Thread (1 message) 1 message, 1 author, 2021-05-17

Re: [yocto-security] OE-core CVE metrics for master on Sun 16 May 2021 04:00:01 AM HST

From: Richard Purdie <hidden>
Date: 2021-05-17 09:53:20

On Mon, 2021-05-17 at 10:33 +0100, Richard Purdie via lists.yoctoproject.org wrote:
quoted
CVE-2020-35517: qemu:qemu-native:qemu-system-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-35517 *
Needs investigation.
quoted
CVE-2021-20255: qemu:qemu-native:qemu-system-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-20255 *
Still being worked upstream, no fix (available patch is wrong).
quoted
CVE-2021-20266: rpm:rpm-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-20266 *
This one has been fixed in our code. Whitelist for the recipe 
sent, CPE tweak may be possible, they haven't accounted for 
the point release for rpm (same as CVE-2021-20271).
quoted
CVE-2021-25214: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25214 *
CVE-2021-25215: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25215 *
CVE-2021-25216: bind https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25216 *
Should all be fixed by the next bind version upgrade in -next.
All need investigation.
quoted
CVE-2021-25317: cups https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25317 *
Needs investigation.
quoted
CVE-2021-29921: python3:python3-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-29921 *
Should be fixed by our python upgrade but CPE entry not caught up. We can 
exclude, sent a CPE update or wait.


Cheers,

Richard
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help