On Mon Aug 17, 2026 at 6:42 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Hetvi Thakar <[email protected]> > > This patch backports the upstream fix for CVE-2026-8643. The > commit is included in pip 26.1.2 and referenced in [1]. The public > CVE advisory is referenced in [2]. > > The selected commit is self-contained. Later upstream commits refactor > the validation to use a shared containment helper and update release > notes; they are not prerequisites for this fix. > > [1] > https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb > [2] https://github.com/advisories/GHSA-wf93-45jw-7689 > > Signed-off-by: Hetvi Thakar <[email protected]> > --- > .../python/python3-pip/CVE-2026-8643.patch | 80 +++++++++++++++++++ > .../python/python3-pip_26.0.1.bb | 4 +- > 2 files changed, 83 insertions(+), 1 deletion(-) > create mode 100644 > meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
Hello, Thanks for the patch. The scarthgap fix for this CVE[0] has 2 regression patches in addition to the CVE fix itself. Don't we need those for wrynose as well? I'll hold CVE-2026-8643 patches (scarthgap/wrynose) in the meantime. [0]: https://patchwork.yoctoproject.org/project/oe-core/patch/[email protected]/ Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244901): https://lists.openembedded.org/g/openembedded-core/message/244901 Mute This Topic: https://lists.openembedded.org/mt/120786097/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
