diff mbox series

[kirkstone] libyaml: ignore CVE-2024-35326

Message ID 20240807215441.11715-1-peter.marko@siemens.com
State Accepted, archived
Commit 18e011245dd978985eecc368c503822f61d52f21
Delegated to: Steve Sakoman
Headers show
Series [kirkstone] libyaml: ignore CVE-2024-35326 | expand

Commit Message

Peter Marko Aug. 7, 2024, 9:54 p.m. UTC
From: Peter Marko <peter.marko@siemens.com>

This is the same problem as already ignored CVE-2024-35328.
See laso this comment in addition:
https://github.com/yaml/libyaml/issues/298#issuecomment-2167684233

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 meta/recipes-support/libyaml/libyaml_0.2.5.bb | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Peter Marko Aug. 13, 2024, 12:45 p.m. UTC | #1
Gentle ping
maybe this was missed because of title similarity with the CVE-2024-35328?
Peter

> -----Original Message-----
> From: Marko, Peter (ADV D EU SK BFS1) <Peter.Marko@siemens.com>
> Sent: Wednesday, August 7, 2024 23:55
> To: openembedded-core@lists.openembedded.org
> Cc: Marko, Peter (ADV D EU SK BFS1) <Peter.Marko@siemens.com>
> Subject: [OE-core][kirkstone][PATCH] libyaml: ignore CVE-2024-35326
> 
> From: Peter Marko <peter.marko@siemens.com>
> 
> This is the same problem as already ignored CVE-2024-35328.
> See laso this comment in addition:
> https://github.com/yaml/libyaml/issues/298#issuecomment-2167684233
> 
> Signed-off-by: Peter Marko <peter.marko@siemens.com>
> ---
>  meta/recipes-support/libyaml/libyaml_0.2.5.bb | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/meta/recipes-support/libyaml/libyaml_0.2.5.bb b/meta/recipes-
> support/libyaml/libyaml_0.2.5.bb
> index f7c29e7e0f..e30dc5a43f 100644
> --- a/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> +++ b/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> @@ -19,6 +19,6 @@ DISABLE_STATIC:class-nativesdk = ""
>  DISABLE_STATIC:class-native = ""
> 
>  # upstream-wontfix: Upstream thinks there is no working code that is
> exploitable - https://github.com/yaml/libyaml/issues/302
> -CVE_CHECK_IGNORE += "CVE-2024-35328"
> +CVE_CHECK_IGNORE += "CVE-2024-35326 CVE-2024-35328"
> 
>  BBCLASSEXTEND = "native nativesdk"
> --
> 2.30.2
Steve Sakoman Aug. 13, 2024, 1:05 p.m. UTC | #2
On Tue, Aug 13, 2024 at 5:45 AM Marko, Peter <Peter.Marko@siemens.com> wrote:
>
> Gentle ping
> maybe this was missed because of title similarity with the CVE-2024-35328?

Sorry!  I've got it in my test queue now.

Steve

> Peter
>
> > -----Original Message-----
> > From: Marko, Peter (ADV D EU SK BFS1) <Peter.Marko@siemens.com>
> > Sent: Wednesday, August 7, 2024 23:55
> > To: openembedded-core@lists.openembedded.org
> > Cc: Marko, Peter (ADV D EU SK BFS1) <Peter.Marko@siemens.com>
> > Subject: [OE-core][kirkstone][PATCH] libyaml: ignore CVE-2024-35326
> >
> > From: Peter Marko <peter.marko@siemens.com>
> >
> > This is the same problem as already ignored CVE-2024-35328.
> > See laso this comment in addition:
> > https://github.com/yaml/libyaml/issues/298#issuecomment-2167684233
> >
> > Signed-off-by: Peter Marko <peter.marko@siemens.com>
> > ---
> >  meta/recipes-support/libyaml/libyaml_0.2.5.bb | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/meta/recipes-support/libyaml/libyaml_0.2.5.bb b/meta/recipes-
> > support/libyaml/libyaml_0.2.5.bb
> > index f7c29e7e0f..e30dc5a43f 100644
> > --- a/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> > +++ b/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> > @@ -19,6 +19,6 @@ DISABLE_STATIC:class-nativesdk = ""
> >  DISABLE_STATIC:class-native = ""
> >
> >  # upstream-wontfix: Upstream thinks there is no working code that is
> > exploitable - https://github.com/yaml/libyaml/issues/302
> > -CVE_CHECK_IGNORE += "CVE-2024-35328"
> > +CVE_CHECK_IGNORE += "CVE-2024-35326 CVE-2024-35328"
> >
> >  BBCLASSEXTEND = "native nativesdk"
> > --
> > 2.30.2
>
diff mbox series

Patch

diff --git a/meta/recipes-support/libyaml/libyaml_0.2.5.bb b/meta/recipes-support/libyaml/libyaml_0.2.5.bb
index f7c29e7e0f..e30dc5a43f 100644
--- a/meta/recipes-support/libyaml/libyaml_0.2.5.bb
+++ b/meta/recipes-support/libyaml/libyaml_0.2.5.bb
@@ -19,6 +19,6 @@  DISABLE_STATIC:class-nativesdk = ""
 DISABLE_STATIC:class-native = ""
 
 # upstream-wontfix: Upstream thinks there is no working code that is exploitable - https://github.com/yaml/libyaml/issues/302
-CVE_CHECK_IGNORE += "CVE-2024-35328"
+CVE_CHECK_IGNORE += "CVE-2024-35326 CVE-2024-35328"
 
 BBCLASSEXTEND = "native nativesdk"