[oe][meta-python][scarthgap][PATCH 1/2] python3-filelock: fix CVE-2025-68146
"Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
| Newsgroups | org.openembedded.lists.openembedded-devel |
|---|---|
| Message-ID | <[email protected]> |
From: Darsh Kelaiya <[email protected]> This patch applies the reviewed upstream fix shown in [1]. The advisory identifying the fix is referenced in [2]. [1] https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e [2] https://nvd.nist.gov/vuln/detail/CVE-2025-68146 Signed-off-by: Darsh Kelaiya <[email protected]> --- .../python3-filelock/CVE-2025-68146.patch | 88 +++++++++++++++++++ .../python/python3-filelock_3.13.4.bb | 3 + 2 files changed, 91 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch diff --git a/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch new file mode 100644 index 0000000000..95670f25be --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch @@ -0,0 +1,88 @@ +From 4003a6635c9a429de3f64ce967e8322ecbc6e71a Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Bern=C3=A1t=20G=C3=A1bor?= <[email protected]> +Date: Mon, 15 Dec 2025 15:52:12 -0800 +Subject: [PATCH] Fix TOCTOU symlink vulnerability in lock file creation (#461) + +CVE: CVE-2025-68146 +Upstream-Status: Backport [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e] + +(cherry picked from commit 4724d7f8c3393ec1f048c93933e6e3e6ec321f0e) +Signed-off-by: Darsh Kelaiya <[email protected]> +--- + src/filelock/_unix.py | 2 +- + src/filelock/_windows.py | 38 ++++++++++++++++++++++++++++++++++++++ + 2 files changed, 39 insertions(+), 1 deletion(-) + +diff --git a/src/filelock/_unix.py b/src/filelock/_unix.py +index 4ae1fbe..28d3673 100644 +--- a/src/filelock/_unix.py ++++ b/src/filelock/_unix.py +@@ -36,7 +36,7 @@ else: # pragma: win32 no cover + + def _acquire(self) -> None: + ensure_directory_exists(self.lock_file) +- open_flags = os.O_RDWR | os.O_TRUNC ++ open_flags = os.O_RDWR | os.O_TRUNC | os.O_NOFOLLOW + if not Path(self.lock_file).exists(): + open_flags |= os.O_CREAT + fd = os.open(self.lock_file, open_flags, self._context.mode) +diff --git a/src/filelock/_windows.py b/src/filelock/_windows.py +index 8db55dc..fe3d45c 100644 +--- a/src/filelock/_windows.py ++++ b/src/filelock/_windows.py +@@ -11,7 +11,38 @@ from ._api import BaseFileLock + from ._util import ensure_directory_exists, raise_on_not_writable_file + + if sys.platform == "win32": # pragma: win32 cover ++ import ctypes + import msvcrt ++ from ctypes import wintypes ++ ++ # Windows API constants for reparse point detection ++ FILE_ATTRIBUTE_REPARSE_POINT = 0x00000400 ++ INVALID_FILE_ATTRIBUTES = 0xFFFFFFFF ++ ++ # Load kernel32.dll ++ _kernel32 = ctypes.WinDLL("kernel32", use_last_error=True) ++ _kernel32.GetFileAttributesW.argtypes = [wintypes.LPCWSTR] ++ _kernel32.GetFileAttributesW.restype = wintypes.DWORD ++ ++ def _is_reparse_point(path: str) -> bool: ++ """ ++ Check if a path is a reparse point (symlink, junction, etc.) on Windows. ++ ++ :param path: Path to check ++ :return: True if path is a reparse point, False otherwise ++ :raises OSError: If GetFileAttributesW fails for reasons other than file-not-found ++ """ ++ attrs = _kernel32.GetFileAttributesW(path) ++ if attrs == INVALID_FILE_ATTRIBUTES: ++ # File doesn't exist yet - that's fine, we'll create it ++ err = ctypes.get_last_error() ++ if err == 2: # noqa: PLR2004 # ERROR_FILE_NOT_FOUND ++ return False ++ if err == 3: # noqa: PLR2004 # ERROR_PATH_NOT_FOUND ++ return False ++ # Some other error - let caller handle it ++ return False ++ return bool(attrs & FILE_ATTRIBUTE_REPARSE_POINT) + + class WindowsFileLock(BaseFileLock): + """Uses the :func:`msvcrt.locking` function to hard lock the lock file on Windows systems.""" +@@ -19,6 +50,13 @@ if sys.platform == "win32": # pragma: win32 cover + def _acquire(self) -> None: + raise_on_not_writable_file(self.lock_file) + ensure_directory_exists(self.lock_file) ++ ++ # Security check: Refuse to open reparse points (symlinks, junctions) ++ # This prevents TOCTOU symlink attacks (CVE-TBD) ++ if _is_reparse_point(self.lock_file): ++ msg = f"Lock file is a reparse point (symlink/junction): {self.lock_file}" ++ raise OSError(msg) ++ + flags = ( + os.O_RDWR # open for read and write + | os.O_CREAT # create file if not exists +-- +2.44.4 + diff --git a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb index 4d6d19551a..9fa5f95ff1 100644 --- a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb +++ b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb @@ -8,6 +8,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=911690f51af322440237a253d695d19f" SRC_URI[sha256sum] = "d13f466618bfde72bd2c18255e269f72542c6e70e7bac83a0232d6b1cc5c8cf4" +SRC_URI += "file://CVE-2025-68146.patch \ + " + BBCLASSEXTEND = "native nativesdk" inherit pypi python_hatchling -- 2.44.4