From ba90fb0f3d2aca9f99982d58215b113336ace298 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Mon, 6 Mar 2023 15:17:08 +0000 Subject: [PATCH] shadow: ignore CVE-2016-15024 This recently got an updated CPE which matches this recipe, but the issue is related to an entirely different shadow project so ignore it. (From OE-Core rev: 9d5a05c27a01b3859eae70590ba7dd836abe2719) Signed-off-by: Ross Burton Signed-off-by: Alexandre Belloni (cherry picked from commit 2331e98abb09cbcd56625d65c4e5d258dc29dd04) Signed-off-by: Steve Sakoman Signed-off-by: Richard Purdie --- meta/recipes-extended/shadow/shadow_4.8.1.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-extended/shadow/shadow_4.8.1.bb b/meta/recipes-extended/shadow/shadow_4.8.1.bb index ff4aad926f..9dfcd4bc10 100644 --- a/meta/recipes-extended/shadow/shadow_4.8.1.bb +++ b/meta/recipes-extended/shadow/shadow_4.8.1.bb @@ -9,3 +9,7 @@ BBCLASSEXTEND = "native nativesdk" # Severity is low and marked as closed and won't fix. # https://bugzilla.redhat.com/show_bug.cgi?id=884658 CVE_CHECK_WHITELIST += "CVE-2013-4235" + +# This is an issue for a different shadow +CVE_CHECK_WHITELIST += "CVE-2016-15024" +