKufRNbBl4VmprP/ThTgGHQrnDSAoN1UZaCp 6Tz5Yr2Ay6IQ+JxizZELqP2X+Vvxwb+jmbLtnD5Ax9Drxr5dbHfkaoQ4HD4ue+GDMA4w+sosnFX clN0LEM5IXEV9HdynO2IWsK9kt5FKpD5XisoPLoZivt2EFX62N3M+46A49q5i3FFeTl5MYjbQ== X-Received: by 2002:a05:6000:1787:b0:488:6561:b324 with SMTP id ffacd0b85a97d-48dba9bdb31mr10896965f8f.9.1791708089230; Sun, 11 Oct 2026 01:41:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 43/60] expat: patch CVE-2026-93990 Date: Sun, 11 Oct 2026 10:40:16 +0200 Message-ID: <15ef201a2b30e2513f949040fdc999299ddba77c.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247552 From: Peter Marko Pick patches per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-93990 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-93990-01.patch | 191 ++++++++++ .../expat/expat/CVE-2026-93990-02.patch | 328 ++++++++++++++++++ meta/recipes-core/expat/expat_2.8.3.bb | 2 + 3 files changed, 521 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-01.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-02.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-93990-01.patch b/meta/recipes-core/expat/expat/CVE-2026-93990-01.patch new file mode 100644 index 00000000000..fde01b916ad --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-93990-01.patch @@ -0,0 +1,191 @@ +From 0cfd15bdf4b2c22d6b0df73610709dfb60921091 Mon Sep 17 00:00:00 2001 +From: Kartik Kenchi +Date: Tue, 23 Jun 2026 15:51:06 +0530 +Subject: [PATCH] lib: reject UTF-16 high surrogate not followed by a low + surrogate + +CVE: CVE-2026-93990 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091] +Signed-off-by: Peter Marko +--- + lib/xmltok.c | 53 ++++++++++++++++++++++++++++++++++++++++------- + lib/xmltok_impl.c | 4 ---- + 2 files changed, 45 insertions(+), 12 deletions(-) + +diff --git a/lib/xmltok.c b/lib/xmltok.c +index 8abb145e..5f4e78ec 100644 +--- a/lib/xmltok.c ++++ b/lib/xmltok.c +@@ -232,6 +232,19 @@ struct normal_encoding { + /* isNmstrt2 */ NULL, /* isNmstrt3 */ NULL, /* isNmstrt4 */ NULL, \ + /* isInvalid2 */ NULL, /* isInvalid3 */ NULL, /* isInvalid4 */ NULL + ++/* Like NULL_VTABLE but with a real isInvalid4 so the UTF-16 encodings reject a ++ high surrogate that is not followed by a low surrogate. Only needed for the ++ XML_MIN_SIZE build, where the shared tokenizer dispatches through the vtable; ++ the regular build inlines the same check via IS_INVALID_CHAR. */ ++#ifdef XML_MIN_SIZE ++# define UTF16_NULL_VTABLE(E) \ ++ /* isName2 */ NULL, /* isName3 */ NULL, /* isName4 */ NULL, \ ++ /* isNmstrt2 */ NULL, /* isNmstrt3 */ NULL, /* isNmstrt4 */ NULL, \ ++ /* isInvalid2 */ NULL, /* isInvalid3 */ NULL, E##isInvalid4 ++#else ++# define UTF16_NULL_VTABLE(E) NULL_VTABLE ++#endif ++ + static int FASTCALL checkCharRefNumber(int result); + + #include "xmltok_impl.h" +@@ -749,6 +762,11 @@ DEFINE_UTF16_TO_UTF16(big2_) + UCS2_GET_NAMING(namePages, (unsigned char)p[1], (unsigned char)p[0]) + #define LITTLE2_IS_NMSTRT_CHAR_MINBPC(p) \ + UCS2_GET_NAMING(nmstrtPages, (unsigned char)p[1], (unsigned char)p[0]) ++/* A 4-byte UTF-16 character is a surrogate pair; byteType only reports BT_LEAD4 ++ for a high surrogate, so the pair is invalid unless the second unit is a low ++ surrogate (U+DC00..U+DFFF, i.e. high byte 0xDC..0xDF). */ ++#define LITTLE2_IS_INVALID_CHAR(p, n) \ ++ ((n) == 4 && ((unsigned char)(p)[3] & 0xFC) != 0xDC) + + #ifdef XML_MIN_SIZE + +@@ -781,6 +799,12 @@ little2_isNmstrtMin(const ENCODING *enc, const char *p) { + return LITTLE2_IS_NMSTRT_CHAR_MINBPC(p); + } + ++static int ++little2_isInvalid4(const ENCODING *enc, const char *p) { ++ UNUSED_P(enc); ++ return LITTLE2_IS_INVALID_CHAR(p, 4); ++} ++ + # undef VTABLE + # define VTABLE VTABLE1, little2_toUtf8, little2_toUtf16 + +@@ -797,6 +821,7 @@ little2_isNmstrtMin(const ENCODING *enc, const char *p) { + # define IS_NAME_CHAR_MINBPC(enc, p) LITTLE2_IS_NAME_CHAR_MINBPC(p) + # define IS_NMSTRT_CHAR(enc, p, n) (0) + # define IS_NMSTRT_CHAR_MINBPC(enc, p) LITTLE2_IS_NMSTRT_CHAR_MINBPC(p) ++# define IS_INVALID_CHAR(enc, p, n) LITTLE2_IS_INVALID_CHAR(p, n) + + # define XML_TOK_IMPL_C + # include "xmltok_impl.c" +@@ -828,7 +853,7 @@ static const struct normal_encoding little2_encoding_ns + # include "asciitab.h" + # include "latin1tab.h" + }, +- STANDARD_VTABLE(little2_) NULL_VTABLE}; ++ STANDARD_VTABLE(little2_) UTF16_NULL_VTABLE(little2_)}; + + #endif + +@@ -846,7 +871,7 @@ static const struct normal_encoding little2_encoding + #undef BT_COLON + #include "latin1tab.h" + }, +- STANDARD_VTABLE(little2_) NULL_VTABLE}; ++ STANDARD_VTABLE(little2_) UTF16_NULL_VTABLE(little2_)}; + + #if BYTEORDER != 4321 + +@@ -858,7 +883,7 @@ static const struct normal_encoding internal_little2_encoding_ns + # include "iasciitab.h" + # include "latin1tab.h" + }, +- STANDARD_VTABLE(little2_) NULL_VTABLE}; ++ STANDARD_VTABLE(little2_) UTF16_NULL_VTABLE(little2_)}; + + # endif + +@@ -870,7 +895,7 @@ static const struct normal_encoding internal_little2_encoding + # undef BT_COLON + # include "latin1tab.h" + }, +- STANDARD_VTABLE(little2_) NULL_VTABLE}; ++ STANDARD_VTABLE(little2_) UTF16_NULL_VTABLE(little2_)}; + + #endif + +@@ -882,6 +907,11 @@ static const struct normal_encoding internal_little2_encoding + UCS2_GET_NAMING(namePages, (unsigned char)p[0], (unsigned char)p[1]) + #define BIG2_IS_NMSTRT_CHAR_MINBPC(p) \ + UCS2_GET_NAMING(nmstrtPages, (unsigned char)p[0], (unsigned char)p[1]) ++/* A 4-byte UTF-16 character is a surrogate pair; byteType only reports BT_LEAD4 ++ for a high surrogate, so the pair is invalid unless the second unit is a low ++ surrogate (U+DC00..U+DFFF, i.e. high byte 0xDC..0xDF). */ ++#define BIG2_IS_INVALID_CHAR(p, n) \ ++ ((n) == 4 && ((unsigned char)(p)[2] & 0xFC) != 0xDC) + + #ifdef XML_MIN_SIZE + +@@ -914,6 +944,12 @@ big2_isNmstrtMin(const ENCODING *enc, const char *p) { + return BIG2_IS_NMSTRT_CHAR_MINBPC(p); + } + ++static int ++big2_isInvalid4(const ENCODING *enc, const char *p) { ++ UNUSED_P(enc); ++ return BIG2_IS_INVALID_CHAR(p, 4); ++} ++ + # undef VTABLE + # define VTABLE VTABLE1, big2_toUtf8, big2_toUtf16 + +@@ -930,6 +966,7 @@ big2_isNmstrtMin(const ENCODING *enc, const char *p) { + # define IS_NAME_CHAR_MINBPC(enc, p) BIG2_IS_NAME_CHAR_MINBPC(p) + # define IS_NMSTRT_CHAR(enc, p, n) (0) + # define IS_NMSTRT_CHAR_MINBPC(enc, p) BIG2_IS_NMSTRT_CHAR_MINBPC(p) ++# define IS_INVALID_CHAR(enc, p, n) BIG2_IS_INVALID_CHAR(p, n) + + # define XML_TOK_IMPL_C + # include "xmltok_impl.c" +@@ -961,7 +998,7 @@ static const struct normal_encoding big2_encoding_ns + # include "asciitab.h" + # include "latin1tab.h" + }, +- STANDARD_VTABLE(big2_) NULL_VTABLE}; ++ STANDARD_VTABLE(big2_) UTF16_NULL_VTABLE(big2_)}; + + #endif + +@@ -979,7 +1016,7 @@ static const struct normal_encoding big2_encoding + #undef BT_COLON + #include "latin1tab.h" + }, +- STANDARD_VTABLE(big2_) NULL_VTABLE}; ++ STANDARD_VTABLE(big2_) UTF16_NULL_VTABLE(big2_)}; + + #if BYTEORDER != 1234 + +@@ -991,7 +1028,7 @@ static const struct normal_encoding internal_big2_encoding_ns + # include "iasciitab.h" + # include "latin1tab.h" + }, +- STANDARD_VTABLE(big2_) NULL_VTABLE}; ++ STANDARD_VTABLE(big2_) UTF16_NULL_VTABLE(big2_)}; + + # endif + +@@ -1003,7 +1040,7 @@ static const struct normal_encoding internal_big2_encoding + # undef BT_COLON + # include "latin1tab.h" + }, +- STANDARD_VTABLE(big2_) NULL_VTABLE}; ++ STANDARD_VTABLE(big2_) UTF16_NULL_VTABLE(big2_)}; + + #endif + +diff --git a/lib/xmltok_impl.c b/lib/xmltok_impl.c +index b7a9b5eb..3cc9e5ab 100644 +--- a/lib/xmltok_impl.c ++++ b/lib/xmltok_impl.c +@@ -44,10 +44,6 @@ + + #ifdef XML_TOK_IMPL_C + +-# ifndef IS_INVALID_CHAR // i.e. for UTF-16 and XML_MIN_SIZE not defined +-# define IS_INVALID_CHAR(enc, ptr, n) (0) +-# endif +- + # define INVALID_LEAD_CASE(n, ptr, nextTokPtr) \ + case BT_LEAD##n: \ + if (end - ptr < n) \ diff --git a/meta/recipes-core/expat/expat/CVE-2026-93990-02.patch b/meta/recipes-core/expat/expat/CVE-2026-93990-02.patch new file mode 100644 index 00000000000..25e38e39565 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-93990-02.patch @@ -0,0 +1,328 @@ +From 28fcfba540f6933aa8904a1514c4811713d2ab72 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Thu, 17 Sep 2026 15:12:43 +0200 +Subject: [PATCH] tests: Cover UTF-16 decoding of surrogates + +Co-authored-by: Kartik Kenchi + +CVE: CVE-2026-93990 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/28fcfba540f6933aa8904a1514c4811713d2ab72] +Signed-off-by: Peter Marko +--- + tests/basic_tests.c | 296 ++++++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 296 insertions(+) + +diff --git a/tests/basic_tests.c b/tests/basic_tests.c +index dd0494ce..92172a27 100644 +--- a/tests/basic_tests.c ++++ b/tests/basic_tests.c +@@ -1845,6 +1845,301 @@ START_TEST(test_utf16_bad_surrogate_pair) { + } + END_TEST + ++// Helper that creates a UTF-16LE copy of UTF-16BE literal input and vice versa ++static char * ++utf16_dup_flipped(const char *text, size_t lenBytes) { ++ assert_true(lenBytes < SIZE_MAX); ++ assert_true(lenBytes % 2 == 0); ++ char *const buffer = malloc(lenBytes + 1); ++ assert_true(buffer != NULL); ++ ++ for (size_t i = 0; i < lenBytes; i++) { ++ // This maps 0 -> 1, 1 -> 0, 2 -> 3, 3 -> 2, 4 -> 5, .. ++ size_t j = i + ((i % 2 == 0) ? +1 : -1); ++ assert_true(j < lenBytes); ++ buffer[j] = text[i]; ++ } ++ ++ buffer[lenBytes] = '\0'; ++ ++ return buffer; ++} ++ ++/* Tests that invalid combinations of surrogates are detected when decoding ++ UTF-16, both little-endian and big-endian. ++ Previously, a high surrogate not followed by a low surrogate slipped ++ through. Without validation the high would consume the next ++ code unit as a fake low, hiding e.g. a following '<' from the ++ tokenizer. */ ++START_TEST(test_utf16_surrogate_pairs) { ++ struct TestCase { ++ const char *idea; ++ const char *content; ++ bool expectedSuccess; ++ }; ++ ++ struct TestCase testCases[] = { ++ // Group {smallest high - 1}{*} ++ {"{smallest high - 1}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{smallest high - 1}{smallest high}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high - 1}{largest high}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high - 1}{smallest low}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high - 1}{largest low}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high - 1}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xD7\xFF" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ true}, ++ // Group {smallest high}{*} ++ {"{smallest high}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high}{smallest high}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high}{largest high}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest high}{smallest low}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{smallest high}{largest low}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{smallest high}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xD8\x00" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ // Group {largest high}{*} ++ {"{largest high}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest high}{smallest high}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest high}{largest high}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest high}{smallest low}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{largest high}{largest low}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{largest high}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xDB\xFF" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ // Group {smallest low}{*} ++ {"{smallest low}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest low}{smallest high}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest low}{largest high}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest low}{smallest low}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest low}{largest low}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{smallest low}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xDC\x00" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ // Group {largest low}{*} ++ {"{largest low}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low}{smallest high}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low}{largest high}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low}{smallest low}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low}{largest low}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xDF\xFF" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ // Group {largest low + 1}{*} ++ {"{largest low + 1}{smallest high - 1}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xD7\xFF" ++ "\0<\0/\0a\0>", ++ true}, ++ {"{largest low + 1}{smallest high}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xD8\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low + 1}{largest high}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xDB\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low + 1}{smallest low}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xDC\x00" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low + 1}{largest low}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xDF\xFF" ++ "\0<\0/\0a\0>", ++ false}, ++ {"{largest low + 1}{largest low + 1}", ++ "\0<\0a\0>" ++ "\xE0\x00" ++ "\xE0\x00" ++ "\0<\0/\0a\0>", ++ true}, ++ }; ++ ++ for (size_t i = 0; i < sizeof(testCases) / sizeof(testCases[0]); i++) { ++ set_subtest("%s", testCases[i].idea); ++ ++ const int lenBytes = /**/ 6 + /*first*/ 2 + /*second*/ 2 + /**/ 8; ++ const bool expectedSuccess = testCases[i].expectedSuccess; ++ const enum XML_Status expectedStatus ++ = (expectedSuccess ? XML_STATUS_OK : XML_STATUS_ERROR); ++ ++ const char *const bigEndian = testCases[i].content; ++ char *const littleEndian = utf16_dup_flipped(bigEndian, lenBytes); ++ assert_true(littleEndian != NULL); ++ const char *endianCases[] = {bigEndian, littleEndian}; ++ ++ for (size_t j = 0; j < sizeof(endianCases) / sizeof(endianCases[0]); j++) { ++ const char *text = endianCases[j]; ++ ++ assert_true(text[lenBytes] == '\0'); // self-test ++ assert_true((text[0] == '\0') ++ != (text[lenBytes - 1] == '\0')); // self-test ++ ++ XML_Parser parser = XML_ParserCreate(NULL); ++ assert_true(parser != NULL); ++ ++ assert_true(_XML_Parse_SINGLE_BYTES(parser, text, lenBytes, XML_TRUE) ++ == expectedStatus); ++ if (! expectedSuccess) { ++ assert_true(XML_GetErrorCode(parser) == XML_ERROR_INVALID_TOKEN); ++ } ++ ++ XML_ParserFree(parser); ++ } ++ ++ free(littleEndian); ++ } ++} ++END_TEST ++ + START_TEST(test_bad_cdata) { + struct CaseData { + const char *text; +@@ -6711,6 +7006,7 @@ make_basic_test_case(Suite *s) { + tcase_add_test(tc_basic, test_long_cdata_utf16); + tcase_add_test(tc_basic, test_multichar_cdata_utf16); + tcase_add_test(tc_basic, test_utf16_bad_surrogate_pair); ++ tcase_add_test(tc_basic, test_utf16_surrogate_pairs); + tcase_add_test(tc_basic, test_bad_cdata); + tcase_add_test(tc_basic, test_bad_cdata_utf16); + tcase_add_test(tc_basic, test_stop_parser_between_cdata_calls); diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb index c9a1c9b18e3..6d08a3fd94b 100644 --- a/meta/recipes-core/expat/expat_2.8.3.bb +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -16,6 +16,8 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ file://CVE-2026-76956.patch \ file://CVE-2026-76957-01.patch \ file://CVE-2026-76957-02.patch \ + file://CVE-2026-93990-01.patch \ + file://CVE-2026-93990-02.patch \ " GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" From patchwork Sun Oct 11 08:40:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100346 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7848DCA9ED7 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23454.1791708091789543366 for ; Sun, 11 Oct 2026 01:41:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=siGfsJ6Y; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-48c4d870d54so487179f8f.2 for ; Sun, 11 Oct 2026 01:41:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708090; x=1792312890; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZiDnD0G/xOk+a0RM2S/PfDj7Z1O2VHY3GSZ6M6UfrtA=; b=siGfsJ6YFSLObe8WJ/g784DY3HF3gJST8faMIMhGCdrIANQn7jhVc/v0ai6t4qYKn1 HSXhlwGDgmSvqSRqYd1ArStAqEyyKkUycs9PPvVO7udKDbfA8djJ84F7QQRrMsocr/4t eGI8k4/eDanHWE3F6W5tl+Gvgj8OhiSNqv6AM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708090; x=1792312890; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZiDnD0G/xOk+a0RM2S/PfDj7Z1O2VHY3GSZ6M6UfrtA=; b=RJ+twwn4WUIGJoIscpyYt0aXiUXnJzDysWtFUrEafQ56fPu/wUNSUgog9qCS6Dk451 5ZzmBaLMIw/aJjl8VAGPZW1oP9CVFDVrZgkifpdNe5NVs1RVqh7WGCjrulMLYSLO2PA2 bvQ3OraTiy7H98e++OULi9eZn4gemm0B8CrtpNIEbQGS82dxn01XbjRbqe/GxaWBlGl2 DpVeCDbC4QsJKG4TpG4p+WHtv70Pye/XYcTvU8Jr5A8fvaPGJxcOz0slVUip4clc5blT be4M59QHvu2hteRsTesfY2cwUWIArdcFDkv2bTQM6mETLsJ+1WBQkG5Z90DwchCpbbud 61XA== X-Gm-Message-State: AFq9FYI8XzBxSM1SZbN2teJOfGC/Ci+DXGt4V0zHIaSy9llBPnmh8rmL zeLK763Q5qopMPD/oljYUqXB9yUP1u8KwuMEHwjeOwy0g7Lw13iP+gezLtOL77qwP2y3AQl1bKL wnd5SYWM= X-Gm-Gg: AYBFou1A0JQ3AkP1dGQseo4KM4ypElEXwP/WgnJ+4Cm31JDNnvmu7OlJn8c2f+INWWd 6ECxet1Zs+owfC1pP/u/PSt4aZ3aatkE6m+LwhIvpQAsj3f/K0daHU5rQk7UgUKs3iS2q9IEAvh VPhr28xO+SBNUtyGu6d3Z3awFA5tdvjtzR0revHR6G4EttMHaMZ5N0NPoVHpwqrB9S2bmxS8XiR WAgequxVJE/vFeXj3wK4/GpV2RoRlHWgIiDwll9MbxvfyJokrgMyxQdQMCL03I4pKOMIEHfx6Iy LyUlpKum5RhiyU+P3y1Z4UCTHp3HcYNmjgLYaJanZ5Zjgajt6u1QJL+exRmO00MVrzmIAaeCH1A vf5PcJ8/7YdEaTt/93X80Wo7zQZ/t66N8TkOPN2VN/S7owjPrj+XMqaVeUDdv3iXtBlX2hvEzzT 5EAEsdGv+dMraCigFFjC1RW5Bxob6cjQXKqobGrkFd6sWEbgkuoniJoNx2tYQmd/LB30Sxy5FRJ rfJ0yAiuZRi0qJj6XXYgwShvdiRsY6kkBS3hoM2qK8KKgaQ2R/PLV/E3AwS+9uIysoc+6BO1g== X-Received: by 2002:a05:6000:26c5:b0:48c:7ab9:99cc with SMTP id ffacd0b85a97d-48dbacf9da3mr11475251f8f.52.1791708089774; Sun, 11 Oct 2026 01:41:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 44/60] ffmpeg: Fix for CVE-2026-66036 Date: Sun, 11 Oct 2026 10:40:17 +0200 Message-ID: <76e0d54cd1cb355c8ae98af515ae9ce9b3d8fd85.