From: Jaipaul Cheernam Date: Wed, 8 Jul 2026 18:53:32 +0000 (+0200) Subject: gzip: fix CVE-2026-41992 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=deaaaacabbf8d21fb9271e3f6f83055893510cff;p=thirdparty%2Fopenembedded%2Fopenembedded-core-contrib.git gzip: fix CVE-2026-41992 Backport upstream fix for a global buffer overflow in the LZH decompression logic (unlzh.c). The left[] and right[] global arrays shared across LZW and LZH decompression routines are not reinitialized between files processed in the same invocation, allowing an out-of-bounds read in the LZH decoder. Adapted for gzip 1.14: - Refreshed NEWS and THANKS hunks to match 1.14 release context. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41992 Signed-off-by: Jaipaul Cheernam Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie --- diff --git a/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch b/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch new file mode 100644 index 00000000000..f55c89978d6 --- /dev/null +++ b/meta/recipes-extended/gzip/gzip-1.14/CVE-2026-41992.patch @@ -0,0 +1,64 @@ +From 63dbf6b3b9e6e781df1a6a64e609b10e23969681 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Wed, 15 Apr 2026 12:00:17 -0700 +Subject: =?UTF-8?q?gzip:=20don=E2=80=99t=20mishandle=20.lzh=20after=20.Z?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* unlzh.c (read_c_len): Clear left and right when n == 0. + +CVE: CVE-2026-41992 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681] +Signed-off-by: Jaipaul Cheernam +--- + NEWS | 4 ++++ + THANKS | 1 + + unlzh.c | 6 ++++++ + 3 files changed, 11 insertions(+) + +diff --git a/NEWS b/NEWS +index 6388227..8fb8918 100644 +--- a/NEWS ++++ b/NEWS +@@ -4,6 +4,10 @@ GNU gzip NEWS -*- outline -*- + + ** Bug fixes + ++ A buffer overflow has been fixed when decompressing an .lzh file ++ after decompressing a .Z file. ++ [bug present since the beginning] ++ + 'gzip -d' no longer omits the last partial output buffer when the + input ends unexpectedly on an IBM Z platform. + [bug introduced in gzip-1.11] +diff --git a/THANKS b/THANKS +index 4e545d9..a7d25e4 100644 +--- a/THANKS ++++ b/THANKS +@@ -186,6 +186,7 @@ Jamie Lokier u90jl@ecs.oxford.ac.uk + Richard Lloyd R.K.Lloyd@csc.liv.ac.uk + David J. MacKenzie djm@eng.umd.edu + John R MacMillan john@chance.gts.org ++Michał Majchrowicz mmajchrowicz@afine.com + Ron Male male@eso.mc.xerox.com + Jakub Martisko jamartis@redhat.com + Don R. Maszle maze@bea.lbl.gov +diff --git a/unlzh.c b/unlzh.c +index 3320196..a6cf109 100644 +--- a/unlzh.c ++++ b/unlzh.c +@@ -232,6 +232,12 @@ read_c_len () + c = getbits(CBIT); + for (i = 0; i < NC; i++) c_len[i] = 0; + for (i = 0; i < 4096; i++) c_table[i] = c; ++ ++ /* Needed in case LEFT and RIGHT are reused from a previous ++ LZW decompression. It may be overkill to clear all of both ++ arrays, but nobody has had time to analyze this carefully. */ ++ memzero(left, (2 * NC - 1) * sizeof *left); ++ memzero(right, (2 * NC - 1) * sizeof *left); + } else { + i = 0; + while (i < n) { diff --git a/meta/recipes-extended/gzip/gzip_1.14.bb b/meta/recipes-extended/gzip/gzip_1.14.bb index c7837cdae01..99174a58c53 100644 --- a/meta/recipes-extended/gzip/gzip_1.14.bb +++ b/meta/recipes-extended/gzip/gzip_1.14.bb @@ -6,6 +6,7 @@ LICENSE = "GPL-3.0-or-later" SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \ file://run-ptest \ + file://CVE-2026-41992.patch \ " SRC_URI:append:class-target = " file://wrong-path-fix.patch"