These CVEs were fixed in 2.14, however Redhat CNA does not fill any
version to CPEs.
References for fixes are in Debian security tracker:
* https://security-tracker.debian.org/tracker/CVE-2025-54770
* https://security-tracker.debian.org/tracker/CVE-2025-54771
* https://security-tracker.debian.org/tracker/CVE-2025-61661
* https://security-tracker.debian.org/tracker/CVE-2025-61662
* https://security-tracker.debian.org/tracker/CVE-2025-61663
* https://security-tracker.debian.org/tracker/CVE-2025-61664
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
CVE_STATUS[CVE-2024-1048] = "not-applicable-platform: Applies only to RHEL/Fedora"
CVE_STATUS[CVE-2024-2312] = "not-applicable-platform: Applies only to Ubuntu"
CVE_STATUS[CVE-2024-49504] = "not-applicable-platform: Applies only to SUSE"
+CVE_STATUS[CVE-2025-54770] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-54771] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61661] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61662] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61663] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61664] = "fixed-version: fixed since 2.14"
DEPENDS = "flex-native bison-native gettext-native gawk-replacement-native"