mbox series

[kirkstone,0/1] Ignore CVE-2023-47100

Message ID 20240403193216.971802-1-alex.stewart@ni.com
Headers show
Series Ignore CVE-2023-47100 | expand

Message

Alex Stewart April 3, 2024, 7:32 p.m. UTC
CVE-2023-47100 is an NVD 9.8 vulnerability filed against perl 5.30.0,
through 5.38.2 - which includes the 5.34.3 version used in OE-core
kirkstone.

But the issue and reported fix are the same as CVE-2023-47038, whose fix
has already been merged into the 5.34.3 source. Further, both CVEs have
inaccurate configuration ranges reported on NVD. NI filed several
requests to MITRE to correct the duplication weeks ago, but there hasn't
been any action.

I manually checked the kirkstone perl sources and confirmed that the
common fix for both CVEs is in place.

-47038 is already correctly-reported as 'patched' (due to the erroneous
configuration string). This patchset further ignores the duplicate
-47100 filing.

Alex Stewart (1):
  perl: ignore CVE-2023-47100

 meta/recipes-devtools/perl/perl_5.34.3.bb | 3 +++
 1 file changed, 3 insertions(+)