Openembedded Devel Discussions
 help / color / mirror / Atom feed
* [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014
@ 2026-09-03  9:49 ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
                   ` (20 more replies)
  0 siblings, 21 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2025-49014

Fixes:
WARNING: jq-1.8.1-r0 do_sbom_cve_check_recipe: jq-1.8.1: Found unpatched CVEs: CVE-2025-49014

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 meta-oe/recipes-devtools/jq/jq_1.8.1.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb
index 5d2a1be398..9d4ae74c00 100644
--- a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb
+++ b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb
@@ -30,6 +30,8 @@ SRC_URI = "git://github.com/jqlang/jq.git;protocol=https;branch=master;tag=jq-${
            file://CVE-2026-39956.patch \
            "
 
+CVE_STATUS[CVE-2025-49014] = "fixed-version: fixed in v1.8.1"
+
 inherit autotools ptest
 
 UPSTREAM_CHECK_GITTAGREGEX = "${BPN}-(?P<pver>\d+(\.\d+)+)"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched ankur.tyagi85
                   ` (19 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-42798

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../lcms/lcms/CVE-2026-42798.patch            | 38 +++++++++++++++++++
 meta-oe/recipes-support/lcms/lcms_2.18.bb     |  1 +
 2 files changed, 39 insertions(+)
 create mode 100644 meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch

diff --git a/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch
new file mode 100644
index 0000000000..fa3f497be6
--- /dev/null
+++ b/meta-oe/recipes-support/lcms/lcms/CVE-2026-42798.patch
@@ -0,0 +1,38 @@
+From e05d3427b84028854177a417572e96543a40c3eb Mon Sep 17 00:00:00 2001
+From: Marti Maria <marti.maria@littlecms.com>
+Date: Thu, 19 Feb 2026 08:48:50 +0100
+Subject: [PATCH] Fix for ParseCube integer overflow in LUT allocation
+
+thanks to @zerojackyi for reporting
+
+(cherry picked from commit 6a686019825a89b715d16671f18d049523354176)
+
+CVE: CVE-2026-42798
+Upstream-Status: Backport [https://github.com/mm2/Little-CMS/commit/6a686019825a89b715d16671f18d049523354176]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/cmscgats.c | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/src/cmscgats.c b/src/cmscgats.c
+index 862eb91..7248d39 100644
+--- a/src/cmscgats.c
++++ b/src/cmscgats.c
+@@ -3180,7 +3180,16 @@ cmsBool ParseCube(cmsIT8* cube, cmsStage** Shaper, cmsStage** CLUT, char title[]
+ 
+             if (lut_size > 0) {
+ 
+-                int nodes = lut_size * lut_size * lut_size;
++                int nodes;
++                
++                /**
++                * Professional LUT‑generation tools (e.g., Nobe LutBake) list 65×65×65 as their highest supported size.                
++                */
++                if (lut_size > 65)
++                    return SynError(cube, "LUT size '%d' is over maximum of 65", lut_size);
++
++                nodes = lut_size * lut_size * lut_size;
++
+ 
+                 cmsFloat32Number* lut_table = (cmsFloat32Number*) _cmsMalloc(cube->ContextID, nodes * 3 * sizeof(cmsFloat32Number));
+                 if (lut_table == NULL) return FALSE;
diff --git a/meta-oe/recipes-support/lcms/lcms_2.18.bb b/meta-oe/recipes-support/lcms/lcms_2.18.bb
index 1ff3b3908f..501e1e2a79 100644
--- a/meta-oe/recipes-support/lcms/lcms_2.18.bb
+++ b/meta-oe/recipes-support/lcms/lcms_2.18.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e9ce323c4b71c943a785db90142b228a"
 SRC_URI = "${SOURCEFORGE_MIRROR}/lcms/lcms2-${PV}.tar.gz \
            file://CVE-2026-41254_1.patch \
            file://CVE-2026-41254_2.patch \
+           file://CVE-2026-42798.patch \
            "
 SRC_URI[sha256sum] = "ee67be3566f459362c1ee094fde2c159d33fa0390aa4ed5f5af676f9e5004347"
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 ankur.tyagi85
                   ` (18 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Release Note[1] also mentions fixed CVE.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-45382
https://nvd.nist.gov/vuln/detail/cve-2026-45383

[1] https://github.com/strukturag/libde265/releases/tag/v1.0.19

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index c5fbedb22a..54f158eef9 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -22,3 +22,6 @@ PACKAGECONFIG[libsdl] = "-DENABLE_SDL=ON,-DENABLE_SDL=OFF,virtual/libsdl2"
 FILES:${PN} += "${libdir}/libde265.so"
 FILES:${PN}-dev = "${includedir} ${libdir}/cmake ${libdir}/pkgconfig"
 INSANE_SKIP:${PN} = "dev-so"
+
+CVE_STATUS[CVE-2026-45382] = "fixed-version: fixed in v1.0.19"
+CVE_STATUS[CVE-2026-45383] = "fixed-version: fixed in v1.0.19"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 ankur.tyagi85
                   ` (17 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49295

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libde265/libde265/CVE-2026-49295.patch    | 41 +++++++++++++++++++
 .../libde265/libde265_1.0.19.bb               |  4 +-
 2 files changed, 44 insertions(+), 1 deletion(-)
 create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch

diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch
new file mode 100644
index 0000000000..189d330b9a
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49295.patch
@@ -0,0 +1,41 @@
+From 7d5e48dbf9324691ba3ce4cd8ffa089d735b0b70 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 25 May 2026 20:14:07 +0200
+Subject: [PATCH] bound aggregate short-term RPS size (GHSA-g2rg-wj66-w594)
+
+(cherry picked from commit 691f3a3c55b3d32478c4a49895dee061a282652b)
+
+CVE: CVE-2026-49295
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/refpic.cc | 16 ++++++++++++++++
+ 1 file changed, 16 insertions(+)
+
+diff --git a/libde265/refpic.cc b/libde265/refpic.cc
+index ea4db4b0..dcd2b214 100644
+--- a/libde265/refpic.cc
++++ b/libde265/refpic.cc
+@@ -322,6 +322,22 @@ bool read_short_term_ref_pic_set(error_queue* errqueue,
+ 
+   out_set->compute_derived_values();
+ 
++  // The unused short-term references are all collected into a single PocStFoll array
++  // of MAX_NUM_REF_PICS entries (see decoder_context::process_reference_picture_set).
++  // While each individual list is bounded above, the predicted-RPS construction can
++  // append the current-picture delta to an already-full source set, pushing the
++  // combined count past MAX_NUM_REF_PICS. Reject such sets to avoid an out-of-bounds
++  // write when filling PocStFoll.
++  if (out_set->NumDeltaPocs > MAX_NUM_REF_PICS) {
++    out_set->NumNegativePics = 0;
++    out_set->NumPositivePics = 0;
++    out_set->NumDeltaPocs = 0;
++    out_set->NumPocTotalCurr_shortterm_only = 0;
++
++    errqueue->add_warning(DE265_WARNING_MAX_NUM_REF_PICS_EXCEEDED, false);
++    return false;
++  }
++
+   return true;
+ }
+ 
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index 54f158eef9..b4f80d18a7 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -8,7 +8,9 @@ LICENSE = "LGPL-3.0-only & MIT"
 LICENSE_FLAGS = "commercial"
 LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
 
-SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV}"
+SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
+           file://CVE-2026-49295.patch \
+"
 SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
 
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (2 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 ankur.tyagi85
                   ` (16 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49337

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libde265/libde265/CVE-2026-49337.patch    | 53 +++++++++++++++++++
 .../libde265/libde265_1.0.19.bb               |  1 +
 2 files changed, 54 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch

diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch
new file mode 100644
index 0000000000..88e0e32949
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49337.patch
@@ -0,0 +1,53 @@
+From 2f0c53241cb9bf2f5acded53c25f1b74db536de7 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 25 May 2026 20:29:40 +0200
+Subject: [PATCH] free orphaned slice header when no active image unit
+ (GHSA-g5hj-rf9f-7vxm)
+
+(cherry picked from commit 683cb9fa603e35840642f98765ab95cdb71cadf9)
+
+CVE: CVE-2026-49337
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/decctx.cc | 12 ++++++++----
+ 1 file changed, 8 insertions(+), 4 deletions(-)
+
+diff --git a/libde265/decctx.cc b/libde265/decctx.cc
+index fbb3baa1..5deddc37 100644
+--- a/libde265/decctx.cc
++++ b/libde265/decctx.cc
+@@ -478,10 +478,6 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+     shdr->entry_point_offset[i] -= skipped;
+   }
+ 
+-  this->img->add_slice_segment_header(shdr);
+-
+-
+-
+   // --- start a new image if this is the first slice ---
+ 
+   if (shdr->first_slice_segment_in_pic_flag) {
+@@ -495,6 +491,13 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+ 
+   if ( ! image_units.empty() ) {
+ 
++    // Hand the slice header to the picture (which takes ownership and frees it
++    // on release). Only do this when there is an active image unit to decode
++    // the slice; otherwise the header would be retained on img->slices forever,
++    // which a crafted stream of non-first slice NALs can exploit to grow memory
++    // without bound.
++    this->img->add_slice_segment_header(shdr);
++
+     slice_unit* sliceunit = new slice_unit(this);
+     sliceunit->nal = nal;
+     sliceunit->shdr = shdr;
+@@ -507,6 +510,7 @@ de265_error decoder_context::read_slice_NAL(bitreader& reader, NAL_unit* nal, na
+   }
+   else {
+     nal_parser.free_NAL_unit(nal);
++    delete shdr;
+   }
+ 
+   bool did_work;
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index b4f80d18a7..bca5c9d776 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -10,6 +10,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
 
 SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
            file://CVE-2026-49295.patch \
+           file://CVE-2026-49337.patch \
 "
 SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (3 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 ankur.tyagi85
                   ` (15 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-49346

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libde265/libde265/CVE-2026-49346.patch    | 102 ++++++++++++++++++
 .../libde265/libde265_1.0.19.bb               |   1 +
 2 files changed, 103 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch

diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch
new file mode 100644
index 0000000000..288295b08a
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-49346.patch
@@ -0,0 +1,102 @@
+From 1667c33f2778a04f08ba4f7d6c1c16508350a779 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Tue, 26 May 2026 00:59:08 +0200
+Subject: [PATCH] fix integer overflow in image plane allocation size
+ (GHSA-vv8h-932h-7r86)
+
+(cherry picked from commit 8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8)
+
+CVE: CVE-2026-49346
+Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libde265/image.cc | 46 +++++++++++++++++++++++++++-------------------
+ 1 file changed, 27 insertions(+), 19 deletions(-)
+
+diff --git a/libde265/image.cc b/libde265/image.cc
+index 0b6071ba..94f3c974 100644
+--- a/libde265/image.cc
++++ b/libde265/image.cc
+@@ -70,10 +70,11 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx,
+                                            void* inputdata, int inputstride, void *userdata)
+ {
+   int alignment = STANDARD_ALIGNMENT;
+-  int stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment;
+-  int height = img->get_height(cIdx);
++  uint32_t stride = (img->get_width(cIdx) + alignment-1) / alignment * alignment;
++  uint32_t height = img->get_height(cIdx);
+ 
+-  uint8_t* p = static_cast<uint8_t*>(ALLOC_ALIGNED_16(stride * height + MEMORY_PADDING));
++  // size computed in size_t: stride*height can exceed UINT32_MAX for large planes
++  uint8_t* p = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(stride) * height + MEMORY_PADDING));
+ 
+   if (p==nullptr) { return nullptr; }
+ 
+@@ -82,12 +83,14 @@ LIBDE265_API void* de265_alloc_image_plane(struct de265_image* img, int cIdx,
+   // copy input data if provided
+ 
+   if (inputdata != nullptr) {
+-    if (inputstride == stride) {
+-      memcpy(p, inputdata, stride*height);
++    if (inputstride == static_cast<int>(stride)) {
++      memcpy(p, inputdata, static_cast<size_t>(stride) * height);
+     }
+     else {
+-      for (int y=0;y<height;y++) {
+-        memcpy(p+y*stride, static_cast<char*>(inputdata) + inputstride*y, inputstride);
++      for (uint32_t y=0;y<height;y++) {
++        memcpy(p + static_cast<size_t>(y) * stride,
++               static_cast<char*>(inputdata) + static_cast<size_t>(inputstride) * y,
++               inputstride);
+       }
+     }
+   }
+@@ -107,30 +110,35 @@ LIBDE265_API void de265_free_image_plane(struct de265_image* img, int cIdx)
+ static int  de265_image_get_buffer(de265_decoder_context* ctx,
+                                    de265_image_spec* spec, de265_image* img, void* userdata)
+ {
+-  const int rawChromaWidth  = spec->width  / img->SubWidthC;
+-  const int rawChromaHeight = spec->height / img->SubHeightC;
++  const uint32_t rawChromaWidth  = spec->width  / img->SubWidthC;
++  const uint32_t rawChromaHeight = spec->height / img->SubHeightC;
+ 
+-  int luma_stride   = (spec->width    + spec->alignment-1) / spec->alignment * spec->alignment;
+-  int chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment;
++  uint32_t luma_stride   = (spec->width    + spec->alignment-1) / spec->alignment * spec->alignment;
++  uint32_t chroma_stride = (rawChromaWidth + spec->alignment-1) / spec->alignment * spec->alignment;
+ 
+   assert(img->BitDepth_Y >= 8 && img->BitDepth_Y <= 16);
+   assert(img->BitDepth_C >= 8 && img->BitDepth_C <= 16);
+ 
+-  int luma_bpl   = luma_stride   * ((img->BitDepth_Y+7)/8);
+-  int chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8);
++  uint32_t luma_bpl   = luma_stride   * ((img->BitDepth_Y+7)/8);
++  uint32_t chroma_bpl = chroma_stride * ((img->BitDepth_C+7)/8);
+ 
+-  int luma_height   = spec->height;
+-  int chroma_height = rawChromaHeight;
++  uint32_t luma_height   = spec->height;
++  uint32_t chroma_height = rawChromaHeight;
+ 
+   bool alloc_failed = false;
+ 
+-  uint8_t* p[3] = { 0,0,0 };
+-  p[0] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(luma_height   * luma_bpl   + MEMORY_PADDING));
++  // Compute the plane sizes in size_t. Each operand fits in uint32_t, but the
++  // height * bytes-per-line product can exceed UINT32_MAX for large frames, so
++  // the multiplication must be done in 64 bits. Computing it in 32 bits wraps
++  // the allocation size to a small value while fill_image() later writes the
++  // real (size_t) size -> heap buffer overflow (GHSA-vv8h-932h-7r86).
++  uint8_t* p[3] = { nullptr,nullptr,nullptr };
++  p[0] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(luma_height) * luma_bpl + MEMORY_PADDING));
+   if (p[0]==nullptr) { alloc_failed=true; }
+ 
+   if (img->get_chroma_format() != de265_chroma_mono) {
+-    p[1] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING));
+-    p[2] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(chroma_height * chroma_bpl + MEMORY_PADDING));
++    p[1] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(chroma_height) * chroma_bpl + MEMORY_PADDING));
++    p[2] = static_cast<uint8_t*>(ALLOC_ALIGNED_16(static_cast<size_t>(chroma_height) * chroma_bpl + MEMORY_PADDING));
+ 
+     if (p[1]==nullptr || p[2]==nullptr) { alloc_failed=true; }
+   }
diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
index bca5c9d776..07d108b915 100644
--- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
+++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb
@@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=695b556799abb2435c97a113cdca512f"
 SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https;tag=v${PV} \
            file://CVE-2026-49295.patch \
            file://CVE-2026-49337.patch \
+           file://CVE-2026-49346.patch \
 "
 SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06"
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (4 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 ankur.tyagi85
                   ` (14 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40947

