From ee6ee9bd489c126b99d15c1011560df2f840a6e9 Mon Sep 17 00:00:00 2001 From: Richard Purdie Date: Mon, 10 May 2021 13:36:02 +0100 Subject: qemu: Exclude CVE-2018-18438 from cve-check The issues were investigated and found not to be an issue therefore exclude from checks. Signed-off-by: Richard Purdie --- meta/recipes-devtools/qemu/qemu.inc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index 32be057d0e..82d1cb5566 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc @@ -72,6 +72,10 @@ CVE_CHECK_WHITELIST += "CVE-2017-5957" # enable it by default. CVE_CHECK_WHITELIST += "CVE-2007-0998" +# 'The issues identified by this CVE were determined to not constitute a vulnerability.' +# https://bugzilla.redhat.com/show_bug.cgi?id=1609015#c11 +CVE_CHECK_WHITELIST += "CVE-2018-18438" + COMPATIBLE_HOST_mipsarchn32 = "null" COMPATIBLE_HOST_mipsarchn64 = "null" -- cgit 1.2.3-korg