On Tue Sep 29, 2026 at 6:18 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Hetvi Thakar <[email protected]> > > The fix for CVE-2026-86139 adds a zero-length guard in > xmlURIEscapeStr, as shown in the upstream commit [1]. > > The libxml2 2.12.10 source already contains the equivalent guard, > so no additional patch is required. Mark the CVE as fixed in the > recipe.
Can you provide a link to the function so this can be quickly verified? > > [1] > https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86139 > > Signed-off-by: Hetvi Thakar <[email protected]> > --- > meta/recipes-core/libxml/libxml2_2.12.10.bb | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb > b/meta/recipes-core/libxml/libxml2_2.12.10.bb > index 28ae601118..93b7a23754 100644 > --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb > +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb > @@ -46,6 +46,10 @@ CVE_STATUS[CVE-2023-45322] = "disputed: issue requires > memory allocation to fail > # https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 > CVE_STATUS[CVE-2025-8732] = "disputed: the code maintainer explains, that > the issue can only be triggered with untrusted SGML catalogs and it makes > absolutely no sense to use untrusted catalogs. The issue triggers a crash if > an invalid file is provided. > https://gitlab.gnome.org/GNOME/libxml2/-/issues/958" > > +# The Scarthgap 2.12.10 source already contains the equivalent zero-length > +# guard required for the xmlURIEscapeStr integer-overflow issue. > +CVE_STATUS[CVE-2026-86139] = "fixed-version: xmlURIEscapeStr returns NULL > when xmlStrlen returns zero" > + > BINCONFIG = "${bindir}/xml2-config" > > PACKAGECONFIG ??= "python \ Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247127): https://lists.openembedded.org/g/openembedded-core/message/247127 Mute This Topic: https://lists.openembedded.org/mt/121485375/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
