diff options
| author | Narpat Mali <narpat.mali@windriver.com> | 2023-12-06 08:59:00 +0000 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2023-12-12 04:20:34 -1000 |
| commit | 31507dd07a36234b888759bab256644446b85ff3 (patch) | |
| tree | 4b43042486b56ee33094fb8318272fcdfe79f062 /meta/recipes-devtools/python/python3-cryptography_36.0.2.bb | |
| parent | 82e76d21dcf8ca39ce1a0f7d6af9b66e665625a4 (diff) | |
| download | poky-31507dd07a36234b888759bab256644446b85ff3.tar.gz | |
python3-cryptography: fix CVE-2023-49083
cryptography is a package designed to expose cryptographic primitives
and recipes to Python developers. Calling `load_pem_pkcs7_certificates`
or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference
and segfault. Exploitation of this vulnerability poses a serious risk of
Denial of Service (DoS) for any application attempting to deserialize a
PKCS7 blob/certificate. The consequences extend to potential disruptions
in system availability and stability. This vulnerability has been patched
in version 41.0.6.
References:
https://nvd.nist.gov/vuln/detail/CVE-2023-49083
https://security-tracker.debian.org/tracker/CVE-2023-49083
(From OE-Core rev: 2d104f78cd13a10640bc284c7fc8358bf305279c)
Signed-off-by: Narpat Mali <narpat.mali@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-devtools/python/python3-cryptography_36.0.2.bb')
| -rw-r--r-- | meta/recipes-devtools/python/python3-cryptography_36.0.2.bb | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb b/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb index c3ae0c1ab9..c429c75e1b 100644 --- a/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb +++ b/meta/recipes-devtools/python/python3-cryptography_36.0.2.bb | |||
| @@ -18,6 +18,7 @@ SRC_URI += " \ | |||
| 18 | file://0002-Cargo.toml-edition-2018-2021.patch \ | 18 | file://0002-Cargo.toml-edition-2018-2021.patch \ |
| 19 | file://fix-leak-metric.patch \ | 19 | file://fix-leak-metric.patch \ |
| 20 | file://CVE-2023-23931.patch \ | 20 | file://CVE-2023-23931.patch \ |
| 21 | file://CVE-2023-49083.patch \ | ||
| 21 | " | 22 | " |
| 22 | 23 | ||
| 23 | inherit pypi python_setuptools3_rust | 24 | inherit pypi python_setuptools3_rust |
