* [OE-core][scarthgap][PATCH 2/5] apr-util: Fix CVE-2026-32327
2026-08-26 5:36 [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-26 5:36 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 3/5] apr-util: Mark CVE-2026-34191 not applicable Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:36 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport the upstream test compatibility prerequisite [1], which is
required by the regression tests included with the XML nesting-depth
fix [2]. The fix addresses CVE-2026-32327 as described by the advisory
[3].
[1] https://github.com/apache/apr-util/commit/dba5d434dba0547478f411d6fa068766455446ce
[2] https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-32327
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../apr-util/CVE-2026-32327-dependent.patch | 34 +
.../apr/apr-util/CVE-2026-32327.patch | 2162 +++++++++++++++++
meta/recipes-support/apr/apr-util_1.6.3.bb | 2 +
3 files changed, 2198 insertions(+)
create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch
create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-32327.patch
diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch b/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch
new file mode 100644
index 0000000000..c3c570f407
--- /dev/null
+++ b/meta/recipes-support/apr/apr-util/CVE-2026-32327-dependent.patch
@@ -0,0 +1,34 @@
+From dba5d434dba0547478f411d6fa068766455446ce Mon Sep 17 00:00:00 2001
+From: Joe Orton <jorton@apache.org>
+Date: Tue, 19 Dec 2023 11:20:33 +0000
+Subject: [PATCH] Merge r1914772 from 1.7.x:
+
+* test/testutil.h: Define APR_ASSERT_SUCCESS for compatibility
+ with apr trunk.
+
+
+
+git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1914774 13f79535-47bb-0310-9956-ffa450edef68
+
+CVE: CVE-2026-32327
+Upstream-Status: Backport [https://github.com/apache/apr-util/commit/dba5d434dba0547478f411d6fa068766455446ce]
+
+(cherry picked from commit dba5d434dba0547478f411d6fa068766455446ce)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ test/testutil.h | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/test/testutil.h b/test/testutil.h
+index eaa7e759..4c5e30b8 100644
+--- a/test/testutil.h
++++ b/test/testutil.h
+@@ -40,6 +40,8 @@ extern apr_pool_t *p;
+ /* Assert that RV is an APR_SUCCESS value; else fail giving strerror
+ * for RV and CONTEXT message. */
+ void apr_assert_success(abts_case* tc, const char *context, apr_status_t rv);
++#define APR_ASSERT_SUCCESS(tc, ctxt, rv) \
++ apr_assert_success(tc, ctxt, rv)
+
+ void apr_assert_failure(abts_case* tc, const char *context,
+ apr_status_t rv, int lineno);
diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch b/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch
new file mode 100644
index 0000000000..a0c4004709
--- /dev/null
+++ b/meta/recipes-support/apr/apr-util/CVE-2026-32327.patch
@@ -0,0 +1,2162 @@
+From 414e12e427c89f135d8ee66ab1203feffd3e2bd8 Mon Sep 17 00:00:00 2001
+From: Joe Orton <jorton@apache.org>
+Date: Mon, 3 Aug 2026 12:34:32 +0000
+Subject: [PATCH] Merge r1936807 from 1.7.x:
+
+limit XML processing depth
+
+Submitted By: jorton
+Reviewed By: jorton, jfclere, ivan
+
+
+git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936815 13f79535-47bb-0310-9956-ffa450edef68
+
+CVE: CVE-2026-32327
+Upstream-Status: Backport [https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8]
+
+(cherry picked from commit 414e12e427c89f135d8ee66ab1203feffd3e2bd8)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ CMakeLists.txt | 3 +
+ test/data/nesting.xml | 2001 +++++++++++++++++++++++++++++++++++++++++
+ test/testxml.c | 32 +
+ xml/apr_xml.c | 21 +-
+ 4 files changed, 2056 insertions(+), 1 deletion(-)
+ create mode 100644 test/data/nesting.xml
+
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index fcbfc582..65b9194d 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -288,6 +288,9 @@ IF(APR_BUILD_TESTAPR)
+ EXECUTE_PROCESS(COMMAND ${CMAKE_COMMAND} -E copy_if_different
+ ${PROJECT_SOURCE_DIR}/test/data/billion-laughs.xml
+ ${PROJECT_BINARY_DIR}/data/billion-laughs.xml)
++ EXECUTE_PROCESS(COMMAND ${CMAKE_COMMAND} -E copy_if_different
++ ${PROJECT_SOURCE_DIR}/test/data/nesting.xml
++ ${PROJECT_BINARY_DIR}/data/nesting.xml)
+
+ IF(TEST_STATIC_LIBS)
+ SET(whichapr aprutil-1)
+diff --git a/test/data/nesting.xml b/test/data/nesting.xml
+new file mode 100644
+index 00000000..a4efda86
+--- /dev/null
++++ b/test/data/nesting.xml
+@@ -0,0 +1,2001 @@
++<?xml version="1.0"?>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++<n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
