From b479e720ab9565c010effe0a40cfafb774cce8d7 Mon Sep 17 00:00:00 2001 From: Yogesh Tyagi Date: Wed, 7 Sep 2022 13:14:18 +0800 Subject: dpdk: ignore CVE-2022-0669 This is fixed in 21.11.1 but the CPE data in NVD is incomplete. [ upstream commit link https://git.dpdk.org/dpdk-stable/commit/?h=21.11&id=6cb68162e4b598b7c0747372fa3fcec9cddd19b8 ] Signed-off-by: Yogesh Tyagi Signed-off-by: Anuj Mittal --- recipes-extended/dpdk/dpdk_21.11.2.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/recipes-extended/dpdk/dpdk_21.11.2.bb b/recipes-extended/dpdk/dpdk_21.11.2.bb index 570648a..6f1c521 100644 --- a/recipes-extended/dpdk/dpdk_21.11.2.bb +++ b/recipes-extended/dpdk/dpdk_21.11.2.bb @@ -11,8 +11,11 @@ S = "${WORKDIR}/git" # CVE-2021-3839 has been fixed by commit 4c40d30d2b in 21.11.1 # NVD database is incomplete +# CVE-2022-0669 has been fixed by commit 6cb68162e4 in 21.11.1 +# NVD database is incomplete CVE_CHECK_IGNORE += "\ CVE-2021-3839 \ + CVE-2022-0669 \ " # kernel module is provide by dpdk-module recipe, so disable here -- cgit v1.2.3-54-g00ecf