diff mbox series

[12/16] linux-yocto/6.12: update CVE exclusions (6.12.58)

Message ID f5d9554c03561cfac7d5204cb3219fa53dab229e.1764822465.git.bruce.ashfield@gmail.com
State New
Headers show
Series [01/16] linux-yocto/6.17: fix -tiny kernel boot | expand

Commit Message

Bruce Ashfield Dec. 4, 2025, 4:30 a.m. UTC
From: Bruce Ashfield <bruce.ashfield@gmail.com>

Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 4 changes (0 new | 4 updated): - 0 new CVEs: - 4 updated CVEs: CVE-2025-60674, CVE-2025-60676, CVE-2025-7195, CVE-2025-8870
        Date: Fri, 14 Nov 2025 16:39:11 +0000

    ]

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
---
 .../linux/cve-exclusion_6.12.inc              | 204 +++++++++++++++++-
 1 file changed, 201 insertions(+), 3 deletions(-)
diff mbox series

Patch

diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.12.inc b/meta/recipes-kernel/linux/cve-exclusion_6.12.inc
index b35fb07d314..b66f36a2023 100644
--- a/meta/recipes-kernel/linux/cve-exclusion_6.12.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion_6.12.inc
@@ -1,11 +1,11 @@ 
 
 # Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2025-11-03 18:50:12.770797+00:00 for kernel version 6.12.57
-# From linux_kernel_cves cve_2025-11-03_1800Z-3-g832f00439f0
+# Generated at 2025-11-14 16:49:37.841595+00:00 for kernel version 6.12.58
+# From linux_kernel_cves cve_2025-11-14_1600Z-2-g7d42ca6d8de
 
 
 python check_kernel_cve_status_version() {
-    this_version = "6.12.57"
+    this_version = "6.12.58"
     kernel_version = d.getVar("LINUX_VERSION")
     if kernel_version != this_version:
         bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -17692,8 +17692,206 @@  CVE_STATUS[CVE-2025-40106] = "cpe-stable-backport: Backported in 6.12.56"
 
 CVE_STATUS[CVE-2025-40107] = "cpe-stable-backport: Backported in 6.12.52"
 
+CVE_STATUS[CVE-2025-40108] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40109] = "cpe-stable-backport: Backported in 6.12.52"
+
+CVE_STATUS[CVE-2025-40110] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40111] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40112] = "cpe-stable-backport: Backported in 6.12.53"
+
+# CVE-2025-40113 needs backporting (fixed from 6.18rc1)
+
 CVE_STATUS[CVE-2025-40114] = "cpe-stable-backport: Backported in 6.12.23"
 
+CVE_STATUS[CVE-2025-40115] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40116] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40117] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40118] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40119] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40120] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40121] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40122] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40123] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40124] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40125] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40126] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40127] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40129] = "cpe-stable-backport: Backported in 6.12.53"
+
+# CVE-2025-40130 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40131] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40132] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40133] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40134] = "cpe-stable-backport: Backported in 6.12.53"
+
+# CVE-2025-40135 needs backporting (fixed from 6.18rc1)
+
+# CVE-2025-40136 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40137] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40138] = "fixed-version: only affects 6.17 onwards"
+
+# CVE-2025-40139 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40140] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40141] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40142] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40143] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40144] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40145] = "fixed-version: only affects 6.15 onwards"
+
+# CVE-2025-40146 needs backporting (fixed from 6.18rc1)
+
+# CVE-2025-40147 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40148] = "fixed-version: only affects 6.16 onwards"
+
+# CVE-2025-40149 needs backporting (fixed from 6.18rc1)
+
+# CVE-2025-40150 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40151] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40152] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2025-40153] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40154] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40155] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40156] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40157] = "cpe-stable-backport: Backported in 6.12.53"
+
+# CVE-2025-40158 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40159] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40160] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40161] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40162] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40163] = "fixed-version: only affects 6.17 onwards"
+
+# CVE-2025-40164 needs backporting (fixed from 6.18rc2)
+
+CVE_STATUS[CVE-2025-40165] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40166] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40167] = "cpe-stable-backport: Backported in 6.12.55"
+
+# CVE-2025-40168 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40169] = "cpe-stable-backport: Backported in 6.12.53"
+
+# CVE-2025-40170 needs backporting (fixed from 6.18rc1)
+
+CVE_STATUS[CVE-2025-40171] = "cpe-stable-backport: Backported in 6.12.53"
+
+CVE_STATUS[CVE-2025-40172] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40173] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40174] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2025-40175] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40176] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40177] = "cpe-stable-backport: Backported in 6.12.55"
+
+CVE_STATUS[CVE-2025-40178] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40179] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40180] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40181] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40182] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40183] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40184] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40185] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40186] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40187] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40188] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40189] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2025-40190] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40191] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2025-40192] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40193] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40194] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40195] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40196] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40197] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40198] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40199] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40200] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40201] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40202] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40203] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40204] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40205] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40206] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40207] = "cpe-stable-backport: Backported in 6.12.54"
+
+CVE_STATUS[CVE-2025-40208] = "fixed-version: only affects 6.15 onwards"
+
 CVE_STATUS[CVE-2025-40300] = "cpe-stable-backport: Backported in 6.12.47"
 
 # CVE-2025-40325 needs backporting (fixed from 6.15)