* [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010
@ 2026-07-15 17:23 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (5 more replies)
0 siblings, 6 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58010. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58010.patch | 113 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 114 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
new file mode 100644
index 0000000000..842d53af5c
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
@@ -0,0 +1,113 @@
+From 333f164f00fb874e3c670ce70d2a2a3667b9ebf9 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 19:10:41 +0100
+Subject: [PATCH] gvariant: Fix an off-by-one error in an offset comparison
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This allows a single byte out-of-bounds read off the end of the
+(potentially untrusted) byte array backing a `GVariant` when it’s
+being checked for normal form.
+
+I can’t see how this could practically be exploited, but it’s certainly
+a security bug as the `GVariant` normal form checking code is supposed
+to be robust to malicious inputs.
+
+Spotted by linhlhq as #YWH-PGM9867-190, and fix and reproducer provided
+by them too, thanks. Confirmed and turned into a unit test by me.
+
+Fixes: #3915
+
+CVE: CVE-2026-58010
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit aa1cb87d56111ef989811e824f0ac77484cc997f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gvariant-serialiser.c | 2 +-
+ glib/tests/gvariant.c | 48 ++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 49 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gvariant-serialiser.c b/glib/gvariant-serialiser.c
+index 4e4a73ad1..99a1d3fbd 100644
+--- a/glib/gvariant-serialiser.c
++++ b/glib/gvariant-serialiser.c
+@@ -1247,7 +1247,7 @@ gvs_tuple_is_normal (GVariantSerialised value)
+
+ while (offset & alignment)
+ {
+- if (offset > value.size || value.data[offset] != '\0')
++ if (offset >= value.size || value.data[offset] != '\0')
+ return FALSE;
+ offset++;
+ }
+diff --git a/glib/tests/gvariant.c b/glib/tests/gvariant.c
+index c8f13360c..55e2cee00 100644
+--- a/glib/tests/gvariant.c
++++ b/glib/tests/gvariant.c
+@@ -5637,6 +5637,52 @@ test_normal_checking_tuple_offsets5 (void)
+ g_variant_unref (variant);
+ }
+
++/* This is a regression test that looping over the padding bytes in a short
++ * (non-normal) tuple doesn’t overflow the input data.
++ *
++ * See https://gitlab.gnome.org/GNOME/glib/-/issues/3915 */
++static void
++test_normal_checking_tuple_offsets6 (void)
++{
++ /*
++ * Type: (ynqiuxthdsog) — 12 members, first member 'y' (byte) has
++ * alignment 0, second 'n' (int16) has alignment 1.
++ * With 1 byte of data (0x28), after reading the first byte member,
++ * offset=1, alignment check for 'n' requires offset to be even,
++ * so the while loop checks value.data[1] — but size is only 1.
++ *
++ * Use heap allocation via GBytes so ASan reports heap-buffer-overflow.
++ */
++ guint8 *heap_data = NULL;
++ GBytes *bytes = NULL;
++ const GVariantType *data_type = G_VARIANT_TYPE ("(ynqiuxthdsog)");
++ GVariant *variant = NULL;
++ GVariant *normal_variant = NULL;
++ GVariant *expected = NULL;
++
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3915");
++
++ heap_data = g_malloc (1);
++ heap_data[0] = 0x28;
++ bytes = g_bytes_new_take (heap_data, 1);
++
++ variant = g_variant_new_from_bytes (data_type, bytes, FALSE);
++ g_assert_nonnull (variant);
++
++ g_assert_false (g_variant_is_normal_form (variant));
++
++ normal_variant = g_variant_get_normal_form (variant);
++ g_assert_nonnull (normal_variant);
++
++ expected = g_variant_new_parsed ("(byte 0x28, int16 0, uint16 0, 0, uint32 0, int64 0, uint64 0, handle 0, 0.0, '', objectpath '/', signature '')");
++ g_assert_cmpvariant (expected, variant);
++ g_assert_cmpvariant (expected, normal_variant);
++
++ g_variant_unref (expected);
++ g_variant_unref (normal_variant);
++ g_variant_unref (variant);
++}
++
+ /* Test that an otherwise-valid serialised GVariant is considered non-normal if
+ * its offset table entries are too wide.
