aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRichard Purdie <richard.purdie@linuxfoundation.org>2021-05-11 13:47:54 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2021-05-22 10:00:45 +0100
commit21b6975cc6c785aa3bf7f7d4ea2400e11f1800bd (patch)
treeda97d4cadc9cd8ae8c2f25bee23ee6e33e83d9f7
parente19caff111bcbd70e5e7507388a4aaea2d10f7e0 (diff)
downloadopenembedded-core-21b6975cc6c785aa3bf7f7d4ea2400e11f1800bd.tar.gz
openembedded-core-21b6975cc6c785aa3bf7f7d4ea2400e11f1800bd.tar.bz2
openembedded-core-21b6975cc6c785aa3bf7f7d4ea2400e11f1800bd.zip
bluez: Exclude CVE-2020-12352 CVE-2020-24490 from cve-check
These CVEs are fixed with kernel changes and don't affect the bluez recipe. Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-connectivity/bluez5/bluez5_5.56.bb3
1 files changed, 3 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/bluez5/bluez5_5.56.bb b/meta/recipes-connectivity/bluez5/bluez5_5.56.bb
index 676cb2dbb2..ae0f72b678 100644
--- a/meta/recipes-connectivity/bluez5/bluez5_5.56.bb
+++ b/meta/recipes-connectivity/bluez5/bluez5_5.56.bb
@@ -3,6 +3,9 @@ require bluez5.inc
SRC_URI[md5sum] = "e6c51b2aefa7c56ff072819a78611fa5"
SRC_URI[sha256sum] = "59c4dba9fc8aae2a6a5f8f12f19bc1b0c2dc27355c7ca3123eed3fe6bd7d0b9d"
+# These issues have kernel fixes rather than bluez fixes so exclude here
+CVE_CHECK_WHITELIST += "CVE-2020-12352 CVE-2020-24490"
+
# noinst programs in Makefile.tools that are conditional on READLINE
# support
NOINST_TOOLS_READLINE ?= " \