On Wed Sep 9, 2026 at 9:29 AM CEST, Yoann Congal wrote:
> From: Hetvi Thakar <[email protected]>
>
> Analysis:
> - NVD identifies the vulnerable code as net/tcp.c when
>   CONFIG_PROT_TCP is enabled [1].
> - tools-only_defconfig disables networking, so this code is not built
>   into u-boot-tools [2].
> - Hence ignoring the CVE for this recipe.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
> [2] 
> https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> Signed-off-by: Yoann Congal <[email protected]>
> ---
>  meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb 
> b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> index 7eaf721ca83..0e57bb88849 100644
> --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> @@ -1,2 +1,4 @@
>  require u-boot-common.inc
>  require u-boot-tools.inc
> +
> +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig 
> disables networking; net/tcp.c is not compiled into u-boot-tools."

Hello,

I just noticed that these CVEs are not visible from our tracking because
the CPE is "u-boot" vs the PN "u-boot-tools".

To fix this, I plan to add to this series the recent patch:
[wrynose][PATCH] u-boot: share CVE_PRODUCT with u-boot-tools - Hiago De Franco
https://lore.kernel.org/all/20260909-uboot-cve-product-wrynose-v1-1-072b994b4...@baylibre.com/

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245483): 
https://lists.openembedded.org/g/openembedded-core/message/245483
Mute This Topic: https://lists.openembedded.org/mt/121158865/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to