From: Ross Burton Date: Wed, 6 Nov 2019 15:37:55 +0000 (+0200) Subject: procps: whitelist CVE-2018-1121 X-Git-Url: https://code.ossystems.io/gitweb?a=commitdiff_plain;h=618a3203d53d33e6403386f1204bcaf327b68f37;p=openembedded-core.git procps: whitelist CVE-2018-1121 This CVE is about race conditions in 'ps' which make it unsuitable for security audits. As these race conditions are unavoidable ps shouldn't be used for security auditing, so this isn't a valid CVE. (From OE-Core rev: b3fa0654abf9ac32f683ac174e453ea5e64b6cb8) Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Conflicts: meta/recipes-extended/procps/procps_3.3.15.bb --- diff --git a/meta/recipes-extended/procps/procps_3.3.12.bb b/meta/recipes-extended/procps/procps_3.3.12.bb index 6e15b0a5a0..d4ebaf9db0 100644 --- a/meta/recipes-extended/procps/procps_3.3.12.bb +++ b/meta/recipes-extended/procps/procps_3.3.12.bb @@ -64,3 +64,6 @@ python __anonymous() { d.setVarFlag('ALTERNATIVE_LINK_NAME', prog, '%s/%s' % (d.getVar('base_sbindir'), prog)) } +# 'ps' isn't suitable for use as a security tool so whitelist this CVE. +# https://bugzilla.redhat.com/show_bug.cgi?id=1575473#c3 +CVE_CHECK_WHITELIST += "CVE-2018-1121"