All of lore.kernel.org
 help / color / mirror / Atom feed
From: ankur.tyagi85@gmail.com
To: openembedded-devel@lists.openembedded.org
Cc: Ankur Tyagi <ankur.tyagi85@gmail.com>
Subject: [oe][meta-networking][wrynose][PATCH 32/33] wolfssl: patch CVE-2026-6731
Date: Mon,  7 Sep 2026 22:23:16 +1200	[thread overview]
Message-ID: <20260907102318.2459883-32-ankur.tyagi85@gmail.com> (raw)
In-Reply-To: <20260907102318.2459883-1-ankur.tyagi85@gmail.com>

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-6731

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../wolfssl/files/CVE-2026-6731-1.patch       |  39 ++++
 .../wolfssl/files/CVE-2026-6731-2.patch       | 171 ++++++++++++++++++
 .../wolfssl/wolfssl_5.9.1.bb                  |   2 +
 3 files changed, 212 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-1.patch
 create mode 100644 meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-2.patch

diff --git a/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-1.patch b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-1.patch
new file mode 100644
index 0000000000..c6a1762b27
--- /dev/null
+++ b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-1.patch
@@ -0,0 +1,39 @@
+From df2df57a027066708b498f41ce0b591704b579cc Mon Sep 17 00:00:00 2001
+From: Ruby Martin <ruby@wolfssl.com>
+Date: Tue, 14 Apr 2026 12:39:34 -0600
+Subject: [PATCH] Apply DNS constraints to subject CN when SAN is not
+ available.
+
+(cherry picked from commit e7b7fddacb4cc794e5dfc7693586d87a539f5aad)
+
+CVE: CVE-2026-6731
+Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/e7b7fddacb4cc794e5dfc7693586d87a539f5aad]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wolfcrypt/src/asn.c | 11 +++++++++--
+ 1 file changed, 9 insertions(+), 2 deletions(-)
+
+diff --git a/wolfcrypt/src/asn.c b/wolfcrypt/src/asn.c
+index f8db5c457..d12a78850 100644
+--- a/wolfcrypt/src/asn.c
++++ b/wolfcrypt/src/asn.c
+@@ -17665,9 +17665,16 @@ static int ConfirmNameConstraints(Signer* signer, DecodedCert* cert)
+         XMEMSET(&subjectDnsName, 0, sizeof(DNS_entry));
+         switch (nameType) {
+             case ASN_DNS_TYPE:
+-                /* Should it also consider CN in subject? It could use
+-                 * subjectDnsName too */
+                 name = cert->altNames;
++
++                /* When no SAN is present, apply DNS name constraints to the
++                 * Subject CN. */
++                if (cert->subjectCN != NULL && cert->altNames == NULL) {
++                    subjectDnsName.next = NULL;
++                    subjectDnsName.type = ASN_DNS_TYPE;
++                    subjectDnsName.len  = cert->subjectCNLen;
++                    subjectDnsName.name = cert->subjectCN;
++                }
+                 break;
+             case ASN_IP_TYPE:
+                 /* IP addresses are stored in altNames with type ASN_IP_TYPE */
diff --git a/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-2.patch b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-2.patch
new file mode 100644
index 0000000000..be5132048e
--- /dev/null
+++ b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6731-2.patch
@@ -0,0 +1,171 @@
+From 9d1ee979f67c8e31a04b73fadac61f4697bcb7c6 Mon Sep 17 00:00:00 2001
+From: Ruby Martin <ruby@wolfssl.com>
+Date: Tue, 14 Apr 2026 12:44:21 -0600
+Subject: [PATCH] test DNS name constraints on CA are applied against Subject
+ CN name when SAN name is unavailable
+
+test correct CN with no SAN available is accepted
+
+(cherry picked from commit 797ba3f03b1a8dc05c7b91a86c2e6698d76bfc8a)
+
+CVE: CVE-2026-6731
+Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/797ba3f03b1a8dc05c7b91a86c2e6698d76bfc8a]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ tests/api/test_certman.c | 121 +++++++++++++++++++++++++++++++++++++++
+ tests/api/test_certman.h |   2 +
