On Wed Aug 19, 2026 at 7:54 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Darsh Kelaiya <[email protected]> > > This patch applies the upstream fix as referenced in [2], using the > commit shown in [1]. > > [1] > https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358 > [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw > > Signed-off-by: Darsh Kelaiya <[email protected]> > --- > .../python/python3-lxml/CVE-2026-41066.patch | 4613 +++++++++++++++++ > .../python/python3-lxml_5.0.2.bb | 4 +- > 2 files changed, 4616 insertions(+), 1 deletion(-) > create mode 100644 > meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > > diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > new file mode 100644 > index 0000000000..9c333d7ef7 > --- /dev/null > +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > @@ -0,0 +1,4613 @@ > +From 4fe0735416504223919151aa43c8ccba4626597f Mon Sep 17 00:00:00 2001 > +From: Stefan Behnel <[email protected]> > +Date: Fri, 10 Apr 2026 10:13:03 +0200 > +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for > + all parser subclasses. > + > +CVE: CVE-2026-41066 > +Upstream-Status: Backport > [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358] > + > +Backport Changes: > +- Keep the lxml 5.0.2 XMLParser signature without decompress. > +- Regenerate etree.c because Scarthgap builds without Cython. > + > +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358) > +Signed-off-by: Darsh Kelaiya <[email protected]> > +--- > + src/lxml/etree.c | 1242 ++++++++++++++++++++-------------------- > + src/lxml/iterparse.pxi | 8 +- > + src/lxml/parser.pxi | 6 +- > + 3 files changed, 629 insertions(+), 627 deletions(-)
Hello, As I wrote in https://lore.kernel.org/all/[email protected]/: > Also, if we go through with regenerating etree.c with cython. I'd > appreciate: > * some info about how it was done, > * a little effort to decrease patch size (the scarthgap one had a lot of > meaningless line number changes): I'd accept a patch format change from > upstream if that results in a small etree.c patch. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244943): https://lists.openembedded.org/g/openembedded-core/message/244943 Mute This Topic: https://lists.openembedded.org/mt/120825834/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
