All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
To: openembedded-core@lists.openembedded.org
Subject: [PATCH 4/4] glib-networking: upgrade 2.80.1 -> 2.90.0
Date: Fri,  2 Oct 2026 09:15:57 +0200	[thread overview]
Message-ID: <20261002071557.74249-5-jaipaul.cheernam@est.tech> (raw)
In-Reply-To: <20261002071557.74249-1-jaipaul.cheernam@est.tech>

NEWS: https://gitlab.gnome.org/GNOME/glib-networking/-/blob/2.90.0/NEWS

2.90.0 - September 10, 2026
===========================

* Bugs fixed:
  - !286 meson: Remove version checks that are always true (correctmost)

2.90.alpha - June 25, 2026
==========================

* Bugs fixed:
  - #222 test fails with openssl 3.4.x (Michael Catanzaro)
  - #226 (CVE-2025-60018) (#YWH-PGM9867-106) Out of Bond Reads on glib-
    networking through tls/openssl/gtlscertificate-openssl.c via
    "g_tls_certificate_openssl_get_property()" due to Incorrect BIO_write Return
    Value Validation in Certificate PEM Export (Michael Catanzaro)
  - #228 (CVE-2026-2574) (#YWH-PGM9867-150) OOB Read on glib-networking through
    tls/openssl/gtlsclientconnection-openssl.c via
    g_tls_client_connection_openssl_get_property() (Michael Catanzaro)
  - #231 (CVE-2026-10028) (#YWH-PGM9867-278) Infinite loop in certification path
    building (Michael Catanzaro)
  - !261 meson: Introduce option for enable/disable tests (Leonid Zaburunov)
  - !263 openssl: check return value of g_tls_bio_alloc() and BIO_new() (Michael
    Catanzaro)
  - !265 openssl: delete support for OCSP stapling (Michael Catanzaro)
  - !268 Fix file database and PKCS11 test failures and update CI! (Michael
    Catanzaro)
  - !270 Fix miscellaneous safety issues reported by bug hunters (Michael
    Catanzaro)
  - !271 Delete gtlshttp (Michael Catanzaro)
  - !272 Fix connection test reusing a GError (Michael Catanzaro)
  - !273 openssl: fix error code confusion (Michael Catanzaro)
  - !274 ci: add catch for reporting stack traces (Michael Catanzaro)
  - !277 Require OpenSSL 1.1.1 or newer (Michael Catanzaro)
  - !280 Some fixes found with kiro (Ignacio Casal Quinteiro)
  - !281 Fix various memory leaks (Michael Catanzaro)
  - !283 openssl: refactor error handling code (Michael Catanzaro)
  - !284 openssl: use ERR_clear_error() all over the place (Michael Catanzaro)
  - !285 gnutls: always notify accepted-cas property after handshake (Michael
    Catanzaro)

- Drop the four backported OpenSSL CVE patches (CVE-2025-60018,
CVE-2025-60019, CVE-2026-2574); all are now included upstream in 2.90.0.

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
 ...-check-return-value-when-writing-to-.patch |  82 ----------
 ...heck-return-value-of-g_tls_bio_alloc.patch |  42 -----
 ...enssl-check-return-values-of-BIO_new.patch | 146 ------------------
 ...of-bounds-read-in-accepted-cas-prope.patch |  48 ------
 ...ng_2.80.1.bb => glib-networking_2.90.0.bb} |  10 +-
 5 files changed, 4 insertions(+), 324 deletions(-)
 delete mode 100644 meta/recipes-core/glib-networking/glib-networking/0001-openssl-properly-check-return-value-when-writing-to-.patch
 delete mode 100644 meta/recipes-core/glib-networking/glib-networking/0002-openssl-check-return-value-of-g_tls_bio_alloc.patch
 delete mode 100644 meta/recipes-core/glib-networking/glib-networking/0003-openssl-check-return-values-of-BIO_new.patch
 delete mode 100644 meta/recipes-core/glib-networking/glib-networking/0004-openssl-fix-out-of-bounds-read-in-accepted-cas-prope.patch
 rename meta/recipes-core/glib-networking/{glib-networking_2.80.1.bb => glib-networking_2.90.0.bb} (81%)

diff --git a/meta/recipes-core/glib-networking/glib-networking/0001-openssl-properly-check-return-value-when-writing-to-.patch b/meta/recipes-core/glib-networking/glib-networking/0001-openssl-properly-check-return-value-when-writing-to-.patch
deleted file mode 100644
index 72f0c0c61ef..00000000000
--- a/meta/recipes-core/glib-networking/glib-networking/0001-openssl-properly-check-return-value-when-writing-to-.patch
+++ /dev/null
@@ -1,82 +0,0 @@
-From 330f59dcb39386b3d640ce94fcd3f75e1668ad88 Mon Sep 17 00:00:00 2001
-From: Michael Catanzaro <mcatanzaro@redhat.com>
-Date: Mon, 4 Aug 2025 15:10:21 -0500
-Subject: [PATCH 1/3] openssl: properly check return value when writing to BIO
- objects
-
-In particular, we will read out of bounds, and then write the invalid
-memory, if BIO_write() fails when getting the PROP_CERTIFICATE_PEM
-property. Here we attempt to check the return value, but the check is
-not correct.
-
-This also fixes a leak of the BIO in the same place.
-
-Also add error checking to PROP_SUBJECT_NAME and PROP_ISSUER_NAME, for
-good measure.
-
-Fixes #226
-
-CVE: CVE-2025-60018
-Upstream-Status: Backport
-Signed-off-by: Ross Burton <ross.burton@arm.com>
----
- tls/openssl/gtlscertificate-openssl.c | 25 +++++++++++++++----------
- 1 file changed, 15 insertions(+), 10 deletions(-)
-
-diff --git a/tls/openssl/gtlscertificate-openssl.c b/tls/openssl/gtlscertificate-openssl.c
-index 648f3e8..b536559 100644
---- a/tls/openssl/gtlscertificate-openssl.c
-+++ b/tls/openssl/gtlscertificate-openssl.c
-@@ -362,15 +362,12 @@ g_tls_certificate_openssl_get_property (GObject    *object,
-     case PROP_CERTIFICATE_PEM:
-       bio = BIO_new (BIO_s_mem ());
- 
--      if (!PEM_write_bio_X509 (bio, openssl->cert) || !BIO_write (bio, "\0", 1))
--        certificate_pem = NULL;
--      else
-+      if (PEM_write_bio_X509 (bio, openssl->cert) == 1 && BIO_write (bio, "\0", 1) == 1)
-         {
-           BIO_get_mem_data (bio, &certificate_pem);
-           g_value_set_string (value, certificate_pem);
--
--          BIO_free_all (bio);
-         }
-+      BIO_free_all (bio);
-       break;
- 
-     case PROP_PRIVATE_KEY:
-@@ -411,8 +408,12 @@ g_tls_certificate_openssl_get_property (GObject    *object,
-     case PROP_SUBJECT_NAME:
-       bio = BIO_new (BIO_s_mem ());
-       name = X509_get_subject_name (openssl->cert);
--      X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS);
--      BIO_write (bio, "\0", 1);
-+      if (X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0 ||
-+          BIO_write (bio, "\0", 1) != 1)
-+        {
-+          BIO_free_all (bio);
-+          break;
-+        }
-       BIO_get_mem_data (bio, (char **)&name_string);
-       g_value_set_string (value, name_string);
-       BIO_free_all (bio);
-@@ -421,9 +422,13 @@ g_tls_certificate_openssl_get_property (GObject    *object,
-     case PROP_ISSUER_NAME:
-       bio = BIO_new (BIO_s_mem ());
-       name = X509_get_issuer_name (openssl->cert);
--      X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS);
--      BIO_write (bio, "\0", 1);
--      BIO_get_mem_data (bio, &name_string);
-+      if (X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0 ||
-+          BIO_write (bio, "\0", 1) != 1)
-+        {
-+          BIO_free_all (bio);
-+          break;
-+        }
-+      BIO_get_mem_data (bio, (char **)&name_string);
-       g_value_set_string (value, name_string);
