* [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched ankur.tyagi85
` (19 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-42798
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../lcms/lcms/CVE-2026-42798.patch | 38 +++++++++++++++++++
meta-oe/recipes-support/lcms/lcms_2.18.bb | 1 +
2 files changed, 39 insertions(+)
create mode 100644 meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch
diff --git a/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch
new file mode 100644
index 0000000000..fa3f497be6
--- /dev/null
+++ b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch
@@ -0,0 +1,38 @@
+From e05d3427b84028854177a417572e96543a40c3eb Mon Sep 17 00:00:00 2001
+From: Marti Maria <marti.maria@littlecms.com>
+Date: Thu, 19 Feb 2026 08:48:50 +0100
+Subject: [PATCH] Fix for ParseCube integer overflow in LUT allocation
+
+thanks to @zerojackyi for reporting
+
+(cherry picked from commit 6a686019825a89b715d16671f18d049523354176)
+
+CVE: CVE-2026-42798
+Upstream-Status: Backport [https://github.com/mm2/Little-CMS/commit/6a686019825a89b715d16671f18d049523354176]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/cmscgats.c | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/src/cmscgats.c b/src/cmscgats.c
+index 862eb91..7248d39 100644
+--- a/src/cmscgats.c
++++ b/src/cmscgats.c
+@@ -3180,7 +3180,16 @@ cmsBool ParseCube(cmsIT8* cube, cmsStage** Shaper, cmsStage** CLUT, char title[]
+
+ if (lut_size > 0) {
+
+- int nodes = lut_size * lut_size * lut_size;
++ int nodes;
++
++ /**
++ * Professional LUT‑generation tools (e.g., Nobe LutBake) list 65×65×65 as their highest supported size.
++ */
++ if (lut_size > 65)
++ return SynError(cube, "LUT size '%d' is over maximum of 65", lut_size);
++
++ nodes = lut_size * lut_size * lut_size;
++
+
+ cmsFloat32Number* lut_table = (cmsFloat32Number*) _cmsMalloc(cube->ContextID, nodes * 3 * sizeof(cmsFloat32Number));
+ if (lut_table == NULL) return FALSE;
diff --git a/meta-oe/recipes-support/lcms/lcms_2.18.bb b/meta-oe/recipes-support/lcms/lcms_2.18.bb
index 1ff3b3908f..501e1e2a79 100644
--- a/meta-oe/recipes-support/lcms/lcms_2.18.bb
+++ b/meta-oe/recipes-support/lcms/lcms_2.18.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e9ce323c4b71c943a785db90142b228a"
SRC_URI = "${SOURCEFORGE_MIRROR}/lcms/lcms2-${PV}.tar.gz \
file://CVE-2026-41254_1.patch \
file://CVE-2026-41254_2.patch \
+ file://CVE-2026-42798.patch \
"
SRC_URI[sha256sum] = "ee67be3566f459362c1ee094fde2c159d33fa0390aa4ed5f5af676f9e5004347"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 ankur.tyagi85
` (18 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Release Note[1] also mentions fixed CVE.
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-45382
https://nvd.nist.gov/vuln/detail/cve-2026-45383
[1] https://github.com/strukturag/libde265/releases/tag/v1.0.19
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index c5fbedb22a..54f158eef9 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -22,3 +22,6 @@ PACKAGECONFIG[libsdl] = "-DENABLE_SDL=ON,-DENABLE_SDL=OFF,virtual/libsdl2"
FILES:${PN} += "${libdir}/libde265.so"
FILES:${PN}-dev = "${includedir} ${libdir}/cmake ${libdir}/pkgconfig"
INSANE_SKIP:${PN} = "dev-so"
+
+CVE_STATUS[CVE-2026-45382] = "fixed-version: fixed in v1.0.19"
+CVE_STATUS[CVE-2026-45383] = "fixed-version: fixed in v1.0.19"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 ankur.tyagi85
` (17 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49295
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libde265/libde265/CVE-2026-49295.patch | 41 +++++++++++++++++++
.../libde265/libde265_1.0.19.bb | 4 +-
2 files changed, 44 insertions(+), 1 deletion(-)
create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch
new file mode 100644
index 0000000000..189d330b9a
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch
@@ -0,0 +1,41 @@
+From 7d5e48dbf9324691ba3ce4cd8ffa089d735b0b70 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 25 May 2026 20:14:07 +0200
+Subject: [PATCH] bound aggregate short-term RPS size (GHSA-g2rg-wj66-w594)
+
+(cherry picked from commit 691f3a3c55b3d32478c4a49895dee061a282652b)
+
+CVE: CVE-2026-49295
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/refpic.cc | 16 ++++++++++++++++
+ 1 file changed, 16 insertions(+)
+
+diff --git a/libde265/refpic.cc b/libde265/refpic.cc
+index ea4db4b0..dcd2b214 100644
+--- a/libde265/refpic.cc
++++ b/libde265/refpic.cc
+@@ -322,6 +322,22 @@ bool read_short_term_ref_pic_set(error_queue* errqueue,
+
+ out_set->compute_derived_values();
+
++ // The unused short-term references are all collected into a single PocStFoll array
++ // of MAX_NUM_REF_PICS entries (see decoder_context::process_reference_picture_set).
++ // While each individual list is bounded above, the predicted-RPS construction can
++ // append the current-picture delta to an already-full source set, pushing the
++ // combined count past MAX_NUM_REF_PICS. Reject such sets to avoid an out-of-bounds
++ // write when filling PocStFoll.
++ if (out_set->NumDeltaPocs > MAX_NUM_REF_PICS) {
++ out_set->NumNegativePics = 0;
++ out_set->NumPositivePics = 0;
++ out_set->NumDeltaPocs = 0;
++ out_set->NumPocTotalCurr_shortterm_only = 0;
++
++ errqueue->add_warning(DE265_WARNING_MAX_NUM_REF_PICS_EXCEEDED, false);
++ return false;
++ }
++
+ return true;
+ }
+
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index 54f158eef9..b4f80d18a7 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -8,7 +8,9 @@ LICENSE = "LGPL-3.0-only & MIT"
LICENSE_FLAGS = "commercial"
LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
-SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV}"
+SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
+ file://CVE-2026-49295.patch \
+"
SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (2 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 ankur.tyagi85
` (16 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49337
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libde265/libde265/CVE-2026-49337.patch | 53 +++++++++++++++++++
.../libde265/libde265_1.0.19.bb | 1 +
2 files changed, 54 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch
new file mode 100644
index 0000000000..88e0e32949
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch
@@ -0,0 +1,53 @@
+From 2f0c53241cb9bf2f5acded53c25f1b74db536de7 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 25 May 2026 20:29:40 +0200
+Subject: [PATCH] free orphaned slice header when no active image unit
+ (GHSA-g5hj-rf9f-7vxm)
+
+(cherry picked from commit 683cb9fa603e35840642f98765ab95cdb71cadf9)
+
+CVE: CVE-2026-49337
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/decctx.cc | 12 ++++++++----
+ 1 file changed, 8 insertions(+), 4 deletions(-)
+
+diff --git a/libde265/decctx.cc b/libde265/decctx.cc
+index fbb3baa1..5deddc37 100644
+--- a/libde265/decctx.cc
++++ b/libde265/decctx.cc
+@@ -478,10 +478,6 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+ shdr->entry_point_offset[i] -= skipped;
+ }
+
+- this->img->add_slice_segment_header(shdr);
+-
+-
+-
+ // --- start a new image if this is the first slice ---
+
+ if (shdr->first_slice_segment_in_pic_flag) {
+@@ -495,6 +491,13 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+
+ if ( ! image_units.empty() ) {
+
++ // Hand the slice header to the picture (which takes ownership and frees it
++ // on release). Only do this when there is an active image unit to decode
++ // the slice; otherwise the header would be retained on img->slices forever,
++ // which a crafted stream of non-first slice NALs can exploit to grow memory
++ // without bound.
++ this->img->add_slice_segment_header(shdr);
++
+ slice_unit* sliceunit = new slice_unit(this);
+ sliceunit->nal = nal;
+ sliceunit->shdr = shdr;
+@@ -507,6 +510,7 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+ }
+ else {
+ nal_parser.free_NAL_unit(nal);
++ delete shdr;
+ }
+
+ bool did_work;
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index b4f80d18a7..bca5c9d776 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -10,6 +10,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
file://CVE-2026-49295.patch \
+ file://CVE-2026-49337.patch \
"
SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (3 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 ankur.tyagi85
` (15 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49346
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libde265/libde265/CVE-2026-49346.patch | 102 ++++++++++++++++++
.../libde265/libde265_1.0.19.bb | 1 +
2 files changed, 103 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch
new file mode 100644
index 0000000000..288295b08a
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch
@@ -0,0 +1,102 @@
+From 1667c33f2778a04f08ba4f7d6c1c16508350a779 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Tue, 26 May 2026 00:59:08 +0200
+Subject: [PATCH] fix integer overflow in image plane allocation size
+ (GHSA-vv8h-932h-7r86)
+
+(cherry picked from commit 8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8)
+
+CVE: CVE-2026-49346
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/image.cc | 46 +++++++++++++++++++++++++++-------------------
+ 1 file changed, 27 insertions(+), 19 deletions(-)
+
+diff --git a/libde265/image.cc b/libde265/image.cc
+index 0b6071ba..94f3c974 100644
+--- a/libde265/image.cc
++++ b/libde265/image.cc
+@@ -70,10 +70,11 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx,
+ void* inputdata, int inputstride, void *userdata)
+ {
+ int alignment = STANDARD_ALIGNMENT;
+- int stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment;
+- int height = img->get_height(cIdx);
++ uint32_t stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment;
++ uint32_t height = img->get_height(cIdx);
+
+- uint8_t* p = static_cast<uint8_t*>(ALLOC_ALIGNED_16(stride * height + MEMORY_PADDING));
++ // size computed in size_t: stride*height can exceed UINT32_MAX for large planes
++ uint8_t* p = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(stride) * height + MEMORY_PADDING));
+
+ if (p==nullptr) { return nullptr; }
+
+@@ -82,12 +83,14 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx,
+ // copy input data if provided
+
+ if (inputdata != nullptr) {
+- if (inputstride == stride) {
+- memcpy(p, inputdata, stride*height);
++ if (inputstride == static_cast<int>(stride)) {
++ memcpy(p, inputdata, static_cast<size_t>(stride) * height);
+ }
+ else {
+- for (int y=0;y<height;y++) {
+- memcpy(p+y*stride, static_cast<char*>(inputdata) + inputstride*y, inputstride);
++ for (uint32_t y=0;y<height;y++) {
++ memcpy(p + static_cast<size_t>(y) * stride,
++ static_cast<char*>(inputdata) + static_cast<size_t>(inputstride) * y,
++ inputstride);
+ }
+ }
+ }
+@@ -107,30 +110,35 @@ LIBDE265_API void de265_free_image_plane(struct de265_image* img, int cIdx)
+ static int de265_image_get_buffer(de265_decoder_context* ctx,
+ de265_image_spec* spec, de265_image* img, void* userdata)
+ {
+- const int rawChromaWidth = spec->width / img->SubWidthC;
+- const int rawChromaHeight = spec->height / img->SubHeightC;
++ const uint32_t rawChromaWidth = spec->width / img->SubWidthC;
++ const uint32_t rawChromaHeight = spec->height / img->SubHeightC;
+
+- int luma_stride = (spec->width + spec->alignment-1) / spec->alignment * spec->alignment;
+- int chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment;
++ uint32_t luma_stride = (spec->width + spec->alignment-1) / spec->alignment * spec->alignment;
++ uint32_t chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment;
+
+ assert(img->BitDepth_Y >= 8 && img->BitDepth_Y <= 16);
+ assert(img->BitDepth_C >= 8 && img->BitDepth_C <= 16);
+
+- int luma_bpl = luma_stride * ((img->BitDepth_Y+7)/8);
+- int chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8);
++ uint32_t luma_bpl = luma_stride * ((img->BitDepth_Y+7)/8);
++ uint32_t chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8);
+
+- int luma_height = spec->height;
+- int chroma_height = rawChromaHeight;
++ uint32_t luma_height = spec->height;
++ uint32_t chroma_height = rawChromaHeight;
+
+ bool alloc_failed = false;
+
+- uint8_t* p[3] = { 0,0,0 };
+- p[0] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(luma_height * luma_bpl + MEMORY_PADDING));
++ // Compute the plane sizes in size_t. Each operand fits in uint32_t, but the
++ // height * bytes-per-line product can exceed UINT32_MAX for large frames, so
++ // the multiplication must be done in 64 bits. Computing it in 32 bits wraps
++ // the allocation size to a small value while fill_image() later writes the
++ // real (size_t) size -> heap buffer overflow (GHSA-vv8h-932h-7r86).
