linux-yocto CVEs in need of triage
Paul Barker <[email protected]> Mon, 29 Jun 2026 20:33:10 +0100
| Newsgroups | org.yoctoproject.lists.yocto,org.openembedded.lists.openembedded-core |
|---|---|
| Message-ID | <[email protected]> |
--=-0XEesQ6whmklxQQjMezh
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hi all,
We would appreciate help triaging the following CVEs filed against the
Linux Kernel, which therefore affect linux-yocto.
Each of these is missing an upstream fix version in the CVE data, so
they show as unresolved in our CVE metrics. However, they may well be
fixed already in the kernel versions that we ship. So we need some help
to determine the appropriate upstream fix versions.
For each CVE, at a minimum we need to know if they are resolved in the
mainline kernel, and if so then which release they were resolved in. A
pointer to the exact upstream commit resolving the issue would be
preferred. This may involve a bit of investigation, so please share the
information you find that proves that a CVE is resolved in a particular
kernel version.
Once you've investigated a particular CVE, if it is resolved upstream
then please send a patch to update the linux-yocto cve-exclusion.inc
file with the appropriate information. See recent commits to this file
for examples of what we need, e.g:
https://git.openembedded.org/openembedded-core/commit/?id=3Dded28ca69b3=
26e51ac5cf363f06c6f0931a9c1bd
Once we've got patches merged into the master branch, we can look at
backporting to wrynose & scarthgap as appropriate.
The open linux-yocto CVEs lacking an upstream fix version and not
currently tracked in cve-exclusion.inc are:
- CVE-2019-14899
- CVE-2021-3714
- CVE-2021-3864
- CVE-2022-0400
- CVE-2022-1247
- CVE-2022-4543
- CVE-2023-3397
- CVE-2023-3640
- CVE-2023-4010
- CVE-2023-6238
- CVE-2023-6240
Best regards,
--=20
Paul Barker
--=-0XEesQ6whmklxQQjMezh
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE-----
iIcEABYKAC8WIQSzjPXf5Y1BDWhU2iCrY1Tsnbr0bgUCakLIdhEccGF1bEBwYmFy
a2VyLmRldgAKCRCrY1Tsnbr0bkNtAQD9hQerlmRpBQwUSQc6EMfranRD7L4DHbGX
yek6XnvHBAD/d8EmSza+X85R0Zc31rD4QVRD2ONw7Hs64qJxTtjNggI=
=wGkH
-----END PGP SIGNATURE-----
--=-0XEesQ6whmklxQQjMezh--