mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-28 13:00:23 +00:00
libssh: set status for CVE-2026-15370
Analysis: - CVE-2026-15370 affects stack buffer overflow in SFTP server longname construction. - This vulnerable code is not present in the current libssh 0.10.6. - Hence ignoring the CVE for this version. Reference: https://www.cve.org/CVERecord?id=CVE-2026-15370 https://www.libssh.org/security/advisories/CVE-2026-15370.txt Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
@@ -70,3 +70,5 @@ do_install_ptest () {
|
||||
BBCLASSEXTEND = "native nativesdk"
|
||||
|
||||
CVE_STATUS[CVE-2025-14821] = "not-applicable-platform: only affects Windows due to loading configuration from C:\etc"
|
||||
#Reference: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
|
||||
CVE_STATUS[CVE-2026-15370] = "fixed-version: vulnerable SFTP server longname construction handling was introduced in 0.11.0 and is not present in 0.10.6"
|
||||
|
||||
Reference in New Issue
Block a user