++ uint8_t* p[3] = { nullptr,nullptr,nullptr };
++ p[0] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(luma_height) * luma_bpl + MEMORY_PADDING));
+ if (p[0]==nullptr) { alloc_failed=true; }
+
+ if (img->get_chroma_format() != de265_chroma_mono) {
+- p[1] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING));
+- p[2] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING));
++ p[1] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(chroma_height) * chroma_bpl + MEMORY_PADDING));
++ p[2] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(chroma_height) * chroma_bpl + MEMORY_PADDING));
+
+ if (p[1]==nullptr || p[2]==nullptr) { alloc_failed=true; }
+ }
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index bca5c9d776..07d108b915 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
file://CVE-2026-49295.patch \
file://CVE-2026-49337.patch \
+ file://CVE-2026-49346.patch \
"
SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (4 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 ankur.tyagi85
` (14 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40947
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb | 2 ++
meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb | 2 ++
2 files changed, 4 insertions(+)
diff --git a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
index 7d9838b003..053d1f6d45 100644
--- a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
+++ b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
@@ -38,3 +38,5 @@ do_install() {
${S}/src/libfido2.pc.in > ${D}${datadir}/pkgconfig/libfido2.pc
}
+
+CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows"
diff --git a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
index 09d34603d6..8595cbae81 100644
--- a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
+++ b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
@@ -21,3 +21,5 @@ EXTRA_OECMAKE = "-DUDEV_RULES_DIR=${nonarch_base_libdir}/udev/rules.d -DBUILD_EX
PACKAGE_BEFORE_PN = "${PN}-tools"
FILES:${PN}-tools = "${bindir}/fido2-*"
+
+CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (5 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 ankur.tyagi85
` (13 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32738
[1]https://security-tracker.debian.org/tracker/CVE-2026-32738
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-32738.patch | 32 +++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 33 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch
new file mode 100644
index 0000000000..4308aa6195
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch
@@ -0,0 +1,32 @@
+From 95a7008c89335ca97fc22ab8caab5d62b077a34f Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Sat, 14 Mar 2026 20:32:39 +0100
+Subject: [PATCH] check that 'stsc' box does not have zero samples per chunk
+
+(cherry picked from commit bdaa37728442800497ea224bd232ca25e2f9bdff)
+
+CVE: CVE-2026-32738
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/bdaa37728442800497ea224bd232ca25e2f9bdff]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/seq_boxes.cc | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc
+index aec84fd5..91865848 100644
+--- a/libheif/sequences/seq_boxes.cc
++++ b/libheif/sequences/seq_boxes.cc
+@@ -875,6 +875,13 @@ Error Box_stsc::parse(BitstreamRange& range, const heif_security_limits* limits)
+ entry.samples_per_chunk = range.read32();
+ entry.sample_description_index = range.read32();
+
++ if (entry.samples_per_chunk == 0) {
++ return {
++ heif_error_Invalid_input,
++ heif_suberror_Unspecified,
++ "'stsc' box with zero samples per chunk entry."};
++ }
++
+ if (entry.sample_description_index == 0) {
+ return {
+ heif_error_Invalid_input,
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index ab29fa3b02..b238807fc5 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -8,6 +8,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null"
SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \
file://CVE-2026-3949.patch \
+ file://CVE-2026-32738.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (6 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 ankur.tyagi85
` (12 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32739
[1]https://security-tracker.debian.org/tracker/CVE-2026-32739
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-32739.patch | 54 +++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 55 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch
new file mode 100644
index 0000000000..59cd793ef6
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch
@@ -0,0 +1,54 @@
+From 1c6fde64e37efa6031a6be2318dac62dfb38f370 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Fri, 13 Mar 2026 23:39:33 +0100
+Subject: [PATCH] fix infinite loop for sequences with variable frame-rate
+
+CVE: CVE-2026-32739
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/723b58d6ca329b2743822951aeaf3299c7410448]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/seq_boxes.cc | 22 ++++++++--------------
+ 1 file changed, 8 insertions(+), 14 deletions(-)
+
+diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc
+index 91865848..39c2e8f4 100644
+--- a/libheif/sequences/seq_boxes.cc
++++ b/libheif/sequences/seq_boxes.cc
+@@ -621,14 +621,11 @@ Error Box_stts::write(StreamWriter& writer) const
+
+ uint32_t Box_stts::get_sample_duration(uint32_t sample_idx)
+ {
+- size_t i = 0;
+- while (i < m_entries.size()) {
+- if (sample_idx < m_entries[i].sample_count) {
+- return m_entries[i].sample_delta;
+- }
+- else {
+- sample_idx -= m_entries[i].sample_count;
++ for (const auto& entry : m_entries) {
++ if (sample_idx < entry.sample_count) {
++ return entry.sample_delta;
+ }
++ sample_idx -= entry.sample_count;
+ }
+
+ return 0;
+@@ -813,14 +810,11 @@ Error Box_ctts::write(StreamWriter& writer) const
+
+ int32_t Box_ctts::get_sample_offset(uint32_t sample_idx)
+ {
+- size_t i = 0;
+- while (i < m_entries.size()) {
+- if (sample_idx < m_entries[i].sample_count) {
+- return m_entries[i].sample_offset;
+- }
+- else {
+- sample_idx -= m_entries[i].sample_count;
++ for (const auto& entry : m_entries) {
++ if (sample_idx < entry.sample_count) {
++ return entry.sample_offset;
+ }
++ sample_idx -= entry.sample_count;
+ }
+
+ return 0;
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index b238807fc5..ba16ee7afe 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -9,6 +9,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null"
SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \
file://CVE-2026-3949.patch \
file://CVE-2026-32738.patch \
+ file://CVE-2026-32739.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (7 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 ankur.tyagi85
` (11 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1] to the original file which was
renamed by upstream commit[2].
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32740
[1]https://security-tracker.debian.org/tracker/CVE-2026-32740
[2]https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-32740.patch | 40 +++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 41 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch
new file mode 100644
index 0000000000..e6ce0e01f4
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch
@@ -0,0 +1,40 @@
+From eec74f24bf52764d870988bade74cd35075a09df Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 18 May 2026 18:03:01 +0200
+Subject: [PATCH] fix integer overflow when computing chroma sizes
+
+CVE: CVE-2026-32740
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/6721f307ad684804b735e917dde7d372c5faae31]
+
+Upstream commit[1] renamed libheif/pixelimage.cc as libheif/image/pixelimage.cc
+Backport changes to the original file.
+
+[1] https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/pixelimage.cc | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libheif/pixelimage.cc b/libheif/pixelimage.cc
+index a8ab7397..da62ea88 100644
+--- a/libheif/pixelimage.cc
++++ b/libheif/pixelimage.cc
+@@ -54,7 +54,7 @@ uint32_t chroma_width(uint32_t w, heif_chroma chroma)
+ switch (chroma) {
+ case heif_chroma_420:
+ case heif_chroma_422:
+- return (w+1)/2;
++ return w/2 + (w & 1); // note: prevents integer overflow
+ default:
+ return w;
+ }
+@@ -64,7 +64,7 @@ uint32_t chroma_height(uint32_t h, heif_chroma chroma)
+ {
+ switch (chroma) {
+ case heif_chroma_420:
+- return (h+1)/2;
++ return h/2 + (h & 1); // note: prevents integer overflow
+ default:
+ return h;
+ }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index ba16ee7afe..df7f0c56e1 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -10,6 +10,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
file://CVE-2026-3949.patch \
file://CVE-2026-32738.patch \
file://CVE-2026-32739.patch \
+ file://CVE-2026-32740.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (8 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 ankur.tyagi85
` (10 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32741
[1]https://security-tracker.debian.org/tracker/CVE-2026-32741
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-32741.patch | 29 +++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 30 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch
new file mode 100644
index 0000000000..cd550aafa5
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch
@@ -0,0 +1,29 @@
+From 3c38488fa2ea31928fcad8f6a5010c1f6f0c1ace Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Thu, 5 Mar 2026 19:00:57 +0100
+Subject: [PATCH] fix possible buffer overflow when reading mask image
+
+(cherry picked from commit 123694271ac02f2de68a3ccdc5d483eb8a2ae593)
+
+CVE: CVE-2026-32741
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/123694271ac02f2de68a3ccdc5d483eb8a2ae593]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/image-items/mask_image.cc | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libheif/image-items/mask_image.cc b/libheif/image-items/mask_image.cc
+index 328d1797..1c4357ff 100644
+--- a/libheif/image-items/mask_image.cc
++++ b/libheif/image-items/mask_image.cc
+@@ -113,8 +113,8 @@ Error MaskImageCodec::decode_mask_image(const HeifContext* context,
+
+ size_t stride;
+ uint8_t* dst = img->get_plane(heif_channel_Y, &stride);
+- if (((uint32_t)stride) == width) {
+- memcpy(dst, data.data(), data.size());
++ if (stride == static_cast<size_t>(width)) {
++ memcpy(dst, data.data(), static_cast<size_t>(width) * height);
+ }
+ else
+ {
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index df7f0c56e1..92891cb5ef 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -11,6 +11,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
file://CVE-2026-32738.patch \
file://CVE-2026-32739.patch \
file://CVE-2026-32740.patch \
+ file://CVE-2026-32741.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (9 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 ankur.tyagi85
` (9 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Also backport[2] which is needed to cherry-pick[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41071
[1]https://security-tracker.debian.org/tracker/CVE-2026-41071
[2]https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-41071-1.patch | 34 ++++++++++++++
.../libheif/libheif/CVE-2026-41071-2.patch | 44 +++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 2 +
3 files changed, 80 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
new file mode 100644
index 0000000000..7971ea3cef
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
@@ -0,0 +1,34 @@
+From 415b59839dcf46bb05e08de7422a21e65ab28e03 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 13 Apr 2026 19:49:06 +0200
+Subject: [PATCH] fix: reject malformed sequence files with saiz samples but no
+ chunks
+
+(cherry picked from commit 71755d3d41a117685a3274bdd1214fc50a760f20)
+
+CVE: CVE-2026-41071
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/track.cc | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc
+index acb916fa..ac5d5687 100644
+--- a/libheif/sequences/track.cc
++++ b/libheif/sequences/track.cc
+@@ -443,6 +443,14 @@ Error Track::load(const std::shared_ptr<Box_trak>& trak_box)
+ };
+ }
+
++ if (saio->get_num_chunks() != 1 && m_chunks.empty() && saiz->get_num_samples() > 0) {
++ return Error{
++ heif_error_Invalid_input,
++ heif_suberror_Unspecified,
++ "'saiz' box references samples but no chunks exist."
++ };
++ }
++
+ if (aux_info_type == fourcc("suid")) {
+ m_aux_reader_content_ids = std::make_unique<SampleAuxInfoReader>(saiz, saio, m_chunks);
+ }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch
new file mode 100644
index 0000000000..952c366966
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch
@@ -0,0 +1,44 @@
+From b79d7d2a4f1502e93739453025ac2dbfd59e514f Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 13 Apr 2026 20:09:26 +0200
+Subject: [PATCH] fix: reject malformed sequence files where saiz sample count
+ exceeds actual samples
+
+(cherry picked from commit f20c81745e917b4c496615140385c86d7a2fa58d)
+CVE: CVE-2026-41071
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/track.cc | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc
+index ac5d5687..e4b08afa 100644
+--- a/libheif/sequences/track.cc
++++ b/libheif/sequences/track.cc
+@@ -138,7 +138,9 @@ SampleAuxInfoReader::SampleAuxInfoReader(std::shared_ptr<Box_saiz> saiz,
+ for (uint32_t i = 0; i < nSamples; i++) {
+ if (!oneChunk && i > chunks[current_chunk]->last_sample_number()) {
+ current_chunk++;
+- assert(current_chunk < chunks.size());
++ if (current_chunk >= chunks.size()) {
++ break;
++ }
+ offset = saio->get_chunk_offset(current_chunk);
+ }
+
+@@ -451,6 +453,14 @@ Error Track::load(const std::shared_ptr<Box_trak>& trak_box)
+ };
+ }
+
++ if (saiz->get_num_samples() > m_stsz->num_samples()) {
++ return Error{
++ heif_error_Invalid_input,
++ heif_suberror_Unspecified,
++ "Number of samples in 'saiz' box exceeds actual number of samples."
