Ignore CVE-2026-5745 as libarcihive maintainer rejected CVE-2026-5745.
This is reproducible only with UBSAN, using with
'-fsanitize=pointer-overflow -fsanitize-trap=pointer-overflow'.
The root cause remains a UBSAN violation, not a NULL pointer dereference

https://github.com/libarchive/libarchive/issues/2904#issuecomment-4257068822

Signed-off-by: Sana Kazi <[email protected]>
---
 meta/recipes-extended/libarchive/libarchive_3.7.9.bb | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb 
b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
index 6b31256960..e402a485b3 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb
@@ -80,4 +80,9 @@ ALTERNATIVE:bsdcpio = "cpio"
 ALTERNATIVE_LINK_NAME[cpio] = "${base_bindir}/cpio"
 ALTERNATIVE_TARGET[cpio] = "${bindir}/bsdcpio"
 
+python() {
+    if not bb.utils.filter('CFLAGS', '-fsanitize=pointer-overflow 
-fsanitize-trap=pointer-overflow', d):
+        d.setVarFlag("CVE_STATUS", "CVE-2026-5745", "not-applicable-config: 
sanitize is disabled")
+}
+
 BBCLASSEXTEND = "native nativesdk"
-- 
2.34.1

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#237536): 
https://lists.openembedded.org/g/openembedded-core/message/237536
Mute This Topic: https://lists.openembedded.org/mt/119438720/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to