* [OE-core][scarthgap 00/27] Patch review
@ 2024-07-14 12:38 Steve Sakoman
0 siblings, 0 replies; 31+ messages in thread
From: Steve Sakoman @ 2024-07-14 12:38 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, July 16
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/7136
The following changes since commit d511c41dac048fbdd93a54136e93b0623a18a83d:
xz: Update LICENSE variable for xz packages (2024-07-08 05:40:28 -0700)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
Alexander Kanavin (6):
mesa: remove obsolete
0001-meson.build-check-for-all-linux-host_os-combinations.patch
kexec-tools: submit
0003-kexec-ARM-Fix-add_buffer_phys_virt-align-issue.patch upstream
vorbis: mark patch as Inactive-Upstream
grub: mark grub-module-explicitly-keeps-symbole-.module_license.patch
as a workaround
perl: submit the rest of determinism.patch upstream
iptables: submit
0001-configure-Add-option-to-enable-disable-libnfnetlink.patch
upstream
Changqing Li (2):
webkitgtk: fix do_configure error on beaglebone-yocto
webkitgtk: fix do_compile errors on beaglebone-yocto
Enrico Jörns (1):
wic: engine.py: use raw string for escape sequence
Hitendra Prajapati (1):
ruby: fix CVE-2024-27281
Jookia (1):
populate_sdk_ext.bbclass: Fix undefined variable error
Khem Raj (1):
linux-yocto: Enable team net driver
Niko Mauno (1):
dnf/mesa: Fix missing leading whitespace with ':append'
Peter Marko (1):
ncurses: switch to new mirror
Richard Purdie (2):
selftest/cases/runtime_test: Exclude centos-9 from virgl tests
cve-exclusion: Drop the version comparision/warning
Robert Kovacsics (1):
sdk: Fix path length limit to match reserved size
Ross Burton (6):
cpio: mark CVE-2023-7216 as disputed
fribidi: upgrade 1.0.13 -> 1.0.14
gstreamer1.0: skip another known flaky test
libportal: fix rare build race
meson: don't use deprecated pkgconfig variable
curl: skip FTP tests in run-ptest
Wang Mingyu (2):
ed: upgrade 1.20.1 -> 1.20.2
llvm: upgrade 18.1.5 -> 18.1.6
Yi Zhao (2):
libcap-ng: upgrade 0.8.4 -> 0.8.5
libcap-ng-python: upgrade 0.8.4 -> 0.8.5
meta/classes-recipe/populate_sdk_ext.bbclass | 2 +
meta/files/toolchain-shar-extract.sh | 4 +-
meta/lib/oeqa/selftest/cases/runtime_test.py | 2 +-
...icitly-keeps-symbole-.module_license.patch | 2 +-
meta/recipes-core/meta/uninative-tarball.bb | 2 +
meta/recipes-core/ncurses/ncurses.inc | 2 +-
meta/recipes-core/ncurses/ncurses_6.4.bb | 4 +-
meta/recipes-devtools/dnf/dnf_4.19.0.bb | 2 +-
.../llvm/{llvm_18.1.5.bb => llvm_18.1.6.bb} | 2 +-
meta/recipes-devtools/meson/meson_1.3.1.bb | 4 +-
.../perl/files/determinism.patch | 6 +-
.../ruby/ruby/CVE-2024-27281.patch | 97 +++++++++++++++++++
meta/recipes-devtools/ruby/ruby_3.2.2.bb | 1 +
meta/recipes-extended/cpio/cpio_2.15.bb | 1 +
.../ed/{ed_1.20.1.bb => ed_1.20.2.bb} | 2 +-
...ption-to-enable-disable-libnfnetlink.patch | 44 +++++----
...build-race-when-building-GTK-vapi-fi.patch | 49 ++++++++++
.../libportal/libportal_0.7.1.bb | 3 +-
...k-for-all-linux-host_os-combinations.patch | 42 --------
meta/recipes-graphics/mesa/mesa.inc | 3 +-
...Fix-add_buffer_phys_virt-align-issue.patch | 2 +-
.../linux/cve-exclusion_6.6.inc | 18 ++--
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 2 +
.../gstreamer/gstreamer1.0/run-ptest | 9 +-
.../0001-configure-Check-for-clang.patch | 2 +-
...fic-declarations-in-FELighting.h-unn.patch | 44 +++++++++
...icDowncast-adoption-in-platform-code.patch | 65 +++++++++++++
meta/recipes-sato/webkit/webkitgtk_2.44.1.bb | 14 +--
meta/recipes-support/curl/curl/run-ptest | 4 +-
.../{fribidi_1.0.13.bb => fribidi_1.0.14.bb} | 2 +-
...hon-path-when-invoking-py-compile-54.patch | 34 +++++++
.../files/fix-issues-with-swig-4-2.patch | 32 ------
...hon_0.8.4.bb => libcap-ng-python_0.8.5.bb} | 0
meta/recipes-support/libcap-ng/libcap-ng.inc | 4 +-
...{libcap-ng_0.8.4.bb => libcap-ng_0.8.5.bb} | 0
scripts/lib/wic/engine.py | 2 +-
36 files changed, 369 insertions(+), 139 deletions(-)
rename meta/recipes-devtools/llvm/{llvm_18.1.5.bb => llvm_18.1.6.bb} (98%)
create mode 100644 meta/recipes-devtools/ruby/ruby/CVE-2024-27281.patch
rename meta/recipes-extended/ed/{ed_1.20.1.bb => ed_1.20.2.bb} (93%)
create mode 100644 meta/recipes-gnome/libportal/files/0001-meson.build-fix-build-race-when-building-GTK-vapi-fi.patch
delete mode 100644 meta/recipes-graphics/mesa/files/0001-meson.build-check-for-all-linux-host_os-combinations.patch
create mode 100644 meta/recipes-sato/webkit/webkitgtk/0001-Remove-ARM-specific-declarations-in-FELighting.h-unn.patch
create mode 100644 meta/recipes-sato/webkit/webkitgtk/0002-More-dynamicDowncast-adoption-in-platform-code.patch
rename meta/recipes-support/fribidi/{fribidi_1.0.13.bb => fribidi_1.0.14.bb} (89%)
create mode 100644 meta/recipes-support/libcap-ng/files/0001-Fix-python-path-when-invoking-py-compile-54.patch
delete mode 100644 meta/recipes-support/libcap-ng/files/fix-issues-with-swig-4-2.patch
rename meta/recipes-support/libcap-ng/{libcap-ng-python_0.8.4.bb => libcap-ng-python_0.8.5.bb} (100%)
rename meta/recipes-support/libcap-ng/{libcap-ng_0.8.4.bb => libcap-ng_0.8.5.bb} (100%)
--
2.34.1
^ permalink raw reply [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 00/27] Patch review
@ 2024-09-30 1:56 Steve Sakoman
0 siblings, 0 replies; 31+ messages in thread
From: Steve Sakoman @ 2024-09-30 1:56 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, October 1
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/typhoon/#/builders/83/builds/7365
The following changes since commit f888dd911529a828820799a7a1b75dfd3a44847c:
build-appliance-image: Update to scarthgap head revision (2024-09-25 08:06:11 -0700)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
Adrian Freihofer (2):
kernel-fitimage: fix intentation
kernel-fitimage: fix external dtb check
Aleksandar Nikolic (3):
install-buildtools: remove md5 checksum validation
install-buildtools: fix "test installation" step
install-buildtools: update base-url, release and installer version
Alexander Kanavin (1):
pulseaudio, desktop-file-utils: correct freedesktop.org ->
www.freedesktop.org SRC_URI
Bruce Ashfield (11):
linux-yocto/6.6: update to v6.6.36
linux-yocto/6.6: update to v6.6.38
linux-yocto/6.6: update to v6.6.40
linux-yocto/6.6: update to v6.6.43
kernel-devsrc: remove 64 bit vdso cmd files
linux-yocto/6.6: update to v6.6.44
linux-yocto/6.6: update to v6.6.45
linux-yocto/6.6: fix genericarm64 config warning
linux-yocto/6.6: update to v6.6.47
linux-yocto/6.6: update to v6.6.49
linux-yocto/6.6: update to v6.6.50
Deepesh Varatharajan (1):
binutils: stable 2.42 branch updates
Hitendra Prajapati (1):
curl: fix CVE-2024-8096
Jaeyoon Jung (1):
makedevs: Fix issue when rootdir of / is given
Konrad Weihmann (3):
runqemu: keep generating tap devices
testimage: fallback for empty IMAGE_LINK_NAME
testexport: fallback for empty IMAGE_LINK_NAME
Richard Purdie (2):
scripts/install-buildtools: Update to 5.0.3
bitbake.conf: Add truncate to HOSTTOOLS
Victor Kamensky (1):
systemtap: fix systemtap-native build error on Fedora 40
Yi Zhao (1):
rpm: fix expansion of %_libdir in macros
meta/classes-recipe/kernel-fitimage.bbclass | 66 +++---
meta/classes-recipe/testexport.bbclass | 2 +-
meta/classes-recipe/testimage.bbclass | 4 +-
meta/conf/bitbake.conf | 2 +-
.../binutils/binutils-2.42.inc | 2 +-
.../desktop-file-utils_0.27.bb | 2 +-
.../makedevs/makedevs/makedevs.c | 21 +-
...et-libdir-to-CMAKE_INSTALL_FULL_LIBD.patch | 53 +++++
meta/recipes-devtools/rpm/rpm_4.19.1.1.bb | 1 +
meta/recipes-kernel/linux/kernel-devsrc.bb | 1 +
.../linux/linux-yocto-rt_6.6.bb | 6 +-
.../linux/linux-yocto-tiny_6.6.bb | 6 +-
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +--
...gcc-version-compatibility-hack-redux.patch | 32 +++
...e.cxx-gcc-version-compatibility-hack.patch | 52 +++++
.../systemtap/systemtap_git.inc | 2 +
.../pulseaudio/pulseaudio_17.0.bb | 2 +-
.../curl/curl/CVE-2024-8096.patch | 207 ++++++++++++++++++
meta/recipes-support/curl/curl_8.7.1.bb | 1 +
scripts/install-buildtools | 47 ++--
scripts/runqemu | 24 +-
21 files changed, 460 insertions(+), 101 deletions(-)
create mode 100644 meta/recipes-devtools/rpm/files/0001-CMakeLists.txt-set-libdir-to-CMAKE_INSTALL_FULL_LIBD.patch
create mode 100644 meta/recipes-kernel/systemtap/systemtap/0001-elaborate.cxx-gcc-version-compatibility-hack-redux.patch
create mode 100644 meta/recipes-kernel/systemtap/systemtap/0001-elaborate.cxx-gcc-version-compatibility-hack.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2024-8096.patch
--
2.34.1
^ permalink raw reply [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 00/27] Patch review
@ 2024-11-21 21:53 Steve Sakoman
0 siblings, 0 replies; 31+ messages in thread
From: Steve Sakoman @ 2024-11-21 21:53 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for scarthgap and have comments back by
end of day Monday, November 25
Passed a-full on autobuilder:
https://valkyrie.yoctoproject.org/#/builders/29/builds/497
The following changes since commit c9d5a6c480c377399a7dc998f3755e42072e19a6:
libxml-parser-perl: fix do_fetch error (2024-11-13 06:15:28 -0800)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
Alexander Kanavin (2):
package_rpm: use zstd's default compression level
package_rpm: restrict rpm to 4 threads
Bin Lan (1):
lttng-ust: backport patch to fix cmake-multiple-shared-libraries build
error
Changqing Li (1):
sysvinit: backport patch for fixing one issue of pidof
Chen Qi (1):
toolchain-shar-extract.sh: exit when post-relocate-setup.sh fails
Clayton Casciato (1):
uboot-sign: fix concat_dtb arguments
Deepthi Hemraj (1):
binutils: stable 2.42 branch update
Guðni Már Gilbert (2):
shared-mime-info: drop itstool-native from DEPENDS
libpam: drop cracklib from DEPENDS
Hitendra Prajapati (2):
libsoup: fix CVE-2024-52532
ghostscript: upgrade 10.03.1 -> 10.04.0
Jagadeesh Krishnanjanappa (1):
tune-cortexa32: set tune feature as armv8a
Jinfeng Wang (1):
tzdata&tzcode-native: upgrade 2024a -> 2024b
Pavel Zhukov (1):
package_rpm: Check if file exists before open()
Randy MacLeod (1):
systemd: stable update 255.4 -> 255.13
Regis Dargent (1):
udev-extraconf: fix network.sh script did not configure hotplugged
interfaces
Richard Purdie (3):
oeqa/runtime/ssh: Rework ssh timeout
oeqa/runtime/ssh: Fix incorrect timeout fix
qemurunner: Clean up serial_lock handling
Robert Yang (1):
cml1.bbclass: do_diffconfig: Don't override .config with .config.orig
Ross Burton (3):
strace: download release tarballs from GitHub
tcl: skip io-13.6 test case
groff: fix rare build race in hdtbl
Steve Sakoman (2):
webkitgtk: fix erroneous use of unsuported DEBUG_LEVELFLAG variable
llvm: reduce size of -dbg package
Vijay Anusuri (1):
glib-2.0: Backport fix for CVE-2024-52533
Wang Mingyu (1):
wireless-regdb: upgrade 2024.07.04 -> 2024.10.07
meta/classes-global/package_rpm.bbclass | 19 ++-
meta/classes-recipe/cml1.bbclass | 3 +-
meta/classes-recipe/uboot-sign.bbclass | 2 +-
.../include/arm/armv8a/tune-cortexa32.inc | 2 +-
meta/files/toolchain-shar-extract.sh | 4 +
meta/lib/oeqa/runtime/cases/ssh.py | 4 +-
meta/lib/oeqa/utils/qemurunner.py | 11 +-
.../glib-2.0/glib-2.0/CVE-2024-52533.patch | 49 ++++++
.../glib-2.0/gdatetime-test-fail-0001.patch | 72 ++++++++
.../glib-2.0/gdatetime-test-fail-0002.patch | 65 +++++++
.../glib-2.0/gdatetime-test-fail-0003.patch | 63 +++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 4 +
...255.4.bb => systemd-boot-native_255.13.bb} | 0
...d-boot_255.4.bb => systemd-boot_255.13.bb} | 0
meta/recipes-core/systemd/systemd.inc | 2 +-
...1-missing_type.h-add-comparison_fn_t.patch | 7 +-
...k-parse_printf_format-implementation.patch | 13 +-
...tall-dependency-links-at-install-tim.patch | 9 +-
...missing.h-check-for-missing-strndupa.patch | 65 ++++---
...OB_BRACE-and-GLOB_ALTDIRFUNC-is-not-.patch | 14 +-
...005-add-missing-FTW_-macros-for-musl.patch | 7 +-
...06-Use-uintmax_t-for-handling-rlim_t.patch | 11 +-
...T_SYMLINK_NOFOLLOW-flag-to-faccessat.patch | 17 +-
...patible-basename-for-non-glibc-syste.patch | 8 +-
...implment-systemd-sysv-install-for-OE.patch | 5 +-
...uffering-when-writing-to-oom_score_a.patch | 9 +-
...compliant-strerror_r-from-GNU-specif.patch | 13 +-
...definition-of-prctl_mm_map-structure.patch | 7 +-
...-not-disable-buffer-in-writing-files.patch | 59 +++----
.../0013-Handle-__cpu_mask-usage.patch | 7 +-
.../systemd/0014-Handle-missing-gshadow.patch | 9 +-
...l.h-Define-MIPS-ABI-defines-for-musl.patch | 13 +-
...ass-correct-parameters-to-getdents64.patch | 7 +-
.../0017-Adjust-for-musl-headers.patch | 17 +-
...trerror-is-assumed-to-be-GNU-specifi.patch | 9 +-
...util-Make-STRERROR-portable-for-musl.patch | 7 +-
...ake-malloc_trim-conditional-on-glibc.patch | 9 +-
...hared-Do-not-use-malloc_info-on-musl.patch | 7 +-
...22-avoid-missing-LOCK_EX-declaration.patch | 11 +-
.../{systemd_255.4.bb => systemd_255.13.bb} | 0
...rom-Mark-Hindley-which-avoids-cleari.patch | 31 ++++
meta/recipes-core/sysvinit/sysvinit_3.04.bb | 1 +
.../udev/udev-extraconf/network.sh | 32 ----
.../binutils/binutils-2.42.inc | 2 +-
meta/recipes-devtools/llvm/llvm_18.1.6.bb | 2 +
meta/recipes-devtools/strace/strace_6.7.bb | 4 +-
meta/recipes-devtools/tcltk/tcl/run-ptest | 2 +
.../avoid-host-contamination.patch | 6 +-
...ript_10.03.1.bb => ghostscript_10.04.0.bb} | 2 +-
...l-Fix-Savannah-66316-missing-grn-dep.patch | 38 +++++
meta/recipes-extended/groff/groff_1.23.0.bb | 1 +
meta/recipes-extended/pam/libpam_1.5.3.bb | 2 +-
meta/recipes-extended/timezone/timezone.inc | 6 +-
...es-when-rpath-is-stripped-from-in-bu.patch | 161 ++++++++++++++++++
.../0001-Makefile.am-update-rpath-link.patch | 33 ----
meta/recipes-kernel/lttng/lttng-ust_2.13.8.bb | 2 +-
....07.04.bb => wireless-regdb_2024.10.07.bb} | 2 +-
meta/recipes-sato/webkit/webkitgtk_2.44.3.bb | 2 +-
.../libsoup-3.4.4/CVE-2024-52532-0001.patch | 42 +++++
.../libsoup-3.4.4/CVE-2024-52532-0002.patch | 36 ++++
meta/recipes-support/libsoup/libsoup_3.4.4.bb | 5 +-
.../shared-mime-info/shared-mime-info_2.4.bb | 2 +-
62 files changed, 749 insertions(+), 305 deletions(-)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2024-52533.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/gdatetime-test-fail-0001.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/gdatetime-test-fail-0002.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/gdatetime-test-fail-0003.patch
rename meta/recipes-core/systemd/{systemd-boot-native_255.4.bb => systemd-boot-native_255.13.bb} (100%)
rename meta/recipes-core/systemd/{systemd-boot_255.4.bb => systemd-boot_255.13.bb} (100%)
rename meta/recipes-core/systemd/{systemd_255.4.bb => systemd_255.13.bb} (100%)
create mode 100644 meta/recipes-core/sysvinit/sysvinit/0001-Accepted-patch-from-Mark-Hindley-which-avoids-cleari.patch
rename meta/recipes-extended/ghostscript/{ghostscript_10.03.1.bb => ghostscript_10.04.0.bb} (97%)
create mode 100644 meta/recipes-extended/groff/files/0001-hdtbl-Fix-Savannah-66316-missing-grn-dep.patch
create mode 100644 meta/recipes-kernel/lttng/lttng-ust/0001-Fix-Build-examples-when-rpath-is-stripped-from-in-bu.patch
delete mode 100644 meta/recipes-kernel/lttng/lttng-ust/0001-Makefile.am-update-rpath-link.patch
rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2024.07.04.bb => wireless-regdb_2024.10.07.bb} (94%)
create mode 100644 meta/recipes-support/libsoup/libsoup-3.4.4/CVE-2024-52532-0001.patch
create mode 100644 meta/recipes-support/libsoup/libsoup-3.4.4/CVE-2024-52532-0002.patch
--
2.34.1
^ permalink raw reply [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 00/27] Patch review
@ 2026-09-02 5:25 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Yoann Congal
` (26 more replies)
0 siblings, 27 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for scarthgap and have comments back by
end of day Thursday, September 3.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4636
The following changes since commit 310eec2cb646d7d1a3ca99bad7e37495bb418a0d:
build-appliance-image: Update to scarthgap head revision (2026-08-28 09:52:39 +0100)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
for you to fetch changes up to 1b1e13055b4eed838e1411d91dea46de08e1d72f:
patch: Fix CVE-2026-56288 (2026-09-01 17:07:13 +0200)
----------------------------------------------------------------
Emily Vekariya (2):
python3-pyasn1: Fix CVE-2026-59886
python3-pyasn1: Fix CVE-2026-59884
Hemanth Kumar M D (1):
glibc: fix CVE-2026-5435
Hetvi Thakar (5):
wget: Fix CVE-2026-58469
wget: Fix CVE-2026-58471
wget: Fix CVE-2026-58472
patch: Fix CVE-2026-56289
patch: Fix CVE-2026-56288
Jaipaul Cheernam (4):
systemd: Fix CVE-2026-29111
perl: fix CVE-2026-13221
perl: fix CVE-2026-57432
perl: fix CVE-2025-40909
Martin Jansa (1):
socat: fix native build on host with newer glibc
Peter Marko (5):
python3: upgrade 3.12.13 -> 3.12.14
systemd: upgrade 255.21 -> 255.22
libarchive: handle CVE-2026-5121
libarchive: patch CVE-2026-5745
gnutls: set status for CVE-2026-1584
Siddharth Doshi (9):
vim: Security Fix for CVE-2026-55693
vim: Security Fix for CVE-2026-55892
vim: Security Fix for CVE-2026-55895
vim: Security Fix for CVE-2026-57452
vim: Security Fix for CVE-2026-57455
vim: Security Fix for CVE-2026-59856
vim: Security Fix for CVE-2026-59857
vim: Security Fix for CVE-2026-59858
vim: Security Fix for CVE-2026-57456
...ixed-strchr-with-const-for-new-glibc.patch | 38 +
.../socat/socat_1.8.0.0.bb | 1 +
.../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++
meta/recipes-core/glibc/glibc_2.39.bb | 1 +
...55.21.bb => systemd-boot-native_255.22.bb} | 0
...-boot_255.21.bb => systemd-boot_255.22.bb} | 0
meta/recipes-core/systemd/systemd.inc | 2 +-
.../systemd/systemd/CVE-2026-29111-01.patch | 170 +++
.../systemd/systemd/CVE-2026-29111-02.patch | 85 ++
.../systemd/systemd/CVE-2026-29111-03.patch | 106 ++
.../systemd/systemd/CVE-2026-29111-04.patch | 35 +
.../{systemd_255.21.bb => systemd_255.22.bb} | 4 +
.../patch/patch/CVE-2026-56288.patch | 75 +
.../patch/patch/CVE-2026-56289.patch | 36 +
meta/recipes-devtools/patch/patch_2.7.6.bb | 2 +
.../perl-cross/files/CVE-2025-40909-dep.patch | 25 +
.../perl-cross/perlcross_1.6.2.bb | 1 +
.../perl/files/CVE-2025-40909.patch | 412 ++++++
.../perl/files/CVE-2026-13221.patch | 75 +
.../perl/files/CVE-2026-57432-01.patch | 52 +
.../perl/files/CVE-2026-57432-02.patch | 34 +
meta/recipes-devtools/perl/perl_5.38.4.bb | 4 +
.../recipes-devtools/python/python-pyasn1.inc | 2 +
.../python3-pyasn1/CVE-2026-59884.patch | 245 ++++
.../python3-pyasn1/CVE-2026-59886.patch | 252 ++++
...shebang-overflow-on-python-config.py.patch | 2 +-
...-qemu-wrapper-when-gathering-profile.patch | 2 +-
...e-treat-overflow-in-UID-GID-as-failu.patch | 2 +-
.../python/python3/CVE-2025-13462.patch | 142 --
.../python/python3/CVE-2026-11940.patch | 66 -
.../python/python3/CVE-2026-11972.patch | 60 -
.../python/python3/CVE-2026-1502.patch | 113 --
.../python3/CVE-2026-3644_CVE-2026-0672.patch | 154 --
.../python/python3/CVE-2026-4224.patch | 121 --
.../python3/CVE-2026-4519_CVE-2026-4786.patch | 66 -
.../python/python3/CVE-2026-4519_p1.patch | 107 --
.../python/python3/CVE-2026-4519_p2.patch | 159 ---
.../python/python3/CVE-2026-6100.patch | 75 -
.../python/python3/CVE-2026-7210.patch | 148 --
.../python/python3/CVE-2026-9669.patch | 96 --
.../python/python3/makerace.patch | 2 +-
...{python3_3.12.13.bb => python3_3.12.14.bb} | 24 +-
...atch => CVE-2026-4426_CVE-2026-5121.patch} | 1 +
.../libarchive/CVE-2026-5121-02.patch | 1270 +++++++++++++++++
.../libarchive/libarchive/CVE-2026-5745.patch | 39 +
.../libarchive/libarchive_3.7.9.bb | 4 +-
.../wget/CVE-2026-58469-regression_p1.patch | 39 +
.../wget/CVE-2026-58469-regression_p2.patch | 26 +
.../wget/wget/CVE-2026-58469.patch | 53 +
.../wget/wget/CVE-2026-58471.patch | 71 +
.../wget/wget/CVE-2026-58472-regression.patch | 236 +++
.../wget/wget/CVE-2026-58472.patch | 77 +
meta/recipes-extended/wget/wget_1.21.4.bb | 6 +
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 +
.../vim/files/CVE-2026-55693.patch | 88 ++
.../vim/files/CVE-2026-55892.patch | 81 ++
.../vim/files/CVE-2026-55895.patch | 53 +
.../vim/files/CVE-2026-57452.patch | 76 +
.../vim/files/CVE-2026-57455.patch | 72 +
.../vim/files/CVE-2026-57456.patch | 90 ++
.../vim/files/CVE-2026-59856.patch | 103 ++
.../vim/files/CVE-2026-59857.patch | 110 ++
.../vim/files/CVE-2026-59858.patch | 134 ++
meta/recipes-support/vim/vim.inc | 9 +
64 files changed, 4444 insertions(+), 1328 deletions(-)
create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%)
rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%)
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (99%)
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch
rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%)
rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%)
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
^ permalink raw reply [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435 Yoann Congal
` (25 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Martin Jansa <martin.jansa@gmail.com>
Fixes:
../socat-1.8.0.0/filan.c: In function ?printtime?:
../socat-1.8.0.0/filan.c:1065:46: error: assignment of read-only location ?*(const char *)strchr(s, 10)?
1065 | if (strchr(s, '\n')) *strchr(s, '\n') = '\0';
| ^
Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...ixed-strchr-with-const-for-new-glibc.patch | 38 +++++++++++++++++++
.../socat/socat_1.8.0.0.bb | 1 +
2 files changed, 39 insertions(+)
create mode 100644 meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
diff --git a/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch b/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
new file mode 100644
index 00000000000..5a7c19294c4
--- /dev/null
+++ b/meta/recipes-connectivity/socat/files/0001-Fixed-strchr-with-const-for-new-glibc.patch
@@ -0,0 +1,38 @@
+From 3033625d5a67514e3d74021fc39f7fcb542d7f2d Mon Sep 17 00:00:00 2001
+From: Gerhard Rieger <gerhard@dest-unreach.org>
+Date: Wed, 11 Feb 2026 14:06:25 +0100
+Subject: [PATCH] Fixed strchr with const for new glibc
+
+Upstream-Status: Backport [https://repo.or.cz/socat.git/commit/a7058c9340db0bf90bf4372de0ae87ad37f57735]
+Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
+---
+ filan.c | 2 +-
+ xio-ip6.c | 2 +-
+ 2 files changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/filan.c b/filan.c
+index 36def50..e256f74 100644
+--- a/filan.c
++++ b/filan.c
+@@ -1055,7 +1055,7 @@ const char *getfiletypestring(int st_mode) {
+ }
+
+ static int printtime(FILE *outfile, time_t time) {
+- const char *s;
++ char *s;
+
+ if (filan_rawoutput) {
+ fprintf(outfile, "\t"F_time, time);
+diff --git a/xio-ip6.c b/xio-ip6.c
+index bd94bdd..09abdd1 100644
+--- a/xio-ip6.c
++++ b/xio-ip6.c
+@@ -114,7 +114,7 @@ int xioparsenetwork_ip6(
+ struct xiorange *range,
+ const int ai_flags[2])
+ {
+- char *delimpos; /* absolute address of delimiter */
++ const char *delimpos; /* absolute address of delimiter */
+ size_t delimind; /* index of delimiter in string */
+ unsigned int bits; /* netmask bits */
+ char *endptr;
diff --git a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb
index 156fd590aee..1be3a088024 100644
--- a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb
+++ b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb
@@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \
SRC_URI = "http://www.dest-unreach.org/socat/download/socat-${PV}.tar.bz2 \
file://0001-fix-compile-procan.c-failed.patch \
+ file://0001-Fixed-strchr-with-const-for-new-glibc.patch \
file://CVE-2024-54661.patch \
file://CVE-2026-56123.patch \
"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111 Yoann Congal
` (24 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435)
Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy
implementations of TSIG, fixing bug 34033, and partially
fixing bug 34069.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-5435
[2] https://sourceware.org/bugzilla/show_bug.cgi?id=34033
[3] https://sourceware.org/git/?p=glibc.git;a=commit;h=ca44a6609c29a683b03575fa035c6d17aa591e72
Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: This patch will change output of a debug and deprecated function.
Upstream chose to remove the vulnerable implementation instead of
fixing it.
See: https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0011
]
---
.../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++++++++++++++++++
meta/recipes-core/glibc/glibc_2.39.bb | 1 +
2 files changed, 138 insertions(+)
create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
diff --git a/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch b/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
new file mode 100644
index 00000000000..722ec2129ca
--- /dev/null
+++ b/meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
@@ -0,0 +1,137 @@
+From 5d41b8e5aaec3580e4a05d93c5ff2fc69bb3d5a7 Mon Sep 17 00:00:00 2001
+From: Florian Weimer <fweimer@redhat.com>
+Date: Fri, 19 Jun 2026 18:22:20 +0200
+Subject: [PATCH] resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435)
+
+Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy
+implementations of TSIG, fixing bug 34033, and partially
+fixing bug 34069.
