From: Hetvi Thakar <[email protected]> This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86138 Signed-off-by: Hetvi Thakar <[email protected]> --- .../libxml/libxml2/CVE-2026-86138.patch | 52 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch new file mode 100644 index 0000000000..9b918f7570 --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86138.patch @@ -0,0 +1,52 @@ +From d2e3efc8502313a1099ccc4aac19e8e03734e8c9 Mon Sep 17 00:00:00 2001 +From: mohammadmseet-hue <[email protected]> +Date: Thu, 16 Apr 2026 02:54:24 +0200 +Subject: [PATCH] fix: add overflow checks to xmlDictAddQString in dict.c + +xmlDictAddString has overflow guards for pool size calculations, but its +sibling xmlDictAddQString lacks these entirely. The namelen + plen + 1 +addition can overflow unsigned int, and 4 * (overflowed_value) produces +a small allocation, leading to heap buffer overflow when memcpy writes +the prefix and name. + +Add the same SIZE_MAX-based overflow guards and safe size_t cast. + +CVE: CVE-2026-86138 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4] + +(cherry picked from commit a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4) +Signed-off-by: Hetvi Thakar <[email protected]> +--- + dict.c | 19 +++++++++++++++---- + 1 file changed, 15 insertions(+), 4 deletions(-) + +diff --git a/dict.c b/dict.c +index d7156ed3..ae0210ea 100644 +--- a/dict.c ++++ b/dict.c +@@ -225,10 +225,21 @@ xmlDictAddQString(xmlDictPtr dict, const xmlChar *prefix, unsigned int plen, + return(NULL); + } + +- if (size == 0) size = 1000; +- else size *= 4; /* exponential growth */ +- if (size < 4 * (namelen + plen + 1)) +- size = 4 * (namelen + plen + 1); /* just in case ! */ ++ if (size == 0) { ++ size = 1000; ++ } else { ++ if (size < (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size *= 4; /* exponential growth */ ++ else ++ size = SIZE_MAX - sizeof(xmlDictStrings); ++ } ++ if (size / 4 < namelen + plen + 1) { ++ if ((size_t) namelen + plen + 1 < ++ (SIZE_MAX - sizeof(xmlDictStrings)) / 4) ++ size = 4 * ((size_t) namelen + plen + 1); /* just in case ! */ ++ else ++ return(NULL); ++ } + pool = (xmlDictStringsPtr) xmlMalloc(sizeof(xmlDictStrings) + size); + if (pool == NULL) + return(NULL); diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index e4db345af4..28ae601118 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -33,6 +33,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-1757.patch \ file://CVE-2026-11979.patch \ file://CVE-2026-86137.patch \ + file://CVE-2026-86138.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246810): https://lists.openembedded.org/g/openembedded-core/message/246810 Mute This Topic: https://lists.openembedded.org/mt/121485374/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
