On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org 
wrote:
> Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion,
> where the maintainer states that "[...] this is wrong usage of a tool or 
> social
> engineering".
>
> Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html
>
> Signed-off-by: Roland Kovacs <[email protected]>
> ---
> v1: https://lists.openembedded.org/g/openembedded-core/message/243897
> v1 -> v2:
>       - Fix patchtest complaint about empty commit message.
>  meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb 
> b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> index c85de6047f..3ebea399d7 100644
> --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb
> @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = ""
>  
>  CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be 
> keen on merging the proposed commit - https://dev.gnupg.org/T5993";
>  CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was 
> backported to version 2.4.8"
> +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE 
> invalid - 
> https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html";

Hello,

I don't think we need this fix since MITRE data shows CVE-2025-68972 only
affect <= 2.4.8 and we are at 2.4.9.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244766): 
https://lists.openembedded.org/g/openembedded-core/message/244766
Mute This Topic: https://lists.openembedded.org/mt/120858960/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to