++ };
++ }
++
+ if (aux_info_type == fourcc("suid")) {
+ m_aux_reader_content_ids = std::make_unique<SampleAuxInfoReader>(saiz, saio, m_chunks);
+ }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index 92891cb5ef..f3f03abdc7 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -12,6 +12,8 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
file://CVE-2026-32739.patch \
file://CVE-2026-32740.patch \
file://CVE-2026-32741.patch \
+ file://CVE-2026-41071-1.patch \
+ file://CVE-2026-41071-2.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (10 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 ankur.tyagi85
` (8 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit identified by Debian[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-62289
[1]https://security-tracker.debian.org/tracker/CVE-2026-62289
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-62289.patch | 189 ++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 190 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch
new file mode 100644
index 0000000000..5473a2ae18
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch
@@ -0,0 +1,189 @@
+From 49e188ca7a6a81fd1c7d5e76254308c82cbcb5c3 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Thu, 25 Jun 2026 19:58:57 +0200
+Subject: [PATCH] Fix clap transform double-application in image tiling
+ (GHSA-jc8f-p23p-5hjg)
+
+The base ImageItem::get_heif_image_tiling() returned the already
+transformed m_width/m_height, but process_image_transformations_on_tiling()
+applies the transformative properties (irot, imir, clap) itself. This
+applied every transform twice. For a clap that rounds the image down to
+zero, the second application passed 0 into Box_clap::left_rounded(), where
+`image_width - 1U` underflowed to UINT32_MAX and overflowed the Fraction
+constructor (assert abort in debug builds, corrupt crop in release builds).
+The grid, unc and tiled overrides already return coded dimensions, so the
+base class was the lone outlier.
+
+Fixes, in three layers:
+
+ - image_item.cc: base get_heif_image_tiling() now reports coded (ispe)
+ dimensions when available, matching the other overrides, so transforms
+ are applied exactly once. This also fixes a silent irot/imir
+ double-transform on the same path.
+ - context.cc: reject a clap that rounds a dimension to zero or less at
+ parse time, mirroring the existing ispe zero-size check.
+ - box.cc: guard left_rounded()/top_rounded() against a zero image
+ dimension as defense in depth.
+
+Add tests/clap_zero_size.cc covering the hardened clap helpers.
+
+(cherry picked from commit f01870c1d7323a3003796d58eba7fff502be994c)
+
+CVE: CVE-2026-62289
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/box.cc | 11 ++++++++
+ libheif/context.cc | 12 +++++++--
+ libheif/image-items/image_item.cc | 23 ++++++++++++++---
+ tests/CMakeLists.txt | 1 +
+ tests/clap_zero_size.cc | 42 +++++++++++++++++++++++++++++++
+ 5 files changed, 83 insertions(+), 6 deletions(-)
+ create mode 100644 tests/clap_zero_size.cc
+
+diff --git a/libheif/box.cc b/libheif/box.cc
+index 76ba0f0a..57912ab0 100644
+--- a/libheif/box.cc
++++ b/libheif/box.cc
+@@ -3592,6 +3592,12 @@ int Box_clap::left_rounded(uint32_t image_width) const
+
+ // left = horizOff + (width-1)/2 - (clapWidth-1)/2
+
++ // Guard against image_width==0: `image_width - 1U` would underflow to
++ // UINT32_MAX and overflow the Fraction (GHSA-jc8f-p23p-5hjg).
++ if (image_width == 0) {
++ return 0;
++ }
++
+ Fraction pcX = m_horizontal_offset + Fraction(image_width - 1U, 2U);
+ Fraction left = pcX - (m_clean_aperture_width - 1) / 2;
+
+@@ -3607,6 +3613,11 @@ int Box_clap::right_rounded(uint32_t image_width) const
+
+ int Box_clap::top_rounded(uint32_t image_height) const
+ {
++ // Guard against image_height==0 underflowing the Fraction (see left_rounded).
++ if (image_height == 0) {
++ return 0;
++ }
++
+ Fraction pcY = m_vertical_offset + Fraction(image_height - 1U, 2U);
+ Fraction top = pcY - (m_clean_aperture_height - 1) / 2;
+
+diff --git a/libheif/context.cc b/libheif/context.cc
+index a1bcc268..a3371207 100644
+--- a/libheif/context.cc
++++ b/libheif/context.cc
+@@ -644,8 +644,16 @@ Error HeifContext::interpret_heif_file_images()
+ for (const auto& prop : properties) {
+ auto clap = std::dynamic_pointer_cast<Box_clap>(prop);
+ if (clap) {
+- image->set_resolution(clap->get_width_rounded(),
+- clap->get_height_rounded());
++ int clap_width = clap->get_width_rounded();
++ int clap_height = clap->get_height_rounded();
++ if (clap_width <= 0 || clap_height <= 0) {
++ return {heif_error_Invalid_input,
++ heif_suberror_Invalid_clean_aperture,
++ "Clean aperture (clap) reduces image to zero size"};
++ }
++
++ image->set_resolution(static_cast<uint32_t>(clap_width),
++ static_cast<uint32_t>(clap_height));
+
+ if (image->has_intrinsic_matrix()) {
+ image->get_intrinsic_matrix().apply_clap(clap.get(), image->get_width(), image->get_height());
+diff --git a/libheif/image-items/image_item.cc b/libheif/image-items/image_item.cc
+index e803107f..d05536e1 100644
+--- a/libheif/image-items/image_item.cc
++++ b/libheif/image-items/image_item.cc
+@@ -967,10 +967,25 @@ heif_image_tiling ImageItem::get_heif_image_tiling() const
+ tiling.num_columns = 1;
+ tiling.num_rows = 1;
+
+- tiling.tile_width = m_width;
+- tiling.tile_height = m_height;
+- tiling.image_width = m_width;
+- tiling.image_height = m_height;
++ // Report the coded (pre-transformation) dimensions here. The caller applies
++ // the transformative properties (irot, imir, clap) via
++ // process_image_transformations_on_tiling(), so handing it the already
++ // transformed m_width/m_height would apply them a second time. For a clap
++ // that shrinks the image to zero this double application underflowed inside
++ // Box_clap::left_rounded() (GHSA-jc8f-p23p-5hjg); for irot/imir it silently
++ // produced wrong dimensions. The grid/unc/tiled overrides likewise report
++ // coded dimensions.
++ uint32_t coded_width = m_width;
++ uint32_t coded_height = m_height;
++ if (has_ispe_resolution()) {
++ coded_width = get_ispe_width();
++ coded_height = get_ispe_height();
++ }
++
++ tiling.tile_width = coded_width;
++ tiling.tile_height = coded_height;
++ tiling.image_width = coded_width;
++ tiling.image_height = coded_height;
+
+ tiling.top_offset = 0;
+ tiling.left_offset = 0;
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index d8fdfd8b..b52bc202 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -38,6 +38,7 @@ if (WITH_REDUCED_VISIBILITY)
+ else()
+ add_libheif_test(bitstream_tests)
+ add_libheif_test(box_equals)
++ add_libheif_test(clap_zero_size)
+ add_libheif_test(conversion)
+ add_libheif_test(idat)
+ add_libheif_test(jpeg2000)
+diff --git a/tests/clap_zero_size.cc b/tests/clap_zero_size.cc
+new file mode 100644
+index 00000000..eafc1258
+--- /dev/null
++++ b/tests/clap_zero_size.cc
+@@ -0,0 +1,42 @@
++/*
++ libheif clean aperture (clap) zero-size unit tests
++
++ MIT License
++
++ Copyright (c) 2026 Dirk Farin <dirk.farin@gmail.com>
++
++ Permission is hereby granted, free of charge, to any person obtaining a copy
++ of this software and associated documentation files (the "Software"), to deal
++ in the Software without restriction, including without limitation the rights
++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
++ copies of the Software, and to permit persons to whom the Software is
++ furnished to do so, subject to the following conditions:
++
++ The above copyright notice and this permission notice shall be included in all
++ copies or substantial portions of the Software.
++
++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
++ SOFTWARE.
++*/
++
++#include "catch_amalgamated.hpp"
++#include "box.h"
++
++// Regression test for GHSA-jc8f-p23p-5hjg: passing a zero image dimension to
++// the clap rounding helpers used to underflow `image_width - 1U` to UINT32_MAX,
++// which overflowed the Fraction constructor (assert abort in debug builds,
++// corrupt crop in release builds). They must now return 0 without aborting.
++TEST_CASE("clap rounding with zero image size") {
++ std::shared_ptr<Box_clap> clap = std::make_shared<Box_clap>();
++ clap->set(100, 200, 150, 250); // clap 100x200 inside a 150x250 image
++
++ REQUIRE(clap->left_rounded(0) == 0);
++ REQUIRE(clap->right_rounded(0) == 99); // clapWidth - 1 + left(0)
++ REQUIRE(clap->top_rounded(0) == 0);
++ REQUIRE(clap->bottom_rounded(0) == 199); // clapHeight - 1 + top(0)
++}
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index f3f03abdc7..1dfab46513 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -14,6 +14,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
file://CVE-2026-32741.patch \
file://CVE-2026-41071-1.patch \
file://CVE-2026-41071-2.patch \
+ file://CVE-2026-62289.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (11 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched ankur.tyagi85
` (7 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/CVE-2026-62377
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libheif/libheif/CVE-2026-62377.patch | 175 ++++++++++++++++++
.../libheif/libheif_1.21.2.bb | 1 +
2 files changed, 176 insertions(+)
create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch
new file mode 100644
index 0000000000..5481c198b6
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch
@@ -0,0 +1,175 @@
+From cace54a7491cd8eb46617f17ca7078182d9903b0 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Fri, 26 Jun 2026 10:03:31 +0200
+Subject: [PATCH] Return error instead of asserting in get_track() without
+ sequence (#1844)
+
+HeifContext::get_track() asserted has_sequence() up front. Calling the
+public heif_context_get_track() on a context that has no sequence tracks
+(e.g. a still image, or a crafted sequence file accepted with zero tracks)
+therefore aborted the process via the assert, instead of letting the public
+wrapper return the documented nullptr. In NDEBUG builds the assert was
+compiled out and the track_id==0 path dereferenced begin() on an empty map.
+
+Replace the assert with a normal error return so the public wrapper hands
+the caller nullptr as documented.
+
+(cherry picked from commit e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3)
+
+CVE: CVE-2026-62377
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/context.cc | 9 +++-
+ tests/CMakeLists.txt | 1 +
+ tests/sequence_no_track.cc | 108 +++++++++++++++++++++++++++++++++++++
+ 3 files changed, 117 insertions(+), 1 deletion(-)
+ create mode 100644 tests/sequence_no_track.cc
+
+diff --git a/libheif/context.cc b/libheif/context.cc
+index a3371207..170f8314 100644
+--- a/libheif/context.cc
++++ b/libheif/context.cc
+@@ -1945,7 +1945,14 @@ std::vector<uint32_t> HeifContext::get_track_IDs() const
+
+ Result<std::shared_ptr<Track>> HeifContext::get_track(uint32_t track_id)
+ {
+- assert(has_sequence());
++ // The caller is expected to have confirmed (via has_sequence()) that there are
++ // sequence tracks before requesting one. Guard against an empty track map anyway,
++ // since this is reachable through the public API (e.g. on a still image file).
++ if (!has_sequence()) {
++ return Error{heif_error_Usage_error,
++ heif_suberror_Unspecified,
++ "File contains no sequence tracks"};
++ }
+
+ if (track_id != 0) {
+ auto iter = m_tracks.find(track_id);
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index b52bc202..d66ffb38 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -59,6 +59,7 @@ endif()
+ add_libheif_test(encode)
+ add_libheif_test(extended_type)
+ add_libheif_test(region)
++add_libheif_test(sequence_no_track)
+ add_libheif_test(tai)
+ add_libheif_test(text)
+ add_libheif_test(cxx_wrapper)
+diff --git a/tests/sequence_no_track.cc b/tests/sequence_no_track.cc
+new file mode 100644
+index 00000000..cde11f77
+--- /dev/null
++++ b/tests/sequence_no_track.cc
+@@ -0,0 +1,108 @@
++/*
++ libheif regression test for requesting a track from a context without sequence tracks.
++
++ MIT License
++
++ Copyright (c) 2026 Dirk Farin <dirk.farin@gmail.com>
++
++ Permission is hereby granted, free of charge, to any person obtaining a copy
++ of this software and associated documentation files (the "Software"), to deal
++ in the Software without restriction, including without limitation the rights
++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
++ copies of the Software, and to permit persons to whom the Software is
++ furnished to do so, subject to the following conditions:
++
++ The above copyright notice and this permission notice shall be included in all
++ copies or substantial portions of the Software.
++
++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
++ SOFTWARE.
++*/
++
++#include "catch_amalgamated.hpp"
++#include "libheif/heif.h"
++#include "libheif/heif_sequences.h"
++#include "test_utils.h"
++
++#include <cstdint>
++#include <vector>
++
++namespace {
++
++// Sequence API queries that must work on a context that holds no sequence
++// tracks (a still image, or no image at all). heif_context_get_track() is
++// documented to return nullptr on failure; it must not abort/crash. This
++// formerly tripped assert(has_sequence()) in HeifContext::get_track().
++// See https://github.com/strukturag/libheif/issues/1844.
++void check_no_sequence_apis(heif_context* ctx)
++{
++ REQUIRE(heif_context_has_sequence(ctx) == 0);
++ REQUIRE(heif_context_number_of_sequence_tracks(ctx) == 0);
++
++ // Listing track IDs must work (and write nothing) when there are no tracks.
++ heif_context_get_track_ids(ctx, nullptr);
++
++ heif_track* track = heif_context_get_track(ctx, 0);
++ REQUIRE(track == nullptr);
++}
++
++heif_error mem_writer(heif_context*, const void* data, size_t size, void* userdata)
++{
++ auto* out = static_cast<std::vector<uint8_t>*>(userdata);
++ const auto* p = static_cast<const uint8_t*>(data);
++ out->insert(out->end(), p, p + size);
++ return heif_error{heif_error_Ok, heif_suberror_Unspecified, nullptr};
++}
++
++}
++
++TEST_CASE("get_track on context without sequence returns nullptr")
++{
++ heif_context* ctx = heif_context_alloc();
++ REQUIRE(ctx != nullptr);
++
++ // Fresh context, nothing loaded: no sequence tracks present.
++ check_no_sequence_apis(ctx);
++
++ heif_context_free(ctx);
++}
++
++TEST_CASE("get_track on a still-image file returns nullptr")
++{
++ // Encode a tiny still image to an in-memory HEIF file, then read it back.
++ // A still image is a perfectly valid file that contains no sequence tracks.
++ heif_image* img = nullptr;
++ REQUIRE(heif_image_create(16, 16, heif_colorspace_YCbCr, heif_chroma_420, &img).code == heif_error_Ok);
++ fill_new_plane(img, heif_channel_Y, 16, 16);
++ fill_new_plane(img, heif_channel_Cb, 8, 8);
++ fill_new_plane(img, heif_channel_Cr, 8, 8);
++
++ heif_encoder* enc = get_encoder_or_skip_test(heif_compression_HEVC);
++
++ heif_context* enc_ctx = heif_context_alloc();
++ REQUIRE(heif_context_encode_image(enc_ctx, img, enc, nullptr, nullptr).code == heif_error_Ok);
++
++ std::vector<uint8_t> file;
++ heif_writer writer{};
++ writer.writer_api_version = 1;
++ writer.write = mem_writer;
++ REQUIRE(heif_context_write(enc_ctx, &writer, &file).code == heif_error_Ok);
++
++ heif_encoder_release(enc);
++ heif_context_free(enc_ctx);
++ heif_image_release(img);
++
++ // Read the still image back and query the sequence API on it.
++ heif_context* ctx = heif_context_alloc();
++ REQUIRE(ctx != nullptr);
++ REQUIRE(heif_context_read_from_memory(ctx, file.data(), file.size(), nullptr).code == heif_error_Ok);
++
++ check_no_sequence_apis(ctx);
++
++ heif_context_free(ctx);
++}
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index 1dfab46513..165ed0ad2a 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -15,6 +15,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
file://CVE-2026-41071-1.patch \
file://CVE-2026-41071-2.patch \
file://CVE-2026-62289.patch \
+ file://CVE-2026-62377.patch \
"
SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (12 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 ankur.tyagi85
` (6 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
NVD[1] mentions commit[2] for v1.5 but is also present in v1.6[3]
[1] https://nvd.nist.gov/vuln/detail/cve-2024-45969
[2] https://github.com/mz-automation/libiec61850/commit/7afa40390b26ad1f4cf93deaa0052fe7e357ef33
[3] https://github.com/mz-automation/libiec61850/commit/d1ab50298fcba3f87b1e58dabff92f8615b14ee7
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../recipes-connectivity/libiec61850/libiec61850_1.6.1.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index c46ed88d83..5a76ba5330 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -35,3 +35,5 @@ FILES:${PN} += " \
${PYTHON_SITEPACKAGES_DIR}/pyiec61850.py \
${PYTHON_SITEPACKAGES_DIR}/_pyiec61850.so \
"
+
+CVE_STATUS[CVE-2024-45969] = "fixed-version: fixed since v1.6.0"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (13 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 ankur.tyagi85
` (5 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-18582
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libiec61850/files/CVE-2026-18582.patch | 51 +++++++++++++++++++
.../libiec61850/libiec61850_1.6.1.bb | 1 +
2 files changed, 52 insertions(+)
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch
new file mode 100644
index 0000000000..6fcd1662b9
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch
@@ -0,0 +1,51 @@
+From 43aa106301639f2afddf11302d25e84c5482e26c Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 16 Jun 2026 19:24:12 +0100
+Subject: [PATCH] - MMS server: fixed - oversized RptID written to RCB can
+ trigger invalid free when reports are sent later
+ (LIB61850-561)(GHSA-7qg8-hm25-rv5v)
+
+(cherry picked from commit 5b2a69f44256b8548927d8afdd7ac5f5381abe1e)
+
+CVE: CVE-2026-18582
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/iec61850/server/mms_mapping/reporting.c | 9 +++++++--
+ 1 file changed, 7 insertions(+), 2 deletions(-)
+
+diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c
+index 2a230c28..a44f0583 100644
+--- a/src/iec61850/server/mms_mapping/reporting.c
++++ b/src/iec61850/server/mms_mapping/reporting.c
+@@ -557,7 +557,6 @@ updateSingleTrackingValue(MmsMapping* self, ReportControl* rc, const char* name,
+ attributeToUpdate = trkInst->resv;
+ else if (!strcmp(name, "DatSet"))
+ {
+-
+ char datSet[130];
+ const char* datSetStr = MmsValue_toString(newValue);
+
+@@ -2664,6 +2663,12 @@ Reporting_RCBWriteAccessHandler(MmsMapping* self, ReportControl* rc, const char*
+ goto exit_function;
+ }
+
++ if (MmsValue_getStringSize(value) > 129)
++ {
++ retVal = DATA_ACCESS_ERROR_OBJECT_VALUE_INVALID;
++ goto exit_function;
++ }
++
+ #if (CONFIG_MMS_THREADLESS_STACK != 1)
+ Semaphore_wait(rc->rcbValuesLock);
+ #endif
+@@ -3677,7 +3682,7 @@ sendNextReportEntrySegment(ReportControl* self)
+
+ const char* rptIdStr = MmsValue_toString(rptIdFromRcb);
+
+- if (rptIdStr[0] == 0)
++ if (rptIdStr[0] == 0 || MmsValue_getStringSize(rptIdFromRcb) > 129)
+ {
+ /* use default rptId when RptID is empty in RCB */
+ updateWithDefaultRptId(self, &rptId);
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index 5a76ba5330..b22d8a09c9 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -17,6 +17,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8"
SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \
file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
+ file://CVE-2026-18582.patch \
"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (14 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 ankur.tyagi85
` (4 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-18583
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libiec61850/files/CVE-2026-18583.patch | 35 +++++++++++++++++++
.../libiec61850/libiec61850_1.6.1.bb | 1 +
2 files changed, 36 insertions(+)
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch
new file mode 100644
index 0000000000..8acf7e1465
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch
@@ -0,0 +1,35 @@
+From c8baade187e1c31ac9e9ca71dced5a46765d97b2 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 16 Jun 2026 18:23:52 +0100
+Subject: [PATCH] - MMS server: fixed - potential crash in access control check
+ handler for association and vmd specific data sets
+ (LIB61850-560)(GHSA-7v2x-39mw-2979)
+
+(cherry picked from commit 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d)
+
+CVE: CVE-2026-18583
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/iec61850/server/mms_mapping/mms_mapping.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c
+index e5e6b034..5620f63f 100644
+--- a/src/iec61850/server/mms_mapping/mms_mapping.c
++++ b/src/iec61850/server/mms_mapping/mms_mapping.c
+@@ -3807,11 +3807,11 @@ checkDataSetAccess(MmsMapping* self, MmsServerConnection connection, MmsVariable
+ if (listType == MMS_ASSOCIATION_SPECIFIC)
+ {
+ dataSetRef[0] = '@';
+- StringUtils_copyStringToBuffer(dataSetRef + 1, listName);
++ StringUtils_copyStringMax(dataSetRef + 1, 129, listName);
+ }
+ else if (listType == MMS_VMD_SPECIFIC)
+ {
+- StringUtils_copyStringToBuffer(dataSetRef, listName);
++ StringUtils_copyStringMax(dataSetRef, 129, listName);
+ }
+ else if (listType == MMS_DOMAIN_SPECIFIC)
+ {
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index b22d8a09c9..408b4d2d11 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -18,6 +18,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8"
SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \
file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
file://CVE-2026-18582.patch \
+ file://CVE-2026-18583.patch \
"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (15 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 ankur.tyagi85
` (3 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-19108
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libiec61850/files/CVE-2026-19108.patch | 208 ++++++++++++++++++
.../libiec61850/libiec61850_1.6.1.bb | 1 +
2 files changed, 209 insertions(+)
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch
new file mode 100644
index 0000000000..673ce29af0
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch
@@ -0,0 +1,208 @@
+From 846bd407527061665a3c109eaa6ee7e870ae6bc1 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 21 Jul 2026 10:26:33 +0000
+Subject: [PATCH] - MMS server: fixed - Update URCB that used an association
+ specific dataset of another connection can cause heap-use-after-free
+ (LIB61850-577)(#596) - fixed bitbucket sonarcloud pipeline
+
+(cherry picked from commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168)
+
+CVE: CVE-2026-19108
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ bitbucket-pipelines.yml | 11 +++----
+ src/iec61850/inc_private/reporting.h | 1 +
+ src/iec61850/server/mms_mapping/mms_mapping.c | 29 +++++++++++++++++--
+ src/iec61850/server/mms_mapping/reporting.c | 17 +++++++----
+ .../iso_mms/server/mms_server_connection.c | 19 ++++++++++++
+ 5 files changed, 65 insertions(+), 12 deletions(-)
+
+diff --git a/bitbucket-pipelines.yml b/bitbucket-pipelines.yml
+index a7493663..30dce281 100644
+--- a/bitbucket-pipelines.yml
++++ b/bitbucket-pipelines.yml
+@@ -1,4 +1,4 @@
+-image: atlassian/default-image:4
++image: atlassian/default-image:5
+
+ clone:
+ depth: full # SonarCloud scanner needs the full history to assign issues properly
+@@ -12,12 +12,13 @@ definitions:
+ caches:
+ - sonar
+ script:
+- - export SONAR_SCANNER_VERSION=5.0.1.3006
+- - export SONAR_SCANNER_OPTS="-Dsonar.javaHome=/usr/lib/jvm/java-17-openjdk-amd64"
+- - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux
++ - export SONAR_SCANNER_VERSION=6.2.1.4610
++ - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux-x64
+ - export BW_OUTPUT=$HOME/.sonar/bw-output
+ - mkdir -p $BW_OUTPUT
+- - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux.zip
++ - apt-get update -qq
++ - apt-get install openjdk-21-jre cmake -y
++ - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux-x64.zip
+ - unzip -o $HOME/.sonar/sonar-scanner.zip -d $HOME/.sonar/
+ - export PATH=$SONAR_SCANNER_HOME/bin:$PATH
+ - curl --create-dirs -sSLo $HOME/.sonar/build-wrapper-linux-x86.zip https://sonarcloud.io/static/cpp/build-wrapper-linux-x86.zip
+diff --git a/src/iec61850/inc_private/reporting.h b/src/iec61850/inc_private/reporting.h
+index eddeb2d1..bc23f937 100644
+--- a/src/iec61850/inc_private/reporting.h
++++ b/src/iec61850/inc_private/reporting.h
+@@ -67,6 +67,7 @@ typedef struct {
+ bool buffered; /* true if report is a buffered report */
+
+ MmsValue** bufferedDataSetValues; /* used to buffer values during bufTm time */
