summaryrefslogtreecommitdiffstats
path: root/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb
diff options
context:
space:
mode:
authorNarpat Mali <narpat.mali@windriver.com>2023-12-06 08:59:00 +0000
committerSteve Sakoman <steve@sakoman.com>2023-12-12 04:20:34 -1000
commit31507dd07a36234b888759bab256644446b85ff3 (patch)
tree4b43042486b56ee33094fb8318272fcdfe79f062 /meta/recipes-devtools/python/python3-cryptography_36.0.2.bb
parent82e76d21dcf8ca39ce1a0f7d6af9b66e665625a4 (diff)
downloadpoky-31507dd07a36234b888759bab256644446b85ff3.tar.gz
python3-cryptography: fix CVE-2023-49083
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6. References: https://nvd.nist.gov/vuln/detail/CVE-2023-49083 https://security-tracker.debian.org/tracker/CVE-2023-49083 (From OE-Core rev: 2d104f78cd13a10640bc284c7fc8358bf305279c) Signed-off-by: Narpat Mali <narpat.mali@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-devtools/python/python3-cryptography_36.0.2.bb')
-rw-r--r--meta/recipes-devtools/python/python3-cryptography_36.0.2.bb1
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb b/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb
index c3ae0c1ab9..c429c75e1b 100644
--- a/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb
+++ b/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb
@@ -18,6 +18,7 @@ SRC_URI += " \
18 file://0002-Cargo.toml-edition-2018-2021.patch \ 18 file://0002-Cargo.toml-edition-2018-2021.patch \
19 file://fix-leak-metric.patch \ 19 file://fix-leak-metric.patch \
20 file://CVE-2023-23931.patch \ 20 file://CVE-2023-23931.patch \
21 file://CVE-2023-49083.patch \
21" 22"
22 23
23inherit pypi python_setuptools3_rust 24inherit pypi python_setuptools3_rust