This should be submitted also to master.

> -----Original Message-----
> From: [email protected] <openembedded-
> [email protected]> On Behalf Of Yogita Urade -X (yurade - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
> Sent: Monday, September 28, 2026 6:27 PM
> To: [email protected]
> Subject: [OE-core][wrynose][PATCH] bison: Fix CVE-2026-56390
> 
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
> 
> [1]
> https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448
> c925513742d4efcf0
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56390
> 
> Signed-off-by: Yogita Urade <[email protected]>
> ---
>  .../bison/bison/CVE-2026-56390.patch          | 236 ++++++++++++++++++
>  meta/recipes-devtools/bison/bison_3.8.2.bb    |   1 +
>  2 files changed, 237 insertions(+)
>  create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56390.patch
> 
> diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56390.patch 
> b/meta/recipes-
> devtools/bison/bison/CVE-2026-56390.patch
> new file mode 100644
> index 0000000000..82a80a3a28
> --- /dev/null
> +++ b/meta/recipes-devtools/bison/bison/CVE-2026-56390.patch
> @@ -0,0 +1,236 @@
> +From 81b11844fcbc7abb3df91c629cd2f2c076f107cc Mon Sep 17 00:00:00 2001
> +From: Paul Eggert <[email protected]>
> +Date: Thu, 23 Apr 2026 12:41:25 -0700
> +Subject: [PATCH] bison: tighten up output file names
> +MIME-Version: 1.0
> +Content-Type: text/plain; charset=UTF-8
> +Content-Transfer-Encoding: 8bit
> +
> +Problem reported by Michał Majchrowicz.
> +* src/parse-gram.y: Do not allow '/' in %header and %output directives.
> +
> +CVE: CVE-2026-56390
> +Upstream-Status: Backport
> [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a44
> 8c925513742d4efcf0]
> +
> +Backport Changes:
> +- Adapted generated src/parse-gram.c to the Bison 3.8.2 source tree.
> +- omitted upstream generator-version/copyright metadata and
> +  src/parse-gram.h-only metadata changes while retaining the
> +  security-relevant parser changes.
> +
> +(cherry picked from commit 8d101c19d4d9aaedf83a448c925513742d4efcf0)
> +Signed-off-by: Yogita Urade <[email protected]>
> +---
> + THANKS           |  1 +
> + doc/bison.texi   |  2 ++
> + src/parse-gram.c | 56 ++++++++++++++++++++++++++++++++----------------
> + src/parse-gram.y | 31 ++++++++++++++++++++++-----
> + 4 files changed, 67 insertions(+), 23 deletions(-)
> +
> +diff --git a/THANKS b/THANKS
> +index be743a23..0e481561 100644
> +--- a/THANKS
> ++++ b/THANKS
> +@@ -128,6 +128,7 @@ Michael Catanzaro         [email protected]
> + Michael Felt              [email protected]
> + Michael Hayes             [email protected]
> + Michael Raskin            [email protected]
> ++Michał Majchrowicz        [email protected]
> + Michel d'Hooge            [email protected]
> + Michiel De Wilde          [email protected]
> + Mickael Labau             [email protected]
> +diff --git a/doc/bison.texi b/doc/bison.texi
> +index a559649c..44a4e159 100644
> +--- a/doc/bison.texi
> ++++ b/doc/bison.texi
> +@@ -5973,6 +5973,7 @@ Introduced in Bison 3.8.
> +
> + @deffn {Directive} %header @var{header-file}
> + Same as above, but save in the file @file{@var{header-file}}.
> ++The @var{header-file} name should not contain slashes.
> + @end deffn
> +
> + @deffn {Directive} %language "@var{language}"
> +@@ -6026,6 +6027,7 @@ file, treating it as an independent source file in its 
> own
> right.
> +
> + @deffn {Directive} %output "@var{file}"
> + Generate the parser implementation in @file{@var{file}}.
> ++The @var{file} name should not contain slashes.
> + @end deffn
> +
> + @deffn {Directive} %pure-parser
> +diff --git a/src/parse-gram.c b/src/parse-gram.c
> +index 3c1d8229..7f6deb33 100644
> +--- a/src/parse-gram.c
> ++++ b/src/parse-gram.c
> +@@ -276,8 +276,11 @@ typedef enum yysymbol_kind_t yysymbol_kind_t;
> +      string from the scanner (should be CODE). */
> +   static char const *translate_code_braceless (char *code, location loc);
> +
> ++  /* Is FILE a valid output file name?  */
> ++  static bool valid_output_file_name (char const *file);
> ++
> +   /* Handle a %header directive.  */
> +-  static void handle_header (char const *value);
> ++  static void handle_header (location const *loc, char const *value);
> +
> +   /* Handle a %error-verbose directive.  */
> +   static void handle_error_verbose (location const *loc, char const 
> *directive);
> +@@ -663,19 +666,19 @@ union yyalloc
> + /* YYRLINE[YYN] -- Source line where rule number YYN was defined.  */
> + static const yytype_int16 yyrline[] =
> + {
> +-       0,   310,   310,   319,   320,   324,   325,   331,   335,   340,
> +-     341,   342,   343,   344,   345,   350,   355,   356,   357,   358,
> +-     359,   360,   360,   361,   362,   363,   364,   365,   366,   367,
> +-     368,   372,   373,   382,   383,   387,   398,   402,   406,   414,
> +-     424,   425,   435,   436,   442,   455,   455,   460,   460,   465,
> +-     465,   470,   480,   481,   482,   483,   488,   489,   493,   494,
> +-     499,   500,   504,   505,   509,   510,   511,   524,   533,   537,
> +-     541,   549,   550,   554,   567,   568,   573,   574,   575,   593,
> +-     597,   601,   609,   611,   616,   623,   633,   637,   641,   649,
> +-     655,   668,   669,   675,   676,   677,   684,   684,   692,   693,
> +-     694,   699,   702,   704,   706,   708,   710,   712,   714,   716,
> +-     718,   723,   724,   733,   757,   758,   759,   760,   772,   774,
> +-     798,   803,   804,   809,   817,   818
> ++       0,   314,   314,   323,   324,   328,   329,   335,   339,   344,
> ++     345,   346,   347,   348,   349,   354,   359,   360,   361,   362,
> ++     363,   372,   372,   373,   374,   375,   376,   377,   378,   379,
> ++     380,   384,   385,   394,   395,   399,   410,   414,   418,   426,
> ++     436,   437,   447,   448,   454,   467,   467,   472,   472,   477,
> ++     477,   482,   492,   493,   494,   495,   500,   501,   505,   506,
> ++     511,   512,   516,   517,   521,   522,   523,   536,   545,   549,
> ++     553,   561,   562,   566,   579,   580,   585,   586,   587,   605,
> ++     609,   613,   621,   623,   628,   635,   645,   649,   653,   661,
> ++     667,   680,   681,   687,   688,   689,   696,   696,   704,   705,
> ++     706,   711,   714,   716,   718,   720,   722,   724,   726,   728,
> ++     730,   735,   736,   745,   769,   770,   771,   772,   784,   786,
> ++     810,   815,   816,   821,   829,   830
> + };
> + #endif
> +
> +@@ -2217,7 +2220,7 @@ yyreduce:
> +
> +   case 9: /* prologue_declaration: "%header" string.opt  */
> + #line 340 "src/parse-gram.y"
> +-                                   { handle_header ((yyvsp[0].yykind_75)); }
> ++                                   { handle_header (&(yylsp[0]), 
> (yyvsp[0].yykind_75)); }
> + #line 2222 "src/parse-gram.c"
> +     break;
> +
> +@@ -2289,7 +2292,14 @@ yyreduce:
> +
> +   case 20: /* prologue_declaration: "%output" "string"  */
> + #line 359 "src/parse-gram.y"
> +-                                { spec_outfile = unquote 
> ((yyvsp[0].STRING));
> gram_scanner_last_string_free (); }
> ++    {
> ++      char *file = unquote ((yyvsp[0].STRING));
> ++      if (valid_output_file_name (file))
> ++        spec_outfile = file;
> ++      else
> ++        complain (&(yylsp[0]), complaint, _("invalid %%output file name 
> ignored"));
> ++      gram_scanner_last_string_free ();
> ++    }
> + #line 2294 "src/parse-gram.c"
> +     break;
> +
> +@@ -3290,14 +3300,24 @@ add_param (param_type type, char *decl, location loc)
> + }
> +
> +
> ++static bool
> ++valid_output_file_name (char const *file)
> ++{
> ++  return !strchr (file, '/');
> ++}
> ++
> ++
> + static void
> +-handle_header (char const *value)
> ++handle_header (location const *loc, char const *value)
> + {
> +   header_flag = true;
> +   if (value)
> +     {
> +       char *file = unquote (value);
> +-      spec_header_file = xstrdup (file);
> ++      if (valid_output_file_name (file))
> ++        spec_header_file = xstrdup (file);
> ++      else
> ++        complain (loc, complaint, _("invalid %%header file name ignored"));
> +       gram_scanner_last_string_free ();
> +       unquote_free (file);
> +     }
> +diff --git a/src/parse-gram.y b/src/parse-gram.y
> +index 15180cb5..114c5c44 100644
> +--- a/src/parse-gram.y
> ++++ b/src/parse-gram.y
> +@@ -95,8 +95,11 @@
> +      string from the scanner (should be CODE). */
> +   static char const *translate_code_braceless (char *code, location loc);
> +
> ++  /* Is FILE a valid output file name?  */
> ++  static bool valid_output_file_name (char const *file);
> ++
> +   /* Handle a %header directive.  */
> +-  static void handle_header (char const *value);
> ++  static void handle_header (location const *loc, char const *value);
> +
> +   /* Handle a %error-verbose directive.  */
> +   static void handle_error_verbose (location const *loc, char const 
> *directive);
> +@@ -337,7 +340,7 @@ prologue_declaration:
> +       muscle_percent_define_insert ($2, @$, $3.kind, $3.chars,
> +                                     MUSCLE_PERCENT_DEFINE_GRAMMAR_FILE);
> +     }
> +-| "%header" string.opt             { handle_header ($2); }
> ++| "%header" string.opt             { handle_header (&@2, $2); }
> + | "%error-verbose"                 { handle_error_verbose (&@$, $1); }
> + | "%expect" INT_LITERAL            { expected_sr_conflicts = $2; }
> + | "%expect-rr" INT_LITERAL         { expected_rr_conflicts = $2; }
> +@@ -356,7 +359,15 @@ prologue_declaration:
> + | "%name-prefix" STRING         { handle_name_prefix (&@$, $1, $2); }
> + | "%no-lines"                   { no_lines_flag = true; }
> + | "%nondeterministic-parser"    { nondeterministic_parser = true; }
> +-| "%output" STRING              { spec_outfile = unquote ($2);
> gram_scanner_last_string_free (); }
> ++| "%output" STRING
> ++    {
> ++      char *file = unquote ($2);
> ++      if (valid_output_file_name (file))
> ++        spec_outfile = file;
> ++      else
> ++        complain (&@2, complaint, _("invalid %%output file name ignored"));
> ++      gram_scanner_last_string_free ();
> ++    }
> + | "%param" { current_param = $1; } params { current_param = param_none; }
> + | "%pure-parser"                { handle_pure_parser (&@$, $1); }
> + | "%require" STRING             { handle_require (&@2, $2); }
> +@@ -952,14 +963,24 @@ add_param (param_type type, char *decl, location loc)
> + }
> +
> +
> ++static bool
> ++valid_output_file_name (char const *file)
> ++{
> ++  return !strchr (file, '/');
> ++}
> ++
> ++
> + static void
> +-handle_header (char const *value)
> ++handle_header (location const *loc, char const *value)
> + {
> +   header_flag = true;
> +   if (value)
> +     {
> +       char *file = unquote (value);
> +-      spec_header_file = xstrdup (file);
> ++      if (valid_output_file_name (file))
> ++        spec_header_file = xstrdup (file);
> ++      else
> ++        complain (loc, complaint, _("invalid %%header file name ignored"));
> +       gram_scanner_last_string_free ();
> +       unquote_free (file);
> +     }
> +--
> +2.44.4
> +
> diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes-
> devtools/bison/bison_3.8.2.bb
> index 9808a96e99..08962ae133 100644
> --- a/meta/recipes-devtools/bison/bison_3.8.2.bb
> +++ b/meta/recipes-devtools/bison/bison_3.8.2.bb
> @@ -13,6 +13,7 @@ SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \
>             file://autoconf-2.73.patch \
>             file://add-with-bisonlocaledir.patch \
>             file://CVE-2026-56389.patch \
> +           file://CVE-2026-56390.patch \
>             "
>  SRC_URI[sha256sum] =
> "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2"
> 
> --
> 2.44.4

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246783): 
https://lists.openembedded.org/g/openembedded-core/message/246783
Mute This Topic: https://lists.openembedded.org/mt/121475043/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Yogita Urade -X (yurade - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Peter Marko via lists.openembedded.org

Reply via email to