]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
dpkg: set status for CVE-2025-6297
authorPeter Marko <peter.marko@siemens.com>
Fri, 15 Aug 2025 17:05:17 +0000 (19:05 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 19 Aug 2025 08:48:33 +0000 (09:48 +0100)
NVD tracks this CVE as "Up to (excluding) 2025-06-30"
(which is fix commit date, not dpkg version)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/dpkg/dpkg_1.22.21.bb

index d793c26d57abe5b164bd4f8fb11d42936b9afe43..69b3c3d8804bcb0f39079d6e10fe428527b54615 100644 (file)
@@ -19,3 +19,6 @@ SRC_URI = "git://salsa.debian.org/dpkg-team/dpkg.git;protocol=https;branch=1.22.
 SRC_URI:append:class-native = " file://0001-build.c-ignore-return-of-1-from-tar-cf.patch"
 
 SRCREV = "d72b038fd2113cb62972e4071db03dd1388394d8"
+
+# NVD tracks this CVE as "Up to (excluding) 2025-06-30" (which is fix commit date, not dpkg version)
+CVE_STATUS[CVE-2025-6297] = "cpe-incorrect: this is fixed in 1.22.21"