From patchwork Wed Aug 19 17:10:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 95825 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D78DDC5DF89 for ; Wed, 19 Aug 2026 17:10:43 +0000 (UTC) Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1401.1787159433159982433 for ; Wed, 19 Aug 2026 10:10:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=CTAmJM8d; spf=pass (domain: cisco.com, ip: 173.37.142.95, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=2988; q=dns/txt; s=iport01; t=1787159433; x=1788369033; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=B7t/7APYlzEzcHAC9/Tky3aR0gmT0fnWPIcGJ5KWGus=; b=CTAmJM8dWTKEikS5pTJKCWgEJ0qBLKnTaWLbGMFkxRtOpY39E4K5Ka4C WqEKn3d8I5JCuCdyd6rlcJNe71qIOgZboRzjsOWu/JvSh3gMesab6hvDU QSuH+5zXKzgW2Kj+y+7IcITrcIUNgnZwnHIwsTSVP2kkEf2XhXk7GAy09 juO0Er2LFXeFI0wgCzvsiX3u+X1xlQleO2u7wo3OkjcjAyBF90V3KoCwA LaRuCCpsmGq0/Q6qnsddsssoKRD2KgQ4hh4HojiCeJ+BWTQ4At5QlK3L/ lwloWj0f1kZisL5KYfNuGGk1coSdaNMSrtnE7DEKkCrDPHS8yB/x0MHW3 w==; X-CSE-ConnectionGUID: JYx//Yy8SayGZ8llYTSM9A== X-CSE-MsgGUID: t1xxywndThC99cuopYWMfg== X-IPAS-Result: A0BEAgD84oVq/48QJK1aglmCV3ReQ0m0aIF+DwEBAQ9EDQQBAYQ/Ro1tAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhloBAgE1ARgBLSwDAQJaIyGDAgGCOgM3AxHEGoIsgQGDKAE/AkNQ2EsQglUBCxQBgTiFP4giXRgBhHwnGxuBcoR+gQWBXAEBgi2FeASCIoEMgVqBLZA8SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQ3Ixk2fIEJXoErKmEBEheBCYIKAoJwggYCAUlFDgkMCxgNSBEsNxQZBD5uB45KIIF+TYEOASuoIqEPCiiDdowhlToaM4VbpRELmH2OCpZQhGmBaDyBRwsHcBU7gmcJShkPjjiDa4F/g2XGVScyAgkyAQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:9VHcsKIQigea5jgAFE+Rh5QlxSXFcZb7ZxGr2PjKsXjdYENS12ZRm jBODT3XPKvbZmqhf951aIS0oRsH65DVzYQ2SlMd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZsCCSa/kvxWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9i2clajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1MPVFxerwJqt1+EE58p fgcGQw2S0Gq0rfeLLKTEoGAh+wqKM3teYdasXZ6wHSBU7AtQIvIROPB4towMDUY358VW62AI ZNHL2MzN3wsYDUXUrsTIJ49keOhh2j2WzZZs1mS46Ew5gA/ySQhieS1bISEK4fiqcN9gh+It nPZ+WjFAjpLZdeCziK0zVeiibqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYVX95WVul/4waXx++MvUCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXPIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:jIUI864qfcGCXJ+1OQPXwP7XdLJyesId70hD6qm+c3Nom6uj5q WTdZsgtCMc5Ax9ZJhCo6HjBEDjexPhHPdOiOF7V4tKNzOJhILHFu1fBPPZsl7dMhy70PJB3q F9dKU7ItjxAV9myfve2mCDYrIdKB3tytHPuQ8YpE0dKj1XVw== X-Talos-CUID: 9a23:+RdshGzhydO6mtNPMH4JBgU2K9BiNUzMnEzZMmCKWWJteYGubA65rfY= X-Talos-MUID: 9a23:kQFkoA7h1wXjX33YnTF8UZ4Nxox0urS+GV8LnakGkJjVPjF3IwaiqTq4F9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,231,1779148800"; d="scan'208";a="814046993" Received: from alln-l-core-06.cisco.com ([173.36.16.143]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 Aug 2026 17:10:32 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-06.cisco.com (Postfix) with ESMTPS id 0D58E180006C4; Wed, 19 Aug 2026 17:10:32 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id 9E985CCA79B; Wed, 19 Aug 2026 10:10:31 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: Darsh Kelaiya Subject: [OE-core][scarthgap][PATCH 1/4] python3-git: fix CVE-2026-42284 Date: Wed, 19 Aug 2026 10:10:22 -0700 Message-ID: <20260819171026.750280-1-dkelaiya@cisco.com> X-Mailer: git-send-email 2.44.4 MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: alln-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 19 Aug 2026 17:10:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243774 From: Darsh Kelaiya This patch applies the upstream 3.1.47 backport for CVE-2026-42284. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/gitpython-developers/GitPython/commit/da545232d0401fb9fb7660f9ff67991996674dda [2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284 Signed-off-by: Darsh Kelaiya --- .../python/python3-git/CVE-2026-42284.patch | 37 +++++++++++++++++++ .../python/python3-git_3.1.42.bb | 2 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch new file mode 100644 index 0000000000..456a455e53 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch @@ -0,0 +1,37 @@ +From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001 +From: "GPT 5.4" +Date: Tue, 21 Apr 2026 09:30:29 +0800 +Subject: [PATCH] Make sure that multi-options are checked after splitting them + with `shlex` + +CVE: CVE-2026-42284 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0) +Signed-off-by: Darsh Kelaiya +--- + git/repo/base.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/git/repo/base.py b/git/repo/base.py +index f5069dbf..92ace3a0 100644 +--- a/git/repo/base.py ++++ b/git/repo/base.py +@@ -1271,8 +1271,8 @@ class Repo: + Git.check_unsafe_protocols(str(url)) + if not allow_unsafe_options: + Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options) +- if not allow_unsafe_options and multi_options: +- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options) ++ if not allow_unsafe_options and multi: ++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options) + + proc = git.clone( + multi, +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index 19885a58c7..c294b23112 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta +SRC_URI += "file://CVE-2026-42284.patch \ + " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" DEPENDS += " python3-gitdb" From patchwork Wed Aug 19 17:10:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 95826 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E8E34C5DF88 for ; Wed, 19 Aug 2026 17:10:43 +0000 (UTC) Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1401.1787159433159982433 for ; Wed, 19 Aug 2026 10:10:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=k1UC7W1r; spf=pass (domain: cisco.com, ip: 173.37.142.95, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=8370; q=dns/txt; s=iport01; t=1787159433; x=1788369033; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=uUnlJE8srBk0VgUm7JxfsiVRWs1FFcZx/Xi3JalLWNM=; b=k1UC7W1ryy5ZwszdbWfg5c8kQ6ftvpdOgjyifUMAcrhgZXK8adTum2ZD kRO7nNBXpQkn9LnFZO8bkLf3qdsCIcwl6uOzazypm1cEn05QfB1eKvUNB 9eaXe0vZoEkrfAqk0QOTB8ymgxiu9iQFx9B/FZwtQol3hs2bDlhlkvOPl qfiRHcXQ1xkEzngwDHiXElrIsg6HhjpbWvpT6NrQR3bZfPLxlPvZh4TJA uS/vuJ0CEN+fvVfY6N9MQJIk5VTzXmWFwkD+QLseyiz0z+Ld3CkQcxRBv /aGHM74Z63FbdMpjaZsxy4OdUovMoNo6SUsowDBk+LwrQ+E9wRTMfSd96 Q==; X-CSE-ConnectionGUID: /JOGz9UfR/irLNfbusQhrg== X-CSE-MsgGUID: njhUEpR5SrKTP5XfhTgwcQ== X-IPAS-Result: A0BIAgD84oVq/5AQJK1aglmCV3ReQ0kDlkcDnhuBfg8BAQEPRA0EAQGEP0YCjWsCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgECAQMnCwEYAS0QHAMBAi8rIwgZgwIBgnQDEcQagXkzgQGDKAE/AkNQ2zABCxQBgTiFP4giXRgBRIQ4JxsbgXKBFYNpgQWBXAEBgUyGWQSCInoSgVqBLZA8SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQ3Ixk2fIEJXoErKmEBEheBCYIKAoJwggYCAUlFDgkMCxgNSBEsNxQZBD5uB45KIIF+LSABgQ0BCiGBTaQ0giGhDwoog3aMIZU6GjOqbAuYfY4KlTuBFYRpgWg8gUcLB3AVO4JnCUoZD444g2uBf4NlxlUnMgIGAzIBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:tl4/6a6iOul2ctFu9evmbQxRtG7GchMFZxGqfqrLsTDasY5as4F+v jFKWj3SMvaCYGrwfIokPovk/UgPv8KHmtcxT1c5/i83Zn8b8sCt6fZ1gavT04J+CuWZESqLO u1HMoGowPgcFyGa/lH2dOC98RGQ7InQLpLkEunIJyttcgFtTSYlmHpLlvUw6mJSqYDR7zil5 5Wo/qUzBHf/g2QqajJNuvrawP9SlK2aVA0w7wRWic9j5Dcyp1FNZLoDKKe4KWfPQ4U8NoaSW +bZwbilyXjS9hErB8nNuu6TnpoiG+O60aCm0xK6aoD66vRwjnVaPpUTaJLwXXxqZwChxLid/ jniWauYEm/FNoWU8AgUvoIx/ytWZcWq85efSZSzXFD6I0DuKxPRL/tS4E4eeq8/1fQmPG90s v0CDBYDZA2YvuKsz+fuIgVsrpxLwMjDNYcbvDRkiDreF/tjGc+FSKTR7tge1zA17ixMNa+BP IxCN3w2MlKZP0En1lQ/UPrSmM+khXT7ejxJoXqepLE85C7YywkZPL3FYIOJIoDVHZ0J9qqej mTE/1nUGitHD8a89QLYwnysuuDQlhquDer+E5X9rJaGmma7wXQeDhATX1a3rfS1z0W5Qd93L 00P5jFoqrA/8kGuRNTxUxC05nmesXYht8F4Guk+7kSJj6HT+QvcXjdCRT9aY9tgv8gzLdA36 mK0cxrSLWQHmNWopbi1qt94cRva1fApEFI/ IronPort-HdrOrdr: A9a23:qmmqXaN7XtvvW8BcTuOjsMiBIKoaSvp037Dk7S9MoHtuA6ulfq +V/cjzuSWYtN9VYgBDpTniAtjlfZq/z/5ICOAqVN/INjUO+lHYSb2KhrGN/9SPIUHDH5ZmpM RdWpk7LsHsBl5nisu/ygy5H9E8hOSjysmT9IHjJ7MHd3ATV0mmhD0JczqmLg== X-Talos-CUID: 9a23:RWuJbmHMdzCM78EaqmIg1mk7CJEYfEeazW30BUGyFH1QSKeaHAo= X-Talos-MUID: 9a23:FrDPZA8tqUWPca4O54V9hleQf8Fq45mDEHpQqo8lh/HZBSJwBziChw3iFw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,231,1779148800"; d="scan'208";a="814047004" Received: from alln-l-core-07.cisco.com ([173.36.16.144]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 Aug 2026 17:10:32 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-07.cisco.com (Postfix) with ESMTPS id 106C1180001E6; Wed, 19 Aug 2026 17:10:32 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id A2D6ACCD9B2; Wed, 19 Aug 2026 10:10:31 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: Darsh Kelaiya Subject: [OE-core][scarthgap][PATCH 2/4] python3-git: fix CVE-2026-42215 Date: Wed, 19 Aug 2026 10:10:23 -0700 Message-ID: <20260819171026.750280-2-dkelaiya@cisco.com> X-Mailer: git-send-email 2.44.4 In-Reply-To: <20260819171026.750280-1-dkelaiya@cisco.com> References: <20260819171026.750280-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: alln-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 19 Aug 2026 17:10:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243777 From: Darsh Kelaiya This patch applies the upstream 3.1.47 backport for CVE-2026-42215. