From 7c7c3f3dd3bf7dc34f26d931acf562e93c45e807 Mon Sep 17 00:00:00 2001 From: Richard Purdie Date: Mon, 10 May 2021 13:36:02 +0100 Subject: qemu: Exclude CVE-2018-18438 from cve-check The issues were investigated and found not to be an issue therefore exclude from checks. Signed-off-by: Richard Purdie --- meta/recipes-devtools/qemu/qemu.inc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index c56f341a5e..fbda0c9174 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc @@ -72,6 +72,10 @@ CVE_CHECK_WHITELIST += "CVE-2017-5957" # enable it by default. CVE_CHECK_WHITELIST += "CVE-2007-0998" +# 'The issues identified by this CVE were determined to not constitute a vulnerability.' +# https://bugzilla.redhat.com/show_bug.cgi?id=1609015#c11 +CVE_CHECK_WHITELIST += "CVE-2018-18438" + COMPATIBLE_HOST_mipsarchn32 = "null" COMPATIBLE_HOST_mipsarchn64 = "null" -- cgit 1.2.3-korg