diff options
| author | Hitendra Prajapati <hprajapati@mvista.com> | 2026-04-28 17:55:28 +0530 |
|---|---|---|
| committer | Paul Barker <paul@pbarker.dev> | 2026-05-12 21:31:34 +0100 |
| commit | f0366984060c79d4d72f3733f072a4558e240333 (patch) | |
| tree | e0a09931470d866f6ac647f077089011512fc13c /meta | |
| parent | e9575f38d797516853b75bfe8b9fdec56a435a62 (diff) | |
| download | poky-f0366984060c79d4d72f3733f072a4558e240333.tar.gz | |
systemd: fix for CVE-2026-40225
Backport commit[0] and [1] which fixes this vulnerability as mentioned in Debian report [2].
[0] https://github.com/systemd/systemd/commit/03bb697b8df0339c37f4b845025320b261aeb7cc
[1] https://github.com/systemd/systemd/commit/5887e72ff87d3a66a4c3fa91897fbec1545f4d3d
[2] https://security-tracker.debian.org/tracker/CVE-2026-40225
More details : https://nvd.nist.gov/vuln/detail/CVE-2026-40225
(From OE-Core rev: fc2d33dbb2d5180b77c10865156db342f9d582da)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
| -rw-r--r-- | meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch | 131 | ||||
| -rw-r--r-- | meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch | 39 | ||||
| -rw-r--r-- | meta/recipes-core/systemd/systemd_255.21.bb | 2 |
3 files changed, 172 insertions, 0 deletions
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch b/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch new file mode 100644 index 0000000000..f616e636c2 --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch | |||
| @@ -0,0 +1,131 @@ | |||
| 1 | From 03bb697b8df0339c37f4b845025320b261aeb7cc Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Luca Boccassi <luca.boccassi@gmail.com> | ||
| 3 | Date: Fri, 6 Mar 2026 19:32:35 +0000 | ||
| 4 | Subject: [PATCH] udev: check for invalid chars in various fields received from | ||
| 5 | the kernel | ||
| 6 | |||
| 7 | (cherry picked from commit 16325b35fa6ecb25f66534a562583ce3b96d52f3) | ||
| 8 | (cherry picked from commit 3513862eabe9ec4a6a095d7266e98f998f289ed2) | ||
| 9 | (cherry picked from commit c20d21e0da293e715db468f9f4a15a5c8fbf8273) | ||
| 10 | |||
| 11 | CVE: CVE-2026-40225 | ||
| 12 | Upstream-Status: Backport [https://github.com/systemd/systemd/commit/03bb697b8df0339c37f4b845025320b261aeb7cc] | ||
| 13 | Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> | ||
| 14 | --- | ||
| 15 | src/udev/dmi_memory_id/dmi_memory_id.c | 3 ++- | ||
| 16 | src/udev/scsi_id/scsi_id.c | 5 +++-- | ||
| 17 | src/udev/udev-builtin-net_id.c | 9 +++++++++ | ||
| 18 | src/udev/v4l_id/v4l_id.c | 5 ++++- | ||
| 19 | 4 files changed, 18 insertions(+), 4 deletions(-) | ||
| 20 | |||
| 21 | diff --git a/src/udev/dmi_memory_id/dmi_memory_id.c b/src/udev/dmi_memory_id/dmi_memory_id.c | ||
| 22 | index 52ea250af8..4f2c21b80b 100644 | ||
| 23 | --- a/src/udev/dmi_memory_id/dmi_memory_id.c | ||
| 24 | +++ b/src/udev/dmi_memory_id/dmi_memory_id.c | ||
| 25 | @@ -51,6 +51,7 @@ | ||
| 26 | #include "string-util.h" | ||
| 27 | #include "udev-util.h" | ||
| 28 | #include "unaligned.h" | ||
| 29 | +#include "utf8.h" | ||
| 30 | |||
| 31 | #define SUPPORTED_SMBIOS_VER 0x030300 | ||
| 32 | |||
| 33 | @@ -185,7 +186,7 @@ static void dmi_memory_device_string( | ||
| 34 | |||
| 35 | str = strdupa_safe(dmi_string(h, s)); | ||
| 36 | str = strstrip(str); | ||
| 37 | - if (!isempty(str)) | ||
| 38 | + if (!isempty(str) && utf8_is_valid(str) && !string_has_cc(str, /* ok= */ NULL)) | ||
| 39 | printf("MEMORY_DEVICE_%u_%s=%s\n", slot_num, attr_suffix, str); | ||
| 40 | } | ||
| 41 | |||
| 42 | diff --git a/src/udev/scsi_id/scsi_id.c b/src/udev/scsi_id/scsi_id.c | ||
| 43 | index 6308c52b7e..7e18bc755a 100644 | ||
| 44 | --- a/src/udev/scsi_id/scsi_id.c | ||
