diff mbox series

[1/4] rpm-sequoia: set status for CVE-2026-2625

Message ID 20260509224536.27734-1-peter.marko@siemens.com
State Under Review
Headers show
Series [1/4] rpm-sequoia: set status for CVE-2026-2625 | expand

Commit Message

Peter Marko May 9, 2026, 10:45 p.m. UTC
From: Peter Marko <peter.marko@siemens.com>

This is a version-less RedHat CVE.
[1] points to [2] included in v1.10.2.

[1] https://security-tracker.debian.org/tracker/CVE-2026-2625
[2] https://github.com/rpm-software-management/rpm-sequoia/commit/fa3c60094fa853ede6b4862e936f246412d700de

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 meta/recipes-devtools/rpm-sequoia/rpm-sequoia_1.10.2.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-devtools/rpm-sequoia/rpm-sequoia_1.10.2.bb b/meta/recipes-devtools/rpm-sequoia/rpm-sequoia_1.10.2.bb
index d190db88b6..a6b32bb007 100644
--- a/meta/recipes-devtools/rpm-sequoia/rpm-sequoia_1.10.2.bb
+++ b/meta/recipes-devtools/rpm-sequoia/rpm-sequoia_1.10.2.bb
@@ -77,3 +77,5 @@  RDEPENDS:${PN} = "rpm-sequoia-crypto-policy"
 PACKAGE_WRITE_DEPS += "rpm-sequoia-crypto-policy-native"
 
 BBCLASSEXTEND = "native"
+
+CVE_STATUS[CVE-2026-2625] = "fixed-version: fixed since v1.10.2"