All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] glibc: Fix CVE-2026-5450
@ 2026-09-30 10:21 Sourav Kumar Pramanik
  2026-09-30 10:21 ` [PATCH 2/2] glibc: Fix CVE-2026-5928 Sourav Kumar Pramanik
  2026-09-30 13:53 ` [OE-core] [PATCH 1/2] glibc: Fix CVE-2026-5450 Mathieu Dubois-Briand
  0 siblings, 2 replies; 3+ messages in thread
From: Sourav Kumar Pramanik @ 2026-09-30 10:21 UTC (permalink / raw)
  To: openembedded-core; +Cc: Sourav Kumar Pramanik

From: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>

This change fixes CVE-2026-5450

Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead]

Comment: Patch refreshed as per glibc 2.39 source code

Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
---
 .../glibc/glibc/CVE-2026-5450.patch           | 113 ++++++++++++++++++
 meta/recipes-core/glibc/glibc_2.39.bb         |   1 +
 2 files changed, 114 insertions(+)
 create mode 100644 meta/recipes-core/glibc/glibc/CVE-2026-5450.patch

diff --git a/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch b/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch
new file mode 100644
index 0000000000..adea5c3f01
--- /dev/null
+++ b/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch
@@ -0,0 +1,113 @@
+From 839898777226a3ed88c0859f25ffe712519b4ead Mon Sep 17 00:00:00 2001
+From: Rocket Ma <marocketbd@gmail.com>
+Date: Fri, 17 Apr 2026 23:48:41 -0700
+Subject: [PATCH] stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
+
+* stdio-common/vfscanf-internal.c: When enlarging allocated buffer with
+format %mc or %mC, glibc allocates one byte less, leading to
+user-controlled one byte overflow. This commit fixes BZ #34008, or
+CVE-2026-5450.
+
+CVE: CVE-2026-5450
+Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead]
+Comment: Patch refreshed as per glibc 2.39 source code
+
+Reviewed-by: Carlos O'Donell <carlos@redhat.com>
+Signed-off-by: Rocket Ma <marocketbd@gmail.com>
+Reviewed-by: H.J. Lu <hjl.tools@gmail.com>
+Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
+---
+ stdio-common/Makefile              |  4 ++++
+ stdio-common/tst-vfscanf-bz34008.c | 48 +++++++++++++++++++++++++++++++++++++
+ stdio-common/vfscanf-internal.c    |  6 +++---
+ 3 files changed, 55 insertions(+), 3 deletions(-)
+ create mode 100644 stdio-common/tst-vfscanf-bz34008.c
+
+diff --git a/stdio-common/Makefile b/stdio-common/Makefile
+--- a/stdio-common/Makefile
++++ b/stdio-common/Makefile
+@@ -266,6 +266,7 @@ tests := \
+   tst-vfprintf-width-i18n \
+   tst-vfprintf-width-prec \
+   tst-vfprintf-width-prec-alloc \
++  tst-vfscanf-bz34008 \
+   tst-wc-printf \
+   tstdiomisc \
+   tstgetln \
+@@ -401,6 +402,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \
+ tst-vfprintf-width-prec-ENV = \
+   MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \
+   LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
++tst-vfscanf-bz34008-ENV = \
++  MALLOC_CHECK_=3 \
++  LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
+ tst-printf-bz25691-ENV = \
+   MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \
+   LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
+diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c
+new file mode 100644
+--- /dev/null
++++ b/stdio-common/tst-vfscanf-bz34008.c
+@@ -0,0 +1,48 @@
++/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008)
++   Copyright (C) 2026 The GNU Toolchain Authors.
++   This file is part of the GNU C Library.
++
++   The GNU C Library is free software; you can redistribute it and/or
++   modify it under the terms of the GNU Lesser General Public
++   License as published by the Free Software Foundation; either
++   version 2.1 of the License, or (at your option) any later version.
++
++   The GNU C Library is distributed in the hope that it will be useful,
++   but WITHOUT ANY WARRANTY; without even the implied warranty of
++   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
++   Lesser General Public License for more details.
++
++   You should have received a copy of the GNU Lesser General Public
++   License along with the GNU C Library; if not, see
++   <https://www.gnu.org/licenses/>.  */
++
++#include "malloc/mcheck.h"
++#include <stddef.h>
++#include <stdio.h>
++#include <string.h>
++#include <wchar.h>
++#include <stdlib.h>
++#include <malloc.h>
++#include <support/check.h>
++
++#define WIDTH 0x410
++#define SCANFSTR "%1040mc"
++static int
++do_test (void)
++{
++  mcheck_pedantic (NULL);
++  char *input = malloc (WIDTH + 1);
++  TEST_VERIFY (input != NULL);
++  memset (input, 'A', WIDTH);
++  input[WIDTH] = '\0';
++
++  char *buf = NULL;
++  TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1);
++  TEST_VERIFY (buf != NULL);
++
++  free (buf);
++  free (input);
++  return 0;
++}
++
++#include <support/test-driver.c>
+diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c
+--- a/stdio-common/vfscanf-internal.c
++++ b/stdio-common/vfscanf-internal.c
+@@ -857 +857 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+-			      + (strsize >= width ? width - 1 : strsize);
++			      + (strsize >= width ? width : strsize);
+@@ -928 +928 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+-			= strsize + (strsize > width ? width - 1 : strsize);
++			= strsize + (strsize >= width ? width : strsize);
+@@ -983 +983 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+-		      = strsize + (strsize > width ? width - 1 : strsize);
++		      = strsize + (strsize >= width ? width : strsize);
+-- 
+2.43.7
diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb
index 88ad5e44e8..b01225e530 100644
--- a/meta/recipes-core/glibc/glibc_2.39.bb
+++ b/meta/recipes-core/glibc/glibc_2.39.bb
@@ -57,6 +57,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
            file://0023-qemu-stale-process.patch \
            file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \
            file://0024-CVE-2026-5435.patch \
+           file://CVE-2026-5450.patch \
 "
 S = "${WORKDIR}/git"
 B = "${WORKDIR}/build-${TARGET_SYS}"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH 2/2] glibc: Fix CVE-2026-5928
  2026-09-30 10:21 [PATCH 1/2] glibc: Fix CVE-2026-5450 Sourav Kumar Pramanik
@ 2026-09-30 10:21 ` Sourav Kumar Pramanik
  2026-09-30 13:53 ` [OE-core] [PATCH 1/2] glibc: Fix CVE-2026-5450 Mathieu Dubois-Briand
  1 sibling, 0 replies; 3+ messages in thread
From: Sourav Kumar Pramanik @ 2026-09-30 10:21 UTC (permalink / raw)
  To: openembedded-core; +Cc: Sourav Kumar Pramanik

From: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>

This change fixes CVE-2026-5928

Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=commit;h=ef3bfb5f910011f3780cb06aa47e730035f53285]

Comment: Patch refreshed as per glibc 2.39 source code

Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
---
 .../glibc/glibc/CVE-2026-5928.patch           | 105 ++++++++++++++++++
 meta/recipes-core/glibc/glibc_2.39.bb         |   1 +
 2 files changed, 106 insertions(+)
 create mode 100644 meta/recipes-core/glibc/glibc/CVE-2026-5928.patch

diff --git a/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch b/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch
new file mode 100644
index 0000000000..470ab1a1ec
--- /dev/null
+++ b/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch
@@ -0,0 +1,105 @@
+From ef3bfb5f910011f3780cb06aa47e730035f53285 Mon Sep 17 00:00:00 2001
+From: Rocket Ma <marocketbd@gmail.com>
+Date: Fri, 1 May 2026 20:39:07 -0700
+Subject: [PATCH] libio: Fix ungetwc operating on byte stream [BZ #33998]
+
+* libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one
+character, it accidently compare the wchar to push back with the last
+char from byte stream, instead of wide stream. Under specific coding,
+attacker may exploit this to leak information. This commit fix bug
+33998, or CVE-2026-5928.
+
+CVE: CVE-2026-5928
+Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=commit;h=ef3bfb5f910011f3780cb06aa47e730035f53285]
+Comment: Patch refreshed as per glibc 2.39 source code
+
+Signed-off-by: Rocket Ma <marocketbd@gmail.com>
+Reviewed-by: Carlos O'Donell <carlos@redhat.com>
+Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
+---
+ libio/Makefile              |  1 +
+ libio/bug-wgenops-bz33998.c | 54 +++++++++++++++++++++++++++++++++++++++++++++
+ libio/wgenops.c             |  4 ++--
+ 3 files changed, 57 insertions(+), 2 deletions(-)
+ create mode 100644 libio/bug-wgenops-bz33998.c
+
+diff --git a/libio/Makefile b/libio/Makefile
+--- a/libio/Makefile
++++ b/libio/Makefile
+@@ -83,6 +83,7 @@ tests = \
+   bug-ungetwc1 \
+   bug-ungetwc2 \
+   bug-wfflush \
++  bug-wgenops-bz33998 \
+   bug-wmemstream1 \
+   bug-wsetpos \
+   test-fmemopen \
+diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c
+new file mode 100644
+--- /dev/null
++++ b/libio/bug-wgenops-bz33998.c
+@@ -0,0 +1,54 @@
++/* Regression test for ungetwc operating on byte stream (BZ #33998)
++   Copyright (C) 2026 The GNU Toolchain Authors.
++   This file is part of the GNU C Library.
++
++   The GNU C Library is free software; you can redistribute it and/or
++   modify it under the terms of the GNU Lesser General Public
++   License as published by the Free Software Foundation; either
++   version 2.1 of the License, or (at your option) any later version.
++
++   The GNU C Library is distributed in the hope that it will be useful,
++   but WITHOUT ANY WARRANTY; without even the implied warranty of
++   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
++   Lesser General Public License for more details.
++
++   You should have received a copy of the GNU Lesser General Public
++   License along with the GNU C Library; if not, see
++   <https://www.gnu.org/licenses/>.  */
++
++#include "support/temp_file.h"
++#include "support/xstdio.h"
++#include "support/xunistd.h"
++#include <stdlib.h>
++#include <unistd.h>
++#include <sys/mman.h>