| 45 | +++ b/src/udev/scsi_id/scsi_id.c | ||
| 46 | @@ -27,6 +27,7 @@ | ||
| 47 | #include "strv.h" | ||
| 48 | #include "strxcpyx.h" | ||
| 49 | #include "udev-util.h" | ||
| 50 | +#include "utf8.h" | ||
| 51 | |||
| 52 | static const struct option options[] = { | ||
| 53 | { "device", required_argument, NULL, 'd' }, | ||
| 54 | @@ -443,8 +444,8 @@ static int scsi_id(char *maj_min_dev) { | ||
| 55 | } | ||
| 56 | if (dev_scsi.tgpt_group[0] != '\0') | ||
| 57 | printf("ID_TARGET_PORT=%s\n", dev_scsi.tgpt_group); | ||
| 58 | - if (dev_scsi.unit_serial_number[0] != '\0') | ||
| 59 | - printf("ID_SCSI_SERIAL=%s\n", dev_scsi.unit_serial_number); | ||
| 60 | + if (dev_scsi.unit_serial_number[0] != '\0' && utf8_is_valid(dev_scsi.unit_serial_number) && !string_has_cc(dev_scsi.unit_serial_number, /* ok= */ NULL)) | ||
| 61 | + printf("ID_SCSI_SERIAL=%s\n", serial_str); | ||
| 62 | goto out; | ||
| 63 | } | ||
| 64 | |||
| 65 | diff --git a/src/udev/udev-builtin-net_id.c b/src/udev/udev-builtin-net_id.c | ||
| 66 | index 91b40088f4..715184e282 100644 | ||
| 67 | --- a/src/udev/udev-builtin-net_id.c | ||
| 68 | +++ b/src/udev/udev-builtin-net_id.c | ||
| 69 | @@ -39,6 +39,7 @@ | ||
| 70 | #include "strv.h" | ||
| 71 | #include "strxcpyx.h" | ||
| 72 | #include "udev-builtin.h" | ||
| 73 | +#include "utf8.h" | ||
| 74 | |||
| 75 | #define ONBOARD_14BIT_INDEX_MAX ((1U << 14) - 1) | ||
| 76 | #define ONBOARD_16BIT_INDEX_MAX ((1U << 16) - 1) | ||
| 77 | @@ -247,6 +248,9 @@ static int get_port_specifier(sd_device *dev, bool fallback_to_dev_id, char **re | ||
| 78 | } | ||
| 79 | } | ||
| 80 | |||
| 81 | + if (!utf8_is_valid(phys_port_name) || string_has_cc(phys_port_name, /* ok= */ NULL)) | ||
| 82 | + return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid phys_port_name"); | ||
| 83 | + | ||
| 84 | /* Otherwise, use phys_port_name as is. */ | ||
| 85 | buf = strjoin("n", phys_port_name); | ||
| 86 | if (!buf) | ||
| 87 | @@ -351,6 +355,9 @@ static int names_pci_onboard_label(sd_device *dev, sd_device *pci_dev, const cha | ||
| 88 | if (r < 0) | ||
| 89 | return log_device_debug_errno(pci_dev, r, "Failed to get PCI onboard label: %m"); | ||
| 90 | |||
| 91 | + if (!utf8_is_valid(label) || string_has_cc(label, /* ok= */ NULL)) | ||
| 92 | + return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid label"); | ||
| 93 | + | ||
| 94 | char str[ALTIFNAMSIZ]; | ||
| 95 | if (snprintf_ok(str, sizeof str, "%s%s", | ||
| 96 | naming_scheme_has(NAMING_LABEL_NOPREFIX) ? "" : prefix, | ||
| 97 | @@ -1209,6 +1216,8 @@ static int names_netdevsim(sd_device *dev, const char *prefix, bool test) { | ||
| 98 | if (isempty(phys_port_name)) | ||
| 99 | return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EOPNOTSUPP), | ||
| 100 | "The 'phys_port_name' attribute is empty."); | ||
| 101 | + if (!utf8_is_valid(phys_port_name) || string_has_cc(phys_port_name, /* ok= */ NULL)) | ||
| 102 | + return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid phys_port_name"); | ||
| 103 | |||
| 104 | char str[ALTIFNAMSIZ]; | ||
| 105 | if (snprintf_ok(str, sizeof str, "%si%un%s", prefix, addr, phys_port_name)) | ||
| 106 | diff --git a/src/udev/v4l_id/v4l_id.c b/src/udev/v4l_id/v4l_id.c | ||
| 107 | index 30527e9556..2ec96d8d3a 100644 | ||
| 108 | --- a/src/udev/v4l_id/v4l_id.c | ||
| 109 | +++ b/src/udev/v4l_id/v4l_id.c | ||
| 110 | @@ -29,6 +29,8 @@ | ||
| 111 | #include "build.h" | ||
| 112 | #include "fd-util.h" | ||
| 113 | #include "main-func.h" | ||
| 114 | +#include "string-util.h" | ||
| 115 | +#include "utf8.h" | ||
| 116 | |||
| 117 | static const char *arg_device = NULL; | ||
| 118 | |||
| 119 | @@ -82,7 +84,8 @@ static int run(int argc, char *argv[]) { | ||
