From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 From: Benjamin A. Beasley To: git-commits@fedoraproject.org Subject: [rpms/python-ujson] epel9: Backport fix for CVE-2026-44660; fixes RHBZ#2486949 Date: Tue, 09 Jun 2026 10:17:48 GMT Message-ID: <178100026832.1.4907089244228338096.rpms-python-ujson-607477d5c996@fedoraproject.org> List-ID: X-Git-Repo: rpms/python-ujson X-Git-Branch: epel9 X-Git-Rev: 607477d5c996c3893932f561919cb2bd775affcb QSBuZXcgY29tbWl0IGhhcyBiZWVuIHB1c2hlZC4KClJlcG8gICA6IHJwbXMvcHl0aG9uLXVqc29u CkJyYW5jaCA6IGVwZWw5CkNvbW1pdCA6IDYwNzQ3N2Q1Yzk5NmMzODkzOTMyZjU2MTkxOWNiMmJk Nzc1YWZmY2IKQXV0aG9yIDogQmVuamFtaW4gQS4gQmVhc2xleSA8Y29kZUBtdXNpY2lubXlicmFp bi5uZXQ+CkRhdGUgICA6IDIwMjYtMDYtMDlUMTE6MTY6MjErMDE6MDAKU3RhdHMgIDogKzExNi8t NCBpbiA0IGZpbGUocykKVVJMICAgIDogaHR0cHM6Ly9zcmMuZmVkb3JhcHJvamVjdC5vcmcvcnBt cy9weXRob24tdWpzb24vYy82MDc0NzdkNWM5OTZjMzg5MzkzMmY1NjE5MTljYjJiZDc3NWFmZmNi P2JyYW5jaD1lcGVsOQoKTG9nOgpCYWNrcG9ydCBmaXggZm9yIENWRS0yMDI2LTQ0NjYwOyBmaXhl cyBSSEJaIzI0ODY5NDkKCi0tLQpkaWZmIC0tZ2l0IGEvMDAwMS1GaXgtbWVtb3J5LWxlYWstcGFy c2luZy1sYXJnZS1pbnRlZ2Vycy5wYXRjaCBiLzAwMDEtRml4LW1lbW9yeS1sZWFrLXBhcnNpbmct bGFyZ2UtaW50ZWdlcnMucGF0Y2gKaW5kZXggYjAyYTQ3ZC4uMGJhYTMyMCAxMDA2NDQKLS0tIGEv MDAwMS1GaXgtbWVtb3J5LWxlYWstcGFyc2luZy1sYXJnZS1pbnRlZ2Vycy5wYXRjaAorKysgYi8w MDAxLUZpeC1tZW1vcnktbGVhay1wYXJzaW5nLWxhcmdlLWludGVnZXJzLnBhdGNoCkBAIC0xLDcg KzEsNyBAQAogRnJvbSAxNDg4ZmE4N2I1MTViMDE3Y2Q0MGEwODk0NTk0NThiMTc5NzRmMDM3IE1v biBTZXAgMTcgMDA6MDA6MDAgMjAwMQogRnJvbTogPT9VVEYtOD9xP0JyPUMzPUE5bmFpbm49MjBX b29kc2VuZD89IDxid29vZHNlbmRAZ21haWwuY29tPgogRGF0ZTogV2VkLCAxMCBEZWMgMjAyNSAy MjozNzoyMCArMDAwMAotU3ViamVjdDogW1BBVENIIDEvMl0gRml4IG1lbW9yeSBsZWFrIHBhcnNp bmcgbGFyZ2UgaW50ZWdlcnMKK1N1YmplY3Q6IFtQQVRDSCAxLzNdIEZpeCBtZW1vcnkgbGVhayBw