[langdale,05/27] shadow: ignore CVE-2016-15024

Message ID 8dce0c01d9a0f6855e6a70a65412a43208b034a8.1678401759.git.steve@sakoman.com
Series [langdale,01/27] tiff: fix multiple CVEs | expand

Commit Message

Steve Sakoman March 9, 2023, 10:57 p.m. UTC
From: Ross Burton <ross.burton@arm.com>

This recently got an updated CPE which matches this recipe, but the issue
is related to an entirely different shadow project so ignore it.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
(cherry picked from commit 2331e98abb09cbcd56625d65c4e5d258dc29dd04)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
 meta/recipes-extended/shadow/shadow_4.12.3.bb | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/meta/recipes-extended/shadow/shadow_4.12.3.bb b/meta/recipes-extended/shadow/shadow_4.12.3.bb
index 40b11345c9..d1a3fd5593 100644
--- a/meta/recipes-extended/shadow/shadow_4.12.3.bb
+++ b/meta/recipes-extended/shadow/shadow_4.12.3.bb
@@ -9,3 +9,6 @@  BBCLASSEXTEND = "native nativesdk"
 # Severity is low and marked as closed and won't fix.
 # https://bugzilla.redhat.com/show_bug.cgi?id=884658
 CVE_CHECK_IGNORE += "CVE-2013-4235"
+# This is an issue for a different shadow
+CVE_CHECK_IGNORE += "CVE-2016-15024"