ndpi: ignore CVE-2025-25066

Details: https://nvd.nist.gov/vuln/detail/CVE-2025-25066

The vulnerable code was introduced in version 4.12[1], and
the recipe version is not vulnerable yet. Due to this,
ignore this CVE.

[1]: b9348e9d6e

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Gyorgy Sarvari 2026-02-02 22:13:58 +01:00 committed by Anuj Mittal
parent dfc0632585
commit f52c71189f
No known key found for this signature in database
GPG Key ID: 4340AEFE69F5085C

View File

@ -13,7 +13,6 @@ SRC_URI = "git://github.com/ntop/nDPI.git;branch=4.2-stable;protocol=https \
file://0001-autogen.sh-not-generate-configure.patch \
"
inherit autotools-brokensep pkgconfig
CPPFLAGS += "${SELECTED_OPTIMIZATION}"
@ -25,3 +24,5 @@ do_configure:prepend() {
EXTRA_OEMAKE = " \
libdir=${libdir} \
"
CVE_STATUS[CVE-2025-25066] = "cpe-incorrect: Version 4.2 is not vulnerable yet"