mirror of
https://git.yoctoproject.org/poky
synced 2026-02-20 08:29:42 +01:00
golang: ignore CVE-2022-30580
Only affects Windows platform, as per the release announcement [1]: "If, on Windows, Cmd.Run, cmd.Start, cmd.Output, or cmd.CombinedOutput are executed when Cmd.Path is unset and, in the working directory, there are binaries named either "..com" or "..exe", they will be executed." [1] https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ (From OE-Core rev: 54c40730bc54aa2b2c12b37decbcc99bbcafd07a) Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
d9cfb16b8b
commit
d6dd3b49bd
@@ -65,6 +65,7 @@ CVE_CHECK_WHITELIST += "CVE-2022-29526"
|
||||
|
||||
# Issue only on windows
|
||||
CVE_CHECK_WHITELIST += "CVE-2022-29804"
|
||||
CVE_CHECK_WHITELIST += "CVE-2022-30580"
|
||||
CVE_CHECK_WHITELIST += "CVE-2022-30634"
|
||||
|
||||
# Issue is in golang.org/x/net/html/parse.go, not used in go compiler
|
||||
|
||||
Reference in New Issue
Block a user