已开启
fix(cve): 修复 CVE-2026-12479 在 python-Keras 中的漏洞 #24
fix(cve): 修复 CVE-2026-12479 在 python-Keras 中的漏洞 #24
已开启
infra_team创建于 6月23日
共 4 个文件变更+78-2
@@ -0,0 +1,65 @@
1+From d8caeb58cc9e61ea092445dc7a20908ca8d693e2 Mon Sep 17 00:00:00 2001
2+From: Ziyu Lin <104151270+LinZiyuu@users.noreply.github.com>
3+Date: Wed, 3 Jun 2026 01:57:33 +0800
4+Subject: [PATCH] Validate DiskIOStore asset paths stay within the working
5+ directory (#23017)
6+ 
7+Backport of upstream commit d8caeb58cc9e61ea092445dc7a20908ca8d693e2 to
8+Keras 2.13.1 (keras/saving/saving_lib.py). v2.x uses tf.io.gfile instead
9+of file_utils, and DiskIOStore does not yet have a has_path method, so
10+this patch only updates make()/get() and adds _full_path() with the
11+equivalent v2.x semantics (os.path.realpath for local; string check
12+for remote working directories such as gs://).
13+ 
14+Reference: https://github.com/keras-team/keras/commit/d8caeb58cc9e61ea092445dc7a20908ca8d693e2
15+Signed-off-by: infra_team <zhaiwenjie1@huawei.com>
16+---
17+--- a/keras/saving/saving_lib.py
18++++ b/keras/saving/saving_lib.py
19+@@ -552,10 +552,33 @@
20+ )
21+ tf.io.gfile.makedirs(self.working_dir)
22+
23++ def _full_path(self, path):
24++ """Resolve `path` under the working dir, rejecting traversal."""
25++ # Normalize separators first so a `\` cannot bypass the check below.
26++ path = path.replace("\\", "/")
27++ if "://" in self.working_dir or self.working_dir.startswith("/"):
28++ # `realpath` would corrupt a remote prefix such as `gs://bucket`,
29++ # so validate remote paths by string instead.
30++ if path.startswith("/") or "://" in path or ".." in path.split("/"):
31++ raise ValueError(
32++ f"Invalid asset path: '{path}' escapes the asset directory."
33++ )
34++ return tf.io.gfile.join(self.working_dir, path).replace("\\", "/")
35++ working_dir_real = os.path.realpath(self.working_dir)
36++ joined = os.path.realpath(os.path.join(working_dir_real, path))
37++ if (
38++ joined != working_dir_real
39++ and not joined.startswith(working_dir_real + os.sep)
40++ ):
41++ raise ValueError(
42++ f"Invalid asset path: '{path}' escapes the asset directory."
43++ )
44++ return joined.replace("\\", "/")
45++
46+ def make(self, path):
47+ if not path:
48+ return self.working_dir
49+- path = tf.io.gfile.join(self.working_dir, path)
50++ path = self._full_path(path)
51+ if not tf.io.gfile.exists(path):
52+ tf.io.gfile.makedirs(path)
53+ return path
54+@@ -563,7 +586,7 @@
55+ def get(self, path):
56+ if not path:
57+ return self.working_dir
58+- path = tf.io.gfile.join(self.working_dir, path)
59++ path = self._full_path(path)
60+ if tf.io.gfile.exists(path):
61+ return path
62+ return None
63+ 
64+ keras/saving/saving_lib.py | 25 +++++++++++++++++++++++++--
65+ 1 file changed, 23 insertions(+), 2 deletions(-)
Binary files do not support preview
Binary files do not support preview
@@ -1,14 +1,15 @@
1%global _empty_manifest_terminate_build 01%global _empty_manifest_terminate_build 0
2Name: python-Keras2Name: python-Keras
3-Version: 2.12.03+Version: 2.13.1
4Release: 24Release: 2
5Summary: Deep Learning for humans5Summary: Deep Learning for humans
6License: Apache-2.06License: Apache-2.0
7URL: https://github.com/keras-team/keras7URL: https://github.com/keras-team/keras
8-Source0: https://github.com/keras-team/keras/archive/refs/tags/v2.12.0.tar.gz#/keras-2.12.0.tar.gz8+Source0: https://github.com/keras-team/keras/archive/refs/tags/v%{version}.tar.gz#/keras-%{version}.tar.gz
9BuildArch: noarch9BuildArch: noarch
10 10 
11Patch0: backport-CVE-2025-12058.patch11Patch0: backport-CVE-2025-12058.patch
12+Patch1: backport-CVE-2026-12479.patch
12 13 
13Requires: python3-numpy14Requires: python3-numpy
14Requires: python3-scipy15Requires: python3-scipy
@@ -98,6 +99,16 @@ mv %{buildroot}/doclist.lst .
98%{_docdir}/*99%{_docdir}/*
99 100 
100%changelog101%changelog
102+* Tue Jun 23 2026 infra_team <zhaiwenjie1@huawei.com> - 2.13.1-2
103+- Fix CVE-2026-12479 (DiskIOStore path traversal via un-sanitized asset paths)
104+- Backport upstream commit d8caeb58cc9e61ea092445dc7a20908ca8d693e2 (PR #23017)
105+ to v2.13.1: add `_full_path()` helper in keras/saving/saving_lib.py that
106+ rejects paths containing `..` or absolute/remote prefixes; route make() and
107+ get() through it.
108+ 
109+* Mon Jan 26 2026 openeuler_bot <infra@openeuler.sh> - 2.13.1-1
110+- update python-Keras to 2.13.1
111+ 
101* Mon Nov 10 2025 hugel <gengqihu2@h-partners.com> - 2.12.0-2112* Mon Nov 10 2025 hugel <gengqihu2@h-partners.com> - 2.12.0-2
102- Fix CVE-2025-12058113- Fix CVE-2025-12058
103 114