]> code.ossystems Code Review - openembedded-core.git/commitdiff
gstreamer-plugins-base: ignore CVE-2021-3522 since it is fixed
authorSteve Sakoman <steve@sakoman.com>
Wed, 14 Jul 2021 22:09:06 +0000 (12:09 -1000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 14 Jul 2021 22:27:38 +0000 (12:27 -1000)
CPE entries for gst-plugins-base are listed as gstreamer issues
so we need to ignore the false hit for the CVE we've patched

Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-base_1.16.3.bb

index bcfdef3bbd63007f3c05a3f52bdf0af3ba783e8b..431468d459eb55e407fc8a60293863752f72884c 100644 (file)
@@ -20,6 +20,10 @@ SRC_URI = " \
 SRC_URI[md5sum] = "e3ddb1bae9fb510b49a295f212f1e6e4"
 SRC_URI[sha256sum] = "9f02678b0bbbcc9eff107d3bd89d83ce92fec2154cd607c7c8bd34dc7fee491c"
 
+# CPE entries for gst-plugins-base are listed as gstreamer issues
+# so we need to ignore the false hit
+CVE_CHECK_WHITELIST += "CVE-2021-3522"
+
 S = "${WORKDIR}/gst-plugins-base-${PV}"
 
 DEPENDS += "iso-codes util-linux zlib"