Backport patch to fix CVE-2026-56392. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-56392
Upstream fix: https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d Signed-off-by: Leonid Iziumtsev <[email protected]> --- .../coreutils/coreutils/CVE-2026-56392.patch | 65 +++++++++++++++++++ meta/recipes-core/coreutils/coreutils_9.11.bb | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch diff --git a/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch b/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch new file mode 100644 index 0000000000..8468b4d288 --- /dev/null +++ b/meta/recipes-core/coreutils/coreutils/CVE-2026-56392.patch @@ -0,0 +1,65 @@ +From aa3f6d91fdddcc45c5bb656168f7d20808991fe0 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?P=C3=A1draig=20Brady?= <[email protected]> +Date: Tue, 28 Apr 2026 20:33:10 +0100 +Subject: [PATCH] unexpand: fix heap overflow +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +* src/unexpand.c (unexpand): Use xinmalloc() to gracefully +handle overflow. Also use the runtime locale specific MB_CUR_MAX +rather than the worst case MB_LEN_MAX. +* tests/unexpand/mb.sh: Add a test case that fails in a default +glibc build with either MB_CUR_MAX or MB_LEN_MAX. +* NEWS: Mention the bug fix. +Reported by MichaĆ Majchrowicz. + +CVE: CVE-2026-56392 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d] + +Backport Changes: +- The NEWS file has not been updated. + +Signed-off-by: Leonid Iziumtsev <[email protected]> +--- + src/unexpand.c | 2 +- + tests/unexpand/mb.sh | 8 ++++++++ + 2 files changed, 9 insertions(+), 1 deletion(-) + +diff --git a/src/unexpand.c b/src/unexpand.c +index 4fbf9d3..761c8ea 100644 +--- a/src/unexpand.c ++++ b/src/unexpand.c +@@ -131,7 +131,7 @@ unexpand (void) + /* The worst case is a non-blank character, then one blank, then a + tab stop, then MAX_COLUMN_WIDTH - 1 blanks, then a non-blank; so + allocate MAX_COLUMN_WIDTH bytes to store the blanks. */ +- pending_blank = ximalloc (max_column_width * sizeof (char) * MB_LEN_MAX); ++ pending_blank = xinmalloc (max_column_width, MB_CUR_MAX); + + while (true) + { +diff --git a/tests/unexpand/mb.sh b/tests/unexpand/mb.sh +index 76a2679..076a1c1 100755 +--- a/tests/unexpand/mb.sh ++++ b/tests/unexpand/mb.sh +@@ -17,6 +17,7 @@ + + . "${srcdir=.}/tests/init.sh"; path_prepend_ ./src + print_ver_ unexpand printf ++getlimits_ + + test "$LOCALE_FR_UTF8" != none || skip_ "French UTF-8 locale not available" + export LC_ALL="$LOCALE_FR_UTF8" +@@ -161,4 +162,11 @@ EOF + unexpand -a ./in ./in > out || fail=1 + compare exp out > /dev/null 2>&1 || fail=1 + ++# Ensure overflow is handed gracefully ++# coreutils v9.11 induced a buffer overflow with mb_mul=4 (or 16). ++for mb_mul in 4 6; do ++ printf ' \n' | unexpand -t $(expr $SIZE_MAX / $mb_mul + 1) 2>err; ret=$? ++ test "$ret" = 1 || test "$ret" = 0 || { cat err; fail=1; } ++done ++ + Exit $fail diff --git a/meta/recipes-core/coreutils/coreutils_9.11.bb b/meta/recipes-core/coreutils/coreutils_9.11.bb index 3e4f5fc7dc..63f7810e88 100644 --- a/meta/recipes-core/coreutils/coreutils_9.11.bb +++ b/meta/recipes-core/coreutils/coreutils_9.11.bb @@ -17,6 +17,7 @@ SRC_URI = "${GNU_MIRROR}/coreutils/${BP}.tar.xz \ file://remove-usr-local-lib-from-m4.patch \ file://run-ptest \ file://CVE-2026-56391.patch \ + file://CVE-2026-56392.patch \ " SRC_URI[sha256sum] = "394024eda0a5955217ceda9cd1201e65dc8fa3aa29c2951135a49521d57c3cc3"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242433): https://lists.openembedded.org/g/openembedded-core/message/242433 Mute This Topic: https://lists.openembedded.org/mt/120532932/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
