This should be submitted also to master. > -----Original Message----- > From: [email protected] <openembedded- > [email protected]> On Behalf Of Yogita Urade -X (yurade - E > INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org > Sent: Monday, September 28, 2026 6:27 PM > To: [email protected] > Subject: [OE-core][wrynose][PATCH] bison: Fix CVE-2026-56390 > > This patch applies the upstream fix as referenced in [2], > using the commit shown in [1]. > > [1] > https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448 > c925513742d4efcf0 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-56390 > > Signed-off-by: Yogita Urade <[email protected]> > --- > .../bison/bison/CVE-2026-56390.patch | 236 ++++++++++++++++++ > meta/recipes-devtools/bison/bison_3.8.2.bb | 1 + > 2 files changed, 237 insertions(+) > create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56390.patch > > diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56390.patch > b/meta/recipes- > devtools/bison/bison/CVE-2026-56390.patch > new file mode 100644 > index 0000000000..82a80a3a28 > --- /dev/null > +++ b/meta/recipes-devtools/bison/bison/CVE-2026-56390.patch > @@ -0,0 +1,236 @@ > +From 81b11844fcbc7abb3df91c629cd2f2c076f107cc Mon Sep 17 00:00:00 2001 > +From: Paul Eggert <[email protected]> > +Date: Thu, 23 Apr 2026 12:41:25 -0700 > +Subject: [PATCH] bison: tighten up output file names > +MIME-Version: 1.0 > +Content-Type: text/plain; charset=UTF-8 > +Content-Transfer-Encoding: 8bit > + > +Problem reported by Michał Majchrowicz. > +* src/parse-gram.y: Do not allow '/' in %header and %output directives. > + > +CVE: CVE-2026-56390 > +Upstream-Status: Backport > [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a44 > 8c925513742d4efcf0] > + > +Backport Changes: > +- Adapted generated src/parse-gram.c to the Bison 3.8.2 source tree. > +- omitted upstream generator-version/copyright metadata and > + src/parse-gram.h-only metadata changes while retaining the > + security-relevant parser changes. > + > +(cherry picked from commit 8d101c19d4d9aaedf83a448c925513742d4efcf0) > +Signed-off-by: Yogita Urade <[email protected]> > +--- > + THANKS | 1 + > + doc/bison.texi | 2 ++ > + src/parse-gram.c | 56 ++++++++++++++++++++++++++++++++---------------- > + src/parse-gram.y | 31 ++++++++++++++++++++++----- > + 4 files changed, 67 insertions(+), 23 deletions(-) > + > +diff --git a/THANKS b/THANKS > +index be743a23..0e481561 100644 > +--- a/THANKS > ++++ b/THANKS > +@@ -128,6 +128,7 @@ Michael Catanzaro [email protected] > + Michael Felt [email protected] > + Michael Hayes [email protected] > + Michael Raskin [email protected] > ++Michał Majchrowicz [email protected] > + Michel d'Hooge [email protected] > + Michiel De Wilde [email protected] > + Mickael Labau [email protected] > +diff --git a/doc/bison.texi b/doc/bison.texi > +index a559649c..44a4e159 100644 > +--- a/doc/bison.texi > ++++ b/doc/bison.texi > +@@ -5973,6 +5973,7 @@ Introduced in Bison 3.8. > + > + @deffn {Directive} %header @var{header-file} > + Same as above, but save in the file @file{@var{header-file}}. > ++The @var{header-file} name should not contain slashes. > + @end deffn > + > + @deffn {Directive} %language "@var{language}" > +@@ -6026,6 +6027,7 @@ file, treating it as an independent source file in its > own > right. > + > + @deffn {Directive} %output "@var{file}" > + Generate the parser implementation in @file{@var{file}}. > ++The @var{file} name should not contain slashes. > + @end deffn > + > + @deffn {Directive} %pure-parser > +diff --git a/src/parse-gram.c b/src/parse-gram.c > +index 3c1d8229..7f6deb33 100644 > +--- a/src/parse-gram.c > ++++ b/src/parse-gram.c > +@@ -276,8 +276,11 @@ typedef enum yysymbol_kind_t yysymbol_kind_t; > + string from the scanner (should be CODE). */ > + static char const *translate_code_braceless (char *code, location loc); > + > ++ /* Is FILE a valid output file name? */ > ++ static bool valid_output_file_name (char const *file); > ++ > + /* Handle a %header directive. */ > +- static void handle_header (char const *value); > ++ static void handle_header (location const *loc, char const *value); > + > + /* Handle a %error-verbose directive. */ > + static void handle_error_verbose (location const *loc, char const > *directive); > +@@ -663,19 +666,19 @@ union yyalloc > + /* YYRLINE[YYN] -- Source line where rule number YYN was defined. */ > + static const yytype_int16 yyrline[] = > + { > +- 0, 310, 310, 319, 320, 324, 325, 331, 335, 340, > +- 341, 342, 343, 344, 345, 350, 355, 356, 357, 358, > +- 359, 360, 360, 361, 362, 363, 364, 365, 366, 367, > +- 368, 372, 373, 382, 383, 387, 398, 402, 406, 414, > +- 424, 425, 435, 436, 442, 455, 455, 460, 460, 465, > +- 465, 470, 480, 481, 482, 483, 488, 489, 493, 494, > +- 499, 500, 504, 505, 509, 510, 511, 524, 533, 537, > +- 541, 549, 550, 554, 567, 568, 573, 574, 575, 593, > +- 597, 601, 609, 611, 616, 623, 633, 637, 641, 649, > +- 655, 668, 669, 675, 676, 677, 684, 684, 692, 693, > +- 694, 699, 702, 704, 706, 708, 710, 712, 714, 716, > +- 718, 723, 724, 733, 757, 758, 759, 760, 772, 774, > +- 798, 803, 804, 809, 817, 818 > ++ 0, 314, 314, 323, 324, 328, 329, 335, 339, 344, > ++ 345, 346, 347, 348, 349, 354, 359, 360, 361, 362, > ++ 363, 372, 372, 373, 374, 375, 376, 377, 378, 379, > ++ 380, 384, 385, 394, 395, 399, 410, 414, 418, 426, > ++ 436, 437, 447, 448, 454, 467, 467, 472, 472, 477, > ++ 477, 482, 492, 493, 494, 495, 500, 501, 505, 506, > ++ 511, 512, 516, 517, 521, 522, 523, 536, 545, 549, > ++ 553, 561, 562, 566, 579, 580, 585, 586, 587, 605, > ++ 609, 613, 621, 623, 628, 635, 645, 649, 653, 661, > ++ 667, 680, 681, 687, 688, 689, 696, 696, 704, 705, > ++ 706, 711, 714, 716, 718, 720, 722, 724, 726, 728, > ++ 730, 735, 736, 745, 769, 770, 771, 772, 784, 786, > ++ 810, 815, 816, 821, 829, 830 > + }; > + #endif > + > +@@ -2217,7 +2220,7 @@ yyreduce: > + > + case 9: /* prologue_declaration: "%header" string.opt */ > + #line 340 "src/parse-gram.y" > +- { handle_header ((yyvsp[0].yykind_75)); } > ++ { handle_header (&(yylsp[0]), > (yyvsp[0].yykind_75)); } > + #line 2222 "src/parse-gram.c" > + break; > + > +@@ -2289,7 +2292,14 @@ yyreduce: > + > + case 20: /* prologue_declaration: "%output" "string" */ > + #line 359 "src/parse-gram.y" > +- { spec_outfile = unquote > ((yyvsp[0].STRING)); > gram_scanner_last_string_free (); } > ++ { > ++ char *file = unquote ((yyvsp[0].STRING)); > ++ if (valid_output_file_name (file)) > ++ spec_outfile = file; > ++ else > ++ complain (&(yylsp[0]), complaint, _("invalid %%output file name > ignored")); > ++ gram_scanner_last_string_free (); > ++ } > + #line 2294 "src/parse-gram.c" > + break; > + > +@@ -3290,14 +3300,24 @@ add_param (param_type type, char *decl, location loc) > + } > + > + > ++static bool > ++valid_output_file_name (char const *file) > ++{ > ++ return !strchr (file, '/'); > ++} > ++ > ++ > + static void > +-handle_header (char const *value) > ++handle_header (location const *loc, char const *value) > + { > + header_flag = true; > + if (value) > + { > + char *file = unquote (value); > +- spec_header_file = xstrdup (file); > ++ if (valid_output_file_name (file)) > ++ spec_header_file = xstrdup (file); > ++ else > ++ complain (loc, complaint, _("invalid %%header file name ignored")); > + gram_scanner_last_string_free (); > + unquote_free (file); > + } > +diff --git a/src/parse-gram.y b/src/parse-gram.y > +index 15180cb5..114c5c44 100644 > +--- a/src/parse-gram.y > ++++ b/src/parse-gram.y > +@@ -95,8 +95,11 @@ > + string from the scanner (should be CODE). */ > + static char const *translate_code_braceless (char *code, location loc); > + > ++ /* Is FILE a valid output file name? */ > ++ static bool valid_output_file_name (char const *file); > ++ > + /* Handle a %header directive. */ > +- static void handle_header (char const *value); > ++ static void handle_header (location const *loc, char const *value); > + > + /* Handle a %error-verbose directive. */ > + static void handle_error_verbose (location const *loc, char const > *directive); > +@@ -337,7 +340,7 @@ prologue_declaration: > + muscle_percent_define_insert ($2, @$, $3.kind, $3.chars, > + MUSCLE_PERCENT_DEFINE_GRAMMAR_FILE); > + } > +-| "%header" string.opt { handle_header ($2); } > ++| "%header" string.opt { handle_header (&@2, $2); } > + | "%error-verbose" { handle_error_verbose (&@$, $1); } > + | "%expect" INT_LITERAL { expected_sr_conflicts = $2; } > + | "%expect-rr" INT_LITERAL { expected_rr_conflicts = $2; } > +@@ -356,7 +359,15 @@ prologue_declaration: > + | "%name-prefix" STRING { handle_name_prefix (&@$, $1, $2); } > + | "%no-lines" { no_lines_flag = true; } > + | "%nondeterministic-parser" { nondeterministic_parser = true; } > +-| "%output" STRING { spec_outfile = unquote ($2); > gram_scanner_last_string_free (); } > ++| "%output" STRING > ++ { > ++ char *file = unquote ($2); > ++ if (valid_output_file_name (file)) > ++ spec_outfile = file; > ++ else > ++ complain (&@2, complaint, _("invalid %%output file name ignored")); > ++ gram_scanner_last_string_free (); > ++ } > + | "%param" { current_param = $1; } params { current_param = param_none; } > + | "%pure-parser" { handle_pure_parser (&@$, $1); } > + | "%require" STRING { handle_require (&@2, $2); } > +@@ -952,14 +963,24 @@ add_param (param_type type, char *decl, location loc) > + } > + > + > ++static bool > ++valid_output_file_name (char const *file) > ++{ > ++ return !strchr (file, '/'); > ++} > ++ > ++ > + static void > +-handle_header (char const *value) > ++handle_header (location const *loc, char const *value) > + { > + header_flag = true; > + if (value) > + { > + char *file = unquote (value); > +- spec_header_file = xstrdup (file); > ++ if (valid_output_file_name (file)) > ++ spec_header_file = xstrdup (file); > ++ else > ++ complain (loc, complaint, _("invalid %%header file name ignored")); > + gram_scanner_last_string_free (); > + unquote_free (file); > + } > +-- > +2.44.4 > + > diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes- > devtools/bison/bison_3.8.2.bb > index 9808a96e99..08962ae133 100644 > --- a/meta/recipes-devtools/bison/bison_3.8.2.bb > +++ b/meta/recipes-devtools/bison/bison_3.8.2.bb > @@ -13,6 +13,7 @@ SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \ > file://autoconf-2.73.patch \ > file://add-with-bisonlocaledir.patch \ > file://CVE-2026-56389.patch \ > + file://CVE-2026-56390.patch \ > " > SRC_URI[sha256sum] = > "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2" > > -- > 2.44.4
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246783): https://lists.openembedded.org/g/openembedded-core/message/246783 Mute This Topic: https://lists.openembedded.org/mt/121475043/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
