From 75859969b5ed7359124198eb48c480b8f6fe6f8f Mon Sep 17 00:00:00 2001 From: Peter Marko Date: Fri, 15 Aug 2025 19:05:17 +0200 Subject: [PATCH] dpkg: set status for CVE-2025-6297 NVD tracks this CVE as "Up to (excluding) 2025-06-30" (which is fix commit date, not dpkg version) Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie --- meta/recipes-devtools/dpkg/dpkg_1.22.21.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-devtools/dpkg/dpkg_1.22.21.bb b/meta/recipes-devtools/dpkg/dpkg_1.22.21.bb index d793c26d57a..69b3c3d8804 100644 --- a/meta/recipes-devtools/dpkg/dpkg_1.22.21.bb +++ b/meta/recipes-devtools/dpkg/dpkg_1.22.21.bb @@ -19,3 +19,6 @@ SRC_URI = "git://salsa.debian.org/dpkg-team/dpkg.git;protocol=https;branch=1.22. SRC_URI:append:class-native = " file://0001-build.c-ignore-return-of-1-from-tar-cf.patch" SRCREV = "d72b038fd2113cb62972e4071db03dd1388394d8" + +# NVD tracks this CVE as "Up to (excluding) 2025-06-30" (which is fix commit date, not dpkg version) +CVE_STATUS[CVE-2025-6297] = "cpe-incorrect: this is fixed in 1.22.21" -- 2.47.3