summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@arm.com>2026-05-14 03:33:18 -0700
committerPaul Barker <paul@pbarker.dev>2026-06-10 14:35:20 +0100
commit4e2dac74d55055b500679bdb3d73eb5e24fe51bb (patch)
tree3646ac1aeed6ca6824314c13c5ac6c6e8dcfeb98 /meta
parentb233e7b40f2c13f20704ef276281f5ab4fd5b842 (diff)
downloadpoky-4e2dac74d55055b500679bdb3d73eb5e24fe51bb.tar.gz
perl: link to the system zlib instead of a vendored copy
The perl module Compress-Raw-Zlib defaults to using a vendored copy of the zlib sources which has a number of CVEs. A newer version of perl updates this to zlib 1.3.2 to resolve them, but we should be linking to our zlib recipe instead of the vendored code. This mitigates CVE-2026-4176 so mark it as not appropriate. (From OE-Core rev: 6e83e5520f415fc6ca9029a8aaa0af31cd832a90) Signed-off-by: Ross Burton <ross.burton@arm.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit bf515229043685d4f00c965eb3e0236c37b6b403) Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-devtools/perl/perl_5.38.4.bb5
1 files changed, 5 insertions, 0 deletions
diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb
index e59022e2bd..5ab49ed3d7 100644
--- a/meta/recipes-devtools/perl/perl_5.38.4.bb
+++ b/meta/recipes-devtools/perl/perl_5.38.4.bb
@@ -49,6 +49,11 @@ export ENC2XS_NO_COMMENTS = "1"
49 49
50CFLAGS += "-D_GNU_SOURCE -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" 50CFLAGS += "-D_GNU_SOURCE -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64"
51 51
52# Link Compress-Raw-Zlib to the system zlib instead of a vendored copy
53EXTRA_OEMAKE += "BUILD_ZLIB=False ZLIB_INCLUDE=${STAGING_INCDIR} ZLIB_LIB=${STAGING_LIBDIR}"
54
55CVE_STATUS[CVE-2026-4176] = "not-applicable-config: we do not use the vendorered zlib"
56
52do_configure:prepend() { 57do_configure:prepend() {
53 rm -rf ${B} 58 rm -rf ${B}
54 cp -rfp ${S} ${B} 59 cp -rfp ${S} ${B}