On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via lists.openembedded.org 
wrote:
> Pick patch according to [2]
>
> [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249
> [2] https://security-tracker.debian.org/tracker/CVE-2026-69249
>
> Signed-off-by: Vijay Anusuri <[email protected]>
> ---
>  .../python3-cryptography/CVE-2026-69249.patch | 349 ++++++++++++++++++
>  .../python/python3-cryptography_42.0.5.bb     |   1 +
>  2 files changed, 350 insertions(+)
>  create mode 100644 
> meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
>
> diff --git 
> a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch 
> b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> new file mode 100644
> index 0000000000..a920b4a7cc
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> @@ -0,0 +1,349 @@
> +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001
> +From: William Woodruff <[email protected]>
> +Date: Sat, 6 Jun 2026 23:30:03 -0400
> +Subject: [PATCH] Add a signature validation budget during path construction
> + (#14960)
> +
> +* Add a signature validation budget during path construction
> +
> +This extends our existing NC budget check to include a budget
> +for signature validations. If a path construction exceeds the
> +budget by performing more than the allowed number of signature
> +validation steps, the entire construction fails.
> +
> +For now, our budget is 128 signature validations. This is
> +consistent with (higher than) Go and rustls-webpki, which
> +both set a limit of 100. Like Go, we attempt to make the "best"
> +use of our signature budget by ordering by likelihood, using
> +AKI/SKI match as the strongest signal of fitness.
> +
> +* Bump limbo
> +
> +* Temporary commit
> +
> +* Revert "Temporary commit"
> +
> +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7.
> +
> +* Fudge a coverage test into place
> +
> +* Coverage for the coverage god
> +
> +Upstream-Status: Backport [import from suse 
> python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm
> +Upstream commit 
> https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582]
> +CVE: CVE-2026-69249
> +Signed-off-by: Vijay Anusuri <[email protected]>
> +---
> + .../cryptography-x509-verification/src/lib.rs | 209 +++++++++++++++++-
> + .../src/policy/mod.rs                         |   8 +-
> + 2 files changed, 208 insertions(+), 9 deletions(-)

When I compare CVE-2026-69249-signature-validation-budget.patch in
python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm and this patch, I get a
lot of diffs that don't look trivial to me (In particular, some hunks
about the budget handling disapear...)

Can you explain how/why did you change the upstream patch to match our
code?

Please send a v2 of this series with:
* URLs to download the Suze archive
* backport changes for this patch (2/3 also had changes but those were
  easy to understand)
?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246345): 
https://lists.openembedded.org/g/openembedded-core/message/246345
Mute This Topic: https://lists.openembedded.org/mt/121028974/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to