]> code.ossystems Code Review - openembedded-core.git/commit
glibc: Document and whitelist CVE-2019-1010022-25
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 10 May 2021 10:56:50 +0000 (11:56 +0100)
committerSteve Sakoman <steve@sakoman.com>
Fri, 14 May 2021 17:16:37 +0000 (07:16 -1000)
commit2afbfc1eb6bc7613da4a7f06ac267ea561b5470e
tree9138d229e5449bcb7098f5a6a52cf060d8f168f7
parent9485d568b2b9e2143e1f46859a5c1de644c69b94
glibc: Document and whitelist CVE-2019-1010022-25

These CVEs are disputed by upstream and there is no plan to fix/address them. No
other distros are carrying patches for them. There is a patch for 1010025
however it isn't merged upstream and probably carries more risk of other bugs
than not having it.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit b238db678083cc15313b98d2e33f83cccab03fc6)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/glibc/glibc_2.31.bb