On 2026-08-06 19:49, Marko, Peter wrote:
-----Original Message-----
From: [email protected] <openembedded-
[email protected]> On Behalf Of Jaipaul Cheernam
Sent: Thursday, August 6, 2026 2:43 PM
To: [email protected]
Cc: Jaipaul Cheernam <[email protected]>
Subject: [OE-core] [PATCH] python3: upgrade 3.14.6 -> 3.14.7
Release notes: [1]
Resolves following CVEs:
* CVE-2026-4360
* CVE-2026-11940
* CVE-2026-11972
Where is this list of resolved CVEs coming from? It looks like list of
previously manually patched CVEs.
If I run sbom_cve_check_recipe on python 3.14.7, I get following CVEs with detail
"fixed-version: Fixed from version 3.14.7"
"id": "CVE-2025-15366",
"id": "CVE-2026-0864",
"id": "CVE-2026-11940",
"id": "CVE-2026-11972",
"id": "CVE-2026-12003",
"id": "CVE-2026-4360",
"id": "CVE-2026-6879",
Also note that the new CVE_STATUS entries added in this patch should be removed.
The are resolved automatically and we should explicitly list only those which
are not automated.
Peter
Hi Peter,
Thanks for the review.
You're right — the "Resolves following CVEs" is not the full list
fixed in 3.14.7.
I've also removed the CVE_STATUS entries since the scanner resolves them
automatically.
Will send v2.
Regards,
Jaipaul
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242984):
https://lists.openembedded.org/g/openembedded-core/message/242984
Mute This Topic: https://lists.openembedded.org/mt/120625582/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-