On Mon Jul 27, 2026 at 2:14 PM CEST, Deepak Rathore via lists.openembedded.org 
wrote:
> From: Deepak Rathore <[email protected]>
>
> This patch applies the upstream 2.88.1 stable backports [1] and [2] for
> CVE-2026-58015. The main fix [1] validates the SHA-1 cookie context,
> and the helper fix [2] tightens cookie ID parsing before keyring lookup.
>
> [1] 
> https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a
> [2] 
> https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb
> [3] https://nvd.nist.gov/vuln/detail/CVE-2026-58015
>
> Signed-off-by: Deepak Rathore <[email protected]>
> ---
> Changes in v2:
> - Added the GLib stable helper commit which tightens cookie ID validation
>   before keyring lookup.
>
>  .../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch | 97 +++++++++++++++++++
>  .../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch | 54 +++++++++++
>  meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |  2 +
>  3 files changed, 153 insertions(+)
>  create mode 100644 
> meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
>  create mode 100644 
> meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch

Hello,

These patches have formating issues, I'll mark some but please check the
whole files.
>
> diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch 
> b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
> new file mode 100644
> index 0000000000..50517f23b2
> --- /dev/null
> +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
> @@ -0,0 +1,97 @@
> +From db9c8fae398b0c457e660ce63dd5afec8993046a Mon Sep 17 00:00:00 2001
> +From: Philip Withnall <[email protected]>
> +Date: Tue, 28 Apr 2026 15:47:30 +0100
> +Subject: [PATCH] gdbusauthmechanismsha1: Validate cookie context
> +MIME-Version: 1.0
> +Content-Type: text/plain; charset=UTF-8
> +Content-Transfer-Encoding: 8bit
> +
> +Without validation, the server could send a malicious context which
> +contains path traversal characters, allowing it to exfiltrate a SHA-1
> +hashed copy of arbitrary data from the client's file system.
                                                ^ this character changed
                                                                                
