From: ankur.tyagi85@gmail.com
To: openembedded-devel@lists.openembedded.org
Cc: Ankur Tyagi <ankur.tyagi85@gmail.com>
Subject: [oe][meta-networking][wrynose][PATCH 14/33] tinyproxy: patch CVE-2026-55202
Date: Mon, 7 Sep 2026 22:22:58 +1200 [thread overview]
Message-ID: <20260907102318.2459883-14-ankur.tyagi85@gmail.com> (raw)
In-Reply-To: <20260907102318.2459883-1-ankur.tyagi85@gmail.com>
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-55202
[1]https://security-tracker.debian.org/tracker/CVE-2026-55202
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../tinyproxy/tinyproxy/CVE-2026-55202.patch | 107 ++++++++++++++++++
.../tinyproxy/tinyproxy_1.11.3.bb | 1 +
2 files changed, 108 insertions(+)
create mode 100644 meta-networking/recipes-support/tinyproxy/tinyproxy/CVE-2026-55202.patch
diff --git a/meta-networking/recipes-support/tinyproxy/tinyproxy/CVE-2026-55202.patch b/meta-networking/recipes-support/tinyproxy/tinyproxy/CVE-2026-55202.patch
new file mode 100644
index 0000000000..4e446542e2
--- /dev/null
+++ b/meta-networking/recipes-support/tinyproxy/tinyproxy/CVE-2026-55202.patch
@@ -0,0 +1,107 @@
+From 04b34f814076d790db26925d7df7c30798910c99 Mon Sep 17 00:00:00 2001
+From: rofl0r <rofl0r@users.noreply.github.com>
+Date: Sat, 18 Apr 2026 00:03:15 +0200
+Subject: [PATCH] reqs: improve stathost detection (#606)
+
+until now, only the basicauth code checked the host header, regular connections didn't.
+
+- add a new helper function to compare a hostname with optional
+ trailingcolon/port against the stathost.
+- add stathost check via host header before transparent proxy check,
+ else stathost might be misdetected as a trans host request.
+- refactor existing stathost checks to use the new helper
+
+this should make it easier to access the stathost, for example by
+injecting a host header into a curl command line with -H:
+
+ $ curl -H "Host: tinyproxy.stats" 127.0.0.1:8080
+
+the stathost can also be specified as an ip address, e.g.
+Stathost "127.0.0.10" + a separate Listen statement for that ip.
+in such a case e.g.
+
+ $ curl http://127.0.0.10:8080
+
+would work too, even if curl didn't add a Host header (but it does anyway).
+
+(cherry picked from commit 09312a185ae25cc486b4ff5987638a7917a48bce)
+
+CVE: CVE-2026-55202
+Upstream-Status: Backport [https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/reqs.c | 37 +++++++++++++++++++++++++------------
+ 1 file changed, 25 insertions(+), 12 deletions(-)
+
+diff --git a/src/reqs.c b/src/reqs.c
+index e3cfe76..d5037cf 100644
+--- a/src/reqs.c
++++ b/src/reqs.c
+@@ -316,6 +316,17 @@ static int send_connect_method_response (struct conn_s *connptr)
+ connptr->protocol.minor);
+ }
+
++/* determine whether a hostname with optional trailing colon/port is the
++ stathost */
++static int is_stathost (const char* host)
++{
++ const char *p = config->stathost;
++ const char *q = host;
++ if (!p || !q) return 0;
++ while (*p && *(p++) == *(q++));
++ return *p == 0 && (*q == 0 || *q == ':');
++}
++
+ /*
+ * Break the request line apart and figure out where to connect and
+ * build a new request line. Finally connect to the remote server.
