This CVE is applicable to Python 3.12.13 but is not applicable to Python 3.12.14, as per NVD.
Since the Python upgrade commit has already been merged into Scarthgap, this patch is no longer required.
Thanks,
Darsh
On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
From: Darsh Kelaiya <dkelaiya@cisco.com>Hello,
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
.../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
.../python/python3_3.12.13.bb | 1 +
2 files changed, 73 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-0864.patch
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
new file mode 100644
index 0000000000..e39177bdcb
--- /dev/null
+++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
@@ -0,0 +1,72 @@
+From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
+From: "Miss Islington (bot)"
+ <31488909+miss-islington@users.noreply.github.com>
+Date: Tue, 4 Aug 2026 11:27:20 +0200
+Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF, and
+ LF) in configparser (GH-143929) (#152005)
+
+gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser (GH-143929)
+
+CVE: CVE-2026-0864
+Upstream-Status: Backport [https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6]
+
+(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
+
+Co-authored-by: Seth Larson <seth@python.org>
+(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ Lib/configparser.py | 4 +++-
+ Lib/test/test_configparser.py | 11 +++++++++++
+ .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
+ 3 files changed, 16 insertions(+), 1 deletion(-)
+ create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
That patch does not apply:
ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch' on target directory 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14'
CmdError('quilt --quiltrc bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc push', 0, 'stdout: Applying patch CVE-2026-0864.patch
patching file Lib/configparser.py
Hunk #1 FAILED at 907.
1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py
patching file Lib/test/test_configparser.py
Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines).
patching file Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
Patch CVE-2026-0864.patch does not apply (enforce with -f)
Can you check please?
Thanks,
--
Yoann Congal
Smile ECS