Debian Patches

Status for python-kafka/2.2.3-1

Patch Description Author Forwarded Bugs Origin Last update
do-not-use-sphinxcontrib.napoleon-theme.patch Do not use the sphinxcontrib.napoleon sphinx theme This theme isn't available in Debian (yet), and I don't have the time to
package it, so for now, I'm just disabling the use of it.

===================================================================
Thomas Goirand <zigo@debian.org> no 2015-02-17
remove-multiple-privacy-breaches.patch =================================================================== no
no-intersphinx.patch No intersphinx
===================================================================
Thomas Goirand <zigo@debian.org> no 2016-07-11
skip-integration-test.patch Do not test integration This test is failing as his setup is trying to run kafka-server locally :
INFO:test.service: /<<PKGBUILDDIR>>/servers/0.11.0.2/kafka-bin/bin/kafka-run-class.sh
FileNotFoundError: [Errno 2] No such file or directory: '/<<PKGBUILDDIR>>/servers/0.11.0.2/kafka-bin/bin/kafka-run-class.sh'
This patch is adding pytest decorator to skip
this test.

===================================================================
Michal Arbet <michal.arbet@ultimum.io> no 2020-04-30
CVE-2026-10142_Validate_SASL_SCRAM_iterations.patch kafka.net: Validate SASL/SCRAM iterations (#3026)
===================================================================
Dana Powers <dana.powers@gmail.com> no debian upstream, https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b.patch 2026-11-13
CVE-2026-10142_validate_network_frame_size_restore_log-prefix.patch Validate the network frame size when receiving data, to avoid a denial of service from a malicious or man-in-the-middle
broker: a crafted 4-byte frame length could trigger a multi-gigabyte
memory allocation or an uncaught ValueError that leaves the connection
in a broken state (CVE-2026-10142).
This is a backport to the legacy kafka.conn architecture of upstream
commit bdb46ab, which was written for the kafka.net stack, and cannot
be applied as-is. The 0.8.2 quirk check part is already restricted to
v0 responses in this release, so it was left unchanged.

===================================================================
Dana Powers <dana.powers@gmail.com> not-needed debian upstream upstream, https://github.com/dpkp/kafka-python/commit/bdb46ab1fe4f090dd8bf710c7ddb778993bbc16b.patch 2026-09-17
test_memory_records_builder-float-precision.patch =================================================================== no
docs-conf-py-set-version-var.patch Set the 'version' variable in docs/conf.py docs/conf.py exec()s kafka/version.py, which imports the
importlib.metadata version() function into conf.py's namespace. Since
the 'version' config variable is never assigned, Sphinx's config.version
becomes that function object, and Sphinx 9.1 crashes with a TypeError
("expected string or bytes-like object, got 'function'") when escaping
it while dumping the object inventory (objects.inv).
Thomas Goirand <zigo@debian.org> no 2026-10-06

All known versions for source package 'python-kafka'

Links