I did some triage of the CVEs in this list but realised that this file is a bad 
location for them: whilst we don’t expect people to switch out most recipes, we 
do have to expect BSPs to switch the kernel, so by accumulating a list of 
exclusions in this recipe that are based on the current version of linux-yocto 
we may negatively impact on people using a BSP which, for example, uses a 5.10 
kernel.

Should we move the kernel-specific exclusions, where they’re being done because 
they’re fixed in a release we ship, to the linux-yocto recipe?

Ross
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#182397): 
https://lists.openembedded.org/g/openembedded-core/message/182397
Mute This Topic: https://lists.openembedded.org/mt/99344319/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to