On Fri Oct 2, 2026 at 2:45 PM CEST, Peter Marko wrote: > We should upgrade python version instead of picking patches included in > latest tag. > https://github.com/python/cpython/releases/tag/v3.12.15
Agreed. @João, python is one of the rare recipes we'd rather upgrade than patch with backports on stable. As long as it is maintained upstream, of course. > > I'll probably give it a try over weekend. Thanks Peter! > > Peter > >> -----Original Message----- >> From: [email protected] <openembedded- >> [email protected]> On Behalf Of Joao Marcos Costa via >> lists.openembedded.org >> Sent: Friday, October 2, 2026 2:40 PM >> To: [email protected] >> Cc: [email protected]; [email protected]; João Marcos Costa >> (Schneider Electric) <[email protected]> >> Subject: [OE-core] [scarthgap][PATCH] python3: fix CVE-2026-19445 >> >> From: João Marcos Costa (Schneider Electric) <[email protected]> >> >> This critical vulnerability [1] was fixed originally on 3.14, and then >> backported to >> 3.12 through a PR (already merged) [2]: >> >> "[3.12] gh-156293: Use-after-free for server-side SSLContext with >> sni_callback" >> >> Backport the fix to oe-core's v3.12.14. >> >> [1] https://security-tracker.debian.org/tracker/CVE-2026-19445 >> [2] https://github.com/python/cpython/pull/158517 >> >> Signed-off-by: João Marcos Costa (Schneider Electric) >> <[email protected]> >> --- >> .../python/python3/CVE-2026-19445.patch | 265 ++++++++++++++++++ >> .../python/python3_3.12.14.bb | 1 + >> 2 files changed, 266 insertions(+) >> create mode 100644 meta/recipes-devtools/python/python3/CVE-2026- >> 19445.patch -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247121): https://lists.openembedded.org/g/openembedded-core/message/247121 Mute This Topic: https://lists.openembedded.org/mt/121545671/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
