On Tue Sep 29, 2026 at 6:18 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Hetvi Thakar <[email protected]> > > This patch applies the upstream fix as referenced in [2], > using the commit shown in [1]. > > [1] > https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-86137 > > Signed-off-by: Hetvi Thakar <[email protected]> > --- > .../libxml/libxml2/CVE-2026-86137.patch | 59 +++++++++++++++++++ > meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 + > 2 files changed, 60 insertions(+) > create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch > > diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch > b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch > new file mode 100644 > index 0000000000..a756883d46 > --- /dev/null > +++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86137.patch > @@ -0,0 +1,59 @@ > +From a9d489b86e46188d1c0fde7dbd0aa8281596e6d6 Mon Sep 17 00:00:00 2001 > +From: Hieu Le Minh <[email protected]> > +Date: Sat, 18 Apr 2026 21:18:24 +0700 > +Subject: [PATCH] xmlregexp: Prevent out-of-bounds read in NXT macro > + > +Fixes: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1099 > + > +CVE: CVE-2026-86137 > +Upstream-Status: Backport > [https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2] > + > +Backport Changes: > +- Add the parser-context length field and allocation-failure guard required > by the Scarthgap 2.12.10 source, which lacks both pieces of the upstream > context. > +- The allocation-failure guard is completed by the subsequent > CVE-2026-86141.patch, which moves strlen() after the xmlStrdup() null check; > keep that patch after this one in SRC_URI.
Please wrap this at 80 characters, we are flexible on this but, here, this is too long. Note that this also applies to other patches in this series. Since there are actual dependencies between patches in this series, I hold the whole series and wait for you to send a fixed v2. Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247129): https://lists.openembedded.org/g/openembedded-core/message/247129 Mute This Topic: https://lists.openembedded.org/mt/121485378/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