++#include <stdio.h>
++#include <wchar.h>
++#include <support/check.h>
++
++static int
++do_test (void)
++{
++  char *filename;
++  int fd = create_temp_file ("tst-bz33998-", &filename);
++  TEST_VERIFY (fd != -1);
++  xwrite (fd, "A", sizeof ("A")); // write "A\0" by design
++  xclose (fd);
++
++  FILE *fp = xfopen (filename, "r+");
++  TEST_COMPARE (getwc (fp), L'A');
++  /* If the bug is fixed, then ungetwc should not touch byte stream.
++     If the bug is not fixed, ungetwc firstly match last read char, L'A',
++     failed, then the pbackfail branch, matching last read char in byte
++     stream, that is, '\0' (initialized when setup wide stream). */
++  char *old_read_ptr = fp->_IO_read_ptr;
++  TEST_COMPARE (ungetwc (L'\0', fp), L'\0');
++  TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr);
++
++  xfclose (fp);
++  free (filename);
++
++  return 0;
++}
++
++#include <support/test-driver.c>
+diff --git a/libio/wgenops.c b/libio/wgenops.c
+--- a/libio/wgenops.c
++++ b/libio/wgenops.c
+@@ -111,2 +111,2 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c)
+-      && (wint_t) fp->_IO_read_ptr[-1] == c)
+-    --fp->_IO_read_ptr;
++      && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c)
++    --fp->_wide_data->_IO_read_ptr;
+-- 
+2.43.7
diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb
index b01225e530..74db1ac507 100644
--- a/meta/recipes-core/glibc/glibc_2.39.bb
+++ b/meta/recipes-core/glibc/glibc_2.39.bb
@@ -58,6 +58,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
            file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \
            file://0024-CVE-2026-5435.patch \
            file://CVE-2026-5450.patch \
+           file://CVE-2026-5928.patch \
 "
 S = "${WORKDIR}/git"
 B = "${WORKDIR}/build-${TARGET_SYS}"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [OE-core] [PATCH 1/2] glibc: Fix CVE-2026-5450
  2026-09-30 10:21 [PATCH 1/2] glibc: Fix CVE-2026-5450 Sourav Kumar Pramanik
  2026-09-30 10:21 ` [PATCH 2/2] glibc: Fix CVE-2026-5928 Sourav Kumar Pramanik
@ 2026-09-30 13:53 ` Mathieu Dubois-Briand
  1 sibling, 0 replies; 3+ messages in thread
From: Mathieu Dubois-Briand @ 2026-09-30 13:53 UTC (permalink / raw)
  To: UpStream_IP-SP, openembedded-core; +Cc: Sourav Kumar Pramanik

On Wed Sep 30, 2026 at 12:21 PM CEST, Sourav Kumar Pramanik via lists.openembedded.org wrote:
> From: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
>
> This change fixes CVE-2026-5450
>
> Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead]
>
> Comment: Patch refreshed as per glibc 2.39 source code
>
> Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
> ---

Hi Sourav Kumar,

> diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb
> index 88ad5e44e8..b01225e530 100644
> --- a/meta/recipes-core/glibc/glibc_2.39.bb
> +++ b/meta/recipes-core/glibc/glibc_2.39.bb

Glibc 2.39, I bet this is for a stable branch. Missing the branch name
in mail title?

Thanks,
Mathieu

-- 
Mathieu Dubois-Briand, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-30 13:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 10:21 [PATCH 1/2] glibc: Fix CVE-2026-5450 Sourav Kumar Pramanik
2026-09-30 10:21 ` [PATCH 2/2] glibc: Fix CVE-2026-5928 Sourav Kumar Pramanik
2026-09-30 13:53 ` [OE-core] [PATCH 1/2] glibc: Fix CVE-2026-5450 Mathieu Dubois-Briand

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.