> -----Original Message-----
> From: Richard Purdie <[email protected]>
> Sent: Thursday, January 6, 2022 21:31
> To: Liu, Yongxin <[email protected]>; openembedded-
> [email protected]
> Cc: MacLeod, Randy <[email protected]>; Mittal, Anuj
> <[email protected]>
> Subject: Re: [OE-core][PATCH] grub2: fix CVE-2021-3981
> 
> On Thu, 2022-01-06 at 02:38 +0000, Liu, Yongxin wrote:
> > Hi Richard,
> >
> > I saw this patch has been merged to master.
> >
> > Could you help to merge this patch and
> >
> > commit 0f528608eb48809955b2610ecc4bd689f1cf8899
> > Author: Alexander Kanavin <[email protected]>
> > Date:   2021-06-15 10:12
> >
> >     grub: upgrade 2.04+2.06~rc1 -> 2.06
> >
> >     Signed-off-by: Alexander Kanavin <[email protected]>
> >     Signed-off-by: Richard Purdie <[email protected]>
> >
> > to branch hardknott also? Or do I need to send those patches again for
> hardknott?
> 
> Anuj (cc'd) is the hardknott maintainer who would handle this, not me. We
> generally don't do version increments for stable releases unless there is a
> strong pressing need to do so, particularly on a branch which is nearly out
> of it's maintenance window.

Thanks Richard for your explanation. The upgrade patch is not a must-have.

@Mittal, Anuj

Could you help to cherry pick the following patch from master to branch 
hardknott?

commit bb554d14142f93c39fd1516a31757006531c348f
Author: Yongxin Liu <[email protected]>
Date:   2021-12-27 14:54

    grub2: fix CVE-2021-3981
    
    Signed-off-by: Yongxin Liu <[email protected]>
    Signed-off-by: Richard Purdie <[email protected]>


Thanks,
Yongxin

> 
> Cheers,
> 
> Richard

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#160231): 
https://lists.openembedded.org/g/openembedded-core/message/160231
Mute This Topic: https://lists.openembedded.org/mt/87974226/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to