On Thu Aug 27, 2026 at 8:31 AM CEST, Yogita Urade -X (yurade - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> This patch applies upstream fix for CVE-2026-30922 as referenced in [2],
> using the upstream commit identified in [1].
>
> [1] 
> https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-30922
>
> Signed-off-by: Yogita Urade <[email protected]>
> ---
>  .../recipes-devtools/python/python-pyasn1.inc |   1 +
>  .../python3-pyasn1/CVE-2026-30922.patch       | 260 ++++++++++++++++++
>  2 files changed, 261 insertions(+)
>  create mode 100644 
> meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch
>
> diff --git a/meta/recipes-devtools/python/python-pyasn1.inc 
> b/meta/recipes-devtools/python/python-pyasn1.inc
> index 96b4a3b52a..d69cdf8877 100644
> --- a/meta/recipes-devtools/python/python-pyasn1.inc
> +++ b/meta/recipes-devtools/python/python-pyasn1.inc
> @@ -19,6 +19,7 @@ inherit ptest
>  SRC_URI += " \
>         file://run-ptest \
>         file://CVE-2026-23490.patch \
> +       file://CVE-2026-30922.patch \
>  "
>  
>  RDEPENDS:${PN}-ptest += " \
> diff --git a/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch 
> b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch
> new file mode 100644
> index 0000000000..aad4829f82
> --- /dev/null
> +++ b/meta/recipes-devtools/python/python3-pyasn1/CVE-2026-30922.patch
> @@ -0,0 +1,260 @@
> +From b10f9a671c66a99b91bd916e62a0c81541094dd6 Mon Sep 17 00:00:00 2001
> +From: Simon Pichugin <[email protected]>
> +Date: Mon, 16 Mar 2026 17:23:11 -0700
> +Subject: [PATCH] Merge commit from fork
> +
> +CVE: CVE-2026-30922
> +Upstream-Status: Backport 
> [https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0]
> +
> +(cherry picked from commit 25ad481c19fdb006e20485ef3fc2e5b3eff30ef0)
> +Signed-off-by: Yogita Urade <[email protected]>
> +---
> + pyasn1/codec/ber/decoder.py     |  10 +++
> + tests/codec/ber/test_decoder.py | 116 ++++++++++++++++++++++++++++++++
> + tests/codec/cer/test_decoder.py |  24 +++++++
> + tests/codec/der/test_decoder.py |  42 ++++++++++++
> + 4 files changed, 192 insertions(+)

Hello,

Thanks for the patch but it does not apply cleanly (surely a conflict
with the other recent CVE fixes):
    ERROR: python3-pyasn1-0.5.1-r0 do_patch: QA Issue: Fuzz detected:

    Applying patch CVE-2026-30922.patch
    patching file pyasn1/codec/ber/decoder.py
    Hunk #1 succeeded at 38 with fuzz 2.
    Hunk #2 succeeded at 1520 (offset 4 lines).
    patching file tests/codec/ber/test_decoder.py
    Hunk #1 succeeded at 2048 (offset 60 lines).
    patching file tests/codec/cer/test_decoder.py
    Hunk #1 succeeded at 389 (offset 25 lines).
    patching file tests/codec/der/test_decoder.py
    Hunk #1 succeeded at 396 (offset 34 lines).

Can you rebase and send a refreshed v2?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246193): 
https://lists.openembedded.org/g/openembedded-core/message/246193
Mute This Topic: https://lists.openembedded.org/mt/120952664/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Yogita Urade -X (yurade - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yogita Urade -X (yurade - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org

Reply via email to