diff options
| author | Bruce Ashfield <bruce.ashfield@gmail.com> | 2024-03-11 12:40:22 -0400 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2024-03-13 07:36:51 -1000 |
| commit | 893778ae4e5b9bf4f526cce1ad64ff2ec4532783 (patch) | |
| tree | 5df6bfce7db6ea308c08e59bfbee631ff7f482a3 /meta/recipes-kernel | |
| parent | 84eac79c8914fa80d68d0ccf0782390459f390b5 (diff) | |
| download | poky-893778ae4e5b9bf4f526cce1ad64ff2ec4532783.tar.gz | |
linux-yocto/5.15: update CVE exclusions
Data pulled from: https://github.com/nluedtke/linux_kernel_cves
1/1 [
Author: Nicholas Luedtke
Email: nicholas.luedtke@uwalumni.com
Subject: Update 25Feb24
Date: Sun, 25 Feb 2024 07:03:08 -0500
]
(From OE-Core rev: 66c369b3cc5b975e7c774d5fa99181df8cdb827c)
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-kernel')
| -rw-r--r-- | meta/recipes-kernel/linux/cve-exclusion_5.15.inc | 197 |
1 files changed, 190 insertions, 7 deletions
diff --git a/meta/recipes-kernel/linux/cve-exclusion_5.15.inc b/meta/recipes-kernel/linux/cve-exclusion_5.15.inc index d33f2b3c7f..2e30efe6be 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_5.15.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_5.15.inc | |||
| @@ -1,9 +1,9 @@ | |||
| 1 | 1 | ||
| 2 | # Auto-generated CVE metadata, DO NOT EDIT BY HAND. | 2 | # Auto-generated CVE metadata, DO NOT EDIT BY HAND. |
| 3 | # Generated at 2024-02-06 21:02:11.546853 for version 5.15.148 | 3 | # Generated at 2024-02-26 23:36:34.200936 for version 5.15.149 |
| 4 | 4 | ||
| 5 | python check_kernel_cve_status_version() { | 5 | python check_kernel_cve_status_version() { |
| 6 | this_version = "5.15.148" | 6 | this_version = "5.15.149" |
| 7 | kernel_version = d.getVar("LINUX_VERSION") | 7 | kernel_version = d.getVar("LINUX_VERSION") |
| 8 | if kernel_version != this_version: | 8 | if kernel_version != this_version: |
| 9 | bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) | 9 | bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) |
| @@ -7433,6 +7433,99 @@ CVE_CHECK_IGNORE += "CVE-2023-5197" | |||
| 7433 | # cpe-stable-backport: Backported in 5.15.147 | 7433 | # cpe-stable-backport: Backported in 5.15.147 |
| 7434 | CVE_CHECK_IGNORE += "CVE-2023-52340" | 7434 | CVE_CHECK_IGNORE += "CVE-2023-52340" |
| 7435 | 7435 | ||
| 7436 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7437 | CVE_CHECK_IGNORE += "CVE-2023-52429" | ||
| 7438 | |||
| 7439 | # fixed-version: only affects 6.5rc6 onwards | ||
| 7440 | CVE_CHECK_IGNORE += "CVE-2023-52433" | ||
| 7441 | |||
| 7442 | # CVE-2023-52434 needs backporting (fixed from 6.7rc6) | ||
| 7443 | |||
| 7444 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7445 | CVE_CHECK_IGNORE += "CVE-2023-52435" | ||
| 7446 | |||
| 7447 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7448 | CVE_CHECK_IGNORE += "CVE-2023-52436" | ||
| 7449 | |||
| 7450 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7451 | CVE_CHECK_IGNORE += "CVE-2023-52438" | ||
| 7452 | |||
| 7453 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7454 | CVE_CHECK_IGNORE += "CVE-2023-52439" | ||
| 7455 | |||