++ int bufferedDataSetValuesSize; /* number of dataset entries */
+
+ MmsValue** valueReferences; /* array to store value references for fast access */
+
+diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c
+index 5620f63f..ef6f3580 100644
+--- a/src/iec61850/server/mms_mapping/mms_mapping.c
++++ b/src/iec61850/server/mms_mapping/mms_mapping.c
+@@ -3912,6 +3912,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+ {
+ ReportControl* rc = (ReportControl*) rcElement->data;
+
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++ Semaphore_wait(rc->rcbValuesLock);
++#endif
++
+ if (rc->isDynamicDataSet)
+ {
+ if (rc->dataSet != NULL)
+@@ -3924,6 +3928,11 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+ {
+ if (strcmp(rc->dataSet->logicalDeviceName, MmsDomain_getName(domain) + strlen(self->model->name)) == 0)
+ {
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++ Semaphore_post(rc->rcbValuesLock);
++#endif
++
++ /* dataset is in use and cannot be deleted */
+ allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+ break;
+ }
+@@ -3936,6 +3945,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+ {
+ if (strcmp(rc->dataSet->name, listName) == 0)
+ {
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++ Semaphore_post(rc->rcbValuesLock);
++#endif
++ /* dataset is in use and cannot be deleted */
+ allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+ break;
+ }
+@@ -3947,13 +3960,22 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+ {
+ if (strcmp(rc->dataSet->name, listName) == 0)
+ {
+- allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+- break;
++ /* this is usually called when the connection is closed -> RCB has already been disabled by connection handler */
++
++ MmsMapping_freeDynamicallyCreatedDataSet(rc->dataSet);
++
++ /* cleanup dataset information in RCB instance */
++ rc->dataSet = NULL;
++ rc->isDynamicDataSet = false;
+ }
+ }
+ }
+ }
+ }
++
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++ Semaphore_post(rc->rcbValuesLock);
++#endif
+ }
+
+ #if (CONFIG_IEC61850_LOG_SERVICE == 1)
+@@ -4729,6 +4751,9 @@ MmsMapping_getDomainSpecificDataSet(MmsMapping* self, const char* dataSetName)
+ void
+ MmsMapping_freeDynamicallyCreatedDataSet(DataSet* dataSet)
+ {
++ if (dataSet == NULL)
++ return;
++
+ DataSetEntry* dataSetEntry = dataSet->fcdas;
+
+ while (dataSetEntry)
+diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c
+index a44f0583..03add555 100644
+--- a/src/iec61850/server/mms_mapping/reporting.c
++++ b/src/iec61850/server/mms_mapping/reporting.c
+@@ -193,13 +193,9 @@ deleteDataSetValuesShadowBuffer(ReportControl* self)
+ {
+ if (self->bufferedDataSetValues != NULL)
+ {
+- assert(self->dataSet != NULL);
+-
+- int dataSetSize = DataSet_getSize(self->dataSet);
+-
+ int i;
+
+- for (i = 0; i < dataSetSize; i++)
++ for (i = 0; i < self->bufferedDataSetValuesSize; i++)
+ {
+ if (self->bufferedDataSetValues[i] != NULL)
+ MmsValue_delete(self->bufferedDataSetValues[i]);
+@@ -698,13 +694,24 @@ static void
+ createDataSetValuesShadowBuffer(ReportControl* rc)
+ {
+ int dataSetSize = DataSet_getSize(rc->dataSet);
++ rc->bufferedDataSetValuesSize = dataSetSize;
+
+ MmsValue** dataSetValues = (MmsValue**)GLOBAL_CALLOC(dataSetSize, sizeof(MmsValue*));
+
++ if (dataSetValues == NULL)
++ return;
++
+ rc->bufferedDataSetValues = dataSetValues;
+
+ rc->valueReferences = (MmsValue**)GLOBAL_MALLOC(dataSetSize * sizeof(MmsValue*));
+
++ if (rc->valueReferences == NULL)
++ {
++ GLOBAL_FREEMEM(dataSetValues);
++ rc->bufferedDataSetValues = NULL;
++ return;
++ }
++
+ DataSetEntry* dataSetEntry = rc->dataSet->fcdas;
+
+ int i;
+diff --git a/src/mms/iso_mms/server/mms_server_connection.c b/src/mms/iso_mms/server/mms_server_connection.c
+index 644fcdb1..401ad40b 100644
+--- a/src/mms/iso_mms/server/mms_server_connection.c
++++ b/src/mms/iso_mms/server/mms_server_connection.c
+@@ -829,6 +829,25 @@ MmsServerConnection_destroy(MmsServerConnection self)
+ #endif
+
+ #if (MMS_DYNAMIC_DATA_SETS == 1)
++ /* notify IEC 61850 layer BEFORE destroying named variable lists */
++ if (self->namedVariableLists)
++ {
++ LinkedList element = LinkedList_getNext(self->namedVariableLists);
++
++ while (element)
++ {
++ MmsNamedVariableList variableList = (MmsNamedVariableList)element->data;
++
++ if (variableList && variableList->name)
++ {
++ mmsServer_callVariableListChangedHandler(MMS_VARLIST_DELETE, MMS_ASSOCIATION_SPECIFIC,
++ NULL, /* domain (NULL for aa-specific) */
++ variableList->name, self);
++ }
++ element = LinkedList_getNext(element);
++ }
++ }
++
+ LinkedList_destroyDeep(self->namedVariableLists, (LinkedListValueDeleteFunction) MmsNamedVariableList_destroy);
+ #endif
+
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index 408b4d2d11..c0e6efedd6 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -19,6 +19,7 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;
file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
file://CVE-2026-18582.patch \
file://CVE-2026-18583.patch \
+ file://CVE-2026-19108.patch \
"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (16 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 ankur.tyagi85
` (2 subsequent siblings)
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commits[1][2] in order to cherry pick fix mentioned in NVD.
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-19206
[1]https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c
[2]https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libiec61850/files/CVE-2026-19206-1.patch | 129 +++++++++++++++++
.../libiec61850/files/CVE-2026-19206-2.patch | 134 ++++++++++++++++++
.../libiec61850/files/CVE-2026-19206-3.patch | 115 +++++++++++++++
.../libiec61850/libiec61850_1.6.1.bb | 3 +
4 files changed, 381 insertions(+)
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
new file mode 100644
index 0000000000..b7b86b3f64
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
@@ -0,0 +1,129 @@
+From 04f95bf3e54614122621b520eac29dea160de1c7 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 17 Mar 2026 12:41:32 +0000
+Subject: [PATCH] - fixed memory-safety issues and potential NULL pointer
+ dereferenciations in SV parser (#585)
+
+(cherry picked from commit c85175ddf7018beb753d85a740d4c2c77f61c96c)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/sampled_values/sv_subscriber.c | 35 +++++++++++++++++++++++-------
+ 1 file changed, 27 insertions(+), 8 deletions(-)
+
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index 221eb1a8..bb82818e 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -423,16 +423,24 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ return;
+ }
+
++ if (bufPos + elementLength > length)
++ {
++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: Malformed message: element length exceeds buffer length!\n");
++ return;
++ }
++
+ switch (tag)
+ {
+ case 0x80:
+ asdu.svId = (char*) (buffer + bufPos);
+ svIdLength = elementLength;
++ asdu.svId[svIdLength] = 0;
+ break;
+
+ case 0x81:
+ asdu.datSet = (char*) (buffer + bufPos);
+ datSetLength = elementLength;
++ asdu.datSet[datSetLength] = 0;
+ break;
+
+ case 0x82:
+@@ -471,22 +479,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+
+ bufPos += elementLength;
+ }
+-
+- if (asdu.svId != NULL)
+- asdu.svId[svIdLength] = 0;
+- if (asdu.datSet != NULL)
+- asdu.datSet[datSetLength] = 0;
+
+ if (DEBUG_SV_SUBSCRIBER)
+ {
+ printf("SV_SUBSCRIBER: SV ASDU: ----------------\n");
+ printf("SV_SUBSCRIBER: DataLength: %d\n", asdu.dataBufferLength);
+- printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId);
++ printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId ? asdu.svId : "(empty)");
+ printf("SV_SUBSCRIBER: SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu));
+ printf("SV_SUBSCRIBER: ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu));
+
+ if (SVSubscriber_ASDU_hasDatSet(&asdu))
+- printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet);
++ printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)");
+
+ if (SVSubscriber_ASDU_hasRefrTm(&asdu))
+ #ifndef _MSC_VER
+@@ -598,7 +601,8 @@ exit_error:
+ static void
+ handleSVApdu(SVReceiver self, uint16_t appId, uint8_t* apdu, int apduLength, uint8_t* dstAddr)
+ {
+- if (DEBUG_SV_SUBSCRIBER) {
++ if (DEBUG_SV_SUBSCRIBER)
++ {
+ printf("SV_SUBSCRIBER: SV message: ----------------\n");
+ printf("SV_SUBSCRIBER: APPID: %u\n", appId);
+ printf("SV_SUBSCRIBER: APDU length: %i\n", apduLength);
+@@ -791,6 +795,9 @@ SVSubscriber_setListener(SVSubscriber self, SVUpdateListener listener, void* pa
+ uint8_t
+ SVSubscriber_ASDU_getSmpSynch(SVSubscriber_ASDU self)
+ {
++ if (self->smpSynch == NULL)
++ return 0;
++
+ return self->smpSynch[0];
+ }
+
+@@ -800,6 +807,9 @@ SVSubscriber_ASDU_getSmpCnt(SVSubscriber_ASDU self)
+ uint16_t retVal;
+ uint8_t* valBytes = (uint8_t*) &retVal;
+
++ if (self->smpCnt == NULL)
++ return 0;
++
+ #if (ORDER_LITTLE_ENDIAN == 1)
+ valBytes[0] = self->smpCnt[1];
+ valBytes[1] = self->smpCnt[0];
+@@ -912,6 +922,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self)
+ {
+ uint32_t retVal;
+
++ if (self->confRev == NULL)
++ return 0;
++
+ #if (ORDER_LITTLE_ENDIAN == 1)
+ memcpy_reverse(&retVal, self->confRev, sizeof(uint32_t));
+ #else
+@@ -924,6 +937,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self)
+ uint8_t
+ SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self)
+ {
++ if (self->smpMod == NULL)
++ return 0;
++
+ uint8_t retVal = *((uint8_t*) (self->smpMod));
+
+ return retVal;
+@@ -932,6 +948,9 @@ SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self)
+ uint16_t
+ SVSubscriber_ASDU_getSmpRate(SVSubscriber_ASDU self)
+ {
++ if (self->smpRate == NULL)
++ return 0;
++
+ uint16_t retVal;
+
+ #if (ORDER_LITTLE_ENDIAN == 1)
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
new file mode 100644
index 0000000000..e39cc3e17a
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
@@ -0,0 +1,134 @@
+From 62741cc994ae02ef95e664b9470a22089788cff4 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Wed, 17 Jun 2026 12:22:34 +0100
+Subject: [PATCH] - SV subscriber: fixed - null terminator for svId and datSet
+ overwrites tag and can cause OOB write (LIB61850-563)
+
+(cherry picked from commit 6178540e8cdd26b7884a482905140cc9084966a1)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ .../sv_subscriber/sv_subscriber_example.c | 4 ++
+ src/sampled_values/sv_subscriber.c | 56 ++++++++++++++-----
+ 2 files changed, 46 insertions(+), 14 deletions(-)
+
+diff --git a/examples/sv_subscriber/sv_subscriber_example.c b/examples/sv_subscriber/sv_subscriber_example.c
+index 0e3ff720..6487052b 100644
+--- a/examples/sv_subscriber/sv_subscriber_example.c
++++ b/examples/sv_subscriber/sv_subscriber_example.c
+@@ -30,6 +30,10 @@ svUpdateListener (SVSubscriber subscriber, void* parameter, SVSubscriber_ASDU as
+ if (svID != NULL)
+ printf(" svID=(%s)\n", svID);
+
++ const char* dataSet = SVSubscriber_ASDU_getDatSet(asdu);
++ if (dataSet != NULL)
++ printf(" dataSet=(%s)\n", dataSet);
++
+ printf(" smpCnt: %i\n", SVSubscriber_ASDU_getSmpCnt(asdu));
+ printf(" confRev: %u\n", SVSubscriber_ASDU_getConfRev(asdu));
+
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index bb82818e..97f881f6 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -81,8 +81,12 @@ struct sSVSubscriber
+