++</n>
+diff --git a/test/testxml.c b/test/testxml.c
+index eed10672..5284f888 100644
+--- a/test/testxml.c
++++ b/test/testxml.c
+@@ -20,6 +20,10 @@
+ #include "abts.h"
+ #include "testutil.h"
+
++#ifndef APR_XML_MAX_DEPTH
++#define APR_XML_MAX_DEPTH 256
++#endif
++
+ static apr_status_t create_dummy_file_error(abts_case *tc, apr_pool_t *p,
+ apr_file_t **fd)
+ {
+@@ -166,6 +170,33 @@ static void test_billion_laughs(abts_case *tc, void *data)
+ apr_file_close(fd);
+ }
+
++static void test_nesting_limit(abts_case *tc, void *data)
++{
++ apr_file_t *fd;
++ apr_xml_parser *parser = NULL;
++ apr_xml_doc *doc;
++ apr_status_t rv;
++ char errbuf[256], *err;
++
++ rv = apr_file_open(&fd, "data/nesting.xml",
++ APR_FOPEN_READ, 0, p);
++ APR_ASSERT_SUCCESS(tc, "open nesting.xml", rv);
++
++ rv = apr_xml_parse_file(p, &parser, &doc, fd, 2000);
++ ABTS_TRUE(tc, rv != APR_SUCCESS);
++
++ if (parser) {
++ err = apr_xml_parser_geterror(parser, errbuf, sizeof errbuf);
++ ABTS_STR_EQUAL(tc,
++ "The maximum element nesting limit "
++ "(" APR_STRINGIFY(APR_XML_MAX_DEPTH) ")"
++ " was exceeded.",
++ err);
++ }
++
++ apr_file_close(fd);
++}
++
+ static void test_CVE_2009_3720_alpha(abts_case *tc, void *data)
+ {
+ apr_xml_parser *xp;
+@@ -198,6 +229,7 @@ abts_suite *testxml(abts_suite *suite)
+
+ abts_run_test(suite, test_xml_parser, NULL);
+ abts_run_test(suite, test_billion_laughs, NULL);
++ abts_run_test(suite, test_nesting_limit, NULL);
+ abts_run_test(suite, test_CVE_2009_3720_alpha, NULL);
+ abts_run_test(suite, test_CVE_2009_3720_beta, NULL);
+
+diff --git a/xml/apr_xml.c b/xml/apr_xml.c
+index 2685a9a5..a2535f98 100644
+--- a/xml/apr_xml.c
++++ b/xml/apr_xml.c
+@@ -61,12 +61,19 @@ struct apr_xml_parser {
+ int error; /* an error has occurred */
+ #define APR_XML_ERROR_EXPAT 1
+ #define APR_XML_ERROR_PARSE_DONE 2
+-/* also: public APR_XML_NS_ERROR_* values (if any) */
++#define APR_XML_ERROR_DEPTH_LIMIT 3
+
++/* also: public APR_XML_NS_ERROR_* values (if any) */
++ /** depth of element tree. */
++ unsigned int depth;
+ XML_Parser xp; /* the actual (Expat) XML parser */
+ enum XML_Error xp_err; /* stored Expat error code */
+ };
+
++#ifndef APR_XML_MAX_DEPTH
++#define APR_XML_MAX_DEPTH 256
++#endif
++
+ /* struct for scoping namespace declarations */
+ typedef struct apr_xml_ns_scope {
+ const char *prefix; /* prefix used for this ns */
+@@ -154,6 +161,11 @@ static void start_handler(void *userdata, const char *name, const char **attrs)
+ if (parser->error)
+ return;
+
++ if (++parser->depth > APR_XML_MAX_DEPTH) {
++ parser->error = APR_XML_ERROR_DEPTH_LIMIT;
++ return;
++ }
++
+ elem = apr_pcalloc(parser->p, sizeof(*elem));
+
+ /* prep the element */
+@@ -327,6 +339,8 @@ static void end_handler(void *userdata, const char *name)
+ if (parser->error)
+ return;
+
++ parser->depth--;
++
+ /* pop up one level */
+ parser->cur_elem = parser->cur_elem->parent;
+ }
+@@ -499,6 +513,11 @@ APU_DECLARE(char *) apr_xml_parser_geterror(apr_xml_parser *parser,
+ XML_ErrorString(parser->xp_err), parser->xp_err);
+ return errbuf;
+
++ case APR_XML_ERROR_DEPTH_LIMIT:
++ msg = "The maximum element nesting limit ("
++ APR_STRINGIFY(APR_XML_MAX_DEPTH) ") was exceeded.";
++ break;
++
+ case APR_XML_ERROR_PARSE_DONE:
+ msg = "The parser is not active.";
+ break;
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb
index 06f13e91ca..e3d6a23fcb 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.3.bb
@@ -15,6 +15,8 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \
file://0001-test_transformation-Check-if-transform-is-supported-.patch \
file://CVE-2025-49506_p1.patch \
file://CVE-2025-49506_p2.patch \
+ file://CVE-2026-32327-dependent.patch \
+ file://CVE-2026-32327.patch \
file://run-ptest \
"
--
2.35.6
^ permalink raw reply related [flat|nested] 6+ messages in thread* [OE-core][scarthgap][PATCH 3/5] apr-util: Mark CVE-2026-34191 not applicable
2026-08-26 5:36 [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 2/5] apr-util: Fix CVE-2026-32327 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-26 5:36 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 4/5] apr-util: Fix CVE-2026-34501 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:36 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
CVE-2026-34191 affects only the apr_dbd_oracle provider [1].
The apr-util recipe does not enable --with-oracle, so configure keeps
apu_have_oracle=0 [2]. Hence mark the CVE not applicable to this build.