+ 2 files changed, 123 insertions(+)
+
+diff --git a/tests/api/test_certman.c b/tests/api/test_certman.c
+index 7405f4bff..c76902af2 100644
+--- a/tests/api/test_certman.c
++++ b/tests/api/test_certman.c
+@@ -1584,6 +1584,127 @@ int test_wolfSSL_CertManagerNameConstraint5(void)
+     return EXPECT_RESULT();
+ }
+ 
++int test_wolfSSL_CertManagerNameConstraint_DNS_CN(void)
++{
++    EXPECT_DECLS;
++#if !defined(NO_FILESYSTEM) && !defined(NO_CERTS) && \
++    !defined(NO_WOLFSSL_CM_VERIFY) && !defined(NO_RSA) && \
++    defined(OPENSSL_EXTRA) && defined(WOLFSSL_CERT_GEN) && \
++    defined(WOLFSSL_CERT_EXT) && defined(WOLFSSL_ALT_NAMES) && \
++    !defined(NO_SHA256)
++    /* Test that DNS name constraints are enforced against the Subject CN
++     * when no SAN extension is present. The CA cert (cert-ext-ncdns.der)
++     * permits only DNS:wolfssl.com and DNS:example.com. A leaf cert with
++     * CN=evil.attacker.com and no SAN should be REJECTED. */
++    WOLFSSL_CERT_MANAGER* cm = NULL;
++    WOLFSSL_EVP_PKEY *priv = NULL;
++    WOLFSSL_X509_NAME* name = NULL;
++    const char* ca_cert = "./certs/test/cert-ext-ncdns.der";
++    const char* server_cert = "./certs/test/server-goodcn.pem";
++
++    byte    *der = NULL;
++    int     derSz;
++    byte    *pt;
++    WOLFSSL_X509 *x509 = NULL;
++    WOLFSSL_X509 *ca = NULL;
++
++    pt = (byte*)server_key_der_2048;
++    ExpectNotNull(priv = wolfSSL_d2i_PrivateKey(EVP_PKEY_RSA, NULL,
++                (const unsigned char**)&pt, sizeof_server_key_der_2048));
++
++    ExpectNotNull(cm = wolfSSL_CertManagerNew());
++    ExpectNotNull(ca = wolfSSL_X509_load_certificate_file(ca_cert,
++                WOLFSSL_FILETYPE_ASN1));
++    ExpectNotNull((der = (byte*)wolfSSL_X509_get_der(ca, &derSz)));
++    ExpectIntEQ(wolfSSL_CertManagerLoadCABuffer(cm, der, derSz,
++                WOLFSSL_FILETYPE_ASN1), WOLFSSL_SUCCESS);
++
++    /* Sanity check: cert with SAN=evil.attacker.com is correctly rejected */
++    ExpectNotNull(x509 = wolfSSL_X509_load_certificate_file(server_cert,
++                WOLFSSL_FILETYPE_PEM));
++    ExpectNotNull(name = wolfSSL_X509_get_subject_name(ca));
++    ExpectIntEQ(wolfSSL_X509_set_issuer_name(x509, name), WOLFSSL_SUCCESS);
++    name = NULL;
++
++    ExpectNotNull(name = X509_NAME_new());
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "countryName", MBSTRING_UTF8,
++                                       (byte*)"US", 2, -1, 0), SSL_SUCCESS);
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "commonName", MBSTRING_UTF8,
++                             (byte*)"evil.attacker.com", 17, -1, 0),
++                SSL_SUCCESS);
++    ExpectIntEQ(wolfSSL_X509_set_subject_name(x509, name), WOLFSSL_SUCCESS);
++    X509_NAME_free(name);
++    name = NULL;
++
++    ExpectIntEQ(wolfSSL_X509_add_altname(x509, "evil.attacker.com",
++                                         ASN_DNS_TYPE), WOLFSSL_SUCCESS);
++    ExpectIntGT(wolfSSL_X509_sign(x509, priv, EVP_sha256()), 0);
++    ExpectNotNull((der = (byte*)wolfSSL_X509_get_der(x509, &derSz)));
++    ExpectIntEQ(wolfSSL_CertManagerVerifyBuffer(cm, der, derSz,
++                WOLFSSL_FILETYPE_ASN1), WC_NO_ERR_TRACE(ASN_NAME_INVALID_E));
++    wolfSSL_X509_free(x509);
++    x509 = NULL;
++
++    /* NOW the actual vulnerability test: cert with CN=evil.attacker.com
++     * but NO SAN. The DNS name constraint should still reject this, since
++     * wolfSSL's hostname verification falls back to CN when no SAN exists. */
++    ExpectNotNull(x509 = wolfSSL_X509_load_certificate_file(server_cert,
++                WOLFSSL_FILETYPE_PEM));
++    ExpectNotNull(name = wolfSSL_X509_get_subject_name(ca));
++    ExpectIntEQ(wolfSSL_X509_set_issuer_name(x509, name), WOLFSSL_SUCCESS);
++    name = NULL;
++
++    ExpectNotNull(name = X509_NAME_new());
