From: Hetvi Thakar <[email protected]> This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86143 Signed-off-by: Hetvi Thakar <[email protected]> --- .../libxml/libxml2/CVE-2026-86143.patch | 91 +++++++++++++++++++ meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + 2 files changed, 92 insertions(+) create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch new file mode 100644 index 0000000000..228b5136bb --- /dev/null +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86143.patch @@ -0,0 +1,91 @@ +From 83259eee08067b547d2aaedd436504939b2c343b Mon Sep 17 00:00:00 2001 +From: Daniel Garcia Moreno <[email protected]> +Date: Mon, 4 May 2026 09:54:34 +0200 +Subject: [PATCH] xmlIO: Check for int overflow before calling writecallback + +Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111 + +CVE: CVE-2026-86143 +Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35] + +Backport Changes: +- Change nbchars to size_t in both Scarthgap write functions before assigning the size_t result of xmlBufUse(). Add the INT_MAX guard to both xmlOutputBufferWrite() callback paths. The upstream commit assumes earlier refactoring that changed nbchars to size_t and routed xmlOutputBufferWriteEscape() through the protected write path; the existing flush guards are retained. + +(cherry picked from commit 90f293ba74d28b1d570920382e707586f68ebf35) +Signed-off-by: Hetvi Thakar <[email protected]> +--- + xmlIO.c | 26 ++++++++++++++++++---- + 1 file changed, 22 insertions(+), 4 deletions(-) + +diff --git a/xmlIO.c b/xmlIO.c +index 95d27157..de227d8c 100644 +--- a/xmlIO.c ++++ b/xmlIO.c +@@ -3318,7 +3318,7 @@ + */ + int + xmlOutputBufferWrite(xmlOutputBufferPtr out, int len, const char *buf) { +- int nbchars = 0; /* number of chars to output to I/O */ ++ size_t nbchars = 0; /* number of chars to output to I/O */ + int ret; /* return from function call */ + int written = 0; /* number of char written to I/O so far */ + int chunk; /* number of byte current processed from buf */ +@@ -3378,6 +3378,10 @@ + if ((nbchars < MINLEN) && (len <= 0)) + goto done; + ++ if (nbchars >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + /* + * second write the stuff to the I/O channel + */ +@@ -3487,7 +3491,7 @@ + int + xmlOutputBufferWriteEscape(xmlOutputBufferPtr out, const xmlChar *str, + xmlCharEncodingOutputFunc escaping) { +- int nbchars = 0; /* number of chars to output to I/O */ ++ size_t nbchars = 0; /* number of chars to output to I/O */ + int ret; /* return from function call */ + int written = 0; /* number of char written to I/O so far */ + int oldwritten=0;/* loop guard */ +@@ -3572,6 +3576,10 @@ + if ((nbchars < MINLEN) && (len <= 0)) + goto done; + ++ if (nbchars >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + /* + * second write the stuff to the I/O channel + */ +@@ -3667,15 +3675,25 @@ + */ + if ((out->conv != NULL) && (out->encoder != NULL) && + (out->writecallback != NULL)) { ++ size_t bufsize = xmlBufUse(out->conv); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->conv), +- xmlBufUse(out->conv)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->conv, ret); + } else if (out->writecallback != NULL) { ++ size_t bufsize = xmlBufUse(out->buffer); ++ if (bufsize >= INT_MAX) { ++ out->error = XML_ERR_INTERNAL_ERROR; ++ return(-1); ++ } + ret = out->writecallback(out->context, + (const char *)xmlBufContent(out->buffer), +- xmlBufUse(out->buffer)); ++ bufsize); + if (ret >= 0) + xmlBufShrink(out->buffer, ret); + } diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb index 881b60133d..1b0c3d50da 100644 --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb @@ -37,6 +37,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://CVE-2026-86140.patch \ file://CVE-2026-86141.patch \ file://CVE-2026-86142.patch \ + file://CVE-2026-86143.patch \ " SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246814): https://lists.openembedded.org/g/openembedded-core/message/246814 Mute This Topic: https://lists.openembedded.org/mt/121485379/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
