On Sun, 2026-08-30 at 23:14 -0700, Hetvi Thakar -X (hthakar - E
INFOCHIPS PRIVATE LIMITED at Cisco) wrote:
> From: Hetvi Thakar <[email protected]>
> 
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
> 
> [1] 
> https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f
> [2] https://pkg.go.dev/vuln/GO-2026-4918
> 
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
>  meta/recipes-devtools/go/go-1.22.12.inc       |  1 +
>  .../go/go/CVE-2026-33814.patch                | 44 +++++++++++++++++++
>  2 files changed, 45 insertions(+)
>  create mode 100644 meta/recipes-devtools/go/go/CVE-2026-33814.patch
> 
> diff --git a/meta/recipes-devtools/go/go-1.22.12.inc 
> b/meta/recipes-devtools/go/go-1.22.12.inc
> index 99c5f8b63b..ee2f5ca277 100644
> --- a/meta/recipes-devtools/go/go-1.22.12.inc
> +++ b/meta/recipes-devtools/go/go-1.22.12.inc
> @@ -62,6 +62,7 @@ SRC_URI += "\
>      file://CVE-2026-25679.patch \
>      file://CVE-2026-32288.patch \
>      file://CVE-2026-27145.patch \
> +    file://CVE-2026-33814.patch \
>  "
>  SRC_URI[main.sha256sum] = 
> "012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71"
>  
> diff --git a/meta/recipes-devtools/go/go/CVE-2026-33814.patch 
> b/meta/recipes-devtools/go/go/CVE-2026-33814.patch
> new file mode 100644
> index 0000000000..8265bf205f
> --- /dev/null
> +++ b/meta/recipes-devtools/go/go/CVE-2026-33814.patch
> @@ -0,0 +1,44 @@
> +From 825d42a14d8ffbdbdda87a39e78795eb17e4f0f2 Mon Sep 17 00:00:00 2001
> +From: Mark Freeman <[email protected]>
> +Date: Fri, 17 Apr 2026 16:28:03 -0400
> +Subject: [PATCH] [release-branch.go1.25] all: update x/net to a9171bc8
> +
> +Fixes #78477
> +
> +Change-Id: I0a4c8e25f569fc1bfb8ac39ff728bfe7300b751f
> +Reviewed-on: https://go-review.googlesource.com/c/go/+/768323
> +Reviewed-by: Dmitri Shuralyov <[email protected]>
> +TryBot-Bypass: Dmitri Shuralyov <[email protected]>
> +
> +CVE: CVE-2026-33814
> +Upstream-Status: Backport 
> [https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f]
> +
> +Backport Changes:
> +- Omitted src/go.mod, src/go.sum, and src/vendor/modules.txt because
> +  their x/net version updates are not required for this focused backport.

Hi Hetvi, Yoann,

My Go knowledge is limited, but omitting the go.mod/go.sum changes
didn't seem right to me. Those files track dependencies.

Looking in to it a bit further, the CVE description is:

    When processing HTTP/2 SETTINGS frames, transport will enter an
    infinite loop of writing CONTINUATION frames if it receives a
    SETTINGS_MAX_FRAME_SIZE with a value of 0.

The commit message is "all: update x/net to a9171bc8", if we look at
that commit in the x/net go module [1] it makes other changes which look
relevant to this CVE.

[1]: 
https://go.googlesource.com/net/+/a9171bc8c6f19c50efad8880f96e361359ed5307%5E%21/

Could we check if the backport submitted here is a complete fix? As I
say, my Go knowledge is limited, and I'm not sure how we would pick up
changes to the x/net module if we need to.

Best regards,

-- 
Paul Barker

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246065): 
https://lists.openembedded.org/g/openembedded-core/message/246065
Mute This Topic: https://lists.openembedded.org/mt/121009648/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Paul Barker

Reply via email to