diff mbox series

[meta-networking] libcoap: set CVE version suffix

Message ID 20260116195600.1017576-1-peter.marko@siemens.com
State Under Review
Headers show
Series [meta-networking] libcoap: set CVE version suffix | expand

Commit Message

Peter Marko Jan. 16, 2026, 7:56 p.m. UTC
From: Peter Marko <peter.marko@siemens.com>

CVE metrics currently report CVE-2025-34468 as open.
CPE is <=4.3.5, while recipe version is 4.3.5a which is a higher
version, however by default cve-check only compares numbers.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb b/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb
index 1a8d7ed725..611795e17d 100644
--- a/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb
+++ b/meta-networking/recipes-devtools/libcoap/libcoap_4.3.5a.bb
@@ -12,6 +12,8 @@  SRC_URI = "git://github.com/obgm/libcoap.git;branch=release-4.3.5-patches;protoc
            "
 SRCREV = "e3fdcdcfbd1588754fe9dd4b754ac9397260f0f9"
 
+# patch releases often use alphabetical suffixes
+CVE_VERSION_SUFFIX = "alphabetical"
 
 inherit autotools manpages pkgconfig ptest