From: "Yoann Congal" <yoann.congal@smile.fr>
To: <vanusuri@mvista.com>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][scarthgap][patch 3/3] python3-cryptography: Fix CVE-2026-69249
Date: Mon, 21 Sep 2026 19:16:28 +0200 [thread overview]
Message-ID: <DLL5XRWWZM4D.2RM59FLBTVIJD@smile.fr> (raw)
In-Reply-To: <20260901092741.34198-3-vanusuri@mvista.com>
On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch according to [2]
>
> [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249
> [2] https://security-tracker.debian.org/tracker/CVE-2026-69249
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../python3-cryptography/CVE-2026-69249.patch | 349 ++++++++++++++++++
> .../python/python3-cryptography_42.0.5.bb | 1 +
> 2 files changed, 350 insertions(+)
> create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
>
> diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> new file mode 100644
> index 0000000000..a920b4a7cc
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> @@ -0,0 +1,349 @@
> +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001
> +From: William Woodruff <william@yossarian.net>
> +Date: Sat, 6 Jun 2026 23:30:03 -0400
> +Subject: [PATCH] Add a signature validation budget during path construction
> + (#14960)
> +
> +* Add a signature validation budget during path construction
> +
> +This extends our existing NC budget check to include a budget
> +for signature validations. If a path construction exceeds the
> +budget by performing more than the allowed number of signature
> +validation steps, the entire construction fails.
> +
> +For now, our budget is 128 signature validations. This is
> +consistent with (higher than) Go and rustls-webpki, which
> +both set a limit of 100. Like Go, we attempt to make the "best"
> +use of our signature budget by ordering by likelihood, using
> +AKI/SKI match as the strongest signal of fitness.
> +
> +* Bump limbo
> +
> +* Temporary commit
> +
> +* Revert "Temporary commit"
> +
> +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7.
> +
> +* Fudge a coverage test into place
> +
> +* Coverage for the coverage god
> +
> +Upstream-Status: Backport [import from suse python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm
> +Upstream commit https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582]
> +CVE: CVE-2026-69249
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + .../cryptography-x509-verification/src/lib.rs | 209 +++++++++++++++++-
> + .../src/policy/mod.rs | 8 +-
> + 2 files changed, 208 insertions(+), 9 deletions(-)
When I compare CVE-2026-69249-signature-validation-budget.patch in
python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm and this patch, I get a
lot of diffs that don't look trivial to me (In particular, some hunks
about the budget handling disapear...)
Can you explain how/why did you change the upstream patch to match our
code?
Please send a v2 of this series with:
* URLs to download the Suze archive
* backport changes for this patch (2/3 also had changes but those were
easy to understand)
?
Thanks!
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-21 17:16 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 9:27 [OE-core][scarthgap][patch 1/3] python3-cryptography: Fix CVE-2026-34073 Vijay Anusuri
2026-09-01 9:27 ` [OE-core][scarthgap][patch 2/3] python3-cryptography: Fix CVE-2026-69248 Vijay Anusuri
2026-09-10 14:20 ` Yoann Congal
2026-09-18 5:50 ` Vijay Anusuri
2026-09-18 8:20 ` Yoann Congal
2026-09-21 15:44 ` Yoann Congal
2026-09-21 16:26 ` Vijay Anusuri
2026-09-21 17:10 ` Yoann Congal
2026-09-01 9:27 ` [OE-core][scarthgap][patch 3/3] python3-cryptography: Fix CVE-2026-69249 Vijay Anusuri
2026-09-21 17:16 ` Yoann Congal [this message]
2026-09-22 6:25 ` Vijay Anusuri
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLL5XRWWZM4D.2RM59FLBTVIJD@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
--cc=vanusuri@mvista.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox