Openembedded Core Discussions
 help / color / mirror / Atom feed
From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <dkelaiya@cisco.com>
To: openembedded-core@lists.openembedded.org
Subject: Re: [scarthgap][PATCH] python3: fix CVE-2026-0864
Date: Sun, 20 Sep 2026 03:45:59 -0700	[thread overview]
Message-ID: <632265.1789901159917551066@lists.openembedded.org> (raw)
In-Reply-To: <DLIC3R56WHV2.221JF28TY0KH7@smile.fr>

[-- Attachment #1: Type: text/plain, Size: 3446 bytes --]

Hello Yoann,

This CVE is applicable to Python 3.12.13 but is not applicable to Python 3.12.14, as per NVD.

Since the Python upgrade commit has already been merged into Scarthgap, this patch is no longer required.

Thanks,
Darsh

On Fri, Sep 18, 2026 at 02:58 PM, Yoann Congal wrote:

> 
> On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> From: Darsh Kelaiya <dkelaiya@cisco.com>
>> 
>> This patch applies the upstream fix as referenced in [2],
>> using the commit shown in [1].
>> 
>> [1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
>> 
>> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
>> 
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> .../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
>> .../python/python3_3.12.13.bb | 1 +
>> 2 files changed, 73 insertions(+)
>> create mode 100644
>> meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> 
>> diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> new file mode 100644
>> index 0000000000..e39177bdcb
>> --- /dev/null
>> +++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> @@ -0,0 +1,72 @@
>> +From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
>> +From: "Miss Islington (bot)"
>> + <31488909+miss-islington@users.noreply.github.com>
>> +Date: Tue, 4 Aug 2026 11:27:20 +0200
>> +Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF,
>> and
>> + LF) in configparser (GH-143929) (#152005)
>> +
>> +gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser
>> (GH-143929)
>> +
>> +CVE: CVE-2026-0864
>> +Upstream-Status: Backport [ https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
>> ]
>> +
>> +(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
>> +
>> +Co-authored-by: Seth Larson <seth@python.org>
>> +(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
>> +Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> +---
>> + Lib/configparser.py | 4 +++-
>> + Lib/test/test_configparser.py | 11 +++++++++++
>> + .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
>> + 3 files changed, 16 insertions(+), 1 deletion(-)
>> + create mode 100644
>> Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
> 
> Hello,
> 
> That patch does not apply:
> 
> ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch'
> on target directory
> 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14'
> 
> CmdError('quilt --quiltrc
> bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc
> push', 0, 'stdout: Applying patch CVE-2026-0864.patch
> patching file Lib/configparser.py
> Hunk #1 FAILED at 907.
> 1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py
> patching file Lib/test/test_configparser.py
> Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines).
> patching file
> Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
> Patch CVE-2026-0864.patch does not apply (enforce with -f)
> 
> Can you check please?
> 
> Thanks,
> --
> Yoann Congal
> Smile ECS

[-- Attachment #2: Type: text/html, Size: 4043 bytes --]

      reply	other threads:[~2026-09-20 10:46 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26  5:23 [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-18  9:28 ` Yoann Congal
2026-09-20 10:45   ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=632265.1789901159917551066@lists.openembedded.org \
    --to=dkelaiya@cisco.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox