All of lore.kernel.org
 help / color / mirror / Atom feed
* [wrynose][PATCH 0/2] perl: fix multiple CVEs
@ 2026-07-21 13:45 Jaipaul Cheernam
  2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
  2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
  0 siblings, 2 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
  To: openembedded-core; +Cc: Jaipaul Cheernam

Fix two security vulnerabilities in perl 5.42.0:

- CVE-2026-13221: regex trie overflow causing incorrect matches when
  alternation has more than 65535 fixed string branches (CVSS 9.1)
- CVE-2026-57432: integer overflow in pack/unpack leading to
  out-of-bounds heap read (CVSS 8.4)

Both are fixed upstream in perl 5.44.0.

Jaipaul Cheernam (2):
  perl: fix CVE-2026-13221
  perl: fix CVE-2026-57432

 .../perl/files/CVE-2026-13221.patch           | 75 +++++++++++++++++++
 .../perl/files/CVE-2026-57432-01.patch        | 52 +++++++++++++
 .../perl/files/CVE-2026-57432-02.patch        | 34 +++++++++
 meta/recipes-devtools/perl/perl_5.42.0.bb     |  3 +
 4 files changed, 164 insertions(+)
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch



^ permalink raw reply	[flat|nested] 5+ messages in thread

* [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
  2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
@ 2026-07-21 13:45 ` Jaipaul Cheernam
  2026-07-24 13:37   ` [OE-core] " Yoann Congal
  2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam
  1 sibling, 1 reply; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
  To: openembedded-core; +Cc: Jaipaul Cheernam

This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
[2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
 .../perl/files/CVE-2026-13221.patch           | 75 +++++++++++++++++++
 meta/recipes-devtools/perl/perl_5.42.0.bb     |  1 +
 2 files changed, 76 insertions(+)
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch

diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
new file mode 100644
index 0000000000..03396f3e43
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
@@ -0,0 +1,75 @@
+From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001
+From: Karl Williamson <khw@cpan.org>
+Date: Thu, 26 Mar 2026 10:13:49 -0600
+Subject: [PATCH] regcomp_study: Don't create a trie that would overflow
+
+This addresses GH #23388
+
+The design of the trie compiling code is to batch extra long tries into
+smaller chunks that fit into whatever limitations there are.  However,
+this ticket shows that that isn't always being done.
+
+In this case, a bunch of branches that have TAIL operands can be
+combined together, and the final TAIL is used.  And the code requires
+that the delta between the first branch and this final TAIL fit into a
+16-bit field.  That is the root cause of this bug.
+
+I'm not familiar enough with the trie construction code to easily
+understand why the final tail needs to be used here.  So this patch
+simply doesn't optimize a sequence of branches into a trie that would
+overflow.
+
+This could be revisited by someone who knows more about this than I, or
+earlier in the development cycle.
+
+CVE: CVE-2026-13221
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ regcomp_study.c     | 10 ++++++++++
+ t/re/pat_advanced.t |  9 +++++++++
+ 2 files changed, 19 insertions(+)
+
+diff --git a/regcomp_study.c b/regcomp_study.c
+index db7ab3a409..a1b2c3d4e5 100644
+--- a/regcomp_study.c
++++ b/regcomp_study.c
+@@ -1933,6 +1933,16 @@ Perl_study_chunk(pTHX_
+                             tail = regnext( tail );
+                         }
+ 
++                        /* The code below currently saves the difference from
++                         * start to finish in a 16-bit field, causing
++                         * GH #23388.  This defeats the design of batching
++                         * tries into chunks that each fit.  khw thinks it is
++                         * too late in the 5.44 cycle to relook at the design,
++                         * so for now anyway, don't make a trie that would
++                         * overflow */
++                        if (tail - startbranch >= U16_MAX) {
++                            continue;
++                        }
+ 
+                         DEBUG_TRIE_COMPILE_r({
+                             regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state);
+diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t
+index 398680838d..c9e389ecb3 100644
+--- a/t/re/pat_advanced.t
++++ b/t/re/pat_advanced.t
+@@ -4898,6 +4898,15 @@ EOF_DEBUG_OUT
+         $x =~ s/^[\x{0301}\x{030C}]+//;
+     }
+ 
++    { # GH #23388
++        fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow");
++            my $x = join "|", "aaa".."mzz";
++            my $y = join "|", "naa".."zzz";
++            use re 'Debug';
++            "fnord" =~ m/(?:$x)|(?:$y)/;
++            PROG
++    }
++
+ 
+     # !!! NOTE that tests that aren't at all likely to crash perl should go
+     # a ways above, above these last ones.  There's a comment there that, like
+-- 
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 1833b7a352..1a3451b747 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -18,6 +18,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
            file://0001-cpan-Sys-Syslog-Makefile.PL-Fix-_PATH_LOG-for-determ.patch \
            file://CVE-2026-8376-01.patch \
            file://CVE-2026-8376-02.patch \
+           file://CVE-2026-13221.patch \
            "
 SRC_URI:append:class-native = " \
            file://perl-configpm-switch.patch \


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [wrynose][PATCH 2/2] perl: fix CVE-2026-57432
  2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
  2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
@ 2026-07-21 13:45 ` Jaipaul Cheernam
  1 sibling, 0 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-07-21 13:45 UTC (permalink / raw)
  To: openembedded-core; +Cc: Jaipaul Cheernam

