On Mon, 2026-08-03 at 01:48 -0700, Junjie Cao wrote: > This is v2 of the triage of the CVEs from Paul Barker's "linux-yocto CVEs > in need of triage" request [1], reworked according to his review [2]: > one patch per CVE, primary sources cited in every commit message, and > the three CVEs which have no upstream fix recorded as "unpatched" rather > than left out.
Hi Junjie, We briefly discussed this patch series on the review call today. We're concerned about taking CVE status changes based on AI-Generated analysis from a new contributor, when there are multiple ways to interpret the various discussions online about these issues and it's not immediately clear what the "right" answer is. So we need to give these patches a thorough review. As we often point out in the weekly status emails, we have limited bandwidth to do this sort of in-depth review, so we may not be able to handle these patches quickly. Some quick thoughts below: > Summary of the ten verdicts: > > fixed-version CVE-2022-1247 v6.17, rose_neigh refcount conversion rose_connect() is now gone from mainline, so we can easily say this was fixed with the removal of net/rose. Pointing at an earlier fix requires more detailed review. > CVE-2023-4010 v6.18, imon URB resubmit loop This sounds like we're trying to infer the reporter's intent based on 'imon' being visible in a screenshot. We shouldn't be making guesses just because the initial report quality is poor. > disputed CVE-2022-0400 never substantiated, closed by three > vendors This is probably right, but needs another look. > upstream-wontfix CVE-2019-14899 weak host model, config-only mitigation We shouldn't use upstream-wontfix unless that is an actual upstream opinion. Ubuntu/RedHat are not upstream for the Linux kernel. > CVE-2021-3714 inherent to KSM deduplication As above. > CVE-2021-3864 two fix attempts, neither merged As above. Was the fix actually rejected by upstream or did it just go quiet? > CVE-2022-4543 KASLR not a boundary against local > attackers Sounds like there was some discussion with the kernel security team but probably not a clear wontfix decision. > unpatched CVE-2023-3397 JFS txEnd UAF, proposed fix withdrawn Unclear if there is still a real problem here in mainline. > CVE-2023-6238 NVMe fix applied then reverted Probably correct but not completely sure. > CVE-2023-6240 RSA timing oracle, fixed only in RHEL Also probably correct but not completely sure. The commit message has artifacts of the LLM being confused (Marvell/s390/unrelated commit reference), those can be dropped. Best regards, -- Paul Barker
signature.asc
Description: This is a digitally signed message part
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242935): https://lists.openembedded.org/g/openembedded-core/message/242935 Mute This Topic: https://lists.openembedded.org/mt/120574077/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
