mirror of
git://git.yoctoproject.org/poky.git
synced 2025-07-19 21:09:03 +02:00

Drop upstreamed patch and refresh remaining patches. * https://www.python.org/downloads/release/python-31210/ Python 3.12.10 is the latest maintenance release of Python 3.12, and the last full maintenance release. Subsequent releases of 3.12 will be security-fixes only. * https://www.python.org/downloads/release/python-31211/ Security content in this release * gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links. * gh-133767: Fix use-after-free in the “unicode-escape” decoder with a non-“strict” error handler. * gh-128840: Short-circuit the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. gh-133767 got meawhile CVE-2025-4516 assigned. (From OE-Core rev: 6cca08b2857efd5481e837ecd6bb295cb8a99ee1) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
31 lines
1.3 KiB
Diff
31 lines
1.3 KiB
Diff
From e8bd4f8ee56cbb12a61c1dcabf35a1835a863132 Mon Sep 17 00:00:00 2001
|
|
From: Paulo Neves <ptsneves@gmail.com>
|
|
Date: Tue, 7 Jun 2022 16:16:41 +0200
|
|
Subject: [PATCH] Avoid shebang overflow on python-config.py
|
|
|
|
The whole native path may be too big, leading to shebang
|
|
overflow. Let's just use the env shebang.
|
|
|
|
Denial reason: [1]
|
|
|
|
Upstream-Status: Denied [distribution]
|
|
|
|
[1] https://github.com/python/cpython/pull/93760#pullrequestreview-1005365737
|
|
---
|
|
Makefile.pre.in | 2 ++
|
|
1 file changed, 2 insertions(+)
|
|
|
|
diff --git a/Makefile.pre.in b/Makefile.pre.in
|
|
index 2d235d2..1ac2263 100644
|
|
--- a/Makefile.pre.in
|
|
+++ b/Makefile.pre.in
|
|
@@ -2356,6 +2356,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh
|
|
@ # Substitution happens here, as the completely-expanded BINDIR
|
|
@ # is not available in configure
|
|
sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py
|
|
+ @ # Otherwise we might get huge shebangs with native paths
|
|
+ sed -i -e '1s|^#!.*|#!/usr/bin/env python3|' python-config.py
|
|
@ # Replace makefile compat. variable references with shell script compat. ones; $(VAR) -> ${VAR}
|
|
LC_ALL=C sed -e 's,\$$(\([A-Za-z0-9_]*\)),\$$\{\1\},g' < Misc/python-config.sh >python-config
|
|
@ # On Darwin, always use the python version of the script, the shell
|