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3], [4], and [5]. [1] https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-42215 [3] https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6 [4] https://github.com/gitpython-developers/GitPython/commit/9aed7cf8c20f69effcfcf7ebef09f312f73ab826 [5] https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8 Signed-off-by: Darsh Kelaiya --- .../python3-git/CVE-2026-42215_p1.patch | 61 +++++++++++++++++++ .../python3-git/CVE-2026-42215_p2.patch | 31 ++++++++++ .../python3-git/CVE-2026-42215_p3.patch | 47 ++++++++++++++ .../python/python3-git_3.1.42.bb | 3 + 4 files changed, 142 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p3.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch new file mode 100644 index 0000000000..9d5f10c694 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch @@ -0,0 +1,61 @@ +From 341a49149a37762e12b10eb70605b54f4abfb54d Mon Sep 17 00:00:00 2001 +From: w +Date: Mon, 20 Apr 2026 23:29:50 -0400 +Subject: [PATCH] Block unsafe underscored git kwargs / Fix for + GHSA-rpm5-65cw-6hj4 + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +(cherry picked from commit 142195888e713542189533a52cdfc333f05c3af6) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 21 +++++++++++++-------- + 1 file changed, 13 insertions(+), 8 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index f58e6df5..874acb43 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -540,6 +540,12 @@ class Git(LazyMixin): + f"The `{protocol}::` protocol looks suspicious, use `allow_unsafe_protocols=True` to allow it." + ) + ++ @classmethod ++ def _canonicalize_option_name(cls, option: str) -> str: ++ """Normalize an option or kwarg name for unsafe-option checks.""" ++ option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] ++ return dashify(option_name) ++ + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: + """Check for unsafe options. +@@ -547,15 +553,14 @@ class Git(LazyMixin): + Some options that are passed to `git ` can be used to execute + arbitrary commands, this are blocked by default. + """ +- # Options can be of the form `foo` or `--foo bar` `--foo=bar`, +- # so we need to check if they start with "--foo" or if they are equal to "foo". +- bare_unsafe_options = [option.lstrip("-") for option in unsafe_options] ++ # Options can be of the form `foo`, `--foo`, `--foo bar`, or `--foo=bar`. ++ canonical_unsafe_options = {cls._canonicalize_option_name(option): option for option in unsafe_options} + for option in options: +- for unsafe_option, bare_option in zip(unsafe_options, bare_unsafe_options): +- if option.startswith(unsafe_option) or option == bare_option: +- raise UnsafeOptionError( +- f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." +- ) ++ unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option)) ++ if unsafe_option is not None: ++ raise UnsafeOptionError( ++ f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." ++ ) + + class AutoInterrupt: + """Process wrapper that terminates the wrapped process on finalization. +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch new file mode 100644 index 0000000000..93a5964221 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch @@ -0,0 +1,31 @@ +From aff283771565fc5f5fb41d4f06fb9ad5a9926c18 Mon Sep 17 00:00:00 2001 +From: w +Date: Mon, 20 Apr 2026 23:43:59 -0400 +Subject: [PATCH] linter fix + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/9aed7cf8c20f69effcfcf7ebef09f312f73ab826] + +(cherry picked from commit 9aed7cf8c20f69effcfcf7ebef09f312f73ab826) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 4 +--- + 1 file changed, 1 insertion(+), 3 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index 874acb43..69756216 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -558,9 +558,7 @@ class Git(LazyMixin): + for option in options: + unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option)) + if unsafe_option is not None: +- raise UnsafeOptionError( +- f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." +- ) ++ raise UnsafeOptionError(f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.") + + class AutoInterrupt: + """Process wrapper that terminates the wrapped process on finalization. +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p3.