From ca3783f70de0abf516fd0cb5447440c4325b9d1e Mon Sep 17 00:00:00 2001 From: Peter Marko Date: Tue, 7 Oct 2025 23:02:33 +0200 Subject: [PATCH] gstreamer1.0: ignore CVE-2025-2759 Copy statement from [1] that it is problem of installers (non-Linux). Also [2] linked in NVD says "Fixed in 1.25.1 Gstreamer Installer". Since Yocto builds from sources into our own packages, ignore it. [1] https://security-tracker.debian.org/tracker/CVE-2025-2759 [2] https://www.zerodayinitiative.com/advisories/ZDI-25-268/ (From OE-Core rev: 99ee1df6bde2ffd4fa2ddea44c0a9b94d9d77bae) Reworked to CVE_CHECK_IGNORE format. (From OE-Core rev: 2162bc3b305a0b088018e251baad54c356f7855f) Signed-off-by: Peter Marko Signed-off-by: Steve Sakoman --- meta/recipes-multimedia/gstreamer/gstreamer1.0_1.20.7.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.20.7.bb b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.20.7.bb index b9b9551bc3..3b37503608 100644 --- a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.20.7.bb +++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.20.7.bb @@ -88,4 +88,7 @@ CVE_CHECK_IGNORE += " \ CVE-2024-47777 CVE-2024-47778 CVE-2024-47834 CVE-2025-47183 CVE-2025-47219 \ " +# not-applicable-platform: affects installation packages for non Linux OSes +CVE_CHECK_IGNORE += "CVE-2025-2759" + PTEST_BUILD_HOST_FILES = ""