From patchwork Wed Aug 5 17:28:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94631 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0213EC55ABA for ; Wed, 5 Aug 2026 17:29:15 +0000 (UTC) Received: from mta-64-226.siemens.flowmailer.net (mta-64-226.siemens.flowmailer.net [185.136.64.226]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1101.1785950950616168678 for ; Wed, 05 Aug 2026 10:29:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=C0R0ixPm; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.226, mailfrom: fm-256628-2026080517290738656f53e700020782-9rtcly@rts-flowmailer.siemens.com) Received: by mta-64-226.siemens.flowmailer.net with ESMTPSA id 2026080517290738656f53e700020782 for ; Wed, 05 Aug 2026 19:29:07 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc; bh=Udqjs1fADYrCM4MaNws+KYMCT3uNxCyyDuOPCiVmrn0=; b=C0R0ixPmLMuRXjuL4/cEnZoRXV8s/wfPdGFDOUup6yNXZ9ERG9EIcHJNWWuy0rvz/LydcK FjCyZlV7IqFNMM6Ksb9dHBj/n/YN6H55JfgxqSQa2YaHbFomVNT/nqnTfRx8m6aYUncOhrZs N7kBc0ivckM76NQcDXEIqVcBgdklHl284KBj72KOgqu0KCX67KtrSKeTMyGB/8Rp339WhJKf FF8Drl8EL1e7pGe2Qw2zPyeKIoWqQHFqCBtQY3wxIM8bbgXbmtGthQynsHhjYx8ivSttL5jw WPJOiRfjgX+hE2SUfxclJjMxR5hAUTfe7VtPyYKtHxPLVLoD87kn6KUw==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 1/7] gnutls: set status for CVE-2023-0361 Date: Wed, 5 Aug 2026 19:28:34 +0200 Message-ID: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242880 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this CVE was fixed in v3.8.0. [1] https://security-tracker.debian.org/tracker/CVE-2023-0361 Signed-off-by: Peter Marko --- meta/recipes-support/gnutls/gnutls_3.8.13.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/gnutls/gnutls_3.8.13.bb b/meta/recipes-support/gnutls/gnutls_3.8.13.bb index e360db6fff..f48ded3bcc 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.13.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.13.bb @@ -102,6 +102,7 @@ pkg_postinst_ontarget:${PN}-fips () { fi } +CVE_STATUS[CVE-2023-0361] = "fixed-version: fixed in version 3.8.0" CVE_STATUS[CVE-2025-32989] = "fixed-version: fixed in version 3.8.10" CVE_STATUS[CVE-2025-32990] = "fixed-version: fixed in version 3.8.10" CVE_STATUS[CVE-2026-1584] = "fixed-version: fixed in version 3.8.12" From patchwork Wed Aug 5 17:28:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94632 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 07A73C561E6 for ; Wed, 5 Aug 2026 17:29:15 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1092.1785950952828829887 for ; Wed, 05 Aug 2026 10:29:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=jI/TnpKf; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-202608051729102ecd1cbd26000207af-rlyoci@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 202608051729102ecd1cbd26000207af for ; Wed, 05 Aug 2026 19:29:10 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=O6+ht7bNHNNOqG01nESA40vxs29yJI9mpSvf1MF6f8Q=; b=jI/TnpKfBekDICNNZqVdjH59pZRMR6Xoj/oqlJfwNbbQ309OSeBN0h8n3rQJkaq3ypGY2d OYmonoP8bxuVbamaPU9iAU1TWPRFwEthDxZgOuBsBif+BR9gdCKXxj6O0Kc+mKQm4mlDUdXe pilsLr2GaAATMi0got5PDISzJIC5KzPiuLamDG7S6w7Fvx6acSFMjq9cGaFAFoYKq5NJC7IN hNYRfnEj3kayaF/CI0vsupNxl5Gi5c/FLLa0fcg4HCd3Immsg6qbt6SI3eCU2C4vj9J7Kyq8 x/vv1dDZEf4kVCVqvNxsW6LLJVx8J1Ps3wnr5A/LLaRSOl69PmKtazkQ==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 2/7] glibc: set status for CVE-2011-0536 and CVE-2025-0577 Date: Wed, 5 Aug 2026 19:28:35 +0200 Message-ID: <20260805172840.202825-2-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242881 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). * CVE-2011-0536: CVE desciption says it's related to RedHat patches * CVE-2025-0577: [1] linked CVE report says it's related to RedHat patches and no upstream release is impacted [1] https://bugzilla.redhat.com/show_bug.cgi?id=2338871 Signed-off-by: Peter Marko --- meta/recipes-core/glibc/glibc_2.44.