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p3.patch new file mode 100644 index 0000000000..cef3fe6b01 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p3.patch @@ -0,0 +1,47 @@ +From 3385ff27397b58288d922838e8d2eae87d7534fd Mon Sep 17 00:00:00 2001 +From: w +Date: Tue, 21 Apr 2026 12:03:20 -0400 +Subject: [PATCH] git.cmd: harden unsafe option canonicalization and isolate + push test cases + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8] + +Backport Changes: +- Omit regression test updates because the Scarthgap PyPI + source archive does not include the upstream test suite. + +(cherry picked from commit 43d92dec4683568d11495956dd556161f17c3ea8) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index 69756216..73b4c052 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -542,9 +542,18 @@ class Git(LazyMixin): + + @classmethod + def _canonicalize_option_name(cls, option: str) -> str: +- """Normalize an option or kwarg name for unsafe-option checks.""" +- option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] +- return dashify(option_name) ++ """Return the option name used for unsafe-option checks. ++ ++ Examples: ++ ``"--upload-pack=/tmp/helper"`` -> ``"upload-pack"`` ++ ``"upload_pack"`` -> ``"upload-pack"`` ++ ``"--config core.filemode=false"`` -> ``"config"`` ++ """ ++ option_name = option.lstrip("-").split("=", 1)[0] ++ option_tokens = option_name.split(None, 1) ++ if not option_tokens: ++ return "" ++ return dashify(option_tokens[0]) + + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index c294b23112..4102a2273a 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -13,6 +13,9 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ + file://CVE-2026-42215_p1.patch \ + file://CVE-2026-42215_p2.patch \ + file://CVE-2026-42215_p3.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" From patchwork Wed Aug 19 17:10:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 95824 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C0913C5DF81 for ; Wed, 19 Aug 2026 17:10:43 +0000 (UTC) Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1355.1787159433250376326 for ; Wed, 19 Aug 2026 10:10:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=fsL1drvT; spf=pass (domain: cisco.com, ip: 173.37.142.91, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=10806; q=dns/txt; s=iport01; t=1787159433; x=1788369033; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=TNVFR/Rki+Grv7zspouO4JXrR1FhDf5hu2AYraVl5+w=; b=fsL1drvTlun9gN+PEkL+VqiN9AXQ3RCeqItJqn2snPW7VrXlYnXQehWC 8bxdWLCQNvyHbrjJXxn/xqw7iULimNOguiUiXWKiZL2N2BDMVrrVf9eJU wuPJyjzE9hya3zXG0X6ECrzROYnZ6JADgwB6g+MCX6vqMYA6KuQYK9RMl aUu7+9xmhkgY1NHa4h5lEz/vXxtUsRxXmGKyNM5d6/78W5gDVfQg4Yfrp kP3LKnbRIkTm50U9jloO+i3RTBB/zFkPPkqQFEcJ0mpJqkKxrffpjrYRA UNMHLaLf4GIFxrAEUg4bN0PdXE9WEOB/1wvZZZmEB6tQCc47Snt1aM4eb Q==; X-CSE-ConnectionGUID: Ar8H2QKmRIaVU6h3f3S8qQ== X-CSE-MsgGUID: 04QEhxsfS5Wy/83NXo2D8w== X-IPAS-Result: A0BIAgAm4oVq/44QJK1aglmCV3ReQ0mWSgOeG4F+DwEBAQ9EDQQBAYQ/RgKNawImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAycLARgBLRAcAwECLysjCBmDAgGCOgM3AxHEAoF5M4EBgygBPwJDUNhLEIJVAQsUAYE4hT+IIl0YAUSCVYFjJxsbgXKECHaBBYEyKgEBgSeGfgSCInoSgVqBLZA6SIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQ3Ixk2fIEJXoErKmEBEheBCYIKAoJwggYCAUlFDgkLCxgNSBEsNxQZBD5uB45JIIFZJU10BxMBByQEEwtqFCMCOBIEOwOTEAqQFoIhoQ8KKIN2jCGVOhozhVulEQuYfY4KiQ+MJSkLaIRpgWg8gUcLB3AVO4JnCUoZD444g2uBf4JRgRTGVScyAgkyAQEHAgcOAwuBaJAAAiYEA29gAQE IronPort-Data: A9a23:Nw3xy6vUJ+MbJhs93KI8cuOpjOfnVABfMUV32f8akzHdYApBsoF/q tZmKWGPbPuDamSme99waoS+8kgEvsWBz9ExSQU/rHwwQiIbgMeUXt7xwmUckM+xwmwvaGo9s q3yv/GZdJhcokf0/0nrav666yEgiclkf5KkYMbcICd9WAR4fykojBNnioYRj5Vh6TSDK1vlV eja/YuFZTdJ5xYuajhKs/La+Us21BjPkGpwUmIWNKgjUGD2zxH5PLpHTYmtIn3xRJVjH+LSb 47r0LGj82rFyAwmA9Wjn6yTWhVirmn6ZFXmZtJ+AsBOszAazsAA+v9T2Mk0NS+7vw60c+VZk 72hg3AfpTABZcUgkMxFO/VR/roX0aduoNcrKlDn2SCfItGvn3bEm51T4E8K0YIw0/wnITt31 vkiCTkzU06D3Ozt++Kic7w57igjBJGD0II3s3Vky3TdSP0hW52GG/iM7t5D1zB2jcdLdRrcT 5NGMnw0MlKZPVsWZg1/5JEWxI9EglHzcDBcoVOErII84nPYy0p6172F3N/9KoXRHZsMxxrGz o7A1zylOzwaJMeR8me64zX83cn/mnnXCJ1HQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS4QWJzO/Qpg2eHGVBFmMHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289lte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:zG8ou6nXniv+UJPD27aiiLAXPjfpDfIO3DAbv31ZSRFFG/FwWf rAoB19726StN9/YhAdcLy7VZVoBEmsl6KdgrNhWYtKPjOHhILAFugLhuHfKn/bakjDH4Vmu5 uIHZITNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAH0++8YTzranGfg2J9dOMEKK Y= X-Talos-CUID: 9a23:rwOwFWmaZB+MAQaTlVSvUo01RuXXOVTHnFeKGmy9M0dgdoDLSQSeo5g0ivM7zg== X-Talos-MUID: 9a23:0y0S9ARfXNAL6JbjRXS02AhPNNdz7Z/zN1FKwc4gi87eGXxvbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,231,1779148800"; d="scan'208";a="813061146" Received: from alln-l-core-05.cisco.com ([173.36.16.142]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 Aug 2026 17:10:32 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-05.cisco.com (Postfix) with ESMTPS id 1536B180004AA; Wed, 19 Aug 2026 17:10:32 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id AB8D6CD02B9; Wed, 19 Aug 2026 10:10:31 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: Darsh Kelaiya Subject: [OE-core][scarthgap][PATCH 3/4] python3-git: fix CVE-2026-44243 Date: Wed, 19 Aug 2026 10:10:24 -0700 Message-ID: <20260819171026.750280-3-dkelaiya@cisco.com> X-Mailer: git-send-email 2.44.4 In-Reply-To: <20260819171026.750280-1-dkelaiya@cisco.com> References: <20260819171026.750280-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: alln-l-core-05.