This is v4 of the kernel CVE triage from Paul Barker's "linux-yocto
CVEs in need of triage" request, reworked according to his review of
v3 [1].

Changes since v3:

- Seven entries adopt the comment and CVE_STATUS wordings suggested in
  [1], including triage dates and distribution tracker links in the
  .inc comments; the CVE-2022-1247 entry was approved as-is and is
  unchanged. Commit message detail flagged as unnecessary or
  time-consuming to validate is dropped. One deviation: the
  CVE-2023-6238 status reads "Proposed fix was not merged" rather than
  "withdrawn" - the fix was backed out by the nvme maintainer, not
  withdrawn by its author - matching the comment above the entry.

- CVE-2022-0400 stays out of this series as agreed. Red Hat PSIRT has
  since answered the request for details (ticket PSIRTSUPT-22046) and
  named the affected code; it is the issue fixed in v6.13 that
  upstream tracks as CVE-2024-49568, with the details recorded on the
  public bug [2]. A separate patch records the fixed-version status.

Summary of the eight verdicts:

  fixed-version   CVE-2022-1247   6.17, rose_neigh refcount conversion
  unpatched       CVE-2019-14899  weak host model, no upstream fix
                  CVE-2021-3714   inherent to KSM deduplication
                  CVE-2021-3864   proposed fixes not merged
                  CVE-2022-4543   EntryBleed, no fix proposed
                  CVE-2023-3397   JFS UAF, proposed fix withdrawn
                  CVE-2023-6238   NVMe passthrough, fix not merged
                  CVE-2023-6240   Marvin oracle, fixed only in RHEL

AI assistance is disclosed with the AI-Generated trailer on each patch.

Once these are settled I can prepare the wrynose and scarthgap
backports.

[1] 
https://lore.kernel.org/openembedded-core/[email protected]/
[2] https://bugzilla.redhat.com/show_bug.cgi?id=2044575

v3: 
https://lore.kernel.org/openembedded-core/[email protected]/
v2: 
https://lore.kernel.org/openembedded-core/[email protected]/

Junjie Cao (8):
  cve-exclusions: set status for CVE-2019-14899
  cve-exclusions: set status for CVE-2021-3714
  cve-exclusions: set status for CVE-2021-3864
  cve-exclusions: set status for CVE-2022-1247
  cve-exclusions: set status for CVE-2022-4543
  cve-exclusions: set status for CVE-2023-3397
  cve-exclusions: set status for CVE-2023-6238
  cve-exclusions: set status for CVE-2023-6240

 meta/recipes-kernel/linux/cve-exclusion.inc | 68 +++++++++++++++++++++
 1 file changed, 68 insertions(+)

-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244046): 
https://lists.openembedded.org/g/openembedded-core/message/244046
Mute This Topic: https://lists.openembedded.org/mt/120897554/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to