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-core/glibc/glibc_2.44.bb b/meta/recipes-core/glibc/glibc_2.44.bb index c629b30827..36841e3308 100644 --- a/meta/recipes-core/glibc/glibc_2.44.bb +++ b/meta/recipes-core/glibc/glibc_2.44.bb @@ -16,6 +16,9 @@ CVE_STATUS[CVE-2019-1010025] = "disputed: \ Allows for ASLR bypass so can bypass some hardening, not an exploit in itself, may allow \ easier access for another. 'ASLR bypass itself is not a vulnerability.'" +CVE_STATUS[CVE-2011-0536] = "not-applicable-platform: specific to RHEL patches" +CVE_STATUS[CVE-2025-0577] = "not-applicable-platform: specific to RHEL patches" + # when upgrading, clear CVE list but keep the variables CVE_STATUS_GROUPS += "CVE_STATUS_STABLE_BACKPORTS" CVE_STATUS_STABLE_BACKPORTS = "\ From patchwork Wed Aug 5 17:28:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94635 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01D52C56203 for ; Wed, 5 Aug 2026 17:29:25 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1092.1785950952828829887 for ; Wed, 05 Aug 2026 10:29:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=djBOKtbQ; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-202608051729144def2b647b000207ca-ebv96w@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 202608051729144def2b647b000207ca for ; Wed, 05 Aug 2026 19:29:14 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=dKJIaN9CJiePbEDoPks5oBhii1Jo01za3clW2gBJOG0=; b=djBOKtbQe/mjSBLrkXZNa900oZZBqRUIiofKUFsPo2ccSpKwaHaf7N81Qz5XDeJFGTmfGA wg6cMVeYpncaBQ//7N5qttl66dOqCTtG4YZaAC1cD8Zhyf3nfjbr2H1uwTpUVklMyyCEHjST xfA9Ue/aA6XE9f9rmzz/xcmo1+nTUYxb9kFKvtDf5VV/NYPm/a35OSprShcxzBYNYXa4k3ui uDUTQJmYqZILjWPItAmzD4iwf61LcH44DAp1OJx0/WjKq1oWURCKxWvbGsoEf7t/NuotrPNw +znlTrB4SazbmO4WOySztMQmScoSUJ759/VgQGnUtvrfT/Ql6W63ivWA==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 3/7] ovmf: set status of CVE-2017-5731 and CVE-2019-14584 Date: Wed, 5 Aug 2026 19:28:36 +0200 Message-ID: <20260805172840.202825-3-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242882 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). OVMF has a generic problem that version is encoded in different ways. Both CVE have their fixed version in NVD CVE reports encoded as YYYY-MM-DD... CVE-2017-5731 additionally predates tags in vurrent git repository. Signed-off-by: Peter Marko --- meta/recipes-core/ovmf/ovmf_git.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-core/ovmf/ovmf_git.bb b/meta/recipes-core/ovmf/ovmf_git.bb index ab276bad1f..660aefcf46 100644 --- a/meta/recipes-core/ovmf/ovmf_git.bb +++ b/meta/recipes-core/ovmf/ovmf_git.bb @@ -31,11 +31,13 @@ CVE_VERSION = "${@d.getVar('PV').split('stable')[1]}" CVE_STATUS[CVE-2014-8271] = "fixed-version: Fixed in svn_16280, which is an unusual versioning breaking version comparison." CVE_STATUS[CVE-2014-4859] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2014-4860] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." +CVE_STATUS[CVE-2017-5731] = "fixed-version: fixed since 2017-11-07" CVE_STATUS[CVE-2019-14553] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14559] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14562] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14563] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14575] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." +CVE_STATUS[CVE-2019-14584] = "fixed-version: fixed since edk2-stables202011" CVE_STATUS[CVE-2019-14586] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2019-14587] = "fixed-version: The CPE in the NVD database doesn't reflect correctly the vulnerable versions." CVE_STATUS[CVE-2024-1298] = "fixed-version: fixed since edk2-stable202405" From patchwork Wed Aug 5 17:28:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94634 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D6346C55ABA for ; Wed, 5 Aug 2026 17:29:24 +0000 (UTC) Received: from mta-64-228.siemens.flowmailer.net (mta-64-228.siemens.flowmailer.net [185.136.64.228]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1099.1785950959601981966 for ; Wed, 05 Aug 2026 10:29:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=APIbbb9+; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.228, mailfrom: fm-256628-202608051729178fa16fd31700020716-bsmee6@rts-flowmailer.siemens.com) Received: by mta-64-228.siemens.flowmailer.net with ESMTPSA id 202608051729178fa16fd31700020716 for ; Wed, 05 Aug 2026 19:29:17 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=C9X9UVVjP9DUK23tyL4VsfX3dTKtNbrvsgKCoZfh6nk=; b=APIbbb9+TcmheyXFiozbuiGkM2GWJcByr3KsFnTT0vDc1op3W3o70YSfWOged+8bwl6rnr nLyI+PJKAidV/DCGQ/jWrohQV4ycuE4K0OACEXSGNuSRX8ULpjG54f1t/l7L4OiNCJ1tmHB1 ES92TTBlEloGvZ/aM/pFjesNk3N9E/lx9sQcANJFMz0Ed4a/bC+L6R7qMwO/jKzIU4rNftWn r8w5C4/bmUiWMdGqsshcN2DoEcsZqh75FkpBUyJ5c7k74+Uc7mdakziCeJse6GwIbyb7KVwv I6eJ1Sd4fFGCil0qOmtKywdAANTIRRjxdHcFuSxKz8yljHDgm6AVaPcg==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 4/7] pulseaudio: set status for CVE-2020-15710 and CVE-2020-16123 Date: Wed, 5 Aug 2026 19:28:37 +0200 Message-ID: <20260805172840.202825-4-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242883 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] and [2] these are Ubuntu specific CVEs. [1] https://security-tracker.debian.org/tracker/CVE-2020-15710 [2] https://security-tracker.debian.org/tracker/CVE-2020-16123 Signed-off-by: Peter Marko --- meta/recipes-multimedia/pulseaudio/pulseaudio.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-multimedia/pulseaudio/pulseaudio.inc b/meta/recipes-multimedia/pulseaudio/pulseaudio.inc index 975929918f..c7690d0e18 100644 --- a/meta/recipes-multimedia/pulseaudio/pulseaudio.inc +++ b/meta/recipes-multimedia/pulseaudio/pulseaudio.inc @@ -299,4 +299,6 @@ RDEPENDS:pulseaudio-server += "${@bb.utils.contains('DISTRO_FEATURES', 'x11', \ bb.utils.contains('DISTRO_FEATURES', 'systemd', 'pulseaudio-module-systemd-login', 'pulseaudio-module-console-kit', d), \ '', d)}" +CVE_STATUS[CVE-2020-15710] = "not-applicable-platform: specific to Ubuntu" +CVE_STATUS[CVE-2020-16123] = "not-applicable-platform: specific to Ubuntu" CVE_STATUS[CVE-2024-11586] = "not-applicable-platform: specific to Ubuntu 16.04" From patchwork Wed Aug 5 17:28:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94633 