]> code.ossystems Code Review - openembedded-core.git/commitdiff
tcl: Exclude CVE-2021-35331 from checks
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 3 Sep 2021 09:17:58 +0000 (10:17 +0100)
committerAnuj Mittal <anuj.mittal@intel.com>
Wed, 15 Sep 2021 02:15:07 +0000 (10:15 +0800)
Upstream don't believe this is an issue.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit adf7bafee3f8884e525b5639ba092a1cd8e3beb9)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-devtools/tcltk/tcl_8.6.11.bb

index efb36b32ddae84eb3c3941acb8f4143909815f64..a993d7c95953ac8473e281cdba8eb6479bcb1bc7 100644 (file)
@@ -30,6 +30,9 @@ SRC_URI[sha256sum] = "8c0486668586672c5693d7d95817cb05a18c5ecca2f40e2836b9578064
 SRC_URI_class-native = "${BASE_SRC_URI}"
 
 S = "${WORKDIR}/${BPN}${PV}/unix"
+# Upstream don't believe this is an exploitable issue
+# https://core.tcl-lang.org/tcl/info/7079e4f91601e9c7
+CVE_CHECK_WHITELIST += "CVE-2021-35331"
 
 PSEUDO_IGNORE_PATHS .= ",${WORKDIR}/${BPN}${PV}"
 VER = "${PV}"