All of lore.kernel.org
 help / color / mirror / Atom feed
From: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
To: openembedded-core@lists.openembedded.org,
	Yoann Congal <yoann.congal@smile.fr>
Subject: Re: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
Date: Thu, 10 Sep 2026 10:12:39 +0530	[thread overview]
Message-ID: <e17b296b-ad39-4059-be9b-7f551b822933@windriver.com> (raw)
In-Reply-To: <11fef7c21845e03c044305ba57e289831e7518c9.1788938909.git.yoann.congal@smile.fr>

[-- Attachment #1: Type: text/plain, Size: 7063 bytes --]

Hi Yoann,

This CVE patch will come with the glibc 2.43 stable branch updates:
https://lists.openembedded.org/g/openembedded-core/message/245453 
<https://lists.openembedded.org/g/openembedded-core/message/245453>

Please drop this patch.

On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
> CAUTION: This email comes from a non Wind River email account!
> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>
> From: Harish Sadineni<Harish.Sadineni@windriver.com>
>
> Allocate the maximum array sizes directly, instead of resizing
> the arrays as needed.  This eliminates alloca usage from the
> function, and fixes the out-of-bounds accesses.  The asserts
> guard against the bug coming back if the balancing of the tree
> turns out not to work correctly.
>
> Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> CVE: CVE-2026-19542
>
> Reference:
> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>
> Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> Signed-off-by: Yoann Congal<yoann.congal@smile.fr>
> [YC: fixed CVE: tag in patch]
> ---
>   .../glibc/glibc/0023-CVE-2026-19542.patch     | 98 +++++++++++++++++++
>   meta/recipes-core/glibc/glibc_2.43.bb         |  1 +
>   2 files changed, 99 insertions(+)
>   create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>
> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> new file mode 100644
> index 00000000000..094a50919dc
> --- /dev/null
> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> @@ -0,0 +1,98 @@
> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
> +From: Florian Weimer<fweimer@redhat.com>
> +Date: Fri, 14 Aug 2026 13:41:16 +0200
> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
> +
> +Allocate the maximum array sizes directly, instead of resizing
> +the arrays as needed.  This eliminates alloca usage from the
> +function, and fixes the out-of-bounds accesses.  The asserts
> +guard against the bug coming back if the balancing of the tree
> +turns out not to work correctly.
> +
> +CVE: CVE-2026-19542
> +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> +
> +Reviewed-by: Adhemerval Zanella<adhemerval.zanella@linaro.org>
> +Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> +---
> + misc/tsearch.c | 31 +++++++++++--------------------
> + 1 file changed, 11 insertions(+), 20 deletions(-)
> +
> +diff --git a/misc/tsearch.c b/misc/tsearch.c
> +index 9b2eb34b25..e517dfa712 100644
> +--- a/misc/tsearch.c
> ++++ b/misc/tsearch.c
> +@@ -85,6 +85,7 @@
> + #include <assert.h>
> + #include <stdalign.h>
> + #include <stddef.h>
> ++#include <stdint.h>
> + #include <stdlib.h>
> + #include <string.h>
> + #include <search.h>
> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +   int cmp;
> +   node *rootp = (node *) vrootp;
> +   node root, unchained;
> +-  /* Stack of nodes so we remember the parents without recursion.  It's
> +-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
> +-     would need to have around 250.000 nodes.  */
> +-  int stacksize = 40;
> ++  /* Stack of nodes so we remember the parents without recursion.  The
> ++     stack size is a conservative approximation of the maximum height
> ++     of a red-black tree, based on size of the address space.
> ++     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
> ++  enum { stacksize = 2 * UINTPTR_WIDTH };
> +   int sp = 0;
> +-  node **nodestack = alloca (sizeof (node *) * stacksize);
> ++  node *nodestack[stacksize];
> +
> +   if (rootp == NULL)
> +     return NULL;
> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +   root = DEREFNODEPTR(rootp);
> +   while ((cmp = (*compar) (key, root->key)) != 0)
> +     {
> +-      if (sp == stacksize)
> +-      {
> +-        node **newstack;
> +-        stacksize += 20;
> +-        newstack = alloca (sizeof (node *) * stacksize);
> +-        nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +-      }
> +-
> ++      assert (sp < stacksize);
> +       nodestack[sp++] = rootp;
> +       p = DEREFNODEPTR(rootp);
> +       if (cmp < 0)
> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +       node upn;
> +       for (;;)
> +       {
> +-        if (sp == stacksize)
> +-          {
> +-            node **newstack;
> +-            stacksize += 20;
> +-            newstack = alloca (sizeof (node *) * stacksize);
> +-            nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +-          }
> ++        assert (sp < stacksize);
> +         nodestack[sp++] = parentp;
> +         parentp = up;
> +         upn = DEREFNODEPTR(up);
> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +                 SETNODEPTR(pp,q);
> +                 /* Make sure pp is right if the case below tries to use
> +                    it.  */
> ++                assert (sp < stacksize);
> +                 nodestack[sp++] = pp = LEFTPTR(q);
> +                 q = RIGHT(p);
> +               }
> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +                 SETLEFT(p,RIGHT(q));
> +                 SETRIGHT(q,p);
> +                 SETNODEPTR(pp,q);
> ++                assert (sp < stacksize);
> +                 nodestack[sp++] = pp = RIGHTPTR(q);
> +                 q = LEFT(p);
> +               }
> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
> index 9f3a3814d0a..3ef2301191d 100644
> --- a/meta/recipes-core/glibc/glibc_2.43.bb
> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
> @@ -55,6 +55,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
>              file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
>              file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
>              file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
> +file://0023-CVE-2026-19542.patch \
>   "
>   B = "${WORKDIR}/build-${TARGET_SYS}"
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#245430):https://lists.openembedded.org/g/openembedded-core/message/245430
> Mute This Topic:https://lists.openembedded.org/mt/121158859/10244482
> Group Owner:openembedded-core+owner@lists.openembedded.org
> Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [Hemanth.KumarMD@windriver.com]
> -=-=-=-=-=-=-=-=-=-=-=-

-- 
Regards,
Hemanth Kumar M D

[-- Attachment #2: Type: text/html, Size: 9581 bytes --]

  reply	other threads:[~2026-09-10  4:42 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
2026-09-10  4:42   ` Hemanth Kumar M D [this message]
2026-09-10 12:53     ` Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
2026-09-09 17:00   ` Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e17b296b-ad39-4059-be9b-7f551b822933@windriver.com \
    --to=hemanth.kumarmd@windriver.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=yoann.congal@smile.fr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.