Hi Yoann,

Thanks for the review.

I added #include <stdint.h> because SIZE_MAX is used in bitscale.c. Without
this include, the build fails with the following error:

error: 'SIZE_MAX' undeclared (first use in this function)
note: 'SIZE_MAX' is defined in header '<stdint.h>'; this is probably
fixable by adding '#include <stdint.h>'

For v2, I'll add a note explaining the reason for adding <stdint.h>, and
I'll also fix the indentation change to keep it consistent with upstream
and make future backports easier.

Thanks & Regards,
Vijay


On Fri, Sep 4, 2026 at 2:41 AM Yoann Congal <[email protected]> wrote:

> On Mon Aug 24, 2026 at 8:49 AM CEST, Vijay Anusuri via
> lists.openembedded.org wrote:
> > Pick patch according to [2]
> >
> > [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001
> > [2] https://security-tracker.debian.org/tracker/CVE-2026-56001
> >
> > Signed-off-by: Vijay Anusuri <[email protected]>
> > ---
> >  .../xorg-lib/libxfont/CVE-2026-56001.patch    | 84 +++++++++++++++++++
> >  .../xorg-lib/libxfont_1.5.4.bb                |  3 +
> >  2 files changed, 87 insertions(+)
> >  create mode 100644
> meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> >
> > diff --git
> a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> > new file mode 100644
> > index 0000000000..506a2dc22a
> > --- /dev/null
> > +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
> > @@ -0,0 +1,84 @@
> > +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001
> > +From: Peter Hutterer <[email protected]>
> > +Date: Mon, 1 Jun 2026 16:46:10 +1000
> > +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps
> > + bytestoalloc
> > +
> > +bytestoalloc is declared as unsigned int (32-bit). When the sum of
> > +per-glyph byte counts exceeds 2^32, the value wraps around and calloc()
> > +allocates a buffer that is too small. The subsequent ScaleBitmap loop
> > +then writes past the end of the allocated buffer.
> > +
> > +Change bytestoalloc from unsigned int to size_t to match the actual
> > +allocation size type, and add an explicit overflow check in the
> > +accumulation loop to bail out if the total would exceed SIZE_MAX.
> > +
> > +This vulnerability was discovered by:
> > +Anonymous working with TrendAI Zero Day Initiative
> > +
> > +CVE-2026-56001/ZDI-CAN-30558
> > +
> > +Assisted-by: Claude:claude-opus-4-6
> > +Signed-off-by: Peter Hutterer <[email protected]>
> > +Part-of: <
> https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
> > +
> > +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
> > +Upstream commit
> https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778
> ]
> > +CVE: CVE-2026-56001
> > +Signed-off-by: Vijay Anusuri <[email protected]>
>
> Hello,
>
> This patch (and also the other ones in this series) was non-trivially
> changes without a comment explaining why.
>
> > +---
> > + src/bitmap/bitscale.c | 24 +++++++++++++++++++++---
> > + 1 file changed, 21 insertions(+), 3 deletions(-)
> > +
> > +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
> > +index 13ed924..c87fa96 100644
> > +--- a/src/bitmap/bitscale.c
> > ++++ b/src/bitmap/bitscale.c
> > +@@ -38,6 +38,7 @@ from The Open Group.
> > + #include <X11/fonts/bitmap.h>
> > + #include <X11/fonts/fontutil.h>
> > + #include <math.h>
> > ++#include <stdint.h>
>               ^ This is new: I suppose to get size_t but that should be
>                             explained. Also, "man size_t" tells me that
> size_t in
>                                 stddef.h not stdint.h.
> > +
> > + #ifndef MAX
> > + #define   MAX(a,b)    (((a)>(b)) ? a : b)
> > +@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf,          /* scaled
> font */
> > +             opci;
> > +     FontInfoPtr pfi;
> > +     int         glyph;
> > +-    unsigned    bytestoalloc = 0;
> > ++    size_t      bytestoalloc = 0;
> > +     int             firstCol, lastCol, firstRow, lastRow;
> > +
> > +     double  xform[4], inv_xform[4];
> > +@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf,          /*
> scaled font */
> > +     glyph = pf->glyph;
> > +     for (i = 0; i < nchars; i++)
> > +     {
> > +-    if ((pci = ACCESSENCODING(bitmapFont->encoding, i)))
> > +-        bytestoalloc += BYTES_FOR_GLYPH(pci, glyph);
> > ++    if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) {
> > ++        size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph);
> > ++        if (bytestoalloc > SIZE_MAX - glyphsize) {
> > ++            fprintf(stderr,
> > ++                    "Error: bitmap allocation overflow for scaled
> font\n");
> > ++            goto bail;
> > ++        }
> > ++        bytestoalloc += glyphsize;
> > ++    }
> > ++    }
> > ++
> > ++    /* Reject unreasonably large bitmap allocations that could result
> > ++     * from malicious fonts with extreme scale factors.  256 MiB is
> > ++     * far beyond any legitimate scaled bitmap font. */
> > ++#define BITMAP_SCALE_MAX_ALLOC      (256 * 1024 * 1024)
> > ++    if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) {
> > ++    fprintf(stderr,
> > ++           "Error: scaled bitmap size %zu exceeds limit\n",
> bytestoalloc);
> > ++       goto bail;
>          ^ This line has been reindented from upstream, that might make
>                  future backports needlessly harder.
>
> Can you send a v2 with the changes either removed or explained in the
> patch message?
>
> Thanks!
> --
> Yoann Congal
> Smile ECS
>
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245063): 
https://lists.openembedded.org/g/openembedded-core/message/245063
Mute This Topic: https://lists.openembedded.org/mt/120899335/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to