expat: fix CVE-2026-56407

This patch applies the upstream fix shown in [1] as referenced by [2].

[1] 30c2fc179c
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56407

(From OE-Core rev: 9e565187ad989856ed274feecb343744a4d0d290)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
Deepak Rathore
2026-07-31 11:26:24 +05:30
committed by Paul Barker
parent 2c527003ab
commit 2b8eb621c1
2 changed files with 42 additions and 0 deletions

View File

@@ -0,0 +1,41 @@
From d1cd2bd7da8ed830e9432660616e9b4831df959a Mon Sep 17 00:00:00 2001
From: netliomax25-code <netliomax25@gmail.com>
Date: Tue, 2 Jun 2026 11:59:01 +0530
Subject: [PATCH 12/17] cap entity textLen against signed integer overflow
CVE: CVE-2026-56407
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13]
(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
expat/lib/xmlparse.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
index 9f07b860..8439dc0e 100644
--- a/expat/lib/xmlparse.c
+++ b/expat/lib/xmlparse.c
@@ -5655,6 +5655,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar,
XML_ACCOUNT_NONE);
if (parser->m_declEntity) {
+ /* Detect and prevent signed integer overflow */
+ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) {
+ return XML_ERROR_NO_MEMORY;
+ }
parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool);
parser->m_declEntity->textLen
= (int)(poolLength(&dtd->entityValuePool));
@@ -7076,6 +7080,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) {
return XML_ERROR_NO_MEMORY;
}
+ /* Detect and prevent signed integer overflow */
+ if ((size_t)poolLength(pool) > (size_t)INT_MAX) {
+ poolDiscard(pool);
+ return XML_ERROR_NO_MEMORY;
+ }
entity->textPtr = poolStart(pool);
entity->textLen = (int)(poolLength(pool));
poolFinish(pool);

View File

@@ -72,6 +72,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
file://CVE-2026-56406.patch;striplevel=2 \
file://CVE-2026-56409.patch;striplevel=2 \
file://CVE-2026-56411.patch;striplevel=2 \
file://CVE-2026-56407.patch;striplevel=2 \
"
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"