From cf345ac7253d088f13aeaa2377cf31af8d3d1b95 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stefan=20M=C3=BCller?= Date: Thu, 20 Aug 2026 09:29:40 +0000 Subject: [PATCH] package/wget: fix CVE-2026-58469 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Backport the upstream fix for a buffer underflow in clean_metalink_string(), together with the two required follow-up fixes for the inverted whitespace check and missing ctype.h include. Backport to: 2025.02.x Signed-off-by: Stefan Müller Signed-off-by: Julien Olivain (cherry picked from commit 937e33237ef739350bcba6fe0e18382ef7305afd) Signed-off-by: Titouan Christophe --- ...metalink_string-Fix-buffer-underflow.patch | 54 +++++++++++++++++++ ...ng-Fix-inverted-trailing-space-check.patch | 40 ++++++++++++++ .../0004-src-metalink.c-Include-ctype.h.patch | 28 ++++++++++ package/wget/wget.mk | 5 ++ 4 files changed, 127 insertions(+) create mode 100644 package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch create mode 100644 package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch create mode 100644 package/wget/0004-src-metalink.c-Include-ctype.h.patch diff --git a/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch b/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch new file mode 100644 index 0000000000..652f99786d --- /dev/null +++ b/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch @@ -0,0 +1,54 @@ +From 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 29 Jun 2026 18:32:02 +0200 +Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix buffer + underflow + +Reported-by: TristanInSec@gmail.com +CVE: CVE-2026-58469 +Upstream: https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 +Signed-off-by: Stefan Müller + +--- + src/metalink.c | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/src/metalink.c b/src/metalink.c +index 9e355fd0..3acdc3a2 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -1041,7 +1041,6 @@ void + clean_metalink_string (char **str) + { + int c; +- size_t len; + char *new, *beg, *end; + + if (!str || !*str) +@@ -1049,7 +1048,7 @@ clean_metalink_string (char **str) + + beg = *str; + +- while ((c = *beg) && (c == '\n' || c == '\r' || c == '\t' || c == ' ')) ++ while (isspace(*beg)) + beg++; + + end = beg; +@@ -1062,12 +1061,10 @@ clean_metalink_string (char **str) + /* If we are at the end of the string, search the first legit + character going backward. */ + if (*end == '\0') +- while ((c = *(end - 1)) && (c == '\n' || c == '\r' || c == '\t' || c == ' ')) ++ while (end > beg && !isspace(*(end - 1))) + end--; + +- len = end - beg; +- +- new = xmemdup0 (beg, len); ++ new = xmemdup0 (beg, end - beg); + xfree (*str); + *str = new; + } +-- +GitLab + diff --git a/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch b/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch new file mode 100644 index 0000000000..e6b6b7180a --- /dev/null +++ b/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch @@ -0,0 +1,40 @@ +From 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf Mon Sep 17 00:00:00 2001 +From: ChenYanpan +Date: Wed, 8 Jul 2026 12:09:55 +0800 +Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix inverted + trailing-space check + +37a40fcb added an `end > beg' bound guard to prevent a buffer +underflow, but accidentally flipped the condition from `isspace' to +`!isspace'. The loop therefore walked back over non-space characters +instead of trailing whitespace, collapsing any string without a +trailing newline to "". Every Metalink/HTTP resource URL was wiped, +so wget could not follow any mirror and +testenv/Test-metalink-http.py failed ("Expected file test.meta not +found"). Restore the `isspace' condition. + +Copyright-paperwork-exempt: Yes +CVE: CVE-2026-58469 +Upstream: https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf +Signed-off-by: Stefan Müller + +--- + src/metalink.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/metalink.c b/src/metalink.c +index 3acdc3a2..3794909f 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -1061,7 +1061,7 @@ clean_metalink_string (char **str) + /* If we are at the end of the string, search the first legit + character going backward. */ + if (*end == '\0') +- while (end > beg && !isspace(*(end - 1))) ++ while (end > beg && isspace(*(end - 1))) + end--; + + new = xmemdup0 (beg, end - beg); +-- +GitLab + diff --git a/package/wget/0004-src-metalink.c-Include-ctype.h.patch b/package/wget/0004-src-metalink.c-Include-ctype.h.patch new file mode 100644 index 0000000000..0782bf2563 --- /dev/null +++ b/package/wget/0004-src-metalink.c-Include-ctype.h.patch @@ -0,0 +1,28 @@ +From 82d945ff5dc9942b78b2bf736aac298c24fe00a1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Thu, 9 Jul 2026 14:50:40 +0200 +Subject: [PATCH] * src/metalink.c: Include ctype.h + +CVE: CVE-2026-58469 +Upstream: https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1 +Signed-off-by: Stefan Müller + +--- + src/metalink.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/metalink.c b/src/metalink.c +index 3794909f..954546d2 100644 +--- a/src/metalink.c ++++ b/src/metalink.c +@@ -46,6 +46,7 @@ as that of the covered work. */ + #include "c-strcase.h" + #include + #include /* For unlink. */ ++#include + #include + #ifdef HAVE_GPGME + #include +-- +GitLab + diff --git a/package/wget/wget.mk b/package/wget/wget.mk index e3143647d7..51b71a23ca 100644 --- a/package/wget/wget.mk +++ b/package/wget/wget.mk @@ -12,6 +12,11 @@ WGET_LICENSE = GPL-3.0+ WGET_LICENSE_FILES = COPYING WGET_CPE_ID_VENDOR = gnu +# 0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch +# 0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch +# 0004-src-metalink.c-Include-ctype.h.patch +WGET_IGNORE_CVES += CVE-2026-58469 + ifeq ($(BR2_PACKAGE_LIBPSL),y) WGET_CONF_OPTS += --with-libpsl WGET_DEPENDENCIES += libpsl