Hi Yoann, I have sent the patch for wrynose: [email protected] | [wrynose][PATCH] libpng: fix CVE-2026-34757<https://lists.openembedded.org/g/openembedded-core/topic/120362567>
Thanks for your review. Regards, Deepak ________________________________ From: [email protected] <[email protected]> on behalf of Yoann Congal via lists.openembedded.org <[email protected]> Sent: Monday, July 20, 2026 3:51 AM To: Sudhir Dumbhare -X (sudumbha - E INFOCHIPS PRIVATE LIMITED at Cisco) <[email protected]>; [email protected] <[email protected]> Subject: Re: [OE-core][scarthgap][PATCH v2] libpng: Fix CVE-2026-34757 On Tue Jul 14, 2026 at 3:46 PM CEST, Sudhir Dumbhare via lists.openembedded.org wrote: > From: Sudhir Dumbhare <[email protected]> > > These patches apply the upstream fixes [1][2], which address > getter-to-setter aliasing issues in libpng chunk setters that could > cause stale-pointer reads, as described in [3]. > > [1] > https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a > [2] > https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc > [3] https://github.com/pnggroup/libpng/issues/836 > > Reference: > https://security-tracker.debian.org/tracker/CVE-2026-34757 > https://nvd.nist.gov/vuln/detail/CVE-2026-34757 > > Test results on qemux86-64 using ptest-runner: > START: ptest-runner > 2026-06-04T11:29 > BEGIN: /usr/lib/libpng/ptest > PASS: tests/pnggetset > Testsuite summary > # TOTAL: 33 > # PASS: 33 > # SKIP: 0 > # XFAIL: 0 > # FAIL: 0 > # XPASS: 0 > # ERROR: 0 > DURATION: 80 > END: /usr/lib/libpng/ptest > 2026-06-04T11:31 > STOP: ptest-runner > TOTAL: 1 FAIL: 0 > > Signed-off-by: Sudhir Dumbhare <[email protected]> > --- > Changes v1 -> v2: > - Rebased on latest scarthgap (2bf388381ae3) > > .../libpng/files/CVE-2026-34757_p1.patch | 521 ++++++++++++++++++ > .../libpng/files/CVE-2026-34757_p2.patch | 484 ++++++++++++++++ > .../libpng/libpng_1.6.42.bb | 4 +- > 3 files changed, 1008 insertions(+), 1 deletion(-) > create mode 100644 > meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch > create mode 100644 > meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch As fas as I can tell, this patch is also needed on wrynose. I can't merge here until this is fixed on wrynose. Can you send a patch to fix this and then, ping back here? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241430): https://lists.openembedded.org/g/openembedded-core/message/241430 Mute This Topic: https://lists.openembedded.org/mt/120265698/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