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb | 2 ++
 meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb         | 2 ++
 2 files changed, 4 insertions(+)

diff --git a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
index 7d9838b003..053d1f6d45 100644
--- a/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
+++ b/meta-oe/recipes-support/libfido2/libfido2-initial_1.16.0.bb
@@ -38,3 +38,5 @@ do_install() {
         ${S}/src/libfido2.pc.in > ${D}${datadir}/pkgconfig/libfido2.pc
 
 }
+
+CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows"
diff --git a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
index 09d34603d6..8595cbae81 100644
--- a/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
+++ b/meta-oe/recipes-support/libfido2/libfido2_1.16.0.bb
@@ -21,3 +21,5 @@ EXTRA_OECMAKE = "-DUDEV_RULES_DIR=${nonarch_base_libdir}/udev/rules.d -DBUILD_EX
 PACKAGE_BEFORE_PN = "${PN}-tools"
 
 FILES:${PN}-tools = "${bindir}/fido2-*"
+
+CVE_STATUS[CVE-2026-40947] = "not-applicable-platform: issue only applies on Windows"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (5 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 ankur.tyagi85
                   ` (13 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32738

[1]https://security-tracker.debian.org/tracker/CVE-2026-32738

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-32738.patch      | 32 +++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |  1 +
 2 files changed, 33 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch
new file mode 100644
index 0000000000..4308aa6195
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32738.patch
@@ -0,0 +1,32 @@
+From 95a7008c89335ca97fc22ab8caab5d62b077a34f Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Sat, 14 Mar 2026 20:32:39 +0100
+Subject: [PATCH] check that 'stsc' box does not have zero samples per chunk
+
+(cherry picked from commit bdaa37728442800497ea224bd232ca25e2f9bdff)
+
+CVE: CVE-2026-32738
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/bdaa37728442800497ea224bd232ca25e2f9bdff]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/seq_boxes.cc | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc
+index aec84fd5..91865848 100644
+--- a/libheif/sequences/seq_boxes.cc
++++ b/libheif/sequences/seq_boxes.cc
+@@ -875,6 +875,13 @@ Error Box_stsc::parse(BitstreamRange& range, const heif_security_limits* limits)
+     entry.samples_per_chunk = range.read32();
+     entry.sample_description_index = range.read32();
+ 
++    if (entry.samples_per_chunk == 0) {
++      return {
++        heif_error_Invalid_input,
++        heif_suberror_Unspecified,
++        "'stsc' box with zero samples per chunk entry."};
++    }
++
+     if (entry.sample_description_index == 0) {
+       return {
+       heif_error_Invalid_input,
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index ab29fa3b02..b238807fc5 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -8,6 +8,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null"
 
 SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \
            file://CVE-2026-3949.patch \
+           file://CVE-2026-32738.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (6 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 ankur.tyagi85
                   ` (12 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32739

[1]https://security-tracker.debian.org/tracker/CVE-2026-32739

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-32739.patch      | 54 +++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |  1 +
 2 files changed, 55 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch
new file mode 100644
index 0000000000..59cd793ef6
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32739.patch
@@ -0,0 +1,54 @@
+From 1c6fde64e37efa6031a6be2318dac62dfb38f370 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Fri, 13 Mar 2026 23:39:33 +0100
+Subject: [PATCH] fix infinite loop for sequences with variable frame-rate
+
+CVE: CVE-2026-32739
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/723b58d6ca329b2743822951aeaf3299c7410448]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/seq_boxes.cc | 22 ++++++++--------------
+ 1 file changed, 8 insertions(+), 14 deletions(-)
+
+diff --git a/libheif/sequences/seq_boxes.cc b/libheif/sequences/seq_boxes.cc
+index 91865848..39c2e8f4 100644
+--- a/libheif/sequences/seq_boxes.cc
++++ b/libheif/sequences/seq_boxes.cc
+@@ -621,14 +621,11 @@ Error Box_stts::write(StreamWriter& writer) const
+ 
+ uint32_t Box_stts::get_sample_duration(uint32_t sample_idx)
+ {
+-  size_t i = 0;
+-  while (i < m_entries.size()) {
+-    if (sample_idx < m_entries[i].sample_count) {
+-      return m_entries[i].sample_delta;
+-    }
+-    else {
+-      sample_idx -= m_entries[i].sample_count;
++  for (const auto& entry : m_entries) {
++    if (sample_idx < entry.sample_count) {
++      return entry.sample_delta;
+     }
++    sample_idx -= entry.sample_count;
+   }
+ 
+   return 0;
+@@ -813,14 +810,11 @@ Error Box_ctts::write(StreamWriter& writer) const
+ 
+ int32_t Box_ctts::get_sample_offset(uint32_t sample_idx)
+ {
+-  size_t i = 0;
+-  while (i < m_entries.size()) {
+-    if (sample_idx < m_entries[i].sample_count) {
+-      return m_entries[i].sample_offset;
+-    }
+-    else {
+-      sample_idx -= m_entries[i].sample_count;
++  for (const auto& entry : m_entries) {
++    if (sample_idx < entry.sample_count) {
++      return entry.sample_offset;
+     }
++    sample_idx -= entry.sample_count;
+   }
+ 
+   return 0;
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index b238807fc5..ba16ee7afe 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -9,6 +9,7 @@ COMPATIBLE_MACHINE:powerpc64le = "null"
 SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;tag=v${PV} \
            file://CVE-2026-3949.patch \
            file://CVE-2026-32738.patch \
+           file://CVE-2026-32739.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (7 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 ankur.tyagi85
                   ` (11 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1] to the original file which was
renamed by upstream commit[2].

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32740

[1]https://security-tracker.debian.org/tracker/CVE-2026-32740
[2]https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-32740.patch      | 40 +++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |  1 +
 2 files changed, 41 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch
new file mode 100644
index 0000000000..e6ce0e01f4
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32740.patch
@@ -0,0 +1,40 @@
+From eec74f24bf52764d870988bade74cd35075a09df Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 18 May 2026 18:03:01 +0200
+Subject: [PATCH] fix integer overflow when computing chroma sizes
+
+CVE: CVE-2026-32740
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/6721f307ad684804b735e917dde7d372c5faae31]
+
+Upstream commit[1] renamed libheif/pixelimage.cc as libheif/image/pixelimage.cc
+Backport changes to the original file.
+
+[1] https://github.com/strukturag/libheif/commit/f05c61ee8427ac3e39a3e5802a390b5aa99ae281
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/pixelimage.cc | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libheif/pixelimage.cc b/libheif/pixelimage.cc
+index a8ab7397..da62ea88 100644
+--- a/libheif/pixelimage.cc
++++ b/libheif/pixelimage.cc
+@@ -54,7 +54,7 @@ uint32_t chroma_width(uint32_t w, heif_chroma chroma)
+   switch (chroma) {
+     case heif_chroma_420:
+     case heif_chroma_422:
+-      return (w+1)/2;
++      return w/2 + (w & 1); // note: prevents integer overflow
+     default:
+       return w;
+   }
+@@ -64,7 +64,7 @@ uint32_t chroma_height(uint32_t h, heif_chroma chroma)
+ {
+   switch (chroma) {
+     case heif_chroma_420:
+-      return (h+1)/2;
++      return h/2 + (h & 1); // note: prevents integer overflow
+     default:
+       return h;
+   }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index ba16ee7afe..df7f0c56e1 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -10,6 +10,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
            file://CVE-2026-3949.patch \
            file://CVE-2026-32738.patch \
            file://CVE-2026-32739.patch \
+           file://CVE-2026-32740.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (8 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 ankur.tyagi85
                   ` (10 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-32741

[1]https://security-tracker.debian.org/tracker/CVE-2026-32741

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-32741.patch      | 29 +++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |  1 +
 2 files changed, 30 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch
new file mode 100644
index 0000000000..cd550aafa5
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-32741.patch
@@ -0,0 +1,29 @@
+From 3c38488fa2ea31928fcad8f6a5010c1f6f0c1ace Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Thu, 5 Mar 2026 19:00:57 +0100
+Subject: [PATCH] fix possible buffer overflow when reading mask image
+
+(cherry picked from commit 123694271ac02f2de68a3ccdc5d483eb8a2ae593)
+
+CVE: CVE-2026-32741
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/123694271ac02f2de68a3ccdc5d483eb8a2ae593]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/image-items/mask_image.cc | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/libheif/image-items/mask_image.cc b/libheif/image-items/mask_image.cc
+index 328d1797..1c4357ff 100644
+--- a/libheif/image-items/mask_image.cc
++++ b/libheif/image-items/mask_image.cc
+@@ -113,8 +113,8 @@ Error MaskImageCodec::decode_mask_image(const HeifContext* context,
+ 
+   size_t stride;
+   uint8_t* dst = img->get_plane(heif_channel_Y, &stride);
+-  if (((uint32_t)stride) == width) {
+-    memcpy(dst, data.data(), data.size());
++  if (stride == static_cast<size_t>(width)) {
++    memcpy(dst, data.data(), static_cast<size_t>(width) * height);
+   }
+   else
+   {
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index df7f0c56e1..92891cb5ef 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -11,6 +11,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
            file://CVE-2026-32738.patch \
            file://CVE-2026-32739.patch \
            file://CVE-2026-32740.patch \
+           file://CVE-2026-32741.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (9 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 ankur.tyagi85
                   ` (9 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1]
Also backport[2] which is needed to cherry-pick[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41071

[1]https://security-tracker.debian.org/tracker/CVE-2026-41071
[2]https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-41071-1.patch    | 34 ++++++++++++++
 .../libheif/libheif/CVE-2026-41071-2.patch    | 44 +++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |  2 +
 3 files changed, 80 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
new file mode 100644
index 0000000000..7971ea3cef
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-1.patch
@@ -0,0 +1,34 @@
+From 415b59839dcf46bb05e08de7422a21e65ab28e03 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 13 Apr 2026 19:49:06 +0200
+Subject: [PATCH] fix: reject malformed sequence files with saiz samples but no
+ chunks
+
+(cherry picked from commit 71755d3d41a117685a3274bdd1214fc50a760f20)
+
+CVE: CVE-2026-41071
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/track.cc | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc
+index acb916fa..ac5d5687 100644
+--- a/libheif/sequences/track.cc
++++ b/libheif/sequences/track.cc
+@@ -443,6 +443,14 @@ Error Track::load(const std::shared_ptr<Box_trak>& trak_box)
+         };
+       }
+ 
++      if (saio->get_num_chunks() != 1 && m_chunks.empty() && saiz->get_num_samples() > 0) {
++        return Error{
++          heif_error_Invalid_input,
++          heif_suberror_Unspecified,
++          "'saiz' box references samples but no chunks exist."
++        };
++      }
++
+       if (aux_info_type == fourcc("suid")) {
+         m_aux_reader_content_ids = std::make_unique<SampleAuxInfoReader>(saiz, saio, m_chunks);
+       }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch
new file mode 100644
index 0000000000..952c366966
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-41071-2.patch
@@ -0,0 +1,44 @@
+From b79d7d2a4f1502e93739453025ac2dbfd59e514f Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Mon, 13 Apr 2026 20:09:26 +0200
+Subject: [PATCH] fix: reject malformed sequence files where saiz sample count
+ exceeds actual samples
+
+(cherry picked from commit f20c81745e917b4c496615140385c86d7a2fa58d)
+CVE: CVE-2026-41071
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/sequences/track.cc | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/libheif/sequences/track.cc b/libheif/sequences/track.cc
+index ac5d5687..e4b08afa 100644
+--- a/libheif/sequences/track.cc
++++ b/libheif/sequences/track.cc
+@@ -138,7 +138,9 @@ SampleAuxInfoReader::SampleAuxInfoReader(std::shared_ptr<Box_saiz> saiz,
+     for (uint32_t i = 0; i < nSamples; i++) {
+       if (!oneChunk && i > chunks[current_chunk]->last_sample_number()) {
+         current_chunk++;
+-        assert(current_chunk < chunks.size());
++        if (current_chunk >= chunks.size()) {
++          break;
++        }
+         offset = saio->get_chunk_offset(current_chunk);
+       }
+ 
+@@ -451,6 +453,14 @@ Error Track::load(const std::shared_ptr<Box_trak>& trak_box)
+         };
+       }
+ 
++      if (saiz->get_num_samples() > m_stsz->num_samples()) {
++        return Error{
++          heif_error_Invalid_input,
++          heif_suberror_Unspecified,
++          "Number of samples in 'saiz' box exceeds actual number of samples."
++        };
++      }
++
+       if (aux_info_type == fourcc("suid")) {
+         m_aux_reader_content_ids = std::make_unique<SampleAuxInfoReader>(saiz, saio, m_chunks);
+       }
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index 92891cb5ef..f3f03abdc7 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -12,6 +12,8 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
            file://CVE-2026-32739.patch \
            file://CVE-2026-32740.patch \
            file://CVE-2026-32741.patch \
+           file://CVE-2026-41071-1.patch \
+           file://CVE-2026-41071-2.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (10 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 ankur.tyagi85
                   ` (8 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit identified by Debian[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-62289