| 7456 | # fixed-version: only affects 5.17rc4 onwards | ||
| 7457 | CVE_CHECK_IGNORE += "CVE-2023-52440" | ||
| 7458 | |||
| 7459 | # cpe-stable-backport: Backported in 5.15.145 | ||
| 7460 | CVE_CHECK_IGNORE += "CVE-2023-52441" | ||
| 7461 | |||
| 7462 | # cpe-stable-backport: Backported in 5.15.145 | ||
| 7463 | CVE_CHECK_IGNORE += "CVE-2023-52442" | ||
| 7464 | |||
| 7465 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7466 | CVE_CHECK_IGNORE += "CVE-2023-52443" | ||
| 7467 | |||
| 7468 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7469 | CVE_CHECK_IGNORE += "CVE-2023-52444" | ||
| 7470 | |||
| 7471 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7472 | CVE_CHECK_IGNORE += "CVE-2023-52445" | ||
| 7473 | |||
| 7474 | # fixed-version: only affects 6.2rc1 onwards | ||
| 7475 | CVE_CHECK_IGNORE += "CVE-2023-52446" | ||
| 7476 | |||
| 7477 | # CVE-2023-52447 needs backporting (fixed from 6.8rc1) | ||
| 7478 | |||
| 7479 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7480 | CVE_CHECK_IGNORE += "CVE-2023-52448" | ||
| 7481 | |||
| 7482 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7483 | CVE_CHECK_IGNORE += "CVE-2023-52449" | ||
| 7484 | |||
| 7485 | # fixed-version: only affects 6.2rc1 onwards | ||
| 7486 | CVE_CHECK_IGNORE += "CVE-2023-52450" | ||
| 7487 | |||
| 7488 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7489 | CVE_CHECK_IGNORE += "CVE-2023-52451" | ||
| 7490 | |||
| 7491 | # CVE-2023-52452 needs backporting (fixed from 6.8rc1) | ||
| 7492 | |||
| 7493 | # fixed-version: only affects 6.2rc1 onwards | ||
| 7494 | CVE_CHECK_IGNORE += "CVE-2023-52453" | ||
| 7495 | |||
| 7496 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7497 | CVE_CHECK_IGNORE += "CVE-2023-52454" | ||
| 7498 | |||
| 7499 | # fixed-version: only affects 6.3rc1 onwards | ||
| 7500 | CVE_CHECK_IGNORE += "CVE-2023-52455" | ||
| 7501 | |||
| 7502 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7503 | CVE_CHECK_IGNORE += "CVE-2023-52456" | ||
| 7504 | |||
| 7505 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7506 | CVE_CHECK_IGNORE += "CVE-2023-52457" | ||
| 7507 | |||
| 7508 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7509 | CVE_CHECK_IGNORE += "CVE-2023-52458" | ||
| 7510 | |||
| 7511 | # fixed-version: only affects 6.6rc1 onwards | ||
| 7512 | CVE_CHECK_IGNORE += "CVE-2023-52459" | ||
| 7513 | |||
| 7514 | # fixed-version: only affects 6.7rc1 onwards | ||
| 7515 | CVE_CHECK_IGNORE += "CVE-2023-52460" | ||
| 7516 | |||
| 7517 | # fixed-version: only affects 6.7rc1 onwards | ||
| 7518 | CVE_CHECK_IGNORE += "CVE-2023-52461" | ||
| 7519 | |||
| 7520 | # fixed-version: only affects 5.16rc1 onwards | ||
| 7521 | CVE_CHECK_IGNORE += "CVE-2023-52462" | ||
| 7522 | |||
| 7523 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7524 | CVE_CHECK_IGNORE += "CVE-2023-52463" | ||
| 7525 | |||
| 7526 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7527 | CVE_CHECK_IGNORE += "CVE-2023-52464" | ||
| 7528 | |||
| 7436 | # fixed-version: only affects 6.1rc1 onwards | 7529 | # fixed-version: only affects 6.1rc1 onwards |
