[meta-webserver][PATCH] nginx: set status for CVE-2026-42055 and CVE-2026-48142

Peter Marko <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Peter Marko <[email protected]>

These CVEs were fixed in 1.30.3 but still showing in cve reports.
Fixed version information is e.g. in [1].

[1] https://nginx.org/en/security_advisories.html

Signed-off-by: Peter Marko <[email protected]>
---
 meta-webserver/recipes-httpd/nginx/nginx_1.30.4.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta-webserver/recipes-httpd/nginx/nginx_1.30.4.bb b/meta-webserver/recipes-httpd/nginx/nginx_1.30.4.bb
index bef176949f..7b24e05f0d 100644
--- a/meta-webserver/recipes-httpd/nginx/nginx_1.30.4.bb
+++ b/meta-webserver/recipes-httpd/nginx/nginx_1.30.4.bb
@@ -5,3 +5,6 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=79da1c70d587d3a199af9255ad393f99"
 SRC_URI[sha256sum] = "4261dc90e9e47c1c4041276e9aaa3d48ebe2e664f728e14fa95ae6c67d57a08b"
 
 inherit upstream-version-is-even
+
+CVE_STATUS[CVE-2026-42055] = "fixed-version: Fixed since 1.30.3"
+CVE_STATUS[CVE-2026-48142] = "fixed-version: Fixed since 1.30.3"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.