On Wed Sep 23, 2026 at 8:36 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Darsh Kelaiya <[email protected]> > > This backports the click.edit() hardening identified as the fix in > the public advisory [2], using upstream commit [1]. > > Upstream follow-up commit [3] adds regression-test coverage for editor > command parsing and clarifies the related source comments. It does not > change runtime behavior or provide an additional security fix. Carry it > as a separate patch to preserve the upstream commit boundaries. > > [1] > https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 > [2] > https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw > [3] > https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976 > > Signed-off-by: Darsh Kelaiya <[email protected]> > --- > .../CVE-2026-7246-regression.patch | 124 +++++++++++ > .../python/python3-click/CVE-2026-7246.patch | 201 ++++++++++++++++++ > .../python/python3-click_8.1.7.bb | 6 +- > 3 files changed, 330 insertions(+), 1 deletion(-) > create mode 100644 > meta/recipes-devtools/python/python3-click/CVE-2026-7246-regression.patch > create mode 100644 > meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch > > [...] > diff --git a/meta/recipes-devtools/python/python3-click_8.1.7.bb > b/meta/recipes-devtools/python/python3-click_8.1.7.bb > index b75d9108893..8a077f48c7c 100644 > --- a/meta/recipes-devtools/python/python3-click_8.1.7.bb > +++ b/meta/recipes-devtools/python/python3-click_8.1.7.bb > @@ -12,7 +12,10 @@ SRC_URI[sha256sum] = > "ca9853ad459e787e2192211578cc907e7594e294c7ccc834310722b41b > > inherit pypi setuptools3 ptest > > -SRC_URI += "file://run-ptest" > +SRC_URI += "file://run-ptest \ > + file://CVE-2026-7246.patch \ > + file://CVE-2026-7246-regression.patch \ > + " > > CVE_PRODUCT = "palletsprojects:click" > > @@ -36,6 +39,7 @@ CLEANBROKEN = "1" > RDEPENDS:${PN} += "\ > python3-io \ > python3-threading \
Hello, > + python3-shell \ Why was this added? master does not have this RDEPENDS. If that is an issue to fix, then it should go through master (and other stables) first. > " > > BBCLASSEXTEND = "native nativesdk" FYI, the rest of the patch looks good to me. I've not found convincing reason to ignore the CVE. So the fix is the way forward. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247094): https://lists.openembedded.org/g/openembedded-core/message/247094 Mute This Topic: https://lists.openembedded.org/mt/121388818/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
