]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
Revert "dpkg: set status for CVE-2025-6297"
authorPeter Marko <peter.marko@siemens.com>
Wed, 20 Aug 2025 16:24:14 +0000 (18:24 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 25 Aug 2025 08:07:24 +0000 (09:07 +0100)
This reverts commit 5dce840ba8f409490cca5dce9fe504c9115fb4e5.

CVE entry was corrected in NVD DB.
It looks like NVD is now getting faster and more reliable with
annotations...

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Cc: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
meta/recipes-devtools/dpkg/dpkg_1.22.21.bb

index 69b3c3d8804bcb0f39079d6e10fe428527b54615..d793c26d57abe5b164bd4f8fb11d42936b9afe43 100644 (file)
@@ -19,6 +19,3 @@ SRC_URI = "git://salsa.debian.org/dpkg-team/dpkg.git;protocol=https;branch=1.22.
 SRC_URI:append:class-native = " file://0001-build.c-ignore-return-of-1-from-tar-cf.patch"
 
 SRCREV = "d72b038fd2113cb62972e4071db03dd1388394d8"
-
-# NVD tracks this CVE as "Up to (excluding) 2025-06-30" (which is fix commit date, not dpkg version)
-CVE_STATUS[CVE-2025-6297] = "cpe-incorrect: this is fixed in 1.22.21"