mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-09-17 00:25:36 +00:00
nodejs: ignore CVE-2024-22017
Details: https://nvd.nist.gov/vuln/detail/CVE-2024-22017
The vulnerability is related to the io_uring usage of libuv.
Libuv first introduced io_uring support in v1.45[1].
oe-core ships a non-vulnerable version (1.44.2), and nodejs
vendors also an older version (1.43).
Mark this CVE as ignored for this recipe version.
[1]: d2c31f429b
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
This commit is contained in:
parent
f9ed3b8197
commit
ab83c61385
@ -50,6 +50,9 @@ CVE_PRODUCT = "nodejs node.js"
|
|||||||
# the vulnerabilities were introduced in v20
|
# the vulnerabilities were introduced in v20
|
||||||
CVE_CHECK_IGNORE = "CVE-2023-30583 CVE-2023-30584 CVE-2023-30587"
|
CVE_CHECK_IGNORE = "CVE-2023-30583 CVE-2023-30584 CVE-2023-30587"
|
||||||
|
|
||||||
|
# the vulnerability was introduced later (with libuv 1.45)
|
||||||
|
CVE_CHECK_IGNORE += "CVE-2024-22017"
|
||||||
|
|
||||||
# v8 errors out if you have set CCACHE
|
# v8 errors out if you have set CCACHE
|
||||||
CCACHE = ""
|
CCACHE = ""
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user