From: Peter Marko <[email protected]> Pick patch per [1].
[1] https://security-tracker.debian.org/tracker/CVE-2026-33416 Signed-off-by: Peter Marko <[email protected]> --- .../libpng/files/CVE-2026-33416-05.patch | 58 +++++++++++++++++++ .../libpng/libpng_1.6.42.bb | 1 + 2 files changed, 59 insertions(+) create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-33416-05.patch diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-33416-05.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-33416-05.patch new file mode 100644 index 00000000000..c42f2213b35 --- /dev/null +++ b/meta/recipes-multimedia/libpng/files/CVE-2026-33416-05.patch @@ -0,0 +1,58 @@ +From d4c4e49eb5c8981075ec2cd946428758c0cda6ac Mon Sep 17 00:00:00 2001 +From: Cosmin Truta <[email protected]> +Date: Wed, 15 Apr 2026 14:58:35 +0300 +Subject: [PATCH] fix: Sync `info_ptr->palette` unconditionally after in-place + transforms + +The palette sync in `png_read_transform_info` was guarded by +`if (transformations != 0)`, but the palette-modifying transforms clear +their own bits before this function gets to run. When one of these was +the sole transform, the guard was false and the sync was skipped, which +caused `png_get_PLTE` to return stale palette data. + +Drop this guard. + +This was a regression from commit c1b0318b39 (version 1.6.56). + +Reported-by: ralfjunker <[email protected]> +Resolves: https://github.com/pnggroup/libpng/issues/848 + +CVE: CVE-2026-33416 +Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/d4c4e49eb5c8981075ec2cd946428758c0cda6ac] +Signed-off-by: Peter Marko <[email protected]> +--- + pngrtran.c | 20 ++++++++------------ + 1 file changed, 8 insertions(+), 12 deletions(-) + +diff --git a/pngrtran.c b/pngrtran.c +index 1b04cafa5..0ac8df749 100644 +--- a/pngrtran.c ++++ b/pngrtran.c +@@ -1984,19 +1984,15 @@ png_read_transform_info(png_structrp png_ptr, png_inforp info_ptr) + { + png_debug(1, "in png_read_transform_info"); + +- if (png_ptr->transformations != 0) ++ if (info_ptr->color_type == PNG_COLOR_TYPE_PALETTE && ++ info_ptr->palette != NULL && png_ptr->palette != NULL) + { +- if (info_ptr->color_type == PNG_COLOR_TYPE_PALETTE && +- info_ptr->palette != NULL && png_ptr->palette != NULL) +- { +- /* Sync info_ptr->palette with png_ptr->palette. +- * The function png_init_read_transformations may have modified +- * png_ptr->palette in place (e.g. for gamma correction or for +- * background compositing). +- */ +- memcpy(info_ptr->palette, png_ptr->palette, +- PNG_MAX_PALETTE_LENGTH * (sizeof (png_color))); +- } ++ /* Sync info_ptr->palette with png_ptr->palette, which may ++ * have been modified by png_init_read_transformations ++ * (e.g. for gamma correction or background compositing). ++ */ ++ memcpy(info_ptr->palette, png_ptr->palette, ++ PNG_MAX_PALETTE_LENGTH * (sizeof (png_color))); + } + + #ifdef PNG_READ_EXPAND_SUPPORTED diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb index b226e327b64..f375aa5f4e9 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb @@ -31,6 +31,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/${PV}/${BP}.tar.xz file://CVE-2026-33416-04.patch \ file://CVE-2026-34757_p1.patch \ file://CVE-2026-34757_p2.patch \ + file://CVE-2026-33416-05.patch \ " SRC_URI[sha256sum] = "c919dbc11f4c03b05aba3f8884d8eb7adfe3572ad228af972bb60057bdb48450"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247155): https://lists.openembedded.org/g/openembedded-core/message/247155 Mute This Topic: https://lists.openembedded.org/mt/121560687/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