+
+Reviewed-by: Carlos O'Donell <carlos@redhat.com>
+Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
+
+CVE: CVE-2026-5435
+Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=ca44a6609c29a683b03575fa035c6d17aa591e72]
+
+Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
+---
+ resolv/ns_print.c | 96 -----------------------------------------------
+ 1 file changed, 96 deletions(-)
+
+diff --git a/resolv/ns_print.c b/resolv/ns_print.c
+index cef2212fd2..882a86e58e 100644
+--- a/resolv/ns_print.c
++++ b/resolv/ns_print.c
+@@ -434,96 +434,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen,
+ break;
+ }
+
+- case ns_t_cert: {
+- u_int c_type, key_tag, alg;
+- int n;
+- unsigned int siz;
+- char base64_cert[8192], tmp[40];
+- const char *leader;
+-
+- c_type = ns_get16(rdata); rdata += NS_INT16SZ;
+- key_tag = ns_get16(rdata); rdata += NS_INT16SZ;
+- alg = (u_int) *rdata++;
+-
+- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg));
+- T(addstr(tmp, len, &buf, &buflen));
+- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */
+- if (siz > sizeof(base64_cert) * 3/4) {
+- const char *str = "record too long to print";
+- T(addstr(str, strlen(str), &buf, &buflen));
+- }
+- else {
+- len = b64_ntop(rdata, edata-rdata, base64_cert, siz);
+-
+- if (len < 0)
+- goto formerr;
+- else if (len > 15) {
+- T(addstr(" (", 2, &buf, &buflen));
+- leader = "\n\t\t";
+- spaced = 0;
+- }
+- else
+- leader = " ";
+-
+- for (n = 0; n < len; n += 48) {
+- T(addstr(leader, strlen(leader),
+- &buf, &buflen));
+- T(addstr(base64_cert + n, MIN(len - n, 48),
+- &buf, &buflen));
+- }
+- if (len > 15)
+- T(addstr(" )", 2, &buf, &buflen));
+- }
+- break;
+- }
+-
+- case ns_t_tkey: {
+- /* KJD - need to complete this */
+- u_long t;
+- int mode, err, keysize;
+-
+- /* Algorithm name. */
+- T(addname(msg, msglen, &rdata, origin, &buf, &buflen));
+- T(addstr(" ", 1, &buf, &buflen));
+-
+- /* Inception. */
+- t = ns_get32(rdata); rdata += NS_INT32SZ;
+- len = SPRINTF((tmp, "%lu ", t));
+- T(addstr(tmp, len, &buf, &buflen));
+-
+- /* Expiration. */
+- t = ns_get32(rdata); rdata += NS_INT32SZ;
+- len = SPRINTF((tmp, "%lu ", t));
+- T(addstr(tmp, len, &buf, &buflen));
+-
+- /* Mode , Error, Key Size. */
+- /* Priority, Weight, Port. */
+- mode = ns_get16(rdata); rdata += NS_INT16SZ;
+- err = ns_get16(rdata); rdata += NS_INT16SZ;
+- keysize = ns_get16(rdata); rdata += NS_INT16SZ;
+- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize));
+- T(addstr(tmp, len, &buf, &buflen));
+-
+- /* XXX need to dump key, print otherdata length & other data */
+- break;
+- }
+-
+- case ns_t_tsig: {
+- /* BEW - need to complete this */
+- int n;
+-
+- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen));
+- T(addstr(" ", 1, &buf, &buflen));
+- rdata += 8; /*%< time */
+- n = ns_get16(rdata); rdata += INT16SZ;
+- rdata += n; /*%< sig */
+- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */
+- sprintf(buf, "%d", ns_get16(rdata));
+- rdata += INT16SZ;
+- addlen(strlen(buf), &buf, &buflen);
+- break;
+- }
+-
+ case ns_t_a6: {
+ struct in6_addr a;
+ int pbyte, pbit;
+@@ -557,12 +467,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen,
+ break;
+ }
+
+- case ns_t_opt: {
+- len = SPRINTF((tmp, "%u bytes", class));
+- T(addstr(tmp, len, &buf, &buflen));
+- break;
+- }
+-
+ default:
+ snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type);
+ comment = errbuf;
+--
+2.49.0
+
diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb
index f6be1b5fc93..88ad5e44e80 100644
--- a/meta/recipes-core/glibc/glibc_2.39.bb
+++ b/meta/recipes-core/glibc/glibc_2.39.bb
@@ -56,6 +56,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
file://0022-Avoid-hardcoded-build-time-paths-in-the-output-binar.patch \
file://0023-qemu-stale-process.patch \
file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \
+ file://0024-CVE-2026-5435.patch \
"
S = "${WORKDIR}/git"
B = "${WORKDIR}/build-${TARGET_SYS}"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886 Yoann Congal
` (23 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Backport patches from upstream systemd to fix CVE-2026-29111, where
systemd (as PID 1) hits an assert and freezes execution when an
unprivileged IPC API call is made with spurious data.
Pick patches from [1], [2], [3] and [4] as referenced in [5].
Note: As scarthgap is using 255 version picked fixes from 257
[1] https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6
[2] https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69
[3] https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412
[4] https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f
[5] https://security-tracker.debian.org/tracker/CVE-2026-29111
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../systemd/systemd/CVE-2026-29111-01.patch | 170 ++++++++++++++++++
.../systemd/systemd/CVE-2026-29111-02.patch | 85 +++++++++
.../systemd/systemd/CVE-2026-29111-03.patch | 106 +++++++++++
.../systemd/systemd/CVE-2026-29111-04.patch | 35 ++++
meta/recipes-core/systemd/systemd_255.21.bb | 4 +
5 files changed, 400 insertions(+)
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
create mode 100644 meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
new file mode 100644
index 00000000000..4f6ef76aa98
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-01.patch
@@ -0,0 +1,170 @@
+From 284fd279f9e9c199982aea51aee59a02e90a2eda Mon Sep 17 00:00:00 2001
+From: Lennart Poettering <lennart@poettering.net>
+Date: Mon, 19 May 2025 12:58:52 +0200
+Subject: [PATCH 1/4] path-util: add flavour of path_startswith() that leaves a
+ leading slash in place
+
+(cherry picked from commit ee19edbb9f3455db3f750089082f3e5a925e3a0c)
+
+Note: The test uses assert_se(streq_ptr()) instead of the upstream
+ASSERT_STREQ() macro because ASSERT_STREQ was introduced in systemd v256
+and is not available in v255.
+
+CVE: CVE-2026-29111
+Upstream-Status: Backport [https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/basic/fs-util.c | 2 +-
+ src/basic/mkdir.c | 2 +-
+ src/basic/path-util.c | 39 ++++++++++++++++++++++++++++-----------
+ src/basic/path-util.h | 10 ++++++++--
+ src/test/test-path-util.c | 16 ++++++++++++++++
+ 5 files changed, 54 insertions(+), 15 deletions(-)
+
+diff --git a/src/basic/fs-util.c b/src/basic/fs-util.c
+index 5bc7d2f95b..4633a5cd72 100644
+--- a/src/basic/fs-util.c
++++ b/src/basic/fs-util.c
+@@ -65,7 +65,7 @@ int rmdir_parents(const char *path, const char *stop) {
+ assert(*slash == '/');
+ *slash = '\0';
+
+- if (path_startswith_full(stop, p, /* accept_dot_dot= */ false))
++ if (path_startswith_full(stop, p, /* flags= */ 0))
+ return 0;
+
+ if (rmdir(p) < 0 && errno != ENOENT)
+diff --git a/src/basic/mkdir.c b/src/basic/mkdir.c
+index c770e5ed32..7bc73361a5 100644
+--- a/src/basic/mkdir.c
++++ b/src/basic/mkdir.c
+@@ -155,7 +155,7 @@ int mkdir_parents_internal(const char *prefix, const char *path, mode_t mode, ui
+ assert(_mkdirat != mkdirat);
+
+ if (prefix) {
+- p = path_startswith_full(path, prefix, /* accept_dot_dot= */ false);
++ p = path_startswith_full(path, prefix, /* flags= */ 0);
+ if (!p)
+ return -ENOTDIR;
+ } else
+diff --git a/src/basic/path-util.c b/src/basic/path-util.c
+index 6810bf66aa..e73f5d708e 100644
+--- a/src/basic/path-util.c
++++ b/src/basic/path-util.c
+@@ -403,8 +403,8 @@ char* path_simplify_full(char *path, PathSimplifyFlags flags) {
+ return path;
+ }
+
+-char* path_startswith_full(const char *path, const char *prefix, bool accept_dot_dot) {
+- assert(path);
++char* path_startswith_full(const char *original_path, const char *prefix, PathStartWithFlags flags) {
++ assert(original_path);
+ assert(prefix);
+
+ /* Returns a pointer to the start of the first component after the parts matched by
+@@ -417,28 +417,45 @@ char* path_startswith_full(const char *path, const char *prefix, bool accept_dot
+ * Returns NULL otherwise.
+ */
+
++ const char *path = original_path;
++
+ if ((path[0] == '/') != (prefix[0] == '/'))
+ return NULL;
+
+ for (;;) {
+ const char *p, *q;
+- int r, k;
++ int m, n;
+
+- r = path_find_first_component(&path, accept_dot_dot, &p);
+- if (r < 0)
++ m = path_find_first_component(&path, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &p);
++ if (m < 0)
+ return NULL;
+
+- k = path_find_first_component(&prefix, accept_dot_dot, &q);
+- if (k < 0)
++ n = path_find_first_component(&prefix, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &q);
++ if (n < 0)
+ return NULL;
+
+- if (k == 0)
+- return (char*) (p ?: path);
++ if (n == 0) {
++ if (!p)
++ p = path;
++
++ if (FLAGS_SET(flags, PATH_STARTSWITH_RETURN_LEADING_SLASH)) {
++
++ if (p <= original_path)
++ return NULL;
++
++ p--;
++
++ if (*p != '/')
++ return NULL;
++ }
++
++ return (char*) p;
++ }
+
+- if (r != k)
++ if (m != n)
+ return NULL;
+
+- if (!strneq(p, q, r))
++ if (!strneq(p, q, m))
+ return NULL;
+ }
+ }
+diff --git a/src/basic/path-util.h b/src/basic/path-util.h
+index 6d943e967f..e0ec05f4db 100644
+--- a/src/basic/path-util.h
++++ b/src/basic/path-util.h
+@@ -53,9 +53,15 @@ int safe_getcwd(char **ret);
+ int path_make_absolute_cwd(const char *p, char **ret);
+ int path_make_relative(const char *from, const char *to, char **ret);
+ int path_make_relative_parent(const char *from_child, const char *to, char **ret);
+-char* path_startswith_full(const char *path, const char *prefix, bool accept_dot_dot) _pure_;
++
++typedef enum PathStartWithFlags {
++ PATH_STARTSWITH_ACCEPT_DOT_DOT = 1U << 0,
++ PATH_STARTSWITH_RETURN_LEADING_SLASH = 1U << 1,
++} PathStartWithFlags;
++
++char* path_startswith_full(const char *path, const char *prefix, PathStartWithFlags flags) _pure_;
+ static inline char* path_startswith(const char *path, const char *prefix) {
+- return path_startswith_full(path, prefix, true);
++ return path_startswith_full(path, prefix, PATH_STARTSWITH_ACCEPT_DOT_DOT);
+ }
+
+ int path_compare(const char *a, const char *b) _pure_;
+diff --git a/src/test/test-path-util.c b/src/test/test-path-util.c
+index f5a425689a..71056b08c1 100644
+--- a/src/test/test-path-util.c
++++ b/src/test/test-path-util.c
+@@ -754,6 +754,22 @@ TEST(path_startswith) {
+ test_path_startswith_one("/foo/bar/barfoo/", "/fo", NULL, NULL);
+ }
+
++static void test_path_startswith_return_leading_slash_one(const char *path, const char *prefix, const char *expected) {
++ const char *p;
++
++ log_debug("/* %s(%s, %s) */", __func__, path, prefix);
++
++ p = path_startswith_full(path, prefix, PATH_STARTSWITH_RETURN_LEADING_SLASH);
++ assert_se(streq_ptr(p, expected));
++}
++
++TEST(path_startswith_return_leading_slash) {
++ test_path_startswith_return_leading_slash_one("/foo/bar", "/", "/foo/bar");
++ test_path_startswith_return_leading_slash_one("/foo/bar", "/foo", "/bar");
++ test_path_startswith_return_leading_slash_one("/foo/bar", "/foo/bar", NULL);
++ test_path_startswith_return_leading_slash_one("/foo/bar/", "/foo/bar", "/");
++}
++
+ static void test_prefix_root_one(const char *r, const char *p, const char *expected) {
+ _cleanup_free_ char *s = NULL;
+ const char *t;
+--
+2.43.0
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
new file mode 100644
index 00000000000..9ab94000e65
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-02.patch
@@ -0,0 +1,85 @@
+From ed86ee8a7cc82fe1c68e3fb17be71c9c8e62ca87 Mon Sep 17 00:00:00 2001
+From: Lennart Poettering <lennart@poettering.net>
+Date: Fri, 23 May 2025 06:45:40 +0200
+Subject: [PATCH 2/4] path-util: invert PATH_STARTSWITH_ACCEPT_DOT_DOT flag
+
+As requested: https://github.com/systemd/systemd/pull/37572#pullrequestreview-2861928094
+
+(cherry picked from commit ceed11e465f1c8efff1931412a85924d9de7c08d)
+
+CVE: CVE-2026-29111
+Upstream-Status: Backport [https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/basic/fs-util.c | 2 +-
+ src/basic/mkdir.c | 2 +-
+ src/basic/path-util.c | 4 ++--
+ src/basic/path-util.h | 4 ++--
+ 4 files changed, 6 insertions(+), 6 deletions(-)
+
+diff --git a/src/basic/fs-util.c b/src/basic/fs-util.c
+index 4633a5cd72..21cd6ddcde 100644
+--- a/src/basic/fs-util.c
++++ b/src/basic/fs-util.c
+@@ -65,7 +65,7 @@ int rmdir_parents(const char *path, const char *stop) {
+ assert(*slash == '/');
+ *slash = '\0';
+
+- if (path_startswith_full(stop, p, /* flags= */ 0))
++ if (path_startswith_full(stop, p, PATH_STARTSWITH_REFUSE_DOT_DOT))
+ return 0;
+
+ if (rmdir(p) < 0 && errno != ENOENT)
+diff --git a/src/basic/mkdir.c b/src/basic/mkdir.c
+index 7bc73361a5..8f14c47214 100644
+--- a/src/basic/mkdir.c
++++ b/src/basic/mkdir.c
+@@ -155,7 +155,7 @@ int mkdir_parents_internal(const char *prefix, const char *path, mode_t mode, ui
+ assert(_mkdirat != mkdirat);
+
+ if (prefix) {
+- p = path_startswith_full(path, prefix, /* flags= */ 0);
++ p = path_startswith_full(path, prefix, PATH_STARTSWITH_REFUSE_DOT_DOT);
+ if (!p)
+ return -ENOTDIR;
+ } else
+diff --git a/src/basic/path-util.c b/src/basic/path-util.c
+index e73f5d708e..a65a5c32f6 100644
+--- a/src/basic/path-util.c
++++ b/src/basic/path-util.c
+@@ -426,11 +426,11 @@ char* path_startswith_full(const char *original_path, const char *prefix, PathSt
+ const char *p, *q;
+ int m, n;
+
+- m = path_find_first_component(&path, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &p);
++ m = path_find_first_component(&path, !FLAGS_SET(flags, PATH_STARTSWITH_REFUSE_DOT_DOT), &p);
+ if (m < 0)
+ return NULL;
+
+- n = path_find_first_component(&prefix, FLAGS_SET(flags, PATH_STARTSWITH_ACCEPT_DOT_DOT), &q);
++ n = path_find_first_component(&prefix, !FLAGS_SET(flags, PATH_STARTSWITH_REFUSE_DOT_DOT), &q);
+ if (n < 0)
+ return NULL;
+
+diff --git a/src/basic/path-util.h b/src/basic/path-util.h
+index e0ec05f4db..11a1078df9 100644
+--- a/src/basic/path-util.h
++++ b/src/basic/path-util.h
+@@ -55,13 +55,13 @@ int path_make_relative(const char *from, const char *to, char **ret);
+ int path_make_relative_parent(const char *from_child, const char *to, char **ret);
+
+ typedef enum PathStartWithFlags {
+- PATH_STARTSWITH_ACCEPT_DOT_DOT = 1U << 0,
++ PATH_STARTSWITH_REFUSE_DOT_DOT = 1U << 0,
+ PATH_STARTSWITH_RETURN_LEADING_SLASH = 1U << 1,
+ } PathStartWithFlags;
+
+ char* path_startswith_full(const char *path, const char *prefix, PathStartWithFlags flags) _pure_;
+ static inline char* path_startswith(const char *path, const char *prefix) {
+- return path_startswith_full(path, prefix, PATH_STARTSWITH_ACCEPT_DOT_DOT);
++ return path_startswith_full(path, prefix, 0);
+ }
+
+ int path_compare(const char *a, const char *b) _pure_;
+--
+2.43.0
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
new file mode 100644
index 00000000000..8b9b4d4075c
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-03.patch
@@ -0,0 +1,106 @@
+From 7a1749753b4853866f90ef25d48192e4d1563543 Mon Sep 17 00:00:00 2001
+From: Mike Yuan <me@yhndnzj.com>
+Date: Thu, 26 Feb 2026 11:06:00 +0100
+Subject: [PATCH 3/4] core/cgroup: avoid one unnecessary strjoina()
+
+(cherry picked from commit 42aee39107fbdd7db1ccd402a2151822b2805e9f)
+(cherry picked from commit 80acea4ef80a4bb78560ed970c34952299b890d6)
+(cherry picked from commit b5fd14693057e5f2c9b4a49603be64ec3608ff6c)
+
+Note: This backport uses u->cgroup_path directly instead of the upstream
+CGroupRuntime *crt / crt->cgroup_path pattern because the CGroupRuntime
+struct was introduced in systemd v256 (commit 1d9cc876). In v255, the
+cgroup_path is still a direct member of the Unit struct.
+
+CVE: CVE-2026-29111
+Upstream-Status: Backport [https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/core/cgroup.c | 27 +++++++++++++--------------
+ 1 file changed, 13 insertions(+), 14 deletions(-)
+
+diff --git a/src/core/cgroup.c b/src/core/cgroup.c
+index d398655b0a..e5e7f032c2 100644
+--- a/src/core/cgroup.c
++++ b/src/core/cgroup.c
+@@ -2568,12 +2568,13 @@ static int unit_update_cgroup(
+ return 0;
+ }
+
+-static int unit_attach_pid_to_cgroup_via_bus(Unit *u, pid_t pid, const char *suffix_path) {
++static int unit_attach_pid_to_cgroup_via_bus(Unit *u, const char *cgroup_path, pid_t pid) {
+ _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
+- char *pp;
+ int r;
+
+ assert(u);
++ assert(cgroup_path);
++ assert(pid_is_valid(pid));
+
+ if (MANAGER_IS_SYSTEM(u->manager))
+ return -EINVAL;
+@@ -2581,17 +2582,13 @@ static int unit_attach_pid_to_cgroup_via_bus(Unit *u, pid_t pid, const char *suf
+ if (!u->manager->system_bus)
+ return -EIO;
+
+- if (!u->cgroup_path)
+- return -EINVAL;
+-
+ /* Determine this unit's cgroup path relative to our cgroup root */
+- pp = path_startswith(u->cgroup_path, u->manager->cgroup_root);
++ const char *pp = path_startswith_full(cgroup_path,
++ u->manager->cgroup_root,
++ PATH_STARTSWITH_RETURN_LEADING_SLASH|PATH_STARTSWITH_REFUSE_DOT_DOT);
+ if (!pp)
+ return -EINVAL;
+
+- pp = strjoina("/", pp, suffix_path);
+- path_simplify(pp);
+-
+ r = bus_call_method(u->manager->system_bus,
+ bus_systemd_mgr,
+ "AttachProcessesToUnit",
+@@ -2630,8 +2627,10 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) {
+ return r;
+
+ if (isempty(suffix_path))
+- p = u->cgroup_path;
++ p = empty_to_root(u->cgroup_path);
+ else {
++ assert(path_is_absolute(suffix_path));
++
+ joined = path_join(u->cgroup_path, suffix_path);
+ if (!joined)
+ return -ENOMEM;
+@@ -2649,7 +2648,7 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) {
+ * before we use it */
+ r = pidref_verify(pid);
+ if (r < 0) {
+- log_unit_info_errno(u, r, "PID " PID_FMT " vanished before we could move it to target cgroup '%s', skipping: %m", pid->pid, empty_to_root(p));
++ log_unit_info_errno(u, r, "PID " PID_FMT " vanished before we could move it to target cgroup '%s', skipping: %m", pid->pid, p);
+ continue;
+ }
+
+@@ -2660,7 +2659,7 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) {
+
+ log_unit_full_errno(u, again ? LOG_DEBUG : LOG_INFO, r,
+ "Couldn't move process "PID_FMT" to%s requested cgroup '%s': %m",
+- pid->pid, again ? " directly" : "", empty_to_root(p));
++ pid->pid, again ? " directly" : "", p);
+
+ if (again) {
+ int z;
+@@ -2670,9 +2669,9 @@ int unit_attach_pids_to_cgroup(Unit *u, Set *pids, const char *suffix_path) {
+ * Since it's more privileged it might be able to move the process across the
+ * leaves of a subtree whose top node is not owned by us. */
+
+- z = unit_attach_pid_to_cgroup_via_bus(u, pid->pid, suffix_path);
++ z = unit_attach_pid_to_cgroup_via_bus(u, p, pid->pid);
+ if (z < 0)
+- log_unit_info_errno(u, z, "Couldn't move process "PID_FMT" to requested cgroup '%s' (directly or via the system bus): %m", pid->pid, empty_to_root(p));
++ log_unit_info_errno(u, z, "Couldn't move process "PID_FMT" to requested cgroup '%s' (directly or via the system bus): %m", pid->pid, p);
+ else {
+ if (ret >= 0)
+ ret++; /* Count successful additions */
+--
+2.43.0
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch b/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
new file mode 100644
index 00000000000..ebf2ba9d5b2
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-29111-04.patch
@@ -0,0 +1,35 @@
+From 0d2c41d0f024088a275ac0c02d50205c800dec8a Mon Sep 17 00:00:00 2001
+From: Mike Yuan <me@yhndnzj.com>
+Date: Thu, 26 Feb 2026 11:06:34 +0100
+Subject: [PATCH 4/4] core: validate input cgroup path more prudently
+
+(cherry picked from commit efa6ba2ab625aaa160ac435a09e6482fc63bdbe8)
+(cherry picked from commit 3cee294fe8cf4fa0eff933ab21416d099942cabd)
+(cherry picked from commit 1d22f706bd04f45f8422e17fbde3f56ece17758a)
+
+CVE: CVE-2026-29111
+Upstream-Status: Backport [https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ src/core/dbus-manager.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/src/core/dbus-manager.c b/src/core/dbus-manager.c
+index c7372ca033..cb84ba9866 100644
+--- a/src/core/dbus-manager.c
++++ b/src/core/dbus-manager.c
+@@ -646,6 +646,12 @@ static int method_get_unit_by_control_group(sd_bus_message *message, void *userd
+ if (r < 0)
+ return r;
+
++ if (!path_is_absolute(cgroup))
++ return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Control group path is not absolute: %s", cgroup);
++
++ if (!path_is_normalized(cgroup))
++ return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Control group path is not normalized: %s", cgroup);
++
+ u = manager_get_unit_by_cgroup(m, cgroup);
+ if (!u)
+ return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_UNIT,
+--
+2.43.0
diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.21.bb
index 9c5f8af240a..e5a0fd91700 100644
--- a/meta/recipes-core/systemd/systemd_255.21.bb
+++ b/meta/recipes-core/systemd/systemd_255.21.bb
@@ -33,6 +33,10 @@ SRC_URI += " \
file://CVE-2026-40225-02.patch \
file://CVE-2026-40226-01.patch \
file://CVE-2026-40226-02.patch \
+ file://CVE-2026-29111-01.patch \
+ file://CVE-2026-29111-02.patch \
+ file://CVE-2026-29111-03.patch \
+ file://CVE-2026-29111-04.patch \
"
# patches needed by musl
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884 Yoann Congal
` (22 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Emily Vekariya <evekariy@cisco.com>
The univ.Real type converts its mantissa, base, and exponent to a Python
float using exact big-integer exponentiation. A BER, CER, or DER encoded
REAL value only a few bytes long can carry a very large exponent, causing
float conversion through prettyPrint(), str(), comparison, arithmetic,
int(), or an explicit float() call to consume excessive CPU and memory and
hang applications that decode untrusted ASN.1 data and then print, log, or
compare the decoded objects.
scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in
all versions before 0.6.4.
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59886
Signed-off-by: Emily Vekariya <evekariy@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../recipes-devtools/python/python-pyasn1.inc | 1 +
.../python3-pyasn1/CVE-2026-59886.patch | 252 ++++++++++++++++++
2 files changed, 253 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc
index 96b4a3b52a6..1780ee1d888 100644
--- a/meta/recipes-devtools/python/python-pyasn1.inc
+++ b/meta/recipes-devtools/python/python-pyasn1.inc
@@ -19,6 +19,7 @@ inherit ptest
SRC_URI += " \
file://run-ptest \
file://CVE-2026-23490.patch \
+ file://CVE-2026-59886.patch \
"
RDEPENDS:${PN}-ptest += " \
diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
new file mode 100644
index 00000000000..80468c6a5e8
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59886.patch
@@ -0,0 +1,252 @@
+From 9b89b511a7284f17ef3a2de6d05fbf6030133abb Mon Sep 17 00:00:00 2001
+From: Simon Pichugin <simon.pichugin@gmail.com>
+Date: Wed, 8 Jul 2026 17:32:09 -0700
+Subject: [PATCH] Merge commit from fork
+
+CVE: CVE-2026-59886
+Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886]
+
+(cherry picked from commit e60c691cb91addb8fcefa2f537e85ede6fb1e886)
+Signed-off-by: Emily Vekariya <evekariy@cisco.com>
+---
+ pyasn1/type/univ.py | 21 +++++++++----
+ tests/codec/ber/test_decoder.py | 53 +++++++++++++++++++++++++++------
+ tests/codec/cer/test_decoder.py | 10 +++++++
+ tests/codec/der/test_decoder.py | 19 ++++++++++++
+ tests/type/test_univ.py | 40 +++++++++++++++++++++++++
+ 5 files changed, 129 insertions(+), 14 deletions(-)
+
+diff --git a/pyasn1/type/univ.py b/pyasn1/type/univ.py
+index c5d0778..adff2df 100644
+--- a/pyasn1/type/univ.py
++++ b/pyasn1/type/univ.py
+@@ -1318,7 +1318,7 @@ class Real(base.SimpleAsn1Type):
+ def __normalizeBase10(value):
+ m, b, e = value
+ while m and m % 10 == 0:
+- m /= 10
++ m //= 10
+ e += 1
+ return m, b, e
+
+@@ -1457,10 +1457,21 @@ class Real(base.SimpleAsn1Type):
+ def __float__(self):
+ if self._value in self._inf:
+ return self._value
+- else:
+- return float(
+- self._value[0] * pow(self._value[1], self._value[2])
+- )
++
++ mantissa, base, exponent = self._value
++
++ if not mantissa:
++ return 0.0
++
++ if base == 2:
++ return math.ldexp(float(mantissa), exponent)
++
++ # base is 10 (prettyIn() rejects everything else); refuse to
++ # materialize astronomically large integers via pow()
++ if exponent > sys.float_info.max_10_exp:
++ raise OverflowError('Real value too large to convert to float')
++
++ return float(mantissa * pow(base, exponent))
+
+ def __abs__(self):
+ return self.clone(abs(float(self)))
+diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py
+index f033dfd..f6ff7b0 100644
+--- a/tests/codec/ber/test_decoder.py
++++ b/tests/codec/ber/test_decoder.py
+@@ -21,6 +21,7 @@ from pyasn1.type import univ
+ from pyasn1.type import char
+ from pyasn1.codec import streaming
+ from pyasn1.codec.ber import decoder
++from pyasn1.codec.ber import encoder
+ from pyasn1.codec.ber import eoo
+ from pyasn1.compat.octets import ints2octs, str2octs, null
+ from pyasn1 import error
+@@ -547,17 +548,51 @@ class RealDecoderTestCase(BaseTestCase):
+ ints2octs((9, 4, 161, 255, 1, 3))
+ ) == (univ.Real((3, 2, -1020)), null)
+
+-# TODO: this requires Real type comparison fix
++ def testBin6(self): # large exponent, base = 16
++ value, rest = decoder.decode(
++ bytes((9, 5, 162, 0, 255, 255, 1))
++ )
++
++ assert tuple(value) == (1, 2, 262140)
++ assert rest == b''
++
++ def testBin7(self): # large exponent in 4-octet form, base = 16
++ value, rest = decoder.decode(
++ bytes((9, 7, 227, 4, 1, 35, 69, 103, 1))
++ )
+
+-# def testBin6(self):
+-# assert decoder.decode(
+-# ints2octs((9, 5, 162, 0, 255, 255, 1))
+-# ) == (univ.Real((1, 2, 262140)), null)
++ assert tuple(value) == (-1, 2, 76354972)
++ assert rest == b''
++
++ def testLargeBinaryRoundTrip(self):
++ substrate = encoder.encode(univ.Real((-1, 2, 76354972)))
++ value, rest = decoder.decode(substrate)
++
++ assert tuple(value) == (-1, 2, 76354972)
++ assert rest == b''
++
++ def testLongFormBinaryRealExponentLength(self):
++ value, rest = decoder.decode(
++ bytes((9, 6, 0x83, 3, 0x0f, 0x42, 0x40, 1))
++ )
+
+-# def testBin7(self):
+-# assert decoder.decode(
+-# ints2octs((9, 7, 227, 4, 1, 35, 69, 103, 1))
+-# ) == (univ.Real((-1, 2, 76354972)), null)
++ assert tuple(value) == (1, 2, 1000000)
++ assert rest == b''
++
++ def testLargeBinaryPrettyPrintOverflow(self):
++ value, rest = decoder.decode(
++ b'\t\t\xeb\x060662.666\xd0B\x00\x00\x00\x00\x00\x00\x00'
++ )
++
++ assert value.prettyPrint() == '<overflow>'
++ assert rest == b'6\xd0B\x00\x00\x00\x00\x00\x00\x00'
++
++ try:
++ float(value)
++ except OverflowError:
++ pass
++ else:
++ assert 0, '__float__() tolerated overflow'
+
+ def testPlusInf(self):
+ assert decoder.decode(
+diff --git a/tests/codec/cer/test_decoder.py b/tests/codec/cer/test_decoder.py
+index 133affd..3d27194 100644
+--- a/tests/codec/cer/test_decoder.py
++++ b/tests/codec/cer/test_decoder.py
+@@ -15,6 +15,7 @@ from pyasn1.type import opentype
+ from pyasn1.type import univ
+ from pyasn1.codec.cer import decoder
+ from pyasn1.compat.octets import ints2octs, str2octs, null
++from pyasn1.codec.cer import encoder
+ from pyasn1.error import PyAsn1Error
+
+
+@@ -66,6 +67,15 @@ class OctetStringDecoderTestCase(BaseTestCase):
+ # TODO: test failures on short chunked and long unchunked substrate samples
+
+
++class RealDecoderTestCase(BaseTestCase):
++ def testLargeBinaryRoundTrip(self):
++ substrate = encoder.encode(univ.Real((-1, 2, 76354972)))
++ value, rest = decoder.decode(substrate)
++
++ assert tuple(value) == (-1, 2, 76354972)
++ assert rest == b''
++
++
+ class SequenceDecoderWithUntaggedOpenTypesTestCase(BaseTestCase):
+ def setUp(self):
+ openType = opentype.OpenType(
+diff --git a/tests/codec/der/test_decoder.py b/tests/codec/der/test_decoder.py
+index 5bc9deb..553563c 100644
+--- a/tests/codec/der/test_decoder.py
++++ b/tests/codec/der/test_decoder.py
+@@ -15,6 +15,7 @@ from pyasn1.type import opentype
+ from pyasn1.type import univ
+ from pyasn1.codec.der import decoder
+ from pyasn1.compat.octets import ints2octs, null
++from pyasn1.codec.der import encoder
+ from pyasn1.error import PyAsn1Error
+
+
+@@ -72,6 +73,24 @@ class OctetStringDecoderTestCase(BaseTestCase):
+ assert 0, 'chunked encoding tolerated'
+
+
++class RealDecoderTestCase(BaseTestCase):
++ def testCanonicalLargeBinaryReal(self):
++ substrate = encoder.encode(univ.Real((1, 2, 1000000)))
++ assert substrate == bytes((9, 5, 0x82, 0x0f, 0x42, 0x40, 1))
++
++ value, rest = decoder.decode(substrate)
++
++ assert tuple(value) == (1, 2, 1000000)
++ assert rest == b''
++
++ def testLargeBinaryRoundTrip(self):
++ substrate = encoder.encode(univ.Real((-1, 2, 76354972)))
++ value, rest = decoder.decode(substrate)
++
++ assert tuple(value) == (-1, 2, 76354972)
++ assert rest == b''
++
++
+ class SequenceDecoderWithUntaggedOpenTypesTestCase(BaseTestCase):
+ def setUp(self):
+ openType = opentype.OpenType(
+diff --git a/tests/type/test_univ.py b/tests/type/test_univ.py
+index 8aec183..bc21c37 100644
+--- a/tests/type/test_univ.py
++++ b/tests/type/test_univ.py
+@@ -780,9 +780,49 @@ class RealTestCase(BaseTestCase):
+ def testFloat(self):
+ assert float(univ.Real(4.0)) == 4.0, '__float__() fails'
+
++ def testFloatBase10Precision(self):
++ assert float(univ.Real((3, 10, 23))) == 3e23, '__float__() lost base-10 behavior'
++
++ def testFloatOverflow(self):
++ try:
++ float(univ.Real((1, 2, 1000000)))
++ except OverflowError:
++ pass
++ else:
++ assert 0, '__float__() tolerated overflow'
++
++ assert univ.Real((1, 2, 1000000)).prettyPrint() == '<overflow>'
++
++ def testFloatUnderflow(self):
++ assert float(univ.Real((1, 2, -1000000))) == 0.0, '__float__() failed underflow'
++
++ def testFloatZeroMantissa(self):
++ assert float(univ.Real((0, 10, 1000000000))) == 0.0, '__float__() failed zero mantissa'
++ assert float(univ.Real((0, 2, 1000000000))) == 0.0, '__float__() failed zero mantissa'
++
++ def testFloatBase10Overflow(self):
++ try:
++ float(univ.Real((1, 10, sys.float_info.max_10_exp + 1)))
++ except OverflowError:
++ pass
++ else:
++ assert 0, '__float__() tolerated base-10 overflow'
++
++ def testFloatBase10NormalizedOverflow(self):
++ try:
++ float(univ.Real((10, 10, sys.float_info.max_10_exp)))
++ except OverflowError:
++ pass
++ else:
++ assert 0, '__float__() tolerated normalized base-10 overflow'
++
+ def testPrettyIn(self):
+ assert univ.Real((3, 10, 0)) == 3, 'prettyIn() fails'
+
++ def testPrettyInBigBase10Mantissa(self):
++ assert tuple(univ.Real((10 ** 400, 10, 0))) == (1, 10, 400), \
++ 'prettyIn() big mantissa normalization fails'
++
+ # infinite float values
+ def testStrInf(self):
+ assert str(univ.Real('inf')) == 'inf', 'str() fails'
+--
+2.34.1
+
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14 Yoann Congal
` (21 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Emily Vekariya <evekariy@cisco.com>
The BER decoder shared by the CER and DER codecs parses long-form tags by
accumulating continuation octets without an upper bound on the tag ID size.
