[meta-oe][PATCH 1/6] grpc: set status for CVE-2023-33953 and CVE-2024-37168

Peter Marko <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Peter Marko <[email protected]>

CVE-2023-33953 is fixed since 1.56.2 per [1].
FKIE sets "defaultStatus": "unknown" so it needs to be set explicitly.

CVE-2024-37168 description in [2] says grpc-js.
Even if (like FKIE added) grpc core would be affected, it would be in
old versions (also listed in [2]).

[1] https://nvd.nist.gov/vuln/detail/CVE-2023-33953
[2] https://nvd.nist.gov/vuln/detail/CVE-2024-37168

Signed-off-by: Peter Marko <[email protected]>
---
 meta-oe/recipes-devtools/grpc/grpc_1.80.0.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta-oe/recipes-devtools/grpc/grpc_1.80.0.bb b/meta-oe/recipes-devtools/grpc/grpc_1.80.0.bb
index 14ead4ccf9..2213331a3e 100644
--- a/meta-oe/recipes-devtools/grpc/grpc_1.80.0.bb
+++ b/meta-oe/recipes-devtools/grpc/grpc_1.80.0.bb
@@ -66,3 +66,6 @@ FILES:${PN}-compiler += " \
     ${bindir} \
     ${libdir}/libgrpc_plugin_support${SOLIBS} \
     "
+
+CVE_STATUS[CVE-2023-33953] = "fixed-version: Fixed since 1.56.2"
+CVE_STATUS[CVE-2024-37168] = "cpe-incorrect: This CVE is for grps-js"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.