On Wed Sep 16, 2026 at 11:22 AM CEST, Bhavesh Rajesh Maheshwari wrote: > Hello Yoann, > Thanks for the review. > I agree that a downstream layer could enable Vulkan HEVC hardware > acceleration. However, by default this configuration is not enabled or > built by the ffmpeg recipe. > Since the affected Vulkan HEVC code is not built with the default > recipe configuration, the proposed fix would not be compiled or > exercised in our default build.
Yes, that's understood. > Could we instead handle this using a conditional CVE_STATUS, so that > the CVE is marked as not applicable when Vulkan HEVC hardware > acceleration is not enabled, while still allowing the CVE to be > reported when the relevant configuration is enabled by a downstream > layer? In this case, the patch is really simple. So it can be reviewed by reading it. And, while, yes it would not be compiled during our process. It would be on the code-path of downstream users that would activate vulkan. Then, in case of an issue, they can review/notify us/send fixes. Conditionnal CVE_STATUS are not a desirable outcome and more a "last-resort" kind of thing: Here, I don't think this is worth it. Let's backport the patch instead. Thanks! > > Thanks, > > Bhavesh Maheshwari > Engineer > +91 8827543501 > [email protected]<mailto:[email protected]> > [cid:d82e07d2-bdd2-4ad9-b5ee-cc155ce89991]<https://www.einfochips.com/> > ________________________________ > From: [email protected] > <[email protected]> on behalf of Yoann Congal via > lists.openembedded.org <[email protected]> > Sent: 15 September 2026 19:50 > To: Bhavesh Rajesh Maheshwari <[email protected]>; > [email protected] > <[email protected]> > Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set > CVE_STATUS for CVE-2026-64831 > > > CAUTION: This email originated from outside of the organization. This message > might not be safe, use caution in opening it. If in doubt, do not open the > attachment nor links in the message. > > > On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via > lists.openembedded.org wrote: >> From: Bhavesh R Maheshwari <[email protected]> >> >> Analysis: >> - CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1] >> - The ffmpeg recipe does not enable or build Vulkan HEVC hardware >> acceleration by default. >> - Hence CVE is not applicable. >> >> Reference: >> [1] >> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831> >> >> Signed-off-by: Bhavesh R Maheshwari <[email protected]> >> --- >> meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + >> 1 file changed, 1 insertion(+) >> >> diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb >> b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb >> index 8c1969369b..af05ab4af9 100644 >> --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb >> +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb >> @@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE >> are fixed since v8.0" >> CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0" >> CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since >> v8.0.3" >> CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since >> v8.0.2" >> +CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware >> acceleration is not enabled or built by this recipe." > > Hello, > > Nothing prevent a downstream layer from activating this feature. > > The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg > 8.0.x branch. Can you send a backport of the fix instead? > > I'll keep reviewing the rest of the series. > > [0]: > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2> > > Thanks! > -- > Yoann Congal > Smile ECS -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245949): https://lists.openembedded.org/g/openembedded-core/message/245949 Mute This Topic: https://lists.openembedded.org/mt/121180418/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
