On Wed Aug 19, 2026 at 12:36 PM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <[email protected]>
>
> This patch applies the upstream fix as referenced in [2], using the
> commit shown in [1].
>
> [1] 
> https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358
> [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw
>
> Signed-off-by: Darsh Kelaiya <[email protected]>
> ---
>  .../python/python3-lxml/CVE-2026-41066.patch  | 87 +++++++++++++++++++
>  .../python/python3-lxml_6.0.2.bb              |  4 +-
>  2 files changed, 90 insertions(+), 1 deletion(-)
>  create mode 100644 
> meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
>
> diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch 
> b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
> new file mode 100644
> index 0000000000..c619b2b2b5
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
> @@ -0,0 +1,87 @@
> +From 2851ff7d51681201c950554d52697429413835b5 Mon Sep 17 00:00:00 2001
> +From: Stefan Behnel <[email protected]>
> +Date: Fri, 10 Apr 2026 10:13:03 +0200
> +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for
> + all parser subclasses.
> +
> +CVE: CVE-2026-41066
> +Upstream-Status: Backport 
> [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358]
> +
> +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358)
> +Signed-off-by: Darsh Kelaiya <[email protected]>
> +---
> + src/lxml/iterparse.pxi | 10 ++++++----
> + src/lxml/parser.pxi    |  6 +++---
> + 2 files changed, 9 insertions(+), 7 deletions(-)
> [...]

Hello,

The equivalent scarthgap patch does regenerate etree.c but this one does
not. I've look at build log a bit, and I can't see it regenerated in
wrynose.

Can you check?

Also, if we go through with regenerating etree.c with cython. I'd
appreciate:
* some info about how it was done,
* a little effort to decrease patch size (the scarthgap one had a lot of
  meaningless line number changes): I'd accept a patch format change from
  upstream if that results in a small etree.c patch.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244942): 
https://lists.openembedded.org/g/openembedded-core/message/244942
Mute This Topic: https://lists.openembedded.org/mt/120827350/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to