[Buildroot] [git commit] package/wget: fix CVE-2026-58469

Julien Olivain via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
commit: https://gitlab.com/buildroot.org/buildroot/-/commit/937e33237ef739350bcba6fe0e18382ef7305afd
branch: https://gitlab.com/buildroot.org/buildroot/-/tree/master

Backport the upstream fix for a buffer underflow in
clean_metalink_string(), together with the two required follow-up
fixes for the inverted whitespace check and missing ctype.h include.

Backport to: 2025.02.x

Signed-off-by: Stefan Müller <[email protected]>
Signed-off-by: Julien Olivain <[email protected]>
---
 ...lean_metalink_string-Fix-buffer-underflow.patch | 54 ++++++++++++++++++++++
 ..._string-Fix-inverted-trailing-space-check.patch | 40 ++++++++++++++++
 .../wget/0004-src-metalink.c-Include-ctype.h.patch | 28 +++++++++++
 package/wget/wget.mk                               |  5 ++
 4 files changed, 127 insertions(+)

diff --git a/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch b/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch
new file mode 100644
index 0000000000..652f99786d
--- /dev/null
+++ b/package/wget/0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch
@@ -0,0 +1,54 @@
+From 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <[email protected]>
+Date: Mon, 29 Jun 2026 18:32:02 +0200
+Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix buffer
+ underflow
+
+Reported-by: [email protected]
+CVE: CVE-2026-58469
+Upstream: https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
+Signed-off-by: Stefan Müller <[email protected]>
+
+---
+ src/metalink.c | 9 +++------
+ 1 file changed, 3 insertions(+), 6 deletions(-)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index 9e355fd0..3acdc3a2 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -1041,7 +1041,6 @@ void
+ clean_metalink_string (char **str)
+ {
+   int c;
+-  size_t len;
+   char *new, *beg, *end;
+ 
+   if (!str || !*str)
+@@ -1049,7 +1048,7 @@ clean_metalink_string (char **str)
+ 
+   beg = *str;
+ 
+-  while ((c = *beg) && (c == '\n' || c == '\r' || c == '\t' || c == ' '))
++  while (isspace(*beg))
+     beg++;
+ 
+   end = beg;
+@@ -1062,12 +1061,10 @@ clean_metalink_string (char **str)
+   /* If we are at the end of the string, search the first legit
+      character going backward.  */
+   if (*end == '\0')
+-    while ((c = *(end - 1)) && (c == '\n' || c == '\r' || c == '\t' || c == ' '))
++    while (end > beg && !isspace(*(end - 1)))
+       end--;
+ 
+-  len = end - beg;
+-
+-  new = xmemdup0 (beg, len);
++  new = xmemdup0 (beg, end - beg);
+   xfree (*str);
+   *str = new;
+ }
+-- 
+GitLab
+
diff --git a/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch b/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch
new file mode 100644
index 0000000000..e6b6b7180a
--- /dev/null
+++ b/package/wget/0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch
@@ -0,0 +1,40 @@
+From 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf Mon Sep 17 00:00:00 2001
+From: ChenYanpan <[email protected]>
+Date: Wed, 8 Jul 2026 12:09:55 +0800
+Subject: [PATCH] * src/metalink.c (clean_metalink_string): Fix inverted
+ trailing-space check
+
+37a40fcb added an `end > beg' bound guard to prevent a buffer
+underflow, but accidentally flipped the condition from `isspace' to
+`!isspace'. The loop therefore walked back over non-space characters
+instead of trailing whitespace, collapsing any string without a
+trailing newline to "". Every Metalink/HTTP resource URL was wiped,
+so wget could not follow any mirror and
+testenv/Test-metalink-http.py failed ("Expected file test.meta not
+found"). Restore the `isspace' condition.
+
+Copyright-paperwork-exempt: Yes
+CVE: CVE-2026-58469
+Upstream: https://gitlab.com/gnuwget/wget/-/commit/7b1cdecc49bc77bde220fc575c8a00386c3f3bcf
+Signed-off-by: Stefan Müller <[email protected]>
+
+---
+ src/metalink.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index 3acdc3a2..3794909f 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -1061,7 +1061,7 @@ clean_metalink_string (char **str)
+   /* If we are at the end of the string, search the first legit
+      character going backward.  */
+   if (*end == '\0')
+-    while (end > beg && !isspace(*(end - 1)))
++    while (end > beg && isspace(*(end - 1)))
+       end--;
+ 
+   new = xmemdup0 (beg, end - beg);
+-- 
+GitLab
+
diff --git a/package/wget/0004-src-metalink.c-Include-ctype.h.patch b/package/wget/0004-src-metalink.c-Include-ctype.h.patch
new file mode 100644
index 0000000000..0782bf2563
--- /dev/null
+++ b/package/wget/0004-src-metalink.c-Include-ctype.h.patch
@@ -0,0 +1,28 @@
+From 82d945ff5dc9942b78b2bf736aac298c24fe00a1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <[email protected]>
+Date: Thu, 9 Jul 2026 14:50:40 +0200
+Subject: [PATCH] * src/metalink.c: Include ctype.h
+
+CVE: CVE-2026-58469
+Upstream: https://gitlab.com/gnuwget/wget/-/commit/82d945ff5dc9942b78b2bf736aac298c24fe00a1
+Signed-off-by: Stefan Müller <[email protected]>
+
+---
+ src/metalink.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/metalink.c b/src/metalink.c
+index 3794909f..954546d2 100644
+--- a/src/metalink.c
++++ b/src/metalink.c
+@@ -46,6 +46,7 @@ as that of the covered work.  */
+ #include "c-strcase.h"
+ #include <errno.h>
+ #include <unistd.h> /* For unlink.  */
++#include <ctype.h>
+ #include <metalink/metalink_parser.h>
+ #ifdef HAVE_GPGME
+ #include <gpgme.h>
+-- 
+GitLab
+
diff --git a/package/wget/wget.mk b/package/wget/wget.mk
index de03ec9cef..8118811efe 100644
--- a/package/wget/wget.mk
+++ b/package/wget/wget.mk
@@ -12,6 +12,11 @@ WGET_LICENSE = GPL-3.0+
 WGET_LICENSE_FILES = COPYING
 WGET_CPE_ID_VENDOR = gnu
 
+# 0002-src-metalink.c-clean_metalink_string-Fix-buffer-underflow.patch
+# 0003-src-metalink.c-clean_metalink_string-Fix-inverted-trailing-space-check.patch
+# 0004-src-metalink.c-Include-ctype.h.patch
+WGET_IGNORE_CVES += CVE-2026-58469
+
 WGET_CONF_OPTS += --disable-pcre
 
 ifeq ($(BR2_PACKAGE_LIBPSL),y)

_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.