]> code.ossystems Code Review - openembedded-core.git/commit
flex: Add CVE-2019-6293 to exclusions for checks
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 6 Sep 2021 12:49:26 +0000 (13:49 +0100)
committerAnuj Mittal <anuj.mittal@intel.com>
Wed, 15 Sep 2021 02:19:46 +0000 (10:19 +0800)
commite2de2e5e977d84dab6cb1461800d4c29436da5c9
treeeae05496c863242f60cf5962ca07848c4f5fcbbf
parentd0ff86bccdbcd91e8760001037168043725ef8f4
flex: Add CVE-2019-6293 to exclusions for checks

CVE is effectively disputed - yes there is stack exhaustion but no bug and it
is building the parser, not running it, effectively similar to a compiler ICE.
Upstream no plans to address and there is no security issue.

https://github.com/westes/flex/issues/414

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0cae5d7a24bedf6784781b62cbb3795a44bab4d1)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-devtools/flex/flex_2.6.4.bb