Hi Yoann, Thanks for the review.
I added #include <stdint.h> because SIZE_MAX is used in bitscale.c. Without this include, the build fails with the following error: error: 'SIZE_MAX' undeclared (first use in this function) note: 'SIZE_MAX' is defined in header '<stdint.h>'; this is probably fixable by adding '#include <stdint.h>' For v2, I'll add a note explaining the reason for adding <stdint.h>, and I'll also fix the indentation change to keep it consistent with upstream and make future backports easier. Thanks & Regards, Vijay On Fri, Sep 4, 2026 at 2:41 AM Yoann Congal <[email protected]> wrote: > On Mon Aug 24, 2026 at 8:49 AM CEST, Vijay Anusuri via > lists.openembedded.org wrote: > > Pick patch according to [2] > > > > [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001 > > [2] https://security-tracker.debian.org/tracker/CVE-2026-56001 > > > > Signed-off-by: Vijay Anusuri <[email protected]> > > --- > > .../xorg-lib/libxfont/CVE-2026-56001.patch | 84 +++++++++++++++++++ > > .../xorg-lib/libxfont_1.5.4.bb | 3 + > > 2 files changed, 87 insertions(+) > > create mode 100644 > meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch > > > > diff --git > a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch > b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch > > new file mode 100644 > > index 0000000000..506a2dc22a > > --- /dev/null > > +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch > > @@ -0,0 +1,84 @@ > > +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001 > > +From: Peter Hutterer <[email protected]> > > +Date: Mon, 1 Jun 2026 16:46:10 +1000 > > +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps > > + bytestoalloc > > + > > +bytestoalloc is declared as unsigned int (32-bit). When the sum of > > +per-glyph byte counts exceeds 2^32, the value wraps around and calloc() > > +allocates a buffer that is too small. The subsequent ScaleBitmap loop > > +then writes past the end of the allocated buffer. > > + > > +Change bytestoalloc from unsigned int to size_t to match the actual > > +allocation size type, and add an explicit overflow check in the > > +accumulation loop to bail out if the total would exceed SIZE_MAX. > > + > > +This vulnerability was discovered by: > > +Anonymous working with TrendAI Zero Day Initiative > > + > > +CVE-2026-56001/ZDI-CAN-30558 > > + > > +Assisted-by: Claude:claude-opus-4-6 > > +Signed-off-by: Peter Hutterer <[email protected]> > > +Part-of: < > https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34> > > + > > +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1 > > +Upstream commit > https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778 > ] > > +CVE: CVE-2026-56001 > > +Signed-off-by: Vijay Anusuri <[email protected]> > > Hello, > > This patch (and also the other ones in this series) was non-trivially > changes without a comment explaining why. > > > +--- > > + src/bitmap/bitscale.c | 24 +++++++++++++++++++++--- > > + 1 file changed, 21 insertions(+), 3 deletions(-) > > + > > +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c > > +index 13ed924..c87fa96 100644 > > +--- a/src/bitmap/bitscale.c > > ++++ b/src/bitmap/bitscale.c > > +@@ -38,6 +38,7 @@ from The Open Group. > > + #include <X11/fonts/bitmap.h> > > + #include <X11/fonts/fontutil.h> > > + #include <math.h> > > ++#include <stdint.h> > ^ This is new: I suppose to get size_t but that should be > explained. Also, "man size_t" tells me that > size_t in > stddef.h not stdint.h. > > + > > + #ifndef MAX > > + #define MAX(a,b) (((a)>(b)) ? a : b) > > +@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled > font */ > > + opci; > > + FontInfoPtr pfi; > > + int glyph; > > +- unsigned bytestoalloc = 0; > > ++ size_t bytestoalloc = 0; > > + int firstCol, lastCol, firstRow, lastRow; > > + > > + double xform[4], inv_xform[4]; > > +@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf, /* > scaled font */ > > + glyph = pf->glyph; > > + for (i = 0; i < nchars; i++) > > + { > > +- if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) > > +- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph); > > ++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) { > > ++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph); > > ++ if (bytestoalloc > SIZE_MAX - glyphsize) { > > ++ fprintf(stderr, > > ++ "Error: bitmap allocation overflow for scaled > font\n"); > > ++ goto bail; > > ++ } > > ++ bytestoalloc += glyphsize; > > ++ } > > ++ } > > ++ > > ++ /* Reject unreasonably large bitmap allocations that could result > > ++ * from malicious fonts with extreme scale factors. 256 MiB is > > ++ * far beyond any legitimate scaled bitmap font. */ > > ++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024) > > ++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) { > > ++ fprintf(stderr, > > ++ "Error: scaled bitmap size %zu exceeds limit\n", > bytestoalloc); > > ++ goto bail; > ^ This line has been reindented from upstream, that might make > future backports needlessly harder. > > Can you send a v2 with the changes either removed or explained in the > patch message? > > Thanks! > -- > Yoann Congal > Smile ECS > >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245063): https://lists.openembedded.org/g/openembedded-core/message/245063 Mute This Topic: https://lists.openembedded.org/mt/120899335/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