[1]https://security-tracker.debian.org/tracker/CVE-2026-62289

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-62289.patch      | 189 ++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |   1 +
 2 files changed, 190 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch
new file mode 100644
index 0000000000..5473a2ae18
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62289.patch
@@ -0,0 +1,189 @@
+From 49e188ca7a6a81fd1c7d5e76254308c82cbcb5c3 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Thu, 25 Jun 2026 19:58:57 +0200
+Subject: [PATCH] Fix clap transform double-application in image tiling
+ (GHSA-jc8f-p23p-5hjg)
+
+The base ImageItem::get_heif_image_tiling() returned the already
+transformed m_width/m_height, but process_image_transformations_on_tiling()
+applies the transformative properties (irot, imir, clap) itself. This
+applied every transform twice. For a clap that rounds the image down to
+zero, the second application passed 0 into Box_clap::left_rounded(), where
+`image_width - 1U` underflowed to UINT32_MAX and overflowed the Fraction
+constructor (assert abort in debug builds, corrupt crop in release builds).
+The grid, unc and tiled overrides already return coded dimensions, so the
+base class was the lone outlier.
+
+Fixes, in three layers:
+
+ - image_item.cc: base get_heif_image_tiling() now reports coded (ispe)
+   dimensions when available, matching the other overrides, so transforms
+   are applied exactly once. This also fixes a silent irot/imir
+   double-transform on the same path.
+ - context.cc: reject a clap that rounds a dimension to zero or less at
+   parse time, mirroring the existing ispe zero-size check.
+ - box.cc: guard left_rounded()/top_rounded() against a zero image
+   dimension as defense in depth.
+
+Add tests/clap_zero_size.cc covering the hardened clap helpers.
+
+(cherry picked from commit f01870c1d7323a3003796d58eba7fff502be994c)
+
+CVE: CVE-2026-62289
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/box.cc                    | 11 ++++++++
+ libheif/context.cc                | 12 +++++++--
+ libheif/image-items/image_item.cc | 23 ++++++++++++++---
+ tests/CMakeLists.txt              |  1 +
+ tests/clap_zero_size.cc           | 42 +++++++++++++++++++++++++++++++
+ 5 files changed, 83 insertions(+), 6 deletions(-)
+ create mode 100644 tests/clap_zero_size.cc
+
+diff --git a/libheif/box.cc b/libheif/box.cc
+index 76ba0f0a..57912ab0 100644
+--- a/libheif/box.cc
++++ b/libheif/box.cc
+@@ -3592,6 +3592,12 @@ int Box_clap::left_rounded(uint32_t image_width) const
+ 
+   // left = horizOff + (width-1)/2 - (clapWidth-1)/2
+ 
++  // Guard against image_width==0: `image_width - 1U` would underflow to
++  // UINT32_MAX and overflow the Fraction (GHSA-jc8f-p23p-5hjg).
++  if (image_width == 0) {
++    return 0;
++  }
++
+   Fraction pcX = m_horizontal_offset + Fraction(image_width - 1U, 2U);
+   Fraction left = pcX - (m_clean_aperture_width - 1) / 2;
+ 
+@@ -3607,6 +3613,11 @@ int Box_clap::right_rounded(uint32_t image_width) const
+ 
+ int Box_clap::top_rounded(uint32_t image_height) const
+ {
++  // Guard against image_height==0 underflowing the Fraction (see left_rounded).
++  if (image_height == 0) {
++    return 0;
++  }
++
+   Fraction pcY = m_vertical_offset + Fraction(image_height - 1U, 2U);
+   Fraction top = pcY - (m_clean_aperture_height - 1) / 2;
+ 
+diff --git a/libheif/context.cc b/libheif/context.cc
+index a1bcc268..a3371207 100644
+--- a/libheif/context.cc
++++ b/libheif/context.cc
+@@ -644,8 +644,16 @@ Error HeifContext::interpret_heif_file_images()
+     for (const auto& prop : properties) {
+       auto clap = std::dynamic_pointer_cast<Box_clap>(prop);
+       if (clap) {
+-        image->set_resolution(clap->get_width_rounded(),
+-                              clap->get_height_rounded());
++        int clap_width = clap->get_width_rounded();
++        int clap_height = clap->get_height_rounded();
++        if (clap_width <= 0 || clap_height <= 0) {
++          return {heif_error_Invalid_input,
++                  heif_suberror_Invalid_clean_aperture,
++                  "Clean aperture (clap) reduces image to zero size"};
++        }
++
++        image->set_resolution(static_cast<uint32_t>(clap_width),
++                              static_cast<uint32_t>(clap_height));
+ 
+         if (image->has_intrinsic_matrix()) {
+           image->get_intrinsic_matrix().apply_clap(clap.get(), image->get_width(), image->get_height());
+diff --git a/libheif/image-items/image_item.cc b/libheif/image-items/image_item.cc
+index e803107f..d05536e1 100644
+--- a/libheif/image-items/image_item.cc
++++ b/libheif/image-items/image_item.cc
+@@ -967,10 +967,25 @@ heif_image_tiling ImageItem::get_heif_image_tiling() const
+   tiling.num_columns = 1;
+   tiling.num_rows = 1;
+ 
+-  tiling.tile_width = m_width;
+-  tiling.tile_height = m_height;
+-  tiling.image_width = m_width;
+-  tiling.image_height = m_height;
++  // Report the coded (pre-transformation) dimensions here. The caller applies
++  // the transformative properties (irot, imir, clap) via
++  // process_image_transformations_on_tiling(), so handing it the already
++  // transformed m_width/m_height would apply them a second time. For a clap
++  // that shrinks the image to zero this double application underflowed inside
++  // Box_clap::left_rounded() (GHSA-jc8f-p23p-5hjg); for irot/imir it silently
++  // produced wrong dimensions. The grid/unc/tiled overrides likewise report
++  // coded dimensions.
++  uint32_t coded_width = m_width;
++  uint32_t coded_height = m_height;
++  if (has_ispe_resolution()) {
++    coded_width = get_ispe_width();
++    coded_height = get_ispe_height();
++  }
++
++  tiling.tile_width = coded_width;
++  tiling.tile_height = coded_height;
++  tiling.image_width = coded_width;
++  tiling.image_height = coded_height;
+ 
+   tiling.top_offset = 0;
+   tiling.left_offset = 0;
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index d8fdfd8b..b52bc202 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -38,6 +38,7 @@ if (WITH_REDUCED_VISIBILITY)
+ else()
+     add_libheif_test(bitstream_tests)
+     add_libheif_test(box_equals)
++    add_libheif_test(clap_zero_size)
+     add_libheif_test(conversion)
+     add_libheif_test(idat)
+     add_libheif_test(jpeg2000)
+diff --git a/tests/clap_zero_size.cc b/tests/clap_zero_size.cc
+new file mode 100644
+index 00000000..eafc1258
+--- /dev/null
++++ b/tests/clap_zero_size.cc
+@@ -0,0 +1,42 @@
++/*
++  libheif clean aperture (clap) zero-size unit tests
++
++  MIT License
++
++  Copyright (c) 2026 Dirk Farin <dirk.farin@gmail.com>
++
++  Permission is hereby granted, free of charge, to any person obtaining a copy
++  of this software and associated documentation files (the "Software"), to deal
++  in the Software without restriction, including without limitation the rights
++  to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
++  copies of the Software, and to permit persons to whom the Software is
++  furnished to do so, subject to the following conditions:
++
++  The above copyright notice and this permission notice shall be included in all
++  copies or substantial portions of the Software.
++
++  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
++  IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
++  FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
++  AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
++  LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
++  OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
++  SOFTWARE.
++*/
++
++#include "catch_amalgamated.hpp"
++#include "box.h"
++
++// Regression test for GHSA-jc8f-p23p-5hjg: passing a zero image dimension to
++// the clap rounding helpers used to underflow `image_width - 1U` to UINT32_MAX,
++// which overflowed the Fraction constructor (assert abort in debug builds,
++// corrupt crop in release builds). They must now return 0 without aborting.
++TEST_CASE("clap rounding with zero image size") {
++  std::shared_ptr<Box_clap> clap = std::make_shared<Box_clap>();
++  clap->set(100, 200, 150, 250);  // clap 100x200 inside a 150x250 image
++
++  REQUIRE(clap->left_rounded(0) == 0);
++  REQUIRE(clap->right_rounded(0) == 99);    // clapWidth - 1 + left(0)
++  REQUIRE(clap->top_rounded(0) == 0);
++  REQUIRE(clap->bottom_rounded(0) == 199);  // clapHeight - 1 + top(0)
++}
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index f3f03abdc7..1dfab46513 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -14,6 +14,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
            file://CVE-2026-32741.patch \
            file://CVE-2026-41071-1.patch \
            file://CVE-2026-41071-2.patch \
+           file://CVE-2026-62289.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (11 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched ankur.tyagi85
                   ` (7 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/CVE-2026-62377

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libheif/libheif/CVE-2026-62377.patch      | 175 ++++++++++++++++++
 .../libheif/libheif_1.21.2.bb                 |   1 +
 2 files changed, 176 insertions(+)
 create mode 100644 meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch

diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch
new file mode 100644
index 0000000000..5481c198b6
--- /dev/null
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif/CVE-2026-62377.patch
@@ -0,0 +1,175 @@
+From cace54a7491cd8eb46617f17ca7078182d9903b0 Mon Sep 17 00:00:00 2001
+From: Dirk Farin <dirk.farin@gmail.com>
+Date: Fri, 26 Jun 2026 10:03:31 +0200
+Subject: [PATCH] Return error instead of asserting in get_track() without
+ sequence (#1844)
+
+HeifContext::get_track() asserted has_sequence() up front. Calling the
+public heif_context_get_track() on a context that has no sequence tracks
+(e.g. a still image, or a crafted sequence file accepted with zero tracks)
+therefore aborted the process via the assert, instead of letting the public
+wrapper return the documented nullptr. In NDEBUG builds the assert was
+compiled out and the track_id==0 path dereferenced begin() on an empty map.
+
+Replace the assert with a normal error return so the public wrapper hands
+the caller nullptr as documented.
+
+(cherry picked from commit e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3)
+
+CVE: CVE-2026-62377
+Upstream-Status: Backport [https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ libheif/context.cc         |   9 +++-
+ tests/CMakeLists.txt       |   1 +
+ tests/sequence_no_track.cc | 108 +++++++++++++++++++++++++++++++++++++
+ 3 files changed, 117 insertions(+), 1 deletion(-)
+ create mode 100644 tests/sequence_no_track.cc
+
+diff --git a/libheif/context.cc b/libheif/context.cc
+index a3371207..170f8314 100644
+--- a/libheif/context.cc
++++ b/libheif/context.cc
+@@ -1945,7 +1945,14 @@ std::vector<uint32_t> HeifContext::get_track_IDs() const
+ 
+ Result<std::shared_ptr<Track>> HeifContext::get_track(uint32_t track_id)
+ {
+-  assert(has_sequence());
++  // The caller is expected to have confirmed (via has_sequence()) that there are
++  // sequence tracks before requesting one. Guard against an empty track map anyway,
++  // since this is reachable through the public API (e.g. on a still image file).
++  if (!has_sequence()) {
++    return Error{heif_error_Usage_error,
++                 heif_suberror_Unspecified,
++                 "File contains no sequence tracks"};
++  }
+ 
+   if (track_id != 0) {
+     auto iter = m_tracks.find(track_id);
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index b52bc202..d66ffb38 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -59,6 +59,7 @@ endif()
+ add_libheif_test(encode)
+ add_libheif_test(extended_type)
+ add_libheif_test(region)
++add_libheif_test(sequence_no_track)
+ add_libheif_test(tai)
+ add_libheif_test(text)
+ add_libheif_test(cxx_wrapper)
+diff --git a/tests/sequence_no_track.cc b/tests/sequence_no_track.cc
+new file mode 100644
+index 00000000..cde11f77
+--- /dev/null
++++ b/tests/sequence_no_track.cc
+@@ -0,0 +1,108 @@
++/*
++  libheif regression test for requesting a track from a context without sequence tracks.
++
++  MIT License
++
++  Copyright (c) 2026 Dirk Farin <dirk.farin@gmail.com>
++
++  Permission is hereby granted, free of charge, to any person obtaining a copy
++  of this software and associated documentation files (the "Software"), to deal
++  in the Software without restriction, including without limitation the rights
++  to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
++  copies of the Software, and to permit persons to whom the Software is
++  furnished to do so, subject to the following conditions:
++
++  The above copyright notice and this permission notice shall be included in all
++  copies or substantial portions of the Software.
++
++  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
++  IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
++  FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
++  AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
++  LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
++  OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
++  SOFTWARE.
++*/
++
++#include "catch_amalgamated.hpp"
++#include "libheif/heif.h"
++#include "libheif/heif_sequences.h"
++#include "test_utils.h"
++
++#include <cstdint>
++#include <vector>
++
++namespace {
++
++// Sequence API queries that must work on a context that holds no sequence
++// tracks (a still image, or no image at all). heif_context_get_track() is
++// documented to return nullptr on failure; it must not abort/crash. This
++// formerly tripped assert(has_sequence()) in HeifContext::get_track().
++// See https://github.com/strukturag/libheif/issues/1844.
++void check_no_sequence_apis(heif_context* ctx)
++{
++  REQUIRE(heif_context_has_sequence(ctx) == 0);
++  REQUIRE(heif_context_number_of_sequence_tracks(ctx) == 0);
++
++  // Listing track IDs must work (and write nothing) when there are no tracks.
++  heif_context_get_track_ids(ctx, nullptr);
++
++  heif_track* track = heif_context_get_track(ctx, 0);
++  REQUIRE(track == nullptr);
++}
++
++heif_error mem_writer(heif_context*, const void* data, size_t size, void* userdata)
++{
++  auto* out = static_cast<std::vector<uint8_t>*>(userdata);
++  const auto* p = static_cast<const uint8_t*>(data);
++  out->insert(out->end(), p, p + size);
++  return heif_error{heif_error_Ok, heif_suberror_Unspecified, nullptr};
++}
++
++}
++
++TEST_CASE("get_track on context without sequence returns nullptr")
++{
++  heif_context* ctx = heif_context_alloc();
++  REQUIRE(ctx != nullptr);
++
++  // Fresh context, nothing loaded: no sequence tracks present.
++  check_no_sequence_apis(ctx);
++
++  heif_context_free(ctx);
++}
++
++TEST_CASE("get_track on a still-image file returns nullptr")
++{
++  // Encode a tiny still image to an in-memory HEIF file, then read it back.
++  // A still image is a perfectly valid file that contains no sequence tracks.
++  heif_image* img = nullptr;
++  REQUIRE(heif_image_create(16, 16, heif_colorspace_YCbCr, heif_chroma_420, &img).code == heif_error_Ok);
++  fill_new_plane(img, heif_channel_Y, 16, 16);
++  fill_new_plane(img, heif_channel_Cb, 8, 8);
++  fill_new_plane(img, heif_channel_Cr, 8, 8);
++
++  heif_encoder* enc = get_encoder_or_skip_test(heif_compression_HEVC);
++
++  heif_context* enc_ctx = heif_context_alloc();
++  REQUIRE(heif_context_encode_image(enc_ctx, img, enc, nullptr, nullptr).code == heif_error_Ok);
++
++  std::vector<uint8_t> file;
++  heif_writer writer{};
++  writer.writer_api_version = 1;
++  writer.write = mem_writer;
++  REQUIRE(heif_context_write(enc_ctx, &writer, &file).code == heif_error_Ok);
++
++  heif_encoder_release(enc);
++  heif_context_free(enc_ctx);
++  heif_image_release(img);
++
++  // Read the still image back and query the sequence API on it.
++  heif_context* ctx = heif_context_alloc();
++  REQUIRE(ctx != nullptr);
++  REQUIRE(heif_context_read_from_memory(ctx, file.data(), file.size(), nullptr).code == heif_error_Ok);
++
++  check_no_sequence_apis(ctx);
++
++  heif_context_free(ctx);
++}
diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
index 1dfab46513..165ed0ad2a 100644
--- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
+++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb
@@ -15,6 +15,7 @@ SRC_URI = "git://github.com/strukturag/libheif.git;protocol=https;branch=master;
            file://CVE-2026-41071-1.patch \
            file://CVE-2026-41071-2.patch \
            file://CVE-2026-62289.patch \
+           file://CVE-2026-62377.patch \
            "
 
