On Thu Jul 23, 2026 at 3:40 PM CEST, Deepak Rathore via lists.openembedded.org 
wrote:
> From: Deepak Rathore <[email protected]>
>
> This patch applies the upstream v3.14 backport for CVE-2026-15308.
> The upstream fix commit is referenced in [1], and the public CVE
> advisory is referenced in [2]. The individual backported commit link is
> recorded in the embedded patch header.
>
> [1] 
> https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-15308
>
> Signed-off-by: Deepak Rathore <[email protected]>
> ---
>  .../python/python3/CVE-2026-15308.patch       | 116 ++++++++++++++++++
>  .../recipes-devtools/python/python3_3.14.6.bb |   1 +
>  2 files changed, 117 insertions(+)
>  create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-15308.patch

Hello,

As far as I can tell, this patch is not released on the 3.14 branch yet.
I hold it until it is applied to master (upgrade or backport)

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242083): 
https://lists.openembedded.org/g/openembedded-core/message/242083
Mute This Topic: https://lists.openembedded.org/mt/120410499/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to