Backport upstream fix for CVE-2026-58472 which addresses an integer
and buffer overflow vulnerability in the html_quote_string() function
in src/convert.c. The patch is based on upstream commits dd692d9 and
f76978a, adapted to use INT_ADD_WRAPV instead of INT_ADD_OK since
the gnulib version bundled with wget 1.19.5 does not provide the
latter. The fix adds overflow-safe integer arithmetic to the string
size calculation and aborts on overflow. Unit tests for
construct_relative, match_except_index, find_fragment, and
html_quote_string are included.
CVE: CVE-2026-58472
Upstream patches:
- dd692d9cea.patch
- f76978a51b.patch
Resolves: RHEL-210627
This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.
Assisted-by: Ymir