Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
where the maintainer states that "[...] this is wrong usage of a tool or social
engineering".

Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html

Signed-off-by: Roland Kovacs <[email protected]>
---
v1: https://lists.openembedded.org/g/openembedded-core/message/243897
v1 -> v2:
        - Fix patchtest complaint about empty commit message.
 meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb 
b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
index c85de6047f..3ebea399d7 100644
--- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
+++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
@@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
 
 CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be 
keen on merging the proposed commit - https://dev.gnupg.org/T5993";
 CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was 
backported to version 2.4.8"
+CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE 
invalid - 
https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html";
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243917): 
https://lists.openembedded.org/g/openembedded-core/message/243917
Mute This Topic: https://lists.openembedded.org/mt/120858960/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to