From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <dkelaiya@cisco.com>
To: openembedded-core@lists.openembedded.org
Subject: Re: [scarthgap][PATCH] python3-py: ignore CVE-2022-42969
Date: Tue, 01 Sep 2026 23:16:05 -0700 [thread overview]
Message-ID: <2527846.1788329765934963865@lists.openembedded.org> (raw)
In-Reply-To: <DL3V33TEPWDN.ZM1L9P29KZF9@smile.fr>
[-- Attachment #1: Type: text/plain, Size: 1716 bytes --]
On Tue, Sep 1, 2026 at 02:40 PM, Yoann Congal wrote:
>
> On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>
>> From: Darsh Kelaiya <dkelaiya@cisco.com>
>>
>> Analysis:
>> - NVD marks CVE-2022-42969 as disputed because multiple parties could
>> not reproduce it and argue that it is not a valid vulnerability [1].
>> - GitHub withdrew the advisory because the available evidence does not
>> show a valid, reproducible vulnerability [2].
>> - Wrynose and master use the same python3-py version and carry the same
>> disputed CVE status, so that disposition applies to Scarthgap [3].
>> - Hence ignoring the CVE for now.
>>
>> Reference:
>> [1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
>> [2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
>> [3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
>>
>>
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
>> 1 file changed, 2 insertions(+)
>
> Hello,
>
> This CVE is already not in our metrics. Because OE-Core/scarthgap lacks
> these commits from meta-openembedded:
> * 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31)
> * 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21)
>
> Can you send a v2 series with these backports added?
>
> Thanks!
> --
> Yoann Congal
> Smile ECS
Hi Yoann,
I’ve added the two requested python3-py backports in the v2 series:
https://lists.openembedded.org/g/openembedded-core/topic/scarthgap_patch_v2_1_3/121047195
Thanks,
Darsh Kelaiya
[-- Attachment #2: Type: text/html, Size: 2185 bytes --]
prev parent reply other threads:[~2026-09-02 6:16 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 5:32 [OE-core][scarthgap][PATCH] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 9:10 ` Yoann Congal
2026-09-02 6:16 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2527846.1788329765934963865@lists.openembedded.org \
--to=dkelaiya@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.