Re: [OE-core] [RFC PATCH] cve-extra-exclusions: add more linux-yocto CVE ignores

2023-06-05 Thread Marta Rybczynska
On Mon, Jun 5, 2023 at 6:25 PM Ross Burton wrote: > From: Ross Burton > > These CVEs have all been fixed <6.1.30, which is the default linux-yocto > kernel version. > > Those are pretty new ones, should be all covered by the new CVE format. Is anyone already sending pull requests to include

Re: [OE-core] [RFC PATCH] cve-extra-exclusions: add more linux-yocto CVE ignores

2023-06-05 Thread Marta Rybczynska
On Mon, Jun 5, 2023 at 6:48 PM Richard Purdie < richard.pur...@linuxfoundation.org> wrote: > On Mon, 2023-06-05 at 16:31 +, Ross Burton wrote: > > I did some triage of the CVEs in this list but realised that this > > file is a bad location for them: whilst we don’t expect people to > > switch

Re: [OE-core] [RFC PATCH] cve-extra-exclusions: add more linux-yocto CVE ignores

2023-06-05 Thread Richard Purdie
On Mon, 2023-06-05 at 16:31 +, Ross Burton wrote: > I did some triage of the CVEs in this list but realised that this > file is a bad location for them: whilst we don’t expect people to > switch out most recipes, we do have to expect BSPs to switch the > kernel, so by accumulating a list of

Re: [OE-core] [RFC PATCH] cve-extra-exclusions: add more linux-yocto CVE ignores

2023-06-05 Thread Ross Burton
I did some triage of the CVEs in this list but realised that this file is a bad location for them: whilst we don’t expect people to switch out most recipes, we do have to expect BSPs to switch the kernel, so by accumulating a list of exclusions in this recipe that are based on the current

[OE-core] [RFC PATCH] cve-extra-exclusions: add more linux-yocto CVE ignores

2023-06-05 Thread Ross Burton
From: Ross Burton These CVEs have all been fixed <6.1.30, which is the default linux-yocto kernel version. Signed-off-by: Ross Burton --- .../distro/include/cve-extra-exclusions.inc | 41 +++ 1 file changed, 41 insertions(+) diff --git