On Wed Aug 19, 2026 at 7:54 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <[email protected]>
>
> This patch applies the upstream fix as referenced in [2], using the
> commit shown in [1].
>
> [1] 
> https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358
> [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw
>
> Signed-off-by: Darsh Kelaiya <[email protected]>
> ---
>  .../python/python3-lxml/CVE-2026-41066.patch  | 4613 +++++++++++++++++
>  .../python/python3-lxml_5.0.2.bb              |    4 +-
>  2 files changed, 4616 insertions(+), 1 deletion(-)
>  create mode 100644 
> meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
>
> diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch 
> b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
> new file mode 100644
> index 0000000000..9c333d7ef7
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
> @@ -0,0 +1,4613 @@
> +From 4fe0735416504223919151aa43c8ccba4626597f Mon Sep 17 00:00:00 2001
> +From: Stefan Behnel <[email protected]>
> +Date: Fri, 10 Apr 2026 10:13:03 +0200
> +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for
> + all parser subclasses.
> +
> +CVE: CVE-2026-41066
> +Upstream-Status: Backport 
> [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358]
> +
> +Backport Changes:
> +- Keep the lxml 5.0.2 XMLParser signature without decompress.
> +- Regenerate etree.c because Scarthgap builds without Cython.
> +
> +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358)
> +Signed-off-by: Darsh Kelaiya <[email protected]>
> +---
> + src/lxml/etree.c       | 1242 ++++++++++++++++++++--------------------
> + src/lxml/iterparse.pxi |    8 +-
> + src/lxml/parser.pxi    |    6 +-
> + 3 files changed, 629 insertions(+), 627 deletions(-)

Hello,

As I wrote in 
https://lore.kernel.org/all/[email protected]/:
> Also, if we go through with regenerating etree.c with cython. I'd
> appreciate:
> * some info about how it was done,
> * a little effort to decrease patch size (the scarthgap one had a lot of
>   meaningless line number changes): I'd accept a patch format change from
>   upstream if that results in a small etree.c patch.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244943): 
https://lists.openembedded.org/g/openembedded-core/message/244943
Mute This Topic: https://lists.openembedded.org/mt/120825834/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to