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247553 From: Bhavesh R Maheshwari Pick the patch from [1] and [2], mentioned in PR#23783 [3] which is referenced in the NVD report [4] [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e [2] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c [3] https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783 [4] https://nvd.nist.gov/vuln/detail/cve-2026-66036 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-66036_p1.patch | 120 ++++++++++++++++++ .../ffmpeg/ffmpeg/CVE-2026-66036_p2.patch | 71 +++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 2 + 3 files changed, 193 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch new file mode 100644 index 00000000000..bce02651143 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch @@ -0,0 +1,120 @@ +From 7ac88955c4678fc10cc44a786ff9bf724bb12deb Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 12 Jul 2026 13:05:07 +0200 +Subject: [PATCH 1/2] avfilter/vf_hqdn3d: reject unsupported frame parameter + changes + +Fixes: out of array access +Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py +Fixes: wWDsy2oDvMuR +Found-by: Adrian Junge (vurlo) + +CVE: CVE-2026-66036 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++--------- + libavfilter/vf_hqdn3d.h | 2 ++ + 2 files changed, 27 insertions(+), 9 deletions(-) + +diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c +index 1136931b9b..44fb3574a0 100644 +--- a/libavfilter/vf_hqdn3d.c ++++ b/libavfilter/vf_hqdn3d.c +@@ -165,12 +165,8 @@ static int denoise_depth(HQDN3DContext *s, + case 14: ret = denoise_depth(__VA_ARGS__, 14); break; \ + case 16: ret = denoise_depth(__VA_ARGS__, 16); break; \ + } \ +- if (ret < 0) { \ +- av_frame_free(&out); \ +- if (!direct) \ +- av_frame_free(&in); \ ++ if (ret < 0) \ + return ret; \ +- } \ + } while (0) + + static void precalc_coefs(double dist25, int depth, int16_t *ct) +@@ -283,12 +279,15 @@ static int config_input(AVFilterLink *inlink) + ff_hqdn3d_init_x86(s); + #endif + ++ s->format = inlink->format; ++ s->width = inlink->w; ++ s->height = inlink->h; ++ + return 0; + } + + typedef struct ThreadData { + AVFrame *in, *out; +- int direct; + } ThreadData; + + static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) +@@ -297,7 +296,6 @@ static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) + const ThreadData *td = data; + AVFrame *out = td->out; + AVFrame *in = td->in; +- int direct = td->direct; + + denoise(s, in->data[job_nr], out->data[job_nr], + s->line[job_nr], &s->frame_prev[job_nr], +@@ -314,10 +312,21 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) + { + AVFilterContext *ctx = inlink->dst; + AVFilterLink *outlink = ctx->outputs[0]; ++ HQDN3DContext *s = ctx->priv; + + AVFrame *out; + int direct = av_frame_is_writable(in) && !ctx->is_disabled; + ThreadData td; ++ int ret[3]; ++ ++ if (in->format != s->format || ++ in->width != s->width || ++ in->height != s->height) { ++ av_log(ctx, AV_LOG_ERROR, ++ "Frame size or format changed without filter graph reinitialization\n"); ++ av_frame_free(&in); ++ return AVERROR(EINVAL); ++ } + + if (direct) { + out = in; +@@ -333,9 +342,16 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) + + td.in = in; + td.out = out; +- td.direct = direct; + /* one thread per plane */ +- ff_filter_execute(ctx, do_denoise, &td, NULL, 3); ++ ff_filter_execute(ctx, do_denoise, &td, ret, 3); ++ for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) { ++ if (ret[i] < 0) { ++ av_frame_free(&out); ++ if (!direct) ++ av_frame_free(&in); ++ return ret[i]; ++ } ++ } + + if (ctx->is_disabled) { + av_frame_free(&out); +diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h +index 3279bbcc77..3467f27145 100644 +--- a/libavfilter/vf_hqdn3d.h ++++ b/libavfilter/vf_hqdn3d.h +@@ -36,6 +36,8 @@ typedef struct HQDN3DContext { + double strength[4]; + int hsub, vsub; + int depth; ++ int width, height; ++ enum AVPixelFormat format; + void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal); + } HQDN3DContext; + +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch new file mode 100644 index 00000000000..e5148e86291 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch @@ -0,0 +1,71 @@ +From 6e2b4a7713d9fd4ddfc0e2775af9ba6a03e77d55 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 12 Jul 2026 13:05:33 +0200 +Subject: [PATCH 2/2] avfilter/vf_hqdn3d: support dynamic frame sizes + +CVE: CVE-2026-66036 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/avfilter.c | 3 ++- + libavfilter/vf_hqdn3d.c | 21 ++++++++++++++------- + 2 files changed, 16 insertions(+), 8 deletions(-) + +diff --git a/libavfilter/avfilter.c b/libavfilter/avfilter.c +index 5bcf0b4ef7..c039f3a1ff 100644 +--- a/libavfilter/avfilter.c ++++ b/libavfilter/avfilter.c +@@ -1072,7 +1072,8 @@ int ff_filter_frame(AVFilterLink *link, AVFrame *frame) + strcmp(link->dst->filter->name, "idet") && + strcmp(link->dst->filter->name, "null") && + strcmp(link->dst->filter->name, "scale") && +- strcmp(link->dst->filter->name, "libplacebo")) { ++ strcmp(link->dst->filter->name, "libplacebo") && ++ strcmp(link->dst->filter->name, "hqdn3d")) { + av_assert1(frame->format == link->format); + av_assert1(frame->width == link->w); + av_assert1(frame->height == link->h); +diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c +index 44fb3574a0..92163042eb 100644 +--- a/libavfilter/vf_hqdn3d.c ++++ b/libavfilter/vf_hqdn3d.c +@@ -317,21 +317,28 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) + AVFrame *out; + int direct = av_frame_is_writable(in) && !ctx->is_disabled; + ThreadData td; +- int ret[3]; ++ int err, ret[3]; + +- if (in->format != s->format || +- in->width != s->width || +- in->height != s->height) { +- av_log(ctx, AV_LOG_ERROR, +- "Frame size or format changed without filter graph reinitialization\n"); ++ if (in->format != s->format) { + av_frame_free(&in); + return AVERROR(EINVAL); + } + ++ if (in->width != s->width || in->height != s->height) { ++ inlink->w = in->width; ++ inlink->h = in->height; ++ if ((err = config_input(inlink)) < 0) { ++ av_frame_free(&in); ++ return err; ++ } ++ outlink->w = in->width; ++ outlink->h = in->height; ++ } ++ + if (direct) { + out = in; + } else { +- out = ff_get_video_buffer(outlink, outlink->w, outlink->h); ++ out = ff_get_video_buffer(outlink, in->width, in->height); + if (!out) { + av_frame_free(&in); + return AVERROR(ENOMEM); +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 06c6e402c97..9a2a3353ca4 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -40,6 +40,8 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-66037.patch \ file://CVE-2026-66038.patch \ file://CVE-2026-66039.patch \ + file://CVE-2026-66036_p1.patch \ + file://CVE-2026-66036_p2.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Sun Oct 11 08:40:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100343 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6170CCA9ED6 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23579.1791708092275725052 for ; Sun, 11 Oct 2026 01:41:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=sWItN1iM; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-48af27fe287so818950f8f.0 for ; Sun, 11 Oct 2026 01:41:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708090; x=1792312890; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jmwM0gb3RRp3eEnS9OacUWTESlCkESGENh4KlSgd4I8=; b=sWItN1iMWv3R8PyTdEVA8bIXqstsTDtBdQbsnvNU9cJ0E/Al5IC/xUHMeR/vGpAo7j 0Bq8pjfY/4pgns+uxTyRZ+65zHiM6Y4p5iUvvKtd/1dUvkrYcn/QBEmE7Qnu8+jDwj8j PddIhssKUz1P5A4DdJ5YSs1ZsmlwHVkjluSkI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708090; x=1792312890; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jmwM0gb3RRp3eEnS9OacUWTESlCkESGENh4KlSgd4I8=; b=V0DgbsSc1MsSrU/Ip79RXaI5VV8eR6xaX6muXztovYyV8gx5qszGmAlBO1GXQGdA/7 opkQuknk60MKSDurZ+UfhrV7z8HNLpFKX5r3sPFLHB4mfVehKZghBQoKmBEqiWCVEjkr xjpV5erxyyV0mLz+M4Hl6pI17LjYDQS/oAg/mfvZNWmAUje8c2HRBLh33tLNpcSKl1Po BNHBF3ziB/QuF6US00SvRyhaUt0Zb+aLJ/nVNhpuA6fY3IIrSDCwY2ljWyp/n40586XU 3ccI3D0BgAOWoWpaD5g3qE5mUYAE8I+FtvE+fPs3FUOFnUbAaUDFS88cgGH0798Uym65 KSdg== X-Gm-Message-State: AFq9FYJipo/qj4ar+oLxZJyu2OOew56YO4K2N7E6WTyxwRy+6Vfj4t78 ggCegjqAX23seclfNOoESbl3Y37TJeGdV2I9wDhTVuTYcR3Nz8FksqpHrw9usV4zAm46RD/OpYW QXpinHY0= X-Gm-Gg: AYBFou0NIZnli/jUBaY/fVZApSAhkLNJt+tNmffvor0gzrLaHgKzGlbuXLU3RpYb7G3 QN+kNFnNnBQ4CLh6mwg4gLCC2vAa/ur/6jUOmQaavoBNKisyjvtrNtdDKLS1eyYIoo8M7E03NMu 5rMXtOb27LNURwhxOuykbZXagMLCFNIl9QU6wNtjqVIvgAqpRMAbFgvPG6r1WTeoC1zDuT+8yV4 iwZBuvOrFMtdk5QVcntcMAcBmmdnIc+cV3ESFaYQ4S0IwABy2SgqEPlAU5lk/3cZ4NDihr0EuzP DqHD6N4Mw3dnrwbkISIOfQUbWhXe7ZssTXBYvGsIjBZxTGFv6ovjuvp9izJ4fLVVhFSoPzlXkvY Qn6ny6uGTSoIb/PiI8r/5KCnrQSsbZ2uMgPkceuSttcDkcCrftQspHu5i/phIA7HhXyV82U0+Su EJKfcR/adcB6WPJ/KVGG472wXUc2blVDHKzjovOJjfO5fYg+NBxAFNNnWLuGljUKGNlEnf75PxR +zmZn8YOBYnvGwN+tlOQVnHGG+MT1nxTx+wV3MWcUT1wSDeiwZcqnGXBWolUhC8I+6BKIVmIygQ qxh7kJwt X-Received: by 2002:a05:6000:2907:b0:48d:c18b:d644 with SMTP id ffacd0b85a97d-48dc18bd66dmr8492504f8f.26.1791708090509; Sun, 11 Oct 2026 01:41:30 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 45/60] ffmpeg: Fix for CVE-2026-66041 Date: Sun, 11 Oct 2026 10:40:18 +0200 Message-ID: <1cddc095cdf24208d1cbf33cfd107c1e81e6e239.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247554 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5 [2] https://nvd.nist.gov/vuln/detail/cve-2026-66041 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-66041.patch | 60 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch new file mode 100644 index 00000000000..7a8c4e0c8b9 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch @@ -0,0 +1,60 @@ +From 9db6b5816516b85e981e177863b2eb361dbec3c8 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 28 Jun 2026 15:33:38 +0200 +Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input + size changes + +Fixes: out of array access +Fixes: JbvzNObhorBp +Fixes: 030e140145 (lavfi: add quirc filter) +Found-by: Adrian Junge (vurlo) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-66041 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/vf_quirc.c | 12 ++++++++++++ + 1 file changed, 12 insertions(+) + +diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c +index 59dc84caa8..d2ba48e7bc 100644 +--- a/libavfilter/vf_quirc.c ++++ b/libavfilter/vf_quirc.c +@@ -36,6 +36,7 @@ typedef struct QuircContext { + const AVClass *class; + + struct quirc *quirc; ++ int width, height; + } QuircContext; + + static av_cold int init(AVFilterContext *ctx) +@@ -67,6 +68,8 @@ static int config_input(AVFilterLink *inlink) + if (err == -1) { + return AVERROR(ENOMEM); + } ++ quirc->width = inlink->w; ++ quirc->height = inlink->h; + + return 0; + } +@@ -80,6 +83,15 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *frame) + int codes_count; + uint8_t *image; + ++ if (quirc->width != inlink->w || quirc->height != inlink->h) { ++ if (quirc_resize(quirc->quirc, inlink->w, inlink->h) < 0) { ++ av_frame_free(&frame); ++ return AVERROR(ENOMEM); ++ } ++ quirc->width = inlink->w; ++ quirc->height = inlink->h; ++ } ++ + /* copy input image to quirc buffer */ + image = quirc_begin(quirc->quirc, NULL, NULL); + av_image_copy_plane(image, inlink->w, +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 9a2a3353ca4..b92676d4dbb 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -42,6 +42,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-66039.patch \ file://CVE-2026-66036_p1.patch \ file://CVE-2026-66036_p2.patch \ + file://CVE-2026-66041.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Sun Oct 11 08:40:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100347 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90231CA9EDA for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23455.1791708092944447034 for ; Sun, 11 Oct 2026 01:41:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=sdl9e7sz; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48c4d99c32bso887530f8f.1 for ; Sun, 11 Oct 2026 01:41:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708091; x=1792312891; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hOvwHmNt9Pa7/1EY0aMj62jPFdC3vfssiMePdXOqpcg=; b=sdl9e7szGw2mKrwhvq4k+9mU7uihaSpN+VxDv2OJLce/kG8BL369lDOlXFowgVo7W9 VwRfdozg6eJvkkhURUV5JMIm1j/wOMF7iQ8NtIq5nbwgl7Acg8Fp8hfJeotzGM5GeeZQ yfOCcXkAd8imdovo6FnTNUwZscTWUyKR+4GYQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708091; x=1792312891; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hOvwHmNt9Pa7/1EY0aMj62jPFdC3vfssiMePdXOqpcg=; b=NKf7RVbvpO/C/IJwPyzuXrA9mSf2gtr7hkXmt0/KQcRmxDMU01e2DHUD021hQWWlcV KaxGsBVz+SHjB0xEIOuf5T6jXGSkDnq2Mg54F2I93ixjRS5vI/O2gasD/YAbcV1rDLxF q1NGHIO3byKCTuGyEJ3w/qTzHB3R39CEB5WED8NMOihDBJHL0M5lm6BpS9F6btxsftTi +9WHpuW7WcLVxwEr8wmWvr+WmH2WOpsBo3PRF721wnDA7Mmvte+k7PqpWlBKmNfLpfUr HfGRindb8OiD6Z3h5p7ZD1Xrk6R9RYqGZV0Ddu7GVCV/fxO63307SncF8xrkSli6bIhX e/fg== X-Gm-Message-State: AFq9FYIuxF1DNaaVp7U8zcVNEG8jwQPlZGkzk6iO5LAdjZL4aAHYkBb/ xkserYo9PpS4T/R4qebQ4k/dEnPGM8uqKpK9jt6PxWKlGTbBbWBpqf1N128HHuSG7s+QeMJUkK/ 5uKP0+j0= X-Gm-Gg: AYBFou3c2TKOoLj0THQJ8HrJJnO+HSy3Hdt8Ke9XHahi0WfzvaJdW2MOfwKdOEzAdaq p1F44dMGX57umVmUc/0d86I//Q3dyUTtoj8aw0CtNFQP/sMIc0dShJi4iycwjohgGvGg7ZLAJ0O 9Dm8PuP5V5RMMwd/1qcgOxhSr1tQNIsXepNpNM539OArPe/NIAGmFh44F6SKynguk7N4u/Gh3LS aHG7X05HOrAiB1PUfk59WKiblHeMmIbnlPMGSXYcXFrOR9MEnGE/lmMC2XxxWciWTLxgUvXvsi1 jGDJBMmnC9d+uTZNH6GhYiTDTcSfppfieeKFXa0XHfFemHnjqw4KUxd3g2PS+GFnDFPtBdksvqe 5LYhqtgTwjSzitAsWKBgT9uTA8OTBelG9VdgD/HhvYvZY1Is3mu0Iulx4czJb9fffXK5tnTHKEn YwiYrnNnEw92N4G5dCOfrTSp/x73xzJbi2fCgo0M9pfwftvg+yIHW/L3z78Gj+NQL2rh256doP7 OasyxMgoZsqW5sdYrYPvZBSua0HAeFA5zmvX2TPCQE+0IS/vqOOdnz/091dlmey8ConMMCGNXM2 AxaHfCzy X-Received: by 2002:a05:6000:26ca:b0:48d:c15b:5d29 with SMTP id ffacd0b85a97d-48dc15b5de2mr9373751f8f.2.1791708091030; Sun, 11 Oct 2026 01:41:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 46/60] systemd: fix mDNS hostname changes Date: Sun, 11 Oct 2026 10:40:19 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247555 From: Peter Tatrai When a DNS-SD service unregisters, resolved re-probes its records. The looped-back mDNS announcement can then be treated as a conflicting reply, causing resolved to rename the host. Backport systemd commit 658e5ac06f80ee2078b034f7cc483204d7f91c5e to move the local-address check ahead of reply processing while continuing to allow legacy unicast queries from non-mDNS ports. This is needed on wrynose, which uses systemd 259.5 and checks local addresses only for queries. OE-Core master uses systemd 261, whose source already checks local addresses before the query/reply split. Signed-off-by: Peter Tatrai Signed-off-by: Yoann Congal --- ...use-traffic-from-the-local-host-only.patch | 61 +++++++++++++++++++ meta/recipes-core/systemd/systemd_259.5.bb | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-core/systemd/systemd/0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch diff --git a/meta/recipes-core/systemd/systemd/0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch b/meta/recipes-core/systemd/systemd/0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch new file mode 100644 index 00000000000..efdc2852f9e --- /dev/null +++ b/meta/recipes-core/systemd/systemd/0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch @@ -0,0 +1,61 @@ +From 658e5ac06f80ee2078b034f7cc483204d7f91c5e Mon Sep 17 00:00:00 2001 +From: Bret Comnes +Date: Thu, 26 Mar 2026 05:59:09 +0000 +Subject: [PATCH] Revert "resolve: refuse traffic from the local host only for + queries" + +This reverts commit 526f1594daec073269c3e70ee7914f6dd8740d5c. + +This revert is necessary because the change breaks mDNS hostname stability +whenever a DNS-SD service calls UnregisterService. When a service +unregisters (e.g. on process restart), manager_refresh_rrs() clears and +re-adds all RRs in PROBING state, which sends a multicast announcement +(QR=1). The kernel reflects this back to resolved's own socket. Because +the local-address check was moved inside the query-only branch by the +reverted commit, the reply path in on_mdns_packet() is now unguarded. +The looped-back announcement matches the pending probe transaction and +completes it with DNS_TRANSACTION_SUCCESS. Since the zone item is still +in PROBING state (not ESTABLISHED), dns_zone_item_notify() sets +we_lost=true and calls dns_zone_item_conflict(), which invokes +manager_next_hostname() and renames the hostname (e.g. foo.local to +foo4.local). This happens reliably on every restart of any service using +RegisterService/UnregisterService (homebridge, avahi-compat wrappers, +etc.). + +The top-level local-address check in on_mdns_packet() suppresses all +looped-back multicast traffic before the reply/query split. Restoring it +there is consistent with the overall design: dns_scope_check_conflicts() +already has its own manager_packet_from_local_address() guard and is +unaffected. + +A more targeted long-term fix (e.g. guarding dns_transaction_process_reply() +for mDNS, or avoiding unnecessary re-probing of already-established records +in manager_refresh_rrs()) can be pursued separately. + +Upstream-Status: Backport [https://github.com/systemd/systemd/commit/658e5ac06f80ee2078b034f7cc483204d7f91c5e] +Signed-off-by: Peter Tatrai +--- + src/resolve/resolved-mdns.c | 16 ++++++++-------- + 1 file changed, 8 insertions(+), 8 deletions(-) + +diff --git a/src/resolve/resolved-mdns.c b/src/resolve/resolved-mdns.c +--- a/src/resolve/resolved-mdns.c ++++ b/src/resolve/resolved-mdns.c +@@ -415,0 +416,8 @@ ++ /* Refuse traffic from the local host, to avoid query loops. However, allow legacy mDNS ++ * unicast queries through anyway (we never send those ourselves, hence no risk). ++ * i.e. check for the source port nr. */ ++ if (p->sender_port == MDNS_PORT && manager_packet_from_local_address(m, p)) { ++ log_debug("Got mDNS UDP packet from local host, ignoring."); ++ return 0; ++ } ++ +@@ -532,8 +539,0 @@ +- /* Refuse traffic from the local host, to avoid query loops. However, allow legacy mDNS +- * unicast queries through anyway (we never send those ourselves, hence no risk). +- * i.e. check for the source port nr. */ +- if (p->sender_port == MDNS_PORT && manager_packet_from_local_address(m, p)) { +- log_debug("Got mDNS UDP packet from local host, ignoring."); +- return 0; +- } +- diff --git a/meta/recipes-core/systemd/systemd_259.5.bb b/meta/recipes-core/systemd/systemd_259.5.bb index f3ec0edae72..e924884bf95 100644 --- a/meta/recipes-core/systemd/systemd_259.5.bb +++ b/meta/recipes-core/systemd/systemd_259.5.bb @@ -35,6 +35,7 @@ SRC_URI += " \ file://0001-meson-use-libfido2_cflags-dependency.patch \ file://0018-shared-fdset-add-detailed-debug-logging-to-fdset_new.patch \ file://0004-tpm2-util-fix-PCR-bank-guessing-without-EFI.patch \ + file://0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch \ " PAM_PLUGINS = " \ From patchwork Sun Oct 11 08:40:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100342 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 44AD6CA9ED5 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23580.1791708093396594415 for ; Sun, 11 Oct 2026 01:41:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jmO7zhCb; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48c4207ac26so959399f8f.0 for ; Sun, 11 Oct 2026 01:41:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708092; x=1792312892; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5SYQq43Arbkx6LNu7EH+ccpXmcn5RIKlUEakBft//rI=; b=jmO7zhCbzl8UVaygrsviobZod90uWHDs++zVZ5bJgcKY0xlIeeZuTUnmmZnKFHgOdT gNRBH7vpBDMVHCM8+OmX89VU0EGW+PMEPJrgFvSyhT7B5yrqUZOf1rnA/t42NNM8iDld tbiDkIv0TQKZPsUSEHV/O0gJa8KQ+lv2Pt1Zw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708092; x=1792312892; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5SYQq43Arbkx6LNu7EH+ccpXmcn5RIKlUEakBft//rI=; b=P6xj6hWxamadiXn9+Xhw5vVAugpUCSvCoMzv9EcOgIPp4ItRlHNH3RQ6vU+8Zho52U Vizv/b36Vw2t08DpqlQE34ATo/PfjD53fUN7rUozfnlBEX1llU6Nw8+JnBt9RKwkhn7Q uy25u4wZGAW7IxVWsjq4bLqAwBj4xUYSbI7/hxde5fXCvAqr3ylBehGhd8lCGtE6suWP A2QMi1oqAjSe02eVOx+A0GW9MpbV6RLeh+pVNCoygjY0SEErr/GlZD9bk+nbcRB+vvyA 87WoB7yVyhielC5+wkyu3ecavZEQPyLNM9U4f8YlkunPjiYWbC47Fs5K3UxZNWrMcecV KlKQ== X-Gm-Message-State: AFq9FYIKGe/37w/8Cbur3MR4HRT5gQnrxUUD4TywYHJiqkzHgNYs/0Fu AJQBOa0PEC1+TMhMIMLNRZeyuhv7JB/5WtACFhHsyj4iSerEyXt8qiZqjjUIQ0bw0NX2P95A9e6 1N8uasNk= X-Gm-Gg: AYBFou2uywxxxxqIHlMJK+HVMvUHJ3+A9MNvW50r7iD6KiA8s61Wi/BCjZvvOawC+OX ifrdCq7dt5mBI+VwD5sF5VlhNSlRzM/DeykgsY+07+lmegX/IuYNskNcvh9fdtfi9V8Dujyud15 tUiFnYDl6/if8nsP3M1bjsSamI54Lbl2t2F9nheXGOdFPTpnS+S1rFsFXHM1sYCzBJzvxjSwpE8 ua11BOeatrmeeeiQzH39vnVioZ1ExvLNrShYG2+7nz1tcjz8XJDetqRTOue2tFTRVDZ9Jnv3Y9b sOig9ildoEa+tGr7fwXcpT67v9SvH1kR6yaM9hjjpNW7N+LMfu/8j4nt0KcjPQQDBNI+pFTt3Xk n8P6C7xcHHPGEG/p4a1ijzLtVTPCGfySTluIdPGl04Jo6Ry8032YZPJRWHe3P+9orIQftdVkPjv /ZRRBGswjIS9JasBLPMNUpxUq6IWxZkPreP9UFXaSWMpxodvhzRJJDIqC7fZveYEV0s+77UUV2Q RlYp5L7WO81XLJlmazP0kXsplbT+4OfsdnZQ90mqRt1KkF4mvwxBZgotOLPJBy00BAOgumYsw== X-Received: by 2002:a5d:504d:0:b0:48b:1b6:3df8 with SMTP id ffacd0b85a97d-48dbaaefac4mr8666211f8f.35.1791708091471; Sun, 11 Oct 2026 01:41:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 47/60] gstreamer: skip test_queue:test_leaky_downstream test as it's flakey Date: Sun, 11 Oct 2026 10:40:20 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247556 From: Ross Burton This test occasionally fails, so skip it. A bug has been filed upstream. [ YOCTO #15408 ] Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (cherry picked from commit ac8fa6ada2a0cf0ae27316837985dd57b01e727f) Signed-off-by: Yoann Congal --- meta/recipes-multimedia/gstreamer/gstreamer1.0/run-ptest | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0/run-ptest b/meta/recipes-multimedia/gstreamer/gstreamer1.0/run-ptest index 83a78fabd0f..d425eed825d 100755 --- a/meta/recipes-multimedia/gstreamer/gstreamer1.0/run-ptest +++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0/run-ptest @@ -27,4 +27,7 @@ GST_CHECKS_IGNORE="$GST_CHECKS_IGNORE,parser_convert_duration,parser_pull_frame_ # https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5163 GST_CHECKS_IGNORE="$GST_CHECKS_IGNORE,test_device_monitor" +# https://bugzilla.yoctoproject.org/show_bug.cgi?id=15408 +GST_CHECKS_IGNORE="$GST_CHECKS_IGNORE,test_leaky_downstream" + gnome-desktop-testing-runner --parallel=4 gstreamer "$@" From patchwork Sun Oct 11 08:40:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100341 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 36576CA9ED3 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23581.1791708093797545806 for ; Sun, 11 Oct 2026 01:41:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=R/X77V4n; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48c4be28b82so869626f8f.2 for ; Sun, 11 Oct 2026 01:41:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708092; x=1792312892; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=8JT4plW57wsD//XFDoB+0kiDGKejYZxeW6h9BQXPE5M=; b=R/X77V4n30nHSO1j9BrG5eJYMbs9KaK4BAgNVBUayafWgBybu77lAEeKeyG07wGzKg uUnl8a66SCwMLISllVA3SqD2qwNWBrnGwBS5c2fw3Ou6Rq8Y3hFMICDWExDIpT1jxf0W KoLr1OPkT/1KW4TlwD0OnqJkB3P2qzPt1wuG4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708092; x=1792312892; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=8JT4plW57wsD//XFDoB+0kiDGKejYZxeW6h9BQXPE5M=; b=YXGyT93HwSDKHkXJruHdow2pBha9e0ODVnz/Nn/JvxkevXVfqpAYwN0mMDk7zV1uPa YONPmKHsoHCXIm4nitwDpJMpkP7ae2Msm/02PXwt9+o3GgGdSjzwdaxKlrs0sL4VLpP+ MAbZ0XKLL5Xe988bucrghCkVes0Cj5TSkGuGO3oMOBF/MYQc3UpQD4ojT41RTUlF3c5O 6R6gvENuLpxPjnRuT/Hnqv4VIKj5OKUd7itPJPuXgqOvRQ7WdADBUNy0G2vsQDdgzile Ifyrufo/wox3iU1fUad9+qYXnRtmpRfQ4q9yyEgpI1xHC0r3jsdUa8AOwm+zkaxSFWzp PmvA== X-Gm-Message-State: AFq9FYJGDg3964T20ITRd81yQVqlWnp3dKjiME74NNMTXvfuxL+nRhsX /XinZ5MePQZuIP7eAkHxL5spgxwF8ioIb1VshJskwxfy40aWwWlmR4Xf9Q2wb1XoNvAglG+3yur pYrTEq8M= X-Gm-Gg: AYBFou2+vgH8VB2spVFlHTALPLO0lUW1miFI+vgSMA/He1jK5In62BteiRSYSTSanQU 7xrqHJVVd/ifJgXEx1QJvhv2TRmQ2zzqHxS2Fu9YzarLqdjO0B7vKUE3Z4m9JeCpfgXktQXEQWx kja5TDNeuNq8ObmS32o/vZWfy1gKThZUH90KMEHCYjhdjcPShRyT8z1VbSvbQbTy7ZdLxhVCY1X /Cl9HkAnk4l5HtK9OnNIfbp4ae5DI4jQsrKU4P82xbj1uGzJU7q6mIendxdLnvxk1CBQCAMOzTg ykmZFYkLX4muUvmz9dyHZE51ifs/52rFsl02XsR7q+Wyt2G+mLMP+Huewnm3n7H4x0ft9uBRvXf SkRqVIPEp7jWXukSqkvvp5ruyWf9/ahhrz7mGOumZ5oVE8pYEi2Q6nhZiWJV6DKKYruHecNsT3e xb4G35JiHx3lbgL8xANPMGPaK6WU61YaN1JcBP/5c3t+6uRaKvm2HVSahfzAVStzUM+gHLPi6ei cA4oJGp20/d4DjFaGJW34kKKE0F0NDAwEDw8unfUby1aih6ec/gGB0VSzkhOW/8ywgDIa60Bg== X-Received: by 2002:a05:6000:46db:b0:48b:e50:7152 with SMTP id ffacd0b85a97d-48dbaae21dcmr7723655f8f.28.1791708091991; Sun, 11 Oct 2026 01:41:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 48/60] libaio: update SRC_URI Date: Sun, 11 Oct 2026 10:40:21 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247557 From: Ross Burton libaio has moved to Codeberg as pagure.io will be closed down shortly. Signed-off-by: Ross Burton Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit 237c32e181cd47194c3877d220360d6e6fbb2af8) Suggested-by: Preeti Sachan Signed-off-by: Yoann Congal --- meta/recipes-extended/libaio/libaio_0.3.113.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-extended/libaio/libaio_0.3.113.bb b/meta/recipes-extended/libaio/libaio_0.3.113.bb index 2392fd5db23..5f4c5547a11 100644 --- a/meta/recipes-extended/libaio/libaio_0.3.113.bb +++ b/meta/recipes-extended/libaio/libaio_0.3.113.bb @@ -5,7 +5,7 @@ HOMEPAGE = "http://lse.sourceforge.net/io/aio.html" LICENSE = "LGPL-2.1-or-later" LIC_FILES_CHKSUM = "file://COPYING;md5=d8045f3b8f929c1cb29a1e3fd737b499" -SRC_URI = "git://pagure.io/libaio.git;protocol=https;branch=master \ +SRC_URI = "git://codeberg.org/jmoyer/libaio.git;protocol=https;branch=master;tag=${BP} \ file://00_arches.patch \ file://libaio_fix_for_mips_syscalls.patch \ file://system-linkage.patch \ From patchwork Sun Oct 11 08:40:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100337 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1DEDDCA9ED2 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23456.1791708094233825546 for ; Sun, 11 Oct 2026 01:41:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kGMpzrZd; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48b0ef9c76eso780251f8f.0 for ; Sun, 11 Oct 2026 01:41:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708092; x=1792312892; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vgeB+lzCbWrePotXrQUQAjiDROIT/i2rdF/8vE7AbJI=; b=kGMpzrZdT0JWLl0aOouIuLN86vSTiVxRZW+05vXiv8jX+2OUVwL6idSYuvVMTUeBTl byYcsz//PJJ3FIrvIrNKbcHp8ftMOpHGW4LGjQKTrbdKkvzCr1QTzyXMq3WxVD8mK/qg 70n+iWxMJLRd2tMlpGLWoTR5Gj7GbsTUUQIVs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708092; x=1792312892; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vgeB+lzCbWrePotXrQUQAjiDROIT/i2rdF/8vE7AbJI=; b=wozU56vt7Q72DfQmLS974t96bUOu3fB5nGGecl2FVltHrsWEIqFKDtdiGbZfZKpKPi I8uGPRRyJ83wz38kXSDk8QmU0MmFnuVAUa/M2YyVYOSHL5GGHzsyqgWyE/CnHZygKY5E PFPTKY4eVi6+rSclJruEMVH8ffeIQt3iT0Yk9a5Jsun/pizFSJsUzo0XLvJMBz2r3c4x 6bpTqogvtq56wHDQkHbc/AH5tO6XJ6mVFC+X1QG4lg/wCMbnSfh3hsm4vxQycP19igjG qifZZHKbcfBUpyunMBkRmehRtEwbXLFWpAc3wbQok+d7ifF2NMF8OVqDPluOekgoJ4z1 7aYg== X-Gm-Message-State: AFq9FYITzwxh9jOQBEl6++FGFQvasXDa5jNamQJGlhPNy5E4MHMWSJ6E 6zAAW4UzWP3qLWVvdKnCit5vhPxTZLvAQBZCXF7gTRDbrcFH6mjcHWbvVD7HDjSMw4z1udZ0J1N 5Ambf08M= X-Gm-Gg: AYBFou2tGyOGjSj8xkAyGS5MVsDXWz8lhDzl4HDt5yJUEH/JDhcr3ZTyEc2GWFOFapS G2rsM094k9Sshap2HS0lAdbxuztC30LUjykNJpZh8Jmdq4I53mWXIaJLXiZeUis3GJaIWJ5djyZ hVjtfWdA34K3TFDv4Zvl5D7mB5ETRjaQ6gBZwKPum8ZplNwxXEb1y0RYNhEhmPpnaCY4BZyOu7E 9/FA20EOotD/Hz/m0Ptcu0YT0UqYikZvrsFqY9AtefGc1n1OUMLgC91MSdMD3T9JZNJIjpP3YX/ s48R+PP1yD4Wx3cs7FdySChmRWJZ+Ubuc8K1JFg/NBHfZ8HN9TqTyHKKaBxfLIkqGRHYDN0lZfP 9/P0Ib0QRMUj7J0uwt7gLPWdnjkQtsXklGtemxguFb3eJLlUZG3lTIoEcoYeMn1R7Qd7OVr0iyU BfeBicUx1ZoN0UpHfCkLPD0Q0jkMiJ5Ri5yzHDLihK2jHh4RIYcwI0veun4YkVODfJr2O85K9vD /QgmkpMpBGMrnpUdSXkl6OrxXZ60eudoOjbOxiFabWvsp7RVw41i2H2xAkKPUKv2/kMWX3OTQ== X-Received: by 2002:a05:6000:29d6:b0:487:40d:af29 with SMTP id ffacd0b85a97d-48dba9dd94fmr7395142f8f.36.1791708092430; Sun, 11 Oct 2026 01:41:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 49/60] alsa-lib: patch CVE-2026-90781 Date: Sun, 11 Oct 2026 10:40:22 +0200 Message-ID: <9ccc05d027b9a85e1703bf4cbde8103a03e7a95c.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247558 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-90781 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../alsa/alsa-lib/CVE-2026-90781.patch | 41 +++++++++++++++++++ .../alsa/alsa-lib_1.2.15.3.bb | 1 + 2 files changed, 42 insertions(+) create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch diff --git a/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch new file mode 100644 index 00000000000..b2b2ce84cff --- /dev/null +++ b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch @@ -0,0 +1,41 @@ +From f84cd4ced7b36fddb8e4ee24404cf7c091d27020 Mon Sep 17 00:00:00 2001 +From: Jaroslav Kysela +Date: Sun, 30 Aug 2026 20:20:30 +0200 +Subject: [PATCH] control: ctlparse - another fix for one-byte overrrun in + __snd_ctl_ascii_elem_id_parse + +Follows 1e27d63ef6d1dcf7d1f1a1e1eca3ea779e7de377 . + +Link: https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/ +Reported-by: Harsh Raj Singhania +Signed-off-by: Jaroslav Kysela + +CVE: CVE-2026-90781 +Upstream-Status: Backport [https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020] +Signed-off-by: Peter Marko +--- + src/control/ctlparse.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/control/ctlparse.c b/src/control/ctlparse.c +index c40de2bd..7132210e 100644 +--- a/src/control/ctlparse.c ++++ b/src/control/ctlparse.c +@@ -207,7 +207,7 @@ int __snd_ctl_ascii_elem_id_parse(snd_ctl_elem_id_t *dst, const char *str, + if (*str == '\'' || *str == '\"') { + c = *str++; + while (*str && *str != c) { +- if (size < (int)sizeof(buf)) { ++ if (size < (int)sizeof(buf) - 1) { + *ptr++ = *str; + size++; + } +@@ -217,7 +217,7 @@ int __snd_ctl_ascii_elem_id_parse(snd_ctl_elem_id_t *dst, const char *str, + str++; + } else { + while (*str && *str != ',') { +- if (size < (int)sizeof(buf)) { ++ if (size < (int)sizeof(buf) - 1) { + *ptr++ = *str; + size++; + } diff --git a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb index 04976f3bf77..3081a522cba 100644 --- a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb +++ b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb @@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=a916467b91076e631dd8edb7424769c7 \ SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2" SRC_URI += "file://CVE-2026-25068.patch" SRC_URI += "file://CVE-2026-56109.patch" +SRC_URI += "file://CVE-2026-90781.patch" SRC_URI[sha256sum] = "7b079d614d582cade7ab8db2364e65271d0877a37df8757ac4ac0c8970be861e" inherit autotools pkgconfig From patchwork Sun Oct 11 08:40:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100344 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7C9DCCA9ED9 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23582.1791708094840193614 for ; Sun, 11 Oct 2026 01:41:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UH08cSvI; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48c6955a7c3so127386f8f.1 for ; Sun, 11 Oct 2026 01:41:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708093; x=1792312893; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BelhuWgZeTNqIxMMezqPO2dYte6ayPenCdud4jrLP+A=; b=UH08cSvIL51fkIUCpqrIYxA+Ylgq/KrzefibPaFdYqgykObvzTLfOSq5piecCZXerX Rr1TUg1ZNVCbX/tSU1BIJSzHHQUIk2TErQ+F513gQZJ8Az+G51cT+O/J374qGZaUdy2R uVNeqdLMGRp1cmxQIaDuCM2dqmV0D9u3y87xk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708093; x=1792312893; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=BelhuWgZeTNqIxMMezqPO2dYte6ayPenCdud4jrLP+A=; b=c2b6IpQ17rAsTG0UdNYVFYlBVdtjixdgjh1QGFU/G0Wr0yIFdYfZJ8c7LPPwRLZGm6 qXIDXhTdfTJoYLsHoeLLbVZ3xZHnmHb/7FeOHQtkdHVjJusIAoeiLki2KFZjTZrax8xe jfR4D8C+gfvqSaU+smqeJyVG8N3G85+BjzlYSuwzNgh9QSkrpt/UphN5JRqWzqTS7hzC lFucTA5SGPPe5YNTNsRKexWUKSlCDzW+7v3qCrPog0DYRJDvOQnm/AC/dKNeDuifcg8h VvjL03+49mgjaSJSHqZHt1qzmDW9CnjR0b+UIO3JEASIhChoteRjo4LG6Dqpi9YicfE8 xqPQ== X-Gm-Message-State: AFq9FYJ7W6EheM/tw7NCq/YpAT6RVsS2dMBCoH/ILEq86KWEYhkNR1l8 U/ylteYkTaU/qxZVhiKm8jjg5yf/p9UvVBsFnxBRekU5UOF8kJS89FmgP20Ns5VCr3T1r3uZsjz ObW0x/6Q= X-Gm-Gg: AYBFou0mOKMIz7i2pPjx2C+vPN1CU2L8z/5mR0DJU67bradiU45pDH7Plg5vq1+qiUn iMxdiT/tDE1dDRVZSjTqLRNoA+KXsxwhmnTE7etWu1fK5vjhUXUXZ6a8uncQyf9RtH6GPNferXR hIJrurFm9R4KprVyOST/rxG2LMx2Sdpa25XKiwZ6KbPonabpL4qn8EUgJkly4nax3mQtXtKQWMs zmLuIscO/mLDbOPuwcoYBFct2o8+XkpqeF8hZhyYItq/MFnMP+wxU+WALml4qXOUyJnji7aZWqc cVmNgmmMRbGm3SHxqoWYXHP+vnXi+uzi133wpi7nLSXS+TwoAgNONTzv2fd8idf5FjN8KwbI2DJ KiJ0/OBfHCubrWUcxn6yAG6EKh6W+7KrUacIGSE3QZcLXSxWztOzubvoKmAaBrH4ovVvw9mNfqy B3ScfGBbSEV/K9P4hB+9SlVLvHTLDMF8S5MtCTgWabrSoRIfmgS3w7VYju67TKU0c+ORwqHnwza v9tV9Bt8xrPJ6bPMAp7TLUitwsZktJSG95GNfEYulpMdoZ/oTWY2RGjSDWkkvSetT4YtIlh0w== X-Received: by 2002:a05:6000:454b:b0:48c:7143:610c with SMTP id ffacd0b85a97d-48dbad1252fmr7168733f8f.36.1791708093020; Sun, 11 Oct 2026 01:41:33 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 50/60] weston: fix VNC backend build with aml 1.0 Date: Sun, 11 Oct 2026 10:40:23 +0200 Message-ID: <6331d7ef8e03226460cc7effc07dc3bfe674cadb.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247559 From: Frieder Schrempf meta-oe's aml 1.0 installs aml1.pc, but weston 15 looks for aml 0.3.x, so enabling the vnc PACKAGECONFIG fails at configure time. Backport the aml part of the upstream fix from weston 16 and add aml to the vnc dependencies, as weston uses it directly. Tested by building weston with PACKAGECONFIG vnc for ARMv7. AI-Generated: Uses Claude Code (Claude Opus 5.5) Signed-off-by: Frieder Schrempf Signed-off-by: Yoann Congal --- .../weston/0001-backend-vnc-Use-aml-v1.patch | 24 +++++++++++++++++++ .../recipes-graphics/wayland/weston_15.0.0.bb | 3 ++- 2 files changed, 26 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-graphics/wayland/weston/0001-backend-vnc-Use-aml-v1.patch diff --git a/meta/recipes-graphics/wayland/weston/0001-backend-vnc-Use-aml-v1.patch b/meta/recipes-graphics/wayland/weston/0001-backend-vnc-Use-aml-v1.patch new file mode 100644 index 00000000000..c752a2b3624 --- /dev/null +++ b/meta/recipes-graphics/wayland/weston/0001-backend-vnc-Use-aml-v1.patch @@ -0,0 +1,24 @@ +From: Frieder Schrempf +Subject: [PATCH] backend-vnc: Use aml v1 + +aml 1.0 installs aml1.pc and neatvnc already uses it. Only the aml part +of the upstream commit is taken, as the rest needs Neat VNC 1.0. + +Upstream-Status: Backport [partial, https://gitlab.freedesktop.org/wayland/weston/-/commit/8a1c91e7] +Signed-off-by: Frieder Schrempf +--- + libweston/backend-vnc/meson.build | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/libweston/backend-vnc/meson.build b/libweston/backend-vnc/meson.build +--- a/libweston/backend-vnc/meson.build ++++ b/libweston/backend-vnc/meson.build +@@ -8,7 +8,7 @@ if not dep_neatvnc.found() + error('VNC backend requires neatvnc which was not found. Or, you can use \'-Dbackend-vnc=false\'.') + endif + +-dep_aml = dependency('aml', version: ['>= 0.3.0', '< 0.4.0'], required: false, fallback: ['aml', 'aml_dep']) ++dep_aml = dependency('aml1', version: ['>= 1.0.0', '< 2.0.0'], required: false, fallback: ['aml', 'aml_dep']) + if not dep_aml.found() + error('VNC backend requires libaml which was not found. Or, you can use \'-Dbackend-vnc=false\'.') + endif diff --git a/meta/recipes-graphics/wayland/weston_15.0.0.bb b/meta/recipes-graphics/wayland/weston_15.0.0.bb index da347659f12..3f9fff51fd4 100644 --- a/meta/recipes-graphics/wayland/weston_15.0.0.bb +++ b/meta/recipes-graphics/wayland/weston_15.0.0.bb @@ -9,6 +9,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=d79ee9e66bb0f95d3386a7acae780b70 \ SRC_URI = "https://gitlab.freedesktop.org/wayland/weston/-/releases/${PV}/downloads/${BPN}-${PV}.tar.xz \ file://0001-vulkan-renderer-guard-surface-output-creation-with-b.patch \ file://0001-gl-shaders-Remove-asserts-relying-on-shader-compiler.patch \ + file://0001-backend-vnc-Use-aml-v1.patch \ file://weston.png \ file://weston.desktop \ file://xwayland.weston-start \ @@ -98,7 +99,7 @@ PACKAGECONFIG[image-jpeg] = "-Dimage-jpeg=true,-Dimage-jpeg=false, jpeg" # screencasting via PipeWire PACKAGECONFIG[pipewire] = "-Dbackend-pipewire=true,-Dbackend-pipewire=false,pipewire,pipewire" # VNC remote screensharing -PACKAGECONFIG[vnc] = "-Dbackend-vnc=true,-Dbackend-vnc=false,neatvnc libpam" +PACKAGECONFIG[vnc] = "-Dbackend-vnc=true,-Dbackend-vnc=false,neatvnc aml libpam" # Perfetto performance analysis support PACKAGECONFIG[perfetto] = "-Dperfetto=true,-Dperfetto=false,libperfetto" From patchwork Sun Oct 11 08:40:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100340 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 02EC7CA9ED0 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23583.1791708095508823060 for ; Sun, 11 Oct 2026 01:41:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eVNzMLqn; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48c4be28b82so869638f8f.2 for ; Sun, 11 Oct 2026 01:41:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708094; x=1792312894; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gCRvd2sQ7vyPuT3O/M9IajHe+2y2Lc+HofrVMOmx0Hw=; b=eVNzMLqnQRJbzZRZv06JtJYsfyNjfa30cJt97eRNB52op4eeLKCqoOPu8Pb2uludFk D1NOhqsB2w/DZwhVeDFkm5SIJzQjIWKNYStigE64YEOdXcmYp3epOS2M52dcD3ZWvG+L 9HC5Ar7TDtfyerjRvtBE3lnchA0JkCRNRsgpU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708094; x=1792312894; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gCRvd2sQ7vyPuT3O/M9IajHe+2y2Lc+HofrVMOmx0Hw=; b=OwVpLA5lLt5xD+nhaI2UDy//9NSCgqf9vfMPQmqlKTr5/25855CAm2KlAlVlrP3CSb EEuda0v2rTLYL1zwFzPhltoNaEsyAdAPTrGBbG5Gz13EgyLFy/oc94bQCcDkZhsOpXAt KElualZhUfyJf97nePE9uix7z61oYdZXo9QV0K/cI4qteBezhhkf/3dVUY6H9KtZ+03S SVE5IuMu1xeOcgzOL8ccZhldeCvBad2lwyrNIwYE0e8hMI8rN+GxxEm/2UxyF6Cantj0 FtGRS2WOvFniH4Ax7g4pdhI16aKOINwfpl//V+azfFYLpF1paNb41XubnNguB0GXBna6 YUnQ== X-Gm-Message-State: AFq9FYJMvFNt4EP56Lf1Z0GIhrqTshgcFBhYenLl0Jtfmv5TMa15HNo/ YmxW04PxO+HulZQ0gMCGwXOJYv2nGpARBpf4PV7noKvD/IngftDb8Olru9BzfmrsX3z3Zczi5+z 0CQDesz8= X-Gm-Gg: AYBFou2NDLA/uqKQsb1MXKAhWpKPtXPi8KYwtS5QL1ymRwVrBUK4pIzhGBn/+oTDhCw TBQGJFtJ2pwn1MXjdp0wdn0rXjFF6oGVhJjC/LQAdO1FsjQGxGTyHhG3BqtCALjleEGNJqtcBiC RyRO6ipq41ORB6QhTs09ooCXYvDIt20nqjLPpKCMR+uwPpu/aWiis/qKNacJnguycTohD/fQczK 2bPcLn8seDDG1K/qq6BwRZGK4abgH7izunbAHfLGhui1oiFyuRneZekP7Ds64qrmRaNZKm9QlUv QSQ9hhkkr+P9y7vViQA6wHQ3rJRP9VmQiZq4PVU03FOhGB3ENN87kSg/+UdNBLcsMcvJqJuOFU/ UxN2IgZvWdhof3Yd2qJqhjFR/cBn5DGcH5+kvICQ2kfIPJHhsVT6KZlgtaOaHSrxEyYncC+0mqP T8R9zJg6vL0CD1mVSs9CF/fr7qMAp701iIUo66V2qnLGp+9k4p/IsyD3OC3P1RO9/sWzfZrBEt7 9zdZmclSPjO+Ogl00mYdH8PkVG8px6rZMkzVGzNEfHhskMcivqR2TzZT0wefyXoRoVCbPjg5Q== X-Received: by 2002:a05:6000:29d5:b0:48c:4f83:f432 with SMTP id ffacd0b85a97d-48dbaae70b9mr7279617f8f.35.1791708093476; Sun, 11 Oct 2026 01:41:33 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:33 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 51/60] go: upgrade 1.26.8 -> 1.26.9 Date: Sun, 11 Oct 2026 10:40:24 +0200 Message-ID: <46dc7844b2df99b65b1e84b421273538aa1148b3.