On Wed Sep 23, 2026 at 8:36 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <[email protected]>
>
> This backports the click.edit() hardening identified as the fix in
> the public advisory [2], using upstream commit [1].
>
> Upstream follow-up commit [3] adds regression-test coverage for editor
> command parsing and clarifies the related source comments. It does not
> change runtime behavior or provide an additional security fix. Carry it
> as a separate patch to preserve the upstream commit boundaries.
>
> [1] 
> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42
> [2] 
> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
> [3] 
> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976
>
> Signed-off-by: Darsh Kelaiya <[email protected]>
> ---
>  .../CVE-2026-7246-regression.patch            | 124 +++++++++++
>  .../python/python3-click/CVE-2026-7246.patch  | 201 ++++++++++++++++++
>  .../python/python3-click_8.1.7.bb             |   6 +-
>  3 files changed, 330 insertions(+), 1 deletion(-)
>  create mode 100644 
> meta/recipes-devtools/python/python3-click/CVE-2026-7246-regression.patch
>  create mode 100644 
> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>
> [...]
> diff --git a/meta/recipes-devtools/python/python3-click_8.1.7.bb 
> b/meta/recipes-devtools/python/python3-click_8.1.7.bb
> index b75d9108893..8a077f48c7c 100644
> --- a/meta/recipes-devtools/python/python3-click_8.1.7.bb
> +++ b/meta/recipes-devtools/python/python3-click_8.1.7.bb
> @@ -12,7 +12,10 @@ SRC_URI[sha256sum] = 
> "ca9853ad459e787e2192211578cc907e7594e294c7ccc834310722b41b
>  
>  inherit pypi setuptools3 ptest
>  
> -SRC_URI += "file://run-ptest"
> +SRC_URI += "file://run-ptest \
> +            file://CVE-2026-7246.patch \
> +            file://CVE-2026-7246-regression.patch \
> +           "
>  
>  CVE_PRODUCT = "palletsprojects:click"
>  
> @@ -36,6 +39,7 @@ CLEANBROKEN = "1"
>  RDEPENDS:${PN} += "\
>      python3-io \
>      python3-threading \

Hello,

> +    python3-shell \

Why was this added? master does not have this RDEPENDS. If that is an
issue to fix, then it should go through master (and other stables)
first.

>      "
>  
>  BBCLASSEXTEND = "native nativesdk"

FYI, the rest of the patch looks good to me. I've not found convincing
reason to ignore the CVE. So the fix is the way forward.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247094): 
https://lists.openembedded.org/g/openembedded-core/message/247094
Mute This Topic: https://lists.openembedded.org/mt/121388818/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to