Re: [yocto] linux-yocto CVEs in need of triage

Randy MacLeod <[email protected]> Wed, 22 Jul 2026 10:45:52 -0400
Newsgroups org.yoctoproject.lists.yocto,org.openembedded.lists.openembedded-core
Message-ID <[email protected]>
--------------TkhJXLZsyErZRrNyCvfKsh2G
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable
X-MIME-Autoconverted: from 8bit to quoted-printable by mx0a-0064b401.pphosted.com id 66MDhun11240730

On 2026-06-29 15:33, Paul Barker via lists.yoctoproject.org wrote:
> Hi all,
>
> We would appreciate help triaging the following CVEs filed against the
> Linux Kernel, which therefore affect linux-yocto.
>
> Each of these is missing an upstream fix version in the CVE data, so
> they show as unresolved in our CVE metrics. However, they may well be
> fixed already in the kernel versions that we ship. So we need some help
> to determine the appropriate upstream fix versions.
>
> For each CVE, at a minimum we need to know if they are resolved in the
> mainline kernel, and if so then which release they were resolved in. A
> pointer to the exact upstream commit resolving the issue would be
> preferred. This may involve a bit of investigation, so please share the
> information you find that proves that a CVE is resolved in a particular
> kernel version.
>
> Once you've investigated a particular CVE, if it is resolved upstream
> then please send a patch to update the linux-yocto cve-exclusion.inc
> file with the appropriate information. See recent commits to this file
> for examples of what we need, e.g:
>      https://git.openembedded.org/openembedded-core/commit/?id=3Dded28c=
a69b326e51ac5cf363f06c6f0931a9c1bd
>
> Once we've got patches merged into the master branch, we can look at
> backporting to wrynose & scarthgap as appropriate.
>
> The open linux-yocto CVEs lacking an upstream fix version and not
> currently tracked in cve-exclusion.inc are:
>
> - CVE-2019-14899
> - CVE-2021-3714
> - CVE-2021-3864
> - CVE-2022-0400
> - CVE-2022-1247
> - CVE-2022-4543
> - CVE-2023-3397
> - CVE-2023-3640
> - CVE-2023-4010
> - CVE-2023-6238
> - CVE-2023-6240

Venkata, who goes by Adhitya, has looked into all of these issues.

He's found one CVEs:
 =C2=A0 =C2=A0CVE-2023-3640 - x86 cpu_entry_area KASLR bypass.
that we can backport via linux-stable.

He has notes on the rest of the CVEs and will reply himself shortly.

../Randy


>
> Best regards,
>
>
> -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-
> Links: You receive all messages sent to this group.
> View/Reply Online (#66616):https://lists.yoctoproject.org/g/yocto/messa=
ge/66616
> Mute This Topic:https://lists.yoctoproject.org/mt/120036383/3616765
> Group Owner:[email protected]
> Unsubscribe:https://lists.yoctoproject.org/g/yocto/unsub [randy.macleod=
@windriver.com]
> -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-
>

--=20
# Randy MacLeod
# Wind River Linux

--------------TkhJXLZsyErZRrNyCvfKsh2G
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html><html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <head>

    
  </head>
  <body>
    <div class="moz-cite-prefix">On 2026-06-29 15:33, Paul Barker via
      lists.yoctoproject.org wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:[email protected]">
      <pre wrap="" class="moz-quote-pre">Hi all,

We would appreciate help triaging the following CVEs filed against the
Linux Kernel, which therefore affect linux-yocto.

Each of these is missing an upstream fix version in the CVE data, so
they show as unresolved in our CVE metrics. However, they may well be
fixed already in the kernel versions that we ship. So we need some help
to determine the appropriate upstream fix versions.

For each CVE, at a minimum we need to know if they are resolved in the
mainline kernel, and if so then which release they were resolved in. A
pointer to the exact upstream commit resolving the issue would be
preferred. This may involve a bit of investigation, so please share the
information you find that proves that a CVE is resolved in a particular
kernel version.

Once you've investigated a particular CVE, if it is resolved upstream
then please send a patch to update the linux-yocto cve-exclusion.inc
file with the appropriate information. See recent commits to this file
for examples of what we need, e.g:
    <a class="moz-txt-link-freetext" href="https://git.openembedded.org/openembedded-core/commit/?id=ded28ca69b326e51ac5cf363f06c6f0931a9c1bd">https://git.openembedded.org/openembedded-core/commit/?id=ded28ca69b326e51ac5cf363f06c6f0931a9c1bd</a>

Once we've got patches merged into the master branch, we can look at
backporting to wrynose &amp; scarthgap as appropriate.

The open linux-yocto CVEs lacking an upstream fix version and not
currently tracked in cve-exclusion.inc are:

- CVE-2019-14899
- CVE-2021-3714
- CVE-2021-3864
- CVE-2022-0400
- CVE-2022-1247
- CVE-2022-4543
- CVE-2023-3397
- CVE-2023-3640
- CVE-2023-4010
- CVE-2023-6238
- CVE-2023-6240</pre>
    </blockquote>
    <p>Venkata, who goes by Adhitya, has looked into all of these
      issues.</p>
    <p>He's found one CVEs:&nbsp;<br>
      &nbsp; &nbsp;CVE-2023-3640 -&nbsp;&nbsp;<span lang="EN-CA" style="font-family:&quot;Aptos&quot;,serif">x86 cpu_entry_area
        KASLR bypass.<br>
      </span>that we can backport via linux-stable.&nbsp;</p>
    <p>He has notes on the rest of the CVEs and will reply himself
      shortly.<br>
      <br>
    </p>
    <p>../Randy</p>
    <p><br>
    </p>
    <blockquote type="cite" cite="mid:[email protected]">
      <pre wrap="" class="moz-quote-pre">

Best regards,

</pre>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#66616): <a class="moz-txt-link-freetext" href="https://lists.yoctoproject.org/g/yocto/message/66616">https://lists.yoctoproject.org/g/yocto/message/66616</a>
Mute This Topic: <a class="moz-txt-link-freetext" href="https://lists.yoctoproject.org/mt/120036383/3616765">https://lists.yoctoproject.org/mt/120036383/3616765</a>
Group Owner: <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
Unsubscribe: <a class="moz-txt-link-freetext" href="https://lists.yoctoproject.org/g/yocto/unsub">https://lists.yoctoproject.org/g/yocto/unsub</a> [<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>]
-=-=-=-=-=-=-=-=-=-=-=-

</pre>
    </blockquote>
    <p><br>
    </p>
    <pre class="moz-signature" cols="72">-- 
# Randy MacLeod
# Wind River Linux</pre>
  </body>
</html>

--------------TkhJXLZsyErZRrNyCvfKsh2G--