 SRCREV = "62f1b8c76ed4d8305071fdacbe74ef9717bacac5"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (12 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 ankur.tyagi85
                   ` (6 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

NVD[1] mentions commit[2] for v1.5 but is also present in v1.6[3]

[1] https://nvd.nist.gov/vuln/detail/cve-2024-45969
[2] https://github.com/mz-automation/libiec61850/commit/7afa40390b26ad1f4cf93deaa0052fe7e357ef33
[3] https://github.com/mz-automation/libiec61850/commit/d1ab50298fcba3f87b1e58dabff92f8615b14ee7

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../recipes-connectivity/libiec61850/libiec61850_1.6.1.bb       | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index c46ed88d83..5a76ba5330 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -35,3 +35,5 @@ FILES:${PN} += " \
     ${PYTHON_SITEPACKAGES_DIR}/pyiec61850.py \
     ${PYTHON_SITEPACKAGES_DIR}/_pyiec61850.so \
 "
+
+CVE_STATUS[CVE-2024-45969] = "fixed-version: fixed since v1.6.0"


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (13 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 ankur.tyagi85
                   ` (5 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-18582

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libiec61850/files/CVE-2026-18582.patch    | 51 +++++++++++++++++++
 .../libiec61850/libiec61850_1.6.1.bb          |  1 +
 2 files changed, 52 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch

diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch
new file mode 100644
index 0000000000..6fcd1662b9
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18582.patch
@@ -0,0 +1,51 @@
+From 43aa106301639f2afddf11302d25e84c5482e26c Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 16 Jun 2026 19:24:12 +0100
+Subject: [PATCH] - MMS server: fixed - oversized RptID written to RCB can
+ trigger invalid free when reports are sent later
+ (LIB61850-561)(GHSA-7qg8-hm25-rv5v)
+
+(cherry picked from commit 5b2a69f44256b8548927d8afdd7ac5f5381abe1e)
+
+CVE: CVE-2026-18582
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/iec61850/server/mms_mapping/reporting.c | 9 +++++++--
+ 1 file changed, 7 insertions(+), 2 deletions(-)
+
+diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c
+index 2a230c28..a44f0583 100644
+--- a/src/iec61850/server/mms_mapping/reporting.c
++++ b/src/iec61850/server/mms_mapping/reporting.c
+@@ -557,7 +557,6 @@ updateSingleTrackingValue(MmsMapping* self, ReportControl* rc, const char* name,
+                 attributeToUpdate = trkInst->resv;
+             else if (!strcmp(name, "DatSet"))
+             {
+-
+                 char datSet[130];
+                 const char* datSetStr = MmsValue_toString(newValue);
+ 
+@@ -2664,6 +2663,12 @@ Reporting_RCBWriteAccessHandler(MmsMapping* self, ReportControl* rc, const char*
+                 goto exit_function;
+             }
+ 
++            if (MmsValue_getStringSize(value) > 129)
++            {
++                retVal = DATA_ACCESS_ERROR_OBJECT_VALUE_INVALID;
++                goto exit_function;
++            }
++
+ #if (CONFIG_MMS_THREADLESS_STACK != 1)
+             Semaphore_wait(rc->rcbValuesLock);
+ #endif
+@@ -3677,7 +3682,7 @@ sendNextReportEntrySegment(ReportControl* self)
+ 
+     const char* rptIdStr = MmsValue_toString(rptIdFromRcb);
+ 
+-    if (rptIdStr[0] == 0)
++    if (rptIdStr[0] == 0 || MmsValue_getStringSize(rptIdFromRcb) > 129)
+     {
+         /* use default rptId when RptID is empty in RCB */
+         updateWithDefaultRptId(self, &rptId);
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index 5a76ba5330..b22d8a09c9 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -17,6 +17,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8"
 
 SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \
            file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
+           file://CVE-2026-18582.patch \
 "
 
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (14 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 ankur.tyagi85
                   ` (4 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-18583

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libiec61850/files/CVE-2026-18583.patch    | 35 +++++++++++++++++++
 .../libiec61850/libiec61850_1.6.1.bb          |  1 +
 2 files changed, 36 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch

diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch
new file mode 100644
index 0000000000..8acf7e1465
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-18583.patch
@@ -0,0 +1,35 @@
+From c8baade187e1c31ac9e9ca71dced5a46765d97b2 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 16 Jun 2026 18:23:52 +0100
+Subject: [PATCH] - MMS server: fixed - potential crash in access control check
+ handler for association and vmd specific data sets
+ (LIB61850-560)(GHSA-7v2x-39mw-2979)
+
+(cherry picked from commit 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d)
+
+CVE: CVE-2026-18583
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/iec61850/server/mms_mapping/mms_mapping.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c
+index e5e6b034..5620f63f 100644
+--- a/src/iec61850/server/mms_mapping/mms_mapping.c
++++ b/src/iec61850/server/mms_mapping/mms_mapping.c
+@@ -3807,11 +3807,11 @@ checkDataSetAccess(MmsMapping* self, MmsServerConnection connection, MmsVariable
+         if (listType == MMS_ASSOCIATION_SPECIFIC)
+         {
+             dataSetRef[0] = '@';
+-            StringUtils_copyStringToBuffer(dataSetRef + 1, listName);
++            StringUtils_copyStringMax(dataSetRef + 1, 129, listName);
+         }
+         else if (listType == MMS_VMD_SPECIFIC)
+         {
+-            StringUtils_copyStringToBuffer(dataSetRef, listName);
++            StringUtils_copyStringMax(dataSetRef, 129, listName);
+         }
+         else if (listType == MMS_DOMAIN_SPECIFIC)
+         {
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index b22d8a09c9..408b4d2d11 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -18,6 +18,7 @@ SRCREV = "a13961110b8238d2d8ea577c1fb7592ba3017ad8"
 SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;tag=v${PV} \
            file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
            file://CVE-2026-18582.patch \
+           file://CVE-2026-18583.patch \
 "
 
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (15 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 ankur.tyagi85
                   ` (3 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-19108

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libiec61850/files/CVE-2026-19108.patch    | 208 ++++++++++++++++++
 .../libiec61850/libiec61850_1.6.1.bb          |   1 +
 2 files changed, 209 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch

diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch
new file mode 100644
index 0000000000..673ce29af0
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19108.patch
@@ -0,0 +1,208 @@
+From 846bd407527061665a3c109eaa6ee7e870ae6bc1 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 21 Jul 2026 10:26:33 +0000
+Subject: [PATCH] - MMS server: fixed - Update URCB that used an association
+ specific dataset of another connection can cause heap-use-after-free
+ (LIB61850-577)(#596) - fixed bitbucket sonarcloud pipeline
+
+(cherry picked from commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168)
+
+CVE: CVE-2026-19108
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ bitbucket-pipelines.yml                       | 11 +++----
+ src/iec61850/inc_private/reporting.h          |  1 +
+ src/iec61850/server/mms_mapping/mms_mapping.c | 29 +++++++++++++++++--
+ src/iec61850/server/mms_mapping/reporting.c   | 17 +++++++----
+ .../iso_mms/server/mms_server_connection.c    | 19 ++++++++++++
+ 5 files changed, 65 insertions(+), 12 deletions(-)
+
+diff --git a/bitbucket-pipelines.yml b/bitbucket-pipelines.yml
+index a7493663..30dce281 100644
+--- a/bitbucket-pipelines.yml
++++ b/bitbucket-pipelines.yml
+@@ -1,4 +1,4 @@
+-image:  atlassian/default-image:4
++image:  atlassian/default-image:5
+ 
+ clone:
+   depth: full              # SonarCloud scanner needs the full history to assign issues properly
+@@ -12,12 +12,13 @@ definitions:
+         caches:
+           - sonar
+         script:
+-          - export SONAR_SCANNER_VERSION=5.0.1.3006
+-          - export SONAR_SCANNER_OPTS="-Dsonar.javaHome=/usr/lib/jvm/java-17-openjdk-amd64"
+-          - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux
++          - export SONAR_SCANNER_VERSION=6.2.1.4610
++          - export SONAR_SCANNER_HOME=$HOME/.sonar/sonar-scanner-$SONAR_SCANNER_VERSION-linux-x64
+           - export BW_OUTPUT=$HOME/.sonar/bw-output
+           - mkdir -p $BW_OUTPUT
+-          - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux.zip
++          - apt-get update -qq
++          - apt-get install openjdk-21-jre cmake -y
++          - curl --create-dirs -sSLo $HOME/.sonar/sonar-scanner.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$SONAR_SCANNER_VERSION-linux-x64.zip
+           - unzip -o $HOME/.sonar/sonar-scanner.zip -d $HOME/.sonar/
+           - export PATH=$SONAR_SCANNER_HOME/bin:$PATH
+           - curl --create-dirs -sSLo $HOME/.sonar/build-wrapper-linux-x86.zip https://sonarcloud.io/static/cpp/build-wrapper-linux-x86.zip
+diff --git a/src/iec61850/inc_private/reporting.h b/src/iec61850/inc_private/reporting.h
+index eddeb2d1..bc23f937 100644
+--- a/src/iec61850/inc_private/reporting.h
++++ b/src/iec61850/inc_private/reporting.h
+@@ -67,6 +67,7 @@ typedef struct {
+     bool buffered; /* true if report is a buffered report */
+ 
+     MmsValue** bufferedDataSetValues; /* used to buffer values during bufTm time */
++    int bufferedDataSetValuesSize; /* number of dataset entries */
+ 
+     MmsValue** valueReferences; /* array to store value references for fast access */
+ 
+diff --git a/src/iec61850/server/mms_mapping/mms_mapping.c b/src/iec61850/server/mms_mapping/mms_mapping.c
+index 5620f63f..ef6f3580 100644
+--- a/src/iec61850/server/mms_mapping/mms_mapping.c
++++ b/src/iec61850/server/mms_mapping/mms_mapping.c
+@@ -3912,6 +3912,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+             {
+                 ReportControl* rc = (ReportControl*) rcElement->data;
+ 
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++                Semaphore_wait(rc->rcbValuesLock);
++#endif
++
+                 if (rc->isDynamicDataSet)
+                 {
+                     if (rc->dataSet != NULL)
+@@ -3924,6 +3928,11 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+                                 {
+                                     if (strcmp(rc->dataSet->logicalDeviceName, MmsDomain_getName(domain) + strlen(self->model->name)) == 0)
+                                     {
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++                                        Semaphore_post(rc->rcbValuesLock);
++#endif
++
++                                        /* dataset is in use and cannot be deleted */
+                                         allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+                                         break;
+                                     }
+@@ -3936,6 +3945,10 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+                             {
+                                 if (strcmp(rc->dataSet->name, listName) == 0)
+                                 {
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++                                    Semaphore_post(rc->rcbValuesLock);
++#endif
++                                    /* dataset is in use and cannot be deleted */
+                                     allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+                                     break;
+                                 }
+@@ -3947,13 +3960,22 @@ variableListAccessHandler (void* parameter, MmsVariableListAccessType accessType
+                             {
+                                 if (strcmp(rc->dataSet->name, listName) == 0)
+                                 {
+-                                    allow = MMS_ERROR_SERVICE_OBJECT_CONSTRAINT_CONFLICT;
+-                                    break;
++                                    /* this is usually called when the connection is closed -> RCB has already been disabled by connection handler */
++
++                                    MmsMapping_freeDynamicallyCreatedDataSet(rc->dataSet);
++
++                                    /* cleanup dataset information in RCB instance */
++                                    rc->dataSet = NULL;
++                                    rc->isDynamicDataSet = false;
+                                 }
+                             }
+                         }
+                     }
+                 }
++
++#if (CONFIG_MMS_THREADLESS_STACK != 1)
++                Semaphore_post(rc->rcbValuesLock);
++#endif
+             }
+ 
+ #if (CONFIG_IEC61850_LOG_SERVICE == 1)
+@@ -4729,6 +4751,9 @@ MmsMapping_getDomainSpecificDataSet(MmsMapping* self, const char* dataSetName)
+ void
+ MmsMapping_freeDynamicallyCreatedDataSet(DataSet* dataSet)
+ {
++    if (dataSet == NULL)
++        return;
++
+     DataSetEntry* dataSetEntry = dataSet->fcdas;
+ 
+     while (dataSetEntry)
+diff --git a/src/iec61850/server/mms_mapping/reporting.c b/src/iec61850/server/mms_mapping/reporting.c
+index a44f0583..03add555 100644
+--- a/src/iec61850/server/mms_mapping/reporting.c
++++ b/src/iec61850/server/mms_mapping/reporting.c
+@@ -193,13 +193,9 @@ deleteDataSetValuesShadowBuffer(ReportControl* self)
+ {
+     if (self->bufferedDataSetValues != NULL)
+     {
+-        assert(self->dataSet != NULL);
+-
+-        int dataSetSize = DataSet_getSize(self->dataSet);
+-
+         int i;
+ 
+-        for (i = 0; i < dataSetSize; i++)
++        for (i = 0; i < self->bufferedDataSetValuesSize; i++)
+         {
+             if (self->bufferedDataSetValues[i] != NULL)
+                 MmsValue_delete(self->bufferedDataSetValues[i]);
+@@ -698,13 +694,24 @@ static void
+ createDataSetValuesShadowBuffer(ReportControl* rc)
+ {
+     int dataSetSize = DataSet_getSize(rc->dataSet);
++    rc->bufferedDataSetValuesSize = dataSetSize;
+ 
+     MmsValue** dataSetValues = (MmsValue**)GLOBAL_CALLOC(dataSetSize, sizeof(MmsValue*));
+ 
++    if (dataSetValues == NULL)
++        return;
++
+     rc->bufferedDataSetValues = dataSetValues;
+ 
+     rc->valueReferences = (MmsValue**)GLOBAL_MALLOC(dataSetSize * sizeof(MmsValue*));
+ 
++    if (rc->valueReferences == NULL)
++    {
++        GLOBAL_FREEMEM(dataSetValues);
++        rc->bufferedDataSetValues = NULL;
++        return;
++    }
++
+     DataSetEntry* dataSetEntry = rc->dataSet->fcdas;
+ 
+     int i;
+diff --git a/src/mms/iso_mms/server/mms_server_connection.c b/src/mms/iso_mms/server/mms_server_connection.c
+index 644fcdb1..401ad40b 100644
+--- a/src/mms/iso_mms/server/mms_server_connection.c
++++ b/src/mms/iso_mms/server/mms_server_connection.c
+@@ -829,6 +829,25 @@ MmsServerConnection_destroy(MmsServerConnection self)
+ #endif
+ 
+ #if (MMS_DYNAMIC_DATA_SETS == 1)
++    /* notify IEC 61850 layer BEFORE destroying named variable lists */
++    if (self->namedVariableLists)
++    {
++        LinkedList element = LinkedList_getNext(self->namedVariableLists);
++
++        while (element)
++        {
++            MmsNamedVariableList variableList = (MmsNamedVariableList)element->data;
++
++            if (variableList && variableList->name)
++            {
++                mmsServer_callVariableListChangedHandler(MMS_VARLIST_DELETE, MMS_ASSOCIATION_SPECIFIC,
++                                                            NULL, /* domain (NULL for aa-specific) */
++                                                            variableList->name, self);
++            }
++            element = LinkedList_getNext(element);
++        }
++    }
++
+     LinkedList_destroyDeep(self->namedVariableLists, (LinkedListValueDeleteFunction) MmsNamedVariableList_destroy);
+ #endif
+ 
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index 408b4d2d11..c0e6efedd6 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -19,6 +19,7 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;
            file://0001-pyiec61850-Use-CMAKE_INSTALL_LIBDIR-from-GNUInstallD.patch \
            file://CVE-2026-18582.patch \
            file://CVE-2026-18583.patch \
+           file://CVE-2026-19108.patch \
 "
 
