summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorHugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com>2026-05-20 10:42:13 +0200
committerPaul Barker <paul@pbarker.dev>2026-06-10 14:35:20 +0100
commit5bfb71633fb3e086d496fe079e3f07726f881a19 (patch)
tree1cd7a48bf00e03435b679a54b59fe3985af53526 /meta
parent0c7beb2bd7206dded12c873006c264a4a7657e42 (diff)
downloadpoky-5bfb71633fb3e086d496fe079e3f07726f881a19.tar.gz
libarchive: Fix CVE-2026-4424
Pick patches from [1] and [2] as mentioned in Debian report in [3]. [1] https://github.com/libarchive/libarchive/commit/d379dc0b2976b7207d1ad78f5ed3eb99a5b6d375 [2] https://github.com/libarchive/libarchive/commit/e1907c5832b6489c7b4198b0825f857c93a03c10 [3] https://security-tracker.debian.org/tracker/CVE-2026-4424 (From OE-Core rev: 7fa280872275e194152cc2d355ad39c81a477d50) Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com> Reviewed-by: Bruno VERNAY <bruno.vernay@se.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch61
-rw-r--r--meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch28
-rw-r--r--meta/recipes-extended/libarchive/libarchive_3.7.9.bb2
3 files changed, 91 insertions, 0 deletions
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch
new file mode 100644
index 0000000000..c805092746
--- /dev/null
+++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch
@@ -0,0 +1,61 @@
1From fa32110f851b121a3e1c19fda347e86396fde2bd Mon Sep 17 00:00:00 2001
2From: elhananhaenel <elhanan.haenel@mail.huji.ac.il>
3Date: Sat, 7 Mar 2026 22:32:09 +0200
4Subject: [PATCH 1/2] rar: fix LZSS window size mismatch after PPMd block
5
6When a PPMd-compressed block updates dictionary_size, the LZSS window
7from a prior block is not reallocated. The allocation guard only checks
8if dictionary_size is zero or the window pointer is NULL, not whether
9the existing window is large enough. This allows copy_from_lzss_window()
10to read past the allocated buffer.
11
12Fix the guard to also check whether the current window is undersized.
13Add bounds checks in copy_from_lzss_window() and parse_filter() as
14defense in depth.
15
16CVE: CVE-2026-4424
17Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/d379dc0b2976b7207d1ad78f5ed3eb99a5b6d375]
18Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com>
19---
20 libarchive/archive_read_support_format_rar.c | 11 +++++++++--
21 1 file changed, 9 insertions(+), 2 deletions(-)
22
23diff --git a/libarchive/archive_read_support_format_rar.c b/libarchive/archive_read_support_format_rar.c
24index 88eab627..b23be937 100644
25--- a/libarchive/archive_read_support_format_rar.c
26+++ b/libarchive/archive_read_support_format_rar.c
27@@ -2503,7 +2503,8 @@ parse_codes(struct archive_read *a)
28 return (r);
29 }
30
31- if (!rar->dictionary_size || !rar->lzss.window)
32+ if (!rar->dictionary_size || !rar->lzss.window ||
33+ (rar->lzss.mask + 1) < rar->dictionary_size)
34 {
35 /* Seems as though dictionary sizes are not used. Even so, minimize
36 * memory usage as much as possible.
37@@ -3104,6 +3105,11 @@ copy_from_lzss_window(struct archive_read *a, uint8_t *buffer,
38
39 windowoffs = lzss_offset_for_position(&rar->lzss, startpos);
40 firstpart = lzss_size(&rar->lzss) - windowoffs;
41+ if (length > lzss_size(&rar->lzss)) {
42+ archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
43+ "Bad RAR file data");
44+ return (ARCHIVE_FATAL);
45+ }
46 if (firstpart < 0) {
47 archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
48 "Bad RAR file data");
49@@ -3266,7 +3272,8 @@ parse_filter(struct archive_read *a, const uint8_t *bytes, uint16_t length, uint
50 else
51 blocklength = prog ? prog->oldfilterlength : 0;
52
53- if (blocklength > rar->dictionary_size)
54+ if (blocklength > rar->dictionary_size ||
55+ blocklength > (uint32_t)(rar->lzss.mask + 1))
56 return 0;
57
58 registers[3] = PROGRAM_SYSTEM_GLOBAL_ADDRESS;
59--
602.43.0
61
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch
new file mode 100644
index 0000000000..a5c6ba2d2b
--- /dev/null
+++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch
@@ -0,0 +1,28 @@
1From d696008467844efca026bf198a8814a8647ec2d2 Mon Sep 17 00:00:00 2001
2From: elhananhaenel <elhanan.haenel@mail.huji.ac.il>
3Date: Sun, 8 Mar 2026 15:29:46 +0200
4Subject: [PATCH 2/2] Fix -Wsign-compare: cast mask+1 to unsigned int
5
6CVE: CVE-2026-4424
7Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/e1907c5832b6489c7b4198b0825f857c93a03c10]
8Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com>
9---
10 libarchive/archive_read_support_format_rar.c | 2 +-
11 1 file changed, 1 insertion(+), 1 deletion(-)
12
13diff --git a/libarchive/archive_read_support_format_rar.c b/libarchive/archive_read_support_format_rar.c
14index b23be937..a28a6cba 100644
15--- a/libarchive/archive_read_support_format_rar.c
16+++ b/libarchive/archive_read_support_format_rar.c
17@@ -2504,7 +2504,7 @@ parse_codes(struct archive_read *a)
18 }
19
20 if (!rar->dictionary_size || !rar->lzss.window ||
21- (rar->lzss.mask + 1) < rar->dictionary_size)
22+ (unsigned int)(rar->lzss.mask + 1) < rar->dictionary_size)
23 {
24 /* Seems as though dictionary sizes are not used. Even so, minimize
25 * memory usage as much as possible.
26--
272.43.0
28
diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
index de9682400a..c167b164b4 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
@@ -47,6 +47,8 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \
47 file://CVE-2026-4111-1.patch \ 47 file://CVE-2026-4111-1.patch \
48 file://CVE-2026-4111-2.patch \ 48 file://CVE-2026-4111-2.patch \
49 file://CVE-2026-4426.patch \ 49 file://CVE-2026-4426.patch \
50 file://CVE-2026-4424-1.patch \
51 file://CVE-2026-4424-2.patch \
50 " 52 "
51UPSTREAM_CHECK_URI = "http://libarchive.org/" 53UPSTREAM_CHECK_URI = "http://libarchive.org/"
52 54