summaryrefslogtreecommitdiffstats
path: root/meta/recipes-kernel
diff options
context:
space:
mode:
authorBruce Ashfield <bruce.ashfield@gmail.com>2024-03-11 12:40:22 -0400
committerSteve Sakoman <steve@sakoman.com>2024-03-13 07:36:51 -1000
commit893778ae4e5b9bf4f526cce1ad64ff2ec4532783 (patch)
tree5df6bfce7db6ea308c08e59bfbee631ff7f482a3 /meta/recipes-kernel
parent84eac79c8914fa80d68d0ccf0782390459f390b5 (diff)
downloadpoky-893778ae4e5b9bf4f526cce1ad64ff2ec4532783.tar.gz
linux-yocto/5.15: update CVE exclusions
Data pulled from: https://github.com/nluedtke/linux_kernel_cves 1/1 [ Author: Nicholas Luedtke Email: nicholas.luedtke@uwalumni.com Subject: Update 25Feb24 Date: Sun, 25 Feb 2024 07:03:08 -0500 ] (From OE-Core rev: 66c369b3cc5b975e7c774d5fa99181df8cdb827c) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-kernel')
-rw-r--r--meta/recipes-kernel/linux/cve-exclusion_5.15.inc197
1 files changed, 190 insertions, 7 deletions
diff --git a/meta/recipes-kernel/linux/cve-exclusion_5.15.inc b/meta/recipes-kernel/linux/cve-exclusion_5.15.inc
index d33f2b3c7f..2e30efe6be 100644
--- a/meta/recipes-kernel/linux/cve-exclusion_5.15.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion_5.15.inc
@@ -1,9 +1,9 @@
1 1
2# Auto-generated CVE metadata, DO NOT EDIT BY HAND. 2# Auto-generated CVE metadata, DO NOT EDIT BY HAND.
3# Generated at 2024-02-06 21:02:11.546853 for version 5.15.148 3# Generated at 2024-02-26 23:36:34.200936 for version 5.15.149
4 4
5python check_kernel_cve_status_version() { 5python check_kernel_cve_status_version() {
6 this_version = "5.15.148" 6 this_version = "5.15.149"
7 kernel_version = d.getVar("LINUX_VERSION") 7 kernel_version = d.getVar("LINUX_VERSION")
8 if kernel_version != this_version: 8 if kernel_version != this_version:
9 bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) 9 bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -7433,6 +7433,99 @@ CVE_CHECK_IGNORE += "CVE-2023-5197"
7433# cpe-stable-backport: Backported in 5.15.147 7433# cpe-stable-backport: Backported in 5.15.147
7434CVE_CHECK_IGNORE += "CVE-2023-52340" 7434CVE_CHECK_IGNORE += "CVE-2023-52340"
7435 7435
7436# cpe-stable-backport: Backported in 5.15.149
7437CVE_CHECK_IGNORE += "CVE-2023-52429"
7438
7439# fixed-version: only affects 6.5rc6 onwards
7440CVE_CHECK_IGNORE += "CVE-2023-52433"
7441
7442# CVE-2023-52434 needs backporting (fixed from 6.7rc6)
7443
7444# cpe-stable-backport: Backported in 5.15.149
7445CVE_CHECK_IGNORE += "CVE-2023-52435"
7446
7447# cpe-stable-backport: Backported in 5.15.148
7448CVE_CHECK_IGNORE += "CVE-2023-52436"
7449
7450# cpe-stable-backport: Backported in 5.15.148
7451CVE_CHECK_IGNORE += "CVE-2023-52438"
7452
7453# cpe-stable-backport: Backported in 5.15.148
7454CVE_CHECK_IGNORE += "CVE-2023-52439"
7455
7456# fixed-version: only affects 5.17rc4 onwards
7457CVE_CHECK_IGNORE += "CVE-2023-52440"
7458
7459# cpe-stable-backport: Backported in 5.15.145
7460CVE_CHECK_IGNORE += "CVE-2023-52441"
7461
7462# cpe-stable-backport: Backported in 5.15.145
7463CVE_CHECK_IGNORE += "CVE-2023-52442"
7464
7465# cpe-stable-backport: Backported in 5.15.148
7466CVE_CHECK_IGNORE += "CVE-2023-52443"
7467
7468# cpe-stable-backport: Backported in 5.15.148
7469CVE_CHECK_IGNORE += "CVE-2023-52444"
7470
7471# cpe-stable-backport: Backported in 5.15.148
7472CVE_CHECK_IGNORE += "CVE-2023-52445"
7473
7474# fixed-version: only affects 6.2rc1 onwards
7475CVE_CHECK_IGNORE += "CVE-2023-52446"
7476
7477# CVE-2023-52447 needs backporting (fixed from 6.8rc1)
7478
7479# cpe-stable-backport: Backported in 5.15.148
7480CVE_CHECK_IGNORE += "CVE-2023-52448"
7481
7482# cpe-stable-backport: Backported in 5.15.148
7483CVE_CHECK_IGNORE += "CVE-2023-52449"
7484
7485# fixed-version: only affects 6.2rc1 onwards
7486CVE_CHECK_IGNORE += "CVE-2023-52450"
7487
7488# cpe-stable-backport: Backported in 5.15.148
7489CVE_CHECK_IGNORE += "CVE-2023-52451"
7490
7491# CVE-2023-52452 needs backporting (fixed from 6.8rc1)
7492
7493# fixed-version: only affects 6.2rc1 onwards
7494CVE_CHECK_IGNORE += "CVE-2023-52453"
7495
7496# cpe-stable-backport: Backported in 5.15.148
7497CVE_CHECK_IGNORE += "CVE-2023-52454"
7498
7499# fixed-version: only affects 6.3rc1 onwards
7500CVE_CHECK_IGNORE += "CVE-2023-52455"
7501
7502# cpe-stable-backport: Backported in 5.15.148
7503CVE_CHECK_IGNORE += "CVE-2023-52456"
7504
7505# cpe-stable-backport: Backported in 5.15.148
7506CVE_CHECK_IGNORE += "CVE-2023-52457"
7507
7508# cpe-stable-backport: Backported in 5.15.148
7509CVE_CHECK_IGNORE += "CVE-2023-52458"
7510
7511# fixed-version: only affects 6.6rc1 onwards
7512CVE_CHECK_IGNORE += "CVE-2023-52459"
7513
7514# fixed-version: only affects 6.7rc1 onwards
7515CVE_CHECK_IGNORE += "CVE-2023-52460"
7516
7517# fixed-version: only affects 6.7rc1 onwards
7518CVE_CHECK_IGNORE += "CVE-2023-52461"
7519
7520# fixed-version: only affects 5.16rc1 onwards
7521CVE_CHECK_IGNORE += "CVE-2023-52462"
7522
7523# cpe-stable-backport: Backported in 5.15.148
7524CVE_CHECK_IGNORE += "CVE-2023-52463"
7525
7526# cpe-stable-backport: Backported in 5.15.148
7527CVE_CHECK_IGNORE += "CVE-2023-52464"
7528
7436# fixed-version: only affects 6.1rc1 onwards 7529# fixed-version: only affects 6.1rc1 onwards
7437CVE_CHECK_IGNORE += "CVE-2023-5345" 7530CVE_CHECK_IGNORE += "CVE-2023-5345"
7438 7531
@@ -7464,6 +7557,8 @@ CVE_CHECK_IGNORE += "CVE-2023-6200"
7464 7557
7465# CVE-2023-6238 has no known resolution 7558# CVE-2023-6238 has no known resolution
7466 7559
7560# CVE-2023-6240 has no known resolution
7561
7467# CVE-2023-6270 has no known resolution 7562# CVE-2023-6270 has no known resolution
7468 7563
7469# CVE-2023-6356 has no known resolution 7564# CVE-2023-6356 has no known resolution
@@ -7511,7 +7606,8 @@ CVE_CHECK_IGNORE += "CVE-2023-7192"
7511# fixed-version: only affects 6.5rc6 onwards 7606# fixed-version: only affects 6.5rc6 onwards
7512CVE_CHECK_IGNORE += "CVE-2024-0193" 7607CVE_CHECK_IGNORE += "CVE-2024-0193"
7513 7608
7514# CVE-2024-0340 needs backporting (fixed from 6.4rc6) 7609# cpe-stable-backport: Backported in 5.15.149
7610CVE_CHECK_IGNORE += "CVE-2024-0340"
7515 7611
7516# fixed-version: only affects 6.2rc1 onwards 7612# fixed-version: only affects 6.2rc1 onwards
7517CVE_CHECK_IGNORE += "CVE-2024-0443" 7613CVE_CHECK_IGNORE += "CVE-2024-0443"
@@ -7549,22 +7645,109 @@ CVE_CHECK_IGNORE += "CVE-2024-0775"
7549# cpe-stable-backport: Backported in 5.15.148 7645# cpe-stable-backport: Backported in 5.15.148
7550CVE_CHECK_IGNORE += "CVE-2024-1085" 7646CVE_CHECK_IGNORE += "CVE-2024-1085"
7551 7647
7552# CVE-2024-1086 needs backporting (fixed from 6.8rc2) 7648# cpe-stable-backport: Backported in 5.15.149
7649CVE_CHECK_IGNORE += "CVE-2024-1086"
7650
7651# cpe-stable-backport: Backported in 5.15.149
7652CVE_CHECK_IGNORE += "CVE-2024-1151"
7653
7654# CVE-2024-1312 needs backporting (fixed from 6.5rc4)
7553 7655
7554# CVE-2024-21803 has no known resolution 7656# CVE-2024-21803 has no known resolution
7555 7657
7556# CVE-2024-22099 has no known resolution 7658# CVE-2024-22099 has no known resolution
7557 7659
7660# CVE-2024-22386 has no known resolution
7661
7558# cpe-stable-backport: Backported in 5.15.146 7662# cpe-stable-backport: Backported in 5.15.146
7559CVE_CHECK_IGNORE += "CVE-2024-22705" 7663CVE_CHECK_IGNORE += "CVE-2024-22705"
7560 7664
7665# CVE-2024-23196 has no known resolution
7666
7561# CVE-2024-23307 has no known resolution 7667# CVE-2024-23307 has no known resolution
7562 7668
7563# CVE-2024-23848 has no known resolution 7669# CVE-2024-23848 has no known resolution
7564 7670
7565# CVE-2024-23849 has no known resolution 7671# cpe-stable-backport: Backported in 5.15.149
7672CVE_CHECK_IGNORE += "CVE-2024-23849"
7673
7674# cpe-stable-backport: Backported in 5.15.149
7675CVE_CHECK_IGNORE += "CVE-2024-23850"
7676
7677# cpe-stable-backport: Backported in 5.15.149
7678CVE_CHECK_IGNORE += "CVE-2024-23851"
7679
7680# CVE-2024-24855 needs backporting (fixed from 6.5rc2)
7681
7682# CVE-2024-24857 has no known resolution
7683
7684# CVE-2024-24858 has no known resolution
7685
7686# CVE-2024-24859 has no known resolution
7687
7688# cpe-stable-backport: Backported in 5.15.148
7689CVE_CHECK_IGNORE += "CVE-2024-24860"
7690
7691# CVE-2024-24861 has no known resolution
7692
7693# CVE-2024-24864 has no known resolution
7694
7695# CVE-2024-25739 has no known resolution
7696
7697# CVE-2024-25740 has no known resolution
7698
7699# CVE-2024-25741 has no known resolution
7700
7701# CVE-2024-25744 needs backporting (fixed from 6.7rc5)
7566 7702
7567# CVE-2024-23850 has no known resolution 7703# fixed-version: only affects 6.5rc4 onwards
7704CVE_CHECK_IGNORE += "CVE-2024-26581"
7568 7705
7569# CVE-2024-23851 has no known resolution 7706# fixed-version: only affects 6.0rc1 onwards
7707CVE_CHECK_IGNORE += "CVE-2024-26582"
7708
7709# CVE-2024-26583 needs backporting (fixed from 6.8rc5)
7710
7711# CVE-2024-26584 needs backporting (fixed from 6.8rc5)
7712
7713# CVE-2024-26585 needs backporting (fixed from 6.8rc5)
7714
7715# cpe-stable-backport: Backported in 5.15.148
7716CVE_CHECK_IGNORE += "CVE-2024-26586"
7717
7718# CVE-2024-26587 needs backporting (fixed from 6.8rc1)
7719
7720# CVE-2024-26588 needs backporting (fixed from 6.8rc1)
7721
7722# cpe-stable-backport: Backported in 5.15.148
7723CVE_CHECK_IGNORE += "CVE-2024-26589"
7724
7725# fixed-version: only affects 5.16rc1 onwards
7726CVE_CHECK_IGNORE += "CVE-2024-26590"
7727
7728# cpe-stable-backport: Backported in 5.15.148
7729CVE_CHECK_IGNORE += "CVE-2024-26591"
7730
7731# cpe-stable-backport: Backported in 5.15.149
7732CVE_CHECK_IGNORE += "CVE-2024-26592"
7733
7734# cpe-stable-backport: Backported in 5.15.149
7735CVE_CHECK_IGNORE += "CVE-2024-26593"
7736
7737# cpe-stable-backport: Backported in 5.15.149
7738CVE_CHECK_IGNORE += "CVE-2024-26594"
7739
7740# CVE-2024-26595 needs backporting (fixed from 6.8rc1)
7741
7742# fixed-version: only affects 6.1rc1 onwards
7743CVE_CHECK_IGNORE += "CVE-2024-26596"
7744
7745# cpe-stable-backport: Backported in 5.15.148
7746CVE_CHECK_IGNORE += "CVE-2024-26597"
7747
7748# cpe-stable-backport: Backported in 5.15.148
7749CVE_CHECK_IGNORE += "CVE-2024-26598"
7750
7751# fixed-version: only affects 5.17rc1 onwards
7752CVE_CHECK_IGNORE += "CVE-2024-26599"
7570 7753