mbox series

[meta-python,scarthgap,00/13] python3-aiohttp: fix multiple CVEs

Message ID 20260928174323.1810308-1-dkelaiya@cisco.com
Headers show
Series python3-aiohttp: fix multiple CVEs | expand

Message

From: Darsh Kelaiya <dkelaiya@cisco.com>

Backport thirteen upstream aiohttp security fixes to the 3.9.5 recipe on
scarthgap.

The corresponding fixes are available in aiohttp 3.14.0 and 3.14.1.
Carry them as focused backports instead of upgrading the recipe because
the 3.14 release also introduces new APIs, deprecations, and
backward-incompatible behavior outside the security scope.

The individual commits retain the upstream fix provenance and public
advisory references for each CVE.

Testing:
- Applied the thirteen layer commits to the upstream scarthgap baseline.
- Applied all fifteen embedded patches to aiohttp 3.9.5 in series order
  with no conflicts or fuzz.
- Package build and image build validation completed successfully.

Darsh Kelaiya (13):
  python3-aiohttp: fix CVE-2026-34519
  python3-aiohttp: fix CVE-2026-34516
  python3-aiohttp: fix CVE-2026-34517
  python3-aiohttp: fix CVE-2026-34520
  python3-aiohttp: fix CVE-2026-34525
  python3-aiohttp: fix CVE-2026-47265
  python3-aiohttp: fix CVE-2026-50269
  python3-aiohttp: fix CVE-2026-54274
  python3-aiohttp: fix CVE-2026-54275
  python3-aiohttp: fix CVE-2026-54277
  python3-aiohttp: fix CVE-2026-54278
  python3-aiohttp: fix CVE-2026-54279
  python3-aiohttp: fix CVE-2026-54273

 .../python3-aiohttp/CVE-2026-34516.patch    | 356 +++++++
 .../python3-aiohttp/CVE-2026-34517.patch    |  65 ++
 .../python3-aiohttp/CVE-2026-34519.patch    | 638 ++++++++++++
 .../python3-aiohttp/CVE-2026-34520.patch    | 121 +++
 .../python3-aiohttp/CVE-2026-34525_p1.patch | 128 +++
 .../python3-aiohttp/CVE-2026-34525_p2.patch | 331 +++++++
 .../python3-aiohttp/CVE-2026-47265.patch    |  61 ++
 .../python3-aiohttp/CVE-2026-50269.patch    | 166 ++++
 .../python3-aiohttp/CVE-2026-54273_p1.patch | 798 ++++++++++++++++
 .../python3-aiohttp/CVE-2026-54273_p2.patch | 181 ++++
 .../python3-aiohttp/CVE-2026-54274.patch    | 195 ++++
 .../python3-aiohttp/CVE-2026-54275.patch    | 124 +++
 .../python3-aiohttp/CVE-2026-54277.patch    |  96 ++
 .../python3-aiohttp/CVE-2026-54278.patch    | 209 ++++
 .../python3-aiohttp/CVE-2026-54279.patch    | 317 ++++++
 .../python/python3-aiohttp_3.9.5.bb         |  15 +
 16 files changed, 3801 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34516.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34517.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34519.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34520.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34525_p1.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34525_p2.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54273_p1.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54273_p2.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54274.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54275.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54277.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54278.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54279.patch