A utility for retrieving files using the HTTP or FTP protocols
Go to file
RHEL Packaging Agent 055c68cdfe Fix CVE-2026-58472: integer+buffer overflow in html_quote_string()
Backport upstream fix for CVE-2026-58472 which addresses an integer
and buffer overflow vulnerability in the html_quote_string() function
in src/convert.c. The patch is based on upstream commits dd692d9 and
f76978a, adapted to use INT_ADD_WRAPV instead of INT_ADD_OK since
the gnulib version bundled with wget 1.19.5 does not provide the
latter. The fix adds overflow-safe integer arithmetic to the string
size calculation and aborts on overflow. Unit tests for
construct_relative, match_except_index, find_fragment, and
html_quote_string are included.

CVE: CVE-2026-58472
Upstream patches:
 - dd692d9cea.patch
 - f76978a51b.patch
Resolves: RHEL-210627

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-21 09:17:02 +00:00
.gitignore Resolves: RHEL-43559 - Misinterpretation of input may lead to improper behavior 2024-07-11 07:12:22 +02:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 12:03:46 -08:00
sources Resolves: RHEL-43559 - Misinterpretation of input may lead to improper behavior 2024-07-11 07:12:22 +02:00
wget-1.17-path.patch Resolves: RHEL-43559 - Misinterpretation of input may lead to improper behavior 2024-07-11 07:12:22 +02:00
wget-1.19.5-Add-TLS-1.3-support-for-GnuTLS.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-ca-cert-too-verbose.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-covscan-important-issues.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-CVE-2019-5953.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-CVE-2024-38428.patch Resolves: RHEL-43559 - Misinterpretation of input may lead to improper behavior 2024-07-11 07:12:22 +02:00
wget-1.19.5-CVE-2026-58472.patch Fix CVE-2026-58472: integer+buffer overflow in html_quote_string() 2026-07-21 09:17:02 +00:00
wget-1.19.5-Don-t-limit-the-test-suite-HTTPS-server-to-TLSv1.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-Dont-save-userpw-with---xattr.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-Dont-use-extended-attributes---xattr-by-default.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-Enable-post-handshake-auth-under-gnutls-on-TLS1.3.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-no_proxy-dot-prefix.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-no_proxy-tests.patch Auto sync2gitlab import of wget-1.19.5-10.el8.src.rpm 2022-05-26 16:14:59 -04:00
wget-1.19.5-no-log-when-quiet.patch Auto sync2gitlab import of wget-1.19.5-11.el8.src.rpm 2022-12-15 06:10:47 +00:00
wget.spec Fix CVE-2026-58472: integer+buffer overflow in html_quote_string() 2026-07-21 09:17:02 +00:00