diff options
| -rw-r--r-- | meta/recipes-kernel/linux/cve-exclusion_6.1.inc | 22 | ||||
| -rw-r--r-- | meta/recipes-kernel/linux/linux-yocto-rt_6.1.bb | 6 | ||||
| -rw-r--r-- | meta/recipes-kernel/linux/linux-yocto-tiny_6.1.bb | 6 | ||||
| -rw-r--r-- | meta/recipes-kernel/linux/linux-yocto_6.1.bb | 28 |
4 files changed, 37 insertions, 25 deletions
diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.1.inc b/meta/recipes-kernel/linux/cve-exclusion_6.1.inc index 90b07f0da5..c8ae38b599 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.1.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.1.inc | |||
| @@ -1,9 +1,9 @@ | |||
| 1 | 1 | ||
| 2 | # Auto-generated CVE metadata, DO NOT EDIT BY HAND. | 2 | # Auto-generated CVE metadata, DO NOT EDIT BY HAND. |
| 3 | # Generated at 2023-09-19 16:30:43.403752+00:00 for version 6.1.51 | 3 | # Generated at 2023-09-30 07:24:11.683650+00:00 for version 6.1.52 |
| 4 | 4 | ||
| 5 | python check_kernel_cve_status_version() { | 5 | python check_kernel_cve_status_version() { |
| 6 | this_version = "6.1.51" | 6 | this_version = "6.1.52" |
| 7 | kernel_version = d.getVar("LINUX_VERSION") | 7 | kernel_version = d.getVar("LINUX_VERSION") |
| 8 | if kernel_version != this_version: | 8 | if kernel_version != this_version: |
| 9 | bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) | 9 | bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) |
| @@ -3450,6 +3450,8 @@ CVE_STATUS[CVE-2020-36691] = "fixed-version: Fixed from version 5.8rc1" | |||
| 3450 | 3450 | ||
| 3451 | CVE_STATUS[CVE-2020-36694] = "fixed-version: Fixed from version 5.10" | 3451 | CVE_STATUS[CVE-2020-36694] = "fixed-version: Fixed from version 5.10" |
| 3452 | 3452 | ||
| 3453 | CVE_STATUS[CVE-2020-36766] = "fixed-version: Fixed from version 5.9rc1" | ||
| 3454 | |||
| 3453 | CVE_STATUS[CVE-2020-3702] = "fixed-version: Fixed from version 5.12rc1" | 3455 | CVE_STATUS[CVE-2020-3702] = "fixed-version: Fixed from version 5.12rc1" |
| 3454 | 3456 | ||
| 3455 | CVE_STATUS[CVE-2020-4788] = "fixed-version: Fixed from version 5.10rc5" | 3457 | CVE_STATUS[CVE-2020-4788] = "fixed-version: Fixed from version 5.10rc5" |
| @@ -4644,7 +4646,7 @@ CVE_STATUS[CVE-2023-1192] = "cpe-stable-backport: Backported in 6.1.33" | |||
| 4644 | 4646 | ||
| 4645 | # CVE-2023-1193 has no known resolution | 4647 | # CVE-2023-1193 has no known resolution |
| 4646 | 4648 | ||
| 4647 | # CVE-2023-1194 has no known resolution | 4649 | CVE_STATUS[CVE-2023-1194] = "cpe-stable-backport: Backported in 6.1.34" |
| 4648 | 4650 | ||
| 4649 | CVE_STATUS[CVE-2023-1195] = "fixed-version: Fixed from version 6.1rc3" | 4651 | CVE_STATUS[CVE-2023-1195] = "fixed-version: Fixed from version 6.1rc3" |
| 4650 | 4652 | ||
| @@ -5034,6 +5036,12 @@ CVE_STATUS[CVE-2023-4208] = "cpe-stable-backport: Backported in 6.1.45" | |||
| 5034 | 5036 | ||
| 5035 | CVE_STATUS[CVE-2023-4273] = "cpe-stable-backport: Backported in 6.1.45" | 5037 | CVE_STATUS[CVE-2023-4273] = "cpe-stable-backport: Backported in 6.1.45" |
| 5036 | 5038 | ||
| 5039 | # CVE-2023-42752 needs backporting (fixed from 6.1.53) | ||
| 5040 | |||
| 5041 | # CVE-2023-42753 needs backporting (fixed from 6.1.53) | ||
| 5042 | |||
| 5043 | # CVE-2023-42755 needs backporting (fixed from 6.1.55) | ||
| 5044 | |||
| 5037 | CVE_STATUS[CVE-2023-4385] = "fixed-version: Fixed from version 5.19rc1" | 5045 | CVE_STATUS[CVE-2023-4385] = "fixed-version: Fixed from version 5.19rc1" |
| 5038 | 5046 | ||
| 5039 | CVE_STATUS[CVE-2023-4387] = "fixed-version: Fixed from version 5.18" | 5047 | CVE_STATUS[CVE-2023-4387] = "fixed-version: Fixed from version 5.18" |
| @@ -5054,7 +5062,11 @@ CVE_STATUS[CVE-2023-4611] = "fixed-version: only affects 6.4rc1 onwards" | |||
| 5054 | 5062 | ||