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-34191
[2] https://github.com/apache/apr-util/blob/1.6.3/build/dbd.m4
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
meta/recipes-support/apr/apr-util_1.6.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb
index e3d6a23fcb..3051a08eaf 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.3.bb
@@ -102,3 +102,5 @@ do_install_ptest() {
# Add CVE_PRODUCT to match the NVD CPE product name
CVE_PRODUCT = "apache:apr-util apache:portable_runtime_utility"
+
+CVE_STATUS[CVE-2026-34191] = "not-applicable-config: apr_dbd_oracle is not built because --with-oracle is not enabled"
--
2.35.6
^ permalink raw reply related [flat|nested] 6+ messages in thread* [OE-core][scarthgap][PATCH 4/5] apr-util: Fix CVE-2026-34501
2026-08-26 5:36 [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 2/5] apr-util: Fix CVE-2026-32327 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 3/5] apr-util: Mark CVE-2026-34191 not applicable Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-26 5:36 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 5/5] apr-util: Fix CVE-2026-34502 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-09 18:43 ` [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Yoann Congal
4 siblings, 0 replies; 6+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:36 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport the upstream Redis response-length and error-checking fix [1]
to address CVE-2026-34501 [2].
[1] https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-34501
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../apr/apr-util/CVE-2026-34501.patch | 128 ++++++++++++++++++
meta/recipes-support/apr/apr-util_1.6.3.bb | 1 +
2 files changed, 129 insertions(+)
create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34501.patch
diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch
new file mode 100644
index 0000000000..0056e62171
--- /dev/null
+++ b/meta/recipes-support/apr/apr-util/CVE-2026-34501.patch
@@ -0,0 +1,128 @@
+From e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2 Mon Sep 17 00:00:00 2001
+From: Eric Covener <covener@apache.org>
+Date: Mon, 3 Aug 2026 12:28:37 +0000
+Subject: [PATCH] Merge r1936809 from aprutil 1.7.x:
+
+Merge r1936808 from apr trunk:
+
+apr_redis error checking
+
+Submitted By: jfclere
+Reviewed By: jfclere, jorton, covener
+
+
+
+
+
+git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936810 13f79535-47bb-0310-9956-ffa450edef68
+
+CVE: CVE-2026-34501
+Upstream-Status: Backport [https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2]
+
+(cherry picked from commit e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ redis/apr_redis.c | 54 +++++++++++++++++++++++++++++++++++++----------
+ 1 file changed, 43 insertions(+), 11 deletions(-)
+
+diff --git a/redis/apr_redis.c b/redis/apr_redis.c
+index 8d01fdd6..e7fe2071 100644
+--- a/redis/apr_redis.c
++++ b/redis/apr_redis.c
+@@ -853,26 +853,42 @@ APU_DECLARE(apr_status_t) apr_redis_setex(apr_redis_t *rc,
+ return rv;
+ }
+
++/* Redis upstream default is 512Mb. This code will try to read the entire
++ * response into a brigade, and then copy that into a pool, so impose
++ * some reasonable limit since RAM consumption will be double this.
++ * https://redis.io/docs/latest/develop/reference/protocol-spec/#bulk-strings
++ */
++#ifndef APR_REDIS_MAX_BULK_LEN
++#define APR_REDIS_MAX_BULK_LEN (64 * 1024 * 1024)
++#endif
++
+ static apr_status_t grab_bulk_resp(apr_redis_server_t *rs, apr_redis_t *rc,
+ apr_redis_conn_t *conn, apr_pool_t *p,
+ char **baton, apr_size_t *new_length)
+ {
+- char *length;
++ /* conn->buffer contains "$<length>\r\n" */
++ char *length = conn->buffer + 1;
+ char *last;
+ apr_status_t rv;
+ apr_size_t len = 0;
++ long val;
++
+ *new_length = 0;
++ *baton = NULL;
+
+- length = apr_strtok(conn->buffer + 1, " ", &last);
+- if (length) {
+- len = strtol(length, (char **) NULL, 10);
++ errno = 0;
++ last = NULL;
++ val = strtol(length, &last, 10);
++ if (errno || last == NULL || last == length || *last != '\r'
++ || val < 0 || val > APR_REDIS_MAX_BULK_LEN) {
++ rs_bad_conn(rs, conn);
++ if (rc)
++ apr_redis_disable_server(rc, rs);
++ return val > APR_REDIS_MAX_BULK_LEN ? APR_ENOSPC : APR_EGENERAL;
+ }
++ len = (apr_size_t)val;
+
+- if (len == 0) {
+- *new_length = 0;
+- *baton = NULL;
+- }
+- else {
++ if (len) {
+ apr_bucket_brigade *bbb;
+ apr_bucket *e;
