Re: [yocto-security] OE-core CVE metrics for master on Sun 16 May 2021 04:00:01 AM HST
From: Richard Purdie <hidden>
Date: 2021-05-17 09:53:20
On Mon, 2021-05-17 at 10:33 +0100, Richard Purdie via lists.yoctoproject.org wrote:
quoted
CVE-2020-35517: qemu:qemu-native:qemu-system-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-35517 *Needs investigation.quoted
CVE-2021-20255: qemu:qemu-native:qemu-system-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-20255 *Still being worked upstream, no fix (available patch is wrong).quoted
CVE-2021-20266: rpm:rpm-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-20266 *
This one has been fixed in our code. Whitelist for the recipe sent, CPE tweak may be possible, they haven't accounted for the point release for rpm (same as CVE-2021-20271).
quoted
CVE-2021-25214: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25214 * CVE-2021-25215: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25215 * CVE-2021-25216: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25216 *
Should all be fixed by the next bind version upgrade in -next.
All need investigation.quoted
CVE-2021-25317: cups https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25317 *Needs investigation.quoted
CVE-2021-29921: python3:python3-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-29921 *
Should be fixed by our python upgrade but CPE entry not caught up. We can exclude, sent a CPE update or wait. Cheers, Richard