Backport fix for CVE-2026-3633 [1] and additional supporting patches
[2][3][4] from the upstream libsoup 3 repo.

[1] 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926
[2] 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf
[3] 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa
[4] 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8

Signed-off-by: Jason Stasiak <[email protected]>
---
 .../libsoup/libsoup-2.4/CVE-2026-3633-1.patch |  51 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-2.patch |  53 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-3.patch |  49 ++++++++
 .../libsoup/libsoup-2.4/CVE-2026-3633-4.patch | 113 ++++++++++++++++++
 .../libsoup/libsoup-2.4_2.74.3.bb             |   4 +
 5 files changed, 270 insertions(+)
 create mode 100644 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
 create mode 100644 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
 create mode 100644 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
 create mode 100644 
meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch

diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
new file mode 100644
index 0000000000..37eeb24409
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-1.patch
@@ -0,0 +1,51 @@
+From 5d61da4e261fab02d07dc74bb3049bbd13535247 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <[email protected]>
+Date: Fri, 25 Sep 2026 10:17:05 -0700
+Subject: [PATCH 1/4] CVE-2026-3633: Make SoupMessage a private and final type
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/0120f183ca2b74abeee8439f73abc8ab504fbccf
 ]
+
+Backport the introduction of soup_message_set_method() from upstream
+libsoup 3 patch to begin alignment of libsoup 2.4 code with that needed
+to address CVE-2026-3633.
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-message-private.h |  2 ++
+ libsoup/soup-message.c         | 10 ++++++++++
+ 2 files changed, 12 insertions(+)
+
+diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h
+index c30361c0..ee73112f 100644
+--- a/libsoup/soup-message-private.h
++++ b/libsoup/soup-message-private.h
+@@ -179,4 +179,6 @@ gboolean    soup_message_has_chunk_allocator (SoupMessage 
*msg);
+ SoupBuffer *soup_message_allocate_chunk      (SoupMessage *msg,
+                                             goffset      read_length);
+ 
++void  soup_message_set_method (SoupMessage        *msg,
++                                       const char         *method);
+ #endif /* __SOUP_MESSAGE_PRIVATE_H__ */
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index cc4f22b6..eae11eea 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -2394,3 +2394,13 @@ soup_message_allocate_chunk (SoupMessage *msg,
+ 
+       return priv->chunk_allocator (msg, read_length, 
priv->chunk_allocator_data);
+ }
++
++
++void
++soup_message_set_method (SoupMessage *msg,
++                         const char  *method)
++{
++      g_return_if_fail (method != NULL);
++
++      msg->method = g_intern_string (method);
++}
+\ No newline at end of file
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
new file mode 100644
index 0000000000..c98a26ee6a
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-2.patch
@@ -0,0 +1,53 @@
+From ef7fb85f6bda553c37f50606205396b1a3b363a7 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <[email protected]>
+Date: Fri, 25 Sep 2026 10:23:14 -0700
+Subject: [PATCH 2/4] CVE-2026-3633: message: ensure GObject::notify signal is
+ always emitted when properties change
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/05910f8cb577682d444b0abaef670b4eb028e2fa
 ]
+
+Backport the following portions of the libsoup 3 patch to align
+libsoup 2.4 code with that needed to address CVE-2026-3633:
+- Calling of soup_message_set_property() within soup_message_set_method()
+  for a method property change
+- Update of soup_message_set_property() which triggers the GObject::notify
+  signal when the method property changes
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-message.c | 11 ++++++++---
+ 1 file changed, 8 insertions(+), 3 deletions(-)
+
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index eae11eea..ff8aaab5 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -205,7 +205,7 @@ soup_message_set_property (GObject *object, guint prop_id,
+ 
+       switch (prop_id) {
+       case PROP_METHOD:
+-              msg->method = g_intern_string (g_value_get_string (value));
++              soup_message_set_method (msg, g_value_get_string (value));
+               break;
+       case PROP_URI:
+               soup_message_set_uri (msg, g_value_get_boxed (value));
+@@ -2400,7 +2400,12 @@ void
+ soup_message_set_method (SoupMessage *msg,
+                          const char  *method)
+ {
+-      g_return_if_fail (method != NULL);
++      const char *new_method = g_intern_string (method);
+ 
+-      msg->method = g_intern_string (method);
++      if (msg->method == new_method)
++              return;
++
++      msg->method = new_method;
++
++      g_object_notify (G_OBJECT (msg), "method");
+ }
+\ No newline at end of file
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
new file mode 100644
index 0000000000..825d7f0436
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-3.patch
@@ -0,0 +1,49 @@
+From ac0de649ae76b073c8c405f141e6509eb624ee89 Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <[email protected]>
+Date: Fri, 25 Sep 2026 10:32:36 -0700
+Subject: [PATCH 3/4] CVE-2026-3633: message: make soup_message_set_method
+ public
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/a90c442df5f980dd9a8108c9def3b06607662fc8
 ]
+
+Backport the portion of the libsoup 3 patch that transitions
+soup_message_set_method() from being a private getter to a public
+getter to align the libsoup 2.4 code with that needed to address
+CVE-2026-3633.
