diff options
author | Simone Weiß <simone.p.weiss@posteo.com> | 2024-02-18 22:32:32 +0000 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2024-02-24 16:10:23 +0000 |
commit | 2bcd651a0871a2a3789c2f2907cb372ad45d9b14 (patch) | |
tree | 0ea4bfbe273abb5d403e168ca38e65f1da75b782 | |
parent | 5e21c5d64eaf2a7bd8b7cc74e3ee9671cd6df35e (diff) | |
download | poky-2bcd651a0871a2a3789c2f2907cb372ad45d9b14.tar.gz |
meta: Update CVE_STATUS for incorrect cpes
Set CVE_STATUS as none of the issues apply against the versions
used in the recipes.
(From OE-Core rev: cea8c8bf73e84133f566d1c2ca0637494f2d7afe)
Signed-off-by: Simone Weiß <simone.p.weiss@posteo.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r-- | meta/recipes-bsp/grub/grub2.inc | 2 | ||||
-rw-r--r-- | meta/recipes-devtools/binutils/binutils-2.42.inc | 2 | ||||
-rw-r--r-- | meta/recipes-extended/ghostscript/ghostscript_10.02.1.bb | 1 | ||||
-rw-r--r-- | meta/recipes-multimedia/libtiff/tiff_4.6.0.bb | 1 |
4 files changed, 6 insertions, 0 deletions
diff --git a/meta/recipes-bsp/grub/grub2.inc b/meta/recipes-bsp/grub/grub2.inc index 83cf6047de..bb9aacb478 100644 --- a/meta/recipes-bsp/grub/grub2.inc +++ b/meta/recipes-bsp/grub/grub2.inc | |||
@@ -27,6 +27,8 @@ CVE_STATUS[CVE-2019-14865] = "not-applicable-platform: applies only to RHEL" | |||
27 | CVE_STATUS[CVE-2021-46705] = "not-applicable-platform: Applies only to SUSE" | 27 | CVE_STATUS[CVE-2021-46705] = "not-applicable-platform: Applies only to SUSE" |
28 | CVE_STATUS[CVE-2023-4001] = "not-applicable-platform: Applies only to RHEL/Fedora" | 28 | CVE_STATUS[CVE-2023-4001] = "not-applicable-platform: Applies only to RHEL/Fedora" |
29 | CVE_STATUS[CVE-2024-1048] = "not-applicable-platform: Applies only to RHEL/Fedora" | 29 | CVE_STATUS[CVE-2024-1048] = "not-applicable-platform: Applies only to RHEL/Fedora" |
30 | CVE_STATUS[CVE-2023-4692] = "cpe-incorrect: Fixed in version 2.12 already" | ||
31 | CVE_STATUS[CVE-2023-4693] = "cpe-incorrect: Fixed in version 2.12 already" | ||
30 | 32 | ||
31 | DEPENDS = "flex-native bison-native gettext-native" | 33 | DEPENDS = "flex-native bison-native gettext-native" |
32 | 34 | ||
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index b6c275af46..5fcb4292b3 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc | |||
@@ -18,6 +18,8 @@ SRCBRANCH ?= "binutils-2_42-branch" | |||
18 | 18 | ||
19 | UPSTREAM_CHECK_GITTAGREGEX = "binutils-(?P<pver>\d+_(\d_?)*)" | 19 | UPSTREAM_CHECK_GITTAGREGEX = "binutils-(?P<pver>\d+_(\d_?)*)" |
20 | 20 | ||
21 | CVE_STATUS[CVE-2023-25584] = "cpe-incorrect: Applies only for version 2.40 and earlier" | ||
22 | |||
21 | SRCREV ?= "553c7f61b74badf91df484450944675efd9cd485" | 23 | SRCREV ?= "553c7f61b74badf91df484450944675efd9cd485" |
22 | BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https" | 24 | BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https" |
23 | SRC_URI = "\ | 25 | SRC_URI = "\ |
diff --git a/meta/recipes-extended/ghostscript/ghostscript_10.02.1.bb b/meta/recipes-extended/ghostscript/ghostscript_10.02.1.bb index 2c965b6451..3dff16eec2 100644 --- a/meta/recipes-extended/ghostscript/ghostscript_10.02.1.bb +++ b/meta/recipes-extended/ghostscript/ghostscript_10.02.1.bb | |||
@@ -73,3 +73,4 @@ COMPATIBLE_HOST = "^(?!arc).*" | |||
73 | CVE_PRODUCT = "ghostscript gpl_ghostscript" | 73 | CVE_PRODUCT = "ghostscript gpl_ghostscript" |
74 | 74 | ||
75 | CVE_STATUS[CVE-2023-38560] = "not-applicable-config: PCL isn't part of the Ghostscript release" | 75 | CVE_STATUS[CVE-2023-38560] = "not-applicable-config: PCL isn't part of the Ghostscript release" |
76 | CVE_STATUS[CVE-2023-38559] = "cpe-incorrect: Issue only appears in versions before 10.02.0" | ||
diff --git a/meta/recipes-multimedia/libtiff/tiff_4.6.0.bb b/meta/recipes-multimedia/libtiff/tiff_4.6.0.bb index a26e4694f6..d42ea6a6e5 100644 --- a/meta/recipes-multimedia/libtiff/tiff_4.6.0.bb +++ b/meta/recipes-multimedia/libtiff/tiff_4.6.0.bb | |||
@@ -24,6 +24,7 @@ SRC_URI[sha256sum] = "88b3979e6d5c7e32b50d7ec72fb15af724f6ab2cbf7e10880c360a77e4 | |||
24 | UPSTREAM_CHECK_REGEX = "tiff-(?P<pver>\d+(\.\d+)+).tar" | 24 | UPSTREAM_CHECK_REGEX = "tiff-(?P<pver>\d+(\.\d+)+).tar" |
25 | 25 | ||
26 | CVE_STATUS[CVE-2015-7313] = "fixed-version: Tested with check from https://security-tracker.debian.org/tracker/CVE-2015-7313 and already 4.3.0 doesn't have the issue" | 26 | CVE_STATUS[CVE-2015-7313] = "fixed-version: Tested with check from https://security-tracker.debian.org/tracker/CVE-2015-7313 and already 4.3.0 doesn't have the issue" |
27 | CVE_STATUS[CVE-2023-3164] = "cpe-incorrect: Issue only affects the tiffcrop tool not compiled by default since 4.6.0" | ||
27 | 28 | ||
28 | inherit autotools multilib_header | 29 | inherit autotools multilib_header |
29 | 30 | ||