diff --git a/package/swupdate/0002-CVE-2026-28525.patch b/package/swupdate/0002-CVE-2026-28525.patch new file mode 100644 index 0000000000..75f99a698f --- /dev/null +++ b/package/swupdate/0002-CVE-2026-28525.patch @@ -0,0 +1,51 @@ +From beee2dc0feef1cfe84f1aa6fc980e104b2e47a74 Mon Sep 17 00:00:00 2001 +From: Stefano Babic +Date: Thu, 19 Mar 2026 10:50:13 +0100 +Subject: [PATCH] mongoose: Integer Underflow in Multipart Upload Parser + +The function mg_http_multipart_continue_wait_for_chunk() has +a discrepancy between its guard condition and a subsequent +subtraction in the else branch. The guard at line 250 checks +`(int) io->len < mp_stream->boundary.len + 6`, allowing execution +to continue when io->len >= boundary.len + 6. +However, when mg_strstr() finds the boundary string in the +buffer (else branch at line 264), data_len is computed as +`io->len - (mp_stream->boundary.len + 8)`. The +6 vs +8 +mismatch means that when io->len is in the range [boundary.len + 6, +boundary.len + 7], the subtraction underflows the size_t +variable to SIZE_MAX or SIZE_MAX - 1. + +This will fix CVE-2026-28525. + +Description of issue copied from vulnerability report - many thanks to +Kazuma for his analyses. + +Signed-off-by: Stefano Babic +Reported by: Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc." +Upstream: https://github.com/sbabic/swupdate/commit/beee2dc0feef1cfe84f1aa6fc980e104b2e47a74 +CVE: CVE-2026-28525 +Signed-off-by: Thomas Perale +--- + mongoose/mongoose_multipart.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/mongoose/mongoose_multipart.c b/mongoose/mongoose_multipart.c +index 12ea54348..7fdc18632 100644 +--- a/mongoose/mongoose_multipart.c ++++ b/mongoose/mongoose_multipart.c +@@ -260,12 +260,12 @@ static int mg_http_multipart_continue_wait_for_chunk(struct mg_connection *c) { + } + return 0; + } else { +- size_t data_len = io->len - (mp_stream->boundary.len + 8); ++ size_t data_len = io->len - (mp_stream->boundary.len + 6); + size_t consumed = mg_http_multipart_call_handler(c, MG_EV_HTTP_PART_DATA, +- (char *) io->buf, data_len); ++ (char *) io->buf, data_len); + mg_iobuf_del(io, 0, consumed); + if (consumed == data_len) { +- mg_iobuf_del(io, 0, mp_stream->boundary.len + 8); ++ mg_iobuf_del(io, 0, mp_stream->boundary.len + 6); + mp_stream->state = MPS_FINALIZE; + return 1; + } else { diff --git a/package/swupdate/swupdate.mk b/package/swupdate/swupdate.mk index 647a6f071b..ecf7864225 100644 --- a/package/swupdate/swupdate.mk +++ b/package/swupdate/swupdate.mk @@ -20,6 +20,9 @@ SWUPDATE_LICENSE_FILES = LICENSES/BSD-1-Clause.txt \ SWUPDATE_INSTALL_STAGING = YES SWUPDATE_DEPENDENCIES = json-c libubootenv +# 0002-CVE-2026-28525.patch +SWUPDATE_IGNORE_CVES += CVE-2026-28525 + # swupdate uses $CROSS-cc instead of $CROSS-gcc, which is not # available in all external toolchains, and use CC for linking. Ensure # TARGET_CC is used for both.