[oe][meta-python][wrynose][PATCH 0/10] python3-aiohttp: fix multiple CVEs

"Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Darsh Kelaiya <[email protected]>

Backport ten upstream aiohttp security fixes to the 3.13.5 recipe on
wrynose.

The corresponding fixes are available in aiohttp 3.14.0 and 3.14.1.
Carry them as focused backports instead of upgrading the recipe because
the 3.14 release also introduces new APIs, deprecations, and
backward-incompatible behavior outside the security scope.

The individual commits retain the upstream fix provenance and public
advisory references for each CVE.

Testing:
- Applied the ten layer commits to the upstream wrynose baseline.
- Applied all ten embedded patches to aiohttp 3.13.5 in series order
  with no conflicts or fuzz.
- Package build and image build validation completed successfully.

Darsh Kelaiya (10):
  python3-aiohttp: fix CVE-2026-34993
  python3-aiohttp: fix CVE-2026-47265
  python3-aiohttp: fix CVE-2026-50269
  python3-aiohttp: fix CVE-2026-54274
  python3-aiohttp: fix CVE-2026-54275
  python3-aiohttp: fix CVE-2026-54276
  python3-aiohttp: fix CVE-2026-54277
  python3-aiohttp: fix CVE-2026-54278
  python3-aiohttp: fix CVE-2026-54279
  python3-aiohttp: fix CVE-2026-54280

 .../python3-aiohttp/CVE-2026-34993.patch      | 478 ++++++++++++++++++
 .../python3-aiohttp/CVE-2026-47265.patch      |  64 +++
 .../python3-aiohttp/CVE-2026-50269.patch      |  81 +++
 .../python3-aiohttp/CVE-2026-54274.patch      | 182 +++++++
 .../python3-aiohttp/CVE-2026-54275.patch      | 115 +++++
 .../python3-aiohttp/CVE-2026-54276.patch      | 287 +++++++++++
 .../python3-aiohttp/CVE-2026-54277.patch      | 249 +++++++++
 .../python3-aiohttp/CVE-2026-54278.patch      | 182 +++++++
 .../python3-aiohttp/CVE-2026-54279.patch      | 295 +++++++++++
 .../python3-aiohttp/CVE-2026-54280.patch      | 138 +++++
 .../python/python3-aiohttp_3.13.5.bb          |  13 +
 11 files changed, 2084 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34993.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54274.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54275.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54276.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54277.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54278.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54279.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54280.patch

-- 
2.35.6
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.