Files
meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2/CVE-2026-26209-dependent.patch
T
Devansh Patel b8bd073f05 python3-cbor2: Fix CVE-2026-26209
Scarthgap already contains 4810cd8c5b [3], which backports
fb4ee161 and e61a5f36 for read-ahead/read-size handling. The
associated submission [4] labels that work as CVE-2026-26209, but
it does not add the max_depth protection required for uncontrolled
recursion [2].

Complete the existing backport with the 5.9.0 max-depth chain:
- bcb6cea4: add the C decoder depth limit [1]
- 94e0d212: add the security-essential pure-Python depth limit
- 53521e7c: apply the required type correction
- a7ac10d5: raise the default depth limit to 400
- d903d62c: synchronize the C function signature default

The 5.9.0 upgrade description [5] also identifies max_depth as the
CVE fix. Full upstream commit links are recorded in the embedded
patch headers.

[1] https://github.com/agronholm/cbor2/commit/bcb6cea4edde1d00ff4f0eece883dea951f66e1b
[2] https://github.com/advisories/GHSA-3c37-wwvx-h642
[3] https://git.openembedded.org/meta-openembedded/commit/?id=4810cd8c5bbc0b4349a78eac85a6a882bc0b03a2
[4] https://www.mail-archive.com/openembedded-devel%40lists.openembedded.org/msg105607.html
[5] https://www.mail-archive.com/openembedded-devel%40lists.openembedded.org/msg105418.html

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-01 06:57:25 +05:30

28 lines
949 B
Diff

From d4213ba74d2bf8039f7f062b49955d37a0f4ec02 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Alex=20Gr=C3=B6nholm?= <alex.gronholm@nextday.fi>
Date: Tue, 3 Mar 2026 01:26:17 +0200
Subject: [PATCH] Fixed ssize_t to Py_ssize_t
CVE: CVE-2026-26209
Upstream-Status: Backport [https://github.com/agronholm/cbor2/commit/53521e7ca96c7a19f8a529fe59ef566212a24b3f]
(cherry picked from commit 53521e7ca96c7a19f8a529fe59ef566212a24b3f)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
source/decoder.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/source/decoder.h b/source/decoder.h
index 4536a4a..c4ef1c1 100644
--- a/source/decoder.h
+++ b/source/decoder.h
@@ -22,7 +22,7 @@ typedef struct CBORDecoderObject_ {
PyObject *shareables;
PyObject *stringref_namespace;
PyObject *str_errors;
- ssize_t max_depth;
+ Py_ssize_t max_depth;
bool immutable;
Py_ssize_t shared_index;
Py_ssize_t decode_depth;