Files
buildroot/package/python-filelock
Thomas Perale 70072dc0e2 package/python-filelock: fix CVE-2025-68146
Fixes the following vulnerability:

- CVE-2025-68146

A Time-of-Check-Time-of-Use (TOCTOU) race condition allows local
attackers to corrupt or truncate arbitrary user files through symlink
attacks.

For more informations, see:
  - https://nvd.nist.gov/vuln/detail/CVE-2025-68146
  - https://github.com/tox-dev/filelock/commit/18a99880087934252e7c0c994640f66e80e34be9

(cherry picked from commit d9c1379d1f)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-01-02 18:22:30 +01:00
..