]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
linux-yocto/6.17: update CVE exclusions (6.17.10)
authorBruce Ashfield <bruce.ashfield@gmail.com>
Thu, 4 Dec 2025 04:30:20 +0000 (23:30 -0500)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 8 Dec 2025 14:45:36 +0000 (14:45 +0000)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 4 changes (1 new | 3 updated): - 1 new CVEs: CVE-2025-65406 - 3 updated CVEs: CVE-2024-32384, CVE-2025-13829, CVE-2025-7195
        Date: Mon, 1 Dec 2025 16:21:32 +0000

    ]

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-kernel/linux/cve-exclusion_6.17.inc

index 10dc5930194782b57b9ce28571429c2c6cda749f..0dfce8830313901aa0a20b9227caa5e487d16247 100644 (file)
@@ -1,11 +1,11 @@
 
 # Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2025-11-14 16:03:48.166784+00:00 for kernel version 6.17.8
-# From linux_kernel_cves cve_2025-11-14_1500Z-6-g27598c15037
+# Generated at 2025-12-01 16:25:15.356251+00:00 for kernel version 6.17.10
+# From linux_kernel_cves cve_2025-12-01_1600Z-1-g77d6c1b8483
 
 
 python check_kernel_cve_status_version() {
-    this_version = "6.17.8"
+    this_version = "6.17.10"
     kernel_version = d.getVar("LINUX_VERSION")
     if kernel_version != this_version:
         bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -17656,7 +17656,7 @@ CVE_STATUS[CVE-2025-40088] = "cpe-stable-backport: Backported in 6.17.5"
 
 CVE_STATUS[CVE-2025-40089] = "cpe-stable-backport: Backported in 6.17.5"
 
-CVE_STATUS[CVE-2025-40090] = "cpe-stable-backport: Backported in 6.17.5"
+CVE_STATUS[CVE-2025-40090] = "fixed-version: Fixed from version 6.17.5"
 
 CVE_STATUS[CVE-2025-40091] = "cpe-stable-backport: Backported in 6.17.5"
 
@@ -17762,8 +17762,6 @@ CVE_STATUS[CVE-2025-40142] = "cpe-stable-backport: Backported in 6.17.3"
 
 CVE_STATUS[CVE-2025-40143] = "cpe-stable-backport: Backported in 6.17.3"
 
-CVE_STATUS[CVE-2025-40144] = "cpe-stable-backport: Backported in 6.17.3"
-
 CVE_STATUS[CVE-2025-40145] = "cpe-stable-backport: Backported in 6.17.3"
 
 CVE_STATUS[CVE-2025-40146] = "cpe-stable-backport: Backported in 6.17.3"
@@ -17892,6 +17890,16 @@ CVE_STATUS[CVE-2025-40207] = "cpe-stable-backport: Backported in 6.17.4"
 
 CVE_STATUS[CVE-2025-40208] = "cpe-stable-backport: Backported in 6.17.4"
 
+CVE_STATUS[CVE-2025-40209] = "cpe-stable-backport: Backported in 6.17.8"
+
+CVE_STATUS[CVE-2025-40210] = "cpe-stable-backport: Backported in 6.17.8"
+
+CVE_STATUS[CVE-2025-40211] = "cpe-stable-backport: Backported in 6.17.8"
+
+CVE_STATUS[CVE-2025-40212] = "cpe-stable-backport: Backported in 6.17.9"
+
+CVE_STATUS[CVE-2025-40213] = "cpe-stable-backport: Backported in 6.17.8"
+
 CVE_STATUS[CVE-2025-40300] = "fixed-version: Fixed from version 6.17"
 
 CVE_STATUS[CVE-2025-40325] = "fixed-version: Fixed from version 6.15"