From ac5f12517e74b7eaceefd6d43d25b9612db17a02 Mon Sep 17 00:00:00 2001 From: Bruce Ashfield Date: Tue, 6 Feb 2024 15:53:34 -0500 Subject: linux-yocto/6.6: update CVE exclusions Data pulled from: https://github.com/nluedtke/linux_kernel_cves 1/1 [ Author: Nicholas Luedtke Email: nicholas.luedtke@uwalumni.com Subject: Update 3Feb24 Date: Sat, 3 Feb 2024 00:42:14 -0500 ] (From OE-Core rev: 20ceea5be17b64cbc95d36cc1afd5d41a2517500) Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie --- meta/recipes-kernel/linux/cve-exclusion_6.6.inc | 70 ++++++++++++++++++++++--- 1 file changed, 64 insertions(+), 6 deletions(-) (limited to 'meta/recipes-kernel/linux/cve-exclusion_6.6.inc') diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc index 9398434082..f3b3f32736 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc @@ -1,9 +1,9 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2024-01-25 01:32:27.591716+00:00 for version 6.6.13 +# Generated at 2024-02-04 13:08:50.287438+00:00 for version 6.6.15 python check_kernel_cve_status_version() { - this_version = "6.6.13" + this_version = "6.6.15" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -3668,6 +3668,10 @@ CVE_STATUS[CVE-2021-3348] = "fixed-version: Fixed from version 5.11rc6" CVE_STATUS[CVE-2021-33624] = "fixed-version: Fixed from version 5.13rc7" +CVE_STATUS[CVE-2021-33630] = "fixed-version: Fixed from version 5.4rc1" + +CVE_STATUS[CVE-2021-33631] = "fixed-version: Fixed from version 6.2rc1" + CVE_STATUS[CVE-2021-33655] = "fixed-version: Fixed from version 5.19rc6" CVE_STATUS[CVE-2021-33656] = "fixed-version: Fixed from version 5.12rc1" @@ -4420,7 +4424,7 @@ CVE_STATUS[CVE-2022-3636] = "fixed-version: Fixed from version 5.19rc1" CVE_STATUS[CVE-2022-3640] = "fixed-version: Fixed from version 6.1rc4" -# CVE-2022-36402 has no known resolution +CVE_STATUS[CVE-2022-36402] = "fixed-version: Fixed from version 6.5" # CVE-2022-3642 has no known resolution @@ -5100,8 +5104,12 @@ CVE_STATUS[CVE-2023-4622] = "fixed-version: Fixed from version 6.5rc1" CVE_STATUS[CVE-2023-4623] = "fixed-version: Fixed from version 6.6rc1" +CVE_STATUS[CVE-2023-46343] = "fixed-version: Fixed from version 6.6rc7" + CVE_STATUS[CVE-2023-46813] = "fixed-version: Fixed from version 6.6rc7" +CVE_STATUS[CVE-2023-46838] = "cpe-stable-backport: Backported in 6.6.14" + CVE_STATUS[CVE-2023-46862] = "fixed-version: Fixed from version 6.6" # CVE-2023-47233 has no known resolution @@ -5112,10 +5120,14 @@ CVE_STATUS[CVE-2023-4881] = "fixed-version: Fixed from version 6.6rc1" CVE_STATUS[CVE-2023-4921] = "fixed-version: Fixed from version 6.6rc1" -# CVE-2023-50431 has no known resolution +CVE_STATUS[CVE-2023-50431] = "cpe-stable-backport: Backported in 6.6.14" CVE_STATUS[CVE-2023-5090] = "fixed-version: Fixed from version 6.6rc7" +CVE_STATUS[CVE-2023-51042] = "fixed-version: Fixed from version 6.5rc1" + +CVE_STATUS[CVE-2023-51043] = "fixed-version: Fixed from version 6.5rc3" + CVE_STATUS[CVE-2023-5158] = "fixed-version: Fixed from version 