[meta-virtualization] [scarthgap] [PATCH] criu: Add CVE_PRODUCT to align with NVD CPE

"Himanshu Jadon -X (hjadon - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]> Wed, 22 Apr 2026 21:40:30 -0700
Newsgroups org.yoctoproject.lists.meta-virtualization
Message-ID <[email protected]>
From: Himanshu Jadon <[email protected]>

CVE_PRODUCT has been set to criu:checkpoint/restore_in_userspace to align
with the product naming used in the NVD CPE database for criu.

The slash-containing product token is intentional as NVD references this
project under checkpoint/restore_in_userspace.

Only a single CPE entry exists in the NVD for this product:
 cpe:2.3:a:criu:checkpoint/restore_in_userspace

Signed-off-by: Himanshu Jadon <[email protected]>
Signed-off-by: Bruce Ashfield <[email protected]>
(cherry picked from commit 484a57d2df5d02e2cc64a7b7e03be93ffeaff8d4)
Signed-off-by: Himanshu Jadon <[email protected]>
---
 recipes-containers/criu/criu_git.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/recipes-containers/criu/criu_git.bb b/recipes-containers/criu/criu_git.bb
index cccd3e3c..a8915d16 100644
--- a/recipes-containers/criu/criu_git.bb
+++ b/recipes-containers/criu/criu_git.bb
@@ -111,3 +111,5 @@ FILES:${PN}-staticdev += " \
             ${libexecdir}/compel/std.lib.a \
             ${libexecdir}/compel/fds.lib.a \
             "
+
+CVE_PRODUCT = "criu:checkpoint\/restore_in_userspace"
-- 
2.35.6