+ struct sSVSubscriber_ASDU
+ {
+- char* svId;
+- char* datSet;
++ char svIdBuf[130]; /* copy of svId - only copied when the user requests the svId */
++ char datSetBuf[130]; /* copy of datSet - only copied when the user requests the datSet */
++ char* svId; /* pointer to the start of the svId in the ASDU buffer */
++ char* datSet; /* pointer to the start of the datSet in the ASDU buffer */
++ uint8_t svIdSize; /* size of the svId in the ASDU buffer */
++ uint8_t datSetSize; /* size of the datSet in the ASDU buffer */
+
+ uint8_t* smpCnt;
+ uint8_t* confRev;
+@@ -432,15 +436,27 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ switch (tag)
+ {
+ case 0x80:
+- asdu.svId = (char*) (buffer + bufPos);
+- svIdLength = elementLength;
+- asdu.svId[svIdLength] = 0;
++ if (elementLength > 129)
++ {
++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n");
++ }
++ else
++ {
++ asdu.svId = (char*) (buffer + bufPos);
++ asdu.svIdSize = elementLength;
++ }
+ break;
+
+ case 0x81:
+- asdu.datSet = (char*) (buffer + bufPos);
+- datSetLength = elementLength;
+- asdu.datSet[datSetLength] = 0;
++ if (elementLength > 129)
++ {
++ if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n");
++ }
++ else
++ {
++ asdu.datSet = (char*) (buffer + bufPos);
++ asdu.datSetSize = elementLength;
++ }
+ break;
+
+ case 0x82:
+@@ -479,17 +495,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+
+ bufPos += elementLength;
+ }
+-
++
+ if (DEBUG_SV_SUBSCRIBER)
+ {
+ printf("SV_SUBSCRIBER: SV ASDU: ----------------\n");
+ printf("SV_SUBSCRIBER: DataLength: %d\n", asdu.dataBufferLength);
+- printf("SV_SUBSCRIBER: SvId: %s\n", asdu.svId ? asdu.svId : "(empty)");
++ printf("SV_SUBSCRIBER: SvId: %s\n", SVSubscriber_ASDU_getSvId(&asdu));
+ printf("SV_SUBSCRIBER: SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu));
+ printf("SV_SUBSCRIBER: ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu));
+-
++
+ if (SVSubscriber_ASDU_hasDatSet(&asdu))
+- printf("SV_SUBSCRIBER: DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)");
++ printf("SV_SUBSCRIBER: DatSet: %s\n", SVSubscriber_ASDU_getDatSet(&asdu));
+
+ if (SVSubscriber_ASDU_hasRefrTm(&asdu))
+ #ifndef _MSC_VER
+@@ -899,13 +915,25 @@ SVSubscriber_ASDU_hasSmpMod(SVSubscriber_ASDU self)
+ const char*
+ SVSubscriber_ASDU_getSvId(SVSubscriber_ASDU self)
+ {
+- return self->svId;
++ if (self->svId == NULL)
++ return NULL;
++
++ memcpy(self->svIdBuf, self->svId, self->svIdSize);
++ self->svIdBuf[self->svIdSize] = 0; /* ensure null termination */
++
++ return self->svIdBuf;
+ }
+
+ const char*
+ SVSubscriber_ASDU_getDatSet(SVSubscriber_ASDU self)
+ {
+- return self->datSet;
++ if (self->datSet == NULL)
++ return NULL;
++
++ memcpy(self->datSetBuf, self->datSet, self->datSetSize);
++ self->datSetBuf[self->datSetSize] = 0; /* ensure null termination */
++
++ return self->datSetBuf;
+ }
+
+ static inline void
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch
new file mode 100644
index 0000000000..75e476c6c5
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch
@@ -0,0 +1,115 @@
+From 03841913e3b8220f1ceb2ab5493bc31b769113bd Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Wed, 1 Jul 2026 11:32:34 +0100
+Subject: [PATCH] - SV subscriber: fixed missing length validation of some ASDU
+ elements that can cause OOB reads when these fields are later used by the
+ application (LIB61850-574)
+
+(cherry picked from commit a96bd674e0238276dd1387d31d52e55229d0771e)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/a96bd674e0238276dd1387d31d52e55229d0771e]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/sampled_values/sv_subscriber.c | 48 +++++++++++++++++++++++++-----
+ 1 file changed, 40 insertions(+), 8 deletions(-)
+
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index 97f881f6..55422d87 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -402,6 +402,20 @@ SVReceiver_stopThreadless(SVReceiver self)
+ self->running = false;
+ }
+
++static void
++invalidFieldSize(const char* fieldName, int expectedSize, int actualSize)
++{
++ if (DEBUG_SV_SUBSCRIBER)
++ printf("SV_SUBSCRIBER: Invalid %s size: expected %d, got %d\n", fieldName, expectedSize, actualSize);
++}
++
++static void
++fieldTooLong(const char* fieldName, int maxSize, int actualSize)
++{
++ if (DEBUG_SV_SUBSCRIBER)
++ printf("SV_SUBSCRIBER: %s too long: max %d, got %d\n", fieldName, maxSize, actualSize);
++}
++
+ static void
+ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ {
+@@ -438,7 +452,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ case 0x80:
+ if (elementLength > 129)
+ {
+- if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n");
++ return fieldTooLong("svId", 129, elementLength);
+ }
+ else
+ {
+@@ -450,7 +464,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ case 0x81:
+ if (elementLength > 129)
+ {
+- if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n");
++ return fieldTooLong("datSet", 129, elementLength);
+ }
+ else
+ {
+@@ -460,23 +474,38 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ break;
+
+ case 0x82:
+- asdu.smpCnt = buffer + bufPos;
++ if (elementLength != 2)
++ return invalidFieldSize("SmpCnt", 2, elementLength);
++ else
++ asdu.smpCnt = buffer + bufPos;
+ break;
+
+ case 0x83:
+- asdu.confRev = buffer + bufPos;
++ if (elementLength != 4)
++ return invalidFieldSize("ConfRev", 4, elementLength);
++ else
++ asdu.confRev = buffer + bufPos;
+ break;
+
+ case 0x84:
+- asdu.refrTm = buffer + bufPos;
++ if (elementLength != 8)
++ return invalidFieldSize("RefrTm", 8, elementLength);
++ else
++ asdu.refrTm = buffer + bufPos;
+ break;
+
+ case 0x85:
+- asdu.smpSynch = buffer + bufPos;
++ if (elementLength != 1)
++ return invalidFieldSize("SmpSynch", 1, elementLength);
++ else
++ asdu.smpSynch = buffer + bufPos;
+ break;
+
+ case 0x86:
+- asdu.smpRate = buffer + bufPos;
++ if (elementLength != 2)
++ return invalidFieldSize("SmpRate", 2, elementLength);
++ else
++ asdu.smpRate = buffer + bufPos;
+ break;
+
+ case 0x87:
+@@ -485,7 +514,10 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ break;
+
+ case 0x88:
+- asdu.smpMod = buffer + bufPos;
++ if (elementLength != 1)
++ return invalidFieldSize("SmpMod", 1, elementLength);
++ else
++ asdu.smpMod = buffer + bufPos;
+ break;
+
+ default: /* ignore unknown tag */
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index c0e6efedd6..c0a3d1d29b 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -20,6 +20,9 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;
file://CVE-2026-18582.patch \
file://CVE-2026-18583.patch \
file://CVE-2026-19108.patch \
+ file://CVE-2026-19206-1.patch \
+ file://CVE-2026-19206-2.patch \
+ file://CVE-2026-19206-3.patch \
"
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (17 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 ankur.tyagi85
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commits[1][2] needed to cherry pick fix for the CVE as per the
release notes[3]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71226
[1]https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd
[2]https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311
[3]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libkcapi/libkcapi/CVE-2026-71226-1.patch | 604 ++++++++++++++++++
.../libkcapi/libkcapi/CVE-2026-71226-2.patch | 55 ++
.../libkcapi/libkcapi/CVE-2026-71226-3.patch | 93 +++
.../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 3 +
4 files changed, 755 insertions(+)
create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
new file mode 100644
index 0000000000..d53d29423c
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
@@ -0,0 +1,604 @@
+From 73a34808912e3cfea8d88f0a2c08fc0ed107a9d8 Mon Sep 17 00:00:00 2001
+From: Markus Theil <markus.theil@secunet.com>
+Date: Fri, 3 Apr 2026 15:06:53 +0200
+Subject: [PATCH] fixes found by analysis with LLM
+
+Signed-off-by: Markus Theil <markus.theil@secunet.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+(cherry picked from commit e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd)
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ apps/app-internal.c | 15 +++++++++---
+ apps/kcapi-dgst.c | 11 ++++++---
+ apps/kcapi-enc.c | 9 ++++---
+ apps/kcapi-hasher.c | 12 ++++++---
+ apps/kcapi-rng.c | 24 ++++++++++++------
+ configure.ac | 3 ++-
+ lib/kcapi-aead.c | 12 +++++++--
+ lib/kcapi-kdf.c | 6 +++--
+ lib/kcapi-kernel-if.c | 57 +++++++++++++++++++++++++++++--------------
+ lib/kcapi-kpp.c | 4 +--
+ lib/kcapi-md.c | 2 +-
+ lib/kcapi-sym.c | 6 +++++
+ lib/kcapi-utils.c | 7 ++++--
+ 13 files changed, 118 insertions(+), 50 deletions(-)
+
+diff --git a/apps/app-internal.c b/apps/app-internal.c
+index 7e01dd7..724b0b1 100644
+--- a/apps/app-internal.c
++++ b/apps/app-internal.c
+@@ -173,18 +173,24 @@ static uint8_t bin_char(char hex)
+ void hex2bin(const char *hex, uint32_t hexlen, uint8_t *bin, uint32_t binlen)
+ {
+ uint32_t i;
+- uint32_t chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen;
++ uint32_t chars;
+
+ /*
+ * handle odd-length of strings where the first digit is the least
+ * significant nibble
+ */
+ if (hexlen & 1) {
++ if (!binlen)
++ return;
+ bin[0] = bin_char(hex[0]);
+ bin++;
+ hex++;
++ hexlen--;
++ binlen--;
+ }
+
++ chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen;
++
+ for (i = 0; i < chars; i++) {
+ bin[i] = (uint8_t)(bin_char(hex[(i*2)]) << 4);
+ bin[i] |= bin_char(hex[((i*2)+1)]);
+@@ -238,13 +244,14 @@ ssize_t read_complete(int fd, uint8_t *buf, size_t buflen)
+ if (0 < ret) {
+ buflen -= (size_t)ret;
+ buf += ret;
++ rc += ret;
+ }
+- rc += ret;
+- if (ret)
+- break;
+ } while ((0 < ret || EINTR == errno || ERESTART == errno)
+ && buflen > 0);
+
++ if (ret < 0)
++ return -errno;
++
+ return rc;
+ }
+
+diff --git a/apps/kcapi-dgst.c b/apps/kcapi-dgst.c
+index 591a7fb..42d099c 100644
+--- a/apps/kcapi-dgst.c
++++ b/apps/kcapi-dgst.c
+@@ -128,6 +128,11 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ }
+
+ outlen = kcapi_md_digestsize(handle);
++ if (!outlen) {
++ dolog(KCAPI_LOG_ERR, "Cipher has zero digest size");
++ ret = -EINVAL;
++ goto out;
++ }
+
+ if (opts->hexout)
+ outlen *= 2;
+@@ -285,8 +290,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ }
+
+ while (j < saltbuflen) {
+- ret = kcapi_rng_generate(rng, saltbuf,
+- (size_t)saltbuflen);
++ ret = kcapi_rng_generate(rng, saltbuf + j,
++ (size_t)(saltbuflen - j));
+ if (ret < 0) {
+ kcapi_rng_destroy(rng);
+ free(saltbuf);
+@@ -320,7 +325,7 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ if (opts->key_fd != -1) {
+ ret = read_complete(opts->key_fd, keybuf, sizeof(keybuf));
+ if (ret < 0)
+- return (int)ret;
++ goto out;
+
+ have_key = 1;
+ keybuflen = (uint32_t)ret;
+diff --git a/apps/kcapi-enc.c b/apps/kcapi-enc.c
+index 68cf2f7..e7aa9db 100644
+--- a/apps/kcapi-enc.c
++++ b/apps/kcapi-enc.c
+@@ -218,7 +218,7 @@ static ssize_t return_data_fd(struct kcapi_handle *handle,
+ }
+
+ out:
+- munmap(outmem, outsize);
++ munmap(outmem, outsize + offset);
+ return (ret < 0) ? ret : generated_bytes;
+ }
+
+@@ -609,7 +609,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ }
+
+ /* Get data from file. */
+- } else {
++ } else if (insb.st_size) {
+ uint32_t sent_data = 0;
+
+ inmem = mmap(NULL, (size_t)insb.st_size, PROT_READ, MAP_SHARED,
+@@ -636,6 +636,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ * we will not apply padding.
