Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package pcapplusplus for openSUSE:Factory checked in at 2026-09-24 23:05:44 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/pcapplusplus (Old) and /work/SRC/openSUSE:Factory/.pcapplusplus.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "pcapplusplus" Thu Sep 24 23:05:44 2026 rev:4 rq:1380228 version:26.07 Changes: -------- --- /work/SRC/openSUSE:Factory/pcapplusplus/pcapplusplus.changes 2024-02-29 21:52:58.547718479 +0100 +++ /work/SRC/openSUSE:Factory/.pcapplusplus.new.383539/pcapplusplus.changes 2026-09-24 23:05:51.812351478 +0200 @@ -1,0 +2,334 @@ +Thu Sep 24 14:32:58 UTC 2026 - Luigi Baldoni <[email protected]> + +- Update to version 26.07 + * libpcap / WinPcap / Npcap is now optional. + * Bumped the minimum required C++ standard to C++14 + Protocol support: + * Added Modbus protocol + * Added DoIP – Diagnostic over Internet Protocol + * Added PostgreSQL Wire Protocol (PGWire), including + additional message types + * Added MySQL Wire Protocol + * Discrete FTPControl and FTPData protocol types + * Add support for AccurateECN TCP flag + * Improve SIP packet detection using heuristic parsing + * Recognize LLC payload in SLL2 + Added extensive X.509 / cryptography support: + * X.509 certificate decoding, extension parsing, and parsing + of X.509 certificates embedded in SSL/TLS messages + * Export/import of X.509 certificates to PEM format, plus a + new general-purpose PEM codec + * Cryptographic key decoders (RSA/EC private and public keys) + * Base64 encoding/decoding + * A new X509Toolkit example application + * Expanded ASN.1 codec support: BitString, + UTCTime/GeneralizedTime, ObjectIdentifier and string records, + plus arbitrary-size integer support + * IFileReaderDevice::createReader() and + IFileReaderDevice::tryCreateReader() use file-content + heuristics + to automatically pick the right reader (pcap/pcapng/snoop) + instead of relying solely on the file extension + * Add incremental packet parsing support with + Packet::parsePacket() + * Added multi-language README support: Japanese + * IPv4Address/IPv6Address/MacAddress user-defined literals, + e.g. constructing addresses directly from string literals, + and sized buffer-construction overloads + * Explicit-ownership overloads for RawPacket::setRawData(), + and a sized overload for Layer::copyData() + * Improved zstd support: added a build flag to control zstd + support + * A new SuppressLogs RAII class for temporarily suppressing + log output + * Large-scale internal refactoring of the device layer + (PcapLiveDevice, DpdkDeviceList, file readers/writers, + statistics tracking), the logging infrastructure, and the + packet parsing infrastructure, improving encapsulation, + thread-safety, and maintainability + * Improved benchmarking: added a pure-parsing benchmark and + extended benchmarks to support PcapNG and Snoop files + * Test refactoring: replace packet creation macros in with C++ + functions + * Tons of security and correctness bug fixes + Breaking changes: + * The minimum required C++ standard has been raised to C++14 + * IPcapDevice has been removed; its logic now lives in + PcapLiveDevice + * libpcap/WinPcap/Npcap is now an optional dependency — + building without it disables Pcap++ capture features, though + Common++/Packet++ (including pcap file I/O) remain fully + usable + * Various internal APIs around device lists and statistics + tracking were reworked as part of the refactoring above; this + may affect code relying on undocumented internals + Deprecation list: + * IPv6Address::copyTo() has been deprecated, please use + IPv6Address::copyToNewBuffer() instead + * MacAddress::copyTo() has been deprecated, please use + MacAddress::copyToNewBuffer() instead + * Asn1IntegerRecord::getValue() has been deprecated, please + use Asn1IntegerRecord::getIntValue() instead + * RawPacket::getObjectType() has been deprecated due to + unclear semantics + * RawPacket::setRawData() has been deprecated, please use the + overload that takes takeOwnership parameter for explicit + control + * RawPacket::initWithRawData() has been deprecated, please use + RawPacket::setRawData() with takeOwnership=false instead + * SSLExtension::SSLExtension() has been deprecated, please use + the constructor with bounded span instead + * Several TcpOptionBuilder constructors have been deprecated, + please use the new constructors with TcpOptionEnumType + instead + * TcpLayer::getTcpOption(TcpOptionType option) has been + deprecated, please use the overload + TcpLayer::getTcpOption(TcpOptionEnumType option) instead + * TcpLayer::removeTcpOption(TcpOptionType optionType) has been + deprecated, please use the overload + TcpLayer::removeTcpOption(TcpOptionEnumType optionType) + instead + * MBufRawPacket::getObjectType() has been deprecated due to + unclear semantics + * IFileReaderDevice::getReader() has been deprecated, please + use IFileReaderDevice::tryCreateReader() instead + * PcapFileReaderDevice::isNanoSecondPrecisionSupported() has + been deprecated, nanosecond precision is now natively + supported + by the internal parser and always returns true + * PcapFileWriterDevice::isNanoSecondPrecisionSupported() has + been deprecated, nanosecond precision is now natively + supported + by the internal parser and always returns true + * BpfFilterWrapper::matchPacketWithFilter() has been + deprecated, please use BpfFilterWrapper::matches() instead + * GeneralFilter::matchPacketWithFilter() has been deprecated, + please use GeneralFilter::matches() instead + * PcapLiveDevice::matchPacketWithFilter() has been deprecated, + please use GeneralFilter::matches() directly + * PcapLiveDevice::sendPacket(Packet* packet, bool checkMtu = + true) has been deprecated, please use + PcapLiveDevice::sendPacket(Packet const& packet, bool + checkMtu) instead + * PcapRemoteDeviceList::getRemoteDeviceByIP() has been + deprecated, please use PcapRemoteDeviceList::getDeviceByIP() + instead + * PfRingDeviceList::getPfRingDeviceByName() has been + deprecated, please use PfRingDeviceList::getDeviceByName() + instead +- Drop pcap++-paths.patch (no longer useful) +- This release includes fixes for CVE-2026-13588 (boo#1269620), + CVE-2026-13589 (boo#1269619) and + CVE-2026-13590 (boo#1269618) +- Add CVE-2026-13587.patch and CVE-2026-13587.bin (boo#1269621) + +------------------------------------------------------------------- +Tue Jun 30 16:06:20 UTC 2026 - Luigi Baldoni <[email protected]> + +- Update to version 25.05 + New protocol support: + * WireGuard + * Add gratuitous ARP requests + * GTPv2 + * Cisco HDLC + New features: + * Added the option to build only Common++ and Packet++ + libraries without Pcap++, removing the dependency on third-party + libraries like libpcap or WinPcap/Npcap + * Updated the CMake files to support using pcapplusplus/ as + the include prefix + * Added support for DPDK 23.11 and 24.11 + * Introduced nanosecond precision for timestamps in TCP + reassembly + * Added support for timestamp-related libpcap options + * Added multi-language README support + * Introduced a new benchmark system using Google Benchmark + * Enhanced Python testing and linting infrastructure with ruff + Code refactoring: + * Overhauled the logging infrastructure for better performance + and flexibility + * Reformatted CMakeLists files using gersemi + * Updated the internal implementation of PcapLiveDevice to + store IP information as IPAddress + * Streamlined packet parsing using templated next-layer + sub-construction + * Refactored device list classes + * Improved the internal implementation of MacAddress, + IPAddress and IPNetwork classes + * Enhanced and modernized the internal implementation of + PfRingDevice + * Removed usage of VLAs + * Numerous C++11 modernization efforts + * Improved documentation using triple-slash Doxygen formatting + Other: + * Tons of bug fixes, security fixes and small improvements + Breaking changes: + * Logger::LogLevel has been deprecated and moved to LogLevel. + LogLevel is now an enum class, so arithmetic operations on it + will fail to compile + * The Logger copy constructor and copy assignment operator are + marked as deleted + * The return type of Packet::getRawPacketReadOnly() has been + changed from RawPacket* to RawPacket const* + * SSLv2 support has been removed + Deprecation list: + * PcapLiveDevice::getAddresses(), which was previously + deprecated, has now been removed + * libpcap versions < 0.9 are no longer supported. As a result, + the following CMake options have been removed: + PCAPPP_ENABLE_PCAP_IMMEDIATE_MODE and + PCAPPP_ENABLE_PCAP_SET_DIRECTION + * The following methods are now deprecated and will be removed + in future versions: + * Logger::Error, Logger::Info, and Logger::Debug are + deprecated. Please use LogLevel::XXX instead + * PcapLiveDeviceList::getPcapLiveDeviceBy*** methods have been + deprecated in favor of PcapLiveDeviceList::getDeviceBy*** + * ArpLayer(ArpOpcode opCode, const MacAddress &senderMacAddr, + const MacAddress &targetMacAddr, const IPv4Address + &senderIpAddr, const IPv4Address &targetIpAddr) constructor has + been deprecated in favor of more explicit overloads + version 24.09 + New features: + * Added support for eBPF AF_XDP + New protocols: + * SMTP + * ASN.1 encoding and decoding + * Enabled ASN.1 root record parsing in x509 certificates + * LDAP + * S7COMM + DPDK improvements: + * DPDK 22.11 support + * Jumbo frames support + * Added an option to disable hugepages and driver verification + on initialization + * NUMA awareness + Examples and utils: + * Added XdpExample-FilterTraffic to demonstrate XdpDevice usage + * PcapSplitter: updated output filenames with 5-tuple + information + * Added support for nanosecond precision in reading and + writing pcap files + * Blocking mode packet capture now uses poll() + * Added millisecond precision timeout in RawSocketDevice + * Extended IPFilter to support IPv6 where possible + * Boosted build time with Ccache + * Fixed precision issue in pcapng file reader + * Improved method for retrieving the default gateway on macOS + * Added security and code of conduct guidelines + * Refactoring and modernization of the code base: + * Refactored and cleaned up live devices + + Added a getter for fetching all IP addresses as IPAddress + objects. + * Refactored IP address classes IPv4Address, IPv6Address, + IPAddress + + Added equality operators between IPAddress and in_addr + types + * Refactored the MAC address class MacAddress + * Ported PcapPlusPlus libraries to C++11 + * Ported most of the examples and tutorials to C++11 + * Refactored and cleaned up PF_RING devices + * Refactored and cleaned up the PointerVector class + * Converted Macro Guard to pragma once + * Replaced std::map with std::unordered_map + * Refactored large parts of the packet filtering code + Internal tools: + * Reformatted the entire code base using clang-format + * Added dependabot to keep GitHub Actions and Python packages + up-to-date + * Added OpenSSF Scorecard automation to monitor and enhance + security + * Transitioned from CirrusCI to GitHub Actions for all + workflows + * Scheduled regular CI builds + * Replaced deprecated netifaces by scapy + * Improved fuzzing coverage and added Fuzz CI + * Added a template for opening GitHub issues + * Upgraded LightPcapNg to the latest from master + * Fixed unhandled exceptions crashing the entire test suite + Other: + * Tons of bug fixes, security fixes and small improvements + Breaking changes: + * Removed isValid() from MacAddress, IPAddress, IPv4Address, + IPv6Address, instead they throw an exception if the input + argument is invalid + * Introduced a new TcpOptionEnumType + * Removed the dummy argument in PayloadLayer's constructor + Deprecation list: + Removed methods: + * IPv4Address::matchSubnet() + Methods now marked as deprecated: + * PointerVector::getAndRemoveFromVector() -> replaced by + PointerVector::getAndDetach() + * HttpResponseLayer::HttpResponseLayer(version, statusCode, + statusCodeString) -> use other constructors + * HttpResponseLayer::setStatusCode(newStatusCode, + statusCodeString) -> use the other overload + * TcpOptionType enum -> replaced by TcpOptionEnumType + * TcpOption::getTcpOptionType() -> replaced by + TcpOption::getTcpOptionEnumType() + * TcpOptionBuilder::TcpOptionBuilder() -> use other + constructors + * TcpLayer::getTcpOption(TcpOptionType option) -> use the + other overload + * TcpLayer::addTcpOptionAfter() -> replaced by + TcpLayer::insertTcpOptionAfter() + * TcpLayer::removeTcpOption() -> use the other overload + * PcapLiveDevice::getAddresses() -> replaced by + PcapLiveDevice::getIPAddresses() + * PcapRemoteDeviceList::getRemoteDeviceList() -> replaced by + PcapRemoteDeviceList::createRemoteDeviceList() + version 23.09 + New features: + * PcapPlusPlus moved from a custom build system to CMake! + * Added IP/IPv4/IPv6 network classes to better support netmask + and subnets + * Add support for opening NFLOG live device + * MAC address OUI Lookup + * Intel oneAPI compiler support + DPDK improvements: + * Properly support no RSS mode in DpdkDevice + * Make DPDK app name configurable + * More generic search of DPDK KNI kernel module in + setup_dpdk.py + New protocols: + * NFLOG + * SLL2 + * TPKT ++++ 37 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/pcapplusplus/pcapplusplus.changes ++++ and /work/SRC/openSUSE:Factory/.pcapplusplus.new.383539/pcapplusplus.changes Old: ---- PcapPlusPlus-22.11.tar.gz pcap++-paths.patch New: ---- CVE-2026-13587.bin CVE-2026-13587.patch PcapPlusPlus-26.07.tar.gz ----------(Old B)---------- Old: instead - Drop pcap++-paths.patch (no longer useful) - This release includes fixes for CVE-2026-13588 (boo#1269620), ----------(Old E)---------- ----------(New B)---------- New: CVE-2026-13590 (boo#1269618) - Add CVE-2026-13587.patch and CVE-2026-13587.bin (boo#1269621) ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ pcapplusplus.spec ++++++ --- /var/tmp/diff_new_pack.rpcjZz/_old 2026-09-24 23:05:53.387417560 +0200 +++ /var/tmp/diff_new_pack.rpcjZz/_new 2026-09-24 23:05:53.391417728 +0200 @@ -1,7 +1,7 @@ # # spec file for package pcapplusplus # -# Copyright (c) 2022 SUSE LLC +# Copyright (c) 2026 SUSE LLC and contributors # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -19,16 +19,18 @@ %global _lto_cflags %{_lto_cflags} -ffat-lto-objects %define _oname PcapPlusPlus Name: pcapplusplus -Version: 22.11 +Version: 26.07 Release: 0 Summary: C++ network sniffing and packet parsing and crafting framework License: Unlicense Group: Productivity/Networking/Other URL: https://pcapplusplus.github.io/ Source0: https://github.com/seladb/PcapPlusPlus/archive/v%{version}.tar.gz#/%{_oname}-%{version}.tar.gz -# PATCH-FIX-OPENSUSE pcap++-paths.patch -Patch2: pcap++-paths.patch -BuildRequires: dos2unix +# Part of Patch5 https://github.com/seladb/PcapPlusPlus/raw/8672f766fd2fdcabff53323ecf23b55d67146c09/Tests/Fuzzers/RegressionTests/regression_samples/crash-pcapng-epb-unbounded-length +Source5: CVE-2026-13587.bin +# PATCH-FIX-UPSTREAM CVE-2026-13587.patch +Patch5: CVE-2026-13587.patch +BuildRequires: cmake BuildRequires: fdupes BuildRequires: gcc-c++ BuildRequires: libpcap-devel >= 1.5 @@ -49,30 +51,28 @@ %prep %autosetup -p1 -n %{_oname}-%{version} - -dos2unix Examples/*/* README.md -chmod -x Examples/Tutorials/Tutorial-DpdkL2Fwd/WorkerThread.* +install -m0644 %{SOURCE5} Tests/Fuzzers/RegressionTests/regression_samples/crash-pcapng-epb-unbounded-length +find . -type f -name ".gitignore" -delete %build -export CXXFLAGS="%{optflags}" -./configure-linux.sh \ - --use-immediate-mode \ - --default - -# it looks like the build is not parallel-safe -make libs +%cmake \ + -DPCAPPP_BUILD_EXAMPLES=OFF +%cmake_build %install -make DESTDIR=%{buildroot} PREFIX=%{_prefix} LIB=%{_lib} \ - INCLUDEDIR=%{_includedir} libs install -%fdupes -s %{buildroot} +%cmake_install +%fdupes %{buildroot} %files devel %license LICENSE %doc README.md Examples -%{_libdir}/libCommon++.a -%{_libdir}/libPacket++.a -%{_libdir}/libPcap++.a -%{_libdir}/pkgconfig/PcapPlusPlus.pc %{_includedir}/pcapplusplus +%{_libdir}/libCommon++.so +%{_libdir}/libPacket++.so +%{_libdir}/libPcap++.so +%{_libdir}/libCommon++.so.%{version} +%{_libdir}/libPacket++.so.%{version} +%{_libdir}/libPcap++.so.%{version} +%{_libdir}/cmake/%{name} +%{_libdir}/pkgconfig/PcapPlusPlus.pc ++++++ CVE-2026-13587.patch ++++++ >From 8672f766fd2fdcabff53323ecf23b55d67146c09 Mon Sep 17 00:00:00 2001 From: vsaraikin <[email protected]> Date: Mon, 3 Aug 2026 10:40:35 +0300 Subject: [PATCH] Bound attacker-controlled block lengths in LightPcapNg (OOM/OOB in EPB parsing) (#2182) --- .../LightPcapNg/src/light_pcapng.c | 46 ++++++++++++++++-- .../crash-pcapng-epb-unbounded-length | Bin 0 -> 80 bytes 2 files changed, 43 insertions(+), 3 deletions(-) create mode 100644 Tests/Fuzzers/RegressionTests/regression_samples/crash-pcapng-epb-unbounded-length diff --git a/3rdParty/LightPcapNg/LightPcapNg/src/light_pcapng.c b/3rdParty/LightPcapNg/LightPcapNg/src/light_pcapng.c index 26423426f6..9ecce6103d 100644 --- a/3rdParty/LightPcapNg/LightPcapNg/src/light_pcapng.c +++ b/3rdParty/LightPcapNg/LightPcapNg/src/light_pcapng.c @@ -160,6 +160,19 @@ void parse_by_block_type(struct _light_pcapng *current, const uint32_t *local_da int32_t local_offset; uint32_t actual_len = 0; + // PCPP Patch (GH #2180): captured_packet_length comes straight from the input. + // Bound it to what this block can actually hold (as LIGHT_SIMPLE_PACKET_BLOCK does) + // so a malformed length can't drive an oversized calloc()/memcpy(). + { + uint32_t max_capture = 0; + uint32_t overhead = 2 * sizeof(current->block_total_length) + sizeof(current->block_type) + + 5 * sizeof(uint32_t); + if (current->block_total_length > overhead) + max_capture = current->block_total_length - overhead; + if (captured_packet_length > max_capture) + captured_packet_length = max_capture; + } + PADD32(captured_packet_length, &actual_len); epb = calloc(1, sizeof(struct _light_enhanced_packet_block) + actual_len); @@ -208,6 +221,19 @@ void parse_by_block_type(struct _light_pcapng *current, const uint32_t *local_da int32_t local_offset; uint32_t actual_len = 0; + // PCPP Patch (GH #2180): bound the attacker-controlled len to what this block can + // hold before it sizes the calloc()/memcpy(). + { + uint32_t max_len = 0; + // overhead = block_type + leading/trailing block_total_length + len + reserved0 + reserved1 + uint32_t overhead = 2 * sizeof(current->block_total_length) + sizeof(current->block_type) + + 3 * sizeof(uint32_t); + if (current->block_total_length > overhead) + max_len = current->block_total_length - overhead; + if (len > max_len) + len = max_len; + } + PADD32(len, &actual_len); cnb = calloc(1, sizeof(struct _light_custom_nonstandard_block) + actual_len); cnb->data_length = len; @@ -257,6 +283,21 @@ static size_t __parse_mem_copy(struct _light_pcapng **iter, const uint32_t *memo while (remaining > 12) { const uint32_t *local_data = (const uint32_t *)(memory); + uint32_t block_type = *local_data++; + uint32_t block_total_length = *local_data++; + + DCHECK_INT(((block_total_length % 4) == 0), 0, light_stop); + + // PCPP Patch (GH #2180): block_total_length is read straight from the input and is + // attacker-controlled. The DCHECK_* macros are no-ops in release builds, so reject + // here any block that is smaller than the mandatory framing or claims more bytes + // than are left in the buffer. This runs before the block is allocated and linked, + // so a rejected block leaves no half-initialised entry in the list. + if (block_total_length < 12 || block_total_length > remaining) + { + break; + } + if (current == NULL) { current = calloc(1, sizeof(struct _light_pcapng)); DCHECK_NULLP(current, return block_count); @@ -272,9 +313,8 @@ static size_t __parse_mem_copy(struct _light_pcapng **iter, const uint32_t *memo current = current->next_block; } - current->block_type = *local_data++; - current->block_total_length = *local_data++; - DCHECK_INT(((current->block_total_length % 4) == 0), 0, light_stop); + current->block_type = block_type; + current->block_total_length = block_total_length; parse_by_block_type(current, local_data, memory); ++++++ PcapPlusPlus-22.11.tar.gz -> PcapPlusPlus-26.07.tar.gz ++++++ /work/SRC/openSUSE:Factory/pcapplusplus/PcapPlusPlus-22.11.tar.gz /work/SRC/openSUSE:Factory/.pcapplusplus.new.383539/PcapPlusPlus-26.07.tar.gz differ: char 12, line 1
