summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@arm.com>2023-11-03 13:28:07 +0000
committerRichard Purdie <richard.purdie@linuxfoundation.org>2023-11-03 13:49:14 +0000
commit5b06913e5883c35390c87f6660a0578c73ff4ddd (patch)
tree4b48c47164b0a2a4d6131cac9a840e756d3c07a7
parent8c70e7cecb1beb30a5be4ea9bbc89c2f2e11853b (diff)
downloadopenembedded-core-5b06913e5883c35390c87f6660a0578c73ff4ddd.tar.gz
zlib: ignore CVE-2023-45853
This CVE relates to a bug in the minizip tool, but we don't build that. Signed-off-by: Ross Burton <ross.burton@arm.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-core/zlib/zlib_1.3.bb2
1 files changed, 2 insertions, 0 deletions
diff --git a/meta/recipes-core/zlib/zlib_1.3.bb b/meta/recipes-core/zlib/zlib_1.3.bb
index c8fd855ee6..1ed18172fa 100644
--- a/meta/recipes-core/zlib/zlib_1.3.bb
+++ b/meta/recipes-core/zlib/zlib_1.3.bb
@@ -45,3 +45,5 @@ do_install_ptest() {
}
BBCLASSEXTEND = "native nativesdk"
+
+CVE_STATUS[CVE-2023-45853] = "not-applicable-config: we don't build minizip"