summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorHitendra Prajapati <hprajapati@mvista.com>2026-04-28 17:55:28 +0530
committerPaul Barker <paul@pbarker.dev>2026-05-12 21:31:34 +0100
commitf0366984060c79d4d72f3733f072a4558e240333 (patch)
treee0a09931470d866f6ac647f077089011512fc13c /meta
parente9575f38d797516853b75bfe8b9fdec56a435a62 (diff)
downloadpoky-f0366984060c79d4d72f3733f072a4558e240333.tar.gz
systemd: fix for CVE-2026-40225
Backport commit[0] and [1] which fixes this vulnerability as mentioned in Debian report [2]. [0] https://github.com/systemd/systemd/commit/03bb697b8df0339c37f4b845025320b261aeb7cc [1] https://github.com/systemd/systemd/commit/5887e72ff87d3a66a4c3fa91897fbec1545f4d3d [2] https://security-tracker.debian.org/tracker/CVE-2026-40225 More details : https://nvd.nist.gov/vuln/detail/CVE-2026-40225 (From OE-Core rev: fc2d33dbb2d5180b77c10865156db342f9d582da) Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch131
-rw-r--r--meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch39
-rw-r--r--meta/recipes-core/systemd/systemd_255.21.bb2
3 files changed, 172 insertions, 0 deletions
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch b/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch
new file mode 100644
index 0000000000..f616e636c2
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-40225-01.patch
@@ -0,0 +1,131 @@
1From 03bb697b8df0339c37f4b845025320b261aeb7cc Mon Sep 17 00:00:00 2001
2From: Luca Boccassi <luca.boccassi@gmail.com>
3Date: Fri, 6 Mar 2026 19:32:35 +0000
4Subject: [PATCH] udev: check for invalid chars in various fields received from
5 the kernel
6
7(cherry picked from commit 16325b35fa6ecb25f66534a562583ce3b96d52f3)
8(cherry picked from commit 3513862eabe9ec4a6a095d7266e98f998f289ed2)
9(cherry picked from commit c20d21e0da293e715db468f9f4a15a5c8fbf8273)
10
11CVE: CVE-2026-40225
12Upstream-Status: Backport [https://github.com/systemd/systemd/commit/03bb697b8df0339c37f4b845025320b261aeb7cc]
13Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
14---
15 src/udev/dmi_memory_id/dmi_memory_id.c | 3 ++-
16 src/udev/scsi_id/scsi_id.c | 5 +++--
17 src/udev/udev-builtin-net_id.c | 9 +++++++++
18 src/udev/v4l_id/v4l_id.c | 5 ++++-
19 4 files changed, 18 insertions(+), 4 deletions(-)
20
21diff --git a/src/udev/dmi_memory_id/dmi_memory_id.c b/src/udev/dmi_memory_id/dmi_memory_id.c
22index 52ea250af8..4f2c21b80b 100644
23--- a/src/udev/dmi_memory_id/dmi_memory_id.c
24+++ b/src/udev/dmi_memory_id/dmi_memory_id.c
25@@ -51,6 +51,7 @@
26 #include "string-util.h"
27 #include "udev-util.h"
28 #include "unaligned.h"
29+#include "utf8.h"
30
31 #define SUPPORTED_SMBIOS_VER 0x030300
32
33@@ -185,7 +186,7 @@ static void dmi_memory_device_string(
34
35 str = strdupa_safe(dmi_string(h, s));
36 str = strstrip(str);
37- if (!isempty(str))
38+ if (!isempty(str) && utf8_is_valid(str) && !string_has_cc(str, /* ok= */ NULL))
39 printf("MEMORY_DEVICE_%u_%s=%s\n", slot_num, attr_suffix, str);
40 }
41
42diff --git a/src/udev/scsi_id/scsi_id.c b/src/udev/scsi_id/scsi_id.c
43index 6308c52b7e..7e18bc755a 100644
44--- a/src/udev/scsi_id/scsi_id.c
45+++ b/src/udev/scsi_id/scsi_id.c
46@@ -27,6 +27,7 @@
47 #include "strv.h"
48 #include "strxcpyx.h"
49 #include "udev-util.h"
50+#include "utf8.h"
51
52 static const struct option options[] = {
53 { "device", required_argument, NULL, 'd' },
54@@ -443,8 +444,8 @@ static int scsi_id(char *maj_min_dev) {
55 }
56 if (dev_scsi.tgpt_group[0] != '\0')
57 printf("ID_TARGET_PORT=%s\n", dev_scsi.tgpt_group);
58- if (dev_scsi.unit_serial_number[0] != '\0')
59- printf("ID_SCSI_SERIAL=%s\n", dev_scsi.unit_serial_number);
60+ if (dev_scsi.unit_serial_number[0] != '\0' && utf8_is_valid(dev_scsi.unit_serial_number) && !string_has_cc(dev_scsi.unit_serial_number, /* ok= */ NULL))
61+ printf("ID_SCSI_SERIAL=%s\n", serial_str);
62 goto out;
63 }
64
65diff --git a/src/udev/udev-builtin-net_id.c b/src/udev/udev-builtin-net_id.c
66index 91b40088f4..715184e282 100644
67--- a/src/udev/udev-builtin-net_id.c
68+++ b/src/udev/udev-builtin-net_id.c
69@@ -39,6 +39,7 @@
70 #include "strv.h"
71 #include "strxcpyx.h"
72 #include "udev-builtin.h"
73+#include "utf8.h"
74
75 #define ONBOARD_14BIT_INDEX_MAX ((1U << 14) - 1)
76 #define ONBOARD_16BIT_INDEX_MAX ((1U << 16) - 1)
77@@ -247,6 +248,9 @@ static int get_port_specifier(sd_device *dev, bool fallback_to_dev_id, char **re
78 }
79 }
80
81+ if (!utf8_is_valid(phys_port_name) || string_has_cc(phys_port_name, /* ok= */ NULL))
82+ return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid phys_port_name");
83+
84 /* Otherwise, use phys_port_name as is. */
85 buf = strjoin("n", phys_port_name);
86 if (!buf)
87@@ -351,6 +355,9 @@ static int names_pci_onboard_label(sd_device *dev, sd_device *pci_dev, const cha
88 if (r < 0)
89 return log_device_debug_errno(pci_dev, r, "Failed to get PCI onboard label: %m");
90
91+ if (!utf8_is_valid(label) || string_has_cc(label, /* ok= */ NULL))
92+ return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid label");
93+
94 char str[ALTIFNAMSIZ];
95 if (snprintf_ok(str, sizeof str, "%s%s",
96 naming_scheme_has(NAMING_LABEL_NOPREFIX) ? "" : prefix,
97@@ -1209,6 +1216,8 @@ static int names_netdevsim(sd_device *dev, const char *prefix, bool test) {
98 if (isempty(phys_port_name))
99 return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EOPNOTSUPP),
100 "The 'phys_port_name' attribute is empty.");
101+ if (!utf8_is_valid(phys_port_name) || string_has_cc(phys_port_name, /* ok= */ NULL))
102+ return log_device_debug_errno(dev, SYNTHETIC_ERRNO(EINVAL), "Invalid phys_port_name");
103
104 char str[ALTIFNAMSIZ];
105 if (snprintf_ok(str, sizeof str, "%si%un%s", prefix, addr, phys_port_name))
106diff --git a/src/udev/v4l_id/v4l_id.c b/src/udev/v4l_id/v4l_id.c
107index 30527e9556..2ec96d8d3a 100644
108--- a/src/udev/v4l_id/v4l_id.c
109+++ b/src/udev/v4l_id/v4l_id.c
110@@ -29,6 +29,8 @@
111 #include "build.h"
112 #include "fd-util.h"
113 #include "main-func.h"
114+#include "string-util.h"
115+#include "utf8.h"
116
117 static const char *arg_device = NULL;
118
119@@ -82,7 +84,8 @@ static int run(int argc, char *argv[]) {
120 int capabilities;
121
122 printf("ID_V4L_VERSION=2\n");
123- printf("ID_V4L_PRODUCT=%s\n", v2cap.card);
124+ if (utf8_is_valid((char *)v2cap.card) && !string_has_cc((char *)v2cap.card, /* ok= */ NULL))
125+ printf("ID_V4L_PRODUCT=%s\n", v2cap.card);
126 printf("ID_V4L_CAPABILITIES=:");
127
128 if (v2cap.capabilities & V4L2_CAP_DEVICE_CAPS)
129--
1302.50.1
131
diff --git a/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch b/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch
new file mode 100644
index 0000000000..bc0a5514d4
--- /dev/null
+++ b/meta/recipes-core/systemd/systemd/CVE-2026-40225-02.patch
@@ -0,0 +1,39 @@
1From 5887e72ff87d3a66a4c3fa91897fbec1545f4d3d Mon Sep 17 00:00:00 2001
2From: Luca Boccassi <luca.boccassi@gmail.com>
3Date: Fri, 13 Mar 2026 11:10:47 +0000
4Subject: [PATCH] udev: fix review mixup
5
6The previous version in the PR changed variable and sanitized it
7in place. The second version switched to skip if CCs are in the
8string instead, but didn't move back to the original variable.
