From: Hetvi Thakar <[email protected]> This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f [2] https://pkg.go.dev/vuln/GO-2026-4918 Signed-off-by: Hetvi Thakar <[email protected]> Signed-off-by: Yoann Congal <[email protected]> --- meta/recipes-devtools/go/go-1.22.12.inc | 1 + .../go/go/CVE-2026-33814.patch | 44 +++++++++++++++++++ 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-devtools/go/go/CVE-2026-33814.patch diff --git a/meta/recipes-devtools/go/go-1.22.12.inc b/meta/recipes-devtools/go/go-1.22.12.inc index 99c5f8b63b6..ee2f5ca2777 100644 --- a/meta/recipes-devtools/go/go-1.22.12.inc +++ b/meta/recipes-devtools/go/go-1.22.12.inc @@ -62,6 +62,7 @@ SRC_URI += "\ file://CVE-2026-25679.patch \ file://CVE-2026-32288.patch \ file://CVE-2026-27145.patch \ + file://CVE-2026-33814.patch \ " SRC_URI[main.sha256sum] = "012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71" diff --git a/meta/recipes-devtools/go/go/CVE-2026-33814.patch b/meta/recipes-devtools/go/go/CVE-2026-33814.patch new file mode 100644 index 00000000000..8265bf205f6 --- /dev/null +++ b/meta/recipes-devtools/go/go/CVE-2026-33814.patch @@ -0,0 +1,44 @@ +From 825d42a14d8ffbdbdda87a39e78795eb17e4f0f2 Mon Sep 17 00:00:00 2001 +From: Mark Freeman <[email protected]> +Date: Fri, 17 Apr 2026 16:28:03 -0400 +Subject: [PATCH] [release-branch.go1.25] all: update x/net to a9171bc8 + +Fixes #78477 + +Change-Id: I0a4c8e25f569fc1bfb8ac39ff728bfe7300b751f +Reviewed-on: https://go-review.googlesource.com/c/go/+/768323 +Reviewed-by: Dmitri Shuralyov <[email protected]> +TryBot-Bypass: Dmitri Shuralyov <[email protected]> + +CVE: CVE-2026-33814 +Upstream-Status: Backport [https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f] + +Backport Changes: +- Omitted src/go.mod, src/go.sum, and src/vendor/modules.txt because + their x/net version updates are not required for this focused backport. +- Omitted removal of the SETTINGS_ENABLE_CONNECT_PROTOCOL-specific + s.Valid call because Go 1.22 does not contain that setting case; validation + is added at the start of the settings callback instead. + +(cherry picked from commit 9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f) +Signed-off-by: Hetvi Thakar <[email protected]> +--- + src/net/http/h2_bundle.go | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/net/http/h2_bundle.go b/src/net/http/h2_bundle.go +index c1a2e76ea4d..2f5a6d3d5a2 100644 +--- a/src/net/http/h2_bundle.go ++++ b/src/net/http/h2_bundle.go +@@ -9910,6 +9910,9 @@ func (rl *http2clientConnReadLoop) processSettingsNoWrite(f *http2SettingsFrame) + + var seenMaxConcurrentStreams bool + err := f.ForeachSetting(func(s http2Setting) error { ++ if err := s.Valid(); err != nil { ++ return err ++ } + switch s.ID { + case http2SettingMaxFrameSize: + cc.maxFrameSize = s.Val +-- +2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245675): https://lists.openembedded.org/g/openembedded-core/message/245675 Mute This Topic: https://lists.openembedded.org/mt/121207009/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
