| Summary: | musl CVE-2025-26519 missing in LTS releases | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Cristian Morales Vega <christian.morales.vega> |
| Component: | core | Assignee: | Paul Barker <paul> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | major | ||
| Priority: | Medium+ | CC: | meta.mr.watcher, meta.watcher, raj.khem, randy.macleod, ross.burton, steve |
| Version: | 5.0.15 | ||
| Target Milestone: | 5.0.14 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Cristian Morales Vega
2025-07-11 06:51:56 UTC
Khem, can you comment and/or do the patch backport? As to why it doesn't appear in the CVE reports: our CVE reports are based on data provided by the NIST NVD, and that CVE is relatively new and doesn't have any of the required machine-readable metadata. Notable, https://nvd.nist.gov/vuln/detail/CVE-2025-26519 doesn't have a CPE entry. When the issue gets a CPE entry it will appear in the reports. It is known that the NVD is struggling massively at the moment and we're evaluating how to improve our automated CVE tooling. Email sent to cpe_dictionary@nist.gov: > CVE-2025-26519 is described as follows: > musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write > vulnerability when an attacker can trigger iconv conversion of > untrusted EUC-KR text to UTF-8. > > No CPE is provided at https://nvd.nist.gov/vuln/detail/CVE-2025-26519. > > Looking at https://cveawg.mitre.org/api/cve/CVE-2025-26519, I see the > following: > cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:* > "versionStartIncluding":"0.9.13" > "versionEndExcluding":"1.2.6" > > Please update the NIST vulnerability database to include the CPE. Now we wait for the database to be updated. https://nvd.nist.gov/vuln/detail/CVE-2025-26519 now includes the CPE. This should filter through to the next CVE analysis in the LTS branch. |