From 38eee3870fbcf6bdf8e6b1281bc7a98d32b68521 Mon Sep 17 00:00:00 2001
From: Philip Withnall <pwithnall@gnome.org>
Date: Thu, 16 Apr 2026 15:27:37 +0100
Subject: [PATCH 1/2] gdbusintrospection: Fix XML parser state handling for
 <node> element nesting

The check for whether a `<node>` element in D-Bus introspection XML was
nested correctly was broken. `<node>` elements can only be at the top
level, or nested immediately within another `<node>` element.

Fix the check and add some unit tests for it.

Spotted by linhlhq as #YWH-PGM9867-204. The fix is mine, and the unit test
uses example XML strings adapted from their report.

Signed-off-by: Philip Withnall <pwithnall@gnome.org>

Fixes: #3932

CVE: CVE-2026-58016
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c9da977c178fbfc0e4caf99f9fdf5dc433d6fcc2]

Signed-off-by: Benjamin Robin <benjamin.robin@bootlin.com>
---
 gio/gdbusintrospection.c        |  2 +-
 gio/tests/gdbus-introspection.c | 33 +++++++++++++++++++++++++++++++++
 2 files changed, 34 insertions(+), 1 deletion(-)

diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c
index c7be334ce2f7..6f722ee6153d 100644
--- a/gio/gdbusintrospection.c
+++ b/gio/gdbusintrospection.c
@@ -1258,7 +1258,7 @@ parser_start_element (GMarkupParseContext  *context,
   /* ---------------------------------------------------------------------------------------------------- */
   if (strcmp (element_name, "node") == 0)
     {
-      if (!(g_slist_length (stack) >= 1 || strcmp (stack->next->data, "node") != 0))
+      if (stack->next != NULL && strcmp (stack->next->data, "node") != 0)
         {
           g_set_error_literal (error,
                                G_MARKUP_ERROR,
diff --git a/gio/tests/gdbus-introspection.c b/gio/tests/gdbus-introspection.c
index 44cb7a96af45..daca313f77e7 100644
--- a/gio/tests/gdbus-introspection.c
+++ b/gio/tests/gdbus-introspection.c
@@ -300,6 +300,38 @@ test_extra_data (void)
   g_dbus_node_info_unref (info);
 }
 
+static void
+test_invalid (void)
+{
+  const struct
+    {
+      const char *xml;
+      GMarkupError expected_error_code;
+    }
+  vectors[] =
+    {
+      { "", G_MARKUP_ERROR_EMPTY },
+      { "<node><interface name=\"I\"><method name=\"M\"><node><interface name=\"I2\"></interface></node></method>", G_MARKUP_ERROR_INVALID_CONTENT },
+      { "<node><interface name=\"I\"><signal name=\"S\"><node><interface name=\"I2\"><signal name=\"S2\"></signal></interface></node></signal>", G_MARKUP_ERROR_INVALID_CONTENT },
+      { "<node><interface name=\"I\"><property name=\"P\" type=\"s\" access=\"read\"><node><interface name=\"I2\"></interface></node></property>", G_MARKUP_ERROR_INVALID_CONTENT },
+      { "<node><interface name=\"I\"><method name=\"M\"><arg type=\"\"><node><interface name=\"I2\"><method name=\"M2\"></method></interface></node></arg>", G_MARKUP_ERROR_INVALID_CONTENT },
+    };
+
+  for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
+    {
+      GDBusNodeInfo *node;
+      GError *local_error = NULL;
+
+      g_test_message ("Testing parsing of %s gives an error", vectors[i].xml);
+
+      node = g_dbus_node_info_new_for_xml (vectors[i].xml, &local_error);
+      g_assert_error (local_error, G_MARKUP_ERROR, (int) vectors[i].expected_error_code);
+      g_assert_null (node);
+
+      g_clear_error (&local_error);
+    }
+}
+
 /* ---------------------------------------------------------------------------------------------------- */
 
 int
@@ -317,6 +349,7 @@ main (int   argc,
   g_test_add_func ("/gdbus/introspection-generate", test_generate);
   g_test_add_func ("/gdbus/introspection-default-direction", test_default_direction);
   g_test_add_func ("/gdbus/introspection-extra-data", test_extra_data);
+  g_test_add_func ("/gdbus/introspection/invalid", test_invalid);
 
   ret = session_bus_run ();

--
2.54.0
