linuxptp: ignore CVE-2024-42861

Details: https://nvd.nist.gov/vuln/detail/CVE-2024-42861

The vulnerability report is considered to be bogus and a non-issue
(or at least not a security issue) by upstream[1] and by major
Linux distros[2][3][4].

[1]: https://lists.nwtime.org/sympa/arc/linuxptp-devel/2024-09/msg00080.html
[2]: Ubuntu: https://ubuntu.com/security/CVE-2024-42861
[3]: Debian: https://security-tracker.debian.org/tracker/CVE-2024-42861
[4]: Suse: https://bugzilla.suse.com/show_bug.cgi?id=1230935

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Gyorgy Sarvari
2025-11-15 19:23:10 +01:00
committed by Anuj Mittal
parent da046dd9e0
commit 03f418d36b
@@ -60,3 +60,5 @@ SYSTEMD_AUTO_ENABLE:${PN} = "disable"
PACKAGES =+ "${PN}-configs"
FILES:${PN}-configs += "${docdir}"
CVE_STATUS[2024-42861] = "disputed: Considered to be bogus by upstream and major distros"