From e0baff51a3a7239ee3f9005fe2790cb8bed2f828 Mon Sep 17 00:00:00 2001 From: "mark.yang" Date: Wed, 29 Jul 2026 01:44:15 -0700 Subject: [PATCH] python3-pyopenssl: set CVE_PRODUCT The pypi class default python:pyopenssl matches nothing in the CVE databases, which have used four vendor spellings for pyOpenSSL over the years: * CVE-2013-4314 (jean-paul_calderone:pyopenssl) * CVE-2018-1000807 (pyopenssl:pyopenssl) * CVE-2018-1000808 (pyopenssl_project:pyopenssl) * CVE-2026-27448, CVE-2026-27459 (pyca:pyopenssl in the CNA records, pyopenssl:pyopenssl in the NVD CPEs) Set all four vendor:product pairs. For scarthgap, python3-pyopenssl is 24.0.0. CVE-2026-27448 and CVE-2026-27459 are fixed in 26.0.0, so this metadata change will expose those CVEs as applicable/unpatched. The fixes for these CVEs need to be handled separately. Note: Original commit was for python3-pyopenssl_26.0.0.bb. This is adjusted for scarthgap where recipe version is python3-pyopenssl_24.0.0.bb. (From OE-Core rev: f6cc7e0c0a4a906244fc8cd4b45706d42a931fce) Signed-off-by: mark.yang Signed-off-by: Richard Purdie (cherry picked from commit ba3d752e577004f871fe7f4235e2625410140a08) Signed-off-by: Himanshu Jadon Signed-off-by: Fabien Thomas Signed-off-by: Paul Barker --- meta/recipes-devtools/python/python3-pyopenssl_24.0.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-pyopenssl_24.0.0.bb b/meta/recipes-devtools/python/python3-pyopenssl_24.0.0.bb index 94a70aa17d..ab00730b57 100644 --- a/meta/recipes-devtools/python/python3-pyopenssl_24.0.0.bb +++ b/meta/recipes-devtools/python/python3-pyopenssl_24.0.0.bb @@ -8,6 +8,7 @@ DEPENDS += "openssl python3-cryptography" SRC_URI[sha256sum] = "6aa33039a93fffa4563e655b61d11364d01264be8ccb49906101e02a334530bf" PYPI_PACKAGE = "pyOpenSSL" +CVE_PRODUCT = "jean-paul_calderone:pyopenssl pyca:pyopenssl pyopenssl:pyopenssl pyopenssl_project:pyopenssl" inherit pypi setuptools3 SRC_URI += " \