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (16 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 ankur.tyagi85
                   ` (2 subsequent siblings)
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commits[1][2] in order to cherry pick fix mentioned in NVD.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-19206

[1]https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c
[2]https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libiec61850/files/CVE-2026-19206-1.patch  | 129 +++++++++++++++++
 .../libiec61850/files/CVE-2026-19206-2.patch  | 134 ++++++++++++++++++
 .../libiec61850/files/CVE-2026-19206-3.patch  | 115 +++++++++++++++
 .../libiec61850/libiec61850_1.6.1.bb          |   3 +
 4 files changed, 381 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
 create mode 100644 meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch

diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
new file mode 100644
index 0000000000..b7b86b3f64
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-1.patch
@@ -0,0 +1,129 @@
+From 04f95bf3e54614122621b520eac29dea160de1c7 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Tue, 17 Mar 2026 12:41:32 +0000
+Subject: [PATCH] - fixed memory-safety issues and potential NULL pointer
+ dereferenciations in SV parser (#585)
+
+(cherry picked from commit c85175ddf7018beb753d85a740d4c2c77f61c96c)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/c85175ddf7018beb753d85a740d4c2c77f61c96c]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/sampled_values/sv_subscriber.c | 35 +++++++++++++++++++++++-------
+ 1 file changed, 27 insertions(+), 8 deletions(-)
+
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index 221eb1a8..bb82818e 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -423,16 +423,24 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+             return;
+         }
+ 
++        if (bufPos + elementLength > length)
++        {
++            if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: Malformed message: element length exceeds buffer length!\n");
++            return;
++        }
++
+         switch (tag)
+         {
+         case 0x80:
+             asdu.svId = (char*) (buffer + bufPos);
+             svIdLength = elementLength;
++            asdu.svId[svIdLength] = 0;
+             break;
+ 
+         case 0x81:
+             asdu.datSet = (char*) (buffer + bufPos);
+             datSetLength = elementLength;
++            asdu.datSet[datSetLength] = 0;
+             break;
+ 
+         case 0x82:
+@@ -471,22 +479,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ 
+         bufPos += elementLength;
+     }
+-
+-    if (asdu.svId != NULL)
+-        asdu.svId[svIdLength] = 0;
+-    if (asdu.datSet != NULL)
+-        asdu.datSet[datSetLength] = 0;
+     
+     if (DEBUG_SV_SUBSCRIBER)
+     {
+         printf("SV_SUBSCRIBER:   SV ASDU: ----------------\n");
+         printf("SV_SUBSCRIBER:     DataLength: %d\n", asdu.dataBufferLength);
+-        printf("SV_SUBSCRIBER:     SvId: %s\n", asdu.svId);
++        printf("SV_SUBSCRIBER:     SvId: %s\n", asdu.svId ? asdu.svId : "(empty)");
+         printf("SV_SUBSCRIBER:     SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu));
+         printf("SV_SUBSCRIBER:     ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu));
+         
+         if (SVSubscriber_ASDU_hasDatSet(&asdu))
+-            printf("SV_SUBSCRIBER:     DatSet: %s\n", asdu.datSet);
++            printf("SV_SUBSCRIBER:     DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)");
+ 
+         if (SVSubscriber_ASDU_hasRefrTm(&asdu))
+ #ifndef _MSC_VER
+@@ -598,7 +601,8 @@ exit_error:
+ static void
+ handleSVApdu(SVReceiver self, uint16_t appId, uint8_t* apdu, int apduLength, uint8_t* dstAddr)
+ {
+-    if (DEBUG_SV_SUBSCRIBER) {
++    if (DEBUG_SV_SUBSCRIBER)
++    {
+         printf("SV_SUBSCRIBER: SV message: ----------------\n");
+         printf("SV_SUBSCRIBER:   APPID: %u\n", appId);
+         printf("SV_SUBSCRIBER:   APDU length: %i\n", apduLength);
+@@ -791,6 +795,9 @@ SVSubscriber_setListener(SVSubscriber self,  SVUpdateListener listener, void* pa
+ uint8_t
+ SVSubscriber_ASDU_getSmpSynch(SVSubscriber_ASDU self)
+ {
++    if (self->smpSynch == NULL)
++        return 0;
++
+     return self->smpSynch[0];
+ }
+ 
+@@ -800,6 +807,9 @@ SVSubscriber_ASDU_getSmpCnt(SVSubscriber_ASDU self)
+     uint16_t retVal;
+     uint8_t* valBytes = (uint8_t*) &retVal;
+ 
++    if (self->smpCnt == NULL)
++        return 0;
++
+ #if (ORDER_LITTLE_ENDIAN == 1)
+     valBytes[0] = self->smpCnt[1];
+     valBytes[1] = self->smpCnt[0];
+@@ -912,6 +922,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self)
+ {
+     uint32_t retVal;
+ 
++    if (self->confRev == NULL)
++        return 0;
++
+ #if (ORDER_LITTLE_ENDIAN == 1)
+     memcpy_reverse(&retVal, self->confRev, sizeof(uint32_t));
+ #else
+@@ -924,6 +937,9 @@ SVSubscriber_ASDU_getConfRev(SVSubscriber_ASDU self)
+ uint8_t
+ SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self)
+ {
++    if (self->smpMod == NULL)
++        return 0;
++
+     uint8_t retVal = *((uint8_t*) (self->smpMod));
+ 
+     return retVal;
+@@ -932,6 +948,9 @@ SVSubscriber_ASDU_getSmpMod(SVSubscriber_ASDU self)
+ uint16_t
+ SVSubscriber_ASDU_getSmpRate(SVSubscriber_ASDU self)
+ {
++    if (self->smpRate == NULL)
++        return 0;
++
+     uint16_t retVal;
+ 
+ #if (ORDER_LITTLE_ENDIAN == 1)
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
new file mode 100644
index 0000000000..e39cc3e17a
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-2.patch
@@ -0,0 +1,134 @@
+From 62741cc994ae02ef95e664b9470a22089788cff4 Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Wed, 17 Jun 2026 12:22:34 +0100
+Subject: [PATCH] - SV subscriber: fixed - null terminator for svId and datSet
+ overwrites tag and can cause OOB write (LIB61850-563)
+
+(cherry picked from commit 6178540e8cdd26b7884a482905140cc9084966a1)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/6178540e8cdd26b7884a482905140cc9084966a1]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ .../sv_subscriber/sv_subscriber_example.c     |  4 ++
+ src/sampled_values/sv_subscriber.c            | 56 ++++++++++++++-----
+ 2 files changed, 46 insertions(+), 14 deletions(-)
+
+diff --git a/examples/sv_subscriber/sv_subscriber_example.c b/examples/sv_subscriber/sv_subscriber_example.c
+index 0e3ff720..6487052b 100644
+--- a/examples/sv_subscriber/sv_subscriber_example.c
++++ b/examples/sv_subscriber/sv_subscriber_example.c
+@@ -30,6 +30,10 @@ svUpdateListener (SVSubscriber subscriber, void* parameter, SVSubscriber_ASDU as
+     if (svID != NULL)
+         printf("  svID=(%s)\n", svID);
+ 
++    const char* dataSet = SVSubscriber_ASDU_getDatSet(asdu);
++    if (dataSet != NULL)
++        printf("  dataSet=(%s)\n", dataSet);
++
+     printf("  smpCnt: %i\n", SVSubscriber_ASDU_getSmpCnt(asdu));
+     printf("  confRev: %u\n", SVSubscriber_ASDU_getConfRev(asdu));
+ 
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index bb82818e..97f881f6 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -81,8 +81,12 @@ struct sSVSubscriber
+ 
+ struct sSVSubscriber_ASDU
+ {
+-    char* svId;
+-    char* datSet;
++    char svIdBuf[130];   /* copy of svId - only copied when the user requests the svId */
++    char datSetBuf[130]; /* copy of datSet - only copied when the user requests the datSet */
++    char* svId;          /* pointer to the start of the svId in the ASDU buffer */
++    char* datSet;        /* pointer to the start of the datSet in the ASDU buffer */
++    uint8_t svIdSize;    /* size of the svId in the ASDU buffer */
++    uint8_t datSetSize;  /* size of the datSet in the ASDU buffer */
+ 
+     uint8_t* smpCnt;
+     uint8_t* confRev;
+@@ -432,15 +436,27 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+         switch (tag)
+         {
+         case 0x80:
+-            asdu.svId = (char*) (buffer + bufPos);
+-            svIdLength = elementLength;
+-            asdu.svId[svIdLength] = 0;
++            if (elementLength > 129)
++            {
++                if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n");
++            }
++            else
++            {
++                asdu.svId = (char*) (buffer + bufPos);
++                asdu.svIdSize = elementLength;
++            }
+             break;
+ 
+         case 0x81:
+-            asdu.datSet = (char*) (buffer + bufPos);
+-            datSetLength = elementLength;
+-            asdu.datSet[datSetLength] = 0;
++            if (elementLength > 129)
++            {
++                if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n");
++            }
++            else
++            {
++                asdu.datSet = (char*) (buffer + bufPos);
++                asdu.datSetSize = elementLength;
++            }
+             break;
+ 
+         case 0x82:
+@@ -479,17 +495,17 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ 
+         bufPos += elementLength;
+     }
+-    
++
+     if (DEBUG_SV_SUBSCRIBER)
+     {
+         printf("SV_SUBSCRIBER:   SV ASDU: ----------------\n");
+         printf("SV_SUBSCRIBER:     DataLength: %d\n", asdu.dataBufferLength);
+-        printf("SV_SUBSCRIBER:     SvId: %s\n", asdu.svId ? asdu.svId : "(empty)");
++        printf("SV_SUBSCRIBER:     SvId: %s\n", SVSubscriber_ASDU_getSvId(&asdu));
+         printf("SV_SUBSCRIBER:     SmpCnt: %u\n", SVSubscriber_ASDU_getSmpCnt(&asdu));
+         printf("SV_SUBSCRIBER:     ConfRev: %u\n", SVSubscriber_ASDU_getConfRev(&asdu));
+-        
++
+         if (SVSubscriber_ASDU_hasDatSet(&asdu))
+-            printf("SV_SUBSCRIBER:     DatSet: %s\n", asdu.datSet ? asdu.datSet : "(empty)");
++            printf("SV_SUBSCRIBER:     DatSet: %s\n", SVSubscriber_ASDU_getDatSet(&asdu));
+ 
+         if (SVSubscriber_ASDU_hasRefrTm(&asdu))
+ #ifndef _MSC_VER
+@@ -899,13 +915,25 @@ SVSubscriber_ASDU_hasSmpMod(SVSubscriber_ASDU self)
+ const char*
+ SVSubscriber_ASDU_getSvId(SVSubscriber_ASDU self)
+ {
+-    return self->svId;
++    if (self->svId == NULL)
++        return NULL;
++
++    memcpy(self->svIdBuf, self->svId, self->svIdSize);
++    self->svIdBuf[self->svIdSize] = 0; /* ensure null termination */
++
++    return self->svIdBuf;
+ }
+ 
+ const char*
+ SVSubscriber_ASDU_getDatSet(SVSubscriber_ASDU self)
+ {
+-    return self->datSet;
++    if (self->datSet == NULL)
++        return NULL;
++
++    memcpy(self->datSetBuf, self->datSet, self->datSetSize);
++    self->datSetBuf[self->datSetSize] = 0; /* ensure null termination */
++
++    return self->datSetBuf;
+ }
+ 
+ static inline void
diff --git a/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch
new file mode 100644
index 0000000000..75e476c6c5
--- /dev/null
+++ b/meta-networking/recipes-connectivity/libiec61850/files/CVE-2026-19206-3.patch
@@ -0,0 +1,115 @@
+From 03841913e3b8220f1ceb2ab5493bc31b769113bd Mon Sep 17 00:00:00 2001
+From: Michael Zillgith <michael.zillgith@mz-automation.de>
+Date: Wed, 1 Jul 2026 11:32:34 +0100
+Subject: [PATCH] - SV subscriber: fixed missing length validation of some ASDU
+ elements that can cause OOB reads when these fields are later used by the
+ application (LIB61850-574)
+
+(cherry picked from commit a96bd674e0238276dd1387d31d52e55229d0771e)
+
+CVE: CVE-2026-19206
+Upstream-Status: Backport [https://github.com/mz-automation/libiec61850/commit/a96bd674e0238276dd1387d31d52e55229d0771e]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/sampled_values/sv_subscriber.c | 48 +++++++++++++++++++++++++-----
+ 1 file changed, 40 insertions(+), 8 deletions(-)
+
+diff --git a/src/sampled_values/sv_subscriber.c b/src/sampled_values/sv_subscriber.c
+index 97f881f6..55422d87 100644
+--- a/src/sampled_values/sv_subscriber.c
++++ b/src/sampled_values/sv_subscriber.c
+@@ -402,6 +402,20 @@ SVReceiver_stopThreadless(SVReceiver self)
+     self->running = false;
+ }
+ 
++static void
++invalidFieldSize(const char* fieldName, int expectedSize, int actualSize)
++{
++    if (DEBUG_SV_SUBSCRIBER)
++        printf("SV_SUBSCRIBER: Invalid %s size: expected %d, got %d\n", fieldName, expectedSize, actualSize);
++}
++
++static void
++fieldTooLong(const char* fieldName, int maxSize, int actualSize)
++{
++    if (DEBUG_SV_SUBSCRIBER)
++        printf("SV_SUBSCRIBER: %s too long: max %d, got %d\n", fieldName, maxSize, actualSize);
++}
++
+ static void
+ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+ {
+@@ -438,7 +452,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+         case 0x80:
+             if (elementLength > 129)
+             {
+-                if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: svId too long!\n");
++                return fieldTooLong("svId", 129, elementLength);
+             }
+             else
+             {
+@@ -450,7 +464,7 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+         case 0x81:
+             if (elementLength > 129)
+             {
+-                if (DEBUG_SV_SUBSCRIBER) printf("SV_SUBSCRIBER: datSet too long!\n");
++                return fieldTooLong("datSet", 129, elementLength);
+             }
+             else
+             {
+@@ -460,23 +474,38 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+             break;
+ 
+         case 0x82:
+-            asdu.smpCnt = buffer + bufPos;
++            if (elementLength != 2)
++                return invalidFieldSize("SmpCnt", 2, elementLength);
++            else
++                asdu.smpCnt = buffer + bufPos;
+             break;
+ 
+         case 0x83:
+-            asdu.confRev = buffer + bufPos;
++            if (elementLength != 4)
++                return invalidFieldSize("ConfRev", 4, elementLength);
++            else
++                asdu.confRev = buffer + bufPos;
+             break;
+ 
+         case 0x84:
+-            asdu.refrTm = buffer + bufPos;
++            if (elementLength != 8)
++                return invalidFieldSize("RefrTm", 8, elementLength);
++            else
++                asdu.refrTm = buffer + bufPos;
+             break;
+ 
+         case 0x85:
+-            asdu.smpSynch = buffer + bufPos;
++            if (elementLength != 1)
++                return invalidFieldSize("SmpSynch", 1, elementLength);
++            else
++                asdu.smpSynch = buffer + bufPos;
+             break;
+ 
+         case 0x86:
+-            asdu.smpRate = buffer + bufPos;
++            if (elementLength != 2)
++                return invalidFieldSize("SmpRate", 2, elementLength);
++            else
++                asdu.smpRate = buffer + bufPos;
+             break;
+ 
+         case 0x87:
+@@ -485,7 +514,10 @@ parseASDU(SVReceiver self, SVSubscriber subscriber, uint8_t* buffer, int length)
+             break;
+ 
+         case 0x88:
+-            asdu.smpMod = buffer + bufPos;
++            if (elementLength != 1)
++                return invalidFieldSize("SmpMod", 1, elementLength);
++            else
++                asdu.smpMod = buffer + bufPos;
+             break;
+ 
+         default: /* ignore unknown tag */
diff --git a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
index c0e6efedd6..c0a3d1d29b 100644
--- a/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
+++ b/meta-networking/recipes-connectivity/libiec61850/libiec61850_1.6.1.bb
@@ -20,6 +20,9 @@ SRC_URI = "git://github.com/mz-automation/${BPN}.git;branch=v1.6;protocol=https;
            file://CVE-2026-18582.patch \
            file://CVE-2026-18583.patch \
            file://CVE-2026-19108.patch \
+           file://CVE-2026-19206-1.patch \
+           file://CVE-2026-19206-2.patch \
+           file://CVE-2026-19206-3.patch \
 "
 
