On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via lists.openembedded.org wrote: > Pick patch according to [2] > > [1] https://nvd.nist.gov/vuln/detail/cve-2026-69248 > [2] https://security-tracker.debian.org/tracker/CVE-2026-69248 > > Signed-off-by: Vijay Anusuri <[email protected]> > --- > .../python3-cryptography/CVE-2026-69248.patch | 297 ++++++++++++++++++ > .../python/python3-cryptography_42.0.5.bb | 1 + > 2 files changed, 298 insertions(+) > create mode 100644 > meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch > > diff --git > a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch > b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch > new file mode 100644 > index 0000000000..5ccccd8034 > --- /dev/null > +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch > @@ -0,0 +1,297 @@ > +From 4d035a4225965edeffd312079a510ef25fcfdcb2 Mon Sep 17 00:00:00 2001 > +From: William Woodruff <[email protected]> > +Date: Thu, 21 May 2026 20:44:05 -0400 > +Subject: [PATCH] x509: distinguish NC kinds when evaluating wildcard DNS SANs > + (#14888) > + > +* x509: distinguish NC kinds when evaluating wildcard DNS SANs > + > +* Bump x509-limbo > + > +Upstream-Status: Backport [import from suse > python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm
Hello, "suse python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm": Where can I download this? My usual Search engines/LLMs are not helpful here (and I don't want to resort to boot a Suse container, yet) Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246341): https://lists.openembedded.org/g/openembedded-core/message/246341 Mute This Topic: https://lists.openembedded.org/mt/121028971/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