This patch applies the upstream fix as referenced in [1], using the
commits shown in [2] and [3].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57432
[2] https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55
[3] https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
---
 .../perl/files/CVE-2026-57432-01.patch        | 52 +++++++++++++++++++
 .../perl/files/CVE-2026-57432-02.patch        | 34 ++++++++++++
 meta/recipes-devtools/perl/perl_5.42.0.bb     |  2 +
 3 files changed, 88 insertions(+)
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch

diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
new file mode 100644
index 0000000000..ef92b0d7b2
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
@@ -0,0 +1,52 @@
+From 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Sat, 9 May 2026 17:18:43 +0100
+Subject: [PATCH] pp_pack.c: Avoid ssize_t overflow when calculating the size
+ of a structure
+
+If the user has requested a size that would overflow a SSize_t, then the
+only sensible thing to do is throw an exception, because the structure
+this implies couldn't possibly fit into memory anyway.
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pod/perldiag.pod | 6 ++++++
+ pp_pack.c        | 4 ++++
+ 2 files changed, 10 insertions(+)
+
+diff --git a/pod/perldiag.pod b/pod/perldiag.pod
+index 841e22d580..d9231077363d 100644
+--- a/pod/perldiag.pod
++++ b/pod/perldiag.pod
+@@ -4880,6 +4880,12 @@ mixed-case attribute name, instead.  See L<attributes>.
+ (F) You can't specify a repeat count so large that it overflows your
+ signed integers.  See L<perlfunc/pack>.
+ 
++=item Pack template structure size is too large
++
++(F) You called C<pack> or C<unpack> to operate on a structure, whose
++computed size is too large to fit in memory.  This usually happens as a
++result of embedding a large number as the repeat count for an item.
++
+ =item page overflow
+ 
+ (W io) A single call to write() produced more lines than can fit on a
+diff --git a/pp_pack.c b/pp_pack.c
+index b5c0b261ef..6075e83aac 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+                 break;
+             }
+         }
++        if ((size > 0) &&
++                ((len > SSize_t_MAX / size) ||         /* detect overflow of len * size */
++                 (len * size > SSize_t_MAX - total)))  /* detect overflow of total + len * size */
++            croak("Pack template structure size is too large");
+         total += len * size;
+     }
+     return total;
+-- 
+2.43.0
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
new file mode 100644
index 0000000000..273a247a88
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
@@ -0,0 +1,34 @@
+From 40754edc72dd3e513d758153c0e2f0215897740e Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Mon, 11 May 2026 12:25:33 +0100
+Subject: [PATCH] pp_pack.c: Avoid some other potential overflows when
+ calculating sizes
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pp_pack.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/pp_pack.c b/pp_pack.c
+index 6075e83aac..b2019902203a 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -515,12 +515,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+                 break;
+             case 'B':
+             case 'b':
+-                len = (len + 7)/8;
++                len = (len / 8) + !!(len % 8);
+                 size = 1;
+                 break;
+             case 'H':
+             case 'h':
+-                len = (len + 1)/2;
++                len = (len / 2) + !!(len % 2);
+                 size = 1;
+                 break;
+ 
+-- 
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 1a3451b747..8716f1f257 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -19,6 +19,8 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
            file://CVE-2026-8376-01.patch \
            file://CVE-2026-8376-02.patch \
            file://CVE-2026-13221.patch \
+           file://CVE-2026-57432-01.patch \
+           file://CVE-2026-57432-02.patch \
            "
 SRC_URI:append:class-native = " \
            file://perl-configpm-switch.patch \


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [OE-core] [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
  2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
@ 2026-07-24 13:37   ` Yoann Congal
  2026-08-25  4:33     ` Jaipaul Cheernam
  0 siblings, 1 reply; 5+ messages in thread
From: Yoann Congal @ 2026-07-24 13:37 UTC (permalink / raw)
  To: jaipaul.cheernam, openembedded-core

On Tue Jul 21, 2026 at 3:45 PM CEST, Jaipaul Cheernam via lists.openembedded.org wrote:
> This patch applies the upstream fix as referenced in [1], using the
> commit shown in [2].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
> [2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7
>
> Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
> ---
>  .../perl/files/CVE-2026-13221.patch           | 75 +++++++++++++++++++
>  meta/recipes-devtools/perl/perl_5.42.0.bb     |  1 +
>  2 files changed, 76 insertions(+)
>  create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch

Hello,

For my own tracking, this series needs "perl: upgrade 5.42.2 -> 5.44.0"
on master.

Regards,
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [wrynose][PATCH 1/2] perl: fix CVE-2026-13221
  2026-07-24 13:37   ` [OE-core] " Yoann Congal
@ 2026-08-25  4:33     ` Jaipaul Cheernam
  0 siblings, 0 replies; 5+ messages in thread
From: Jaipaul Cheernam @ 2026-08-25  4:33 UTC (permalink / raw)
  To: openembedded-core

[-- Attachment #1: Type: text/plain, Size: 100 bytes --]

Hi Yoann,

Perl 5.44.0 has been merged to master and can you look on this ?

Regards,
Jaipaul

[-- Attachment #2: Type: text/html, Size: 190 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-25  4:33 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-21 13:45 [wrynose][PATCH 0/2] perl: fix multiple CVEs Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 1/2] perl: fix CVE-2026-13221 Jaipaul Cheernam
2026-07-24 13:37   ` [OE-core] " Yoann Congal
2026-08-25  4:33     ` Jaipaul Cheernam
2026-07-21 13:45 ` [wrynose][PATCH 2/2] perl: fix CVE-2026-57432 Jaipaul Cheernam

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.