From: "Yoann Congal" <yoann.congal@smile.fr>
To: <deepesh.varatharajan@windriver.com>,
<openembedded-core@lists.openembedded.org>
Cc: <Sundeep.Kokkonda@windriver.com>, <sunilkumar.dora@windriver.com>,
<Deepesh.Varatharajan@windriver.com>
Subject: Re: [OE-core] [scarthgap][PATCH] glibc: Fix CVE-2026-6238
Date: Fri, 11 Sep 2026 12:49:50 +0200 [thread overview]
Message-ID: <DLCFGAY7ME0S.2VZPV9KTTLMI@smile.fr> (raw)
In-Reply-To: <20260904130447.1762441-1-Deepesh.Varatharajan@windriver.com>
On Fri Sep 4, 2026 at 3:04 PM CEST, Deepesh via lists.openembedded.org Varatharajan wrote:
> From: Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com>
>
> Backport six commits from upstream glibc to fix CVE-2026-6238.
>
> 4ba0b79b95 resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069)
> a7b60d23bb resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238)
> cd0db208d5 resolv: Check for inet_ntop failure in ns_sprintrrf
> d58415eb17 resolv: Improve formatting of unknown records in ns_sprintrrf
> f69b7f95e3 resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289)
> 360f352c9a resolv: Declare __p_class_syms, __p_type_syms for internal use
>
> The upstream patch series [PATCH 0/5] contains five commits:
> 1/5: Update GLIBC-SA-2026-0012 to mention A6 records (doc only)
> 2/5: resolv: Check for inet_ntop failure in ns_sprintrrf
> 3/5: resolv: Remove incorrect parts of TSIG handling from ns_sprintrrf
> (CVE-2026-5435)
> 4/5: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238)
> 5/5: resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069)
>
> For this backport:
> - Patch 1/5 is skipped (documentation-only change to advisories,
> upstream glibc itself does not backport this to older releases)
> - Patch 3/5 (CVE-2026-5435) is already patched in scarthgap sources
> - Patches 2/5, 4/5, and 5/5 are backported as:
> 0028-CVE-2026-6238-0004.patch (inet_ntop failure check)
> 0029-CVE-2026-6238-0005.patch (buffer overread fix - CVE-2026-6238)
> 0030-CVE-2026-6238-0006.patch (test case for bug 34033, bug 34069)
>
> However, the test case (tst-ns_sprintrr) from patch 5/5 failed on
> scarthgap's glibc 2.39 due to missing prerequisite commits. Three
> additional patches were backported to resolve the test failure:
> 0025-CVE-2026-6238-0001.patch (Declare __p_class_syms, __p_type_syms for internal)
> 0026-CVE-2026-6238-0002.patch (Fix ns_sprintrrf formatting of class, type values)
> 0027-CVE-2026-6238-0003.patch (Improve formatting of unknown records in ns_sprintrrf)
>
> CVE-2026-6238 fixes buffer overreads in ns_sprintrrf affecting A6 and
> LOC record handling. The vulnerable LOC record handling was introduced
> before glibc 2.0, while A6 record handling was added in glibc 2.7.
>
> Reference:
> https://inbox.sourceware.org/libc-alpha/cover.1777546194.git.fweimer@redhat.com/
> https://nvd.nist.gov/vuln/detail/CVE-2026-6238
> https://sourceware.org/bugzilla/show_bug.cgi?id=34069
>
> Testing Results:
> Before After Diff
> PASS 4896 4897 +1
> XPASS 4 4 0
> FAIL 372 372 0
> XFAIL 16 16 0
> UNSUPPORTED 224 224 0
>
> Changes in testcases:
>
> testcase-name before after
> resolv/tst-ns_sprintrr(new) - PASS
>
> commit - 4ba0b79b95 resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069)
> +PASS: resolv/tst-ns_sprintrr
> Signed-off-by: Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com>
> ---
> .../glibc/glibc/0025-CVE-2026-6238-0001.patch | 56 +++
> .../glibc/glibc/0026-CVE-2026-6238-0002.patch | 80 ++++
> .../glibc/glibc/0027-CVE-2026-6238-0003.patch | 55 +++
> .../glibc/glibc/0028-CVE-2026-6238-0004.patch | 70 ++++
> .../glibc/glibc/0029-CVE-2026-6238-0005.patch | 66 +++
> .../glibc/glibc/0030-CVE-2026-6238-0006.patch | 379 ++++++++++++++++++
> meta/recipes-core/glibc/glibc_2.39.bb | 6 +
> 7 files changed, 712 insertions(+)
> create mode 100644 meta/recipes-core/glibc/glibc/0025-CVE-2026-6238-0001.patch
> create mode 100644 meta/recipes-core/glibc/glibc/0026-CVE-2026-6238-0002.patch
> create mode 100644 meta/recipes-core/glibc/glibc/0027-CVE-2026-6238-0003.patch
> create mode 100644 meta/recipes-core/glibc/glibc/0028-CVE-2026-6238-0004.patch
> create mode 100644 meta/recipes-core/glibc/glibc/0029-CVE-2026-6238-0005.patch
> create mode 100644 meta/recipes-core/glibc/glibc/0030-CVE-2026-6238-0006.patch
Hello,
Out of curiosity, did we try to send these backports to upstream? I'd be
more confortable keeping the "update along the upstream maintained
branch" idea we had until now.
The 2.39 branch has not seen updates since 8 weeks so it looks like they
finally stopped maintaining it, but I've not found an anounce, did you?
In the meantime, I'll keep reviewing those.
Thanks!
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-11 10:49 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 13:04 [scarthgap][PATCH] glibc: Fix CVE-2026-6238 Deepesh.Varatharajan
2026-09-11 10:49 ` Yoann Congal [this message]
2026-09-11 11:16 ` [OE-core] " Yoann Congal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLCFGAY7ME0S.2VZPV9KTTLMI@smile.fr \
--to=yoann.congal@smile.fr \
--cc=Sundeep.Kokkonda@windriver.com \
--cc=deepesh.varatharajan@windriver.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=sunilkumar.dora@windriver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.