<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15932</bug_id>
          
          <creation_ts>2025-07-11 06:51:56 +0000</creation_ts>
          <short_desc>musl CVE-2025-26519 missing in LTS releases</short_desc>
          <delta_ts>2025-12-11 09:03:00 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>5.0.15</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>5.0.14</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Cristian Morales Vega">christian.morales.vega</reporter>
          <assigned_to name="Paul Barker">paul</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>raj.khem</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>ross.burton</cc>
    
    <cc>steve</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>102450</commentid>
    <comment_count>0</comment_count>
    <who name="Cristian Morales Vega">christian.morales.vega</who>
    <bug_when>2025-07-11 06:51:56 +0000</bug_when>
    <thetext>The homepage of https://musl.libc.org/ mentions CVE-2025-26519, pointing to two patches, but no new version has been released.

I am not currently using Yocto, I was only evaluating it, so I may be wrong. But my understanding is that you fixed this issue in Walnascar/5.2: https://git.openembedded.org/openembedded-core/commit/meta/recipes-core/musl?h=walnascar&amp;id=bfcc61f7b0ec42fafdcc7441bd50c8a75f456693 (maybe by accident, just wanting a newer version?).

But AFAICT this was never fixed in any of the LTS versions:

- Scarthgap: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=scarthgap

- Kirkstone: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=kirkstone

I am also a bit concerned about this not appearing in https://autobuilder.yocto.io/pub/non-release/patchmetrics/. Is it possible that, because musl has not released a new version, a limitation in whatever creates that webpage fails to report the CVE?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>102477</commentid>
    <comment_count>1</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-07-17 14:35:44 +0000</bug_when>
    <thetext>Khem, can you comment and/or do the patch backport?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>102479</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2025-07-17 14:44:11 +0000</bug_when>
    <thetext>As to why it doesn&apos;t appear in the CVE reports: our CVE reports are based on data provided by the NIST NVD, and that CVE is relatively new and doesn&apos;t have any of the required machine-readable metadata.  Notable, https://nvd.nist.gov/vuln/detail/CVE-2025-26519 doesn&apos;t have a CPE entry.

When the issue gets a CPE entry it will appear in the reports. It is known that the NVD is struggling massively at the moment and we&apos;re evaluating how to improve our automated CVE tooling.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103514</commentid>
    <comment_count>3</comment_count>
    <who name="Paul Barker">paul</who>
    <bug_when>2025-12-10 10:04:37 +0000</bug_when>
    <thetext>Email sent to cpe_dictionary@nist.gov:

&gt; CVE-2025-26519 is described as follows:
&gt;   musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write
&gt;   vulnerability when an attacker can trigger iconv conversion of
&gt;   untrusted EUC-KR text to UTF-8.
&gt;
&gt; No CPE is provided at https://nvd.nist.gov/vuln/detail/CVE-2025-26519.
&gt;
&gt; Looking at https://cveawg.mitre.org/api/cve/CVE-2025-26519, I see the
&gt; following:
&gt;   cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*
&gt;   &quot;versionStartIncluding&quot;:&quot;0.9.13&quot;
&gt;   &quot;versionEndExcluding&quot;:&quot;1.2.6&quot;
&gt;
&gt; Please update the NIST vulnerability database to include the CPE.

Now we wait for the database to be updated.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103519</commentid>
    <comment_count>4</comment_count>
    <who name="Paul Barker">paul</who>
    <bug_when>2025-12-11 09:03:00 +0000</bug_when>
    <thetext>https://nvd.nist.gov/vuln/detail/CVE-2025-26519 now includes the CPE. This should filter through to the next CVE analysis in the LTS branch.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>