]> code.ossystems Code Review - openembedded-core.git/commit
flex: Add CVE-2019-6293 to exclusions for checks
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 6 Sep 2021 12:49:26 +0000 (13:49 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 6 Sep 2021 12:53:15 +0000 (13:53 +0100)
commit0cae5d7a24bedf6784781b62cbb3795a44bab4d1
tree0332175c02cc00a2a50057f6c5c7d26575828e3f
parentd49ba0243e3d28672d16cd02753eb7e85d91bbab
flex: Add CVE-2019-6293 to exclusions for checks

CVE is effectively disputed - yes there is stack exhaustion but no bug and it
is building the parser, not running it, effectively similar to a compiler ICE.
Upstream no plans to address and there is no security issue.

https://github.com/westes/flex/issues/414

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/conf/distro/include/cve-extra-exclusions.inc
meta/recipes-devtools/flex/flex_2.6.4.bb