A crafted input can force construction of an arbitrarily large integer with
CPU cost growing quadratically, and can trigger unhandled ValueError
exceptions in the Python 3.11+ error formatting paths. Any application
decoding untrusted BER, CER, or DER input is affected.
scarthgap ships pyasn1 0.5.1, which is affected as the issue is present in
all versions before 0.6.4.
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59884
Signed-off-by: Emily Vekariya <evekariy@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../recipes-devtools/python/python-pyasn1.inc | 1 +
.../python3-pyasn1/CVE-2026-59884.patch | 245 ++++++++++++++++++
2 files changed, 246 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
diff --git a/meta/recipes-devtools/python/python-pyasn1.inc b/meta/recipes-devtools/python/python-pyasn1.inc
index 1780ee1d888..ae96f09fb1d 100644
--- a/meta/recipes-devtools/python/python-pyasn1.inc
+++ b/meta/recipes-devtools/python/python-pyasn1.inc
@@ -20,6 +20,7 @@ SRC_URI += " \
file://run-ptest \
file://CVE-2026-23490.patch \
file://CVE-2026-59886.patch \
+ file://CVE-2026-59884.patch \
"
RDEPENDS:${PN}-ptest += " \
diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
new file mode 100644
index 00000000000..dd897e2d758
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-59884.patch
@@ -0,0 +1,245 @@
+From 38e8ae286160eb27620e7cb42108b3b28d1f299f Mon Sep 17 00:00:00 2001
+From: Simon Pichugin <simon.pichugin@gmail.com>
+Date: Wed, 8 Jul 2026 17:36:30 -0700
+Subject: [PATCH] Merge commit from fork
+
+CVE: CVE-2026-59884
+Upstream-Status: Backport [https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5]
+
+(cherry picked from commit 628e36ecbb5277a3f01572ce418ef54271b165a5)
+Signed-off-by: Emily Vekariya <evekariy@cisco.com>
+---
+ pyasn1/codec/ber/decoder.py | 13 +++++++++++--
+ pyasn1/type/tag.py | 20 ++++++++++++++++----
+ tests/codec/ber/test_decoder.py | 25 +++++++++++++++++++++++++
+ tests/codec/cer/test_decoder.py | 15 +++++++++++++++
+ tests/codec/der/test_decoder.py | 15 +++++++++++++++
+ tests/type/test_tag.py | 20 ++++++++++++++++++++
+ 6 files changed, 102 insertions(+), 6 deletions(-)
+
+diff --git a/pyasn1/codec/ber/decoder.py b/pyasn1/codec/ber/decoder.py
+index be8ba65..18865c2 100644
+--- a/pyasn1/codec/ber/decoder.py
++++ b/pyasn1/codec/ber/decoder.py
+@@ -39,6 +39,10 @@ SubstrateUnderrunError = error.SubstrateUnderrunError
+ # 20 octets allows up to 140-bit integers, supporting UUID-based OIDs
+ MAX_OID_ARC_CONTINUATION_OCTETS = 20
+
++# Maximum number of octets in a long-form tag ID (20 octets = up to
++# 140-bit tag IDs, matching the OID arc limit)
++MAX_TAG_OCTETS = 20
++
+
+ class AbstractPayloadDecoder(object):
+ protoComponent = None
+@@ -1570,7 +1574,7 @@ class SingleItemDecoder(object):
+
+ if tagId == 0x1F:
+ isShortTag = False
+- lengthOctetIdx = 0
++ tagOctetCount = 0
+ tagId = 0
+
+ while True:
+@@ -1584,7 +1588,12 @@ class SingleItemDecoder(object):
+ )
+
+ integerTag = ord(integerByte)
+- lengthOctetIdx += 1
++ tagOctetCount += 1
++ if tagOctetCount > MAX_TAG_OCTETS:
++ raise error.PyAsn1Error(
++ 'Tag ID octet count exceeds limit (%d)' % (
++ MAX_TAG_OCTETS,)
++ )
+ tagId <<= 7
+ tagId |= (integerTag & 0x7F)
+
+diff --git a/pyasn1/type/tag.py b/pyasn1/type/tag.py
+index a21a405..bbbdd85 100644
+--- a/pyasn1/type/tag.py
++++ b/pyasn1/type/tag.py
+@@ -34,6 +34,16 @@ tagCategoryExplicit = 0x02
+ tagCategoryUntagged = 0x04
+
+
++def _tagIdToStr(tagId):
++ # Decimal rendering of a huge tag ID can exceed the interpreter's
++ # integer-to-string conversion limit (sys.get_int_max_str_digits(),
++ # Python 3.11+) and raise ValueError; hexadecimal is not limited
++ try:
++ return str(tagId)
++ except ValueError:
++ return hex(tagId)
++
++
+ class Tag(object):
+ """Create ASN.1 tag
+
+@@ -56,7 +66,8 @@ class Tag(object):
+ """
+ def __init__(self, tagClass, tagFormat, tagId):
+ if tagId < 0:
+- raise error.PyAsn1Error('Negative tag ID (%s) not allowed' % tagId)
++ raise error.PyAsn1Error(
++ 'Negative tag ID (%s) not allowed' % _tagIdToStr(tagId))
+ self.__tagClass = tagClass
+ self.__tagFormat = tagFormat
+ self.__tagId = tagId
+@@ -65,7 +76,7 @@ class Tag(object):
+
+ def __repr__(self):
+ representation = '[%s:%s:%s]' % (
+- self.__tagClass, self.__tagFormat, self.__tagId)
++ self.__tagClass, self.__tagFormat, _tagIdToStr(self.__tagId))
+ return '<%s object, tag %s>' % (
+ self.__class__.__name__, representation)
+
+@@ -194,8 +205,9 @@ class TagSet(object):
+ self.__hash = hash(self.__superTagsClassId)
+
+ def __repr__(self):
+- representation = '-'.join(['%s:%s:%s' % (x.tagClass, x.tagFormat, x.tagId)
+- for x in self.__superTags])
++ representation = '-'.join(
++ ['%s:%s:%s' % (x.tagClass, x.tagFormat, _tagIdToStr(x.tagId))
++ for x in self.__superTags])
+ if representation:
+ representation = 'tags ' + representation
+ else:
+diff --git a/tests/codec/ber/test_decoder.py b/tests/codec/ber/test_decoder.py
+index f6ff7b0..0152027 100644
+--- a/tests/codec/ber/test_decoder.py
++++ b/tests/codec/ber/test_decoder.py
+@@ -34,6 +34,31 @@ class LargeTagDecoderTestCase(BaseTestCase):
+ def testLongTag(self):
+ assert decoder.decode(ints2octs((0x1f, 2, 1, 0)))[0].tagSet == univ.Integer.tagSet
+
++ def testVeryLongTagRoundTrip(self):
++ # (1 << 140) - 1 is the largest tag ID fitting the 20 octet limit
++ for tagId in (1 << 77, (1 << 140) - 1):
++ largeTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, tagId)
++ asn1Spec = univ.Integer().subtype(implicitTag=largeTag)
++ value = univ.Integer(1).subtype(implicitTag=largeTag)
++
++ decoded, rest = decoder.decode(encoder.encode(value), asn1Spec=asn1Spec)
++
++ assert rest == b''
++ assert decoded == 1
++
++ def testExcessiveLongTag(self):
++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit
++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140)
++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag)
++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag))
++
++ try:
++ decoder.decode(substrate, asn1Spec=asn1Spec)
++ except error.PyAsn1Error:
++ pass
++ else:
++ assert 0, 'excessive long tag tolerated'
++
+ def testTagsEquivalence(self):
+ integer = univ.Integer(2).subtype(implicitTag=tag.Tag(tag.tagClassContext, 0, 0))
+ assert decoder.decode(ints2octs((0x9f, 0x80, 0x00, 0x02, 0x01, 0x02)), asn1Spec=integer) == decoder.decode(
+diff --git a/tests/codec/cer/test_decoder.py b/tests/codec/cer/test_decoder.py
+index 3d27194..d759f76 100644
+--- a/tests/codec/cer/test_decoder.py
++++ b/tests/codec/cer/test_decoder.py
+@@ -67,6 +67,21 @@ class OctetStringDecoderTestCase(BaseTestCase):
+ # TODO: test failures on short chunked and long unchunked substrate samples
+
+
++class LargeTagDecoderTestCase(BaseTestCase):
++ def testExcessiveLongTag(self):
++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit
++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140)
++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag)
++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag))
++
++ try:
++ decoder.decode(substrate, asn1Spec=asn1Spec)
++ except PyAsn1Error:
++ pass
++ else:
++ assert 0, 'excessive long tag tolerated'
++
++
+ class RealDecoderTestCase(BaseTestCase):
+ def testLargeBinaryRoundTrip(self):
+ substrate = encoder.encode(univ.Real((-1, 2, 76354972)))
+diff --git a/tests/codec/der/test_decoder.py b/tests/codec/der/test_decoder.py
+index 553563c..726c999 100644
+--- a/tests/codec/der/test_decoder.py
++++ b/tests/codec/der/test_decoder.py
+@@ -73,6 +73,21 @@ class OctetStringDecoderTestCase(BaseTestCase):
+ assert 0, 'chunked encoding tolerated'
+
+
++class LargeTagDecoderTestCase(BaseTestCase):
++ def testExcessiveLongTag(self):
++ # 1 << 140 is the smallest tag ID needing 21 octets, one over the limit
++ excessiveTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 140)
++ asn1Spec = univ.Integer().subtype(implicitTag=excessiveTag)
++ substrate = encoder.encode(univ.Integer(1).subtype(implicitTag=excessiveTag))
++
++ try:
++ decoder.decode(substrate, asn1Spec=asn1Spec)
++ except PyAsn1Error:
++ pass
++ else:
++ assert 0, 'excessive long tag tolerated'
++
++
+ class RealDecoderTestCase(BaseTestCase):
+ def testCanonicalLargeBinaryReal(self):
+ substrate = encoder.encode(univ.Real((1, 2, 1000000)))
+diff --git a/tests/type/test_tag.py b/tests/type/test_tag.py
+index d0ffa07..ab9b8b1 100644
+--- a/tests/type/test_tag.py
++++ b/tests/type/test_tag.py
+@@ -9,6 +9,7 @@ import unittest
+
+ from tests.base import BaseTestCase
+
++from pyasn1 import error
+ from pyasn1.type import tag
+
+
+@@ -23,6 +24,19 @@ class TagReprTestCase(TagTestCaseBase):
+ def testRepr(self):
+ assert 'Tag' in repr(self.t1)
+
++ def testReprHugeTagId(self):
++ # must not hit the interpreter's int-to-str conversion limit
++ hugeTag = tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 100000)
++ assert 'Tag' in repr(hugeTag)
++
++ def testNegativeHugeTagId(self):
++ try:
++ tag.Tag(tag.tagClassContext, tag.tagFormatSimple, -(1 << 100000))
++ except error.PyAsn1Error:
++ pass
++ else:
++ assert 0, 'negative tag ID tolerated'
++
+
+ class TagCmpTestCase(TagTestCaseBase):
+ def testCmp(self):
+@@ -54,6 +68,12 @@ class TagSetReprTestCase(TagSetTestCaseBase):
+ def testRepr(self):
+ assert 'TagSet' in repr(self.ts1)
+
++ def testReprHugeTagId(self):
++ # must not hit the interpreter's int-to-str conversion limit
++ hugeTagSet = self.ts1.tagImplicitly(
++ tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1 << 100000))
++ assert 'TagSet' in repr(hugeTagSet)
++
+
+ class TagSetCmpTestCase(TagSetTestCaseBase):
+ def testCmp(self):
+--
+2.34.1
+
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22 Yoann Congal
` (20 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
This is a security release of Python 3.12
Release information: [1]
* drop CVE patches included in this release
* refresh all remaining patches via devtool
* remove some tab style in SRC_URI.
* add CVE_STATUS entries for CVEs fixed in this release but still
reported as Unpatched by cve-check (including 2 fixed already in
previous release)
[1] https://www.python.org/downloads/release/python-31214/
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...shebang-overflow-on-python-config.py.patch | 2 +-
...-qemu-wrapper-when-gathering-profile.patch | 2 +-
...e-treat-overflow-in-UID-GID-as-failu.patch | 2 +-
.../python/python3/CVE-2025-13462.patch | 142 ----------------
.../python/python3/CVE-2026-11940.patch | 66 --------
.../python/python3/CVE-2026-11972.patch | 60 -------
.../python/python3/CVE-2026-1502.patch | 113 -------------
.../python3/CVE-2026-3644_CVE-2026-0672.patch | 154 -----------------
.../python/python3/CVE-2026-4224.patch | 121 -------------
.../python3/CVE-2026-4519_CVE-2026-4786.patch | 66 --------
.../python/python3/CVE-2026-4519_p1.patch | 107 ------------
.../python/python3/CVE-2026-4519_p2.patch | 159 ------------------
.../python/python3/CVE-2026-6100.patch | 75 ---------
.../python/python3/CVE-2026-7210.patch | 148 ----------------
.../python/python3/CVE-2026-9669.patch | 96 -----------
.../python/python3/makerace.patch | 2 +-
...{python3_3.12.13.bb => python3_3.12.14.bb} | 24 +--
17 files changed, 13 insertions(+), 1326 deletions(-)
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2025-13462.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-1502.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4224.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-6100.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-7210.patch
delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch
rename meta/recipes-devtools/python/{python3_3.12.13.bb => python3_3.12.14.bb} (96%)
diff --git a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
index a8f98d873e8..6c8b1bf6cd9 100644
--- a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
+++ b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch
@@ -19,7 +19,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in
index 2d235d2..1ac2263 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2356,6 +2356,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
+@@ -2361,6 +2361,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
@ # Substitution happens here, as the completely-expanded BINDIR
@ # is not available in configure
sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py
diff --git a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
index b78f6199580..6066b26e38f 100644
--- a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
+++ b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch
@@ -13,7 +13,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in
index 083f4c7..dce36a5 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -660,8 +660,7 @@ profile-run-stamp:
+@@ -663,8 +663,7 @@ profile-run-stamp:
# enabled.
$(MAKE) profile-gen-stamp
# Next, run the profile task to generate the profile information.
diff --git a/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch b/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch
index 98b3aa42d21..5fdf5f4514e 100644
--- a/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch
+++ b/meta/recipes-devtools/python/python3/0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch
@@ -16,7 +16,7 @@ diff --git a/Lib/tarfile.py b/Lib/tarfile.py
index 0a0f31e..4dfb67d 100755
--- a/Lib/tarfile.py
+++ b/Lib/tarfile.py
-@@ -2688,7 +2688,8 @@ class TarFile(object):
+@@ -2721,7 +2721,8 @@ class TarFile(object):
os.lchown(targetpath, u, g)
else:
os.chown(targetpath, u, g)
diff --git a/meta/recipes-devtools/python/python3/CVE-2025-13462.patch b/meta/recipes-devtools/python/python3/CVE-2025-13462.patch
deleted file mode 100644
index 36d492338ba..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2025-13462.patch
+++ /dev/null
@@ -1,142 +0,0 @@
-From 14d7d2e8f51a17c23c98f13f33743253a0b7a18a Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Mon, 18 May 2026 19:43:51 +0200
-Subject: [PATCH] [3.12] gh-141707: Skip TarInfo DIRTYPE normalization during
- GNU long name handling (#145817)
-
-gh-141707: Skip TarInfo DIRTYPE normalization during GNU long name handling
-
-CVE: CVE-2025-13462
-Upstream-Status: Backport [https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084]
-
-Backport Changes:
-- This file is not present in the current version and is therefore omitted
- Misc/NEWS.d/next/Library/2025-11-18-06-35-53.gh-issue-141707.DBmQIy.rst
-
-(cherry picked from commit 42d754e34c06e57ad6b8e7f92f32af679912d8ab)
-
-Co-authored-by: Seth Michael Larson <seth@python.org>
-Co-authored-by: Eashwar Ranganathan <eashwar@eashwar.com>
-(cherry picked from commit d10950739a78f54d0718d88fb5a868374603c084)
-Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
----
- Lib/tarfile.py | 29 +++++++++++++++++++++++++----
- Lib/test/test_tarfile.py | 19 +++++++++++++++++++
- Misc/ACKS | 1 +
- 3 files changed, 45 insertions(+), 4 deletions(-)
-
-diff --git a/Lib/tarfile.py b/Lib/tarfile.py
-index 99451aa765..70fdbe85b0 100755
---- a/Lib/tarfile.py
-+++ b/Lib/tarfile.py
-@@ -1246,6 +1246,20 @@ class TarInfo(object):
- @classmethod
- def frombuf(cls, buf, encoding, errors):
- """Construct a TarInfo object from a 512 byte bytes object.
-+
-+ To support the old v7 tar format AREGTYPE headers are
-+ transformed to DIRTYPE headers if their name ends in '/'.
-+ """
-+ return cls._frombuf(buf, encoding, errors)
-+
-+ @classmethod
-+ def _frombuf(cls, buf, encoding, errors, *, dircheck=True):
-+ """Construct a TarInfo object from a 512 byte bytes object.
-+
-+ If ``dircheck`` is set to ``True`` then ``AREGTYPE`` headers will
-+ be normalized to ``DIRTYPE`` if the name ends in a trailing slash.
-+ ``dircheck`` must be set to ``False`` if this function is called
-+ on a follow-up header such as ``GNUTYPE_LONGNAME``.
- """
- if len(buf) == 0:
- raise EmptyHeaderError("empty header")
-@@ -1276,7 +1290,7 @@ class TarInfo(object):
-
- # Old V7 tar format represents a directory as a regular
- # file with a trailing slash.
-- if obj.type == AREGTYPE and obj.name.endswith("/"):
-+ if dircheck and obj.type == AREGTYPE and obj.name.endswith("/"):
- obj.type = DIRTYPE
-
- # The old GNU sparse format occupies some of the unused
-@@ -1311,8 +1325,15 @@ class TarInfo(object):
- """Return the next TarInfo object from TarFile object
- tarfile.
- """
-+ return cls._fromtarfile(tarfile)
-+
-+ @classmethod
-+ def _fromtarfile(cls, tarfile, *, dircheck=True):
-+ """
-+ See dircheck documentation in _frombuf().
-+ """
- buf = tarfile.fileobj.read(BLOCKSIZE)
-- obj = cls.frombuf(buf, tarfile.encoding, tarfile.errors)
-+ obj = cls._frombuf(buf, tarfile.encoding, tarfile.errors, dircheck=dircheck)
- obj.offset = tarfile.fileobj.tell() - BLOCKSIZE
- return obj._proc_member(tarfile)
-
-@@ -1370,7 +1391,7 @@ class TarInfo(object):
-
- # Fetch the next header and process it.
- try:
-- next = self.fromtarfile(tarfile)
-+ next = self._fromtarfile(tarfile, dircheck=False)
- except HeaderError as e:
- raise SubsequentHeaderError(str(e)) from None
-
-@@ -1505,7 +1526,7 @@ class TarInfo(object):
-
- # Fetch the next header.