YXJzaW5nIGxhcmdlIGludGVnZXJzCiAKIC0tLQogIHB5dGhvbi9KU09OdG9PYmouYyAgfCAgNCAr KystCkBAIC00OSw1ICs0OSw1IEBAIGluZGV4IGY2ZDg0MjcuLmFlOWVmNWQgMTAwNjQ0CiAgICAg ICJ0ZXN0X2lucHV0LCBleHBlY3RlZCIsCiAgICAgIFsKIC0tIAotMi41My4wCisyLjU0LjAKIAoK ZGlmZiAtLWdpdCBhLzAwMDItRml4LWJ1ZmZlci1vdmVyZmxvdy1pbmZpbml0ZS1sb29wLWZyb20t aW5kZW50LWhhbmRsaS5wYXRjaCBiLzAwMDItRml4LWJ1ZmZlci1vdmVyZmxvdy1pbmZpbml0ZS1s b29wLWZyb20taW5kZW50LWhhbmRsaS5wYXRjaAppbmRleCBlMDUxMjIzLi5jODFjOTIxIDEwMDY0 NAotLS0gYS8wMDAyLUZpeC1idWZmZXItb3ZlcmZsb3ctaW5maW5pdGUtbG9vcC1mcm9tLWluZGVu dC1oYW5kbGkucGF0Y2gKKysrIGIvMDAwMi1GaXgtYnVmZmVyLW92ZXJmbG93LWluZmluaXRlLWxv b3AtZnJvbS1pbmRlbnQtaGFuZGxpLnBhdGNoCkBAIC0xLDcgKzEsNyBAQAogRnJvbSAxYWU3Yzli ZWM0MDExNGI5ODViOWQ5ZDJkYTgxOTNiNTJlMzNlMjVhIE1vbiBTZXAgMTcgMDA6MDA6MDAgMjAw MQogRnJvbTogPT9VVEYtOD9xP0JyPUMzPUE5bmFpbm49MjBXb29kc2VuZD89IDxid29vZHNlbmRA Z21haWwuY29tPgogRGF0ZTogV2VkLCA0IE1hciAyMDI2IDIyOjI4OjExICswMDAwCi1TdWJqZWN0 OiBbUEFUQ0ggMi8yXSBGaXggYnVmZmVyIG92ZXJmbG93L2luZmluaXRlIGxvb3AgZnJvbSBpbmRl bnQgaGFuZGxpbmcKK1N1YmplY3Q6IFtQQVRDSCAyLzNdIEZpeCBidWZmZXIgb3ZlcmZsb3cvaW5m aW5pdGUgbG9vcCBmcm9tIGluZGVudCBoYW5kbGluZwogCiBJZiBpbmRlbnQgKiBuZXN0IGRlcHRo IGlzIGxhcmdlIGVub3VnaCB0byBvdmVyZmxvdyBhbiBpbnQsIGl0IGNhdXNlcyB0aGUKIHJlcXVp cmVkIG91dHB1dCBidWZmZXIgc2l6ZSB0byBiZSB1bmRlcmVzdGltYXRlZCBsZWFkaW5nIHRvIGEg YnVmZmVyCkBAIC0xODYsNSArMTg2LDUgQEAgaW5kZXggYWU5ZWY1ZC4uOTI2OGQ4NiAxMDA2NDQK ICAKICBAcHl0ZXN0Lm1hcmsucGFyYW1ldHJpemUoImZpcnN0X2xlbmd0aCIsIGxpc3QocmFuZ2Uo MiwgNykpKQogLS0gCi0yLjUzLjAKKzIuNTQuMAogCgpkaWZmIC0tZ2l0IGEvMDAwMy1GaXgtZmFp bHVyZS1jbGVhbnVwLXBhdGhzLWluLXVqc29uLmR1bXAucGF0Y2ggYi8wMDAzLUZpeC1mYWlsdXJl LWNsZWFudXAtcGF0aHMtaW4tdWpzb24uZHVtcC5wYXRjaApuZXcgZmlsZSBtb2RlIDEwMDY0NApp bmRleCAwMDAwMDAwLi5hMTBhMDQzCi0tLSAvZGV2L251bGwKKysrIGIvMDAwMy1GaXgtZmFpbHVy