boot/grub2: ignore the last 3 remaining CVEs
authorThomas Petazzoni <thomas.petazzoni@bootlin.com>
Mon, 5 Apr 2021 18:52:30 +0000 (20:52 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 6 Apr 2021 07:36:48 +0000 (09:36 +0200)
commita490687571ef8e199a2480d0b24904ff62ed9a18
tree779fa88f9575389bde2e4db5669aafc8fac25dd3
parent8fd514caef4c9ec303dd72e4a8c11ec7a578328a
boot/grub2: ignore the last 3 remaining CVEs

An analysis of the last 3 remaining CVEs that are reported to affect
the grub2 package has allowed to ensure that we can safely ignore
them:

 * CVE-2020-14372 is already fixed by a patch we have in our patch
   stack for grub2

 * CVE-2019-14865 and CVE-2020-15705 are both distro-specific and do
   not affect grub2 upstream, nor grub2 with the stack of patches we
   have in Buildroot

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
boot/grub2/grub2.mk