+
+@@ -907,6 +923,11 @@ static apr_status_t grab_bulk_resp(apr_redis_server_t *rs, apr_redis_t *rc,
+
+ conn->bb = bbb;
+
++ if (len < 2) {
++ *baton = NULL;
++ *new_length = 0;
++ return APR_EGENERAL;
++ }
+ *new_length = len - 2;
+ (*baton)[*new_length] = '\0';
+ }
+@@ -992,6 +1013,10 @@ APU_DECLARE(apr_status_t) apr_redis_getp(apr_redis_t *rc,
+ }
+ else if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) {
+ rv = grab_bulk_resp(rs, rc, conn, p, baton, new_length);
++ if (rv != APR_SUCCESS) {
++ /* grab_bulk_resp already called rs_bad_conn; do not also release */
++ return rv;
++ }
+ }
+ else {
+ rv = APR_EGENERAL;
+@@ -1172,12 +1197,19 @@ apr_redis_info(apr_redis_server_t *rs, apr_pool_t *p, char **baton)
+ return rv;
+ }
+
+- if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) {
++ if (strncmp(RS_NOT_FOUND_GET, conn->buffer, RS_NOT_FOUND_GET_LEN) == 0) {
++ rv = APR_NOTFOUND;
++ }
++ else if (strncmp(RS_TYPE_STRING, conn->buffer, RS_TYPE_STRING_LEN) == 0) {
+ apr_size_t nl;
+ rv = grab_bulk_resp(rs, NULL, conn, p, baton, &nl);
++ if (rv != APR_SUCCESS) {
++ /* grab_bulk_resp already called rs_bad_conn; do not also release */
++ return rv;
++ }
+ } else {
+ rs_bad_conn(rs, conn);
+- rv = APR_EGENERAL;
++ return APR_EGENERAL;
+ }
+
+ rs_release_conn(rs, conn);
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb
index 3051a08eaf..341975fbca 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.3.bb
@@ -17,6 +17,7 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \
file://CVE-2025-49506_p2.patch \
file://CVE-2026-32327-dependent.patch \
file://CVE-2026-32327.patch \
+ file://CVE-2026-34501.patch \
file://run-ptest \
"
--
2.35.6
^ permalink raw reply related [flat|nested] 6+ messages in thread* [OE-core][scarthgap][PATCH 5/5] apr-util: Fix CVE-2026-34502
2026-08-26 5:36 [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (2 preceding siblings ...)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 4/5] apr-util: Fix CVE-2026-34501 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-26 5:36 ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-09 18:43 ` [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Yoann Congal
4 siblings, 0 replies; 6+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:36 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external, Hetvi Thakar
From: Hetvi Thakar <hthakar@cisco.com>
Backport the upstream memcache validation fix [1] and its follow-up
parsing correction [2] to address CVE-2026-34502 [3].
[1] https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872
[2] https://github.com/apache/apr-util/commit/997c02ce5b9db44083c580e3e47095f5ac4524ae
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-34502
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../apr/apr-util/CVE-2026-34502_p1.patch | 106 ++++++++++++++++++
.../apr/apr-util/CVE-2026-34502_p2.patch | 38 +++++++
meta/recipes-support/apr/apr-util_1.6.3.bb | 2 +
3 files changed, 146 insertions(+)
create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch
create mode 100644 meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch
diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch
new file mode 100644
index 0000000000..d4c6cb39b4
--- /dev/null
+++ b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p1.patch
@@ -0,0 +1,106 @@
+From f1c98dd0847c43375daf3789c936685adbc6d872 Mon Sep 17 00:00:00 2001
+From: Eric Covener <covener@apache.org>
+Date: Mon, 3 Aug 2026 12:33:18 +0000
+Subject: [PATCH] Merge r1936812 from aprutil 1.7.x:
+
+Merge r1936811 from apr trunk:
+
+apr_memcache: error checking
+
+Reviewed By: covener, jorton, jfclere
+
+
+
+
+
+git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936813 13f79535-47bb-0310-9956-ffa450edef68
+
+CVE: CVE-2026-34502
+Upstream-Status: Backport [https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872]
+
+(cherry picked from commit f1c98dd0847c43375daf3789c936685adbc6d872)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ memcache/apr_memcache.c | 31 ++++++++++++++++++++++++++++---
+ 1 file changed, 28 insertions(+), 3 deletions(-)
+
+diff --git a/memcache/apr_memcache.c b/memcache/apr_memcache.c
+index 2c7bd1de..137be778 100644
+--- a/memcache/apr_memcache.c
++++ b/memcache/apr_memcache.c
+@@ -595,6 +595,11 @@ static apr_status_t get_server_line(apr_memcache_conn_t *conn)
+ conn->blen = bsize;
+ conn->buffer[bsize] = '\0';
+
