diff mbox series

[meta-gnome,kirkstone,3/5] gnome-settings-daemon: ignore CVE-2024-38394

Message ID 20260129063129.223926-3-skandigraun@gmail.com
State New
Headers show
Series [meta-python,kirkstone,1/5] python3-twitter: mark CVE-2012-5825 patched | expand

Commit Message

Gyorgy Sarvari Jan. 29, 2026, 6:31 a.m. UTC
Details: https://nvd.nist.gov/vuln/detail/CVE-2024-38394

The CVE has the disputed flag. The project maintainers claim that the issue
is not in gnome-setttings-daemon. If the vulnerability needs to be handled
in gnome-settings-daemon, than it is a new feature rather than a vulnerability fix.

Due to this, ignore this CVE.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
---
 .../gnome-settings-daemon/gnome-settings-daemon_42.2.bb        | 3 +++
 1 file changed, 3 insertions(+)
diff mbox series

Patch

diff --git a/meta-gnome/recipes-gnome/gnome-settings-daemon/gnome-settings-daemon_42.2.bb b/meta-gnome/recipes-gnome/gnome-settings-daemon/gnome-settings-daemon_42.2.bb
index 45622490f0..4617340b06 100644
--- a/meta-gnome/recipes-gnome/gnome-settings-daemon/gnome-settings-daemon_42.2.bb
+++ b/meta-gnome/recipes-gnome/gnome-settings-daemon/gnome-settings-daemon_42.2.bb
@@ -44,3 +44,6 @@  FILES:${PN} += " \
     ${systemd_user_unitdir} \
     ${libdir}/gnome-settings-daemon-42/libgsd.so \
 "
+
+# mitigation would be a new feature, not a CVE
+CVE_CHECK_IGNORE += "CVE-2024-38394"