On Wed Aug 26, 2026 at 7:32 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote: > From: Darsh Kelaiya <[email protected]> > > Analysis: > - NVD marks CVE-2022-42969 as disputed because multiple parties could > not reproduce it and argue that it is not a valid vulnerability [1]. > - GitHub withdrew the advisory because the available evidence does not > show a valid, reproducible vulnerability [2]. > - Wrynose and master use the same python3-py version and carry the same > disputed CVE status, so that disposition applies to Scarthgap [3]. > - Hence ignoring the CVE for now. > > Reference: > [1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969 > [2] https://github.com/advisories/GHSA-w596-4wvx-j9j6 > [3] > https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1 > > Signed-off-by: Darsh Kelaiya <[email protected]> > --- > meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++ > 1 file changed, 2 insertions(+)
Hello, This CVE is already not in our metrics. Because OE-Core/scarthgap lacks these commits from meta-openembedded: * 1fac509459 (python3-py: set CVE_PRODUCT, 2025-12-31) * 26fa8b053b (python3-py: correct CVE_PRODUCT mapping, 2026-08-21) Can you send a v2 series with these backports added? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244812): https://lists.openembedded.org/g/openembedded-core/message/244812 Mute This Topic: https://lists.openembedded.org/mt/120932988/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