++ /* Validate CRLF line termination to prevent integer underflow attacks */
++ if (bsize < 2 || conn->buffer[bsize-2] != '\r' || conn->buffer[bsize-1] != '\n') {
++ return APR_EGENERAL;
++ }
++
+ return apr_brigade_cleanup(conn->tb);
+ }
+
+@@ -1087,9 +1092,14 @@ apr_memcache_version(apr_memcache_server_t *ms,
+ }
+
+ if (strncmp(MS_VERSION, conn->buffer, MS_VERSION_LEN) == 0) {
+- *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1,
+- conn->blen - MS_VERSION_LEN - 2);
+- rv = APR_SUCCESS;
++ if (conn->blen < MS_VERSION_LEN + 2) {
++ rv = APR_EGENERAL;
++ }
++ else {
++ *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1,
++ conn->blen - MS_VERSION_LEN - 2);
++ rv = APR_SUCCESS;
++ }
+ }
+ else {
+ rv = APR_EGENERAL;
+@@ -1555,23 +1565,35 @@ apr_memcache_multgetp(apr_memcache_t *mc,
+ static const char *stat_read_string(apr_pool_t *p, char *buf, apr_size_t len)
+ {
+ /* remove trailing \r\n and null char */
++ if (len < 2) {
++ return apr_pstrdup(p, "");
++ }
+ return apr_pstrmemdup(p, buf, len-2);
+ }
+
+ static apr_uint32_t stat_read_uint32(apr_pool_t *p, char *buf, apr_size_t len)
+ {
++ if (len < 2) {
++ return 0;
++ }
+ buf[len-2] = '\0';
+ return atoi(buf);
+ }
+
+ static apr_uint64_t stat_read_uint64(apr_pool_t *p, char *buf, apr_size_t len)
+ {
++ if (len < 2) {
++ return 0;
++ }
+ buf[len-2] = '\0';
+ return apr_atoi64(buf);
+ }
+
+ static apr_time_t stat_read_time(apr_pool_t *p, char *buf, apr_size_t len)
+ {
++ if (len < 2) {
++ return 0;
++ }
+ buf[len-2] = '\0';
+ return apr_time_from_sec(atoi(buf));
+ }
+@@ -1583,6 +1605,9 @@ static apr_time_t stat_read_rtime(apr_pool_t *p, char *buf, apr_size_t len)
+ char *usecs;
+ const char *sep = ":.";
+
++ if (len < 2) {
++ return apr_time_make(0, 0);
++ }
+ buf[len-2] = '\0';
+
+ secs = apr_strtok(buf, sep, &tok);
diff --git a/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch
new file mode 100644
index 0000000000..844ad8109d
--- /dev/null
+++ b/meta/recipes-support/apr/apr-util/CVE-2026-34502_p2.patch
@@ -0,0 +1,38 @@
+From 997c02ce5b9db44083c580e3e47095f5ac4524ae Mon Sep 17 00:00:00 2001
+From: Eric Covener <covener@apache.org>
+Date: Fri, 7 Aug 2026 14:23:29 +0000
+Subject: [PATCH] fix memcache version parsing
+
+partial port of 1936966 from trunk
+
+
+git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936975 13f79535-47bb-0310-9956-ffa450edef68
+
+CVE: CVE-2026-34502
+Upstream-Status: Backport [https://github.com/apache/apr-util/commit/997c02ce5b9db44083c580e3e47095f5ac4524ae]
+
+(cherry picked from commit 997c02ce5b9db44083c580e3e47095f5ac4524ae)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ memcache/apr_memcache.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/memcache/apr_memcache.c b/memcache/apr_memcache.c
+index 137be778..74146712 100644
+--- a/memcache/apr_memcache.c
++++ b/memcache/apr_memcache.c
+@@ -1092,12 +1092,12 @@ apr_memcache_version(apr_memcache_server_t *ms,
+ }
+
+ if (strncmp(MS_VERSION, conn->buffer, MS_VERSION_LEN) == 0) {
+- if (conn->blen < MS_VERSION_LEN + 2) {
++ if (conn->blen < MS_VERSION_LEN + 4) {
+ rv = APR_EGENERAL;
+ }
+ else {
+ *baton = apr_pstrmemdup(p, conn->buffer+MS_VERSION_LEN+1,
+- conn->blen - MS_VERSION_LEN - 2);
++ conn->blen - MS_VERSION_LEN - 3);
+ rv = APR_SUCCESS;
+ }
+ }
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.3.bb
index 341975fbca..9da2da0816 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.3.bb
@@ -18,6 +18,8 @@ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \
file://CVE-2026-32327-dependent.patch \
file://CVE-2026-32327.patch \
file://CVE-2026-34501.patch \
+ file://CVE-2026-34502_p1.patch \
+ file://CVE-2026-34502_p2.patch \
file://run-ptest \
"
--
2.35.6
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506
2026-08-26 5:36 [OE-core][scarthgap][PATCH 1/5] apr-util: Fix CVE-2025-49506 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
` (3 preceding siblings ...)
2026-08-26 5:36 ` [OE-core][scarthgap][PATCH 5/5] apr-util: Fix CVE-2026-34502 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-09 18:43 ` Yoann Congal
4 siblings, 0 replies; 6+ messages in thread
From: Yoann Congal @ 2026-09-09 18:43 UTC (permalink / raw)
To: hthakar, openembedded-core; +Cc: xe-linux-external
On Wed Aug 26, 2026 at 7:36 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Backport the upstream timing-safe comparison fix [1] and its XLC
> compatibility follow-up [2]. APR-util 1.6.4 identifies this issue as
> fixed [3].