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "countryName", MBSTRING_UTF8,
++                                       (byte*)"US", 2, -1, 0), SSL_SUCCESS);
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "commonName", MBSTRING_UTF8,
++                             (byte*)"evil.attacker.com", 17, -1, 0),
++                SSL_SUCCESS);
++    ExpectIntEQ(wolfSSL_X509_set_subject_name(x509, name), WOLFSSL_SUCCESS);
++    X509_NAME_free(name);
++    name = NULL;
++
++    /* Do NOT add any SAN this is the bypass vector */
++    ExpectIntGT(wolfSSL_X509_sign(x509, priv, EVP_sha256()), 0);
++    ExpectNotNull((der = (byte*)wolfSSL_X509_get_der(x509, &derSz)));
++    /* Should be ASN_NAME_INVALID_E because CN violates the constraint */
++    ExpectIntEQ(wolfSSL_CertManagerVerifyBuffer(cm, der, derSz,
++                WOLFSSL_FILETYPE_ASN1), WC_NO_ERR_TRACE(ASN_NAME_INVALID_E));
++    wolfSSL_X509_free(x509);
++    x509 = NULL;
++
++    /* Positive test: CN matches a permitted name (wolfssl.com) and no SAN is
++     * present. The CN fallback should accept this cert. */
++    ExpectNotNull(x509 = wolfSSL_X509_load_certificate_file(server_cert,
++                WOLFSSL_FILETYPE_PEM));
++    ExpectNotNull(name = wolfSSL_X509_get_subject_name(ca));
++    ExpectIntEQ(wolfSSL_X509_set_issuer_name(x509, name), WOLFSSL_SUCCESS);
++    name = NULL;
++
++    ExpectNotNull(name = X509_NAME_new());
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "countryName", MBSTRING_UTF8,
++                                       (byte*)"US", 2, -1, 0), SSL_SUCCESS);
++    ExpectIntEQ(X509_NAME_add_entry_by_txt(name, "commonName", MBSTRING_UTF8,
++                             (byte*)"wolfssl.com", 11, -1, 0),
++                SSL_SUCCESS);
++    ExpectIntEQ(wolfSSL_X509_set_subject_name(x509, name), WOLFSSL_SUCCESS);
++    X509_NAME_free(name);
++    name = NULL;
++
++    /* No SAN added; CN=wolfssl.com matches the permitted DNS constraint. */
++    ExpectIntGT(wolfSSL_X509_sign(x509, priv, EVP_sha256()), 0);
++    ExpectNotNull((der = (byte*)wolfSSL_X509_get_der(x509, &derSz)));
++    ExpectIntEQ(wolfSSL_CertManagerVerifyBuffer(cm, der, derSz,
++                WOLFSSL_FILETYPE_ASN1), WOLFSSL_SUCCESS);
++
++    wolfSSL_CertManagerFree(cm);
++    wolfSSL_X509_free(x509);
++    wolfSSL_X509_free(ca);
++    wolfSSL_EVP_PKEY_free(priv);
++#endif
++    return EXPECT_RESULT();
++}
++
+ int test_wolfSSL_CertManagerCRL(void)
+ {
+     EXPECT_DECLS;
+diff --git a/tests/api/test_certman.h b/tests/api/test_certman.h
+index 3b6afd0fc..60047cfa3 100644
+--- a/tests/api/test_certman.h
++++ b/tests/api/test_certman.h
+@@ -35,6 +35,7 @@ int test_wolfSSL_CertManagerNameConstraint2(void);
+ int test_wolfSSL_CertManagerNameConstraint3(void);
+ int test_wolfSSL_CertManagerNameConstraint4(void);
+ int test_wolfSSL_CertManagerNameConstraint5(void);
++int test_wolfSSL_CertManagerNameConstraint_DNS_CN(void);
+ int test_wolfSSL_CertManagerCRL(void);
+ int test_wolfSSL_CRL_reason_extensions_cleanup(void);
+ int test_wolfSSL_CRL_static_revoked_list(void);
+@@ -57,6 +58,7 @@ int test_wolfSSL_CertManagerRejectMD5Cert(void);
+     TEST_DECL_GROUP("certman", test_wolfSSL_CertManagerNameConstraint3),    \
+     TEST_DECL_GROUP("certman", test_wolfSSL_CertManagerNameConstraint4),    \
+     TEST_DECL_GROUP("certman", test_wolfSSL_CertManagerNameConstraint5),    \
++    TEST_DECL_GROUP("certman", test_wolfSSL_CertManagerNameConstraint_DNS_CN), \
+     TEST_DECL_GROUP("certman", test_wolfSSL_CertManagerCRL),                \
+     TEST_DECL_GROUP("certman", test_wolfSSL_CRL_reason_extensions_cleanup), \
+     TEST_DECL_GROUP("certman", test_wolfSSL_CRL_static_revoked_list),      \
diff --git a/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb b/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
index 26b86c1b2b..ef03d0c9ff 100644