                from upstream.
> +
> +To exploit this successfully would require the client to choose to
> +connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
> +authentication mechanism in preference to all the other mechanisms. This
> +is vanishingly unlikely.
> +
> +Fixes: #3931
> +
> +CVE: CVE-2026-58015
> +Upstream-Status: Backport 
> [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a]
> +
> +Backport Changes:
> +- Added <stdint.h> include because the target branch does not otherwise
> +  expose uint8_t used by the upstream validation code during native builds.
> +
> +Signed-off-by: Philip Withnall <[email protected]>
> +(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a)
> +Signed-off-by: Deepak Rathore <[email protected]>
> +---
> + gio/gdbusauthmechanismsha1.c | 37 +++++++++++++++++++++++++++++++++++++
> + 1 file changed, 37 insertions(+)
> +
> +diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
> +index c8aa08977c..7f348d862d 100644
> +--- a/gio/gdbusauthmechanismsha1.c
> ++++ b/gio/gdbusauthmechanismsha1.c
> +@@ -22,6 +22,7 @@
> +
   ^ It lacks a whitespace for context here
> + #include "config.h"
> +
   ^ ... also here.
> ++#include <stdint.h>
> + #include <string.h>
> + #include <fcntl.h>
> + #include <errno.h>
> +@@ -1198,6 +1199,34 @@ mechanism_client_initiate (GDBusAuthMechanism   
> *mechanism,
> +   return initial_response;
> + }
> +
> ++/* Context names must be valid ASCII, nonzero length, and may not contain 
> the
> ++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
> ++ * carriage return ("\r"), tab ("\t"), or period (".").
> ++ *
> ++ * See 
> https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha 
> */
> ++static gboolean
> ++validate_cookie_context (const char *cookie_context)
> ++{
> ++  size_t i = 0;
> ++
> ++  g_return_val_if_fail (cookie_context != NULL, FALSE);
> ++
> ++  for (i = 0; cookie_context[i] != '\0'; i++)
> ++    {
> ++      if ((uint8_t) cookie_context[i] >= 128 ||
> ++          cookie_context[i] == '/' ||
> ++          cookie_context[i] == '\\' ||
> ++          cookie_context[i] == ' ' ||
> ++          cookie_context[i] == '\n' ||
> ++          cookie_context[i] == '\r' ||
> ++          cookie_context[i] == '\t' ||
> ++          cookie_context[i] == '.')
> ++        return FALSE;
> ++    }
> ++
> ++  return (i > 0);
> ++}
> ++
> + static void
> + mechanism_client_data_receive (GDBusAuthMechanism   *mechanism,
> +                                const gchar          *data,
> +@@ -1232,6 +1261,14 @@ mechanism_client_data_receive (GDBusAuthMechanism   
> *mechanism,
> +     }
> +
> +   cookie_context = tokens[0];
> ++  if (!validate_cookie_context (tokens[0]))
> ++    {
> ++      g_free (m->priv->reject_reason);
> ++      m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context 
> '%s'", tokens[0]);
> ++      m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
> ++      goto out;
> ++    }
> ++
> +   cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
> +   if (*endp != '\0')
> +     {
> +--
> +GitLab
> diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch 
> b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
> new file mode 100644
> index 0000000000..dd814e192d
> --- /dev/null
> +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
> @@ -0,0 +1,54 @@
> +From c0531125344bb25fd66ffb7435ed6c285de09aeb Mon Sep 17 00:00:00 2001
> +From: Philip Withnall <[email protected]>
> +Date: Tue, 28 Apr 2026 15:49:54 +0100
> +Subject: [PATCH] gdbusauthmechanismsha1: Improve validation of cookie ID
> +MIME-Version: 1.0
> +Content-Type: text/plain; charset=UTF-8
> +Content-Transfer-Encoding: 8bit
> +
> +The D-Bus specification says the cookie ID has to be non-negative, but
> +we weren't checking that (or checking that it was non-empty).
> +
> +CVE: CVE-2026-58015
> +Upstream-Status: Backport 
> [https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb]
> +
> +Signed-off-by: Philip Withnall <[email protected]>
> +(cherry picked from commit c0531125344bb25fd66ffb7435ed6c285de09aeb)
> +Signed-off-by: Deepak Rathore <[email protected]>
> +---
> + gio/gdbusauthmechanismsha1.c | 6 +++---
> + 1 file changed, 3 insertions(+), 3 deletions(-)
> +
> +diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
> +index 7f348d862d..3c17f81a19 100644
> +--- a/gio/gdbusauthmechanismsha1.c
> ++++ b/gio/gdbusauthmechanismsha1.c
> +@@ -1234,7 +1234,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   
> *mechanism,
> +   GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
> +   gchar **tokens;
> +   const gchar *cookie_context;
> +-  guint cookie_id;
> ++  int64_t cookie_id;
> +   const gchar *server_challenge;
> +   gchar *client_challenge;
> +   gchar *endp;
> +@@ -1269,7 +1269,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   
> *mechanism,
> +     }
> +
> +   cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
> +-  if (*endp != '\0')
> ++  if (*endp != '\0' || endp == tokens[1] || cookie_id < 0 || cookie_id > 
> UINT32_MAX)
> +     {
> +       g_free (m->priv->reject_reason);
> +       m->priv->reject_reason = g_strdup_printf ("Malformed cookie_id '%s'", 
> tokens[1]);
> +@@ -1279,7 +1279,7 @@ mechanism_client_data_receive (GDBusAuthMechanism   
> *mechanism,
> +   server_challenge = tokens[2];
> +
> +   error = NULL;
> +-  cookie = keyring_lookup_entry (cookie_context, cookie_id, &error);
> ++  cookie = keyring_lookup_entry (cookie_context, (unsigned int) cookie_id, 
> &error);
> +   if (cookie == NULL)
> +     {
> +       g_free (m->priv->reject_reason);
> +--
> +GitLab
> diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb 
> b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
> index e15aa1fe20..c2feff8988 100644
> --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
> +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
> @@ -54,6 +54,8 @@ SRC_URI = 
> "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
>             file://CVE-2026-58012.patch \
>             file://CVE-2026-58013.patch \
>             file://CVE-2026-58014.patch \
> +           file://CVE-2026-58015_p1.patch \
> +           file://CVE-2026-58015_p2.patch \
>             "
>  SRC_URI:append:class-native = " file://relocate-modules.patch \
>                                  
> file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242102): 
https://lists.openembedded.org/g/openembedded-core/message/242102
Mute This Topic: https://lists.openembedded.org/mt/120465701/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to