On Mon, 2023-02-27 at 12:00 +0100, Geoffrey GIRY wrote:
> Multiple CVE are patched in kernel but appears as active because the NVD
> database is not up to date.
> 
> CVE are ignored if and only if all versions of kernel used by master are 
> patched.
> 
> Also ignore CVEs with wrong CPE (applied to kernel but actually are for
>  another package)
> 
> Signed-off-by: Geoffrey GIRY <[email protected]>
> Reviewed-by: Yoann Congal <[email protected]>
> ---
>  .../distro/include/cve-extra-exclusions.inc   | 296 ++++++++++++++++++
>  1 file changed, 296 insertions(+)

FWIW, with this applied, the list reported by our tooling was reduced
to:

https://autobuilder.yocto.io/pub/non-release/patchmetrics/cve-status-master.txt

Cheers,

Richard
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#177887): 
https://lists.openembedded.org/g/openembedded-core/message/177887
Mute This Topic: https://lists.openembedded.org/mt/97263529/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to