Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion, where the maintainer states that "[...] this is wrong usage of a tool or social engineering".
Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html Signed-off-by: Roland Kovacs <[email protected]> --- v1: https://lists.openembedded.org/g/openembedded-core/message/243897 v1 -> v2: - Fix patchtest complaint about empty commit message. meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb b/meta/recipes-support/gnupg/gnupg_2.4.9.bb index c85de6047f..3ebea399d7 100644 --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = "" CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be keen on merging the proposed commit - https://dev.gnupg.org/T5993" CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was backported to version 2.4.8" +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE invalid - https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243917): https://lists.openembedded.org/g/openembedded-core/message/243917 Mute This Topic: https://lists.openembedded.org/mt/120858960/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
