mirror of
https://git.yoctoproject.org/poky
synced 2026-09-24 10:10:25 +00:00
python3-git: fix CVE-2026-42284
This patch applies the upstream 3.1.47 backport for CVE-2026-42284. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/gitpython-developers/GitPython/commit/da545232d0401fb9fb7660f9ff67991996674dda [2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284 (From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c) Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> [YC: See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224: The author links the fix to this advisory/CVE. ] Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
ab57645a22
commit
1e39c2a5e3
@@ -0,0 +1,37 @@
|
||||
From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001
|
||||
From: "GPT 5.4" <codex@openai.com>
|
||||
Date: Tue, 21 Apr 2026 09:30:29 +0800
|
||||
Subject: [PATCH] Make sure that multi-options are checked after splitting them
|
||||
with `shlex`
|
||||
|
||||
CVE: CVE-2026-42284
|
||||
Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
|
||||
|
||||
Backport Changes:
|
||||
- Omit regression tests because the Scarthgap PyPI source
|
||||
archive does not include the upstream test suite.
|
||||
|
||||
Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
|
||||
(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
|
||||
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
|
||||
---
|
||||
git/repo/base.py | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/git/repo/base.py b/git/repo/base.py
|
||||
index f5069dbf..92ace3a0 100644
|
||||
--- a/git/repo/base.py
|
||||
+++ b/git/repo/base.py
|
||||
@@ -1271,8 +1271,8 @@ class Repo:
|
||||
Git.check_unsafe_protocols(str(url))
|
||||
if not allow_unsafe_options:
|
||||
Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
|
||||
- if not allow_unsafe_options and multi_options:
|
||||
- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
|
||||
+ if not allow_unsafe_options and multi:
|
||||
+ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
|
||||
|
||||
proc = git.clone(
|
||||
multi,
|
||||
--
|
||||
2.35.6
|
||||
Reference in New Issue
Block a user