Hi Yoann,

I have sent the patch for wrynose: [email protected] | 
[wrynose][PATCH] libpng: fix 
CVE-2026-34757<https://lists.openembedded.org/g/openembedded-core/topic/120362567>

Thanks for your review.

Regards,
Deepak
________________________________
From: [email protected] 
<[email protected]> on behalf of Yoann Congal via 
lists.openembedded.org <[email protected]>
Sent: Monday, July 20, 2026 3:51 AM
To: Sudhir Dumbhare -X (sudumbha - E INFOCHIPS PRIVATE LIMITED at Cisco) 
<[email protected]>; [email protected] 
<[email protected]>
Subject: Re: [OE-core][scarthgap][PATCH v2] libpng: Fix CVE-2026-34757

On Tue Jul 14, 2026 at 3:46 PM CEST, Sudhir Dumbhare via lists.openembedded.org 
wrote:
> From: Sudhir Dumbhare <[email protected]>
>
> These patches apply the upstream fixes [1][2], which address
> getter-to-setter aliasing issues in libpng chunk setters that could
> cause stale-pointer reads, as described in [3].
>
> [1] 
> https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a
> [2] 
> https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc
> [3] https://github.com/pnggroup/libpng/issues/836
>
> Reference:
> https://security-tracker.debian.org/tracker/CVE-2026-34757
> https://nvd.nist.gov/vuln/detail/CVE-2026-34757
>
> Test results on qemux86-64 using ptest-runner:
> START: ptest-runner
> 2026-06-04T11:29
> BEGIN: /usr/lib/libpng/ptest
> PASS: tests/pnggetset
> Testsuite summary
> # TOTAL: 33
> # PASS:  33
> # SKIP:  0
> # XFAIL: 0
> # FAIL:  0
> # XPASS: 0
> # ERROR: 0
> DURATION: 80
> END: /usr/lib/libpng/ptest
> 2026-06-04T11:31
> STOP: ptest-runner
> TOTAL: 1 FAIL: 0
>
> Signed-off-by: Sudhir Dumbhare <[email protected]>
> ---
> Changes v1 -> v2:
> - Rebased on latest scarthgap (2bf388381ae3)
>
>  .../libpng/files/CVE-2026-34757_p1.patch      | 521 ++++++++++++++++++
>  .../libpng/files/CVE-2026-34757_p2.patch      | 484 ++++++++++++++++
>  .../libpng/libpng_1.6.42.bb                   |   4 +-
>  3 files changed, 1008 insertions(+), 1 deletion(-)
>  create mode 100644 
> meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
>  create mode 100644 
> meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch

As fas as I can tell, this patch is also needed on wrynose.
I can't merge here until this is fixed on wrynose.

Can you send a patch to fix this and then, ping back here?

Thanks!
--
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241430): 
https://lists.openembedded.org/g/openembedded-core/message/241430
Mute This Topic: https://lists.openembedded.org/mt/120265698/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to