From: Peter Marko <[email protected]>

Pick patch per [1].

[1] https://security-tracker.debian.org/tracker/CVE-2026-90781

Signed-off-by: Peter Marko <[email protected]>
---
 .../alsa/alsa-lib/CVE-2026-90781.patch        | 41 +++++++++++++++++++
 .../alsa/alsa-lib_1.2.16.1.bb                 |  4 +-
 2 files changed, 44 insertions(+), 1 deletion(-)
 create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch

diff --git a/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch 
b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch
new file mode 100644
index 0000000000..57883b8169
--- /dev/null
+++ b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch
@@ -0,0 +1,41 @@
+From f84cd4ced7b36fddb8e4ee24404cf7c091d27020 Mon Sep 17 00:00:00 2001
+From: Jaroslav Kysela <[email protected]>
+Date: Sun, 30 Aug 2026 20:20:30 +0200
+Subject: [PATCH] control: ctlparse - another fix for one-byte overrrun in
+ __snd_ctl_ascii_elem_id_parse
+
+Follows 1e27d63ef6d1dcf7d1f1a1e1eca3ea779e7de377 .
+
+Link: 
https://lore.kernel.org/alsa-devel/CACBQ=p2fho3m6dkv3cwukb6qhs92ouv+fj3sjz_pvbssdjw...@mail.gmail.com/
+Reported-by: Harsh Raj Singhania <[email protected]>
+Signed-off-by: Jaroslav Kysela <[email protected]>
+
+CVE: CVE-2026-90781
+Upstream-Status: Backport 
[https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020]
+Signed-off-by: Peter Marko <[email protected]>
+---
+ src/control/ctlparse.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/control/ctlparse.c b/src/control/ctlparse.c
+index c40de2bd..7132210e 100644
+--- a/src/control/ctlparse.c
++++ b/src/control/ctlparse.c
+@@ -219,7 +219,7 @@ int __snd_ctl_ascii_elem_id_parse(snd_ctl_elem_id_t *dst, 
const char *str,
+                       if (*str == '\'' || *str == '\"') {
+                               c = *str++;
+                               while (*str && *str != c) {
+-                                      if (size < (int)sizeof(buf)) {
++                                      if (size < (int)sizeof(buf) - 1) {
+                                               *ptr++ = *str;
+                                               size++;
+                                       }
+@@ -229,7 +229,7 @@ int __snd_ctl_ascii_elem_id_parse(snd_ctl_elem_id_t *dst, 
const char *str,
+                                       str++;
+                       } else {
+                               while (*str && *str != ',') {
+-                                      if (size < (int)sizeof(buf)) {
++                                      if (size < (int)sizeof(buf) - 1) {
+                                               *ptr++ = *str;
+                                               size++;
+                                       }
diff --git a/meta/recipes-multimedia/alsa/alsa-lib_1.2.16.1.bb 
b/meta/recipes-multimedia/alsa/alsa-lib_1.2.16.1.bb
index 1033250204..48f1689549 100644
--- a/meta/recipes-multimedia/alsa/alsa-lib_1.2.16.1.bb
+++ b/meta/recipes-multimedia/alsa/alsa-lib_1.2.16.1.bb
@@ -9,7 +9,9 @@ LIC_FILES_CHKSUM = 
"file://COPYING;md5=a916467b91076e631dd8edb7424769c7 \
                     
file://src/socket.c;md5=285675b45e83f571c6a957fe4ab79c93;beginline=9;endline=24 
\
                     "
 
-SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2";
+SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2 \
+    file://CVE-2026-90781.patch \
+"
 SRC_URI[sha256sum] = 
"f740db7f488255944ffd4428416ee3390a96742856916433df468c281436480e"
 
 inherit autotools pkgconfig
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246899): 
https://lists.openembedded.org/g/openembedded-core/message/246899
Mute This Topic: https://lists.openembedded.org/mt/121498740/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to