Since Buildroot commit [1] the CVEs are no longer matched to CPEs with versions using '-'. The CVE-2024-32928 introduced in [2] is then no longer matched to the libcurl package. For more information, see the explanation in commit [1]. [1]35f376d88esupport/scripts/cve.py: fix CPE matching [2]7e739d49b2package/libcurl: ignore CVE-2024-32928 Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> (cherry picked from commit b155395a52e50327db98e9bcfc62410e5eb109cd) Signed-off-by: Thomas Perale <thomas.perale@mind.be>