From: "Yoann Congal" <yoann.congal@smile.fr>
To: <daniel.turull@ericsson.com>, <openembedded-core@lists.openembedded.org>
Cc: <paul@pbarker.dev>
Subject: Re: [OE-core] [wrynose][PATCH] libarchive: mark CVE-2026-14164 as not-applicable-platform
Date: Wed, 02 Sep 2026 11:18:58 +0200 [thread overview]
Message-ID: <DL4PVTP9830X.2T1UL0PBOMPPF@smile.fr> (raw)
In-Reply-To: <20260817105942.2295192-1-daniel.turull@ericsson.com>
On Mon Aug 17, 2026 at 12:59 PM CEST, Daniel Turull via lists.openembedded.org wrote:
> From: Daniel Turull <daniel.turull@ericsson.com>
>
> - The RAR5 double-free in init_unpack() is a regression introduced
> upstream by commit 620bdafa on 2026-05-16 and existed only
> on the git master branch until it was fixed by PR #3071 (commit
> 1c914cdf) on 2026-05-24. It was never part of an upstream release.
> - The upstream release tarballs (3.6.x/3.7.x/3.8.6) use the older
> init_unpack() with unchecked calloc and no early-return path, so the
> freed window_buf/filtered_buf pointers are never left dangling and the
> double-free cannot occur.
>
> References:
> https://nvd.nist.gov/vuln/detail/CVE-2026-14164
>
> Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
> ---
> meta/recipes-extended/libarchive/libarchive_3.8.7.bb | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
> index e8c3a3bfe3..0926acd8f9 100644
> --- a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
> +++ b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
> @@ -92,3 +92,7 @@ RDEPENDS:${PN}-ptest += "bsdtar bsdcpio"
> CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7"
> CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7"
> CVE_STATUS[CVE-2026-5745] = "fixed-version: fixed since 3.8.6"
> +CVE_STATUS[CVE-2026-14164] = "not-applicable-platform: Double-free regression in the RAR5\
> + reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\
> + only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\
> + never part of an upstream release tarball."
Hello,
I don't think not-applicable-platform is the right flag for this
CVE_STATUS. See cve-check-map.conf[0]:
> [not-applicable-platform] use when vulnerability affects other platform (e.g. Windows or Debian)
How about "fixed-version"?
Regards,
[0]: https://git.openembedded.org/openembedded-core/tree/meta/conf/cve-check-map.conf?h=wrynose
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-02 9:19 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 10:59 [wrynose][PATCH] libarchive: mark CVE-2026-14164 as not-applicable-platform daniel.turull
2026-09-02 9:18 ` Yoann Congal [this message]
2026-09-02 14:32 ` [OE-core] " Daniel Turull
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DL4PVTP9830X.2T1UL0PBOMPPF@smile.fr \
--to=yoann.congal@smile.fr \
--cc=daniel.turull@ericsson.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=paul@pbarker.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.