+@@ -384,6 +395,16 @@ BAD_REQUEST_ERROR:
+ goto fail;
+ }
+
++ /*
++ * Check to see if they're requesting the stat host
++ */
++ if (is_stathost (pseudomap_find (hashofheaders, "host"))) {
++got_stathost:
++ log_message (LOG_NOTICE, "Request for the stathost.");
++ connptr->show_stats = TRUE;
++ goto fail;
++ }
++
+ #ifdef REVERSE_SUPPORT
+ if (config->reversepath_list != NULL) {
+ /*
+@@ -497,19 +518,11 @@ BAD_REQUEST_ERROR:
+ }
+ }
+ #endif
+-
+-
+- /*
+- * Check to see if they're requesting the stat host
+- */
+- if (config->stathost && strcmp (config->stathost, request->host) == 0) {
+- log_message (LOG_NOTICE, "Request for the stathost.");
+- connptr->show_stats = TRUE;
+- goto fail;
+- }
++ /* check whether hostname from url is the stathost */
++ if (is_stathost (request->host))
++ goto got_stathost;
+
+ safefree (url);
+-
+ return request;
+
+ fail:
+@@ -1688,7 +1701,7 @@ void handle_connection (struct conn_s *connptr, union sockaddr_union* addr)
+
+ if (!authstring && config->stathost) {
+ authstring = pseudomap_find (hashofheaders, "host");
+- if (authstring && !strncmp(authstring, config->stathost, strlen(config->stathost))) {
++ if (authstring && is_stathost(authstring)) {
+ authstring = pseudomap_find (hashofheaders, "authorization");
+ stathost_connect = 1;
+ } else authstring = 0;
diff --git a/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.3.bb b/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.3.bb
index b8a508d8d4..f9d425b45a 100644
--- a/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.3.bb
+++ b/meta-networking/recipes-support/tinyproxy/tinyproxy_1.11.3.bb
@@ -11,6 +11,7 @@ SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/${PV}/${BP}.tar.gz
file://CVE-2026-3945-2.patch \
file://CVE-2026-31842.patch \
file://CVE-2026-54387.patch \
+ file://CVE-2026-55202.patch \
"
SRC_URI[sha256sum] = "9bcf46db1a2375ff3e3d27a41982f1efec4706cce8899ff9f33323a8218f7592"
next prev parent reply other threads:[~2026-09-07 10:24 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 10:22 [oe][meta-oe][wrynose][PATCH 1/33] libnfs: patch CVE-2026-53689 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 2/33] libnfs: patch CVE-2026-57918 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 3/33] libssh: ignore CVE-2025-14821 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 4/33] libssh: mark CVEs patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 5/33] libssh: ignore CVE-2025-59842 ankur.tyagi85
2026-09-15 1:29 ` Anuj Mittal
2026-09-15 1:54 ` Ankur Tyagi
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 6/33] miniupnpd: patch CVE-2026-5720 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 7/33] python3-zeroconf: patch CVE-2026-47180 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 8/33] python3-zeroconf: patch CVE-2026-47183 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 9/33] python3-zeroconf: patch CVE-2026-47184 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 10/33] valkey: mark CVE-2026-56684 and CVE-2026-63639 patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 11/33] libyang: patch CVE-2026-41401 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 12/33] tinyproxy: patch CVE-2026-31842 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 13/33] tinyproxy: patch CVE-2026-54387 ankur.tyagi85
2026-09-07 10:22 ` ankur.tyagi85 [this message]
2026-09-07 10:22 ` [oe][meta-webserver][wrynose][PATCH 15/33] nginx: mark CVE-2026-1642 patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 16/33] open62541: patch CVE-2026-11946 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 17/33] smarty: mark CVEs patched ankur.tyagi85
2026-09-15 1:28 ` Anuj Mittal
2026-09-15 1:53 ` Ankur Tyagi
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 18/33] tesseract: patch CVE-2026-73066 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 19/33] tesseract: patch CVE-2026-73067 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 20/33] wolfssl: mark CVEs patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 21/33] wolfssl: patch CVE-2026-10098 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 22/33] wolfssl: patch CVE-2026-10512 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 23/33] wolfssl: ignore CVE-2026-12340 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 24/33] wolfssl: patch CVE-2026-55958 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 25/33] wolfssl: patch CVE-2026-6091 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 26/33] wolfssl: patch CVE-2026-6092 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 27/33] wolfssl: patch CVE-2026-6094 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 28/33] wolfssl: patch CVE-2026-6291 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 29/33] wolfssl: patch CVE-2026-6325 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 30/33] wolfssl: patch CVE-2026-6412 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 31/33] wolfssl: patch CVE-2026-6450 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 32/33] wolfssl: patch CVE-2026-6731 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 33/33] wolfssl: patch CVE-2026-7531 ankur.tyagi85
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907102318.2459883-14-ankur.tyagi85@gmail.com \
--to=ankur.tyagi85@gmail.com \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.