]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
binutils: set status for CVE-2026-4647
authorPeter Marko <peter.marko@siemens.com>
Thu, 6 Aug 2026 19:22:46 +0000 (21:22 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 7 Aug 2026 08:46:18 +0000 (09:46 +0100)
Per [1] this is fixed in 2.47.

As a RedHat version-less CVE this is currently reported as
"Unpatched": "no-version-ranges".

[1] https://security-tracker.debian.org/tracker/CVE-2026-4647

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/binutils/binutils-2.47.inc

index 3b2dfa4187384e2313abd2881972e22e90c6eba9..ccaf12142ae28a8b046f98dea897908bee88c254 100644 (file)
@@ -18,6 +18,8 @@ SRCBRANCH ?= "binutils-2_47-branch"
 
 UPSTREAM_CHECK_GITTAGREGEX = "binutils-(?P<pver>\d+_(\d_?)*)"
 
+CVE_STATUS[CVE-2026-4647] = "fixed-version: fixed-version: Fixed from version 2.47"
+
 SRCREV ?= "6ce87bbc521cf46eaee9a1f7ef61cee2cdfb3e32"
 BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https"
 SRC_URI = "\