| 7437 | CVE_CHECK_IGNORE += "CVE-2023-5345" | 7530 | CVE_CHECK_IGNORE += "CVE-2023-5345" |
| 7438 | 7531 | ||
| @@ -7464,6 +7557,8 @@ CVE_CHECK_IGNORE += "CVE-2023-6200" | |||
| 7464 | 7557 | ||
| 7465 | # CVE-2023-6238 has no known resolution | 7558 | # CVE-2023-6238 has no known resolution |
| 7466 | 7559 | ||
| 7560 | # CVE-2023-6240 has no known resolution | ||
| 7561 | |||
| 7467 | # CVE-2023-6270 has no known resolution | 7562 | # CVE-2023-6270 has no known resolution |
| 7468 | 7563 | ||
| 7469 | # CVE-2023-6356 has no known resolution | 7564 | # CVE-2023-6356 has no known resolution |
| @@ -7511,7 +7606,8 @@ CVE_CHECK_IGNORE += "CVE-2023-7192" | |||
| 7511 | # fixed-version: only affects 6.5rc6 onwards | 7606 | # fixed-version: only affects 6.5rc6 onwards |
| 7512 | CVE_CHECK_IGNORE += "CVE-2024-0193" | 7607 | CVE_CHECK_IGNORE += "CVE-2024-0193" |
| 7513 | 7608 | ||
| 7514 | # CVE-2024-0340 needs backporting (fixed from 6.4rc6) | 7609 | # cpe-stable-backport: Backported in 5.15.149 |
| 7610 | CVE_CHECK_IGNORE += "CVE-2024-0340" | ||
| 7515 | 7611 | ||
| 7516 | # fixed-version: only affects 6.2rc1 onwards | 7612 | # fixed-version: only affects 6.2rc1 onwards |
| 7517 | CVE_CHECK_IGNORE += "CVE-2024-0443" | 7613 | CVE_CHECK_IGNORE += "CVE-2024-0443" |
| @@ -7549,22 +7645,109 @@ CVE_CHECK_IGNORE += "CVE-2024-0775" | |||
| 7549 | # cpe-stable-backport: Backported in 5.15.148 | 7645 | # cpe-stable-backport: Backported in 5.15.148 |
| 7550 | CVE_CHECK_IGNORE += "CVE-2024-1085" | 7646 | CVE_CHECK_IGNORE += "CVE-2024-1085" |
| 7551 | 7647 | ||
| 7552 | # CVE-2024-1086 needs backporting (fixed from 6.8rc2) | 7648 | # cpe-stable-backport: Backported in 5.15.149 |
| 7649 | CVE_CHECK_IGNORE += "CVE-2024-1086" | ||
| 7650 | |||
| 7651 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7652 | CVE_CHECK_IGNORE += "CVE-2024-1151" | ||
| 7653 | |||
| 7654 | # CVE-2024-1312 needs backporting (fixed from 6.5rc4) | ||
| 7553 | 7655 | ||
| 7554 | # CVE-2024-21803 has no known resolution | 7656 | # CVE-2024-21803 has no known resolution |
| 7555 | 7657 | ||
| 7556 | # CVE-2024-22099 has no known resolution | 7658 | # CVE-2024-22099 has no known resolution |
| 7557 | 7659 | ||
| 7660 | # CVE-2024-22386 has no known resolution | ||
| 7661 | |||
| 7558 | # cpe-stable-backport: Backported in 5.15.146 | 7662 | # cpe-stable-backport: Backported in 5.15.146 |
| 7559 | CVE_CHECK_IGNORE += "CVE-2024-22705" | 7663 | CVE_CHECK_IGNORE += "CVE-2024-22705" |
| 7560 | 7664 | ||
| 7665 | # CVE-2024-23196 has no known resolution | ||
| 7666 | |||
| 7561 | # CVE-2024-23307 has no known resolution | 7667 | # CVE-2024-23307 has no known resolution |
| 7562 | 7668 | ||
| 7563 | # CVE-2024-23848 has no known resolution | 7669 | # CVE-2024-23848 has no known resolution |
| 7564 | 7670 | ||
| 7565 | # CVE-2024-23849 has no known resolution | 7671 | # cpe-stable-backport: Backported in 5.15.149 |
| 7672 | CVE_CHECK_IGNORE += "CVE-2024-23849" | ||
| 7673 | |||
| 7674 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7675 | CVE_CHECK_IGNORE += "CVE-2024-23850" | ||
| 7676 | |||
