From: Peter Marko Date: Wed, 12 Feb 2025 18:00:19 +0000 (+0100) Subject: libpcre2: ignore CVE-2022-1586 X-Git-Tag: yocto-4.0.26~96 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=63cbfcd0262d65c66762aa6a8b17b8e8b809737f;p=thirdparty%2Fopenembedded%2Fopenembedded-core.git libpcre2: ignore CVE-2022-1586 This CVE is fixed in 10.40 NVD wrongly changed <10.40 to =10.40 when adding debian_linux=10.0 Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-1586#VulnChangeHistorySection Signed-off-by: Peter Marko Signed-off-by: Steve Sakoman --- diff --git a/meta/recipes-support/libpcre/libpcre2_10.40.bb b/meta/recipes-support/libpcre/libpcre2_10.40.bb index 74c12ecec21..ba5f8cff323 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.40.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.40.bb @@ -19,6 +19,10 @@ SRC_URI[sha256sum] = "14e4b83c4783933dc17e964318e6324f7cae1bc75d8f3c79bc6969f00c CVE_PRODUCT = "pcre2" +# This CVE is fixed in 10.40 +# NVD wrongly changed <10.40 to =10.40 when adding debian_linux=10.0 +CVE_CHECK_IGNORE += "CVE-2022-1586" + S = "${WORKDIR}/pcre2-${PV}" PROVIDES += "pcre2"