summaryrefslogtreecommitdiffstats
path: root/meta-networking/recipes-connectivity
diff options
context:
space:
mode:
authorAndrej Valek <andrej.valek@siemens.com>2023-07-26 11:50:09 +0200
committerKhem Raj <raj.khem@gmail.com>2023-07-27 08:54:40 -0700
commit8af2f17a6fa8bf282c4c27054adbea1bf0873069 (patch)
tree22b6484379a0f3d3e2b89f958dda0fd45f2a1880 /meta-networking/recipes-connectivity
parent4c201ede939610946847ccd4221320ed776224aa (diff)
downloadmeta-openembedded-8af2f17a6fa8bf282c4c27054adbea1bf0873069.tar.gz
cve_check: convert CVE_CHECK_IGNORE to CVE_STATUS
- Try to add convert and apply statuses for old CVEs - Drop some obsolete ignores, while they are not relevant for current version Signed-off-by: Andrej Valek <andrej.valek@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
Diffstat (limited to 'meta-networking/recipes-connectivity')
-rw-r--r--meta-networking/recipes-connectivity/freeradius/freeradius_3.0.26.bb6
-rw-r--r--meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.3.bb6
-rw-r--r--meta-networking/recipes-connectivity/mbedtls/mbedtls_3.4.0.bb5
-rw-r--r--meta-networking/recipes-connectivity/openthread/wpantund_git.bb9
-rw-r--r--meta-networking/recipes-connectivity/samba/samba_4.18.4.bb7
5 files changed, 8 insertions, 25 deletions
diff --git a/meta-networking/recipes-connectivity/freeradius/freeradius_3.0.26.bb b/meta-networking/recipes-connectivity/freeradius/freeradius_3.0.26.bb
index 9a2bbab39f..35733c5307 100644
--- a/meta-networking/recipes-connectivity/freeradius/freeradius_3.0.26.bb
+++ b/meta-networking/recipes-connectivity/freeradius/freeradius_3.0.26.bb
@@ -43,10 +43,8 @@ SRCREV = "d956f683d37ea40e7977cc5907361f3e6988a439"
43 43
44UPSTREAM_CHECK_GITTAGREGEX = "release_(?P<pver>\d+(\_\d+)+)" 44UPSTREAM_CHECK_GITTAGREGEX = "release_(?P<pver>\d+(\_\d+)+)"
45 45
46CVE_CHECK_IGNORE = "\ 46CVE_CHECK_STATUS[CVE-2002-0318] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions."
47 CVE-2002-0318 \ 47CVE_CHECK_STATUS[CVE-2011-4966] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions."
48 CVE-2011-4966 \
49"
50 48
51PARALLEL_MAKE = "" 49PARALLEL_MAKE = ""
52 50
diff --git a/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.3.bb b/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.3.bb
index ce094d5afb..fff320afd8 100644
--- a/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.3.bb
+++ b/meta-networking/recipes-connectivity/mbedtls/mbedtls_2.28.3.bb
@@ -57,10 +57,8 @@ BBCLASSEXTEND = "native nativesdk"
57 57
58CVE_PRODUCT = "mbed_tls" 58CVE_PRODUCT = "mbed_tls"
59 59
60# Fix merged upstream https://github.com/Mbed-TLS/mbedtls/pull/5310 60CVE_STATUS[CVE-2021-43666] = "backported-patch: Fix merged upstream https://github.com/Mbed-TLS/mbedtls/pull/5310"
61CVE_CHECK_IGNORE += "CVE-2021-43666" 61CVE_STATUS[CVE-2021-43666] = "backported-patch: Fix merged upstream https://github.com/Mbed-TLS/mbedtls/commit/9a4a9c66a48edfe9ece03c7e4a53310adf73a86c"
62# Fix merged upstream https://github.com/Mbed-TLS/mbedtls/commit/9a4a9c66a48edfe9ece03c7e4a53310adf73a86c
63CVE_CHECK_IGNORE += "CVE-2021-45451"
64 62
65# Strip host paths from autogenerated test files 63# Strip host paths from autogenerated test files
66do_compile:append() { 64do_compile:append() {
diff --git a/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.4.0.bb b/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.4.0.bb
index b8c9662de7..10fb7de8ca 100644
--- a/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.4.0.bb
+++ b/meta-networking/recipes-connectivity/mbedtls/mbedtls_3.4.0.bb
@@ -58,11 +58,6 @@ BBCLASSEXTEND = "native nativesdk"
58 58
59CVE_PRODUCT = "mbed_tls" 59CVE_PRODUCT = "mbed_tls"
60 60
61# Fix merged upstream https://github.com/Mbed-TLS/mbedtls/pull/5310
62CVE_CHECK_IGNORE += "CVE-2021-43666"
63# Fix merged upstream https://github.com/Mbed-TLS/mbedtls/commit/9a4a9c66a48edfe9ece03c7e4a53310adf73a86c
64CVE_CHECK_IGNORE += "CVE-2021-45451"
65
66# Strip host paths from autogenerated test files 61# Strip host paths from autogenerated test files
67do_compile:append() { 62do_compile:append() {
68 sed -i 's+${S}/++g' ${B}/tests/*.c 2>/dev/null || : 63 sed -i 's+${S}/++g' ${B}/tests/*.c 2>/dev/null || :
diff --git a/meta-networking/recipes-connectivity/openthread/wpantund_git.bb b/meta-networking/recipes-connectivity/openthread/wpantund_git.bb
index a7fcc202a4..ebb3fc3c1c 100644
--- a/meta-networking/recipes-connectivity/openthread/wpantund_git.bb
+++ b/meta-networking/recipes-connectivity/openthread/wpantund_git.bb
@@ -22,11 +22,8 @@ S = "${WORKDIR}/git"
22 22
23inherit pkgconfig perlnative autotools 23inherit pkgconfig perlnative autotools
24 24
25# CVE-2020-8916 has been fixed in commit
26# 3f108441e23e033b936e85be5b6877dd0a1fbf1c which is included in the SRCREV
27# CVE-2021-33889 has been fixed in commit
28# a8f3f761f6753b567d1e5ad22cbe6b0ceb6f2649 which is included in the SRCREV
29# There has not been a wpantund release as of yet that includes these fixes. 25# There has not been a wpantund release as of yet that includes these fixes.
30# That means cve-check can not match them. Once a new release comes we can 26# That means cve-check can not match them. Once a new release comes we can
31# remove the ignore statement. 27# remove the statement.
32CVE_CHECK_IGNORE = "CVE-2020-8916 CVE-2021-33889" 28CVE_STATUS[CVE-2020-8916] = "backported-patch: fixed via 3f108441e23e033b936e85be5b6877dd0a1fbf1c"
29CVE_STATUS[CVE-2021-33889] = "backported-patch: fixed via 3f108441e23e033b936e85be5b6877dd0a1fbf1c"
diff --git a/meta-networking/recipes-connectivity/samba/samba_4.18.4.bb b/meta-networking/recipes-connectivity/samba/samba_4.18.4.bb
index 66089edad5..3386b93b5e 100644
--- a/meta-networking/recipes-connectivity/samba/samba_4.18.4.bb
+++ b/meta-networking/recipes-connectivity/samba/samba_4.18.4.bb
@@ -38,12 +38,7 @@ UPSTREAM_CHECK_REGEX = "samba\-(?P<pver>4\.18(\.\d+)+).tar.gz"
38 38
39inherit systemd waf-samba cpan-base perlnative update-rc.d perl-version pkgconfig 39inherit systemd waf-samba cpan-base perlnative update-rc.d perl-version pkgconfig
40 40
41# CVE-2011-2411 is valnerble only on HP NonStop Servers. 41CVE_STATUS[CVE-2011-2411] = "not-applicable-platform: vulnerable only on HP NonStop Servers"
42CVE_CHECK_IGNORE += "CVE-2011-2411"
43# Patch for CVE-2018-1050 is applied in version 4.5.15, 4.6.13, 4.7.5.
44CVE_CHECK_IGNORE += "CVE-2018-1050"
45# Patch for CVE-2018-1057 is applied in version 4.3.13, 4.4.16.
46CVE_CHECK_IGNORE += "CVE-2018-1057"
47 42
48# remove default added RDEPENDS on perl 43# remove default added RDEPENDS on perl
49RDEPENDS:${PN}:remove = "perl" 44RDEPENDS:${PN}:remove = "perl"