mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
python3-git: fix CVE-2026-42284
This patch applies the upstream 3.1.47 backport for
CVE-2026-42284. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] da545232d0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284
(From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
ab57645a22
commit
1e39c2a5e3
@@ -0,0 +1,37 @@
|
||||
From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001
|
||||
From: "GPT 5.4" <codex@openai.com>
|
||||
Date: Tue, 21 Apr 2026 09:30:29 +0800
|
||||
Subject: [PATCH] Make sure that multi-options are checked after splitting them
|
||||
with `shlex`
|
||||
|
||||
CVE: CVE-2026-42284
|
||||
Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
|
||||
|
||||
Backport Changes:
|
||||
- Omit regression tests because the Scarthgap PyPI source
|
||||
archive does not include the upstream test suite.
|
||||
|
||||
Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
|
||||
(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
|
||||
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
|
||||
---
|
||||
git/repo/base.py | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/git/repo/base.py b/git/repo/base.py
|
||||
index f5069dbf..92ace3a0 100644
|
||||
--- a/git/repo/base.py
|
||||
+++ b/git/repo/base.py
|
||||
@@ -1271,8 +1271,8 @@ class Repo:
|
||||
Git.check_unsafe_protocols(str(url))
|
||||
if not allow_unsafe_options:
|
||||
Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
|
||||
- if not allow_unsafe_options and multi_options:
|
||||
- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
|
||||
+ if not allow_unsafe_options and multi:
|
||||
+ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
|
||||
|
||||
proc = git.clone(
|
||||
multi,
|
||||
--
|
||||
2.35.6
|
||||
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
|
||||
|
||||
inherit pypi python_setuptools_build_meta
|
||||
|
||||
SRC_URI += "file://CVE-2026-42284.patch \
|
||||
"
|
||||
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
|
||||
|
||||
DEPENDS += " python3-gitdb"
|
||||
|
||||
Reference in New Issue
Block a user