On Tue, Sep 1, 2026 at 02:40 PM, Yoann Congal wrote:
On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
From: Darsh Kelaiya <dkelaiya@cisco.com>
Analysis:
- NVD marks CVE-2022-42969 as disputed because multiple parties could
not reproduce it and argue that it is not a valid vulnerability [1].
- GitHub withdrew the advisory because the available evidence does not
show a valid, reproducible vulnerability [2].
- Wrynose and master use the same python3-py version and carry the same
disputed CVE status, so that disposition applies to Scarthgap [3].
- Hence ignoring the CVE for now.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
[2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
[3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
1 file changed, 2 insertions(+)
Hello,
This CVE is already not in our metrics. Because OE-Core/scarthgap lacks
these commits from meta-openembedded:
* 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31)
* 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21)
Can you send a v2 series with these backports added?
Thanks!
--
Yoann Congal
Smile ECS
Hi Yoann,
I’ve added the two requested python3-py backports in the v2 series:
https://lists.openembedded.org/g/openembedded-core/topic/scarthgap_patch_v2_1_3/121047195
Thanks,
Darsh Kelaiya