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA82CC55174 for ; Wed, 5 Aug 2026 17:29:24 +0000 (UTC) Received: from mta-64-228.siemens.flowmailer.net (mta-64-228.siemens.flowmailer.net [185.136.64.228]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1099.1785950959601981966 for ; Wed, 05 Aug 2026 10:29:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=QufzYe9T; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.228, mailfrom: fm-256628-2026080517292175da8b0ffa000207cb-dgk7_r@rts-flowmailer.siemens.com) Received: by mta-64-228.siemens.flowmailer.net with ESMTPSA id 2026080517292175da8b0ffa000207cb for ; Wed, 05 Aug 2026 19:29:21 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=gIHytUycH0c6Wglal5+e1eKW1qpilc7+ARtuoxiOuGk=; b=QufzYe9T4DZWKdwwQNNu/pz9CLHC0xkd8VgQ5Qk4nvvw8K3Y7N0rPJX+JJebWSpwyHukQv rZI9GmqCTaE+rHVeBo4C3QL16RavhHG8E337G5k06OI1eyzxhW0oeA8RhlCPqtq7nJRVI+oO +9TYyKjvCg9p0QpcvqhrbWRLBL1LvUO9k8dY1jOS+nb2wS2yKF6raRlY1pYjrpfV4aO/xMN1 f0Udy+jJ5iPirPZ+Dz1Sg/TQsCNvk/eDMvkLVYCryc2phHNkDycvIY0BCgkpaFvKSFXQUJVN p+/dZ/UBlHT5A3TxYTAI2LJNMnn3NF3ihc1bpz4HtVg9QjL8yJ/mmQ7w==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 5/7] nfs-utils: set status for CVE-2025-12801 Date: Wed, 5 Aug 2026 19:28:38 +0200 Message-ID: <20260805172840.202825-5-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242884 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). This is RedHat version-less CVE. Signed-off-by: Peter Marko --- meta/recipes-connectivity/nfs-utils/nfs-utils_2.9.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-connectivity/nfs-utils/nfs-utils_2.9.1.bb b/meta/recipes-connectivity/nfs-utils/nfs-utils_2.9.1.bb index 06e4fcb6e0..bae63d4f2f 100644 --- a/meta/recipes-connectivity/nfs-utils/nfs-utils_2.9.1.bb +++ b/meta/recipes-connectivity/nfs-utils/nfs-utils_2.9.1.bb @@ -148,3 +148,5 @@ do_install:append () { chown -R rpcuser:rpcuser ${D}${localstatedir}/lib/nfs/statd chmod 0644 ${D}${localstatedir}/lib/nfs/statd/state } + +CVE_STATUS[CVE-2025-12801] = "fixed-version: Fixed since v2.8.6" From patchwork Wed Aug 5 17:28:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94636 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 03C47C55174 for ; Wed, 5 Aug 2026 17:29:35 +0000 (UTC) Received: from mta-64-225.siemens.flowmailer.net (mta-64-225.siemens.flowmailer.net [185.136.64.225]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1101.1785950966791872879 for ; Wed, 05 Aug 2026 10:29:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=kGmT45PY; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.225, mailfrom: fm-256628-202608051729254bb2040d9e00020702-8ttjcf@rts-flowmailer.siemens.com) Received: by mta-64-225.siemens.flowmailer.net with ESMTPSA id 202608051729254bb2040d9e00020702 for ; Wed, 05 Aug 2026 19:29:25 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=9wdb+Ytz79oUEfX36Af+zx6TaZzk0LQNrOpJuLyaqoc=; b=kGmT45PYHiPsQsvx07GwfydHZ9if+fFwxEM3IP1w8FrukAzQKMwNgx3XyyFm58bjPKJPrU +7fCowCIVYaBrQ5cZQgw2o/bFNePH4ospYWTQfpS2+7NF4aU5sImAiKjIEiOASqruotqWK0o ewN2f3ftSH8yhGSTFpCbr18w3HP82DQuv6qMkInFtRjSJVliCmNIFtZ0m5zOI80eovfj+4Ox 8Pj9NGUWVsdCOTb1JpDsvmp7nuyzhxYA1DdldyN+MasnDGt4x4qoJl22aUNo2H4sXakKoC/T eLbLX70+444DzTQ6g84IgICwfHTA3yy+EhHawa0zDvdj7KHyt02uzu4A==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 6/7] openssl: set status for CVE-2015-3216 Date: Wed, 5 Aug 2026 19:28:39 +0200 Message-ID: <20260805172840.202825-6-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242885 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this fffects Red Hat specific patch. [1] https://security-tracker.debian.org/tracker/CVE-2015-3216 Signed-off-by: Peter Marko --- meta/recipes-connectivity/openssl/openssl_3.5.7.