On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Darsh Kelaiya <[email protected]>
>
> Analysis:
> - NVD marks CVE-2022-42969 as disputed because multiple parties could
>   not reproduce it and argue that it is not a valid vulnerability [1].
> - GitHub withdrew the advisory because the available evidence does not
>   show a valid, reproducible vulnerability [2].
> - Wrynose and master use the same python3-py version and carry the same
>   disputed CVE status, so that disposition applies to Scarthgap [3].
> - Hence ignoring the CVE for now.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
> [2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
> [3] 
> https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
>
> Signed-off-by: Darsh Kelaiya <[email protected]>
> ---
>  meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
>  1 file changed, 2 insertions(+)

Hello,

This CVE is already not in our metrics. Because OE-Core/scarthgap lacks
these commits from meta-openembedded:
* 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31)
* 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21)

Can you send a v2 series with these backports added?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244812): 
https://lists.openembedded.org/g/openembedded-core/message/244812
Mute This Topic: https://lists.openembedded.org/mt/120932988/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to