From: Peter Marko <[email protected]>

Per [1] this is fixed in 5.87.
NVD tracks fix via hash, which cannot be used for version comparison in
sbom-cve-check.

[1] https://nvd.nist.gov/vuln/detail/cve-2026-19774

Signed-off-by: Peter Marko <[email protected]>
---
 meta/recipes-connectivity/bluez5/bluez5_5.87.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-connectivity/bluez5/bluez5_5.87.bb 
b/meta/recipes-connectivity/bluez5/bluez5_5.87.bb
index 687780de21..08682b70d8 100644
--- a/meta/recipes-connectivity/bluez5/bluez5_5.87.bb
+++ b/meta/recipes-connectivity/bluez5/bluez5_5.87.bb
@@ -7,6 +7,7 @@ SRC_URI[sha256sum] = 
"26bdcf2cebd7310c6f598850606b037ef0c515fe6608ebc54d22c50c4c
 CVE_STATUS[CVE-2020-24490] = "cpe-incorrect: This issue has kernel fixes 
rather than bluez fixes"
 CVE_STATUS[CVE-2020-12351] = "cpe-incorrect: This issue has kernel fixes 
rather than bluez fixes"
 CVE_STATUS[CVE-2020-12352] = "cpe-incorrect: This issue has kernel fixes 
rather than bluez fixes"
+CVE_STATUS[CVE-2026-19774] = "fixed-version: Fixed from version 5.87"
 
 # noinst programs in Makefile.tools that are conditional on READLINE
 # support
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246714): 
https://lists.openembedded.org/g/openembedded-core/message/246714
Mute This Topic: https://lists.openembedded.org/mt/121460540/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to