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 19 Aug 2026 17:10:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243776 From: Darsh Kelaiya This patch applies the upstream 3.1.48 backport for CVE-2026-44243. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3] and [4]. [1] https://github.com/gitpython-developers/GitPython/commit/dbfa26476445169cdc9d64a539ba6959fd0a2643 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-44243 [3] https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190 [4] https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6 Signed-off-by: Darsh Kelaiya --- .../python3-git/CVE-2026-44243_p1.patch | 136 ++++++++++++++++++ .../python3-git/CVE-2026-44243_p2.patch | 86 +++++++++++ .../python/python3-git_3.1.42.bb | 2 + 3 files changed, 224 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch new file mode 100644 index 0000000000..6c9af542b5 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch @@ -0,0 +1,136 @@ +From fcd8d016816696780c0dc96dacbe48fc10df80f6 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:17:31 +0800 +Subject: [PATCH] prevent out-of-repo access when manipulating references. + +This previously made it possible to create, modify and delete files outside outside +of the repository, which is a problem if inputs aren't trusted. + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 25ba54dd3fb374b8fade7de4be1ac2ac84722190) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 2 +- + git/refs/remote.py | 5 +++-- + git/refs/symbolic.py | 37 +++++++++++++++++++++++++++++++------ + 3 files changed, 35 insertions(+), 9 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index e45798d8..29293f4a 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -204,7 +204,7 @@ class RefLog(List[RefLogEntry], Serializable): + file though. + :param ref: SymbolicReference instance + """ +- return osp.join(ref.repo.git_dir, "logs", to_native_path(ref.path)) ++ return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + + @classmethod + def iter_entries(cls, stream: Union[str, "BytesIO", mmap]) -> Iterator[RefLogEntry]: +diff --git a/git/refs/remote.py b/git/refs/remote.py +index 59d02a75..e50c54eb 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -64,12 +64,13 @@ class RemoteReference(Head): + # are generally ignored in the refs/ folder. We don't though + # and delete remainders manually. + for ref in refs: ++ cls._check_ref_name_valid(ref.path) + try: +- os.remove(os.path.join(repo.common_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: + pass + try: +- os.remove(os.path.join(repo.git_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.git_dir, ref.path)) + except OSError: + pass + # END for each ref +diff --git a/git/refs/symbolic.py b/git/refs/symbolic.py +index 31f959ac..d5c18290 100644 +--- a/git/refs/symbolic.py ++++ b/git/refs/symbolic.py +@@ -109,6 +109,32 @@ class SymbolicReference: + def abspath(self) -> PathLike: + return join_path_native(_git_dir(self.repo, self.path), self.path) + ++ @staticmethod ++ def _get_validated_path(base: PathLike, path: PathLike) -> str: ++ path = os.fspath(path) ++ base_path = os.path.realpath(os.fspath(base)) ++ abs_path = os.path.realpath(os.path.join(base_path, path)) ++ try: ++ common_path = os.path.commonpath([base_path, abs_path]) ++ except ValueError as e: ++ raise ValueError("Reference path %r escapes the repository" % path) from e ++ if os.path.normcase(common_path) != os.path.normcase(base_path): ++ raise ValueError("Reference path %r escapes the repository" % path) ++ return abs_path ++ ++ @classmethod ++ def _get_validated_ref_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a ref after validating it.""" ++ cls._check_ref_name_valid(path) ++ ref_path = os.fspath(path) ++ return cls._get_validated_path(_git_dir(repo, ref_path), ref_path) ++ ++ @classmethod ++ def _get_validated_reflog_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a reflog after validating it.""" ++ cls._check_ref_name_valid(path) ++ return cls._get_validated_path(os.path.join(repo.git_dir, "logs"), path) ++ + @classmethod + def _get_packed_refs_path(cls, repo: "Repo") -> str: + return os.path.join(repo.common_dir, "packed-refs") +@@ -442,7 +468,7 @@ class SymbolicReference: + # END handle non-existing + # END retrieve old hexsha + +- fpath = self.abspath ++ fpath = self._get_validated_ref_path(self.repo, self.path) + assure_directory_exists(fpath, is_file=True) + + lfd = LockedFD(fpath) +@@ -571,7 +597,7 @@ class SymbolicReference: + Alternatively the symbolic reference to be deleted. + """ + full_ref_path = cls.to_full_path(path) +- abs_path = os.path.join(repo.common_dir, full_ref_path) ++ abs_path = cls._get_validated_ref_path(repo, full_ref_path) + if os.path.exists(abs_path): + os.remove(abs_path) + else: +@@ -635,9 +661,8 @@ class SymbolicReference: + corresponding object and a detached symbolic reference will be created + instead. + """ +- git_dir = _git_dir(repo, path) + full_ref_path = cls.to_full_path(path) +- abs_ref_path = os.path.join(git_dir, full_ref_path) ++ abs_ref_path = cls._get_validated_ref_path(repo, full_ref_path) + + # Figure out target data. + target = reference +@@ -724,8 +749,8 @@ class SymbolicReference: + if self.path == new_path: + return self + +- new_abs_path = os.path.join(_git_dir(self.repo, new_path), new_path) +- cur_abs_path = os.path.join(_git_dir(self.repo, self.path), self.path) ++ new_abs_path = self._get_validated_ref_path(self.repo, new_path) ++ cur_abs_path = self._get_validated_ref_path(self.repo, self.path) + if os.path.isfile(new_abs_path): + if not force: + # If they point to the same file, it's not an error. +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch new file mode 100644 index 0000000000..e14c284d12 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch @@ -0,0 +1,86 @@ +From 2d1f681978b51ffff0db57cf89b0bcd6bffc7418 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:30:41 +0800 +Subject: [PATCH] address review feedback and CI failures + +Consolidate follow-up fixes from review and CI: + +- fix lint and mypy issues in reference log path handling +- validate remote reference paths before invoking git branch deletion +- add symlink escape coverage where realpath resolves symlinks +- ensure temporary test repositories release git resources during cleanup + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6] + +Backport Changes: +- Keep the 3.1.42 docstring layout and path coercion while + applying upstream validation documentation and return type. +- Omit regression test updates because the Scarthgap PyPI + source archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 4af8463cca31c2369312fcaa5309dfc30756c7b6) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 3 ++- + git/refs/remote.py | 4 +++- + git/util.py | 2 +- + 3 files changed, 6 insertions(+), 3 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index 29293f4a..eef525e7 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -21,7 +21,6 @@ from git.util import ( + file_contents_ro_filepath, + ) + +-import os.path as osp + + + # typing ------------------------------------------------------------------ +@@ -203,6 +202,8 @@ class RefLog(List[RefLogEntry], Serializable): + instance would be found. The path is not guaranteed to point to a valid + file though. + :param ref: SymbolicReference instance ++ :raise ValueError: ++ If `ref.path` is invalid or escapes the repository's reflog directory. + """ + return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + +diff --git a/git/refs/remote.py b/git/refs/remote.py +index e50c54eb..70eada81 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -59,12 +59,14 @@ class RemoteReference(Head): + kwargs are given for comparability with the base class method as we + should not narrow the signature. + """ ++ for ref in refs: ++ cls._check_ref_name_valid(ref.path) ++ + repo.git.branch("-d", "-r", *refs) + # The official deletion method will ignore remote symbolic refs - these + # are generally ignored in the refs/ folder. We don't though + # and delete remainders manually. + for ref in refs: +- cls._check_ref_name_valid(ref.path) + try: + os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: +diff --git a/git/util.py b/git/util.py +index 03d62ffc..5a136d18 100644 +--- a/git/util.py ++++ b/git/util.py +@@ -272,7 +272,7 @@ def join_path(a: PathLike, *p: PathLike) -> PathLike: + + if os.name == "nt": + +- def to_native_path_windows(path: PathLike) -> PathLike: ++ def to_native_path_windows(path: PathLike) -> str: + path = str(path) + return path.replace("/", "\\") + +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index 4102a2273a..cbc1be8771 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -16,6 +16,8 @@ SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-42215_p1.patch \ file://CVE-2026-42215_p2.patch \ file://CVE-2026-42215_p3.patch \ + file://CVE-2026-44243_p1.patch \ + file://CVE-2026-44243_p2.