]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
linux: review some historic CVE_STATUS
authorRoss Burton <ross.burton@arm.com>
Mon, 4 Sep 2023 21:33:22 +0000 (22:33 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 6 Sep 2023 16:52:37 +0000 (17:52 +0100)
Do manual review and disposition these CVEs as appropriate.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
meta/conf/distro/include/cve-extra-exclusions.inc
meta/recipes-kernel/linux/cve-exclusion.inc

index 51926f342a189f810730c2446c5836e1a78ab1dc..cfee028e5bab793644f4f88db982292f0163e001 100644 (file)
@@ -68,9 +68,7 @@ replacing bdb with supported and open source friendly alternatives. As a result
 CVE_STATUS_GROUPS += "CVE_STATUS_KERNEL_HISTORIC"
 
 CVE_STATUS_KERNEL_HISTORIC = "CVE-1999-0524 CVE-1999-0656 CVE-2006-2932 CVE-2007-2764 CVE-2007-4998 \ 
-                              CVE-2008-2544 CVE-2008-4609 CVE-2010-0298 CVE-2010-4563 CVE-2011-0640 \
-                              CVE-2014-2648 CVE-2016-0774 CVE-2016-3695 CVE-2016-3699 CVE-2017-1000377 \
-                              CVE-2017-6264"
+                              CVE-2008-2544 CVE-2008-4609 CVE-2010-0298 CVE-2010-4563 CVE-2011-0640"
 CVE_STATUS_KERNEL_HISTORIC[status] = "ignored"
 
 
index 42f1c195c9a938a11dc0219bda4596ec802b5404..28f9c8ff2b6a6a91b0d57806c8117e365911cc95 100644 (file)
@@ -1,3 +1,15 @@
+CVE_STATUS[CVE-2014-2648] = "cpe-incorrect: not Linux"
+
+CVE_STATUS[CVE-2016-0774] = "ignored: result of incomplete backport"
+
+CVE_STATUS[CVE-2016-3695] = "not-applicable-platform: specific to RHEL with securelevel patches"
+
+CVE_STATUS[CVE-2016-3699] = "not-applicable-platform: specific to RHEL with securelevel patches"
+
+CVE_STATUS[CVE-2017-6264] = "not-applicable-platform: Android specific"
+
+CVE_STATUS[CVE-2017-1000377] = "not-applicable-platform: GRSecurity specific"
+
 CVE_STATUS[CVE-2018-6559] = "not-applicable-platform: Issue only affects Ubuntu"
 
 CVE_STATUS[CVE-2020-11935] = "not-applicable-config: Issue only affects aufs, which is not in linux-yocto"