Backport fix for CVE-2026-5119 from upstream libsoup 3 patch [1].

[1] 
https://gitlab.gnome.org/GNOME/libsoup/-/commit/b0626fff8538e3dd4a52f148d91c8348d51d64d1

Signed-off-by: Jason Stasiak <[email protected]>
---
 .../libsoup/libsoup-2.4/CVE-2026-5119.patch   | 129 ++++++++++++++++++
 .../libsoup/libsoup-2.4_2.74.3.bb             |   1 +
 2 files changed, 130 insertions(+)
 create mode 100644 meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch

diff --git a/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch 
b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch
new file mode 100644
index 0000000000..4df1a98ab8
--- /dev/null
+++ b/meta/recipes-support/libsoup/libsoup-2.4/CVE-2026-5119.patch
@@ -0,0 +1,129 @@
+From b0626fff8538e3dd4a52f148d91c8348d51d64d1 Mon Sep 17 00:00:00 2001
+From: Carlos Garcia Campos <[email protected]>
+Date: Fri, 27 Feb 2026 12:03:25 +0100
+Subject: [PATCH] Fix CVE-2026-25119
+
+Upstream-Status: Backport 
[https://gitlab.gnome.org/GNOME/libsoup/-/commit/b0626fff8538e3dd4a52f148d91c8348d51d64d1]
+CVE: CVE-2026-5119
+
+Signed-off-by: Jason Stasiak <[email protected]>
+---
+ libsoup/soup-cookie-jar.c | 25 +++++++++++++++------
+ tests/proxy-test.c        | 46 +++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 64 insertions(+), 7 deletions(-)
+
+diff --git a/libsoup/soup-cookie-jar.c b/libsoup/soup-cookie-jar.c
+index c8231f0e..b9abdc82 100644
+--- a/libsoup/soup-cookie-jar.c
++++ b/libsoup/soup-cookie-jar.c
+@@ -12,6 +12,7 @@
+ #include <string.h>
+ 
+ #include "soup-cookie-jar.h"
++#include "soup-connection.h"
+ #include "soup-message-private.h"
+ #include "soup-misc-private.h"
+ #include "soup.h"
+@@ -818,18 +819,28 @@ process_set_cookie_header (SoupMessage *msg, gpointer 
user_data)
+       g_slist_free (new_cookies);
+ }
+ 
++static gboolean
++allow_cookies_for_request (SoupMessage *msg)
++{
++      /* Do not send cookies to a HTTP proxy for a HTTPS request */
++      return msg->method != SOUP_METHOD_CONNECT || 
!soup_connection_is_tunnelled (soup_message_get_connection (msg));
++}
++
+ static void
+ msg_starting_cb (SoupMessage *msg, gpointer feature)
+ {
+       SoupCookieJar *jar = SOUP_COOKIE_JAR (feature);
+-      GSList *cookies;
++      GSList *cookies = NULL;
++
++      if (allow_cookies_for_request (msg)) {
++              cookies = soup_cookie_jar_get_cookie_list_with_same_site_info 
(jar, soup_message_get_uri (msg),
++                                                                             
soup_message_get_first_party (msg),
++                                                                             
soup_message_get_site_for_cookies (msg),
++                                                                             
TRUE,
++                                                                             
SOUP_METHOD_IS_SAFE (msg->method),
++                                                                             
soup_message_get_is_top_level_navigation (msg));
++      }
+ 
+-      cookies = soup_cookie_jar_get_cookie_list_with_same_site_info (jar, 
soup_message_get_uri (msg),
+-                                                                     
soup_message_get_first_party (msg),
+-                                                                     
soup_message_get_site_for_cookies (msg),
+-                                                                     TRUE,
+-                                                                     
SOUP_METHOD_IS_SAFE (msg->method),
+-                                                                     
soup_message_get_is_top_level_navigation (msg));
+       if (cookies != NULL) {
+               char *cookie_header = soup_cookies_to_cookie_header (cookies);
+               soup_message_headers_replace (msg->request_headers, "Cookie", 
cookie_header);
+diff --git a/tests/proxy-test.c b/tests/proxy-test.c
+index 105a02a6..d8c7e8a1 100644
+--- a/tests/proxy-test.c
++++ b/tests/proxy-test.c
+@@ -435,6 +435,51 @@ do_proxy_auth_cache_test (void)
+       g_object_unref (cache);
+ }
+ 
++static void
++connect_message_wrote_headers_cb (SoupMessage *msg, guint *counter)
++{
++      SoupMessageHeaders *hdrs;
++
++      *counter += 1;
++
++      if (msg->method == SOUP_METHOD_CONNECT)
++              g_assert_null (soup_message_headers_get_one 
(msg->request_headers, "Cookie"));
++      else
++              g_assert_nonnull (soup_message_headers_get_one 
(msg->request_headers, "Cookie"));
++}
++
++static void
++request_queued_cb (SoupSession *session, SoupMessage *msg, guint *counter)
++{
++      g_signal_connect (msg, "wrote-headers", G_CALLBACK 
(connect_message_wrote_headers_cb), counter);
++}
++
++static void
++do_proxy_secure_cookies_test (void)
++{
++      SoupSession *session;
++      SoupMessage *msg;
++      SoupCookieJar *jar;
++      guint counter = 0;
++
++      SOUP_TEST_SKIP_IF_NO_APACHE;
++      SOUP_TEST_SKIP_IF_NO_TLS;
++
++      session = soup_test_session_new (SOUP_TYPE_SESSION_SYNC, 
SOUP_SESSION_PROXY_RESOLVER, proxy_resolvers[SIMPLE_PROXY], NULL);
++      g_signal_connect (session, "request-queued", G_CALLBACK 
(request_queued_cb), &counter);
++
++      soup_session_add_feature_by_type (session, SOUP_TYPE_COOKIE_JAR);
++      jar = SOUP_COOKIE_JAR (soup_session_get_feature (session, 
SOUP_TYPE_COOKIE_JAR));
++
++      msg = soup_message_new (SOUP_METHOD_GET, HTTPS_SERVER);
++      soup_cookie_jar_set_cookie (jar, soup_message_get_uri (msg), 
"user=password; secure");
++      soup_session_send_message (session, msg);
++      soup_test_assert_message_status (msg, SOUP_STATUS_OK);
++      g_assert_cmpuint (counter, ==, 2);
++
++      soup_test_session_abort_unref (session);
++}
++
+ int
+ main (int argc, char **argv)
+ {
+@@ -470,6 +515,7 @@ main (int argc, char **argv)
+       g_test_add_func ("/proxy/redirect", do_proxy_redirect_test);
+       g_test_add_func ("/proxy/auth-redirect", do_proxy_auth_redirect_test);
+       g_test_add_func ("/proxy/auth-cache", do_proxy_auth_cache_test);
++      g_test_add_func ("/proxy/secure-cookies", do_proxy_secure_cookies_test);
+ 
+       ret = g_test_run ();
+ 
+-- 
+2.55.0
+
diff --git a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb 
b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
index 18f82f8ef7..c79bced69d 100644
--- a/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
+++ b/meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb
@@ -44,6 +44,7 @@ SRC_URI = 
"${GNOME_MIRROR}/libsoup/${SHRT_VER}/libsoup-${PV}.tar.xz \
            file://CVE-2026-1539.patch \
            file://CVE-2026-1801.patch \
            file://CVE-2026-2443.patch \
+           file://CVE-2026-5119.patch \
 "
 SRC_URI[sha256sum] = 
"e4b77c41cfc4c8c5a035fcdc320c7bc6cfb75ef7c5a034153df1413fa1d92f13"
 
-- 
2.55.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246897): 
https://lists.openembedded.org/g/openembedded-core/message/246897
Mute This Topic: https://lists.openembedded.org/mt/121498018/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to