Backport patch to fix CVE-2026-15028. References: https://nvd.nist.gov/vuln/detail/CVE-2026-15028
Upstream fix: https://github.com/libarchive/libarchive/commit/40b92de1def08e4fc319d55702785f82cedb7ef2 Signed-off-by: Jakub Szczudlo <[email protected]> --- .../libarchive/CVE-2026-15028.patch | 41 +++++++++++++++++++ .../libarchive/libarchive_3.7.9.bb | 1 + 2 files changed, 42 insertions(+) create mode 100644 meta/recipes-extended/libarchive/libarchive/CVE-2026-15028.patch diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-15028.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-15028.patch new file mode 100644 index 0000000000..c63fcf22f2 --- /dev/null +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-15028.patch @@ -0,0 +1,41 @@ +From 40b92de1def08e4fc319d55702785f82cedb7ef2 Mon Sep 17 00:00:00 2001 +From: datauwu <[email protected]> +Date: Mon, 6 Jul 2026 21:51:15 +0800 +Subject: [PATCH] tar: fix 1-byte OOB read in SUN.holesdata parsing + +header_pax_extension() passes PAX attribute values without the trailing +newline to pax_attribute(). The SUN.holesdata parser read one byte past +the supplied value when the last numeric field ended at the value +boundary. + +Handle length == 0 before checking *e. + +CVE: CVE-2026-15028 +Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/40b92de1def08e4fc319d55702785f82cedb7ef2] +Signed-off-by: Jakub Szczudlo <[email protected]> +--- + libarchive/archive_read_support_format_tar.c | 11 ++++------- + 1 file changed, 4 insertions(+), 7 deletions(-) + +diff --git a/libarchive/archive_read_support_format_tar.c b/libarchive/archive_read_support_format_tar.c +index e07cfdb63b..1c0441db6c 100644 +--- a/libarchive/archive_read_support_format_tar.c ++++ b/libarchive/archive_read_support_format_tar.c +@@ -3448,13 +3448,10 @@ pax_attribute_SUN_holesdata(struct archive_read *a, struct tar *tar, + return (ARCHIVE_FATAL); + tar->sparse_last->hole = hole; + } +- if (length == 0 || *e == '\n') { +- if (length == 0 && *e == '\n') { +- return (ARCHIVE_OK); +- } else { +- return (ARCHIVE_WARN); +- } +- } ++ if (length == 0) ++ return (ARCHIVE_OK); ++ if (*e == '\n') ++ return (ARCHIVE_WARN); + p = e + 1; + length--; + hole = hole == 0; diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index 2eb22e2d61..3719965eed 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb @@ -51,6 +51,7 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \ file://CVE-2026-4424-2.patch \ file://CVE-2026-5121-02.patch \ file://CVE-2026-5745.patch \ + file://CVE-2026-15028.patch \ " UPSTREAM_CHECK_URI = "http://libarchive.org/" -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247107): https://lists.openembedded.org/g/openembedded-core/message/247107 Mute This Topic: https://lists.openembedded.org/mt/121544442/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
