python3-git: fix CVE-2026-42284

This patch applies the upstream 3.1.47 backport for
CVE-2026-42284. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] da545232d0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284

(From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c)

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Darsh Kelaiya
2026-08-19 10:10:22 -07:00
committed by Richard Purdie
parent ab57645a22
commit 1e39c2a5e3
2 changed files with 39 additions and 0 deletions

View File

@@ -0,0 +1,37 @@
From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001
From: "GPT 5.4" <codex@openai.com>
Date: Tue, 21 Apr 2026 09:30:29 +0800
Subject: [PATCH] Make sure that multi-options are checked after splitting them
with `shlex`
CVE: CVE-2026-42284
Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
Backport Changes:
- Omit regression tests because the Scarthgap PyPI source
archive does not include the upstream test suite.
Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
git/repo/base.py | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/git/repo/base.py b/git/repo/base.py
index f5069dbf..92ace3a0 100644
--- a/git/repo/base.py
+++ b/git/repo/base.py
@@ -1271,8 +1271,8 @@ class Repo:
Git.check_unsafe_protocols(str(url))
if not allow_unsafe_options:
Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
- if not allow_unsafe_options and multi_options:
- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
+ if not allow_unsafe_options and multi:
+ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
proc = git.clone(
multi,
--
2.35.6

View File

@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
"
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
DEPENDS += " python3-gitdb"