From: Peter Marko Date: Fri, 28 Mar 2025 18:05:50 +0000 (+0100) Subject: perl: ignore CVE-2023-47038 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=46fd9acd6b0e418009f4cec747ae82af60acbc6b;p=thirdparty%2Fopenembedded%2Fopenembedded-core-contrib.git perl: ignore CVE-2023-47038 Fix for this CVE was backported to 5.34.2 in https://github.com/Perl/perl5/commit/12c313ce49b36160a7ca2e9b07ad5bd92ee4a010 This commit is listed in https://security-tracker.debian.org/tracker/CVE-2023-47038 Signed-off-by: Peter Marko Signed-off-by: Steve Sakoman --- diff --git a/meta/recipes-devtools/perl/perl_5.34.3.bb b/meta/recipes-devtools/perl/perl_5.34.3.bb index 215990c8fab..ed3518b62d4 100644 --- a/meta/recipes-devtools/perl/perl_5.34.3.bb +++ b/meta/recipes-devtools/perl/perl_5.34.3.bb @@ -50,6 +50,8 @@ export ENC2XS_NO_COMMENTS = "1" # Duplicate of CVE-2023-47038, which has already been patched as of perl_5.34.3 CVE_CHECK_IGNORE:append = " CVE-2023-47100" +# This is fixed in 5.34.2 via https://github.com/Perl/perl5/commit/12c313ce49b36160a7ca2e9b07ad5bd92ee4a010 +CVE_CHECK_IGNORE:append = " CVE-2023-47038" do_configure:prepend() { cp -rfp ${STAGING_DATADIR_NATIVE}/perl-cross/* ${S}