 


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (17 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 ankur.tyagi85
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commits[1][2] needed to cherry pick fix for the CVE as per the
release notes[3]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71226

[1]https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd
[2]https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311
[3]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libkcapi/libkcapi/CVE-2026-71226-1.patch  | 604 ++++++++++++++++++
 .../libkcapi/libkcapi/CVE-2026-71226-2.patch  |  55 ++
 .../libkcapi/libkcapi/CVE-2026-71226-3.patch  |  93 +++
 .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb |   3 +
 4 files changed, 755 insertions(+)
 create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
 create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
 create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch

diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
new file mode 100644
index 0000000000..d53d29423c
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-1.patch
@@ -0,0 +1,604 @@
+From 73a34808912e3cfea8d88f0a2c08fc0ed107a9d8 Mon Sep 17 00:00:00 2001
+From: Markus Theil <markus.theil@secunet.com>
+Date: Fri, 3 Apr 2026 15:06:53 +0200
+Subject: [PATCH] fixes found by analysis with LLM
+
+Signed-off-by: Markus Theil <markus.theil@secunet.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+(cherry picked from commit e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd)
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/e8396c28c2cd2b81f69fc68500fcb2ec7163b4fd]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ apps/app-internal.c   | 15 +++++++++---
+ apps/kcapi-dgst.c     | 11 ++++++---
+ apps/kcapi-enc.c      |  9 ++++---
+ apps/kcapi-hasher.c   | 12 ++++++---
+ apps/kcapi-rng.c      | 24 ++++++++++++------
+ configure.ac          |  3 ++-
+ lib/kcapi-aead.c      | 12 +++++++--
+ lib/kcapi-kdf.c       |  6 +++--
+ lib/kcapi-kernel-if.c | 57 +++++++++++++++++++++++++++++--------------
+ lib/kcapi-kpp.c       |  4 +--
+ lib/kcapi-md.c        |  2 +-
+ lib/kcapi-sym.c       |  6 +++++
+ lib/kcapi-utils.c     |  7 ++++--
+ 13 files changed, 118 insertions(+), 50 deletions(-)
+
+diff --git a/apps/app-internal.c b/apps/app-internal.c
+index 7e01dd7..724b0b1 100644
+--- a/apps/app-internal.c
++++ b/apps/app-internal.c
+@@ -173,18 +173,24 @@ static uint8_t bin_char(char hex)
+ void hex2bin(const char *hex, uint32_t hexlen, uint8_t *bin, uint32_t binlen)
+ {
+ 	uint32_t i;
+-	uint32_t chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen;
++	uint32_t chars;
+ 
+ 	/*
+ 	 * handle odd-length of strings where the first digit is the least
+ 	 * significant nibble
+ 	 */
+ 	if (hexlen & 1) {
++		if (!binlen)
++			return;
+ 		bin[0] = bin_char(hex[0]);
+ 		bin++;
+ 		hex++;
++		hexlen--;
++		binlen--;
+ 	}
+ 
++	chars = (binlen > (hexlen / 2)) ? (hexlen / 2) : binlen;
++
+ 	for (i = 0; i < chars; i++) {
+ 		bin[i] = (uint8_t)(bin_char(hex[(i*2)]) << 4);
+ 		bin[i] |= bin_char(hex[((i*2)+1)]);
+@@ -238,13 +244,14 @@ ssize_t read_complete(int fd, uint8_t *buf, size_t buflen)
+ 		if (0 < ret) {
+ 			buflen -= (size_t)ret;
+ 			buf += ret;
++			rc += ret;
+ 		}
+-		rc += ret;
+-		if (ret)
+-			break;
+ 	} while ((0 < ret || EINTR == errno || ERESTART == errno)
+ 		 && buflen > 0);
+ 
++	if (ret < 0)
++		return -errno;
++
+ 	return rc;
+ }
+ 
+diff --git a/apps/kcapi-dgst.c b/apps/kcapi-dgst.c
+index 591a7fb..42d099c 100644
+--- a/apps/kcapi-dgst.c
++++ b/apps/kcapi-dgst.c
+@@ -128,6 +128,11 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ 	}
+ 
+ 	outlen = kcapi_md_digestsize(handle);
++	if (!outlen) {
++		dolog(KCAPI_LOG_ERR, "Cipher has zero digest size");
++		ret = -EINVAL;
++		goto out;
++	}
+ 
+ 	if (opts->hexout)
+ 		outlen *= 2;
+@@ -285,8 +290,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ 			}
+ 
+ 			while (j < saltbuflen) {
+-				ret = kcapi_rng_generate(rng, saltbuf,
+-							 (size_t)saltbuflen);
++				ret = kcapi_rng_generate(rng, saltbuf + j,
++							 (size_t)(saltbuflen - j));
+ 				if (ret < 0) {
+ 					kcapi_rng_destroy(rng);
+ 					free(saltbuf);
+@@ -320,7 +325,7 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ 	if (opts->key_fd != -1) {
+ 		ret = read_complete(opts->key_fd, keybuf, sizeof(keybuf));
+ 		if (ret < 0)
+-			return (int)ret;
++			goto out;
+ 
+ 		have_key = 1;
+ 		keybuflen = (uint32_t)ret;
+diff --git a/apps/kcapi-enc.c b/apps/kcapi-enc.c
+index 68cf2f7..e7aa9db 100644
+--- a/apps/kcapi-enc.c
++++ b/apps/kcapi-enc.c
+@@ -218,7 +218,7 @@ static ssize_t return_data_fd(struct kcapi_handle *handle,
+ 	}
+ 
+ out:
+-	munmap(outmem, outsize);
++	munmap(outmem, outsize + offset);
+ 	return (ret < 0) ? ret : generated_bytes;
+ }
+ 
+@@ -609,7 +609,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ 		}
+ 
+ 	/* Get data from file. */
+-	} else {
++	} else if (insb.st_size) {
+ 		uint32_t sent_data = 0;
+ 
+ 		inmem = mmap(NULL, (size_t)insb.st_size, PROT_READ, MAP_SHARED,
+@@ -636,6 +636,7 @@ static int cipher_op(struct kcapi_handle *handle, struct opt_data *opts)
+ 			 * we will not apply padding.
+ 			 */
+ 			if (!opts->decrypt &&
++			    insb.st_size >= 2 &&
+ 			    !(insb.st_size % opts->func_blocksize(handle)) &&
+ 			    (uint32_t)padbyte < opts->func_blocksize(handle)) {
+ 				uint32_t i;
+@@ -803,8 +804,8 @@ static int set_key(struct kcapi_handle *handle, struct opt_data *opts)
+ 			}
+ 
+ 			while (j < saltbuflen) {
+-				ret = kcapi_rng_generate(rng, saltbuf,
+-							 saltbuflen);
++				ret = kcapi_rng_generate(rng, saltbuf + j,
++							 saltbuflen - j);
+ 				if (ret < 0) {
+ 					kcapi_rng_destroy(rng);
+ 					free(saltbuf);
+diff --git a/apps/kcapi-hasher.c b/apps/kcapi-hasher.c
+index 217f59d..90dc34d 100644
+--- a/apps/kcapi-hasher.c
++++ b/apps/kcapi-hasher.c
+@@ -271,7 +271,7 @@ static int load_file(const char *filename, uint8_t **memory, off_t *size)
+ 				fprintf(stderr, "Key longer than UINT32_MAX\n");
+ 				ret = -ERANGE;
+ 				goto out;
+-			} else if (buffer_size * 2 < buffer_size)
++			} else if (buffer_size > UINT32_MAX / 2)
+ 				buffer_size = UINT32_MAX;
+ 			else
+ 				buffer_size *= 2;
+@@ -340,7 +340,7 @@ static int hasher(struct kcapi_handle *handle, const struct hash_params *params,
+ 			} while (left);
+ 			munmap(memblock, mapped);
+ 			offset = offset + (off_t)mapped;
+-		} while (offset ^ size);
++		} while (offset != size);
+ 	} else {
+ 		uint8_t tmpbuf[TMPBUFLEN] __aligned(KCAPI_APP_ALIGN);
+ 		uint32_t bufsize;
+@@ -647,11 +647,17 @@ static int process_checkfile(const struct hash_params *params,
+ 			hexhash = buf;
+ 
+ 		if (bsd_style) {
++			if (bsd_style > linelen) {
++				fprintf(stderr, "Invalid checkfile format\n");
++				ret = 1;
++				goto out;
++			}
++
+ 			/* Hash starts after separator */
+ 			hexhashlen = linelen - bsd_style + 1;
+ 
+ 			/* remove closing parenthesis behind filename */
+-			if (buf[(bsd_style - 4)] == ')')
++			if (bsd_style >= 4 && buf[(bsd_style - 4)] == ')')
+ 				buf[(bsd_style - 4)] = '\0';
+ 		}
+ 
+diff --git a/apps/kcapi-rng.c b/apps/kcapi-rng.c
+index 9e025cd..46dab02 100644
+--- a/apps/kcapi-rng.c
++++ b/apps/kcapi-rng.c
+@@ -282,16 +282,18 @@ int main(int argc, char *argv[])
+ 	      seedsize);
+ 
+ 	if (!isatty(0) && (errno == EINVAL || errno == ENOTTY)) {
+-		while (fgets((char *)seedbuf, (int)seedsize, stdin)) {
+-			ret = kcapi_rng_seed(rng, seedbuf, seedsize);
++		ssize_t rret;
++
++		while ((rret = read(STDIN_FILENO, seedbuf, seedsize)) > 0) {
++			ret = kcapi_rng_seed(rng, seedbuf, (uint32_t)rret);
+ 			if (ret)
+ 				dolog(KCAPI_LOG_WARN,
+-				      "User-provided seed of %lu bytes not accepted by DRNG (error: %ld)",
+-				      (unsigned long)sizeof(buf), ret);
++				      "User-provided seed of %zd bytes not accepted by DRNG (error: %ld)",
++				      rret, ret);
+ 			else
+ 				dolog(KCAPI_LOG_DEBUG,
+-				      "User-provided seed of %u bytes",
+-				      seedsize);
++				      "User-provided seed of %zd bytes",
++				      rret);
+ 		}
+ 	}
+ 
+@@ -312,9 +314,15 @@ int main(int argc, char *argv[])
+ 			char hexbuf[2 * KCAPI_RNG_BUFSIZE];
+ 
+ 			bin2hex(buf, (size_t)ret, hexbuf, sizeof(hexbuf), 0);
+-			fwrite(hexbuf, 2 * (size_t)ret, 1, stdout);
++			if (fwrite(hexbuf, 2 * (size_t)ret, 1, stdout) != 1) {
++				ret = -EIO;
++				goto out;
++			}
+ 		} else {
+-			fwrite(buf, (size_t)ret, 1, stdout);
++			if (fwrite(buf, (size_t)ret, 1, stdout) != 1) {
++				ret = -EIO;
++				goto out;
++			}
+ 		}
+ 
+ 		outlen -= (size_t)ret;
+diff --git a/configure.ac b/configure.ac
+index fbae4f9..446b8a8 100644
+--- a/configure.ac
++++ b/configure.ac
+@@ -14,16 +14,17 @@ m4_define([__KCAPI_MINVERSION], [5])
+ m4_define([__KCAPI_PATCHLEVEL], [0])
+ m4_define([KCAPI_VERSION], [__KCAPI_MAJVERSION.__KCAPI_MINVERSION.__KCAPI_PATCHLEVEL])
+ 
++AC_PREREQ([2.69])
+ AC_INIT([libkcapi], [KCAPI_VERSION])
+ AC_DEFINE([KCAPI_MAJVERSION], [__KCAPI_MAJVERSION])
+ AC_DEFINE([KCAPI_MINVERSION], [__KCAPI_MINVERSION])
+ AC_DEFINE([KCAPI_PATCHLEVEL], [__KCAPI_PATCHLEVEL])
++AC_CONFIG_MACRO_DIRS([m4])
+ AM_INIT_AUTOMAKE([foreign])
+ LT_INIT([pic-only])
+ AC_SUBST([LIBTOOL_DEPS])
+ AC_PROG_CC
+ AC_CONFIG_FILES([Makefile])
+-AC_CONFIG_MACRO_DIR([m4])
+ AX_PROG_CC_FOR_BUILD
+ AX_CHECK_PIE
+ 
+diff --git a/lib/kcapi-aead.c b/lib/kcapi-aead.c
+index b52dda0..3a7d711 100644
+--- a/lib/kcapi-aead.c
++++ b/lib/kcapi-aead.c
+@@ -566,7 +566,11 @@ size_t impl_aead_outbuflen_enc(struct kcapi_handle *handle,
+ {
+ 	struct kcapi_handle_tfm *tfm = handle->tfm;
+ 	uint32_t bs = tfm->info.blocksize;
+-	size_t outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen;
++	size_t outlen;
++
++	if (!bs)
++		return 0;
++	outlen = (inlen + bs - 1) / bs * bs + taglen + assoclen;
+ 
+ 	/* the kernel does not like zero length output buffers */
+ 	if (!outlen)
+@@ -591,7 +595,11 @@ size_t impl_aead_outbuflen_dec(struct kcapi_handle *handle,
+ {
+ 	struct kcapi_handle_tfm *tfm = handle->tfm;
+ 	uint32_t bs = tfm->info.blocksize;
+-	size_t outlen = (inlen + bs - 1) / bs * bs + assoclen;
++	size_t outlen;
++
++	if (!bs)
++		return 0;
++	outlen = (inlen + bs - 1) / bs * bs + assoclen;
+ 
+ 	if (!handle->flags.ge_v4_9 == true)
+ 		outlen += taglen;
+diff --git a/lib/kcapi-kdf.c b/lib/kcapi-kdf.c
+index 54dc1ec..5f389b6 100644
+--- a/lib/kcapi-kdf.c
++++ b/lib/kcapi-kdf.c
+@@ -54,6 +54,8 @@
+ #include "kcapi.h"
+ #include "internal.h"
+ 
++#define MAX_DIGESTSIZE 64
++
+ #ifndef __has_builtin
+ # define __has_builtin(x) 0
+ #endif
+@@ -101,7 +103,7 @@ ssize_t impl_kdf_dpi(struct kcapi_handle *handle,
+ 	ssize_t err = 0;
+ 	uint8_t *dst_orig = dst;
+ 	size_t dlen_orig = dlen;
+-	uint8_t Ai[h];
++	uint8_t Ai[MAX_DIGESTSIZE];
+ 	uint32_t i = 1;
+ 
+ 	if (dlen > INT_MAX)
+@@ -448,7 +450,7 @@ static inline uint64_t kcapi_get_time(void)
+ {
+ 	struct timespec time;
+ 
+-	if (clock_gettime(CLOCK_REALTIME, &time) == 0)
++	if (clock_gettime(CLOCK_MONOTONIC, &time) == 0)
+ 		return (uint64_t)time.tv_nsec;
+ 
+ 	return 0;
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 835e45a..b37f0dc 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle,
+ 		}
+ 		header->cmsg_level = SOL_ALG;
+ 		header->cmsg_type = ALG_SET_IV;
+-		header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size);
++		header->cmsg_len = CMSG_LEN(iv_msg_size);
+ 		alg_iv = (void*)CMSG_DATA(header);
+ 		alg_iv->ivlen = tfm->info.ivsize;
+ 		memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize);
+@@ -409,8 +409,10 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+ 				    "AF_ALG: splice syscall returned %zd", ret);
+ 		}
+ 
++		if (ret == 0)
++			return -EPIPE;
+ 		processed += ret;
+-		inlen -= (uint32_t)ret;
++		inlen -= (size_t)ret;
+ 	}
+ 
+ 	return processed;
+@@ -434,14 +436,17 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 
+ 		for (i = 0; i < rc; i++) {
+ 			struct iocb *cb;
++			unsigned int idx = (unsigned int)events[i].data;
++
++			if (idx >= KCAPI_AIO_CONCURRENT)
++				return -EOVERFLOW;
+ 
+ 			/*
+ 			 * If one cipher operation fails, so will the entire
+ 			 * AIO operation
+ 			 */
+ 			if (events[i].res < 0) {
+-				handle->aio.iocb_ret[events[i].data] =
+-							events[i].res;
++				handle->aio.iocb_ret[idx] = events[i].res;
+ 				return (int)events[i].res;
+ 			}
+ 
