On Tue Sep 29, 2026 at 6:18 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Hetvi Thakar <[email protected]> > > This patch applies the upstream fix as referenced in [2], > using the commit shown in [1]. > > [1] > https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86144 > > Signed-off-by: Hetvi Thakar <[email protected]> > --- > .../libxml/libxml2/CVE-2026-86144.patch | 219 ++++++++++++++++++ > meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + > 2 files changed, 220 insertions(+) > create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch > > diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch > b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch > new file mode 100644 > index 0000000000..41fee42732 > --- /dev/null > +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch > @@ -0,0 +1,219 @@ > +From 8d0c6eb94f8a32a49e3c9122a6da82c519198063 Mon Sep 17 00:00:00 2001 > +From: Ruben Thijssen <[email protected]> > +Date: Fri, 15 May 2026 15:42:18 +1000 > +Subject: [PATCH] fix(xinclude): propagate parseFlags in xmlXIncludeProcess > and > + xmlXIncludeProcessTree > + > +CVE: CVE-2026-86144 > +Upstream-Status: Backport > [https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61] > + > +Backport Changes: > +- Use xmlLoadExternalEntity() with xmlCtxtUseOptions() because Scarthgap > 2.12.10 predates xmlLoadResource() and resource-loader callbacks. > +- Adapt the regression tests for 2.12.10 by using the global > structured-error handler, matching 2.12.10 loader network-entity diagnostics, > and restoring the test handler after xmlXIncludeProcess(). > +- Omit the upstream XML_IO_NETWORK_ATTEMPT filter because the 2.12.10 > xmlLoadExternalEntity() path has no corresponding post-load error-filtering > block. > +- Add a parser-context allocation guard because the target version can > return NULL from xmlNewParserCtxt(). ^ Please wrap this at 80 chars
> +(cherry picked from commit b63cd517afecb76582dd9488c55e54ceaf50de61) > +Signed-off-by: Hetvi Thakar <[email protected]> > +--- > + result/XInclude/issue1120-1.xml | 4 ++ > + result/XInclude/issue1120-1.xml.err | 1 + > + result/XInclude/issue1120-2.xml | 4 ++ > + result/XInclude/issue1120-2.xml.err | 1 + > + runtest.c | 75 +++++++++++++++++++++++++ > + test/XInclude/issue1120/issue1120-1.xml | 6 ++ > + test/XInclude/issue1120/issue1120-2.xml | 6 ++ > + xinclude.c | 9 ++- > + 8 files changed, 104 insertions(+), 2 deletions(-) > + create mode 100644 result/XInclude/issue1120-1.xml > + create mode 100644 result/XInclude/issue1120-1.xml.err > + create mode 100644 result/XInclude/issue1120-2.xml > + create mode 100644 result/XInclude/issue1120-2.xml.err > + create mode 100644 test/XInclude/issue1120/issue1120-1.xml > + create mode 100644 test/XInclude/issue1120/issue1120-2.xml > + > +diff --git a/runtest.c b/runtest.c > +index e91e2dfd..297cb5e2 100644 > +--- a/runtest.c > ++++ b/runtest.c > +@@ -2444,6 +2444,75 @@ noentParseTest(const char *filename, const char > *result, > + return(res); > + } > + > ++#ifdef LIBXML_XINCLUDE_ENABLED > ++/** > ++ * Parse a file and run xmlXIncludeProcess() to verify that doc->parseFlags > ++ * is propagated properly. > ++ * > ++ * @param filename the file to parse > ++ * @param result the file with expected result > ++ * @param err the file with error messages > ++ * @returns 0 in case of success, an error code otherwise > ++ */ > ++static int > ++xincludeProcessTest(const char *filename, const char *result, const char > *err, > ++ int options) { > [...] > ++ /* > ++ * Run xmlXIncludeProcess() with a structured error handler to check > that > ++ * the parse flags are propagated. > ++ */ > ++ xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler); > ++ xmlXIncludeProcess(doc); > ++ xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler); Upstream commit calls "xmlSetStructuredErrorFunc(NULL, NULL);" here but this change is not explained. > [...] > +diff --git a/xinclude.c b/xinclude.c > +index b6581558..0d57f5a1 100644 > +--- a/xinclude.c > ++++ b/xinclude.c > +@@ -1688,6 +1688,11 @@ xmlXIncludeLoadTxt(xmlXIncludeCtxtPtr ctxt, const > xmlChar *url, > + * Load it. > + */ > + pctxt = xmlNewParserCtxt(); > ++ if (pctxt == NULL) { > ++ xmlXIncludeErrMemory(ctxt, ref->elem, NULL); > ++ goto error; > ++ } This if statement comes from another commit: 78eab7a1 - xinclude: Report malloc failures It look a bit intrusive to be backported but at least we need to reference it in the changelog. > ++ xmlCtxtUseOptions(pctxt, ctxt->parseFlags); > + inputStream = xmlLoadExternalEntity((const char*)URL, NULL, pctxt); > + if(inputStream == NULL) > + goto error; > [...] > diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb > b/meta/recipes-core/libxml/libxml2_2.12.10.bb > index 1b0c3d50da..c100ef2a8c 100644 > --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb > +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb > @@ -38,6 +38,7 @@ SRC_URI += > "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt > file://CVE-2026-86141.patch \ > file://CVE-2026-86142.patch \ > file://CVE-2026-86143.patch \ > + file://CVE-2026-86144.patch \ > " > > SRC_URI[archive.sha256sum] = > "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995" Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247124): https://lists.openembedded.org/g/openembedded-core/message/247124 Mute This Topic: https://lists.openembedded.org/mt/121485381/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
