All of lore.kernel.org
 help / color / mirror / Atom feed
* [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
@ 2026-08-21  9:30 Roland Kovacs
  2026-08-31 14:21 ` [OE-core] " Yoann Congal
  0 siblings, 1 reply; 3+ messages in thread
From: Roland Kovacs @ 2026-08-21  9:30 UTC (permalink / raw)
  To: openembedded-core

Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
where the maintainer states that "[...] this is wrong usage of a tool or social
engineering".

Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html

Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
---
v1: https://lists.openembedded.org/g/openembedded-core/message/243897
v1 -> v2:
	- Fix patchtest complaint about empty commit message.
 meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
index c85de6047f..3ebea399d7 100644
--- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
+++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
@@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
 
 CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the proposed commit - https://dev.gnupg.org/T5993"
 CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version 2.4.8"
+CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid - https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [OE-core] [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
  2026-08-21  9:30 [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix Roland Kovacs
@ 2026-08-31 14:21 ` Yoann Congal
  2026-08-31 16:00   ` Roland Kovács
  0 siblings, 1 reply; 3+ messages in thread
From: Yoann Congal @ 2026-08-31 14:21 UTC (permalink / raw)
  To: roland.kovacs, openembedded-core

On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org wrote:
> Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
> where the maintainer states that "[...] this is wrong usage of a tool or social
> engineering".
>
> Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
>
> Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
> ---
> v1: https://lists.openembedded.org/g/openembedded-core/message/243897
> v1 -> v2:
> 	- Fix patchtest complaint about empty commit message.
>  meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> index c85de6047f..3ebea399d7 100644
> --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
>  
>  CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the proposed commit - https://dev.gnupg.org/T5993"
>  CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version 2.4.8"
> +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid - https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"

Hello,

I don't think we need this fix since MITRE data shows CVE-2025-68972 only
affect <= 2.4.8 and we are at 2.4.9.

Regards,
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [OE-core] [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
  2026-08-31 14:21 ` [OE-core] " Yoann Congal
@ 2026-08-31 16:00   ` Roland Kovács
  0 siblings, 0 replies; 3+ messages in thread
From: Roland Kovács @ 2026-08-31 16:00 UTC (permalink / raw)
  To: openembedded-core@lists.openembedded.org, yoann.congal@smile.fr

On Mon, 2026-08-31 at 16:21 +0200, Yoann Congal wrote:
> On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org wrote:
> > Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
> > where the maintainer states that "[...] this is wrong usage of a tool or social
> > engineering".
> > 
> > Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
> > 
> > Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
> > ---
> > v1: https://lists.openembedded.org/g/openembedded-core/message/243897
> > v1 -> v2:
> > 	- Fix patchtest complaint about empty commit message.
> >  meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
> >  1 file changed, 1 insertion(+)
> > 
> > diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-
> > support/gnupg/gnupg_2.4.9.bb
> > index c85de6047f..3ebea399d7 100644
> > --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> > +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> > @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
> >  
> >  CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the
> > proposed commit - https://dev.gnupg.org/T5993"
> >  CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version
> > 2.4.8"
> > +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid -
> > https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
> 
> Hello,
> 
> I don't think we need this fix since MITRE data shows CVE-2025-68972 only
> affect <= 2.4.8 and we are at 2.4.9.
> 
> Regards,
Hi Yoann,

Sorry about it, feel free to drop!

It probably got in my queue before the recipe update, and I was just slow to react. :)
It's also possible that it is showing up on my side because debian tracker still marks this version
vulnerable (and we aggregate the sources).

https://security-tracker.debian.org/tracker/CVE-2025-68972

Cheers,
	Roland

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-31 16:00 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-21  9:30 [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix Roland Kovacs
2026-08-31 14:21 ` [OE-core] " Yoann Congal
2026-08-31 16:00   ` Roland Kovács

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.