diff mbox series

[meta-python,1/2] python3-aiodns: set CVE_PRODUCT and set status for CVE-2025-48945

Message ID 20260722060935.273232-1-mark.yang@lge.com
State Under Review
Headers show
Series [meta-python,1/2] python3-aiodns: set CVE_PRODUCT and set status for CVE-2025-48945 | expand

Commit Message

mark.yang July 22, 2026, 6:09 a.m. UTC
From: "mark.yang" <mark.yang@lge.com>

The pypi class default python:aiodns doesn't match how aiodns is
tracked in the CVE databases. NVD has no CPE for aiodns yet; the only
existing record (CVE-2025-48945) carries aio-libs:aiodns in its CNA
affected entry [1], so set that pair.

CVE-2025-48945 itself is a use-after-free in pycares: the GHSA lives
in the pycares repository [2] and the affected range "< 4.9.0" uses
pycares version numbers (fixed in pycares 4.9.0 [3], we ship 5.0.1).
Mark it cpe-incorrect so it doesn't get reported against aiodns.

[1] https://www.cve.org/CVERecord?id=CVE-2025-48945
[2] https://github.com/saghul/pycares/security/advisories/GHSA-5qpg-rh4j-qp35
[3] https://github.com/saghul/pycares/releases/tag/v4.9.0

Signed-off-by: mark.yang <mark.yang@lge.com>
---
 meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb | 3 +++
 1 file changed, 3 insertions(+)
diff mbox series

Patch

diff --git a/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb b/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb
index 875ec724d3..eb66cc5f34 100644
--- a/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb
+++ b/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb
@@ -15,4 +15,7 @@  RDEPENDS:${PN} += " \
     python3-pycares \
 "
 
+CVE_PRODUCT = "aio-libs:aiodns"
+CVE_STATUS[CVE-2025-48945] = "cpe-incorrect: this CVE is for pycares, fixed in pycares 4.9.0"
+
 BBCLASSEXTEND = "native nativesdk"