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247560 From: Peter Marko Upgrade to latest 1.26.x release [1]: $ git --no-pager log --oneline go1.26.8..go1.26.9 2ae494ef9f (tag: go1.26.9) [release-branch.go1.26] go1.26.9 6e04952188 [release-branch.go1.26] net/http: bundled HTTP/2 vuln fixes eb25b4e532 [release-branch.go1.26] net/http: limit the size of range headers parsed in ServeContent be88124d06 [release-branch.go1.26] os: correct Root junction handling on Windows (avoid mkdir escape) 087de1ff08 [release-branch.go1.26] net/http: avoid server reuse of connection after CONNECT 3fe1aac0ce [release-branch.go1.26] net/http, net/http/httputil: avoid post-CONNECT pool corruption d7a7aa8e67 [release-branch.go1.26] net/textproto: enforce MIME memory limit on first line eb1bf6e0c4 [release-branch.go1.26] crypto/tls: validate ECH outer extension references 7325b729f0 [release-branch.go1.26] cmd/go: always verify toolchain downloads with sumdb 5fa9de4696 [release-branch.go1.26] cmd/go: bundle go.sum h1 hashes for golang.org/fips140 5d84f6f08c [release-branch.go1.26] html/template: recognize `yield` as regexp preceder keyword e59c03e695 [release-branch.go1.26] html/template: reset JS context for template expressions 7060ef9d77 [release-branch.go1.26] cmd/link: pass -no_fixup_chains to C linker when building plugin on macOS 305bfa6252 [release-branch.go1.26] cmd/go: include VetxOnly in the vet action ID 179610a1ed [release-branch.go1.26] os: preserve completion notification modes for NewFile handles 2a1834bf42 [release-branch.go1.26] cmd/compile: fix slice backing store analysis c7183cd20d [release-branch.go1.26] os: handle unsupported OBJ_DONT_REPARSE on older Windows 19777cc57f [release-branch.go1.26] cmd/compile: don't stack-allocate a slice whose element interior escapes 5bf869b5ac [release-branch.go1.26] internal/runtime/syscall/linux: sync EpollEvent with the kernel header 6a97c5bf7c [release-branch.go1.26] net/http: vendor in CL 836505 ee49ded5ca [release-branch.go1.26] cmd/compile: fix large riscv64 move/zero 25d767a9a1 [release-branch.go1.26] runtime: netpoll: fix 32-bit little-endian eventfd type confusion 5e38ca6aaa [release-branch.go1.26] runtime: disable mutex profile during async preemption on windows 2c99952588 [release-branch.go1.26] crypto/mlkem: fix FIPS 130-3 CAST Fixes CVE-2026-97032, CVE-2026-78659, CVE-2026-97031, CVE-2026-94444, CVE-2026-94447, CVE-2026-94448, CVE-2026-97030, CVE-2026-94440, CVE-2026-56866, CVE-2026-94439, CVE-2026-78669, CVE-2026-78660, CVE-2026-56857, CVE-2026-78667 and CVE-2026-78663. Release information: [2] [1] https://github.com/golang/go/compare/go1.26.8...go1.26.9 [2] https://groups.google.com/g/golang-announce/c/U2fTuyDJznI Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/{go-1.26.8.inc => go-1.26.9.inc} | 2 +- ...binary-native_1.26.8.bb => go-binary-native_1.26.9.bb} | 6 +++--- ...oss-canadian_1.26.8.bb => go-cross-canadian_1.26.9.bb} | 0 .../go/{go-cross_1.26.8.bb => go-cross_1.26.9.bb} | 0 .../go/{go-crosssdk_1.26.8.bb => go-crosssdk_1.26.9.bb} | 0 .../go/{go-runtime_1.26.8.bb => go-runtime_1.26.9.bb} | 0 ...go-make-content-based-hash-generation-less-pedan.patch | 8 ++++---- .../go/go/0003-ld-add-soname-to-shareable-objects.patch | 6 +++--- .../go/0006-cmd-go-make-GOROOT-precious-by-default.patch | 2 +- ....go-filter-out-build-specific-paths-from-linker-.patch | 4 ++-- meta/recipes-devtools/go/{go_1.26.8.bb => go_1.26.9.bb} | 0 11 files changed, 14 insertions(+), 14 deletions(-) rename meta/recipes-devtools/go/{go-1.26.8.inc => go-1.26.9.inc} (90%) rename meta/recipes-devtools/go/{go-binary-native_1.26.8.bb => go-binary-native_1.26.9.bb} (80%) rename meta/recipes-devtools/go/{go-cross-canadian_1.26.8.bb => go-cross-canadian_1.26.9.bb} (100%) rename meta/recipes-devtools/go/{go-cross_1.26.8.bb => go-cross_1.26.9.bb} (100%) rename meta/recipes-devtools/go/{go-crosssdk_1.26.8.bb => go-crosssdk_1.26.9.bb} (100%) rename meta/recipes-devtools/go/{go-runtime_1.26.8.bb => go-runtime_1.26.9.bb} (100%) rename meta/recipes-devtools/go/{go_1.26.8.bb => go_1.26.9.bb} (100%) diff --git a/meta/recipes-devtools/go/go-1.26.8.inc b/meta/recipes-devtools/go/go-1.26.9.inc similarity index 90% rename from meta/recipes-devtools/go/go-1.26.8.inc rename to meta/recipes-devtools/go/go-1.26.9.inc index 7fa02ad7100..e2657cf8ad8 100644 --- a/meta/recipes-devtools/go/go-1.26.8.inc +++ b/meta/recipes-devtools/go/go-1.26.9.inc @@ -16,4 +16,4 @@ SRC_URI += "\ file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \ file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \ " -SRC_URI[main.sha256sum] = "4e39b98e42f946fa05ac8bc5b71877df97dbdb7cbb1a777b541667ad7117fd2e" +SRC_URI[main.sha256sum] = "9735d7dcdb65b35d3fa577f04064737c03b89cf1a2b71e6e69fe2f3c6f9fd4ca" diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.8.bb b/meta/recipes-devtools/go/go-binary-native_1.26.9.bb similarity index 80% rename from meta/recipes-devtools/go/go-binary-native_1.26.8.bb rename to meta/recipes-devtools/go/go-binary-native_1.26.9.bb index 1865c700fd4..a42ce443604 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.26.8.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.26.9.bb @@ -9,9 +9,9 @@ PROVIDES = "go-native" # Checksums available at https://go.dev/dl/ SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}" -SRC_URI[go_linux_amd64.sha256sum] = "d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b" -SRC_URI[go_linux_arm64.sha256sum] = "211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0" -SRC_URI[go_linux_ppc64le.sha256sum] = "0ddf3ecab842013e6bd618602823a0b8158a18d3e9362f2540463ea5aa184975" +SRC_URI[go_linux_amd64.sha256sum] = "42d158b4d8f7b61ac0a830567c940a86098fb7aac52e467a5ebec03ef5cc2f8d" +SRC_URI[go_linux_arm64.sha256sum] = "4a97373d49fcacdcf3694fea368a500b00ee3e963974f3e7514132717632f052" +SRC_URI[go_linux_ppc64le.sha256sum] = "a21a65001146ca0c6c022c690d5418f8298c5513a81fb5eed42f6cdb29f40063" UPSTREAM_CHECK_URI = "https://golang.org/dl/" UPSTREAM_CHECK_REGEX = "go(?P\d+(\.\d+)+)\.linux" diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.8.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.9.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross-canadian_1.26.8.bb rename to meta/recipes-devtools/go/go-cross-canadian_1.26.9.bb diff --git a/meta/recipes-devtools/go/go-cross_1.26.8.bb b/meta/recipes-devtools/go/go-cross_1.26.9.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross_1.26.8.bb rename to meta/recipes-devtools/go/go-cross_1.26.9.bb diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.8.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.9.bb similarity index 100% rename from meta/recipes-devtools/go/go-crosssdk_1.26.8.bb rename to meta/recipes-devtools/go/go-crosssdk_1.26.9.bb diff --git a/meta/recipes-devtools/go/go-runtime_1.26.8.bb b/meta/recipes-devtools/go/go-runtime_1.26.9.bb similarity index 100% rename from meta/recipes-devtools/go/go-runtime_1.26.8.bb rename to meta/recipes-devtools/go/go-runtime_1.26.9.bb diff --git a/meta/recipes-devtools/go/go/0001-cmd-go-make-content-based-hash-generation-less-pedan.patch b/meta/recipes-devtools/go/go/0001-cmd-go-make-content-based-hash-generation-less-pedan.patch index 077bebe743b..cd61571e2c7 100644 --- a/meta/recipes-devtools/go/go/0001-cmd-go-make-content-based-hash-generation-less-pedan.patch +++ b/meta/recipes-devtools/go/go/0001-cmd-go-make-content-based-hash-generation-less-pedan.patch @@ -109,7 +109,7 @@ index 7b073165d5..1f618be0bb 100644 } // Configuration specific to compiler toolchain. -@@ -2804,8 +2806,25 @@ func envList(key, def string) []string { +@@ -2805,8 +2807,25 @@ func envList(key, def string) []string { return args } @@ -136,7 +136,7 @@ index 7b073165d5..1f618be0bb 100644 if cppflags, err = buildFlags("CPPFLAGS", "", p.CgoCPPFLAGS, checkCompilerFlags); err != nil { return } -@@ -2821,6 +2840,13 @@ func (b *Builder) CFlags(p *load.Package) (cppflags, cflags, cxxflags, fflags, l +@@ -2822,6 +2841,13 @@ func (b *Builder) CFlags(p *load.Package) (cppflags, cflags, cxxflags, fflags, l if ldflags, err = buildFlags("LDFLAGS", DefaultCFlags, p.CgoLDFLAGS, checkLinkerFlags); err != nil { return } @@ -150,7 +150,7 @@ index 7b073165d5..1f618be0bb 100644 return } -@@ -2909,7 +2935,7 @@ func (b *Builder) runCgo(ctx context.Context, a *Action) error { +@@ -2910,7 +2936,7 @@ func (b *Builder) runCgo(ctx context.Context, a *Action) error { cgoExe := base.Tool("cgo") cgofiles = mkAbsFiles(p.Dir, cgofiles) @@ -159,7 +159,7 @@ index 7b073165d5..1f618be0bb 100644 if err != nil { return err } -@@ -3462,7 +3488,7 @@ func (b *Builder) swigOne(a *Action, file, objdir string, pcCFLAGS []string, cxx +@@ -3463,7 +3489,7 @@ func (b *Builder) swigOne(a *Action, file, objdir string, pcCFLAGS []string, cxx p := a.Package sh := b.Shell(a) diff --git a/meta/recipes-devtools/go/go/0003-ld-add-soname-to-shareable-objects.patch b/meta/recipes-devtools/go/go/0003-ld-add-soname-to-shareable-objects.patch index 0b5026fc123..f7f4dbead93 100644 --- a/meta/recipes-devtools/go/go/0003-ld-add-soname-to-shareable-objects.patch +++ b/meta/recipes-devtools/go/go/0003-ld-add-soname-to-shareable-objects.patch @@ -22,7 +22,7 @@ diff --git a/src/cmd/link/internal/ld/lib.go b/src/cmd/link/internal/ld/lib.go index 2d8f964f35..dfc72e02c0 100644 --- a/src/cmd/link/internal/ld/lib.go +++ b/src/cmd/link/internal/ld/lib.go -@@ -1652,6 +1652,7 @@ func (ctxt *Link) hostlink() { +@@ -1660,6 +1660,7 @@ func (ctxt *Link) hostlink() { argv = append(argv, "-Wl,-z,relro") } argv = append(argv, "-shared") @@ -30,7 +30,7 @@ index 2d8f964f35..dfc72e02c0 100644 if ctxt.HeadType == objabi.Hwindows { argv = addASLRargs(argv, *flagAslr) } else { -@@ -1667,6 +1668,7 @@ func (ctxt *Link) hostlink() { +@@ -1675,6 +1676,7 @@ func (ctxt *Link) hostlink() { argv = append(argv, "-Wl,-z,relro") } argv = append(argv, "-shared") @@ -38,7 +38,7 @@ index 2d8f964f35..dfc72e02c0 100644 case BuildModePlugin: if ctxt.HeadType == objabi.Hdarwin { argv = append(argv, "-dynamiclib") -@@ -1675,6 +1677,7 @@ func (ctxt *Link) hostlink() { +@@ -1683,6 +1685,7 @@ func (ctxt *Link) hostlink() { argv = append(argv, "-Wl,-z,relro") } argv = append(argv, "-shared") diff --git a/meta/recipes-devtools/go/go/0006-cmd-go-make-GOROOT-precious-by-default.patch b/meta/recipes-devtools/go/go/0006-cmd-go-make-GOROOT-precious-by-default.patch index 9aebc2f0dc3..70e16a1d57c 100644 --- a/meta/recipes-devtools/go/go/0006-cmd-go-make-GOROOT-precious-by-default.patch +++ b/meta/recipes-devtools/go/go/0006-cmd-go-make-GOROOT-precious-by-default.patch @@ -94,7 +94,7 @@ index 1f618be0bb..651fa64582 100644 if err := sh.Mkdir(buildAction.Objdir); err != nil { return nil, err } -@@ -1888,6 +1905,14 @@ func (b *Builder) linkShared(ctx context.Context, a *Action) (err error) { +@@ -1889,6 +1906,14 @@ func (b *Builder) linkShared(ctx context.Context, a *Action) (err error) { return err } diff --git a/meta/recipes-devtools/go/go/0007-exec.go-filter-out-build-specific-paths-from-linker-.patch b/meta/recipes-devtools/go/go/0007-exec.go-filter-out-build-specific-paths-from-linker-.patch index 2598a7b34a9..a620a9cb637 100644 --- a/meta/recipes-devtools/go/go/0007-exec.go-filter-out-build-specific-paths-from-linker-.patch +++ b/meta/recipes-devtools/go/go/0007-exec.go-filter-out-build-specific-paths-from-linker-.patch @@ -19,7 +19,7 @@ diff --git a/src/cmd/go/internal/work/exec.go b/src/cmd/go/internal/work/exec.go index 651fa64582..586079afb4 100644 --- a/src/cmd/go/internal/work/exec.go +++ b/src/cmd/go/internal/work/exec.go -@@ -1563,6 +1563,29 @@ func (b *Builder) linkActionID(a *Action) cache.ActionID { +@@ -1564,6 +1564,29 @@ func (b *Builder) linkActionID(a *Action) cache.ActionID { return h.Sum() } @@ -49,7 +49,7 @@ index 651fa64582..586079afb4 100644 // printLinkerConfig prints the linker config into the hash h, // as part of the computation of a linker-related action ID. func (b *Builder) printLinkerConfig(h io.Writer, p *load.Package) { -@@ -1573,7 +1596,7 @@ func (b *Builder) printLinkerConfig(h io.Writer, p *load.Package) { +@@ -1574,7 +1597,7 @@ func (b *Builder) printLinkerConfig(h io.Writer, p *load.Package) { case "gc": fmt.Fprintf(h, "link %s %q %s\n", b.toolID("link"), forcedLdflags, ldBuildmode) if p != nil { diff --git a/meta/recipes-devtools/go/go_1.26.8.bb b/meta/recipes-devtools/go/go_1.26.9.bb similarity index 100% rename from meta/recipes-devtools/go/go_1.26.8.bb rename to meta/recipes-devtools/go/go_1.26.9.bb From patchwork Sun Oct 11 08:40:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100338 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E5375CA9ED1 for ; Sun, 11 Oct 2026 08:41:39 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23584.1791708096239296998 for ; Sun, 11 Oct 2026 01:41:36 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Oe8uvABi; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48c4649b3aaso514294f8f.2 for ; Sun, 11 Oct 2026 01:41:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708094; x=1792312894; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=H+X6OAp+nQehujSJQqE+H+ngxA9jq6jg9v0VXpplhHw=; b=Oe8uvABibnSTKojd2fr1FUIZIEjqmfbuVfeTGNEpdFh/qMY9rD1OKKEaGFa8hWzRTd BX4t39xJfdQ8OriwCjpZy0zlqvCAf4EL9hzDToVwH57Em+ZjNbW/qjkM2v0opVVkXV4u 4VJMyabzcPTRvcLSE6EWCK5IZc4xbiFGrCDJU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708094; x=1792312894; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=H+X6OAp+nQehujSJQqE+H+ngxA9jq6jg9v0VXpplhHw=; b=rzqkmjAQ4JGznzNniCNELqvnRC8q69GSkaZmelhWtLQTREciJMQ9oBG6BUVbsA0cYH RnHYW2mWbQUVQdgDvHE5HcO43kX4O+aOfcsCqx0yznSaouUnxvhQiZsVZoBZhr/9VfPa p+TsaLgjK3QYvx+XJN1Q42jxIZoNHQG0W7ao0vNVXBJ6PEdVLnWbV8fphrLG4Ri9Blry +WeNidKizNHvTDgOHj1R2Dey5Vs+aznpfzFuV9WgXwfTNBC/IKMnWWSN1SKZlLh/UU7z l7cCA07OhADhO0VoNvayDPP8Blm9DW3bwB334Kzpc552tPgurnK0vAG7uavtzQVrpIrE pCxA== X-Gm-Message-State: AFq9FYJPpmzRDyELFYsYFnu8fiXZztc5WdU+A8r4zH7twL1NM7UVb4xx D+YHbKhJ2gdb1GBHvp2TBFC3uVl4Vt4tap4Au3Sfa06cIALJXk0yCfocYIn8Bz5XH5qL2lEziV4 crrMruWY= X-Gm-Gg: AYBFou0QcTVwl4L6FLX9RSglPLsrbAF/wucR9o5qoX+6Qf6/jXy9q73+yxghrn/tnpn U06lCrQt75z0W/i+KEeFy0o3GW9Bs1H/Q86edO/1jnH/s+u50sCDfSRxRHVdGwQf8wEksoVNuYK r22Q4tvvNccUCzN0DUnPecbxLoaU8a3FI3gGkUOurfSTCjGmCytIZim0v5QkksskHymIMljsjGV Y+WuBUBP5PBkTuyZZlGBjBHspZRjEdudtZLvTpMCOapMlwJdW1UAiAoVQgI0zCtLgg0I+F6zf4U e0cS9ZoyE28Wza3iyhbj/6FLScPycDL6YsvJLutOrZ4z9vUfMfjLFx6ZEUMzt/QHE/E7tDSkTkB z+asH660NhvuNsupLxjliYUu+jzvJ+wZ2HDpTl0/rzf9WAPUljuIJlV7gtHe9/tmb5EepPDbTtR PjRnH9LYYmaGYdMXDPwaInZTZI2j29T6XES3mDuA7vkcUbxI6j2HvJdNLM4CweGwNFB/JtT2ztg YGG/vkx9BF3jkAppYyzEhqP6I9ymAIuypCj+mLmexSjLfYaNZmuB+flJzIzbO+tAy48A+UwAQ== X-Received: by 2002:a05:6000:1ac5:b0:487:91e:d8ed with SMTP id ffacd0b85a97d-48dba784ca9mr11751975f8f.2.1791708094338; Sun, 11 Oct 2026 01:41:34 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:33 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 52/60] wget: fix CVE-2026-15146 Date: Sun, 11 Oct 2026 10:40:25 +0200 Message-ID: <4f963a7691766a181a743b6fa91339800454be20.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247561 From: Ghanshyam Banait GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port.This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. Backport patch to fix CVE-2026-15146. https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b Ptest Result DURATION: 18 END: /usr/lib/wget/ptest 2026-10-09T11:05 STOP: ptest-runner TOTAL: 1 FAIL: 0 References: https://nvd.nist.gov/vuln/detail/CVE-2026-15146 https://www.cve.org/CVERecord?id=CVE-2026-15146 https://security-tracker.debian.org/tracker/CVE-2026-15146 https://ubuntu.com/security/CVE-2026-15146 Signed-off-by: Ghanshyam Banait Signed-off-by: Richard Purdie (cherry picked from commit 1a3f905de376f5a79a2a8b70545f08a4daec5a37) Signed-off-by: Yoann Congal --- .../wget/wget/CVE-2026-15146.patch | 126 ++++++++++++++++++ meta/recipes-extended/wget/wget_1.25.0.bb | 1 + 2 files changed, 127 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-15146.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-15146.patch b/meta/recipes-extended/wget/wget/CVE-2026-15146.patch new file mode 100644 index 00000000000..5d8d1a898ea --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-15146.patch @@ -0,0 +1,126 @@ +From 4f85853f641863d5915786a8413e1a213726a62b Mon Sep 17 00:00:00 2001 +From: Acts1631 +Date: Sun, 5 Jul 2026 17:22:55 -0400 +Subject: ftp: validate PASV/LPSV response address against control connection + peer + +* src/ftp-basic.c (ftp_pasv): Reject if peer address doesn't match advertised + address, + (ftp_lpsv): Likewise. + +ftp_pasv() and ftp_lpsv() copied the IP address and port advertised in +the server's 227 response without checking that it matched the peer +of the control connection. A malicious or compromised FTP server +could therefore direct wget's data connection to an arbitrary host and +port of its choosing (e.g. an internal service unreachable from the +attacker directly), which is a server-side request forgery. + +ftp_epsv() was already safe since it only extracts a port and reuses +the pre-filled control-connection address. + +Fix ftp_pasv() and ftp_lpsv() the same way: capture the control +connection's peer address via socket_ip_address() before parsing the +response, and reject the response (FTPINVPASV) if the parsed address +does not match. + +Verified with a fake FTP server that returns a PASV response pointing +at a different loopback address (127.0.0.2 instead of the real peer +127.0.0.1): before the fix wget connects to the spoofed address, after +the fix it rejects the response with "Cannot parse PASV response." +Legitimate transfers using a correctly-addressed PASV response +continue to work. + +Copyright-paperwork-exempt: Yes + +CVE: CVE-2026-15146 + +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b] + +Signed-off-by: Ghanshyam Banait +--- + src/ftp-basic.c | 40 ++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 40 insertions(+) + +diff --git a/src/ftp-basic.c b/src/ftp-basic.c +index 4870256a..0f4bb821 100644 +--- a/src/ftp-basic.c ++++ b/src/ftp-basic.c +@@ -623,10 +623,19 @@ ftp_pasv (int csock, ip_address *addr, int *port) + int nwritten, i; + uerr_t err; + unsigned char tmp[6]; ++ ip_address peer_addr; + + assert (addr != NULL); + assert (port != NULL); + ++ /* Remember who we are talking to on the control connection, so that ++ the address returned in the PASV response can be checked below. ++ Accepting an arbitrary server-supplied address would let a ++ malicious FTP server redirect our data connection to any host of ++ its choosing (SSRF). */ ++ if (!socket_ip_address (csock, &peer_addr, ENDPOINT_PEER)) ++ return FTPINVPASV; ++ + xzero (*addr); + + /* Form the request. */ +@@ -677,6 +686,16 @@ ftp_pasv (int csock, ip_address *addr, int *port) + memcpy (IP_INADDR_DATA (addr), tmp, 4); + *port = ((tmp[4] << 8) & 0xff00) + tmp[5]; + ++ /* Reject the response if the advertised address does not match the ++ control connection's peer. */ ++ if (peer_addr.family != AF_INET ++ || memcmp (IP_INADDR_DATA (addr), IP_INADDR_DATA (&peer_addr), 4) != 0) ++ { ++ xzero (*addr); ++ *port = 0; ++ return FTPINVPASV; ++ } ++ + return FTPOK; + } + +@@ -692,10 +711,19 @@ ftp_lpsv (int csock, ip_address *addr, int *port) + uerr_t err; + unsigned char tmp[16]; + unsigned char tmpprt[2]; ++ ip_address peer_addr; + + assert (addr != NULL); + assert (port != NULL); + ++ /* Remember who we are talking to on the control connection, so that ++ the address returned in the LPSV response can be checked below. ++ Accepting an arbitrary server-supplied address would let a ++ malicious FTP server redirect our data connection to any host of ++ its choosing (SSRF). */ ++ if (!socket_ip_address (csock, &peer_addr, ENDPOINT_PEER)) ++ return FTPINVPASV; ++ + xzero (*addr); + + /* Form the request. */ +@@ -842,6 +870,18 @@ ftp_lpsv (int csock, ip_address *addr, int *port) + DEBUGP (("*port is: %d\n", *port)); + } + ++ /* Reject the response if the advertised address does not match the ++ control connection's peer. */ ++ if (peer_addr.family != addr->family ++ || memcmp (IP_INADDR_DATA (addr), IP_INADDR_DATA (&peer_addr), ++ af == 4 ? 