]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
grub: set status for 6 CVEs fixed in 2.14
authorPeter Marko <peter.marko@siemens.com>
Wed, 15 Apr 2026 20:14:42 +0000 (22:14 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 16 Apr 2026 10:09:38 +0000 (11:09 +0100)
These CVEs were fixed in 2.14, however Redhat CNA does not fill any
version to CPEs.
References for fixes are in Debian security tracker:
* https://security-tracker.debian.org/tracker/CVE-2025-54770
* https://security-tracker.debian.org/tracker/CVE-2025-54771
* https://security-tracker.debian.org/tracker/CVE-2025-61661
* https://security-tracker.debian.org/tracker/CVE-2025-61662
* https://security-tracker.debian.org/tracker/CVE-2025-61663
* https://security-tracker.debian.org/tracker/CVE-2025-61664

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-bsp/grub/grub2.inc

index da67975290c1b4b4b20f869a6b95641b105417e7..0656489ead3426cda406244aeb71aea1806b1d6b 100644 (file)
@@ -28,6 +28,12 @@ CVE_STATUS[CVE-2023-4001]  = "not-applicable-platform: Applies only to RHEL/Fedo
 CVE_STATUS[CVE-2024-1048]  = "not-applicable-platform: Applies only to RHEL/Fedora"
 CVE_STATUS[CVE-2024-2312]  = "not-applicable-platform: Applies only to Ubuntu"
 CVE_STATUS[CVE-2024-49504] = "not-applicable-platform: Applies only to SUSE"
+CVE_STATUS[CVE-2025-54770] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-54771] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61661] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61662] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61663] = "fixed-version: fixed since 2.14"
+CVE_STATUS[CVE-2025-61664] = "fixed-version: fixed since 2.14"
 
 DEPENDS = "flex-native bison-native gettext-native gawk-replacement-native"