* [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864
@ 2026-08-26 5:23 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-18 9:28 ` Yoann Congal
0 siblings, 1 reply; 3+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:23 UTC (permalink / raw)
To: openembedded-core; +Cc: Darsh Kelaiya
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
.../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
.../python/python3_3.12.13.bb | 1 +
2 files changed, 73 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-0864.patch
diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
new file mode 100644
index 0000000000..e39177bdcb
--- /dev/null
+++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
@@ -0,0 +1,72 @@
+From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
+From: "Miss Islington (bot)"
+ <31488909+miss-islington@users.noreply.github.com>
+Date: Tue, 4 Aug 2026 11:27:20 +0200
+Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF, and
+ LF) in configparser (GH-143929) (#152005)
+
+gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser (GH-143929)
+
+CVE: CVE-2026-0864
+Upstream-Status: Backport [https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6]
+
+(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
+
+Co-authored-by: Seth Larson <seth@python.org>
+(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ Lib/configparser.py | 4 +++-
+ Lib/test/test_configparser.py | 11 +++++++++++
+ .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
+ 3 files changed, 16 insertions(+), 1 deletion(-)
+ create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
+
+diff --git a/Lib/configparser.py b/Lib/configparser.py
+index f96704eb455..8ae35a0a189 100644
+--- a/Lib/configparser.py
++++ b/Lib/configparser.py
+@@ -907,7 +907,9 @@ class RawConfigParser(MutableMapping):
+ value = self._interpolation.before_write(self, section_name, key,
+ value)
+ if value is not None or not self._allow_no_value:
+- value = delimiter + str(value).replace('\n', '\n\t')
++ # Convert all possible line-endings into '\n\t'
++ value = (delimiter + str(value).replace('\r\n', '\n')
++ .replace('\r', '\n').replace('\n', '\n\t'))
+ else:
+ value = ""
+ fp.write("{}{}\n".format(key, value))
+diff --git a/Lib/test/test_configparser.py b/Lib/test/test_configparser.py
+index b7e68d7a3e7..389aa15e670 100644
+--- a/Lib/test/test_configparser.py
++++ b/Lib/test/test_configparser.py
+@@ -527,6 +527,17 @@ boolean {0[0]} NO
+ cf.get(self.default_section, "Foo"), "Bar",
+ "could not locate option, expecting case-insensitive defaults")
+
++ def test_crlf_normalization(self):
++ cf = self.newconfig({"key1": "a\nb","key2": "a\rb", "key3": "a\r\nb", "key4": "a\r\nb"})
++ buf = io.StringIO()
++ cf.write(buf)
++ cf_str = buf.getvalue()
++ self.assertNotIn("\r", cf_str)
++ self.assertNotIn("\r\n", cf_str)
++ self.assertEqual(cf_str.count("\n"), 10)
++ self.assertEqual(cf_str.count("\n\t"), 4)
++ self.assertTrue(cf_str.endswith("\n\n"))
++
+ def test_parse_errors(self):
+ cf = self.newconfig()
+ self.parse_error(cf, configparser.ParsingError,
+diff --git a/Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst b/Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
+new file mode 100644
+index 00000000000..ca554997e5c
+--- /dev/null
++++ b/Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
+@@ -0,0 +1,2 @@
++Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing
++multi-line configparser values.