- try:
-- next = self.fromtarfile(tarfile)
-+ next = self._fromtarfile(tarfile, dircheck=False)
- except HeaderError as e:
- raise SubsequentHeaderError(str(e)) from None
-
-diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
-index 759fa03ead..82637841ed 100644
---- a/Lib/test/test_tarfile.py
-+++ b/Lib/test/test_tarfile.py
-@@ -1134,6 +1134,25 @@ class LongnameTest:
- self.assertIsNotNone(tar.getmember(longdir))
- self.assertIsNotNone(tar.getmember(longdir.removesuffix('/')))
-
-+ def test_longname_file_not_directory(self):
-+ # Test reading a longname file and ensure it is not handled as a directory
-+ # Issue #141707
-+ buf = io.BytesIO()
-+ with tarfile.open(mode='w', fileobj=buf, format=self.format) as tar:
-+ ti = tarfile.TarInfo()
-+ ti.type = tarfile.AREGTYPE
-+ ti.name = ('a' * 99) + '/' + ('b' * 3)
-+ tar.addfile(ti)
-+
-+ expected = {t.name: t.type for t in tar.getmembers()}
-+
-+ buf.seek(0)
-+ with tarfile.open(mode='r', fileobj=buf) as tar:
-+ actual = {t.name: t.type for t in tar.getmembers()}
-+
-+ self.assertEqual(expected, actual)
-+
-+
- class GNUReadTest(LongnameTest, ReadTest, unittest.TestCase):
-
- subdir = "gnu"
-diff --git a/Misc/ACKS b/Misc/ACKS
-index a6e63a991f..30d5f99ebb 100644
---- a/Misc/ACKS
-+++ b/Misc/ACKS
-@@ -1492,6 +1492,7 @@ Dhushyanth Ramasamy
- Ashwin Ramaswami
- Jeff Ramnani
- Bayard Randel
-+Eashwar Ranganathan
- Varpu Rantala
- Brodie Rao
- Rémi Rampin
---
-2.35.6
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch
deleted file mode 100644
index 0851138ae89..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch
+++ /dev/null
@@ -1,66 +0,0 @@
-From 91a9bd79cdbab8f8518c4a5e669b3f19680a2f31 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Tue, 23 Jun 2026 14:31:38 +0100
-Subject: [PATCH] gh-151558: Fix symlink escape via `tarfile`
- hardlink-extraction fallback (GH-151559)
-
-CVE: CVE-2026-11940
-Upstream-Status: Backport [https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f]
-
-Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
----
- Lib/tarfile.py | 3 +++
- Lib/test/test_tarfile.py | 24 ++++++++++++++++++++++++
- 2 files changed, 27 insertions(+)
-
-diff --git a/Lib/tarfile.py b/Lib/tarfile.py
-index 59d3f6e5cce1..83226e907e4b 100755
---- a/Lib/tarfile.py
-+++ b/Lib/tarfile.py
-@@ -2650,6 +2650,9 @@ def makelink_with_filter(self, tarinfo, targetpath,
- "makelink_with_filter: if filter_function is not None, "
- + "extraction_root must also not be None")
- try:
-+ filter_function(
-+ unfiltered.replace(name=tarinfo.name, deep=False),
-+ extraction_root)
- filtered = filter_function(unfiltered, extraction_root)
- except _FILTER_ERRORS as cause:
- raise LinkFallbackError(tarinfo, unfiltered.name) from cause
-diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
-index 759fa03ead70..29719d95b6c1 100644
---- a/Lib/test/test_tarfile.py
-+++ b/Lib/test/test_tarfile.py
-@@ -4080,6 +4080,30 @@ def test_sneaky_hardlink_fallback(self):
- self.expect_file("boom", symlink_to='../../link_here')
- self.expect_file("c", symlink_to='b')
-
-+ @symlink_test
-+ def test_sneaky_hardlink_fallback_deep(self):
-+ # (CVE-2026-11940)
-+ with ArchiveMaker() as arc:
-+ arc.add("a/b/s", symlink_to=os.path.join("..", "escape"))
-+ arc.add("s", hardlink_to=os.path.join("a", "b", "s"))
-+
-+ with self.check_context(arc.open(), 'data'):
-+ e = self.expect_exception(
-+ tarfile.LinkFallbackError,
-+ "link 's' would be extracted as a copy of "
-+ + "'a/b/s', which was rejected")
-+ self.assertIsInstance(e.__cause__,
-+ tarfile.LinkOutsideDestinationError)
-+
-+ for filter in 'tar', 'fully_trusted':
-+ with self.subTest(filter), self.check_context(arc.open(), filter):
-+ if not os_helper.can_symlink():
-+ self.expect_file("a/")
-+ self.expect_file("a/b/")
-+ else:
-+ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape'))
-+ self.expect_file("s", symlink_to=os.path.join('..', 'escape'))
-+
- @symlink_test
- def test_exfiltration_via_symlink(self):
- # (CVE-2025-4138)
---
-2.54.0
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch
deleted file mode 100644
index 36334f247e6..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch
+++ /dev/null
@@ -1,60 +0,0 @@
-From a83ebdb495a9cbd28a03675acdeda235fade90b3 Mon Sep 17 00:00:00 2001
-From: Petr Viktorin <encukou@gmail.com>
-Date: Tue, 23 Jun 2026 15:13:30 +0200
-Subject: [PATCH] gh-151981: Make tarfile._Stream.seek break at EOF (GH-151982)
-
-Co-authored-by: Stan Ulbrych <stan@python.org>
-
-CVE: CVE-2026-11972
-Upstream-Status: Backport [https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896]
-
-Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
----
- Lib/tarfile.py | 4 +++-
- Lib/test/test_tarfile.py | 16 ++++++++++++++++
- 2 files changed, 19 insertions(+), 1 deletion(-)
-
-diff --git a/Lib/tarfile.py b/Lib/tarfile.py
-index 83226e907e4b..c0007a78f700 100755
---- a/Lib/tarfile.py
-+++ b/Lib/tarfile.py
-@@ -516,7 +516,9 @@ def seek(self, pos=0):
- if pos - self.pos >= 0:
- blocks, remainder = divmod(pos - self.pos, self.bufsize)
- for i in range(blocks):
-- self.read(self.bufsize)
-+ data = self.read(self.bufsize)
-+ if not data:
-+ break
- self.read(remainder)
- else:
- raise StreamError("seeking backwards is not allowed")
-diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
-index 29719d95b6c1..8aeb2e1b1b9a 100644
---- a/Lib/test/test_tarfile.py
-+++ b/Lib/test/test_tarfile.py
-@@ -4480,6 +4480,22 @@ def valueerror_filter(tarinfo, path):
- with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter):
- self.expect_exception(TypeError) # errorlevel is not int
-
-+ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT])
-+ def test_getmembers_big_size(self, format):
-+ # gh-151981: A loop in seek() for streaming files tried to read the
-+ # declared number of blocks even at EOF
-+ tinfo = tarfile.TarInfo("huge-file")
-+ tinfo.size = 1 << 64
-+ bio = io.BytesIO()
-+ # Write header without data
-+ bio.write(tinfo.tobuf(format))
-+
-+ # Reset & try to get contents
-+ bio.seek(0)
-+ with tarfile.open(fileobj=bio, mode="r|") as tar:
-+ with self.assertRaises(tarfile.ReadError):
-+ tar.getmembers()
-+
-
- class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase):
- testdir = os.path.join(TEMPDIR, "testoverwrite")
---
-2.54.0
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-1502.patch b/meta/recipes-devtools/python/python3/CVE-2026-1502.patch
deleted file mode 100644
index be6a8379a85..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-1502.patch
+++ /dev/null
@@ -1,113 +0,0 @@
-From 05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69 Mon Sep 17 00:00:00 2001
-From: Seth Larson <seth@python.org>
-Date: Fri, 10 Apr 2026 10:21:42 -0500
-Subject: [PATCH] gh-146211: Reject CR/LF in HTTP tunnel request headers
- (#146212)
-
-Co-authored-by: Illia Volochii <illia.volochii@gmail.com>
-
-CVE: CVE-2026-1502
-Upstream-Status: Backport [https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69]
-Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
----
- Lib/http/client.py | 11 ++++-
- Lib/test/test_httplib.py | 45 +++++++++++++++++++
- ...-03-20-09-29-42.gh-issue-146211.PQVbs7.rst | 2 +
- 3 files changed, 57 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-
-diff --git a/Lib/http/client.py b/Lib/http/client.py
-index 70451d6..7db4807 100644
---- a/Lib/http/client.py
-+++ b/Lib/http/client.py
-@@ -972,13 +972,22 @@ class HTTPConnection:
- return ip
-
- def _tunnel(self):
-+ if _contains_disallowed_url_pchar_re.search(self._tunnel_host):
-+ raise ValueError('Tunnel host can\'t contain control characters %r'
-+ % (self._tunnel_host,))
- connect = b"CONNECT %s:%d %s\r\n" % (
- self._wrap_ipv6(self._tunnel_host.encode("idna")),
- self._tunnel_port,
- self._http_vsn_str.encode("ascii"))
- headers = [connect]
- for header, value in self._tunnel_headers.items():
-- headers.append(f"{header}: {value}\r\n".encode("latin-1"))
-+ header_bytes = header.encode("latin-1")
-+ value_bytes = value.encode("latin-1")
-+ if not _is_legal_header_name(header_bytes):
-+ raise ValueError('Invalid header name %r' % (header_bytes,))
-+ if _is_illegal_header_value(value_bytes):
-+ raise ValueError('Invalid header value %r' % (value_bytes,))
-+ headers.append(b"%s: %s\r\n" % (header_bytes, value_bytes))
- headers.append(b"\r\n")
- # Making a single send() call instead of one per line encourages
- # the host OS to use a more optimal packet size instead of
-diff --git a/Lib/test/test_httplib.py b/Lib/test/test_httplib.py
-index e46dac0..e027d93 100644
---- a/Lib/test/test_httplib.py
-+++ b/Lib/test/test_httplib.py
-@@ -369,6 +369,51 @@ class HeaderTests(TestCase):
- with self.assertRaisesRegex(ValueError, 'Invalid header'):
- conn.putheader(name, value)
-
-+ def test_invalid_tunnel_headers(self):
-+ cases = (
-+ ('Invalid\r\nName', 'ValidValue'),
-+ ('Invalid\rName', 'ValidValue'),
-+ ('Invalid\nName', 'ValidValue'),
-+ ('\r\nInvalidName', 'ValidValue'),
-+ ('\rInvalidName', 'ValidValue'),
-+ ('\nInvalidName', 'ValidValue'),
-+ (' InvalidName', 'ValidValue'),
-+ ('\tInvalidName', 'ValidValue'),
-+ ('Invalid:Name', 'ValidValue'),
-+ (':InvalidName', 'ValidValue'),
-+ ('ValidName', 'Invalid\r\nValue'),
-+ ('ValidName', 'Invalid\rValue'),
-+ ('ValidName', 'Invalid\nValue'),
-+ ('ValidName', 'InvalidValue\r\n'),
-+ ('ValidName', 'InvalidValue\r'),
-+ ('ValidName', 'InvalidValue\n'),
-+ )
-+ for name, value in cases:
-+ with self.subTest((name, value)):
-+ conn = client.HTTPConnection('example.com')
-+ conn.set_tunnel('tunnel', headers={
-+ name: value
-+ })
-+ conn.sock = FakeSocket('')
-+ with self.assertRaisesRegex(ValueError, 'Invalid header'):
-+ conn._tunnel() # Called in .connect()
-+
-+ def test_invalid_tunnel_host(self):
-+ cases = (
-+ 'invalid\r.host',
-+ '\ninvalid.host',
-+ 'invalid.host\r\n',
-+ 'invalid.host\x00',
-+ 'invalid host',
-+ )
-+ for tunnel_host in cases:
-+ with self.subTest(tunnel_host):
-+ conn = client.HTTPConnection('example.com')
-+ conn.set_tunnel(tunnel_host)
-+ conn.sock = FakeSocket('')
-+ with self.assertRaisesRegex(ValueError, 'Tunnel host can\'t contain control characters'):
-+ conn._tunnel() # Called in .connect()
-+
- def test_headers_debuglevel(self):
- body = (
- b'HTTP/1.1 200 OK\r\n'
-diff --git a/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-new file mode 100644
-index 0000000..4993633
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-@@ -0,0 +1,2 @@
-+Reject CR/LF characters in tunnel request headers for the
-+HTTPConnection.set_tunnel() method.
---
-2.50.1
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch b/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
deleted file mode 100644
index 42d8133a183..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-3644_CVE-2026-0672.patch
+++ /dev/null
@@ -1,154 +0,0 @@
-From 6e291d2eba0b6820bc924e68f1db750328bf6c75 Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Mon, 16 Mar 2026 15:05:13 +0100
-Subject: [PATCH] [3.13] gh-145599, CVE 2026-3644: Reject control
- characters in `http.cookies.Morsel.update()` (GH-145600) (#146024)
-
-gh-145599, CVE 2026-3644: Reject control characters in `http.cookies.Morsel.update()` (GH-145600)
-
-Reject control characters in `http.cookies.Morsel.update()` and `http.cookies.BaseCookie.js_output`.
-
-CVE: CVE-2026-3644 CVE-2026-0672
-Upstream-Status: Backport [https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd]
-
-Backport Changes:
-- This file is not present in the current version and is therefore omitted
- Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst
-
-(cherry picked from commit 57e88c1cf95e1481b94ae57abe1010469d47a6b4)
-
-Co-authored-by: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com>
-Co-authored-by: Victor Stinner <vstinner@python.org>
-Co-authored-by: Victor Stinner <victor.stinner@gmail.com>
-(cherry picked from commit d16ecc6c3626f0e2cc8f08c309c83934e8a979dd)
-Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
----
- Lib/http/cookies.py | 24 ++++++++++++++++++----
- Lib/test/test_http_cookies.py | 38 +++++++++++++++++++++++++++++++++++
- 2 files changed, 58 insertions(+), 4 deletions(-)
-
-diff --git a/Lib/http/cookies.py b/Lib/http/cookies.py
-index d0a69cbe191..63d119ad46c 100644
---- a/Lib/http/cookies.py
-+++ b/Lib/http/cookies.py
-@@ -335,9 +335,16 @@ class Morsel(dict):
- key = key.lower()
- if key not in self._reserved:
- raise CookieError("Invalid attribute %r" % (key,))
-+ if _has_control_character(key, val):
-+ raise CookieError("Control characters are not allowed in "
-+ f"cookies {key!r} {val!r}")
- data[key] = val
- dict.update(self, data)
-
-+ def __ior__(self, values):
-+ self.update(values)
-+ return self
-+
- def isReservedKey(self, K):
- return K.lower() in self._reserved
-
-@@ -363,9 +370,15 @@ class Morsel(dict):
- }
-
- def __setstate__(self, state):
-- self._key = state['key']
-- self._value = state['value']
-- self._coded_value = state['coded_value']
-+ key = state['key']
-+ value = state['value']
-+ coded_value = state['coded_value']
-+ if _has_control_character(key, value, coded_value):
-+ raise CookieError("Control characters are not allowed in cookies "
-+ f"{key!r} {value!r} {coded_value!r}")
-+ self._key = key
-+ self._value = value
-+ self._coded_value = coded_value
-
- def output(self, attrs=None, header="Set-Cookie:"):
- return "%s %s" % (header, self.OutputString(attrs))
-@@ -377,13 +390,16 @@ class Morsel(dict):
-
- def js_output(self, attrs=None):
- # Print javascript
-+ output_string = self.OutputString(attrs)
-+ if _has_control_character(output_string):
-+ raise CookieError("Control characters are not allowed in cookies")
- return """
- <script type="text/javascript">
- <!-- begin hiding
- document.cookie = \"%s\";
- // end hiding -->
- </script>
-- """ % (self.OutputString(attrs).replace('"', r'\"'))
-+ """ % (output_string.replace('"', r'\"'))
-
- def OutputString(self, attrs=None):
- # Build up our result
-diff --git a/Lib/test/test_http_cookies.py b/Lib/test/test_http_cookies.py
-index f196bcc48e3..2478a6c630f 100644
---- a/Lib/test/test_http_cookies.py
-+++ b/Lib/test/test_http_cookies.py
-@@ -573,6 +573,14 @@ class MorselTests(unittest.TestCase):
- with self.assertRaises(cookies.CookieError):
- morsel["path"] = c0
-
-+ # .__setstate__()
-+ with self.assertRaises(cookies.CookieError):
-+ morsel.__setstate__({'key': c0, 'value': 'val', 'coded_value': 'coded'})
-+ with self.assertRaises(cookies.CookieError):
-+ morsel.__setstate__({'key': 'key', 'value': c0, 'coded_value': 'coded'})
-+ with self.assertRaises(cookies.CookieError):
-+ morsel.__setstate__({'key': 'key', 'value': 'val', 'coded_value': c0})
-+
- # .setdefault()
- with self.assertRaises(cookies.CookieError):
- morsel.setdefault("path", c0)
-@@ -587,6 +595,18 @@ class MorselTests(unittest.TestCase):
- with self.assertRaises(cookies.CookieError):
- morsel.set("path", "val", c0)
-
-+ # .update()
-+ with self.assertRaises(cookies.CookieError):
-+ morsel.update({"path": c0})
-+ with self.assertRaises(cookies.CookieError):
-+ morsel.update({c0: "val"})
-+
-+ # .__ior__()
-+ with self.assertRaises(cookies.CookieError):
-+ morsel |= {"path": c0}
-+ with self.assertRaises(cookies.CookieError):
-+ morsel |= {c0: "val"}
-+
- def test_control_characters_output(self):
- # Tests that even if the internals of Morsel are modified
- # that a call to .output() has control character safeguards.
-@@ -607,6 +627,24 @@ class MorselTests(unittest.TestCase):
- with self.assertRaises(cookies.CookieError):
- cookie.output()
-
-+ # Tests that .js_output() also has control character safeguards.
-+ for c0 in support.control_characters_c0():
-+ morsel = cookies.Morsel()
-+ morsel.set("key", "value", "coded-value")
-+ morsel._key = c0 # Override private variable.
-+ cookie = cookies.SimpleCookie()
-+ cookie["cookie"] = morsel
-+ with self.assertRaises(cookies.CookieError):
-+ cookie.js_output()
-+
-+ morsel = cookies.Morsel()
-+ morsel.set("key", "value", "coded-value")
-+ morsel._coded_value = c0 # Override private variable.
-+ cookie = cookies.SimpleCookie()
-+ cookie["cookie"] = morsel
-+ with self.assertRaises(cookies.CookieError):
-+ cookie.js_output()
-+
-
- def load_tests(loader, tests, pattern):
- tests.addTest(doctest.DocTestSuite(cookies))
---
-2.35.6
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4224.patch b/meta/recipes-devtools/python/python3/CVE-2026-4224.patch
deleted file mode 100644
index 09dd2dda003..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-4224.patch
+++ /dev/null
@@ -1,121 +0,0 @@
-From ca301e24e20d1d9d58bbd432ff103cab2cb87128 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Wed, 8 Apr 2026 11:27:39 +0100
-Subject: [PATCH] gh-145986: Avoid unbound C recursion in `conv_content_model`
- in `pyexpat.c` (CVE-2026-4224) (GH-145987) (#146000)
-MIME-Version: 1.0
-Content-Type: text/plain; charset=UTF-8
-Content-Transfer-Encoding: 8bit
-
-* [3.11] gh-145986: Avoid unbound C recursion in `conv_content_model` in `pyexpat.c` (CVE-2026-4224) (GH-145987)
-
-Fix C stack overflow (CVE-2026-4224) when an Expat parser
-with a registered `ElementDeclHandler` parses inline DTD
-containing deeply nested content model.
-
----------
-(cherry picked from commit eb0e8be3a7e11b87d198a2c3af1ed0eccf532768)
-(cherry picked from commit e5caf45faac74b0ed869e3336420cffd3510ce6e)
-
-Co-authored-by: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com>
-Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
-
-* Update Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-
----------
-
-Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
-
-CVE: CVE-2026-4224
-Upstream-Status: Backport [https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785]
-
-Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
----
- Lib/test/test_pyexpat.py | 18 ++++++++++++++++++
- ...6-03-14-17-31-39.gh-issue-145986.ifSSr8.rst | 4 ++++
- Modules/pyexpat.c | 9 ++++++++-
- 3 files changed, 30 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-
-diff --git a/Lib/test/test_pyexpat.py b/Lib/test/test_pyexpat.py
-index 38f951573f0..37d9086f40a 100644
---- a/Lib/test/test_pyexpat.py
-+++ b/Lib/test/test_pyexpat.py
-@@ -675,6 +675,24 @@ class ChardataBufferTest(unittest.TestCase):
- parser.Parse(xml2, True)
- self.assertEqual(self.n, 4)
-
-+class ElementDeclHandlerTest(unittest.TestCase):
-+ def test_deeply_nested_content_model(self):
-+ # This should raise a RecursionError and not crash.
-+ # See https://github.com/python/cpython/issues/145986.
-+ N = 500_000
-+ data = (
-+ b'<!DOCTYPE root [\n<!ELEMENT root '
-+ + b'(a, ' * N + b'a' + b')' * N
-+ + b'>\n]>\n<root/>\n'
-+ )
-+
-+ parser = expat.ParserCreate()
-+ parser.ElementDeclHandler = lambda _1, _2: None
-+ with support.infinite_recursion():
-+ with self.assertRaises(RecursionError):
-+ parser.Parse(data)
-+
-+
- class MalformedInputTest(unittest.TestCase):
- def test1(self):
- xml = b"\0\r\n"
-diff --git a/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-new file mode 100644
-index 00000000000..cb9dbadb72d
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-@@ -0,0 +1,4 @@
-+:mod:`xml.parsers.expat`: Fixed a crash caused by unbounded C recursion when
-+converting deeply nested XML content models with
-+:meth:`~xml.parsers.expat.xmlparser.ElementDeclHandler`.
-+This addresses `CVE-2026-4224 <https://www.cve.org/CVERecord?id=CVE-2026-4224>`_.
-diff --git a/Modules/pyexpat.c b/Modules/pyexpat.c
-index 79492ca5c4f..8673540f358 100644
---- a/Modules/pyexpat.c
-+++ b/Modules/pyexpat.c
-@@ -3,6 +3,7 @@
- #endif
-
- #include "Python.h"
-+#include "pycore_ceval.h" // _Py_EnterRecursiveCall()
- #include "pycore_runtime.h" // _Py_ID()
- #include <ctype.h>
-
-@@ -578,6 +579,10 @@ static PyObject *
- conv_content_model(XML_Content * const model,
- PyObject *(*conv_string)(const XML_Char *))
- {
-+ if (_Py_EnterRecursiveCall(" in conv_content_model")) {
-+ return NULL;
-+ }
-+
- PyObject *result = NULL;
- PyObject *children = PyTuple_New(model->numchildren);
- int i;
-@@ -589,7 +594,7 @@ conv_content_model(XML_Content * const model,
- conv_string);
- if (child == NULL) {
- Py_XDECREF(children);
-- return NULL;
-+ goto done;
- }
- PyTuple_SET_ITEM(children, i, child);
- }
-@@ -597,6 +602,8 @@ conv_content_model(XML_Content * const model,
- model->type, model->quant,
- conv_string,model->name, children);
- }
-+done:
-+ _Py_LeaveRecursiveCall();
- return result;
- }
-
---
-2.34.1
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
deleted file mode 100644
index 6a4714f25ae..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-4519_CVE-2026-4786.patch
+++ /dev/null
@@ -1,66 +0,0 @@
-From b9af29b9f2f880cdcdc49a1460743680f59dcb4e Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Mon, 13 Apr 2026 22:41:51 +0100
-Subject: [PATCH] [3.11] gh-148169: Fix webbrowser `%action` substitution
- bypass of dash-prefix check (GH-148170) (#148520)
-
-CVE: CVE-2026-4519 CVE-2026-4786
-Upstream-Status: Backport [https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769]
-
-Backport Changes:
-- This file is not present in the current version and is therefore omitted.
- Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst
-
-(cherry picked from commit d22922c8a7958353689dc4763dd72da2dea03fff)
-(cherry picked from commit f4654824ae0850ac87227fb270f9057477946769)
-Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
----
- Lib/test/test_webbrowser.py | 8 ++++++++
- Lib/webbrowser.py | 5 +++--
- 2 files changed, 11 insertions(+), 2 deletions(-)
-
-diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py
-index c9bf525360d..1d21f133725 100644
---- a/Lib/test/test_webbrowser.py
-+++ b/Lib/test/test_webbrowser.py
-@@ -103,6 +103,14 @@ class ChromeCommandTest(CommandTestMixin, unittest.TestCase):
- options=[],
- arguments=[URL])
-
-+ def test_reject_action_dash_prefixes(self):
-+ browser = self.browser_class(name=CMD_NAME)
-+ with self.assertRaises(ValueError):
-+ browser.open('%action--incognito')
-+ # new=1: action is "--new-window", so "%action" itself expands to
-+ # a dash-prefixed flag even with no dash in the original URL.
-+ with self.assertRaises(ValueError):
-+ browser.open('%action', new=1)
-
- class EdgeCommandTest(CommandTestMixin, unittest.TestCase):
-
-diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py
-index 000e89275b7..97c4eec9080 100755
---- a/Lib/webbrowser.py
-+++ b/Lib/webbrowser.py
-@@ -268,7 +268,6 @@ class UnixBrowser(BaseBrowser):
-
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-- self._check_url(url)
- if new == 0:
- action = self.remote_action
- elif new == 1:
-@@ -282,7 +281,9 @@ class UnixBrowser(BaseBrowser):
- raise Error("Bad 'new' parameter to open(); " +
- "expected 0, 1, or 2, got %s" % new)
-
-- args = [arg.replace("%s", url).replace("%action", action)
-+ self._check_url(url.replace("%action", action))
-+
-+ args = [arg.replace("%action", action).replace("%s", url)
- for arg in self.remote_args]
- args = [arg for arg in args if arg]
- success = self._invoke(args, True, autoraise, url)
---
-2.35.6
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
deleted file mode 100644
index 1514d2c5414..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-4519_p1.patch
+++ /dev/null
@@ -1,107 +0,0 @@
-From 7df48dd3c6330611a04d85a5159c0ea424dc1e62 Mon Sep 17 00:00:00 2001
-From: Pinky <pinky00ch@gmail.com>
-Date: Wed, 25 Mar 2026 01:02:37 +0530
-Subject: [PATCH] [3.12] gh-143930: Reject leading dashes in webbrowser
- URLs (GH-146360)
-
-CVE: CVE-2026-4519
-Upstream-Status: Backport [https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48]
-
-Backport Changes:
-- This file is not present in the current version and is therefore omitted
- Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
-
-(cherry picked from commit 82a24a4442312bdcfc4c799885e8b3e00990f02b)
-
-Co-authored-by: Seth Michael Larson <seth@python.org>
-(cherry picked from commit cbba6119391112aba9c5aebf7b94aea447922c48)
-Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
----
- Lib/test/test_webbrowser.py | 5 +++++
- Lib/webbrowser.py | 12 ++++++++++++
- 2 files changed, 17 insertions(+)
-
-diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py
-index 2d695bc8831..60f094fd6a1 100644
---- a/Lib/test/test_webbrowser.py
-+++ b/Lib/test/test_webbrowser.py
-@@ -59,6 +59,11 @@ class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase):
- options=[],
- arguments=[URL])
-
-+ def test_reject_dash_prefixes(self):
-+ browser = self.browser_class(name=CMD_NAME)
-+ with self.assertRaises(ValueError):
-+ browser.open(f"--key=val {URL}")
-+
-
- class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase):
-
-diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py
-index 13b9e85f9e1..0bdb644d7db 100755
---- a/Lib/webbrowser.py
-+++ b/Lib/webbrowser.py
-@@ -158,6 +158,12 @@ class BaseBrowser(object):
- def open_new_tab(self, url):
- return self.open(url, 2)
-
-+ @staticmethod
-+ def _check_url(url):
-+ """Ensures that the URL is safe to pass to subprocesses as a parameter"""
-+ if url and url.lstrip().startswith("-"):
-+ raise ValueError(f"Invalid URL: {url}")
-+
-
- class GenericBrowser(BaseBrowser):
- """Class for all browsers started with a command
-@@ -175,6 +181,7 @@ class GenericBrowser(BaseBrowser):
-
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- cmdline = [self.name] + [arg.replace("%s", url)
- for arg in self.args]
- try:
-@@ -195,6 +202,7 @@ class BackgroundBrowser(GenericBrowser):
- cmdline = [self.name] + [arg.replace("%s", url)
- for arg in self.args]
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- try:
- if sys.platform[:3] == 'win':
- p = subprocess.Popen(cmdline)
-@@ -260,6 +268,7 @@ class UnixBrowser(BaseBrowser):
-
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- if new == 0:
- action = self.remote_action
- elif new == 1:
-@@ -350,6 +359,7 @@ class Konqueror(BaseBrowser):
-
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- # XXX Currently I know no way to prevent KFM from opening a new win.
- if new == 2:
- action = "newTab"
-@@ -554,6 +564,7 @@ if sys.platform[:3] == "win":
- class WindowsDefault(BaseBrowser):
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- try:
- os.startfile(url)
- except OSError:
-@@ -638,6 +649,7 @@ if sys.platform == 'darwin':
-
- def open(self, url, new=0, autoraise=True):
- sys.audit("webbrowser.open", url)
-+ self._check_url(url)
- if self.name == 'default':
- script = 'open location "%s"' % url.replace('"', '%22') # opens in default browser
- else:
---
-2.35.6
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch b/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
deleted file mode 100644
index 7ee145e5e80..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-4519_p2.patch
+++ /dev/null
@@ -1,159 +0,0 @@
-From 3ca64ff1722d2410a4e50e760de70f6279fa99fa Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Sat, 4 Apr 2026 00:53:49 +0200
-Subject: [PATCH] [3.11] gh-143930: Tweak the exception message and
- increase test coverage (GH-146476) (GH-148045) (GH-148051) (GH-148052)
-MIME-Version: 1.0
-Content-Type: text/plain; charset=UTF-8
-Content-Transfer-Encoding: 8bit
-
-CVE: CVE-2026-4519
-Upstream-Status: Backport [https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c]
-
-Backport Changes:
-- This file is not present in the current version and is therefore omitted.
- Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
-- The file introduced in v3.12 by this commit;
- https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
-
-(cherry picked from commit cc023511238ad93ecc8796157c6f9139a2bb2932)
-(cherry picked from commit 89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4)
-(cherry picked from commit 3681d47a440865aead912a054d4599087b4270dd)
-
-Co-authored-by: Łukasz Langa <lukasz@langa.pl>
-(cherry picked from commit 96fc5048605863c7b6fd6289643feb0e97edd96c)
-Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
----
- Lib/test/test_webbrowser.py | 81 ++++++++++++++++++++++++++++++++++---
- Lib/webbrowser.py | 2 +-
- 2 files changed, 76 insertions(+), 7 deletions(-)
-
-diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py
-index 60f094fd6a1..c9bf525360d 100644
---- a/Lib/test/test_webbrowser.py
-+++ b/Lib/test/test_webbrowser.py
-@@ -1,6 +1,7 @@
-+import io
-+import os
- import webbrowser
- import unittest
--import os
- import sys
- import subprocess
- from unittest import mock
-@@ -49,6 +50,14 @@ class CommandTestMixin:
- popen_args.pop(popen_args.index(option))
- self.assertEqual(popen_args, arguments)
-
-+ def test_reject_dash_prefixes(self):
-+ browser = self.browser_class(name=CMD_NAME)
-+ with self.assertRaisesRegex(
-+ ValueError,
-+ r"^Invalid URL \(leading dash disallowed\): '--key=val http.*'$"
-+ ):
-+ browser.open(f"--key=val {URL}")
-+
-
- class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase):
-
-@@ -59,11 +68,6 @@ class GenericBrowserCommandTest(CommandTestMixin, unittest.TestCase):
- options=[],
- arguments=[URL])
-
-- def test_reject_dash_prefixes(self):
-- browser = self.browser_class(name=CMD_NAME)
-- with self.assertRaises(ValueError):
-- browser.open(f"--key=val {URL}")
--
-
- class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase):
-
-@@ -224,6 +228,71 @@ class ELinksCommandTest(CommandTestMixin, unittest.TestCase):
- arguments=['openURL({},new-tab)'.format(URL)])
-
-
-+class MockPopenPipe:
-+ def __init__(self, cmd, mode):
-+ self.cmd = cmd
-+ self.mode = mode
-+ self.pipe = io.StringIO()
-+ self._closed = False
-+
-+ def write(self, buf):
-+ self.pipe.write(buf)
-+
-+ def close(self):
-+ self._closed = True
-+ return None
-+
-+
-+@unittest.skipUnless(sys.platform == "darwin", "macOS specific test")
-+class MacOSXOSAScriptTest(unittest.TestCase):
-+ def setUp(self):
-+ # Ensure that 'BROWSER' is not set to 'open' or something else.
-+ # See: https://github.com/python/cpython/issues/131254.
-+ env = self.enterContext(os_helper.EnvironmentVarGuard())
-+ env.unset("BROWSER")
-+
-+ support.patch(self, os, "popen", self.mock_popen)
-+ self.browser = webbrowser.MacOSXOSAScript("default")
-+
-+ def mock_popen(self, cmd, mode):
-+ self.popen_pipe = MockPopenPipe(cmd, mode)
-+ return self.popen_pipe
-+
-+ def test_default(self):
-+ browser = webbrowser.get()
-+ assert isinstance(browser, webbrowser.MacOSXOSAScript)
-+ self.assertEqual(browser.name, "default")
-+
-+ def test_default_open(self):
-+ url = "https://python.org"
-+ self.browser.open(url)
-+ self.assertTrue(self.popen_pipe._closed)
-+ self.assertEqual(self.popen_pipe.cmd, "osascript")
-+ script = self.popen_pipe.pipe.getvalue()
-+ self.assertEqual(script.strip(), f'open location "{url}"')
-+
-+ def test_url_quote(self):
-+ self.browser.open('https://python.org/"quote"')
-+ script = self.popen_pipe.pipe.getvalue()
-+ self.assertEqual(
-+ script.strip(), 'open location "https://python.org/%22quote%22"'
-+ )
-+
-+ def test_explicit_browser(self):
-+ browser = webbrowser.MacOSXOSAScript("safari")
-+ browser.open("https://python.org")
-+ script = self.popen_pipe.pipe.getvalue()
-+ self.assertIn('tell application "safari"', script)
-+ self.assertIn('open location "https://python.org"', script)
-+
-+ def test_reject_dash_prefixes(self):
-+ with self.assertRaisesRegex(
-+ ValueError,
-+ r"^Invalid URL \(leading dash disallowed\): '--key=val http.*'$"
-+ ):
-+ self.browser.open(f"--key=val {URL}")
-+
-+
- class BrowserRegistrationTest(unittest.TestCase):
-
- def setUp(self):
-diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py
-index 0bdb644d7db..000e89275b7 100755
---- a/Lib/webbrowser.py
-+++ b/Lib/webbrowser.py
-@@ -162,7 +162,7 @@ class BaseBrowser(object):
- def _check_url(url):
- """Ensures that the URL is safe to pass to subprocesses as a parameter"""
- if url and url.lstrip().startswith("-"):
-- raise ValueError(f"Invalid URL: {url}")
-+ raise ValueError(f"Invalid URL (leading dash disallowed): {url!r}")
-
-
- class GenericBrowser(BaseBrowser):
---
-2.35.6
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-6100.patch b/meta/recipes-devtools/python/python3/CVE-2026-6100.patch
deleted file mode 100644
index 9084101434b..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-6100.patch
+++ /dev/null
@@ -1,75 +0,0 @@
-From c3cf71c3366fe49acb776a639405c0eea6169c20 Mon Sep 17 00:00:00 2001
-From: "Miss Islington (bot)"
- <31488909+miss-islington@users.noreply.github.com>
-Date: Mon, 13 Apr 2026 03:35:24 +0200
-Subject: [PATCH] [3.13] gh-148395: Fix a possible UAF in
- `{LZMA,BZ2,_Zlib}Decompressor` (GH-148396) (#148479)
-
-gh-148395: Fix a possible UAF in `{LZMA,BZ2,_Zlib}Decompressor` (GH-148396)
-
-Fix dangling input pointer after `MemoryError` in _lzma/_bz2/_ZlibDecompressor.decompress
-(cherry picked from commit 8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2)
-
-Co-authored-by: Stan Ulbrych <stan@python.org>
-
-CVE: CVE-2026-6100
-Upstream-Status: Backport [https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20]
-Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
----
- .../Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst | 5 +++++
- Modules/_bz2module.c | 1 +
- Modules/_lzmamodule.c | 1 +
- Modules/zlibmodule.c | 1 +
- 4 files changed, 8 insertions(+)
- create mode 100644 Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-
-diff --git a/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-new file mode 100644
-index 0000000..9502189
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-@@ -0,0 +1,5 @@
-+Fix a dangling input pointer in :class:`lzma.LZMADecompressor`,
-+:class:`bz2.BZ2Decompressor`, and internal :class:`!zlib._ZlibDecompressor`
-+when memory allocation fails with :exc:`MemoryError`, which could let a
-+subsequent :meth:`!decompress` call read or write through a stale pointer to
-+the already-released caller buffer.
-diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c
-index 97bd44b..a732e89 100644
---- a/Modules/_bz2module.c
-+++ b/Modules/_bz2module.c
-@@ -587,6 +587,7 @@ decompress(BZ2Decompressor *d, char *data, size_t len, Py_ssize_t max_length)
- return result;
-
- error:
-+ bzs->next_in = NULL;
- Py_XDECREF(result);
- return NULL;
- }
-diff --git a/Modules/_lzmamodule.c b/Modules/_lzmamodule.c
-index 7bbd656..103a6ef 100644
---- a/Modules/_lzmamodule.c
-+++ b/Modules/_lzmamodule.c
-@@ -1114,6 +1114,7 @@ decompress(Decompressor *d, uint8_t *data, size_t len, Py_ssize_t max_length)
- return result;
-
- error:
-+ lzs->next_in = NULL;
- Py_XDECREF(result);
- return NULL;
- }
-diff --git a/Modules/zlibmodule.c b/Modules/zlibmodule.c
-index f94c57e..9759593 100644
---- a/Modules/zlibmodule.c
-+++ b/Modules/zlibmodule.c
-@@ -1645,6 +1645,7 @@ decompress(ZlibDecompressor *self, uint8_t *data,
- return result;
-
- error:
-+ self->zst.next_in = NULL;
- Py_XDECREF(result);
- return NULL;
- }
---
-2.50.1
-
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-7210.patch b/meta/recipes-devtools/python/python3/CVE-2026-7210.patch
deleted file mode 100644
index 029eb713e42..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-7210.patch
+++ /dev/null
@@ -1,148 +0,0 @@
-From 2ed6138dea0bc94c726f879501e4525712e885d1 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Sun, 10 May 2026 18:36:26 +0100
-Subject: [PATCH] gh-149018: Use `XML_SetHashSalt16Bytes` in
- `pyexpat`/`_elementtree` when possible (#149023)
-
-
-CVE: CVE-2026-7210
-Upstream-Status: Backport [https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4]
-
-[yocto: Use weak symbol detection for XML_SetHashSalt16Bytes instead of
-XML_COMBINED_VERSION >= 20800, since our backported expat 2.6.4 provides
-the function but does not bump the version macros.]
-
-Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
----
- Include/pyexpat.h | 3 +++
- Include/pyhash.h | 8 +++++---
- .../2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst | 3 +++
- Modules/_elementtree.c | 8 ++++++--
- Modules/pyexpat.c | 22 ++++++++++++++++------
- 5 files changed, 33 insertions(+), 11 deletions(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
-
-diff --git a/Include/pyexpat.h b/Include/pyexpat.h
-index 04548b7684a..d28d6828975 100644
---- a/Include/pyexpat.h
-+++ b/Include/pyexpat.h
-@@ -57,6 +57,9 @@ struct PyExpat_CAPI
- XML_Parser parser, unsigned long long activationThresholdBytes);
- XML_Bool (*SetAllocTrackerMaximumAmplification)(
- XML_Parser parser, float maxAmplificationFactor);
-+ /* might be NULL for expat < 2.8.0 */
-+ XML_Bool (*SetHashSalt16Bytes)(
-+ XML_Parser parser, const uint8_t entropy[16]);
- /* always add new stuff to the end! */
- };
-
-diff --git a/Include/pyhash.h b/Include/pyhash.h
-index 182d223fab1..ec359bd2f35 100644
---- a/Include/pyhash.h
-+++ b/Include/pyhash.h
-@@ -39,14 +39,14 @@ PyAPI_FUNC(Py_hash_t) _Py_HashBytes(const void*, Py_ssize_t);
- * pppppppp ssssssss ........ fnv -- two Py_hash_t
- * k0k0k0k0 k1k1k1k1 ........ siphash -- two uint64_t
- * ........ ........ ssssssss djbx33a -- 16 bytes padding + one Py_hash_t
-- * ........ ........ eeeeeeee pyexpat XML hash salt
-+ * eeeeeeee eeeeeeee eeeeeeee pyexpat XML hash salt
- *
- * memory layout on 32 bit systems
- * cccccccc cccccccc cccccccc uc
- * ppppssss ........ ........ fnv -- two Py_hash_t
- * k0k0k0k0 k1k1k1k1 ........ siphash -- two uint64_t (*)
- * ........ ........ ssss.... djbx33a -- 16 bytes padding + one Py_hash_t
-- * ........ ........ eeee.... pyexpat XML hash salt
-+ * eeeeeeee eeeeeeee eeee.... pyexpat XML hash salt
- *
- * (*) The siphash member may not be available on 32 bit platforms without
- * an unsigned int64 data type.
-@@ -71,7 +71,9 @@ typedef union {
- Py_hash_t suffix;
- } djbx33a;
- struct {
-- unsigned char padding[16];
-+ /* 16 bytes for XML_SetHashSalt16Bytes */
-+ uint8_t hashsalt16[16];
-+ /* 4/8 bytes for legacy XML_SetHashSalt */
- Py_hash_t hashsalt;
- } expat;
- } _Py_HashSecret_t;
-diff --git a/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst b/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
-new file mode 100644
-index 00000000000..d1b5b368684
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
-@@ -0,0 +1,3 @@
-+Improved protection against XML hash-flooding attacks in
-+:mod:`xml.parsers.expat` and :mod:`xml.etree.ElementTree` when Python is
-+compiled with libExpat 2.8.0 or later.
-diff --git a/Modules/_elementtree.c b/Modules/_elementtree.c
-index 56d1508af13..941376613b0 100644
---- a/Modules/_elementtree.c
-+++ b/Modules/_elementtree.c
-@@ -3657,8 +3657,12 @@ _elementtree_XMLParser___init___impl(XMLParserObject *self, PyObject *target,
- PyErr_NoMemory();
- return -1;
- }
-- /* expat < 2.1.0 has no XML_SetHashSalt() */
-- if (EXPAT(st, SetHashSalt) != NULL) {
-+ // Prefer 16-byte entropy, only expat >= 2.8.0. See gh-149018
-+ if (EXPAT(st, SetHashSalt16Bytes) != NULL) {
-+ EXPAT(st, SetHashSalt16Bytes)(self->parser,
-+ _Py_HashSecret.expat.hashsalt16);
-+ }
-+ else if (EXPAT(st, SetHashSalt) != NULL) {
- EXPAT(st, SetHashSalt)(self->parser,
- (unsigned long)_Py_HashSecret.expat.hashsalt);
- }
-diff --git a/Modules/pyexpat.c b/Modules/pyexpat.c
-index 79492ca5c4f..47e3a1b2c00 100644
---- a/Modules/pyexpat.c
-+++ b/Modules/pyexpat.c
-@@ -14,6 +14,11 @@
-
- #include "pyexpat.h"
-
-+/* Use weak symbol to detect XML_SetHashSalt16Bytes at link time.
-+ This allows using the backported function from expat even when the
-+ version macros have not been bumped (e.g. expat 2.6.4 + CVE-2026-41080). */
-+#pragma weak XML_SetHashSalt16Bytes
-+
- /* Do not emit Clinic output to a file as that wreaks havoc with conditionally
- included methods. */
- /*[clinic input]
-@@ -1388,10 +1393,16 @@ newxmlparseobject(pyexpat_state *state, const char *encoding,
- Py_DECREF(self);
- return NULL;
- }
--#if XML_COMBINED_VERSION >= 20100
-- /* This feature was added upstream in libexpat 2.1.0. */
-- XML_SetHashSalt(self->itself,
-- (unsigned long)_Py_HashSecret.expat.hashsalt);
-+ /* Prefer 16-byte entropy (expat >= 2.8.0 or backported). */
-+ if (XML_SetHashSalt16Bytes != NULL) {
-+ XML_SetHashSalt16Bytes(self->itself, _Py_HashSecret.expat.hashsalt16);
-+ }
-+#if XML_COMBINED_VERSION >= 20100
-+ else {
-+ /* This feature was added upstream in libexpat 2.1.0. */
-+ XML_SetHashSalt(self->itself,
-+ (unsigned long)_Py_HashSecret.expat.hashsalt);
-+ }
- #endif
- XML_SetUserData(self->itself, (void *)self);
- XML_SetUnknownEncodingHandler(self->itself,
-@@ -2257,6 +2267,12 @@ pyexpat_exec(PyObject *mod)
- #else
- capi->SetHashSalt = NULL;
- #endif
-+ /* Detect at runtime via weak symbol */
-+ if (XML_SetHashSalt16Bytes != NULL) {
-+ capi->SetHashSalt16Bytes = XML_SetHashSalt16Bytes;
-+ } else {
-+ capi->SetHashSalt16Bytes = NULL;
-+ }
- #if XML_COMBINED_VERSION >= 20600
- capi->SetReparseDeferralEnabled = XML_SetReparseDeferralEnabled;
- #else
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-9669.patch b/meta/recipes-devtools/python/python3/CVE-2026-9669.patch
deleted file mode 100644
index 266c8beef05..00000000000
--- a/meta/recipes-devtools/python/python3/CVE-2026-9669.patch
+++ /dev/null
@@ -1,96 +0,0 @@
-From 5b412e1f7bdb3e0667b2bc8b216ad216d59d8373 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Mon, 8 Jun 2026 11:55:32 +0200
-Subject: [PATCH] gh-150599: Prevent bz2 decompressor reuse after errors
- (GH-150600)
-
-CVE: CVE-2026-9669
-Upstream-Status: Backport [https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e]
-
-Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
----
- Lib/test/test_bz2.py | 15 +++++++++++++++
- Modules/_bz2module.c | 18 +++++++++++++++---
- 2 files changed, 30 insertions(+), 3 deletions(-)
-
-diff --git a/Lib/test/test_bz2.py b/Lib/test/test_bz2.py
-index cb730a1a46e2..dcbf6a298264 100644
---- a/Lib/test/test_bz2.py
-+++ b/Lib/test/test_bz2.py
-@@ -958,6 +958,21 @@ def test_failure(self):
- # Previously, a second call could crash due to internal inconsistency
- self.assertRaises(Exception, bzd.decompress, self.BAD_DATA * 30)
-
-+ def test_decompress_after_data_error(self):
-+ data = bytes.fromhex(
-+ "425a6839314159265359000000000000007fffff000000000000000000000000"
-+ "00000000000000000000000000000000000000e0370000000000000000000000"
-+ "000000000000000000000000000000000000000000000000000083f3"
-+ )
-+ bzd = BZ2Decompressor()
-+ with self.assertRaisesRegex(OSError, "Invalid data stream"):
-+ bzd.decompress(data)
-+ # Previously, a second call could crash due to internal inconsistency
-+ self.assertFalse(bzd.needs_input)
-+ self.assertFalse(bzd.eof)
-+ with self.assertRaisesRegex(ValueError, "previous error"):
-+ bzd.decompress(b'\x00' * 18)
-+
- @support.refcount_test
- def test_refleaks_in___init__(self):
- gettotalrefcount = support.get_attribute(sys, 'gettotalrefcount')
-diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c
-index 97bd44b4ac96..0b0916142f57 100644
---- a/Modules/_bz2module.c
-+++ b/Modules/_bz2module.c
-@@ -114,6 +114,7 @@ typedef struct {
- typedef struct {
- PyObject_HEAD
- bz_stream bzs;
-+ int bzerror;
- char eof; /* T_BOOL expects a char */
- PyObject *unused_data;
- char needs_input;
-@@ -453,8 +454,11 @@ decompress_buf(BZ2Decompressor *d, Py_ssize_t max_length)
-
- d->bzs_avail_in_real += bzs->avail_in;
-
-- if (catch_bz2_error(bzret))
-+ if (catch_bz2_error(bzret)) {
-+ d->bzerror = bzret;
-+ d->needs_input = 0;
- goto error;
-+ }
- if (bzret == BZ_STREAM_END) {
- d->eof = 1;
- break;
-@@ -621,10 +625,17 @@ _bz2_BZ2Decompressor_decompress_impl(BZ2Decompressor *self, Py_buffer *data,
- PyObject *result = NULL;
-
- ACQUIRE_LOCK(self);
-- if (self->eof)
-+ if (self->eof) {
- PyErr_SetString(PyExc_EOFError, "End of stream already reached");
-- else
-+ }
-+ else if (self->bzerror) {
-+ // Re-entering BZ2_bzDecompress() after an error can write out of bounds.
-+ PyErr_SetString(PyExc_ValueError,
-+ "Decompressor is unusable after a previous error");
-+ }
-+ else {
- result = decompress(self, data->buf, data->len, max_length);
-+ }
- RELEASE_LOCK(self);
- return result;
- }
-@@ -658,6 +669,7 @@ _bz2_BZ2Decompressor_impl(PyTypeObject *type)
- return NULL;
- }
-
-+ self->bzerror = 0;
- self->needs_input = 1;
- self->bzs_avail_in_real = 0;
- self->input_buffer = NULL;
---
-2.54.0
diff --git a/meta/recipes-devtools/python/python3/makerace.patch b/meta/recipes-devtools/python/python3/makerace.patch
index fbe12a5fca2..4575a30bfcf 100644
--- a/meta/recipes-devtools/python/python3/makerace.patch
+++ b/meta/recipes-devtools/python/python3/makerace.patch
@@ -20,7 +20,7 @@ diff --git a/Makefile.pre.in b/Makefile.pre.in
index dce36a5..2d235d2 100644
--- a/Makefile.pre.in
+++ b/Makefile.pre.in
-@@ -2267,7 +2267,7 @@ COMPILEALL_OPTS=-j0
+@@ -2272,7 +2272,7 @@ COMPILEALL_OPTS=-j0
TEST_MODULES=@TEST_MODULES@
.PHONY: libinstall
diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.14.bb
similarity index 96%
rename from meta/recipes-devtools/python/python3_3.12.13.bb
rename to meta/recipes-devtools/python/python3_3.12.14.bb
index b6ceb0c6343..7ee32601cd3 100644
--- a/meta/recipes-devtools/python/python3_3.12.13.bb
+++ b/meta/recipes-devtools/python/python3_3.12.14.bb
@@ -31,30 +31,18 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \
file://0001-test_storlines-skip-due-to-load-variability.patch \
file://0001-test_shutdown-skip-problematic-test.patch \
file://0001-gh-107811-tarfile-treat-overflow-in-UID-GID-as-failu.patch \
- file://0001-test_deadlock-skip-problematic-test.patch \
- file://0001-test_active_children-skip-problematic-test.patch \
+ file://0001-test_deadlock-skip-problematic-test.patch \
+ file://0001-test_active_children-skip-problematic-test.patch \
file://0001-test_readline-skip-limited-history-test.patch \
- file://CVE-2026-1502.patch \
- file://CVE-2026-6100.patch \
- file://CVE-2026-3644_CVE-2026-0672.patch \
- file://CVE-2026-4519_p1.patch \
- file://CVE-2026-4519_p2.patch \
- file://CVE-2026-4519_CVE-2026-4786.patch \
file://CVE-2026-6019_p1.patch \
file://CVE-2026-6019_p2.patch \
- file://CVE-2025-13462.patch \
- file://CVE-2026-4224.patch \
- file://CVE-2026-11940.patch \
- file://CVE-2026-11972.patch \
- file://CVE-2026-9669.patch \
- file://CVE-2026-7210.patch \
"
SRC_URI:append:class-native = " \
file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \
"
-SRC_URI[sha256sum] = "c08bc65a81971c1dd5783182826503369466c7e67374d1646519adf05207b684"
+SRC_URI[sha256sum] = "5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a"
# exclude pre-releases for both python 2.x and 3.x
UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
@@ -69,6 +57,12 @@ CVE_STATUS[CVE-2022-26488] = "not-applicable-platform: Issue only applies on Win
CVE_STATUS[CVE-2015-20107] = "upstream-wontfix: The mailcap module is insecure by design, so this can't be fixed in a meaningful way"
CVE_STATUS[CVE-2023-36632] = "disputed: Not an issue, in fact expected behaviour"
CVE_STATUS[CVE-2026-3087] = "not-applicable-platform: Issue only applies on Windows"
+CVE_STATUS[CVE-2025-12084] = "cpe-stable-backport: Fixed in v3.12.13"
+CVE_STATUS[CVE-2025-13462] = "cpe-stable-backport: Fixed in v3.12.14"
+CVE_STATUS[CVE-2025-13837] = "cpe-stable-backport: Fixed in v3.12.13"
+CVE_STATUS[CVE-2026-3644] = "cpe-stable-backport: Fixed in v3.12.14"
+CVE_STATUS[CVE-2026-4519] = "cpe-stable-backport: Fixed in v3.12.14"
+CVE_STATUS[CVE-2026-7210] = "cpe-stable-backport: Fixed in v3.12.14"
PYTHON_MAJMIN = "3.12"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121 Yoann Congal
` (19 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Full changelog (36 commits):
* https://github.com/systemd/systemd-stable/compare/v255.21...v255.22
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed changelog URL]
---
...temd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} | 0
.../systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} | 0
meta/recipes-core/systemd/systemd.inc | 2 +-
.../systemd/{systemd_255.21.bb => systemd_255.22.bb} | 0
4 files changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-core/systemd/{systemd-boot-native_255.21.bb => systemd-boot-native_255.22.bb} (100%)
rename meta/recipes-core/systemd/{systemd-boot_255.21.bb => systemd-boot_255.22.bb} (100%)
rename meta/recipes-core/systemd/{systemd_255.21.bb => systemd_255.22.bb} (100%)
diff --git a/meta/recipes-core/systemd/systemd-boot-native_255.21.bb b/meta/recipes-core/systemd/systemd-boot-native_255.22.bb
similarity index 100%
rename from meta/recipes-core/systemd/systemd-boot-native_255.21.bb
rename to meta/recipes-core/systemd/systemd-boot-native_255.22.bb
diff --git a/meta/recipes-core/systemd/systemd-boot_255.21.bb b/meta/recipes-core/systemd/systemd-boot_255.22.bb
similarity index 100%
rename from meta/recipes-core/systemd/systemd-boot_255.21.bb
rename to meta/recipes-core/systemd/systemd-boot_255.22.bb
diff --git a/meta/recipes-core/systemd/systemd.inc b/meta/recipes-core/systemd/systemd.inc
index 28392b6b09d..42e51913da4 100644
--- a/meta/recipes-core/systemd/systemd.inc
+++ b/meta/recipes-core/systemd/systemd.inc
@@ -15,7 +15,7 @@ LICENSE:libsystemd = "LGPL-2.1-or-later"
LIC_FILES_CHKSUM = "file://LICENSE.GPL2;md5=751419260aa954499f7abaabaa882bbe \
file://LICENSE.LGPL2.1;md5=4fbd65380cdd255951079008b364516c"
-SRCREV = "70500d37992a01d3275b1c414c3ed161d6f91f9e"
+SRCREV = "356c54394add8c6a1d52773852c23656590dc33b"
SRCBRANCH = "v255-stable"
SRC_URI = "git://github.com/systemd/systemd-stable.git;protocol=https;branch=${SRCBRANCH}"
diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.22.bb
similarity index 100%
rename from meta/recipes-core/systemd/systemd_255.21.bb
rename to meta/recipes-core/systemd/systemd_255.22.bb
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745 Yoann Congal
` (18 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Cherry-pick patch for this CVE mentioned in [1].
Since the actual code change is already included in previous patch for
CVE-2026-4426, add reference to CVE-2026-5121 to that patch and keep the
remaining part (test) as CVE-2026-5121-02.patch.
[1] https://security-tracker.debian.org/tracker/CVE-2026-5121
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...atch => CVE-2026-4426_CVE-2026-5121.patch} | 1 +
.../libarchive/CVE-2026-5121-02.patch | 1270 +++++++++++++++++
.../libarchive/libarchive_3.7.9.bb | 3 +-
3 files changed, 1273 insertions(+), 1 deletion(-)
rename meta/recipes-extended/libarchive/libarchive/{CVE-2026-4426.patch => CVE-2026-4426_CVE-2026-5121.patch} (99%)
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch
similarity index 99%
rename from meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch
rename to meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch
index c303c2372a5..bc754e742a9 100644
--- a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426.patch
+++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4426_CVE-2026-5121.patch
@@ -21,6 +21,7 @@ decompression path from executing.
Found by fuzzing with ASAN/UBSAN.
CVE: CVE-2026-4426
+CVE: CVE-2026-5121
Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/c3cb1c568ebf9e8f7f478cfc0356ae54e99712b0]
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
---
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
new file mode 100644
index 00000000000..90b9e6f6102
--- /dev/null
+++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5121-02.patch
@@ -0,0 +1,1270 @@
+From a2a73a8f14b3208c7f6acbbc93265254a7c1efd0 Mon Sep 17 00:00:00 2001
+From: elhananhaenel <elhanan.haenel@mail.huji.ac.il>
+Date: Thu, 19 Mar 2026 16:43:29 +0200
+Subject: [PATCH] Add regression test for zisofs 32-bit heap overflow
+
+A crafted ISO with pz_log2_bs=2 and pz_uncompressed_size=0xFFFFFFF9
+causes an integer overflow in the block pointer allocation in
+zisofs_read_data(). On 32-bit, (ceil+1)*4 wraps size_t to 0, malloc(0)
+returns a tiny buffer, and the code writes ~4GB past it.
+
+The pz_log2_bs validation fix prevents this. Add a regression test with
+a crafted 48KB ISO that triggers the overflow on unfixed 32-bit builds.
+
+CVE: CVE-2026-5121
+Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/a2a73a8f14b3208c7f6acbbc93265254a7c1efd0]
+Modification: part of oupstream patch is moved to CVE-2026-4426_CVE-2026-5121.patch
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ Makefile.am | 2 +
+ libarchive/test/CMakeLists.txt | 1 +
+ .../test_read_format_iso_zisofs_overflow.c | 104 ++
+ ...est_read_format_iso_zisofs_overflow.iso.uu | 1096 +++++++++++++++++
+ 4 files changed, 1203 insertions(+)
+ create mode 100644 libarchive/test/test_read_format_iso_zisofs_overflow.c
+ create mode 100644 libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu
+
+diff --git a/Makefile.am b/Makefile.am
+index 57102431..e55882af 100644
+--- a/Makefile.am
++++ b/Makefile.am
+@@ -505,6 +505,7 @@ libarchive_test_SOURCES= \
+ libarchive/test/test_read_format_isorr_new_bz2.c \
+ libarchive/test/test_read_format_isorr_rr_moved.c \
+ libarchive/test/test_read_format_isozisofs_bz2.c \
++ libarchive/test/test_read_format_iso_zisofs_overflow.c \
+ libarchive/test/test_read_format_lha.c \
+ libarchive/test/test_read_format_lha_bugfix_0.c \
+ libarchive/test/test_read_format_lha_filename.c \
+@@ -861,6 +862,7 @@ libarchive_test_EXTRA_DIST=\
+ libarchive/test/test_read_format_iso_rockridge_rr_moved.iso.Z.uu \
+ libarchive/test/test_read_format_iso_xorriso.iso.Z.uu \
+ libarchive/test/test_read_format_iso_zisofs.iso.Z.uu \
++ libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu \
+ libarchive/test/test_read_format_lha_bugfix_0.lzh.uu \
+ libarchive/test/test_read_format_lha_filename_cp932.lzh.uu \
+ libarchive/test/test_read_format_lha_filename_utf16.lzh.uu \
+diff --git a/libarchive/test/CMakeLists.txt b/libarchive/test/CMakeLists.txt
+index 4838f336..95c1b33f 100644
+--- a/libarchive/test/CMakeLists.txt
++++ b/libarchive/test/CMakeLists.txt
+@@ -149,6 +149,7 @@ IF(ENABLE_TEST)
+ test_read_format_isorr_new_bz2.c
+ test_read_format_isorr_rr_moved.c
+ test_read_format_isozisofs_bz2.c
++ test_read_format_iso_zisofs_overflow.c
+ test_read_format_lha.c
+ test_read_format_lha_bugfix_0.c
+ test_read_format_lha_filename.c
+diff --git a/libarchive/test/test_read_format_iso_zisofs_overflow.c b/libarchive/test/test_read_format_iso_zisofs_overflow.c
+new file mode 100644
+index 00000000..bad52b15
+--- /dev/null
++++ b/libarchive/test/test_read_format_iso_zisofs_overflow.c
+@@ -0,0 +1,104 @@
++/*-
++ * Copyright (c) 2025
++ * All rights reserved.
++ *
++ * Redistribution and use in source and binary forms, with or without
++ * modification, are permitted provided that the following conditions
++ * are met:
++ * 1. Redistributions of source code must retain the above copyright
++ * notice, this list of conditions and the following disclaimer.
++ * 2. Redistributions in binary form must reproduce the above copyright
++ * notice, this list of conditions and the following disclaimer in the
++ * documentation and/or other materials provided with the distribution.
++ *
++ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR
++ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
++ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
++ * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT,
++ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
++ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
++ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
++ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
++ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
++ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
++ */
++#include "test.h"
++
++/*
++ * Verify that a crafted ISO9660 image with an invalid zisofs block-size
++ * exponent (pz_log2_bs) is handled gracefully.
++ *
++ * The ZF extension in the Rock Ridge entry stores pz_log2_bs as a raw
++ * byte from the image. The zisofs spec only permits values 15-17.
++ * Values outside that range can cause:
++ * - Undefined behavior via oversized bit shifts (any platform)
++ * - Integer overflow in block pointer allocation on 32-bit platforms,
++ * leading to a heap buffer overflow write
++ *
++ * The test image has pz_log2_bs=2 (out of spec) combined with
++ * pz_uncompressed_size=0xFFFFFFF9. On 32-bit, (ceil+1)*4 overflows
++ * size_t to 0, malloc(0) returns a tiny buffer, and the code attempts
++ * to write ~4GB into it. On 64-bit the allocation is huge and safely
++ * fails.
++ *
++ * We verify the fix by checking archive_entry_size() after reading the
++ * header. When pz_log2_bs validation rejects the bad value (pz=0),
++ * the entry keeps its raw on-disk size (small). Without the fix,
++ * the reader sets the entry size to pz_uncompressed_size (0xFFFFFFF9).
++ *
++ * We intentionally do NOT call archive_read_data() here. Without the
++ * fix, the data-read path triggers a heap buffer overflow on 32-bit
++ * that silently corrupts the process heap, causing later tests to
++ * crash rather than this one.
++ */
++DEFINE_TEST(test_read_format_iso_zisofs_overflow)
++{
++ const char reffile[] = "test_read_format_iso_zisofs_overflow.iso";
++ struct archive *a;
++ struct archive_entry *ae;
++ int r = ARCHIVE_OK;
++ int found_regular_file = 0;
++
++ extract_reference_file(reffile);
++ assert((a = archive_read_new()) != NULL);
++ assertEqualIntA(a, ARCHIVE_OK, archive_read_support_filter_all(a));
++ assertEqualIntA(a, ARCHIVE_OK, archive_read_support_format_all(a));
++ assertEqualIntA(a, ARCHIVE_OK,
++ archive_read_open_filename(a, reffile, 10240));
++
++ while ((r = archive_read_next_header(a, &ae)) == ARCHIVE_OK ||
++ r == ARCHIVE_WARN) {
++ /*
++ * With the fix, pz_log2_bs=2 is rejected and pz is set
++ * to 0, so the entry keeps its small raw size from the
++ * ISO directory record. Without the fix, zisofs sets
++ * the entry size to pz_uncompressed_size (0xFFFFFFF9).
++ *
++ * We intentionally do NOT call archive_read_data().
++ * Without the fix, the data-read path triggers a heap
++ * buffer overflow on 32-bit that silently corrupts the
++ * process heap, causing later tests to crash rather
++ * than this one.
++ */
++ if (archive_entry_filetype(ae) == AE_IFREG) {
++ la_int64_t sz = archive_entry_size(ae);
++ failure("entry \"%s\" has size %jd"
++ "; expected < 1 MiB"
++ " (if size is 4294966265 = 0xFFFFFFF9, the"
++ " pz_log2_bs validation is missing)",
++ archive_entry_pathname(ae), (intmax_t)sz);
++ assert(sz < 1024 * 1024);
++ found_regular_file = 1;
++ }
++ }
++
++ /* Iteration must have completed normally. */
++ assertEqualInt(ARCHIVE_EOF, r);
++
++ /* The PoC image contains a regular file; if we never saw one,
++ * something is wrong with the test image. */
++ assert(found_regular_file);
++
++ assertEqualIntA(a, ARCHIVE_OK, archive_read_close(a));
++ assertEqualInt(ARCHIVE_OK, archive_read_free(a));
++}
+diff --git a/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu b/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu
+new file mode 100644
+index 00000000..5e7dcc37
+--- /dev/null
++++ b/libarchive/test/test_read_format_iso_zisofs_overflow.iso.uu
+@@ -0,0 +1,1096 @@
++begin 664 test_read_format_iso_zisofs_overflow.iso
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M```````````!0T0P,#$!````````````````````````````````````````
++M````4$]#7U=2251%`````````````````````````````````````````!@`
++M```````8```````````````````````````````````````````!```!`0``
++M`0`("``*````````"A(`````````````$@`````B`!,````````3``@`````
++M"`!Z`1D,`````@```0```0$`````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M``````````````````````````````````````````````$`````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M`````````````````````````````````````````/]#1#`P,0$`````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M`````````````0`3`````0``````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M``````````````````````````````````````````!5`!,````````3``@`
++M````"`!Z`1D,`````@```0```0$`4U`'`;[O`%!8+`'M00````!![0(`````
++M```"``````````````````````$````````!(@`3````````$P`(``````@`
++M>@$9#`````(```$```$!`7T`%````````!00"``````($'H!&0P````````!