+ *
+@@ -5890,6 +5936,8 @@ main (int argc, char **argv)
+ test_normal_checking_tuple_offsets4);
+ g_test_add_func ("/gvariant/normal-checking/tuple-offsets5",
+ test_normal_checking_tuple_offsets5);
++ g_test_add_func ("/gvariant/normal-checking/tuple-offsets6",
++ test_normal_checking_tuple_offsets6);
+ g_test_add_func ("/gvariant/normal-checking/tuple-offsets/minimal-sized",
+ test_normal_checking_tuple_offsets_minimal_sized);
+ g_test_add_func ("/gvariant/normal-checking/empty-object-path",
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index b8212c9d12..32e578db3c 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -47,6 +47,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-1489-02.patch \
file://CVE-2026-1489-03.patch \
file://CVE-2026-1489-04.patch \
+ file://CVE-2026-58010.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-15 17:23 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 3/6] glib-2.0: fix CVE-2026-58012 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 subsequent siblings)
5 siblings, 0 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58011. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58011
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58011.patch | 78 +++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 79 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
new file mode 100644
index 0000000000..a8d31c1270
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
@@ -0,0 +1,78 @@
+From 371dbccb6b9a9a42b93c4b371214b159e7e94792 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 23:46:17 +0100
+Subject: [PATCH] gdatetime: Add missing range validation to
+ g_date_time_add_full()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Otherwise it’s possible to create a non-`NULL` but invalid `GDateTime`,
+which breaks all kinds of internal assumptions.
+
+Spotted by linhlhq as #YWH-PGM9867-191. Thanks to them for providing a
+suggested fix and a test case, which I have adapted and validated.
+
+Fixes: #3917
+
+CVE: CVE-2026-58011
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b]
+
+Backport Changes:
+- Used the target branch's existing literal day bounds because it does
+ not have upstream's MIN_DAYS/MAX_DAYS helper macros.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit ae27363f025ffc131e2d75ee88a5cd8320dffe3b)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gdatetime.c | 4 +++-
+ glib/tests/gdatetime.c | 18 ++++++++++++++++++
+ 2 files changed, 21 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gdatetime.c b/glib/gdatetime.c
+index 2640e3b24..73eea643b 100644
+--- a/glib/gdatetime.c
++++ b/glib/gdatetime.c
+@@ -2024,7 +2024,9 @@ g_date_time_add_full (GDateTime *datetime,
+ new->days = full_time / USEC_PER_DAY;
+ new->usec = full_time % USEC_PER_DAY;
+
+- /* XXX validate */
++ /* Validate it’s still in the range 0001-01-01 to 9999-12-31 */
++ if (new->days < 1 || new->days > 3652059)
++ g_clear_pointer (&new, g_date_time_unref);
+
+ return new;
+ }
+diff --git a/glib/tests/gdatetime.c b/glib/tests/gdatetime.c
+index 49390c900..527d61a11 100644
+--- a/glib/tests/gdatetime.c
++++ b/glib/tests/gdatetime.c
+@@ -1117,6 +1117,24 @@ test_GDateTime_add_full (void)
+ TEST_ADD_FULL (2010, 8, 25, 22, 45, 0,
+ 0, 1, 6, 1, 25, 0,
+ 2010, 10, 2, 0, 10, 0);
++
++#define TEST_ADD_FULL_ERROR(y,m,d,h,mi,s,ay,am,ad,ah,ami,as) G_STMT_START { \
++ GDateTime *dt; \
++ dt = g_date_time_new_utc (y, m, d, h, mi, s); \
++ g_assert_null (g_date_time_add_full (dt, ay, am, ad, ah, ami, as)); \
++ g_date_time_unref (dt); \
++} G_STMT_END
++
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ -1, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ 10000, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
++ -10000, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ 0, 0, 3660001, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
++ 0, 0, -3660001, 0, 0, 0);
+ }
+
+ static void
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 32e578db3c..6532d7eac0 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -48,6 +48,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-1489-03.patch \
file://CVE-2026-1489-04.patch \
file://CVE-2026-58010.patch \
+ file://CVE-2026-58011.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [OE-core][scarthgap][PATCH 3/6] glib-2.0: fix CVE-2026-58012
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-15 17:23 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 4/6] glib-2.0: fix CVE-2026-58013 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 subsequent siblings)
5 siblings, 0 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58012. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58012
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58012.patch | 228 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 229 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
new file mode 100644
index 0000000000..7f8435809c
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
@@ -0,0 +1,228 @@
+From 74564fefcec22fc1efc187c36aa1fb8dcfe34454 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 31 Mar 2026 16:13:57 +0100
+Subject: [PATCH] gregex: Fix case changing substitutions with G_REGEX_RAW
+
+In `G_REGEX_RAW` mode, the input string is treated as a byte array
+(basically ASCII) rather than a unichar array. Accordingly, the case
+changing code for substitutions needs to operate on bytes with
+`G_REGEX_RAW`, rather than operating on unichars.