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_3.5.7.bb index 212879dfa3..04b2b3de92 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.7.bb @@ -296,3 +296,5 @@ INSANE_SKIP:${PN} = "already-stripped" BBCLASSEXTEND = "native nativesdk" CVE_PRODUCT = "openssl:openssl" + +CVE_STATUS[CVE-2015-3216] = "not-applicable-platform: specific to RHEL patches" From patchwork Wed Aug 5 17:28:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 94637 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E7DBAC55ABA for ; Wed, 5 Aug 2026 17:29:34 +0000 (UTC) Received: from mta-64-225.siemens.flowmailer.net (mta-64-225.siemens.flowmailer.net [185.136.64.225]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1113.1785950970095656161 for ; Wed, 05 Aug 2026 10:29:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=BfYpluIb; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.225, mailfrom: fm-256628-202608051729289b02c1f1a500020794-ul71ox@rts-flowmailer.siemens.com) Received: by mta-64-225.siemens.flowmailer.net with ESMTPSA id 202608051729289b02c1f1a500020794 for ; Wed, 05 Aug 2026 19:29:28 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=pYUmKjiZOvMLH6SWMFvoHxsvMAJykmP4rJ44xvIbth4=; b=BfYpluIb7o8oHepWzYKNcQjwid9ZamDFSNCQ1Ake5R9ESnxAVNt8852cKSwFqwkSl+k85m /lEtBAP8oP1zuhCt45ucSiafS2i6EzZNbBLeJfsOqg55D/Z6ML+fTEzTyJFQkP1pTif62ftE 2fzgg+dWzH5n1tfi/8SbwpOiy1ICOA7T++Em+DmJ6kHT0ThOTasOt4CIXA5zzsxfAOVkRuUx 90cN/G9IBZOgtVBhCyr9CqkONcDGovE3oVkxBw1GaODkhAvDLLaTjtbC8+qQUTHHOcnBc4T9 j0I2Lbft4Wq08mojC2qrFVUB/sCrCEg24Qtqp50TQnU15Zl2+IA8uygg==; From: Peter Marko To: openembedded-core@lists.openembedded.org Cc: Peter Marko Subject: [PATCH 7/7] ppp: set status for CVE-2020-15704 Date: Wed, 5 Aug 2026 19:28:40 +0200 Message-ID: <20260805172840.202825-7-peter.marko@siemens.com> In-Reply-To: <20260805172840.202825-1-peter.marko@siemens.com> References: <20260805172840.202825-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 05 Aug 2026 17:29:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242886 From: Peter Marko New version of sbom-cve-check makes more torough version validation and version strings with distro specific suffix is no longer accepted, thus leaving some CVEs without version to compare (no-version-ranges). Per [1] this is Ubuntu-specific issue. [1] https://security-tracker.debian.org/tracker/CVE-2020-15704 Signed-off-by: Peter Marko --- meta/recipes-connectivity/ppp/ppp_2.5.3.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/ppp/ppp_2.5.3.bb b/meta/recipes-connectivity/ppp/ppp_2.5.3.bb index 3718fabbe8..1815782169 100644 --- a/meta/recipes-connectivity/ppp/ppp_2.5.3.bb +++ b/meta/recipes-connectivity/ppp/ppp_2.5.3.bb @@ -78,3 +78,4 @@ SUMMARY:${PN}-l2tp = "Plugin for PPP for l2tp support" SUMMARY:${PN}-dhcpv6relay = "Plugin which can be used to provide IPv6 RAs to the remote side and relay the subsequent incoming DHCPv6 requests to a DHCPv6 server" SUMMARY:${PN}-tools = "Additional tools for the PPP package" +CVE_STATUS[CVE-2020-15704] = "not-applicable-platform: specific to Ubuntu"