>
> [1] https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e
> [2] https://github.com/apache/apr-util/commit/e35eee2ea9e1f77bdec26c3bfdb5caca457acd66
> [3] https://nvd.nist.gov/vuln/detail/CVE-2025-49506
>
> Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> ---
> .../apr/apr-util/CVE-2025-49506_p1.patch | 310 ++++++++++++++++++
> .../apr/apr-util/CVE-2025-49506_p2.patch | 42 +++
> meta/recipes-support/apr/apr-util_1.6.3.bb | 2 +
> 3 files changed, 354 insertions(+)
> create mode 100644 meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch
> create mode 100644 meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch
>
> diff --git a/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch
> new file mode 100644
> index 0000000000..0ab5cf0648
> --- /dev/null
> +++ b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p1.patch
> @@ -0,0 +1,310 @@
> +From f77a20761cb15686f8d4de5b5eafc534ae24b19e Mon Sep 17 00:00:00 2001
> +From: Eric Covener <covener@apache.org>
> +Date: Mon, 3 Aug 2026 12:10:13 +0000
> +Subject: [PATCH] Merge r1936804 from aprutil 1.7.x:
> +
> +use timing safe comparison
> +
> +Submitted By: ylavic
> +Reviewed By: ylavic, rpluem, covener
> +
> +
> +
> +
> +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936805 13f79535-47bb-0310-9956-ffa450edef68
> +
> +CVE: CVE-2025-49506
> +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e]
> +
> +(cherry picked from commit f77a20761cb15686f8d4de5b5eafc534ae24b19e)
> +Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> +---
> + crypto/apr_crypto.c | 60 +++++++++++++++++---
> + crypto/apr_passwd.c | 135 ++++++++++++++++++++++++++++++++++++++++----
> + 2 files changed, 176 insertions(+), 19 deletions(-)
> +
> +diff --git a/crypto/apr_crypto.c b/crypto/apr_crypto.c
> +index 9ba190ef..ca3f0887 100644
> +--- a/crypto/apr_crypto.c
> ++++ b/crypto/apr_crypto.c
> +@@ -21,6 +21,7 @@
> + #include "apu.h"
> + #include "apr_pools.h"
> + #include "apr_dso.h"
> ++#include "apr_version.h"
> + #include "apr_strings.h"
> + #include "apr_hash.h"
> + #include "apr_thread_mutex.h"
> +@@ -173,19 +174,64 @@ APU_DECLARE(apr_status_t) apr_crypto_memzero(void *buffer, apr_size_t size)
> + return APR_SUCCESS;
> + }
> +
> ++/* Borrow this from APR-1.8 if not available */
> ++#if !APR_VERSION_AT_LEAST(1,8,0)
> ++
> ++/* A volatile variable which is always zero but allows to block the compiler
> ++ * from optimizing or eliding code using it. Volatile forces the compiler to
> ++ * emit a memory load for which no value can be assumed, so for instance an
> ++ * add/sub/xor/or with "optblocker" is a noop that will hide the result to
> ++ * the optimizer.
> ++ */
> ++static volatile const apr_uint32_t optblocker;
> ++
> ++/* Return whether x is not zero, with no branching controlled by x.
> ++ *
> ++ * Taken from the cryptoint library (public domain) by D. J. Bernstein,
> ++ * which provides timing attacks safe integer operations/primitives.
> ++ * Code:
> ++ * https://lib.mceliece.org/libmceliece-20250507/cryptoint/crypto_uint32.h
> ++ * Paper:
> ++ * https://cr.yp.to/papers/cryptoint-20250424.pdf
> ++ */
> ++#if __has_attribute(always_inline)
> ++__attribute__((always_inline))
> ++#endif
> ++static APR_INLINE int test_nonzero_timingsafe(apr_uint32_t x)
> ++{
> ++ x |= -x; /* sets the most significant bit unless x == 0 */
> ++
> ++ /* shift bit 31 (MSB) to bit 0 */
> ++ x >>= 32-6; /* keep 6 bits */
> ++ x += optblocker; /* lose the optimizer */
> ++ x >>= 5; /* keep the (original) MSB only */
> ++
> ++ /* x is now 0 or 1 */
> ++ return x & INT_MAX;
> ++}
> ++
> ++#endif /* !APR_VERSION_AT_LEAST(1,8,0) */
> ++
> + APU_DECLARE(int) apr_crypto_equals(const void *buf1, const void *buf2,
> + apr_size_t size)
> + {
> +- const unsigned char *p1 = buf1;
> +- const unsigned char *p2 = buf2;
> +- unsigned char diff = 0;
> +- apr_size_t i;
> ++#if APR_VERSION_AT_LEAST(1,8,0)
> ++ return apr_memeq_timingsafe(buf1, buf2, size);
> ++#else
> ++ apr_uint32_t diff = 0;
> ++ volatile apr_size_t count = size; /* prevent loop unrolling */
> ++ apr_size_t i = 0;
> +
> +- for (i = 0; i < size; ++i) {
> +- diff |= p1[i] ^ p2[i];
> ++ for (; i < count; ++i) {
> ++ const unsigned char c1 = ((volatile const unsigned char *)buf1)[i];
> ++ const unsigned char c2 = ((volatile const unsigned char *)buf2)[i];
> ++
> ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */
> + }
> +
> +- return 1 & ((diff - 1) >> 8);
> ++ /* (diff == 0) <=> (diff != 0) ^ 1 */
> ++ return test_nonzero_timingsafe(diff) ^ 1;
> ++#endif
> + }
> +
> + APU_DECLARE(apr_status_t) apr_crypto_get_driver(
> +diff --git a/crypto/apr_passwd.c b/crypto/apr_passwd.c
> +index c961de2b..74b5fc17 100644
> +--- a/crypto/apr_passwd.c
> ++++ b/crypto/apr_passwd.c
> +@@ -14,6 +14,7 @@
> + * limitations under the License.
> + */
> +
> ++#include "apr_version.h"
> + #include "apr_strings.h"
> + #include "apr_md5.h"
> + #include "apr_lib.h"
> +@@ -39,6 +40,111 @@
> +
> + static const char * const apr1_id = "$apr1$";
> +
> ++#if APR_VERSION_AT_LEAST(1,8,0)
> ++
> ++#define streq_timingsafe apr_streq_timingsafe
> ++#define strneq_timingsafe apr_strneq_timingsafe
> ++
> ++#else /* borrow code from APR-1.8 if not available */
> ++
> ++/* A volatile variable which is always zero but allows to block the compiler
> ++ * from optimizing or eliding code using it. Volatile forces the compiler to
> ++ * emit a memory load for which no value can be assumed, so for instance an
> ++ * add/sub/xor/or with "optblocker" is a noop that will hide the result to
> ++ * the optimizer.
> ++ */
> ++static volatile const apr_uint32_t optblocker;
> ++
> ++/* Return whether x is not zero, with no branching controlled by x.
> ++ *
> ++ * Taken from the cryptoint library (public domain) by D. J. Bernstein,
> ++ * which provides timing attacks safe integer operations/primitives.
> ++ * Code:
> ++ * https://lib.mceliece.org/libmceliece-20250507/cryptoint/crypto_uint32.h
> ++ * Paper:
> ++ * https://cr.yp.to/papers/cryptoint-20250424.pdf
> ++ */
> ++#if __has_attribute(always_inline)
> ++__attribute__((always_inline))
> ++#endif
> ++static APR_INLINE int test_nonzero_timingsafe(apr_uint32_t x)
> ++{
> ++ x |= -x; /* sets the most significant bit unless x == 0 */
> ++
> ++ /* shift bit 31 (MSB) to bit 0 */
> ++ x >>= 32-6; /* keep 6 bits */
> ++ x += optblocker; /* lose the optimizer */
> ++ x >>= 5; /* keep the (original) MSB only */
> ++
> ++ /* x is now 0 or 1 */
> ++ return x & INT_MAX;
> ++}
> ++
> ++static int streq_timingsafe(const char *sec1, const char *str2)
> ++{
> ++ apr_uint32_t diff = 0;
> ++ apr_size_t i1 = 0, i2 = 0;
> ++
> ++ for (;; ++i2) {
> ++ const unsigned char c1 = ((volatile const unsigned char *)sec1)[i1];
> ++ const unsigned char c2 = ((volatile const unsigned char *)str2)[i2];
> ++
> ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */
> ++
> ++ /* Not a shortest/longest match because an attacker would usually know
> ++ * one of the strings and could then determine the length of the other.
> ++ * So assume only sec1 and its length are secret and stop the loop at
> ++ * the end of str2. If sec1 is shorter than str2 the loop will continue
> ++ * by comparing the rest of str2 with the trailing NUL byte of sec1.
> ++ * In any case since the diff above is computed up to and including a
> ++ * NUL byte, only the same content and length will raise match.
> ++ */
> ++ if (!c2) {
> ++ break;
> ++ }
> ++
> ++ /* Don't go above sec1's NUL byte */
> ++ i1 += test_nonzero_timingsafe(c1);
> ++ }
> ++
> ++ /* (diff == 0) <=> (diff != 0) ^ 1 */
> ++ return test_nonzero_timingsafe(diff) ^ 1;
> ++}
> ++
> ++static int strneq_timingsafe(const char *sec1, const char *str2, apr_size_t n)
> ++{
> ++ apr_uint32_t diff = 0;
> ++ volatile apr_size_t count = n; /* prevent loop unrolling */
> ++ apr_size_t i1 = 0, i2 = 0;
> ++
> ++ for (; i2 < count; ++i2) {
> ++ const unsigned char c1 = ((volatile const unsigned char *)sec1)[i1];
> ++ const unsigned char c2 = ((volatile const unsigned char *)str2)[i2];
> ++
> ++ diff |= c1 ^ c2; /* sets diff to non-zero whenever c1 != c2 */
> ++
> ++ /* Not a shortest/longest match because an attacker would usually know
> ++ * one of the strings and could then determine the length of the other.
> ++ * So assume only sec1 and its length are secret and stop the loop at
> ++ * the end of str2. If sec1 is shorter than str2 the loop will continue
> ++ * by comparing the rest of str2 with the trailing NUL byte of sec1.
> ++ * In any case since the diff above is computed up to and including a
> ++ * NUL byte, only the same content and length will raise match.
> ++ */
> ++ if (!c2) {
> ++ break;
> ++ }
> ++
> ++ /* Don't go above sec1's NUL byte */
> ++ i1 += test_nonzero_timingsafe(c1);
> ++ }
> ++
> ++ /* (diff == 0) <=> (diff != 0) ^ 1 */
> ++ return test_nonzero_timingsafe(diff) ^ 1;
> ++}
> ++
> ++#endif /* APR_VERSION_AT_LEAST(1,8,0) */
> ++
> + #if !defined(WIN32) && !defined(BEOS) && !defined(NETWARE)
> + #if defined(APU_CRYPT_THREADSAFE) || !APR_HAS_THREADS || \
> + defined(CRYPT_R_CRYPTD) || defined(CRYPT_R_STRUCT_CRYPT_DATA)
> +@@ -86,28 +192,33 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd,
> + #if !CRYPT_MISSING
> + char *crypt_pw;
> + #endif
> +- if (hash[0] == '$'
> +- && hash[1] == '2'
> +- && (hash[2] == 'a' || hash[2] == 'y')
> +- && hash[3] == '$') {
> ++
> ++ if ((strneq_timingsafe(hash, "$2a$", 4) | /* test both */
> ++ strneq_timingsafe(hash, "$2y$", 4))) {
> ++ /*
> ++ * The hash was created using [apr_]bcrypt encoding.