| 120 | int capabilities; | ||
| 121 | |||
| 122 | printf("ID_V4L_VERSION=2\n"); | ||
| 123 | - printf("ID_V4L_PRODUCT=%s\n", v2cap.card); | ||
| 124 | + if (utf8_is_valid((char *)v2cap.card) && !string_has_cc((char *)v2cap.card, /* ok= */ NULL)) | ||
| 125 | + printf("ID_V4L_PRODUCT=%s\n", v2cap.card); | ||
| 126 | printf("ID_V4L_CAPABILITIES=:"); | ||
| 127 | |||
| 128 | if (v2cap.capabilities & V4L2_CAP_DEVICE_CAPS) | ||
| 129 | -- | ||
| 130 | 2.50.1 | ||
| 131 | |||
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch b/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch new file mode 100644 index 0000000000..bc0a5514d4 --- /dev/null +++ b/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch | |||
| @@ -0,0 +1,39 @@ | |||
| 1 | From 5887e72ff87d3a66a4c3fa91897fbec1545f4d3d Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Luca Boccassi <luca.boccassi@gmail.com> | ||
| 3 | Date: Fri, 13 Mar 2026 11:10:47 +0000 | ||
| 4 | Subject: [PATCH] udev: fix review mixup | ||
| 5 | |||
| 6 | The previous version in the PR changed variable and sanitized it | ||
| 7 | in place. The second version switched to skip if CCs are in the | ||
| 8 | string instead, but didn't move back to the original variable. | ||
| 9 | Because it's an existing variable, no CI caught it. | ||
| 10 | |||
| 11 | Follow-up for 16325b35fa6ecb25f66534a562583ce3b96d52f3 | ||
| 12 | |||
| 13 | (cherry picked from commit 54f880b02ecf7362e630ffc885d1466df6ee6820) | ||
| 14 | (cherry picked from commit 4425d8523e79f3cc00b3b93a0b5e7c6cdc284a97) | ||
| 15 | (cherry picked from commit 75c585beae60e73208941e6b3f64cf249223f53d) | ||
| 16 | |||
| 17 | CVE: CVE-2026-40225 | ||
| 18 | Upstream-Status: Backport [https://github.com/systemd/systemd/commit/5887e72ff87d3a66a4c3fa91897fbec1545f4d3d] | ||
| 19 | Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> | ||
| 20 | --- | ||
| 21 | src/udev/scsi_id/scsi_id.c | 2 +- | ||
| 22 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
| 23 | |||
| 24 | diff --git a/src/udev/scsi_id/scsi_id.c b/src/udev/scsi_id/scsi_id.c | ||
| 25 | index 7e18bc755a..b2df8d9f7f 100644 | ||
| 26 | --- a/src/udev/scsi_id/scsi_id.c | ||
| 27 | +++ b/src/udev/scsi_id/scsi_id.c | ||
| 28 | @@ -445,7 +445,7 @@ static int scsi_id(char *maj_min_dev) { | ||
| 29 | if (dev_scsi.tgpt_group[0] != '\0') | ||
| 30 | printf("ID_TARGET_PORT=%s\n", dev_scsi.tgpt_group); | ||
| 31 | if (dev_scsi.unit_serial_number[0] != '\0' && utf8_is_valid(dev_scsi.unit_serial_number) && !string_has_cc(dev_scsi.unit_serial_number, /* ok= */ NULL)) | ||
| 32 | - printf("ID_SCSI_SERIAL=%s\n", serial_str); | ||
| 33 | + printf("ID_SCSI_SERIAL=%s\n", dev_scsi.unit_serial_number); | ||
| 34 | goto out; | ||
| 35 | } | ||
| 36 | |||
| 37 | -- | ||
| 38 | 2.50.1 | ||
| 39 | |||
diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.21.bb index 87e186bbfa..fe9d699816 100644 --- a/meta/recipes-core/systemd/systemd_255.21.bb +++ b/meta/recipes-core/systemd/systemd_255.21.bb | |||
| @@ -29,6 +29,8 @@ SRC_URI += " \ | |||
| 29 | file://0002-binfmt-Don-t-install-dependency-links-at-install-tim.patch \ | 29 | file://0002-binfmt-Don-t-install-dependency-links-at-install-tim.patch \ |
| 30 | file://0003-timedated-Respond-on-org.freedesktop.timedate1.SetNT.patch \ | 30 | file://0003-timedated-Respond-on-org.freedesktop.timedate1.SetNT.patch \ |
| 31 | file://0008-implment-systemd-sysv-install-for-OE.patch \ | 31 | file://0008-implment-systemd-sysv-install-for-OE.patch \ |
| 32 | file://CVE-2026-40225-01.patch \ | ||
| 33 | file://CVE-2026-40225-02.patch \ | ||
| 32 | " | 34 | " |
| 33 | 35 | ||
| 34 | # patches needed by musl | 36 | # patches needed by musl |
