summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@intel.com>2019-11-04 14:26:54 +0000
committerRichard Purdie <richard.purdie@linuxfoundation.org>2019-11-05 10:36:20 +0000
commit2c2f70f0f364474e2d9c7d7e5480e80c77e5dea4 (patch)
tree1e4fb1d786797ac0c8db91432704e37f7abe011f
parentb3fa0654abf9ac32f683ac174e453ea5e64b6cb8 (diff)
downloadopenembedded-core-contrib-2c2f70f0f364474e2d9c7d7e5480e80c77e5dea4.tar.gz
openembedded-core-contrib-2c2f70f0f364474e2d9c7d7e5480e80c77e5dea4.tar.bz2
openembedded-core-contrib-2c2f70f0f364474e2d9c7d7e5480e80c77e5dea4.zip
libsndfile1: whitelist CVE-2018-13419
This is a memory leak that nobody else can replicate and has been rejected by upstream. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb4
1 files changed, 4 insertions, 0 deletions
diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb
index ffb45855a4..7855008f3d 100644
--- a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb
+++ b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb
@@ -33,3 +33,7 @@ PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib"
PACKAGECONFIG[regtest] = "--enable-sqlite,--disable-sqlite,sqlite3"
inherit autotools lib_package pkgconfig
+
+# This can't be replicated and is just a memory leak.
+# https://github.com/erikd/libsndfile/issues/398
+CVE_CHECK_WHITELIST += "CVE-2018-13419"