On Mon Aug 17, 2026 at 6:42 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Hetvi Thakar <[email protected]>
>
> This patch backports the upstream fix for CVE-2026-8643. The
> commit is included in pip 26.1.2 and referenced in [1]. The public
> CVE advisory is referenced in [2].
>
> The selected commit is self-contained. Later upstream commits refactor
> the validation to use a shared containment helper and update release
> notes; they are not prerequisites for this fix.
>
> [1] 
> https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
> [2] https://github.com/advisories/GHSA-wf93-45jw-7689
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
>  .../python/python3-pip/CVE-2026-8643.patch    | 80 +++++++++++++++++++
>  .../python/python3-pip_26.0.1.bb              |  4 +-
>  2 files changed, 83 insertions(+), 1 deletion(-)
>  create mode 100644 
> meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch

Hello,

Thanks for the patch.

The scarthgap fix for this CVE[0] has 2 regression patches in addition to
the CVE fix itself. Don't we need those for wrynose as well?

I'll hold CVE-2026-8643 patches (scarthgap/wrynose) in the meantime.

[0]: 
https://patchwork.yoctoproject.org/project/oe-core/patch/[email protected]/

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244901): 
https://lists.openembedded.org/g/openembedded-core/message/244901
Mute This Topic: https://lists.openembedded.org/mt/120786097/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Yoann Congal via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to