]> code.ossystems Code Review - openembedded-core.git/commitdiff
bluez: Exclude CVE-2020-12352 CVE-2020-24490 from cve-check
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 11 May 2021 12:47:54 +0000 (13:47 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 22 May 2021 09:00:45 +0000 (10:00 +0100)
These CVEs are fixed with kernel changes and don't affect the bluez recipe.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/bluez5/bluez5_5.56.bb

index 676cb2dbb2ab09e7cd23aee6e9054770bc1cc9b5..ae0f72b678ae97383c435254c5519e007a194468 100644 (file)
@@ -3,6 +3,9 @@ require bluez5.inc
 SRC_URI[md5sum] = "e6c51b2aefa7c56ff072819a78611fa5"
 SRC_URI[sha256sum] = "59c4dba9fc8aae2a6a5f8f12f19bc1b0c2dc27355c7ca3123eed3fe6bd7d0b9d"
 
+# These issues have kernel fixes rather than bluez fixes so exclude here
+CVE_CHECK_WHITELIST += "CVE-2020-12352 CVE-2020-24490"
+
 # noinst programs in Makefile.tools that are conditional on READLINE
 # support
 NOINST_TOOLS_READLINE ?= " \