ZS1jbGVhbnVwLXBhdGhzLWluLXVqc29uLmR1bXAucGF0Y2gKQEAgLTAsMCArMSwxMDMgQEAKK0Zy b20gNjhlMTliODcxZWMyNWUwYWQ0ZjRlMjUyMWM0ODBmZWE0OTc2NzY2MSBNb24gU2VwIDE3IDAw OjAwOjAwIDIwMDEKK0Zyb206ID0/VVRGLTg/cT9Ccj1DMz1BOW5haW5uPTIwV29vZHNlbmQ/PSA8 Yndvb2RzZW5kQGdtYWlsLmNvbT4KK0RhdGU6IFN1biwgMyBNYXkgMjAyNiAxMjoyMjo0OCArMDEw MAorU3ViamVjdDogW1BBVENIIDMvM10gRml4IGZhaWx1cmUgY2xlYW51cCBwYXRocyBpbiB1anNv bi5kdW1wKCkKKworKiBBZGQgbWlzc2luZyBkZWMtcmVmcyBmb3IgaWYgUHlUdXBsZV9QYWNrKCkg b3Igd3JpdGluZyB0aGUgcGF5bG9hZCB0bworICBmaWxlIGZhaWxzCisKKyogQWRkIG1pc3Npbmcg YmFpbG91dCBmb3IgZmFpbGVkIFB5VHVwbGVfUGFjaygpCisKKyogQWRkIHRlc3RzIGZvciBhbGwg YnV0IHRoZSBQeVR1cGxlX1BhY2soKSBmYWlsaW5nICh3aGljaCByZXF1aXJlcworICBpbmR1Y2lu ZyBhIG1hbGxvYygpIGZhaWx1cmUpCistLS0KKyBweXRob24vb2JqVG9KU09OLmMgIHwgIDcgKysr KysrKworIHRlc3RzL3Rlc3RfdWpzb24ucHkgfCAzMyArKysrKysrKysrKysrKysrKysrKysrKysr KysrKysrKysKKyAyIGZpbGVzIGNoYW5nZWQsIDQwIGluc2VydGlvbnMoKykKKworZGlmZiAtLWdp dCBhL3B5dGhvbi9vYmpUb0pTT04uYyBiL3B5dGhvbi9vYmpUb0pTT04uYworaW5kZXggYzc2NzVj Yi4uZTI4MTg2ZSAxMDA2NDQKKy0tLSBhL3B5dGhvbi9vYmpUb0pTT04uYworKysrIGIvcHl0aG9u L29ialRvSlNPTi5jCitAQCAtMTA1MCw2ICsxMDUwLDExIEBAIFB5T2JqZWN0KiBvYmpUb0pTT05G aWxlKFB5T2JqZWN0KiBzZWxmLCBQeU9iamVjdCAqYXJncywgUHlPYmplY3QgKmt3YXJncykKKyAg IH0KKyAKKyAgIGFyZ3R1cGxlID0gUHlUdXBsZV9QYWNrKDEsIGRhdGEpOworKyAgaWYgKGFyZ3R1 cGxlID09IE5VTEwpCisrICB7CisrICAgIFB5X1hERUNSRUYod3JpdGUpOworKyAgICByZXR1cm4g TlVMTDsKKysgIH0KKyAKKyAgIHN0cmluZyA9IG9ialRvSlNPTiAoc2VsZiwgYXJndHVwbGUsIGt3 YXJncyk7CisgCitAQCAtMTA2Niw2ICsxMDcxLDcgQEAgUHlPYmplY3QqIG9ialRvSlNPTkZpbGUo UHlPYmplY3QqIHNlbGYsIFB5T2JqZWN0ICphcmdzLCBQeU9iamVjdCAqa3dhcmdzKQorICAgaWYg KGFyZ3R1cGxlID09IE5VTEwpCisgICB7CisgICAgIFB5X1hERUNSRUYod3JpdGUpOworKyAgICBQ eV9ERUNSRUYoc3RyaW5nKTsKKyAgICAgcmV0dXJuIE5VTEw7CisgICB9CisgCitAQCAtMTA3Myw2 