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" From patchwork Wed Aug 19 17:10:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 95823 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 72A7CC5DF85 for ; Wed, 19 Aug 2026 17:10:43 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1402.1787159433344224866 for ; Wed, 19 Aug 2026 10:10:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=DSaA19Jh; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=7436; q=dns/txt; s=iport01; t=1787159433; x=1788369033; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=iUcttlWSW+cCGaFQyLb4Y2xDfVcncDHYm1IRdW5IE3w=; b=DSaA19JhzZDAQIoMLMuF/guiiSeF+aEHM/Y7eO166W7Hjnzxw44nc82s Sq47m14L/wQqfjzDRZYGSUVreGLKR/MaJ2KklKEdUIj4kr9+DaoNkLzyE Du8f26nzTxMIWMGBsDpGJET9S2yIgEliU1a/zj8WNaOfP/4C6dEJdjjqU gRvCZCUojirsuRxCv03N12CpeIfaX15DeQW+q02yeZEXgY6f+SmIjuJMP 4vEgIz+rislODUJfs63CKBb7fEqjWhm6m3QsnxDtJ9Nv6Y53ik0Nea2tS cHixQLD2VtGSpfu+PQaj54nLGE790JGp9V8K+VbrPU5DcxCOFx74fLicO A==; X-CSE-ConnectionGUID: BOmkjRs1QPWsMbRt5Mg50g== X-CSE-MsgGUID: oFkHb/NwReOhhpSm1jzSAw== X-IPAS-Result: A0BIAgD84oVq/4oQJK1aglmCV3ReQ0mWSgOeG4F+DwEBAQ9EDQQBAYQ/RgKNawImNAkOAQIEAwIDAQEBAQEBAQEBAQEBCgEBBQEBAQIBBwWBDhOGTw2GWgECAQMnCwEYAS0QHAMBAi8rIwgZgwIBgjoDNwMRxBqBeTOBAYMoAT8CQ1DYSxCCVQELFAGBOIU/iCJdGAGEfCcbG4FyhH6BBYFcAQGBJ4Z+BIIiehKBWm6Qe0iBHgNZLAFVEw0KCwcFgWYDNRIqFW4yHYEjPheBDRsGBYEdgSiENyMZNnyBCV6BKyphARIXgQmCCgKCcIIGAgFJRQ4JDAsYDUgRLDcUGQQ+bgeOSiCBfjsSDoEAAQohlT0mkj+hDwoog3aMIZU6GjOEBIFXkkCSUQuYfY4KllCEaYFoPIFHCwdwFYMiCUoZD44qDguDYIF/g2XGVScyAgkyAQEHAgcOAwuBaIRhix8CJgeBTwEB IronPort-Data: A9a23:jSJAN6KTQfDkcbcGFE+Rh5QlxSXFcZb7ZxGr2PjKsXjdYENS1zxVz mQWDTzXOaqONzT0Kd1+OYXn8UsG6pbVx9UyGwMd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZpCCea+Uv9WlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9i2clajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1EK0Q1P7cDo99PPnpr/ 8YEdRUCM0iM0rfeLLKTEoGAh+wqKM3teYdasXZ6wHSBVLAtQIvIROPB4towMDUY358VW62AI ZNHL2M0PHwsYDUXUrsTIJ49keOhh2j2WzZZs1mS46Ew5gA/ySQhiuizb4ePI4XiqcN9mWibh miB2XvDDzYaNMSkzGOH4EmFmbqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYVX95WVul/4waXx++MukCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXLIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:QOBakaC986eOmLvlHemO55DYdb4zR+YMi2TDGXofdfUzSL3+qy nAppUmPHPP5Qr5HUtQ++xoW5PwJU80l6QU3WB5B97LN2PbUSmTXeRfBODZrQEIdReTygck79 YCT4FOTPvtEFN9kcH2pCO8E9om3Z271ZrAv5a585+oJjsaE52JKGxCe3+mLnE= X-Talos-CUID: 9a23:DRXK6WA9Z4phOpj6EwNA8U0WINt8S0Xi11LaGVPlLGk0ELLAHA== X-Talos-MUID: 9a23:345LeQpKdLo5iqppn5AezzZMN+dipIKxMk0qkZUegMzdNz5LEijI2Q== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,231,1779148800"; d="scan'208";a="828675211" Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 Aug 2026 17:10:32 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id 225FA18002444; Wed, 19 Aug 2026 17:10:32 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id B1AC7CD02BA; Wed, 19 Aug 2026 10:10:31 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: Darsh Kelaiya Subject: [OE-core][scarthgap][PATCH 4/4] python3-git: fix CVE-2026-44244 Date: Wed, 19 Aug 2026 10:10:25 -0700 Message-ID: <20260819171026.750280-4-dkelaiya@cisco.com> X-Mailer: git-send-email 2.44.4 In-Reply-To: <20260819171026.750280-1-dkelaiya@cisco.com> References: <20260819171026.750280-1-dkelaiya@cisco.com> MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: alln-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 19 Aug 2026 17:10:43 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243775 From: Darsh Kelaiya This patch applies the upstream 3.1.49 backport for CVE-2026-44244. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3] and [4]. [1] https://github.com/gitpython-developers/GitPython/commit/b049a13105992f22376ad0c7ec945bf3bfb365ae [2] https://nvd.nist.gov/vuln/detail/CVE-2026-44244 [3] https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2 [4] https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3 Signed-off-by: Darsh Kelaiya --- .../python3-git/CVE-2026-44244_p1.patch | 104 ++++++++++++++++++ .../python3-git/CVE-2026-44244_p2.patch | 30 +++++ .../python/python3-git_3.1.42.bb | 2 + 3 files changed, 136 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch new file mode 100644 index 0000000000..92aa905622 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch @@ -0,0 +1,104 @@ +From 19e86eacc9471f2c3ef6f6a55dcaed40e5e139a0 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 05:47:57 +0800 +Subject: [PATCH] reject control chars in written values in configuration + +Reject CR, LF, and NUL in GitConfigParser values before writing them +to git config files (which also is a deviation from Git which escapes them). + +GitConfigParser._write() serializes embedded newlines as indented +continuation lines by replacing "\n" with "\n\t". Git itself skips +leading whitespace before parsing config tokens, so an injected value +such as: + + foo + [core] + hooksPath=/tmp/hooks + +is written in a form where the indented "[core]" line is still parsed by +Git as a real section header. This lets attacker-controlled input passed +to config_writer().set_value() poison repository config, including +core.hooksPath, and redirect hook execution for later Git operations. + +Fail closed instead of stripping or normalizing these characters. Silent +normalization can hide unsanitized caller input, and GitPython does not +currently round-trip Git-style escaped values such as "\n" as embedded +newlines. + +Apply the validation to set_value(), add_value(), and the public set() +path so callers cannot bypass the safer helper API. Add regression tests +for the advisory payload and for CR, LF, NUL, and bytes values. + +This preserves existing read behavior for config files that already +contain multiline values while preventing GitPython from writing new +unsafe values. + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 24 ++++++++++++++++++++++-- + 1 file changed, 22 insertions(+), 2 deletions(-) + +diff --git a/git/config.py b/git/config.py +index 85f75419..ce307110 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -841,6 +841,24 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + return str(value) + return force_text(value) + ++ def _value_to_string_safe(self, value: Union[str, bytes, int, float, bool]) -> str: ++ value_str = self._value_to_string(value) ++ if re.search(r"[\r\n\x00]", value_str): ++ raise ValueError("Git config values must not contain CR, LF, or NUL") ++ return value_str ++ ++ @needs_values ++ @set_dirty_and_flush_changes ++ def set( ++ self, ++ section: str, ++ option: str, ++ value: Union[str, bytes, int, float, bool, None] = None, ++ ) -> None: ++ if value is not None: ++ value = self._value_to_string_safe(value) ++ return super().set(section, option, value) ++ + @needs_values + @set_dirty_and_flush_changes + def set_value(self, section: str, option: str, value: Union[str, bytes, int, float, bool]) -> "GitConfigParser": +@@ -855,9 +873,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + a string. + :return: This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, self._value_to_string(value)) ++ self.set(section, option, value_str) + return self + + @needs_values +@@ -875,9 +894,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + to a string + :return: This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self._sections[section].add(option, self._value_to_string(value)) ++ self._sections[section].add(option, value_str) + return self + + def rename_section(self, section: str, new_name: str) -> "GitConfigParser": +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch new file mode 100644 index 0000000000..fcc3a87275 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch @@ -0,0 +1,30 @@ +From cf273ba3958ad02afa361167a0d0f82e1f4b5f4d Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 06:39:02 +0800 +Subject: [PATCH] avoid duplicate validation in set_value + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3] + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/git/config.py b/git/config.py +index ce307110..7988f5d9 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -876,7 +876,7 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, value_str) ++ super().set(section, option, value_str) + return self + + @needs_values +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index cbc1be8771..3b0f7f96e7 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -18,6 +18,8 @@ SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-42215_p3.patch \ file://CVE-2026-44243_p1.patch \ file://CVE-2026-44243_p2.patch \ + file://CVE-2026-44244_p1.patch \ + file://CVE-2026-44244_p2.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"