Hello Yoann, This CVE is applicable to Python 3.12.13 but is not applicable to Python 3.12.14, as per NVD.
Since the Python upgrade commit has already been merged into Scarthgap, this patch is no longer required. Thanks, Darsh On Fri, Sep 18, 2026 at 02:58 PM, Yoann Congal wrote: > > On Wed Aug 26, 2026 at 7:23 AM CEST, Darsh Kelaiya -X (dkelaiya - E > INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > >> From: Darsh Kelaiya <[email protected]> >> >> This patch applies the upstream fix as referenced in [2], >> using the commit shown in [1]. >> >> [1] >> https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6 >> >> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-0864 >> >> Signed-off-by: Darsh Kelaiya <[email protected]> >> --- >> .../python/python3/CVE-2026-0864.patch | 72 +++++++++++++++++++ >> .../python/python3_3.12.13.bb | 1 + >> 2 files changed, 73 insertions(+) >> create mode 100644 >> meta/recipes-devtools/python/python3/CVE-2026-0864.patch >> >> diff --git a/meta/recipes-devtools/python/python3/CVE-2026-0864.patch >> b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch >> new file mode 100644 >> index 0000000000..e39177bdcb >> --- /dev/null >> +++ b/meta/recipes-devtools/python/python3/CVE-2026-0864.patch >> @@ -0,0 +1,72 @@ >> +From 1426c0d9d57a1ed19f95de0d461903e7cd6f6f64 Mon Sep 17 00:00:00 2001 >> +From: "Miss Islington (bot)" >> + <[email protected]> >> +Date: Tue, 4 Aug 2026 11:27:20 +0200 >> +Subject: [PATCH] [3.12] gh-143927: Normalize all line endings (CR, CRLF, >> and >> + LF) in configparser (GH-143929) (#152005) >> + >> +gh-143927: Normalize all line endings (CR, CRLF, and LF) in configparser >> (GH-143929) >> + >> +CVE: CVE-2026-0864 >> +Upstream-Status: Backport [ >> https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6 >> ] >> + >> +(cherry picked from commit 5858e42c539dac8394636a6e9b30472b8994851f) >> + >> +Co-authored-by: Seth Larson <[email protected]> >> +(cherry picked from commit db4a157c790479710a1a840d7937c5c815a6f8b6) >> +Signed-off-by: Darsh Kelaiya <[email protected]> >> +--- >> + Lib/configparser.py | 4 +++- >> + Lib/test/test_configparser.py | 11 +++++++++++ >> + .../2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst | 2 ++ >> + 3 files changed, 16 insertions(+), 1 deletion(-) >> + create mode 100644 >> Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst > > Hello, > > That patch does not apply: > > ERROR: python3-3.12.14-r0 do_patch: Applying patch 'CVE-2026-0864.patch' > on target directory > 'bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/Python-3.12.14' > > CmdError('quilt --quiltrc > bitbake-builds/scarthgap/tmp-glibc/work/core2-64-oe-linux/python3/3.12.14/recipe-sysroot-native/etc/quiltrc > push', 0, 'stdout: Applying patch CVE-2026-0864.patch > patching file Lib/configparser.py > Hunk #1 FAILED at 907. > 1 out of 1 hunk FAILED -- rejects in file Lib/configparser.py > patching file Lib/test/test_configparser.py > Hunk #1 succeeded at 538 with fuzz 2 (offset 11 lines). > patching file > Misc/NEWS.d/next/Security/2026-01-16-11-58-19.gh-issue-143927.aviFeG.rst > Patch CVE-2026-0864.patch does not apply (enforce with -f) > > Can you check please? > > Thanks, > -- > Yoann Congal > Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246262): https://lists.openembedded.org/g/openembedded-core/message/246262 Mute This Topic: https://lists.openembedded.org/mt/120932906/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
