python3-git: fix CVE-2026-44244

This patch applies the upstream 3.1.49 backport for
CVE-2026-44244. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2]. The individual
backported commits are referenced in [3] and [4].

[1] b049a13105
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-44244
[3] c417af469f
[4] 8e24503b42

(From OE-Core rev: 9aaa23d4f6c04049fcdb532f6a83c654e8e6e15d)

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Darsh Kelaiya
2026-08-19 10:10:25 -07:00
committed by Richard Purdie
parent 96afd71237
commit 7be1953871
3 changed files with 136 additions and 0 deletions

View File

@@ -15,6 +15,8 @@ inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
file://CVE-2026-44243_p1.patch \
file://CVE-2026-44243_p2.patch \
file://CVE-2026-44244_p1.patch \
file://CVE-2026-44244_p2.patch \
"
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"