Pick patch from [1] also mentioned at Debian tracker in [2]

[1] 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354
[2] https://security-tracker.debian.org/tracker/CVE-2026-3082

Signed-off-by: Rohini Sangam <[email protected]>
---
 .../CVE-2026-3082.patch                       | 46 +++++++++++++++++++
 .../gstreamer1.0-plugins-bad_1.22.12.bb       |  1 +
 2 files changed, 47 insertions(+)
 create mode 100644 
meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch

diff --git 
a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
 
b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
new file mode 100644
index 0000000000..26e27ee5f5
--- /dev/null
+++ 
b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
@@ -0,0 +1,46 @@
+From 83e9225bb9e89948e7b1c9f37ef9218d2dcde354 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?V=C3=ADctor=20Manuel=20J=C3=A1quez=20Leal?=
+ <[email protected]>
+Date: Wed, 11 Feb 2026 22:07:49 +0100
+Subject: [PATCH] libs: jpegparser: boundary checks before copying it
+
+READ_BYTES macro reads data from a byte reader and then copy it to a storage
+variable. This patch adds a validation that the length to read cannot be bigger
+than the storage size.
+
+This macro right now is used only for storage variables of guint8 arrays.
+
+We have validated in the specification (sections F.1.2.1.2 and F.1.2.2.1 in ITU
+T.81) that Huffman tables (both AC and DC) aren't bigger than 256.
+
+Fixes SA-2026-0003, CVE-2026-3082, ZDI-CAN-28840.
+
+Fixes: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/4899>
+Part-of: 
<https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/10946>
+
+CVE: CVE-2026-3082
+Upstream-Status: Backport 
[https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354]
+
+Signed-off-by: Rohini Sangam <[email protected]>
+---
+ gst-libs/gst/codecparsers/gstjpegparser.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/gst-libs/gst/codecparsers/gstjpegparser.c 
b/gst-libs/gst/codecparsers/gstjpegparser.c
+index 6411076..86125b3 100644
+--- a/gst-libs/gst/codecparsers/gstjpegparser.c
++++ b/gst-libs/gst/codecparsers/gstjpegparser.c
+@@ -79,6 +79,10 @@ ensure_debug_category (void)
+ 
+ #define READ_BYTES(reader, buf, length) G_STMT_START {          \
+     const guint8 *vals;                                         \
++    if (length > sizeof (buf)) {                                \
++      GST_WARNING ("data size is bigger than its storage");     \
++      goto failed;                                              \
++    }                                                           \
+     if (!gst_byte_reader_get_data (reader, length, &vals)) {    \
+       GST_WARNING ("failed to read bytes, size:%d", length);    \
+       goto failed;                                              \
+-- 
+2.44.4
+
diff --git 
a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb 
b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
index f6d0711bd8..64e0aa6dcb 100644
--- a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
+++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
@@ -12,6 +12,7 @@ SRC_URI = 
"https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad
            
file://0005-v4l2codecs-Always-chain-up-to-parent-decide_allocati.patch \
            file://CVE-2025-3887-1.patch \
            file://CVE-2025-3887-2.patch \
+           file://CVE-2026-3082.patch \
            "
 SRC_URI[sha256sum] = 
"388b4c4412f42e36a38b17cc34119bc11879bd4d9fbd4ff6d03b2c7fc6b4d494"
 
-- 
2.34.1

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247013): 
https://lists.openembedded.org/g/openembedded-core/message/247013
Mute This Topic: https://lists.openembedded.org/mt/121522872/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to