From: Bruce Ashfield Date: Thu, 4 Dec 2025 04:30:20 +0000 (-0500) Subject: linux-yocto/6.17: update CVE exclusions (6.17.10) X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=751916970844bad0744f7ff70a63764ee1b7d000;p=thirdparty%2Fopenembedded%2Fopenembedded-core-contrib.git linux-yocto/6.17: update CVE exclusions (6.17.10) Data pulled from: https://github.com/CVEProject/cvelistV5 1/1 [ Author: cvelistV5 Github Action Email: github_action@example.com Subject: 4 changes (1 new | 3 updated): - 1 new CVEs: CVE-2025-65406 - 3 updated CVEs: CVE-2024-32384, CVE-2025-13829, CVE-2025-7195 Date: Mon, 1 Dec 2025 16:21:32 +0000 ] Signed-off-by: Bruce Ashfield Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie --- diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.17.inc b/meta/recipes-kernel/linux/cve-exclusion_6.17.inc index 10dc5930194..0dfce883031 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.17.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.17.inc @@ -1,11 +1,11 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2025-11-14 16:03:48.166784+00:00 for kernel version 6.17.8 -# From linux_kernel_cves cve_2025-11-14_1500Z-6-g27598c15037 +# Generated at 2025-12-01 16:25:15.356251+00:00 for kernel version 6.17.10 +# From linux_kernel_cves cve_2025-12-01_1600Z-1-g77d6c1b8483 python check_kernel_cve_status_version() { - this_version = "6.17.8" + this_version = "6.17.10" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -17656,7 +17656,7 @@ CVE_STATUS[CVE-2025-40088] = "cpe-stable-backport: Backported in 6.17.5" CVE_STATUS[CVE-2025-40089] = "cpe-stable-backport: Backported in 6.17.5" -CVE_STATUS[CVE-2025-40090] = "cpe-stable-backport: Backported in 6.17.5" +CVE_STATUS[CVE-2025-40090] = "fixed-version: Fixed from version 6.17.5" CVE_STATUS[CVE-2025-40091] = "cpe-stable-backport: Backported in 6.17.5" @@ -17762,8 +17762,6 @@ CVE_STATUS[CVE-2025-40142] = "cpe-stable-backport: Backported in 6.17.3" CVE_STATUS[CVE-2025-40143] = "cpe-stable-backport: Backported in 6.17.3" -CVE_STATUS[CVE-2025-40144] = "cpe-stable-backport: Backported in 6.17.3" - CVE_STATUS[CVE-2025-40145] = "cpe-stable-backport: Backported in 6.17.3" CVE_STATUS[CVE-2025-40146] = "cpe-stable-backport: Backported in 6.17.3" @@ -17892,6 +17890,16 @@ CVE_STATUS[CVE-2025-40207] = "cpe-stable-backport: Backported in 6.17.4" CVE_STATUS[CVE-2025-40208] = "cpe-stable-backport: Backported in 6.17.4" +CVE_STATUS[CVE-2025-40209] = "cpe-stable-backport: Backported in 6.17.8" + +CVE_STATUS[CVE-2025-40210] = "cpe-stable-backport: Backported in 6.17.8" + +CVE_STATUS[CVE-2025-40211] = "cpe-stable-backport: Backported in 6.17.8" + +CVE_STATUS[CVE-2025-40212] = "cpe-stable-backport: Backported in 6.17.9" + +CVE_STATUS[CVE-2025-40213] = "cpe-stable-backport: Backported in 6.17.8" + CVE_STATUS[CVE-2025-40300] = "fixed-version: Fixed from version 6.17" CVE_STATUS[CVE-2025-40325] = "fixed-version: Fixed from version 6.15"