From: Sourav Kumar Pramanik <[email protected]> This change fixes CVE-2026-5450
Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead] Comment: Patch refreshed as per glibc 2.39 source code Signed-off-by: Sourav Kumar Pramanik <[email protected]> --- .../glibc/glibc/CVE-2026-5450.patch | 113 ++++++++++++++++++ meta/recipes-core/glibc/glibc_2.39.bb | 1 + 2 files changed, 114 insertions(+) create mode 100644 meta/recipes-core/glibc/glibc/CVE-2026-5450.patch diff --git a/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch b/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch new file mode 100644 index 0000000000..adea5c3f01 --- /dev/null +++ b/meta/recipes-core/glibc/glibc/CVE-2026-5450.patch @@ -0,0 +1,113 @@ +From 839898777226a3ed88c0859f25ffe712519b4ead Mon Sep 17 00:00:00 2001 +From: Rocket Ma <[email protected]> +Date: Fri, 17 Apr 2026 23:48:41 -0700 +Subject: [PATCH] stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] + +* stdio-common/vfscanf-internal.c: When enlarging allocated buffer with +format %mc or %mC, glibc allocates one byte less, leading to +user-controlled one byte overflow. This commit fixes BZ #34008, or +CVE-2026-5450. + +CVE: CVE-2026-5450 +Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead] +Comment: Patch refreshed as per glibc 2.39 source code + +Reviewed-by: Carlos O'Donell <[email protected]> +Signed-off-by: Rocket Ma <[email protected]> +Reviewed-by: H.J. Lu <[email protected]> +Signed-off-by: Sourav Kumar Pramanik <[email protected]> +--- + stdio-common/Makefile | 4 ++++ + stdio-common/tst-vfscanf-bz34008.c | 48 +++++++++++++++++++++++++++++++++++++ + stdio-common/vfscanf-internal.c | 6 +++--- + 3 files changed, 55 insertions(+), 3 deletions(-) + create mode 100644 stdio-common/tst-vfscanf-bz34008.c + +diff --git a/stdio-common/Makefile b/stdio-common/Makefile +--- a/stdio-common/Makefile ++++ b/stdio-common/Makefile +@@ -266,6 +266,7 @@ tests := \ + tst-vfprintf-width-i18n \ + tst-vfprintf-width-prec \ + tst-vfprintf-width-prec-alloc \ ++ tst-vfscanf-bz34008 \ + tst-wc-printf \ + tstdiomisc \ + tstgetln \ +@@ -401,6 +402,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ + tst-vfprintf-width-prec-ENV = \ + MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ + LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so ++tst-vfscanf-bz34008-ENV = \ ++ MALLOC_CHECK_=3 \ ++ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so + tst-printf-bz25691-ENV = \ + MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ + LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so +diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c +new file mode 100644 +--- /dev/null ++++ b/stdio-common/tst-vfscanf-bz34008.c +@@ -0,0 +1,48 @@ ++/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) ++ Copyright (C) 2026 The GNU Toolchain Authors. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ <https://www.gnu.org/licenses/>. */ ++ ++#include "malloc/mcheck.h" ++#include <stddef.h> ++#include <stdio.h> ++#include <string.h> ++#include <wchar.h> ++#include <stdlib.h> ++#include <malloc.h> ++#include <support/check.h> ++ ++#define WIDTH 0x410 ++#define SCANFSTR "%1040mc" ++static int ++do_test (void) ++{ ++ mcheck_pedantic (NULL); ++ char *input = malloc (WIDTH + 1); ++ TEST_VERIFY (input != NULL); ++ memset (input, 'A', WIDTH); ++ input[WIDTH] = '\0'; ++ ++ char *buf = NULL; ++ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); ++ TEST_VERIFY (buf != NULL); ++ ++ free (buf); ++ free (input); ++ return 0; ++} ++ ++#include <support/test-driver.c> +diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c +--- a/stdio-common/vfscanf-internal.c ++++ b/stdio-common/vfscanf-internal.c +@@ -857 +857 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, +- + (strsize >= width ? width - 1 : strsize); ++ + (strsize >= width ? width : strsize); +@@ -928 +928 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, +- = strsize + (strsize > width ? width - 1 : strsize); ++ = strsize + (strsize >= width ? width : strsize); +@@ -983 +983 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, +- = strsize + (strsize > width ? width - 1 : strsize); ++ = strsize + (strsize >= width ? width : strsize); +-- +2.43.7 diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb index 88ad5e44e8..b01225e530 100644 --- a/meta/recipes-core/glibc/glibc_2.39.bb +++ b/meta/recipes-core/glibc/glibc_2.39.bb @@ -57,6 +57,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \ file://0023-qemu-stale-process.patch \ file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \ file://0024-CVE-2026-5435.patch \ + file://CVE-2026-5450.patch \ " S = "${WORKDIR}/git" B = "${WORKDIR}/build-${TARGET_SYS}" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246951): https://lists.openembedded.org/g/openembedded-core/message/246951 Mute This Topic: https://lists.openembedded.org/mt/121505922/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