| 5055 | # CVE-2023-4623 needs backporting (fixed from 6.1.53) | 5063 | # CVE-2023-4623 needs backporting (fixed from 6.1.53) |
| 5056 | 5064 | ||
| 5057 | # CVE-2023-4881 needs backporting (fixed from 6.6rc1) | 5065 | # CVE-2023-4881 needs backporting (fixed from 6.1.54) |
| 5066 | |||
| 5067 | # CVE-2023-4921 needs backporting (fixed from 6.1.54) | ||
| 5068 | |||
| 5069 | # CVE-2023-5158 has no known resolution | ||
| 5058 | 5070 | ||
| 5059 | # CVE-2023-4921 needs backporting (fixed from 6.6rc1) | 5071 | # CVE-2023-5197 needs backporting (fixed from 6.6rc3) |
| 5060 | 5072 | ||
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.1.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.1.bb index 5a42da2019..05e0b69331 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.1.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.1.bb | |||
| @@ -14,13 +14,13 @@ python () { | |||
| 14 | raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") | 14 | raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") |
| 15 | } | 15 | } |
| 16 | 16 | ||
| 17 | SRCREV_machine ?= "ad7c05a03b8d70ee30ecce783a861cb96ea258cf" | 17 | SRCREV_machine ?= "7327e7ab3b5508182380405a51f2657f5bf669b4" |
| 18 | SRCREV_meta ?= "f845a7f37d7114230d6609e2bd630070f2f6cd9b" | 18 | SRCREV_meta ?= "9e389e7f44a22bc637328f15e106f6d60631780e" |
| 19 | 19 | ||
| 20 | SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ | 20 | SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ |
| 21 | git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.1;destsuffix=${KMETA};protocol=https" | 21 | git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.1;destsuffix=${KMETA};protocol=https" |
| 22 | 22 | ||
| 23 | LINUX_VERSION ?= "6.1.51" | 23 | LINUX_VERSION ?= "6.1.52" |
| 24 | 24 | ||
| 25 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" | 25 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" |
| 26 | 26 | ||
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.1.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.1.bb index 3fd9a0e2a9..942aa48c02 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.1.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.1.bb | |||
| @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc | |||
| 8 | # CVE exclusions | 8 | # CVE exclusions |
| 9 | include recipes-kernel/linux/cve-exclusion_6.1.inc | 9 | include recipes-kernel/linux/cve-exclusion_6.1.inc |
| 10 | 10 | ||
| 11 | LINUX_VERSION ?= "6.1.51" | 11 | LINUX_VERSION ?= "6.1.52" |
| 12 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" | 12 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" |
| 13 | 13 | ||
| 14 | DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" | 14 | DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" |
| @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" | |||
| 17 | KMETA = "kernel-meta" | 17 | KMETA = "kernel-meta" |
| 18 | KCONF_BSP_AUDIT_LEVEL = "2" | 18 | KCONF_BSP_AUDIT_LEVEL = "2" |
| 19 | 19 | ||
| 20 | SRCREV_machine ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 20 | SRCREV_machine ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 21 | SRCREV_meta ?= "f845a7f37d7114230d6609e2bd630070f2f6cd9b" | 21 | SRCREV_meta ?= "9e389e7f44a22bc637328f15e106f6d60631780e" |
| 22 | 22 | ||
| 23 | PV = "${LINUX_VERSION}+git" | 23 | PV = "${LINUX_VERSION}+git" |
| 24 | 24 | ||
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.1.bb b/meta/recipes-kernel/linux/linux-yocto_6.1.bb index 3798ae3db9..000317379f 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.1.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.1.bb | |||
| @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.1/standard/base" | |||