+
+This fixes a potential buffer overflow when trying to do a case change
+on a match of a set of bytes which are a truncated multi-byte UTF-8
+encoding at the end of the input buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-193. I adapted their reproducer as
+the unit test, but implemented the fix in `gregex.c` independently.
+
+Fixes: #3918
+
+CVE: CVE-2026-58012
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit d337aabd24ee2b8ac2a690dba3ccf26aa70e638f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gregex.c | 59 ++++++++++++++++++++++++++++++++++------------
+ glib/tests/regex.c | 53 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 97 insertions(+), 15 deletions(-)
+
+diff --git a/glib/gregex.c b/glib/gregex.c
+index 116ecacbb..496b34bbd 100644
+--- a/glib/gregex.c
++++ b/glib/gregex.c
+@@ -3147,19 +3147,25 @@ split_replacement (const gchar *replacement,
+ return g_list_reverse (list);
+ }
+
+-/* Change the case of c based on change_case. */
+-#define CHANGE_CASE(c, change_case) \
++/* Change the case of c based on change_case.
++ * g_ascii_to*() will happily pass through non-ASCII bytes unchanged. */
++#define UTF8_CHANGE_CASE(c, change_case) \
+ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
+ g_unichar_tolower (c) : \
+ g_unichar_toupper (c))
++#define RAW_CHANGE_CASE(c, change_case) \
++ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
++ g_ascii_tolower (c) : \
++ g_ascii_toupper (c))
+
++/* If @text_is_raw is set, @text might not be valid UTF-8 (but will be
++ * nul-terminated). */
+ static void
+ string_append (GString *string,
+ const gchar *text,
++ gboolean text_is_raw,
+ ChangeCase *change_case)
+ {
+- gunichar c;
+-
+ if (text[0] == '\0')
+ return;
+
+@@ -3169,22 +3175,44 @@ string_append (GString *string,
+ }
+ else if (*change_case & CHANGE_CASE_SINGLE_MASK)
+ {
+- c = g_utf8_get_char (text);
+- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+- g_string_append (string, g_utf8_next_char (text));
++ if (!text_is_raw)
++ {
++ gunichar c = g_utf8_get_char (text);
++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++ g_string_append (string, g_utf8_next_char (text));
++ }
++ else
++ {
++ g_string_append_c (string, RAW_CHANGE_CASE (text[0], *change_case));
++ g_string_append (string, text + 1);
++ }
++
+ *change_case = CHANGE_CASE_NONE;
+ }
+ else
+ {
+- while (*text != '\0')
++ if (!text_is_raw)
+ {
+- c = g_utf8_get_char (text);
+- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+- text = g_utf8_next_char (text);
++ while (*text != '\0')
++ {
++ gunichar c = g_utf8_get_char (text);
++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++ text = g_utf8_next_char (text);
++ }
++ }
++ else
++ {
++ while (*text != '\0')
++ {
++ char c = *text;
++ g_string_append_c (string, RAW_CHANGE_CASE (c, *change_case));
++ text++;
++ }
+ }
+ }
+ }
+
++/* @match_info is (nullable) */
+ static gboolean
+ interpolate_replacement (const GMatchInfo *match_info,
+ GString *result,
+@@ -3194,6 +3222,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ InterpolationData *idata;
+ gchar *match;
+ ChangeCase change_case = CHANGE_CASE_NONE;
++ gboolean is_raw = (match_info != NULL && (match_info->regex->orig_compile_opts & G_REGEX_RAW));
+
+ for (list = data; list; list = list->next)
+ {
+@@ -3201,10 +3230,10 @@ interpolate_replacement (const GMatchInfo *match_info,
+ switch (idata->type)
+ {
+ case REPL_TYPE_STRING:
+- string_append (result, idata->text, &change_case);
++ string_append (result, idata->text, is_raw, &change_case);
+ break;
+ case REPL_TYPE_CHARACTER:
+- g_string_append_c (result, CHANGE_CASE (idata->c, change_case));
++ g_string_append_c (result, UTF8_CHANGE_CASE (idata->c, change_case));
+ if (change_case & CHANGE_CASE_SINGLE_MASK)
+ change_case = CHANGE_CASE_NONE;
+ break;
+@@ -3212,7 +3241,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ match = g_match_info_fetch (match_info, idata->num);
+ if (match)
+ {
+- string_append (result, match, &change_case);
++ string_append (result, match, is_raw, &change_case);
+ g_free (match);
+ }
+ break;
+@@ -3220,7 +3249,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ match = g_match_info_fetch_named (match_info, idata->text);
+ if (match)
+ {
+- string_append (result, match, &change_case);
++ string_append (result, match, is_raw, &change_case);
+ g_free (match);
+ }
+ break;
+diff --git a/glib/tests/regex.c b/glib/tests/regex.c
+index d7a698ec6..bffb52a87 100644
+--- a/glib/tests/regex.c
