Skip to content

Commit

Permalink
fix(newlib): sbom: add CVE-2024-30949 to cve-exclude-list
Browse files Browse the repository at this point in the history
  • Loading branch information
Lapshin committed Oct 2, 2024
1 parent ffdf59a commit c4acf3f
Show file tree
Hide file tree
Showing 2 changed files with 12 additions and 0 deletions.
3 changes: 3 additions & 0 deletions components/newlib/sbom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,6 @@ cpe: cpe:2.3:a:newlib_project:newlib:{}:*:*:*:*:*:*:*
supplier: 'Organization: Espressif Systems (Shanghai) CO LTD'
originator: 'Organization: Red Hat Incorporated'
description: An open-source C standard library implementation with additional features and patches from Espressif.
cve-exclude-list:
- cve: CVE-2024-30949
reason: A vulnerability was discovered in the gettimeofday system call implementation within the RISC-V libgloss component of Newlib. ESP-IDF does not link against libgloss for RISC-V, hence the issue is not directly applicable. Still, the relevant fix has been patched through https://github.com/espressif/newlib-esp32/commit/047ba47013c2656a1e7838dc86cbc75aeeaa67a7
9 changes: 9 additions & 0 deletions docs/en/security/vulnerabilities.rst
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,15 @@ This page briefly lists all of the vulnerabilities that are discovered and fixed
CVE-2024
--------

CVE-2024-30949
~~~~~~~~~~~~~~

RISC-V gettimeofday system call vulnerability in Newlib's

* Impact: ESP-IDF does not use system call implementations from Newlib
* Resolution: NA


CVE-2024-28183
~~~~~~~~~~~~~~

Expand Down

0 comments on commit c4acf3f

Please sign in to comment.