Explorar o código

libyaml: Update status of CVE-2024-35328

This is open yet but seems to be disputed

(From OE-Core rev: 4cba8ad405b1728afda3873f99ac88711ab85644)

Signed-off-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Khem Raj hai 10 meses
pai
achega
56b6b35626
Modificáronse 1 ficheiros con 2 adicións e 0 borrados
  1. 2 0
      meta/recipes-support/libyaml/libyaml_0.2.5.bb

+ 2 - 0
meta/recipes-support/libyaml/libyaml_0.2.5.bb

@@ -18,4 +18,6 @@ inherit autotools
 DISABLE_STATIC:class-nativesdk = ""
 DISABLE_STATIC:class-native = ""
 
+CVE_STATUS[CVE-2024-35328] = "disputed: Upstream thinks there is no working code that is exploitable - https://github.com/yaml/libyaml/issues/302"
+
 BBCLASSEXTEND = "native nativesdk"