mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 08:14:09 -09:00
package/glibc: remove stale IGNORE_CVES
Since Buildroot commit [1] the CVEs are no longer matched to CPEs with versions using '-'. These IGNORE_CVES entries introduced in [2] are then no longer matched to the glibc package. For more information, see the explanation in commit [1]. [1]35f376d88esupport/scripts/cve.py: fix CPE matching [2]adaae82c58package/glibc: ignore CVEs not considered as security issues by upstream Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> (cherry picked from commit9383a3a726) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
@@ -34,19 +34,10 @@ GLIBC_IGNORE_CVES += CVE-2025-5702
|
||||
# Fixed by glibc-2.41-64-g1e16d0096d80a6e12d5bfa8e0aafdd13c47efd65
|
||||
GLIBC_IGNORE_CVES += CVE-2025-8058
|
||||
|
||||
# All these CVEs are considered as not being security issues by
|
||||
# This CVE is considered as not being security issues by
|
||||
# upstream glibc:
|
||||
# https://security-tracker.debian.org/tracker/CVE-2010-4756
|
||||
# https://security-tracker.debian.org/tracker/CVE-2019-1010022
|
||||
# https://security-tracker.debian.org/tracker/CVE-2019-1010023
|
||||
# https://security-tracker.debian.org/tracker/CVE-2019-1010024
|
||||
# https://security-tracker.debian.org/tracker/CVE-2019-1010025
|
||||
GLIBC_IGNORE_CVES += \
|
||||
CVE-2010-4756 \
|
||||
CVE-2019-1010022 \
|
||||
CVE-2019-1010023 \
|
||||
CVE-2019-1010024 \
|
||||
CVE-2019-1010025
|
||||
GLIBC_IGNORE_CVES += CVE-2010-4756
|
||||
|
||||
# glibc is part of the toolchain so disable the toolchain dependency
|
||||
GLIBC_ADD_TOOLCHAIN_DEPENDENCY = NO
|
||||
|
||||
Reference in New Issue
Block a user