summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPeter Marko <peter.marko@siemens.com>2026-02-20 17:21:31 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2026-02-27 17:45:07 +0000
commite1fb45c7b3b57ddc2d7cfa274cdd75f0b5ff01d6 (patch)
tree185f7f5dabbba35c038d2e52670d1701f8ca1af9
parentfd826a83c7d7e44527dcc8d6fb20ad34830cd67e (diff)
downloadpoky-e1fb45c7b3b57ddc2d7cfa274cdd75f0b5ff01d6.tar.gz
glib-2.0: patch CVE-2026-1485
Pick patch from [1] linked from [2]. [1] https://gitlab.gnome.org/GNOME/glib/-/issues/3871 [2] https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4981 (From OE-Core rev: 64c332e99d0487178aab96578008bec9b133533f) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-1485.patch44
-rw-r--r--meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb1
2 files changed, 45 insertions, 0 deletions
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-1485.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-1485.patch
new file mode 100644
index 0000000000..73c29db999
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-1485.patch
@@ -0,0 +1,44 @@
1From ee5acb2cefc643450509374da2600cd3bf49a109 Mon Sep 17 00:00:00 2001
2From: Marco Trevisan <mail@3v1n0.net>
3Date: Fri, 23 Jan 2026 19:05:44 +0100
4Subject: [PATCH] gio/gcontenttype-fdo: Do not overflow if header is longer
5 than MAXINT
6MIME-Version: 1.0
7Content-Type: text/plain; charset=UTF-8
8Content-Transfer-Encoding: 8bit
9
10In case the header size is longer than MAXINT we may read and write to
11invalid locations
12
13Spotted by treeplus.
14Thanks to the Sovereign Tech Resilience programme from the Sovereign
15Tech Agency.
16
17ID: #YWH-PGM9867-169
18Closes: #3871
19
20
21(cherry picked from commit aacda5b07141b944408c79e83bcbed3b2e1e6e45)
22
23Co-authored-by: Marco Trevisan (TreviƱo) <mail@3v1n0.net>
24
25CVE: CVE-2026-1485
26Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ee5acb2cefc643450509374da2600cd3bf49a109]
27Signed-off-by: Peter Marko <peter.marko@siemens.com>
28---
29 gio/gcontenttype.c | 2 +-
30 1 file changed, 1 insertion(+), 1 deletion(-)
31
32diff --git a/gio/gcontenttype.c b/gio/gcontenttype.c
33index 230cea182..11323973a 100644
34--- a/gio/gcontenttype.c
35+++ b/gio/gcontenttype.c
36@@ -1021,7 +1021,7 @@ tree_match_free (TreeMatch *match)
37 static TreeMatch *
38 parse_header (gchar *line)
39 {
40- gint len;
41+ size_t len;
42 gchar *s;
43 TreeMatch *match;
44
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 43a28273e9..fefa3ad7d6 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -42,6 +42,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
42 file://CVE-2026-0988.patch \ 42 file://CVE-2026-0988.patch \
43 file://CVE-2026-1484-01.patch \ 43 file://CVE-2026-1484-01.patch \
44 file://CVE-2026-1484-02.patch \ 44 file://CVE-2026-1484-02.patch \
45 file://CVE-2026-1485.patch \
45 " 46 "
46SRC_URI:append:class-native = " file://relocate-modules.patch \ 47SRC_URI:append:class-native = " file://relocate-modules.patch \
47 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \ 48 file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \