已开启
fix(cve): 修复 CVE-2026-12479 在 python-Keras 中的漏洞 #24
infra_team创建于 6月23日
fix(cve): 修复 CVE-2026-12479 在 python-Keras 中的漏洞 #24
已开启
共 4 个文件变更+78-2
| @@ -0,0 +1,65 @@ | |||
| 1 | +From d8caeb58cc9e61ea092445dc7a20908ca8d693e2 Mon Sep 17 00:00:00 2001 | ||
| 2 | +From: Ziyu Lin <104151270+LinZiyuu@users.noreply.github.com> | ||
| 3 | +Date: Wed, 3 Jun 2026 01:57:33 +0800 | ||
| 4 | +Subject: [PATCH] Validate DiskIOStore asset paths stay within the working | ||
| 5 | + directory (#23017) | ||
| 6 | + | ||
| 7 | +Backport of upstream commit d8caeb58cc9e61ea092445dc7a20908ca8d693e2 to | ||
| 8 | +Keras 2.13.1 (keras/saving/saving_lib.py). v2.x uses tf.io.gfile instead | ||
| 9 | +of file_utils, and DiskIOStore does not yet have a has_path method, so | ||
| 10 | +this patch only updates make()/get() and adds _full_path() with the | ||
| 11 | +equivalent v2.x semantics (os.path.realpath for local; string check | ||
| 12 | +for remote working directories such as gs://). | ||
| 13 | + | ||
| 14 | +Reference: https://github.com/keras-team/keras/commit/d8caeb58cc9e61ea092445dc7a20908ca8d693e2 | ||
| 15 | +Signed-off-by: infra_team <zhaiwenjie1@huawei.com> | ||
| 16 | +--- | ||
| 17 | +--- a/keras/saving/saving_lib.py | ||
| 18 | ++++ b/keras/saving/saving_lib.py | ||
| 19 | + | ||
| 20 | + ) | ||
| 21 | + tf.io.gfile.makedirs(self.working_dir) | ||
| 22 | + | ||
| 23 | ++ def _full_path(self, path): | ||
| 24 | ++ """Resolve `path` under the working dir, rejecting traversal.""" | ||
| 25 | ++ # Normalize separators first so a `\` cannot bypass the check below. | ||
| 26 | ++ path = path.replace("\\", "/") | ||
| 27 | ++ if "://" in self.working_dir or self.working_dir.startswith("/"): | ||
| 28 | ++ # `realpath` would corrupt a remote prefix such as `gs://bucket`, | ||
| 29 | ++ # so validate remote paths by string instead. | ||
| 30 | ++ if path.startswith("/") or "://" in path or ".." in path.split("/"): | ||
| 31 | ++ raise ValueError( | ||
| 32 | ++ f"Invalid asset path: '{path}' escapes the asset directory." | ||
| 33 | ++ ) | ||
| 34 | ++ return tf.io.gfile.join(self.working_dir, path).replace("\\", "/") | ||
| 35 | ++ working_dir_real = os.path.realpath(self.working_dir) | ||
| 36 | ++ joined = os.path.realpath(os.path.join(working_dir_real, path)) | ||
| 37 | ++ if ( | ||
| 38 | ++ joined != working_dir_real | ||
| 39 | ++ and not joined.startswith(working_dir_real + os.sep) | ||
| 40 | ++ ): | ||
| 41 | ++ raise ValueError( | ||
| 42 | ++ f"Invalid asset path: '{path}' escapes the asset directory." | ||
| 43 | ++ ) | ||
| 44 | ++ return joined.replace("\\", "/") | ||
| 45 | ++ | ||
| 46 | + def make(self, path): | ||
| 47 | + if not path: | ||
| 48 | + return self.working_dir | ||
| 49 | +- path = tf.io.gfile.join(self.working_dir, path) | ||
| 50 | ++ path = self._full_path(path) | ||
| 51 | + if not tf.io.gfile.exists(path): | ||
| 52 | + tf.io.gfile.makedirs(path) | ||
| 53 | + return path | ||
| 54 | + | ||
| 55 | + def get(self, path): | ||
| 56 | + if not path: | ||
| 57 | + return self.working_dir | ||
| 58 | +- path = tf.io.gfile.join(self.working_dir, path) | ||
| 59 | ++ path = self._full_path(path) | ||
| 60 | + if tf.io.gfile.exists(path): | ||
| 61 | + return path | ||
| 62 | + return None | ||
| 63 | + | ||
| 64 | + keras/saving/saving_lib.py | 25 +++++++++++++++++++++++++-- | ||
| 65 | + 1 file changed, 23 insertions(+), 2 deletions(-) | ||
Binary files do not support preview
| @@ -1,14 +1,15 @@ | |||
| 1 | %global _empty_manifest_terminate_build 0 | 1 | %global _empty_manifest_terminate_build 0 |
| 2 | Name: python-Keras | 2 | Name: python-Keras |
| 3 | -Version: 2.12.0 | 3 | +Version: 2.13.1 |
| 4 | Release: 2 | 4 | Release: 2 |
| 5 | Summary: Deep Learning for humans | 5 | Summary: Deep Learning for humans |
| 6 | License: Apache-2.0 | 6 | License: Apache-2.0 |
| 7 | URL: https://github.com/keras-team/keras | 7 | URL: https://github.com/keras-team/keras |
| 8 | -Source0: https://github.com/keras-team/keras/archive/refs/tags/v2.12.0.tar.gz#/keras-2.12.0.tar.gz | 8 | +Source0: https://github.com/keras-team/keras/archive/refs/tags/v%{version}.tar.gz#/keras-%{version}.tar.gz |
| 9 | BuildArch: noarch | 9 | BuildArch: noarch |
| 10 | 10 | ||
| 11 | Patch0: backport-CVE-2025-12058.patch | 11 | Patch0: backport-CVE-2025-12058.patch |
| 12 | +Patch1: backport-CVE-2026-12479.patch | ||
| 12 | 13 | ||
| 13 | Requires: python3-numpy | 14 | Requires: python3-numpy |
| 14 | Requires: python3-scipy | 15 | Requires: python3-scipy |
| @@ -98,6 +99,16 @@ mv %{buildroot}/doclist.lst . | |||
| 98 | %{_docdir}/* | 99 | %{_docdir}/* |
| 99 | 100 | ||
| 100 | %changelog | 101 | %changelog |
| 102 | +* Tue Jun 23 2026 infra_team <zhaiwenjie1@huawei.com> - 2.13.1-2 | ||
| 103 | +- Fix CVE-2026-12479 (DiskIOStore path traversal via un-sanitized asset paths) | ||
| 104 | +- Backport upstream commit d8caeb58cc9e61ea092445dc7a20908ca8d693e2 (PR #23017) | ||
| 105 | + to v2.13.1: add `_full_path()` helper in keras/saving/saving_lib.py that | ||
| 106 | + rejects paths containing `..` or absolute/remote prefixes; route make() and | ||
| 107 | + get() through it. | ||
| 108 | + | ||
| 109 | +* Mon Jan 26 2026 openeuler_bot <infra@openeuler.sh> - 2.13.1-1 | ||
| 110 | +- update python-Keras to 2.13.1 | ||
| 111 | + | ||
| 101 | * Mon Nov 10 2025 hugel <gengqihu2@h-partners.com> - 2.12.0-2 | 112 | * Mon Nov 10 2025 hugel <gengqihu2@h-partners.com> - 2.12.0-2 |
| 102 | - Fix CVE-2025-12058 | 113 | - Fix CVE-2025-12058 |
| 103 | 114 | ||