From 3c430b70b7541a3202d6f565cbfa8a5fa1c23e04 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Mon, 13 May 2024 15:21:30 +0000 Subject: [PATCH] cpio: mark CVE-2023-7216 as disputed Upstream consider the behaviour described in this CVE as intentional, and provide an option to stop it. (From OE-Core rev: 0f2cd2bbaddba3b8c80d71db274bbcd941d0e60e) Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (cherry picked from commit 6c99147037ba8ca424ee42520183bd2bd55c7056) Signed-off-by: Steve Sakoman --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index 52070f59a2..95f82cdf3a 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -16,6 +16,7 @@ SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee41834 inherit autotools gettext texinfo ptest CVE_STATUS[CVE-2010-4226] = "not-applicable-platform: Issue applies to use of cpio in SUSE/OBS" +CVE_STATUS[CVE-2023-7216] = "disputed: intended behaviour, see https://lists.gnu.org/archive/html/bug-cpio/2024-03/msg00000.html" EXTRA_OECONF += "DEFAULT_RMT_DIR=${sbindir}"