On Mon Aug 24, 2026 at 8:49 AM CEST, Vijay Anusuri via lists.openembedded.org 
wrote:
> Pick patch according to [2]
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001
> [2] https://security-tracker.debian.org/tracker/CVE-2026-56001
>
> Signed-off-by: Vijay Anusuri <[email protected]>
> ---
>  .../xorg-lib/libxfont/CVE-2026-56001.patch    | 84 +++++++++++++++++++
>  .../xorg-lib/libxfont_1.5.4.bb                |  3 +
>  2 files changed, 87 insertions(+)
>  create mode 100644 
> meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
>
> diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch 
> b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> new file mode 100644
> index 0000000000..506a2dc22a
> --- /dev/null
> +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> @@ -0,0 +1,84 @@
> +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001
> +From: Peter Hutterer <[email protected]>
> +Date: Mon, 1 Jun 2026 16:46:10 +1000
> +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps
> + bytestoalloc
> +
> +bytestoalloc is declared as unsigned int (32-bit). When the sum of
> +per-glyph byte counts exceeds 2^32, the value wraps around and calloc()
> +allocates a buffer that is too small. The subsequent ScaleBitmap loop
> +then writes past the end of the allocated buffer.
> +
> +Change bytestoalloc from unsigned int to size_t to match the actual
> +allocation size type, and add an explicit overflow check in the
> +accumulation loop to bail out if the total would exceed SIZE_MAX.
> +
> +This vulnerability was discovered by:
> +Anonymous working with TrendAI Zero Day Initiative
> +
> +CVE-2026-56001/ZDI-CAN-30558
> +
> +Assisted-by: Claude:claude-opus-4-6
> +Signed-off-by: Peter Hutterer <[email protected]>
> +Part-of: 
> <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
> +
> +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
> +Upstream commit 
> https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778]
> +CVE: CVE-2026-56001
> +Signed-off-by: Vijay Anusuri <[email protected]>

Hello,

This patch (and also the other ones in this series) was non-trivially
changes without a comment explaining why.

> +---
> + src/bitmap/bitscale.c | 24 +++++++++++++++++++++---
> + 1 file changed, 21 insertions(+), 3 deletions(-)
> +
> +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
> +index 13ed924..c87fa96 100644
> +--- a/src/bitmap/bitscale.c
> ++++ b/src/bitmap/bitscale.c
> +@@ -38,6 +38,7 @@ from The Open Group.
> + #include <X11/fonts/bitmap.h>
> + #include <X11/fonts/fontutil.h>
> + #include <math.h>
> ++#include <stdint.h>
              ^ This is new: I suppose to get size_t but that should be
                            explained. Also, "man size_t" tells me that size_t 
in
                                stddef.h not stdint.h.
> + 
> + #ifndef MAX
> + #define   MAX(a,b)    (((a)>(b)) ? a : b)
> +@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf,          /* scaled font 
> */
> +             opci;
> +     FontInfoPtr pfi;
> +     int         glyph;
> +-    unsigned    bytestoalloc = 0;
> ++    size_t      bytestoalloc = 0;
> +     int             firstCol, lastCol, firstRow, lastRow;
> + 
> +     double  xform[4], inv_xform[4];
> +@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf,          /* scaled 
> font */
> +     glyph = pf->glyph;
> +     for (i = 0; i < nchars; i++)
> +     {
> +-    if ((pci = ACCESSENCODING(bitmapFont->encoding, i)))
> +-        bytestoalloc += BYTES_FOR_GLYPH(pci, glyph);
> ++    if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) {
> ++        size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph);
> ++        if (bytestoalloc > SIZE_MAX - glyphsize) {
> ++            fprintf(stderr,
> ++                    "Error: bitmap allocation overflow for scaled font\n");
> ++            goto bail;
> ++        }
> ++        bytestoalloc += glyphsize;
> ++    }
> ++    }
> ++
> ++    /* Reject unreasonably large bitmap allocations that could result
> ++     * from malicious fonts with extreme scale factors.  256 MiB is
> ++     * far beyond any legitimate scaled bitmap font. */
> ++#define BITMAP_SCALE_MAX_ALLOC      (256 * 1024 * 1024)
> ++    if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) {
> ++    fprintf(stderr,
> ++           "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc);
> ++       goto bail;
         ^ This line has been reindented from upstream, that might make
                 future backports needlessly harder.

Can you send a v2 with the changes either removed or explained in the
patch message?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245043): 
https://lists.openembedded.org/g/openembedded-core/message/245043
Mute This Topic: https://lists.openembedded.org/mt/120899335/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to