From: Ross Burton Date: Mon, 5 Jun 2023 16:25:46 +0000 (+0100) Subject: cve-extra-exclusions: add more linux-yocto CVE ignores X-Git-Tag: uninative-4.1~529 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=73f03970f0aadfb053666a1e93f6f6d5b5156ca6;p=thirdparty%2Fopenembedded%2Fopenembedded-core.git cve-extra-exclusions: add more linux-yocto CVE ignores These CVEs have all been fixed <6.1.30, which is the default linux-yocto kernel version. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie --- diff --git a/meta/conf/distro/include/cve-extra-exclusions.inc b/meta/conf/distro/include/cve-extra-exclusions.inc index 0ca75bae3ef..ff5d381523c 100644 --- a/meta/conf/distro/include/cve-extra-exclusions.inc +++ b/meta/conf/distro/include/cve-extra-exclusions.inc @@ -555,5 +555,46 @@ CVE_CHECK_IGNORE += "CVE-2019-12067" # done about the bug, ignore from an OE perspective. CVE_CHECK_IGNORE += "CVE-2020-18974" +# https://www.linuxkernelcves.com/cves/CVE-2023-0459 +# Fixed in 6.1.14 onwards +CVE_CHECK_IGNORE += "CVE-2023-0459" +# https://www.linuxkernelcves.com/cves/CVE-2023-0615 +# Fixed in 6.1 onwards +CVE_CHECK_IGNORE += "CVE-2023-0615" +# https://www.linuxkernelcves.com/cves/CVE-2023-1380 +# Fixed in 6.1.27 +CVE_CHECK_IGNORE += "CVE-2023-1380" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1611 +# Fixed in 6.1.23 +CVE_CHECK_IGNORE += "CVE-2023-1611" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1855 +# Fixed in 6.1.21 +CVE_CHECK_IGNORE += "CVE-2023-1855" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1859 +# Fixed in 6.1.25 +CVE_CHECK_IGNORE += "CVE-2023-1859" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1989 +# Fixed in 6.1.22 +CVE_CHECK_IGNORE += "CVE-2023-1989" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1990 +# Fixed in 6.1.21 +CVE_CHECK_IGNORE += "CVE-2023-1990" + +# https://www.linuxkernelcves.com/cves/CVE-2023-1999 +# Fixed in 6.1.16 +CVE_CHECK_IGNORE += "CVE-2023-1998" + +# https://www.linuxkernelcves.com/cves/CVE-2023-2156 +# Fixed in 6.1.26 +CVE_CHECK_IGNORE += "CVE-2023-2156" + +# https://www.linuxkernelcves.com/cves/CVE-2023-2162 +# Fixed in 6.1.11 +CVE_CHECK_IGNORE += "CVE-2023-2162"