> -----Original Message-----
> From: [email protected] <openembedded-
> [email protected]> On Behalf Of Jaipaul Cheernam
> Sent: Thursday, August 6, 2026 2:43 PM
> To: [email protected]
> Cc: Jaipaul Cheernam <[email protected]>
> Subject: [OE-core] [PATCH] python3: upgrade 3.14.6 -> 3.14.7
> 
> Release notes: [1]
> 
> Resolves following CVEs:
> * CVE-2026-4360
> * CVE-2026-11940
> * CVE-2026-11972

Where is this list of resolved CVEs coming from? It looks like list of 
previously manually patched CVEs.
If I run sbom_cve_check_recipe on python 3.14.7, I get following CVEs with 
detail "fixed-version: Fixed from version 3.14.7"
          "id": "CVE-2025-15366",
          "id": "CVE-2026-0864",
          "id": "CVE-2026-11940",
          "id": "CVE-2026-11972",
          "id": "CVE-2026-12003",
          "id": "CVE-2026-4360",
          "id": "CVE-2026-6879",

Also note that the new CVE_STATUS entries added in this patch should be removed.
The are resolved automatically and we should explicitly list only those which 
are not automated.

Peter

> 
> Removed patches included in this release.
> Removed obsolete CVE_STATUS entries.
> 
> [1] https://docs.python.org/3/whatsnew/changelog.html#python-3-14-7-final
> 
> Signed-off-by: Jaipaul Cheernam <[email protected]>
> ---
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242967): 
https://lists.openembedded.org/g/openembedded-core/message/242967
Mute This Topic: https://lists.openembedded.org/mt/120625582/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to