Przeglądaj źródła

package/openssh: add CVE ignore for CVE-2024-6387

Commit e7f124e9b632 (package/openssh: disable async-signal-unsafe code in
sshsigdie()) add a patch for CVE-2024-6387 but forgot to add an _IGNORE_CVES
entry.  Fix that.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Peter Korsgaard 1 rok temu
rodzic
commit
144a817f4f
1 zmienionych plików z 3 dodań i 0 usunięć
  1. 3 0
      package/openssh/openssh.mk

+ 3 - 0
package/openssh/openssh.mk

@@ -16,6 +16,9 @@ OPENSSH_LICENSE_FILES = LICENCE
 # 0001-Improve-detection-of-fzero-call-used-regs-used.patch
 OPENSSH_AUTORECONF = YES
 
+# 0002-sshsigdie-async-signal-unsafe.patch
+OPENSSH_IGNORE_CVES += CVE-2024-6387
+
 OPENSSH_CONF_ENV = \
 	LD="$(TARGET_CC)" \
 	LDFLAGS="$(TARGET_CFLAGS)" \