diff options
author | Peter Marko <peter.marko@siemens.com> | 2025-06-08 23:43:47 +0200 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2025-06-13 08:42:35 -0700 |
commit | 8cd040c21873bbba5008c725a8eb412b128b7f6a (patch) | |
tree | 9512b7d7da865b982b3e29bfaf86a1201c1ee150 /meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch | |
parent | 57421fdde6b8202f64ff0bdf911e56398fc07853 (diff) | |
download | poky-8cd040c21873bbba5008c725a8eb412b128b7f6a.tar.gz |
python3: upgrade 3.10.16 -> 3.10.18
Drop upstreamed patch and refresh remaining patches.
* https://www.python.org/downloads/release/python-31017/
Security content in this release
* gh-131809: Upgrade vendored expat to 2.7.1
* gh-80222: Folding of quoted string in display_name violates RFC
* gh-121284: Invalid RFC 2047 address header after refolding with
email.policy.default
* gh-131261: Update libexpat to 2.7.0
* gh-105704: CVE-2025-0938 urlparse does not flag hostname containing
[ or ] as incorrect
* gh-119511: OOM vulnerability in the imaplib module
* https://www.python.org/downloads/release/python-31018/
Security content in this release
* gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330]
[CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed
tarfile extraction filters (filter="data" and filter="tar") to be
bypassed using crafted symlinks and hard links.
* gh-133767: Fix use-after-free in the “unicode-escape” decoder with a
non-“strict” error handler.
* gh-128840: Short-circuit the processing of long IPv6 addresses early
in ipaddress to prevent excessive memory consumption and a minor
denial-of-service.
gh-133767 got meawhile CVE-2025-4516 assigned.
(From OE-Core rev: 838a8b5ca148dfa6c6c2c76f1705d1e358a31648)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch')
-rw-r--r-- | meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch b/meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch index 8c554feb4b..025239df1d 100644 --- a/meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch +++ b/meta/recipes-devtools/python/python3/0017-setup.py-do-not-report-missing-dependencies-for-disa.patch | |||
@@ -23,7 +23,7 @@ diff --git a/setup.py b/setup.py | |||
23 | index 85a2b26357..7605347bf5 100644 | 23 | index 85a2b26357..7605347bf5 100644 |
24 | --- a/setup.py | 24 | --- a/setup.py |
25 | +++ b/setup.py | 25 | +++ b/setup.py |
26 | @@ -517,6 +517,14 @@ def print_three_column(lst): | 26 | @@ -517,6 +517,14 @@ class PyBuildExt(build_ext): |
27 | print("%-*s %-*s %-*s" % (longest, e, longest, f, | 27 | print("%-*s %-*s %-*s" % (longest, e, longest, f, |
28 | longest, g)) | 28 | longest, g)) |
29 | 29 | ||