From: Peter Marko <[email protected]> Per [1] this is fixed in 1.28.2. cvelistV5 has just hash in version so creates false positive.
[1] https://security-tracker.debian.org/tracker/CVE-2026-5056 Signed-off-by: Peter Marko <[email protected]> Signed-off-by: Fabien Thomas <[email protected]> --- meta/recipes-multimedia/gstreamer/gstreamer1.0_1.28.2.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.28.2.bb b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.28.2.bb index b727783746..4e51418c98 100644 --- a/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.28.2.bb +++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0_1.28.2.bb @@ -71,4 +71,6 @@ RDEPENDS:${PN}-ptest:append:libc-glibc = " glibc-gconv-iso8859-5" CVE_PRODUCT = "gstreamer" +CVE_STATUS[CVE-2026-5056] = "cpe-stable-backport: Fixed since 1.28.2" + PTEST_BUILD_HOST_FILES = ""
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243368): https://lists.openembedded.org/g/openembedded-core/message/243368 Mute This Topic: https://lists.openembedded.org/mt/120735237/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
