]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
linux-yocto/6.17: update CVE exclusions (6.17.7)
authorBruce Ashfield <bruce.ashfield@gmail.com>
Thu, 4 Dec 2025 04:30:15 +0000 (23:30 -0500)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 8 Dec 2025 14:45:36 +0000 (14:45 +0000)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 5 changes (0 new | 5 updated): - 0 new CVEs: - 5 updated CVEs: CVE-2025-43384, CVE-2025-43408, CVE-2025-43435, CVE-2025-43474, CVE-2025-43478
        Date: Tue, 4 Nov 2025 13:42:11 +0000

    ]

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-kernel/linux/cve-exclusion_6.17.inc

index 126afb8ede6504f3823fee13574723f2a3b5311f..f60050d64707315c238c4a21779ed4df68ce3845 100644 (file)
@@ -1,11 +1,11 @@
 
 # Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2025-10-30 16:47:14.266821+00:00 for kernel version 6.17.6
-# From linux_kernel_cves cve_2025-10-30_1600Z-2-g07cefa3115c
+# Generated at 2025-11-04 13:42:54.522185+00:00 for kernel version 6.17.7
+# From linux_kernel_cves cve_2025-11-04_1300Z-2-geaff4df6d09
 
 
 python check_kernel_cve_status_version() {
-    this_version = "6.17.6"
+    this_version = "6.17.7"
     kernel_version = d.getVar("LINUX_VERSION")
     if kernel_version != this_version:
         bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -17644,7 +17644,7 @@ CVE_STATUS[CVE-2025-40082] = "cpe-stable-backport: Backported in 6.17.3"
 
 CVE_STATUS[CVE-2025-40083] = "fixed-version: Fixed from version 6.16"
 
-# CVE-2025-40084 has no known resolution
+CVE_STATUS[CVE-2025-40084] = "cpe-stable-backport: Backported in 6.17.6"
 
 CVE_STATUS[CVE-2025-40085] = "cpe-stable-backport: Backported in 6.17.5"
 
@@ -17688,6 +17688,10 @@ CVE_STATUS[CVE-2025-40104] = "cpe-stable-backport: Backported in 6.17.5"
 
 CVE_STATUS[CVE-2025-40105] = "cpe-stable-backport: Backported in 6.17.5"
 
+CVE_STATUS[CVE-2025-40106] = "cpe-stable-backport: Backported in 6.17.6"
+
+CVE_STATUS[CVE-2025-40107] = "fixed-version: Fixed from version 6.17"
+
 CVE_STATUS[CVE-2025-40114] = "fixed-version: Fixed from version 6.15"
 
 CVE_STATUS[CVE-2025-40300] = "fixed-version: Fixed from version 6.17"