From 2aaf663547c99c1912594b33a1534081229c5160 Mon Sep 17 00:00:00 2001 From: Peter Marko Date: Fri, 23 Jan 2026 18:02:21 +0100 Subject: [PATCH] libmad: ignore CVE-2017-11552 and CVE-2018-7263 These CVEs are for mpg321, not libmad. See Debian assessment: * https://security-tracker.debian.org/tracker/CVE-2017-11552 * https://security-tracker.debian.org/tracker/CVE-2018-7263 Signed-off-by: Peter Marko Signed-off-by: Khem Raj (cherry picked from commit fee86a312fbcaef7aaad66fe2f6756bd7e57d585) Signed-off-by: Gyorgy Sarvari Signed-off-by: Anuj Mittal --- meta-oe/recipes-multimedia/libmad/libmad_0.15.1b.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-oe/recipes-multimedia/libmad/libmad_0.15.1b.bb b/meta-oe/recipes-multimedia/libmad/libmad_0.15.1b.bb index e70c8e3ed1..060fde0403 100644 --- a/meta-oe/recipes-multimedia/libmad/libmad_0.15.1b.bb +++ b/meta-oe/recipes-multimedia/libmad/libmad_0.15.1b.bb @@ -34,3 +34,6 @@ do_configure:prepend () { } ARM_INSTRUCTION_SET = "arm" + +CVE_STATUS[CVE-2017-11552] = "cpe-incorrect: this CVE is for mpg321, not libmad" +CVE_STATUS[CVE-2018-7263] = "cpe-incorrect: this CVE is for mpg321, not libmad"