* [PATCH 1/5] python3-wheel: fix CVE_PRODUCT
@ 2026-08-09 23:21 tim.orling
2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling
2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling
0 siblings, 2 replies; 4+ messages in thread
From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw)
To: openembedded-core; +Cc: Tim Orling
From: Tim Orling <tim.orling@konsulko.com>
The proper CVE_PRODUCT is "wheel_project:wheel".
BEFORE: python:wheel -> 0 CVEs
AFTER: wheel_project:wheel -> 2 CVEs
* Already patched at 0.47.0.
- CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1.
- CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary
files. Affects 0.40.0–<0.46.2.
AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
---
meta/recipes-devtools/python/python3-wheel_0.47.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-wheel_0.47.0.bb b/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
index 88b54c2ee2..4320442729 100644
--- a/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
+++ b/meta/recipes-devtools/python/python3-wheel_0.47.0.bb
@@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "cc72bd1009ba0cf63922e28f94d9d83b920aa2bb28f798a31d0691b02f
inherit python_flit_core pypi ptest-python-pytest
+CVE_PRODUCT = "wheel_project:wheel"
+
RDEPENDS:${PN} += "python3-packaging"
# One test is skipped but requires the "full" python3-flit, not just python3-flit-core
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH 2/5] python3-attrs: fix CVE_PRODUCT 2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling @ 2026-08-09 23:21 ` tim.orling 2026-08-10 0:45 ` [OE-core] " Tim Orling 2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling 1 sibling, 1 reply; 4+ messages in thread From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw) To: openembedded-core; +Cc: Tim Orling From: Tim Orling <tim.orling@konsulko.com> No new CVEs are caught, but attrs_project:attrs matches the CPE upstream. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling <tim.orling@konsulko.com> --- meta/recipes-devtools/python/python3-attrs_26.1.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb index 03621e41a6..1c28809728 100644 --- a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb +++ b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "d03ceb89cb322a8fd706d4fb91940737b6642aa36998fe130a9bc96c98 inherit pypi ptest-python-pytest python_hatchling +CVE_PRODUCT = "attrs_project:attrs" + DEPENDS += " \ python3-hatch-vcs-native \ python3-hatch-fancy-pypi-readme-native \ -- 2.47.3 ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [OE-core] [PATCH 2/5] python3-attrs: fix CVE_PRODUCT 2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling @ 2026-08-10 0:45 ` Tim Orling 0 siblings, 0 replies; 4+ messages in thread From: Tim Orling @ 2026-08-10 0:45 UTC (permalink / raw) To: tim.orling; +Cc: openembedded-core [-- Attachment #1: Type: text/plain, Size: 1602 bytes --] This might not be correct. Hold off until we verify the CPE upstream. On Sun, Aug 9, 2026 at 4:21 PM Tim Orling via lists.openembedded.org <tim.orling=konsulko.com@lists.openembedded.org> wrote: > From: Tim Orling <tim.orling@konsulko.com> > > No new CVEs are caught, but attrs_project:attrs matches the CPE upstream. > > AI-Generated: Claude Sonnet 5 > Signed-off-by: Tim Orling <tim.orling@konsulko.com> > --- > meta/recipes-devtools/python/python3-attrs_26.1.0.bb | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb > b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb > index 03621e41a6..1c28809728 100644 > --- a/meta/recipes-devtools/python/python3-attrs_26.1.0.bb > +++ b/meta/recipes-devtools/python/python3-attrs_26.1.0.bb > @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = > "d03ceb89cb322a8fd706d4fb91940737b6642aa36998fe130a9bc96c98 > > inherit pypi ptest-python-pytest python_hatchling > > +CVE_PRODUCT = "attrs_project:attrs" > + > DEPENDS += " \ > python3-hatch-vcs-native \ > python3-hatch-fancy-pypi-readme-native \ > -- > 2.47.3 > > > -=-=-=-=-=-=-=-=-=-=-=- > Links: You receive all messages sent to this group. > View/Reply Online (#243084): > https://lists.openembedded.org/g/openembedded-core/message/243084 > Mute This Topic: https://lists.openembedded.org/mt/120677496/924729 > Group Owner: openembedded-core+owner@lists.openembedded.org > Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [ > ticotimo@gmail.com] > -=-=-=-=-=-=-=-=-=-=-=- > > [-- Attachment #2: Type: text/html, Size: 3032 bytes --] ^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 3/5] python3-babel: fix CVE_PRODUCT 2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling 2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling @ 2026-08-09 23:21 ` tim.orling 1 sibling, 0 replies; 4+ messages in thread From: tim.orling @ 2026-08-09 23:21 UTC (permalink / raw) To: openembedded-core; +Cc: Tim Orling From: Tim Orling <tim.orling@konsulko.com> Recipe (PV): python3-babel (2.18.0) Before -> After: python:babel -> pocoo:babel Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE) Status: patched (fixed 2.9.1) AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling <tim.orling@konsulko.com> --- meta/recipes-devtools/python/python3-babel_2.18.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-babel_2.18.0.bb b/meta/recipes-devtools/python/python3-babel_2.18.0.bb index b0abb2c62e..26847372bf 100644 --- a/meta/recipes-devtools/python/python3-babel_2.18.0.bb +++ b/meta/recipes-devtools/python/python3-babel_2.18.0.bb @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "b80b99a14bd085fcacfa15c9165f651fbb3406e66cc603abf11c575093 inherit pypi setuptools3 +CVE_PRODUCT = "pocoo:babel" + S = "${UNPACKDIR}/babel-${PV}" CLEANBROKEN = "1" -- 2.47.3 ^ permalink raw reply related [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-10 0:45 UTC | newest] Thread overview: 4+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-09 23:21 [PATCH 1/5] python3-wheel: fix CVE_PRODUCT tim.orling 2026-08-09 23:21 ` [PATCH 2/5] python3-attrs: " tim.orling 2026-08-10 0:45 ` [OE-core] " Tim Orling 2026-08-09 23:21 ` [PATCH 3/5] python3-babel: " tim.orling
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox