Bug 15932 - musl CVE-2025-26519 missing in LTS releases
Summary: musl CVE-2025-26519 missing in LTS releases
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 5.0.15
Hardware: x86 Multiple
: Medium+ major
Target Milestone: 5.0.14
Assignee: Paul Barker
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2025-07-11 06:51 UTC by Cristian Morales Vega
Modified: 2025-12-11 09:03 UTC (History)
6 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cristian Morales Vega 2025-07-11 06:51:56 UTC
The homepage of https://musl.libc.org/ mentions CVE-2025-26519, pointing to two patches, but no new version has been released.

I am not currently using Yocto, I was only evaluating it, so I may be wrong. But my understanding is that you fixed this issue in Walnascar/5.2: https://git.openembedded.org/openembedded-core/commit/meta/recipes-core/musl?h=walnascar&id=bfcc61f7b0ec42fafdcc7441bd50c8a75f456693 (maybe by accident, just wanting a newer version?).

But AFAICT this was never fixed in any of the LTS versions:

- Scarthgap: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=scarthgap

- Kirkstone: https://git.openembedded.org/openembedded-core/log/meta/recipes-core/musl?h=kirkstone

I am also a bit concerned about this not appearing in https://autobuilder.yocto.io/pub/non-release/patchmetrics/. Is it possible that, because musl has not released a new version, a limitation in whatever creates that webpage fails to report the CVE?
Comment 1 Randy MacLeod 2025-07-17 14:35:44 UTC
Khem, can you comment and/or do the patch backport?
Comment 2 Ross Burton 2025-07-17 14:44:11 UTC
As to why it doesn't appear in the CVE reports: our CVE reports are based on data provided by the NIST NVD, and that CVE is relatively new and doesn't have any of the required machine-readable metadata.  Notable, https://nvd.nist.gov/vuln/detail/CVE-2025-26519 doesn't have a CPE entry.

When the issue gets a CPE entry it will appear in the reports. It is known that the NVD is struggling massively at the moment and we're evaluating how to improve our automated CVE tooling.
Comment 3 Paul Barker 2025-12-10 10:04:37 UTC
Email sent to cpe_dictionary@nist.gov:

> CVE-2025-26519 is described as follows:
>   musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write
>   vulnerability when an attacker can trigger iconv conversion of
>   untrusted EUC-KR text to UTF-8.
>
> No CPE is provided at https://nvd.nist.gov/vuln/detail/CVE-2025-26519.
>
> Looking at https://cveawg.mitre.org/api/cve/CVE-2025-26519, I see the
> following:
>   cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*
>   "versionStartIncluding":"0.9.13"
>   "versionEndExcluding":"1.2.6"
>
> Please update the NIST vulnerability database to include the CPE.

Now we wait for the database to be updated.
Comment 4 Paul Barker 2025-12-11 09:03:00 UTC
https://nvd.nist.gov/vuln/detail/CVE-2025-26519 now includes the CPE. This should filter through to the next CVE analysis in the LTS branch.