On Sun, 2026-08-23 at 23:21 -0500, Junjie Cao wrote:
> This is v4 of the kernel CVE triage from Paul Barker's "linux-yocto
> CVEs in need of triage" request, reworked according to his review of
> v3 [1].
> 
> Changes since v3:
> 
> - Seven entries adopt the comment and CVE_STATUS wordings suggested in
>   [1], including triage dates and distribution tracker links in the
>   .inc comments; the CVE-2022-1247 entry was approved as-is and is
>   unchanged. Commit message detail flagged as unnecessary or
>   time-consuming to validate is dropped. One deviation: the
>   CVE-2023-6238 status reads "Proposed fix was not merged" rather than
>   "withdrawn" - the fix was backed out by the nvme maintainer, not
>   withdrawn by its author - matching the comment above the entry.
> 
> - CVE-2022-0400 stays out of this series as agreed. Red Hat PSIRT has
>   since answered the request for details (ticket PSIRTSUPT-22046) and
>   named the affected code; it is the issue fixed in v6.13 that
>   upstream tracks as CVE-2024-49568, with the details recorded on the
>   public bug [2]. A separate patch records the fixed-version status.
> 
> Summary of the eight verdicts:
> 
>   fixed-version   CVE-2022-1247   6.17, rose_neigh refcount conversion
>   unpatched       CVE-2019-14899  weak host model, no upstream fix
>                   CVE-2021-3714   inherent to KSM deduplication
>                   CVE-2021-3864   proposed fixes not merged
>                   CVE-2022-4543   EntryBleed, no fix proposed
>                   CVE-2023-3397   JFS UAF, proposed fix withdrawn
>                   CVE-2023-6238   NVMe passthrough, fix not merged
>                   CVE-2023-6240   Marvin oracle, fixed only in RHEL
> 
> AI assistance is disclosed with the AI-Generated trailer on each patch.
> 
> Once these are settled I can prepare the wrynose and scarthgap
> backports.
> 
> [1] 
> https://lore.kernel.org/openembedded-core/[email protected]/
> [2] https://bugzilla.redhat.com/show_bug.cgi?id=2044575
> 
> v3: 
> https://lore.kernel.org/openembedded-core/[email protected]/
> v2: 
> https://lore.kernel.org/openembedded-core/[email protected]/
> 
> Junjie Cao (8):
>   cve-exclusions: set status for CVE-2019-14899
>   cve-exclusions: set status for CVE-2021-3714
>   cve-exclusions: set status for CVE-2021-3864
>   cve-exclusions: set status for CVE-2022-1247
>   cve-exclusions: set status for CVE-2022-4543
>   cve-exclusions: set status for CVE-2023-3397
>   cve-exclusions: set status for CVE-2023-6238
>   cve-exclusions: set status for CVE-2023-6240

These all look good to me now, thanks for working through them!

Best regards,

-- 
Paul Barker

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244070): 
https://lists.openembedded.org/g/openembedded-core/message/244070
Mute This Topic: https://lists.openembedded.org/mt/120897554/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to