From 072623d57811f042a330ff394b09198a66957330 Mon Sep 17 00:00:00 2001 From: Gyorgy Sarvari Date: Tue, 7 Oct 2025 16:51:45 +0200 Subject: [PATCH] luajit: ignore CVE-2024-2517{6,7,8} All 3 CVEs are fixed in the currently used revision. Fixes: CVE-2024-25176: https://github.com/LuaJIT/LuaJIT/commit/343ce0edaf3906a62022936175b2f5410024cbfc CVE-2024-25177: https://github.com/LuaJIT/LuaJIT/commit/85b4fed0b0353dd78c8c875c2f562d522a2b310f CVE-2024-25178: https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8 Signed-off-by: Gyorgy Sarvari Signed-off-by: Khem Raj --- meta-oe/recipes-devtools/luajit/luajit_git.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta-oe/recipes-devtools/luajit/luajit_git.bb b/meta-oe/recipes-devtools/luajit/luajit_git.bb index f4a1345ab2..9df5fca0e6 100644 --- a/meta-oe/recipes-devtools/luajit/luajit_git.bb +++ b/meta-oe/recipes-devtools/luajit/luajit_git.bb @@ -95,3 +95,7 @@ COMPATIBLE_HOST:powerpc64 = "null" COMPATIBLE_HOST:powerpc64le = "null" COMPATIBLE_HOST:riscv64 = "null" COMPATIBLE_HOST:riscv32 = "null" + +CVE_STATUS[CVE-2024-25176] = "fixed-version: The used revision contains the fix already." +CVE_STATUS[CVE-2024-25177] = "fixed-version: The used revision contains the fix already." +CVE_STATUS[CVE-2024-25178] = "fixed-version: The used revision contains the fix already."