From: Hetvi Thakar <[email protected]>

Analysis:
- NVD identifies the vulnerable code as net/tcp.c when
  CONFIG_PROT_TCP is enabled [1].
- tools-only_defconfig disables networking, so this code is not built
  into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig

Signed-off-by: Hetvi Thakar <[email protected]>
Signed-off-by: Yoann Congal <[email protected]>
---
 meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb 
b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 7eaf721ca83..0e57bb88849 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -1,2 +1,4 @@
 require u-boot-common.inc
 require u-boot-tools.inc
+
+CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig 
disables networking; net/tcp.c is not compiled into u-boot-tools."
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245436): 
https://lists.openembedded.org/g/openembedded-core/message/245436
Mute This Topic: https://lists.openembedded.org/mt/121158865/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to