diff options
| author | Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com> | 2026-05-20 10:42:13 +0200 |
|---|---|---|
| committer | Paul Barker <paul@pbarker.dev> | 2026-06-10 14:35:20 +0100 |
| commit | 5bfb71633fb3e086d496fe079e3f07726f881a19 (patch) | |
| tree | 1cd7a48bf00e03435b679a54b59fe3985af53526 /meta | |
| parent | 0c7beb2bd7206dded12c873006c264a4a7657e42 (diff) | |
| download | poky-5bfb71633fb3e086d496fe079e3f07726f881a19.tar.gz | |
libarchive: Fix CVE-2026-4424
Pick patches from [1] and [2] as mentioned in Debian report in [3].
[1] https://github.com/libarchive/libarchive/commit/d379dc0b2976b7207d1ad78f5ed3eb99a5b6d375
[2] https://github.com/libarchive/libarchive/commit/e1907c5832b6489c7b4198b0825f857c93a03c10
[3] https://security-tracker.debian.org/tracker/CVE-2026-4424
(From OE-Core rev: 7fa280872275e194152cc2d355ad39c81a477d50)
Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com>
Reviewed-by: Bruno VERNAY <bruno.vernay@se.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
3 files changed, 91 insertions, 0 deletions
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch new file mode 100644 index 0000000000..c805092746 --- /dev/null +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-1.patch | |||
| @@ -0,0 +1,61 @@ | |||
| 1 | From fa32110f851b121a3e1c19fda347e86396fde2bd Mon Sep 17 00:00:00 2001 | ||
| 2 | From: elhananhaenel <elhanan.haenel@mail.huji.ac.il> | ||
| 3 | Date: Sat, 7 Mar 2026 22:32:09 +0200 | ||
| 4 | Subject: [PATCH 1/2] rar: fix LZSS window size mismatch after PPMd block | ||
| 5 | |||
| 6 | When a PPMd-compressed block updates dictionary_size, the LZSS window | ||
| 7 | from a prior block is not reallocated. The allocation guard only checks | ||
| 8 | if dictionary_size is zero or the window pointer is NULL, not whether | ||
| 9 | the existing window is large enough. This allows copy_from_lzss_window() | ||
| 10 | to read past the allocated buffer. | ||
| 11 | |||
| 12 | Fix the guard to also check whether the current window is undersized. | ||
| 13 | Add bounds checks in copy_from_lzss_window() and parse_filter() as | ||
| 14 | defense in depth. | ||
| 15 | |||
| 16 | CVE: CVE-2026-4424 | ||
| 17 | Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/d379dc0b2976b7207d1ad78f5ed3eb99a5b6d375] | ||
| 18 | Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com> | ||
| 19 | --- | ||
| 20 | libarchive/archive_read_support_format_rar.c | 11 +++++++++-- | ||
| 21 | 1 file changed, 9 insertions(+), 2 deletions(-) | ||
| 22 | |||
| 23 | diff --git a/libarchive/archive_read_support_format_rar.c b/libarchive/archive_read_support_format_rar.c | ||
| 24 | index 88eab627..b23be937 100644 | ||
| 25 | --- a/libarchive/archive_read_support_format_rar.c | ||
| 26 | +++ b/libarchive/archive_read_support_format_rar.c | ||
| 27 | @@ -2503,7 +2503,8 @@ parse_codes(struct archive_read *a) | ||
| 28 | return (r); | ||
| 29 | } | ||
| 30 | |||
| 31 | - if (!rar->dictionary_size || !rar->lzss.window) | ||
| 32 | + if (!rar->dictionary_size || !rar->lzss.window || | ||
| 33 | + (rar->lzss.mask + 1) < rar->dictionary_size) | ||
| 34 | { | ||
| 35 | /* Seems as though dictionary sizes are not used. Even so, minimize | ||
| 36 | * memory usage as much as possible. | ||
| 37 | @@ -3104,6 +3105,11 @@ copy_from_lzss_window(struct archive_read *a, uint8_t *buffer, | ||
| 38 | |||
| 39 | windowoffs = lzss_offset_for_position(&rar->lzss, startpos); | ||
| 40 | firstpart = lzss_size(&rar->lzss) - windowoffs; | ||
| 41 | + if (length > lzss_size(&rar->lzss)) { | ||
| 42 | + archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT, | ||
| 43 | + "Bad RAR file data"); | ||
| 44 | + return (ARCHIVE_FATAL); | ||
| 45 | + } | ||
| 46 | if (firstpart < 0) { | ||
| 47 | archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT, | ||
| 48 | "Bad RAR file data"); | ||
| 49 | @@ -3266,7 +3272,8 @@ parse_filter(struct archive_read *a, const uint8_t *bytes, uint16_t length, uint | ||
| 50 | else | ||
| 51 | blocklength = prog ? prog->oldfilterlength : 0; | ||
| 52 | |||
| 53 | - if (blocklength > rar->dictionary_size) | ||
| 54 | + if (blocklength > rar->dictionary_size || | ||
| 55 | + blocklength > (uint32_t)(rar->lzss.mask + 1)) | ||
| 56 | return 0; | ||
| 57 | |||
| 58 | registers[3] = PROGRAM_SYSTEM_GLOBAL_ADDRESS; | ||
| 59 | -- | ||
| 60 | 2.43.0 | ||
| 61 | |||
diff --git a/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch new file mode 100644 index 0000000000..a5c6ba2d2b --- /dev/null +++ b/meta/recipes-extended/libarchive/libarchive/CVE-2026-4424-2.patch | |||
| @@ -0,0 +1,28 @@ | |||
| 1 | From d696008467844efca026bf198a8814a8647ec2d2 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: elhananhaenel <elhanan.haenel@mail.huji.ac.il> | ||
| 3 | Date: Sun, 8 Mar 2026 15:29:46 +0200 | ||
| 4 | Subject: [PATCH 2/2] Fix -Wsign-compare: cast mask+1 to unsigned int | ||
| 5 | |||
| 6 | CVE: CVE-2026-4424 | ||
| 7 | Upstream-Status: Backport [https://github.com/libarchive/libarchive/commit/e1907c5832b6489c7b4198b0825f857c93a03c10] | ||
| 8 | Signed-off-by: Hugo SIMELIERE (Schneider Electric) <hsimeliere.opensource@witekio.com> | ||
| 9 | --- | ||
| 10 | libarchive/archive_read_support_format_rar.c | 2 +- | ||
| 11 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
| 12 | |||
| 13 | diff --git a/libarchive/archive_read_support_format_rar.c b/libarchive/archive_read_support_format_rar.c | ||
| 14 | index b23be937..a28a6cba 100644 | ||
| 15 | --- a/libarchive/archive_read_support_format_rar.c | ||
| 16 | +++ b/libarchive/archive_read_support_format_rar.c | ||
| 17 | @@ -2504,7 +2504,7 @@ parse_codes(struct archive_read *a) | ||
| 18 | } | ||
| 19 | |||
| 20 | if (!rar->dictionary_size || !rar->lzss.window || | ||
| 21 | - (rar->lzss.mask + 1) < rar->dictionary_size) | ||
| 22 | + (unsigned int)(rar->lzss.mask + 1) < rar->dictionary_size) | ||
| 23 | { | ||
| 24 | /* Seems as though dictionary sizes are not used. Even so, minimize | ||
| 25 | * memory usage as much as possible. | ||
| 26 | -- | ||
| 27 | 2.43.0 | ||
| 28 | |||
diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index de9682400a..c167b164b4 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb | |||
| @@ -47,6 +47,8 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \ | |||
| 47 | file://CVE-2026-4111-1.patch \ | 47 | file://CVE-2026-4111-1.patch \ |
| 48 | file://CVE-2026-4111-2.patch \ | 48 | file://CVE-2026-4111-2.patch \ |
| 49 | file://CVE-2026-4426.patch \ | 49 | file://CVE-2026-4426.patch \ |
| 50 | file://CVE-2026-4424-1.patch \ | ||
| 51 | file://CVE-2026-4424-2.patch \ | ||
| 50 | " | 52 | " |
| 51 | UPSTREAM_CHECK_URI = "http://libarchive.org/" | 53 | UPSTREAM_CHECK_URI = "http://libarchive.org/" |
| 52 | 54 | ||