+@@ -452,16 +457,15 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 			 * return code.
+ 			 */
+ 			if (events[i].res > 0) {
+-				handle->aio.iocb_ret[events[i].data] =
+-								events[i].res;
++				handle->aio.iocb_ret[idx] = events[i].res;
+ 			} else {
+-				handle->aio.iocb_ret[events[i].data] =
++				handle->aio.iocb_ret[idx] =
+ 							(__s64)cb->aio_nbytes;
+ 			}
+ 
+ 			cb->aio_fildes = 0;
+ 		}
+-		toread -= (uint32_t)rc;
++		toread -= (size_t)rc;
+ 	}
+ 
+ 	return 0;
+@@ -613,7 +617,7 @@ ssize_t _kcapi_common_read_data(struct kcapi_handle *handle,
+ 			ret = read(*_kcapi_get_opfd(handle), out, outlen);
+ 			if (ret > 0) {
+ 				out += ret;
+-				outlen -= (uint32_t)ret;
++				outlen -= (size_t)ret;
+ 				totallen += ret;
+ 			}
+ 			kcapi_dolog(KCAPI_LOG_DEBUG,
+@@ -722,13 +726,13 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 		goto out;
+ 	}
+ 	if (addr_len != sizeof(nl)) {
+-		ret = -errno;
++		ret = -EPROTO;
+ 		kcapi_dolog(KCAPI_LOG_ERR,
+ 			    "Netlink error: wrong address length %d", addr_len);
+ 		goto out;
+ 	}
+ 	if (nl.nl_family != AF_NETLINK) {
+-		ret = -errno;
++		ret = -EPROTO;
+ 		kcapi_dolog(KCAPI_LOG_ERR,
+ 			    "Netlink error: wrong address family %d",
+ 			    nl.nl_family);
+@@ -764,12 +768,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 			goto out;
+ 		}
+ 		if (rc == 0) {
+-			ret = -errno;
++			ret = -ENODATA;
+ 			kcapi_dolog(KCAPI_LOG_ERR, "Netlink error: no data");
+ 			goto out;
+ 		}
+ 		if (rc > (ssize_t)sizeof(buf)) {
+-			ret = -errno;
++			ret = -EOVERFLOW;
+ 			kcapi_dolog(KCAPI_LOG_ERR,
+ 				    "Netlink error: received too much data");
+ 			goto out;
+@@ -779,6 +783,12 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 
+ 	ret = -EFAULT;
+ 	res_len = res_n->nlmsg_len;
++	if (res_len > sizeof(buf)) {
++		kcapi_dolog(KCAPI_LOG_ERR,
++			    "Netlink error: nlmsg_len %lu exceeds buffer",
++			    res_len);
++		goto out;
++	}
+ 	if (res_n->nlmsg_type == NLMSG_ERROR) {
+ 		/*
+ 		 * return -EAGAIN -- this error will occur if we received a
+@@ -819,6 +829,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 
+ 	if (tb[CRYPTOCFGA_REPORT_HASH]) {
+ 		struct rtattr *rta = tb[CRYPTOCFGA_REPORT_HASH];
++
++		if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_hash))
++			goto out;
+ 		struct crypto_report_hash *rsh =
+ 			(struct crypto_report_hash *) RTA_DATA(rta);
+ 		tfm->info.hash_digestsize = rsh->digestsize;
+@@ -831,6 +844,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 	}
+ 	if (tb[CRYPTOCFGA_REPORT_BLKCIPHER]) {
+ 		struct rtattr *rta = tb[CRYPTOCFGA_REPORT_BLKCIPHER];
++
++		if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_blkcipher))
++			goto out;
+ 		struct crypto_report_blkcipher *rblk =
+ 			(struct crypto_report_blkcipher *) RTA_DATA(rta);
+ 		tfm->info.blocksize = rblk->blocksize;
+@@ -845,6 +861,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 	}
+ 	if (tb[CRYPTOCFGA_REPORT_AEAD]) {
+ 		struct rtattr *rta = tb[CRYPTOCFGA_REPORT_AEAD];
++
++		if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_aead))
++			goto out;
+ 		struct crypto_report_aead *raead =
+ 			(struct crypto_report_aead *) RTA_DATA(rta);
+ 		tfm->info.blocksize = raead->blocksize;
+@@ -858,6 +877,9 @@ static int __kcapi_common_getinfo(struct kcapi_handle *handle,
+ 	}
+ 	if (tb[CRYPTOCFGA_REPORT_RNG]) {
+ 		struct rtattr *rta = tb[CRYPTOCFGA_REPORT_RNG];
++
++		if (RTA_PAYLOAD(rta) < sizeof(struct crypto_report_rng))
++			goto out;
+ 		struct crypto_report_rng *rrng =
+ 			(struct crypto_report_rng *) RTA_DATA(rta);
+ 		tfm->info.rng_seedsize = rrng->seedsize;
+@@ -981,19 +1003,19 @@ static int _kcapi_get_kernver(struct kcapi_handle *handle)
+ 	/* 3.15.0 */
+ 	res = strtok_r(kernel.release, ".", &saveptr);
+ 	if (!res) {
+-		printf("Could not parse kernel version");
++		kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ 		return -EFAULT;
+ 	}
+ 	tfm->sysinfo.kernel_maj = strtoul(res, NULL, 10);
+ 	res = strtok_r(NULL, ".", &saveptr);
+ 	if (!res) {
+-		printf("Could not parse kernel version");
++		kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ 		return -EFAULT;
+ 	}
+ 	tfm->sysinfo.kernel_minor = strtoul(res, NULL, 10);
+ 	res = strtok_r(NULL, ".", &saveptr);
+ 	if (!res) {
+-		printf("Could not parse kernel version");
++		kcapi_dolog(KCAPI_LOG_ERR, "Could not parse kernel version");
+ 		return -EFAULT;
+ 	}
+ 	tfm->sysinfo.kernel_patchlevel = strtoul(res, NULL, 10);
+@@ -1217,7 +1239,6 @@ static int _kcapi_handle_init_tfm(struct kcapi_handle *handle, const char *type,
+ 
+ 	ret = _kcapi_common_getinfo(handle, ciphername);
+ 	if (ret) {
+-		ret = -errno;
+ 		kcapi_dolog(KCAPI_LOG_ERR, "NETLINK_CRYPTO: cannot obtain cipher information for %s (is required crypto_user.c patch missing? see documentation)",
+ 			    ciphername);
+ 		return ret;
+@@ -1368,7 +1389,7 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle,
+ 		in += inprocess;
+ 		inlen -= inprocess;
+ 		out += ret;
+-		outlen -= (uint32_t)ret;
++		outlen -= (size_t)ret;
+ 	}
+ 
+ 	return totallen;
+diff --git a/lib/kcapi-kpp.c b/lib/kcapi-kpp.c
+index 814485a..d0383d6 100644
+--- a/lib/kcapi-kpp.c
++++ b/lib/kcapi-kpp.c
+@@ -52,12 +52,12 @@ int kcapi_kpp_ecdh_setcurve(struct kcapi_handle *handle,
+ 			    unsigned long curve_id)
+ {
+ 	struct kcapi_handle_tfm *tfm = handle->tfm;
+-	char curve_id_str[sizeof(unsigned long)];
++	char curve_id_str[24];
+ 	int ret = 0;
+ 
+ 	snprintf(curve_id_str, sizeof(curve_id_str), "%lu", curve_id);
+ 	ret = setsockopt(tfm->tfmfd, SOL_ALG, ALG_SET_ECDH_CURVE,
+-			 curve_id_str, sizeof(curve_id_str));
++			 curve_id_str, (socklen_t)strlen(curve_id_str));
+ 	return (ret >= 0) ? ret : -errno;
+ }
+ 
+diff --git a/lib/kcapi-md.c b/lib/kcapi-md.c
+index bddd76b..5f493eb 100644
+--- a/lib/kcapi-md.c
++++ b/lib/kcapi-md.c
+@@ -196,7 +196,7 @@ ssize_t impl_md_sha256(const uint8_t *in, size_t inlen,
+ }
+ 
+ ORIG_SYMVER(md_sha256, "1.0.0")
+-ssize_t orig_md_sha256(const uint8_t *in, uint32_t inlen,
++int32_t orig_md_sha256(const uint8_t *in, uint32_t inlen,
+ 		       uint8_t *out, uint32_t outlen)
+ {
+ 	return (int32_t)kcapi_md_conv_common("sha256", in, inlen, out, outlen);
+diff --git a/lib/kcapi-sym.c b/lib/kcapi-sym.c
+index 911ec1e..d500061 100644
+--- a/lib/kcapi-sym.c
++++ b/lib/kcapi-sym.c
+@@ -47,6 +47,9 @@ ssize_t impl_cipher_encrypt(struct kcapi_handle *handle,
+ 	struct kcapi_handle_tfm *tfm = handle->tfm;
+ 	uint32_t bs = tfm->info.blocksize;
+ 
++	if (!bs)
++		return -EINVAL;
++
+ 	/* require properly sized output data size */
+ 	if (outlen < ((inlen + bs - 1) / bs * bs))
+ 		kcapi_dolog(KCAPI_LOG_WARN,
+@@ -120,6 +123,9 @@ ssize_t impl_cipher_decrypt(struct kcapi_handle *handle,
+ {
+ 	struct kcapi_handle_tfm *tfm = handle->tfm;
+ 
++	if (!tfm->info.blocksize)
++		return -EINVAL;
++
+ 	/* require properly sized output data size */
+ 	if (inlen % tfm->info.blocksize)
+ 		kcapi_dolog(KCAPI_LOG_WARN,
+diff --git a/lib/kcapi-utils.c b/lib/kcapi-utils.c
+index 46fd330..e801d29 100644
+--- a/lib/kcapi-utils.c
++++ b/lib/kcapi-utils.c
+@@ -96,7 +96,7 @@ err:
+ 	} else {
+ 		kcapi_dolog(KCAPI_LOG_WARN,
+ 			    "AF_ALG: setting maximum splice pipe size to %u failed: %s",
+-			    size, strerror(ret));
++			    size, strerror(-ret));
+ 	}
+ 	return ret;
+ }
+@@ -109,7 +109,10 @@ int kcapi_get_maxsplicesize(struct kcapi_handle *handle)
+ 		return -EINVAL;
+ 
+ 	/* Both pipe endpoints should have the same pipe size */
+-	handle->pipesize = (unsigned int)fcntl(handle->pipes[0], F_GETPIPE_SZ);
++	int ret = fcntl(handle->pipes[0], F_GETPIPE_SZ);
++	if (ret < 0)
++		return -errno;
++	handle->pipesize = (unsigned int)ret;
+ 
+ 	/*
+ 	 * For vmsplice to allow the maximum number of 16 pages, we need to
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
new file mode 100644
index 0000000000..856d7a9879
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-2.patch
@@ -0,0 +1,55 @@
+From 79198067bdf027f5d4d5e2804b086a0a37b277ec Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Fri, 3 Apr 2026 17:43:05 +0200
+Subject: [PATCH] fix kernel invocation
+
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+(cherry picked from commit d9f16d5fbcf8270110a8f6f35523525f345ca311)
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/d9f16d5fbcf8270110a8f6f35523525f345ca311]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index b37f0dc..5d3b352 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -216,7 +216,7 @@ ssize_t _kcapi_common_send_meta(struct kcapi_handle *handle,
+ 		}
+ 		header->cmsg_level = SOL_ALG;
+ 		header->cmsg_type = ALG_SET_IV;
+-		header->cmsg_len = CMSG_LEN(iv_msg_size);
++		header->cmsg_len = kcapi_downcast_socklen_t(iv_msg_size);
+ 		alg_iv = (void*)CMSG_DATA(header);
+ 		alg_iv->ivlen = tfm->info.ivsize;
+ 		memcpy(alg_iv->iv, handle->cipher.iv, tfm->info.ivsize);
+@@ -411,6 +411,7 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+ 
+ 		if (ret == 0)
+ 			return -EPIPE;
++
+ 		processed += ret;
+ 		inlen -= (size_t)ret;
+ 	}
+@@ -436,7 +437,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 
+ 		for (i = 0; i < rc; i++) {
+ 			struct iocb *cb;
+-			unsigned int idx = (unsigned int)events[i].data;
++			uint64_t idx = events[i].data;
+ 
+ 			if (idx >= KCAPI_AIO_CONCURRENT)
+ 				return -EOVERFLOW;
+@@ -459,8 +460,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 			if (events[i].res > 0) {
+ 				handle->aio.iocb_ret[idx] = events[i].res;
+ 			} else {
+-				handle->aio.iocb_ret[idx] =
+-							(__s64)cb->aio_nbytes;
++				handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes;
+ 			}
+ 
+ 			cb->aio_fildes = 0;
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch
new file mode 100644
index 0000000000..591c32412b
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71226-3.patch
@@ -0,0 +1,93 @@
+From 8ab3c8939276848ec8f43156a7658f7c5dae4026 Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:36:32 +0200
+Subject: [PATCH] fix memory corruption
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71226
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 33 ++++++++++++++-------------------
+ 1 file changed, 14 insertions(+), 19 deletions(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 5d3b352..8a12c09 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -423,6 +423,8 @@ ssize_t _kcapi_common_vmsplice_chunk(struct kcapi_handle *handle,
+ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 			struct timespec *timeout)
+ {
++	int err = 0;
++
+ 	if (toread > KCAPI_AIO_CONCURRENT)
+ 		return -EINVAL;
+ 
+@@ -433,34 +435,26 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 				      events, timeout);
+ 
+ 		if (rc < 0)
+-			return rc;
++			return err == 0 ? rc : err;
+ 
+ 		for (i = 0; i < rc; i++) {
+ 			struct iocb *cb;
+ 			uint64_t idx = events[i].data;
+ 
+-			if (idx >= KCAPI_AIO_CONCURRENT)
+-				return -EOVERFLOW;
+-
+-			/*
+-			 * If one cipher operation fails, so will the entire
+-			 * AIO operation
+-			 */
+-			if (events[i].res < 0) {
+-				handle->aio.iocb_ret[idx] = events[i].res;
+-				return (int)events[i].res;
++			if (idx >= KCAPI_AIO_CONCURRENT) {
++				if (err == 0)
++					err = -EOVERFLOW;
++				continue;
+ 			}
+ 
+ 			cb = (struct iocb *)(uintptr_t)events[i].obj;
+ 
+-			/*
+-			 * Older symmetric AIO implementations used a wrong
+-			 * return code.
+-			 */
+-			if (events[i].res > 0) {
+-				handle->aio.iocb_ret[idx] = events[i].res;
+-			} else {
++			if (events[i].res == 0) {
+ 				handle->aio.iocb_ret[idx] = (__s64)cb->aio_nbytes;
++			} else {
++				handle->aio.iocb_ret[idx] = events[i].res;
++				if (events[i].res < 0 && err == 0)
++					err = (int)events[i].res;
+ 			}
+ 
+ 			cb->aio_fildes = 0;
+@@ -468,7 +462,7 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 		toread -= (size_t)rc;
+ 	}
+ 
+-	return 0;
++	return err;
+ }
+ 
+ int _kcapi_aio_send_iov(struct kcapi_handle *handle, struct iovec *iov,
+@@ -544,6 +538,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle,
+ 		} else {
+ 			kcapi_dolog(KCAPI_LOG_ERR,
+ 				    "Could not sumbit AIO read\n");
++			_kcapi_aio_read_all(handle, (size_t)ret, NULL);
+ 			return -EIO;
+ 		}
+ 	}
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index 532c9e29df..f2ddc25336 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -5,6 +5,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=3d8a091d797491204567185a6efce70f"
 
