* [OE-core][scarthgap][PATCH] python3-py: ignore CVE-2022-42969
@ 2026-08-26 5:32 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 9:10 ` Yoann Congal
0 siblings, 1 reply; 3+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 5:32 UTC (permalink / raw)
To: openembedded-core; +Cc: Darsh Kelaiya
From: Darsh Kelaiya <dkelaiya@cisco.com>
Analysis:
- NVD marks CVE-2022-42969 as disputed because multiple parties could
not reproduce it and argue that it is not a valid vulnerability [1].
- GitHub withdrew the advisory because the available evidence does not
show a valid, reproducible vulnerability [2].
- Wrynose and master use the same python3-py version and carry the same
disputed CVE status, so that disposition applies to Scarthgap [3].
- Hence ignoring the CVE for now.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
[2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
[3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index 31d5a377a7..2a16c6406b 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -5,6 +5,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
+CVE_STATUS[CVE-2022-42969] = "disputed: upstream could not reproduce it and GitHub withdrew the advisory"
+
DEPENDS += "python3-setuptools-scm-native"
inherit pypi python_setuptools_build_meta
--
2.35.6
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [OE-core][scarthgap][PATCH] python3-py: ignore CVE-2022-42969
2026-08-26 5:32 [OE-core][scarthgap][PATCH] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-01 9:10 ` Yoann Congal
2026-09-02 6:16 ` [scarthgap][PATCH] " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 1 reply; 3+ messages in thread
From: Yoann Congal @ 2026-09-01 9:10 UTC (permalink / raw)
To: dkelaiya, openembedded-core
On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <dkelaiya@cisco.com>
>
> Analysis:
> - NVD marks CVE-2022-42969 as disputed because multiple parties could
> not reproduce it and argue that it is not a valid vulnerability [1].
> - GitHub withdrew the advisory because the available evidence does not
> show a valid, reproducible vulnerability [2].
> - Wrynose and master use the same python3-py version and carry the same
> disputed CVE status, so that disposition applies to Scarthgap [3].
> - Hence ignoring the CVE for now.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
> [2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
> [3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
>
> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> ---
> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
> 1 file changed, 2 insertions(+)
Hello,
This CVE is already not in our metrics. Because OE-Core/scarthgap lacks
these commits from meta-openembedded:
* 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31)
* 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21)
Can you send a v2 series with these backports added?
Thanks!
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [scarthgap][PATCH] python3-py: ignore CVE-2022-42969
2026-09-01 9:10 ` Yoann Congal
@ 2026-09-02 6:16 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 3+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02 6:16 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 1716 bytes --]
On Tue, Sep 1, 2026 at 02:40 PM, Yoann Congal wrote:
>
> On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>
>> From: Darsh Kelaiya <dkelaiya@cisco.com>
>>
>> Analysis:
>> - NVD marks CVE-2022-42969 as disputed because multiple parties could
>> not reproduce it and argue that it is not a valid vulnerability [1].
>> - GitHub withdrew the advisory because the available evidence does not
>> show a valid, reproducible vulnerability [2].
>> - Wrynose and master use the same python3-py version and carry the same
>> disputed CVE status, so that disposition applies to Scarthgap [3].
>> - Hence ignoring the CVE for now.
>>
>> Reference:
>> [1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
>> [2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
>> [3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
>>
>>
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
>> 1 file changed, 2 insertions(+)
>
> Hello,
>
> This CVE is already not in our metrics. Because OE-Core/scarthgap lacks
> these commits from meta-openembedded:
> * 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31)
> * 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21)
>
> Can you send a v2 series with these backports added?
>
> Thanks!
> --
> Yoann Congal
> Smile ECS
Hi Yoann,
I’ve added the two requested python3-py backports in the v2 series:
https://lists.openembedded.org/g/openembedded-core/topic/scarthgap_patch_v2_1_3/121047195
Thanks,
Darsh Kelaiya
[-- Attachment #2: Type: text/html, Size: 2185 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-02 6:16 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 5:32 [OE-core][scarthgap][PATCH] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-01 9:10 ` Yoann Congal
2026-09-02 6:16 ` [scarthgap][PATCH] " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.