]> code.ossystems Code Review - openembedded-core.git/commitdiff
gcc: Add CVE-2021-37322 to the list of CVEs to ignore
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 9 Dec 2021 00:12:12 +0000 (00:12 +0000)
committerAnuj Mittal <anuj.mittal@intel.com>
Fri, 10 Dec 2021 04:39:43 +0000 (12:39 +0800)
The CVE applies to binutils 2.26 and not to gcc so ignore there.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit fea2726663a3db03170c49fceaffc632c509aeea)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-devtools/gcc/gcc-10.2.inc

index 248e002106495bafa5ca0dc9d2fe8e2356e34388..5626bf20f0adeca846526b1bf25a89a508de642b 100644 (file)
@@ -122,3 +122,6 @@ EXTRA_OECONF_PATHS = "\
     --with-sysroot=/not/exist \
     --with-build-sysroot=${STAGING_DIR_TARGET} \
 "
+
+# Is a binutils 2.26 issue, not gcc
+CVE_CHECK_WHITELIST += "CVE-2021-37322"