Patchtest results for [OE-core][mickledore 2/5] grub2: fix CVE-2023-4693

2023-10-31 Thread Steve Sakoman
Thank you for your submission. Patchtest identified one or more issues with the patch. Please see the log below for more information: --- Testing patch /home/patchtest/share/mboxes/mickledore-2-5-grub2-fix-CVE-2023-4693.patch FAIL: test CVE presence in commit message: A CVE tag should be

[OE-core][mickledore 2/5] grub2: fix CVE-2023-4693

2023-10-31 Thread Steve Sakoman
From: Xiangyu Chen There an out-of-bounds read at fs/ntfs.c, a physically present attacker may leverage that by presenting a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack may allow sensitive data cached in memory or EFI variables values to be