<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-el-common.git/recipes-devtools, branch kirkstone</title>
<subtitle>Commmon distro layer for Enea Linux</subtitle>
<id>https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=kirkstone</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=kirkstone'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/'/>
<updated>2022-08-02T07:44:43+00:00</updated>
<entry>
<title>Update layer for kirkstone build</title>
<updated>2022-08-02T07:44:43+00:00</updated>
<author>
<name>Bogdan Oprescu</name>
<email>bogdan.oprescu@enea.com</email>
</author>
<published>2022-06-17T15:44:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=ce0397ba44158ff139c3d1bb98a81c29ff07aa99'/>
<id>urn:sha1:ce0397ba44158ff139c3d1bb98a81c29ff07aa99</id>
<content type='text'>
Change-Id: Iaf8381bd4e43bdbcae44325627ed99ebec3f6a34
Signed-off-by: Bogdan Oprescu &lt;bogdan.oprescu@enea.com&gt;
</content>
</entry>
<entry>
<title>python: Remove CVE patches</title>
<updated>2019-08-09T11:21:57+00:00</updated>
<author>
<name>Adrian Mangeac</name>
<email>Adrian.Mangeac@enea.com</email>
</author>
<published>2019-08-09T11:21:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=89fcde81a924774214389e3e9e96eddc4af34339'/>
<id>urn:sha1:89fcde81a924774214389e3e9e96eddc4af34339</id>
<content type='text'>
The following patches were fixed in upstream:
  CVE-2018-1060
  CVE-2018-1061

Change-Id: I063270d94aa1214ded8c51842cfada3410bbe70c
Signed-off-by: Adrian Mangeac &lt;Adrian.Mangeac@enea.com&gt;
</content>
</entry>
<entry>
<title>python: fix for CVE-2018-1060 &amp; CVE-2018-1061</title>
<updated>2018-09-14T08:12:35+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2018-09-14T07:39:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=205f0cd0ded4b0c7b39202eac7b9d6c2470626b6'/>
<id>urn:sha1:205f0cd0ded4b0c7b39202eac7b9d6c2470626b6</id>
<content type='text'>
References:
https://bugs.python.org/issue32981
https://nvd.nist.gov/vuln/detail/CVE-2018-1060
https://nvd.nist.gov/vuln/detail/CVE-2018-1061

Patch is taken from https://github.com/python/cpython/tree/2.7

Change-Id: I3c561499076480c344fe7d34d2edea84615ac9fa
Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
</content>
</entry>
<entry>
<title>qemu: Drop CVE patches</title>
<updated>2018-03-01T09:38:09+00:00</updated>
<author>
<name>Martin Borg</name>
<email>martin.borg@enea.com</email>
</author>
<published>2018-03-01T09:34:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=2c0b43b3032f9a55edd395ae37f45fffce44fa9d'/>
<id>urn:sha1:2c0b43b3032f9a55edd395ae37f45fffce44fa9d</id>
<content type='text'>
The CVEs have been fixed in upstream poky/rocko.

Signed-off-by: Martin Borg &lt;martin.borg@enea.com&gt;
</content>
</entry>
<entry>
<title>Drop CVE patches that have been fixed in upstream poky/rocko</title>
<updated>2018-02-28T08:33:50+00:00</updated>
<author>
<name>Martin Borg</name>
<email>martin.borg@enea.com</email>
</author>
<published>2018-02-28T08:33:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=495b231e8e0da5046b6b1803d372fe33d0b14be9'/>
<id>urn:sha1:495b231e8e0da5046b6b1803d372fe33d0b14be9</id>
<content type='text'>
Signed-off-by: Martin Borg &lt;martin.borg@enea.com&gt;
</content>
</entry>
<entry>
<title>DPKG: Fix and test case for CVE-2017-8283</title>
<updated>2017-12-14T14:31:54+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-12-14T12:17:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=ef74e9d6103be37e4f4a43fb4c8b948789346b7c'/>
<id>urn:sha1:ef74e9d6103be37e4f4a43fb4c8b948789346b7c</id>
<content type='text'>
Directory Traversal Vulnerability

References:
https://nvd.nist.gov/vuln/detail/CVE-2017-8283
http://www.securityfocus.com/bid/98064/info

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
<entry>
<title>run-postinsts: don't call update-rc.d if systemd is present</title>
<updated>2017-12-06T10:43:12+00:00</updated>
<author>
<name>Gabriel Ionescu</name>
<email>gabriel.ionescu@enea.com</email>
</author>
<published>2017-12-05T14:08:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=6fe6de08fe746ae3df54eb3bb6eee35e95914b6d'/>
<id>urn:sha1:6fe6de08fe746ae3df54eb3bb6eee35e95914b6d</id>
<content type='text'>
This patch removes the call to update-rc.d in order to fix the console login
issue for the Cavium board.

Signed-off-by: Gabriel Ionescu &lt;gabriel.ionescu@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
<entry>
<title>run-postinsts: Disable dpkg --configure for debs to fix boot lockup</title>
<updated>2017-11-22T10:46:21+00:00</updated>
<author>
<name>Gabriel Ionescu</name>
<email>gabriel.ionescu@enea.com</email>
</author>
<published>2017-11-20T18:03:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=2c80876ac2a42928167ed5567dc803179485c815'/>
<id>urn:sha1:2c80876ac2a42928167ed5567dc803179485c815</id>
<content type='text'>
When a board boots for the first time, it executes run-postinsts.service and
dpkg-configure.service. Since both services run dpkg --configure, it sometimes
results in locking up the login service.

This patch disables the execution of dpkg --configure from run-postinsts by
removing the deb keyword from the list of scanned packet types.

Signed-off-by: Gabriel Ionescu &lt;gabriel.ionescu@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
<entry>
<title>qemu: CVE-2017-5931</title>
<updated>2017-09-18T11:54:31+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-09-14T06:16:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=4c6acb2de2b9612dfae273e63348c40921ebf235'/>
<id>urn:sha1:4c6acb2de2b9612dfae273e63348c40921ebf235</id>
<content type='text'>
Fixes integer overflow in in handling virtio-crypto requests

Reference:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5931

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Martin Borg &lt;martin.borg@enea.com&gt;
</content>
</entry>
<entry>
<title>qemu: CVE-2017-8309</title>
<updated>2017-08-29T11:32:58+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-08-29T08:29:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=7da6ebdca2d6b30dd6240db73b0c7605c310a4f1'/>
<id>urn:sha1:7da6ebdca2d6b30dd6240db73b0c7605c310a4f1</id>
<content type='text'>
Qemu built with the Audio subsystem support is vulnerable to
a host memory leakage issue. It could occur if a guest user
was to repeatedly start and stop audio capture.

A privileged user inside guest could use this flaw to exhaust host memory,
resulting in DoS.

Reference:
==========
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-8309
Upstream patch:
https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg05587.html

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
</feed>
