diff options
| author | Daniel Turull <daniel.turull@ericsson.com> | 2026-03-09 02:16:21 -0700 |
|---|---|---|
| committer | Paul Barker <paul@pbarker.dev> | 2026-03-25 17:34:13 +0000 |
| commit | eb31e34477ce1a6b074c178b7ea64249fdd671b0 (patch) | |
| tree | 09f9f0c9fa304bf59d6fe78d739226367a7d9c9c /scripts/contrib | |
| parent | f7363369bf29891e6ca23a6cb22ac6d36820095b (diff) | |
| download | poky-eb31e34477ce1a6b074c178b7ea64249fdd671b0.tar.gz | |
improve_kernel_cve_report: do not override backported-patch
If the user has a CVE_STATUS for their own backported patch,
the backport takes priority over upstream vulnerable versions.
(From OE-Core rev: d317e2a52bd29a772de9bcd751f5b0e03277bd77)
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0beef05be119ea465ba06553a42edea03dfc9fd3)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'scripts/contrib')
| -rwxr-xr-x | scripts/contrib/improve_kernel_cve_report.py | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py index 829cc4cd30..a81aa0ff94 100755 --- a/scripts/contrib/improve_kernel_cve_report.py +++ b/scripts/contrib/improve_kernel_cve_report.py | |||
| @@ -340,6 +340,10 @@ def cve_update(cve_data, cve, entry): | |||
| 340 | if cve_data[cve]['status'] == entry['status']: | 340 | if cve_data[cve]['status'] == entry['status']: |
| 341 | return | 341 | return |
| 342 | if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched": | 342 | if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched": |
| 343 | # Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch) | ||
| 344 | # has priority over unpatch from CNA | ||
| 345 | if cve_data[cve]['detail'] == "backported-patch": | ||
| 346 | return | ||
| 343 | logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve) | 347 | logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve) |
| 344 | cve_data[cve] = copy_data(cve_data[cve], entry) | 348 | cve_data[cve] = copy_data(cve_data[cve], entry) |
| 345 | return | 349 | return |
