The homepage of https://musl.libc.org/ mentions CVE-2025-26519, pointing to two patches, but no new version has been released. I am not currently using Yocto, I was only evaluating it, so I may be wrong. But my understanding is that you fixed this issue in Walnascar/5.2: https://git.openembedded.org/openembedded-core/commit/meta/recipes-core/musl?h=walnascar&id=bfcc61f7b0ec42fafdcc7441bd50c8a75f456693 (maybe by accident, just wanting a newer version?). But AFAICT this was never fixed in any of the LTS versions: - Scarthgap: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=scarthgap - Kirkstone: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=kirkstone I am also a bit concerned about this not appearing in https://autobuilder.yocto.io/pub/non-release/patchmetrics/. Is it possible that, because musl has not released a new version, a limitation in whatever creates that webpage fails to report the CVE?
Khem, can you comment and/or do the patch backport?
As to why it doesn't appear in the CVE reports: our CVE reports are based on data provided by the NIST NVD, and that CVE is relatively new and doesn't have any of the required machine-readable metadata. Notable, https://nvd.nist.gov/vuln/detail/CVE-2025-26519 doesn't have a CPE entry. When the issue gets a CPE entry it will appear in the reports. It is known that the NVD is struggling massively at the moment and we're evaluating how to improve our automated CVE tooling.
Email sent to cpe_dictionary@nist.gov: > CVE-2025-26519 is described as follows: > musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write > vulnerability when an attacker can trigger iconv conversion of > untrusted EUC-KR text to UTF-8. > > No CPE is provided at https://nvd.nist.gov/vuln/detail/CVE-2025-26519. > > Looking at https://cveawg.mitre.org/api/cve/CVE-2025-26519, I see the > following: > cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:* > "versionStartIncluding":"0.9.13" > "versionEndExcluding":"1.2.6" > > Please update the NIST vulnerability database to include the CPE. Now we wait for the database to be updated.
https://nvd.nist.gov/vuln/detail/CVE-2025-26519 now includes the CPE. This should filter through to the next CVE analysis in the LTS branch.