expat: fix CVE-2026-56408

This patch applies the upstream fix shown in [1] as referenced by [2].
The fix is adapted to the existing Scarthgap Expat 2.6.4 source.

[1] 16e2efd867
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-56408

(From OE-Core rev: 7a0997b570488debe1ae1f2ab5a312150a96b940)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
Deepak Rathore
2026-07-31 11:26:17 +05:30
committed by Paul Barker
parent 2003935a78
commit 65887ca9e7
2 changed files with 30 additions and 0 deletions

View File

@@ -0,0 +1,29 @@
From c1ad5610cf060c6374d8f8d3b39163edd7053321 Mon Sep 17 00:00:00 2001
From: Sebastian Pipping <sebastian@pipping.org>
Date: Thu, 23 Apr 2026 10:31:45 +0200
Subject: [PATCH 03/17] lib: Waterproof `copyString` from integer overflow
CVE: CVE-2026-56408
Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817]
(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
---
expat/lib/xmlparse.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c
index df92a3ca..12bbe23e 100644
--- a/expat/lib/xmlparse.c
+++ b/expat/lib/xmlparse.c
@@ -8489,6 +8489,10 @@ copyString(const XML_Char *s, XML_Parser parser) {
/* Include the terminator */
charsRequired++;
+ /* Detect and prevent integer overflow */
+ if (charsRequired > SIZE_MAX / sizeof(XML_Char))
+ return NULL;
+
/* Now allocate space for the copy */
result = MALLOC(parser, charsRequired * sizeof(XML_Char));
if (result == NULL)

View File

@@ -63,6 +63,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
file://CVE-2026-45186-07.patch \
file://CVE-2026-56403_p1.patch;striplevel=2 \
file://CVE-2026-56403_p2.patch;striplevel=2 \
file://CVE-2026-56408.patch;striplevel=2 \
"
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"