++M```!#D]615)&3$]7+D))3CLQ`%I&$`%P>@0"^?O__P````!.31$!`$]615)&
++M3$]7+D))3E!8+`&D@0````"!I`$````````!``````````````````````(`
++M```````"````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M`````````````#?D4Y;)V]8'^?O__P0"``!!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!
++M0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"
++M0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#
++M1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$04)#1$%"0T1!0D-$
++M04)#1```````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++M````````````````````````````````````````````````````````````
++,````````````````
++`
++end
diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
index c167b164b4b..fb6ed5686df 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
@@ -46,9 +46,10 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \
file://CVE-2025-60753-02.patch \
file://CVE-2026-4111-1.patch \
file://CVE-2026-4111-2.patch \
- file://CVE-2026-4426.patch \
+ file://CVE-2026-4426_CVE-2026-5121.patch \
file://CVE-2026-4424-1.patch \
file://CVE-2026-4424-2.patch \
+ file://CVE-2026-5121-02.patch \
"
UPSTREAM_CHECK_URI = "http://libarchive.org/"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584 Yoann Congal
` (17 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://security-tracker.debian.org/tracker/CVE-2026-5745
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libarchive/libarchive/CVE-2026-5745.patch | 39 +++++++++++++++++++
.../libarchive/libarchive_3.7.9.bb | 1 +
2 files changed, 40 insertions(+)
create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
new file mode 100644
index 00000000000..a060b081ad8
--- /dev/null
+++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-5745.patch
@@ -0,0 +1,39 @@
+From 5f7025543205106d64081cbafd8c345bf859b86f Mon Sep 17 00:00:00 2001
+From: Tim Kientzle <kientzle@acm.org>
+Date: Sat, 18 Apr 2026 21:04:59 -0700
+Subject: [PATCH] Merge pull request #2905 from Patsakas/Patsakas-fix-acl-bug
+
+Fix NULL pointer increment in archive_acl_from_text_nl
+
+(Not a security issue, and arguably not really even a bug, but easy to fix regardless.)
+
+(cherry picked from commit 0b0b888f86b46e3b279f5f7c6eef0479f35978ee)
+
+CVE: CVE-2026-5745
+Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/5f7025543205106d64081cbafd8c345bf859b86f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ libarchive/archive_acl.c | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/libarchive/archive_acl.c b/libarchive/archive_acl.c
+index ab601833..14a107a4 100644
+--- a/libarchive/archive_acl.c
++++ b/libarchive/archive_acl.c
+@@ -1718,7 +1718,6 @@ archive_acl_from_text_nl(struct archive_acl *acl, const char *text,
+
+ tag = 0;
+ s = field[n].start;
+- st = field[n].start + 1;
+ len = field[n].end - field[n].start;
+
+ if (len == 0) {
+@@ -1726,6 +1725,8 @@ archive_acl_from_text_nl(struct archive_acl *acl, const char *text,
+ continue;
+ }
+
++ st = s + 1;
++
+ switch (*s) {
+ case 'u':
+ if (len == 1 || (len == 4
diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
index fb6ed5686df..b36632cc1fe 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
@@ -50,6 +50,7 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \
file://CVE-2026-4424-1.patch \
file://CVE-2026-4424-2.patch \
file://CVE-2026-5121-02.patch \
+ file://CVE-2026-5745.patch \
"
UPSTREAM_CHECK_URI = "http://libarchive.org/"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221 Yoann Congal
` (16 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Set status per [1].
[1] https://security-tracker.debian.org/tracker/CVE-2026-1584
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
index 676c5c6f940..0eabc517ce5 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
@@ -129,3 +129,4 @@ pkg_postinst_ontarget:${PN}-fips () {
}
CVE_STATUS[CVE-2026-3832] = "fixed-version: vulnerable multi-record OCSP response handling was introduced in 3.8.8 and is not present in 3.8.4"
+CVE_STATUS[CVE-2026-1584] = "fixed-version: vulnerable code not present, introduced with 3.8.11"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432 Yoann Congal
` (15 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-13221
[2] https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../perl/files/CVE-2026-13221.patch | 75 +++++++++++++++++++
meta/recipes-devtools/perl/perl_5.38.4.bb | 1 +
2 files changed, 76 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-13221.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-13221.patch b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
new file mode 100644
index 00000000000..03396f3e434
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-13221.patch
@@ -0,0 +1,75 @@
+From 03f74bbbd3a68350d926ee93d56ee4808c28c4c7 Mon Sep 17 00:00:00 2001
+From: Karl Williamson <khw@cpan.org>
+Date: Thu, 26 Mar 2026 10:13:49 -0600
+Subject: [PATCH] regcomp_study: Don't create a trie that would overflow
+
+This addresses GH #23388
+
+The design of the trie compiling code is to batch extra long tries into
+smaller chunks that fit into whatever limitations there are. However,
+this ticket shows that that isn't always being done.
+
+In this case, a bunch of branches that have TAIL operands can be
+combined together, and the final TAIL is used. And the code requires
+that the delta between the first branch and this final TAIL fit into a
+16-bit field. That is the root cause of this bug.
+
+I'm not familiar enough with the trie construction code to easily
+understand why the final tail needs to be used here. So this patch
+simply doesn't optimize a sequence of branches into a trie that would
+overflow.
+
+This could be revisited by someone who knows more about this than I, or
+earlier in the development cycle.
+
+CVE: CVE-2026-13221
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ regcomp_study.c | 10 ++++++++++
+ t/re/pat_advanced.t | 9 +++++++++
+ 2 files changed, 19 insertions(+)
+
+diff --git a/regcomp_study.c b/regcomp_study.c
+index db7ab3a409..a1b2c3d4e5 100644
+--- a/regcomp_study.c
++++ b/regcomp_study.c
+@@ -1933,6 +1933,16 @@ Perl_study_chunk(pTHX_
+ tail = regnext( tail );
+ }
+
++ /* The code below currently saves the difference from
++ * start to finish in a 16-bit field, causing
++ * GH #23388. This defeats the design of batching
++ * tries into chunks that each fit. khw thinks it is
++ * too late in the 5.44 cycle to relook at the design,
++ * so for now anyway, don't make a trie that would
++ * overflow */
++ if (tail - startbranch >= U16_MAX) {
++ continue;
++ }
+
+ DEBUG_TRIE_COMPILE_r({
+ regprop(RExC_rx, RExC_mysv, tail, NULL, pRExC_state);
+diff --git a/t/re/pat_advanced.t b/t/re/pat_advanced.t
+index 398680838d..c9e389ecb3 100644
+--- a/t/re/pat_advanced.t
++++ b/t/re/pat_advanced.t
+@@ -4898,6 +4898,15 @@ EOF_DEBUG_OUT
+ $x =~ s/^[\x{0301}\x{030C}]+//;
+ }
+
++ { # GH #23388
++ fresh_perl_is(<<~'PROG', , "", {}, "Avoid trie overflow");
++ my $x = join "|", "aaa".."mzz";
++ my $y = join "|", "naa".."zzz";
++ use re 'Debug';
++ "fnord" =~ m/(?:$x)|(?:$y)/;
++ PROG
++ }
++
+
+ # !!! NOTE that tests that aren't at all likely to crash perl should go
+ # a ways above, above these last ones. There's a comment there that, like
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb
index 9f4cc1c4044..8dccd34499b 100644
--- a/meta/recipes-devtools/perl/perl_5.38.4.bb
+++ b/meta/recipes-devtools/perl/perl_5.38.4.bb
@@ -20,6 +20,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://0001-Fix-intermittent-failure-of-test-t-op-sigsystem.t.patch \
file://CVE-2026-8376-01.patch \
file://CVE-2026-8376-02.patch \
+ file://CVE-2026-13221.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (10 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909 Yoann Congal
` (14 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
This patch applies the upstream fix as referenced in [1], using the
commits shown in [2] and [3].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57432
[2] https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55
[3] https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../perl/files/CVE-2026-57432-01.patch | 52 +++++++++++++++++++
.../perl/files/CVE-2026-57432-02.patch | 34 ++++++++++++
meta/recipes-devtools/perl/perl_5.38.4.bb | 2 +
3 files changed, 88 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
new file mode 100644
index 00000000000..ef92b0d7b21
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-01.patch
@@ -0,0 +1,52 @@
+From 5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Sat, 9 May 2026 17:18:43 +0100
+Subject: [PATCH] pp_pack.c: Avoid ssize_t overflow when calculating the size
+ of a structure
+
+If the user has requested a size that would overflow a SSize_t, then the
+only sensible thing to do is throw an exception, because the structure
+this implies couldn't possibly fit into memory anyway.
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pod/perldiag.pod | 6 ++++++
+ pp_pack.c | 4 ++++
+ 2 files changed, 10 insertions(+)
+
+diff --git a/pod/perldiag.pod b/pod/perldiag.pod
+index 841e22d580..d9231077363d 100644
+--- a/pod/perldiag.pod
++++ b/pod/perldiag.pod
+@@ -4880,6 +4880,12 @@ mixed-case attribute name, instead. See L<attributes>.
+ (F) You can't specify a repeat count so large that it overflows your
+ signed integers. See L<perlfunc/pack>.
+
++=item Pack template structure size is too large
++
++(F) You called C<pack> or C<unpack> to operate on a structure, whose
++computed size is too large to fit in memory. This usually happens as a
++result of embedding a large number as the repeat count for an item.
++
+ =item page overflow
+
+ (W io) A single call to write() produced more lines than can fit on a
+diff --git a/pp_pack.c b/pp_pack.c
+index b5c0b261ef..6075e83aac 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -528,6 +528,10 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+ break;
+ }
+ }
++ if ((size > 0) &&
++ ((len > SSize_t_MAX / size) || /* detect overflow of len * size */
++ (len * size > SSize_t_MAX - total))) /* detect overflow of total + len * size */
++ croak("Pack template structure size is too large");
+ total += len * size;
+ }
+ return total;
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
new file mode 100644
index 00000000000..273a247a88f
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57432-02.patch
@@ -0,0 +1,34 @@
+From 40754edc72dd3e513d758153c0e2f0215897740e Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Mon, 11 May 2026 12:25:33 +0100
+Subject: [PATCH] pp_pack.c: Avoid some other potential overflows when
+ calculating sizes
+
+CVE: CVE-2026-57432
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ pp_pack.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/pp_pack.c b/pp_pack.c
+index 6075e83aac..b2019902203a 100644
+--- a/pp_pack.c
++++ b/pp_pack.c
+@@ -515,12 +515,12 @@ S_measure_struct(pTHX_ tempsym_t* symptr)
+ break;
+ case 'B':
+ case 'b':
+- len = (len + 7)/8;
++ len = (len / 8) + !!(len % 8);
+ size = 1;
+ break;
+ case 'H':
+ case 'h':
+- len = (len + 1)/2;
++ len = (len / 2) + !!(len % 2);
+ size = 1;
+ break;
+
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb
index 8dccd34499b..b4927646d75 100644
--- a/meta/recipes-devtools/perl/perl_5.38.4.bb
+++ b/meta/recipes-devtools/perl/perl_5.38.4.bb
@@ -21,6 +21,8 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://CVE-2026-8376-01.patch \
file://CVE-2026-8376-02.patch \
file://CVE-2026-13221.patch \
+ file://CVE-2026-57432-01.patch \
+ file://CVE-2026-57432-02.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (11 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469 Yoann Congal
` (13 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
This patch applies the upstream fix as referenced in [1], using the
commit shown in [2].
[1] https://nvd.nist.gov/vuln/detail/CVE-2025-40909
[2] https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: CVE-2025-40909.patch is not merged on a main branch but was
provided by upstream to facilitate backport (Thanks!)
https://github.com/Perl/perl5/issues/23010#issuecomment-2919448987
]
---
.../perl-cross/files/CVE-2025-40909-dep.patch | 25 ++
.../perl-cross/perlcross_1.6.2.bb | 1 +
.../perl/files/CVE-2025-40909.patch | 412 ++++++++++++++++++
meta/recipes-devtools/perl/perl_5.38.4.bb | 1 +
4 files changed, 439 insertions(+)
create mode 100644 meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2025-40909.patch
diff --git a/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch b/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
new file mode 100644
index 00000000000..d5d4bf279d2
--- /dev/null
+++ b/meta/recipes-devtools/perl-cross/files/CVE-2025-40909-dep.patch
@@ -0,0 +1,25 @@
+From f702c387e6940fab3801d7562a668b974a2b3a8f Mon Sep 17 00:00:00 2001
+From: Audrey Dutcher <audrey@rhelmot.io>
+Date: Fri, 30 May 2025 12:29:54 -0700
+Subject: [PATCH] add d_fdopendir configuration
+
+Upstream-Status: Submitted [https://github.com/arsv/perl-cross/pull/159]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ cnf/configure_func.sh | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/cnf/configure_func.sh b/cnf/configure_func.sh
+index 4c13e4c..b24fe03 100644
+--- a/cnf/configure_func.sh
++++ b/cnf/configure_func.sh
+@@ -83,6 +83,7 @@ checkfunc d_fchmodat 'fchmodat' "0,NULL,0,0" 'unistd.h sys/stat.h'
+ checkfunc d_fchown 'fchown' "0,0,0" 'unistd.h'
+ checkfunc d_fcntl 'fcntl' "0,0" 'unistd.h fcntl.h'
+ checkfunc d_fdclose 'fdclose' "NULL,NULL" 'stdio.h'
++checkfunc d_fdopendir 'fdopendir' "0" 'dirent.h'
+ checkfunc d_ffs 'ffs' "0" 'strings.h'
+ checkfunc d_ffsl 'ffsl' "0" 'strings.h'
+ checkfunc d_fgetpos 'fgetpos' "NULL, 0" 'stdio.h'
+--
+2.43.0
diff --git a/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb b/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb
index e4bd90c5723..1c5fc27d97b 100644
--- a/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb
+++ b/meta/recipes-devtools/perl-cross/perlcross_1.6.2.bb
@@ -15,6 +15,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/${PV}/perl-cross-${PV}.tar.gz;name=perl-c
file://0001-perl-cross-add-LDFLAGS-when-linking-libperl.patch \
file://determinism.patch \
file://0001-Makefile-check-the-file-if-patched-or-not.patch \
+ file://CVE-2025-40909-dep.patch \
"
GITHUB_BASE_URI = "https://github.com/arsv/perl-cross/releases/"
diff --git a/meta/recipes-devtools/perl/files/CVE-2025-40909.patch b/meta/recipes-devtools/perl/files/CVE-2025-40909.patch
new file mode 100644
index 00000000000..c9418a3574d
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2025-40909.patch
@@ -0,0 +1,412 @@
+From 918bfff86ca8d6d4e4ec5b30994451e0bd74aba9 Mon Sep 17 00:00:00 2001
+From: Leon Timmermans <fawaka@gmail.com>
+Date: Fri, 23 May 2025 15:40:41 +0200
+Subject: [PATCH] CVE-2025-40909: Clone dirhandles without fchdir
+
+This uses fdopendir and dup to dirhandles. This means it won't change
+working directory during thread cloning, which prevents race conditions
+that can happen if a third thread is active at the same time.
+
+CVE: CVE-2025-40909
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9]
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ Configure | 6 ++
+ Cross/config.sh-arm-linux | 1 +
+ Cross/config.sh-arm-linux-n770 | 1 +
+ Porting/Glossary | 5 ++
+ Porting/config.sh | 1 +
+ config_h.SH | 6 ++
+ configure.com | 1 +
+ plan9/config_sh.sample | 1 +
+ sv.c | 91 +----------------------------
+ t/op/threads-dirh.t | 104 +--------------------------------
+ win32/config.gc | 1 +
+ win32/config.vc | 1 +
+ 12 files changed, 28 insertions(+), 191 deletions(-)
+
+diff --git a/Configure b/Configure
+index 44c12ced4014..7a13249caa96 100755
+--- a/Configure
++++ b/Configure
+@@ -478,6 +478,7 @@ d_fd_set=''
+ d_fds_bits=''
+ d_fdclose=''
+ d_fdim=''
++d_fdopendir=''
+ d_fegetround=''
+ d_ffs=''
+ d_ffsl=''
+@@ -13344,6 +13345,10 @@ esac
+ set i_fcntl
+ eval $setvar
+
++: see if fdopendir exists
++set fdopendir d_fdopendir
++eval $inlibc
++
+ : see if fork exists
+ set fork d_fork
+ eval $inlibc
+@@ -25052,6 +25057,7 @@ d_flockproto='$d_flockproto'
+ d_fma='$d_fma'
+ d_fmax='$d_fmax'
+ d_fmin='$d_fmin'
++d_fdopendir='$d_fdopendir'
+ d_fork='$d_fork'
+ d_fp_class='$d_fp_class'
+ d_fp_classify='$d_fp_classify'
+diff --git a/Cross/config.sh-arm-linux b/Cross/config.sh-arm-linux
+index bfa0b00d5f0f..9e056539198b 100644
+--- a/Cross/config.sh-arm-linux
++++ b/Cross/config.sh-arm-linux
+@@ -212,6 +212,7 @@ d_fd_macros='define'
+ d_fd_set='define'
+ d_fdclose='undef'
+ d_fdim='undef'
++d_fdopendir=undef
+ d_fds_bits='undef'
+ d_fegetround='define'
+ d_ffs='undef'
+diff --git a/Cross/config.sh-arm-linux-n770 b/Cross/config.sh-arm-linux-n770
+index 47ad5c37e3fd..365e4c4f9671 100644
+--- a/Cross/config.sh-arm-linux-n770
++++ b/Cross/config.sh-arm-linux-n770
+@@ -211,6 +211,7 @@ d_fd_macros='define'
+ d_fd_set='define'
+ d_fdclose='undef'
+ d_fdim='undef'
++d_fdopendir=undef
+ d_fds_bits='undef'
+ d_fegetround='define'
+ d_ffs='undef'
+diff --git a/Porting/Glossary b/Porting/Glossary
+index bb505c653b0b..8b2965ca99c6 100644
+--- a/Porting/Glossary
++++ b/Porting/Glossary
+@@ -947,6 +947,11 @@ d_fmin (d_fmin.U):
+ This variable conditionally defines the HAS_FMIN symbol, which
+ indicates to the C program that the fmin() routine is available.
+
++d_fdopendir (d_fdopendir.U):
++ This variable conditionally defines the HAS_FORK symbol, which
++ indicates that the fdopen routine is available to open a
++ directory descriptor.
++
+ d_fork (d_fork.U):
+ This variable conditionally defines the HAS_FORK symbol, which
+ indicates to the C program that the fork() routine is available.
+diff --git a/Porting/config.sh b/Porting/config.sh
+index a921f7e1c79a..6231ea0f31ea 100644
+--- a/Porting/config.sh
++++ b/Porting/config.sh
+@@ -223,6 +223,7 @@ d_fd_macros='define'
+ d_fd_set='define'
+ d_fdclose='undef'
+ d_fdim='define'
++d_fdopendir='define'
+ d_fds_bits='define'
+ d_fegetround='define'
+ d_ffs='define'
+diff --git a/config_h.SH b/config_h.SH
+index da0f2dbcd7b7..5a0f81cf2011 100755
+--- a/config_h.SH
++++ b/config_h.SH
+@@ -142,6 +142,12 @@ sed <<!GROK!THIS! >$CONFIG_H -e 's!^#undef\(.*/\)\*!/\*#define\1 \*!' -e 's!^#un
+ */
+ #$d_fcntl HAS_FCNTL /**/
+
++/* HAS_FDOPENDIR:
++ * This symbol, if defined, indicates that the fdopen routine is
++ * available to open a directory descriptor.
++ */
++#$d_fdopendir HAS_FDOPENDIR /**/
++
+ /* HAS_FGETPOS:
+ * This symbol, if defined, indicates that the fgetpos routine is
+ * available to get the file position indicator, similar to ftell().
+diff --git a/configure.com b/configure.com
+index 99527c180bfc..7c38711bb85d 100644
+--- a/configure.com
++++ b/configure.com
+@@ -6010,6 +6010,7 @@ $ WC "d_fd_set='" + d_fd_set + "'"
+ $ WC "d_fd_macros='define'"
+ $ WC "d_fdclose='undef'"
+ $ WC "d_fdim='" + d_fdim + "'"
++$ WC "d_fdopendir='undef'"
+ $ WC "d_fds_bits='define'"
+ $ WC "d_fegetround='undef'"
+ $ WC "d_ffs='undef'"
+diff --git a/plan9/config_sh.sample b/plan9/config_sh.sample
+index 636acbdf6db3..246bad954424 100644
+--- a/plan9/config_sh.sample
++++ b/plan9/config_sh.sample
+@@ -212,6 +212,7 @@ d_fd_macros='undef'
+ d_fd_set='undef'
+ d_fdclose='undef'
+ d_fdim='undef'
++d_fdopendir=undef
+ d_fds_bits='undef'
+ d_fegetround='undef'
+ d_ffs='undef'
+diff --git a/sv.c b/sv.c
+index ae6d09dea28a..8a005b2d165b 100644
+--- a/sv.c
++++ b/sv.c
+@@ -14096,15 +14096,6 @@ Perl_dirp_dup(pTHX_ DIR *const dp, CLONE_PARAMS *const param)
+ {
+ DIR *ret;
+
+-#if defined(HAS_FCHDIR) && defined(HAS_TELLDIR) && defined(HAS_SEEKDIR)
+- DIR *pwd;
+- const Direntry_t *dirent;
+- char smallbuf[256]; /* XXX MAXPATHLEN, surely? */
+- char *name = NULL;
+- STRLEN len = 0;
+- long pos;
+-#endif
+-
+ PERL_UNUSED_CONTEXT;
+ PERL_ARGS_ASSERT_DIRP_DUP;
+
+@@ -14116,89 +14107,13 @@ Perl_dirp_dup(pTHX_ DIR *const dp, CLONE_PARAMS *const param)
+ if (ret)
+ return ret;
+
+-#if defined(HAS_FCHDIR) && defined(HAS_TELLDIR) && defined(HAS_SEEKDIR)
++#ifdef HAS_FDOPENDIR
+
+ PERL_UNUSED_ARG(param);
+
+- /* create anew */
+-
+- /* open the current directory (so we can switch back) */
+- if (!(pwd = PerlDir_open("."))) return (DIR *)NULL;
+-
+- /* chdir to our dir handle and open the present working directory */
+- if (fchdir(my_dirfd(dp)) < 0 || !(ret = PerlDir_open("."))) {
+- PerlDir_close(pwd);
+- return (DIR *)NULL;
+- }
+- /* Now we should have two dir handles pointing to the same dir. */
+-
+- /* Be nice to the calling code and chdir back to where we were. */
+- /* XXX If this fails, then what? */
+- PERL_UNUSED_RESULT(fchdir(my_dirfd(pwd)));
++ ret = fdopendir(dup(my_dirfd(dp)));
+
+- /* We have no need of the pwd handle any more. */
+- PerlDir_close(pwd);
+-
+-#ifdef DIRNAMLEN
+-# define d_namlen(d) (d)->d_namlen
+-#else
+-# define d_namlen(d) strlen((d)->d_name)
+-#endif
+- /* Iterate once through dp, to get the file name at the current posi-
+- tion. Then step back. */
+- pos = PerlDir_tell(dp);
+- if ((dirent = PerlDir_read(dp))) {
+- len = d_namlen(dirent);
+- if (len > sizeof(dirent->d_name) && sizeof(dirent->d_name) > PTRSIZE) {
+- /* If the len is somehow magically longer than the
+- * maximum length of the directory entry, even though
+- * we could fit it in a buffer, we could not copy it
+- * from the dirent. Bail out. */
+- PerlDir_close(ret);
+- return (DIR*)NULL;
+- }
+- if (len <= sizeof smallbuf) name = smallbuf;
+- else Newx(name, len, char);
+- Move(dirent->d_name, name, len, char);
+- }
+- PerlDir_seek(dp, pos);
+-
+- /* Iterate through the new dir handle, till we find a file with the
+- right name. */
+- if (!dirent) /* just before the end */
+- for(;;) {
+- pos = PerlDir_tell(ret);
+- if (PerlDir_read(ret)) continue; /* not there yet */
+- PerlDir_seek(ret, pos); /* step back */
+- break;
+- }
+- else {
+- const long pos0 = PerlDir_tell(ret);
+- for(;;) {
+- pos = PerlDir_tell(ret);
+- if ((dirent = PerlDir_read(ret))) {
+- if (len == (STRLEN)d_namlen(dirent)
+- && memEQ(name, dirent->d_name, len)) {
+- /* found it */
+- PerlDir_seek(ret, pos); /* step back */
+- break;
+- }
+- /* else we are not there yet; keep iterating */
+- }
+- else { /* This is not meant to happen. The best we can do is
+- reset the iterator to the beginning. */
+- PerlDir_seek(ret, pos0);
+- break;
+- }
+- }
+- }
+-#undef d_namlen
+-
+- if (name && name != smallbuf)
+- Safefree(name);
+-#endif
+-
+-#ifdef WIN32
++#elif defined(WIN32)
+ ret = win32_dirp_dup(dp, param);
+ #endif
+
+diff --git a/t/op/threads-dirh.t b/t/op/threads-dirh.t
+index bb4bcfc14184..14c399ca19cd 100644
+--- a/t/op/threads-dirh.t
++++ b/t/op/threads-dirh.t
+@@ -13,16 +13,12 @@ BEGIN {
+ skip_all_if_miniperl("no dynamic loading on miniperl, no threads");
+ skip_all("runs out of memory on some EBCDIC") if $ENV{PERL_SKIP_BIG_MEM_TESTS};
+
+- plan(6);
++ plan(1);
+ }
+
+ use strict;
+ use warnings;
+ use threads;
+-use threads::shared;
+-use File::Path;
+-use File::Spec::Functions qw 'updir catdir';
+-use Cwd 'getcwd';
+
+ # Basic sanity check: make sure this does not crash
+ fresh_perl_is <<'# this is no comment', 'ok', {}, 'crash when duping dirh';
+@@ -31,101 +27,3 @@ fresh_perl_is <<'# this is no comment', 'ok', {}, 'crash when duping dirh';
+ async{}->join for 1..2;
+ print "ok";
+ # this is no comment
+-
+-my $dir;
+-SKIP: {
+- skip "telldir or seekdir not defined on this platform", 5
+- if !$Config::Config{d_telldir} || !$Config::Config{d_seekdir};
+- my $skip = sub {
+- chdir($dir);
+- chdir updir;
+- skip $_[0], 5
+- };
+-
+- if(!$Config::Config{d_fchdir} && $^O ne "MSWin32") {
+- $::TODO = 'dir handle cloning currently requires fchdir on non-Windows platforms';
+- }
+-
+- my @w :shared; # warnings accumulator
+- local $SIG{__WARN__} = sub { push @w, $_[0] };
+-
+- $dir = catdir getcwd(), "thrext$$" . int rand() * 100000;
+-
+- rmtree($dir) if -d $dir;
+- mkdir($dir);
+-
+- # Create a dir structure like this:
+- # $dir
+- # |
+- # `- toberead
+- # |
+- # +---- thrit
+- # |
+- # +---- rile
+- # |
+- # `---- zor
+-
+- chdir($dir);
+- mkdir 'toberead';
+- chdir 'toberead';
+- {open my $fh, ">thrit" or &$skip("Cannot create file thrit")}
+- {open my $fh, ">rile" or &$skip("Cannot create file rile")}
+- {open my $fh, ">zor" or &$skip("Cannot create file zor")}
+- chdir updir;
+-
+- # Then test that dir iterators are cloned correctly.
+-
+- opendir my $toberead, 'toberead';
+- my $start_pos = telldir $toberead;
+- my @first_2 = (scalar readdir $toberead, scalar readdir $toberead);
+- my @from_thread = @{; async { [readdir $toberead ] } ->join };
+- my @from_main = readdir $toberead;
+- is join('-', sort @from_thread), join('-', sort @from_main),
+- 'dir iterator is copied from one thread to another';
+- like
+- join('-', "", sort(@first_2, @from_thread), ""),
+- qr/(?<!-rile)-rile-thrit-zor-(?!zor-)/i,
+- 'cloned iterator iterates exactly once over everything not already seen';
+-
+- seekdir $toberead, $start_pos;
+- readdir $toberead for 1 .. @first_2+@from_thread;
+- {
+- local $::TODO; # This always passes when dir handles are not cloned.
+- is
+- async { readdir $toberead // 'undef' } ->join, 'undef',
+- 'cloned dir iterator that points to the end of the directory'
+- ;
+- }
+-
+- # Make sure the cloning code can handle file names longer than 255 chars
+- SKIP: {
+- chdir 'toberead';
+- open my $fh,
+- ">floccipaucinihilopilification-"
+- . "pneumonoultramicroscopicsilicovolcanoconiosis-"
+- . "lopadotemachoselachogaleokranioleipsanodrimypotrimmatosilphiokarabo"
+- . "melitokatakechymenokichlepikossyphophattoperisteralektryonoptokephal"
+- . "liokinklopeleiolagoiosiraiobaphetraganopterygon"
+- or
+- chdir updir,
+- skip("OS does not support long file names (and I mean *long*)", 1);
+- chdir updir;
+- opendir my $dirh, "toberead";
+- my $test_name
+- = "dir iterators can be cloned when the next fn > 255 chars";
+- while() {
+- my $pos = telldir $dirh;
+- my $fn = readdir($dirh);
+- if(!defined $fn) { fail($test_name); last SKIP; }
+- if($fn =~ 'lagoio') {
+- seekdir $dirh, $pos;
+- last;
+- }
+- }
+- is length async { scalar readdir $dirh } ->join, 258, $test_name;
+- }
+-
+- is scalar @w, 0, 'no warnings during all that' or diag @w;
+- chdir updir;
+-}
+-rmtree($dir);
+diff --git a/win32/config.gc b/win32/config.gc
+index f8776188c09c..34aa8de6ed75 100644
+--- a/win32/config.gc
++++ b/win32/config.gc
+@@ -199,6 +199,7 @@ d_fd_macros='define'
+ d_fd_set='define'
+ d_fdclose='undef'
+ d_fdim='undef'
++d_fdopendir='undef'
+ d_fds_bits='define'
+ d_fegetround='undef'
+ d_ffs='undef'
+diff --git a/win32/config.vc b/win32/config.vc
+index 619979e22b53..536085fe94e0 100644
+--- a/win32/config.vc
++++ b/win32/config.vc
+@@ -199,6 +199,7 @@ d_fd_macros='define'
+ d_fd_set='define'
+ d_fdclose='undef'
+ d_fdim='undef'
++d_fdopendir='undef'
+ d_fds_bits='define'
+ d_fegetround='undef'
+ d_ffs='undef'
diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb
index b4927646d75..b86c58f5402 100644
--- a/meta/recipes-devtools/perl/perl_5.38.4.bb
+++ b/meta/recipes-devtools/perl/perl_5.38.4.bb
@@ -23,6 +23,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://CVE-2026-13221.patch \
file://CVE-2026-57432-01.patch \
file://CVE-2026-57432-02.patch \
+ file://CVE-2025-40909.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (12 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471 Yoann Congal
` (12 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
It also includes the upstream follow-up fixes referenced in [3]
and [4]. These correct the trailing whitespace check introduced
by the original fix and add the required <ctype.h> include for
isspace().
[1] https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58469
[3] https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf
[4] https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../wget/CVE-2026-58469-regression_p1.patch | 39 ++++++++++++++
.../wget/CVE-2026-58469-regression_p2.patch | 26 +++++++++
.../wget/wget/CVE-2026-58469.patch | 53 +++++++++++++++++++
meta/recipes-extended/wget/wget_1.21.4.bb | 3 ++
4 files changed, 121 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58469.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
new file mode 100644
index 00000000000..0f8e93c2d3c
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p1.patch
@@ -0,0 +1,39 @@
+From be4edfe6d30a9db8e51215f0232d31eb92d502ec Mon Sep 17 00:00:00 2001
+From: ChenYanpan <chenyanpan@xfusion.com>
+Date: Wed, 8 Jul 2026 12:09:55 +0800
+Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix inverted
+ trailing-space check
+
+37a40fcb added an `end > beg' bound guard to prevent a buffer
+underflow, but accidentally flipped the condition from `isspace' to
+`!isspace'. The loop therefore walked back over non-space characters
+instead of trailing whitespace, collapsing any string without a
+trailing newline to "". Every Metalink/HTTP resource URL was wiped,
+so wget could not follow any mirror and
+testenv/Test-metalink-http.py failed ("Expected file test.meta not
+found"). Restore the `isspace' condition.
+
+Copyright-paperwork-exempt: Yes
+
+CVE: CVE-2026-58469
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf]
+
+(cherry picked from commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/metalink.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index 10d58cf7..9f969a60 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -1061,7 +1061,7 @@ clean_metalink_string (char **str)
+ /* If we are at the end of the string, search the first legit
+ character going backward. */
+ if (*end == '\0')
+- while (end > beg && !isspace(*(end - 1)))
++ while (end > beg && isspace(*(end - 1)))
+ end--;
+
+ new = xmemdup0 (beg, end - beg);
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
new file mode 100644
index 00000000000..940d63e00c7
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58469-regression_p2.patch
@@ -0,0 +1,26 @@
+From aa412523158313619dd04d49b6f769d639e7dcc5 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Thu, 9 Jul 2026 14:50:40 +0200
+Subject: [PATCH] * src/metalink.c: Include ctype.h
+
+CVE: CVE-2026-58469
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1]
+
+(cherry picked from commit 82d945ff5dc9942b78b2bf736aac298c24fe00a1)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/metalink.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index 9f969a60..16933be4 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -46,6 +46,7 @@ as that of the covered work. */
+ #include "c-strcase.h"
+ #include <errno.h>
+ #include <unistd.h> /* For unlink. */
++#include <ctype.h>
+ #include <metalink/metalink_parser.h>
+ #ifdef HAVE_GPGME
+ #include <gpgme.h>
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58469.patch b/meta/recipes-extended/wget/wget/CVE-2026-58469.patch
new file mode 100644
index 00000000000..96bcb62df7c
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58469.patch
@@ -0,0 +1,53 @@
+From 2442499cc090e6aa804b0295fe9f881b78df2940 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Mon, 29 Jun 2026 18:32:02 +0200
+Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix buffer
+ underflow
+
+Reported-by: TristanInSec@gmail.com
+
+CVE: CVE-2026-58469
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826]
+
+(cherry picked from commit 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/metalink.c | 9 +++------
+ 1 file changed, 3 insertions(+), 6 deletions(-)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index eca839c2..10d58cf7 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -1041,7 +1041,6 @@ void
+ clean_metalink_string (char **str)
+ {
+ int c;
+- size_t len;
+ char *new, *beg, *end;
+
+ if (!str || !*str)
+@@ -1049,7 +1048,7 @@ clean_metalink_string (char **str)
+
+ beg = *str;
+
+- while ((c = *beg) && (c == '\n' || c == '\r' || c == '\t' || c == ' '))
++ while (isspace(*beg))
+ beg++;
+
+ end = beg;
+@@ -1062,12 +1061,10 @@ clean_metalink_string (char **str)
+ /* If we are at the end of the string, search the first legit
+ character going backward. */
+ if (*end == '\0')
+- while ((c = *(end - 1)) && (c == '\n' || c == '\r' || c == '\t' || c == ' '))
++ while (end > beg && !isspace(*(end - 1)))
+ end--;
+
+- len = end - beg;
+-
+- new = xmemdup0 (beg, len);
++ new = xmemdup0 (beg, end - beg);
+ xfree (*str);
+ *str = new;
+ }
diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb
index b5f50f6c841..cb05ff34f89 100644
--- a/meta/recipes-extended/wget/wget_1.21.4.bb
+++ b/meta/recipes-extended/wget/wget_1.21.4.bb
@@ -2,6 +2,9 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://0002-improve-reproducibility.patch \
file://CVE-2024-38428.patch \
file://CVE-2024-10524.patch \
+ file://CVE-2026-58469.patch \
+ file://CVE-2026-58469-regression_p1.patch \
+ file://CVE-2026-58469-regression_p2.patch \
"
SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (13 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472 Yoann Congal
` (11 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58471
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../wget/wget/CVE-2026-58471.patch | 71 +++++++++++++++++++
meta/recipes-extended/wget/wget_1.21.4.bb | 1 +
2 files changed, 72 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58471.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58471.patch b/meta/recipes-extended/wget/wget/CVE-2026-58471.patch
new file mode 100644
index 00000000000..4938e6761a5
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58471.patch
@@ -0,0 +1,71 @@
+From f419222cc7e02dea2da104b4fb5a997019bab9a9 Mon Sep 17 00:00:00 2001
+From: Arkadi Vainbrand <arkadva8@gmail.com>
+Date: Tue, 13 Jan 2026 12:22:04 +0200
+Subject: [PATCH] Fix buffer size handling in filename conversion
+
+* src/url.c (convert_fname): Fix buffer overflow.
+
+Copyright-paperwork-exempt: Yes
+
+CVE: CVE-2026-58471
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee]
+
+Signed-off-by: Arkadi Vainbrand <arkadva8@gmail.com>
+(cherry picked from commit c2640fe5171c59f87c58dc9fcb195b2d18b010ee)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/url.c | 20 +++++++++++++-------
+ 1 file changed, 13 insertions(+), 7 deletions(-)
+
+diff --git a/src/url.c b/src/url.c
+index 68688256..6a9efe88 100644
+--- a/src/url.c
++++ b/src/url.c
+@@ -1603,7 +1603,7 @@ convert_fname (char *fname)
+ const char *from_encoding = opt.encoding_remote;
+ const char *to_encoding = opt.locale;
+ iconv_t cd;
+- size_t len, done, inlen, outlen;
++ size_t len, inlen, outlen;
+ char *s;
+ const char *orig_fname;
+
+@@ -1625,7 +1625,6 @@ convert_fname (char *fname)
+ inlen = strlen (fname);
+ len = outlen = inlen * 2;
+ converted_fname = s = xmalloc (outlen + 1);
+- done = 0;
+
+ for (;;)
+ {
+@@ -1633,7 +1632,7 @@ convert_fname (char *fname)
+ if (iconv (cd, (ICONV_CONST char **) &fname, &inlen, &s, &outlen) == 0
+ && iconv (cd, NULL, NULL, &s, &outlen) == 0)
+ {
+- *(converted_fname + len - outlen - done) = '\0';
++ *s = '\0';
+ iconv_close (cd);
+ DEBUGP (("Converted file name '%s' (%s) -> '%s' (%s)\n",
+ orig_fname, from_encoding, converted_fname, to_encoding));
+@@ -1656,10 +1655,17 @@ convert_fname (char *fname)
+ }
+ else if (errno == E2BIG) /* Output buffer full */
+ {
+- done = len;
+- len = outlen = done + inlen * 2;
+- converted_fname = xrealloc (converted_fname, outlen + 1);
+- s = converted_fname + done;
++ size_t used = s - converted_fname;
++ size_t newlen = used + inlen * 2 + 1;
++
++ /* Ensure we actually grow the buffer */
++ if (newlen <= len)
++ newlen = len * 2;
++
++ converted_fname = xrealloc (converted_fname, newlen + 1);
++ len = newlen;
++ s = converted_fname + used;
++ outlen = len - used;
+ }
+ else /* Weird, we got an unspecified error */
+ {
diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb
index cb05ff34f89..9c7d42bd3f0 100644
--- a/meta/recipes-extended/wget/wget_1.21.4.bb
+++ b/meta/recipes-extended/wget/wget_1.21.4.bb
@@ -5,6 +5,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://CVE-2026-58469.patch \
file://CVE-2026-58469-regression_p1.patch \
file://CVE-2026-58469-regression_p2.patch \
+ file://CVE-2026-58471.patch \
"
SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (14 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693 Yoann Congal
` (10 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
Apply the upstream fix referenced in [2] using the commit
listed in [1].
Also include the upstream follow-up commit [3], which fixes
encoded entity length handling and adds regression tests.
[1] https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58472
[3] https://gitlab.com/gnuwget/wget/-/commit/f76978a51ba9365e7ecaed96c1cfb73197a38ca2
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../wget/wget/CVE-2026-58472-regression.patch | 236 ++++++++++++++++++
.../wget/wget/CVE-2026-58472.patch | 77 ++++++
meta/recipes-extended/wget/wget_1.21.4.bb | 2 +
3 files changed, 315 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58472.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
new file mode 100644
index 00000000000..c82d2f2b060
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58472-regression.patch
@@ -0,0 +1,236 @@
+From 6ab6b6d2fc2ed5e4cbb4908b9ad282110f30a688 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Thu, 2 Jul 2026 13:13:07 +0200
+Subject: [PATCH] Regression: Fix buffer overflow in html_quote_string()
+
+The regression has been introduced in commit dd692d9 and
+is not part of any release.
+
+The tests allow the address sanitizer to find the issue.
+
+* src/convert.c: Fix string size calculation.
+* tests/unit-tests.c: Added tests including tests for html_quote_string().
+* tests/unit-tests.h: Add definitions for the test functions.
+
+Reported-by: Trung Nguyen <trungnh@cystack.net>
+
+CVE: CVE-2026-58472
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/f76978a51ba9365e7ecaed96c1cfb73197a38ca2]
+
+(cherry picked from commit f76978a51ba9365e7ecaed96c1cfb73197a38ca2)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/convert.c | 148 +++++++++++++++++++++++++++++++++++++++++++--
+ tests/unit-tests.c | 4 ++
+ tests/unit-tests.h | 4 ++
+ 3 files changed, 152 insertions(+), 4 deletions(-)
+
+diff --git a/src/convert.c b/src/convert.c
+index 51636340..4dae497c 100644
+--- a/src/convert.c
++++ b/src/convert.c
+@@ -48,6 +48,9 @@ as that of the covered work. */
+ #include "css-url.h"
+ #include "iri.h"
+ #include "xstrndup.h"
++#ifdef TESTING
++#include "../tests/unit-tests.h"
++#endif
+
+ static struct hash_table *dl_file_url_map;
+ struct hash_table *dl_url_file_map;
+@@ -1177,13 +1180,13 @@ html_quote_string (const char *s)
+ for (i = 0; *s; s++)
+ {
+ if (*s == '&')
+- ok = INT_ADD_OK (i, 4, &i); /* `amp;' */
++ ok = INT_ADD_OK (i, 4 + 1, &i); /* `amp;' */
+ else if (*s == '<' || *s == '>')
+- ok = INT_ADD_OK (i, 3, &i); /* `lt;' and `gt;' */
++ ok = INT_ADD_OK (i, 3 + 1, &i); /* `lt;' and `gt;' */
+ else if (*s == '\"')
+- ok = INT_ADD_OK (i, 5, &i); /* `quot;' */
++ ok = INT_ADD_OK (i, 5 + 1, &i); /* `quot;' */
+ else if (*s == ' ')
+- ok = INT_ADD_OK (i, 4, &i); /* #32; */
++ ok = INT_ADD_OK (i, 4 + 1, &i); /* #32; */
+ else
+ ok = INT_ADD_OK (i, 1, &i);
+
+@@ -1242,6 +1245,143 @@ html_quote_string (const char *s)
+ return res;
+ }
+
++#ifdef TESTING
++
++const char *
++test_construct_relative (void)
++{
++ static const struct {
++ const char *basefile;
++ const char *linkfile;
++ const char *expected;
++ } test_array[] = {
++ { "foo", "bar", "bar" },
++ { "A/foo", "A/bar", "bar" },
++ { "A/foo", "A/B/bar", "B/bar" },
++ { "A/X/foo", "A/Y/bar", "../Y/bar" },
++ { "X/", "Y/bar", "../Y/bar" },
++ { "/foo", "/bar", "bar" },
++ { "/a/b/c", "/a/b/d", "d" },
++ { "/a/b/c", "/a/b/c/d", "c/d" },
++ { "/a/b/c", "/a/b/c/d/e", "c/d/e" },
++ { "/a/b/c", "/x/y/z", "../../x/y/z" },
++ { "a/b", "c/d", "../c/d" },
++ { "./foo", "./bar", "bar" },
++ };
++
++ for (unsigned i = 0; i < countof (test_array); ++i)
++ {
++ char *result = construct_relative (test_array[i].basefile,
++ test_array[i].linkfile);
++ mu_assert ("test_construct_relative: wrong result",
++ strcmp (result, test_array[i].expected) == 0);
++ xfree (result);
++ }
++
++ return NULL;
++}
++
++const char *
++test_match_except_index (void)
++{
++ static const struct {
++ const char *s1;
++ const char *s2;
++ bool expected;
++ } test_array[] = {
++ { "foo/index.html", "foo/", true },
++ { "foo/", "foo/index.html", true },
++ { "foo", "foo/index.html", true },
++ { "foo", "foo/", true },
++ { "foo", "foo", true },
++ { "/foo/index.html", "/foo/", true },
++ { "/foo/", "/foo/index.html", true },
++ { "/foo", "/foo/index.html", true },
++ { "/foo", "/foo/", true },
++ { "foo/bar", "foo/qux", false },
++ { "foo/bar", "bar/foo", false },
++ };
++
++ for (unsigned i = 0; i < countof (test_array); ++i)
++ {
++ bool result = match_except_index (test_array[i].s1, test_array[i].s2);
++ mu_assert ("test_match_except_index: wrong result",
++ result == test_array[i].expected);
++ }
++
++ return NULL;
++}
++
++const char *
++test_find_fragment (void)
++{
++ static const struct {
++ const char *input;
++ int size;
++ bool has_fragment;
++ const char *fragment;
++ } test_array[] = {
++ { "http://example.com#section", 26, true, "#section" },
++ { "http://example.com", 18, false, NULL },
++ { "http://example.com?a=1#frag", 24, true, "#frag" },
++ { "http://example.com?a=1%26#frag", 28, true, "#frag" },
++ { "http://example.com?a=1&b=2#frag", 30, true, "#frag" },
++ { "a#b", 3, true, "#b" },
++ { "a", 1, false, NULL },
++ };
++ const char *bp, *ep;
++
++ for (unsigned i = 0; i < countof (test_array); ++i)
++ {
++ bool result = find_fragment (test_array[i].input,
++ test_array[i].size, &bp, &ep);
++ mu_assert ("test_find_fragment: wrong result",
++ result == test_array[i].has_fragment);
++ if (test_array[i].has_fragment)
++ {
++ mu_assert ("test_find_fragment: wrong fragment", bp != NULL);
++ mu_assert ("test_find_fragment: fragment mismatch",
++ strncmp (bp, test_array[i].fragment,
++ strlen (test_array[i].fragment)) == 0 &&
++ ep == test_array[i].input + test_array[i].size);
++ }
++ }
++
++ return NULL;
++}
++
++const char *
++test_html_quote_string (void)
++{
++ static const struct {
++ const char *input;
++ const char *expected;
++ } test_array[] = {
++ { "hello", "hello" },
++ { "a&b", "a&b" },
++ { "<tag>", "<tag>" },
++ { "\"quote\"", ""quote"" },
++ { "space here", "space here" },
++ { "&<>\" ", "&<>" " },
++ { "no special", "no special" },
++ { "&&&&", "&&&&" },
++ { "<<>>", "<<>>" },
++ { "" , "" },
++ };
++
++ for (unsigned i = 0; i < countof (test_array); ++i)
++ {
++ char *result = html_quote_string (test_array[i].input);
++ mu_assert ("test_html_quote_string: wrong result",
++ strcmp (result, test_array[i].expected) == 0);
++ xfree (result);
++ }
++
++ return NULL;
++}
++
++#endif /* TESTING */
++
+ /*
+ * vim: et ts=2 sw=2
+ */
+diff --git a/tests/unit-tests.c b/tests/unit-tests.c
+index 085a0321..f92d72b4 100644
+--- a/tests/unit-tests.c
++++ b/tests/unit-tests.c
+@@ -66,6 +66,10 @@ all_tests(void)
+ mu_run_test (test_hsts_read_database);
+ #endif
+ mu_run_test (test_parse_netrc);
++ mu_run_test (test_construct_relative);
++ mu_run_test (test_match_except_index);
++ mu_run_test (test_find_fragment);
++ mu_run_test (test_html_quote_string);
+
+ return NULL;
+ }
+diff --git a/tests/unit-tests.h b/tests/unit-tests.h
+index 16573b1c..7542660b 100644
+--- a/tests/unit-tests.h
++++ b/tests/unit-tests.h
+@@ -62,6 +62,10 @@ const char *test_hsts_url_rewrite_superdomain(void);
+ const char *test_hsts_url_rewrite_congruent(void);
+ const char *test_hsts_read_database(void);
+ const char *test_parse_netrc(void);
++const char *test_construct_relative(void);
++const char *test_match_except_index(void);
++const char *test_find_fragment(void);
++const char *test_html_quote_string(void);
+
+ #endif /* TEST_H */
+
+--
+2.35.6
+
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58472.patch b/meta/recipes-extended/wget/wget/CVE-2026-58472.patch
new file mode 100644
index 00000000000..29f6f23d07a
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58472.patch
@@ -0,0 +1,77 @@
+From 7d0400b63382fbf336df9b63c787571d2df8a772 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Mon, 29 Jun 2026 19:13:15 +0200
+Subject: [PATCH] * src/convert.c (html_quote_string): Fix integer+buffer
+ overflow
+
+Reported-by: TristanInSec@gmail.com
+
+CVE: CVE-2026-58472
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812]
+
+(cherry picked from commit dd692d9cea5335b181d877ae917fe6e75587a812)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/convert.c | 31 ++++++++++++++++++++++++-------
+ 1 file changed, 24 insertions(+), 7 deletions(-)
+
+diff --git a/src/convert.c b/src/convert.c
+index b934d49b..51636340 100644
+--- a/src/convert.c
++++ b/src/convert.c
+@@ -36,6 +36,7 @@ as that of the covered work. */
+ #include <unistd.h>
+ #include <errno.h>
+ #include <assert.h>
++#include <intprops.h>
+ #include "convert.h"
+ #include "url.h"
+ #include "recur.h"
+@@ -1169,21 +1170,37 @@ html_quote_string (const char *s)
+ {
+ const char *b = s;
+ char *p, *res;
+- int i;
++ size_t i;
++ int ok;
+
+ /* Pass through the string, and count the new size. */
+- for (i = 0; *s; s++, i++)
++ for (i = 0; *s; s++)
+ {
+ if (*s == '&')
+- i += 4; /* `amp;' */
++ ok = INT_ADD_OK (i, 4, &i); /* `amp;' */
+ else if (*s == '<' || *s == '>')
+- i += 3; /* `lt;' and `gt;' */
++ ok = INT_ADD_OK (i, 3, &i); /* `lt;' and `gt;' */
+ else if (*s == '\"')
+- i += 5; /* `quot;' */
++ ok = INT_ADD_OK (i, 5, &i); /* `quot;' */
+ else if (*s == ' ')
+- i += 4; /* #32; */
++ ok = INT_ADD_OK (i, 4, &i); /* #32; */
++ else
++ ok = INT_ADD_OK (i, 1, &i);
++
++ if (!ok)
++ {
++ DEBUGP (("Overflow detected in html_quote_string().\n"));
++ abort();
++ }
+ }
+- res = xmalloc (i + 1);
++
++ if (!INT_ADD_OK (i, 1, &i))
++ {
++ DEBUGP (("Overflow detected in html_quote_string().\n"));
++ abort();
++ }
++
++ res = xmalloc (i);
+ s = b;
+ for (p = res; *s; s++)
+ {
+--
+2.35.6
+
diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb
index 9c7d42bd3f0..8ae0bcf1f05 100644
--- a/meta/recipes-extended/wget/wget_1.21.4.bb
+++ b/meta/recipes-extended/wget/wget_1.21.4.bb
@@ -6,6 +6,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://CVE-2026-58469-regression_p1.patch \
file://CVE-2026-58469-regression_p2.patch \
file://CVE-2026-58471.patch \
+ file://CVE-2026-58472.patch \
+ file://CVE-2026-58472-regression.patch \
"
SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (15 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892 Yoann Congal
` (9 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693
[2] https://security-tracker.debian.org/tracker/CVE-2026-55693
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-55693.patch | 88 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 89 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-55693.patch b/meta/recipes-support/vim/files/CVE-2026-55693.patch
new file mode 100644
index 00000000000..d35b6f5fe54
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55693.patch
@@ -0,0 +1,88 @@
+From 315b35adb406138c962bcc653db95acc3c87c8ab Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Mon, 15 Jun 2026 19:39:08 +0000
+Subject: [PATCH 09/17] patch 9.2.0653: [security]: out-of-bounds write in
+ tree_count_words()
+
+Problem: [security]: a crafted spell file can drive tree_count_words()
+ past the end of its MAXWLEN-sized depth arrays; the descent
+ loop has no depth bound.
+Solution: only descend while depth < MAXWLEN - 1, as the sibling trie
+ walkers already do; apply the same guard to sug_filltree().
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq
+
+Supported by AI.
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7]
+CVE: CVE-2026-55693
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ src/spellfile.c | 4 ++--
+ src/testdir/test_spellfile.vim | 27 +++++++++++++++++++++++++++
+ 2 files changed, 29 insertions(+), 2 deletions(-)
+
+diff --git a/src/spellfile.c b/src/spellfile.c
+index 0b9536dc16..0010d9aa27 100644
+--- a/src/spellfile.c
++++ b/src/spellfile.c
+@@ -645,7 +645,7 @@ tree_count_words(char_u *byts, idx_T *idxs)
+ ++curi[depth];
+ }
+ }
+- else
++ else if (depth < MAXWLEN - 1)
+ {
+ // Normal char, go one level deeper to count the words.
+ ++depth;
+@@ -5648,7 +5648,7 @@ sug_filltree(spellinfo_T *spin, slang_T *slang)
+ ++curi[depth];
+ }
+ }
+- else
++ else if (depth < MAXWLEN - 1)
+ {
+ // Normal char, go one level deeper.
+ tword[depth++] = c;
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index b72974ed07..e5f8c5778f 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1166,4 +1166,31 @@ func Test_mkspell_empty_dic()
+ endfunc
+
+
++func Test_spell_sug_tree_count_words_overflow()
++ " A crafted .spl/.sug pair with a BY_INDEX self-cycle in the fold word tree
++ " parses cleanly (shared refs aren't recursed, so read_tree_node()'s depth
++ " cap never trips), but drove tree_count_words() past its MAXWLEN-sized depth
++ " arrays -> stack out-of-bounds write. The walk only happens when
++ " spellsuggest() loads the matching .sug. Reaching the assert == no OOB.
++ call mkdir('Xrtp/spell', 'pR')
++ " VIMspell + v50, SN_SUGFILE(ts), SN_END, LWORDTREE{node:1,BY_INDEX->0,'A'},
++ " empty KWORDTREE/PREFIXTREE
++ let spl = eval('0z56494D7370656C6C320B0000000008000000001234'
++ \ .. '5678FF000000020101000000410000000000000000')
++ " VIMsug + v1, matching ts, SUGWORDTREE word "a", empty SUGTABLE
++ let sug = 0z56494D737567010000000012345678000000040161010000000000
++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b')
++ call writefile(sug, 'Xrtp/spell/xx.utf-8.sug', 'b')
++
++ new
++ set runtimepath+=./Xrtp
++ set spelllang=xx
++ set spell
++ " Unpatched: OOB write here (ASan abort, or crash). Patched: returns a list.
++ call assert_equal(v:t_list, type(spellsuggest('helloo')))
++
++ set spell& spelllang& runtimepath&
++ bwipe!
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index ec2cedc965d..248160a82c2 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-43961.patch \
file://CVE-2026-47162.patch \
file://CVE-2026-47167.patch \
+ file://CVE-2026-55693.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (16 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895 Yoann Congal
` (8 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892
[2] https://security-tracker.debian.org/tracker/CVE-2026-55892
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-55892.patch | 81 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 82 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-55892.patch b/meta/recipes-support/vim/files/CVE-2026-55892.patch
new file mode 100644
index 00000000000..5f46c97cfa3
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55892.patch
@@ -0,0 +1,81 @@
+From f0df4a48a426bd67c0c2f5ad536000a4368cd4c0 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Tue, 16 Jun 2026 20:32:21 +0000
+Subject: [PATCH 10/17] patch 9.2.0662: [security] Stack out-of-bounds write in
+ dump_prefixes()
+
+Problem: [security]: a crafted spell file with a self-referential
+ BY_INDEX node in the prefix tree can drive dump_prefixes()
+ past the end of its MAXWLEN-sized depth arrays on :spelldump
+ (cipher-creator)
+Solution: only descend while depth < MAXWLEN - 1, as the sibling trie
+ walkers already do (Yasuhiro Matsumoto)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241fc8633d93dff996b]
+CVE: CVE-2026-55892
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ src/spell.c | 2 +-
+ src/testdir/test_spell.vim | 27 +++++++++++++++++++++++++++
+ 2 files changed, 28 insertions(+), 1 deletion(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 2281986435..6ef3fa899b 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -4328,7 +4328,7 @@ dump_prefixes(
+ }
+ }
+ }
+- else
++ else if (depth < MAXWLEN - 1)
+ {
+ // Normal char, go one level deeper.
+ prefix[depth++] = c;
+diff --git a/src/testdir/test_spell.vim b/src/testdir/test_spell.vim
+index 170ea57926..2a3f0e3696 100644
+--- a/src/testdir/test_spell.vim
++++ b/src/testdir/test_spell.vim
+@@ -1567,4 +1567,31 @@ let g:test_data_aff_sal = [
+ \"SAL Z S",
+ \ ]
+
++" A crafted .spl with a self-referential BY_INDEX node in the PREFIXTREE drove
++" dump_prefixes() past its MAXWLEN-sized depth arrays (stack out-of-bounds
++" write). The tree parses cleanly (shared refs aren't recursed); the walk
++" happens on :spelldump. Reaching the assert means no OOB. Same class as the
++" tree_count_words() fix (9.2.0653).
++func Test_spelldump_prefixtree_overflow()
++ CheckUnix
++ call mkdir('Xrtp/spell', 'pR')
++ " VIMspell + v50, SN_PREFCOND(prefixcnt=1), SN_END,
++ " LWORDTREE word "a" with affixID=1 (so dump_prefixes runs),
++ " empty KWORDTREE, PREFIXTREE child BY_INDEX -> nodeidx 0 (self-cycle), 'A'
++ let spl = eval('0z56494D7370656C6C32030000000003000100FF00000004'
++ \ .. '0161010220010000000000000002010100000041')
++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b')
++
++ new
++ set runtimepath+=./Xrtp
++ set spelllang=xx
++ set spell
++ spelldump
++ call assert_true(line('$') > 1)
++
++ set spell& spelllang& runtimepath&
++ bwipe!
++ bwipe!