-       BIO_free_all (bio);
-       break;
--- 
-2.43.0
-
diff --git a/meta/recipes-core/glib-networking/glib-networking/0002-openssl-check-return-value-of-g_tls_bio_alloc.patch b/meta/recipes-core/glib-networking/glib-networking/0002-openssl-check-return-value-of-g_tls_bio_alloc.patch
deleted file mode 100644
index 9c3d19f373d..00000000000
--- a/meta/recipes-core/glib-networking/glib-networking/0002-openssl-check-return-value-of-g_tls_bio_alloc.patch
+++ /dev/null
@@ -1,42 +0,0 @@
-From b5a3a8b28b7616403d5454f5f1816c933c34cdac Mon Sep 17 00:00:00 2001
-From: Michael Catanzaro <mcatanzaro@redhat.com>
-Date: Thu, 21 Aug 2025 16:58:54 -0500
-Subject: [PATCH 2/3] openssl: check return value of g_tls_bio_alloc()
-
-This function may fail, in which case the parameter remains
-uninitialized. We'd better not dereference it in that case.
-
-CVE: CVE-2025-60019
-Upstream-Status: Backport
-Signed-off-by: Ross Burton <ross.burton@arm.com>
----
- tls/openssl/gtlsbio.c | 6 ++++--
- 1 file changed, 4 insertions(+), 2 deletions(-)
-
-diff --git a/tls/openssl/gtlsbio.c b/tls/openssl/gtlsbio.c
-index 0f603fe..1e54943 100644
---- a/tls/openssl/gtlsbio.c
-+++ b/tls/openssl/gtlsbio.c
-@@ -370,7 +370,8 @@ g_tls_bio_new_from_iostream (GIOStream *io_stream)
-   GTlsBio *gbio;
- 
-   ret = g_tls_bio_alloc (&gbio);
--  gbio->io_stream = g_object_ref (io_stream);
-+  if (ret)
-+    gbio->io_stream = g_object_ref (io_stream);
- 
-   return ret;
- }
-@@ -382,7 +383,8 @@ g_tls_bio_new_from_datagram_based (GDatagramBased *socket)
-   GTlsBio *gbio;
- 
-   ret = g_tls_bio_alloc (&gbio);
--  gbio->socket = g_object_ref (socket);
-+  if (ret)
-+    gbio->socket = g_object_ref (socket);
- 
-   return ret;
- }
--- 
-2.43.0
-
diff --git a/meta/recipes-core/glib-networking/glib-networking/0003-openssl-check-return-values-of-BIO_new.patch b/meta/recipes-core/glib-networking/glib-networking/0003-openssl-check-return-values-of-BIO_new.patch
deleted file mode 100644
index 1e925da980c..00000000000
--- a/meta/recipes-core/glib-networking/glib-networking/0003-openssl-check-return-values-of-BIO_new.patch
+++ /dev/null
@@ -1,146 +0,0 @@
-From 9c22e08b41255543bc15017123ed6c64b97b9b7c Mon Sep 17 00:00:00 2001
-From: Michael Catanzaro <mcatanzaro@redhat.com>
-Date: Thu, 21 Aug 2025 17:21:01 -0500
-Subject: [PATCH 3/3] openssl: check return values of BIO_new()
-
-We probably need to check even more return values of even more OpenSSL
-functions, but these ones allocate memory and that's particularly
-important to get right.
-
-CVE: CVE-2025-60019
-Upstream-Status: Backport
-Signed-off-by: Ross Burton <ross.burton@arm.com>
----
- tls/openssl/gtlscertificate-openssl.c | 42 ++++++++++++++++++++-------
- 1 file changed, 32 insertions(+), 10 deletions(-)
-
-diff --git a/tls/openssl/gtlscertificate-openssl.c b/tls/openssl/gtlscertificate-openssl.c
-index b536559..4fa5286 100644
---- a/tls/openssl/gtlscertificate-openssl.c
-+++ b/tls/openssl/gtlscertificate-openssl.c
-@@ -166,6 +166,9 @@ export_privkey_to_der (GTlsCertificateOpenssl  *openssl,
-     goto err;
- 
-   bio = BIO_new (BIO_s_mem ());
-+  if (!bio)
-+    goto err;
-+
-   if (i2d_PKCS8_PRIV_KEY_INFO_bio (bio, pkcs8) == 0)
-     goto err;
- 
-@@ -199,6 +202,9 @@ export_privkey_to_pem (GTlsCertificateOpenssl *openssl)
-     return NULL;
- 
-   bio = BIO_new (BIO_s_mem ());
-+  if (!bio)
-+    goto out;
-+
