On Mon, 2023-02-27 at 12:00 +0100, Geoffrey GIRY wrote: > Multiple CVE are patched in kernel but appears as active because the NVD > database is not up to date. > > CVE are ignored if and only if all versions of kernel used by master are > patched. > > Also ignore CVEs with wrong CPE (applied to kernel but actually are for > another package) > > Signed-off-by: Geoffrey GIRY <[email protected]> > Reviewed-by: Yoann Congal <[email protected]> > --- > .../distro/include/cve-extra-exclusions.inc | 296 ++++++++++++++++++ > 1 file changed, 296 insertions(+)
FWIW, with this applied, the list reported by our tooling was reduced to: https://autobuilder.yocto.io/pub/non-release/patchmetrics/cve-status-master.txt Cheers, Richard
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#177887): https://lists.openembedded.org/g/openembedded-core/message/177887 Mute This Topic: https://lists.openembedded.org/mt/97263529/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
