Hi Yoann,

On Mon, Sep 21, 2026 at 10:46 PM Yoann Congal <[email protected]> wrote:

> On Tue Sep 1, 2026 at 11:27 AM CEST, Vijay Anusuri via
> lists.openembedded.org wrote:
> > Pick patch according to [2]
> >
> > [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249
> > [2] https://security-tracker.debian.org/tracker/CVE-2026-69249
> >
> > Signed-off-by: Vijay Anusuri <[email protected]>
> > ---
> >  .../python3-cryptography/CVE-2026-69249.patch | 349 ++++++++++++++++++
> >  .../python/python3-cryptography_42.0.5.bb     |   1 +
> >  2 files changed, 350 insertions(+)
> >  create mode 100644
> meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> >
> > diff --git
> a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> > new file mode 100644
> > index 0000000000..a920b4a7cc
> > --- /dev/null
> > +++
> b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch
> > @@ -0,0 +1,349 @@
> > +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001
> > +From: William Woodruff <[email protected]>
> > +Date: Sat, 6 Jun 2026 23:30:03 -0400
> > +Subject: [PATCH] Add a signature validation budget during path
> construction
> > + (#14960)
> > +
> > +* Add a signature validation budget during path construction
> > +
> > +This extends our existing NC budget check to include a budget
> > +for signature validations. If a path construction exceeds the
> > +budget by performing more than the allowed number of signature
> > +validation steps, the entire construction fails.
> > +
> > +For now, our budget is 128 signature validations. This is
> > +consistent with (higher than) Go and rustls-webpki, which
> > +both set a limit of 100. Like Go, we attempt to make the "best"
> > +use of our signature budget by ordering by likelihood, using
> > +AKI/SKI match as the strongest signal of fitness.
> > +
> > +* Bump limbo
> > +
> > +* Temporary commit
> > +
> > +* Revert "Temporary commit"
> > +
> > +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7.
> > +
> > +* Fudge a coverage test into place
> > +
> > +* Coverage for the coverage god
> > +
> > +Upstream-Status: Backport [import from suse
> python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm
> > +Upstream commit
> https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582
> ]
> > +CVE: CVE-2026-69249
> > +Signed-off-by: Vijay Anusuri <[email protected]>
> > +---
> > + .../cryptography-x509-verification/src/lib.rs | 209 +++++++++++++++++-
> > + .../src/policy/mod.rs                         |   8 +-
> > + 2 files changed, 208 insertions(+), 9 deletions(-)
>
> When I compare CVE-2026-69249-signature-validation-budget.patch in
> python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm and this patch, I get a
> lot of diffs that don't look trivial to me (In particular, some hunks
> about the budget handling disapear...)
>

the budget-handling changes that are missing from our version of the patch
are already present in our codebase. Therefore, those hunks were not
included in the backport. so those changes were not applied again.

>
> Can you explain how/why did you change the upstream patch to match our
> code?
>
> Please send a v2 of this series with:
> * URLs to download the Suze archive
> * backport changes for this patch (2/3 also had changes but those were
>   easy to understand)
> ?
>

I will send the updated v2 series shortly.

>
> Thanks!
> --
> Yoann Congal
> Smile ECS
>
>
Thanks & Regards,
Vijay
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246378): 
https://lists.openembedded.org/g/openembedded-core/message/246378
Mute This Topic: https://lists.openembedded.org/mt/121028974/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to