4 : 16) != 0) ++ { ++ xzero (*addr); ++ *port = 0; ++ xfree (respline); ++ return FTPINVPASV; ++ } ++ + xfree (respline); + return FTPOK; + } +-- +cgit v1.3 + diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb index 26f5c84e5a7..b8c803aae1f 100644 --- a/meta/recipes-extended/wget/wget_1.25.0.bb +++ b/meta/recipes-extended/wget/wget_1.25.0.bb @@ -24,6 +24,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-16599.patch \ file://CVE-2026-58470.patch \ file://CVE-2026-58470-regression.patch \ + file://CVE-2026-15146.patch \ " SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784" From patchwork Sun Oct 11 08:40:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100339 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D5E61CA9ECA for ; Sun, 11 Oct 2026 08:41:39 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23585.1791708097038521589 for ; Sun, 11 Oct 2026 01:41:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=abSk/DJK; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4a018792ab3so8339845e9.0 for ; Sun, 11 Oct 2026 01:41:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708095; x=1792312895; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VuLA0mMc5DUSyznsCU4szGXCGr6itUmi9afYjccLrg0=; b=abSk/DJK5FrWVHIiYndlgcolpJosm9eCOv9k3BvN4UTcgKR5Ys8l+IpL46tkpC6LfH rKCrl9MDxA59KFDbS9lZjsznE6FLrmSCTa+8yqsGt5RXSiGE1NDCexKWRQ/J2viiWJvz 7F9Dx6/xLgScRQ/vtC0Nh3cNcdZ1NQsU5f9bg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708095; x=1792312895; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VuLA0mMc5DUSyznsCU4szGXCGr6itUmi9afYjccLrg0=; b=XmuKDoLr3vPQv49cEAOmZGss07gJA08Pe0lNGxAhipdp56vNOGrbU7lhSgRfH+FDgX utieMIuOn3qNR2cPerEQsyvsdCRTRRhh0bk5xhnBuTOYzRdkW4A0ZyC9ah++7mTH8U/d RacsQlMTSc31Vh8PeaRs2FyY/qLXkKuKvHx8+Y13EWv9lsOJr17J7HqUZr6CORb9wxmZ kDhO/fesDUfASFSp6yoMcPL4Lc2+VeJatk4rLnrFUfvdy4iB/lex35ojOLNZb5Qf22H9 Yz1ofAY5Jv+R+uAB42tef82pPpqtGRwMZ5A6VRJ82jmvoeBaP6tIvCvrmmZz6LKNJXhb 7g1w== X-Gm-Message-State: AFq9FYIvIyM5bz82TBwnm6XJePMO/I+uG8cRoP96X560znuKhBoOs0qO b4UrKSr/HVJxEE6cboG9YHT9qBbC/AyUa0Mq3D1vJr/Ikb9BNbCYJdH+O9H4z2uCW4vuUNYi0Nu fU2NEMPE= X-Gm-Gg: AYBFou3dXnK8P77bBSvnOE6faqic8HkuRrhUD32DZ1ZUqQNUrULfnC03gsAhNgOHJZu qpJqj9KafHp9rJLW8kgTkwhY4B4od6/QbwmkYNIWSOtAMqHeGiJRcp/xWGFcf/qMRbnpLly2eIb +g9foidNxJt3NQAXZ3LDC+XPuOrH68voH6ngoNBryTcSmTGL7eeQL7qr1w/j5cekfye42lrELe4 /y9f1dCsXh6mXulIrqtr75rCkf32QhhTyl1Xjlw/eyUh2CIpOgze1r3U70NdsqPHSJYKHEoEPSs NS5LL5mbn6gcFTyDXhcaScxs3XMyrOPR0CDssDrNz5+aFhqeB4AzYt6585+WiRYO1LE7iTSA1xy v6ZTVAEILSPEx6yNb+ec54+V/N6J+3ITVZJdzR4Pap6quB9Hw7QIbT1R6H/mM2LHKLoc+ae3MJb sxobCGGi0kTsRjEwrbjFAc19s/NKSlUaHFMMKciEaP6r8/248d7AO4rC6aB1DMOs+t7filU/2mn Vkr6/R0F9xGGL1FNmx6afrzHrlKOMzaT4geKcNt2lGmxm2r9PwTGnzNPR8Uydhtg0iBgOlG3Q== X-Received: by 2002:a05:600d:1b:b0:4a1:9661:14b7 with SMTP id 5b1f17b1804b1-4a196611b9amr40980395e9.32.1791708095116; Sun, 11 Oct 2026 01:41:35 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.34 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:34 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 53/60] libpcre2: patch CVE-2026-89162 Date: Sun, 11 Oct 2026 10:40:26 +0200 Message-ID: <97f556be4dc13ec70e7b898f44ee7fecdde2e679.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247562 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89162 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89162.patch | 88 +++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 89 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch new file mode 100644 index 00000000000..efc6c856b98 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch @@ -0,0 +1,88 @@ +From edc111a6831591f68b5355a08cc9df8be8f35304 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Sat, 25 Oct 2025 10:50:27 +0100 +Subject: [PATCH] Write padding values to ensure pcre2_serialize_encode() + outputs defined values (#826) + +Fixes low-severity valgrind error reported in GHSA-q7rw-r7qq-2hx6. + +CVE: CVE-2026-89162 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/edc111a6831591f68b5355a08cc9df8be8f35304] +Signed-off-by: Peter Marko +--- + src/pcre2_compile_class.c | 17 +++++++---------- + src/pcre2test_inc.h | 25 +++++++++++++++++++++++++ + 2 files changed, 32 insertions(+), 10 deletions(-) + +diff --git a/src/pcre2_compile_class.c b/src/pcre2_compile_class.c +index 9a1fc022..55b641c1 100644 +--- a/src/pcre2_compile_class.c ++++ b/src/pcre2_compile_class.c +@@ -1802,17 +1802,14 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + PUT(code, 0, (uint32_t)(char_lists_size >> 1)); + code += LINK_SIZE; + +-#if defined PCRE2_DEBUG || defined SUPPORT_VALGRIND ++ /* If we added padding to align the list, initialize the bytes to ++ defined values, so the library is valgrind-clean. It could also ++ be a security concern for clients calling into PCRE2 via bindings ++ from a memory-safe language, if pcre2_serialize_encode() exposes ++ uninitialized memory that may contain sensitive information. */ ++ + if ((char_lists_size & 0x2) != 0) +- { +- /* In debug the unused 16 bit value is set +- to a fixed value and marked unused. */ +- ((uint16_t*)data)[-1] = 0x5555; +-#ifdef SUPPORT_VALGRIND +- VALGRIND_MAKE_MEM_NOACCESS(data - 2, 2); +-#endif +- } +-#endif ++ ((uint16_t*)data)[-1] = 0xdead; + + cb->char_lists_size = + CLIST_ALIGN_TO(char_lists_size, sizeof(uint32_t)); +diff --git a/src/pcre2test_inc.h b/src/pcre2test_inc.h +index 8124e9ca..c4707417 100644 +--- a/src/pcre2test_inc.h ++++ b/src/pcre2test_inc.h +@@ -2019,6 +2019,9 @@ uint32_t use_forbid_utf = forbid_utf; + PCRE2_SIZE patlen, full_patlen; + PCRE2_SIZE valgrind_access_length; + PCRE2_SIZE erroroffset; ++int32_t serialize_rc; ++uint8_t *serialized_bytes; ++PCRE2_SIZE serialized_size; + + /* The perltest.sh script supports only / as a delimiter. */ + +@@ -2966,6 +2969,28 @@ if ((pat_patctl.control2 & CTL2_NL_SET) != 0) + rc = show_pattern_info(); + if (rc != PR_OK) return rc; + ++/* Verify that the compiled structure can be serialized without generating ++memory errors. */ ++ ++serialize_rc = pcre2_serialize_encode((const pcre2_code **)&compiled_code, 1, ++ &serialized_bytes, &serialized_size, general_context); ++if (serialize_rc != 1) ++ { ++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned %d instead of 1\n", ++ serialize_rc); ++ return PR_ABEND; ++ } ++ ++#if defined SUPPORT_VALGRIND ++if (VALGRIND_CHECK_MEM_IS_DEFINED(serialized_bytes, serialized_size) != 0) ++ { ++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned undefined data\n"); ++ return PR_ABEND; ++ } ++#endif ++ ++pcre2_serialize_free(serialized_bytes); ++ + /* The "push" control requests that the compiled pattern be remembered on a + stack. This is mainly for testing the serialization functionality. */ + diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 70079e0b65b..b81480c8ffb 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -14,6 +14,7 @@ LIC_FILES_CHKSUM = "file://LICENCE.md;md5=6720bf3bcff57543b915c2b22e526df0 \ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ + file://CVE-2026-89162.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100345 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52D80CA9ED4 for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23457.1791708097773871313 for ; Sun, 11 Oct 2026 01:41:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=lMZCYZZQ; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4a061a13884so8430565e9.3 for ; Sun, 11 Oct 2026 01:41:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708096; x=1792312896; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pCUpZdb8y1a0Hrd02Mcs5yiVk0CBgwN0inhjEHB/4AU=; b=lMZCYZZQ+B9ptbl+Jbl3BFFh+mM1OlX95qmmAkI9+FI3OKlBV4S5qXDs0HIpy5G4lQ 8J3J2KGorQjQzNx1eDcuYn+3bOplDPoppo28q9cFyfYi77kjBXWubMzVJ49g4UnPr7Kl mjarBc0wPVtR/AUdJnUk/rtzkjuNg504J8FI0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708096; x=1792312896; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pCUpZdb8y1a0Hrd02Mcs5yiVk0CBgwN0inhjEHB/4AU=; b=OvLS3LYGxWrAXG+MhkbaeXWvJRfptmkNntTGIj3Cgis80Iva/Cm3mHpSaJzDetewOl JSJdYm37Xi+WwLHsyHLM+L2uUOlWCczFL55ktB1G5UEcVASpMb+1JNMnDbvtgY8S20oU EL38bSdoOasVK9qBifqXW5NRSLhqUsyegkTtZdntWAurnJ66Q6Wb7lhT1K8ctignq14n BBFIm1cFMTAwGnpLzECqz7P9smBkYHDviZT8G6iQIeGWePieSQYVY4aHpLGMO7ZCp0Wg dE1gwrYgylJT4/YXb4DSfdD4wjRHQEhjADDBj8MUETxG3xE0/FQOUxux7T6/ByWJGF9S Kwjg== X-Gm-Message-State: AFq9FYLqcxFbL0OJHal8aX1By724urmvLRFNBsKhNbyxaoY4FRz8f/Kq rYFzKxDAF7wraaN8EMb6gyhqj/G0WJ3BbI/qdQhlNM2b6xDY2ZlWuda+zDwZcoxFY9OoeevuCSW 4bY1LDqs= X-Gm-Gg: AYBFou2pJx5Z5edxwGv6VMR9Vm/Cj9L88hSjHmy144UwvLctVl3mOxNrfJlgWYcXG0m kfrGdpAJhRWgtXLE1vunUTXMsjgAJEGTobgHG2uB30ViXiQbpyGOjx4txHmeqD/YQ5frs7M9N4E H0JEEWFAVjtbNDB0U4C9HtD9vXqoBvzjvWkpHuZXW9Do9RiaGma6/BmPbdkW+/e1nD+gdbBTjFW PYX3ZdsVBKSrQGkZT6YZhmReJx2BMxn2WIKjNBCdrcJ1Xus7qgo1YMcE+6udS2Q2tBNGccnX5qp 0uPRv4U/XFWbHdaQxd/5SoXXdls5I+qryAUPj1heAeLJ/AbkIbcWm/9BrgPFpZY+yfjdpD749J8 0XLmCqjAHjE+mI7T1gaEqJqOZbXIkindCe8g73MEoJPmxX9P+ny4xjtPhlTJlb5rDplmGZlTtJq /cHlJ+tesj+DV80eT4Y/WVQu2PkQffZ3QXSgH5RG4BD30HFzMnbtWqOZqrtcwy7g2LZpHneflwK CJQ02ckJeYoZjTmId+9BL7RKd786Z5mqrJ0j08Kyd1sWI8O0ATbYoucoI+KHtvwJW4h9t9SbmA= X-Received: by 2002:a05:600c:154c:b0:49f:ce78:3562 with SMTP id 5b1f17b1804b1-4a18e4a9159mr132024565e9.19.1791708095802; Sun, 11 Oct 2026 01:41:35 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.35 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:35 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 54/60] libpcre2: patch CVE-2026-89161 Date: Sun, 11 Oct 2026 10:40:27 +0200 Message-ID: <7971cdddb4458fa6b5c1ca5f6846d34be6f178c5.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247563 From: Peter Marko Pick patch per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89161 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89161.patch | 221 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 222 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch new file mode 100644 index 00000000000..42e69acbcc1 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch @@ -0,0 +1,221 @@ +From 1dcd0cf42a6a7cb62cc9a7c024196733abcfda95 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Sat, 8 Aug 2026 19:17:36 +0100 +Subject: [PATCH] Fix leak & stale PCRE2_MD_COPIED_SUBJECT if pcre2_jit_match + used with existing match context (#937) + +The problem is not that pcre2_jit_match() needs to add support for PCRE2_COPY_MATCHED_SUBJECT. Instead, if the passed-in context somehow contains a previously-copied subject (by non-JIT matcher using a global or cached subject) then it will be leaked, and worse, incorrectly free'd later. + +CVE: CVE-2026-89161 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95] +Signed-off-by: Peter Marko +--- + doc/html/pcre2jit.html | 9 +++--- + doc/pcre2.txt | 10 +++---- + doc/pcre2jit.3 | 9 +++--- + src/pcre2_jit_match_inc.h | 10 +++++++ + src/pcre2test_inc.h | 60 ++++++++++++++++++++++++++++++++------- + testdata/testinput17 | 1 + + testdata/testoutput17 | 2 ++ + 7 files changed, 77 insertions(+), 24 deletions(-) + +diff --git a/doc/html/pcre2jit.html b/doc/html/pcre2jit.html +index cc26cc06..4e6d31e5 100644 +--- a/doc/html/pcre2jit.html ++++ b/doc/html/pcre2jit.html +@@ -460,10 +460,11 @@ processed by pcre2_jit_compile()). + The fast path function is called pcre2_jit_match(), and it takes exactly + the same arguments as pcre2_match(). However, the subject string must be + specified with a length; PCRE2_ZERO_TERMINATED is not supported. Unsupported +-option bits (for example, PCRE2_ANCHORED and PCRE2_ENDANCHORED) are ignored, as +-is the PCRE2_NO_JIT option. The return values are also the same as for +-pcre2_match(), plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial +-or complete) is requested that was not compiled. ++option bits (for example, PCRE2_ANCHORED, PCRE2_ENDANCHORED, and ++PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the PCRE2_NO_JIT option. The ++return values are also the same as for pcre2_match(), plus ++PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial or complete) is requested ++that was not compiled. +

+

+ When you call pcre2_match(), as well as testing for invalid options, a +diff --git a/doc/pcre2.txt b/doc/pcre2.txt +index 693908ee..cc316178 100644 +--- a/doc/pcre2.txt ++++ b/doc/pcre2.txt +@@ -6176,11 +6176,11 @@ JIT FAST PATH API + The fast path function is called pcre2_jit_match(), and it takes ex- + actly the same arguments as pcre2_match(). However, the subject string + must be specified with a length; PCRE2_ZERO_TERMINATED is not sup- +- ported. Unsupported option bits (for example, PCRE2_ANCHORED and +- PCRE2_ENDANCHORED) are ignored, as is the PCRE2_NO_JIT option. The re- +- turn values are also the same as for pcre2_match(), plus PCRE2_ER- +- ROR_JIT_BADOPTION if a matching mode (partial or complete) is requested +- that was not compiled. ++ ported. Unsupported option bits (for example, PCRE2_ANCHORED, PCRE2_EN- ++ DANCHORED, and PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the ++ PCRE2_NO_JIT option. The return values are also the same as for ++ pcre2_match(), plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (par- ++ tial or complete) is requested that was not compiled. + + When you call pcre2_match(), as well as testing for invalid options, a + number of other sanity checks are performed on the arguments. For exam- +diff --git a/doc/pcre2jit.3 b/doc/pcre2jit.3 +index 95451b56..729d898f 100644 +--- a/doc/pcre2jit.3 ++++ b/doc/pcre2jit.3 +@@ -444,10 +444,11 @@ processed by \fBpcre2_jit_compile()\fP). + The fast path function is called \fBpcre2_jit_match()\fP, and it takes exactly + the same arguments as \fBpcre2_match()\fP. However, the subject string must be + specified with a length; PCRE2_ZERO_TERMINATED is not supported. Unsupported +-option bits (for example, PCRE2_ANCHORED and PCRE2_ENDANCHORED) are ignored, as +-is the PCRE2_NO_JIT option. The return values are also the same as for +-\fBpcre2_match()\fP, plus PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial +-or complete) is requested that was not compiled. ++option bits (for example, PCRE2_ANCHORED, PCRE2_ENDANCHORED, and ++PCRE2_COPY_MATCHED_SUBJECT) are ignored, as is the PCRE2_NO_JIT option. The ++return values are also the same as for \fBpcre2_match()\fP, plus ++PCRE2_ERROR_JIT_BADOPTION if a matching mode (partial or complete) is requested ++that was not compiled. + .P + When you call \fBpcre2_match()\fP, as well as testing for invalid options, a + number of other sanity checks are performed on the arguments. For example, if +diff --git a/src/pcre2_jit_match_inc.h b/src/pcre2_jit_match_inc.h +index 32d4c8a5..4163cf61 100644 +--- a/src/pcre2_jit_match_inc.h ++++ b/src/pcre2_jit_match_inc.h +@@ -125,6 +125,16 @@ else if ((options & PCRE2_PARTIAL_SOFT) != 0) + if (functions == NULL || functions->executable_funcs[index] == NULL) + return match_data->rc = PCRE2_ERROR_JIT_BADOPTION; + ++/* If the match data block was previously used with PCRE2_COPY_MATCHED_SUBJECT, ++free the memory that was obtained. */ ++ ++if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) != 0) ++ { ++ match_data->memctl.free((void *)match_data->subject, ++ match_data->memctl.memory_data); ++ match_data->flags &= ~PCRE2_MD_COPIED_SUBJECT; ++ } ++ + /* Sanity checks should be handled by pcre2_match. */ + arguments.str = subject + start_offset; + arguments.begin = subject; +diff --git a/src/pcre2test_inc.h b/src/pcre2test_inc.h +index 5d282435..a74e3368 100644 +--- a/src/pcre2test_inc.h ++++ b/src/pcre2test_inc.h +@@ -5171,20 +5171,28 @@ for (gmatched = 0;; gmatched++) + /* If PCRE2_COPY_MATCHED_SUBJECT was set, check that things are as they + should be, but not for fast JIT, where it isn't supported. */ + +- if ((dat_datctl.options & PCRE2_COPY_MATCHED_SUBJECT) != 0 && +- (pat_patctl.control & CTL_JITFAST) == 0) ++ if ((dat_datctl.options & PCRE2_COPY_MATCHED_SUBJECT) != 0) + { +- if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) == 0) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: flag not set after copy_matched_subject\n"); ++ if ((pat_patctl.control & CTL_JITFAST) != 0) ++ { ++ if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) != 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: flag set after unsupported copy_matched_subject\n"); ++ } ++ else ++ { ++ if ((match_data->flags & PCRE2_MD_COPIED_SUBJECT) == 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: flag not set after copy_matched_subject\n"); + +- if (match_data->subject == pp) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: copy_matched_subject has not copied\n"); ++ if (match_data->subject == pp) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: copy_matched_subject has not copied\n"); + +- if (memcmp(match_data->subject, pp, ulen) != 0) +- cfprintf(clr_test_error, outfile, +- "** PCRE2 error: copy_matched_subject mismatch\n"); ++ if (memcmp(match_data->subject, pp, ulen) != 0) ++ cfprintf(clr_test_error, outfile, ++ "** PCRE2 error: copy_matched_subject mismatch\n"); ++ } + } + + /* If this is not the first time round a global loop, check that the +@@ -5661,6 +5669,9 @@ pcre2_match_context *test_dat_context = NULL, *test_dat_context_copy = NULL; + pcre2_convert_context *test_con_context = NULL, *test_con_context_copy = NULL; + pcre2_match_data *test_match_data = NULL; + pcre2_code *test_compiled_code = NULL; ++#ifdef SUPPORT_JIT ++BOOL test_compiled_with_jit = FALSE; ++#endif + PCRE2_UCHAR pattern[] = { CHAR_A, CHAR_B, CHAR_C, 0 }; + PCRE2_UCHAR callout_int_pattern[] = { + CHAR_LEFT_PARENTHESIS, CHAR_QUESTION_MARK, CHAR_C, CHAR_RIGHT_PARENTHESIS, 0 }; +@@ -5965,11 +5976,38 @@ ASSERT(rc == 0 && sizeval == 0, "pcre2_pattern_info(JIT)"); + + if (pcre2_jit_compile(test_compiled_code, PCRE2_JIT_COMPLETE) == 0) + { ++ test_compiled_with_jit = TRUE; ++ + rc = pcre2_pattern_info(test_compiled_code, PCRE2_INFO_JITSIZE, &sizeval); + ASSERT(rc == 0 && sizeval > 0, "pcre2_pattern_info(JIT after compile)"); + } + #endif + ++/* ----------------------- Matching functions ------------------------------ */ ++ ++#ifdef SUPPORT_JIT ++ ++/* Check that fast JIT releases a copied subject when reusing match data. */ ++if (test_compiled_with_jit) ++ { ++ test_match_data = pcre2_match_data_create_from_pattern(test_compiled_code, ++ test_gen_context); ++ ASSERT(test_match_data != NULL, "pcre2_match_data_create_from_pattern(JIT)"); ++ ++ rc = pcre2_match(test_compiled_code, pattern, 3, 0, ++ PCRE2_COPY_MATCHED_SUBJECT, test_match_data, NULL); ++ ASSERT(rc == 1, "pcre2_match(COPY_MATCHED_SUBJECT)"); ++ ++ rc = pcre2_jit_match(test_compiled_code, subject_abcz, 4, 0, 0, ++ test_match_data, NULL); ++ ASSERT(rc == 1, "pcre2_jit_match(reused match data)"); ++ ++ pcre2_match_data_free(test_match_data); ++ test_match_data = NULL; ++ } ++ ++#endif ++ + /* ----------------------- POSIX functions --------------------------------- */ + + #if PCRE2_CODE_UNIT_WIDTH == 8 +diff --git a/testdata/testinput17 b/testdata/testinput17 +index 08fd72e0..9d728965 100644 +--- a/testdata/testinput17 ++++ b/testdata/testinput17 +@@ -298,6 +298,7 @@ + + /abc/jitfast + abc ++ abc\=copy_matched_subject + abc\=no_jit + + # ---- +diff --git a/testdata/testoutput17 b/testdata/testoutput17 +index 6d550084..773ec18a 100644 +--- a/testdata/testoutput17 ++++ b/testdata/testoutput17 +@@ -542,6 +542,8 @@ Failed: error -47: match limit exceeded + + /abc/jitfast + abc ++ 0: abc (JIT) ++ abc\=copy_matched_subject + 0: abc (JIT) + abc\=no_jit + 0: abc (JIT) diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index b81480c8ffb..fa59747fdca 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -15,6 +15,7 @@ LIC_FILES_CHKSUM = "file://LICENCE.md;md5=6720bf3bcff57543b915c2b22e526df0 \ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ file://CVE-2026-89162.patch \ + file://CVE-2026-89161.