python3-protobuf: mark CVE-2026-0994 patched

Details: https://nvd.nist.gov/vuln/detail/CVE-2026-0994

It is fixed already in the currently used version, however NVD tracks
it without any version info, so it still shows up in CVE reports.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Gyorgy Sarvari 2026-03-08 16:36:50 +01:00 committed by Anuj Mittal
parent 7b418ef060
commit 6bb74fff88
No known key found for this signature in database
GPG Key ID: 4340AEFE69F5085C

View File

@ -13,6 +13,7 @@ inherit pypi setuptools3
SRC_URI[sha256sum] = "6ddcac2a081f8b7b9642c09406bc6a4290128fce5f471cddd165960bb9119e5c"
CVE_PRODUCT += "google:protobuf protobuf:protobuf google-protobuf protobuf-python"
CVE_STATUS[CVE-2026-0994] = "fixed-version: it is fixed in 6.33.5"
# http://errors.yoctoproject.org/Errors/Details/184715/
# Can't find required file: ../src/google/protobuf/descriptor.proto