diff mbox series

[3/5] python3-babel: fix CVE_PRODUCT

Message ID 20260809232107.367378-7-tim.orling@konsulko.com
State Under Review
Headers show
Series [1/5] python3-wheel: fix CVE_PRODUCT | expand

Commit Message

Tim Orling Aug. 9, 2026, 11:21 p.m. UTC
From: Tim Orling <tim.orling@konsulko.com>

Recipe (PV): python3-babel (2.18.0)
Before -> After: python:babel -> pocoo:babel
Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE)
Status: patched (fixed 2.9.1)

AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
---
 meta/recipes-devtools/python/python3-babel_2.18.0.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-devtools/python/python3-babel_2.18.0.bb b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
index b0abb2c62e..26847372bf 100644
--- a/meta/recipes-devtools/python/python3-babel_2.18.0.bb
+++ b/meta/recipes-devtools/python/python3-babel_2.18.0.bb
@@ -7,6 +7,8 @@  SRC_URI[sha256sum] = "b80b99a14bd085fcacfa15c9165f651fbb3406e66cc603abf11c575093
 
 inherit pypi setuptools3
 
+CVE_PRODUCT = "pocoo:babel"
+
 S = "${UNPACKDIR}/babel-${PV}"
 
 CLEANBROKEN = "1"