From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Subject: [wrynose][PATCH v2 6/7] libpcap: Fix CVE-2026-18313
Date: Tue, 15 Sep 2026 21:16:22 +0200 [thread overview]
Message-ID: <20260915191623.42107-7-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20260915191623.42107-1-jaipaul.cheernam@est.tech>
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313
Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
.../libpcap/libpcap/06-CVE-2026-18313.patch | 90 +++++++++++++++++++
.../libpcap/libpcap_1.10.6.bb | 1 +
2 files changed, 91 insertions(+)
create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
new file mode 100644
index 0000000000..eae9aaa989
--- /dev/null
+++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch
@@ -0,0 +1,90 @@
+From b039b8b66616852673c21ec5c7e0bad3190eae59 Mon Sep 17 00:00:00 2001
+From: Denis Ovsienko <denis@ovsienko.info>
+Date: Sat, 1 Aug 2026 18:24:48 +0100
+Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd.
+
+This vulnerability was originally reported publicly, hence no credit is
+given.
+
+daemon_unpackapplyfilter() can allocate a temporary buffer for up to
+RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each
+received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message.
+It never frees the memory, so repeated messages from a client will
+eventually leak enough memory on the server to cause problems. This
+holds for all connections that pass the validation and some connections
+that do not.
+
+48 bytes in 1 blocks are definitely lost in loss record 2 of 2
+ at 0x4844818: malloc (vg_replace_malloc.c:446)
+ by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372)
+ by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139)
+ by 0x114808: daemon_serviceloop (daemon.c:901)
+ by 0x115BC7: accept_connection (rpcapd.c:1321)
+ by 0x115BC7: accept_connections (rpcapd.c:1118)
+ by 0x115BC7: main_startup (rpcapd.c:709)
+ by 0x1112BD: main (rpcapd.c:567)
+
+To fix this, after a successful malloc() return exactly once, after the
+free() call.
+
+(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b)
+
+(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7)
+
+Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7]
+CVE: CVE-2026-18313
+
+Notes on backporting to 1.10.6:
+ - The upstream commit was made after the "bogus instructions" -> "invalid
+ instructions" message change (commit 836d0fd0), which is not backported.
+ The 1.10.6 wording ("The filter contains bogus instructions") is therefore
+ kept; only the memory-leak fix (goto free_and_return_status / free()) is
+ applied.
+ - The upstream CHANGES/changelog hunk is not backported.
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c
+index 87274665..b720cc45 100644
+--- a/rpcapd/daemon.c
++++ b/rpcapd/daemon.c
+@@ -2380,14 +2380,8 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se
+ {
+ status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn,
+ sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf);
+- if (status == -1)
+- {
+- return -1;
+- }
+- if (status == -2)
+- {
+- return -2;
+- }
++ if (status == -1 || status == -2)
++ goto free_and_return_status;
+
+ bf_insn->code = ntohs(insn.code);
+ bf_insn->jf = insn.jf;
+@@ -2403,16 +2397,19 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se
+ if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0)
+ {
+ snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions");
+- return -2;
++ status = -2;
++ goto free_and_return_status;
+ }
+
+ if (pcap_setfilter(session->fp, &bf_prog))
+ {
+ snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp));
+- return -2;
++ status = -2;
+ }
+
+- return 0;
++free_and_return_status:
++ free(bf_prog.bf_insns);
++ return status;
+ }
+
+ static int
diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
index 6ca75117e1..859897acc5 100644
--- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
+++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb
@@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \
file://03-CVE-2026-31911.patch \
file://04-CVE-2026-6244.patch \
file://05-CVE-2026-6554.patch \
+ file://06-CVE-2026-18313.patch \
"
SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc"
next prev parent reply other threads:[~2026-09-15 19:16 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 5:11 [wrynose][PATCH 0/7] libpcap: backport seven CVE fixes from 1.10.7 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 1/7] libpcap: Fix CVE-2026-0799 Jaipaul Cheernam
2026-09-15 12:42 ` [OE-core] " Yoann Congal
2026-09-15 19:16 ` [wrynose][PATCH v2 0/7] libpcap: backport seven CVE fixes from 1.10.7 Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 1/7] libpcap: Fix CVE-2026-0799 Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 2/7] libpcap: Fix CVE-2026-31912 Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 3/7] libpcap: Fix CVE-2026-31911 Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 4/7] libpcap: Fix CVE-2026-6244 Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 5/7] libpcap: Fix CVE-2026-6554 Jaipaul Cheernam
2026-09-15 19:16 ` Jaipaul Cheernam [this message]
2026-09-17 12:47 ` [OE-core] [wrynose][PATCH v2 6/7] libpcap: Fix CVE-2026-18313 Yoann Congal
2026-09-17 15:23 ` Jaipaul Cheernam
2026-09-17 15:34 ` Yoann Congal
2026-09-17 16:41 ` Jaipaul Cheernam
2026-09-15 19:16 ` [wrynose][PATCH v2 7/7] libpcap: Fix CVE-2026-18238 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 2/7] libpcap: Fix CVE-2026-31912 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 3/7] libpcap: Fix CVE-2026-31911 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 4/7] libpcap: Fix CVE-2026-6244 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 5/7] libpcap: Fix CVE-2026-6554 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 6/7] libpcap: Fix CVE-2026-18313 Jaipaul Cheernam
2026-09-10 5:11 ` [wrynose][PATCH 7/7] libpcap: Fix CVE-2026-18238 Jaipaul Cheernam
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915191623.42107-7-jaipaul.cheernam@est.tech \
--to=jaipaul.cheernam@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.