From: "Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)" <deeratho@cisco.com>
To: openembedded-core@lists.openembedded.org
Subject: [OE-core][scarthgap][PATCH v3 6/6] glib-2.0: fix CVE-2026-58015
Date: Fri, 31 Jul 2026 15:40:13 +0530 [thread overview]
Message-ID: <20260731101013.208779-1-deeratho@cisco.com> (raw)
In-Reply-To: <20260727121444.3158996-1-deeratho@cisco.com>
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream glib-2-88 stable backport chain for
CVE-2026-58015. The issue is in the D-Bus SHA-1 authentication
mechanism, where a malicious peer could provide an unchecked cookie
context and cause the client to access unintended files while resolving
the cookie challenge.
Backport the upstream GLib fix chain from the glib-2-88 stable branch:
- db9c8fae398b validates cookie_context before keyring lookup. This is
the primary security fix for CVE-2026-58015 [1].
- c0531125344b tightens cookie ID parsing so empty, negative, and
out-of-range values are rejected. This hardens the same SHA-1 cookie
challenge parser and is covered by the upstream regression test [2].
- 060aea67de75 exposes the private client reject-reason vfunc. This is
test-support plumbing required by the upstream regression test [3].
- 091930196229 adds the upstream regression test for SHA-1 cookie
challenge parsing [4].
Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon
when building the new installed D-Bus regression test for ptest. This is
kept as a native-only test dependency to avoid adding a target dbus
dependency to glib.
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a
[2] https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb
[3] https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22
[4] https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-58015
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
Changes in v3:
- Carry the full upstream stable backport chain for CVE-2026-58015,
including the cookie ID hardening, private test-support vfunc, and
regression test commits.
- Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon
and build/install the new D-Bus regression test for ptest.
- Expand the commit message references so each upstream commit in the
backport chain is linked from the explanatory text.
.../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch | 98 ++++++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch | 55 +++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 ++++++++++++++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 219 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 4 +
meta/recipes-core/glib-2.0/glib.inc | 2 +-
6 files changed, 575 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
new file mode 100644
index 0000000000..3c3b74fc58
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
@@ -0,0 +1,98 @@
+From 1d0d0dc891399e8572a6c96b116149d076e2de28 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:47:30 +0100
+Subject: [PATCH 1/4] gdbusauthmechanismsha1: Validate cookie context
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Without validation, the server could send a malicious context which
+contains path traversal characters, allowing it to exfiltrate a SHA-1
+hashed copy of arbitrary data from the client's file system.
+
+To exploit this successfully would require the client to choose to
+connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
+authentication mechanism in preference to all the other mechanisms. This
+is vanishingly unlikely.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a]
+
+Backport Changes:
+- Added <stdint.h> include because the target branch does not otherwise
+ expose uint8_t used by the upstream validation code during native builds.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+
+Fixes: #3931
+(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 37 ++++++++++++++++++++++++++++++++++++
+ 1 file changed, 37 insertions(+)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index c8aa08977..7d8fc1922 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -22,6 +22,7 @@
+
+ #include "config.h"
+
++#include <stdint.h>
+ #include <string.h>
+ #include <fcntl.h>
+ #include <errno.h>
+@@ -1198,6 +1199,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+ return initial_response;
+ }
+
++/* Context names must be valid ASCII, nonzero length, and may not contain the
++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
++ * carriage return ("\r"), tab ("\t"), or period (".").
++ *
++ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */
++static gboolean
++validate_cookie_context (const char *cookie_context)
++{
++ size_t i = 0;
++
++ g_return_val_if_fail (cookie_context != NULL, FALSE);
++
++ for (i = 0; cookie_context[i] != '\0'; i++)
++ {
++ if ((uint8_t) cookie_context[i] >= 128 ||
++ cookie_context[i] == '/' ||
++ cookie_context[i] == '\\' ||
++ cookie_context[i] == ' ' ||
++ cookie_context[i] == '\n' ||
++ cookie_context[i] == '\r' ||
++ cookie_context[i] == '\t' ||
++ cookie_context[i] == '.')
++ return FALSE;
++ }
++
++ return (i > 0);
++}
++
+ static void
+ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ const gchar *data,
+@@ -1232,6 +1261,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ }
+
+ cookie_context = tokens[0];
++ if (!validate_cookie_context (tokens[0]))
++ {
++ g_free (m->priv->reject_reason);
++ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]);
++ m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
++ goto out;
++ }
++
+ cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+ if (*endp != '\0')
+ {
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
new file mode 100644
index 0000000000..28f496734a
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
@@ -0,0 +1,55 @@
+From a94b2df7e2bc5f49661e53c2781ce99ae48d18aa Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:49:54 +0100
+Subject: [PATCH 2/4] gdbusauthmechanismsha1: Improve validation of cookie ID
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The D-Bus specification says the cookie ID has to be non-negative, but
+we weren’t checking that (or checking that it was non-empty).
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit c0531125344bb25fd66ffb7435ed6c285de09aeb)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index 7d8fc1922..e753d139d 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -1235,7 +1235,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+ gchar **tokens;
+ const gchar *cookie_context;
+- guint cookie_id;
++ int64_t cookie_id;
+ const gchar *server_challenge;
+ gchar *client_challenge;
+ gchar *endp;
+@@ -1270,7 +1270,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ }
+
+ cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+- if (*endp != '\0')
++ if (*endp != '\0' || endp == tokens[1] || cookie_id < 0 || cookie_id > UINT32_MAX)
+ {
+ g_free (m->priv->reject_reason);
+ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_id '%s'", tokens[1]);
+@@ -1280,7 +1280,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ server_challenge = tokens[2];
+
+ error = NULL;
+- cookie = keyring_lookup_entry (cookie_context, cookie_id, &error);
++ cookie = keyring_lookup_entry (cookie_context, (unsigned int) cookie_id, &error);
+ if (cookie == NULL)
+ {
+ g_free (m->priv->reject_reason);
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
new file mode 100644
index 0000000000..b6bd2baeb3
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
@@ -0,0 +1,198 @@
+From 99c7abffbd1d549f6c625de6f2028efcdeea5c49 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:51:00 +0100
+Subject: [PATCH 3/4] gdbusauthmechanism: Expose client reject reason as a new
+ vfunc
+
+We can do this because `gdbusauthmechanism.h` is a private header.
+
+Hook it up to the existing `reject_reason` code in each
+`GDBusAuthMechanism` implementation, as all three implementations
+currently intermingle reject reasons from the server and client code, so
+there would currently be no benefit to having a separate server and
+client implementation of `*_get_reject_reason()`.
+
+This new private API will be used in a new unit test in the following
+commit.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 060aea67de7517d531b8fe2cdc07aa1a00ddeb22)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanism.c | 7 +++++++
+ gio/gdbusauthmechanism.h | 2 ++
+ gio/gdbusauthmechanismanon.c | 8 ++++----
+ gio/gdbusauthmechanismexternal.c | 8 ++++----
+ gio/gdbusauthmechanismsha1.c | 8 ++++----
+ 5 files changed, 21 insertions(+), 12 deletions(-)
+
+diff --git a/gio/gdbusauthmechanism.c b/gio/gdbusauthmechanism.c
+index 6e494dbd9..0d4ef4389 100644
+--- a/gio/gdbusauthmechanism.c
++++ b/gio/gdbusauthmechanism.c
+@@ -328,6 +328,13 @@ _g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism,
+ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_send (mechanism, out_data_len);
+ }
+
++gchar *
++_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM (mechanism), NULL);
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
+ void
+ _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
+ {
+diff --git a/gio/gdbusauthmechanism.h b/gio/gdbusauthmechanism.h
+index f0edd19a3..e906a47ac 100644
+--- a/gio/gdbusauthmechanism.h
++++ b/gio/gdbusauthmechanism.h
+@@ -100,6 +100,7 @@ struct _GDBusAuthMechanismClass
+ gsize data_len);
+ gchar *(*client_data_send) (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
++ gchar *(*client_get_reject_reason) (GDBusAuthMechanism *mechanism);
+ void (*client_shutdown) (GDBusAuthMechanism *mechanism);
+ };
+
+@@ -148,6 +149,7 @@ void _g_dbus_auth_mechanism_client_data_receive (GDBus
+ gsize data_len);
+ gchar *_g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
++gchar *_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ void _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism);
+
+
+diff --git a/gio/gdbusauthmechanismanon.c b/gio/gdbusauthmechanismanon.c
+index 5f59d4a61..3d80ec15f 100644
+--- a/gio/gdbusauthmechanismanon.c
++++ b/gio/gdbusauthmechanismanon.c
+@@ -56,7 +56,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -103,12 +103,13 @@ _g_dbus_auth_mechanism_anon_class_init (GDBusAuthMechanismAnonClass *klass)
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -222,12 +223,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismAnon *m = G_DBUS_AUTH_MECHANISM_ANON (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_ANON (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismexternal.c b/gio/gdbusauthmechanismexternal.c
+index 6fe8b1bed..b223ead04 100644
+--- a/gio/gdbusauthmechanismexternal.c
++++ b/gio/gdbusauthmechanismexternal.c
+@@ -64,7 +64,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -111,12 +111,13 @@ _g_dbus_auth_mechanism_external_class_init (GDBusAuthMechanismExternalClass *kla
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -321,12 +322,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index e753d139d..6c1682d3a 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -120,7 +120,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -173,12 +173,13 @@ _g_dbus_auth_mechanism_sha1_class_init (GDBusAuthMechanismSha1Class *klass)
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -1129,12 +1130,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_SHA1 (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ return g_strdup (m->priv->reject_reason);
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
new file mode 100644
index 0000000000..e7072bc6b4
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
@@ -0,0 +1,219 @@
+From 80d2edcc14f476d0ec82dc0733964afa6e9ca74d Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:52:53 +0100
+Subject: [PATCH 4/4] tests: Add a unit test for GDBusAuthMechanismSha1 cookie
+ context parsing
+
+This checks for regressions in the fixes from the previous few commits.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+Helps: #3931
+(cherry picked from commit 0919301962291a712067ee0c5d273cc392f33277)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/tests/gdbus-auth-mechanism-sha1.c | 177 ++++++++++++++++++++++++++
+ gio/tests/meson.build | 1 +
+ 2 files changed, 178 insertions(+)
+ create mode 100644 gio/tests/gdbus-auth-mechanism-sha1.c
+
+diff --git a/gio/tests/gdbus-auth-mechanism-sha1.c b/gio/tests/gdbus-auth-mechanism-sha1.c
+new file mode 100644
+index 000000000..abcdb4e3e
+--- /dev/null
++++ b/gio/tests/gdbus-auth-mechanism-sha1.c
+@@ -0,0 +1,177 @@
++/* GLib testing framework examples and tests
++ *
++ * Copyright (C) 2026 Philip Withnall
++ *
++ * SPDX-License-Identifier: LGPL-2.1-or-later
++ *
++ * This library is free software; you can redistribute it and/or
++ * modify it under the terms of the GNU Lesser General Public
++ * License as published by the Free Software Foundation; either
++ * version 2.1 of the License, or (at your option) any later version.
++ *
++ * This library is distributed in the hope that it will be useful,
++ * but WITHOUT ANY WARRANTY; without even the implied warranty of
++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
++ * Lesser General Public License for more details.
++ *
++ * You should have received a copy of the GNU Lesser General
++ * Public License along with this library; if not, see <http://www.gnu.org/licenses/>.
++ *
++ * Author: Philip Withnall <pwithnall@gnome.org>
++ */
++
++#include <locale.h>
++#include <gio/gio.h>
++
++#include <string.h>
++#include <unistd.h>
++
++#include "gdbus-tests.h"
++
++#ifdef G_OS_UNIX
++#include <gio/gunixconnection.h>
++#include <gio/gnetworkingprivate.h>
++#include <gio/gunixsocketaddress.h>
++#include <gio/gunixfdlist.h>
++#endif
++
++#define GIO_COMPILATION 1
++#include "gdbusauthmechanism.h"
++#include "gdbusauthmechanismsha1.h"
++
++/* Vfunc wrappers copied from gdbusauthmechanism.c as they are not public. */
++static gboolean
++dbus_auth_mechanism_is_supported (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->is_supported (mechanism);
++}
++
++static GDBusAuthMechanismState
++dbus_auth_mechanism_client_get_state (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_state (mechanism);
++}
++
++static gchar *
++dbus_auth_mechanism_client_initiate (GDBusAuthMechanism *mechanism,
++ GDBusConnectionFlags conn_flags,
++ size_t *out_initial_response_len)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_initiate (mechanism,
++ conn_flags,
++ out_initial_response_len);
++}
++
++static void
++dbus_auth_mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
++ const char *data,
++ size_t data_len)
++{
++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_receive (mechanism, data, data_len);
++}
++
++static char *
++dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
++static void
++dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
++{
++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_shutdown (mechanism);
++}
++
++static void
++test_server_challenge_validation (void)
++{
++ const struct
++ {
++ const char *server_challenge;
++ const char *expected_reject_reason_prefix;
++ }
++ vectors[] = {
++ { "valid_context 123 456", "Problems looking up entry in keyring" },
++ { "invalid/context 123 456", "Malformed cookie_context" },
++ { "invalid.context 123 456", "Malformed cookie_context" },
++ { " 123 456", "Malformed cookie_context" },
++ { "😀 123 456", "Malformed cookie_context" },
++ { "invalid\ncontext 123 456", "Malformed cookie_context" },
++ { "invalid\rcontext 123 456", "Malformed cookie_context" },
++ { "invalid\tcontext 123 456", "Malformed cookie_context" },
++ { "invalid\\context 123 456", "Malformed cookie_context" },
++ { "valid_context 456", "Malformed cookie_id" },
++ { "valid_context 123notanumber 456", "Malformed cookie_id" },
++ { "valid_context -1 456", "Malformed cookie_id" },
++ { "valid_context 4294967296 456", "Malformed cookie_id" },
++ { "valid_context 123 ", "Malformed data" },
++ { "valid_context ", "Malformed data" },
++ };
++ GType mechanism_type;
++ GDBusConnection *connection = NULL;
++
++ g_test_summary ("Test that GDBusAuthMechanismSha1 rejects various malformed server data lines");
++
++ /* Briefly connect to the actual bus to ensure the GDBusAuth mechanisms are
++ * all registered. */
++ session_bus_up ();
++
++ connection = g_bus_get_sync (G_BUS_TYPE_SESSION, NULL, NULL);
++ g_assert_nonnull (connection);
++ g_clear_object (&connection);
++
++ session_bus_down ();
++
++ /* Check that we now have the type ID for GDBusAuthMechanismSha1 */
++ mechanism_type = g_type_from_name ("GDBusAuthMechanismSha1");
++ g_assert_cmpint (mechanism_type, !=, 0);
++
++ for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
++ {
++ GDBusAuthMechanism *mechanism = NULL;
++ char *data = NULL;
++ size_t data_len = 0;
++ char *reject_reason = NULL;
++
++ mechanism = g_object_new (mechanism_type, NULL);
++
++ if (!dbus_auth_mechanism_is_supported (mechanism))
++ {
++ g_test_skip ("Mechanism not supported");
++ g_clear_object (&mechanism);
++ return;
++ }
++
++ data = dbus_auth_mechanism_client_initiate (mechanism,
++ G_DBUS_CONNECTION_FLAGS_AUTHENTICATION_CLIENT,
++ &data_len);
++ g_free (data);
++
++ dbus_auth_mechanism_client_data_receive (mechanism, vectors[i].server_challenge, strlen (vectors[i].server_challenge));
++
++ g_assert_cmpint (dbus_auth_mechanism_client_get_state (mechanism), ==, G_DBUS_AUTH_MECHANISM_STATE_REJECTED);
++
++ reject_reason = dbus_auth_mechanism_client_get_reject_reason (mechanism);
++ g_assert_true (g_str_has_prefix (reject_reason, vectors[i].expected_reject_reason_prefix));
++ g_free (reject_reason);
++
++ dbus_auth_mechanism_client_shutdown (mechanism);
++
++ g_clear_object (&mechanism);
++ }
++}
++
++int
++main (int argc,
++ char *argv[])
++{
++ setlocale (LC_ALL, "C");
++
++ g_test_init (&argc, &argv, G_TEST_OPTION_ISOLATE_DIRS, NULL);
++
++ g_test_dbus_unset ();
++
++ g_test_add_func ("/gdbus/auth-mechanism-sha1/server-challenge-validation", test_server_challenge_validation);
++
++ return g_test_run ();
++}
+diff --git a/gio/tests/meson.build b/gio/tests/meson.build
+index e7699c336..74ea481ff 100644
+--- a/gio/tests/meson.build
++++ b/gio/tests/meson.build
+@@ -418,6 +418,7 @@ if host_system != 'windows'
+ },
+ 'fdo-notification-backend': {},
+ 'gdbus-auth' : {'extra_sources' : extra_sources},
++ 'gdbus-auth-mechanism-sha1': {'extra_sources' : extra_sources},
+ 'gdbus-bz627724' : {'extra_sources' : extra_sources},
+ 'gdbus-close-pending' : {'extra_sources' : extra_sources},
+ 'gdbus-connection' : {
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index e15aa1fe20..70b0b74e88 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -54,6 +54,10 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58012.patch \
file://CVE-2026-58013.patch \
file://CVE-2026-58014.patch \
+ file://CVE-2026-58015_p1.patch \
+ file://CVE-2026-58015_p2.patch \
+ file://CVE-2026-58015_p3.patch \
+ file://CVE-2026-58015_p4.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc
index fac8875d84..5b69c9d7d3 100644
--- a/meta/recipes-core/glib-2.0/glib.inc
+++ b/meta/recipes-core/glib-2.0/glib.inc
@@ -39,7 +39,7 @@ PACKAGECONFIG ??= "libmount \
PACKAGECONFIG[libmount] = "-Dlibmount=enabled,-Dlibmount=disabled,util-linux"
PACKAGECONFIG[manpages] = "-Dman=true, -Dman=false, libxslt-native xmlto-native"
PACKAGECONFIG[libelf] = "-Dlibelf=enabled,-Dlibelf=disabled,elfutils"
-PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,"
+PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,dbus-native"
PACKAGECONFIG[selinux] = "-Dselinux=enabled,-Dselinux=disabled,libselinux"
EXTRA_OEMESON = "-Ddtrace=false -Dsystemtap=false"
--
2.35.6
next prev parent reply other threads:[~2026-07-31 10:10 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 3/6] glib-2.0: fix CVE-2026-58012 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 4/6] glib-2.0: fix CVE-2026-58013 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 5/6] glib-2.0: fix CVE-2026-58014 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-25 6:42 ` [scarthgap][PATCH " Siddharth Doshi
2026-07-27 12:18 ` Deepak Rathore
2026-07-27 17:48 ` Siddharth Doshi
2026-07-27 12:14 ` [OE-core][scarthgap][PATCH v2 " Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-27 17:27 ` Yoann Congal
2026-07-27 17:58 ` [scarthgap][PATCH " Siddharth Doshi
2026-07-30 5:14 ` [OE-core] " Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-31 10:10 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-07-31 10:16 ` Patchtest results for [OE-core][scarthgap][PATCH v3 " patchtest
2026-08-13 8:58 ` Deepak Rathore
2026-08-13 8:57 ` [OE-core][scarthgap][PATCH v4 " Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-19 22:56 ` [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Yoann Congal
2026-07-20 5:50 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731101013.208779-1-deeratho@cisco.com \
--to=deeratho@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox