Re: [OE-core] [yocto] linux-yocto CVEs in need of triage
Paul Barker <[email protected]> Fri, 24 Jul 2026 15:18:37 +0100
| Newsgroups | org.yoctoproject.lists.yocto,org.openembedded.lists.openembedded-core |
|---|---|
| Message-ID | <[email protected]> |
--=-FXjoV3aPt1CGHMOhc3d9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
On Thu, 2026-07-23 at 12:15 +0000, Navuduri, Venkata Adhitya via
lists.openembedded.org wrote:
> Hello,
>=20
> Regarding CVE-2023-3640 (x86 cpu_entry_area KASLR bypass, CVSS 7.8):
> The mainline fix is commit 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry=
area") by Peter Zijlstra, merged in v6.2-rc1 https://git.kernel.org/pub/sc=
m/linux/kernel/git/torvalds/linux.git/commit/?id=3D97e3d26b5e5f
>=20
>=20
> So, for Yocto releases shipping kernel >=3D6.2 version this fix is alread=
y present. This fix needs back porting to kernel <6.2
>=20
> For now, I can prepare a patch to add this CVE in the cve-exclusion.inc t=
o stop the CVE tool from reporting on this.
>=20
Hi Adhitya,
Please send a patch to update cve-exclusion.inc, in the commit message
please include any information or references you have to to identify
commit 97e3d26b5e5f as the fix.
Best regards,
--=20
Paul Barker
--=-FXjoV3aPt1CGHMOhc3d9
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE-----
iIcEABYKAC8WIQSzjPXf5Y1BDWhU2iCrY1Tsnbr0bgUCamN0PREccGF1bEBwYmFy
a2VyLmRldgAKCRCrY1Tsnbr0boK8AQCjGMUGE0trQbRtkzhSEs8/8s4/lKI5vroO
yX+yMw63wQEAk1PrI0oL3+e7WeA6cHl4E8zfYXiefHTMw/Efab3wiQs=
=vRQ4
-----END PGP SIGNATURE-----
--=-FXjoV3aPt1CGHMOhc3d9--