6.6rc5" CVE_STATUS[CVE-2023-51779] = "cpe-stable-backport: Backported in 6.6.9" @@ -5130,6 +5142,8 @@ CVE_STATUS[CVE-2023-51782] = "cpe-stable-backport: Backported in 6.6.8" CVE_STATUS[CVE-2023-5197] = "fixed-version: Fixed from version 6.6rc3" +CVE_STATUS[CVE-2023-52340] = "fixed-version: Fixed from version 6.3rc1" + CVE_STATUS[CVE-2023-5345] = "fixed-version: Fixed from version 6.6rc4" CVE_STATUS[CVE-2023-5633] = "fixed-version: Fixed from version 6.6rc6" @@ -5148,6 +5162,8 @@ CVE_STATUS[CVE-2023-6121] = "cpe-stable-backport: Backported in 6.6.4" CVE_STATUS[CVE-2023-6176] = "fixed-version: Fixed from version 6.6rc2" +CVE_STATUS[CVE-2023-6200] = "cpe-stable-backport: Backported in 6.6.9" + # CVE-2023-6238 has no known resolution # CVE-2023-6270 has no known resolution @@ -5166,7 +5182,7 @@ CVE_STATUS[CVE-2023-6560] = "cpe-stable-backport: Backported in 6.6.5" CVE_STATUS[CVE-2023-6606] = "cpe-stable-backport: Backported in 6.6.9" -# CVE-2023-6610 needs backporting (fixed from 6.7rc7) +CVE_STATUS[CVE-2023-6610] = "cpe-stable-backport: Backported in 6.6.13" CVE_STATUS[CVE-2023-6622] = "cpe-stable-backport: Backported in 6.6.7" @@ -5174,6 +5190,8 @@ CVE_STATUS[CVE-2023-6679] = "fixed-version: only affects 6.7rc1 onwards" CVE_STATUS[CVE-2023-6817] = "cpe-stable-backport: Backported in 6.6.7" +CVE_STATUS[CVE-2023-6915] = "cpe-stable-backport: Backported in 6.6.13" + CVE_STATUS[CVE-2023-6931] = "cpe-stable-backport: Backported in 6.6.7" CVE_STATUS[CVE-2023-6932] = "cpe-stable-backport: Backported in 6.6.5" @@ -5188,5 +5206,45 @@ CVE_STATUS[CVE-2024-0340] = "fixed-version: Fixed from version 6.4rc6" CVE_STATUS[CVE-2024-0443] = "fixed-version: Fixed from version 6.4rc7" -# Skipping dd=CVE-2023-1476, no affected_versions +CVE_STATUS[CVE-2024-0562] = "fixed-version: Fixed from version 6.0rc3" + +# CVE-2024-0564 has no known resolution + +CVE_STATUS[CVE-2024-0565] = "cpe-stable-backport: Backported in 6.6.8" + +CVE_STATUS[CVE-2024-0582] = "cpe-stable-backport: Backported in 6.6.5" + +CVE_STATUS[CVE-2024-0584] = "cpe-stable-backport: Backported in 6.6.5" + +CVE_STATUS[CVE-2024-0607] = "cpe-stable-backport: Backported in 6.6.3" + +CVE_STATUS[CVE-2024-0639] = "fixed-version: Fixed from version 6.5rc1" + +CVE_STATUS[CVE-2024-0641] = "fixed-version: Fixed from version 6.6rc5" + +CVE_STATUS[CVE-2024-0646] = "cpe-stable-backport: Backported in 6.6.7" + +CVE_STATUS[CVE-2024-0775] = "fixed-version: Fixed from version 6.4rc2" + +# CVE-2024-0841 has no known resolution + +CVE_STATUS[CVE-2024-1085] = "cpe-stable-backport: Backported in 6.6.14" + +CVE_STATUS[CVE-2024-1086] = "cpe-stable-backport: Backported in 6.6.15" + +# CVE-2024-21803 has no known resolution + +# CVE-2024-22099 has no known resolution + +CVE_STATUS[CVE-2024-22705] = "cpe-stable-backport: Backported in 6.6.10" + +# CVE-2024-23307 has no known resolution + +# CVE-2024-23848 has no known resolution + +# CVE-2024-23849 has no known resolution + +# CVE-2024-23850 has no known resolution + +# CVE-2024-23851 has no known resolution -- cgit v1.2.3-54-g00ecf