[oe][meta-python][scarthgap][PATCH 1/2] python3-filelock: fix CVE-2025-68146

"Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Darsh Kelaiya <[email protected]>

This patch applies the reviewed upstream fix shown in [1]. The
advisory identifying the fix is referenced in [2].

[1] https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e
[2] https://nvd.nist.gov/vuln/detail/CVE-2025-68146

Signed-off-by: Darsh Kelaiya <[email protected]>
---
 .../python3-filelock/CVE-2025-68146.patch     | 88 +++++++++++++++++++
 .../python/python3-filelock_3.13.4.bb         |  3 +
 2 files changed, 91 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch

diff --git a/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch
new file mode 100644
index 0000000000..95670f25be
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-filelock/CVE-2025-68146.patch
@@ -0,0 +1,88 @@
+From 4003a6635c9a429de3f64ce967e8322ecbc6e71a Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Bern=C3=A1t=20G=C3=A1bor?= <[email protected]>
+Date: Mon, 15 Dec 2025 15:52:12 -0800
+Subject: [PATCH] Fix TOCTOU symlink vulnerability in lock file creation (#461)
+
+CVE: CVE-2025-68146
+Upstream-Status: Backport [https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e]
+
+(cherry picked from commit 4724d7f8c3393ec1f048c93933e6e3e6ec321f0e)
+Signed-off-by: Darsh Kelaiya <[email protected]>
+---
+ src/filelock/_unix.py    |  2 +-
+ src/filelock/_windows.py | 38 ++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 39 insertions(+), 1 deletion(-)
+
+diff --git a/src/filelock/_unix.py b/src/filelock/_unix.py
+index 4ae1fbe..28d3673 100644
+--- a/src/filelock/_unix.py
++++ b/src/filelock/_unix.py
+@@ -36,7 +36,7 @@ else:  # pragma: win32 no cover
+ 
+         def _acquire(self) -> None:
+             ensure_directory_exists(self.lock_file)
+-            open_flags = os.O_RDWR | os.O_TRUNC
++            open_flags = os.O_RDWR | os.O_TRUNC | os.O_NOFOLLOW
+             if not Path(self.lock_file).exists():
+                 open_flags |= os.O_CREAT
+             fd = os.open(self.lock_file, open_flags, self._context.mode)
+diff --git a/src/filelock/_windows.py b/src/filelock/_windows.py
+index 8db55dc..fe3d45c 100644
+--- a/src/filelock/_windows.py
++++ b/src/filelock/_windows.py
+@@ -11,7 +11,38 @@ from ._api import BaseFileLock
+ from ._util import ensure_directory_exists, raise_on_not_writable_file
+ 
+ if sys.platform == "win32":  # pragma: win32 cover
++    import ctypes
+     import msvcrt
++    from ctypes import wintypes
++
++    # Windows API constants for reparse point detection
++    FILE_ATTRIBUTE_REPARSE_POINT = 0x00000400
++    INVALID_FILE_ATTRIBUTES = 0xFFFFFFFF
++
++    # Load kernel32.dll
++    _kernel32 = ctypes.WinDLL("kernel32", use_last_error=True)
++    _kernel32.GetFileAttributesW.argtypes = [wintypes.LPCWSTR]
++    _kernel32.GetFileAttributesW.restype = wintypes.DWORD
++
++    def _is_reparse_point(path: str) -> bool:
++        """
++        Check if a path is a reparse point (symlink, junction, etc.) on Windows.
++
++        :param path: Path to check
++        :return: True if path is a reparse point, False otherwise
++        :raises OSError: If GetFileAttributesW fails for reasons other than file-not-found
++        """
++        attrs = _kernel32.GetFileAttributesW(path)
++        if attrs == INVALID_FILE_ATTRIBUTES:
++            # File doesn't exist yet - that's fine, we'll create it
++            err = ctypes.get_last_error()
++            if err == 2:  # noqa: PLR2004  # ERROR_FILE_NOT_FOUND
++                return False
++            if err == 3:  # noqa: PLR2004 # ERROR_PATH_NOT_FOUND
++                return False
++            # Some other error - let caller handle it
++            return False
++        return bool(attrs & FILE_ATTRIBUTE_REPARSE_POINT)
+ 
+     class WindowsFileLock(BaseFileLock):
+         """Uses the :func:`msvcrt.locking` function to hard lock the lock file on Windows systems."""
+@@ -19,6 +50,13 @@ if sys.platform == "win32":  # pragma: win32 cover
+         def _acquire(self) -> None:
+             raise_on_not_writable_file(self.lock_file)
+             ensure_directory_exists(self.lock_file)
++
++            # Security check: Refuse to open reparse points (symlinks, junctions)
++            # This prevents TOCTOU symlink attacks (CVE-TBD)
++            if _is_reparse_point(self.lock_file):
++                msg = f"Lock file is a reparse point (symlink/junction): {self.lock_file}"
++                raise OSError(msg)
++
+             flags = (
+                 os.O_RDWR  # open for read and write
+                 | os.O_CREAT  # create file if not exists
+-- 
+2.44.4
+
diff --git a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
index 4d6d19551a..9fa5f95ff1 100644
--- a/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
+++ b/meta-python/recipes-devtools/python/python3-filelock_3.13.4.bb
@@ -8,6 +8,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=911690f51af322440237a253d695d19f"
 
 SRC_URI[sha256sum] = "d13f466618bfde72bd2c18255e269f72542c6e70e7bac83a0232d6b1cc5c8cf4"
 
+SRC_URI += "file://CVE-2025-68146.patch \
+           "
+
 BBCLASSEXTEND = "native nativesdk"
 inherit pypi python_hatchling
 
-- 
2.44.4
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.