From: Darsh Kelaiya <[email protected]>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] 
https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0
[2] 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485

Signed-off-by: Darsh Kelaiya <[email protected]>
---
 .../python/python3-git/CVE-2026-42284.patch   | 36 +++++++++++++++++++
 .../python/python3-git_3.1.43.bb              |  2 ++
 2 files changed, 38 insertions(+)
 create mode 100644 
meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch

diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch 
b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
new file mode 100644
index 0000000000..3e5b9908a7
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch
@@ -0,0 +1,36 @@
+From 01d579e1b0a3e78cf82695b84967d0c343cfdd0f Mon Sep 17 00:00:00 2001
+From: "GPT 5.4" <[email protected]>
+Date: Tue, 21 Apr 2026 09:30:29 +0800
+Subject: [PATCH] Make sure that multi-options are checked after splitting them
+ with `shlex`
+
+CVE: CVE-2026-42284
+Upstream-Status: Backport 
[https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
+
+Backport Changes:
+- Omitted test/test_clone.py and test/test_submodule.py because the
+  PyPI 3.1.43 source used by the recipe does not ship the upstream
+  test tree.
+
+Co-authored-by: Sebastian Thiel <[email protected]>
+(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
+Signed-off-by: Darsh Kelaiya <[email protected]>
+---
+ git/repo/base.py | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/git/repo/base.py b/git/repo/base.py
+index 51ea7690..8059fceb 100644
+--- a/git/repo/base.py
++++ b/git/repo/base.py
+@@ -1365,8 +1365,8 @@ class Repo:
+             Git.check_unsafe_protocols(str(url))
+         if not allow_unsafe_options:
+             Git.check_unsafe_options(options=list(kwargs.keys()), 
unsafe_options=cls.unsafe_git_clone_options)
+-        if not allow_unsafe_options and multi_options:
+-            Git.check_unsafe_options(options=multi_options, 
unsafe_options=cls.unsafe_git_clone_options)
++        if not allow_unsafe_options and multi:
++            Git.check_unsafe_options(options=multi, 
unsafe_options=cls.unsafe_git_clone_options)
+ 
+         proc = git.clone(
+             multi,
diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb 
b/meta/recipes-devtools/python/python3-git_3.1.43.bb
index 45c988117b..bfbdd80289 100644
--- a/meta/recipes-devtools/python/python3-git_3.1.43.bb
+++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
 
 inherit pypi python_setuptools_build_meta
 
+SRC_URI += "file://CVE-2026-42284.patch \
+           "
 SRC_URI[sha256sum] = 
"35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c"
 
 DEPENDS += " python3-gitdb"
-- 
2.35.6

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243697): 
https://lists.openembedded.org/g/openembedded-core/message/243697
Mute This Topic: https://lists.openembedded.org/mt/120825620/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to