diff --git a/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch
new file mode 100644
index 0000000000..95670f25be
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch
@@ -0,0 +1,88 @@
+From 4003a6635c9a429de3f64ce967e8322ecbc6e71a Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Bern=C3=A1t=20G=C3=A1bor?= <gaborjbernat@gmail.com>
+Date: Mon, 15 Dec 2025 15:52:12 -0800
+Subject: [PATCH] Fix TOCTOU symlink vulnerability in lock file creation (#461)
+
+CVE: CVE-2025-68146
+Upstream-Status: Backport [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e]
+
+(cherry picked from commit 4724d7f8c3393ec1f048c93933e6e3e6ec321f0e)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ src/filelock/_unix.py    |  2 +-
+ src/filelock/_windows.py | 38 ++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 39 insertions(+), 1 deletion(-)
+
+diff --git a/src/filelock/_unix.py b/src/filelock/_unix.py
+index 4ae1fbe..28d3673 100644
+--- a/src/filelock/_unix.py
++++ b/src/filelock/_unix.py
+@@ -36,7 +36,7 @@ else:  # pragma: win32 no cover
+ 
+         def _acquire(self) -> None:
+             ensure_directory_exists(self.lock_file)
+-            open_flags = os.O_RDWR | os.O_TRUNC
++            open_flags = os.O_RDWR | os.O_TRUNC | os.O_NOFOLLOW
+             if not Path(self.lock_file).exists():
+                 open_flags |= os.O_CREAT
+             fd = os.open(self.lock_file, open_flags, self._context.mode)
+diff --git a/src/filelock/_windows.py b/src/filelock/_windows.py
+index 8db55dc..fe3d45c 100644
+--- a/src/filelock/_windows.py
++++ b/src/filelock/_windows.py
+@@ -11,7 +11,38 @@ from ._api import BaseFileLock
+ from ._util import ensure_directory_exists, raise_on_not_writable_file
+ 
+ if sys.platform == "win32":  # pragma: win32 cover
++    import ctypes
+     import msvcrt
++    from ctypes import wintypes
++
++    # Windows API constants for reparse point detection
++    FILE_ATTRIBUTE_REPARSE_POINT = 0x00000400
++    INVALID_FILE_ATTRIBUTES = 0xFFFFFFFF
++
++    # Load kernel32.dll
++    _kernel32 = ctypes.WinDLL("kernel32", use_last_error=True)
++    _kernel32.GetFileAttributesW.argtypes = [wintypes.LPCWSTR]
++    _kernel32.GetFileAttributesW.restype = wintypes.DWORD
++
++    def _is_reparse_point(path: str) -> bool:
++        """
++        Check if a path is a reparse point (symlink, junction, etc.) on Windows.
++
++        :param path: Path to check
++        :return: True if path is a reparse point, False otherwise
++        :raises OSError: If GetFileAttributesW fails for reasons other than file-not-found
++        """
++        attrs = _kernel32.GetFileAttributesW(path)
++        if attrs == INVALID_FILE_ATTRIBUTES:
++            # File doesn't exist yet - that's fine, we'll create it
++            err = ctypes.get_last_error()
++            if err == 2:  # noqa: PLR2004  # ERROR_FILE_NOT_FOUND
++                return False
++            if err == 3:  # noqa: PLR2004 # ERROR_PATH_NOT_FOUND
++                return False
++            # Some other error - let caller handle it
++            return False
++        return bool(attrs & FILE_ATTRIBUTE_REPARSE_POINT)
+ 
+     class WindowsFileLock(BaseFileLock):
+         """Uses the :func:`msvcrt.locking` function to hard lock the lock file on Windows systems."""
+@@ -19,6 +50,13 @@ if sys.platform == "win32":  # pragma: win32 cover
+         def _acquire(self) -> None:
+             raise_on_not_writable_file(self.lock_file)
+             ensure_directory_exists(self.lock_file)
++
++            # Security check: Refuse to open reparse points (symlinks, junctions)
++            # This prevents TOCTOU symlink attacks (CVE-TBD)
++            if _is_reparse_point(self.lock_file):
++                msg = f"Lock file is a reparse point (symlink/junction): {self.lock_file}"
++                raise OSError(msg)
++
+             flags = (
+                 os.O_RDWR  # open for read and write
+                 | os.O_CREAT  # create file if not exists
+-- 
+2.44.4
+
diff --git a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
index 4d6d19551a..9fa5f95ff1 100644
--- a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
+++ b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
@@ -8,6 +8,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=911690f51af322440237a253d695d19f"
 
 SRC_URI[sha256sum] = "d13f466618bfde72bd2c18255e269f72542c6e70e7bac83a0232d6b1cc5c8cf4"
 
+SRC_URI += "file://CVE-2025-68146.patch \
+           "
+
 BBCLASSEXTEND = "native nativesdk"
 inherit pypi python_hatchling
 
