From 381ff2bf69bb069cd6192594979e3131f090a9d6 Mon Sep 17 00:00:00 2001 From: Thomas Petazzoni Date: Sun, 18 May 2025 10:57:03 +0200 Subject: [PATCH] package/qt5/qt5base: drop stale ignore CVE entries, add CPE version The qt5base was reported to have 2 stale ignore CVE entries, one not stale. Turns out that because the version is a Git commit hash, the version comparaison did not make a lot of sense. This commit adds QT5BASE_CPE_ID_VERSION, assigned to the closest upstream version that we package (the Git repo we fetch is 5.15.14 plus a number of fixes). With this done, all 3 ignore CVE entries are stale because the vulnerabilities have been fixed prior to 5.15.14. In addition, setting QT5BASE_CPE_ID_VERSION allows to reduce the number of CVEs affecting qt5base from 20 to 8. Cc: Roy Kollen Svendsen Cc: Quentin Schulz Cc: Christian Hitz Signed-off-by: Thomas Petazzoni Signed-off-by: Julien Olivain --- package/qt5/qt5base/qt5base.mk | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/package/qt5/qt5base/qt5base.mk b/package/qt5/qt5base/qt5base.mk index add460c257..3ad2bdfc04 100644 --- a/package/qt5/qt5base/qt5base.mk +++ b/package/qt5/qt5base/qt5base.mk @@ -9,20 +9,13 @@ QT5BASE_SITE = $(QT5_SITE)/qtbase QT5BASE_SITE_METHOD = git QT5BASE_CPE_ID_VENDOR = qt QT5BASE_CPE_ID_PRODUCT = qt +# Closest upstream version +QT5BASE_CPE_ID_VERSION = 5.15.14 QT5BASE_DEPENDENCIES = host-pkgconf pcre2 zlib QT5BASE_INSTALL_STAGING = YES QT5BASE_SYNC_QT_HEADERS = YES -# From commits: -# 4ce7053a59 "Avoid processing-intensive painting of high number of tiny dashes" -# e7ea2ed27c "Improve fix for avoiding huge number of tiny dashes" -QT5BASE_IGNORE_CVES += CVE-2021-38593 -# From commit 2766b2cba6ca4b1c430304df5437e2a6c874b107 "QProcess/Unix: ensure we don't accidentally execute something from CWD" -QT5BASE_IGNORE_CVES += CVE-2022-25255 -# From commit e68ca8e51375d963b2391715f70b42707992dbd8 "Windows: use QSystemLibrary instead of LoadLibrary directly" -QT5BASE_IGNORE_CVES += CVE-2022-25634 - # A few comments: # * -no-pch to workaround the issue described at # http://comments.gmane.org/gmane.comp.lib.qt.devel/5933.