[Buildroot] [git commit branch/2026.05.x] package/mbedtls: fix CPE

Titouan Christophe via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
commit: https://gitlab.com/buildroot.org/buildroot/-/commit/0916cf0a64b7e5b95f8b99ddb303b6c6d07ca609
branch: https://gitlab.com/buildroot.org/buildroot/-/tree/2026.05.x

A new (and hopefully definitive) CPE is to be used for mbedtls:

cpe:2.3:a:trustedfirmware:mbed_tls:

CVEs for projects under the TrustedFirmware umbrella are now seemingly
handled under the CPE vendor "trustedfirmware"[1].

NVD correctly reports[2] the new CPE deprecates the "old" one Buildroot
was using.

[1] https://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/49486/comment/2fd93ed7_df27998e/ before last comment from Sandrine
[2] https://nvd.nist.gov/products/cpe/detail/453A781D-74D5-4FB5-9BB6-8C1F7F281A7A
Signed-off-by: Quentin Schulz <[email protected]>
Signed-off-by: Julien Olivain <[email protected]>
(cherry picked from commit d2ceab1c154aeab278f50f4f1451afdacda630f4)
Signed-off-by: Titouan Christophe <[email protected]>
---
 package/mbedtls/mbedtls.mk | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/package/mbedtls/mbedtls.mk b/package/mbedtls/mbedtls.mk
index e8bb0a71b9..9def876808 100644
--- a/package/mbedtls/mbedtls.mk
+++ b/package/mbedtls/mbedtls.mk
@@ -15,7 +15,7 @@ MBEDTLS_CONF_OPTS = \
 MBEDTLS_INSTALL_STAGING = YES
 MBEDTLS_LICENSE = Apache-2.0 or GPL-2.0+
 MBEDTLS_LICENSE_FILES = LICENSE
-MBEDTLS_CPE_ID_VENDOR = arm
+MBEDTLS_CPE_ID_VENDOR = trustedfirmware
 MBEDTLS_CPE_ID_PRODUCT = mbed_tls
 
 # This is mandatory for hiawatha
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.