Skip to content

Commit 6410cef

Browse files
committed
[CVE-2026-3479] Fix pkgutil.get_data() documentation
The documentation still claimed that get_data() can follow parent directories and absolute paths, which contradicts the validation added for CVE-2026-3479. Also register the `cve` Sphinx role used by the NEWS entry for this CVE. Fixes: bsc#1259989 (CVE-2026-3479) Patch: CVE-2026-3479-pkgutil_get_data-docs.patch
1 parent 756111e commit 6410cef

2 files changed

Lines changed: 15 additions & 3 deletions

File tree

‎Doc/library/pkgutil.rst‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -226,9 +226,10 @@ support.
226226
d = os.path.dirname(sys.modules[package].__file__)
227227
data = open(os.path.join(d, resource), 'rb').read()
228228

229-
Like the :func:`open` function, :func:`!get_data` can follow parent
230-
directories (``../``) and absolute paths (starting with ``/`` or ``C:/``,
231-
for example).
229+
The *resource* argument must be a relative path that stays within the
230+
package directory. Absolute paths (starting with ``/`` or ``C:/``,
231+
for example) and paths containing a parent directory component
232+
(``..``) raise :exc:`ValueError`.
232233

233234
.. warning::
234235

‎Doc/tools/extensions/pyspecific.py‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,7 @@
4242
ISSUE_URI = 'https://bugs.python.org/issue%s'
4343
GH_ISSUE_URI = 'https://github.com/python/cpython/issues/%s'
4444
SOURCE_URI = 'https://github.com/python/cpython/tree/3.6/%s'
45+
CVE_URI = 'https://www.cve.org/CVERecord?id=CVE-%s'
4546

4647
# monkey-patch reST parser to disable alphabetic and roman enumerated lists
4748
from docutils.parsers.rst.states import Body
@@ -100,6 +101,15 @@ def gh_issue_role(typ, rawtext, text, lineno, inliner, options={}, content=[]):
100101
return [refnode], []
101102

102103

104+
# Support for linking to CVE records in backported NEWS entries.
105+
106+
def cve_role(typ, rawtext, text, lineno, inliner, options={}, content=[]):
107+
cve = utils.unescape(text)
108+
text = 'CVE-' + cve
109+
refnode = nodes.reference(text, text, refuri=CVE_URI % cve)
110+
return [refnode], []
111+
112+
103113
# Support for linking to Python source files easily
104114

105115
def source_role(typ, rawtext, text, lineno, inliner, options={}, content=[]):
@@ -414,6 +424,7 @@ def setup(app):
414424
app.add_role('issue', issue_role)
415425
app.add_role('gh', gh_issue_role)
416426
app.add_role('source', source_role)
427+
app.add_role('cve', cve_role)
417428
app.add_directive('impl-detail', ImplementationDetail)
418429
app.add_directive('deprecated-removed', DeprecatedRemoved)
419430
app.add_builder(PydocTopicsBuilder)

0 commit comments

Comments
 (0)