mirror of
https://git.yoctoproject.org/poky
synced 2026-09-19 00:49:33 +02:00
expat: fix CVE-2026-56409
This patch applies the upstream fix shown in [1] as referenced by [2].
[1] 61f7cdda22
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56409
(From OE-Core rev: 6e0669fdbf661569083b7fe479bf829e6e476f72)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
committed by
Paul Barker
parent
8ef6ff8a53
commit
12aa2868f6
51
meta/recipes-core/expat/expat/CVE-2026-56409.patch
Normal file
51
meta/recipes-core/expat/expat/CVE-2026-56409.patch
Normal file
@@ -0,0 +1,51 @@
|
|||||||
|
From 174ce18f2a283be634d830a5259bd07142635fe8 Mon Sep 17 00:00:00 2001
|
||||||
|
From: netliomax25-code <netliomax25@gmail.com>
|
||||||
|
Date: Mon, 1 Jun 2026 11:53:19 +0530
|
||||||
|
Subject: [PATCH 10/17] xmlwf: protect output path join from integer overflow
|
||||||
|
|
||||||
|
CVE: CVE-2026-56409
|
||||||
|
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e]
|
||||||
|
|
||||||
|
Backport Changes:
|
||||||
|
- Adapt the allocation hunk to the explicit XML_Char cast used by
|
||||||
|
Scarthgap 2.6.4; overflow checks are unchanged.
|
||||||
|
|
||||||
|
(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e)
|
||||||
|
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
|
||||||
|
---
|
||||||
|
expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++--
|
||||||
|
1 file changed, 20 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c
|
||||||
|
index 7bbdb303..bd5f68a4 100644
|
||||||
|
--- a/expat/xmlwf/xmlwf.c
|
||||||
|
+++ b/expat/xmlwf/xmlwf.c
|
||||||
|
@@ -1240,8 +1240,26 @@ tmain(int argc, XML_Char **argv) {
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
}
|
||||||
|
- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2)
|
||||||
|
- * sizeof(XML_Char));
|
||||||
|
+ const size_t outputDirLen = tcslen(outputDir);
|
||||||
|
+ const size_t fileLen = tcslen(file);
|
||||||
|
+
|
||||||
|
+ /* Detect and prevent integer overflow in the addition (without
|
||||||
|
+ risking underflow) and the multiplication, mirroring the guards
|
||||||
|
+ in xcsdup() and resolveSystemId() */
|
||||||
|
+ if (outputDirLen > SIZE_MAX - fileLen
|
||||||
|
+ || outputDirLen > SIZE_MAX - fileLen - 2) {
|
||||||
|
+ tperror(T("Could not allocate memory"));
|
||||||
|
+ exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ const size_t charsRequired = outputDirLen + fileLen + 2;
|
||||||
|
+
|
||||||
|
+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) {
|
||||||
|
+ tperror(T("Could not allocate memory"));
|
||||||
|
+ exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ outName = malloc(charsRequired * sizeof(XML_Char));
|
||||||
|
if (! outName) {
|
||||||
|
tperror(T("Could not allocate memory"));
|
||||||
|
exit(XMLWF_EXIT_INTERNAL_ERROR);
|
||||||
@@ -70,6 +70,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
|
|||||||
file://CVE-2026-56410_p2.patch;striplevel=2 \
|
file://CVE-2026-56410_p2.patch;striplevel=2 \
|
||||||
file://CVE-2026-56406-dependent.patch;striplevel=2 \
|
file://CVE-2026-56406-dependent.patch;striplevel=2 \
|
||||||
file://CVE-2026-56406.patch;striplevel=2 \
|
file://CVE-2026-56406.patch;striplevel=2 \
|
||||||
|
file://CVE-2026-56409.patch;striplevel=2 \
|
||||||
"
|
"
|
||||||
|
|
||||||
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
|
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
|
||||||
|
|||||||
Reference in New Issue
Block a user