From 59e6bf89f6ba8c87e229391fb989e705b8448283 Mon Sep 17 00:00:00 2001 From: "mark.yang" Date: Wed, 22 Jul 2026 15:09:34 +0900 Subject: [PATCH] python3-aiodns: set CVE_PRODUCT and set status for CVE-2025-48945 The pypi class default python:aiodns doesn't match how aiodns is tracked in the CVE databases. NVD has no CPE for aiodns yet; the only existing record (CVE-2025-48945) carries aio-libs:aiodns in its CNA affected entry [1], so set that pair. CVE-2025-48945 itself is a use-after-free in pycares: the GHSA lives in the pycares repository [2] and the affected range "< 4.9.0" uses pycares version numbers (fixed in pycares 4.9.0 [3], we ship 5.0.1). Mark it cpe-incorrect so it doesn't get reported against aiodns. [1] https://www.cve.org/CVERecord?id=CVE-2025-48945 [2] https://github.com/saghul/pycares/security/advisories/GHSA-5qpg-rh4j-qp35 [3] https://github.com/saghul/pycares/releases/tag/v4.9.0 Signed-off-by: mark.yang Signed-off-by: Khem Raj --- meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb b/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb index 875ec724d3..eb66cc5f34 100644 --- a/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb +++ b/meta-python/recipes-devtools/python/python3-aiodns_4.0.4.bb @@ -15,4 +15,7 @@ RDEPENDS:${PN} += " \ python3-pycares \ " +CVE_PRODUCT = "aio-libs:aiodns" +CVE_STATUS[CVE-2025-48945] = "cpe-incorrect: this CVE is for pycares, fixed in pycares 4.9.0" + BBCLASSEXTEND = "native nativesdk"