From 3f2293398fdd5834f771e1a33422529215a90715 Mon Sep 17 00:00:00 2001 From: Gyorgy Sarvari Date: Sun, 26 Apr 2026 13:50:52 +0200 Subject: [PATCH] nodejs: mark CVE-2026-21710 patched Details: https://nvd.nist.gov/vuln/detail/CVE-2026-21710 The CVE is fixed in the current recipe version[1], but NVD tracks it without verison info. Mark it as patched in the recipe. [1]: https://github.com/nodejs/node/blob/v22.x/doc/changelogs/CHANGELOG_V22.md Signed-off-by: Gyorgy Sarvari Signed-off-by: Khem Raj (cherry picked from commit b483760dba76bb66bad820ea0246a38692c28c45) Signed-off-by: Gyorgy Sarvari Signed-off-by: Anuj Mittal --- meta-oe/recipes-devtools/nodejs/nodejs_22.22.2.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-oe/recipes-devtools/nodejs/nodejs_22.22.2.bb b/meta-oe/recipes-devtools/nodejs/nodejs_22.22.2.bb index c64cc5b7c2..2b04c6df97 100644 --- a/meta-oe/recipes-devtools/nodejs/nodejs_22.22.2.bb +++ b/meta-oe/recipes-devtools/nodejs/nodejs_22.22.2.bb @@ -218,6 +218,7 @@ python __anonymous () { BBCLASSEXTEND = "native" +CVE_STATUS[CVE-2026-21710] = "fixed-version: fixed since v22.22.2" CVE_STATUS[CVE-2026-21712] = "cpe-incorrect: only v24 and v25 are affected" CVE_STATUS[CVE-2026-21713] = "fixed-version: fixed since v22.22.2" CVE_STATUS[CVE-2026-21714] = "fixed-version: fixed since v22.22.2"