On Fri, Sep 11, 2026 at 06:19 PM, Yoann Congal wrote:

> 
> On Fri Sep 11, 2026 at 2:46 PM CEST, Yoann Congal wrote:
> 
>> On Wed Aug 26, 2026 at 10:12 AM CEST, Hetvi Thakar -X (hthakar - E
>> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>> 
>>> From: Hetvi Thakar <[email protected]>
>>> 
>>> Analysis:
>>> - CVE-2024-42040 affects the U-Boot DHCP client in net/bootp.c [1].
>>> - u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled
>>> [2].
>>> - Hence ignore this CVE for u-boot-tools; the exclusion is
>>> configuration-based.
>>> 
>>> Reference:
>>> [1] https://nvd.nist.gov/vuln/detail/CVE-2024-42040
>>> [2] 
>>> https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig
>>> 
>>> 
>>> Signed-off-by: Hetvi Thakar <[email protected]>
>>> ---
>>> meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 2 ++
>>> 1 file changed, 2 insertions(+)
>>> 
>>> diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
>>> b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
>>> index 4b6d89ed4e..b5711e1f97 100644
>>> --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
>>> +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb
>>> @@ -2,3 +2,5 @@ require u-boot-common.inc
>>> require u-boot-tools.inc
>>> 
>>> SRC_URI += "file://CVE-2026-46728.patch"
>>> +
>>> +CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in
>>> net/bootp.c is not built by tools-only_defconfig, which disables
>>> CONFIG_NET."
>> 
>> Hello,
>> 
>> I don't think we need this because, even if the code is not compiled, it
>> has been fixed earlier in scarthgap:
>> See 5c086db3f44 (u-boot: fix CVE-2024-42040, 2025-10-29)
>> Same reasonning apply to other patches in this series. Can you check if
>> we really need those?
>> 
>> Thanks!
> 
> In the meantime, I took 1/11 in my branch and held the rest (2-11/11).
> Be aware of this if you send a new series.

Hi Yoann,

Thanks for pointing this out.

The referenced fix was initially added in u-boot-common.inc, where
it applied to both u-boot and u-boot-tools. It was later moved to
u-boot.inc [1], so it now applies only to the u-boot recipe and
not to u-boot-tools.

u-boot-tools does not inherit u-boot.inc; it uses
u-boot-common.inc and u-boot-tools.inc. Therefore, the existing
CVE status is no longer applied to u-boot-tools.

The CVE is still reported against u-boot-tools because its
CVE_PRODUCT [2] maps to the U-Boot product. However, u-boot-tools
uses tools-only_defconfig, where CONFIG_NET is disabled, so the
vulnerable DHCP client code in net/bootp.c is not compiled.

Therefore, the proposed change only adds a recipe-specific CVE status
for u-boot-tools; it does not duplicate the source fix.

I also noticed Peter's proposed change [3], which moves these CVE
patches from u-boot.inc to u-boot-common.inc. Since
u-boot-common.inc is inherited by both u-boot and u-boot-tools,
this would cause all of those patches to be applied to u-boot-tools
as well.

I don't think this move is necessary, since not all of the affected
code is built by u-boot-tools. The actual source fixes should remain
with u-boot, where they are required. For u-boot-tools, the CVEs
whose vulnerable code is not compiled can instead be handled with the
appropriate CVE_STATUS entries.

References:
[1] 
https://git.openembedded.org/openembedded-core/commit/?h=scarthgap&id=f4ced8ff03147dd532a88cf3ce08d61fab057522
[2] 
https://git.openembedded.org/openembedded-core/commit/?h=scarthgap&id=9170fe393c379b9161a8843506420269f5b53e40
[3] 
https://patchwork.yoctoproject.org/project/oe-core/patch/[email protected]/

Regards,
Hetvi

> 
> 
> Thanks!
> --
> Yoann Congal
> Smile ECS
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246577): 
https://lists.openembedded.org/g/openembedded-core/message/246577
Mute This Topic: https://lists.openembedded.org/mt/120933878/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
      • ... Yoann Congal via lists.openembedded.org
        • ... Yoann Congal via lists.openembedded.org
          • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to