| Message ID | b1f2c26126e8733439832f840621c3b29169374d.1789163914.git.yoann.congal@smile.fr |
|---|---|
| State | RFC, archived |
| Headers | show |
| Series | [scarthgap,01/13] linux-yocto/6.6: update CVE exclusions (6.6.151) | expand |
diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index b36632cc1fe..2eb22e2d61a 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb @@ -84,3 +84,8 @@ ALTERNATIVE_LINK_NAME[cpio] = "${base_bindir}/cpio" ALTERNATIVE_TARGET[cpio] = "${bindir}/bsdcpio" BBCLASSEXTEND = "native nativesdk" + +CVE_STATUS[CVE-2026-14164] = "fixed-version: Double-free regression in the RAR5\ + reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\ + only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\ + never part of an upstream release tarball."