--- a/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
+++ b/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
@@ -34,6 +34,8 @@ SRC_URI = " \
     file://CVE-2026-6412-2.patch \
     file://CVE-2026-6450-1.patch \
     file://CVE-2026-6450-2.patch \
+    file://CVE-2026-6731-1.patch \
+    file://CVE-2026-6731-2.patch \
 "
 
 SRCREV = "1d363f3adceba9d1478230ede476a37b0dcdef24"


  parent reply	other threads:[~2026-09-07 10:25 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07 10:22 [oe][meta-oe][wrynose][PATCH 1/33] libnfs: patch CVE-2026-53689 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 2/33] libnfs: patch CVE-2026-57918 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 3/33] libssh: ignore CVE-2025-14821 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 4/33] libssh: mark CVEs patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 5/33] libssh: ignore CVE-2025-59842 ankur.tyagi85
2026-09-15  1:29   ` Anuj Mittal
2026-09-15  1:54     ` Ankur Tyagi
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 6/33] miniupnpd: patch CVE-2026-5720 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 7/33] python3-zeroconf: patch CVE-2026-47180 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 8/33] python3-zeroconf: patch CVE-2026-47183 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 9/33] python3-zeroconf: patch CVE-2026-47184 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 10/33] valkey: mark CVE-2026-56684 and CVE-2026-63639 patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 11/33] libyang: patch CVE-2026-41401 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 12/33] tinyproxy: patch CVE-2026-31842 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 13/33] tinyproxy: patch CVE-2026-54387 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 14/33] tinyproxy: patch CVE-2026-55202 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-webserver][wrynose][PATCH 15/33] nginx: mark CVE-2026-1642 patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 16/33] open62541: patch CVE-2026-11946 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 17/33] smarty: mark CVEs patched ankur.tyagi85
2026-09-15  1:28   ` Anuj Mittal
2026-09-15  1:53     ` Ankur Tyagi
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 18/33] tesseract: patch CVE-2026-73066 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 19/33] tesseract: patch CVE-2026-73067 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 20/33] wolfssl: mark CVEs patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 21/33] wolfssl: patch CVE-2026-10098 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 22/33] wolfssl: patch CVE-2026-10512 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 23/33] wolfssl: ignore CVE-2026-12340 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 24/33] wolfssl: patch CVE-2026-55958 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 25/33] wolfssl: patch CVE-2026-6091 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 26/33] wolfssl: patch CVE-2026-6092 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 27/33] wolfssl: patch CVE-2026-6094 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 28/33] wolfssl: patch CVE-2026-6291 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 29/33] wolfssl: patch CVE-2026-6325 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 30/33] wolfssl: patch CVE-2026-6412 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 31/33] wolfssl: patch CVE-2026-6450 ankur.tyagi85
2026-09-07 10:23 ` ankur.tyagi85 [this message]
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 33/33] wolfssl: patch CVE-2026-7531 ankur.tyagi85

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260907102318.2459883-32-ankur.tyagi85@gmail.com \
    --to=ankur.tyagi85@gmail.com \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.