All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Subject: [wrynose][PATCH v2 3/7] libpcap: Fix CVE-2026-31911
Date: Tue, 15 Sep 2026 21:16:19 +0200	[thread overview]
Message-ID: <20260915191623.42107-4-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech>

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
 .../libpcap/libpcap/03-CVE-2026-31911.patch   | 45 +++++++++++++++++++
 .../libpcap/libpcap_1.10.6.bb                 |  1 +
 2 files changed, 46 insertions(+)
 create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch

diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch
new file mode 100644
index 0000000000..1060b3c372
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch
@@ -0,0 +1,45 @@
+From 0067e8fd1f3caf866da3d95508831389f3b20e11 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Thu, 30 Jul 2026 13:34:08 +0100
+Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
+
+This vulnerability has been discovered by FuzzAnything Organization.
+
+The current revision of pcapint_filter_with_aux_data() calls abort() if
+the current instruction opcode is invalid, and assumes this never to be
+the case.  This holds for programs that have been generated by libpcap.
+
+However, this does not necessarily hold for programs that come from an
+external source via pcap_offline_filter() or [deprecated] bpf_filter().
+Furthermore, this does not necessarily hold for programs that have been
+validated by libpcap because the current revision of the validator has
+gaps in the checks and accepts a number of invalid opcodes (another
+commit addresses that).
+
+Thus in pcapint_filter_with_aux_data(), when the instruction opcode is
+invalid, just reject the packet.
+
+(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7)
+
+(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9)
+
+Notes on backporting to 1.10.6:
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9]
+CVE: CVE-2026-31911
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/bpf_filter.c b/bpf_filter.c
+index 4f9adeea..f8b842d6 100644
+--- a/bpf_filter.c
++++ b/bpf_filter.c
+@@ -152,7 +152,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen,
+ 		switch (pc->code) {
+ 
+ 		default:
+-			abort();
++			return 0;
+ 		case BPF_RET|BPF_K:
+ 			return (u_int)pc->k;
+ 
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index aa5265a54c..da218bd87b 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -14,6 +14,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
 	   file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \
 	   file://01-CVE-2026-0799.patch \
 	   file://02-CVE-2026-31912.patch \
+	   file://03-CVE-2026-31911.patch \
           "
 SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
 


  parent reply	other threads:[~2026-09-15 19:16 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10  5:11 [wrynose][PATCH 0/7] libpcap: backport seven CVE fixes from 1.10.7 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 1/7] libpcap: Fix CVE-2026-0799 Jaipaul Cheernam
2026-09-15 12:42   ` [OE-core] " Yoann Congal
2026-09-15 19:16   ` [wrynose][PATCH v2 0/7] libpcap: backport seven CVE fixes from 1.10.7 Jaipaul Cheernam
2026-09-15 19:16     ` [wrynose][PATCH v2 1/7] libpcap: Fix CVE-2026-0799 Jaipaul Cheernam
2026-09-15 19:16     ` [wrynose][PATCH v2 2/7] libpcap: Fix CVE-2026-31912 Jaipaul Cheernam
2026-09-15 19:16     ` Jaipaul Cheernam [this message]
2026-09-15 19:16     ` [wrynose][PATCH v2 4/7] libpcap: Fix CVE-2026-6244 Jaipaul Cheernam
2026-09-15 19:16     ` [wrynose][PATCH v2 5/7] libpcap: Fix CVE-2026-6554 Jaipaul Cheernam
2026-09-15 19:16     ` [wrynose][PATCH v2 6/7] libpcap: Fix CVE-2026-18313 Jaipaul Cheernam
2026-09-17 12:47       ` [OE-core] " Yoann Congal
2026-09-17 15:23         ` Jaipaul Cheernam
2026-09-17 15:34           ` Yoann Congal
2026-09-17 16:41             ` Jaipaul Cheernam
2026-09-15 19:16     ` [wrynose][PATCH v2 7/7] libpcap: Fix CVE-2026-18238 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 2/7] libpcap: Fix CVE-2026-31912 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 3/7] libpcap: Fix CVE-2026-31911 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 4/7] libpcap: Fix CVE-2026-6244 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 5/7] libpcap: Fix CVE-2026-6554 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 6/7] libpcap: Fix CVE-2026-18313 Jaipaul Cheernam
2026-09-10  5:11 ` [wrynose][PATCH 7/7] libpcap: Fix CVE-2026-18238 Jaipaul Cheernam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915191623.42107-4-jaipaul.cheernam@est.tech \
    --to=jaipaul.cheernam@est.tech \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.