public inbox for openembedded-core@lists.openembedded.org
 help / color / mirror / Atom feed
* [PATCH 0/2] meta: remove reference in patches to rejected CVE
@ 2026-02-20 11:01 Benjamin Robin (Schneider Electric)
  2026-02-20 11:01 ` [PATCH 1/2] meta: update avahi patch to remove ref " Benjamin Robin (Schneider Electric)
  2026-02-20 11:01 ` [PATCH 2/2] meta: in lz4 remove reference to rejected CVE-2025-62813 Benjamin Robin (Schneider Electric)
  0 siblings, 2 replies; 6+ messages in thread
From: Benjamin Robin (Schneider Electric) @ 2026-02-20 11:01 UTC (permalink / raw)
  To: openembedded-core
  Cc: ross.burton, thomas.petazzoni, mathieu.dubois-briand,
	antonin.godard, jpewhacker, Benjamin Robin (Schneider Electric),
	Peter Marko

Remove the reference of 2 CVE identifiers in patch files, since the
CVEs are rejected. Remove reference to CVE-2025-62813 and to
CVE-2021-3502.

These 2 issues were found by using sbom-cve-check on the whole layer.

Signed-off-by: Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>
---
Benjamin Robin (Schneider Electric) (2):
      meta: update avahi patch to remove ref to rejected CVE
      meta: in lz4 remove reference to rejected CVE-2025-62813

 meta/recipes-connectivity/avahi/files/local-ping.patch                  | 1 -
 .../lz4/lz4/{CVE-2025-62813.patch => fix-null-error-handling.patch}     | 1 -
 meta/recipes-support/lz4/lz4_1.10.0.bb                                  | 2 +-
 3 files changed, 1 insertion(+), 3 deletions(-)
---
base-commit: 74ba238ff1ba1e9b612aece1989b828f3a8f8770
change-id: 20260220-update-patch-with-rejected-cve-13cd13bb3e4f

Best regards,
-- 
Benjamin Robin (Schneider Electric) <benjamin.robin@bootlin.com>



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-02-20 15:50 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-02-20 11:01 [PATCH 0/2] meta: remove reference in patches to rejected CVE Benjamin Robin (Schneider Electric)
2026-02-20 11:01 ` [PATCH 1/2] meta: update avahi patch to remove ref " Benjamin Robin (Schneider Electric)
2026-02-20 15:46   ` [OE-core] " Peter Kjellerstedt
2026-02-20 15:50     ` Benjamin ROBIN
2026-02-20 11:01 ` [PATCH 2/2] meta: in lz4 remove reference to rejected CVE-2025-62813 Benjamin Robin (Schneider Electric)
2026-02-20 15:47   ` [OE-core] " Peter Kjellerstedt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox