* [OE-core][wrynose][PATCH] python3-wheel: fix CVE_PRODUCT
@ 2026-08-20 9:07 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-20 9:07 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external
From: Tim Orling <tim.orling@konsulko.com>
The proper CVE_PRODUCT is "wheel_project:wheel".
BEFORE: python:wheel -> 0 CVEs
AFTER: wheel_project:wheel -> 2 CVEs
* Already patched at 0.46.3.
- CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1.
- CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary
files. Affects 0.40.0–<0.46.2.
Note: The original commit targeted python3-wheel_0.47.0.bb. This is
adjusted for Wrynose, where the recipe version is 0.46.3.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit fe55278e01bbe434452191109278b436bf008ebc)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
meta/recipes-devtools/python/python3-wheel_0.46.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
index 2545e5496e..7338e8edcd 100644
--- a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
+++ b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb
@@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "e3e79874b07d776c40bd6033f8ddf76a7dad46a7b8aa1b2787a8308351
inherit python_flit_core pypi ptest-python-pytest
+CVE_PRODUCT = "wheel_project:wheel"
+
RDEPENDS:${PN} += "python3-packaging"
# One test is skipped but requires the "full" python3-flit, not just python3-flit-core
--
2.35.6
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-20 9:08 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20 9:07 [OE-core][wrynose][PATCH] python3-wheel: fix CVE_PRODUCT Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.