From: Sourav Kumar Pramanik <[email protected]> This change fixes CVE-2026-5928
Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=commit;h=ef3bfb5f910011f3780cb06aa47e730035f53285] Comment: Patch refreshed as per glibc 2.39 source code Signed-off-by: Sourav Kumar Pramanik <[email protected]> --- .../glibc/glibc/CVE-2026-5928.patch | 105 ++++++++++++++++++ meta/recipes-core/glibc/glibc_2.39.bb | 1 + 2 files changed, 106 insertions(+) create mode 100644 meta/recipes-core/glibc/glibc/CVE-2026-5928.patch diff --git a/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch b/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch new file mode 100644 index 0000000000..470ab1a1ec --- /dev/null +++ b/meta/recipes-core/glibc/glibc/CVE-2026-5928.patch @@ -0,0 +1,105 @@ +From ef3bfb5f910011f3780cb06aa47e730035f53285 Mon Sep 17 00:00:00 2001 +From: Rocket Ma <[email protected]> +Date: Fri, 1 May 2026 20:39:07 -0700 +Subject: [PATCH] libio: Fix ungetwc operating on byte stream [BZ #33998] + +* libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one +character, it accidently compare the wchar to push back with the last +char from byte stream, instead of wide stream. Under specific coding, +attacker may exploit this to leak information. This commit fix bug +33998, or CVE-2026-5928. + +CVE: CVE-2026-5928 +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=commit;h=ef3bfb5f910011f3780cb06aa47e730035f53285] +Comment: Patch refreshed as per glibc 2.39 source code + +Signed-off-by: Rocket Ma <[email protected]> +Reviewed-by: Carlos O'Donell <[email protected]> +Signed-off-by: Sourav Kumar Pramanik <[email protected]> +--- + libio/Makefile | 1 + + libio/bug-wgenops-bz33998.c | 54 +++++++++++++++++++++++++++++++++++++++++++++ + libio/wgenops.c | 4 ++-- + 3 files changed, 57 insertions(+), 2 deletions(-) + create mode 100644 libio/bug-wgenops-bz33998.c + +diff --git a/libio/Makefile b/libio/Makefile +--- a/libio/Makefile ++++ b/libio/Makefile +@@ -83,6 +83,7 @@ tests = \ + bug-ungetwc1 \ + bug-ungetwc2 \ + bug-wfflush \ ++ bug-wgenops-bz33998 \ + bug-wmemstream1 \ + bug-wsetpos \ + test-fmemopen \ +diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c +new file mode 100644 +--- /dev/null ++++ b/libio/bug-wgenops-bz33998.c +@@ -0,0 +1,54 @@ ++/* Regression test for ungetwc operating on byte stream (BZ #33998) ++ Copyright (C) 2026 The GNU Toolchain Authors. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ <https://www.gnu.org/licenses/>. */ ++ ++#include "support/temp_file.h" ++#include "support/xstdio.h" ++#include "support/xunistd.h" ++#include <stdlib.h> ++#include <unistd.h> ++#include <sys/mman.h> ++#include <stdio.h> ++#include <wchar.h> ++#include <support/check.h> ++ ++static int ++do_test (void) ++{ ++ char *filename; ++ int fd = create_temp_file ("tst-bz33998-", &filename); ++ TEST_VERIFY (fd != -1); ++ xwrite (fd, "A", sizeof ("A")); // write "A\0" by design ++ xclose (fd); ++ ++ FILE *fp = xfopen (filename, "r+"); ++ TEST_COMPARE (getwc (fp), L'A'); ++ /* If the bug is fixed, then ungetwc should not touch byte stream. ++ If the bug is not fixed, ungetwc firstly match last read char, L'A', ++ failed, then the pbackfail branch, matching last read char in byte ++ stream, that is, '\0' (initialized when setup wide stream). */ ++ char *old_read_ptr = fp->_IO_read_ptr; ++ TEST_COMPARE (ungetwc (L'\0', fp), L'\0'); ++ TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr); ++ ++ xfclose (fp); ++ free (filename); ++ ++ return 0; ++} ++ ++#include <support/test-driver.c> +diff --git a/libio/wgenops.c b/libio/wgenops.c +--- a/libio/wgenops.c ++++ b/libio/wgenops.c +@@ -111,2 +111,2 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c) +- && (wint_t) fp->_IO_read_ptr[-1] == c) +- --fp->_IO_read_ptr; ++ && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c) ++ --fp->_wide_data->_IO_read_ptr; +-- +2.43.7 diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb index b01225e530..74db1ac507 100644 --- a/meta/recipes-core/glibc/glibc_2.39.bb +++ b/meta/recipes-core/glibc/glibc_2.39.bb @@ -58,6 +58,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \ file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \ file://0024-CVE-2026-5435.patch \ file://CVE-2026-5450.patch \ + file://CVE-2026-5928.patch \ " S = "${WORKDIR}/git" B = "${WORKDIR}/build-${TARGET_SYS}" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246952): https://lists.openembedded.org/g/openembedded-core/message/246952 Mute This Topic: https://lists.openembedded.org/mt/121505927/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