-   ret = PEM_write_bio_PKCS8PrivateKey (bio, openssl->key, NULL, NULL, 0, NULL, NULL);
-   if (ret == 0)
-     goto out;
-@@ -211,7 +217,7 @@ export_privkey_to_pem (GTlsCertificateOpenssl *openssl)
-   result = g_strdup (data);
- 
- out:
--  BIO_free_all (bio);
-+  g_clear_pointer (&bio, BIO_free_all);
-   return result;
- }
- 
-@@ -232,6 +238,9 @@ maybe_import_pkcs12 (GTlsCertificateOpenssl *openssl)
-     return;
- 
-   bio = BIO_new (BIO_s_mem ());
-+  if (!bio)
-+    goto import_failed;
-+
-   status = BIO_write (bio, openssl->pkcs12_data->data, openssl->pkcs12_data->len);
-   if (status <= 0)
-     goto import_failed;
-@@ -323,7 +332,7 @@ g_tls_certificate_openssl_get_property (GObject    *object,
-   guint8 *data;
-   BIO *bio;
-   GByteArray *byte_array;
--  char *certificate_pem;
-+  const char *certificate_pem;
-   long size;
- 
-   const ASN1_TIME *time_asn1;
-@@ -362,12 +371,12 @@ g_tls_certificate_openssl_get_property (GObject    *object,
-     case PROP_CERTIFICATE_PEM:
-       bio = BIO_new (BIO_s_mem ());
- 
--      if (PEM_write_bio_X509 (bio, openssl->cert) == 1 && BIO_write (bio, "\0", 1) == 1)
-+      if (bio && PEM_write_bio_X509 (bio, openssl->cert) == 1 && BIO_write (bio, "\0", 1) == 1)
-         {
-           BIO_get_mem_data (bio, &certificate_pem);
-           g_value_set_string (value, certificate_pem);
-         }
--      BIO_free_all (bio);
-+      g_clear_pointer (&bio, BIO_free_all);
-       break;
- 
-     case PROP_PRIVATE_KEY:
-@@ -407,6 +416,8 @@ g_tls_certificate_openssl_get_property (GObject    *object,
- 
-     case PROP_SUBJECT_NAME:
-       bio = BIO_new (BIO_s_mem ());
-+      if (!bio)
-+        break;
-       name = X509_get_subject_name (openssl->cert);
-       if (X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0 ||
-           BIO_write (bio, "\0", 1) != 1)
-@@ -421,6 +432,8 @@ g_tls_certificate_openssl_get_property (GObject    *object,
- 
-     case PROP_ISSUER_NAME:
-       bio = BIO_new (BIO_s_mem ());
-+      if (!bio)
-+        break;
-       name = X509_get_issuer_name (openssl->cert);
-       if (X509_NAME_print_ex (bio, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0 ||
-           BIO_write (bio, "\0", 1) != 1)
-@@ -533,8 +546,11 @@ g_tls_certificate_openssl_set_property (GObject      *object,
-         break;
-       CRITICAL_IF_CERTIFICATE_INITIALIZED ("certificate-pem");
-       bio = BIO_new_mem_buf ((gpointer)string, -1);
--      openssl->cert = PEM_read_bio_X509 (bio, NULL, NULL, NULL);
--      BIO_free (bio);
-+      if (bio)
-+        {
-+          openssl->cert = PEM_read_bio_X509 (bio, NULL, NULL, NULL);
-+          BIO_free (bio);
-+        }
-       if (openssl->cert)
-         openssl->have_cert = TRUE;
-       else if (!openssl->construct_error)
-@@ -554,8 +570,11 @@ g_tls_certificate_openssl_set_property (GObject      *object,
-       CRITICAL_IF_KEY_INITIALIZED ("private-key");
- 
-       bio = BIO_new_mem_buf (bytes->data, bytes->len);
--      openssl->key = d2i_PrivateKey_bio (bio, NULL);
--      BIO_free (bio);
-+      if (bio)
-+        {
-+          openssl->key = d2i_PrivateKey_bio (bio, NULL);
-+          BIO_free (bio);
-+        }
-       if (openssl->key)
-         openssl->have_key = TRUE;
-       else if (!openssl->construct_error)
-@@ -575,8 +594,11 @@ g_tls_certificate_openssl_set_property (GObject      *object,
-       CRITICAL_IF_KEY_INITIALIZED ("private-key-pem");
