mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-08 08:30:47 -09:00
package/unbound: mark CVE-2025-5994 as not applicable
Unbound is vulnerable to CVE-2025-5994: "Cache poisoning via the ECS-enabled
Rebirthday Attack" if built with --enable-subnet, which is not the case in
Buildroot, so mark it as not applicable.
https://nlnetlabs.nl/downloads/unbound/CVE-2025-5994.txt
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit c7721b0174)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
This commit is contained in:
committed by
Titouan Christophe
parent
575465c786
commit
18809021cc
@@ -23,6 +23,9 @@ UNBOUND_CONF_OPTS = \
|
||||
--with-libexpat=$(STAGING_DIR)/usr \
|
||||
--with-ssl=$(STAGING_DIR)/usr
|
||||
|
||||
# Only vulnerable if built with --enable-subnet
|
||||
UNBOUND_IGNORE_CVES += CVE-2025-5994
|
||||
|
||||
ifeq ($(BR2_TOOLCHAIN_HAS_THREADS_NPTL),y)
|
||||
UNBOUND_CONF_OPTS += --with-pthreads
|
||||
else
|
||||
|
||||
Reference in New Issue
Block a user