++++ b/glib/tests/regex.c
+@@ -2529,6 +2529,58 @@ test_compiled_regex_after_jit_failure (void)
+ g_regex_unref (regex);
+ }
+
++static void
++test_replace_raw_change_case (void)
++{
++ GError *local_error = NULL;
++ GRegex *regex = NULL;
++
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3918");
++ g_test_summary ("Test that case changes as part of a replacement are handled correctly in G_REGEX_RAW mode");
++
++ /*
++ * Match a multi-byte sequence in RAW mode. The pattern matches
++ * exactly 2 bytes. The subject contains a 4-byte UTF-8 lead (0xF4)
++ * followed by only one continuation byte, then NUL.
++ *
++ * The matched substring will be "\xf4\x80" (2 bytes, heap-allocated
++ * as 3-byte buffer with NUL). If the code regresses and tries to handle
++ * the replacement as UTF-8 then g_utf8_get_char() would see 0xF4 and try
++ * to read 4 bytes, going 1 byte past the NUL into OOB territory.
++ */
++ regex = g_regex_new ("..", G_REGEX_RAW, 0, &local_error);
++ g_assert_no_error (local_error);
++
++ /*
++ * Build a subject string with truncated UTF-8.
++ * \xF4 = 4-byte UTF-8 lead byte
++ * \x80 = continuation byte
++ * No 3rd/4th continuation bytes — the match is only 2 bytes.
++ *
++ * \U\0 = uppercase the entire match → triggers string_append()
++ * with case change on the 2-byte non-UTF-8 match.
++ */
++ char subject[] = "\xf4\x80";
++ char *result = g_regex_replace (regex, subject, -1, 0, "\\U\\0", 0, &local_error);
++ g_assert_no_error (local_error);
++
++ g_clear_pointer (&result, g_free);
++ g_clear_pointer (®ex, g_regex_unref);
++
++ /*
++ * Second variant: single-char case change \u with \0 backreference.
++ */
++ regex = g_regex_new (".", G_REGEX_RAW, 0, &local_error);
++ g_assert_no_error (local_error);
++
++ char subject2[] = "\xe6\xb0"; /* 3-byte UTF-8 lead, only 2 bytes */
++ result = g_regex_replace (regex, subject2, -1, 0, "\\u\\0", 0, &local_error);
++ g_assert_no_error (local_error);
++
++ g_clear_pointer (&result, g_free);
++ g_clear_pointer (®ex, g_regex_unref);
++}
++
+ int
+ main (int argc, char *argv[])
+ {
+@@ -2550,6 +2602,7 @@ main (int argc, char *argv[])
+ g_test_add_func ("/regex/jit-unsupported-matching", test_jit_unsupported_matching_options);
+ g_test_add_func ("/regex/unmatched-named-subpattern", test_unmatched_named_subpattern);
+ g_test_add_func ("/regex/compiled-regex-after-jit-failure", test_compiled_regex_after_jit_failure);
++ g_test_add_func ("/regex/replace-raw-change-case", test_replace_raw_change_case);
+
+ /* TEST_NEW(pattern, compile_opts, match_opts) */
+ TEST_NEW("[A-Z]+", G_REGEX_CASELESS | G_REGEX_EXTENDED | G_REGEX_OPTIMIZE, G_REGEX_MATCH_NOTBOL | G_REGEX_MATCH_PARTIAL);
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 6532d7eac0..2a4a1dad5b 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -49,6 +49,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-1489-04.patch \
file://CVE-2026-58010.patch \
file://CVE-2026-58011.patch \
+ file://CVE-2026-58012.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [OE-core][scarthgap][PATCH 4/6] glib-2.0: fix CVE-2026-58013
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 3/6] glib-2.0: fix CVE-2026-58012 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-15 17:23 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 5/6] glib-2.0: fix CVE-2026-58014 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 subsequent siblings)
5 siblings, 0 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.88.1 backport for
CVE-2026-58013. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58013
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58013.patch | 140 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 141 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
new file mode 100644
index 0000000000..fa3db56bdb
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
@@ -0,0 +1,140 @@
+From cb9d97e1b261d75eb8ea255e0a9f3e846d547af7 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 16:45:14 +0100
+Subject: [PATCH] giochannel: Fix memcmp() off the end of the buffer with long
+ terminators
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+If the line terminator is longer than a single byte, and the current
+line extends to the end of the buffer, and the buffer (which is a
+`GString`) is near a power of two in length (as that’s how `GString`s
+are allocated) it’s possible for the `memcmp()` which checks the
+terminator to read off the end of the string buffer.
