mirror of
https://git.yoctoproject.org/poky
synced 2026-04-30 12:32:12 +02:00
linux: review some historic CVE_STATUS
Do manual review and disposition these CVEs as appropriate. (From OE-Core rev: a8db0735e228465715cf885d3b889fddfd68efc6) Signed-off-by: Ross Burton <ross.burton@arm.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
733afeffd1
commit
0dd973297d
@@ -68,9 +68,7 @@ replacing bdb with supported and open source friendly alternatives. As a result
|
||||
CVE_STATUS_GROUPS += "CVE_STATUS_KERNEL_HISTORIC"
|
||||
|
||||
CVE_STATUS_KERNEL_HISTORIC = "CVE-1999-0524 CVE-1999-0656 CVE-2006-2932 CVE-2007-2764 CVE-2007-4998 \
|
||||
CVE-2008-2544 CVE-2008-4609 CVE-2010-0298 CVE-2010-4563 CVE-2011-0640 \
|
||||
CVE-2014-2648 CVE-2016-0774 CVE-2016-3695 CVE-2016-3699 CVE-2017-1000377 \
|
||||
CVE-2017-6264"
|
||||
CVE-2008-2544 CVE-2008-4609 CVE-2010-0298 CVE-2010-4563 CVE-2011-0640"
|
||||
CVE_STATUS_KERNEL_HISTORIC[status] = "ignored"
|
||||
|
||||
|
||||
|
||||
@@ -1,3 +1,15 @@
|
||||
CVE_STATUS[CVE-2014-2648] = "cpe-incorrect: not Linux"
|
||||
|
||||
CVE_STATUS[CVE-2016-0774] = "ignored: result of incomplete backport"
|
||||
|
||||
CVE_STATUS[CVE-2016-3695] = "not-applicable-platform: specific to RHEL with securelevel patches"
|
||||
|
||||
CVE_STATUS[CVE-2016-3699] = "not-applicable-platform: specific to RHEL with securelevel patches"
|
||||
|
||||
CVE_STATUS[CVE-2017-6264] = "not-applicable-platform: Android specific"
|
||||
|
||||
CVE_STATUS[CVE-2017-1000377] = "not-applicable-platform: GRSecurity specific"
|
||||
|
||||
CVE_STATUS[CVE-2018-6559] = "not-applicable-platform: Issue only affects Ubuntu"
|
||||
|
||||
CVE_STATUS[CVE-2020-11935] = "not-applicable-config: Issue only affects aufs, which is not in linux-yocto"
|
||||
|
||||
Reference in New Issue
Block a user