+--
+2.44.4
+
diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb
index b6ceb0c634..752e2b888f 100644
--- a/meta/recipes-devtools/python/python3_3.12.13.bb
+++ b/meta/recipes-devtools/python/python3_3.12.13.bb
@@ -48,6 +48,7 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \
file://CVE-2026-11972.patch \
file://CVE-2026-9669.patch \
file://CVE-2026-7210.patch \
+ file://CVE-2026-0864.patch \
"
SRC_URI:append:class-native = " \
--
2.35.6
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864
2026-08-26 5:23 [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-18 9:28 ` Yoann Congal
2026-09-20 10:45 ` [scarthgap][PATCH] " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 1 reply; 3+ messages in thread
From: Yoann Congal @ 2026-09-18 9:28 UTC (permalink / raw)
To: dkelaiya, openembedded-core
On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <dkelaiya@cisco.com>
>
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
>
> [1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
>
> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> ---
> .../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
> .../python/python3_3.12.13.bb | 1 +
> 2 files changed, 73 insertions(+)
> create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>
> diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
> new file mode 100644
> index 0000000000..e39177bdcb
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
> @@ -0,0 +1,72 @@
> +From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
> +From: "Miss Islington (bot)"
> + <31488909+miss-islington@users.noreply.github.com>
> +Date: Tue, 4 Aug 2026 11:27:20 +0200
> +Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF, and
> + LF) in configparser (GH-143929) (#152005)
> +
> +gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser (GH-143929)
> +
> +CVE: CVE-2026-0864
> +Upstream-Status: Backport [https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6]
> +
> +(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
> +
> +Co-authored-by: Seth Larson <seth@python.org>
> +(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
> +Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> +---
> + Lib/configparser.py | 4 +++-
> + Lib/test/test_configparser.py | 11 +++++++++++
> + .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
> + 3 files changed, 16 insertions(+), 1 deletion(-)
> + create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
Hello,
That patch does not apply:
ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch' on target directory 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14'
CmdError('quilt --quiltrc bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc push', 0, 'stdout: Applying patch CVE-2026-0864.patch
patching file Lib/configparser.py
Hunk #1 FAILED at 907.
1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py
patching file Lib/test/test_configparser.py
Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines).
patching file Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
Patch CVE-2026-0864.patch does not apply (enforce with -f)
Can you check please?
Thanks,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [scarthgap][PATCH] python3: fix CVE-2026-0864
2026-09-18 9:28 ` Yoann Congal
@ 2026-09-20 10:45 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 3+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-20 10:45 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 3446 bytes --]
Hello Yoann,
This CVE is applicable to Python 3.12.13 but is not applicable to Python 3.12.14, as per NVD.
Since the Python upgrade commit has already been merged into Scarthgap, this patch is no longer required.
Thanks,
Darsh
On Fri, Sep 18, 2026 at 02:58 PM, Yoann Congal wrote:
>
> On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>
>> From: Darsh Kelaiya <dkelaiya@cisco.com>
>>
>> This patch applies the upstream fix as referenced in [2],
>> using the commit shown in [1].
>>
>> [1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
>>
>> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
>>
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> .../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
>> .../python/python3_3.12.13.bb | 1 +
>> 2 files changed, 73 insertions(+)
>> create mode 100644
>> meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>>
>> diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> new file mode 100644
>> index 0000000000..e39177bdcb
>> --- /dev/null
>> +++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>> @@ -0,0 +1,72 @@
>> +From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
>> +From: "Miss Islington (bot)"
>> + <31488909+miss-islington@users.noreply.github.com>
>> +Date: Tue, 4 Aug 2026 11:27:20 +0200
>> +Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF,
>> and
>> + LF) in configparser (GH-143929) (#152005)
>> +
>> +gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser
>> (GH-143929)
>> +
>> +CVE: CVE-2026-0864
>> +Upstream-Status: Backport [ https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
>> ]
>> +
>> +(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
>> +
>> +Co-authored-by: Seth Larson <seth@python.org>
>> +(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
>> +Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> +---
>> + Lib/configparser.py | 4 +++-
>> + Lib/test/test_configparser.py | 11 +++++++++++
>> + .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
>> + 3 files changed, 16 insertions(+), 1 deletion(-)
>> + create mode 100644
>> Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
>
> Hello,
>
> That patch does not apply:
>
> ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch'
> on target directory
> 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14'
>
> CmdError('quilt --quiltrc
> bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc
> push', 0, 'stdout: Applying patch CVE-2026-0864.patch
> patching file Lib/configparser.py
> Hunk #1 FAILED at 907.
> 1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py
> patching file Lib/test/test_configparser.py
> Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines).
> patching file
> Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
> Patch CVE-2026-0864.patch does not apply (enforce with -f)
>
> Can you check please?
>
> Thanks,
> --
> Yoann Congal
> Smile ECS
[-- Attachment #2: Type: text/html, Size: 4043 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-20 10:46 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 5:23 [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-18 9:28 ` Yoann Congal
2026-09-20 10:45 ` [scarthgap][PATCH] " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox