On Thu Sep 10, 2026 at 6:42 AM CEST, Hemanth Kumar M D wrote:
> Hi Yoann,
>
> This CVE patch will come with the glibc 2.43 stable branch updates:
> https://lists.openembedded.org/g/openembedded-core/message/245453 
> <https://lists.openembedded.org/g/openembedded-core/message/245453>
>
> Please drop this patch.

Right,

For the record, the patch fixing this CVE in this branch is:
0afa34adb0 misc: Fix out-of-bounds array write in tdelete (bug 34506)

I will drop this one before requesting a merge.

Thanks!
>
> On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
>> CAUTION: This email comes from a non Wind River email account!
>> Do not click links or open attachments unless you recognize the sender and 
>> know the content is safe.
>>
>> From: Harish Sadineni<[email protected]>
>>
>> Allocate the maximum array sizes directly, instead of resizing
>> the arrays as needed.  This eliminates alloca usage from the
>> function, and fixes the out-of-bounds accesses.  The asserts
>> guard against the bug coming back if the balancing of the tree
>> turns out not to work correctly.
>>
>> Upstream-Status: Backport 
>> [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> CVE: CVE-2026-19542
>>
>> Reference:
>> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
>> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
>> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>>
>> Signed-off-by: Harish Sadineni<[email protected]>
>> Signed-off-by: Yoann Congal<[email protected]>
>> [YC: fixed CVE: tag in patch]
>> ---
>>   .../glibc/glibc/0023-CVE-2026-19542.patch     | 98 +++++++++++++++++++
>>   meta/recipes-core/glibc/glibc_2.43.bb         |  1 +
>>   2 files changed, 99 insertions(+)
>>   create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>>
>> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch 
>> b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> new file mode 100644
>> index 00000000000..094a50919dc
>> --- /dev/null
>> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> @@ -0,0 +1,98 @@
>> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
>> +From: Florian Weimer<[email protected]>
>> +Date: Fri, 14 Aug 2026 13:41:16 +0200
>> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
>> +
>> +Allocate the maximum array sizes directly, instead of resizing
>> +the arrays as needed.  This eliminates alloca usage from the
>> +function, and fixes the out-of-bounds accesses.  The asserts
>> +guard against the bug coming back if the balancing of the tree
>> +turns out not to work correctly.
>> +
>> +CVE: CVE-2026-19542
>> +Upstream-Status: Backport 
>> [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> +
>> +Reviewed-by: Adhemerval Zanella<[email protected]>
>> +Signed-off-by: Harish Sadineni<[email protected]>
>> +---
>> + misc/tsearch.c | 31 +++++++++++--------------------
>> + 1 file changed, 11 insertions(+), 20 deletions(-)
>> +
>> +diff --git a/misc/tsearch.c b/misc/tsearch.c
>> +index 9b2eb34b25..e517dfa712 100644
>> +--- a/misc/tsearch.c
>> ++++ b/misc/tsearch.c
>> +@@ -85,6 +85,7 @@
>> + #include <assert.h>
>> + #include <stdalign.h>
>> + #include <stddef.h>
>> ++#include <stdint.h>
>> + #include <stdlib.h>
>> + #include <string.h>
>> + #include <search.h>
>> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, 
>> __compar_fn_t compar)
>> +   int cmp;
>> +   node *rootp = (node *) vrootp;
>> +   node root, unchained;
>> +-  /* Stack of nodes so we remember the parents without recursion.  It's
>> +-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
>> +-     would need to have around 250.000 nodes.  */
>> +-  int stacksize = 40;
>> ++  /* Stack of nodes so we remember the parents without recursion.  The
>> ++     stack size is a conservative approximation of the maximum height
>> ++     of a red-black tree, based on size of the address space.
>> ++     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
>> ++  enum { stacksize = 2 * UINTPTR_WIDTH };
>> +   int sp = 0;
>> +-  node **nodestack = alloca (sizeof (node *) * stacksize);
>> ++  node *nodestack[stacksize];
>> +
>> +   if (rootp == NULL)
>> +     return NULL;
>> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, 
>> __compar_fn_t compar)
>> +   root = DEREFNODEPTR(rootp);
>> +   while ((cmp = (*compar) (key, root->key)) != 0)
>> +     {
>> +-      if (sp == stacksize)
>> +-      {
>> +-        node **newstack;
>> +-        stacksize += 20;
>> +-        newstack = alloca (sizeof (node *) * stacksize);
>> +-        nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +-      }
>> +-
>> ++      assert (sp < stacksize);
>> +       nodestack[sp++] = rootp;
>> +       p = DEREFNODEPTR(rootp);
>> +       if (cmp < 0)
>> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, 
>> __compar_fn_t compar)
>> +       node upn;
>> +       for (;;)
>> +       {
>> +-        if (sp == stacksize)
>> +-          {
>> +-            node **newstack;
>> +-            stacksize += 20;
>> +-            newstack = alloca (sizeof (node *) * stacksize);
>> +-            nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +-          }
>> ++        assert (sp < stacksize);
>> +         nodestack[sp++] = parentp;
>> +         parentp = up;
>> +         upn = DEREFNODEPTR(up);
>> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, 
>> __compar_fn_t compar)
>> +                 SETNODEPTR(pp,q);
>> +                 /* Make sure pp is right if the case below tries to use
>> +                    it.  */
>> ++                assert (sp < stacksize);
>> +                 nodestack[sp++] = pp = LEFTPTR(q);
>> +                 q = RIGHT(p);
>> +               }
>> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, 
>> __compar_fn_t compar)
>> +                 SETLEFT(p,RIGHT(q));
>> +                 SETRIGHT(q,p);
>> +                 SETNODEPTR(pp,q);
>> ++                assert (sp < stacksize);
>> +                 nodestack[sp++] = pp = RIGHTPTR(q);
>> +                 q = LEFT(p);
>> +               }
>> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb 
>> b/meta/recipes-core/glibc/glibc_2.43.bb
>> index 9f3a3814d0a..3ef2301191d 100644
>> --- a/meta/recipes-core/glibc/glibc_2.43.bb
>> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
>> @@ -55,6 +55,7 @@ SRC_URI =  
>> "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
>>              
>> file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
>>              
>> file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
>>              
>> file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
>> +file://0023-CVE-2026-19542.patch \
>>   "
>>   B = "${WORKDIR}/build-${TARGET_SYS}"
>>
>> 


-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245561): 
https://lists.openembedded.org/g/openembedded-core/message/245561
Mute This Topic: https://lists.openembedded.org/mt/121158859/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to