+ */
+ if (!opts->decrypt &&
++ insb.st_size >= 2 &&
+ !(insb.st_size % opts->func_blocksize(handle)) &&
+ (uint32_t)padbyte < opts->func_blocksize(handle)) {
+ uint32_t i;
+@@ -803,8 +804,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ }
+
+ while (j < saltbuflen) {
+- ret = kcapi_rng_generate(rng, saltbuf,
+- saltbuflen);
++ ret = kcapi_rng_generate(rng, saltbuf + j,
++ saltbuflen - j);
+ if (ret < 0) {
+ kcapi_rng_destroy(rng);
+ free(saltbuf);
+diff --git a/apps/kcapi-hasher.c b/apps/kcapi-hasher.c
+index 217f59d..90dc34d 100644
+--- a/apps/kcapi-hasher.c
++++ b/apps/kcapi-hasher.c
+@@ -271,7 +271,7 @@ static int load_file(const char *filename, uint8_t **memory, off_t *size)
+ fprintf(stderr, "Key longer than UINT32_MAX\n");
+ ret = -ERANGE;
+ goto out;
+- } else if (buffer_size * 2 < buffer_size)
++ } else if (buffer_size > UINT32_MAX / 2)
+ buffer_size = UINT32_MAX;
+ else
+ buffer_size *= 2;
+@@ -340,7 +340,7 @@ static int hasher(struct kcapi_handle *handle, const struct hash_params *params,
+ } while (left);
+ munmap(memblock, mapped);
+ offset = offset + (off_t)mapped;
+- } while (offset ^ size);
++ } while (offset != size);
+ } else {
+ uint8_t tmpbuf[TMPBUFLEN] __aligned(KCAPI_APP_ALIGN);
+ uint32_t bufsize;
+@@ -647,11 +647,17 @@ static int process_checkfile(const struct hash_params *params,
+ hexhash = buf;
+
+ if (bsd_style) {
++ if (bsd_style > linelen) {
++ fprintf(stderr, "Invalid checkfile format\n");
++ ret = 1;
++ goto out;
++ }
++
+ /* Hash starts after separator */
+ hexhashlen = linelen - bsd_style + 1;
+
+ /* remove closing parenthesis behind filename */
+- if (buf[(bsd_style - 4)] == ')')
++ if (bsd_style >= 4 && buf[(bsd_style - 4)] == ')')
+ buf[(bsd_style - 4)] = '\0';
+ }
+
+diff --git a/apps/kcapi-rng.c b/apps/kcapi-rng.c
+index 9e025cd..46dab02 100644
+--- a/apps/kcapi-rng.c
++++ b/apps/kcapi-rng.c
+@@ -282,16 +282,18 @@ int main(int argc, char *argv[])
+ seedsize);
+
+ if (!isatty(0) && (errno == EINVAL || errno == ENOTTY)) {
+- while (fgets((char *)seedbuf, (int)seedsize, stdin)) {
+- ret = kcapi_rng_seed(rng, seedbuf, seedsize);
++ ssize_t rret;
++
++ while ((rret = read(STDIN_FILENO, seedbuf, seedsize)) > 0) {
++ ret = kcapi_rng_seed(rng, seedbuf, (uint32_t)rret);
+ if (ret)
+ dolog(KCAPI_LOG_WARN,
+- "User-provided seed of %lu bytes not accepted by DRNG (error: %ld)",
+- (unsigned long)sizeof(buf), ret);
++ "User-provided seed of %zd bytes not accepted by DRNG (error: %ld)",
++ rret, ret);
+ else
+ dolog(KCAPI_LOG_DEBUG,
+- "User-provided seed of %u bytes",
+- seedsize);
++ "User-provided seed of %zd bytes",
++ rret);
+ }
+ }
+
+@@ -312,9 +314,15 @@ int main(int argc, char *argv[])
+ char hexbuf[2 * KCAPI_RNG_BUFSIZE];
+
+ bin2hex(buf, (size_t)ret, hexbuf, sizeof(hexbuf), 0);
+- fwrite(hexbuf, 2 * (size_t)ret, 1, stdout);
++ if (fwrite(hexbuf, 2 * (size_t)ret, 1, stdout) != 1) {
++ ret = -EIO;
++ goto out;
++ }
+ } else {
+- fwrite(buf, (size_t)ret, 1, stdout);
++ if (fwrite(buf, (size_t)ret, 1, stdout) != 1) {
++ ret = -EIO;
++ goto out;
++ }
+ }
+
+ outlen -= (size_t)ret;
+diff --git a/configure.ac b/configure.ac
+index fbae4f9..446b8a8 100644
+--- a/configure.ac
++++ b/configure.ac
+@@ -14,16 +14,17 @@ m4_define([__KCAPI_MINVERSION], [5])
+ m4_define([__KCAPI_PATCHLEVEL], [0])
+ m4_define([KCAPI_VERSION], [__KCAPI_MAJVERSION.__KCAPI_MINVERSION.__KCAPI_PATCHLEVEL])
+
++AC_PREREQ([2.69])
+ AC_INIT([libkcapi], [KCAPI_VERSION])
+ AC_DEFINE([KCAPI_MAJVERSION], [__KCAPI_MAJVERSION])
+ AC_DEFINE([KCAPI_MINVERSION], [__KCAPI_MINVERSION])
+ AC_DEFINE([KCAPI_PATCHLEVEL], [__KCAPI_PATCHLEVEL])
++AC_CONFIG_MACRO_DIRS([m4])
+ AM_INIT_AUTOMAKE([foreign])
+ LT_INIT([pic-only])
+ AC_SUBST([LIBTOOL_DEPS])
+ AC_PROG_CC
+ AC_CONFIG_FILES([Makefile])
+-AC_CONFIG_MACRO_DIR([m4])
+ AX_PROG_CC_FOR_BUILD
+ AX_CHECK_PIE
+
+diff --git a/lib/kcapi-aead.c b/lib/kcapi-aead.c
+index b52dda0..3a7d711 100644
+--- a/lib/kcapi-aead.c
++++ b/lib/kcapi-aead.c
+@@ -566,7 +566,11 @@ size_t impl_aead_outbuflen_enc(struct kcapi_handle *handle,
+ {
+ struct kcapi_handle_tfm *tfm = handle->tfm;
+ uint32_t bs = tfm->info.blocksize;
+- size_t outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen;
++ size_t outlen;
++
++ if (!bs)
++ return 0;
++ outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen;
+
+ /* the kernel does not like zero length output buffers */
+ if (!outlen)
+@@ -591,7 +595,11 @@ size_t impl_aead_outbuflen_dec(struct kcapi_handle *handle,
+ {
+ struct kcapi_handle_tfm *tfm = handle->tfm;
+ uint32_t bs = tfm->info.blocksize;
+- size_t outlen = (inlen + bs - 1) / bs * bs + assoclen;
++ size_t outlen;
++
++ if (!bs)
++ return 0;
++ outlen = (inlen + bs - 1) / bs * bs + assoclen;
+
+ if (!handle->flags.ge_v4_9 == true)
+ outlen += taglen;
+diff --git a/lib/kcapi-kdf.c b/lib/kcapi-kdf.c
+index 54dc1ec..5f389b6 100644
+--- a/lib/kcapi-kdf.c
++++ b/lib/kcapi-kdf.c
+@@ -54,6 +54,8 @@
+ #include "kcapi.h"
+ #include "internal.h"
+
++#define MAX_DIGESTSIZE 64
++
+ #ifndef __has_builtin
+ # define __has_builtin(x) 0
+ #endif
+@@ -101,7 +103,7 @@ ssize_t impl_kdf_dpi(struct kcapi_handle *handle,
+ ssize_t err = 0;
+ uint8_t *dst_orig = dst;
+ size_t dlen_orig = dlen;
+- uint8_t Ai[h];
++ uint8_t Ai[MAX_DIGESTSIZE];
+ uint32_t i = 1;
+
+ if (dlen > INT_MAX)
+@@ -448,7 +450,7 @@ static inline uint64_t kcapi_get_time(void)
+ {
+ struct timespec time;
+
+- if (clock_gettime(CLOCK_REALTIME, &time) == 0)
++ if (clock_gettime(CLOCK_MONOTONIC, &time) == 0)
+ return (uint64_t)time.tv_nsec;
+
+ return 0;
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 835e45a..b37f0dc 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle,
+ }
+ header->cmsg_level = SOL_ALG;
+ header->cmsg_type = ALG_SET_IV;
+- header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size);
++ header->cmsg_len = CMSG_LEN(iv_msg_size);
+ alg_iv = (void*)CMSG_DATA(header);
+ alg_iv->ivlen = tfm->info.ivsize;
+ memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize);
+@@ -409,8 +409,10 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+ "AF_ALG: splice syscall returned %zd", ret);
+ }
+
++ if (ret == 0)
++ return -EPIPE;
+ processed += ret;
+- inlen -= (uint32_t)ret;
++ inlen -= (size_t)ret;
+ }
+
+ return processed;
+@@ -434,14 +436,17 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+
+ for (i = 0; i < rc; i++) {
+ struct iocb *cb;
++ unsigned int idx = (unsigned int)events[i].data;
++
++ if (idx >= KCAPI_AIO_CONCURRENT)
++ return -EOVERFLOW;
+
+ /*
+ * If one cipher operation fails, so will the entire
+ * AIO operation
+ */
+ if (events[i].res < 0) {
+- handle->aio.iocb_ret[events[i].data] =
+- events[i].res;
++ handle->aio.iocb_ret[idx] = events[i].res;
+ return (int)events[i].res;
+ }
+
+@@ -452,16 +457,15 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ * return code.
+ */
+ if (events[i].res > 0) {
+- handle->aio.iocb_ret[events[i].data] =
+- events[i].res;
++ handle->aio.iocb_ret[idx] = events[i].res;
+ } else {
+- handle->aio.iocb_ret[events[i].data] =
++ handle->aio.iocb_ret[idx] =
+ (__s64)cb->aio_nbytes;
+ }
+
+ cb->aio_fildes = 0;
+ }
+- toread -= (uint32_t)rc;
++ toread -= (size_t)rc;
+ }
+
+ return 0;
+@@ -613,7 +617,7 @@ ssize_t _kcapi_common_read_data(struct kcapi_handle *handle,
+ ret = read(*_kcapi_get_opfd(handle), out, outlen);
+ if (ret > 0) {
+ out += ret;
+- outlen -= (uint32_t)ret;
++ outlen -= (size_t)ret;
+ totallen += ret;
+ }
+ kcapi_dolog(KCAPI_LOG_DEBUG,
+@@ -722,13 +726,13 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ goto out;
+ }
+ if (addr_len != sizeof(nl)) {
+- ret = -errno;
++ ret = -EPROTO;
+ kcapi_dolog(KCAPI_LOG_ERR,
+ "Netlink error: wrong address length %d", addr_len);
+ goto out;
+ }
+ if (nl.nl_family != AF_NETLINK) {
+- ret = -errno;
++ ret = -EPROTO;
+ kcapi_dolog(KCAPI_LOG_ERR,
+ "Netlink error: wrong address family %d",
+ nl.nl_family);
+@@ -764,12 +768,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ goto out;
+ }
+ if (rc == 0) {
+- ret = -errno;
++ ret = -ENODATA;
+ kcapi_dolog(KCAPI_LOG_ERR, "Netlink error: no data");
+ goto out;
+ }
+ if (rc > (ssize_t)sizeof(buf)) {
+- ret = -errno;
++ ret = -EOVERFLOW;
+ kcapi_dolog(KCAPI_LOG_ERR,
+ "Netlink error: received too much data");
+ goto out;
+@@ -779,6 +783,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+
+ ret = -EFAULT;
+ res_len = res_n->nlmsg_len;
++ if (res_len > sizeof(buf)) {
++ kcapi_dolog(KCAPI_LOG_ERR,
++ "Netlink error: nlmsg_len %lu exceeds buffer",
++ res_len);
++ goto out;
++ }
+ if (res_n->nlmsg_type == NLMSG_ERROR) {
+ /*
+ * return -EAGAIN -- this error will occur if we received a
+@@ -819,6 +829,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+
+ if (tb[CRYPTOCFGA_REPORT_HASH]) {
+ struct rtattr *rta = tb[CRYPTOCFGA_REPORT_HASH];
++
++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_hash))
++ goto out;
+ struct crypto_report_hash *rsh =
+ (struct crypto_report_hash *) RTA_DATA(rta);
+ tfm->info.hash_digestsize = rsh->digestsize;
+@@ -831,6 +844,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ }
+ if (tb[CRYPTOCFGA_REPORT_BLKCIPHER]) {
+ struct rtattr *rta = tb[CRYPTOCFGA_REPORT_BLKCIPHER];
++
++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_blkcipher))
++ goto out;
+ struct crypto_report_blkcipher *rblk =
+ (struct crypto_report_blkcipher *) RTA_DATA(rta);
+ tfm->info.blocksize = rblk->blocksize;
+@@ -845,6 +861,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ }
+ if (tb[CRYPTOCFGA_REPORT_AEAD]) {
+ struct rtattr *rta = tb[CRYPTOCFGA_REPORT_AEAD];
++
++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_aead))
++ goto out;
+ struct crypto_report_aead *raead =
+ (struct crypto_report_aead *) RTA_DATA(rta);
+ tfm->info.blocksize = raead->blocksize;
+@@ -858,6 +877,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ }
+ if (tb[CRYPTOCFGA_REPORT_RNG]) {
+ struct rtattr *rta = tb[CRYPTOCFGA_REPORT_RNG];
++
++ if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_rng))
++ goto out;
+ struct crypto_report_rng *rrng =
+ (struct crypto_report_rng *) RTA_DATA(rta);
+ tfm->info.rng_seedsize = rrng->seedsize;
+@@ -981,19 +1003,19 @@ static int _kcapi_get_kernver(struct kcapi_handle *handle)
+ /* 3.15.0 */
+ res = strtok_r(kernel.release, ".", &saveptr);
+ if (!res) {
+- printf("Could not parse kernel version");
++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ return -EFAULT;
+ }
+ tfm->sysinfo.kernel_maj = strtoul(res, NULL, 10);
+ res = strtok_r(NULL, ".", &saveptr);
+ if (!res) {
+- printf("Could not parse kernel version");
++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ return -EFAULT;
+ }
+ tfm->sysinfo.kernel_minor = strtoul(res, NULL, 10);
+ res = strtok_r(NULL, ".", &saveptr);
+ if (!res) {
+- printf("Could not parse kernel version");
++ kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ return -EFAULT;
+ }
+ tfm->sysinfo.kernel_patchlevel = strtoul(res, NULL, 10);
+@@ -1217,7 +1239,6 @@ static int _kcapi_handle_init_tfm(struct kcapi_handle *handle, const char *type,
+
+ ret = _kcapi_common_getinfo(handle, ciphername);
+ if (ret) {
+- ret = -errno;
+ kcapi_dolog(KCAPI_LOG_ERR, "NETLINK_CRYPTO: cannot obtain cipher information for %s (is required crypto_user.c patch missing? see documentation)",
+ ciphername);
+ return ret;
