Commit 6410cef
committed
[CVE-2026-3479] Fix pkgutil.get_data() documentation
The documentation still claimed that get_data() can follow parent
directories and absolute paths, which contradicts the validation added
for CVE-2026-3479. Also register the `cve` Sphinx role used by the
NEWS entry for this CVE.
Fixes: bsc#1259989 (CVE-2026-3479)
Patch: CVE-2026-3479-pkgutil_get_data-docs.patch1 parent 756111e commit 6410cef
2 files changed
Lines changed: 15 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
229 | | - | |
230 | | - | |
231 | | - | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
232 | 233 | | |
233 | 234 | | |
234 | 235 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
| 45 | + | |
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
| |||
100 | 101 | | |
101 | 102 | | |
102 | 103 | | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
103 | 113 | | |
104 | 114 | | |
105 | 115 | | |
| |||
414 | 424 | | |
415 | 425 | | |
416 | 426 | | |
| 427 | + | |
417 | 428 | | |
418 | 429 | | |
419 | 430 | | |
| |||
0 commit comments