* [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
@ 2026-08-21 9:30 Roland Kovacs
2026-08-31 14:21 ` [OE-core] " Yoann Congal
0 siblings, 1 reply; 3+ messages in thread
From: Roland Kovacs @ 2026-08-21 9:30 UTC (permalink / raw)
To: openembedded-core
Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
where the maintainer states that "[...] this is wrong usage of a tool or social
engineering".
Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
---
v1: https://lists.openembedded.org/g/openembedded-core/message/243897
v1 -> v2:
- Fix patchtest complaint about empty commit message.
meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
index c85de6047f..3ebea399d7 100644
--- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
+++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
@@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the proposed commit - https://dev.gnupg.org/T5993"
CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version 2.4.8"
+CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid - https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [OE-core] [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
2026-08-21 9:30 [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix Roland Kovacs
@ 2026-08-31 14:21 ` Yoann Congal
2026-08-31 16:00 ` Roland Kovács
0 siblings, 1 reply; 3+ messages in thread
From: Yoann Congal @ 2026-08-31 14:21 UTC (permalink / raw)
To: roland.kovacs, openembedded-core
On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org wrote:
> Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
> where the maintainer states that "[...] this is wrong usage of a tool or social
> engineering".
>
> Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
>
> Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
> ---
> v1: https://lists.openembedded.org/g/openembedded-core/message/243897
> v1 -> v2:
> - Fix patchtest complaint about empty commit message.
> meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> index c85de6047f..3ebea399d7 100644
> --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
>
> CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the proposed commit - https://dev.gnupg.org/T5993"
> CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version 2.4.8"
> +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid - https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
Hello,
I don't think we need this fix since MITRE data shows CVE-2025-68972 only
affect <= 2.4.8 and we are at 2.4.9.
Regards,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [OE-core] [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix
2026-08-31 14:21 ` [OE-core] " Yoann Congal
@ 2026-08-31 16:00 ` Roland Kovács
0 siblings, 0 replies; 3+ messages in thread
From: Roland Kovács @ 2026-08-31 16:00 UTC (permalink / raw)
To: openembedded-core@lists.openembedded.org, yoann.congal@smile.fr
On Mon, 2026-08-31 at 16:21 +0200, Yoann Congal wrote:
> On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org wrote:
> > Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
> > where the maintainer states that "[...] this is wrong usage of a tool or social
> > engineering".
> >
> > Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
> >
> > Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
> > ---
> > v1: https://lists.openembedded.org/g/openembedded-core/message/243897
> > v1 -> v2:
> > - Fix patchtest complaint about empty commit message.
> > meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
> > 1 file changed, 1 insertion(+)
> >
> > diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-
> > support/gnupg/gnupg_2.4.9.bb
> > index c85de6047f..3ebea399d7 100644
> > --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> > +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> > @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
> >
> > CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the
> > proposed commit - https://dev.gnupg.org/T5993"
> > CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version
> > 2.4.8"
> > +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid -
> > https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
>
> Hello,
>
> I don't think we need this fix since MITRE data shows CVE-2025-68972 only
> affect <= 2.4.8 and we are at 2.4.9.
>
> Regards,
Hi Yoann,
Sorry about it, feel free to drop!
It probably got in my queue before the recipe update, and I was just slow to react. :)
It's also possible that it is showing up on my side because debian tracker still marks this version
vulnerable (and we aggregate the sources).
https://security-tracker.debian.org/tracker/CVE-2025-68972
Cheers,
Roland
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-31 16:00 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-21 9:30 [scarthgap][PATCH v2] gnupg: Mark CVE-2025-68972 as upstream-wontfix Roland Kovacs
2026-08-31 14:21 ` [OE-core] " Yoann Congal
2026-08-31 16:00 ` Roland Kovács
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.