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 248160a82c2..07f7b7dd16c 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-47162.patch \
file://CVE-2026-47167.patch \
file://CVE-2026-55693.patch \
+ file://CVE-2026-55892.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (17 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452 Yoann Congal
` (7 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895
[2] https://security-tracker.debian.org/tracker/CVE-2026-55895
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-55895.patch | 53 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 54 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch
new file mode 100644
index 00000000000..0084006b72d
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch
@@ -0,0 +1,53 @@
+From 0d286458d71ff7b4d759621dd9a567aa9354819a Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Tue, 16 Jun 2026 21:00:28 +0000
+Subject: [PATCH 11/17] patch 9.2.0663: [security]: runtime(netrw): code
+ injection in local file deletion
+
+Problem: [security]: s:NetrwLocalRmFile() escapes only the backslash in
+ the file name before passing it to :execute, so a name
+ containing "|" injects arbitrary Ex commands when the file is
+ deleted (cipher-creator)
+Solution: Use fnameescape() to correctly escape the file name
+ (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2]
+CVE: CVE-2026-55895
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ runtime/pack/dist/opt/netrw/autoload/netrw.vim | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+index 9014ca339b..af43f469d1 100644
+--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+@@ -3025,7 +3025,7 @@ function s:NetrwBrowse(islocal,dirname)
+ elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"'
+ " s:NetrwBrowse : remote regular file handler {{{3
+ if bufname(dirname) != ""
+- exe "NetrwKeepj b ".bufname(dirname)
++ exe "NetrwKeepj b ".fnameescape(bufname(dirname))
+ else
+ " attempt transfer of remote regular file
+
+@@ -8737,7 +8737,7 @@ function s:NetrwLocalRmFile(path, fname, all)
+ call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile))
+ else
+ " Remove file only if there are no pending changes
+- execute printf('silent! bwipeout %s', rmfile)
++ execute printf('silent! bwipeout %s', fnameescape(rmfile))
+ endif
+
+ elseif dir && (all || empty(ok))
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 07f7b7dd16c..bd1d52eaf67 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-47167.patch \
file://CVE-2026-55693.patch \
file://CVE-2026-55892.patch \
+ file://CVE-2026-55895.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (18 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455 Yoann Congal
` (6 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452
[2] https://security-tracker.debian.org/tracker/CVE-2026-57452
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-57452.patch | 76 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 77 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57452.patch b/meta/recipes-support/vim/files/CVE-2026-57452.patch
new file mode 100644
index 00000000000..aaefbe80eb7
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57452.patch
@@ -0,0 +1,76 @@
+From c8777cec25dcfae89c42e9aff51af61f71c5745f Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Thu, 18 Jun 2026 18:41:16 +0000
+Subject: [PATCH] patch 9.2.0671: [security]: possible out-of-bounds read with
+ sodium encrypted files
+
+Problem: [security]: possible out-of-bounds read with sodium encrypted
+ files (cipher-creator)
+Solution: Verify that there is enough space before calling
+ crypto_secretstream_xchacha20poly1305_init_pull()
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f]
+CVE: CVE-2026-57452
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ src/crypt.c | 3 ++-
+ src/testdir/test_crypt.vim | 24 ++++++++++++++++++++++++
+ 2 files changed, 26 insertions(+), 1 deletion(-)
+
+diff --git a/src/crypt.c b/src/crypt.c
+index 55edd6c6de..a11d204e5e 100644
+--- a/src/crypt.c
++++ b/src/crypt.c
+@@ -1257,7 +1257,8 @@ crypt_sodium_buffer_decode(
+
+ if (sod_st->count == 0)
+ {
+- if (crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state,
++ if (len < crypto_secretstream_xchacha20poly1305_HEADERBYTES ||
++ crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state,
+ from, sod_st->key) != 0)
+ {
+ emsg(_(e_libsodium_decryption_failed_header_incomplete));
+diff --git a/src/testdir/test_crypt.vim b/src/testdir/test_crypt.vim
+index 4a96c30702..151a4dea17 100644
+--- a/src/testdir/test_crypt.vim
++++ b/src/testdir/test_crypt.vim
+@@ -459,4 +459,28 @@ func Test_crypt_set_key_disallow_append_subtract()
+ bwipe!
+ endfunc
+
++func Test_crypt_sodium_short_body()
++ CheckFeature sodium
++ " A VimCrypt~04! file with a complete 36-byte header (12 magic + 16 salt +
++ " 8 seed) but a body shorter than one secretstream header (24 bytes) used to
++ " underflow the body length and crash with a wild out-of-bounds read in
++ " crypto_secretstream_xchacha20poly1305_pull(). It must now fail cleanly.
++ " Bytes: "VimCrypt~04!" + 16 salt + 8 seed + 8-byte body = 44 bytes.
++ call writefile(0z56696D43727970747E303421
++ \ + 0zA0A1A2A3A4A5A6A7A8A9AAABACADAEAF
++ \ + 0zB0B1B2B3B4B5B6B7
++ \ + 0z0000000000000000, 'Xtest_sodium_short')
++
++ let v:errmsg = ''
++ try
++ call feedkeys(":split Xtest_sodium_short\<CR>foobar\<CR>", "xt")
++ catch /^Vim\%((\S\+)\)\=:E1198:/
++ " no-op
++ endtry
++
++ bwipe!
++ call delete('Xtest_sodium_short')
++ set key=
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index bd1d52eaf67..567da7be0cf 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-55693.patch \
file://CVE-2026-55892.patch \
file://CVE-2026-55895.patch \
+ file://CVE-2026-57452.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (19 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856 Yoann Congal
` (5 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455
[2] https://security-tracker.debian.org/tracker/CVE-2026-57455
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-57455.patch | 72 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 73 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch
new file mode 100644
index 00000000000..722238c794a
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch
@@ -0,0 +1,72 @@
+From 497d2fb19b2af9bccf139bb910e4f91b583e769d Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:20:03 +0000
+Subject: [PATCH 13/17] patch 9.2.0698: [security]: Out-of-bounds write with
+ soundfold()
+
+Problem: [security]: Out-of-bounds write with soundfold()
+ (cipher-creator)
+Solution: Add an abort condition to the for loop to validate the buffer
+ size.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b]
+CVE: CVE-2026-57455
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ src/spell.c | 2 +-
+ src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++
+ 2 files changed, 22 insertions(+), 1 deletion(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 6ef3fa899b..a7909ef46e 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3273,7 +3273,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res)
+ else
+ {
+ // The sl_sal_first[] table contains the translation.
+- for (s = inword; (c = *s) != NUL; ++s)
++ for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s)
+ {
+ if (VIM_ISWHITE(c))
+ c = ' ';
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index e5f8c5778f..d04d024911 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1193,4 +1193,25 @@ func Test_spell_sug_tree_count_words_overflow()
+ bwipe!
+ endfunc
+
++" A word longer than MAXWLEN must not overflow the soundfold result buffer in
++" the single-byte SOFO branch of spell_soundfold_sofo().
++func Test_soundfold_overflow()
++ let _enc=&enc
++ set enc=latin1
++ call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D')
++ call writefile(['1', 'foo'], 'Xtest.dic', 'D')
++ mkspell! Xtest Xtest
++ defer delete('Xtest.latin1.spl')
++ defer delete('Xtest.latin1.sug')
++ setl spelllang=Xtest.latin1.spl spell
++
++ " Before the fix the copy loop wrote one byte per input byte into a
++ " MAXWLEN (254) stack buffer with no upper bound, smashing the stack.
++ let sound = soundfold(repeat('ab', 300))
++ call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN')
++
++ set spell& spelllang&
++ let &enc = _enc
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 567da7be0cf..8794f831b05 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -45,6 +45,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-55892.patch \
file://CVE-2026-55895.patch \
file://CVE-2026-57452.patch \
+ file://CVE-2026-57455.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (20 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857 Yoann Congal
` (4 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856
[2] https://security-tracker.debian.org/tracker/CVE-2026-59856
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-59856.patch | 103 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 104 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch
new file mode 100644
index 00000000000..01267460d11
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch
@@ -0,0 +1,103 @@
+From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 20:07:01 +0900
+Subject: [PATCH] patch 9.2.0736: potential command execution in PHP
+ omni-completion
+
+Problem: With PHP omni-completion, a crafted file can potentially
+ execute arbitrary commands when completing a class member.
+Solution: Quote the class name before inserting it into the search()
+ pattern run via win_execute().
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24]
+CVE: CVE-2026-59856
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ runtime/autoload/phpcomplete.vim | 3 ++-
+ src/testdir/Make_all.mak | 2 ++
+ src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++
+ 3 files changed, 39 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_phpcomplete.vim
+
+diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim
+index 5b4263ae45..93f7d8b450 100644
+--- a/runtime/autoload/phpcomplete.vim
++++ b/runtime/autoload/phpcomplete.vim
+@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam
+ let result = []
+ let popup_id = popup_create(a:file_lines, {'hidden': v:true})
+
+- call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')')
++ call win_execute(popup_id, 'call search('
++ \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')')
+ call win_execute(popup_id, "let cfline = line('.')")
+ call win_execute(popup_id, "call search('{')")
+ call win_execute(popup_id, "let endline = line('.')")
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index 0d4aeb0432..7d57b2e727 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -248,6 +248,7 @@ NEW_TESTS = \
+ test_plugin_man \
+ test_plugin_matchparen \
+ test_plugin_python3complete \
++ test_plugin_phpcomplete \
+ test_plugin_tar \
+ test_plugin_termdebug \
+ test_plugin_tohtml \
+@@ -522,6 +523,7 @@ NEW_TESTS_RES = \
+ test_plugin_man.res \
+ test_plugin_matchparen.res \
+ test_plugin_python3complete.res \
++ test_plugin_phpcomplete.res \
+ test_plugin_tar.res \
+ test_plugin_termdebug.res \
+ test_plugin_tohtml.res \
+
+diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim
+new file mode 100644
+index 0000000000..7f66be47b7
+--- /dev/null
++++ b/src/testdir/test_plugin_phpcomplete.vim
+@@ -0,0 +1,35 @@
++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim).
++
++" A buffer class name is interpolated into a search() pattern run via
++" win_execute(). Without escaping, "'" closes the string and "|" starts a new
++" Ex command, so the name runs as an Ex command during completion.
++func Test_phpcomplete_no_exec_via_class_name()
++ unlet! g:phpcomplete_injected
++ let lines = ['<?php', 'class x {}', '']
++ let payload = "x')|let g:phpcomplete_injected = 1|call search('"
++
++ try
++ call phpcomplete#GetClassContentsStructure('x.php', lines, payload)
++ catch
++ endtry
++
++ call assert_false(exists('g:phpcomplete_injected'),
++ \ 'class name was executed as an Ex command during completion')
++
++ unlet! g:phpcomplete_injected
++endfunc
++
++func Test_phpcomplete_class_lookup_still_works()
++ let lines = ['<?php', 'class Foo {', ' public $bar;', '}', '']
++ let result = phpcomplete#GetClassContentsStructure('Foo.php', lines, 'Foo')
++
++ call assert_equal(type([]), type(result),
++ \ 'GetClassContentsStructure did not return a list')
++ call assert_true(len(result) > 0, 'no class structure returned')
++ call assert_match('class Foo', result[0].content,
++ \ 'class body missing from returned content')
++ call assert_match('bar', result[0].content,
++ \ 'class member missing from returned content')
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 8794f831b05..37a965429a9 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -46,6 +46,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-55895.patch \
file://CVE-2026-57452.patch \
file://CVE-2026-57455.patch \
+ file://CVE-2026-59856.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (21 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858 Yoann Congal
` (3 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857
[2] https://security-tracker.debian.org/tracker/CVE-2026-59857
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-59857.patch | 110 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 111 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch
new file mode 100644
index 00000000000..ed92190a954
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch
@@ -0,0 +1,110 @@
+From 48287480f53acfb5e6f9172e571ed2f0508dfab2 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Mon, 22 Jun 2026 13:00:36 +0900
+Subject: [PATCH 16/17] patch 9.2.0725: [security]: Stack out-of-bounds write
+ in spell_soundfold_sal()
+
+Problem: [security]: A crafted spell file with non-collapsing SAL rules
+ can make soundfold() write one byte past the end of the
+ MAXWLEN result buffer. This is the same class of
+ out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698
+ for the SOFO branch), found while auditing the surrounding
+ code.
+Solution: Bound the single-byte SAL result writes and the terminating
+ NUL to MAXWLEN - 1, matching the SOFO branch.
+
+The single-byte branch of spell_soundfold_sal() guarded its writes with
+"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254). The trailing
+"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer
+res[MAXWLEN], an off-by-one out-of-bounds write. Input is case-folded to
+about 253 characters, so a 253-character argument together with a SAL map
+that does not collapse (collapse_result false) reaches the boundary.
+
+Related to previous issue
+[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4)
+(9.2.0698)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30]
+CVE: CVE-2026-59857
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ src/spell.c | 6 +++---
+ src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++
+ 2 files changed, 27 insertions(+), 3 deletions(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index a7909ef46e..05d6f0159d 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3516,7 +3516,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ // no '<' rule used
+ i += k - 1;
+ z = 0;
+- while (*s != NUL && s[1] != NUL && reslen < MAXWLEN)
++ while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1)
+ {
+ if (reslen == 0 || res[reslen - 1] != *s)
+ res[reslen++] = *s;
+@@ -3526,7 +3526,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ c = *s;
+ if (strstr((char *)pf, "^^") != NULL)
+ {
+- if (c != NUL)
++ if (c != NUL && reslen < MAXWLEN - 1)
+ res[reslen++] = c;
+ STRMOVE(word, word + i + 1);
+ i = 0;
+@@ -3545,7 +3545,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+
+ if (z0 == 0)
+ {
+- if (k && !p0 && reslen < MAXWLEN && c != NUL
++ if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL
+ && (!slang->sl_collapse || reslen == 0
+ || res[reslen - 1] != c))
+ // condense only double letters
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index d04d024911..c8c7ac2642 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -383,6 +383,30 @@ func Test_spellfile_format_error()
+ let &rtp = save_rtp
+ endfunc
+
++" An over-length soundfold() argument must not overflow the MAXWLEN result
++" buffer in the single-byte branch of spell_soundfold_sal().
++func Test_spellfile_soundfold_sal_overflow()
++ let save_enc = &encoding
++ set encoding=latin1
++ " A SAL map that appends without collapsing, so the result is not shorter
++ " than the input.
++ call writefile(['SET ISO8859-1', 'SAL collapse_result false',
++ \ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff')
++ call writefile(['2', 'hello', 'world'], 'Xsal.dic')
++ mkspell! Xsal Xsal
++ set spl=Xsal.latin1.spl spell
++
++ " 253 input characters hit the buffer boundary; the result must not exceed
++ " MAXWLEN - 1.
++ call assert_true(strlen(soundfold(repeat('a', 253))) <= 253)
++
++ set nospell spl& spelllang&
++ call delete('Xsal.aff')
++ call delete('Xsal.dic')
++ call delete('Xsal.latin1.spl')
++ let &encoding = save_enc
++endfunc
++
+ " Test for format errors in suggest file
+ func Test_sugfile_format_error()
+ let save_rtp = &rtp
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 37a965429a9..a484a5c8405 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -47,6 +47,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-57452.patch \
file://CVE-2026-57455.patch \
file://CVE-2026-59856.patch \
+ file://CVE-2026-59857.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (22 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456 Yoann Congal
` (2 subsequent siblings)
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
[2] https://security-tracker.debian.org/tracker/CVE-2026-59858
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 135 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch
new file mode 100644
index 00000000000..0b754ec2d34
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
@@ -0,0 +1,134 @@
+From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 15:41:24 +0900
+Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem: [security]: With C omni-completion, a crafted tags file can execute
+ arbitrary Ex commands when completing a struct/union member
+ (cipher-creator)
+Solution: Escape the type field before inserting it into the :vimgrep
+ pattern so it cannot close the pattern and start a new command
+ (Hirohito Higashi).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e]
+CVE: CVE-2026-59858
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ runtime/autoload/ccomplete.vim | 2 +-
+ src/testdir/Make_all.mak | 2 +
+ src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
+ 3 files changed, 65 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_ccomplete.vim
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index cb4bb2c167..248d6f2e60 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -593,7 +593,7 @@ def StructMembers( # {{{1
+ return []
+ endif
+ execute 'silent! keepjumps noautocmd '
+- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
+ .. fnames
+
+ qflist = getqflist()
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index 7d57b2e727..681e9b3b2a 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -242,6 +242,7 @@ NEW_TESTS = \
+ test_partial \
+ test_paste \
+ test_perl \
++ test_plugin_ccomplete \
+ test_plugin_comment \
+ test_plugin_glvs \
+ test_plugin_helptoc \
+@@ -516,6 +517,7 @@ NEW_TESTS_RES = \
+ test_partial.res \
+ test_paste.res \
+ test_perl.res \
++ test_plugin_ccomplete.res \
+ test_plugin_comment.res \
+ test_plugin_glvs.res \
+ test_plugin_helptoc.res \
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+new file mode 100644
+index 0000000000..a635bd50bd
+--- /dev/null
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -0,0 +1,62 @@
++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim).
++
++func s:WriteTags(lines)
++ " Mark unsorted so lookup is a linear scan regardless of entry order.
++ let tagsfile = tempname()
++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
++ return tagsfile
++endfunc
++
++" A crafted typeref field is interpolated into the :vimgrep pattern in
++" StructMembers(). Without escaping, "/" closes the pattern and "|" starts a
++" new Ex command, so the field runs as an Ex command during completion.
++func Test_ccomplete_no_exec_via_typeref()
++ unlet! g:ccomplete_injected
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ call ccomplete#Complete(0, 'myvar.x')
++
++ call assert_false(exists('g:ccomplete_injected'),
++ \ 'typeref field was executed as an Ex command during omni-completion')
++
++ bwipe!
++ let &tags = save_tags
++ unlet! g:ccomplete_injected
++endfunc
++
++" A legitimate typeref must still drive struct-member completion: escaping the
++" field value must not break the normal path.
++func Test_ccomplete_typeref_completion_still_works()
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ let items = ccomplete#Complete(0, 'myvar.')
++
++ call assert_equal(type([]), type(items),
++ \ 'ccomplete#Complete did not return a list')
++ let names = map(copy(items), 'v:val.word')
++ call assert_true(index(names, 'alpha') >= 0,
++ \ 'struct member "alpha" missing from completion: ' . string(names))
++ call assert_true(index(names, 'beta') >= 0,
++ \ 'struct member "beta" missing from completion: ' . string(names))
++
++ bwipe!
++ let &tags = save_tags
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index a484a5c8405..6ef9745b574 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -48,6 +48,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-57455.patch \
file://CVE-2026-59856.patch \
file://CVE-2026-59857.patch \
+ file://CVE-2026-59858.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (23 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288 Yoann Congal
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Siddharth Doshi <sdoshi@mvista.com>
Picking patch as per [1], and same patch is mentioned in [2]
References:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456
[2] https://security-tracker.debian.org/tracker/CVE-2026-57456
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-57456.patch | 90 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 91 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch
new file mode 100644
index 00000000000..b9f3fcc84d4
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch
@@ -0,0 +1,90 @@
+From 911e10a2e8e677c3982d392e185b7d9b3e574401 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:50:56 +0000
+Subject: [PATCH 14/17] patch 9.2.0699: [security]: possible code execution
+ with python complete
+
+Problem: [security]: possible code execution with python complete
+ (morningbread)
+Solution: Use repr() to quote the doc strings correctly
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8]
+CVE: CVE-2026-57456
+Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
+---
+ runtime/autoload/python3complete.vim | 6 +++---
+ runtime/autoload/pythoncomplete.vim | 6 +++---
+ 2 files changed, 6 insertions(+), 6 deletions(-)
+
+diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
+index 56ee636b8d..e7cd149cdd 100644
+--- a/runtime/autoload/python3complete.vim
++++ b/runtime/autoload/python3complete.vim
+@@ -326,7 +326,7 @@ class Scope(object):
+
+ def get_code(self):
+ str = ""
+- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+ str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
+ for sub in self.subscopes:
+ str += sub.get_code()
+@@ -369,7 +369,7 @@ class Class(Scope):
+ if _DOTTED_NAME_RE.match(s.strip())]
+ if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+ str += ':\n'
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ if len(self.subscopes) > 0:
+ for s in self.subscopes: str += s.get_code()
+ else:
+@@ -392,7 +392,7 @@ class Function(Scope):
+ safe_params = [p for p in safe_params if p]
+ str = "%sdef %s(%s):\n" % \
+ (self.currentindent(),self.name,','.join(safe_params))
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ str += "%spass\n" % self.childindent()
+ return str
+
+diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
+index 0f41405c0e..abef32faf2 100644
+--- a/runtime/autoload/pythoncomplete.vim
++++ b/runtime/autoload/pythoncomplete.vim
+@@ -341,7 +341,7 @@ class Scope(object):
+
+ def get_code(self):
+ str = ""
+- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+ str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
+ for sub in self.subscopes:
+ str += sub.get_code()
+@@ -384,7 +384,7 @@ class Class(Scope):
+ if _DOTTED_NAME_RE.match(s.strip())]
+ if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+ str += ':\n'
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ if len(self.subscopes) > 0:
+ for s in self.subscopes: str += s.get_code()
+ else:
+@@ -407,7 +407,7 @@ class Function(Scope):
+ safe_params = [p for p in safe_params if p]
+ str = "%sdef %s(%s):\n" % \
+ (self.currentindent(),self.name,','.join(safe_params))
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ str += "%spass\n" % self.childindent()
+ return str
+
+--
+2.44.4
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 6ef9745b574..a4f8162d31c 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -49,6 +49,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-59856.patch \
file://CVE-2026-59857.patch \
file://CVE-2026-59858.patch \
+ file://CVE-2026-57456.patch \
"
PV .= ".1683"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (24 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288 Yoann Congal
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].
[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56289
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 48c1aa91e829a87c398e8c012cde45cd8c1aab0a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../patch/patch/CVE-2026-56289.patch | 36 +++++++++++++++++++
meta/recipes-devtools/patch/patch_2.7.6.bb | 1 +
2 files changed, 37 insertions(+)
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
diff --git a/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch b/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
new file mode 100644
index 00000000000..cfcb2216c35
--- /dev/null
+++ b/meta/recipes-devtools/patch/patch/CVE-2026-56289.patch
@@ -0,0 +1,36 @@
+From a40c835ab06314526d623e62ae27830d0ad88752 Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Tue, 21 Apr 2026 13:16:10 -0700
+Subject: [PATCH] =?UTF-8?q?Don=E2=80=99t=20infloop=20on=20null=20ranges?=
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Problem reported by Michał Majchrowicz.
+* src/patch.c (locate_hunk): Don’t attempt to optimize
+matches of a null range. Instead, apply all the checks
+we apply to non-null ranges.
+
+CVE: CVE-2026-56289
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9]
+
+(cherry picked from commit faba04ef4f2b410257f76c1b9dc85e350929c4b9)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/patch.c | 3 ---
+ 1 file changed, 3 deletions(-)
+
+diff --git a/src/patch.c b/src/patch.c
+index b348b5c..0e8d5c9 100644
+--- a/src/patch.c
++++ b/src/patch.c
+@@ -1146,9 +1146,6 @@ locate_hunk (lin fuzz)
+ lin max_offset = MAX(max_pos_offset, max_neg_offset);
+ lin min_offset;
+
+- if (!pat_lines) /* null range matches always */
+- return first_guess;
+-
+ /* Do not try lines <= 0. */
+ if (first_guess <= max_neg_offset)
+ max_neg_offset = first_guess - 1;
diff --git a/meta/recipes-devtools/patch/patch_2.7.6.bb b/meta/recipes-devtools/patch/patch_2.7.6.bb
index e0e44f9c977..74d9085c6b9 100644
--- a/meta/recipes-devtools/patch/patch_2.7.6.bb
+++ b/meta/recipes-devtools/patch/patch_2.7.6.bb
@@ -11,6 +11,7 @@ SRC_URI += "file://0001-Unset-need_charset_alias-when-building-for-musl.patch \
file://0001-Don-t-leak-temporary-file-on-failed-ed-style-patch.patch \
file://0001-Don-t-leak-temporary-file-on-failed-multi-file-ed.patch \
file://CVE-2019-20633.patch \
+ file://CVE-2026-56289.patch \
"
SRC_URI[md5sum] = "4c68cee989d83c87b00a3860bcd05600"
^ permalink raw reply related [flat|nested] 31+ messages in thread
* [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
` (25 preceding siblings ...)
2026-09-02 5:25 ` [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289 Yoann Congal
@ 2026-09-02 5:25 ` Yoann Congal
26 siblings, 0 replies; 31+ messages in thread
From: Yoann Congal @ 2026-09-02 5:25 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix referenced by NVD in [2], using
the commit shown in [1].
[1] https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56288
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a30cd69993f9f48d5cf55e57181e49171f0a1b7a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../patch/patch/CVE-2026-56288.patch | 75 +++++++++++++++++++
meta/recipes-devtools/patch/patch_2.7.6.bb | 1 +
2 files changed, 76 insertions(+)
create mode 100644 meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
diff --git a/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch b/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
new file mode 100644
index 00000000000..03e1211f2ed
--- /dev/null
+++ b/meta/recipes-devtools/patch/patch/CVE-2026-56288.patch
@@ -0,0 +1,75 @@
+From f98fd4b5f696d1fcc9d86f81555370cf4b21150f Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Tue, 21 Apr 2026 10:05:02 -0700
+Subject: [PATCH] Avoid null pointer derefence with bad hunks
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Problem reported by Michał Majchrowicz.
+* src/pch.c (another_hunk): Keep chars_read positive
+even with malformed hunks.
+
+CVE: CVE-2026-56288
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313]
+
+(cherry picked from commit e6d6a4e021660679d7fc9150f981d4920f722313)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pch.c | 15 ++++++++++-----
+ 1 file changed, 10 insertions(+), 5 deletions(-)
+
+diff --git a/src/pch.c b/src/pch.c
+index 6f9f36f..0a31f72 100644
+--- a/src/pch.c
++++ b/src/pch.c
+@@ -1728,7 +1728,8 @@ another_hunk (enum diff difftype, bool rev)
+ p_end = filldst-1;
+ malformed ();
+ }
+- chars_read -= fillsrc == p_ptrn_lines && incomplete_line ();
++ chars_read -= (1 < chars_read && fillsrc == p_ptrn_lines
++ && incomplete_line ());
+ p_Char[fillsrc] = ch;
+ p_line[fillsrc] = s;
+ p_len[fillsrc++] = chars_read;
+@@ -1745,7 +1746,8 @@ another_hunk (enum diff difftype, bool rev)
+ malformed ();
+ }
+ context++;
+- chars_read -= fillsrc == p_ptrn_lines && incomplete_line ();
++ chars_read -= (1 < chars_read && fillsrc == p_ptrn_lines
++ && incomplete_line ());
+ p_Char[fillsrc] = ch;
+ p_line[fillsrc] = s;
+ p_len[fillsrc++] = chars_read;
+@@ -1765,7 +1767,8 @@ another_hunk (enum diff difftype, bool rev)
+ p_end = fillsrc-1;
+ malformed ();
+ }
+- chars_read -= filldst == p_end && incomplete_line ();
++ chars_read -= (1 < chars_read && filldst == p_end
++ && incomplete_line ());
+ p_Char[filldst] = ch;
+ p_line[filldst] = s;
+ p_len[filldst++] = chars_read;
+@@ -1852,7 +1855,8 @@ another_hunk (enum diff difftype, bool rev)
+ if (buf[0] != '<' || (buf[1] != ' ' && buf[1] != '\t'))
+ fatal ("'<' followed by space or tab expected at line %s of patch",
+ format_linenum (numbuf0, p_input_line));
+- chars_read -= 2 + (i == p_ptrn_lines && incomplete_line ());
++ chars_read -= 2 + (3 < chars_read && i == p_ptrn_lines
++ && incomplete_line ());
+ p_len[i] = chars_read;
+ p_line[i] = savebuf (buf + 2, chars_read);
+ if (chars_read && ! p_line[i]) {
+@@ -1897,7 +1901,8 @@ another_hunk (enum diff difftype, bool rev)
+ if (buf[0] != '>' || (buf[1] != ' ' && buf[1] != '\t'))
+ fatal ("'>' followed by space or tab expected at line %s of patch",
+ format_linenum (numbuf0, p_input_line));
+- chars_read -= 2 + (i == p_end && incomplete_line ());
++ chars_read -= 2 + (3 < chars_read && i == p_end
++ && incomplete_line ());
+ p_len[i] = chars_read;
+ p_line[i] = savebuf (buf + 2, chars_read);
+ if (chars_read && ! p_line[i]) {
diff --git a/meta/recipes-devtools/patch/patch_2.7.6.bb b/meta/recipes-devtools/patch/patch_2.7.6.bb
index 74d9085c6b9..53e96dea0f8 100644
--- a/meta/recipes-devtools/patch/patch_2.7.6.bb
+++ b/meta/recipes-devtools/patch/patch_2.7.6.bb
@@ -12,6 +12,7 @@ SRC_URI += "file://0001-Unset-need_charset_alias-when-building-for-musl.patch \
file://0001-Don-t-leak-temporary-file-on-failed-multi-file-ed.patch \
file://CVE-2019-20633.patch \
file://CVE-2026-56289.patch \
+ file://CVE-2026-56288.patch \
"
SRC_URI[md5sum] = "4c68cee989d83c87b00a3860bcd05600"
^ permalink raw reply related [flat|nested] 31+ messages in thread
end of thread, other threads:[~2026-09-02 5:27 UTC | newest]
Thread overview: 31+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 5:25 [OE-core][scarthgap 00/27] Patch review Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 01/27] socat: fix native build on host with newer glibc Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 02/27] glibc: fix CVE-2026-5435 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 03/27] systemd: Fix CVE-2026-29111 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 04/27] python3-pyasn1: Fix CVE-2026-59886 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 05/27] python3-pyasn1: Fix CVE-2026-59884 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 06/27] python3: upgrade 3.12.13 -> 3.12.14 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 07/27] systemd: upgrade 255.21 -> 255.22 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 08/27] libarchive: handle CVE-2026-5121 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 09/27] libarchive: patch CVE-2026-5745 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 10/27] gnutls: set status for CVE-2026-1584 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 11/27] perl: fix CVE-2026-13221 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 12/27] perl: fix CVE-2026-57432 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 13/27] perl: fix CVE-2025-40909 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 14/27] wget: Fix CVE-2026-58469 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 15/27] wget: Fix CVE-2026-58471 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 16/27] wget: Fix CVE-2026-58472 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 17/27] vim: Security Fix for CVE-2026-55693 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 18/27] vim: Security Fix for CVE-2026-55892 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 19/27] vim: Security Fix for CVE-2026-55895 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 20/27] vim: Security Fix for CVE-2026-57452 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 21/27] vim: Security Fix for CVE-2026-57455 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 22/27] vim: Security Fix for CVE-2026-59856 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 23/27] vim: Security Fix for CVE-2026-59857 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 24/27] vim: Security Fix for CVE-2026-59858 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 25/27] vim: Security Fix for CVE-2026-57456 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 26/27] patch: Fix CVE-2026-56289 Yoann Congal
2026-09-02 5:25 ` [OE-core][scarthgap 27/27] patch: Fix CVE-2026-56288 Yoann Congal
-- strict thread matches above, loose matches on Subject: below --
2024-11-21 21:53 [OE-core][scarthgap 00/27] Patch review Steve Sakoman
2024-09-30 1:56 Steve Sakoman
2024-07-14 12:38 Steve Sakoman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.