On 28 Feb 2026, at 21:45, Peter Marko via lists.openembedded.org 
<[email protected]> wrote:
> 
> From: Peter Marko <[email protected]>
> 
> Per [1] is patch for this CVE [2].
> This is equivalent of [3] which is included in n8.0.
> 
> [1] https://security-tracker.debian.org/tracker/CVE-2025-12343
> [2] 
> https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/b8d5f65b9e89d893f27cf00799dbc15fc0ca2f8e
> [3] 
> https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/263e819aa45cd3c48bf6887be02b4ec504c02048

Is this exposing a problem in cve-check?  The CVE metadata says “from 
(including) 6.1” and “up to (excluding) 8.1” so we should be marking this as 
handled already?

Ross
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#232333): 
https://lists.openembedded.org/g/openembedded-core/message/232333
Mute This Topic: https://lists.openembedded.org/mt/118067499/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to