On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via lists.openembedded.org wrote: > Pick patch according to [2] > > [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249 > [2] https://security-tracker.debian.org/tracker/CVE-2026-69249 > > Signed-off-by: Vijay Anusuri <[email protected]> > --- > .../python3-cryptography/CVE-2026-69249.patch | 349 ++++++++++++++++++ > .../python/python3-cryptography_42.0.5.bb | 1 + > 2 files changed, 350 insertions(+) > create mode 100644 > meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch > > diff --git > a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch > b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch > new file mode 100644 > index 0000000000..a920b4a7cc > --- /dev/null > +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch > @@ -0,0 +1,349 @@ > +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001 > +From: William Woodruff <[email protected]> > +Date: Sat, 6 Jun 2026 23:30:03 -0400 > +Subject: [PATCH] Add a signature validation budget during path construction > + (#14960) > + > +* Add a signature validation budget during path construction > + > +This extends our existing NC budget check to include a budget > +for signature validations. If a path construction exceeds the > +budget by performing more than the allowed number of signature > +validation steps, the entire construction fails. > + > +For now, our budget is 128 signature validations. This is > +consistent with (higher than) Go and rustls-webpki, which > +both set a limit of 100. Like Go, we attempt to make the "best" > +use of our signature budget by ordering by likelihood, using > +AKI/SKI match as the strongest signal of fitness. > + > +* Bump limbo > + > +* Temporary commit > + > +* Revert "Temporary commit" > + > +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7. > + > +* Fudge a coverage test into place > + > +* Coverage for the coverage god > + > +Upstream-Status: Backport [import from suse > python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm > +Upstream commit > https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582] > +CVE: CVE-2026-69249 > +Signed-off-by: Vijay Anusuri <[email protected]> > +--- > + .../cryptography-x509-verification/src/lib.rs | 209 +++++++++++++++++- > + .../src/policy/mod.rs | 8 +- > + 2 files changed, 208 insertions(+), 9 deletions(-)
When I compare CVE-2026-69249-signature-validation-budget.patch in python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm and this patch, I get a lot of diffs that don't look trivial to me (In particular, some hunks about the budget handling disapear...) Can you explain how/why did you change the upstream patch to match our code? Please send a v2 of this series with: * URLs to download the Suze archive * backport changes for this patch (2/3 also had changes but those were easy to understand) ? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246345): https://lists.openembedded.org/g/openembedded-core/message/246345 Mute This Topic: https://lists.openembedded.org/mt/121028974/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
