]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
gcc-shared-source: whitelist CVE-2023-4039
authorPeter Marko <peter.marko@siemens.com>
Tue, 13 Feb 2024 07:38:09 +0000 (13:08 +0530)
committerSteve Sakoman <steve@sakoman.com>
Wed, 14 Feb 2024 17:02:54 +0000 (07:02 -1000)
Concept of gcc-source prevents cve-check to detect existing
CVE patch file.
So whitelist this CVE in all recipes using gcc-source via this
include file.

(From OE-Core rev: 04511734c6dc8c7dda3a943b385cd273d012d8c7)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
(cherry picked from commit d803ca653139aa2d6acb4f99469c76a9d232b307)
Signed-off-by: Dnyandev Padalkar <padalkards17082001@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/gcc/gcc-shared-source.inc

index aac4b49313cb3b85f765750431eb40f21e2440d1..4baf7874d24984ff8811cda21abcd3a34421d510 100644 (file)
@@ -9,3 +9,6 @@ SRC_URI = ""
 
 do_configure[depends] += "gcc-source-${PV}:do_preconfigure"
 do_populate_lic[depends] += "gcc-source-${PV}:do_unpack"
+
+# patch is available via gcc-source recipe
+CVE_CHECK_WHITELIST += "CVE-2023-4039"