Pick patch from [1] also mentioned at Debian tracker in [2] [1] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354 [2] https://security-tracker.debian.org/tracker/CVE-2026-3082
Signed-off-by: Rohini Sangam <[email protected]> --- .../CVE-2026-3082.patch | 46 +++++++++++++++++++ .../gstreamer1.0-plugins-bad_1.22.12.bb | 1 + 2 files changed, 47 insertions(+) create mode 100644 meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch new file mode 100644 index 0000000000..26e27ee5f5 --- /dev/null +++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch @@ -0,0 +1,46 @@ +From 83e9225bb9e89948e7b1c9f37ef9218d2dcde354 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?V=C3=ADctor=20Manuel=20J=C3=A1quez=20Leal?= + <[email protected]> +Date: Wed, 11 Feb 2026 22:07:49 +0100 +Subject: [PATCH] libs: jpegparser: boundary checks before copying it + +READ_BYTES macro reads data from a byte reader and then copy it to a storage +variable. This patch adds a validation that the length to read cannot be bigger +than the storage size. + +This macro right now is used only for storage variables of guint8 arrays. + +We have validated in the specification (sections F.1.2.1.2 and F.1.2.2.1 in ITU +T.81) that Huffman tables (both AC and DC) aren't bigger than 256. + +Fixes SA-2026-0003, CVE-2026-3082, ZDI-CAN-28840. + +Fixes: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/4899> +Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/10946> + +CVE: CVE-2026-3082 +Upstream-Status: Backport [https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354] + +Signed-off-by: Rohini Sangam <[email protected]> +--- + gst-libs/gst/codecparsers/gstjpegparser.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/gst-libs/gst/codecparsers/gstjpegparser.c b/gst-libs/gst/codecparsers/gstjpegparser.c +index 6411076..86125b3 100644 +--- a/gst-libs/gst/codecparsers/gstjpegparser.c ++++ b/gst-libs/gst/codecparsers/gstjpegparser.c +@@ -79,6 +79,10 @@ ensure_debug_category (void) + + #define READ_BYTES(reader, buf, length) G_STMT_START { \ + const guint8 *vals; \ ++ if (length > sizeof (buf)) { \ ++ GST_WARNING ("data size is bigger than its storage"); \ ++ goto failed; \ ++ } \ + if (!gst_byte_reader_get_data (reader, length, &vals)) { \ + GST_WARNING ("failed to read bytes, size:%d", length); \ + goto failed; \ +-- +2.44.4 + diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb index f6d0711bd8..64e0aa6dcb 100644 --- a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb +++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb @@ -12,6 +12,7 @@ SRC_URI = "https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad file://0005-v4l2codecs-Always-chain-up-to-parent-decide_allocati.patch \ file://CVE-2025-3887-1.patch \ file://CVE-2025-3887-2.patch \ + file://CVE-2026-3082.patch \ " SRC_URI[sha256sum] = "388b4c4412f42e36a38b17cc34119bc11879bd4d9fbd4ff6d03b2c7fc6b4d494" -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247013): https://lists.openembedded.org/g/openembedded-core/message/247013 Mute This Topic: https://lists.openembedded.org/mt/121522872/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