+
+Fix that by checking the terminator length against the last character
+before calling `memcmp()`. Add a unit test.
+
+Spotted by linhlhq as #YWH-PGM9867-199. The fix is theirs (validated by
+me), and the unit test is adapted from their proof of concept.
+
+Fixes: #3925
+
+CVE: CVE-2026-58013
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244]
+
+Backport Changes:
+- Added the <stdint.h> include for the regression test because these target
+ branches do not otherwise expose uint8_t in glib/tests/io-channel.c.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 6a2583dec39bfe05553b16d9b7419d6c2a257244)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/giochannel.c | 3 ++-
+ glib/tests/io-channel.c | 61 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 63 insertions(+), 1 deletion(-)
+
+diff --git a/glib/giochannel.c b/glib/giochannel.c
+index 7572c47a2..8d867d0fb 100644
+--- a/glib/giochannel.c
++++ b/glib/giochannel.c
+@@ -1833,7 +1833,8 @@ read_again:
+ {
+ if (channel->line_term)
+ {
+- if (memcmp (channel->line_term, nextchar, line_term_len) == 0)
++ if ((size_t) (lastchar - nextchar) >= line_term_len &&
++ memcmp (channel->line_term, nextchar, line_term_len) == 0)
+ {
+ line_length = nextchar - use_buf->str;
+ got_term_len = line_term_len;
+diff --git a/glib/tests/io-channel.c b/glib/tests/io-channel.c
+index c5dd01d04..cf81a9f6b 100644
+--- a/glib/tests/io-channel.c
++++ b/glib/tests/io-channel.c
+@@ -29,6 +29,7 @@
+
+ #include <glib.h>
+ #include <glib/gstdio.h>
++#include <stdint.h>
+
+ static void
+ test_small_writes (void)
+@@ -216,6 +217,65 @@ test_read_line_embedded_nuls (void)
+ g_free (filename);
+ }
+
++static void
++test_read_line_long_terminator (void)
++{
++ uint8_t *test_data = NULL;
++ size_t test_data_len = 0;
++ int fd;
++ char *filename = NULL;
++ GIOChannel *channel = NULL;
++ GError *local_error = NULL;
++ char *line = NULL;
++ size_t line_length, terminator_pos;
++ const char *line_term;
++ int line_term_length;
++ GIOStatus status;
++
++ g_test_summary ("Test that reading a line when using a long terminator doesn’t over-read the buffer.");
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/work_items/3925");
++
++ /* Write out a temporary file containing 2047 bytes. This is enough to make it
++ * near the length of the GString buffer when read back in. */
++ fd = g_file_open_tmp ("glib-test-io-channel-XXXXXX", &filename, &local_error);
++ g_assert_no_error (local_error);
++ g_close (g_steal_fd (&fd), NULL);
++
++ test_data_len = 2047;
++ test_data = g_malloc (test_data_len);
++ memset (test_data, 'M', test_data_len);
++ g_file_set_contents (filename, (const gchar *) test_data, test_data_len, &local_error);
++ g_assert_no_error (local_error);
++
++ /* Create the channel. */
++ channel = g_io_channel_new_file (filename, "r", &local_error);
++ g_assert_no_error (local_error);
++
++ /* Use a long line terminator so it could potentially over-read the end of the buffer. */
++ g_io_channel_set_line_term (channel, "DEADBEEF", 8);
++
++ line_term = g_io_channel_get_line_term (channel, &line_term_length);
++ g_assert_cmpstr (line_term, ==, "DEADBEEF");
++ g_assert_cmpint (line_term_length, ==, 8);
++
++ g_io_channel_set_encoding (channel, "UTF-8", &local_error);
++ g_assert_no_error (local_error);
++
++ status = g_io_channel_read_line (channel, &line, &line_length,
++ &terminator_pos, &local_error);
++ g_assert_no_error (local_error);
++ g_assert_cmpint (status, ==, G_IO_STATUS_NORMAL);
++ g_assert_cmpuint (line_length, ==, 2047);
++ g_assert_cmpuint (terminator_pos, ==, 2047);
++ g_assert_cmpmem (line, line_length, test_data, test_data_len);
++
++ g_free (line);
++ g_io_channel_unref (channel);
++ g_free (test_data);
++ g_unlink (filename);
++ g_free (filename);
++}
++
+ int
+ main (int argc,
+ char *argv[])
+@@ -224,6 +283,7 @@ main (int argc,
+
+ g_test_add_func ("/io-channel/read-write", test_read_write);
+ g_test_add_func ("/io-channel/read-line/embedded-nuls", test_read_line_embedded_nuls);
++ g_test_add_func ("/io-channel/read-line/long-terminator", test_read_line_long_terminator);