| 7677 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7678 | CVE_CHECK_IGNORE += "CVE-2024-23851" | ||
| 7679 | |||
| 7680 | # CVE-2024-24855 needs backporting (fixed from 6.5rc2) | ||
| 7681 | |||
| 7682 | # CVE-2024-24857 has no known resolution | ||
| 7683 | |||
| 7684 | # CVE-2024-24858 has no known resolution | ||
| 7685 | |||
| 7686 | # CVE-2024-24859 has no known resolution | ||
| 7687 | |||
| 7688 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7689 | CVE_CHECK_IGNORE += "CVE-2024-24860" | ||
| 7690 | |||
| 7691 | # CVE-2024-24861 has no known resolution | ||
| 7692 | |||
| 7693 | # CVE-2024-24864 has no known resolution | ||
| 7694 | |||
| 7695 | # CVE-2024-25739 has no known resolution | ||
| 7696 | |||
| 7697 | # CVE-2024-25740 has no known resolution | ||
| 7698 | |||
| 7699 | # CVE-2024-25741 has no known resolution | ||
| 7700 | |||
| 7701 | # CVE-2024-25744 needs backporting (fixed from 6.7rc5) | ||
| 7566 | 7702 | ||
| 7567 | # CVE-2024-23850 has no known resolution | 7703 | # fixed-version: only affects 6.5rc4 onwards |
| 7704 | CVE_CHECK_IGNORE += "CVE-2024-26581" | ||
| 7568 | 7705 | ||
| 7569 | # CVE-2024-23851 has no known resolution | 7706 | # fixed-version: only affects 6.0rc1 onwards |
| 7707 | CVE_CHECK_IGNORE += "CVE-2024-26582" | ||
| 7708 | |||
| 7709 | # CVE-2024-26583 needs backporting (fixed from 6.8rc5) | ||
| 7710 | |||
| 7711 | # CVE-2024-26584 needs backporting (fixed from 6.8rc5) | ||
| 7712 | |||
| 7713 | # CVE-2024-26585 needs backporting (fixed from 6.8rc5) | ||
| 7714 | |||
| 7715 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7716 | CVE_CHECK_IGNORE += "CVE-2024-26586" | ||
| 7717 | |||
| 7718 | # CVE-2024-26587 needs backporting (fixed from 6.8rc1) | ||
| 7719 | |||
| 7720 | # CVE-2024-26588 needs backporting (fixed from 6.8rc1) | ||
| 7721 | |||
| 7722 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7723 | CVE_CHECK_IGNORE += "CVE-2024-26589" | ||
| 7724 | |||
| 7725 | # fixed-version: only affects 5.16rc1 onwards | ||
| 7726 | CVE_CHECK_IGNORE += "CVE-2024-26590" | ||
| 7727 | |||
| 7728 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7729 | CVE_CHECK_IGNORE += "CVE-2024-26591" | ||
| 7730 | |||
| 7731 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7732 | CVE_CHECK_IGNORE += "CVE-2024-26592" | ||
| 7733 | |||
| 7734 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7735 | CVE_CHECK_IGNORE += "CVE-2024-26593" | ||
| 7736 | |||
| 7737 | # cpe-stable-backport: Backported in 5.15.149 | ||
| 7738 | CVE_CHECK_IGNORE += "CVE-2024-26594" | ||
| 7739 | |||
| 7740 | # CVE-2024-26595 needs backporting (fixed from 6.8rc1) | ||
| 7741 | |||
| 7742 | # fixed-version: only affects 6.1rc1 onwards | ||
| 7743 | CVE_CHECK_IGNORE += "CVE-2024-26596" | ||
| 7744 | |||
| 7745 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7746 | CVE_CHECK_IGNORE += "CVE-2024-26597" | ||
| 7747 | |||
| 7748 | # cpe-stable-backport: Backported in 5.15.148 | ||
| 7749 | CVE_CHECK_IGNORE += "CVE-2024-26598" | ||
| 7750 | |||
| 7751 | # fixed-version: only affects 5.17rc1 onwards | ||
| 7752 | CVE_CHECK_IGNORE += "CVE-2024-26599" | ||
| 7570 | 7753 | ||
