From: Darsh Kelaiya <[email protected]> This patch applies the upstream fix as referenced in [2], using the commit shown in [1].
[1] https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0 [2] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485 Signed-off-by: Darsh Kelaiya <[email protected]> --- .../python/python3-git/CVE-2026-42284.patch | 36 +++++++++++++++++++ .../python/python3-git_3.1.43.bb | 2 ++ 2 files changed, 38 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch new file mode 100644 index 0000000000..3e5b9908a7 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch @@ -0,0 +1,36 @@ +From 01d579e1b0a3e78cf82695b84967d0c343cfdd0f Mon Sep 17 00:00:00 2001 +From: "GPT 5.4" <[email protected]> +Date: Tue, 21 Apr 2026 09:30:29 +0800 +Subject: [PATCH] Make sure that multi-options are checked after splitting them + with `shlex` + +CVE: CVE-2026-42284 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0] + +Backport Changes: +- Omitted test/test_clone.py and test/test_submodule.py because the + PyPI 3.1.43 source used by the recipe does not ship the upstream + test tree. + +Co-authored-by: Sebastian Thiel <[email protected]> +(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0) +Signed-off-by: Darsh Kelaiya <[email protected]> +--- + git/repo/base.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/git/repo/base.py b/git/repo/base.py +index 51ea7690..8059fceb 100644 +--- a/git/repo/base.py ++++ b/git/repo/base.py +@@ -1365,8 +1365,8 @@ class Repo: + Git.check_unsafe_protocols(str(url)) + if not allow_unsafe_options: + Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options) +- if not allow_unsafe_options and multi_options: +- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options) ++ if not allow_unsafe_options and multi: ++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options) + + proc = git.clone( + multi, diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index 45c988117b..bfbdd80289 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta +SRC_URI += "file://CVE-2026-42284.patch \ + " SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" DEPENDS += " python3-gitdb" -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243697): https://lists.openembedded.org/g/openembedded-core/message/243697 Mute This Topic: https://lists.openembedded.org/mt/120825620/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