+
+ return g_test_run ();
+ }
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 2a4a1dad5b..5486969abb 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -50,6 +50,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58010.patch \
file://CVE-2026-58011.patch \
file://CVE-2026-58012.patch \
+ file://CVE-2026-58013.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [OE-core][scarthgap][PATCH 5/6] glib-2.0: fix CVE-2026-58014
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 preceding siblings ...)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 4/6] glib-2.0: fix CVE-2026-58013 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-15 17:23 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-19 22:56 ` [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Yoann Congal
5 siblings, 0 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.88.1 backport for
CVE-2026-58014. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58014
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58014.patch | 106 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 107 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
new file mode 100644
index 0000000000..4e5262b66d
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
@@ -0,0 +1,106 @@
+From ba0478c206bc04542df774343c6c85f77df49f6e Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sat, 11 Apr 2026 14:42:57 +0100
+Subject: [PATCH] gkeyfile: Fix a one-byte heap under-read with
+ g_key_file_get_locale_string_list()
+
+If this method was called on a key file key which has an empty value,
+`len == 0` and this leads to a one-byte under-read off the start of the
+key file buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-200. The suggested fix is theirs, and
+the unit test is adapted from their report. I added the fuzzing test.
+
+Fixes: #3930
+
+CVE: CVE-2026-58014
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 94ecb5b44a1cae09f481dd5e693832f129948893)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ fuzzing/fuzz_key.c | 9 +++++++++
+ glib/gkeyfile.c | 2 +-
+ glib/tests/keyfile.c | 23 +++++++++++++++++++++++
+ 3 files changed, 33 insertions(+), 1 deletion(-)
+
+diff --git a/fuzzing/fuzz_key.c b/fuzzing/fuzz_key.c
+index 77cb684..7d00443 100644
+--- a/fuzzing/fuzz_key.c
++++ b/fuzzing/fuzz_key.c
+@@ -26,11 +26,20 @@ test_parse (const gchar *data,
+ GKeyFileFlags flags)
+ {
+ GKeyFile *key = NULL;
++ char *comment = NULL;
++ char **list = NULL;
+
+ key = g_key_file_new ();
+ g_key_file_load_from_data (key, (const gchar*) data, size, G_KEY_FILE_NONE,
+ NULL);
+
++ /* Also try some additional parsing and see if it crashes */
++ comment = g_key_file_get_comment (key, "group", "key", NULL);
++ g_free (comment);
++
++ list = g_key_file_get_locale_string_list (key, "group", "key", "de", NULL, NULL);
++ g_strfreev (list);
++
+ g_key_file_free (key);
+ }
+
+diff --git a/glib/gkeyfile.c b/glib/gkeyfile.c
+index d08a485..54d77a5 100644
+--- a/glib/gkeyfile.c
++++ b/glib/gkeyfile.c
+@@ -2421,7 +2421,7 @@ g_key_file_get_locale_string_list (GKeyFile *key_file,
+ }
+
+ len = strlen (value);
+- if (value[len - 1] == key_file->list_separator)
++ if (len > 0 && value[len - 1] == key_file->list_separator)
+ value[len - 1] = '\0';
+
+ list_separator[0] = key_file->list_separator;
+diff --git a/glib/tests/keyfile.c b/glib/tests/keyfile.c
+index bc125c1..289bd2b 100644
+--- a/glib/tests/keyfile.c
++++ b/glib/tests/keyfile.c
+@@ -850,6 +850,28 @@ test_locale_string_multiple_loads (void)
+ g_free (old_locale);
+ }
+
++static void
++test_locale_string_empty (void)
++{
++ GKeyFile *keyfile = NULL;
++ GError *local_error = NULL;
++ const char *data =
++ "[valid]\n"
++ "key1=\n";
++
++ g_test_summary ("Check that loading an empty translatable string works");
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3930");
++
++ keyfile = g_key_file_new ();
++
++ g_key_file_load_from_data (keyfile, data, -1, G_KEY_FILE_NONE, &local_error);
++ g_assert_no_error (local_error);
++
++ check_locale_string_list_value (keyfile, "valid", "key1", NULL, NULL);
++
++ g_key_file_free (keyfile);
++}
++
+ static void
+ test_lists (void)
+ {
+@@ -1939,6 +1961,7 @@ main (int argc, char *argv[])
+ g_test_add_func ("/keyfile/number", test_number);
+ g_test_add_func ("/keyfile/locale-string", test_locale_string);
+ g_test_add_func ("/keyfile/locale-string/multiple-loads", test_locale_string_multiple_loads);
++ g_test_add_func ("/keyfile/locale-string/empty", test_locale_string_empty);
+ g_test_add_func ("/keyfile/lists", test_lists);
+ g_test_add_func ("/keyfile/lists-set-get", test_lists_set_get);
+ g_test_add_func ("/keyfile/group-remove", test_group_remove);
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 5486969abb..9f1cdbe544 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -51,6 +51,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58011.patch \
file://CVE-2026-58012.patch \
file://CVE-2026-58013.patch \
+ file://CVE-2026-58014.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 preceding siblings ...)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 5/6] glib-2.0: fix CVE-2026-58014 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-15 17:23 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-25 6:42 ` [scarthgap][PATCH " Siddharth Doshi
2026-07-19 22:56 ` [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Yoann Congal
5 siblings, 1 reply; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-15 17:23 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.88.1 backport for
CVE-2026-58015. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58015
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
.../glib-2.0/glib-2.0/CVE-2026-58015.patch | 95 +++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 96 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015.patch
new file mode 100644
index 0000000000..4af0c1aa29
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015.patch
@@ -0,0 +1,95 @@
+From 90119b27e94759d942d2e8eb55b13d17237b423d Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:47:30 +0100
+Subject: [PATCH] gdbusauthmechanismsha1: Validate cookie context
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Without validation, the server could send a malicious context which
+contains path traversal characters, allowing it to exfiltrate a SHA-1
+hashed copy of arbitrary data from the client’s file system.
+
+To exploit this successfully would require the client to choose to
+connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
+authentication mechanism in preference to all the other mechanisms. This
+is vanishingly unlikely.
+
+Fixes: #3931
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a]
+
+Backport Changes:
+- Added <stdint.h> include because the target branch does not otherwise
+ expose uint8_t used by the upstream validation code during native builds.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 37 +++++++++++++++++++++++++++++++++++++
+ 1 file changed, 37 insertions(+)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index c8aa089..7f348d8 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -22,6 +22,7 @@
+
+ #include "config.h"
+
++#include <stdint.h>
+ #include <string.h>
+ #include <fcntl.h>
+ #include <errno.h>
+@@ -1198,6 +1198,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+ return initial_response;
+ }
+
++/* Context names must be valid ASCII, nonzero length, and may not contain the
++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
++ * carriage return ("\r"), tab ("\t"), or period (".").
++ *
++ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */
++static gboolean
++validate_cookie_context (const char *cookie_context)
++{
++ size_t i = 0;
++
++ g_return_val_if_fail (cookie_context != NULL, FALSE);
++
++ for (i = 0; cookie_context[i] != '\0'; i++)
++ {
++ if ((uint8_t) cookie_context[i] >= 128 ||
++ cookie_context[i] == '/' ||
++ cookie_context[i] == '\\' ||
++ cookie_context[i] == ' ' ||
++ cookie_context[i] == '\n' ||
++ cookie_context[i] == '\r' ||
++ cookie_context[i] == '\t' ||
++ cookie_context[i] == '.')
