From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <dkelaiya@cisco.com>
To: openembedded-core@lists.openembedded.org
Cc: xe-linux-external@cisco.com, Darsh Kelaiya <dkelaiya@cisco.com>
Subject: [OE-core][wrynose][PATCH 4/4] python3-git: fix CVE-2026-44244
Date: Tue, 18 Aug 2026 22:08:08 -0700 [thread overview]
Message-ID: <20260819050808.3986732-4-dkelaiya@cisco.com> (raw)
In-Reply-To: <20260819050808.3986732-1-dkelaiya@cisco.com>
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [3], using all the
backported commits shown in [1] and [2].
[1] https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2
[2] https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3
[3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
.../python3-git/CVE-2026-44244_p1.patch | 102 ++++++++++++++++++
.../python3-git/CVE-2026-44244_p2.patch | 28 +++++
.../python/python3-git_3.1.43.bb | 2 +
3 files changed, 132 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
new file mode 100644
index 0000000000..66ba5e9697
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch
@@ -0,0 +1,102 @@
+From 4ac5a1c848582f606655d03bfbc1243fe1754dc8 Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Wed, 29 Apr 2026 05:47:57 +0800
+Subject: [PATCH] reject control chars in written values in configuration
+
+Reject CR, LF, and NUL in GitConfigParser values before writing them
+to git config files (which also is a deviation from Git which escapes them).
+
+GitConfigParser._write() serializes embedded newlines as indented
+continuation lines by replacing "\n" with "\n\t". Git itself skips
+leading whitespace before parsing config tokens, so an injected value
+such as:
+
+ foo
+ [core]
+ hooksPath=/tmp/hooks
+
+is written in a form where the indented "[core]" line is still parsed by
+Git as a real section header. This lets attacker-controlled input passed
+to config_writer().set_value() poison repository config, including
+core.hooksPath, and redirect hook execution for later Git operations.
+
+Fail closed instead of stripping or normalizing these characters. Silent
+normalization can hide unsanitized caller input, and GitPython does not
+currently round-trip Git-style escaped values such as "\n" as embedded
+newlines.
+
+Apply the validation to set_value(), add_value(), and the public set()
+path so callers cannot bypass the safer helper API. Add regression tests
+for the advisory payload and for CR, LF, NUL, and bytes values.
+
+This preserves existing read behavior for config files that already
+contain multiline values while preventing GitPython from writing new
+unsafe values.
+
+CVE: CVE-2026-44244
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2]
+
+Backport Changes:
+- Omitted test/test_config.py because the PyPI 3.1.43 source used
+ by the recipe does not ship the upstream test tree.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/config.py | 24 ++++++++++++++++++++++--
+ 1 file changed, 22 insertions(+), 2 deletions(-)
+
+diff --git a/git/config.py b/git/config.py
+index 3ce9b123..d45cc31b 100644
+--- a/git/config.py
++++ b/git/config.py
+@@ -863,6 +863,24 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ return str(value)
+ return force_text(value)
+
++ def _value_to_string_safe(self, value: Union[str, bytes, int, float, bool]) -> str:
++ value_str = self._value_to_string(value)
++ if re.search(r"[\r\n\x00]", value_str):
++ raise ValueError("Git config values must not contain CR, LF, or NUL")
++ return value_str
++
++ @needs_values
++ @set_dirty_and_flush_changes
++ def set(
++ self,
++ section: str,
++ option: str,
++ value: Union[str, bytes, int, float, bool, None] = None,
++ ) -> None:
++ if value is not None:
++ value = self._value_to_string_safe(value)
++ return super().set(section, option, value)
++
+ @needs_values
+ @set_dirty_and_flush_changes
+ def set_value(self, section: str, option: str, value: Union[str, bytes, int, float, bool]) -> "GitConfigParser":
+@@ -883,9 +901,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ :return:
+ This instance
+ """
++ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self.set(section, option, self._value_to_string(value))
++ self.set(section, option, value_str)
+ return self
+
+ @needs_values
+@@ -910,9 +929,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ :return:
+ This instance
+ """
++ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self._sections[section].add(option, self._value_to_string(value))
++ self._sections[section].add(option, value_str)
+ return self
+
+ def rename_section(self, section: str, new_name: str) -> "GitConfigParser":
diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
new file mode 100644
index 0000000000..43aea2fd56
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch
@@ -0,0 +1,28 @@
+From cfa5a26453544e93be3689101e710b6b07a6e2b0 Mon Sep 17 00:00:00 2001
+From: "GPT 5.5" <codex@openai.com>
+Date: Wed, 29 Apr 2026 06:39:02 +0800
+Subject: [PATCH] avoid duplicate validation in set_value
+
+CVE: CVE-2026-44244
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3]
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit 8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/config.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/git/config.py b/git/config.py
+index d45cc31b..1595d51f 100644
+--- a/git/config.py
++++ b/git/config.py
+@@ -904,7 +904,7 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder):
+ value_str = self._value_to_string_safe(value)
+ if not self.has_section(section):
+ self.add_section(section)
+- self.set(section, option, value_str)
++ super().set(section, option, value_str)
+ return self
+
+ @needs_values
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index bd2b113489..d572857747 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -18,6 +18,8 @@ SRC_URI += "file://CVE-2026-42284.patch \
file://CVE-2026-42215_p3.patch \
file://CVE-2026-44243_p1.patch \
file://CVE-2026-44243_p2.patch \
+ file://CVE-2026-44244_p1.patch \
+ file://CVE-2026-44244_p2.patch \
"
SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
--
2.35.6
prev parent reply other threads:[~2026-08-19 5:08 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 5:08 [OE-core][wrynose][PATCH 1/4] python3-git: fix CVE-2026-42284 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 5:08 ` [OE-core][wrynose][PATCH 2/4] python3-git: fix CVE-2026-42215 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 13:01 ` Yoann Congal
2026-09-04 9:46 ` [wrynose][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 5:08 ` [OE-core][wrynose][PATCH 3/4] python3-git: fix CVE-2026-44243 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-19 5:08 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819050808.3986732-4-dkelaiya@cisco.com \
--to=dkelaiya@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=xe-linux-external@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox