On Mon Sep 7, 2026 at 11:26 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > On Sun, Sep 6, 2026 at 04:46 AM, Yoann Congal wrote: > >> >> On Fri Aug 21, 2026 at 6:32 PM CEST, Darsh Kelaiya -X (dkelaiya - E >> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: >> >>> From: Darsh Kelaiya <[email protected]> >>> >>> This patch applies the upstream fix for CVE-2026-7246 as referenced >>> in [2], using the upstream commit identified in [1]. >>> >>> The backport also adapts editor regression tests from the upstream >>> test and documentation follow-up identified in [3]. This follow-up >>> does not contain an additional production security fix. >>> >>> [1] >>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 >>> >>> [2] >>> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw >>> >>> [3] >>> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976 >>> >>> >>> Signed-off-by: Darsh Kelaiya <[email protected]> >>> --- >>> .../python/python3-click/CVE-2026-7246.patch | 245 ++++++++++++++++++ >>> .../python/python3-click_8.1.7.bb | 5 +- >>> 2 files changed, 249 insertions(+), 1 deletion(-) >>> create mode 100644 >>> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>> >>> diff --git >>> a/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>> b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>> new file mode 100644 >>> index 0000000000..47ee1a551f >>> --- /dev/null >>> +++ b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>> @@ -0,0 +1,245 @@ >>> +From cb30f575b1a251e8698909bca2a443d41dad1824 Mon Sep 17 00:00:00 2001 >>> +From: Kevin Deldycke <[email protected]> >>> +Date: Wed, 4 Mar 2026 14:51:58 +0400 >>> +Subject: [PATCH] Document and fix command string sanitizing with >>> `shlex.split` >>> + >>> +Removes last use of `shell=True` use for command invokation for >>> defense-in-depth. >>> +Refs: #1026, #1477 and #2775 >>> + >>> +CVE: CVE-2026-7246 >>> +Upstream-Status: Backport [ >>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 >>> ] >>> + >>> +Backport Changes: >>> +- Click 8.1.7 uses Editor.edit_file(filename), not the newer >>> + Editor.edit_files(filenames) API. Apply the argv-list change >>> + to one filename without adding the multi-file API. >>> +- Adapt editor tests from b96c2601 and follow-up b5529479 to >> >> Hello, >> >> This commit has both b96c2601 and b5529479 squashed. Please keep >> upstream backport patches split. >> >> Can you send a v2 with as the CVE fix (b96c2601) and its followup >> (b5529479)? >> >> Thanks! >> >> -- >> Yoann Congal >> Smile ECS > > Hi Yoann, > > While preparing v2, I noticed that NVD now marks CVE-2026-7246 as disputed > and states that the Pallets Click project does not consider it a valid > vulnerability: > > https://nvd.nist.gov/vuln/detail/CVE-2026-7246 > > However, the published advisory identifies upstream commit b96c2601 as the > fix: > > https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw > > Upstream describes the removal of shell=True as defense-in-depth, so I wanted > to confirm the preferred handling. Should I replace the backport patches with > a status entry such as: > > CVE_STATUS[CVE-2026-7246] = "disputed: Pallets Click does not consider this a > valid vulnerability" > > Or should I continue with the split v2 backport patches as hardening?
Hello, It depends on the patch complexity: If it is small and easely understandable let's backport it. If not, we can ignore it but I'd like to see the Pallets Click project reasonning for disputing it please. Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246312): https://lists.openembedded.org/g/openembedded-core/message/246312 Mute This Topic: https://lists.openembedded.org/mt/120864409/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