++ return FALSE;
++ }
++
++ return (i > 0);
++}
++
+ static void
+ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ const gchar *data,
+@@ -1232,6 +1260,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ }
+
+ cookie_context = tokens[0];
++ if (!validate_cookie_context (tokens[0]))
++ {
++ g_free (m->priv->reject_reason);
++ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]);
++ m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
++ goto out;
++ }
++
+ cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+ if (*endp != '\0')
+ {
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 9f1cdbe544..d3934fbee5 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -52,6 +52,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58012.patch \
file://CVE-2026-58013.patch \
file://CVE-2026-58014.patch \
+ file://CVE-2026-58015.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
--
2.35.6
^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (4 preceding siblings ...)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-19 22:56 ` Yoann Congal
2026-07-20 5:50 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
5 siblings, 1 reply; 9+ messages in thread
From: Yoann Congal @ 2026-07-19 22:56 UTC (permalink / raw)
To: deeratho, openembedded-core
On Wed Jul 15, 2026 at 7:23 PM CEST, Deepak Rathore via lists.openembedded.org wrote:
> From: Deepak Rathore <deeratho@cisco.com>
>
> This patch applies the upstream 2.86.5 backport for
> CVE-2026-58010. The upstream fix commit is referenced in [1],
> and the public CVE advisory is referenced in [2].
>
> [1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010
>
> Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Hello,
FYI, I will merge [wrynose][PATCH] glib-2.0: upgrade 2.88.0 -> 2.88.2
https://lore.kernel.org/openembedded-core/20260719221822.3458326-1-peter.marko@siemens.com/T/#u
first, then this series.
Thanks!
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010
2026-07-19 22:56 ` [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Yoann Congal
@ 2026-07-20 5:50 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 9+ messages in thread
From: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-07-20 5:50 UTC (permalink / raw)
To: openembedded-core@lists.openembedded.org, yoann.congal@smile.fr
[-- Attachment #1: Type: text/plain, Size: 1334 bytes --]
Thanks, Yoann, for the update.
Regards,
Deepak
________________________________
From: openembedded-core@lists.openembedded.org <openembedded-core@lists.openembedded.org> on behalf of Yoann Congal via lists.openembedded.org <yoann.congal=smile.fr@lists.openembedded.org>
Sent: Monday, July 20, 2026 4:26 AM
To: Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco) <deeratho@cisco.com>; openembedded-core@lists.openembedded.org <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010
On Wed Jul 15, 2026 at 7:23 PM CEST, Deepak Rathore via lists.openembedded.org wrote:
> From: Deepak Rathore <deeratho@cisco.com>
>
> This patch applies the upstream 2.86.5 backport for
> CVE-2026-58010. The upstream fix commit is referenced in [1],
> and the public CVE advisory is referenced in [2].
>
> [1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010
>
> Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Hello,
FYI, I will merge [wrynose][PATCH] glib-2.0: upgrade 2.88.0 -> 2.88.2
https://lore.kernel.org/openembedded-core/20260719221822.3458326-1-peter.marko@siemens.com/T/#u
first, then this series.
Thanks!
--
Yoann Congal
Smile ECS
[-- Attachment #2: Type: text/html, Size: 3059 bytes --]
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-07-25 6:42 ` Siddharth Doshi
0 siblings, 0 replies; 9+ messages in thread
From: Siddharth Doshi @ 2026-07-25 6:42 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 187 bytes --]
Hello,
there are 2 commits which are required to completely fix this CVE. (Main fix and helper fix of same glib bug)
Could you please check it and send a v2 ?
Regards,
Siddharth
[-- Attachment #2: Type: text/html, Size: 228 bytes --]
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-07-25 6:42 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-15 17:23 [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 2/6] glib-2.0: fix CVE-2026-58011 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 3/6] glib-2.0: fix CVE-2026-58012 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 4/6] glib-2.0: fix CVE-2026-58013 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 5/6] glib-2.0: fix CVE-2026-58014 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-15 17:23 ` [OE-core][scarthgap][PATCH 6/6] glib-2.0: fix CVE-2026-58015 Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-07-25 6:42 ` [scarthgap][PATCH " Siddharth Doshi
2026-07-19 22:56 ` [OE-core][scarthgap][PATCH 1/6] glib-2.0: fix CVE-2026-58010 Yoann Congal
2026-07-20 5:50 ` Deepak Rathore -X (deeratho - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox