From: Peter Marko Date: Thu, 6 Aug 2026 19:22:46 +0000 (+0200) Subject: binutils: set status for CVE-2026-4647 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=2222a4fb085ebaac7147700d8b64355a9c514f76;p=thirdparty%2Fopenembedded%2Fopenembedded-core.git binutils: set status for CVE-2026-4647 Per [1] this is fixed in 2.47. As a RedHat version-less CVE this is currently reported as "Unpatched": "no-version-ranges". [1] https://security-tracker.debian.org/tracker/CVE-2026-4647 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie --- diff --git a/meta/recipes-devtools/binutils/binutils-2.47.inc b/meta/recipes-devtools/binutils/binutils-2.47.inc index 3b2dfa4187..ccaf12142a 100644 --- a/meta/recipes-devtools/binutils/binutils-2.47.inc +++ b/meta/recipes-devtools/binutils/binutils-2.47.inc @@ -18,6 +18,8 @@ SRCBRANCH ?= "binutils-2_47-branch" UPSTREAM_CHECK_GITTAGREGEX = "binutils-(?P\d+_(\d_?)*)" +CVE_STATUS[CVE-2026-4647] = "fixed-version: fixed-version: Fixed from version 2.47" + SRCREV ?= "6ce87bbc521cf46eaee9a1f7ef61cee2cdfb3e32" BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https" SRC_URI = "\