CVE-2022-47696 and CVE-2023-25588 are representing similar kind
of vulnerability.
Reference:
https://ubuntu.com/security/CVE-2022-47696
https://sourceware.org/bugzilla/show_bug.cgi?id=29677
Signed-off-by: poojitha adireddy
---
meta/recipes-devtools/binutils/binutils/CVE-2023-25588.patch | 3 +++
Upstream Repository: https://sourceware.org/git/binutils-gdb.git
Bug Details: https://nvd.nist.gov/vuln/detail/CVE-2021-46174
Type: Security Fix
CVE: CVE-2021-46174
Score: 7.5
Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cad4d6b91e97
Signed-off-by: poojitha adireddy
---
...
Reason:
CVE-2021-3947, issue introduced in v6.0.0-rc0
Reference:
https://security-tracker.debian.org/tracker/CVE-2021-3947
Dunfell utilizes qemu v4.2.0, Hence whitelisting the CVE.
Signed-off-by: poojitha adireddy
---
meta/recipes-devtools/qemu/qemu.inc | 3 +++
1 file changed, 3 insertions(+)