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-message-private.h | 2 --
+ libsoup/soup-message.h         | 4 ++++
+ 2 files changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/libsoup/soup-message-private.h b/libsoup/soup-message-private.h
+index ee73112f..c30361c0 100644
+--- a/libsoup/soup-message-private.h
++++ b/libsoup/soup-message-private.h
+@@ -179,6 +179,4 @@ gboolean    soup_message_has_chunk_allocator (SoupMessage 
*msg);
+ SoupBuffer *soup_message_allocate_chunk      (SoupMessage *msg,
+                                             goffset      read_length);
+ 
+-void  soup_message_set_method (SoupMessage        *msg,
+-                                       const char         *method);
+ #endif /* __SOUP_MESSAGE_PRIVATE_H__ */
+diff --git a/libsoup/soup-message.h b/libsoup/soup-message.h
+index 42379a4b..18066d35 100644
+--- a/libsoup/soup-message.h
++++ b/libsoup/soup-message.h
+@@ -115,6 +115,10 @@ SoupHTTPVersion  soup_message_get_http_version    
(SoupMessage       *msg);
+ SOUP_AVAILABLE_IN_2_4
+ gboolean         soup_message_is_keepalive        (SoupMessage       *msg);
+ 
++SOUP_AVAILABLE_IN_2_4
++void             soup_message_set_method          (SoupMessage        *msg,
++                                                 const char       *method);
++
+ SOUP_AVAILABLE_IN_2_4
+ SoupURI         *soup_message_get_uri             (SoupMessage       *msg);
+ SOUP_AVAILABLE_IN_2_4
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch
new file mode 100644
index 0000000000..471df33ec9
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-3633-4.patch
@@ -0,0 +1,113 @@
+From bd9d3c8c6af2783fed2745834f6623a2df70f75d Mon Sep 17 00:00:00 2001
+From: Jason Stasiak <[email protected]>
+Date: Fri, 25 Sep 2026 10:39:16 -0700
+Subject: [PATCH 4/4] Fix CVE-2026-3633
+
+CVE: CVE-2026-3633
+Upstream-Status: Backport [ 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/7f2013d874f005035f2245e382ec82823a439926
 ]
+
+Backport the upstream libsoup 3 fix for CVE-2026-3633 to
+libsoup 2.4.
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-message.c | 32 ++++++++++++++++++++++++++++++--
+ tests/misc-test.c      | 22 ++++++++++++++++++++++
+ 2 files changed, 52 insertions(+), 2 deletions(-)
+
+diff --git a/libsoup/soup-message.c b/libsoup/soup-message.c
+index ff8aaab5..08f22c19 100644
+--- a/libsoup/soup-message.c
++++ b/libsoup/soup-message.c
+@@ -2395,17 +2395,45 @@ soup_message_allocate_chunk (SoupMessage *msg,
+       return priv->chunk_allocator (msg, read_length, 
priv->chunk_allocator_data);
+ }
+ 
++/* Validates that a method string conforms to the RFC 9110 'token' 
specification. */
++static gboolean
++method_is_valid (const char *method)
++{
++      const char *p;
++
++      if (method == NULL || *method == '\0')
++              return FALSE;
++
++      for (p = method; *p != '\0'; p++) {
++      char c = *p;
++
++      if (g_ascii_isalnum (c))
++              continue;
++
++      if (strchr ("!#$%&\'*+-.^_`|~", c) == NULL)
++              return FALSE;
++      }
++
++      return TRUE;
++}
+ 
+ void
+ soup_message_set_method (SoupMessage *msg,
+                          const char  *method)
+ {
+-      const char *new_method = g_intern_string (method);
++      const char *new_method;
++
++      g_return_if_fail (method != NULL);
+ 
++      if (!method_is_valid (method)) {
++              g_warning ("soup_message_set_method: Rejecting invalid method 
'%s'", method);
++              return;
++      }
++
++      new_method = g_intern_string (method);
+       if (msg->method == new_method)
+               return;
+ 
+       msg->method = new_method;
+-
+       g_object_notify (G_OBJECT (msg), "method");
+ }
+\ No newline at end of file
+diff --git a/tests/misc-test.c b/tests/misc-test.c
+index 0f9b0d33..afb7bb30 100644
+--- a/tests/misc-test.c
++++ b/tests/misc-test.c
+@@ -89,6 +89,27 @@ server_callback (SoupServer *server, SoupMessage *msg,
+       }
+ }
+ 
++static void
++do_method_injection_test (void)
++{
++      SoupMessage *msg;
++
++      g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING,
++                             "soup_message_set_method: Rejecting invalid 
method*");
++      msg = soup_message_new_from_uri ("GET / HTTP/1.1\r\nX-Injected: evil", 
base_uri);
++      g_assert_null (msg->method);
++      g_test_assert_expected_messages ();
++      g_object_unref (msg);
++
++      g_test_expect_message ("libsoup", G_LOG_LEVEL_WARNING,
++                             "soup_message_set_method: Rejecting invalid 
method*");
++      msg = soup_message_new_from_uri (SOUP_METHOD_GET, base_uri);
++      soup_message_set_method (msg, "POST /evil HTTP/1.1\r\nHost: 
attacker\r\n\r\nGET");
++      g_assert_cmpstr (msg->method, ==, SOUP_METHOD_GET);
++      g_test_assert_expected_messages ();
++      g_object_unref (msg);
++}
++
+ /* Host header handling: client must be able to override the default
+  * value, server must be able to recognize different Host values.
+  */
+@@ -1276,6 +1297,7 @@ main (int argc, char **argv)
+ 
+       g_test_add_func ("/misc/bigheader", do_host_big_header);
+       g_test_add_func ("/misc/host", do_host_test);
++      g_test_add_func ("/misc/method-injection", do_method_injection_test);
+       g_test_add_func ("/misc/callback-unref/msg", do_callback_unref_test);
+       g_test_add_func ("/misc/callback-unref/req", 
do_callback_unref_req_test);
+       g_test_add_func ("/misc/msg-reuse", do_msg_reuse_test);
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb 
b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
index c79bced69d..19a2d96b91 100644
--- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
+++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
@@ -45,6 +45,10 @@ SRC_URI = 
"${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \
            file://CVE-2026-1801.patch \
            file://CVE-2026-2443.patch \
            file://CVE-2026-5119.patch \
+           file://CVE-2026-3633-1.patch \
+           file://CVE-2026-3633-2.patch \
+           file://CVE-2026-3633-3.patch \
+           file://CVE-2026-3633-4.patch \
 "
 SRC_URI[sha256sum] = 
"e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"
 
-- 
2.55.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246898): 
https://lists.openembedded.org/g/openembedded-core/message/246898
Mute This Topic: https://lists.openembedded.org/mt/121498019/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to