[meta-python][scarthgap][PATCH 2/4] python3-ujson: Fix CVE-2026-32874

"Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Hetvi Thakar <[email protected]>

This patch applies the upstream fix referenced in [2], using the
commit shown in [1].

[1] https://github.com/ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-32874

Signed-off-by: Hetvi Thakar <[email protected]>
---
 .../python/python3-ujson/CVE-2026-32874.patch | 61 +++++++++++++++++++
 .../python/python3-ujson_5.9.0.bb             |  1 +
 2 files changed, 62 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-ujson/CVE-2026-32874.patch

diff --git a/meta-python/recipes-devtools/python/python3-ujson/CVE-2026-32874.patch b/meta-python/recipes-devtools/python/python3-ujson/CVE-2026-32874.patch
new file mode 100644
index 0000000000..09730b9623
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-ujson/CVE-2026-32874.patch
@@ -0,0 +1,61 @@
+From cf988dbccb1b71cc1cb27c59ac73e09f3a68c3c1 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Br=C3=A9nainn=20Woodsend?= <[email protected]>
+Date: Wed, 10 Dec 2025 22:37:20 +0000
+Subject: [PATCH] Fix memory leak parsing large integers
+
+CVE: CVE-2026-32874
+Upstream-Status: Backport [https://github.com/ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2]
+
+Backport Changes:
+- Adjusted source paths for ujson 5.9.0's pre-src-layout tree.
+
+(cherry picked from commit 4baeb950df780092bd3c89fc702a868e99a3a1d2)
+Signed-off-by: Hetvi Thakar <[email protected]>
+---
+ python/JSONtoObj.c  |  4 +++-
+ tests/test_ujson.py | 14 ++++++++++++++
+ 2 files changed, 17 insertions(+), 1 deletion(-)
+
+diff --git a/python/JSONtoObj.c b/python/JSONtoObj.c
+index 208055c..93e87f3 100644
+--- a/python/JSONtoObj.c
++++ b/python/JSONtoObj.c
+@@ -136,7 +136,9 @@ static JSOBJ Object_newIntegerFromString(void *prv, char *value, size_t length)
+   char *buf = PyObject_Malloc(length + 1);
+   memcpy(buf, value, length);
+   buf[length] = '\0';
+-  return PyLong_FromString(buf, NULL, 10);
++  PyObject *ret = PyLong_FromString(buf, NULL, 10);
++  PyObject_Free(buf);
++  return ret;
+ }
+ 
+ static JSOBJ Object_newDouble(void *prv, double value)
+diff --git a/tests/test_ujson.py b/tests/test_ujson.py
+index d24edb0..9ba6f55 100644
+--- a/tests/test_ujson.py
++++ b/tests/test_ujson.py
+@@ -653,6 +653,20 @@ def test_encode_decode_big_int(i, mode):
+             assert ujson.decode(json_string) == python_object
+ 
+ 
[email protected](
++    sys.implementation.name == "pypy",
++    reason="PyPy's PyNumber_ToBase ignores sys.get_int_max_str_digits()",
++)
++def test_encode_too_big_int_error():
++    with pytest.raises(ValueError, match="integer string conversion"):
++        ujson.dumps(pow(10, 10_000))
++
++
++def test_decode_too_big_int_error():
++    with pytest.raises(ValueError, match="integer string conversion"):
++        ujson.loads("9" * 10_000)
++
++
+ @pytest.mark.parametrize(
+     "test_input, expected",
+     [
+-- 
+2.35.6
+
diff --git a/meta-python/recipes-devtools/python/python3-ujson_5.9.0.bb b/meta-python/recipes-devtools/python/python3-ujson_5.9.0.bb
index c6b69790e8..8b970ee564 100644
--- a/meta-python/recipes-devtools/python/python3-ujson_5.9.0.bb
+++ b/meta-python/recipes-devtools/python/python3-ujson_5.9.0.bb
@@ -12,6 +12,7 @@ SRC_URI += " \
     file://run-ptest \
     file://0001-setup.py-Do-not-strip-debugging-symbols.patch \
     file://CVE-2026-32875.patch \
+    file://CVE-2026-32874.patch \
 "
 
 DEPENDS += "python3-setuptools-scm-native"
-- 
2.35.6
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.