From: Vijay Anusuri <[email protected]> Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/cve-2026-18938 [2] https://ubuntu.com/security/CVE-2026-18938 Signed-off-by: Vijay Anusuri <[email protected]> Signed-off-by: Yoann Congal <[email protected]> --- .../p11-kit/files/CVE-2026-18938.patch | 52 +++++++++++++++++++ .../recipes-support/p11-kit/p11-kit_0.25.3.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-support/p11-kit/files/CVE-2026-18938.patch diff --git a/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch b/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch new file mode 100644 index 00000000000..9439a4da318 --- /dev/null +++ b/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch @@ -0,0 +1,52 @@ +From 3e64244e538550c6a7fcf826fa8c50a4604416dc Mon Sep 17 00:00:00 2001 +From: Zoltan Fridrich <[email protected]> +Date: Thu, 6 Aug 2026 11:39:22 +0200 +Subject: [PATCH] rpc: guard against overflow when decoding nested attributes + (CVE-2026-18938) + +A local attacker, or one with equivalent access to a reachable RPC channel, +could exploit an integer overflow vulnerability. By sending specially crafted +messages, the attacker can cause the system to miscalculate memory allocation +for nested attributes. This leads to a memory corruption issue, specifically +a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, +resulting in a Denial of Service (DoS). This vulnerability is only exploitable +on 32 bit systems. + +Signed-off-by: Zoltan Fridrich <[email protected]> + +Upstream-Status: Backport [https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc] +CVE: CVE-2026-18938 +Signed-off-by: Vijay Anusuri <[email protected]> +--- + p11-kit/rpc-message.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c +index d6f0aad..105a4f1 100644 +--- a/p11-kit/rpc-message.c ++++ b/p11-kit/rpc-message.c +@@ -1160,6 +1160,10 @@ p11_rpc_buffer_get_attribute_array_value (p11_buffer *buffer, + if (!p11_rpc_buffer_get_uint32 (buffer, offset, &count)) + return false; + ++ /* Guard against overflow */ ++ if (count != 0 && (SIZE_MAX / count) < sizeof (CK_ATTRIBUTE)) ++ return false; ++ + if (!value) { + memset (&temp, 0, sizeof (CK_ATTRIBUTE)); + attr = &temp; +@@ -1191,6 +1195,10 @@ p11_rpc_buffer_get_mechanism_type_array_value (p11_buffer *buffer, + if (!p11_rpc_buffer_get_uint32 (buffer, offset, &count)) + return false; + ++ /* Guard against overflow */ ++ if (count != 0 && (SIZE_MAX / count) < sizeof (CK_MECHANISM_TYPE)) ++ return false; ++ + if (!value) { + memset (&temp, 0, sizeof (CK_MECHANISM_TYPE)); + mech = &temp; +-- +2.43.0 + diff --git a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb index 6c5b82e6bc9..ca10bbc6acf 100644 --- a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb +++ b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb @@ -13,6 +13,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else '' SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https \ file://fix-parallel-build-failures.patch \ file://CVE-2026-13757.patch \ + file://CVE-2026-18938.patch \ " SRCREV = "917e02a3211dabbdea4b079cb598581dce84fda1" S = "${WORKDIR}/git"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245671): https://lists.openembedded.org/g/openembedded-core/message/245671 Mute This Topic: https://lists.openembedded.org/mt/121207005/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