ICsxMDc5LDcgQEAgUHlPYmplY3QqIG9ialRvSlNPTkZpbGUoUHlPYmplY3QqIHNlbGYsIFB5T2Jq ZWN0ICphcmdzLCBQeU9iamVjdCAqa3dhcmdzKQorICAgaWYgKHdyaXRlX3Jlc3VsdCA9PSBOVUxM KQorICAgeworICAgICBQeV9YREVDUkVGKHdyaXRlKTsKKysgICAgUHlfREVDUkVGKHN0cmluZyk7 CisgICAgIFB5X1hERUNSRUYoYXJndHVwbGUpOworICAgICByZXR1cm4gTlVMTDsKKyAgIH0KK2Rp ZmYgLS1naXQgYS90ZXN0cy90ZXN0X3Vqc29uLnB5IGIvdGVzdHMvdGVzdF91anNvbi5weQoraW5k ZXggOTI2OGQ4Ni4uZGUzNWMyYiAxMDA2NDQKKy0tLSBhL3Rlc3RzL3Rlc3RfdWpzb24ucHkKKysr KyBiL3Rlc3RzL3Rlc3RfdWpzb24ucHkKK0BAIC04LDYgKzgsNyBAQCBpbXBvcnQgb3MucGF0aAor IGltcG9ydCByZQorIGltcG9ydCBzdWJwcm9jZXNzCisgaW1wb3J0IHN5cworK2ltcG9ydCB0eXBl cworIGltcG9ydCB1dWlkCisgZnJvbSBjb2xsZWN0aW9ucyBpbXBvcnQgT3JkZXJlZERpY3QKKyBm cm9tIHBhdGhsaWIgaW1wb3J0IFBhdGgKK0BAIC0zNjUsNiArMzY2LDM4IEBAIGRlZiB0ZXN0X2R1 bXBfdG9fZmlsZV9saWtlX29iamVjdCgpOgorIGRlZiB0ZXN0X2R1bXBfZmlsZV9hcmdzX2Vycm9y KCk6CisgICAgIHdpdGggcHl0ZXN0LnJhaXNlcyhUeXBlRXJyb3IpOgorICAgICAgICAgdWpzb24u ZHVtcChbXSwgIiIpCisrICAgIHdpdGggcHl0ZXN0LnJhaXNlcyhUeXBlRXJyb3IpOgorKyAgICAg ICAgdWpzb24uZHVtcChbXSwgIiIsICIiKQorKworKworK2RlZiB0ZXN0X2R1bXBfbm9uX2NhbGxh YmxlX3dyaXRlKCk6CisrICAgIGZpbGUgPSB0eXBlcy5TaW1wbGVOYW1lc3BhY2Uod3JpdGU9ImEi KQorKyAgICB3aXRoIHB5dGVzdC5yYWlzZXMoVHlwZUVycm9yKToKKysgICAgICAgIHVqc29uLmR1 bXAoWzddICogMTAwLCBmaWxlKQorKworKworK2RlZiB0ZXN0X2ZhaWxlZF9kdW1wKCk6CisrICAg IHdpdGggcHl0ZXN0LnJhaXNlcyhUeXBlRXJyb3IpOgorKyAgICAgICAgdWpzb24uZHVtcChbWzBd ICogMTAwLCBvYmplY3QoKV0sIGlvLlN0cmluZ0lPKCkpCisrCisrCisrZGVmIHRlc3RfZmFpbGVk X2R1bXBfYm9ndXNfZmlsZSgpOgorKyAgICBmaWxlID0gdHlwZXMuU2ltcGxlTmFtZXNwYWNlKHdy aXRlPWxhbWJkYTogTm9uZSkKKysgICAgd2l0aCBweXRlc3QucmFpc2VzKFR5cGVFcnJvciwgbWF0 Y2g9IjAgcG9zaXRpb25hbCBhcmd1bWVudHMiKToKKysgICAgICAgIHVqc29uLmR1bXAoWzBdICog MTAwLCBmaWxlKQorKworKworK2RlZiB0ZXN0X2ZhaWxlZF9kdW1wX2ZhaWxlZF93cml0ZSgpOgor