diff mbox series

[meta-networking,scarthgap] ntpsec: add CVE_STATUS for CVE-2016-1548

Message ID 20261001144223.2075665-1-joaomarcos.costa@bootlin.com
State New
Headers show
Series [meta-networking,scarthgap] ntpsec: add CVE_STATUS for CVE-2016-1548 | expand

Commit Message

Joao Marcos Costa Oct. 1, 2026, 2:42 p.m. UTC
From: João Marcos Costa (Schneider Electric) <joaomarcos.costa@bootlin.com>

This vulnerability was fixed since v0.9.3 (tag name 'NTPsec_0_9_3') [1],
and the version range is not well defined as of today, for instance,
in NVD database [2]. This can lead to false positives in CVE reports.

Mark this CVE as fixed.

[1] https://github.com/ntpsec/ntpsec/blob/master/NEWS.adoc#2016-05-17-093
[2] https://nvd.nist.gov/vuln/detail/cve-2016-1548

Signed-off-by: João Marcos Costa (Schneider Electric) <joaomarcos.costa@bootlin.com>
---
 meta-networking/recipes-support/ntpsec/ntpsec_1.2.2a.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta-networking/recipes-support/ntpsec/ntpsec_1.2.2a.bb b/meta-networking/recipes-support/ntpsec/ntpsec_1.2.2a.bb
index 9ad97e7689..4b6125b4c5 100644
--- a/meta-networking/recipes-support/ntpsec/ntpsec_1.2.2a.bb
+++ b/meta-networking/recipes-support/ntpsec/ntpsec_1.2.2a.bb
@@ -19,6 +19,8 @@  SRC_URI = "https://ftp.ntpsec.org/pub/releases/ntpsec-${PV}.tar.gz \
 
 SRC_URI[sha256sum] = "e0ce93af222a0a9860e6f5a51aadba9bb5ca601d80b2aea118a62f0a3226950e"
 
+CVE_STATUS[CVE-2016-1548] = "fixed-version: fixed at ntpsec upstream, since NTPsec_0_9_3 tag"
+
 UPSTREAM_CHECK_URI = "ftp://ftp.ntpsec.org/pub/releases/"
 
 inherit pkgconfig python3-dir python3targetconfig systemd update-alternatives update-rc.d useradd waf features_check