On Fri Aug 21, 2026 at 11:30 AM CEST, Roland Kovács via lists.openembedded.org wrote: > Mark CVE-2025-68972 as upstream-wontfix based on mailing list discussion, > where the maintainer states that "[...] this is wrong usage of a tool or > social > engineering". > > Link: https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html > > Signed-off-by: Roland Kovacs <[email protected]> > --- > v1: https://lists.openembedded.org/g/openembedded-core/message/243897 > v1 -> v2: > - Fix patchtest complaint about empty commit message. > meta/recipes-support/gnupg/gnupg_2.4.9.bb | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/meta/recipes-support/gnupg/gnupg_2.4.9.bb > b/meta/recipes-support/gnupg/gnupg_2.4.9.bb > index c85de6047f..3ebea399d7 100644 > --- a/meta/recipes-support/gnupg/gnupg_2.4.9.bb > +++ b/meta/recipes-support/gnupg/gnupg_2.4.9.bb > @@ -85,3 +85,4 @@ lcl_maybe_fortify:mipsarch = "" > > CVE_STATUS[CVE-2022-3219] = "upstream-wontfix: Upstream doesn't seem to be > keen on merging the proposed commit - https://dev.gnupg.org/T5993" > CVE_STATUS[CVE-2025-30258] = "cpe-stable-backport: fir for this CVE was > backported to version 2.4.8" > +CVE_STATUS[CVE-2025-68972] = "upstream-wontfix: Upstream considers this CVE > invalid - > https://lists.gnupg.org/pipermail/gnupg-devel/2026-January/036154.html"
Hello, I don't think we need this fix since MITRE data shows CVE-2025-68972 only affect <= 2.4.8 and we are at 2.4.9. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244766): https://lists.openembedded.org/g/openembedded-core/message/244766 Mute This Topic: https://lists.openembedded.org/mt/120858960/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
