Gentle ping
maybe this was missed because of title similarity with the CVE-2024-35328?
Peter

> -----Original Message-----
> From: Marko, Peter (ADV D EU SK BFS1) <[email protected]>
> Sent: Wednesday, August 7, 2024 23:55
> To: [email protected]
> Cc: Marko, Peter (ADV D EU SK BFS1) <[email protected]>
> Subject: [OE-core][kirkstone][PATCH] libyaml: ignore CVE-2024-35326
> 
> From: Peter Marko <[email protected]>
> 
> This is the same problem as already ignored CVE-2024-35328.
> See laso this comment in addition:
> https://github.com/yaml/libyaml/issues/298#issuecomment-2167684233
> 
> Signed-off-by: Peter Marko <[email protected]>
> ---
>  meta/recipes-support/libyaml/libyaml_0.2.5.bb | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/meta/recipes-support/libyaml/libyaml_0.2.5.bb b/meta/recipes-
> support/libyaml/libyaml_0.2.5.bb
> index f7c29e7e0f..e30dc5a43f 100644
> --- a/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> +++ b/meta/recipes-support/libyaml/libyaml_0.2.5.bb
> @@ -19,6 +19,6 @@ DISABLE_STATIC:class-nativesdk = ""
>  DISABLE_STATIC:class-native = ""
> 
>  # upstream-wontfix: Upstream thinks there is no working code that is
> exploitable - https://github.com/yaml/libyaml/issues/302
> -CVE_CHECK_IGNORE += "CVE-2024-35328"
> +CVE_CHECK_IGNORE += "CVE-2024-35326 CVE-2024-35328"
> 
>  BBCLASSEXTEND = "native nativesdk"
> --
> 2.30.2

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#203276): 
https://lists.openembedded.org/g/openembedded-core/message/203276
Mute This Topic: https://lists.openembedded.org/mt/107777686/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to