[wrynose][meta-python][PATCH 3/4] python3-h11: set CVE_PRODUCT
Anuj Mittal <[email protected]> Fri, 24 Jul 2026 06:37:45 +0530
| Newsgroups | org.openembedded.lists.openembedded-devel |
|---|---|
| Message-ID | <[email protected]> |
From: mark.yang <[email protected]> The pypi class default python:h11 doesn't match how h11 is tracked in the CVE databases. NVD has no CPE for it yet; the only existing record (CVE-2025-43859) carries python-hyper:h11 in its CNA affected entry [1], so set that pair. CVE-2025-43859 (request smuggling) is fixed in 0.16.0, the version we ship, so it resolves as not affected. [1] https://www.cve.org/CVERecord?id=CVE-2025-43859 Signed-off-by: mark.yang <[email protected]> Signed-off-by: Khem Raj <[email protected]> (cherry picked from commit a9bfe001bdfe740e89cf8afd41e6348e31a07211) Signed-off-by: Anuj Mittal <[email protected]> --- meta-python/recipes-devtools/python/python3-h11_0.16.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb b/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb index a47e6ab61e..ed1702ff54 100644 --- a/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb +++ b/meta-python/recipes-devtools/python/python3-h11_0.16.0.bb @@ -7,4 +7,6 @@ inherit pypi setuptools3 SRC_URI[sha256sum] = "4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208ee5ff1" +CVE_PRODUCT = "python-hyper:h11" + RDEPENDS:${PN} += "python3-profile" -- 2.54.0