On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via lists.openembedded.org 
wrote:
> Pick patch according to [2]
>
> [1] https://nvd.nist.gov/vuln/detail/cve-2026-69248
> [2] https://security-tracker.debian.org/tracker/CVE-2026-69248
>
> Signed-off-by: Vijay Anusuri <[email protected]>
> ---
>  .../python3-cryptography/CVE-2026-69248.patch | 297 ++++++++++++++++++
>  .../python/python3-cryptography_42.0.5.bb     |   1 +
>  2 files changed, 298 insertions(+)
>  create mode 100644 
> meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
>
> diff --git 
> a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch 
> b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
> new file mode 100644
> index 0000000000..5ccccd8034
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch
> @@ -0,0 +1,297 @@
> +From 4d035a4225965edeffd312079a510ef25fcfdcb2 Mon Sep 17 00:00:00 2001
> +From: William Woodruff <[email protected]>
> +Date: Thu, 21 May 2026 20:44:05 -0400
> +Subject: [PATCH] x509: distinguish NC kinds when evaluating wildcard DNS SANs
> + (#14888)
> +
> +* x509: distinguish NC kinds when evaluating wildcard DNS SANs
> +
> +* Bump x509-limbo
> +
> +Upstream-Status: Backport [import from suse 
> python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm

Hello,

"suse python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm": Where can I
download this? My usual Search engines/LLMs are not helpful here (and I
don't want to resort to boot a Suse container, yet)

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246341): 
https://lists.openembedded.org/g/openembedded-core/message/246341
Mute This Topic: https://lists.openembedded.org/mt/121028971/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to