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100335 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AFB22CA9EC7 for ; Sun, 11 Oct 2026 08:41:39 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23586.1791708098420887811 for ; Sun, 11 Oct 2026 01:41:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Lcw7NT1c; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-487049569b6so599049f8f.1 for ; Sun, 11 Oct 2026 01:41:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708097; x=1792312897; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=oMjLdpMGWIVPR8wbcZu8G9+bRfmuoeWrPSiczNbJ9jc=; b=Lcw7NT1cWmm7abcQqc3TUUvMrNgMwE034cSHNMXLaJ0gW0gmQE2E2NQejhT2HvFpDw 08MyJ2BC73dVCfSOFVQqILbWt1b1/E/KcT1Xb5UVVueTYvxp4k9pFMNTimgw3YpoYNm1 Ryim4nf6g6fiEpVP9ACyYO8VNTnaNMhY5mMlo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708097; x=1792312897; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=oMjLdpMGWIVPR8wbcZu8G9+bRfmuoeWrPSiczNbJ9jc=; b=xFSZT4BzqGmGLAdqszO5yPo6FZQO5hzR6a3emtR/ev4F0nV6dxJb+XCW4V7k986fnH W4hOBbvHO3Tp5AO32elmcp+gijMGCXU/hA5EYKKVudHKrsbWcI8KePuBDxIt0bU/lUK8 6JODESywmJeeLf0tHXPpgyRBfg7sQ6DToU4mEYZTSJAwms8cPbeLC6FI3cA1eMfoF5fp ix5X9C4iV71t/+KxBs5ajTbEn4TyjLLYEy8/a1WahUt0lnwV7goqA45rDp0P0gY3xK/q 77thr7jEkzBTh9ILxL4P445j/XJBku6yPikNdh0L7MGQt+gsmE8MGTfiJ1L/lhDxxtHg qpZg== X-Gm-Message-State: AFq9FYLEaK8aN0TDHPky+QFAAm7esE23uRvBsueEoaXaRfztRnfgCsxX 7ikJneH1x4LcF6NkBoPsb7wHbyyTOF1FO57aNL2gy06komAAm8bQ+WhkPJf5m3j+M9FXdcnMs8w V8MBHsKM= X-Gm-Gg: AYBFou3j7T1SATl4WjbTfRY1PImwjDsygpfEYEO9Ehylh35aTKmGPbnT7FCFCLo+GZs gEi7mJoCRmGnG784GE/1KH+rj/aGScH08zJVw8tV1lQVwe7m4kFAR5oPQ1AJacPgS1QqrN/8aho F4qtKi1f+MMHztDdyiiF/ODp6t1dWk5BgSHJxNmRlR1E3ddAfFJUPpkoMz4GKKL+Sz7ug7bfZa8 AgGV1fBZpIeLHoqV1tEAtneVoyqgtAZu9uDpQDI32c1jfTQ0KDaCIBaYalhjFeszVf9u+PqEfm9 FZp9NrtXr0tRJIKNrmiVhKxepQynBO3+AGmwXqhEKEtfOSgNi01uFpC6xfefI0yOA/6e1sY+VXW JGoB8p76bD2NKynq6W07CH/Y39HZ+arq3Ne1p/e3qGKD1tir/tOtdCToCLOZEBDovqc3pDnc//0 jmJH9nYJwTqjOEk1Z1lK97T+6ABLc5ItM1xPPk0r9s53DetfwM4TTH5cunrAjn0Po9h639UVDb1 eY++yUnosdKpukb5a/b9QaB9uUAOGCmHFNkaw7ixTwa0Ne6XfkNVWfbyfHZyiuiDA6bIqMl7Q== X-Received: by 2002:adf:e013:0:20b0:487:930:8acc with SMTP id ffacd0b85a97d-48dbaaddbd5mr8039708f8f.16.1791708096412; Sun, 11 Oct 2026 01:41:36 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.35 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:35 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 55/60] libpcre2: patch CVE-2026-89156 Date: Sun, 11 Oct 2026 10:40:28 +0200 Message-ID: <00c50f277c65970a6a0776ce93bcf5b4ae91f01b.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247564 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89156 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89156.patch | 275 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 276 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch new file mode 100644 index 00000000000..7937a6a4c5b --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch @@ -0,0 +1,275 @@ +From f67db227af31bba7cdf2a7a00b97af91b588c2f5 Mon Sep 17 00:00:00 2001 +From: Zoltan Herczeg +Date: Sun, 9 Aug 2026 11:05:54 +0200 +Subject: [PATCH] Fix pcre2_match to check for JIT support before JIT + validation & execution (#926) + +This fixes the issue that the JIT branch's UTF validation is not pinned to be identical to the interpreter's validation. + +This was not robust, and lead to a bug, in the case where the JIT UTF validation is done, but because the relevant JIT mode was not compiled, it falls through to the interpreter and skips the interpreter's own UTF validation and setup. + +CVE: CVE-2026-89156 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5] +Signed-off-by: Peter Marko +--- + src/pcre2_internal.h | 2 + + src/pcre2_jit_match_inc.h | 1 + + src/pcre2_jit_misc_inc.h | 38 +++++++++++++--- + src/pcre2_match.c | 95 +++++++++++++++------------------------ + 4 files changed, 71 insertions(+), 65 deletions(-) + +diff --git a/src/pcre2_internal.h b/src/pcre2_internal.h +index 2e8c7e47..930c745b 100644 +--- a/src/pcre2_internal.h ++++ b/src/pcre2_internal.h +@@ -2296,6 +2296,7 @@ is available. */ + #define _pcre2_is_newline PCRE2_SUFFIX(_pcre2_is_newline_) + #define _pcre2_jit_free_rodata PCRE2_SUFFIX(_pcre2_jit_free_rodata_) + #define _pcre2_jit_free PCRE2_SUFFIX(_pcre2_jit_free_) ++#define _pcre2_jit_check_exec PCRE2_SUFFIX(_pcre2_jit_check_exec_) + #define _pcre2_jit_get_size PCRE2_SUFFIX(_pcre2_jit_get_size_) + #define _pcre2_jit_get_target PCRE2_SUFFIX(_pcre2_jit_get_target_) + #define _pcre2_memctl_malloc PCRE2_SUFFIX(_pcre2_memctl_malloc_) +@@ -2325,6 +2326,7 @@ extern BOOL _pcre2_is_newline(PCRE2_SPTR, uint32_t, PCRE2_SPTR, + uint32_t *, BOOL); + extern void _pcre2_jit_free_rodata(void *, void *); + extern void _pcre2_jit_free(void *, pcre2_memctl *); ++extern BOOL _pcre2_jit_check_exec(void *, uint32_t); + extern size_t _pcre2_jit_get_size(void *); + const char * _pcre2_jit_get_target(void); + extern void * _pcre2_memctl_malloc(size_t, pcre2_memctl *); +diff --git a/src/pcre2_jit_match_inc.h b/src/pcre2_jit_match_inc.h +index 4163cf61..ba210007 100644 +--- a/src/pcre2_jit_match_inc.h ++++ b/src/pcre2_jit_match_inc.h +@@ -117,6 +117,7 @@ jit_arguments arguments; + int rc; + int index = 0; + ++/* The same check is performed by jit_check_exec(). */ + if ((options & PCRE2_PARTIAL_HARD) != 0) + index = 2; + else if ((options & PCRE2_PARTIAL_SOFT) != 0) +diff --git a/src/pcre2_jit_misc_inc.h b/src/pcre2_jit_misc_inc.h +index 0225fc6b..16c230e9 100644 +--- a/src/pcre2_jit_misc_inc.h ++++ b/src/pcre2_jit_misc_inc.h +@@ -200,17 +200,28 @@ if (jit_stack != NULL) + + + /************************************************* +-* Get target CPU type * ++* Checks function compilation * + *************************************************/ + +-const char* +-PRIV(jit_get_target)(void) ++BOOL ++PRIV(jit_check_exec)(void *executable_jit, uint32_t options) + { + #ifndef SUPPORT_JIT +-return "JIT is not supported"; ++(void)executable_jit; ++(void)options; ++return FALSE; + #else /* SUPPORT_JIT */ +-return sljit_get_platform_name(); +-#endif /* SUPPORT_JIT */ ++/* The same check is performed at the beginning of pcre2_jit_match(). */ ++executable_functions *functions = (executable_functions *)executable_jit; ++int index = 0; ++ ++if ((options & PCRE2_PARTIAL_HARD) != 0) ++ index = 2; ++else if ((options & PCRE2_PARTIAL_SOFT) != 0) ++ index = 1; ++ ++return functions->executable_funcs[index] != NULL; ++#endif + } + + +@@ -231,4 +242,19 @@ return executable_sizes[0] + executable_sizes[1] + executable_sizes[2]; + #endif + } + ++/************************************************* ++* Get target CPU type * ++*************************************************/ ++ ++const char* ++PRIV(jit_get_target)(void) ++{ ++#ifndef SUPPORT_JIT ++return "JIT is not supported"; ++#else /* SUPPORT_JIT */ ++return sljit_get_platform_name(); ++#endif /* SUPPORT_JIT */ ++} ++ ++ + /* End of pcre2_jit_misc_inc.h */ +diff --git a/src/pcre2_match.c b/src/pcre2_match.c +index 9ee8a476..a5a8421f 100644 +--- a/src/pcre2_match.c ++++ b/src/pcre2_match.c +@@ -6995,10 +6995,6 @@ PCRE2_SPTR req_cu_ptr; + PCRE2_SPTR start_partial; + PCRE2_SPTR match_partial; + +-#ifdef SUPPORT_JIT +-BOOL use_jit; +-#endif +- + /* This flag is needed even when Unicode is not supported for convenience + (it is used by the IS_NEWLINE macro). */ + +@@ -7008,9 +7004,6 @@ BOOL utf = FALSE; + BOOL ucp = FALSE; + BOOL allow_invalid; + uint32_t fragment_options = 0; +-#ifdef SUPPORT_JIT +-BOOL jit_checked_utf = FALSE; +-#endif + #endif /* SUPPORT_UNICODE */ + + PCRE2_SIZE frame_size; +@@ -7073,15 +7066,6 @@ options |= (re->flags & FF) / ((FF & (~FF+1)) / (OO & (~OO+1))); + #undef FF + #undef OO + +-/* If the pattern was successfully studied with JIT support, we will run the +-JIT executable instead of the rest of this function. Most options must be set +-at compile time for the JIT code to be usable. */ +- +-#ifdef SUPPORT_JIT +-use_jit = (re->executable_jit != NULL && +- (options & ~PUBLIC_JIT_MATCH_OPTIONS) == 0); +-#endif +- + /* Initialize UTF/UCP parameters. */ + + #ifdef SUPPORT_UNICODE +@@ -7128,20 +7112,25 @@ match_data->startchar = 0; + + /* ============================= JIT matching ============================== */ + +-/* Prepare for JIT matching. Check a UTF string for validity unless no check is +-requested or invalid UTF can be handled. We check only the portion of the +-subject that might be be inspected during matching - from the offset minus the +-maximum lookbehind to the given length. This saves time when a small part of a +-large subject is being matched by the use of a starting offset. Note that the +-maximum lookbehind is a number of characters, not code units. */ ++/* If the pattern was successfully studied with JIT support, we will run the ++JIT executable instead of the rest of this function. Most options must be set ++at compile time for the JIT code to be usable. */ + + #ifdef SUPPORT_JIT +-if (use_jit) ++if (re->executable_jit != NULL && ++ (options & ~PUBLIC_JIT_MATCH_OPTIONS) == 0 && ++ PRIV(jit_check_exec)(re->executable_jit, options)) + { ++ /* Prepare for JIT matching. Check a UTF string for validity unless no check ++ is requested or invalid UTF can be handled. We check only the portion of the ++ subject that might be be inspected during matching - from the offset minus ++ the maximum lookbehind to the given length. This saves time when a small part ++ of a large subject is being matched by the use of a starting offset. Note that ++ the maximum lookbehind is a number of characters, not code units. */ ++ + #ifdef SUPPORT_UNICODE + if (utf && (options & PCRE2_NO_UTF_CHECK) == 0 && !allow_invalid) + { +- + /* For 8-bit and 16-bit UTF, check that the first code unit is a valid + character start. */ + +@@ -7194,40 +7183,36 @@ if (use_jit) + match_data->startchar += start_match - subject; + return match_data->rc = rc; + } +- jit_checked_utf = TRUE; + } + #endif /* SUPPORT_UNICODE */ + +- /* If JIT returns BADOPTION, which means that the selected complete or +- partial matching mode was not compiled, fall through to the interpreter. */ +- + rc = pcre2_jit_match(code, subject, length, start_offset, options, + match_data, mcontext); +- if (rc != PCRE2_ERROR_JIT_BADOPTION) ++ /* JIT must be able to perform the match. */ ++ PCRE2_ASSERT(rc != PCRE2_ERROR_JIT_BADOPTION); ++ ++ match_data->options = original_options; ++ if (rc >= 0 && (options & PCRE2_COPY_MATCHED_SUBJECT) != 0) + { +- match_data->options = original_options; +- if (rc >= 0 && (options & PCRE2_COPY_MATCHED_SUBJECT) != 0) ++ if (length != 0) + { +- if (length != 0) +- { +- match_data->subject = match_data->memctl.malloc(CU2BYTES(length), +- match_data->memctl.memory_data); +- if (match_data->subject == NULL) +- return match_data->rc = PCRE2_ERROR_NOMEMORY; +- memcpy((void *)match_data->subject, subject, CU2BYTES(length)); +- } +- else +- match_data->subject = NULL; +- match_data->flags |= PCRE2_MD_COPIED_SUBJECT; ++ match_data->subject = match_data->memctl.malloc(CU2BYTES(length), ++ match_data->memctl.memory_data); ++ if (match_data->subject == NULL) ++ return match_data->rc = PCRE2_ERROR_NOMEMORY; ++ memcpy((void *)match_data->subject, subject, CU2BYTES(length)); + } + else +- { +- /* When pcre2_jit_match sets the subject, it doesn't know what the +- original passed-in pointer was. */ +- if (match_data->subject != NULL) match_data->subject = original_subject; +- } +- return rc; ++ match_data->subject = NULL; ++ match_data->flags |= PCRE2_MD_COPIED_SUBJECT; + } ++ else ++ { ++ /* When pcre2_jit_match sets the subject, it doesn't know what the ++ original passed-in pointer was. */ ++ if (match_data->subject != NULL) match_data->subject = original_subject; ++ } ++ return rc; + } + #endif /* SUPPORT_JIT */ + +@@ -7240,12 +7225,8 @@ this. */ + + mb->check_subject = subject; + +-/* If a UTF subject string was not checked for validity in the JIT code above, +-check it here, and handle support for invalid UTF strings. The check above +-happens only when invalid UTF is not supported and PCRE2_NO_CHECK_UTF is unset. +-If we get here in those circumstances, it means the subject string is valid, +-but for some reason JIT matching was not successful. There is no need to check +-the subject again. ++/* Check the validity of UTF subject strings. The check happens only when ++PCRE2_NO_CHECK_UTF is unset. + + We check only the portion of the subject that might be be inspected during + matching - from the offset minus the maximum lookbehind to the given length. +@@ -7257,11 +7238,7 @@ Note also that support for invalid UTF forces a check, overriding the setting + of PCRE2_NO_CHECK_UTF. */ + + #ifdef SUPPORT_UNICODE +-if (utf && +-#ifdef SUPPORT_JIT +- !jit_checked_utf && +-#endif +- ((options & PCRE2_NO_UTF_CHECK) == 0 || allow_invalid)) ++if (utf && ((options & PCRE2_NO_UTF_CHECK) == 0 || allow_invalid)) + { + #if PCRE2_CODE_UNIT_WIDTH != 32 + BOOL skipped_bad_start = FALSE; diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index fa59747fdca..7d027e90eec 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -16,6 +16,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://run-ptest \ file://CVE-2026-89162.patch \ file://CVE-2026-89161.patch \ + file://CVE-2026-89156.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100334 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 99D07CA9EC9 for ; Sun, 11 Oct 2026 08:41:39 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23458.1791708098862697627 for ; Sun, 11 Oct 2026 01:41:39 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tWoE9z0T; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-48c4649b35bso864132f8f.3 for ; Sun, 11 Oct 2026 01:41:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708097; x=1792312897; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RJXo6hANb+/pGk36L0UqITkH6/wLY3pz5vtCa0GqhiU=; b=tWoE9z0TKk/LEi5MRZM8cs541EkzgcYJECarXgw9HXhm4ZMlcBCvGIUbMOowzkfLR8 DdMmrzkGVqC6ngCZwpaQTqGkdymPjD5wyXun3+F4hYnqjLhiIm7YswUXtMgmLTqeoeWQ 3Ifwg4ZqhZp2TiASQhYWFFOYl2tTNM6efyLVo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708097; x=1792312897; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RJXo6hANb+/pGk36L0UqITkH6/wLY3pz5vtCa0GqhiU=; b=KGAjfo4/oUMgg9Uh3fpF5bF4qH39p1PT4/elqIuu23n1pLmHNE1nF9BuTTjkvH6Emb 15Yuf92O7154tXIsJBTZqDXOwtoBTKLvi7CPzE46ZhBZqC6oaAJPYglCkATpYFTEotGs cfrms/0Eh5GTSffNA9QhCi3KA3TWi4fcTk1WxEhd+lRZgMEzYgIqHeD/3hdOUDbXxr+L 586lXlBcC7S1VIltpfC/zBLtre9lA+ax8BJdYrl/qD6xYRom9hz7pvlFzWLZClu577GM Rjv0qigXSihJ/rswqI7Qna/So55KGwv7Aptloel+f/FEpfvJlRXY6fJeMtyMDPGPkYBq ezbg== X-Gm-Message-State: AFq9FYIpV77oaxOH7/2+QUXHTSbLPntlCSSLB2h1Q5uQ884ub5Z6eXnb 38u0Q5QphslYVIe3ULF31mU+6cBr5Djsh4xurWn/FbrGILurWmJX0gZsjRuB7zVNIQXRbDngG4q sm7c2pMQ= X-Gm-Gg: AYBFou07eij5Ksy3YqwbGR3QMHbh/UU2V/kEkKboMYZyqQrk6f9HpKYaYL30g2+fA4D 1Q1vTSxLAvM1gecbf/hgr/veG5snTdMdD7RlCVCcSCvsUNNkQQ/xfpuCw4tD9nUQApfrkpG/1BH rubXkVHVNkVvLw0hCeoxk2mnO/Gl+F6Hk7G2NzV7G1EQoJzQiFLKzFO4/UDCv4PyRAcrOomyETC FRU8JmCR7dpOoZL4ngGTOChLXNBhH4vHRkMFqNzajZgeoyTm2oyEZLK50Um94cIxK/vqTvf7Cxa /2MZtOjpKeybczEXMcLMjZtV7cfrjMxe2um/Pt8xcQgnOwcalLhU9SFoitg22yQiM3C5dTJbkUm K/ToU8SMBKzhe0cfV6I6y5O32oJmVww1M1N/720eqZZBpOPsZF8YOGElMb5wJU2mgR2KWuiLUyJ DBWfF7pRFEYXnGZrz+KgXHRzmS/7fL1H5zvQ+eEEhSQU+InAgO+vaq1Hon+OBXq09Xw0ta4HXqS gbkw1PzCaOij0Cmj/UhOYrpOSbedMiR8EvFz3tbmR0qGe+pAMwtt7k1+D8CZoPGvAEbSywRlg== X-Received: by 2002:adf:e183:0:b0:487:490:8391 with SMTP id ffacd0b85a97d-48dbaadd94cmr11179495f8f.16.1791708097058; Sun, 11 Oct 2026 01:41:37 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:36 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 56/60] libpcre2: patch CVE-2026-89157 Date: Sun, 11 Oct 2026 10:40:29 +0200 Message-ID: <08b716da1674d64eafb3a4bf7c7d5b9bc6a33138.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247565 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-89157 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89157.patch | 61 +++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch new file mode 100644 index 00000000000..fa525c79d87 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch @@ -0,0 +1,61 @@ +From 8156b3989a82f2ddf9504d8248496e9b124be7f3 Mon Sep 17 00:00:00 2001 +From: Ilia Alshanetsky +Date: Sun, 9 Aug 2026 07:15:03 -0400 +Subject: [PATCH] Use CU2BYTES for byte sizing in two allocation sites (#909) + +Two allocation sites multiplied by PCRE2_CODE_UNIT_WIDTH (the bit width: +8, 16, or 32) where the CU2BYTES(x) byte-count helper is intended. The +result over-allocates by the code-unit byte width: 8x in 8-bit mode, 16x +in 16-bit, 32x in 32-bit. Subsequent memcpy calls already use CU2BYTES +correctly, so no out-of-bounds write occurs; the over-allocation is +leaked until the buffer is freed. + +Also guard each site against integer overflow in +sizeof(pcre2_memctl) + CU2BYTES(N + 1) by rejecting N greater than +(PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1) - 1. + +CVE: CVE-2026-89157 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3] +Signed-off-by: Peter Marko +--- + src/pcre2_convert.c | 8 +++++--- + src/pcre2_substring.c | 7 ++++--- + 2 files changed, 9 insertions(+), 6 deletions(-) + +diff --git a/src/pcre2_convert.c b/src/pcre2_convert.c +index ad7312ab..8a2b293d 100644 +--- a/src/pcre2_convert.c ++++ b/src/pcre2_convert.c +@@ -1215,9 +1215,11 @@ for (int i = 0; i < 2; i++) + /* Allocate memory for the buffer, with hidden space for an allocator at + the start. The next time round the loop runs the conversion for real. */ + +- allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + +- (*bufflenptr + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)ccontext); +- if (allocated == NULL) ++ if (*bufflenptr > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / ++ CU2BYTES(1)) - 1 || ++ (allocated = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + ++ CU2BYTES(*bufflenptr + 1), ++ (pcre2_memctl *)ccontext)) == NULL) + { + *bufflenptr = 0; /* Error offset */ + return PCRE2_ERROR_NOMEMORY; +diff --git a/src/pcre2_substring.c b/src/pcre2_substring.c +index f68b464e..a6f5277a 100644 +--- a/src/pcre2_substring.c ++++ b/src/pcre2_substring.c +@@ -210,9 +210,10 @@ PCRE2_SIZE size; + PCRE2_UCHAR *yield; + rc = pcre2_substring_length_bynumber(match_data, stringnumber, &size); + if (rc < 0) return rc; +-yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + +- (size + 1)*PCRE2_CODE_UNIT_WIDTH, (pcre2_memctl *)match_data); +-if (yield == NULL) return PCRE2_ERROR_NOMEMORY; ++if (size > ((PCRE2_SIZE_MAX - sizeof(pcre2_memctl)) / CU2BYTES(1)) - 1 || ++ (yield = PRIV(memctl_malloc)(sizeof(pcre2_memctl) + ++ CU2BYTES(size + 1), (pcre2_memctl *)match_data)) == NULL) ++ return PCRE2_ERROR_NOMEMORY; + yield = (PCRE2_UCHAR *)(((char *)yield) + sizeof(pcre2_memctl)); + if (size != 0) memcpy(yield, match_data->subject + match_data->ovector[stringnumber*2], + CU2BYTES(size)); diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 7d027e90eec..bbe37573215 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -17,6 +17,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89162.patch \ file://CVE-2026-89161.patch \ file://CVE-2026-89156.patch \ + file://CVE-2026-89157.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100350 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CF904CA9EDF for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23459.1791708099678164364 for ; Sun, 11 Oct 2026 01:41:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1t68sBC1; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48870973bddso533774f8f.1 for ; Sun, 11 Oct 2026 01:41:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708098; x=1792312898; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=A3DcDtqcC5qc1JDR4EqCY7a0FAIAb+d2++rTXC5PREw=; b=1t68sBC1Vj+CZdD9hNnAOtYMO3woH6plohSrsF7pUbOo7wVUqSLOaRFDA4HBBP1elp AX/6sCB6kLGuapdD3Df0MHFFYzz8pKfJ9Vy+4pOOR63Ar1IJ/iBEmd2JVcymcOeUllut qBVy07LQEFhnqK9Du1gmELvNaTP93CcqeBUoM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708098; x=1792312898; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=A3DcDtqcC5qc1JDR4EqCY7a0FAIAb+d2++rTXC5PREw=; b=sWZrwuIfiI9UByOOrWz/F0po3Kv03KC3RSek9sYJAnNw0R0x0lY7rC3k6Gd6wB48u6 zoRwEP7t+z++aQYlX9EEu2WF2F+dwzoi5yCwBOHDaGVpo/MrtrFCLfIJjShE7+V/Ncq/ 1SGdeQH078gHD83M7s8K1b/wkdTtHD0SeLnH+FC5zHQVUJIohKstpiX7r4rdKIpO5uv6 VmtLZHVSSrZOn3cY4aEz0VTLNg2B9tR16zQmTYs9AXr9Cn6GTcUbranBOq0Ib/+kAro9 9ZxL5EYlAL0a4gVDUMznkjXGs8PI9o29CZRe5/JPB7Dvwd9LwRCQpWFi35HXa044ILNX cGxA== X-Gm-Message-State: AFq9FYKA2BP//PSbXaJzGT3+xO/AvHqHqLMXAKuQLbkSyQhfOEm1JIy0 xHGeMHVyzcGt/NFvnZebujV47hyHDkRTKyEwFfFaBRxdCUXDzerR0b/Ur8ZY2pQTRQr1AHRcjqn MtK1eUlc= X-Gm-Gg: AYBFou146yC3acq9tTDiiQsuOTrRDszHa4/ojv7Z8G5OskjHAG9SQtzVLxoxBrUTvnf vuGaK22vXVPQ/fTZdp2PeY1SmffwJ7JKLQazLb2JMulJ5YjgkLRcKuy4ifNe5NfwcPh725Aw/+u uwS9LvKXap7fLpPK3+O1p8HvveMvWRA6hbKA9RA8EQ5rfaoxMXfTiJSj0YTG76Ok2yu1z8nPDM9 eBVLaJh0o7Gy61tc/Ot0FXtz2/8jbdtBRGgptLHYc790B2MyMJLN6KaVIL8mUU2K9CuZzgBxOaq A/bbNiaF8lU+il7cad3A/TP5DsTeBGcYMSbshT0kuna9/hz7F7ullm9k3wGy0yS0xdrpfbMNeYP G3Jl2Zg00OeXqvOakOPOO+u4qPiElwtPTuY0VDIPJgQ/04OCdOD3/SGQ4JOfLMHtW9+IVdvObu2 2a4yt+YUeYrvBvcwZ6tiq5lcFbb2v0Xzx9NqmTOwTsNKaKub8k8wTi7++z2cFQwgCZKxlvHsVkH 7q2XlI9UG1cWSbr471xGf4aWFZDutGTmEM2qLCd8Dlxc5z/L95tTYZLzYBv54VMVI0m9SQ+MA== X-Received: by 2002:a5d:4d45:0:b0:48a:fe00:ad1 with SMTP id ffacd0b85a97d-48dba9e641amr9443966f8f.6.1791708097650; Sun, 11 Oct 2026 01:41:37 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.37 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:37 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 57/60] libpcre2: patch CVE-2026-89160 Date: Sun, 11 Oct 2026 10:40:30 +0200 Message-ID: <2e1cea675dfe766f31abbb42f6554852553ae14b.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247566 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89160 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89160.patch | 225 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 226 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch new file mode 100644 index 00000000000..bff6bc83efa --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch @@ -0,0 +1,225 @@ +From 4889caf31a4c5a6b3c051f0031bf2dbd78f2c287 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix invalid UTF backwards-scan reads; see GHSA-9qww-pwc4-77qq + for details + +CVE: CVE-2026-89160 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287] +Signed-off-by: Peter Marko +--- + src/pcre2_extuni.c | 10 +++++----- + src/pcre2_match.c | 10 +++++----- + testdata/testinput10 | 10 ++++++++++ + testdata/testinput12 | 10 ++++++++++ + testdata/testoutput10 | 12 ++++++++++++ + testdata/testoutput12-16 | 12 ++++++++++++ + testdata/testoutput12-32 | 12 ++++++++++++ + 7 files changed, 66 insertions(+), 10 deletions(-) + +diff --git a/src/pcre2_extuni.c b/src/pcre2_extuni.c +index 1b7f04b4..fea098a7 100644 +--- a/src/pcre2_extuni.c ++++ b/src/pcre2_extuni.c +@@ -54,12 +54,12 @@ support, because some compilers do not like functionless source files. */ + + #ifndef SUPPORT_UNICODE + PCRE2_SPTR +-PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR start_subject, ++PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR check_subject, + PCRE2_SPTR end_subject, BOOL utf, int *xcount) + { + (void)c; + (void)eptr; +-(void)start_subject; ++(void)check_subject; + (void)end_subject; + (void)utf; + (void)xcount; +@@ -80,7 +80,7 @@ same behaviour. + Arguments: + c the first character + eptr pointer to next character +- start_subject pointer to start of subject ++ check_subject pointer to start of validated subject + end_subject pointer to end of subject + utf TRUE if in UTF mode + xcount pointer to count of additional characters, +@@ -90,7 +90,7 @@ Returns: pointer after the end of the sequence + */ + + PCRE2_SPTR +-PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR start_subject, ++PRIV(extuni)(uint32_t c, PCRE2_SPTR eptr, PCRE2_SPTR check_subject, + PCRE2_SPTR end_subject, BOOL utf, int *xcount) + { + BOOL was_ep_ZWJ = FALSE; +@@ -121,7 +121,7 @@ while (eptr < end_subject) + + /* bptr is pointing to the left-hand character */ + +- while (bptr > start_subject) ++ while (bptr > check_subject) + { + bptr--; + if (utf) +diff --git a/src/pcre2_match.c b/src/pcre2_match.c +index a5a8421f..966576e1 100644 +--- a/src/pcre2_match.c ++++ b/src/pcre2_match.c +@@ -2893,7 +2893,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, utf, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, utf, + NULL); + } + CHECK_PARTIAL(); +@@ -3244,7 +3244,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, + mb->end_subject, utf, NULL); + } + CHECK_PARTIAL(); +@@ -4069,7 +4069,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, + utf, NULL); + } + CHECK_PARTIAL(); +@@ -4658,7 +4658,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + else + { + GETCHARINCTEST(fc, Feptr); +- Feptr = PRIV(extuni)(fc, Feptr, mb->start_subject, mb->end_subject, ++ Feptr = PRIV(extuni)(fc, Feptr, mb->check_subject, mb->end_subject, + utf, NULL); + } + CHECK_PARTIAL(); +@@ -6233,7 +6233,7 @@ fprintf(stderr, "++ %2ld op=%3d %s\n", Fecode - mb->start_code, *Fecode, + { + for (i = 0; i < Lmax; i++) + { +- if (Feptr == mb->start_subject) ++ if (Feptr <= mb->check_subject) + { + if (i < Lmin) RRETURN(MATCH_NOMATCH); + Lmax = i; +diff --git a/testdata/testinput10 b/testdata/testinput10 +index d9e6ba8c..bfa9dad8 100644 +--- a/testdata/testinput10 ++++ b/testdata/testinput10 +@@ -585,6 +585,16 @@ + AAA\x80BXYZ + AAA\x80BBXYZ + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x80X ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x80\x{1f1e6}\x{1f1e7} ++ + # ------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testinput12 b/testdata/testinput12 +index 01cc76a4..c4a89a26 100644 +--- a/testdata/testinput12 ++++ b/testdata/testinput12 +@@ -498,6 +498,16 @@ + /(..)(*scs:(1)ab$)/match_invalid_utf + ab\x{df00}cde + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput10 b/testdata/testoutput10 +index 393ac207..9e124e2b 100644 +--- a/testdata/testoutput10 ++++ b/testdata/testoutput10 +@@ -1779,6 +1779,18 @@ No match + AAA\x80BBXYZ + No match + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x80X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x80\x{1f1e6}\x{1f1e7} ++No match ++ + # ------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput12-16 b/testdata/testoutput12-16 +index d235c11f..b0676a19 100644 +--- a/testdata/testoutput12-16 ++++ b/testdata/testoutput12-16 +@@ -1659,6 +1659,18 @@ No match + 0: ab + 1: ab + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++No match ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I +diff --git a/testdata/testoutput12-32 b/testdata/testoutput12-32 +index 725cb274..a97051a6 100644 +--- a/testdata/testoutput12-32 ++++ b/testdata/testoutput12-32 +@@ -1658,6 +1658,18 @@ No match + 0: ab + 1: ab + ++# Backward scans must not enter the invalid prefix before check_subject. ++ ++/(?<=a{1,2})X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}X ++No match ++ ++/\X\X/utf,match_invalid_utf ++\= Expect no match ++ \x{dc00}\x{1f1e6}\x{1f1e7} ++No match ++ + # ---------------------------------------------------- + + /(*UTF)(?=\x{123})/I diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index bbe37573215..ef8274c9b16 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -18,6 +18,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89161.patch \ file://CVE-2026-89156.patch \ file://CVE-2026-89157.patch \ + file://CVE-2026-89160.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100352 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C020DCA9EDD for ; Sun, 11 Oct 2026 08:41:40 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23587.1791708100159847413 for ; Sun, 11 Oct 2026 01:41:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qrw1kNmf; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-48b02b1b4cfso1947423f8f.0 for ; Sun, 11 Oct 2026 01:41:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708098; x=1792312898; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eT/T38/ITBxXm+fBFVBkDOApdUQ3mfKdRd5ZwkzkilY=; b=qrw1kNmfp5Ht2iXZp2EcAyE8mMyA7rLeax6osIS+GIn0eOXMCPJ7FpTR1PklFBXp0C 2jHWb83VwNQ6Js9sJAMLUaxx5QI1scbvoI+SM5JF152AsqaOxvnw0CgXXC2Y/hKbA3hr 58A/KE6F6xTgxQK/gBMHxUz+b8GuHHZaMD48E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708098; x=1792312898; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=eT/T38/ITBxXm+fBFVBkDOApdUQ3mfKdRd5ZwkzkilY=; b=Gakaxg+sMs2ueIMKfQFRTA4PnD0Z0DtXMWZ0Jjfj0G69MU+h66qbeSJRbe4WkWItkG LLKK9X5qbkljBPezlX/6xL9RsPfHM14EhiJ1w/z3GGc3K3hfQG7u/E4A+pEQzYlcJ/hZ gopXFv5kC/MJQDVb82qAJaN7PlzHLZ/XIiIlCLzpc6E4dvwI4mmzUJVWqNn3Q7h2VB+y eYyD3a80pNYRDk3XePiaDB6KjKSfGG7dFwSR7ZzQym1TK521m057VWD1biKotzxwa8aG E64T1ZUVlWxCfo+Krb/TLoybtZqMdbEaxbvtVbsTjE6CrNPe6KrdPbgdPwqA7Vtw7bLK OOqg== X-Gm-Message-State: AFq9FYKRZSD8iSIuH1uHh4iBcI50c7ttDVUyzJ5rN2WYmL13Bdxu7W0Y KM18jU12HQx43+hlq/G6g813AxIcVX0yX0a+cgZYsCRrW97Tsrez8M/DvJjfuSnEOAAlRLxpCsz yxZz+Jco= X-Gm-Gg: AYBFou1DF80Li+nfvk67iPmaH9xyWDvvo+0k8zd2BeTKXaQYnQd1rKmOlRmg5PdjfJu RR39L/cTo2UXb7Z3qQgZmy88OhpBl5Z11lAv3LYkB7tDlJh5liii8O99/T8u+PJIX5GI1nUcpNQ J8t72WWjgwcdlMZBVQaZg4PeMsvm7p7MOOuuRLHsL2OFTWkXukfT857KHudZlX1iXwJJPqFABmk wN1U/1bEx20LIIHxCYu64VrEx6XUgM2ZzrwL3uH1r1CPtHI+w5riQH1lnkbGqbE6Ku+Yt+0Rqr1 uVE0+x3ZA5a7XVUyh0p6+xE4q+COCfRtcx1gxjRtSYYFFKXp06lDRYgcToB3W7JRr/lLHUhYudP 8DNiMklifTImj7Kfw2/CU8GGVDtigcl2an2v5VdNODtgJ3EYNaNyQpYkOqU8mSn5AT/nBDpq7At kZTGF1q1+wPbEOAOj7cywZtFjVJJkojGIvbkiD79XykLhV3NouWA3wleKQHqdi1U0erpjLRFuCO yTbIck8IbJzS63tKQW37PJeD+uYmqsIAdvCHPfo8sgX8wRbPS5Yyur3IoUzKrQM7/I6ANSRMg== X-Received: by 2002:a05:6000:298d:20b0:48b:469:b562 with SMTP id ffacd0b85a97d-48dba7b3284mr8836136f8f.2.1791708098251; Sun, 11 Oct 2026 01:41:38 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.37 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:37 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 58/60] libpcre2: patch CVE-2026-89158 Date: Sun, 11 Oct 2026 10:40:31 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247567 From: Peter Marko Pick patch per [1] since [2] does not provide it. [1] https://security-tracker.debian.org/tracker/CVE-2026-89158 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-89158.patch | 208 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 209 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch new file mode 100644 index 00000000000..80996674332 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch @@ -0,0 +1,208 @@ +From ec9c286d5c10cf1c388b58a442ccefded42254fd Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix compiler integer overflows; see GHSA-fmgr-6ggq-9859 for + details + +CVE: CVE-2026-89158 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd] +Signed-off-by: Peter Marko +--- + src/pcre2_compile.c | 55 ++++++++++++++++++++++++++++++++++++--- + src/pcre2_compile_class.c | 35 ++++++++++++++++--------- + 2 files changed, 74 insertions(+), 16 deletions(-) + +diff --git a/src/pcre2_compile.c b/src/pcre2_compile.c +index 1081cf64..32cb32f6 100644 +--- a/src/pcre2_compile.c ++++ b/src/pcre2_compile.c +@@ -6195,7 +6195,8 @@ for (;; pptr++) + + if (meta < META_ASTERISK || meta > META_MINMAX_QUERY) + { +- if (OFLOW_MAX - *lengthptr < (PCRE2_SIZE)(code - orig_code)) ++ if (*lengthptr > OFLOW_MAX || ++ OFLOW_MAX - *lengthptr < (PCRE2_SIZE)(code - orig_code)) + { + *errorcodeptr = ERR20; /* Integer overflow */ + cb->erroroffset = 0; +@@ -8795,7 +8796,8 @@ for (;;) + *reqcuflagsptr = reqcuflags; + if (lengthptr != NULL) + { +- if (OFLOW_MAX - *lengthptr < length) ++ if (*lengthptr > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - *lengthptr < length) + { + *errorcodeptr = ERR20; + return 0; +@@ -8818,6 +8820,19 @@ for (;;) + { + code = *codeptr + 1 + LINK_SIZE + skipunits; + length += 1 + LINK_SIZE; ++ ++ /* Move the accumulated length into *lengthptr, providing the next call to ++ compile_branch with as much space in &length and &code as the first did. */ ++ ++ if (*lengthptr > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - *lengthptr < length) ++ { ++ *errorcodeptr = ERR20; ++ cb->erroroffset = 0; ++ return 0; ++ } ++ *lengthptr += length; ++ length = 0; + } + else + { +@@ -10831,7 +10846,8 @@ if (errorcode != 0) goto HAD_CB_ERROR; /* Offset is in cb.erroroffset */ + #if defined SUPPORT_WIDE_CHARS + PCRE2_ASSERT((cb.char_lists_size & 0x3) == 0); + if (length > MAX_PATTERN_SIZE || +- MAX_PATTERN_SIZE - length < (cb.char_lists_size / sizeof(PCRE2_UCHAR))) ++ BYTES2CU(cb.char_lists_size) > MAX_PATTERN_SIZE || ++ MAX_PATTERN_SIZE - length < BYTES2CU(cb.char_lists_size)) + #else + if (length > MAX_PATTERN_SIZE) + #endif +@@ -10856,11 +10872,36 @@ if (cb.char_lists_size != 0) + /* Align to 32 bit first. This ensures the + allocated area will also be 32 bit aligned. */ + re_blocksize = (PCRE2_SIZE)CLIST_ALIGN_TO(re_blocksize, sizeof(uint32_t)); ++#else ++ /* Already 32 bit aligned. */ + #endif ++ ++ /* We have bounded the length and BYTES2CU(char_lists_size) to ++ MAX_PATTERN_SIZE units, however (with 32-bit code units) char_lists_size ++ in bytes could still be extremely close to (or greater than) SIZE_MAX, so ++ we require another overflow check. */ ++ ++ if (cb.char_lists_size > PCRE2_SIZE_MAX - re_blocksize) ++ { ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += cb.char_lists_size; + } + #endif + ++if (length > BYTES2CU(PCRE2_SIZE_MAX - re_blocksize)) ++ { ++ /* Given the current value of 2^30 for MAX_PATTERN_SIZE, this block is only ++ reachable when both PCRE2_CODE_UNIT_WIDTH >= 16 and sizeof(size_t) is ++ 32 bits. */ ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += CU2BYTES(length); + + if (re_blocksize > ccontext->max_pattern_compiled_length) +@@ -10870,7 +10911,15 @@ if (re_blocksize > ccontext->max_pattern_compiled_length) + goto HAD_CB_ERROR; + } + ++if (sizeof(pcre2_real_code) > PCRE2_SIZE_MAX - re_blocksize) ++ { ++ errorcode = ERR20; ++ cb.erroroffset = 0; ++ goto HAD_CB_ERROR; ++ } ++ + re_blocksize += sizeof(pcre2_real_code); ++ + re = (pcre2_real_code *) + ccontext->memctl.malloc(re_blocksize, ccontext->memctl.memory_data); + if (re == NULL) +diff --git a/src/pcre2_compile_class.c b/src/pcre2_compile_class.c +index c6f30d6f..c0606643 100644 +--- a/src/pcre2_compile_class.c ++++ b/src/pcre2_compile_class.c +@@ -498,7 +498,7 @@ static const uint32_t char_list_starts[] = { + + static class_ranges * + compile_optimize_class(uint32_t *start_ptr, uint32_t options, +- uint32_t xoptions, compile_block *cb) ++ uint32_t xoptions, int *errorcodeptr, compile_block *cb) + { + class_ranges* cranges; + uint32_t *ptr; +@@ -538,12 +538,23 @@ PCRE2_ASSERT((range_list_size & 0x1) == 0); + + total_size = range_list_size + + ((range_list_size >= 2) ? CHAR_LIST_EXTRA_SIZE : 0); ++if (total_size > (PCRE2_SIZE_MAX - sizeof(class_ranges)) / sizeof(uint32_t)) ++ { ++ *errorcodeptr = ERR20; ++ cb->erroroffset = 0; ++ return NULL; ++ } + + cranges = cb->cx->memctl.malloc( + sizeof(class_ranges) + total_size * sizeof(uint32_t), + cb->cx->memctl.memory_data); + +-if (cranges == NULL) return NULL; ++if (cranges == NULL) ++ { ++ *errorcodeptr = ERR21; ++ cb->erroroffset = 0; ++ return NULL; ++ } + + cranges->header.next = NULL; + #ifdef PCRE2_DEBUG +@@ -1116,13 +1127,10 @@ if (utf) + { + if (lengthptr != NULL) + { +- cranges = compile_optimize_class(pptr, options, xoptions, cb); ++ cranges = compile_optimize_class(pptr, options, xoptions, errorcodeptr, cb); + + if (cranges == NULL) +- { +- *errorcodeptr = ERR21; + return NULL; +- } + + /* Caching the pre-processed character ranges. */ + if (cb->last_data != NULL) +@@ -1755,18 +1763,17 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + *lengthptr += 1 + LINK_SIZE; + #endif + +- cb->char_lists_size += char_lists_size; ++ PCRE2_ASSERT(BYTES2CU(cb->char_lists_size) <= MAX_PATTERN_SIZE); + +- char_lists_size /= sizeof(PCRE2_UCHAR); +- +- /* Storage space for character lists is included +- in the maximum pattern size. */ +- if (*lengthptr > MAX_PATTERN_SIZE || +- MAX_PATTERN_SIZE - *lengthptr < char_lists_size) ++ if (char_lists_size > PCRE2_SIZE_MAX - cb->char_lists_size || ++ BYTES2CU(char_lists_size) > MAX_PATTERN_SIZE || ++ BYTES2CU(cb->char_lists_size) > MAX_PATTERN_SIZE - BYTES2CU(char_lists_size)) + { + *errorcodeptr = ERR20; /* Pattern is too large */ + return NULL; + } ++ ++ cb->char_lists_size += char_lists_size; + } + else + { +@@ -1789,6 +1796,8 @@ if ((xclass_props & XCLASS_REQUIRED) != 0) + Each list is aligned to 32 bit with an optional unused + 16 bit value at the beginning of the character list. */ + ++ PCRE2_ASSERT(char_lists_size <= PCRE2_SIZE_MAX - cb->char_lists_size); ++ + cb->char_lists_size += char_lists_size; + data = (uint8_t*)cb->start_code - cb->char_lists_size; + diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index ef8274c9b16..2f40ef463eb 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -19,6 +19,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89156.patch \ file://CVE-2026-89157.patch \ file://CVE-2026-89160.patch \ + file://CVE-2026-89158.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100354 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB7B8CA9ECA for ; Sun, 11 Oct 2026 08:41:50 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.23460.1791708100901681068 for ; Sun, 11 Oct 2026 01:41:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jqCkmlMZ; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48c5358fc28so690461f8f.0 for ; Sun, 11 Oct 2026 01:41:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708099; x=1792312899; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mwrZqK4Qplpg6atDCoeQoX12HRu82oZKicCONPa8fEk=; b=jqCkmlMZpolG4PdaERSxSFzvfV2OKwo5w0exKswzKcAzNvKATvmdMhEIV2CK1p5VM3 gTzvh1n72HJg3aF7c2Rf7IXe2bfo1jek2qoLtoimt1cWRm5zNAr/l+05+MMEYxJKLQmv ANCfMKPHB5xqFcFOyT7Hhizstw5LJrj4stvk0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708099; x=1792312899; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=mwrZqK4Qplpg6atDCoeQoX12HRu82oZKicCONPa8fEk=; b=M/76FU9sQn9ESLHiwBWkRHlXpmMb/Hqc8MeQ8gpCeXpFpEzEphCwpxHrXGr5oLqxQz /LlG2pRnhAyXFksIhqQL1Xm62R1454YeUC7yuxOgV/e5mJSspsTDPrB0qlUkeT945TC4 Uo1B39h7N0j7rj+QxN8e8jFQHjCtJU0lqOfNeeDbUd1hSiQFxRiJ6wmdLWCbPbvJOweB faBvoJXrLjmwN3zCPzFlaKStMCR6RCi0NgRypquO90BRblvLdsVHpTsR3c9SSUrl55Wa 6xCYb2ACGeyUeSjDzcEYYhpHsNY/fFcMsXacSPeQbhtZBQ1fr6jSO63cpU+mVhRalFCD SZ+A== X-Gm-Message-State: AFq9FYKSUnDEaFpef5dCc0aNI7sbzYPlyEpaMh/kSJ2yehCxDA1SC0XE SIhcmiXZ6bCYLJth82rjCMEGDG6ULIZW7v2ChuvO/lKyHaAZp7jmMDQLy8WkP5A7sGebP0KuRZR zN+qD2CI= X-Gm-Gg: AYBFou3Q/qtIrk3so1RnMtJHlLRWUthpVZrQyUU1RlmelVOoJJ7TuUn81wv++b6g+Hq 1E23WkN2rsGZchKc/CKk3hmpSplM/wMtSh+8t1Bk0EogNeeWNLHyGB7U80Ap0LDOkdbpPieti7k yT6xwUfizplxdHrq8BVskzYNJVItVHoG/hPo9d1BT4S2djat1cT9A3x/UzQc6VgsBSpzmIiyYCY /48qrtGNBn+3Sq2DcPP8jCa/6b2ON4RnQCCfoxqirWqmCEdm9zOgT7h/InRXwT6O3Paj6L/W8uu BjvAHTRH0v2akpWo6Zeck5kFmJpUC6MZpnYznAHX8yFG5QeziUKCxgajuPzGY2SnAvgZZ0JvvS1 AXPgXdv3lWmNSUr2j/0mU8IOZwCp8dYCxQAAE57YAawyNwSu8iB3ryju8CFzonyhJnzC6I6Vmz6 /5EjhGawFF+rGcHyi/e7JTYvLBatKzrbpoKbyHRTy3FKdxkak2SccillrHVk0pIvYPNmPxTAAcx /N9aLuHZBNTVqJTmHpbJL0WU5htzjQGBQFHR+NoDFaQbxx37B5pROJGNkOj3sUpnSx60hTbqA== X-Received: by 2002:adf:f24d:0:b0:485:8c16:5ee9 with SMTP id ffacd0b85a97d-48dbaaef911mr8531132f8f.35.1791708098864; Sun, 11 Oct 2026 01:41:38 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 59/60] libpcre2: patch CVE-2026-86145 Date: Sun, 11 Oct 2026 10:40:32 +0200 Message-ID: <2bd1c40bcfc139c47eb5433b3a2e3aa5de18ae53.1791707817.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247568 From: Peter Marko Pick patch per [1] since [2] does not provide valid commit hash. [1] https://security-tracker.debian.org/tracker/CVE-2026-86145 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-86145.patch | 158 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 159 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch new file mode 100644 index 00000000000..a044a006e5f --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch @@ -0,0 +1,158 @@ +From c932e70451eafef922ebef364ac25042f0031135 Mon Sep 17 00:00:00 2001 +From: Nicholas Wilson +Date: Thu, 27 Aug 2026 16:52:16 +0100 +Subject: [PATCH] Fix DFA workspace overflows; see GHSA-3r4p-g7gg-ppmf for + details + +CVE: CVE-2026-86145 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135] +Signed-off-by: Peter Marko +--- + src/pcre2_dfa_match.c | 44 ++++++++++++++++++++++++++++++++++++------- + testdata/testinput6 | 7 +++++++ + testdata/testoutput6 | 8 ++++++++ + 3 files changed, 52 insertions(+), 7 deletions(-) + +diff --git a/src/pcre2_dfa_match.c b/src/pcre2_dfa_match.c +index 314e9775..8e9512c4 100644 +--- a/src/pcre2_dfa_match.c ++++ b/src/pcre2_dfa_match.c +@@ -405,8 +405,8 @@ return (mb->callout)(cb, mb->callout_data); + + /* This function is called when internal_dfa_match() is about to be called + recursively and there is insufficient working space left in the current +-workspace block. If there's an existing next block, use it; otherwise get a new +-block unless the heap limit is reached. ++workspace block. If there's a sufficiently large next block, use it; get a new ++block unless the heap limit is (or has been) reached. + + Arguments: + rwsptr pointer to block pointer (updated) +@@ -422,9 +422,18 @@ more_workspace(RWS_anchor **rwsptr, unsigned int ovecsize, dfa_match_block *mb) + { + RWS_anchor *rws = *rwsptr; + RWS_anchor *new; ++uint32_t requested; ++ ++PCRE2_ASSERT(ovecsize <= UINT32_MAX - RWS_RSIZE - RWS_ANCHOR_SIZE); ++requested = RWS_RSIZE + ovecsize + RWS_ANCHOR_SIZE; + + if (rws->next != NULL) + { ++ /* Although the initial block is large, and subsequent ones try to double, the ++ heap limit may cause the last one to be smaller; in this case, we have already ++ hit the heap limit and allocating a larger block will not be possible. */ ++ if (rws->next->size < requested) ++ return PCRE2_ERROR_HEAPLIMIT; + new = rws->next; + } + +@@ -434,14 +443,30 @@ overflow. */ + + else + { +- uint32_t newsize = (rws->size >= UINT32_MAX/(sizeof(int)*2))? UINT32_MAX/sizeof(int) : rws->size * 2; ++ uint32_t newsize = (rws->size >= (UINT32_MAX/sizeof(int))/2)? ++ UINT32_MAX/sizeof(int) : rws->size * 2; + uint32_t newsizeK = newsize/(1024/sizeof(int)); + +- if (newsizeK + mb->heap_used > mb->heap_limit) +- newsizeK = (uint32_t)(mb->heap_limit - mb->heap_used); +- newsize = newsizeK*(1024/sizeof(int)); ++ /* Clamp the allocation to the remaining heap allowance with care for overflows */ + +- if (newsize < RWS_RSIZE + ovecsize + RWS_ANCHOR_SIZE) ++ if (mb->heap_used >= mb->heap_limit) ++ { ++ newsize = 0; ++ newsizeK = 0; ++ } ++ else ++ { ++ PCRE2_SIZE availableK = mb->heap_limit - mb->heap_used; ++ /* newsize always capped at UINT32_MAX/sizeof(int), so newsizeK also capped; ++ and - if availableK is smaller - then multiplication to form newsize is safe */ ++ if (newsizeK > availableK) ++ { ++ newsize = (uint32_t)(availableK*(1024/sizeof(int))); ++ newsizeK = availableK; ++ } ++ } ++ ++ if (newsize < requested) + return PCRE2_ERROR_HEAPLIMIT; + new = mb->memctl.malloc(newsize*sizeof(int), mb->memctl.memory_data); + if (new == NULL) return PCRE2_ERROR_NOMEMORY; +@@ -2801,6 +2826,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + while (*endasscode == OP_ALT) endasscode += GET(endasscode, 1); +@@ -2900,6 +2926,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + while (*endasscode == OP_ALT) endasscode += GET(endasscode, 1); +@@ -2951,6 +2978,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_RSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_RSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_RSIZE; + + /* Check for repeating a recursion without advancing the subject +@@ -3050,6 +3078,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + if (codevalue == OP_BRAPOSZERO) +@@ -3149,6 +3178,7 @@ for (;;) + + local_offsets = (PCRE2_SIZE *)(RWS + rws->size - rws->free); + local_workspace = ((int *)local_offsets) + RWS_OVEC_OSIZE; ++ PCRE2_ASSERT(rws->free >= RWS_RSIZE + RWS_OVEC_OSIZE); + rws->free -= RWS_RSIZE + RWS_OVEC_OSIZE; + + rc = internal_dfa_match( +diff --git a/testdata/testinput6 b/testdata/testinput6 +index f6f5cbf4..197f6f76 100644 +--- a/testdata/testinput6 ++++ b/testdata/testinput6 +@@ -5263,4 +5263,11 @@ + abc\=replace=xyz + abc\=replace=xyz,substitute_matched + ++# -------------- ++ ++# Test workspace resizing and workspace re-use ++ ++/(*LIMIT_HEAP=4)(?=(?=(?=(?=(?=(?=(?=(?=a))(?R)))))))./ ++ a\=dfa ++ + # End of testinput6 +diff --git a/testdata/testoutput6 b/testdata/testoutput6 +index 8ecf0040..4316c8a6 100644 +--- a/testdata/testoutput6 ++++ b/testdata/testoutput6 +@@ -8237,4 +8237,12 @@ Failed: error -42: pattern contains an item that is not supported for DFA matchi + abc\=replace=xyz,substitute_matched + Failed: error -41: function is not supported for DFA matching + ++# -------------- ++ ++# Test workspace resizing and workspace re-use ++ ++/(*LIMIT_HEAP=4)(?=(?=(?=(?=(?=(?=(?=(?=a))(?R)))))))./ ++ a\=dfa ++Failed: error -63: heap limit exceeded ++ + # End of testinput6 diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 2f40ef463eb..60ba56014bf 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -20,6 +20,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89157.patch \ file://CVE-2026-89160.patch \ file://CVE-2026-89158.patch \ + file://CVE-2026-86145.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" From patchwork Sun Oct 11 08:40:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 100353 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C8161CA9EC9 for ; Sun, 11 Oct 2026 08:41:50 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.23588.1791708101308108688 for ; Sun, 11 Oct 2026 01:41:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=izuewGq6; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48afe0081a6so609257f8f.2 for ; Sun, 11 Oct 2026 01:41:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1791708099; x=1792312899; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=y+/h+CeNecC7ZCX8QrR5HB0tJLtzxXhB55wiZToO7LU=; b=izuewGq6Z+278kFkpVJF7gTQ1tanWQLkKr1CIRsnUy/jpLC+iElXHiywCBcL8bxQOb Te6nufggCTA05RtY+19/7iSBixw5ag+wo3t6OAopiZb+z2FxSBbq1diW4PhG21Y1TOGS 7K8/V8FEW7ZHz45vNuOncankogKxZ2l7Ts7VE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791708099; x=1792312899; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=y+/h+CeNecC7ZCX8QrR5HB0tJLtzxXhB55wiZToO7LU=; b=RGZiHXOZEZXaV7HpRGXEGc43bJcoGl/jnv6oC/J4jh2NfHExypd6ST2f8zeBXVBYot bwBZ5TLvll+9vds9H+w+nZA/bJ+os4+BdJhZaiZum1uENn6i80kcnq+GMMsy7+rJg7Zr CFVVTUmUGD53jFxPyuY65Rz/jgPft1I5ZlVvVs+oMcChqicQqfL27alM5OIb9x3MeETt SCo4y4fdt4g+5dYjrTYc6T+7G9RgtQ89YSQ4q0nyO4C1DilYutrWLieuEiuplykSXmn1 r7jMC79/RS0CQKwg8nN7PhQSrEH19Ajxh3Lc6rOnAGpWREnzlAwNYTMH2WnLptG/h/+G 6JIw== X-Gm-Message-State: AFq9FYKN1nnksj91N0nkv4bLb8+TGv3UE3daMvEZMx7IQu6gZBmsKIGW Kp9fDrLzsyw+lxTK2VfwgXR+MZlsDsfCq62si6l8Sfmgh6MQpgs3GGQk4pgdppi7gL5wQ0fNZsT XoMJS+EU= X-Gm-Gg: AYBFou3Xk10J0bS0ul7tsqWeO0UNl12Owl1OPt15Hx17hIeBVEjcdl3DxdKj3XaQjXJ 12M+yJKTkUlDbmhRPUI4c6bK+of+DfInoP7etqW3LKZb1d13Hp5PHm4/s6OlUU02XAgkiol6rKq amruDKhUPcxMhdEqAP/SVaIwX+bNDyhaGZXvBg5/KCfD3qgvSab7JdONvvR9WREQ2xyGiXB1BAF WSaK1Ux3blD4Z4C1369cGxVT7n602AflYHyVV3UvjoMxL2azxf7O2MTnXjPYzkmfG/0usWW9ReQ +OKHaMnC7wzVUPbnYsex0RqsTrNKATVA1q4aC6540FncaRQ4spH8Zo0N/gKc+dLHyZH85IN3yRm JzDBGuVV8HUvPtGhfcNaOWDqg/Uvtx/NjaDtuH7VKzbFfOn8NokBGrWupPAO3C3SvXN7BTA7QKI GfyVetVzyXOOnKWad0GYeazurrJXGXqrjgmAwRy3RB4hq81PKzpHqL71/IbO0UljqgzRwtKv6tT n0GNU5KACZu3Ncr9Xr4OPyQmlvECB/B0/VD6bXJsPVguf0xFGjKxscCOl6HF4F0I8zGyl/Vyw== X-Received: by 2002:a5d:5f8f:0:b0:48b:42c:8b44 with SMTP id ffacd0b85a97d-48dbaaee9bcmr11080666f8f.32.1791708099381; Sun, 11 Oct 2026 01:41:39 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48db9acfa28sm13481734f8f.51.2026.10.11.01.41.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 11 Oct 2026 01:41:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 60/60] libpcre2: patch CVE-2026-103111 Date: Sun, 11 Oct 2026 10:40:33 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 11 Oct 2026 08:41:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247569 From: Peter Marko Pick patch per [1] and [2]. [1] https://security-tracker.debian.org/tracker/CVE-2026-103111 [2] https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../libpcre/libpcre2/CVE-2026-103111.patch | 111 ++++++++++++++++++ .../recipes-support/libpcre/libpcre2_10.47.bb | 1 + 2 files changed, 112 insertions(+) create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch diff --git a/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch b/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch new file mode 100644 index 00000000000..6006566d840 --- /dev/null +++ b/meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch @@ -0,0 +1,111 @@ +From 2b4038298072684b0fae29b15bedfb1a75bda46d Mon Sep 17 00:00:00 2001 +From: Zoltan Herczeg +Date: Mon, 21 Sep 2026 07:46:13 +0000 +Subject: [PATCH] Fix large JIT stack allocation + +(GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out of bounds write with +arbitrary data. Applications are only affected if using the +pcre2_jit_stack_assign() API to create a growable JIT stack, and then matching +against a pattern with an extremely JIT stack usage, such as a large number of +capturing groups. + +The implications of an out of bounds write could include arbitrary code +execution. + +The issue is not a regression and affects releases 10.48 and earlier. + +CVE: CVE-2026-103111 +Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/2b4038298072684b0fae29b15bedfb1a75bda46d] +Signed-off-by: Peter Marko +--- + src/pcre2_jit_compile.c | 21 +++++++++++++++++++-- + testdata/testinput17 | 5 +++++ + testdata/testoutput17 | 6 ++++++ + 3 files changed, 30 insertions(+), 2 deletions(-) + +diff --git a/src/pcre2_jit_compile.c b/src/pcre2_jit_compile.c +index 105a1dd3..c5da883c 100644 +--- a/src/pcre2_jit_compile.c ++++ b/src/pcre2_jit_compile.c +@@ -99,7 +99,7 @@ Fast, but limited size. */ + + /* Growth rate for stack allocated by the OS. Should be the multiply + of page size. */ +-#define STACK_GROWTH_RATE 8192 ++#define STACK_GROWTH_RATE (sljit_sw)8192 + + /* Enable to check that the allocation could destroy temporaries. */ + #if defined SLJIT_DEBUG && SLJIT_DEBUG +@@ -472,6 +472,8 @@ typedef struct compiler_common { + BOOL local_quit_available; + /* Currently in a positive assertion. */ + BOOL in_positive_assertion; ++ /* More than STACK_GROWTH_RATE / 2 stack memory is allocated. */ ++ BOOL large_stack_allocation; + /* Newline control. */ + int nltype; + sljit_u32 nlmax; +@@ -3523,6 +3525,8 @@ static SLJIT_INLINE void allocate_stack(compiler_common *common, sljit_s32 size) + DEFINE_COMPILER; + + SLJIT_ASSERT(size > 0); ++if (size > (STACK_GROWTH_RATE / (SSIZE_OF(sw) * 2))) ++ common->large_stack_allocation = TRUE; + OP2(SLJIT_SUB, STACK_TOP, 0, STACK_TOP, 0, SLJIT_IMM, size * SSIZE_OF(sw)); + #ifdef DESTROY_REGISTERS + OP1(SLJIT_MOV, TMP1, 0, SLJIT_IMM, 12345); +@@ -13974,7 +13978,20 @@ SLJIT_ASSERT(TMP1 == SLJIT_R0 && STR_PTR == SLJIT_R1); + + OP1(SLJIT_MOV, SLJIT_MEM1(SLJIT_SP), LOCAL1, STR_PTR, 0); + OP1(SLJIT_MOV, SLJIT_R0, 0, ARGUMENTS, 0); +-OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE); ++if (common->large_stack_allocation) ++ { ++ SLJIT_COMPILE_ASSERT((STACK_GROWTH_RATE & (STACK_GROWTH_RATE - 1)) == 0, stack_growth_must_be_power_of_2); ++ // Negative difference. The positive difference would also use the same amount ++ // of operations, but the last subtraction emits several instructions on x86. ++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_TOP, 0, STACK_LIMIT, 0); ++ // Minimum extra space after allocation. ++ OP2(SLJIT_SUB, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, (STACK_GROWTH_RATE / 2)); ++ // Rounds down negative numbers. ++ OP2(SLJIT_AND, SLJIT_R1, 0, SLJIT_R1, 0, SLJIT_IMM, ~(STACK_GROWTH_RATE - 1)); ++ OP2(SLJIT_ADD, SLJIT_R1, 0, SLJIT_R1, 0, STACK_LIMIT, 0); ++ } ++else ++ OP2(SLJIT_SUB, SLJIT_R1, 0, STACK_LIMIT, 0, SLJIT_IMM, STACK_GROWTH_RATE); + OP1(SLJIT_MOV, SLJIT_R0, 0, SLJIT_MEM1(SLJIT_R0), SLJIT_OFFSETOF(jit_arguments, stack)); + OP1(SLJIT_MOV, STACK_LIMIT, 0, TMP2, 0); + +diff --git a/testdata/testinput17 b/testdata/testinput17 +index a02e6be2..486998b4 100644 +--- a/testdata/testinput17 ++++ b/testdata/testinput17 +@@ -188,6 +188,11 @@ + /(?(R)a*(?1)|((?R))b)/ + \= Expect JIT stack limit reached + aaaabcde ++ ++# A single large stack allocation must grow beyond the current stack top. ++ ++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit ++ AAAAAA\=jitstack=192 + + # Invalid options disable JIT when called via pcre2_match(), causing the + # match to happen via the interpreter, but for fast JIT invalid options are +diff --git a/testdata/testoutput17 b/testdata/testoutput17 +index c678587f..b6e7e1a6 100644 +--- a/testdata/testoutput17 ++++ b/testdata/testoutput17 +@@ -350,6 +350,12 @@ Failed: error -46: JIT stack limit reached + \= Expect JIT stack limit reached + aaaabcde + Failed: error -46: JIT stack limit reached ++ ++# A single large stack allocation must grow beyond the current stack top. ++ ++/((?(DEFINE)\[()\g{-1}]{1400}).{1}(?R)|)/expand,jit ++ AAAAAA\=jitstack=192 ++Failed: error -46: JIT stack limit reached + + # Invalid options disable JIT when called via pcre2_match(), causing the + # match to happen via the interpreter, but for fast JIT invalid options are diff --git a/meta/recipes-support/libpcre/libpcre2_10.47.bb b/meta/recipes-support/libpcre/libpcre2_10.47.bb index 60ba56014bf..4884ffb0928 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.47.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.47.bb @@ -21,6 +21,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ file://CVE-2026-89160.patch \ file://CVE-2026-89158.patch \ file://CVE-2026-86145.patch \ + file://CVE-2026-103111.patch \ " GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"