 SRCREV = "fc937358e71253a6efaa3ba74885364976b040ea"
 SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https \
+           file://CVE-2026-71226-1.patch \
+           file://CVE-2026-71226-2.patch \
+           file://CVE-2026-71226-3.patch \
           "
 
 inherit autotools


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (18 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 ankur.tyagi85
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit fixing the CVE as per the release notes[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71227

[1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libkcapi/libkcapi/CVE-2026-71227.patch    | 40 +++++++++++++++++++
 .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb |  1 +
 2 files changed, 41 insertions(+)
 create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch

diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch
new file mode 100644
index 0000000000..6074c0da27
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71227.patch
@@ -0,0 +1,40 @@
+From d85279e3bec7578f8c238aec92539985c2032616 Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:38:10 +0200
+Subject: [PATCH] Fix potential infinite loop
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71227
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index 8a12c09..a54cdaa 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -436,6 +436,8 @@ int _kcapi_aio_read_all(struct kcapi_handle *handle, size_t toread,
+ 
+ 		if (rc < 0)
+ 			return err == 0 ? rc : err;
++		if (rc == 0)
++			return err == 0 ? -ETIMEDOUT : err;
+ 
+ 		for (i = 0; i < rc; i++) {
+ 			struct iocb *cb;
+@@ -509,7 +511,7 @@ int _kcapi_aio_read_iov(struct kcapi_handle *handle,
+ 			timeout.tv_sec = 0;
+ 			timeout.tv_nsec = 10000;
+ 			ret = _kcapi_aio_read_all(handle, iovlen, &timeout);
+-			if (ret < 0)
++			if (ret < 0 && ret != -ETIMEDOUT)
+ 				return ret;
+ 		}
+ 
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index f2ddc25336..f1fe6a0940 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -8,6 +8,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https
            file://CVE-2026-71226-1.patch \
            file://CVE-2026-71226-2.patch \
            file://CVE-2026-71226-3.patch \
+           file://CVE-2026-71227.patch \
           "
 
 inherit autotools


^ permalink raw reply related	[flat|nested] 22+ messages in thread

* [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225
  2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
                   ` (19 preceding siblings ...)
  2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 ankur.tyagi85
@ 2026-09-03  9:49 ` ankur.tyagi85
  20 siblings, 0 replies; 22+ messages in thread
From: ankur.tyagi85 @ 2026-09-03  9:49 UTC (permalink / raw)
  To: openembedded-devel; +Cc: Ankur Tyagi

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commit fixing the CVE as per the release notes[1]

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-71225

[1]https://github.com/smuellerDD/libkcapi/releases/tag/v1.5.1

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../libkcapi/libkcapi/CVE-2026-71225.patch    | 38 +++++++++++++++++++
 .../recipes-crypto/libkcapi/libkcapi_1.5.0.bb |  1 +
 2 files changed, 39 insertions(+)
 create mode 100644 meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch

diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch
new file mode 100644
index 0000000000..8a2e4220e7
--- /dev/null
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi/CVE-2026-71225.patch
@@ -0,0 +1,38 @@
+From ca418d6cc684057bcead18b3dd68d64cb3e156af Mon Sep 17 00:00:00 2001
+From: Stephan Mueller <smueller@chronox.de>
+Date: Thu, 30 Jul 2026 08:39:37 +0200
+Subject: [PATCH] Add safety measure to prevent IV reuse
+
+Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
+Signed-off-by: Stephan Mueller <smueller@chronox.de>
+
+CVE: CVE-2026-71225
+Upstream-Status: Backport [https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6]
+
+Dropped changes to the CHANGES.md file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ lib/kcapi-kernel-if.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/lib/kcapi-kernel-if.c b/lib/kcapi-kernel-if.c
+index a54cdaa..859ecdf 100644
+--- a/lib/kcapi-kernel-if.c
++++ b/lib/kcapi-kernel-if.c
+@@ -1387,6 +1387,15 @@ ssize_t _kcapi_cipher_crypt_chunk(struct kcapi_handle *handle,
+ 		inlen -= inprocess;
+ 		out += ret;
+ 		outlen -= (size_t)ret;
++
++		/*
++		 * Clear the IV so subsequent chunks do not override the
++		 * kernel's chained IV via ALG_SET_IV.  The kernel updates
++		 * its internal IV after each operation; by not sending
++		 * ALG_SET_IV for later chunks, the next chunk continues
++		 * where the previous one left off.
++		 */
++		handle->cipher.iv = NULL;
+ 	}
+ 
+ 	return totallen;
diff --git a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
index f1fe6a0940..edc8c0e47a 100644
--- a/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
+++ b/meta-oe/recipes-crypto/libkcapi/libkcapi_1.5.0.bb
@@ -9,6 +9,7 @@ SRC_URI = "git://github.com/smuellerDD/libkcapi.git;branch=master;protocol=https
            file://CVE-2026-71226-2.patch \
            file://CVE-2026-71226-3.patch \
            file://CVE-2026-71227.patch \
+           file://CVE-2026-71225.patch \
           "
 
 inherit autotools


^ permalink raw reply related	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2026-09-03  9:50 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03  9:49 [oe][meta-oe][wrynose][PATCH 1/22] jq: ignore CVE-2025-49014 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 2/22] lcms: patch CVE-2026-42798 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 3/22] libde265: mark CVE-2026-45382 and CVE-2026-45383 patched ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 4/22] libde265: patch CVE-2026-49295 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 5/22] libde265: patch CVE-2026-49337 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 6/22] libde265: patch CVE-2026-49346 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 7/22] libfido2, libfido2-initial: ignore CVE-2026-40947 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 8/22] libheif: patch CVE-2026-32738 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 9/22] libheif: patch CVE-2026-32739 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 10/22] libheif: patch CVE-2026-32740 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 11/22] libheif: patch CVE-2026-32741 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 12/22] libheif: patch CVE-2026-41071 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 13/22] libheif: patch CVE-2026-62289 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-multimedia][wrynose][PATCH 14/22] libheif: patch CVE-2026-62377 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 15/22] libiec61850: mark CVE-2024-45969 patched ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 16/22] libiec61850: patch CVE-2026-18582 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 17/22] libiec61850: patch CVE-2026-18583 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 18/22] libiec61850: patch CVE-2026-19108 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-networking][wrynose][PATCH 19/22] libiec61850: patch CVE-2026-19206 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 20/22] libkcapi: patch CVE-2026-71226 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 21/22] libkcapi: patch CVE-2026-71227 ankur.tyagi85
2026-09-03  9:49 ` [oe][meta-oe][wrynose][PATCH 22/22] libkcapi: patch CVE-2026-71225 ankur.tyagi85

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox