Backport fix for CVE-2026-1539 from meta-oe to OE-core.
Update CVE patch to restore the auth-redirect proxy validation
unit test from the upstream libsoup3 patch.

(From meta-oe rev: 07d67228162018f5f619dce7183f85e79293378d)

Signed-off-by: Jason Stasiak <[email protected]>
---
 .../libsoup/libsoup-2.4/CVE-2026-1539.patch   | 104 ++++++++++++++++++
 .../libsoup/libsoup-2.4_2.74.3.bb             |   1 +
 2 files changed, 105 insertions(+)
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch

diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch
new file mode 100644
index 0000000000..e8c9ee0583
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-1539.patch
@@ -0,0 +1,104 @@
+From 285faea567e1e2a95226201175dbf745a64a2439 Mon Sep 17 00:00:00 2001
+From: Changqing Li <[email protected]>
+Date: Fri, 20 Mar 2026 15:04:22 +0800
+Subject: [PATCH 4/4] Also remove Proxy-Authorization header on cross origin
+ redirect
+
+Closes #489
+
+Upstream-Status: Backport 
[https://gitlab.gnome.org/GNOME/libsoup/-/commit/98c1285d9d78662c38bf14b4a128af01ccfdb446]
+CVE: CVE-2026-1539
+
+Signed-off-by: Changqing Li <[email protected]>
+
+Backport the auth-redirect proxy validation unit tests from the upstream
+libsoup3 patch
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-session.c |  1 +
+ tests/httpd.conf.in    |  1 +
+ tests/proxy-test.c     | 36 ++++++++++++++++++++++++++++++++++++
+ 3 files changed, 38 insertions(+)
+
+diff --git a/libsoup/soup-session.c b/libsoup/soup-session.c
+index fadd5cd2..4cad0946 100644
+--- a/libsoup/soup-session.c
++++ b/libsoup/soup-session.c
+@@ -1192,6 +1192,7 @@ soup_session_redirect_message (SoupSession *session, 
SoupMessage *msg)
+       /* Strip all credentials on cross-origin redirect. */
+       if (!soup_uri_host_equal (soup_message_get_uri (msg), new_uri)) {
+               soup_message_headers_remove (msg->request_headers, 
"Authorization");
++              soup_message_headers_remove (msg->request_headers, 
"Proxy-Authorization");
+               soup_message_set_auth (msg, NULL);
+       }
+
+diff --git a/tests/httpd.conf.in b/tests/httpd.conf.in
+index 93fb7ff4..e190b6f7 100644
+--- a/tests/httpd.conf.in
++++ b/tests/httpd.conf.in
+@@ -37,6 +37,7 @@ DirectoryIndex index.txt
+ TypesConfig /dev/null
+ AddType application/x-httpd-php .php
+ Redirect permanent /redirected /index.txt
++Redirect permanent /Basic/realm1/redirected https://127.0.0.1:47525/index.txt
+
+ # Proxy #1: unauthenticated
+ Listen 127.0.0.1:47526
+diff --git a/tests/proxy-test.c b/tests/proxy-test.c
+index 1d68aa05..105a02a6 100644
+--- a/tests/proxy-test.c
++++ b/tests/proxy-test.c
+@@ -322,6 +322,41 @@ do_proxy_redirect_test (void)
+       soup_test_session_abort_unref (session);
+ }
+
++static void proxy_auth_redirect_message_restarted (SoupMessage *msg)
++{
++      if (msg->status_code != SOUP_STATUS_MOVED_PERMANENTLY)
++              return;
++
++      g_assert_null (soup_message_headers_get_one (msg->request_headers, 
"Proxy-Authorization"));
++}
++
++static void
++do_proxy_auth_redirect_test (void)
++{
++      SoupSession *session;
++      SoupMessage *msg;
++      char *url;
++
++      SOUP_TEST_SKIP_IF_NO_APACHE;
++      SOUP_TEST_SKIP_IF_NO_TLS;
++
++      session = soup_test_session_new (SOUP_TYPE_SESSION_ASYNC,
++              SOUP_SESSION_PROXY_RESOLVER, proxy_resolvers[AUTH_PROXY],
++              NULL);
++
++      url = g_strconcat (HTTP_SERVER, "/Basic/realm1/redirected", NULL);
++      msg = soup_message_new (SOUP_METHOD_GET, url);
++      g_signal_connect (session, "authenticate", G_CALLBACK (authenticate), 
NULL);
++      g_signal_connect (msg, "restarted", G_CALLBACK 
(proxy_auth_redirect_message_restarted), NULL);
++
++      soup_session_send_message (session, msg);
++      soup_test_assert_message_status (msg, SOUP_STATUS_OK);
++
++      g_free (url);
++      g_object_unref (msg);
++      soup_test_session_abort_unref (session);
++}
++
+ static void
+ do_proxy_auth_request (const char *url, SoupSession *session, gboolean 
do_read)
+ {
+@@ -433,6 +468,7 @@ main (int argc, char **argv)
+
+       g_test_add_data_func ("/proxy/fragment", base_uri, 
do_proxy_fragment_test);
+       g_test_add_func ("/proxy/redirect", do_proxy_redirect_test);
++      g_test_add_func ("/proxy/auth-redirect", do_proxy_auth_redirect_test);
+       g_test_add_func ("/proxy/auth-cache", do_proxy_auth_cache_test);
+
+       ret = g_test_run ();
+--
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb 
b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
index 7e00cd678a..4fe1e36f03 100644
--- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
+++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
@@ -41,6 +41,7 @@ SRC_URI = 
"${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \
            file://CVE-2025-4476.patch \
            file://CVE-2025-2784.patch \
            file://CVE-2025-4945.patch \
+           file://CVE-2026-1539.patch \
 "
 SRC_URI[sha256sum] = 
"e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"
 
-- 
2.55.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246894): 
https://lists.openembedded.org/g/openembedded-core/message/246894
Mute This Topic: https://lists.openembedded.org/mt/121498015/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to