| 18 | KBRANCH:qemuloongarch64 ?= "v6.1/standard/base" | 18 | KBRANCH:qemuloongarch64 ?= "v6.1/standard/base" |
| 19 | KBRANCH:qemumips64 ?= "v6.1/standard/mti-malta64" | 19 | KBRANCH:qemumips64 ?= "v6.1/standard/mti-malta64" |
| 20 | 20 | ||
| 21 | SRCREV_machine:qemuarm ?= "8c81de99a4b9f69345873b06077f9d4e1321298e" | 21 | SRCREV_machine:qemuarm ?= "3028542fe5ece9dd32c8e3b9b14b2c9f4c9cafac" |
| 22 | SRCREV_machine:qemuarm64 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 22 | SRCREV_machine:qemuarm64 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 23 | SRCREV_machine:qemuloongarch64 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 23 | SRCREV_machine:qemuloongarch64 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 24 | SRCREV_machine:qemumips ?= "733cb5842aeac106f5606df4da7c64a180f0c500" | 24 | SRCREV_machine:qemumips ?= "33c0b5a0c1af6abb4dee11ffa5ece66ffd01d3c8" |
| 25 | SRCREV_machine:qemuppc ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 25 | SRCREV_machine:qemuppc ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 26 | SRCREV_machine:qemuriscv64 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 26 | SRCREV_machine:qemuriscv64 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 27 | SRCREV_machine:qemuriscv32 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 27 | SRCREV_machine:qemuriscv32 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 28 | SRCREV_machine:qemux86 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 28 | SRCREV_machine:qemux86 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 29 | SRCREV_machine:qemux86-64 ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 29 | SRCREV_machine:qemux86-64 ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 30 | SRCREV_machine:qemumips64 ?= "1c11fe963667e9380725bef0650aeaea8544ea8b" | 30 | SRCREV_machine:qemumips64 ?= "ee418f38dbc9794b7976ad11fd74f5a3490c7c5e" |
| 31 | SRCREV_machine ?= "526b5bf2f74f881356bce8b44840dc86785fb7bf" | 31 | SRCREV_machine ?= "b3879adf00e338e66e92431a434fa2549ac88b83" |
| 32 | SRCREV_meta ?= "f845a7f37d7114230d6609e2bd630070f2f6cd9b" | 32 | SRCREV_meta ?= "9e389e7f44a22bc637328f15e106f6d60631780e" |
| 33 | 33 | ||
| 34 | # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll | 34 | # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll |
| 35 | # get the <version>/base branch, which is pure upstream -stable, and the same | 35 | # get the <version>/base branch, which is pure upstream -stable, and the same |
| 36 | # meta SRCREV as the linux-yocto-standard builds. Select your version using the | 36 | # meta SRCREV as the linux-yocto-standard builds. Select your version using the |
| 37 | # normal PREFERRED_VERSION settings. | 37 | # normal PREFERRED_VERSION settings. |
| 38 | BBCLASSEXTEND = "devupstream:target" | 38 | BBCLASSEXTEND = "devupstream:target" |
| 39 | SRCREV_machine:class-devupstream ?= "c2cbfe5f51227dfe6ef7be013f0d56a32c040faa" | 39 | SRCREV_machine:class-devupstream ?= "59b13c2b647e464dd85622c89d7f16c15d681e96" |
| 40 | PN:class-devupstream = "linux-yocto-upstream" | 40 | PN:class-devupstream = "linux-yocto-upstream" |
| 41 | KBRANCH:class-devupstream = "v6.1/base" | 41 | KBRANCH:class-devupstream = "v6.1/base" |
| 42 | 42 | ||
| @@ -45,7 +45,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA | |||
| 45 | SRC_URI += "file://0001-perf-cpumap-Make-counter-as-unsigned-ints.patch" | 45 | SRC_URI += "file://0001-perf-cpumap-Make-counter-as-unsigned-ints.patch" |
| 46 | 46 | ||
| 47 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" | 47 | LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" |
| 48 | LINUX_VERSION ?= "6.1.51" | 48 | LINUX_VERSION ?= "6.1.52" |
| 49 | 49 | ||
| 50 | PV = "${LINUX_VERSION}+git" | 50 | PV = "${LINUX_VERSION}+git" |
| 51 | 51 | ||
