diff mbox series

[scarthgap,15/35] python3-babel: fix CVE_PRODUCT

Message ID 27c524d5c69993338612461831f7aec054eb4d00.1788787321.git.yoann.congal@smile.fr
State New
Headers show
Series [scarthgap,01/35] apt: mark CVE-2011-3374 as not-applicable-config | expand

Commit Message

Yoann Congal Sept. 7, 2026, 1:35 p.m. UTC
From: Tim Orling <tim.orling@konsulko.com>

Recipe (PV): python3-babel (2.14.0)
Before -> After: python:Babel -> pocoo:babel
Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE)
Status: patched (fixed 2.9.1)

Note: The original commit targeted python3-babel_2.18.0.bb. This is
adjusted for Scarthgap, where the recipe version is 2.14.0.

AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 134175fa92b85e639dc4646d9a88eeaba0fae4d3)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-devtools/python/python3-babel_2.14.0.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-devtools/python/python3-babel_2.14.0.bb b/meta/recipes-devtools/python/python3-babel_2.14.0.bb
index cd40d4222bf..5185fb21f56 100644
--- a/meta/recipes-devtools/python/python3-babel_2.14.0.bb
+++ b/meta/recipes-devtools/python/python3-babel_2.14.0.bb
@@ -9,6 +9,8 @@  PYPI_PACKAGE = "Babel"
 
 inherit pypi setuptools3
 
+CVE_PRODUCT = "pocoo:babel"
+
 CLEANBROKEN = "1"
 
 RDEPENDS:${PN} += " \