Hello Yoann, Thanks for the feedback.
The upstream fix and its follow-up are kept as separate patches in v2. Since the follow-up is small and self-contained, I have included the backport, as shown in [1]. For reference, the NVD record [2] documents the Pallets Click project’s position regarding the disputed CVE. [1] https://lists.openembedded.org/g/openembedded-core/message/246451 [2] https://nvd.nist.gov/vuln/detail/cve-2026-7246 Best regards, Darsh On Mon, Sep 21, 2026 at 03:26 PM, Yoann Congal wrote: > > On Mon Sep 7, 2026 at 11:26 AM CEST, Darsh Kelaiya -X (dkelaiya - E > INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > >> On Sun, Sep 6, 2026 at 04:46 AM, Yoann Congal wrote: >> >> >>> >>> On Fri Aug 21, 2026 at 6:32 PM CEST, Darsh Kelaiya -X (dkelaiya - E >>> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: >>> >>> >>>> From: Darsh Kelaiya <[email protected]> >>>> >>>> This patch applies the upstream fix for CVE-2026-7246 as referenced >>>> in [2], using the upstream commit identified in [1]. >>>> >>>> The backport also adapts editor regression tests from the upstream >>>> test and documentation follow-up identified in [3]. This follow-up >>>> does not contain an additional production security fix. >>>> >>>> [1] >>>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 >>>> >>>> >>>> [2] >>>> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw >>>> >>>> >>>> [3] >>>> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976 >>>> >>>> >>>> >>>> Signed-off-by: Darsh Kelaiya <[email protected]> >>>> --- >>>> .../python/python3-click/CVE-2026-7246.patch | 245 ++++++++++++++++++ >>>> .../python/python3-click_8.1.7.bb | 5 +- >>>> 2 files changed, 249 insertions(+), 1 deletion(-) >>>> create mode 100644 >>>> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>>> >>>> diff --git >>>> a/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>>> b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>>> new file mode 100644 >>>> index 0000000000..47ee1a551f >>>> --- /dev/null >>>> +++ b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch >>>> @@ -0,0 +1,245 @@ >>>> +From cb30f575b1a251e8698909bca2a443d41dad1824 Mon Sep 17 00:00:00 2001 >>>> +From: Kevin Deldycke <[email protected]> >>>> +Date: Wed, 4 Mar 2026 14:51:58 +0400 >>>> +Subject: [PATCH] Document and fix command string sanitizing with >>>> `shlex.split` >>>> + >>>> +Removes last use of `shell=True` use for command invokation for >>>> defense-in-depth. >>>> +Refs: #1026, #1477 and #2775 >>>> + >>>> +CVE: CVE-2026-7246 >>>> +Upstream-Status: Backport [ >>>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 >>>> >>>> ] >>>> + >>>> +Backport Changes: >>>> +- Click 8.1.7 uses Editor.edit_file(filename), not the newer >>>> + Editor.edit_files(filenames) API. Apply the argv-list change >>>> + to one filename without adding the multi-file API. >>>> +- Adapt editor tests from b96c2601 and follow-up b5529479 to >>> >>> Hello, >>> >>> This commit has both b96c2601 and b5529479 squashed. Please keep >>> upstream backport patches split. >>> >>> Can you send a v2 with as the CVE fix (b96c2601) and its followup >>> (b5529479)? >>> >>> Thanks! >>> >>> -- >>> Yoann Congal >>> Smile ECS >> >> Hi Yoann, >> >> While preparing v2, I noticed that NVD now marks CVE-2026-7246 as disputed >> and states that the Pallets Click project does not consider it a valid >> vulnerability: >> >> https://nvd.nist.gov/vuln/detail/CVE-2026-7246 >> >> However, the published advisory identifies upstream commit b96c2601 as the >> fix: >> >> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw >> >> >> Upstream describes the removal of shell=True as defense-in-depth, so I >> wanted to confirm the preferred handling. Should I replace the backport >> patches with a status entry such as: >> >> CVE_STATUS[CVE-2026-7246] = "disputed: Pallets Click does not consider >> this a valid vulnerability" >> >> Or should I continue with the split v2 backport patches as hardening? > > Hello, > > It depends on the patch complexity: If it is small and easely > understandable let's backport it. If not, we can ignore it but I'd like > to see the Pallets Click project reasonning for disputing it please. > > Thanks! > -- > Yoann Congal > Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246452): https://lists.openembedded.org/g/openembedded-core/message/246452 Mute This Topic: https://lists.openembedded.org/mt/120864409/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
