From 0160cb77513e7df459942b21c5b5851731e330e1 Mon Sep 17 00:00:00 2001 From: Peter Marko Date: Wed, 12 Feb 2025 19:00:19 +0100 Subject: [PATCH] libpcre2: ignore CVE-2022-1586 This CVE is fixed in 10.40 NVD wrongly changed <10.40 to =10.40 when adding debian_linux=10.0 Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-1586#VulnChangeHistorySection (From OE-Core rev: 63cbfcd0262d65c66762aa6a8b17b8e8b809737f) Signed-off-by: Peter Marko Signed-off-by: Steve Sakoman --- meta/recipes-support/libpcre/libpcre2_10.40.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-support/libpcre/libpcre2_10.40.bb b/meta/recipes-support/libpcre/libpcre2_10.40.bb index 74c12ecec2..ba5f8cff32 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.40.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.40.bb @@ -19,6 +19,10 @@ SRC_URI[sha256sum] = "14e4b83c4783933dc17e964318e6324f7cae1bc75d8f3c79bc6969f00c CVE_PRODUCT = "pcre2" +# This CVE is fixed in 10.40 +# NVD wrongly changed <10.40 to =10.40 when adding debian_linux=10.0 +CVE_CHECK_IGNORE += "CVE-2022-1586" + S = "${WORKDIR}/pcre2-${PV}" PROVIDES += "pcre2"