From: Hetvi Thakar <[email protected]> The fix for CVE-2026-86139 adds a zero-length guard in xmlURIEscapeStr, as shown in the upstream commit [1].
The libxml2 2.12.10 source already contains the equivalent guard, so no additional patch is required. Mark the CVE as fixed in the recipe. [1] https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86139 Signed-off-by: Hetvi Thakar <[email protected]> --- meta/recipes-core/libxml/libxml2_2.12.10.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 28ae601118..93b7a23754 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -46,6 +46,10 @@ CVE_STATUS[CVE-2023-45322] = "disputed: issue requires memory allocation to fail # https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 CVE_STATUS[CVE-2025-8732] = "disputed: the code maintainer explains, that the issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. The issue triggers a crash if an invalid file is provided. https://gitlab.gnome.org/GNOME/libxml2/-/issues/958" +# The Scarthgap 2.12.10 source already contains the equivalent zero-length +# guard required for the xmlURIEscapeStr integer-overflow issue. +CVE_STATUS[CVE-2026-86139] = "fixed-version: xmlURIEscapeStr returns NULL when xmlStrlen returns zero" + BINCONFIG = "${bindir}/xml2-config" PACKAGECONFIG ??= "python \ -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246811): https://lists.openembedded.org/g/openembedded-core/message/246811 Mute This Topic: https://lists.openembedded.org/mt/121485375/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
