From 7dd1d3973e850f403922b46ba3a82781ce2e8426 Mon Sep 17 00:00:00 2001 From: Steve Sakoman Date: Tue, 5 Dec 2023 04:46:44 -1000 Subject: cve-exclusion_5.4.inc: update for 5.4.262 (From OE-Core rev: fa5f8927e547da16588cf11dcf090f4ed53f3933) Signed-off-by: Steve Sakoman --- meta/recipes-kernel/linux/cve-exclusion_5.4.inc | 79 ++++++++++++++++++++----- 1 file changed, 64 insertions(+), 15 deletions(-) (limited to 'meta/recipes-kernel') diff --git a/meta/recipes-kernel/linux/cve-exclusion_5.4.inc b/meta/recipes-kernel/linux/cve-exclusion_5.4.inc index 4c17b701df..983424d427 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_5.4.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_5.4.inc @@ -1,9 +1,9 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2023-10-24 06:03:05.289306 for version 5.4.257 +# Generated at 2023-12-05 04:45:42.561193 for version 5.4.262 python check_kernel_cve_status_version() { - this_version = "5.4.257" + this_version = "5.4.262" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -5638,7 +5638,8 @@ CVE_CHECK_WHITELIST += "CVE-2021-43976" # cpe-stable-backport: Backported in 5.4.170 CVE_CHECK_WHITELIST += "CVE-2021-44733" -# CVE-2021-44879 needs backporting (fixed from 5.17rc1) +# cpe-stable-backport: Backported in 5.4.260 +CVE_CHECK_WHITELIST += "CVE-2021-44879" # cpe-stable-backport: Backported in 5.4.171 CVE_CHECK_WHITELIST += "CVE-2021-45095" @@ -6500,7 +6501,7 @@ CVE_CHECK_WHITELIST += "CVE-2022-43945" # CVE-2022-44033 needs backporting (fixed from 6.4rc1) -# CVE-2022-44034 has no known resolution +# CVE-2022-44034 needs backporting (fixed from 6.4rc1) # CVE-2022-4543 has no known resolution @@ -6670,7 +6671,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-1118" # fixed-version: only affects 5.15rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-1192" -# CVE-2023-1193 has no known resolution +# fixed-version: only affects 5.15rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-1193" # fixed-version: only affects 5.15rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-1194" @@ -6964,7 +6966,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-3106" # CVE-2023-31084 needs backporting (fixed from 6.4rc3) -# CVE-2023-31085 needs backporting (fixed from 5.4.258) +# cpe-stable-backport: Backported in 5.4.258 +CVE_CHECK_WHITELIST += "CVE-2023-31085" # cpe-stable-backport: Backported in 5.4.247 CVE_CHECK_WHITELIST += "CVE-2023-3111" @@ -7079,7 +7082,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-34256" # fixed-version: only affects 6.1 onwards CVE_CHECK_WHITELIST += "CVE-2023-34319" -# CVE-2023-34324 needs backporting (fixed from 5.4.258) +# fixed-version: only affects 5.10rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-34324" # fixed-version: only affects 5.15rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-3439" @@ -7104,7 +7108,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-35824" # fixed-version: only affects 5.18rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-35826" -# CVE-2023-35827 has no known resolution +# cpe-stable-backport: Backported in 5.4.259 +CVE_CHECK_WHITELIST += "CVE-2023-35827" # cpe-stable-backport: Backported in 5.4.243 CVE_CHECK_WHITELIST += "CVE-2023-35828" @@ -7182,7 +7187,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-3867" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-39189" -# CVE-2023-39191 needs backporting (fixed from 6.3rc1) +# fixed-version: only affects 5.19rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-39191" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-39192" @@ -7193,6 +7199,11 @@ CVE_CHECK_WHITELIST += "CVE-2023-39193" # cpe-stable-backport: Backported in 5.4.255 CVE_CHECK_WHITELIST += "CVE-2023-39194" +# cpe-stable-backport: Backported in 5.4.251 +CVE_CHECK_WHITELIST += "CVE-2023-39197" + +# CVE-2023-39198 needs backporting (fixed from 6.5rc7) + # fixed-version: only affects 5.6rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-4004" @@ -7204,7 +7215,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-4015" # cpe-stable-backport: Backported in 5.4.253 CVE_CHECK_WHITELIST += "CVE-2023-40283" -# CVE-2023-40791 needs backporting (fixed from 6.5rc6) +# fixed-version: only affects 6.3rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-40791" # cpe-stable-backport: Backported in 5.4.253 CVE_CHECK_WHITELIST += "CVE-2023-4128" @@ -7246,7 +7258,8 @@ CVE_CHECK_WHITELIST += "CVE-2023-42752" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-42753" -# CVE-2023-42754 needs backporting (fixed from 5.4.258) +# cpe-stable-backport: Backported in 5.4.258 +CVE_CHECK_WHITELIST += "CVE-2023-42754" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-42755" @@ -7281,14 +7294,16 @@ CVE_CHECK_WHITELIST += "CVE-2023-4569" # cpe-stable-backport: Backported in 5.4.235 CVE_CHECK_WHITELIST += "CVE-2023-45862" -# CVE-2023-45863 needs backporting (fixed from 6.3rc1) +# cpe-stable-backport: Backported in 5.4.260 +CVE_CHECK_WHITELIST += "CVE-2023-45863" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-45871" -# CVE-2023-45898 needs backporting (fixed from 6.6rc1) +# fixed-version: only affects 6.5rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-45898" -# CVE-2023-4610 has no known resolution +# CVE-2023-4610 needs backporting (fixed from 6.4) # fixed-version: only affects 6.4rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-4611" @@ -7298,6 +7313,13 @@ CVE_CHECK_WHITELIST += "CVE-2023-4611" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-4623" +# fixed-version: only affects 5.10rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-46813" + +# CVE-2023-46862 needs backporting (fixed from 6.6) + +# CVE-2023-47233 has no known resolution + # CVE-2023-4732 needs backporting (fixed from 5.14rc1) # CVE-2023-4881 needs backporting (fixed from 6.6rc1) @@ -7305,7 +7327,14 @@ CVE_CHECK_WHITELIST += "CVE-2023-4623" # cpe-stable-backport: Backported in 5.4.257 CVE_CHECK_WHITELIST += "CVE-2023-4921" -# CVE-2023-5158 has no known resolution +# fixed-version: only affects 6.0rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-5090" + +# fixed-version: only affects 5.13rc1 onwards +CVE_CHECK_WHITELIST += "CVE-2023-5158" + +# cpe-stable-backport: Backported in 5.4.260 +CVE_CHECK_WHITELIST += "CVE-2023-5178" # fixed-version: only affects 5.9rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-5197" @@ -7313,3 +7342,23 @@ CVE_CHECK_WHITELIST += "CVE-2023-5197" # fixed-version: only affects 6.1rc1 onwards CVE_CHECK_WHITELIST += "CVE-2023-5345" +# fixed-version: only affects 6.2 onwards +CVE_CHECK_WHITELIST += "CVE-2023-5633" + +# cpe-stable-backport: Backported in 5.4.259 +CVE_CHECK_WHITELIST += "CVE-2023-5717" + +# CVE-2023-5972 needs backporting (fixed from 6.6rc7) + +# CVE-2023-6039 needs backporting (fixed from 6.5rc5) + +# fixed-version: only affects 6.6rc3 onwards +CVE_CHECK_WHITELIST += "CVE-2023-6111" + +# CVE-2023-6121 needs backporting (fixed from 6.7rc3) + +# fixed-version: only affects 5.7rc7 onwards +CVE_CHECK_WHITELIST += "CVE-2023-6176" + +# CVE-2023-6238 has no known resolution + -- cgit v1.2.3-54-g00ecf