From f9a754faa64e419e3a3590f136372ae765477236 Mon Sep 17 00:00:00 2001 From: Richard Purdie Date: Tue, 11 May 2021 13:47:54 +0100 Subject: bluez: Exclude CVE-2020-12352 CVE-2020-24490 from cve-check These CVEs are fixed with kernel changes and don't affect the bluez recipe. (From OE-Core rev: d7779a9d58b088ce078956af4fdc0325d8c03c35) Signed-off-by: Richard Purdie (cherry picked from commit 658902477840ea34d414083c4c79616bf5e999a2) Signed-off-by: Steve Sakoman Signed-off-by: Richard Purdie --- meta/recipes-connectivity/bluez5/bluez5_5.55.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-connectivity/bluez5/bluez5_5.55.bb b/meta/recipes-connectivity/bluez5/bluez5_5.55.bb index 8190924562..e5353bd815 100644 --- a/meta/recipes-connectivity/bluez5/bluez5_5.55.bb +++ b/meta/recipes-connectivity/bluez5/bluez5_5.55.bb @@ -3,6 +3,9 @@ require bluez5.inc SRC_URI[md5sum] = "94972b8bc7ade60c72b0ffa6ccff2c0a" SRC_URI[sha256sum] = "8863717113c4897e2ad3271fc808ea245319e6fd95eed2e934fae8e0894e9b88" +# These issues have kernel fixes rather than bluez fixes so exclude here +CVE_CHECK_WHITELIST += "CVE-2020-12352 CVE-2020-24490" + # noinst programs in Makefile.tools that are conditional on READLINE # support NOINST_TOOLS_READLINE ?= " \ -- cgit v1.2.3-54-g00ecf