From 1dddfafa3218e786c07f1e8a4dab187514997465 Mon Sep 17 00:00:00 2001 From: Bruce Ashfield Date: Thu, 30 Oct 2025 13:12:22 -0400 Subject: [PATCH] linux-yocto/6.12: update CVE exclusions (6.12.53) Data pulled from: https://github.com/CVEProject/cvelistV5 1/1 [ Author: cvelistV5 Github Action Email: github_action@example.com Subject: 1 changes (0 new | 1 updated): - 0 new CVEs: - 1 updated CVEs: CVE-2025-9152 Date: Thu, 16 Oct 2025 13:08:42 +0000 ] Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie --- .../linux/cve-exclusion_6.12.inc | 74 ++++++++++++++++++- 1 file changed, 71 insertions(+), 3 deletions(-) diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.12.inc b/meta/recipes-kernel/linux/cve-exclusion_6.12.inc index f84d42cfe1..48a7d59689 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.12.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.12.inc @@ -1,11 +1,11 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2025-10-14 01:23:30.027767+00:00 for kernel version 6.12.52 -# From linux_kernel_cves 2025-10-14_baseline-1-gddc0a257837 +# Generated at 2025-10-16 13:21:03.993902+00:00 for kernel version 6.12.53 +# From linux_kernel_cves cve_2025-10-16_1200Z-2-g676292fb5cd python check_kernel_cve_status_version() { - this_version = "6.12.52" + this_version = "6.12.53" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -17274,8 +17274,76 @@ CVE_STATUS[CVE-2025-39964] = "cpe-stable-backport: Backported in 6.12.49" CVE_STATUS[CVE-2025-39965] = "cpe-stable-backport: Backported in 6.12.50" +CVE_STATUS[CVE-2025-39966] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39967] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39968] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39969] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39970] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39971] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39972] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39973] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39974] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2025-39975] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39976] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2025-39977] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39978] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39979] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2025-39980] = "cpe-stable-backport: Backported in 6.12.50" + +# CVE-2025-39981 needs backporting (fixed from 6.17) + +CVE_STATUS[CVE-2025-39982] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39983] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2025-39984] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39985] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39986] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39987] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39988] = "cpe-stable-backport: Backported in 6.12.50" + CVE_STATUS[CVE-2025-39989] = "cpe-stable-backport: Backported in 6.12.23" +CVE_STATUS[CVE-2025-39990] = "cpe-stable-backport: Backported in 6.12.50" + +CVE_STATUS[CVE-2025-39991] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39992] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39993] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39994] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39995] = "cpe-stable-backport: Backported in 6.12.52" + +CVE_STATUS[CVE-2025-39996] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39997] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2025-39998] = "cpe-stable-backport: Backported in 6.12.51" + +CVE_STATUS[CVE-2025-39999] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2025-40000] = "cpe-stable-backport: Backported in 6.12.52" + # CVE-2025-40014 needs backporting (fixed from 6.15) CVE_STATUS[CVE-2025-40114] = "cpe-stable-backport: Backported in 6.12.23" -- 2.47.3