All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Subject: [wrynose][PATCH 4/7] libpcap: Fix CVE-2026-6244
Date: Thu, 10 Sep 2026 07:11:51 +0200	[thread overview]
Message-ID: <20260910051154.30595-5-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260910051154.30595-1-jaipaul.cheernam@est.tech>

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
 .../libpcap/libpcap/04-CVE-2026-6244.patch    | 62 +++++++++++++++++++
 .../libpcap/libpcap_1.10.6.bb                 |  1 +
 2 files changed, 63 insertions(+)
 create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch

diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch
new file mode 100644
index 0000000000..0ef98e4580
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch
@@ -0,0 +1,62 @@
+From e2f4d78f71237c44f730fee11fa0497b756e9d81 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:34:21 +0100
+Subject: [PATCH] CVE-2026-6244: Avoid division by zero via
+ pcap_offline_filter().
+
+The current revision of pcapint_filter_with_aux_data() for "div x" and
+"mod x" correctly rejects the packet if X is zero, but for "div #k" and
+"mod #k" it assumes that k is never zero.  This holds for programs that
+have been generated or validated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter()
+and have not been explicitly validated.  If the interpreter executes
+such a program, it can attempt a division by zero, which will typically
+terminate the process via SIGFPE.
+
+To fix this problem, in pcapint_filter_with_aux_data() treat "div #k"
+and "mod #k" the same way as "div x" and "mod x".
+
+(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4)
+
+(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19)
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19]
+CVE: CVE-2026-6244
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ CHANGES                  | 1 +
+ bpf_filter.c | 4 ++++
+ 2 files changed, 5 insertions(+)
+diff --git a/CHANGES b/CHANGES
+index f0b5974..35121e7 100644
+--- a/CHANGES
++++ b/CHANGES
+@@ -3,6 +3,7 @@
+     CVE-2026-0799: Access M[] safely in the BPF interpreter.
+     CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
+     CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
++    CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
+ 
+ Tuesday, December 30, 2025 / The Tcpdump Group
+   Summary for 1.10.6 libpcap release
+diff --git a/bpf_filter.c b/bpf_filter.c
+index f8b842d6..0178aae5 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -420,10 +420,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH
+ 			continue;
+ 
+ 		case BPF_ALU|BPF_DIV|BPF_K:
++			if (pc->k == 0)
++				return 0;
+ 			A /= pc->k;
+ 			continue;
+ 
+ 		case BPF_ALU|BPF_MOD|BPF_K:
++			if (pc->k == 0)
++				return 0;
+ 			A %= pc->k;
+ 			continue;
+ 
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index da218bd87b..258a15f5ba 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -15,6 +15,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
 	   file://01-CVE-2026-0799.patch \
 	   file://02-CVE-2026-31912.patch \
 	   file://03-CVE-2026-31911.patch \
+	   file://04-CVE-2026-6244.patch \
           "
 SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
 


  parent reply	other threads:[~2026-09-10  5:12 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10  5:11 [wrynose][PATCH 0/7] libpcap: backport seven CVE fixes from 1.10.7 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 1/7] libpcap: Fix CVE-2026-0799 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 2/7] libpcap: Fix CVE-2026-31912 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 3/7] libpcap: Fix CVE-2026-31911 Jaipaul Cheernam
2026-09-10  5:11 ` Jaipaul Cheernam [this message]
2026-09-10  5:11 ` [wrynose][PATCH 5/7] libpcap: Fix CVE-2026-6554 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 6/7] libpcap: Fix CVE-2026-18313 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 7/7] libpcap: Fix CVE-2026-18238 Jaipaul Cheernam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260910051154.30595-5-jaipaul.cheernam@est.tech \
    --to=jaipaul.cheernam@est.tech \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.