From: Peter Marko <[email protected]> Per [1] this is fixed in 5.87. NVD tracks fix via hash, which cannot be used for version comparison in sbom-cve-check.
[1] https://nvd.nist.gov/vuln/detail/cve-2026-19774 Signed-off-by: Peter Marko <[email protected]> --- meta/recipes-connectivity/bluez5/bluez5_5.87.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/bluez5/bluez5_5.87.bb b/meta/recipes-connectivity/bluez5/bluez5_5.87.bb index 687780de21..08682b70d8 100644 --- a/meta/recipes-connectivity/bluez5/bluez5_5.87.bb +++ b/meta/recipes-connectivity/bluez5/bluez5_5.87.bb @@ -7,6 +7,7 @@ SRC_URI[sha256sum] = "26bdcf2cebd7310c6f598850606b037ef0c515fe6608ebc54d22c50c4c CVE_STATUS[CVE-2020-24490] = "cpe-incorrect: This issue has kernel fixes rather than bluez fixes" CVE_STATUS[CVE-2020-12351] = "cpe-incorrect: This issue has kernel fixes rather than bluez fixes" CVE_STATUS[CVE-2020-12352] = "cpe-incorrect: This issue has kernel fixes rather than bluez fixes" +CVE_STATUS[CVE-2026-19774] = "fixed-version: Fixed from version 5.87" # noinst programs in Makefile.tools that are conditional on READLINE # support
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246714): https://lists.openembedded.org/g/openembedded-core/message/246714 Mute This Topic: https://lists.openembedded.org/mt/121460540/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
