]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
python3: fix CVE-2025-6075
authorPraveen Kumar <praveen.kumar@windriver.com>
Fri, 21 Nov 2025 11:26:42 +0000 (16:56 +0530)
committerSteve Sakoman <steve@sakoman.com>
Mon, 24 Nov 2025 15:34:36 +0000 (07:34 -0800)
commit9a7f33d85355ffbe382aa175c04c64541e77b441
tree6794be6873e34d3e87a53394fd50f711b7b2a5eb
parent6b2a2e689a69deef6098f6c266542234e46fb24b
python3: fix CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment variables.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-6075

Upstream-patch:
https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca

Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/python/python3/CVE-2025-6075.patch [new file with mode: 0644]
meta/recipes-devtools/python/python3_3.10.19.bb