From: Hetvi Thakar <[email protected]> Analysis:
- The vulnerable code for CVE-2026-51400 is in src/os_vms.c. [1] - src/os_vms.c is VMS-specific and is not compiled for Linux builds. - Record the not-applicable-platform status; no source patch is required. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-51400 Signed-off-by: Hetvi Thakar <[email protected]> --- meta/recipes-support/vim/vim.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 77f681410a..afdb46b4be 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -50,6 +50,8 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} PV .= ".0340" SRCREV = "6addd6c101117706bc9b3609d3a418e26e92618f" +CVE_STATUS[CVE-2026-51400] = "not-applicable-platform: Vulnerable code is in src/os_vms.c, which is not compiled for Linux builds." + # Do not consider .z in x.y.z, as that is updated with every commit UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>\d+\.\d+)\.0" # Ignore that the upstream version .z in x.y.z is always newer -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246806): https://lists.openembedded.org/g/openembedded-core/message/246806 Mute This Topic: https://lists.openembedded.org/mt/121485277/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
