* [PATCH 1/5] python3-wheel: fix CVE_PRODUCT
@ 2026-08-09 23:21 tim.orling
2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling
2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling
0 siblings, 2 replies; 4+ messages in thread
From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw)
To: openembedded-core; +Cc: Tim Orling
From: Tim Orling <tim.orling@konsulko.com>
The proper CVE_PRODUCT is "wheel_project:wheel".
BEFORE: python:wheel -> 0 CVEs
AFTER: wheel_project:wheel -> 2 CVEs
* Already patched at 0.47.0.
- CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1.
- CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary
files. Affects 0.40.0–<0.46.2.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
---
meta/recipes-devtools/python/python3-wheel_0.47.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-wheel_0.47.0.bb b/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
index 88b54c2ee2..4320442729 100644
--- a/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
+++ b/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
@@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "cc72bd1009ba0cf63922e28f94d9d83b920aa2bb28f798a31d0691b02f
inherit python_flit_core pypi ptest-python-pytest
+CVE_PRODUCT = "wheel_project:wheel"
+
RDEPENDS:${PN} += "python3-packaging"
# One test is skipped but requires the "full" python3-flit, not just python3-flit-core
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 2/5] python3-attrs: fix CVE_PRODUCT
2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling
@ 2026-08-09 23:21 ` tim.orling
2026-08-10 0:45 ` [OE-core] " Tim Orling
2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling
1 sibling, 1 reply; 4+ messages in thread
From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw)
To: openembedded-core; +Cc: Tim Orling
From: Tim Orling <tim.orling@konsulko.com>
No new CVEs are caught, but attrs_project:attrs matches the CPE upstream.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
---
meta/recipes-devtools/python/python3-attrs_26.1.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
index 03621e41a6..1c28809728 100644
--- a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
+++ b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "d03ceb89cb322a8fd706d4fb91940737b6642aa36998fe130a9bc96c98
inherit pypi ptest-python-pytest python_hatchling
+CVE_PRODUCT = "attrs_project:attrs"
+
DEPENDS += " \
python3-hatch-vcs-native \
python3-hatch-fancy-pypi-readme-native \
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 3/5] python3-babel: fix CVE_PRODUCT
2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling
2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling
@ 2026-08-09 23:21 ` tim.orling
1 sibling, 0 replies; 4+ messages in thread
From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw)
To: openembedded-core; +Cc: Tim Orling
From: Tim Orling <tim.orling@konsulko.com>
Recipe (PV): python3-babel (2.18.0)
Before -> After: python:babel -> pocoo:babel
Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE)
Status: patched (fixed 2.9.1)
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
---
meta/recipes-devtools/python/python3-babel_2.18.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-babel_2.18.0.bb b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
index b0abb2c62e..26847372bf 100644
--- a/meta/recipes-devtools/python/python3-babel_2.18.0.bb
+++ b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "b80b99a14bd085fcacfa15c9165f651fbb3406e66cc603abf11c575093
inherit pypi setuptools3
+CVE_PRODUCT = "pocoo:babel"
+
S = "${UNPACKDIR}/babel-${PV}"
CLEANBROKEN = "1"
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [OE-core] [PATCH 2/5] python3-attrs: fix CVE_PRODUCT
2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling
@ 2026-08-10 0:45 ` Tim Orling
0 siblings, 0 replies; 4+ messages in thread
From: Tim Orling @ 2026-08-10 0:45 UTC (permalink / raw)
To: tim.orling; +Cc: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 1602 bytes --]
This might not be correct. Hold off until we verify the CPE upstream.
On Sun, Aug 9, 2026 at 4:21 PM Tim Orling via lists.openembedded.org
<tim.orling=konsulko.com@lists.openembedded.org> wrote:
> From: Tim Orling <tim.orling@konsulko.com>
>
> No new CVEs are caught, but attrs_project:attrs matches the CPE upstream.
>
> AI-Generated: Claude Sonnet 5
> Signed-off-by: Tim Orling <tim.orling@konsulko.com>
> ---
> meta/recipes-devtools/python/python3-attrs_26.1.0.bb | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
> b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
> index 03621e41a6..1c28809728 100644
> --- a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
> +++ b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb
> @@ -7,6 +7,8 @@ SRC_URI[sha256sum] =
> "d03ceb89cb322a8fd706d4fb91940737b6642aa36998fe130a9bc96c98
>
> inherit pypi ptest-python-pytest python_hatchling
>
> +CVE_PRODUCT = "attrs_project:attrs"
> +
> DEPENDS += " \
> python3-hatch-vcs-native \
> python3-hatch-fancy-pypi-readme-native \
> --
> 2.47.3
>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#243084):
> https://lists.openembedded.org/g/openembedded-core/message/243084
> Mute This Topic: https://lists.openembedded.org/mt/120677496/924729
> Group Owner: openembedded-core+owner@lists.openembedded.org
> Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [
> ticotimo@gmail.com]
> -=-=-=-=-=-=-=-=-=-=-=-
>
>
[-- Attachment #2: Type: text/html, Size: 3032 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-10 0:45 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling
2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling
2026-08-10 0:45 ` [OE-core] " Tim Orling
2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox