Backport patch to fix CVE-2026-56392.

Reference:
  https://nvd.nist.gov/vuln/detail/CVE-2026-56392

Upstream fix:
  
https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

Signed-off-by: Leonid Iziumtsev <[email protected]>
---
 .../coreutils/coreutils/CVE-2026-56392.patch  | 65 +++++++++++++++++++
 meta/recipes-core/coreutils/coreutils_9.11.bb |  1 +
 2 files changed, 66 insertions(+)
 create mode 100644 meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch

diff --git a/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch 
b/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch
new file mode 100644
index 0000000000..8468b4d288
--- /dev/null
+++ b/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch
@@ -0,0 +1,65 @@
+From aa3f6d91fdddcc45c5bb656168f7d20808991fe0 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?P=C3=A1draig=20Brady?= <[email protected]>
+Date: Tue, 28 Apr 2026 20:33:10 +0100
+Subject: [PATCH] unexpand: fix heap overflow
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+* src/unexpand.c (unexpand): Use xinmalloc() to gracefully
+handle overflow.  Also use the runtime locale specific MB_CUR_MAX
+rather than the worst case MB_LEN_MAX.
+* tests/unexpand/mb.sh: Add a test case that fails in a default
+glibc build with either MB_CUR_MAX or MB_LEN_MAX.
+* NEWS: Mention the bug fix.
+Reported by MichaƂ Majchrowicz.
+
+CVE: CVE-2026-56392
+Upstream-Status: Backport 
[https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d]
+
+Backport Changes:
+- The NEWS file has not been updated.
+
+Signed-off-by: Leonid Iziumtsev <[email protected]>
+---
+ src/unexpand.c       | 2 +-
+ tests/unexpand/mb.sh | 8 ++++++++
+ 2 files changed, 9 insertions(+), 1 deletion(-)
+
+diff --git a/src/unexpand.c b/src/unexpand.c
+index 4fbf9d3..761c8ea 100644
+--- a/src/unexpand.c
++++ b/src/unexpand.c
+@@ -131,7 +131,7 @@ unexpand (void)
+   /* The worst case is a non-blank character, then one blank, then a
+      tab stop, then MAX_COLUMN_WIDTH - 1 blanks, then a non-blank; so
+      allocate MAX_COLUMN_WIDTH bytes to store the blanks.  */
+-  pending_blank = ximalloc (max_column_width * sizeof (char) * MB_LEN_MAX);
++  pending_blank = xinmalloc (max_column_width, MB_CUR_MAX);
+ 
+   while (true)
+     {
+diff --git a/tests/unexpand/mb.sh b/tests/unexpand/mb.sh
+index 76a2679..076a1c1 100755
+--- a/tests/unexpand/mb.sh
++++ b/tests/unexpand/mb.sh
+@@ -17,6 +17,7 @@
+ 
+ . "${srcdir=.}/tests/init.sh"; path_prepend_ ./src
+ print_ver_ unexpand printf
++getlimits_
+ 
+ test "$LOCALE_FR_UTF8" != none || skip_ "French UTF-8 locale not available"
+ export LC_ALL="$LOCALE_FR_UTF8"
+@@ -161,4 +162,11 @@ EOF
+ unexpand -a ./in ./in > out || fail=1
+ compare exp out > /dev/null 2>&1 || fail=1
+ 
++# Ensure overflow is handed gracefully
++# coreutils v9.11 induced a buffer overflow with mb_mul=4 (or 16).
++for mb_mul in 4 6; do
++  printf '   \n' | unexpand -t $(expr $SIZE_MAX / $mb_mul + 1) 2>err; ret=$?
++  test "$ret" = 1 || test "$ret" = 0 || { cat err; fail=1; }
++done
++
+ Exit $fail
diff --git a/meta/recipes-core/coreutils/coreutils_9.11.bb 
b/meta/recipes-core/coreutils/coreutils_9.11.bb
index 3e4f5fc7dc..63f7810e88 100644
--- a/meta/recipes-core/coreutils/coreutils_9.11.bb
+++ b/meta/recipes-core/coreutils/coreutils_9.11.bb
@@ -17,6 +17,7 @@ SRC_URI = "${GNU_MIRROR}/coreutils/${BP}.tar.xz \
            file://remove-usr-local-lib-from-m4.patch \
            file://run-ptest \
            file://CVE-2026-56391.patch \
+           file://CVE-2026-56392.patch \
            "
 SRC_URI[sha256sum] = 
"394024eda0a5955217ceda9cd1201e65dc8fa3aa29c2951135a49521d57c3cc3"
 
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242433): 
https://lists.openembedded.org/g/openembedded-core/message/242433
Mute This Topic: https://lists.openembedded.org/mt/120532932/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to