KyAgICBmaWxlID0gdHlwZXMuU2ltcGxlTmFtZXNwYWNlKHdyaXRlPWxhbWJkYSB4OiAxIC8gMCkK KysgICAgd2l0aCBweXRlc3QucmFpc2VzKFplcm9EaXZpc2lvbkVycm9yKToKKysgICAgICAgIHVq c29uLmR1bXAoWzBdICogMTAwLCBmaWxlKQorKworKworK2RlZiB0ZXN0X2ZhaWxlZF9kdW1wX2Ns b3NlZF9maWxlKCk6CisrICAgIGZpbGUgPSBpby5TdHJpbmdJTygpCisrICAgIGZpbGUuY2xvc2Uo KQorKyAgICB3aXRoIHB5dGVzdC5yYWlzZXMoVmFsdWVFcnJvciwgbWF0Y2g9ImNsb3NlZCBmaWxl Iik6CisrICAgICAgICB1anNvbi5kdW1wKFswXSAqIDEwMCwgZmlsZSkKKyAKKyAKKyBkZWYgdGVz dF9sb2FkX2ZpbGUoKToKKy0tIAorMi41NC4wCisKCmRpZmYgLS1naXQgYS9weXRob24tdWpzb24u c3BlYyBiL3B5dGhvbi11anNvbi5zcGVjCmluZGV4IDNmYzQ2ZDMuLjc5NjJlNjIgMTAwNjQ0Ci0t LSBhL3B5dGhvbi11anNvbi5zcGVjCisrKyBiL3B5dGhvbi11anNvbi5zcGVjCkBAIC00Nyw2ICs0 NywxNSBAQCBQYXRjaDogICAgICAgICAgMDAwMS1GaXgtbWVtb3J5LWxlYWstcGFyc2luZy1sYXJn ZS1pbnRlZ2Vycy5wYXRjaAogIyBodHRwczovL2dpdGh1Yi5jb20vdWx0cmFqc29uL3VsdHJhanNv bi9jb21taXQvNDg2YmQ0NTUzZGM0NzFhMWRlMTE2MTNiYzczNDdhNmIzMThlMzdlYQogIyBDaGVy cnktcGlja2VkIHRvIHY1LjguMAogUGF0Y2g6ICAgICAgICAgIDAwMDItRml4LWJ1ZmZlci1vdmVy Zmxvdy1pbmZpbml0ZS1sb29wLWZyb20taW5kZW50LWhhbmRsaS5wYXRjaAorIyBCYWNrcG9ydCBm aXggZm9yIENWRS0yMDI2LTQ0NjYwIGZyb20gdjUuMTIuMQorIyBodHRwczovL3d3dy5jdmUub3Jn L0NWRVJlY29yZD9pZD1DVkUtMjAyNi00NDY2MAorIyBodHRwczovL2J1Z3ppbGxhLnJlZGhhdC5j b20vc2hvd19idWcuY2dpP2lkPTI0ODY5NDkKKyMgaHR0cHM6Ly9naXRodWIuY29tL3VsdHJhanNv bi91bHRyYWpzb24vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLWMzOGYtd3g4OS1wMnhnCisjCisj IEZpeCBmYWlsdXJlIGNsZWFudXAgcGF0aHMgaW4gdWpzb24uZHVtcCgpCisjIGh0dHBzOi8vZ2l0 aHViLmNvbS91bHRyYWpzb24vdWx0cmFqc29uL2NvbW1pdC84MmFmMWQwYWMwMWQwOWFhNDBjODg3 YjQ2MGQ0NGI5ZDlmNGJjY2Q5CisjIENoZXJyeS1waWNrZWQgdG8gdjUuOC4wCitQYXRjaDogICAg ICAgICAgMDAwMy1GaXgtZmFpbHVyZS1jbGVhbnVwLXBhdGhzLWluLXVqc29uLmR1bXAucGF0Y2gK IAogQnVpbGRSZXF1aXJlczogIGdjYwogQnVpbGRSZXF1aXJlczogIGdjYy1jKysK