On Sun, 2026-08-30 at 23:14 -0700, Hetvi Thakar -X (hthakar - E
INFOCHIPS PRIVATE LIMITED at Cisco) wrote:
> From: Hetvi Thakar <[email protected]>
>
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
>
> [1]
> https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f
> [2] https://pkg.go.dev/vuln/GO-2026-4918
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
> meta/recipes-devtools/go/go-1.22.12.inc | 1 +
> .../go/go/CVE-2026-33814.patch | 44 +++++++++++++++++++
> 2 files changed, 45 insertions(+)
> create mode 100644 meta/recipes-devtools/go/go/CVE-2026-33814.patch
>
> diff --git a/meta/recipes-devtools/go/go-1.22.12.inc
> b/meta/recipes-devtools/go/go-1.22.12.inc
> index 99c5f8b63b..ee2f5ca277 100644
> --- a/meta/recipes-devtools/go/go-1.22.12.inc
> +++ b/meta/recipes-devtools/go/go-1.22.12.inc
> @@ -62,6 +62,7 @@ SRC_URI += "\
> file://CVE-2026-25679.patch \
> file://CVE-2026-32288.patch \
> file://CVE-2026-27145.patch \
> + file://CVE-2026-33814.patch \
> "
> SRC_URI[main.sha256sum] =
> "012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71"
>
> diff --git a/meta/recipes-devtools/go/go/CVE-2026-33814.patch
> b/meta/recipes-devtools/go/go/CVE-2026-33814.patch
> new file mode 100644
> index 0000000000..8265bf205f
> --- /dev/null
> +++ b/meta/recipes-devtools/go/go/CVE-2026-33814.patch
> @@ -0,0 +1,44 @@
> +From 825d42a14d8ffbdbdda87a39e78795eb17e4f0f2 Mon Sep 17 00:00:00 2001
> +From: Mark Freeman <[email protected]>
> +Date: Fri, 17 Apr 2026 16:28:03 -0400
> +Subject: [PATCH] [release-branch.go1.25] all: update x/net to a9171bc8
> +
> +Fixes #78477
> +
> +Change-Id: I0a4c8e25f569fc1bfb8ac39ff728bfe7300b751f
> +Reviewed-on: https://go-review.googlesource.com/c/go/+/768323
> +Reviewed-by: Dmitri Shuralyov <[email protected]>
> +TryBot-Bypass: Dmitri Shuralyov <[email protected]>
> +
> +CVE: CVE-2026-33814
> +Upstream-Status: Backport
> [https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f]
> +
> +Backport Changes:
> +- Omitted src/go.mod, src/go.sum, and src/vendor/modules.txt because
> + their x/net version updates are not required for this focused backport.
Hi Hetvi, Yoann,
My Go knowledge is limited, but omitting the go.mod/go.sum changes
didn't seem right to me. Those files track dependencies.
Looking in to it a bit further, the CVE description is:
When processing HTTP/2 SETTINGS frames, transport will enter an
infinite loop of writing CONTINUATION frames if it receives a
SETTINGS_MAX_FRAME_SIZE with a value of 0.
The commit message is "all: update x/net to a9171bc8", if we look at
that commit in the x/net go module [1] it makes other changes which look
relevant to this CVE.
[1]:
https://go.googlesource.com/net/+/a9171bc8c6f19c50efad8880f96e361359ed5307%5E%21/
Could we check if the backport submitted here is a complete fix? As I
say, my Go knowledge is limited, and I'm not sure how we would pick up
changes to the x/net module if we need to.
Best regards,
--
Paul Barker
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246065):
https://lists.openembedded.org/g/openembedded-core/message/246065
Mute This Topic: https://lists.openembedded.org/mt/121009648/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-