On Sun, 2026-08-23 at 23:21 -0500, Junjie Cao wrote: > This is v4 of the kernel CVE triage from Paul Barker's "linux-yocto > CVEs in need of triage" request, reworked according to his review of > v3 [1]. > > Changes since v3: > > - Seven entries adopt the comment and CVE_STATUS wordings suggested in > [1], including triage dates and distribution tracker links in the > .inc comments; the CVE-2022-1247 entry was approved as-is and is > unchanged. Commit message detail flagged as unnecessary or > time-consuming to validate is dropped. One deviation: the > CVE-2023-6238 status reads "Proposed fix was not merged" rather than > "withdrawn" - the fix was backed out by the nvme maintainer, not > withdrawn by its author - matching the comment above the entry. > > - CVE-2022-0400 stays out of this series as agreed. Red Hat PSIRT has > since answered the request for details (ticket PSIRTSUPT-22046) and > named the affected code; it is the issue fixed in v6.13 that > upstream tracks as CVE-2024-49568, with the details recorded on the > public bug [2]. A separate patch records the fixed-version status. > > Summary of the eight verdicts: > > fixed-version CVE-2022-1247 6.17, rose_neigh refcount conversion > unpatched CVE-2019-14899 weak host model, no upstream fix > CVE-2021-3714 inherent to KSM deduplication > CVE-2021-3864 proposed fixes not merged > CVE-2022-4543 EntryBleed, no fix proposed > CVE-2023-3397 JFS UAF, proposed fix withdrawn > CVE-2023-6238 NVMe passthrough, fix not merged > CVE-2023-6240 Marvin oracle, fixed only in RHEL > > AI assistance is disclosed with the AI-Generated trailer on each patch. > > Once these are settled I can prepare the wrynose and scarthgap > backports. > > [1] > https://lore.kernel.org/openembedded-core/[email protected]/ > [2] https://bugzilla.redhat.com/show_bug.cgi?id=2044575 > > v3: > https://lore.kernel.org/openembedded-core/[email protected]/ > v2: > https://lore.kernel.org/openembedded-core/[email protected]/ > > Junjie Cao (8): > cve-exclusions: set status for CVE-2019-14899 > cve-exclusions: set status for CVE-2021-3714 > cve-exclusions: set status for CVE-2021-3864 > cve-exclusions: set status for CVE-2022-1247 > cve-exclusions: set status for CVE-2022-4543 > cve-exclusions: set status for CVE-2023-3397 > cve-exclusions: set status for CVE-2023-6238 > cve-exclusions: set status for CVE-2023-6240
These all look good to me now, thanks for working through them! Best regards, -- Paul Barker
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244070): https://lists.openembedded.org/g/openembedded-core/message/244070 Mute This Topic: https://lists.openembedded.org/mt/120897554/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