+@@ -1368,7 +1389,7 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle,
+ in += inprocess;
+ inlen -= inprocess;
+ out += ret;
+- outlen -= (uint32_t)ret;
++ outlen -= (size_t)ret;
+ }
+
+ return totallen;
+diff --git a/lib/kcapi-kpp.c b/lib/kcapi-kpp.c
+index 814485a..d0383d6 100644
+--- a/lib/kcapi-kpp.c
++++ b/lib/kcapi-kpp.c
+@@ -52,12 +52,12 @@ int kcapi_kpp_ecdh_setcurve(struct kcapi_handle *handle,
+ unsigned long curve_id)
+ {
+ struct kcapi_handle_tfm *tfm = handle->tfm;
+- char curve_id_str[sizeof(unsigned long)];
++ char curve_id_str[24];
+ int ret = 0;
+
+ snprintf(curve_id_str, sizeof(curve_id_str), "%lu", curve_id);
+ ret = setsockopt(tfm->tfmfd, SOL_ALG, ALG_SET_ECDH_CURVE,
+- curve_id_str, sizeof(curve_id_str));
++ curve_id_str, (socklen_t)strlen(curve_id_str));
+ return (ret >= 0) ? ret : -errno;
+ }
+
+diff --git a/lib/kcapi-md.c b/lib/kcapi-md.c
+index bddd76b..5f493eb 100644
+--- a/lib/kcapi-md.c
++++ b/lib/kcapi-md.c
+@@ -196,7 +196,7 @@ ssize_t impl_md_sha256(const uint8_t *in, size_t inlen,
+ }
+
+ ORIG_SYMVER(md_sha256, "1.0.0")
+-ssize_t orig_md_sha256(const uint8_t *in, uint32_t inlen,
++int32_t orig_md_sha256(const uint8_t *in, uint32_t inlen,
+ uint8_t *out, uint32_t outlen)
+ {
+ return (int32_t)kcapi_md_conv_common("sha256", in, inlen, out, outlen);
+diff --git a/lib/kcapi-sym.c b/lib/kcapi-sym.c
+index 911ec1e..d500061 100644
+--- a/lib/kcapi-sym.c
++++ b/lib/kcapi-sym.c
+@@ -47,6 +47,9 @@ ssize_t impl_cipher_encrypt(struct kcapi_handle *handle,
+ struct kcapi_handle_tfm *tfm = handle->tfm;
+ uint32_t bs = tfm->info.blocksize;
+
++ if (!bs)
++ return -EINVAL;
++
+ /* require properly sized output data size */
+ if (outlen < ((inlen + bs - 1) / bs * bs))
+ kcapi_dolog(KCAPI_LOG_WARN,
+@@ -120,6 +123,9 @@ ssize_t impl_cipher_decrypt(struct kcapi_handle *handle,
+ {
+ struct kcapi_handle_tfm *tfm = handle->tfm;
+
++ if (!tfm->info.blocksize)
++ return -EINVAL;
++
+ /* require properly sized output data size */
+ if (inlen % tfm->info.blocksize)
+ kcapi_dolog(KCAPI_LOG_WARN,
+diff --git a/lib/kcapi-utils.c b/lib/kcapi-utils.c
+index 46fd330..e801d29 100644
+--- a/lib/kcapi-utils.c
++++ b/lib/kcapi-utils.c
+@@ -96,7 +96,7 @@ err:
+ } else {
+ kcapi_dolog(KCAPI_LOG_WARN,
+ "AF_ALG: setting maximum splice pipe size to %u failed: %s",
+- size, strerror(ret));
++ size, strerror(-ret));
+ }
+ return ret;
+ }
+@@ -109,7 +109,10 @@ int kcapi_get_maxsplicesize(struct kcapi_handle *handle)
+ return -EINVAL;
+
+ /* Both pipe endpoints should have the same pipe size */
+- handle->pipesize = (unsigned int)fcntl(handle->pipes[0], F_GETPIPE_SZ);
++ int ret = fcntl(handle->pipes[0], F_GETPIPE_SZ);
++ if (ret < 0)
++ return -errno;
++ handle->pipesize = (unsigned int)ret;
+
+ /*
+ * For vmsplice to allow the maximum number of 16 pages, we need to
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
new file mode 100644
index 0000000000..856d7a9879
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
@@ -0,0 +1,55 @@
+From 79198067bdf027f5d4d5e2804b086a0a37b277ec Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Fri, 3 Apr 2026 17:43:05 +0200
+Subject: [PATCH] fix kernel invocation
+
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+(cherry picked from commit d9f16d5fbcf8270110a8f6f35523525f345ca311)
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index b37f0dc..5d3b352 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle,
+ }
+ header->cmsg_level = SOL_ALG;
+ header->cmsg_type = ALG_SET_IV;
+- header->cmsg_len = CMSG_LEN(iv_msg_size);
++ header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size);
+ alg_iv = (void*)CMSG_DATA(header);
+ alg_iv->ivlen = tfm->info.ivsize;
+ memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize);
+@@ -411,6 +411,7 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+
+ if (ret == 0)
+ return -EPIPE;
++
+ processed += ret;
+ inlen -= (size_t)ret;
+ }
+@@ -436,7 +437,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+
+ for (i = 0; i < rc; i++) {
+ struct iocb *cb;
+- unsigned int idx = (unsigned int)events[i].data;
++ uint64_t idx = events[i].data;
+
+ if (idx >= KCAPI_AIO_CONCURRENT)
+ return -EOVERFLOW;
+@@ -459,8 +460,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ if (events[i].res > 0) {
+ handle->aio.iocb_ret[idx] = events[i].res;
+ } else {
+- handle->aio.iocb_ret[idx] =
+- (__s64)cb->aio_nbytes;
++ handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes;
+ }
+
+ cb->aio_fildes = 0;
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch
new file mode 100644
index 0000000000..591c32412b
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch
@@ -0,0 +1,93 @@
+From 8ab3c8939276848ec8f43156a7658f7c5dae4026 Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:36:32 +0200
+Subject: [PATCH] fix memory corruption
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 33 ++++++++++++++-------------------
+ 1 file changed, 14 insertions(+), 19 deletions(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 5d3b352..8a12c09 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -423,6 +423,8 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ struct timespec *timeout)
+ {
++ int err = 0;
++
+ if (toread > KCAPI_AIO_CONCURRENT)
+ return -EINVAL;
+
+@@ -433,34 +435,26 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ events, timeout);
+
+ if (rc < 0)
+- return rc;
++ return err == 0 ? rc : err;
+
+ for (i = 0; i < rc; i++) {
+ struct iocb *cb;
+ uint64_t idx = events[i].data;
+
+- if (idx >= KCAPI_AIO_CONCURRENT)
+- return -EOVERFLOW;
+-
+- /*
+- * If one cipher operation fails, so will the entire
+- * AIO operation
+- */
+- if (events[i].res < 0) {
+- handle->aio.iocb_ret[idx] = events[i].res;
+- return (int)events[i].res;
++ if (idx >= KCAPI_AIO_CONCURRENT) {
++ if (err == 0)
++ err = -EOVERFLOW;
++ continue;
+ }
+
+ cb = (struct iocb *)(uintptr_t)events[i].obj;
+
+- /*
+- * Older symmetric AIO implementations used a wrong
+- * return code.
+- */
+- if (events[i].res > 0) {
+- handle->aio.iocb_ret[idx] = events[i].res;
+- } else {
++ if (events[i].res == 0) {
+ handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes;
++ } else {
++ handle->aio.iocb_ret[idx] = events[i].res;
++ if (events[i].res < 0 && err == 0)
++ err = (int)events[i].res;
+ }
+
+ cb->aio_fildes = 0;
+@@ -468,7 +462,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ toread -= (size_t)rc;
+ }
+
+- return 0;
++ return err;
+ }
+
+ int _kcapi_aio_send_iov(struct kcapi_handle *handle, struct iovec *iov,
+@@ -544,6 +538,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle,
+ } else {
+ kcapi_dolog(KCAPI_LOG_ERR,
+ "Could not sumbit AIO read\n");
++ _kcapi_aio_read_all(handle, (size_t)ret, NULL);
+ return -EIO;
+ }
+ }
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index 532c9e29df..f2ddc25336 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -5,6 +5,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=3d8a091d797491204567185a6efce70f"
SRCREV = "fc937358e71253a6efaa3ba74885364976b040ea"
SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https \
+ file://CVE-2026-71226-1.patch \
+ file://CVE-2026-71226-2.patch \
+ file://CVE-2026-71226-3.patch \
"
inherit autotools
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (18 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 ankur.tyagi85
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit fixing the CVE as per the release notes[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71227
[1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libkcapi/libkcapi/CVE-2026-71227.patch | 40 +++++++++++++++++++
.../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 1 +
2 files changed, 41 insertions(+)
create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch
new file mode 100644
index 0000000000..6074c0da27
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch
@@ -0,0 +1,40 @@
+From d85279e3bec7578f8c238aec92539985c2032616 Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:38:10 +0200
+Subject: [PATCH] Fix potential infinite loop
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71227
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 8a12c09..a54cdaa 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -436,6 +436,8 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+
+ if (rc < 0)
+ return err == 0 ? rc : err;
++ if (rc == 0)
++ return err == 0 ? -ETIMEDOUT : err;
+
+ for (i = 0; i < rc; i++) {
+ struct iocb *cb;
+@@ -509,7 +511,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle,
+ timeout.tv_sec = 0;
+ timeout.tv_nsec = 10000;
+ ret = _kcapi_aio_read_all(handle, iovlen, &timeout);
+- if (ret < 0)
++ if (ret < 0 && ret != -ETIMEDOUT)
+ return ret;
+ }
+
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index f2ddc25336..f1fe6a0940 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -8,6 +8,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https
file://CVE-2026-71226-1.patch \
file://CVE-2026-71226-2.patch \
file://CVE-2026-71226-3.patch \
+ file://CVE-2026-71227.patch \
"
inherit autotools
^ permalink raw reply related [flat|nested] 22+ messages in thread* [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225
2026-09-03 9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
` (19 preceding siblings ...)
2026-09-03 9:49 ` [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 ankur.tyagi85
@ 2026-09-03 9:49 ` ankur.tyagi85
20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03 9:49 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit fixing the CVE as per the release notes[1]
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71225
[1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../libkcapi/libkcapi/CVE-2026-71225.patch | 38 +++++++++++++++++++
.../recipes-crypto/libkcapi/libkcapi_1.5.0.bb | 1 +
2 files changed, 39 insertions(+)
create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch
new file mode 100644
index 0000000000..8a2e4220e7
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch
@@ -0,0 +1,38 @@
+From ca418d6cc684057bcead18b3dd68d64cb3e156af Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:39:37 +0200
+Subject: [PATCH] Add safety measure to prevent IV reuse
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71225
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index a54cdaa..859ecdf 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -1387,6 +1387,15 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle,
+ inlen -= inprocess;
+ out += ret;
+ outlen -= (size_t)ret;
++
++ /*
++ * Clear the IV so subsequent chunks do not override the
++ * kernel's chained IV via ALG_SET_IV. The kernel updates
++ * its internal IV after each operation; by not sending
++ * ALG_SET_IV for later chunks, the next chunk continues
++ * where the previous one left off.
++ */
++ handle->cipher.iv = NULL;
+ }
+
+ return totallen;
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index f1fe6a0940..edc8c0e47a 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -9,6 +9,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https
file://CVE-2026-71226-2.patch \
file://CVE-2026-71226-3.patch \
file://CVE-2026-71227.patch \
+ file://CVE-2026-71225.patch \
"
inherit autotools
^ permalink raw reply related [flat|nested] 22+ messages in thread