9Because it's an existing variable, no CI caught it.
10
11Follow-up for 16325b35fa6ecb25f66534a562583ce3b96d52f3
12
13(cherry picked from commit 54f880b02ecf7362e630ffc885d1466df6ee6820)
14(cherry picked from commit 4425d8523e79f3cc00b3b93a0b5e7c6cdc284a97)
15(cherry picked from commit 75c585beae60e73208941e6b3f64cf249223f53d)
16
17CVE: CVE-2026-40225
18Upstream-Status: Backport [https://github.com/systemd/systemd/commit/5887e72ff87d3a66a4c3fa91897fbec1545f4d3d]
19Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
20---
21 src/udev/scsi_id/scsi_id.c | 2 +-
22 1 file changed, 1 insertion(+), 1 deletion(-)
23
24diff --git a/src/udev/scsi_id/scsi_id.c b/src/udev/scsi_id/scsi_id.c
25index 7e18bc755a..b2df8d9f7f 100644
26--- a/src/udev/scsi_id/scsi_id.c
27+++ b/src/udev/scsi_id/scsi_id.c
28@@ -445,7 +445,7 @@ static int scsi_id(char *maj_min_dev) {
29 if (dev_scsi.tgpt_group[0] != '\0')
30 printf("ID_TARGET_PORT=%s\n", dev_scsi.tgpt_group);
31 if (dev_scsi.unit_serial_number[0] != '\0' && utf8_is_valid(dev_scsi.unit_serial_number) && !string_has_cc(dev_scsi.unit_serial_number, /* ok= */ NULL))
32- printf("ID_SCSI_SERIAL=%s\n", serial_str);
33+ printf("ID_SCSI_SERIAL=%s\n", dev_scsi.unit_serial_number);
34 goto out;
35 }
36
37--
382.50.1
39
diff --git a/meta/recipes-core/systemd/systemd_255.21.bb b/meta/recipes-core/systemd/systemd_255.21.bb
index 87e186bbfa..fe9d699816 100644
--- a/meta/recipes-core/systemd/systemd_255.21.bb
+++ b/meta/recipes-core/systemd/systemd_255.21.bb
@@ -29,6 +29,8 @@ SRC_URI += " \
29 file://0002-binfmt-Don-t-install-dependency-links-at-install-tim.patch \ 29 file://0002-binfmt-Don-t-install-dependency-links-at-install-tim.patch \
30 file://0003-timedated-Respond-on-org.freedesktop.timedate1.SetNT.patch \ 30 file://0003-timedated-Respond-on-org.freedesktop.timedate1.SetNT.patch \
31 file://0008-implment-systemd-sysv-install-for-OE.patch \ 31 file://0008-implment-systemd-sysv-install-for-OE.patch \
32 file://CVE-2026-40225-01.patch \
33 file://CVE-2026-40225-02.patch \
32 " 34 "
33 35
34# patches needed by musl 36# patches needed by musl