- 
-       bio = BIO_new_mem_buf ((gpointer)string, -1);
--      openssl->key = PEM_read_bio_PrivateKey (bio, NULL, NULL, NULL);
--      BIO_free (bio);
-+      if (bio)
-+        {
-+          openssl->key = PEM_read_bio_PrivateKey (bio, NULL, NULL, NULL);
-+          BIO_free (bio);
-+        }
-       if (openssl->key)
-         openssl->have_key = TRUE;
-       else if (!openssl->construct_error)
--- 
-2.43.0
-
diff --git a/meta/recipes-core/glib-networking/glib-networking/0004-openssl-fix-out-of-bounds-read-in-accepted-cas-prope.patch b/meta/recipes-core/glib-networking/glib-networking/0004-openssl-fix-out-of-bounds-read-in-accepted-cas-prope.patch
deleted file mode 100644
index d3673656ad5..00000000000
--- a/meta/recipes-core/glib-networking/glib-networking/0004-openssl-fix-out-of-bounds-read-in-accepted-cas-prope.patch
+++ /dev/null
@@ -1,48 +0,0 @@
-From be2173eb9b769255df9474a9128e642b60894f10 Mon Sep 17 00:00:00 2001
-From: Michael Catanzaro <mcatanzaro@gnome.org>
-Date: Thu, 12 Mar 2026 12:47:00 -0500
-Subject: [PATCH] openssl: fix out of bounds read in accepted-cas property
- getter
-
-The d2i and i2d functions are quite dangerous because they advance the
-provided pointer, so we have to pass a temporary pointer if we're later
-going to do anything with the original pointer.
-
-I've audited the codebase and found this is our only such mistake.
-
-Fixes #228 (CVE-2026-2574)
-
-Part-of: <https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/269>
-
-
-(cherry picked from commit c3c84b269165f2a312d47fa15c5cbc7f8ead7631)
-
-Co-authored-by: Michael Catanzaro <mcatanzaro@gnome.org>
-
-CVE: CVE-2026-2574
-Upstream-Status: Backport
-Signed-off-by: Ross Burton <ross.burton@arm.com>
----
- tls/openssl/gtlsclientconnection-openssl.c | 4 +++-
- 1 file changed, 3 insertions(+), 1 deletion(-)
-
-diff --git a/tls/openssl/gtlsclientconnection-openssl.c b/tls/openssl/gtlsclientconnection-openssl.c
-index e98fb0b..e2ff0d4 100644
---- a/tls/openssl/gtlsclientconnection-openssl.c
-+++ b/tls/openssl/gtlsclientconnection-openssl.c
-@@ -141,9 +141,11 @@ g_tls_client_connection_openssl_get_property (GObject    *object,
-               if (size > 0)
-                 {
-                   unsigned char *ca;
-+                  unsigned char *tmp;
- 
-                   ca = g_malloc (size);
--                  size = i2d_X509_NAME (sk_X509_NAME_value (openssl->ca_list, i), &ca);
-+                  tmp = ca;
-+                  size = i2d_X509_NAME (sk_X509_NAME_value (openssl->ca_list, i), &tmp);
-                   if (size > 0)
-                     accepted_cas = g_list_prepend (accepted_cas, g_byte_array_new_take (
-                                                    ca, size));
--- 
-2.43.0
-
diff --git a/meta/recipes-core/glib-networking/glib-networking_2.80.1.bb b/meta/recipes-core/glib-networking/glib-networking_2.90.0.bb
similarity index 81%
rename from meta/recipes-core/glib-networking/glib-networking_2.80.1.bb
rename to meta/recipes-core/glib-networking/glib-networking_2.90.0.bb
index aa13900da1e..1850712690c 100644
--- a/meta/recipes-core/glib-networking/glib-networking_2.80.1.bb
+++ b/meta/recipes-core/glib-networking/glib-networking_2.90.0.bb
@@ -13,7 +13,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=4fbd65380cdd255951079008b364516c \
 SECTION = "libs"
 DEPENDS = "glib-2.0-native glib-2.0"
 
