]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
cve-extra-exclusions: Add kernel CVEs
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 25 May 2022 16:49:12 +0000 (17:49 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 27 May 2022 22:47:20 +0000 (23:47 +0100)
commit319d465d44328b5f062d2da0526c0e8b189b4239
tree44d44b832439e95f3d873cd5f1abfbc18de02bfb
parent32ba67bc37b5ca73f7d29cb6c7de281ab8f824bd
cve-extra-exclusions: Add kernel CVEs

For OE-Core our policy is to stay as close to the kernel stable releases
as we can. This should ensure the bulk of the major kernel CVEs are fixed
and we don't dive into each individual issue as the stable maintainers are
much more able to do that.

Rather than just ignore all kernel CVEs which is what we have been doing,
list the ones we ignore on this basis here, allowing new issues to be
visible. If anyone wishes to clean up CPE entries with NIST for these, we'd
welcome than and then entries can likely be removed from here.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/conf/distro/include/cve-extra-exclusions.inc