diff mbox series

[scarthgap,09/11] u-boot-tools: Ignore CVE-2026-29007

Message ID c4f4930eff400c1948d196e90c32db0d68e6aaab.1787731424.git.hthakar@cisco.com
State New
Headers show
Series u-boot-tools: address multiple CVEs | expand

Commit Message

From: Hetvi Thakar <hthakar@cisco.com>

Analysis:
- CVE-2026-29007 affects U-Boot TCP processing in net/tcp.c [1].
- u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled
  [2].
- Hence ignore this CVE for u-boot-tools; the exclusion is
  configuration-based.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
[2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
 meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 +
 1 file changed, 1 insertion(+)
diff mbox series

Patch

diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
index 898b808063..b13135c4de 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
@@ -10,3 +10,4 @@  CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not bu
 CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig."
 CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocator and affected target architecture code are not linked into the host tools produced by tools-only_defconfig."
 CVE_STATUS[CVE-2024-57259] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig."
+CVE_STATUS[CVE-2026-29007] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET."