On Wed Aug 19, 2026 at 12:36 PM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Darsh Kelaiya <[email protected]> > > This patch applies the upstream fix as referenced in [2], using the > commit shown in [1]. > > [1] > https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358 > [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw > > Signed-off-by: Darsh Kelaiya <[email protected]> > --- > .../python/python3-lxml/CVE-2026-41066.patch | 87 +++++++++++++++++++ > .../python/python3-lxml_6.0.2.bb | 4 +- > 2 files changed, 90 insertions(+), 1 deletion(-) > create mode 100644 > meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > > diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > new file mode 100644 > index 0000000000..c619b2b2b5 > --- /dev/null > +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch > @@ -0,0 +1,87 @@ > +From 2851ff7d51681201c950554d52697429413835b5 Mon Sep 17 00:00:00 2001 > +From: Stefan Behnel <[email protected]> > +Date: Fri, 10 Apr 2026 10:13:03 +0200 > +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for > + all parser subclasses. > + > +CVE: CVE-2026-41066 > +Upstream-Status: Backport > [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358] > + > +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358) > +Signed-off-by: Darsh Kelaiya <[email protected]> > +--- > + src/lxml/iterparse.pxi | 10 ++++++---- > + src/lxml/parser.pxi | 6 +++--- > + 2 files changed, 9 insertions(+), 7 deletions(-) > [...]
Hello, The equivalent scarthgap patch does regenerate etree.c but this one does not. I've look at build log a bit, and I can't see it regenerated in wrynose. Can you check? Also, if we go through with regenerating etree.c with cython. I'd appreciate: * some info about how it was done, * a little effort to decrease patch size (the scarthgap one had a lot of meaningless line number changes): I'd accept a patch format change from upstream if that results in a small etree.c patch. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244942): https://lists.openembedded.org/g/openembedded-core/message/244942 Mute This Topic: https://lists.openembedded.org/mt/120827350/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
