diff mbox series

[walnascar,03/10] gstreamer1.0: set status of CVE-2025-3887 to patched

Message ID 20250925140514.1103300-3-peter.marko@siemens.com
State Accepted
Delegated to: Steve Sakoman
Headers show
Series [walnascar,01/10] gstreamer1.0: set status of 5 CVEs to patched | expand

Commit Message

Peter Marko Sept. 25, 2025, 2:05 p.m. UTC
From: Peter Marko <peter.marko@siemens.com>

This CVE was fixed in plugins-bad.
See [1] and [2] which is included in 1.24.13.
These commits are backport of [3] to 1.24.
Commits fixing this CVE were copied from [4].

[1] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/e4351ef03f1331410b0c1216a6178d885f37e495
[2] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/ed4c2ce380f7168bd4a3423f4398eb341cb931c7
[3] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8884
[4] https://security-tracker.debian.org/tracker/CVE-2025-3887

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 meta/recipes-multimedia/gstreamer/gstreamer1.0_1.24.13.bb | 4 ++++
 1 file changed, 4 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.24.13.bb b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.24.13.bb
index 71a360ae7b3..d15b7daab8c 100644
--- a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.24.13.bb
+++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.24.13.bb
@@ -77,4 +77,8 @@  CVE_STATUS_STABLE_BACKPORT[status] = "cpe-stable-backport: these CVEs are patche
 
 CVE_STATUS[CVE-2025-2759] = "not-applicable-platform: affects installation packages for non Linux OSes"
 
+CVE_STATUS_GROUPS += "CVE_STATUS_PLUGINS_BAD"
+CVE_STATUS_PLUGINS_BAD = "CVE-2025-3887"
+CVE_STATUS_PLUGINS_BAD[status] = "cpe-incorrect: these CVEs is patched in current version of gstreamer1.0-plugins-bad"
+
 PTEST_BUILD_HOST_FILES = ""