]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
cve-extra-exclusions: Add kernel CVEs
authorRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 25 May 2022 16:49:12 +0000 (17:49 +0100)
committerSteve Sakoman <steve@sakoman.com>
Mon, 30 May 2022 15:29:15 +0000 (05:29 -1000)
commit726ce5bf1ea64d31f523ec5aff905407480c1095
tree78885ebd99055ee6c5772057375f9f1fb327180c
parent65498411d73e8008d5550c2d0a1148f990717587
cve-extra-exclusions: Add kernel CVEs

For OE-Core our policy is to stay as close to the kernel stable releases
as we can. This should ensure the bulk of the major kernel CVEs are fixed
and we don't dive into each individual issue as the stable maintainers are
much more able to do that.

Rather than just ignore all kernel CVEs which is what we have been doing,
list the ones we ignore on this basis here, allowing new issues to be
visible. If anyone wishes to clean up CPE entries with NIST for these, we'd
welcome than and then entries can likely be removed from here.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 319d465d44328b5f062d2da0526c0e8b189b4239)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/conf/distro/include/cve-extra-exclusions.inc