From: Ankur Tyagi <[email protected]> Debian[1] also identified the fix.
[1]https://security-tracker.debian.org/tracker/CVE-2026-44950 Signed-off-by: Ankur Tyagi <[email protected]> --- .../xorg-lib/libxfont2/CVE-2026-44950.patch | 99 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 100 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch new file mode 100644 index 0000000000..96e3c1f0a8 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch @@ -0,0 +1,99 @@ +From b48aa50f2ba02f74167492c1c3aa312a7590991a Mon Sep 17 00:00:00 2001 +From: Peter Hutterer <[email protected]> +Date: Mon, 13 Jul 2026 15:50:09 +1000 +Subject: [PATCH] fserve: bounds-check cumulative glyph data writes in + fs_read_glyphs + +fs_read_glyphs() copies each glyph's bitmap into a single allbits +buffer allocated to rep->nbytes bytes. The per-glyph guard validates +only that the source slice (position, length) lies within the pbitmaps +source buffer. It does not check whether the running destination cursor +has exceeded the allocation. + +A malicious font server can send overlapping source offsets (e.g. 1000 +glyphs each referencing {position:0, length:64} with nbytes=64). Each +individual source range passes validation, but the cumulative writes +total 64000 bytes into a 64-byte destination buffer. + +Interestingly there was an unconditional debug printf in place that +sort-of warned about this but didn't prevent this. Let's remove that and +instead use the actual check to bail out before we run OOB. + +A regression test is included that sends 100 glyphs each referencing +the same 64-byte source slice into a 64-byte destination buffer, and +verifies the library rejects the overflow. + +CVE-2026-44950 + +Found-by: Zhixi "Jace" Sun, independent security researcher +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer <[email protected]> +Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/36> +(cherry picked from commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a) + +CVE: CVE-2026-44950 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/c2d222bb22c623d8a40f3275077fc7e6617f2c8a] + +Dropped test changes during the backport. + +Signed-off-by: Ankur Tyagi <[email protected]> +--- + src/fc/fserve.c | 23 ++++++++++++++--------- + 1 file changed, 14 insertions(+), 9 deletions(-) + +diff --git a/src/fc/fserve.c b/src/fc/fserve.c +index abf7d07..0fdc090 100644 +--- a/src/fc/fserve.c ++++ b/src/fc/fserve.c +@@ -1899,10 +1899,7 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + fsOffset32 local_off; + char *off_adr; + pointer pbitmaps; +- char *bits, *allbits; +-#ifdef DEBUG +- char *origallbits; +-#endif ++ char *bits, *allbits, *origallbits; + int i, + err; + int nranges = 0; +@@ -1992,8 +1989,8 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + goto bail; + } + +-#ifdef DEBUG + origallbits = allbits; ++#ifdef DEBUG + fprintf (stderr, "Reading %d glyphs in %d bytes for %s\n", + (int) rep->num_chars, (int) rep->nbytes, fsd->name); + #endif +@@ -2014,6 +2011,18 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + (local_off.position < rep->nbytes) && + (local_off.length <= (rep->nbytes - local_off.position))) + { ++ /* Check that the destination buffer has enough room ++ for this glyph to prevent a heap overflow from ++ overlapping source offsets. */ ++ if (local_off.length > ++ rep->nbytes - (allbits - origallbits)) ++ { ++ ErrorF("fserve: glyph data overflow: " ++ "cumulative write exceeds nbytes (%u)\n", ++ (unsigned) rep->nbytes); ++ err = AllocError; ++ goto bail; ++ } + bits = allbits; + allbits += local_off.length; + memcpy(bits, (char *)pbitmaps + local_off.position, +@@ -2041,10 +2050,6 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + } + off_adr += SIZEOF(fsOffset32); + } +-#ifdef DEBUG +- fprintf (stderr, "Used %d bytes instead of %d\n", +- (int) (allbits - origallbits), (int) rep->nbytes); +-#endif + + if (blockrec->type == FS_OPEN_FONT) + { diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index 8775d1cc13..17cfc133d6 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -19,6 +19,7 @@ SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ file://CVE-2026-56003.patch \ file://CVE-2026-59679.patch \ + file://CVE-2026-44950.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245912): https://lists.openembedded.org/g/openembedded-core/message/245912 Mute This Topic: https://lists.openembedded.org/mt/121271911/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
