diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index d27d7644..aaba26fe 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -192,3 +192,10 @@ CVE_STATUS[CVE-2025-68195] = "fixed-version: Fixed from 6.18"
 # Fix https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3
 # Backport https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
 CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
+
+# Consequence of the default weak host model, not a specific defect.
+# Mitigation is configuration only: rp_filter for IPv4, or a strong host
+# model rule such as the one wg-quick(8) installs, which also covers IPv6.
+# https://www.openwall.com/lists/oss-security/2019/12/05/1
+CVE_STATUS[CVE-2019-14899] = "upstream-wontfix: consequence of the default weak \
+host model, no kernel fix exists or is planned, mitigated by firewall configuration"
