From: "Yoann Congal" <yoann.congal@smile.fr>
To: <dkelaiya@cisco.com>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864
Date: Fri, 18 Sep 2026 11:28:23 +0200 [thread overview]
Message-ID: <DLIC3R56WHV2.221JF28TY0KH7@smile.fr> (raw)
In-Reply-To: <20260826052322.716321-1-dkelaiya@cisco.com>
On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <dkelaiya@cisco.com>
>
> This patch applies the upstream fix as referenced in [2],
> using the commit shown in [1].
>
> [1] https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864
>
> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> ---
> .../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++
> .../python/python3_3.12.13.bb | 1 +
> 2 files changed, 73 insertions(+)
> create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-0864.patch
>
> diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
> new file mode 100644
> index 0000000000..e39177bdcb
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch
> @@ -0,0 +1,72 @@
> +From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001
> +From: "Miss Islington (bot)"
> + <31488909+miss-islington@users.noreply.github.com>
> +Date: Tue, 4 Aug 2026 11:27:20 +0200
> +Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF, and
> + LF) in configparser (GH-143929) (#152005)
> +
> +gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser (GH-143929)
> +
> +CVE: CVE-2026-0864
> +Upstream-Status: Backport [https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6]
> +
> +(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f)
> +
> +Co-authored-by: Seth Larson <seth@python.org>
> +(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6)
> +Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> +---
> + Lib/configparser.py | 4 +++-
> + Lib/test/test_configparser.py | 11 +++++++++++
> + .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++
> + 3 files changed, 16 insertions(+), 1 deletion(-)
> + create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
Hello,
That patch does not apply:
ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch' on target directory 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14'
CmdError('quilt --quiltrc bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc push', 0, 'stdout: Applying patch CVE-2026-0864.patch
patching file Lib/configparser.py
Hunk #1 FAILED at 907.
1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py
patching file Lib/test/test_configparser.py
Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines).
patching file Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst
Patch CVE-2026-0864.patch does not apply (enforce with -f)
Can you check please?
Thanks,
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-18 9:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 5:23 [OE-core][scarthgap][PATCH] python3: fix CVE-2026-0864 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-18 9:28 ` Yoann Congal [this message]
2026-09-20 10:45 ` [scarthgap][PATCH] " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLIC3R56WHV2.221JF28TY0KH7@smile.fr \
--to=yoann.congal@smile.fr \
--cc=dkelaiya@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox