diff options
| -rw-r--r-- | meta-networking/recipes-support/strongswan/strongswan/CVE-2026-25075.patch | 50 | ||||
| -rw-r--r-- | meta-networking/recipes-support/strongswan/strongswan_5.9.14.bb | 1 |
2 files changed, 51 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-25075.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-25075.patch new file mode 100644 index 0000000000..46ce5d5ad2 --- /dev/null +++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-25075.patch | |||
| @@ -0,0 +1,50 @@ | |||
| 1 | From d4b3c39776f06948d875614a0eddea9561159f2a Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Tobias Brunner <tobias@strongswan.org> | ||
| 3 | Date: Thu, 5 Mar 2026 12:43:12 +0100 | ||
| 4 | Subject: [PATCH] eap-ttls: Prevent crash if AVP length header field is invalid | ||
| 5 | |||
| 6 | The length field in the AVP header includes the 8 bytes of the header | ||
| 7 | itself. Not checking for that and later subtracting it causes an | ||
| 8 | integer underflow that usually triggers a crash when accessing a | ||
| 9 | NULL pointer that resulted from the failing chunk_alloc() call because | ||
| 10 | of the high value. | ||
| 11 | |||
| 12 | The attempted allocations for invalid lengths (0-7) are 0xfffffff8, | ||
| 13 | 0xfffffffc, or 0x100000000 (0 on 32-bit hosts), so this doesn't result | ||
| 14 | in a buffer overflow even if the allocation succeeds. | ||
| 15 | |||
| 16 | Fixes: 79f2102cb442 ("implemented server side support for EAP-TTLS") | ||
| 17 | Fixes: CVE-2026-25075 | ||
| 18 | |||
| 19 | Upstream-Status: Backport [https://download.strongswan.org/security/CVE-2026-25075/strongswan-4.5.0-6.0.4_eap_ttls_avp_len.patch] | ||
| 20 | CVE: CVE-2026-25075 | ||
| 21 | Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> | ||
| 22 | --- | ||
| 23 | src/libcharon/plugins/eap_ttls/eap_ttls_avp.c | 4 ++-- | ||
| 24 | 1 file changed, 2 insertions(+), 2 deletions(-) | ||
| 25 | |||
| 26 | diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c b/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c | ||
| 27 | index 06389f7ca73e..2983bd021ded 100644 | ||
| 28 | --- a/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c | ||
| 29 | +++ b/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c | ||
| 30 | @@ -119,7 +119,7 @@ METHOD(eap_ttls_avp_t, process, status_t, | ||
| 31 | chunk_free(&this->input); | ||
| 32 | this->inpos = 0; | ||
| 33 | |||
| 34 | - if (!success) | ||
| 35 | + if (!success || avp_len < AVP_HEADER_LEN) | ||
| 36 | { | ||
| 37 | DBG1(DBG_IKE, "received invalid AVP header"); | ||
| 38 | return FAILED; | ||
| 39 | @@ -130,7 +130,7 @@ METHOD(eap_ttls_avp_t, process, status_t, | ||
| 40 | return FAILED; | ||
| 41 | } | ||
| 42 | this->process_header = FALSE; | ||
| 43 | - this->data_len = avp_len - 8; | ||
| 44 | + this->data_len = avp_len - AVP_HEADER_LEN; | ||
| 45 | this->input = chunk_alloc(this->data_len + (4 - avp_len) % 4); | ||
| 46 | } | ||
| 47 | |||
| 48 | -- | ||
| 49 | 2.43.0 | ||
| 50 | |||
diff --git a/meta-networking/recipes-support/strongswan/strongswan_5.9.14.bb b/meta-networking/recipes-support/strongswan/strongswan_5.9.14.bb index 4592381a36..820a1ad9e8 100644 --- a/meta-networking/recipes-support/strongswan/strongswan_5.9.14.bb +++ b/meta-networking/recipes-support/strongswan/strongswan_5.9.14.bb | |||
| @@ -10,6 +10,7 @@ DEPENDS:append = "${@bb.utils.contains('DISTRO_FEATURES', 'tpm2', ' tpm2-tss', | |||
| 10 | 10 | ||
| 11 | SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ | 11 | SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \ |
| 12 | file://CVE-2025-62291.patch \ | 12 | file://CVE-2025-62291.patch \ |
| 13 | file://CVE-2026-25075.patch \ | ||
| 13 | " | 14 | " |
| 14 | 15 | ||
| 15 | SRC_URI[sha256sum] = "728027ddda4cb34c67c4cec97d3ddb8c274edfbabdaeecf7e74693b54fc33678" | 16 | SRC_URI[sha256sum] = "728027ddda4cb34c67c4cec97d3ddb8c274edfbabdaeecf7e74693b54fc33678" |
