All of lore.kernel.org
 help / color / mirror / Atom feed
* [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892
@ 2026-08-23 10:03 Peter Marko
  2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
  2026-09-01 14:57 ` [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Bruce Ashfield
  0 siblings, 2 replies; 4+ messages in thread
From: Peter Marko @ 2026-08-23 10:03 UTC (permalink / raw)
  To: meta-virtualization; +Cc: Peter Marko

From: Peter Marko <peter.marko@siemens.com>

Pick patch per [1].

[1] https://security-tracker.debian.org/tracker/CVE-2026-30892

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 .../crun/crun/CVE-2026-30892.patch            | 53 +++++++++++++++++++
 recipes-containers/crun/crun_git.bb           |  1 +
 2 files changed, 54 insertions(+)
 create mode 100644 recipes-containers/crun/crun/CVE-2026-30892.patch

diff --git a/recipes-containers/crun/crun/CVE-2026-30892.patch b/recipes-containers/crun/crun/CVE-2026-30892.patch
new file mode 100644
index 00000000..3d900cc3
--- /dev/null
+++ b/recipes-containers/crun/crun/CVE-2026-30892.patch
@@ -0,0 +1,53 @@
+From 1bd7f42446999b0e76bc3d575392e05c943b0b01 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Erik=20Sj=C3=B6lund?= <erik.sjolund@gmail.com>
+Date: Sat, 7 Mar 2026 19:19:41 +0100
+Subject: [PATCH] exec: fix CVE-2026-30892
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Fix parsing of the -u (--user) option for "crun exec".
+
+Before:
+Value "1" is interpreted as UID=0 GID=0
+
+After:
+Value "1" is interpreted as UID=1 GID=0
+
+Commit 85d4db3d8b27c9ca606eea5f007c58a752ae77aa introduced the
+regression.
+
+Reference:
+https://github.com/containers/crun/security/advisories/GHSA-4vg2-xjqj-7chj
+
+Signed-off-by: Erik Sjölund <erik.sjolund@gmail.com>
+
+CVE: CVE-2026-30892
+Upstream-Status: Backport [https://github.com/containers/crun/commit/1bd7f42446999b0e76bc3d575392e05c943b0b01]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/exec.c | 7 +++----
+ 1 file changed, 3 insertions(+), 4 deletions(-)
+
+diff --git a/src/exec.c b/src/exec.c
+index 36c6084c..5713bbcf 100644
+--- a/src/exec.c
++++ b/src/exec.c
+@@ -214,14 +214,13 @@ make_oci_process_user (const char *userspec)
+   l = strtoll (userspec, &endptr, 10);
+   if (errno == ERANGE)
+     libcrun_fail_with_error (0, "invalid UID specified");
++  if (l < INT_MIN || l > INT_MAX)
++    libcrun_fail_with_error (0, "invalid UID specified");
++  u->uid = (int) l;
+   if (*endptr == '\0')
+     return u;
+   if (*endptr != ':')
+     libcrun_fail_with_error (0, "invalid USERSPEC specified");
+-  if (l < INT_MIN || l > INT_MAX)
+-    libcrun_fail_with_error (0, "invalid UID specified");
+-
+-  u->uid = (int) l;
+ 
+   errno = 0;
+   l = strtoll (endptr + 1, &endptr, 10);
diff --git a/recipes-containers/crun/crun_git.bb b/recipes-containers/crun/crun_git.bb
index ea14e8ec..e8d87484 100644
--- a/recipes-containers/crun/crun_git.bb
+++ b/recipes-containers/crun/crun_git.bb
@@ -17,6 +17,7 @@ SRC_URI = "git://github.com/containers/crun.git;branch=main;name=crun;protocol=h
            git://github.com/containers/yajl.git;branch=main;name=yajl;destsuffix=${BB_GIT_DEFAULT_DESTSUFFIX}/libocispec/yajl;protocol=https \
            file://0001-libocispec-correctly-parse-JSON-schema-references.patch;patchdir=libocispec \
            file://0002-libocispec-fix-array-items-parsing.patch;patchdir=libocispec \
+           file://CVE-2026-30892.patch \
           "
 
 PV = "1.26.0+git"


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-01 14:58 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-23 10:03 [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Peter Marko
2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
2026-09-01 14:57   ` Bruce Ashfield
2026-09-01 14:57 ` [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Bruce Ashfield

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.