From: Peter Marko <[email protected]>

Patch [1] mentioned as commit fixing this CVE in NVD or Debian reports
is fixing code adding new feature (route advertisment processing) which
is also mentioned in the CVE descripiton.
That was introduced in commit [2] which is v10.0.7 (>10.0.6)

[1] 
https://github.com/NetworkConfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0
[2] 
https://github.com/NetworkConfiguration/dhcpcd/commit/f1cf924ad691bc1e6bf33013407fbf838fa40fbe

Signed-off-by: Peter Marko <[email protected]>
---
 meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb 
b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb
index e6854e1c7f2..c32db0adf5d 100644
--- a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb
+++ b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb
@@ -62,3 +62,5 @@ do_install:append () {
 }
 
 FILES:${PN}-dbg += "${libdir}/dhcpcd/dev/.debug"
+
+CVE_STATUS[CVE-2026-56116] = "fixed-version: vulnerability was only introduced 
in v10.0.7"
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247157): 
https://lists.openembedded.org/g/openembedded-core/message/247157
Mute This Topic: https://lists.openembedded.org/mt/121561293/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to