> ++ */
> + if (_crypt_blowfish_rn(passwd, hash, sample, sizeof(sample)) == NULL)
> + return APR_FROM_OS_ERROR(errno);
> + }
> +- else if (!strncmp(hash, apr1_id, strlen(apr1_id))) {
> ++ else if (strneq_timingsafe(hash, apr1_id, strlen(apr1_id))) {
> + /*
> + * The hash was created using our custom algorithm.
> + */
> + apr_md5_encode(passwd, hash, sample, sizeof(sample));
> + }
> +- else if (!strncmp(hash, APR_SHA1PW_ID, APR_SHA1PW_IDLEN)) {
> +- apr_sha1_base64(passwd, (int)strlen(passwd), sample);
> ++ else if (strneq_timingsafe(hash, APR_SHA1PW_ID, APR_SHA1PW_IDLEN)) {
> ++ /*
> ++ * The hash is a (naked) SHA1.
> ++ */
> ++ apr_sha1_base64(passwd, (int)strlen(passwd), sample);
> + }
> + else {
> + /*
> + * It's not our algorithm, so feed it to crypt() if possible.
> + */
> + #if CRYPT_MISSING
> +- return (strcmp(passwd, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH;
> ++ return streq_timingsafe(hash, passwd) ? APR_SUCCESS : APR_EMISMATCH;
> + #elif defined(CRYPT_R_CRYPTD)
> + apr_status_t rv;
> + CRYPTD *buffer = malloc(sizeof(*buffer));
> +@@ -118,7 +229,7 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd,
> + if (!crypt_pw)
> + rv = APR_EMISMATCH;
> + else
> +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH;
> ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH;
> + free(buffer);
> + return rv;
> + #elif defined(CRYPT_R_STRUCT_CRYPT_DATA)
> +@@ -149,7 +260,7 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd,
> + if (!crypt_pw)
> + rv = APR_EMISMATCH;
> + else
> +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH;
> ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH;
> + free(buffer);
> + return rv;
> + #else
> +@@ -173,14 +284,14 @@ APU_DECLARE(apr_status_t) apr_password_validate(const char *passwd,
> + rv = APR_EMISMATCH;
> + }
> + else {
> +- rv = (strcmp(crypt_pw, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH;
> ++ rv = streq_timingsafe(hash, crypt_pw) ? APR_SUCCESS : APR_EMISMATCH;
> + }
> + crypt_mutex_unlock();
> + return rv;
> + }
> + #endif
> + }
> +- return (strcmp(sample, hash) == 0) ? APR_SUCCESS : APR_EMISMATCH;
> ++ return streq_timingsafe(hash, sample) ? APR_SUCCESS : APR_EMISMATCH;
> + }
> +
> + static const char * const bcrypt_id = "$2y$";
> diff --git a/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch
> new file mode 100644
> index 0000000000..b2acaf52d4
> --- /dev/null
> +++ b/meta/recipes-support/apr/apr-util/CVE-2025-49506_p2.patch
> @@ -0,0 +1,42 @@
> +From e35eee2ea9e1f77bdec26c3bfdb5caca457acd66 Mon Sep 17 00:00:00 2001
> +From: Eric Covener <covener@apache.org>
> +Date: Mon, 3 Aug 2026 13:45:25 +0000
> +Subject: [PATCH] Merge r1936827 from aprutil 1.7.x:
> +
> +hide __has_attribute on traditional xlc platforms
> +
> +The backport of 1917748 omitted this in apr.h on purpose,
> +but this is a new/narrow usage and not in a header
> +where it would taint anyones use of __has_attribute.
> +
> +
> +
> +
> +git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.6.x@1936828 13f79535-47bb-0310-9956-ffa450edef68
> +
> +CVE: CVE-2025-49506
> +Upstream-Status: Backport [https://github.com/apache/apr-util/commit/e35eee2ea9e1f77bdec26c3bfdb5caca457acd66]
> +
> +(cherry picked from commit e35eee2ea9e1f77bdec26c3bfdb5caca457acd66)
> +Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> +---
> + crypto/apr_passwd.c | 6 ++++++
> + 1 file changed, 6 insertions(+)
> +
> +diff --git a/crypto/apr_passwd.c b/crypto/apr_passwd.c
> +index 74b5fc17..9231d312 100644
> +--- a/crypto/apr_passwd.c
> ++++ b/crypto/apr_passwd.c
> +@@ -64,6 +64,12 @@ static volatile const apr_uint32_t optblocker;
> + * Paper:
> + * https://cr.yp.to/papers/cryptoint-20250424.pdf
> + */
> ++#if (defined(__xlc__) && !defined(__GNUC__))
> ++#ifndef __has_attribute
> ++#define __has_attribute(__x) 0
> ++#endif
> ++#endif
Hello,
What is "xlc"? Does this case happens for Yocto/OE-Core users?
I do not want to carry code that can't be reached.
Regards,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 6+ messages in thread