On Tue Sep 29, 2026 at 6:18 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Hetvi Thakar <[email protected]>
>
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
>
> [1] 
> https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86144
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
>  .../libxml/libxml2/CVE-2026-86144.patch       | 219 ++++++++++++++++++
>  meta/recipes-core/libxml/libxml2_2.12.10.bb   |   1 +
>  2 files changed, 220 insertions(+)
>  create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch
>
> diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch 
> b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch
> new file mode 100644
> index 0000000000..41fee42732
> --- /dev/null
> +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86144.patch
> @@ -0,0 +1,219 @@
> +From 8d0c6eb94f8a32a49e3c9122a6da82c519198063 Mon Sep 17 00:00:00 2001
> +From: Ruben Thijssen <[email protected]>
> +Date: Fri, 15 May 2026 15:42:18 +1000
> +Subject: [PATCH] fix(xinclude): propagate parseFlags in xmlXIncludeProcess 
> and
> + xmlXIncludeProcessTree
> +
> +CVE: CVE-2026-86144
> +Upstream-Status: Backport 
> [https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61]
> +
> +Backport Changes:
> +- Use xmlLoadExternalEntity() with xmlCtxtUseOptions() because Scarthgap 
> 2.12.10 predates xmlLoadResource() and resource-loader callbacks.
> +- Adapt the regression tests for 2.12.10 by using the global 
> structured-error handler, matching 2.12.10 loader network-entity diagnostics, 
> and restoring the test handler after xmlXIncludeProcess().
> +- Omit the upstream XML_IO_NETWORK_ATTEMPT filter because the 2.12.10 
> xmlLoadExternalEntity() path has no corresponding post-load error-filtering 
> block.
> +- Add a parser-context allocation guard because the target version can 
> return NULL from xmlNewParserCtxt().
     ^ Please wrap this at 80 chars

> +(cherry picked from commit b63cd517afecb76582dd9488c55e54ceaf50de61)
> +Signed-off-by: Hetvi Thakar <[email protected]>
> +---
> + result/XInclude/issue1120-1.xml         |  4 ++
> + result/XInclude/issue1120-1.xml.err     |  1 +
> + result/XInclude/issue1120-2.xml         |  4 ++
> + result/XInclude/issue1120-2.xml.err     |  1 +
> + runtest.c                               | 75 +++++++++++++++++++++++++
> + test/XInclude/issue1120/issue1120-1.xml |  6 ++
> + test/XInclude/issue1120/issue1120-2.xml |  6 ++
> + xinclude.c                              |  9 ++-
> + 8 files changed, 104 insertions(+), 2 deletions(-)
> + create mode 100644 result/XInclude/issue1120-1.xml
> + create mode 100644 result/XInclude/issue1120-1.xml.err
> + create mode 100644 result/XInclude/issue1120-2.xml
> + create mode 100644 result/XInclude/issue1120-2.xml.err
> + create mode 100644 test/XInclude/issue1120/issue1120-1.xml
> + create mode 100644 test/XInclude/issue1120/issue1120-2.xml
> +
> +diff --git a/runtest.c b/runtest.c
> +index e91e2dfd..297cb5e2 100644
> +--- a/runtest.c
> ++++ b/runtest.c
> +@@ -2444,6 +2444,75 @@ noentParseTest(const char *filename, const char 
> *result,
> +     return(res);
> + }
> + 
> ++#ifdef LIBXML_XINCLUDE_ENABLED
> ++/**
> ++ * Parse a file and run xmlXIncludeProcess() to verify that doc->parseFlags
> ++ * is propagated properly.
> ++ *
> ++ * @param filename  the file to parse
> ++ * @param result  the file with expected result
> ++ * @param err  the file with error messages
> ++ * @returns 0 in case of success, an error code otherwise
> ++ */
> ++static int
> ++xincludeProcessTest(const char *filename, const char *result, const char 
> *err,
> ++                    int options) {
> [...]
> ++    /*
> ++     * Run xmlXIncludeProcess() with a structured error handler to check 
> that
> ++     * the parse flags are propagated.
> ++     */
> ++    xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler);
> ++    xmlXIncludeProcess(doc);
> ++    xmlSetStructuredErrorFunc(NULL, testStructuredErrorHandler);
Upstream commit calls "xmlSetStructuredErrorFunc(NULL, NULL);" here but
this change is not explained.


> [...]
> +diff --git a/xinclude.c b/xinclude.c
> +index b6581558..0d57f5a1 100644
> +--- a/xinclude.c
> ++++ b/xinclude.c
> +@@ -1688,6 +1688,11 @@ xmlXIncludeLoadTxt(xmlXIncludeCtxtPtr ctxt, const 
> xmlChar *url,
> +      * Load it.
> +      */
> +     pctxt = xmlNewParserCtxt();
> ++    if (pctxt == NULL) {
> ++        xmlXIncludeErrMemory(ctxt, ref->elem, NULL);
> ++        goto error;
> ++    }

This if statement comes from another commit:
78eab7a1 - xinclude: Report malloc failures

It look a bit intrusive to be backported but at least we need to
reference it in the changelog.

> ++    xmlCtxtUseOptions(pctxt, ctxt->parseFlags);
> +     inputStream = xmlLoadExternalEntity((const char*)URL, NULL, pctxt);
> +     if(inputStream == NULL)
> +     goto error;
> [...]
> diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb 
> b/meta/recipes-core/libxml/libxml2_2.12.10.bb
> index 1b0c3d50da..c100ef2a8c 100644
> --- a/meta/recipes-core/libxml/libxml2_2.12.10.bb
> +++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb
> @@ -38,6 +38,7 @@ SRC_URI += 
> "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
>             file://CVE-2026-86141.patch \
>             file://CVE-2026-86142.patch \
>             file://CVE-2026-86143.patch \
> +           file://CVE-2026-86144.patch \
>             "
>  
>  SRC_URI[archive.sha256sum] = 
> "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247124): 
https://lists.openembedded.org/g/openembedded-core/message/247124
Mute This Topic: https://lists.openembedded.org/mt/121485381/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org

Reply via email to