From f65ce1d3264f3c9be76d88c34cf181264a47c7a3 Mon Sep 17 00:00:00 2001 From: Tim Orling Date: Thu, 20 Aug 2026 02:07:26 -0700 Subject: [PATCH] python3-wheel: fix CVE_PRODUCT MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The proper CVE_PRODUCT is "wheel_project:wheel". BEFORE: python:wheel -> 1 CVE AFTER: wheel_project:wheel -> 2 CVEs * Both are patched at 0.42.0. - CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1. - CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary files. Affects 0.40.0–<0.46.2; covered by the existing CVE-2026-24049.patch. Note: The original commit targeted python3-wheel_0.47.0.bb. This is adjusted for Scarthgap, where the recipe version is 0.42.0. AI-Generated: Claude Sonnet 5 (From OE-Core rev: 6125825144dac3f5aea440307e4b6b7e76d5333a) Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit fe55278e01bbe434452191109278b436bf008ebc) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal Signed-off-by: Richard Purdie --- meta/recipes-devtools/python/python3-wheel_0.42.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-wheel_0.42.0.bb b/meta/recipes-devtools/python/python3-wheel_0.42.0.bb index 934f258a93..b3e4a08d85 100644 --- a/meta/recipes-devtools/python/python3-wheel_0.42.0.bb +++ b/meta/recipes-devtools/python/python3-wheel_0.42.0.bb @@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "c45be39f7882c9d34243236f2d63cbd58039e360f85d0913425fbd7cee inherit python_flit_core pypi +CVE_PRODUCT = "wheel_project:wheel" + SRC_URI += "file://CVE-2026-24049.patch" BBCLASSEXTEND = "native nativesdk"