From: Peter Marko <[email protected]> Patch [1] mentioned as commit fixing this CVE in NVD or Debian reports is fixing code adding new feature (route advertisment processing) which is also mentioned in the CVE descripiton. That was introduced in commit [2] which is v10.0.7 (>10.0.6)
[1] https://github.com/NetworkConfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0 [2] https://github.com/NetworkConfiguration/dhcpcd/commit/f1cf924ad691bc1e6bf33013407fbf838fa40fbe Signed-off-by: Peter Marko <[email protected]> --- meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb index e6854e1c7f2..c32db0adf5d 100644 --- a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb +++ b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.0.6.bb @@ -62,3 +62,5 @@ do_install:append () { } FILES:${PN}-dbg += "${libdir}/dhcpcd/dev/.debug" + +CVE_STATUS[CVE-2026-56116] = "fixed-version: vulnerability was only introduced in v10.0.7"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247157): https://lists.openembedded.org/g/openembedded-core/message/247157 Mute This Topic: https://lists.openembedded.org/mt/121561293/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
