]> code.ossystems Code Review - openembedded-core.git/commitdiff
procps: whitelist CVE-2018-1121
authorRoss Burton <ross.burton@intel.com>
Tue, 5 Nov 2019 21:44:48 +0000 (23:44 +0200)
committerArmin Kuster <akuster808@gmail.com>
Sun, 24 Nov 2019 16:55:09 +0000 (08:55 -0800)
This CVE is about race conditions in 'ps' which make it unsuitable for security
audits.  As these race conditions are unavoidable ps shouldn't be used for
security auditing, so this isn't a valid CVE.

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Adrian Bunk <bunk@stusta.de>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-extended/procps/procps_3.3.15.bb

index 9756db0e7b77a202e6a14d4f5bd9a48d208b7449..a20917b223368509d849f17857e0b5afa32cf1ab 100644 (file)
@@ -64,3 +64,6 @@ python __anonymous() {
         d.setVarFlag('ALTERNATIVE_LINK_NAME', prog, '%s/%s' % (d.getVar('base_sbindir'), prog))
 }
 
+# 'ps' isn't suitable for use as a security tool so whitelist this CVE.
+# https://bugzilla.redhat.com/show_bug.cgi?id=1575473#c3
+CVE_CHECK_WHITELIST += "CVE-2018-1121"