On Wed Sep 9, 2026 at 9:29 AM CEST, Yoann Congal wrote: > From: Hetvi Thakar <[email protected]> > > Analysis: > - NVD identifies the vulnerable code as net/tcp.c when > CONFIG_PROT_TCP is enabled [1]. > - tools-only_defconfig disables networking, so this code is not built > into u-boot-tools [2]. > - Hence ignoring the CVE for this recipe. > > Reference: > [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007 > [2] > https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig > > Signed-off-by: Hetvi Thakar <[email protected]> > Signed-off-by: Yoann Congal <[email protected]> > --- > meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb > b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb > index 7eaf721ca83..0e57bb88849 100644 > --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb > +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb > @@ -1,2 +1,4 @@ > require u-boot-common.inc > require u-boot-tools.inc > + > +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig > disables networking; net/tcp.c is not compiled into u-boot-tools."
Hello, I just noticed that these CVEs are not visible from our tracking because the CPE is "u-boot" vs the PN "u-boot-tools". To fix this, I plan to add to this series the recent patch: [wrynose][PATCH] u-boot: share CVE_PRODUCT with u-boot-tools - Hiago De Franco https://lore.kernel.org/all/20260909-uboot-cve-product-wrynose-v1-1-072b994b4...@baylibre.com/ Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245483): https://lists.openembedded.org/g/openembedded-core/message/245483 Mute This Topic: https://lists.openembedded.org/mt/121158865/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
