From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <dkelaiya@cisco.com>
To: openembedded-core@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Darsh Kelaiya <dkelaiya@cisco.com>
Subject: [OE-core][wrynose][PATCH 1/4] python3-git: fix CVE-2026-42284
Date: Tue, 18 Aug 2026 22:08:05 -0700 [thread overview]
Message-ID: <20260819050808.3986732-1-dkelaiya@cisco.com> (raw)
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0
[2] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
.../python/python3-git/CVE-2026-42284.patch | 36 +++++++++++++++++++
.../python/python3-git_3.1.43.bb | 2 ++
2 files changed, 38 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
new file mode 100644
index 0000000000..3e5b9908a7
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
@@ -0,0 +1,36 @@
+From 01d579e1b0a3e78cf82695b84967d0c343cfdd0f Mon Sep 17 00:00:00 2001
+From: "GPT 5.4" <codex@openai.com>
+Date: Tue, 21 Apr 2026 09:30:29 +0800
+Subject: [PATCH] Make sure that multi-options are checked after splitting them
+ with `shlex`
+
+CVE: CVE-2026-42284
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
+
+Backport Changes:
+- Omitted test/test_clone.py and test/test_submodule.py because the
+ PyPI 3.1.43 source used by the recipe does not ship the upstream
+ test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/repo/base.py | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/git/repo/base.py b/git/repo/base.py
+index 51ea7690..8059fceb 100644
+--- a/git/repo/base.py
++++ b/git/repo/base.py
+@@ -1365,8 +1365,8 @@ class Repo:
+ Git.check_unsafe_protocols(str(url))
+ if not allow_unsafe_options:
+ Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
+- if not allow_unsafe_options and multi_options:
+- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
++ if not allow_unsafe_options and multi:
++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
+
+ proc = git.clone(
+ multi,
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index 45c988117b..bfbdd80289 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
+SRC_URI += "file://CVE-2026-42284.patch \
+ "
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
DEPENDS += " python3-gitdb"
--
2.35.6
next reply other threads:[~2026-08-19 5:08 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 5:08 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-08-19 5:08 ` [OE-core][wrynose][PATCH 2/4] python3-git: fix CVE-2026-42215 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 13:01 ` Yoann Congal
2026-09-04 9:46 ` [wrynose][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 5:08 ` [OE-core][wrynose][PATCH 3/4] python3-git: fix CVE-2026-44243 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 5:08 ` [OE-core][wrynose][PATCH 4/4] python3-git: fix CVE-2026-44244 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819050808.3986732-1-dkelaiya@cisco.com \
--to=dkelaiya@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox