diff mbox series

[master,nanbield,2/4] zlib: ignore CVE-2023-45853

Message ID 20231023173822.3476595-2-ross.burton@arm.com
State New, archived
Headers show
Series [master,nanbield,1/4] libxml2: ignore disputed CVE-2023-45322 | expand

Commit Message

Ross Burton Oct. 23, 2023, 5:38 p.m. UTC
From: Ross Burton <ross.burton@arm.com>

This CVE relates to a bug in the minizip tool, but we don't build that.

Signed-off-by: Ross Burton <ross.burton@arm.com>
---
 meta/recipes-core/zlib/zlib_1.3.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-core/zlib/zlib_1.3.bb b/meta/recipes-core/zlib/zlib_1.3.bb
index c8fd855ee67..1ed18172faa 100644
--- a/meta/recipes-core/zlib/zlib_1.3.bb
+++ b/meta/recipes-core/zlib/zlib_1.3.bb
@@ -45,3 +45,5 @@  do_install_ptest() {
 }
 
 BBCLASSEXTEND = "native nativesdk"
+
+CVE_STATUS[CVE-2023-45853] = "not-applicable-config: we don't build minizip"