From: Devansh Patel <[email protected]>

u-boot-tools builds host utilities from the same source as u-boot, but it
does not inherit the existing CVE_PRODUCT assignment and falls back to its
unrecognized recipe-name identity.  Move the mapping to u-boot-common.inc
so both recipes inherit it.

Use "u-boot:u-boot" for the CNA/CVE List V5 affected-data identity and
"denx:u-boot" for the NVD dictionary CPE and configuration identity.  The
CNA records are also covered by NVD today, but retaining both authoritative
identities permits direct matching independently of NVD enrichment.

(cherry picked from commit bc30a343627e2d207c38d2262a7b07f506259051)

Signed-off-by: Devansh Patel <[email protected]>
Signed-off-by: Mathieu Dubois-Briand <[email protected]>
Signed-off-by: Richard Purdie <[email protected]>
Signed-off-by: Hiago De Franco <[email protected]>
---
 meta/recipes-bsp/u-boot/u-boot-common.inc | 2 ++
 meta/recipes-bsp/u-boot/u-boot.inc        | 2 --
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/meta/recipes-bsp/u-boot/u-boot-common.inc 
b/meta/recipes-bsp/u-boot/u-boot-common.inc
index 5e2ec08c30..88f6ee91b1 100644
--- a/meta/recipes-bsp/u-boot/u-boot-common.inc
+++ b/meta/recipes-bsp/u-boot/u-boot-common.inc
@@ -10,6 +10,8 @@ LICENSE = "GPL-2.0-or-later"
 LIC_FILES_CHKSUM = 
"file://Licenses/README;md5=2ca5f2c35c8cc335f0a19756634782f1"
 PE = "1"
 
+CVE_PRODUCT = "u-boot:u-boot denx:u-boot"
+
 # We use the revision in order to avoid having to fetch it from the
 # repo during parse
 SRCREV = "127a42c7257a6ffbbd1575ed1cbaa8f5408a44b3"
diff --git a/meta/recipes-bsp/u-boot/u-boot.inc 
b/meta/recipes-bsp/u-boot/u-boot.inc
index a75948dfc3..8a084d8ac0 100644
--- a/meta/recipes-bsp/u-boot/u-boot.inc
+++ b/meta/recipes-bsp/u-boot/u-boot.inc
@@ -21,8 +21,6 @@ PACKAGECONFIG ??= "openssl"
 # a host build dependency.
 PACKAGECONFIG[openssl] = ",,openssl-native"
 
-CVE_PRODUCT = "denx:u-boot"
-
 # Allow setting an additional version string that will be picked up by the
 # u-boot build system and appended to the u-boot version.  If the .scmversion
 # file already exists it will not be overwritten.

---
base-commit: 9da814ca3685ada3fce46b8987f04ed3d57247b7
change-id: 20260909-uboot-cve-product-wrynose-33e07f593ab6

Best regards,
--  
Hiago

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245461): 
https://lists.openembedded.org/g/openembedded-core/message/245461
Mute This Topic: https://lists.openembedded.org/mt/121162088/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to