From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-core@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Hetvi Thakar <hthakar@cisco.com>
Subject: [OE-core][wrynose][PATCH 2/4] wget: Fix CVE-2026-58470
Date: Wed, 22 Jul 2026 03:07:52 -0700 [thread overview]
Message-ID: <20260722100754.1568842-2-hthakar@cisco.com> (raw)
In-Reply-To: <20260722100754.1568842-1-hthakar@cisco.com>
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58470
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../wget/wget/CVE-2026-58470.patch | 79 +++++++++++++++++++
meta/recipes-extended/wget/wget_1.25.0.bb | 1 +
2 files changed, 80 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
new file mode 100644
index 0000000000..5d864c5fda
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
@@ -0,0 +1,79 @@
+From 8740efcdd0d9e7eb04122f63bdb151f1f4d94af8 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Mon, 29 Jun 2026 18:57:54 +0200
+Subject: [PATCH] * src/http.c (parse_content_range): Fix integer overflow
+
+Reported-by: TristanInSec@gmail.com
+
+CVE: CVE-2026-58470
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf]
+
+(cherry picked from commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/http.c | 35 ++++++++++++++++++++++++-----------
+ 1 file changed, 24 insertions(+), 11 deletions(-)
+
+diff --git a/src/http.c b/src/http.c
+index 07af1867..ea2e591b 100644
+--- a/src/http.c
++++ b/src/http.c
+@@ -914,6 +914,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ wgint *last_byte_ptr, wgint *entity_length_ptr)
+ {
+ wgint num;
++ char *end;
+
+ /* Ancient versions of Netscape proxy server, presumably predating
+ rfc2068, sent out `Content-Range' without the "bytes"
+@@ -932,27 +933,39 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ }
+ if (!c_isdigit (*hdr))
+ return false;
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
+- if (*hdr != '-' || !c_isdigit (*(hdr + 1)))
++
++ errno = 0;
++ num = strtol(hdr, &end, 10);
++ if (errno == ERANGE)
++ return false;
++ hdr = end;
++
++ if (*hdr++ != '-' || !c_isdigit (*hdr))
+ return false;
+ *first_byte_ptr = num;
+- ++hdr;
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
+- if (*hdr != '/')
++
++ errno = 0;
++ num = strtol(hdr, &end, 10);
++ if (errno == ERANGE)
++ return false;
++ hdr = end;
++
++ if (*hdr++ != '/')
+ return false;
+ *last_byte_ptr = num;
+- if (!(c_isdigit (*(hdr + 1)) || *(hdr + 1) == '*'))
++ if (!(c_isdigit (*hdr) || *hdr == '*'))
+ return false;
+ if (*last_byte_ptr < *first_byte_ptr)
+ return false;
+- ++hdr;
+ if (*hdr == '*')
+ num = -1;
+ else
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
++ {
++ errno = 0;
++ num = strtol(hdr, NULL, 10);
++ if (errno == ERANGE)
++ return false;
++ }
+ *entity_length_ptr = num;
+ if ((*entity_length_ptr <= *last_byte_ptr) && *entity_length_ptr != -1)
+ return false;
diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb
index fb77754965..e8847de042 100644
--- a/meta/recipes-extended/wget/wget_1.25.0.bb
+++ b/meta/recipes-extended/wget/wget_1.25.0.bb
@@ -18,6 +18,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://CVE-2026-58469.patch \
file://CVE-2026-58469-regression_p1.patch \
file://CVE-2026-58469-regression_p2.patch \
+ file://CVE-2026-58470.patch \
"
SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784"
--
2.35.6
next prev parent reply other threads:[~2026-07-22 10:08 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 10:07 [OE-core][wrynose][PATCH 1/4] wget: Fix CVE-2026-58469 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-22 10:07 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-25 13:47 ` [OE-core][wrynose][PATCH 2/4] wget: Fix CVE-2026-58470 Yoann Congal
2026-09-03 21:18 ` Yoann Congal
2026-09-04 4:42 ` [wrynose][PATCH " Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-22 10:07 ` [OE-core][wrynose][PATCH 3/4] wget: Fix CVE-2026-58471 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-22 10:07 ` [OE-core][wrynose][PATCH 4/4] wget: Fix CVE-2026-58472 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-22 17:41 ` [OE-core][wrynose][PATCH 1/4] wget: Fix CVE-2026-58469 Yoann Congal
2026-07-23 8:44 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-26 20:54 ` Yoann Congal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722100754.1568842-2-hthakar@cisco.com \
--to=hthakar@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox