[meta-oe][wrynose][PATCH] bit7z: set status for CVE-2026-45380 and CVE-2026-45384

Peter Marko <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Peter Marko <[email protected]>

These CVEs were fixed in 4.0.12 as seen in release notes [1].
Current CVE-CHECK still reports them as unfixed, correct it.

[1] https://github.com/rikyoz/bit7z/releases/tag/v4.0.12

Signed-off-by: Peter Marko <[email protected]>
---
 meta-oe/recipes-extended/7zip/bit7z_4.0.12.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta-oe/recipes-extended/7zip/bit7z_4.0.12.bb b/meta-oe/recipes-extended/7zip/bit7z_4.0.12.bb
index 300d9bc3cc..2e788b72a5 100644
--- a/meta-oe/recipes-extended/7zip/bit7z_4.0.12.bb
+++ b/meta-oe/recipes-extended/7zip/bit7z_4.0.12.bb
@@ -80,3 +80,6 @@ ALLOW_EMPTY:${PN} = "1"
 RDEPENDS:${PN}-ptest += "libstdc++ 7zip"
 # test data contains various file types with different architectures
 INSANE_SKIP:${PN}-ptest += "arch"
+
+CVE_STATUS[CVE-2026-45380] = "fixed-version: Fixed since 4.0.12"
+CVE_STATUS[CVE-2026-45384] = "fixed-version: Fixed since 4.0.12"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.