]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
zlib: ignore CVE-2026-22184
authorPeter Marko <peter.marko@siemens.com>
Fri, 16 Jan 2026 19:39:21 +0000 (20:39 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 22 Jan 2026 14:21:21 +0000 (14:21 +0000)
This is CVE for example tool contrib/untgz.
This is not compiled in Yocto zlib recipe.

This CVE has controversial CVSS3 score of 9.8.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/zlib/zlib_1.3.1.bb

index 592b7f142296fee3010ca278549760a2e3ae5701..ef8314212160dcf71827074c04789236d838955b 100644 (file)
@@ -51,3 +51,5 @@ BBCLASSEXTEND = "native nativesdk"
 
 # Adding 'CVE_PRODUCT' to avoid false detection of CVEs
 CVE_PRODUCT = "zlib:zlib gnu:zlib"
+
+CVE_STATUS[CVE-2026-22184] = "not-applicable-config: vulnerable file is not compiled"