-SRC_URI[archive.sha256sum] = "b80e2874157cd55071f1b6710fa0b911d5ac5de106a9ee2a4c9c7bee61782f8e"
+SRC_URI[archive.sha256sum] = "83a75e3d9c36b66ee86d3281c2fc997816101968a5126ba322b2acb9a74dd8c0"
 
 # Upstream note that for the openssl backend, half the tests where this backend don't return
 # the expected error code or don't work as expected so default to gnutls
@@ -28,11 +28,9 @@ PACKAGECONFIG[gnomeproxy] = "-Dgnome_proxy=enabled,-Dgnome_proxy=disabled,gsetti
 
 inherit gnomebase gettext upstream-version-is-even gio-module-cache ptest-gnome
 
-SRC_URI += "file://0001-openssl-properly-check-return-value-when-writing-to-.patch \
-            file://0002-openssl-check-return-value-of-g_tls_bio_alloc.patch \
-            file://0003-openssl-check-return-values-of-BIO_new.patch \
-            file://0004-openssl-fix-out-of-bounds-read-in-accepted-cas-prope.patch \
-            file://run-ptest"
+SRC_URI += "\
+            file://run-ptest \
+            "
 
 FILES:${PN} += "\
                 ${libdir}/gio/modules/libgio*.so \


      parent reply	other threads:[~2026-10-02  7:16 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02  7:15 [PATCH 0/4] Upgrades on 02-10-2026 Jaipaul Cheernam
2026-10-02  7:15 ` [PATCH 1/4] libjitterentropy: upgrade 3.6.3 -> 3.7.0 Jaipaul Cheernam
2026-10-02  8:52   ` [OE-core] " Mathieu Dubois-Briand
2026-10-02  9:35     ` Alexander Kanavin
2026-10-05  6:51       ` Jaipaul Cheernam
2026-10-02  7:15 ` [PATCH 2/4] libjitterentropy: Fix HOMEPAGE Jaipaul Cheernam
2026-10-02  7:15 ` [PATCH 3/4] shadow: upgrade 4.20.2 -> 4.20.3 Jaipaul Cheernam
2026-10-02  8:25   ` [OE-core] " Mathieu Dubois-Briand
2026-10-02 10:49     ` Jaipaul Cheernam
2026-10-02 11:57   ` [PATCH v2] " Jaipaul Cheernam
2026-10-02  7:15 ` Jaipaul Cheernam [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002071557.74249-5-jaipaul.cheernam@est.tech \
    --to=jaipaul.cheernam@est.tech \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.