From 092abbe0352d62af8c17167e4f48e76aeea7ce99 Mon Sep 17 00:00:00 2001 From: Thomas Perale Date: Tue, 11 Aug 2026 13:35:01 +0200 Subject: [PATCH] package/busybox: re-introduce IGNORE_CVES for CVE-2023-42366 The patch `0008-awk.c-fix-CVE-2023-42366-bug-15874.patch` was introduced in [1]. The IGNORE_CVES entry was removed while the patch is still present in [2]. Re-introduce this IGNORE_CVES entry. [1] 75c594d446 package/busybox: fix pending CVEs [2] f88537c46b package/busybox: drop stale IGNORE_CVES entries Signed-off-by: Thomas Perale [Julien: fix patch number in comment (s/0008/0007/)] Signed-off-by: Julien Olivain --- package/busybox/busybox.mk | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/package/busybox/busybox.mk b/package/busybox/busybox.mk index 32a765c6a4..681624f6dd 100644 --- a/package/busybox/busybox.mk +++ b/package/busybox/busybox.mk @@ -15,6 +15,10 @@ BUSYBOX_CPE_ID_VENDOR = busybox # 0004-nslookup-sanitize-all-printed-strings-with-printable.patch BUSYBOX_IGNORE_CVES += CVE-2022-28391 +# This is not stale, NVD entry mentions up to version 1.36.1. +# 0007-awk.c-fix-CVE-2023-42366-bug-15874.patch +BUSYBOX_IGNORE_CVES += CVE-2023-42366 + # 0010-testsuite-tar-tests-fix-test-after-cve-2025-46394.patch BUSYBOX_IGNORE_CVES += CVE-2025-46394