On Thu Jul 23, 2026 at 3:40 PM CEST, Deepak Rathore via lists.openembedded.org wrote: > From: Deepak Rathore <[email protected]> > > This patch applies the upstream v3.14 backport for CVE-2026-15308. > The upstream fix commit is referenced in [1], and the public CVE > advisory is referenced in [2]. The individual backported commit link is > recorded in the embedded patch header. > > [1] > https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-15308 > > Signed-off-by: Deepak Rathore <[email protected]> > --- > .../python/python3/CVE-2026-15308.patch | 116 ++++++++++++++++++ > .../recipes-devtools/python/python3_3.14.6.bb | 1 + > 2 files changed, 117 insertions(+) > create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-15308.patch
Hello, As far as I can tell, this patch is not released on the 3.14 branch yet. I hold it until it is applied to master (upgrade or backport) Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242083): https://lists.openembedded.org/g/openembedded-core/message/242083 Mute This Topic: https://lists.openembedded.org/mt/120410499/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
